Pay to Win: Cheap, Cross-Chain Bribing Attacks on PoW Cryptocurrencies

Aljosha Judmayer, Nicholas Stifter, Alexei Zamyatin, Itay Tsabary, Ittay Eyal, Peter Gaži, Sarah Meiklejohn, Edgar Weippl

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

In this paper we extend the attack landscape of bribing attacks on cryptocurrencies by presenting a new method, which we call Pay-To-Win (P2W). To the best of our knowledge, it is the first approach capable of facilitating double-spend collusion across different blockchains. Moreover, our technique can also be used to specifically incentivize transaction exclusion or (re)ordering. For our construction we rely on smart contracts to render the payment and receipt of bribes trustless for the briber as well as the bribee. Attacks using our approach are operated and financed out-of-band i.e., on a funding cryptocurrency, while the consequences are induced in a different target cryptocurrency. Hereby, the main requirement is that smart contracts on the funding cryptocurrency are able to verify consensus rules of the target. For a concrete instantiation of our P2W method, we choose Bitcoin as a target and Ethereum as a funding cryptocurrency. Our P2W method is designed in a way that reimburses collaborators even in the case of an unsuccessful attack. Interestingly, this actually renders our approach approximately one order of magnitude cheaper than comparable bribing techniques (e.g., the whale attack). We demonstrate the technical feasibility of P2W attacks through publishing all relevant artifacts of this paper, ranging from calculations of success probabilities to a fully functional proof-of-concept implementation, consisting of an Ethereum smart contract and a Python client.

Original languageEnglish
Title of host publicationFinancial Cryptography and Data Security. FC 2021 International Workshops - CoDecFin, DeFi, VOTING, and WTSC, Revised Selected Papers
EditorsMatthew Bernhard, Andrea Bracciali, Lewis Gudgeon, Thomas Haines, Ariah Klages-Mundt, Shin'ichiro Matsuo, Daniel Perez, Massimiliano Sala, Sam Werner
PublisherSpringer Science and Business Media Deutschland GmbH
Pages533-549
Number of pages17
ISBN (Print)9783662639573
DOIs
StatePublished - 2021
Event2nd Workshop on Coordination of Decentralized Finance, CoDecFin 2021, 1st Workshop on Decentralized Finance, DeFi 2021, 6th Workshop on Advances in Secure Electronic Voting, VOTING 2021, and 5th Workshop on Trusted Smart Contracts, WTSC 2021, held in co... - Virtual, Online
Duration: 5 Mar 20215 Mar 2021

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume12676 LNCS

Conference

Conference2nd Workshop on Coordination of Decentralized Finance, CoDecFin 2021, 1st Workshop on Decentralized Finance, DeFi 2021, 6th Workshop on Advances in Secure Electronic Voting, VOTING 2021, and 5th Workshop on Trusted Smart Contracts, WTSC 2021, held in co...
CityVirtual, Online
Period5/03/215/03/21

Keywords

  • Algorithmic incentive manipulation
  • Bitcoin
  • Bribing
  • Ethereum
  • Smart contracts

All Science Journal Classification (ASJC) codes

  • Theoretical Computer Science
  • Computer Science(all)

Fingerprint

Dive into the research topics of 'Pay to Win: Cheap, Cross-Chain Bribing Attacks on PoW Cryptocurrencies'. Together they form a unique fingerprint.

Cite this