428
X. Liu et al.
8.10 Vulnerabilities of Blockchain
Although blockchain technology provides numerous advantages and application
potentials, it is not perfect. It is important to be aware of its weaknesses. Potential
attacks can occur on several aspects of blockchain technology. Systems based on
blockchain technology can even be used to commit crimes.
The first vulnerability of blockchain technology is originated from its consensus
mechanism, which is susceptible to a 51% attack [33]. Specifically, in a Power-ofWork-based blockchain network, if the computational power of a single miner node
exceeds 50% of the total power of the entire blockchain network, then the entire
blockchain could potentially be controlled by that attacker. In a Power-of-Stakebased blockchain network, the 51% attack can also occur if the number of stakes
owned by a single node is more than 50% of that of the total blockchain network.
The attackers of a 51% attack are able to reverse transactions, conduct doublespending, exclude transactions, reorder transactions, cause problems for operations
for normal transaction confirmation, and stop the mining operations of other mining
nodes.
Sybil attack is also a vulnerability of blockchain which takes advantage of the
fact that public blockchain networks have no centrally trusted nodes and every
transaction is sent to a number of other nodes for processing. A Sybil attack is
initiated by assigning a number of identifiers to the same node. During a Sybil
attack, the attacker is able to outvote honest nodes and takes control of the network.
Therefore, the consequence of a Sybil attack is equivalent to a 51% attack.
Private keys are another source of vulnerabilities in a blockchain network. A
private key is the identity of a user. It is used to sign transactions and verify asset
owners. Private keys are also used in transaction validation and candidate block
verification. However, a legitimate user’s private key can get lost. If this happens,
there is no way to recover the private key. The legitimate user will not be able to
access his/her account on the blockchain network anymore and will therefore lose
the assets he or she owns. If a private key is stolen by a criminal, the legitimate
user’s blockchain account can get tampered. Whatever damage the criminal does
is difficult to track, repair, and recover because there are no centralized third-party
trusted institutions to seek assistance from.
Although it is commonly known that, by introducing consensus algorithms, a
blockchain network can prevent the double-spending attack, as claimed by the
Bitcoin paper [1], it is still possible for double-spending to occur in a blockchain
network. It is misleading to believe that double-spending is fully eliminated by
the consensus mechanism during validation. Among all blockchains, the Power-ofWork-based blockchain network is especially vulnerable, as the attacker can exploit
the time interval between the initiation and confirmation of two transactions to
quickly launch a double-spending attack. Double-spending refers to the fact that a
malicious user spends the same cryptocurrency for multiple transactions. Knowing
it takes time to mine a block and reach consensus, the attacker could launch a
race attack involving two consecutive transactions. Before the second transaction
Précédent

- 433/647

Suivant