From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Mon, 18 Mar 2024 06:31:44 -0700 Received: from mail-yb1-f185.google.com ([209.85.219.185]) by mail.fairlystable.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1rmD5b-0000Wp-VQ for bitcoindev@gnusha.org; Mon, 18 Mar 2024 06:31:44 -0700 Received: by mail-yb1-f185.google.com with SMTP id 3f1490d57ef6-dcc05887ee9sf5231006276.1 for ; Mon, 18 Mar 2024 06:31:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1710768697; x=1711373497; darn=gnusha.org; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-sender:mime-version :subject:message-id:to:from:date:sender:from:to:cc:subject:date :message-id:reply-to; bh=T0zJENI+aP+nXaOJgA5t1z39BoQC2zwahx27cA3jlus=; b=q9Gn2VgdfUU9tv+/QD+V6lXkAQYEG4hKSxvnyqFY4XHrZzBwGv9IRU13O6xPw/NudC H+4+hk6u979nPTZ4cZbf8O6EV2VhovHwSULjoGBbz9t/264JVfxahSIc8Dk/KYvA2bMK Z08+bIbuqeYnJPU74ccQ4kKzid8YTX9XlQGX2d+xeLEcNchOb6IFfKN0o4vsK2sp+TRO BziIZzNSrSkuIOvH84dTtfJ517gdlI8DZ3iBCSjJPDtJViFCiyHBL4OLtP/Co7ytTQJ4 oNU8Bue6DrSM6lSIctViBxh7GxABYAr5yxhXcxQKdpZIqrQDsPsM/7UxIEU5BnzrUdbG rl8Q== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1710768697; x=1711373497; darn=gnusha.org; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-sender:mime-version :subject:message-id:to:from:date:from:to:cc:subject:date:message-id :reply-to; bh=T0zJENI+aP+nXaOJgA5t1z39BoQC2zwahx27cA3jlus=; b=MuWzaA2ESJ/qS7jXbQm+nNojmIl+6GC5dkzA4DujL65UNa63HNIDPEovI0wCdV+ZrR VfKHc3zsFaBoXHbsMCxbnwh4kCjR5gYtLJEKGVzf6YxHtcexit5hJthZt6LW48tNM/1i tSVntxll1H5Ea36nlymRmnD6Mj4GJBIjuKNORQRh4Y6sgeraYEPxIpqAyRrDv1VcaHk+ EPYWjKqCicMbN4erAro8f7GPX797o/XUygYqHdV0FwXE9T62+ZRHu67gsdCQZn1/fkZ8 0uCxiBq2MQmNMXZ2ua742D0agXfuYzQyFq1MD6JgD0ODT2oRkIecA2YMQQ8Bb03SKmlg 5NDA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1710768697; x=1711373497; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-sender:mime-version :subject:message-id:to:from:date:x-beenthere:x-gm-message-state :sender:from:to:cc:subject:date:message-id:reply-to; bh=T0zJENI+aP+nXaOJgA5t1z39BoQC2zwahx27cA3jlus=; b=EjP2xGFL8YIIk1f0pG4bHwHvsyn5CfdfdHpX4yT/jvevRFT6mLtoEGz7usnsryp1g6 d/o5OglKbYI6eUg/4TB6q2JGqlJh5H1xPj/vYmNPusPRm//G7b7Yjv2FUlEBFoF5deXP njInedie/dq+wFYPUW9nCEd9EUffF1cFuUaYzqD02OKzBaUKTGOhE2K5JDCT+wqQ2+kp wh4qSn/dko/tRnsrwEqxoE5vxyJSgVBHhHJuUAhRzO3mHmQ1vQLw5CXRg71Rn3tjJqei DwmVpyvo+sY84xUxW5NLiqchfMCLQrdDijkxRaatEHppfzXmXvVEprPY0r9WEpk/l4BL j78g== Sender: bitcoindev@googlegroups.com X-Forwarded-Encrypted: i=1; AJvYcCW9HvauZ5NyUPNVRwGG+LHGcG3c5gg153A4sHm2qZ+uF8NWpGTKG8N2DS/XdsZ7xKvf8jHr55TAhZI6VpdbncTLaPgLQMg= X-Gm-Message-State: AOJu0YyG9cCePZ/oSdUdV4522f8MhpdnlRf0DLVp8lspjqOHDGDSQI0M AGmwsNniphEolyOzelslV2ajXI7HNbj2So29shkuAKOw9miENqTP X-Google-Smtp-Source: AGHT+IHt7o6w4VlAjQedOkwr2NFJNPQ6eI41NpZqC6xX9xOZmt7Zoub869RFZU9hudRefFv5n2hESQ== X-Received: by 2002:a25:bcc6:0:b0:dc6:ff32:aae2 with SMTP id l6-20020a25bcc6000000b00dc6ff32aae2mr8198946ybm.63.1710768697177; Mon, 18 Mar 2024 06:31:37 -0700 (PDT) X-BeenThere: bitcoindev@googlegroups.com Received: by 2002:a25:c7d3:0:b0:dcb:bfe0:81b8 with SMTP id w202-20020a25c7d3000000b00dcbbfe081b8ls787554ybe.0.-pod-prod-09-us; Mon, 18 Mar 2024 06:31:36 -0700 (PDT) X-Received: by 2002:a05:6902:2306:b0:dc7:9218:df47 with SMTP id do6-20020a056902230600b00dc79218df47mr3827625ybb.5.1710768696236; Mon, 18 Mar 2024 06:31:36 -0700 (PDT) Received: by 2002:a05:690c:113:b0:60a:de42:2427 with SMTP id 00721157ae682-60ade422672ms7b3; Mon, 18 Mar 2024 06:19:04 -0700 (PDT) X-Received: by 2002:a81:91c3:0:b0:607:a30d:8cf with SMTP id i186-20020a8191c3000000b00607a30d08cfmr2320439ywg.4.1710767943272; Mon, 18 Mar 2024 06:19:03 -0700 (PDT) Date: Mon, 18 Mar 2024 06:19:02 -0700 (PDT) From: Or Sattath To: Bitcoin Development Mailing List Message-Id: <573ba0d7-522c-424e-898f-caa780c6ecf0n@googlegroups.com> Subject: [bitcoindev] 51% Attack via Difficulty Increase with a Small Quantum Miner MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_Part_424242_415350983.1710767942889" X-Original-Sender: sattath@gmail.com Precedence: list Mailing-list: list bitcoindev@googlegroups.com; contact bitcoindev+owners@googlegroups.com List-ID: X-Google-Group-Id: 786775582512 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Score: -0.5 (/) ------=_Part_424242_415350983.1710767942889 Content-Type: multipart/alternative; boundary="----=_Part_424243_1589595985.1710767942889" ------=_Part_424243_1589595985.1710767942889 Content-Type: text/plain; charset="UTF-8" Hi, In a recent work with Bolton Bailey (still not peer-reviewed) , we showed how a single quantum miner, with relatively little hashing power, can execute a 51% attack. *The attack isn't relevant for the forthcoming years, requiring an extremely fast, noise-tolerant quantum computer.* The attack is surprisingly simple. The attacker creates a private fork, increasing the difficulty by a factor c. Due to the properties of Grover's algorithm, it is only \sqrt c harder for the quantum miner to mine at the new difficulty level, but these blocks count as $c$ times more for the PoW. Therefore, by mining even a single epoch for a large enough $c$, the quantum miner can generate more proof-of-work than the competing (classical) chain. The complexity of the attack is ~1/r^2 epochs, where r is the fraction of the block rewards that the quantum miner would have received if they mined honestly. This attack (or variants thereof) provides essentially the same benefits as classical 51% attacks, including double spending, and all the revenue from the block rewards. This attack might be relevant when considering future protocol modifications. Or -- You received this message because you are subscribed to the Google Groups "Bitcoin Development Mailing List" group. To unsubscribe from this group and stop receiving emails from it, send an email to bitcoindev+unsubscribe@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/bitcoindev/573ba0d7-522c-424e-898f-caa780c6ecf0n%40googlegroups.com. ------=_Part_424243_1589595985.1710767942889 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi,
In a recent work= =C2=A0with=C2=A0Bolton Bailey (still not peer-reviewed)=C2=A0, we showed ho= w a single quantum miner, with relatively little hashing power, can execute= a 51% attack. The attack isn't relevant for the=C2=A0forthcoming years, requiring an extremel= y fast, noise-tolerant quantum computer.
The attack is= surprisingly simple. The attacker creates a private fork, increasing the d= ifficulty by a factor c. Due to the properties of Grover's algorithm, it is= only \sqrt c harder for the quantum miner to mine at the new difficulty le= vel, but these blocks count as $c$ times more for the PoW. Therefore, by mi= ning even a single epoch for a large enough $c$, the quantum miner can gene= rate more proof-of-work than the competing (classical) chain. The complexit= y of the attack is ~1/r^2 epochs, where r is the fraction of the block rewa= rds that the quantum miner would have received if they mined honestly. This= attack (or variants thereof) provides essentially the same benefits as cla= ssical 51% attacks, including double spending, and all the revenue from the= block rewards.=C2=A0

This attack might be relev= ant when considering future protocol modifications.

<= div>Or



--
You received this message because you are subscribed to the Google Groups &= quot;Bitcoin Development Mailing List" group.
To unsubscribe from this group and stop receiving emails from it, send an e= mail to bitcoind= ev+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msg= id/bitcoindev/573ba0d7-522c-424e-898f-caa780c6ecf0n%40googlegroups.com.=
------=_Part_424243_1589595985.1710767942889-- ------=_Part_424242_415350983.1710767942889--