Close Menu
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • Blockchain
    • Mining
  • Stocks
  • Forex
  • Personal Finance
  • World Economy
  • AI in Finance
  • Commodities
  • DeFi
  • Fintech
  • NFTs
  • Learn Finance
Trending
  • Strategies for Investing in Bitcoin
  • XRP Macro Pattern Points To $22 Target – Details
  • Ethereum OG Whale Returns To Market With $19.5M ETH Buy — Details
  • Inside SIREN’s 865% Monthly Surge and What’s Next
  • Gear Up! New Bitcoin Bull Market Is About To Begin — Time To Buy?
  • Meet Cohort 4 of the Next Billion Fellows!
  • ‘Extreme Fear’ Grips Crypto Markets as Bitcoin Drops to 3-Week Low
  • Bitcoin-S&P 500 Correlation Coefficient Signals Impending Market Crash
Facebook X (Twitter) Instagram YouTube
Finance Insider Today
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • Blockchain
    • Mining
  • Stocks
  • Forex
  • Personal Finance
  • World Economy
  • AI in Finance
  • Commodities
  • DeFi
  • Fintech
  • NFTs
  • Learn Finance
Finance Insider Today
Home » Ethereum
Ethereum

The P + epsilon Attack

Finance Insider TodayBy Finance Insider TodayAugust 12, 2025No Comments10 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email


Particular because of Andrew Miller for developing with this assault, and to Zack Hess, Vlad Zamfir and Paul Sztorc for dialogue and responses

One of many extra fascinating surprises in cryptoeconomics in current weeks got here from an assault on SchellingCoin conceived by Andrew Miller earlier this month. Though it has at all times been understood that SchellingCoin, and related programs (together with the extra superior Truthcoin consensus), depend on what’s thus far a brand new and untested cryptoeconomic safety assumption – that one can safely depend on folks appearing actually in a simultaneous consensus sport simply because they imagine that everybody else will – the issues which have been raised thus far need to do with comparatively marginal points like an attacker’s capability to exert small however growing quantities of affect on the output over time by making use of continued strain. This assault, however, exhibits a way more basic drawback.

The situation is described as follows. Suppose that there exists a easy Schelling sport the place customers vote on whether or not or not some explicit truth is true (1) or false (0); say in our instance that it is truly false. Every person can both vote 1 or 0. If a person votes the identical as the bulk, they get a reward of P; in any other case they get 0. Thus, the payoff matrix appears as follows:


You vote 0 You vote 1
Others vote 0 P 0
Others vote 1 0 P


The idea is that if everybody expects everybody else to vote in truth, then their incentive is to additionally vote in truth as a way to adjust to the bulk, and that is the explanation why one can anticipate others to vote in truth within the first place; a self-reinforcing Nash equilibrium.

Now, the assault. Suppose that the attacker credibly commits (eg. by way of an Ethereum contract, by merely placing one’s repute at stake, or by leveraging the repute of a trusted escrow supplier) to pay out X to voters who voted 1 after the sport is over, the place X = P + ε if the bulk votes 0, and X = 0 if the bulk votes 1. Now, the payoff matrix appears like this:


You vote 0 You vote 1
Others vote 0 P P + ε
Others vote 1 0 P


Thus, it is a dominant technique for anybody to vote 1 it doesn’t matter what you assume the bulk will do. Therefore, assuming the system just isn’t dominated by altruists, the bulk will vote 1, and so the attacker is not going to have to pay something in any respect. The assault has efficiently managed to take over the mechanism at zero price. Be aware that this differs from Nicholas Houy’s argument about zero-cost 51% attacks on proof of stake (an argument technically extensible to ASIC-based proof of labor) in that right here no epistemic takeover is required; even when everybody stays lifeless set in a conviction that the attacker goes to fail, their incentive remains to be to vote to help the attacker, as a result of the attacker takes on the failure danger themselves.

Salvaging Schelling Schemes

There are a number of avenues that one can take to attempt to salvage the Schelling mechanism. One method is that as an alternative of spherical N of the Schelling consensus itself deciding who will get rewarded based mostly on the “majority is correct” precept, we use spherical N + 1 to find out who must be rewarded throughout spherical N, with the default equilibrium being that solely individuals who voted accurately throughout spherical N (each on the precise truth in query and on who must be rewarded in spherical N – 1) must be rewarded. Theoretically, this requires an attacker wishing to carry out a cost-free assault to deprave not only one spherical, but additionally all future rounds, making the required capital deposit that the attacker should make unbounded.

Nevertheless, this method has two flaws. First, the mechanism is fragile: if the attacker manages to deprave some spherical within the far future by truly paying up P + ε to everybody, no matter who wins, then the expectation of that corrupted spherical causes an incentive to cooperate with the attacker to back-propagate to all earlier rounds. Therefore, corrupting one spherical is expensive, however corrupting hundreds of rounds just isn’t rather more expensive.

Second, due to discounting, the required deposit to beat the scheme doesn’t must be infinite; it simply must be very very massive (ie. inversely proportional to the prevailing rate of interest). But when all we wish is to make the minimal required bribe bigger, then there exists a a lot easier and higher technique for doing so, pioneered by Paul Storcz: require contributors to place down a big deposit, and construct in a mechanism by which the extra competition there’s, the extra funds are at stake. On the restrict, the place barely over 50% of votes are in favor of 1 final result and 50% in favor of the opposite, the complete deposit it taken away from minority voters. This ensures that the assault nonetheless works, however the bribe should now be larger than the deposit (roughly equal to the payout divided by the discounting price, giving us equal efficiency to the infinite-round sport) relatively than simply the payout for every spherical. Therefore, as a way to overcome such a mechanism, one would want to have the ability to show that one is able to pulling off a 51% assault, and maybe we might merely be comfy with assuming that attackers of that dimension don’t exist.

One other method is to depend on counter-coordination; basically, in some way coordinate, maybe by way of credible commitments, on voting A (if A is the reality) with chance 0.6 and B with chance 0.4, the speculation being that this may permit customers to (probabilistically) declare the mechanism’s reward and a portion of the attacker’s bribe on the identical time. This (appears to) work significantly nicely in video games the place as an alternative of paying out a continuing reward to every majority-compliant voter, the sport is structured to have a continuing complete payoff, adjusting particular person payoffs to perform this objective is required. In such conditions, from a collective-rationality standpoint it’s certainly the case that the group earns a highest revenue by having 49% of its members vote B to say the attacker’s reward and 51% vote A to ensure the attacker’s reward is paid out.




Nevertheless, this method itself suffers from the flaw that, if the attacker’s bribe is excessive sufficient, even from there one can defect. The elemental drawback is that given a probabilistic blended technique between A and B, for every the return at all times modifications (virtually) linearly with the chance parameter. Therefore, if, for the person, it makes extra sense to vote for B than for A, it can additionally make extra sense to vote with chance 0.51 for B than with chance 0.49 for B, and voting with chance 1 for B will work even higher.




Therefore, everybody will defect from the “49% for 1” technique by merely at all times voting for 1, and so 1 will win and the attacker can have succeeded within the costless takeover. The truth that such sophisticated schemes exist, and are available so near “seeming to work” means that maybe within the close to future some advanced counter-coordination scheme will emerge that truly does work; nonetheless, we should be ready for the eventuality that no such scheme can be developed.

Additional Penalties

Given the sheer variety of cryptoeconomic mechanisms that SchellingCoin makes attainable, and the significance of such schemes in practically all purely “trust-free” makes an attempt to forge any type of hyperlink between the cryptographic world and the actual world, this assault poses a possible critical menace – though, as we are going to later see, Schelling schemes as a class are in the end partially salvageable. Nevertheless, what’s extra fascinating is the a lot bigger class of mechanisms that do not look fairly like SchellingCoin at first look, however in reality have very related units of strengths and weaknesses.

Notably, allow us to level to at least one very particular instance: proof of labor. Proof of labor is in reality a multi-equilibrium sport in a lot the identical approach that Schelling schemes are: if there exist two forks, A and B, then in case you mine on the fork that finally ends up profitable you get 25 BTC and in case you mine on the fork that finally ends up dropping you get nothing.


You mine on A You mine on B
Others mine on A 25 0
Others mine on B 0 25


Now, suppose that an attacker launches a double-spend assault in opposition to many events concurrently (this requirement ensures that there is no such thing as a single get together with very robust incentive to oppose the attacker, opposition as an alternative changing into a public good; alternatively the double spend may very well be purely an try to crash the value with the attacker shorting at 10x leverage), and name the “most important” chain A and the attacker’s new double-spend fork B. By default, everybody expects A to win. Nevertheless, the attacker credibly commits to paying out 25.01 BTC to everybody who mines on B if B finally ends up dropping. Therefore, the payoff matrix turns into:


You mine on A You mine on B
Others mine on A 25 25.01
Others mine on B 0 25


Thus, mining on B is a dominant technique no matter one’s epistemic beliefs, and so everybody mines on B, and so the attacker wins and pays out nothing in any respect. Notably, be aware that in proof of labor we do not need deposits, so the extent of bribe required is proportional solely to the mining reward multiplied by the fork size, not the capital price of 51% of all mining gear. Therefore, from a cryptoeconomic safety standpoint, one can in some sense say that proof of labor has just about no cryptoeconomic safety margin in any respect (in case you are bored with opponents of proof of stake pointing you to this article by Andrew Poelstra, be happy to hyperlink them right here in response). If one is genuinely uncomfortable with the weak subjectivity situation of pure proof of stake, then it follows that the right resolution might maybe be to enhance proof of labor with hybrid proof of stake by including safety deposits and double-voting-penalties to mining.

In fact, in follow, proof of labor has survived regardless of this flaw, and certainly it might proceed to outlive for a very long time nonetheless; it might simply be the case that there is a excessive sufficient diploma of altruism that attackers should not truly 100% satisfied that they may succeed – however then, if we’re allowed to depend on altruism, naive proof of stake works fantastic too. Therefore, Schelling schemes too might nicely merely find yourself working in follow, even when they don’t seem to be completely sound in principle.

The subsequent a part of this submit will talk about the idea of “subjective” mechanisms in additional element, and the way they can be utilized to theoretically get round a few of these issues.



Source link

⚠️ Investment Disclaimer
The content published on Finance Insider Today is for informational and educational purposes only. It does not constitute financial advice, investment advice, or any other form of professional advice. Always conduct your own research and consult a qualified financial advisor before making any investment decisions. Finance Insider Today is not responsible for any financial losses resulting from decisions made based on information published on this website. Past performance is not indicative of future results. Financial markets carry significant risk. Never invest more than you can afford to lose.
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Finance Insider Today

Related Posts

Ethereum OG Whale Returns To Market With $19.5M ETH Buy — Details

March 22, 2026

Meet Cohort 4 of the Next Billion Fellows!

March 22, 2026

ZK Grants Round Announcement | Ethereum Foundation Blog

March 22, 2026

Devcon 2024 updates – Secure your tickets, apply to speak, and get involved!

March 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Tornado Cash Trial Enters Week Three, Defense’s Expert Digital Forensics Witness Takes The Stand

July 29, 2025

Ethereum faces diverging paths as Buterin sells, Foundation stakes

March 14, 2026

How To Use Bitcoin ATMs

June 9, 2025

Market Cap Not A Hindrance To XRP Price Reaching $1,000, Expert Explains Why

August 2, 2025

Ripple (XRP) Price Explosion, Shiba Inu’s (SHIB) Potential, and More: Bits Recap July 18

July 18, 2025
CurrencyPrice
UAE Dirham 
UAE Dirham
3.6725
Australian Dollar 
Australian Dollar
1.4235up
Canadian Dollar 
Canadian Dollar
1.3726up
Swiss Franc 
Swiss Franc
0.7883up
Renminbi 
Renminbi
6.8958up
Euro 
Euro
0.8638up
British Pound 
British Pound
0.7495down
Japanese Yen 
Japanese Yen
159.2137down
Malaysian Ringgit 
Malaysian Ringgit
3.9373up
New Zealand Dollar 
New Zealand Dollar
1.7138up
US Dollar 
US Dollar
1
22 Mar · FX Source: CurrencyRate 
CurrencyRate.Today
Check: 22 Mar 2026 15:40 UTC
Latest change: 22 Mar 2026 15:33 UTC
API: CurrencyRate
Disclaimers. This plugin or website cannot guarantee the accuracy of the exchange rates displayed. You should confirm current rates before making any transactions that could be affected by changes in the exchange rates.
⚡You can install this WP plugin on your website from the WordPress official website: Exchange Rates🚀
Categories
  • Altcoins
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Ethereum
  • Forex
  • Mining
  • Personal Finance
  • Stocks
  • World Economy
About us

Finance Insider Today is an independent financial news platform covering global markets, cryptocurrency, economy, fintech, and personal finance. Published daily.

Top Insights

Strategies for Investing in Bitcoin

March 22, 2026

XRP Macro Pattern Points To $22 Target – Details

March 22, 2026

Ethereum OG Whale Returns To Market With $19.5M ETH Buy — Details

March 22, 2026
Categories
  • Altcoins
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Ethereum
  • Forex
  • Mining
  • Personal Finance
  • Stocks
  • World Economy
X (Twitter) Instagram YouTube
  • About us
  • Contact us
  • Advertise With Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
Copyright © 2026 Financeinsidertoday.com All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.