<oembed><type>rich</type><version>1.0</version><author_name>npub1dw88wd5gqsqn6ufxhf9h03uk8087l7gfzdtez5csjlt6pupu4pwsj8plrw</author_name><author_url>https://nostr.ae/npub1dw88wd5gqsqn6ufxhf9h03uk8087l7gfzdtez5csjlt6pupu4pwsj8plrw</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2022-07-11&#xA;📝 Original message:Oops, you are right.  We need the bribe to be the output of the coinbase,&#xA;but due to the maturity rule, it isn&#39;t really a bribe.&#xA;&#xA;Too bad coinbases cannot take other coinbase outputs as inputs to bypass&#xA;the maturity rule.&#xA;&#xA;I guess that means the bribe has to be by leaving transactions in the&#xA;mempool.&#xA;&#xA;Also your point about centralization pressure is well taken.&#xA;&#xA;On Mon, Jul 11, 2022 at 5:56 PM Peter Todd &lt;pete at petertodd.org&gt; wrote:&#xA;&#xA;&gt; On Mon, Jul 11, 2022 at 05:36:52PM -0400, Peter Todd via bitcoin-dev wrote:&#xA;&gt; &gt; On Mon, Jul 11, 2022 at 04:35:02PM -0400, Russell O&#39;Connor via&#xA;&gt; bitcoin-dev wrote:&#xA;&gt; &gt; &gt; &gt; What happens after that I&#39;m not sure.&#xA;&gt; &gt; &gt; &gt;&#xA;&gt; &gt; &gt;&#xA;&gt; &gt; &gt; Miners will learn to create anyone-can-spend outputs to bribe other&#xA;&gt; miners&#xA;&gt; &gt; &gt; to build on their block rather than reorg it.  (Due to the coinbase&#xA;&gt; &gt; &gt; maturity, this will require some amount of floating capital.)&#xA;&gt; &gt;&#xA;&gt; &gt; ...and that&#39;s a disaster for mining centralization, because the smaller&#xA;&gt; miners&#xA;&gt; &gt; need to pay larger bribes than larger miners. Not to mention having to&#xA;&gt; keep&#xA;&gt; &gt; capital around to do it.&#xA;&gt;&#xA;&gt; Also, note how from a practical point of view, we&#39;ll need to add a new&#xA;&gt; type of&#xA;&gt; tx that&#39;s only valid in a specific block, or other miners will just reorg&#xA;&gt; those&#xA;&gt; anyone-can-spend outputs to steal them. It&#39;s not all that trivial to&#xA;&gt; actually&#xA;&gt; do that... you&#39;d have to have a signature that commits to the non-segwit&#xA;&gt; part&#xA;&gt; of the coinbase outputs. Ugh.&#xA;&gt;&#xA;&gt; --&#xA;&gt; https://petertodd.org &#39;peter&#39;[:-1]@petertodd.org&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20220711/2b9c824a/attachment.html&gt;</html></oembed>