It seems like a 26% attacker can censor BIP 300 bundles indefinitely: Assume some drivechain publishes a valid bundle, the attacker can send ALARM messages in all of her blocks to reduce its score by 1 in each block. Since the expected score increase per block is 0.74 - 0.26 = 0.48, its expected score in the 26300 block window is 0.48 * 26300 = 12624, which is less than the required score of 13150, so the bundle will almost certainly fail (this is only an approximation, since hitting the 13150 wall at any point is enough for the bundle to get accepted). I think the fix to it should be quite simple: once we forbid ALARM messages or any kind of downvote, we can revert to the honest majority security assumption - a proposal with 51% support will almost certainly succeed to pass the threshold, and a proposal with 49% support will almost certainly fail to pass it. If this is intentional, I suggest changing the BIP to reflect the 75% honest majority assumption, since this is a strong deviation from Bitcoin's security model (one argument for it would be to make it extra difficult for an attacker with less than 75% of the hashrate to steal funds). If this is not intentional, I suggest to forbid ALARM messages or any kind of downvote, so we revert to the 50% honest majority security assumption - a proposal with 51% support will almost certainly succeed to pass the threshold, and a proposal with 49% support will almost certainly fail to pass it. -- You received this message because you are subscribed to the Google Groups "Bitcoin Development Mailing List" group. To unsubscribe from this group and stop receiving emails from it, send an email to bitcoindev+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/bitcoindev/2e554c89-a2a1-4bcf-941c-32f6a8ba9567n%40googlegroups.com.