A recently published Social Science Research Network (SSRN) paper by Lucas Nuzzi, Kyle Waters, and Matias Andrade introduces a new approach to calculating the Total Cost of Attack (TCA) of Bitcoin and Ethereum.
Uncovering the Costs of Compromise: A Comprehensive Study of Attacking Bitcoin and Ethereum
This comprehensive analysis highlights the economic barriers to 51% attacks, challenging previous assumptions about blockchain vulnerabilities On Thursday, the head of research and development at Coinmetrics, Lucas Nuzzi, revealed a new paper he co-authored with Kyle Waters and Matias Andrade. "How much would it cost to attack 51% of Bitcoin and Ethereum?" Nuzzi posted on social media platform X.

"To find out, we simulated what an attack would look like. Our paper, Breaking BFT, was published today with some interesting results." This study presents a Total Cost to Attack (TCA) model, an important metric that combines the capital and operational costs required to execute a 51% attack or violate Byzantine Fault Tolerance (BFT).
This metric offers a new lens through which to assess the economic feasibility of such an attack, providing insight into the robust security measures of Bitcoin and Ethereum. This research closely analyzes several scenarios, including the potential for nation-state attackers to compromise these blockchains. Exploration details of the various attack vectors underscore the complexity and costs involved, further emphasizing the resilience of these networks to potential threats. "As an open source, stateless alternative to systems such as central bank digital currencies (CBDCs), states may be motivated to permanently cripple these systems," the study notes.
"However, this becomes a fundamental problem with regard to 51% attacks: it is very difficult to make them permanent. Even in a scenario where the attacker simply mines empty blocks and continuously attacks, the network can fight back." Among other scenarios discussed, the paper examines the implications of decreasing block rewards on network security. "Decreasing subsidies have been of particular concern in the context of Bitcoin's long-term security and its vulnerability to attacks," the paper explains. "This concern relates to Bitcoin's security relying on subsidies replaced by user fees," the paper's authors added:
Contrary to popular belief, these findings suggest that network security may not be directly correlated with transaction fee revenues, challenging the prevailing narrative in the digital currency community. The implicit assumption that justifies such concerns is that Bitcoin fees are correlated with security. The higher the fees collected by miners, the more secure the network is. Surprisingly, although this makes sense, we found that this is not a historically observed phenomenon.
The study also explores the motivations behind potential attackers, distinguishing between profit-driven actors and ideologically motivated actors. This distinction is critical to understanding the various threats to blockchain security and the economic impracticality of attacks for both groups.
Applying the TCA model to Bitcoin and Ethereum shows that, despite the large number of theoretical vulnerabilities, the actual cost of launching a successful 51% attack is very high. It provides empirical evidence supporting the idea of Nash Equilibrium in these networks."Because adversarial actions become unattractive when compared with other strategies, such as honest participation in the network or abstaining from attacking, we provide the first empirical evidence of Nash Equilibrium in Bitcoin and Ethereum ," the paper explains.
Other factors influence miner behavior and appear to challenge this assumption, and finally, this paper contributes to the ongoing discourse on the long-term sustainability of Bitcoin and Ethereum's deflationary monetary policies. By highlighting the speculative behavior of miners and the impact of this behavior on network security, the authors offer a nuanced view of how economic incentives underpin blockchain resilience, as Bitcoin and Ethereum continue to evolve, the findings underscore the importance of ongoing research and adaptation in protecting the cryptocurrency frontier from adverse threats.
What do you think about research papers that calculate the true costs of attacking Bitcoin and Ethereum? Share your thoughts and opinions on this topic in the comments section below.