Trusted merkle tree depth for safe tx inclusion proofs without a soft fork



Summary:

In an email conversation on June 9, 2018, Sergio Demian Lerner stated that an attacker having only $1.3 million could perform a brute-force attack on 72 bits in four days using ASICs and can thereby perform the same attack. Therefore, no one should accept more than $1 million using an SPV wallet. In response, Peter Todd noted that this did not make sense as one could fool a SPV wallet by creating a fake block at far less cost with a sybil attack. Sybils are not difficult to pull off when one has the budget to create fake blocks. Additionally, Lerner stated that the attack could be repeated, but Todd clarified that txouts can only be spent once, so 2^40 work would need to be done each time to grind the matching part of the prevout again.


Updated on: 2023-06-13T03:14:23.118004+00:00