From the forums: one-confirmation attack



Summary:

The email conversation between Gavin Andresen and Joel discusses the lessons learned from a recent Bitcoin attack. The main takeaways are to not accept 1-confirmation transactions and to be well-connected. Another lesson is to not trust information from only one peer or to watch for peers trying to fool you. This attack seems to rely on the target not using the deposit transaction as input, so having separate wallets for each account could make this class of attacks ineffective. Receiving a block with a transaction that hasn't been broadcast to the network is suspect, and in such cases, it may be best to not treat the block as confirmation at all and instead start counting from the next one.


Updated on: 2023-05-26T20:21:07.753054+00:00