{"type":"rich","version":"1.0","author_name":"npub1pwd0zptc6gwp9sah20h0f4qhpdfkyzc2p078zvm66vzea8pkc4jstdck4f","author_url":"https://nostr.ae/npub1pwd0zptc6gwp9sah20h0f4qhpdfkyzc2p078zvm66vzea8pkc4jstdck4f","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2015-07-15\n📝 Original message:With my black hat on I recently performed numerous profitable \ndouble-spend attacks against zeroconf accepting fools. With my white hat \non, I'm warning everyone. The strategy is simple:\n\ntx1: To merchant, but dust/low-fee/reused-address/large-size/etc. \nanything that miners don't always accept.\n\ntx2: After merchant gives up valuable thing in return, normal tx without \ntriggering spam protections. (loltasticly a Mike Hearn Bitcoin XT node \nwas used to relay the double-spends)\n\nExample success story: tx1 paying Shapeshift.io with 6uBTC output is not \ndust under post-Hearn-relay-drop rules, but is dust under \npre-Hearn-relay-drop rules, followed by tx2 w/o the output and not \npaying Shapeshift.io. F2Pool/Eligius/BTCChina/AntPool etc. are all \nminers who have reverted Hearn's 10x relay fee drop as recommended by \nv0.11.0 release notes and accept these double-spends. Shapeshift.io lost \n~3 BTC this week in multiple txs. (they're no longer accepting zeroconf)\n\nExample success story #2: tx1 with post-Hearn-relay drop fee, followed \nby tx2 with higher fee. Such stupidly low fee txs just don't get mined, \nso wait for a miner to mine tx2. Bought a silly amount of reddit gold \noff Coinbase this way among other things. I'm surprised that reddit \ndidn't cancel the \"fools-gold\" after tx reversal. (did Coinbase \nguarantee those txs?) Also found multiple Bitcoin ATMs vulnerable to \nthis attack. (but simulated attack with tx2s still paying ATM because \ndidn't want to go to trouble of good phys opsec)\n\nShoutouts to BitPay who did things right and notified merchant properly \nwhen tx was reversed.\n\nIn summary, every target depending on zeroconf vulnerable and lost \nsignificant sums of money to totally trivial attacks with high \nprobability. No need for RBF to do this, just normal variations in miner \npolicy. Shapeshift claims to use Super Sophisticated Network Sybil \nAttacking Monitoring from Blockcypher, but relay nodes != miner policy.\n\nConsider yourself warned! My hat is whiter than most, and my skills not \nparticularly good.\n\nWhat to do? Users: Listen to the experts and stop relying on zeroconf. \nBlack hats: Profit!"}
