back
174 comments
I think this misses the elephant in the room: the tech may have flaws, but there's far worse flaws.

Who is it that actually has control and influence in crypto?

1. The developers. 2. The miners. 3. Everyone else (very distant from the rest)

The developers aren't decentralized at all, they typically are a single, small team with some sort of leader. They can make a lot of decisions almost unilaterally.

Then very close below are the miners. The miners have serious economic concerns, so they can do things like refusing to run the software the developers provide. So we can expect devs and miners to be in close contact in most cryptocurrencies.

And very far below that is everyone else. You can run your "full node", but most nobody cares. Miners decide what goes or doesn't on the network.

And that's why Bitcoin is the way it is. Back when fees rose to $50/transaction because the capacity was overwhelmed...

Did the devs have a problem? No, because they had ideas how to sell add-on products to deal with that issue, and such products are much easier to sell when there's a problem that needs fixing.

Did the miners have a problem? No, because the network was still heavily used and they were reaping all those juicy fees coming their way.

Did the users have a problem? Yes, their experience sucked badly. But for both parties actually in control solving those problems would require losing money.

And thus crypto ends up being controlled by a small cabal of elites, while the normal users get screwed.

> You can run your "full node", but most nobody cares. Miners decide what goes or doesn't on the network.

Limiting myself to BTC, this is not how it works.

Miners can emit as much nonsense, noise, malformed information as they want. Full nodes perform validation: they decide what a compliant chain looks like, and only accept contributions from miners which have that shape.

This is why there was such a vicious fight about block size: the side which won the mindshare and economic value fought for a small blockchain so that running a full node remains feasible forever.

Validation is a huge problem with more profligate blockchains, some/many of which are de-facto centralized due to the excessive hardware requirements.

It is on an architecture and algorithm level a critical part of the decentralization of bitcoin, something I expect HN to get right regardless of their position on bitcoin's worth to civilization.

Edit for more detail: an object-level example is that miners cannot unilaterally start issuing larger blocks. These will fail validation by the full nodes, ergo, it is the full nodes which determine what Bitcoin is or isn't. Miners merely construct data which has that shape.

Yanis Varoufakis recently called crypto currencies “oligarchic” which is very fitting. Quote:

“I do not believe that the… ‘oligarchic,’ by definition, cryptocurrency like Bitcoin is ever going to replace [conventional currency]. It shouldn’t, it can’t, and it would be a nightmare if it did.”

Full interview in which he also discusses his proposal for cryptocurrencies run by central banks and why that’s (according to him) the way to go: https://www.kitco.com/news/2022-05-27/Gold-and-Bitcoin-won-t...

> The developers aren't decentralized at all, they typically are a single, small team with some sort of leader. They can make a lot of decisions almost unilaterally.

That's painting everyone with the same brush...

It may be true for many projects, but the second largest blockchain (by marketcap), Ethereum, has like 10 independent client teams and a strong concentration on client diversity [1].

The media likes to paint Vitalik (one of the original founders) as the "leader" of Ethereum, but everyone that's actually working in Ethereum knows that he's at best an advisor these days, and has intentionally taken a back seat in terms of leadership to avoid the very effect you are describing.

> And very far below that is everyone else. You can run your "full node", but most nobody cares. Miners decide what goes or doesn't on the network.

> And that's why Bitcoin is the way it is. Back when fees rose to $50/transaction because the capacity was overwhelmed...

That is not why transaction fees are high... and miners do not decide what goes or doesn't on the network. That's a huge misconception.

Transaction fees are driven by demand, plain and simple. Demand is high in a scarce blockspace, so the fee goes up to keep the network stable.

Also, miners can't decide to just change the rules, that's a big misconception of the Sybil problem further driven by popular media. The rules are the rules, if miners don't follow them, clients (full or light) won't follow that chain, period.

Even if 50%+ of miners colluded, all they could do is prevent a consensus from forming (called "censorship"), so basically a DDoS. They cannot change the rules and "trick" clients into following them, as it is often portrayed!

If you're referring to miners having influence on what the rules are, as in influence over development, that's been tried and failed multiple times on multiple networks. In reality, devs and companies/user sentiment drives the majority of "social consensus".

If you need evidence of that, Ethereum's switch to PoS will eliminate mining, and yet it's still happening. For a past example, EIP-1559 was opposed by many large mining pools, still happened (because it improved user experience by making gas fees more predictable / reducing failed transactions -- in direct contradiction to your point).

[1] https://clientdiversity.org/

Ethereum has five independent execution clients, five independent staking clients, and an open community of researchers.
Everybody who is insanely dissatisfied about the direction some blockchain develops into can drum up a following and do a hard fork of the blockchain if they desire.
Your analysis seems correct in theory -- but in practice, in terms of "the things that actually affect people," you're overwhelmingly missing that group that is in "3" that's easily number one -- which is the whales who control the price?
This is assuming the developers are willing to act in the way you are describing but with our ability to audit their work I am not convinced that will necessarily happen.
I was wondering how Ethereum founder Vitalik Buterin is able to walk around without a security detail, going on extensive backpacking trips, what if someone steals his keys?

He’d just fork the entire blockchain.

Normal users don’t have that luxury.

This is interesting research and I encourage everyone to go read the article. But, on the assumption that a lot of people will just read the headline and comments I'm going to preemptively talk about the question there ...

People misunderstand decentralisation in practice. Computer types, when they talk about decentralisation, usually mean a relatively large number of homogeneous nodes acting as peers. Which is cool but not how decentralised systems work in practice out in the meaty reality we all live in.

In reality, we have an economy that quickly works out who is the best (say, Samuel is the best) at something (say, mining bitcoin) and routes most of the resources available for hashing to Samuel. The situation is still decentralised, because if Samuel stops being the best at calculating hashes then resources will be reallocated to someone else. But in the short term all the resources will go to Samuel and he could do a lot of damage to the network.

People keep thinking that because the economy picks out a few winners that means that the system is now locked in stone - that isn't the case. The economy is perfectly happy to change things up radically when the situation changes. At least until a government steps in and regulates the ability to change flexibly out of the system.

Except that Samuel wants to keep his place. So he will do whatever he can to leverage his current centrality to continue. His hope is to be in control when the hammer falls and flexibility stops. One way of doing that is to force the issue. Those in central positions within a dynamic market eventually seek to kill that market, leaving them in the monopoly position (amazon, google, facebook etc). To maintain decentralization in the long term such leaders need to be periodically culled, hopefully though market forces prior to them killing the market. In bitcoin, that might mean periodic removal of the largest commercial actors, perhaps by periodic price crashes that favor niche setups.
> At least until a government steps in and regulates the ability to change flexibly out of the system.

Just as often, the government is the only one who can keep the flexibility and ensure free competition. E.g. https://en.wikipedia.org/wiki/Sherman_Antitrust_Act_of_1890

By this definition, the current financial system is also decentralised. After all, if one bank fails, a new bank could very easily take its place. Even our system of central banks consists of a relatively large number of more or less equal peers. If the US central bank fails, I'm sure "the economy" will be more than happy to change things up radically and reassign some of the global influence on the financial system that the fed currently has to competing nations' central banks.
> Which is cool but not how decentralised systems work in practice ... In reality, we have an economy that quickly works out who is the best .. and routes most of the resources available for hashing there

I disagree, somewhat. It depends on the purpose of the decentralisation. If your aim is "best" which I think also means "cheapest" then yes, you have described what could happen.

But decentralisation can also have "resilience" as the goal, even at the expense of the best performance.

These goals might even be in conflict. What if Samuel, as noted "wants to keep his place". What if Samuel wants all the traffic to go him so that at some time, he can subvert it in some way. He may only need 51% of the traffic. He may be willing to take a loss for a while to get into this position. He may even have a government backer willing to spend a lot on outcomes and not be seeking a profit in itself.

And as noted, when Samuel is suddenly no the "best" after a long time in that position, chaos could ensue.

I hear "resilient" when "decentralised" is said. Many others will too. You're showing how this may be very misleading.

By your definition of decentralization (a central entity could theoretically be replaced) everything from the Roman Empire to North Korea is decentralized - nothing is guaranteed to have its place forever. A definition that applies to every imaginable instance is pointless, but more importantly, it's far from how people commonly use the word.
> People keep thinking that because the economy picks out a few winners that means that the system is now locked in stone - that isn't the case. The economy is perfectly happy to change things up radically when the situation changes. At least until a government steps in and regulates the ability to change flexibly out of the system.

This flexibility and survival of the fittest mentality is costing people billions; of course a government would step in, because clearly the economic techno-libertarians aren't able to come up with a secure and stable system.

At some point, cryptocurrencies and blockchain technologies sounded like We The People taking power back from the big bad government and banks. In practice, it turns out - to everyone's sarcastic surprise - that a handful of people got very rich off it and shat on those lofty goals.

I'm not buying it. Never did. Yeah I missed the boat on getting rich and I am salty about it, so it exceeded my initial cynicism, but it's still inherently broken. Unregulated finance attracts conmen. So does regulated finance but at least they can be tracked down.

The royal family of Britain has occasionally changed over time. Is it decentralized?
What the article is missing is the incentive structure.

For example: "The number of entities sufficient to disrupt a blockchain is relatively low: four for Bitcoin".

This probably refers to the 4 largest mining pools.

Yes, they could temporarily annoy some people by not processing their transactions. But it would come at a giant cost to them. They would be out of business quickly as miners can switch to a different pool in minutes.

That is like saying the US economy is brittle because if Walmart, Apple, Amazon and ExxonMobil would just send everybody home and set their premises on fire, there would be a problem.

Completely agree. It's impossible to inspect any aspect of Bitcoin's design without considering its incentive structures. They are the innovation in my mind. Every blockchain/crypto/Dao/<insert buzz word> forgoes one of Bitcoin's perfectly balanced incentive structures in favor of some "innovation" (speed, programability, founder/VC enrichment) which always inevitably leads to centralization and exploitable risk somewhere in the system.

Every time it happens it hardens my opinion that a L1 should be like the foundation of a building - it should have one job (be hard money), it should be simply and elegantly designed, it shouldn't have any cracks (a.k.a misaligned incentive structures), it should evolve very slowly if at all, and it should be designed to be built on top of. L1 exists to anchor L1+N to the real world and that's it.

It would be easier even than that, observe what happened in 2017. Bitfinex said they would allocate the BTC ticker to the present BTC chain no matter what the hash power indicated was the actual canonical chain and that was the end of it.

Contrary to popular belief, miners aren't choosing anything when it comes to BTC. They're rubber stamping the decisions of the BTC core developers, who are blessed by the exchanges such as Bitfinex, and they are collecting fees on that rubber stamp.

That's fair enough, but I believe the paper stayed in its bounds; it is correct that given the means or the willpower control could be assumed. What you should be more worried about than blatant double-spends are all the hidden ways having 51% of network control allows you to cartel, centralize, and siphon funds away from smaller, newer players in the system.

https://saito.tech/the-double-spend-attack-is-not-the-same-a...

But those companies only exist because the US regulatory framework allows them to exist as long as they follow the rules. If the CEO of Walmart sent out an email saying that everyone was fired and that all stores should be demolished, he would be fired by the board of directors within hours. Also other executives would respond to the email telling everyone to ignore the previous email while they see if the CEO was hacked.

The entire point of crypto is to bypass the regulatory framework. In some cases that may make for a more robust system in some cases it may not.

Yes they’re incentivized not to, but when push comes to shove, they can basically choose their own form of “truth” and ignore/disrupt/revert transactions and others would need to fork the chain. It’s not a given which would succeed.

This has happened before

This is great research and if anything understates the case for alarm; Bitcoin is one of the more-decentralized projects, and PoW generally has some incentives for diverse hosting (if not network layer). PoS systems often end up on AWS specifically, and sometimes depend on some of the more niche AWS services -- an outage (engineered or accidental) in those could cause easy degradation and facilitate takeover.
Actually, no. It isn't that great. A lot of people are correcting specific points here in the comments.

> More than one in five Bitcoin nodes are running an old version of the Bitcoin core client that is known to be vulnerable.

This is brought out as an issue, but it really doesn't matter. Being a large decentralized systems means that having nodes which are at all sorts of different versions, can still work. This is like saying that everyone has to be at the same web browser version for websites to work.

The thing that matters is that the nodes that are used for forming blocks (ie: the nodes the pools are running), are updated.

Honestly there’s a lot of valid points to be made here but the actual report reads as if their intention was to prove blockchains are insecure and centralized.

That is true for a lot of them, but true Nakamoto consensus is not quite as fragile as they suggest it is.

They don’t provide an analysis of the true cost of launching a 51% attack.

Their assertions about the security risk of “altering the software that nodes run” fail to mention how this is a voluntary process which all node operators choose to undergo. If a consensus emerges on the network or a subset of the network that the changes are problematic, these dissenting node operators can choose to hard fork. There will be few supporters of an obviously malicious attack in the network, so it would be unable to gain traction.

Their point about the number of entities in control of Bitcoin is technically correct, because of the way that pooling works in Bitcoin: many nodes send any propfs they find to one node, and that one node writes to the blockchain. So, there is a definite concentration of power. There are some in depth game theoretical analyses of why this is unlikely to become a problem but in general it is easy to imagine that, for instance, the US treasury would not want to destroy trust in the USD.

Interestingly, Chia, a new proof of work blockchain which launched a year ago, developed by Bram Cohen, has a unique and innovative solution to pooling which does not result in concentration of power: individual node operators submit proofs to the network, not to the pool, and the pool receives a fraction of the reward for minting a new block. Chia also has more full nodes than any oher blockchain, including Bitcoin. At this point it’s relatively unknown however.

> They don’t provide an analysis of the true cost of launching a 51% attack.

Andreas Antonopoulos has done this many times already.

https://www.youtube.com/watch?v=ncPyMUfNyVM (one of my favorites and only a couple minutes long)

https://www.youtube.com/watch?v=-ZTGmTjqXEU

https://www.youtube.com/watch?v=N-La8gyNVCI

https://www.youtube.com/watch?v=JDZVW4hri2g

The subtext of the DARPA funding makes me think the purpose of this paper is to analyze whether governments can disrupt, block, or compromise cryptocurrencies. The conclusions make some more sense in that light. Still, I think they fail to address several mitigating factors for each of the issues, which weakens the overall message:

(1) Mining pools are not even remotely static. In fact, they gain/lose marketshare very quickly, and when problems are discovered, miners actually move. Therefore, it would have to be shown that these pools can be disrupted clandestinely, otherwise an attempted takeover/51% attack would just cause a rebalancing of the pools. To better understand this, it's good to visualize it; here's a graph of changes to miner pool distribution over time: [0]

(2) 51% attacks permit double-spend, but many guarantees persist in the light of 51% attacks - nobody can invent coins they don't have with a 51% attack; they can just undo transactions that were assumed to be settled [1].

(3) Software centralization and the implied lack of immutability is subject to the voting influences of node operators; maintainers can't just do whatever they want (in other words, backdoors would probably need to be bugdoors, else they would not be deployed and therefore de facto rejected). Taking Bitcoin as an example, many BIPs have been withdrawn or rejected, either early in the development process or later by the community refusing to adopt releases they don't support: [2]. And you can see this process at work in the block size debates and ultimate resolution [3].

ISP centrality and the vulnerability of the network to malicious Tor exit nodes is the most interesting point to me. Miners can go switch pools, and node operators can band together & refuse to update to new software that does things they disagree with. But can node operators/miners switch ISPs quickly and easily? Not really. There's virtually no free market competition among ISPs, so people can't freely switch ISPs if theirs starts inserting arbitrary latency into Bitcoin traffic. We probably need some ways to operate nodes/miners that are less sensitive to corrupt ISP disruption.

Encrypting BTC P2P traffic and developing strategies for operating nodes/miners behind anti-censorship software like ShadowSocks should be high-priority.

[0]: https://public.flourish.studio/visualisation/2879848/

[1]: "Even a 51% attacker cannot propose a block that takes away your ETH, because such a block would violate the protocol rules and so it would get rejected by the network. Even if 99% of the hashpower or stake wants to take away your ETH, everyone running a node would just follow the chain with the remaining 1%, because only its blocks follow the protocol rules. More generally, if you have an application on Ethereum, then a 51% attack could censor or revert it for some time, but what comes out at the end is a consistent state." - Vitalik, https://old.reddit.com/r/ethereum/comments/rwojtk/ama_we_are...

[2]: https://en.wikipedia.org/wiki/Bitcoin_Improvement_Proposals#...

[3]: https://en.bitcoin.it/wiki/Block_size_limit_controversy

> The research to which this blog post refers was conducted by Trail of Bits based upon work supported by DARPA under Contract No. HR001120C0084

More info: https://govtribe.com/award/federal-contract-award/definitive...

"On October 25, 2021, a vulnerability in all prior versions of Geth was discovered that permitted a carefully crafted peer-to-peer message to inflict a denial-of-service attack on the receiving node. 42 From our crawls of the Bitcoin network, we observe that 21% of Bitcoin nodes are running an old version of the Bitcoin Core client that is known to be vulnerable."

The beginning of this excerpt is talking about Geth, and how unpatched Geth resulted in a fork of Ethereum. Then, out of nowhere they indicated 21% of Bitcoin nodes are vulnerable and running an old version of the bitcoin core client, and they bold it. They didn't say anything about this vulnerability in the preceding paragraph. Vulnerable to what? Certainly not vulnerable to the same thing that Geth exploit took advantage of.

In July 2016, we created a simple spreadsheet [1] comparing different blockchains and security state of the art at that time [2]. There are things to review there but the theoretical attack to Bitcoin was relatively low for state actors and miners. Miners are not incentivized to do this or do it only as the latest option.

It is also important to know that new blockchain technologies such as Solana, Algorand, Avalanche don't have enough scientific peer reviews to make a strong claim in favor or against them now.

[1] https://blog.coinfabrik.com/wp-content/uploads/2016/07/Block...

[2] https://blog.coinfabrik.com/cryptocurrency/overview-of-block...

> Tor is now the largest network provider in Bitcoin; just about 55% of Bitcoin nodes were addressable only via Tor (as of March 2022). A malicious Tor exit node can modify or drop traffic.

Tor's onion services are end-to-end encrypted and do not use exit nodes.

> Tor is now the largest network provider in Bitcoin; just about 55% of Bitcoin nodes were addressable only via Tor (as of March 2022). A malicious Tor exit node can modify or drop traffic.

I'm not sure if I understand this criticism. Is it not true that if something is ONLY available via Tor, then exit nodes are NOT used at all when accessing it, and all of the traffic is encrypted with Tor's encryption layer?

You are correct, the researchers just did not realize this.
I found it interesting reading the blog post, but delving into the report, some areas didn't seem as straightforward.

I expect to get some flak for saying this, and I don't mean to be cynical, but it's interesting how the table on p. 9 of the report lists Solana with a relatively high Nakamoto coefficient (19 to Bitcoin's 4), given the recent events with Solana [0].

From p. 1 of the report, emphasis my own:

> Trail of Bits also operates a center of excellence for blockchain security. Notable projects include audits of Algorand, Bitcoin SV, Chainlink, Compound, Cosmos, Ethereum 2.0, MakerDAO, Matic, Polkadot, Solana, Uniswap, Web3, and Zcash.

Some of those notable projects are fervently anti-bitcoin, so while some criticisms and concerns may appear to be valid at a first glance, I don't think it can be said to be without bias.

[0]: https://www.coindesk.com/tech/2022/06/19/solana-defi-platfor...

Trail of Bits has no pro- or anti- position when it comes to various cryptocurrency projects. Moreover, this research was entirely funded by DARPA, and was not assisted by any project. Finally, the results only address decentralization, and not the myriad other ways in which these schemes can be economically, politically, or cryptographically unsound.

FD: My employer.

That was Solend, not Solana. The concern was just that a liquidation of that scale would significantly move the market.
There are very good reasons to be fervently anti-BTC given its history since 2017.
> "For a blockchain to be optimally distributed, there must be a so-called Sybil cost. There is currently no known way to implement Sybil costs in a permissionless blockchain like Bitcoin or Ethereum without employing a centralized trusted third party (TTP). Until a mechanism for enforcing Sybil costs without a TTP is discovered, it will be almost impossible for permissionless blockchains to achieve satisfactory decentralization."

https://saito.tech/wolves-and-sheep/

I would love to see a follow-up that addresses emergent centralization due to winner-take-all or winner-take-most dynamics. This is how we end up with monopolies/duopolies elsewhere in the tech sector, and I suspect the same would hold for blockchain.
>>Key Findings

>>The number of entities sufficient to disrupt a blockchain is relatively low: four for Bitcoin, two for Ethereum, and less than a dozen for most proof-of-stake networks.

then why we haven't seen a Bitcoin hack before ? Maybe it is the most secured system.

They are talking here about mining pools I suppose since the biggest 4 mining pools account for more than 50% of validated blocks.

Also the word is "disrupt" so it means some time of chaos, the mining pools never tried to disrupt Bitcoin because they have no incentive to do so.

> More than one in five Bitcoin nodes are running an old version of the Bitcoin core client that is known to be vulnerable.

Patching software that is remotely accessible is a pretty basic security measure. I suppose the risk of a hacked node is fairly low, maybe about the same as a node that's run by a malicious owner. Although exploiting nodes would extend the reach if a malicious party.

I am always impressed with Trail of Bits work.
I found this information about the DARPA contract that funded this research: https://govtribe.com/award/federal-contract-award/definitive...
Some issues with this report:

> The challenge with using a blockchain is that one has to either (a) accept its immutability and trust that the programmers did not introduce a bug, or (b) permit upgradeable contracts or off-chain code that share the same trust issues as a centralized approach.

This paints the issue as binary, although there is more to it. Look at the WETH contract in which we both (a) accept its immutability and trust there are no bugs, but also (c) can migrate to a fork at a later point if desired through social consensus. There is another option (d) which is a less developed area: governance models that are not entirely centralized, see Uniswap and Aave.

> The number of entities sufficient to disrupt a blockchain is relatively low: four for Bitcoin, two for Ethereum, and less than a dozen for most proof-of-stake networks.

The Nakamoto coefficient relates to validator pools colluding to form a 51% attack. In Ethereum PoS this count is a bit higher, around 25-35[1]. Important to note the extreme costs of these attacks, and the defense mechanisms of PoS. If enough validators collude to 51% attack a PoS chain, users can follow a fork and have the attackers coins burned. Attacker would have to continually re-purchase coins to re-attack the new soft forks.[2]

> For a blockchain to be optimally distributed, there must be a so-called Sybil cost. There is currently no known way to implement Sybil costs in a permissionless blockchain like Bitcoin or Ethereum without employing a centralized trusted third party (TTP). Until a mechanism for enforcing Sybil costs without a TTP is discovered, it will be almost impossible for permissionless blockchains to achieve satisfactory decentralization.

This is based on the Kwon paper which defines "full decentralization" as a set of specific numerical constraints, and demonstrates that it is theoretically impossible for any permissionless system currently known to mankind to satisfy these constraints. Kwon makes no claims about whether this degree of decentralization is "satisfactory" or even necessary for a blockchain. A system that is distributed across thousands of nodes and highly resistant to 51% attacks and collusion is likely enough for it to be considered "decentralized" for practical purposes.

[1] https://shsr2001.github.io/beacondigest/notebooks/2021/07/19...

[2] https://vitalik.ca/general/2020/11/06/pos2020.html

The article doesn't say the research pointed out that many users aren't decentralized at all.

They don't run full-node. They relies on somebody else's SaaS.

Yup, I've come to realize that the word(s) "centralized/decentralized" are doing way too much heavy-lifting in these discussions, and that examining the details is very important.

When you use one of these words, you have to immediately ask -- "the power to do WHAT, exactly?" As in, compare to the question e.g. "Is Tesla centralized w/r/t Elon Musk?" You can't meaningfully answer the question with yes or no, and this gets even more complicated with many things in crypto, especially with (the extremely stupidly named) "Smart Contract" as a part of the game.