[Opt-in full-RBF] Zero-conf apps in immediate danger



Summary:

On bitcoin-dev mailing list, there has been a discussion about the opt-in replace-by-fee (RBF) feature in Bitcoin which allows users to replace an unconfirmed transaction with another version that has a higher fee. The developers of three main coinjoin implementations that are claimed to be impacted by opt-in RBF have not made any remarks. Wasabi and Joinmarket, two of the implementations, do not signal RBF in coinjoins and have other Denial-of-Service vectors. Max Hillebrand from Wasabi confirmed that full-RBF doesn't really affect them and they handle replacements/reorgs gracefully. AdamISZ/waxwing from Joinmarket also confirmed that opt-in RBF would be another DOS vector, but it wouldn't change their security model as nothing in the logic of the protocol relies on unconfirmed transactions. They may take a new look at it if this becomes the norm, but there shouldn't be any security issue.


Updated on: 2023-06-16T00:47:29.549236+00:00