Source-linked AI summary
The Miner's Dilemma
Ittay Eyal
TL;DR
Open proof-of-work mining pools can be sabotaged by members who withhold full proofs while sharing pool rewards. The paper defines and analyzes a game of pool infiltration and finds that attacks can become equilibrium behavior, reducing revenues for all pools in relevant settings. It also connects the two-pool case to the iterative prisoner’s dilemma and discusses possible movement toward smaller closed pools.
Problem
Open mining pools allow members to withhold full proofs of work while receiving a share of pool revenue, reducing earnings for contributing participants.
Method
The paper defines a pool game in which pools infiltrate other pools with some miners and discard the full proofs those miners discover.
Results
With any number of pools, no-pool-attacks is not a Nash equilibrium; with two or identical multiple pools, attack equilibria leave pools earning less than under no attacks.
Takeaways & Limitations
The miner’s dilemma may make open-pool revenues vulnerable and potentially push miners toward smaller private pools.
Abstract
from arXiv · showhide
An open distributed system can be secured by requiring participants to present proof of work and rewarding them for participation. The Bitcoin digital currency introduced this mechanism, which is adopted by almost all contemporary digital currencies and related services. A natural process leads participants of such systems to form pools, where members aggregate their power and share the rewards. Experience with Bitcoin shows that the largest pools are often open, allowing anyone to join. It has long been known that a member can sabotage an open pool by seemingly joining it but never sharing its proofs of work. The pool shares its revenue with the attacker, and so each of its participants earns less. We define and analyze a game where pools use some of their participants to infiltrate other pools and perform such an attack. With any number of pools, no-pool-attacks is not a Nash equilibrium. With two pools, or any number of identical pools, there exists an equilibrium that constitutes a tragedy of the commons where the pools attack one another and all earn less than they would have if none had attacked. For two pools, the decision whether or not to attack is the miner's dilemma, an instance of the iterative prisoner's dilemma. The game is played daily by the active Bitcoin pools, which apparently choose not to attack. If this balance breaks, the revenue of open pools might diminish, making them unattractive to participants.
I. INTRODUCTION
Bitcoin-style proof-of-work systems use rewards and mining pools to secure participation, but open pools enable block-withholding infiltration attacks. The resulting pool game has equilibria in which attacks spread and reduce pool revenues.
- System background: Proof-of-work systems require costly computation and reward participants, a model used by Bitcoin and related digital-currency services.Bitcoin uses the blockchain as a global ledger maintained by an open distributed system.
- System background: Mining pools aggregate miners’ power and share revenue because individual miners may wait a long time to generate a block.Bitcoin adjusts difficulty so one block is added every 10 minutes, making pool-based revenue sharing attractive.
- Attack model: In a block-withholding attack, infiltrating miners submit partial proofs while discarding full proofs, appearing productive without contributing blocks.The attacker shares revenue from the victim pool while reducing the revenue of its other members.
- Attack model: Pools choose which other pools to attack and how much mining power to infiltrate, while attacks alter revenue allocation, attacker capacity, and system-wide effective power.Reduced effective power causes the Bitcoin protocol to lower difficulty.
- Equilibrium results: With any number of pools, no-pool-attacks is not a Nash equilibrium because a pool can increase its revenue by attacking when others do not.For two pools, static infiltration rates converge, and the game has a single Nash equilibrium.
- Equilibrium results: For two pools and for identical multiple pools, equilibria involve mutual attacks that leave pools earning less than under no attacks.The two-pool case is modeled as the miner’s dilemma, an iterative prisoner’s dilemma; reduced open-pool revenue may push miners toward smaller closed pools.
Forks
Bitcoin mining pools improve payment regularity by aggregating miners, but open pools face block withholding attacks that reduce members’ revenue and are difficult to attribute to individuals.
- Pools: Mining pools let participants share block rewards, increasing payment frequency despite infrequent individual block discovery.Pool revenue is distributed among members in proportion to mining power.
- Pools: Open pools accept new miners through registration and mining interfaces, making participation broadly accessible.Pool managers assign tasks, collect submitted solutions, and distribute revenue.
- Block Withholding: Classical block withholding occurs when a pool member submits partial proofs but discards full solutions, lowering the pool’s total revenue.The attack is illustrated as miners targeting Pool 2.
- Block Withholding: The attacker also earns less than through solo mining or honest pool participation, so the attack is costly sabotage.The proof of work cannot be reused because it is valid only for its specific block.
- Detection: Pools can often detect aggregate withholding but may not identify individual attackers when expected full proofs are rare.Using multiple small miners and replacing them frequently can prevent statistically confident attribution.
III. MODEL AND STANDARD OPERATION
The model represents Bitcoin-style proof-of-work participation as discrete steps in which miners generate partial and full proofs, pools coordinate work, and revenue is normalized and distributed.
- III. MODEL AND STANDARD OPERATION: The model applies to proof-of-work systems that reward participants at a dynamically normalized rate, while using Bitcoin terminology.The paper presents Bitcoin as the working example of this broader class of systems.
- III. MODEL AND STANDARD OPERATION: Each node generates tasks, miners work on them for one step, and work produces Poisson-distributed partial and full proofs.All miners have identical power and therefore identical proof-generation probabilities.
- III. MODEL AND STANDARD OPERATION: The network pays for published full proofs, and protocol normalization keeps average total revenue per step constant.Payments are associated with the task’s node identifier.
- III. MODEL AND STANDARD OPERATION: The analysis assumes instantaneous local operations and arbitrarily divisible mining power, with miner loyalty to pools fixed over time.These assumptions support a quasi-static treatment of pool membership and mining allocation.
- III. MODEL AND STANDARD OPERATION: Pools generate tasks, collect partial and full proofs, publish full proofs, and distribute revenue according to submitted partial proofs.The standard miner and pool procedures are specified through the model’s algorithms.
D. Block Withholding Miner
A block withholding miner appears to work normally by submitting partial proofs while withholding full proofs, causing the pool to share unchanged effective revenue among more members.
- D. Block Withholding Miner: A withholding miner sends partial proofs to appear active but never sends full proofs of work to the pool.The pool cannot distinguish this behavior from honest mining using its ordinary registration and proof submissions.
- D. Block Withholding Miner: The attacker does not contribute to the pool’s overall mining power but still receives a share of its revenue.Its payments are based on the partial proofs it submits.
- D. Block Withholding Miner: Revenue density is defined as average member revenue divided by the average revenue that member would earn as a solo miner.An unattacked pool and a solo miner both have revenue density 1.
- D. Block Withholding Miner: An attacked pool’s revenue density decreases because its revenue is shared with a noncontributing attacker.The model replaces random proof outcomes with continuous expected proof sizes for average-revenue analysis.
A. The Pool Block Withholding Attack
In a pool block withholding attack, one pool infiltrates another with loyal miners that submit partial proofs but withhold full proofs, redistributing revenue across pools and creating convergent revenue dynamics.
- A. The Pool Block Withholding Attack: An attacking pool registers infiltrating miners with a victim pool and transfers their partial proofs while withholding their full proofs.The infiltration rate is the mining power assigned to this attack.
- A. The Pool Block Withholding Attack: Pools choose which other pools to attack and how much mining power to allocate, forming a strategic pool game.The model tracks infiltrating miners with x_i,j(t).
- A. The Pool Block Withholding Attack: The analysis assumes infiltrating miners are loyal to the attacking pool, but disloyal infiltrators can redirect withheld-work revenue and create risk.Pools therefore need enough verified miners known to be loyal; pool-owned miners provide one practical source.
- Revenue Convergence: Revenue stabilizes after the longest infiltration-chain length, while loops produce convergence to a certain revenue.Infiltration revenue arrives one step later for each hop in the chain.
- Revenue Convergence: If infiltration rates remain constant, pool revenues converge because the infiltration matrix has largest eigenvalue below 1.The paper states this as Lemma 1 and derives convergence from the matrix’s row sums.
D. The Pool Game
The pool game models pools that optimize infiltration rates against other pools while holding miner populations fixed. It proceeds in rounds, with pools updating their rates sequentially after revenue approximates convergence.
- Pools optimize infiltration rates of other pools to maximize revenue while loyal-miner and total-miner counts remain constant.
- Each round contains s steps, with normalized total revenue of one, followed by one round-robin pool updating its infiltration rates.The integer s is chosen large enough for revenue to approximate its convergence limit.
- The implementation waits for the round to end before paying miners according to their proof-of-work shares.
- The algorithm accumulates infiltration revenue from each round for subsequent accounting.
Pool Knowledge:
Pools can estimate attack rates and revenue densities from proof-of-work information, while no-attack revenue is proportional to mining power. The one-attacker model tracks how infiltration changes direct and shared revenues.
- A pool estimates attackers’ rates from the relative frequencies of partial and full proofs of work.Pools may also publish attack data or probe other pools with nominal mining power.
- The pool game represents x_i,j(t) as the number of pool i miners infiltrating pool j at step t.
- Without block withholding, each miner’s revenue is proportional to mining power, whether pooled or solo.
- In the one-attacker scenario, pool 1 reduces direct mining by x_1,2 while pool 2 retains all loyal miners.
- Pool 2 divides revenue among loyal and infiltrating miners, whereas pool 1 combines direct revenue with infiltration revenue from pool 2.
A. Game Progress
In the one-way attack game, pool 1 chooses its infiltration rate to maximize per-miner revenue, producing a stable optimum. Across feasible pool sizes, attacking benefits pool 1 and reduces pool 2’s revenue, while no-attack is not an equilibrium.
- Pool 1 chooses x_1,2 to maximize its revenue density on the first round of the pool game.
- A unique feasible maximizer defines the stable infiltration rate because pool 2 cannot respond to pool 1’s attack.
- The numerical analysis varies m_1 and m_2 across their feasible range and records equilibrium infiltration rates and revenues.The analysis normalizes total miner count to m = 1.
- In the entire feasible range, pool 1 uses strictly positive infiltration, earns strictly more than 1, and pool 2 earns strictly less than 1.The baseline value 1 is the revenue pool 1 would obtain without attacking.
- Reduced total mining power raises third-party revenue from 1/m to 1/(m − x_1,2), leaving pool 2 to fund gains for its attacker and other miners.
- With any number of pools, the all-zero infiltration profile is not an equilibrium because a pool can improve revenue by attacking another pool.
VI. TWO POOLS
When two pools can attack each other, each selects its own infiltration rate and revenues depend on both rates. Concavity yields unique best responses, and analysis identifies a single Nash equilibrium distinct from no attack.
- Two pools independently control infiltration rates x_1,2 and x_2,1 against each other, while other miners work solo.
- Each pool’s total revenue combines direct mining revenue with infiltration revenue and is shared among loyal and infiltrating miners.
- The revenue functions are r_1 = [m_2R_1 + x_1,2(R_1 + R_2)]/[m_1m_2 + m_1x_1,2 + m_2x_2,1] and the symmetric expression for r_2.
- Each round lets the acting pool optimize its own infiltration rate given the other pool’s current rate.
- Concavity makes each pool’s optimal solution unique, occurring at a feasible boundary or where its revenue derivative is zero.
- A single Nash equilibrium exists, and no attack is excluded because both pools can increase revenue with positive infiltration.
A. Numerical Analysis
The analysis shows that attacks are usually favored in two-pool settings, while mutual attacks reduce both pools’ revenues. Symmetric multi-pool equilibria exhibit the same inferior-revenue outcome.
- Two-pool numerical analysis: At equilibrium, a pool refrains from attacking only when the other pool controls about 80% of total mining power.
- Two-pool numerical analysis: A pool improves its revenue over no attacks only when it controls a strict majority of total mining power.
- Two-pool numerical analysis: When neither pool has a strict majority, both earn less at equilibrium than if neither attacked.
- Prisoner’s Dilemma: Attack is the dominant strategy for each pool, although mutual non-attack would yield higher payoffs for both.
- Prisoner’s Dilemma: In the iterative game, cooperation with neither pool attacking can remain stable despite attack being the single-round Nash equilibrium.
- Identical pools: With identical pools, a symmetric equilibrium exists in which all pools attack one another and earn less than under no attacks.
VIII. DISCUSSION
The discussion considers why attacks are uncommon, how attacks could destabilize open pools, and how reduced revenues might redirect miners toward private or smaller pools. It also identifies modeling assumptions and unresolved pool-fee and miner-interaction issues.
- Bitcoin’s Health: Attacks are rarely reported, possibly because active pools have reached an implicit or explicit agreement not to attack one another.
- Bitcoin’s Health: An attacked pool cannot identify which miners or pool controls the infiltrators, making an implicit agreement vulnerable to a pool’s unilateral decision to attack.
- Bitcoin’s Health: If attacks reduce open-pool revenue density, large miners may mine solo while smaller miners may join closed pools limited to trusted participants.
- Revenue timing: The model analyzes eventual revenues after difficulty normalization; before normalization, attacking reduces the attacker’s revenue, although its revenue density relative to the victim improves immediately.
- Revenue timing: After difficulty adjustment, the attacker may obtain an absolute revenue benefit from the enhanced block-withholding attack.
- Scope and assumptions: The pool-game model does not represent the dynamic interaction between pools and miners, which is left for future work.
- Scope and assumptions: Pool fees reduce an attacker’s revenue and make a pool less attractive as a target, but also make it less attractive to miners.
IX. RELATED WORK
The paper distinguishes pool block withholding from earlier withholding, double-spending, and selfish-mining attacks, and places it within broader proof-of-work systems. It also discusses defenses and the possibility that attacks could encourage smaller, closed pools.
- Prior attacks: Classical block withholding was previously described as a miner sabotaging a pool at the cost of reducing its own revenue; earlier work did not study pools infiltrating other pools.
- Prior attacks: This work extends prior analysis by considering mutual attacks among pools and settings where not all mining uses public pools.
- Prior attacks: The attack studied here withholds blocks permanently, unlike temporary withholding used to improve revenue or support other attacks.
- Prior attacks: Double spending uses withheld conflicting blocks to revoke a published transaction and is unrelated to the pool attack analyzed here.
- Broader applicability: Proof-of-work cryptocurrencies including Litecoin, Dogecoin, and Permacoin are susceptible because miners can distinguish full solutions from partial proofs.
- Defenses and implications: A honey-pot block-structure change, a different proof-of-work algorithm, or another defense could reduce or remove block-withholding risk.
- Defenses and implications: Open P2Pool groups remain infiltrable, whereas closed P2Pool groups exclude untrusted miners and are protected against block withholding.
- Conclusion: The paper concludes that no attacks are not an equilibrium, while mutual attacks can produce lower revenues and potentially push miners toward smaller private pools.