Double-spending unconfirmed transactions is a lot easier than most people realise



Summary:

The author of a Reddit post titled "Double-spending unconfirmed transactions is a lot easier than most people realize" has conducted further experiments with good results. The author provided an example of a real-world double-spend on gambling service Lucky Bit, which was mined by Eligius using blacklisted transactions. The attack is profitable when automated and uses the author's replace-by-fee patch. However, Lucky Bit has added case-specific code to reject transactions with blacklisted outputs, making this particular type of double-spend no longer possible. The company is also considering implementing replace-by-fee scorched earth and moving towards off-chain transactions. The author included links to their patch and other relevant information.


Updated on: 2023-06-08T20:42:33.649706+00:00