REVIEW 15 references
Bitcoin Security under Temporary Dishonest Majority
T0 review · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read Extends the Bitcoin backbone security analysis to temporary dishonest majority with offline parties, but leaves the central proofs to a self-cited full version.
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
Extended reading notes
Core claim
The paper's central assertion is stated in the Abstract: 'We prove Bitcoin is secure under temporary dishonest majority.' More specifically, Section 3 claims that in the q-bounded synchronous model, the Bitcoin backbone protocol satisfies chain growth, common prefix, and chain quality under the expected honest majority assumption t <= c(1-delta)E[nalert], with proofs deferred to the full version [2]. If the paper is correct, Bitcoin tolerates an adversary that may corrupt a fraction of parties and put honest parties offline, provided the expected number of alert honest parties is a c(1-delta) majority.
Load-bearing premise
In Section 5.1, the security bounds in the message-loss model rely on the assumption that 'the adversary is not informed if a party Pi is set to sleep, after sending an instruction (sleep, Pi) to the control program C.' The derived upper bounds on s assume the adversary cannot tell which sleep instructions succeeded. If the adversary knew which honest parties were asleep, the honest majority condition would have to be t + E[nsleepy] <= c(1-delta)E[n*_alert], and the paper states this would require a different model. This ignorance-of-sleep-success assumption is load-bearing: if real-world attackers can detect when their DDoS or eclipse attempts succeed, the tolerance bounds in this paper do not apply.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Assumptions & free parameters
free parameters (4)
- c =
0.5 in Section 6
- delta =
delta >= 2E[Xi]+2eps (sync), >= 2Delta E[Xi]+4eps+4Delta/(eta kappa) (semi-sync), >= 3eps+2E[X*_i] (message loss)
- epsilon =
0.005 in Section 6
- E[Xi] =
0.03 for all three models in Section 6
assumptions (5)
- standard math Random oracle and diffusion functionalities model the hash function and network communication.
- domain assumption Each honest party is independently set to sleep with probability s each round.
- standard math Typical execution: Chernoff concentration and no hash collisions hold with overwhelming probability.
- domain assumption The adversary is not informed whether a sleep instruction succeeds.
- ad hoc to paper 2E[Xi] <= 1.
Cite this review
Pith. "Pith review of Bitcoin Security under Temporary Dishonest Majority." pith.science (2026). https://pith.science/paper/AW6KWRP2
@misc{pith2026190800427,
author = {Pith},
title = {Pith review of: Bitcoin Security under Temporary Dishonest Majority},
year = {2026},
howpublished = {\url{https://pith.science/paper/AW6KWRP2}},
note = {Machine review of arXiv:1908.00427}
}
read the original abstract
We prove Bitcoin is secure under temporary dishonest majority. We assume the adversary can corrupt a specific fraction of parties and also introduce crash failures, i.e., some honest participants are offline during the execution of the protocol. We demand a majority of honest online participants on expectation. We explore three different models and present the requirements for proving Bitcoin's security in all of them: we first examine a synchronous model, then extend to a bounded delay model and last we consider a synchronous model that allows message losses.
Figures
Reference graph
Works this paper leans on
-
[1]
In: 2017 IEEE Symposium on Security and P rivacy, SP 2017, San Jose, CA, USA, May 22-26, 2017
Apostolaki, M., Zohar, A., Vanbever, L.: Hijacking bitco in: Routing attacks on cryptocurrencies. In: 2017 IEEE Symposium on Security and P rivacy, SP 2017, San Jose, CA, USA, May 22-26, 2017. pp. 375–392 (2017)
work page 2017
-
[2]
Avarikioti, G., K¨ appeli, L., Wang, Y., Wattenhofer, R.: Bitcoin Security under Temporary Dishonest Majority (2019)
work page 2019
-
[3]
In: Bitcoin18: Proceedings of the 5th Workshop on Bitcoin and Blockchain Research (2018 )
Bonneau, J.: Hostile blockchain takeovers (short paper) . In: Bitcoin18: Proceedings of the 5th Workshop on Bitcoin and Blockchain Research (2018 )
work page 2018
-
[4]
In: IEEE P2P 2013 Proceedings (Sep 2013)
Decker, C., Wattenhofer, R.: Information propagation in the bitcoin network. In: IEEE P2P 2013 Proceedings (Sep 2013)
work page 2013
-
[5]
In: 2015 IEEE Symposium on S ecurity and Privacy, SP 2015, San Jose, CA, USA, May 17-21, 2015
Eyal, I.: The miner’s dilemma. In: 2015 IEEE Symposium on S ecurity and Privacy, SP 2015, San Jose, CA, USA, May 17-21, 2015. pp. 89–103 (2015)
work page 2015
-
[6]
Eyal, I., Sirer, E.G.: Majority is not enough: Bitcoin min ing is vulnerable. In: Commun. ACM (Nov 2013)
work page 2013
-
[7]
Garay, J.A., Kiayias, A., Leonardos, N.: The bitcoin back bone protocol: Analysis and applications. In: Advances in Cryptology - EUROCRYPT 20 15 - 34th An- nual International Conference on the Theory and Applicatio ns of Cryptographic Techniques, Sofia, Bulgaria, April 26-30, 2015, Proceeding s, Part II. pp. 281–310 (2015)
work page 2015
-
[8]
In: Proceedings of the 24th USENIX Co nference on Security Symposium
Heilman, E., Kendler, A., Zohar, A., Goldberg, S.: Eclips e attacks on bitcoin’s peer-to-peer network. In: Proceedings of the 24th USENIX Co nference on Security Symposium. pp. 129–144. SEC’15, USENIX Association, Berkeley, CA, USA (2015)
work page 2015
Show all 15 references
-
[9]
In: Pr oceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Secur ity, CCS 2017, Dallas, TX, USA, October 30 - November 03, 2017
Kwon, Y., Kim, D., Son, Y., Vasserman, E.Y., Kim, Y.: Be sel fish and avoid dilem- mas: Fork after withholding (F A W) attacks on bitcoin. In: Pr oceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Secur ity, CCS 2017, Dallas, TX, USA, October 30 - Novemb...
2017
-
[10]
In: https://bitcoin.org/bitcoin.pdf (Oct 2008)
Nakamoto, S.: Bitcoin: A peer-to-peer electronic cash s ystem. In: https://bitcoin.org/bitcoin.pdf (Oct 2008)
2008
-
[11]
2016 IEEE Europ ean Symposium on Security and Privacy (EuroS&P) pp
Nayak, K., Kumar, S., Miller, A., Shi, E.: Stubborn minin g: Generalizing selfish mining and combining with an eclipse attack. 2016 IEEE Europ ean Symposium on Security and Privacy (EuroS&P) pp. 305–320 (2015)
2015
-
[12]
In: Taka gi, T., Peyrin, T
Pass, R., Shi, E.: The sleepy model of consensus. In: Taka gi, T., Peyrin, T. (eds.) Advances in Cryptology – ASIACRYPT 2017. pp. 380–409. Sprin ger International Publishing, Cham (2017)
2017
-
[13]
In: Financial Cryptography and Data Security - 20t h International Confer- ence, FC 2016, Christ Church, Barbados, February 22-26, 201 6, Revised Selected Papers
Sapirshtein, A., Sompolinsky, Y., Zohar, A.: Optimal se lfish mining strategies in bitcoin. In: Financial Cryptography and Data Security - 20t h International Confer- ence, FC 2016, Christ Church, Barbados, February 22-26, 201 6, Revised Selected Papers. pp. 515–532 (2016)
2016
-
[14]
In: IEEE Infocom 2006 (Apr 2 006)
Singh, A., Ngan, T.W.J., Druschel, P., Wallach, D.S.: Ec lipse attacks on overlay networks: Threats and defenses. In: IEEE Infocom 2006 (Apr 2 006)
2006
-
[15]
In: Springer, pp
Sit, E., Morris, R.: Security considerations for peer-t o-peer distributed hash tables. In: Springer, pp. 261269 (Oct 2002)
2002
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.