Abnormally Large Tor node accepting only Bitcoin traffic



Summary:

A potential network exploit has been noticed, with a node processing the most traffic out of any tor node in the last three days. The node's identity is not revealed, but it is known that only port 8333 is open and mostly plaintext Bitcoin traffic is being processed. Running such a node could be expensive, which suggests a possible sybil attack or logging attack. To reduce orphan rates, a mining pool may have set up this node cleverly as a Tor exit node to get plausible deniability. It is also noted that implementing better incoming connection limiting is necessary and gmaxwell's scheme with interactive proof-of-memory is recommended. A link to GitHub explaining Bloom IO attack is also provided.


Updated on: 2023-06-09T01:36:51.246504+00:00