Research paid for by DARPA (research division/weapons for US) regarding the centralization and vulnerability 'choke points' of blockchain tech, including bitcoin, revealed several vulnerable points beyond a 51% attack. 1)ISPs can delay or prevent communications related to the blockchain, effectively a ddos. Tor and a handful (3-4) ISPs could potentially prevent certain proof of work mechanisms to fail, also ddos-styled 2) software primarily used by miners is often outdated and may have vulnerabilities introduced easily. there is spare documentation regarding some of these tools used by miners and outdated software opens the door to attacks on a blockchain. 3) centralized teams are vulnerable as they can be targeted, especially those holding keys for core code modification 4) using Pegasys spyware certain devs' credentials were accessed, making the entire ecosystem of one blockchain vulnerable 5) another form of 51% attack is fake nodes introduced to mining, en masse; perhaps, if I understood correctly, a type of ddos attack that relies on mass rejections of the fake nodes. 6) windows operating system and the smart contract coding software itself has many vulnerabilities that can be exploited to prevent communication with the blockchain to transact etc The redacted research doc here: https://www.trailofbits.com/reports/Unintended_Centralities_in_Distributed_Ledgers.pdf
No comments yet