Hus

← writing · free 🪂

The Realistic, Lucrative Case of an Ethereum Classic Attack

Published on Medium, 2018-05-28 · medium/@HusamABBOUD

Distillation trail — captured 2018-04 (a NiceHash calculator open in one tab, an ETC chart in the other) → rooted 2018-05 (“hash-rent economics”, note since merged) → freed 2018-05-28. This is how notes grow here: capture → root → free.

A 51% attack is usually discussed as a ghost story. On Ethereum Classic in 2018, it was a business plan — and the numbers closed.

The premise

Proof-of-work security has a price, and the price is public. A chain is safe when the cost of a majority of its hashrate exceeds what an attacker can extract. For Bitcoin that cost is a sovereign budget. For Ethereum Classic in May 2018, it was a rental invoice.

ETC ran the same Ethash algorithm as Ethereum, at roughly 3% of Ethereum’s hashrate. Every Ethereum miner was, by definition, latent ETC attack capacity. And marketplaces like NiceHash would rent it by the hour — no warehouse, no hardware, no commitment.

The math

InputValue (May 2018)
ETC network hashrate≈ 8.8 TH/s
Cost to rent a matching hashrate, per hour≈ US$ 3,800
Hours needed for a deep reorganization1–4
Double-spend capacity per pass (exchange limits)US$ 1–10 M

Rent the hashrate. Deposit ETC on an exchange. Sell it, withdraw, then publish your longer private chain — the deposit never happened, and you hold both the ETC and the proceeds. Cost of the attempt: a few thousand dollars an hour. Upside: seven figures. The asymmetry was the article.

Security is not a property of the ledger. It is a price, quoted hourly, and for ETC the price was wrong.

What I argued

1) Rentable hashrate turns 51% attacks from capital expenditure into operating expense. 2) Chains that share an algorithm with a much larger sibling inherit that sibling’s idle capacity as a standing threat. 3) Exchange confirmation policies — not consensus — were the real security parameter, and they were set as if attacks were fiction.

What happened

In January 2019 Ethereum Classic was 51%-attacked. Deep reorganizations, roughly US$ 1.1 M double-spent, confirmed by Coinbase. The playbook was the one described eight months earlier. I take no pleasure in the accuracy — the point was that the math was public, and anyone could read it.


Press that covered it

original: medium.com/@HusamABBOUD · …8fa0430a7c25