March 2015 Journal

58 minute read

WORDS is a monthly journal of Bitcoin commentary. This issue collects the March 2015 writing in the WORDS archive. For the uninitiated, getting up to speed on Bitcoin can seem daunting. Content is scattered across the internet, in some cases behind paywalls, and content has been lost forever. That’s why we made this journal, to preserve and further the understanding of Bitcoin.

Subscribe


Bitcoin is unfair. That’s the point and so it shall remain.

By Pete Dushenski

Posted March 8, 2015

Some New Yorker over at The New Republic recently wrote one of the most misguided, late-to-the-party, pitiful pieces of journalistici wankery I’ve read in months. I’d honestly thought that such derpage was dead and buried, but since this doesn’t appear to be the case, for your enlightenment and entertainment, I’m going to address of few areas where Mr. Nathan Schneider goes off the rails in After The Bitcoin Gold Rush :

The search for riches in the ground has motivated some of history’s most extravagant endeavors. It has inspired explorers, enslaved populations, and put opera houses in dusty mountain towns. But when the boom ends, the miners themselves have often been left in the lurch. They handle the raw material, turn it from hard earth to something potentially of value. Fabulous wealth comes to only a few, who rarely hold onto it long enough to be considered lucky. The search for bitcoins is little different.

Yes, the search for new lands has rewarded those brave enough to venture off the edge of the world, where the horizon ends and the oceans tumble over the planet’s precipice into the vast emptiness of outer space. This is in fact the very same world that created the art, architecture, heroes, and stories that we still appreciate today. The ones we still vacation to Europe for just to catch a glimpse of that bygone splendour. This is the world that rewarded risk just as severely as it punished it.

Also, yes, we agree that the problem and promise of fabulous wealth is an obstacle in Bitcoin just as it was in the wild west days of gold mining – being early,ii holding on to your winnings, dodging wallet inspectors, keeping private keys safe
 Many started out on this journey, far fewer survived. Just as it should be.iii

Those miners left in the lurch after the dust settled, those whose corpses lined the ditches along the road up towards Victory Mountain, are but the hangers-on of history, the also-rans, the redditards. They’ll be able to say “I was there” and nothing more. History forgets such accidents.

Yes, this is also exactly how derps see “lucky” people. “Oh, you’ve been successful at investing for 15 years, you’re just a lucky punk with no skillz !” etc. Come to think of it, casinos must be the luckiest businesses around ! That house edge that they enjoy is pure good fortune ! I mean, there’s no possible way it’s by design, right ?

Nick Spanos founded the Bitcoin Center a few hours before New Year’s Eve in 2013. He is a New York City real estate broker who learned about Bitcoin “pretty early,” he says, at a libertarian meetup.

Speaking of accidents and those who aren’t so “lucky,” you’ll recall that Nick Spanos “knows everything there is to know about Bitcoin” despite the fact that he hasn’t, to my knowledge, completed his 6 month certification. Spanos is therefore an absolute nothing. In fact, even if he and “The Bitcoin Centre” started out as something, doubtful though this is, he’s pissed the last two years and God knows how many coins into “the community.” Because that’s how everything works, isn’t it ? Well, yes, but only if you ignore causes and beeline straight for your own imaginary purposes.

He envisioned his storefront as a beachhead for Bitcoin in the heart of the Financial District, but it has been losing money as he waits for government agencies, such as New York’s Department of Financial Services, to decide how to regulate virtual currencies.

“Oh please Mr. Government man, please let me run a business so I can feed my children myself, so y’know, I don’t have to go on food stamps to leech off of the people who already have your approval to eat.”

Bitcoin can’t be regulated anymore than the clouds can be regulated. The NYDFS knows this, which is why they choked to death on their braindamanged “BitLicense” proposal.

“I feel like a martyr—a Bitcoin martyr,” he told me. “We’re bleeding out.”

Yes, you are, Spanos. Just like everyone else who sympathises with your stupidity and pretends like Bitcoin doesn’t already have its own established hierarchy, all there is for you to do is bleed out and go off quietly into the night.

But for anyone invested in a commodity whose value depends on confidence, spreading pessimism can be costly. Without much conviction, Spanos insisted that Bitcoin “is going to change the world.”

Fuck Nathan with a spiky cactus branch. Seriously. It’s motherfucking fiat, not Bitcoin, that depends on confidence. It’s fiat, not Bitcoin, that’s so unbearably susceptible to pessimism thatits central bankers are reduced to PR muppets who hold press conferences three times a week!iv

It’s Bitcoin, not fiat, that’s based on immutable maths. It’s Bitcoin, not fiat, that’s a force of nature. It’s Bitcoin, not fiat, that doesn’t give a shit whether you like it or not.

I mean really, can you honestly think of a less consumerist, less democratic underpinning for an economy ? Because I can’t for the life of me. And whether you like it or not, it’s happening. Bitcoin is here and there’s no putting pandora back in her box. So just like everything else that’s out of your power to change, be it the colour of the morning sky or the shape of a crocodile’s toes, you might as well enjoy it !

Bitcoin was supposed to usher in a new, global economy—gold for the Internet age, managed not by a central authority but by infallible algorithms running on the computers of those who use it. [
] But the Bitcoin revolution has begun to look more and more like the system it was intended to replace—except perhaps more centralized, less egalitarian, and even more clogged by unseemly interests.

Ok, this is completely contradictory and entirely ignorant of what the gold standard meant in praxis. To recap : Bitcoin looks nothing like the fiat system it intends to replace and that’s because, not except, because it’s more centralised and less egalitarian. I don’t really grok what “unseemly interests” is would seem to map to something vaguely socialistoidian, which is to say that Bitcoin doesn’t give away free shit to people who didn’t earn it. This is true, very much the point, and very much a return to the gold standard. But I suppose it isn’t “fair” by the post-post-modern definition. But what of it ?

Mining, especially, was supposed to be an act of democracy. On the P2P Foundation’s online forum, Bitcoin’s pseudonymous creator Satoshi Nakamoto wrote, “The root problem with conventional currency is all the trust that’s required to make it work.”

Satoshi was referring to the trust required for transactions. Sorry Nathan, but you don’t get to misrepresent facts anyway you like because reasons. Mining Bitcoin was never “supposed to be an act of democracy,” at least not in the sense of a full-franchise democracy you’re thinking of. Bitcoin is more aristocratic than anything else. For which, for all the art and splendour that is to come, and in advance, you’re most welcome.

Nakamoto designed Bitcoin to resemble gold in more ways than one—a finite supply, its value backed by its scarcity and the energy required to extract it. This was unquestionably a breakthrough. For the first time, the technology underlying Bitcoin made possible a secure, decentralized, open-source financial network. Users wouldn’t have to trust an agency or authority, just the software.

So true and so beautiful. This is exactly what Bitcoin is about : a breakthrough the likes of which hasn’t been seen since that joo from Nazareth burst forth from the divine cunt to wash his friends’ feet. And can you believe our good fortune that we’re alive to see it ??

Together Bitcoin’s miners amount to hundreds of times more computing power than the combined output of the world’s top 500 supercomputers. Processing and protecting the more than $3 billion worth of bitcoins in circulation requires more than $100 million in electricity each year, generating a volume of carbon emissions to match.

And not a moment too soon, came those power-devouring ASICs.v A year or more later and state-level actors would’ve had the resources to crush it, or at least put up a bit more of a fight. Now it’s beyond them all – be it China, Russia, or the US – just as Niagara Falls is beyond a single fallen tree to stop.

All that computing power, which could be curing cancer or exploring the stars, is locked up in machines that do nothing but process Bitcoin-type transactions.

Machines that “do nothing” but disrupt everything and anything you can wrap your noodle around seem to me like a pretty reasonable use of computing power. Curing cancer and star-gazing are not only infinitely less important, but the former is a money-trough for feeding post-doc cows and the latter is a hobby, so how can these really compare ?

The prospects for democracy in the system have grown dimmer still. [
] A distributed network of users now has to trust an oligarchy of capital-intensive miners.

Yes, as Bitcoin matures, the weak hands are definitely caving to the strong hands, but also, the whole fucking point of Bitcoin is that the users don’t have to trust the miners.

That’s what it means when we say that Bitcoin is “censorship-resistant.” The users have the power, those in the WoTeven more so. The miners are merely acting in their own self-interest, they could care less whose transactions they’re relaying, they just want to get paid. We’re merely here to ensure that this remains so.

“Some of the New York Bitcoin Center guys are pretty religious,” says Tim Swanson. [
] Swanson has grown increasingly skeptical that Bitcoin will unsettle the existing finance megaliths.

Swanson would be skeptical of Bitcoin, especially afterI hung him up to dry for being a derp.

“Being your own bank sounds cool in theory,” Swanson says, “but it’s a pain in reality.”

Ok, Swanson has a point here. This is precisely why Bitcoin will never be about mass adoption. The barriers to entry for even appreciating a sliver of its potential impact, combined with the technical savviness needed to not get raped using it, are as high as the walls of Babylon.

Bitcoin, in any case, is only the beginning.

Not only is there no Bitcoin 2.0, Bitcoin doesn’t even need such a thing.

Last June I went to the Bitcoin Center to hear a speech by Vitalik Buterin, a 20-year-old Russian-Canadian tech-prodigy. [
] With a World Cup game projected silently above him, Buterin presented an update on his new project, Ethereum, a platform that proposes to take what Bitcoin does for money and do it for just about everything else.

Sure, except that Ethereum is a fucking scam. Hey Vitalik, where’s your magic pixie dust that’s going to revolutionise all the things in all the places ? We’re still waiting !

“Distributed technologies do not necessarily lead to distributed outcomes,” writes Michel Bauwens, the Belgian-born founder of the P2P Foundation, which Satoshi Nakamoto turned to early on to promote his vision. Bauwens points out that the Bitcoin economy is more unequal than the conventional one. Currently, the top 100 users hold at least 20 percent of the wealth.

One could argue that a dentist’s drill is a “distributed technology” as they’re available online for a few hundred bucks, and yet, you don’t drill your own teeth ! Now why is that ? Is it perhaps because you don’t have the skills, training, knowledge, and ability to handle it safely ?

If it is, that sounds a lot like Bitcoin : a dangerous offering that you’d be well advised to steer clear from unless you’re, shall we say, adventurous. Y’know, like Giovanni Caboto.

Entrusting our money to algorithms, it turns out, is no guarantee of a better result than managing it with flawed institutions and flawed people. Perhaps we should be imagining tools that help us trust each other more, rather than entrusting ourselves to a rush for digital gold. The technology at work in Bitcoin can do this. It can be rearranged for cooperation rather than competition, for reputation rather than anonymity, for democracy rather than oligarchy.

Bitcoin is arranged for reputation. That’s sorta exactly what the WoT is all about and why it’s so important. Now that we’ve removed physicality from business and removed physical recourse from contracts, all we have to go on is reputation. This makes Bitcoin in the WoT quite cooperative while the pretenders outside eat each other like crabs in a bucket, mostly to great lulz.

The allure of the machines makes it easy to forget that what we need is not a newer, slicker system but a better society.

Isn’t that exactly what we’re doing ?? Oh, that’s right, it is !! Nathan and I just happen to disagree about what “better” means. Nathan says it means more free shit for everyone, that is, more of the same. Bitcoin says it means death to consumerist retardation. I think I’ll side with Bitcoin here


One recent evening at the Bitcoin Center, a middle-aged woman with a pearl necklace visible beneath her trenchcoat approached a shaggy-haired staffer standing next to the miners. She was from Harlem; the only name she cared to give was “Miss E.”

“What is this Bitcoin?” she asked the staffer, who embarked on a long explanation of Bitcoin as a “layer” on the Internet for finance and of the cryptographic mechanics that kept secure. He was far from done when Miss E started to look like she was ready to leave.

“I thought I would come in here and find someone who was gonna replace these banks,” she said, gesturing out the window to Broad Street. “We need to distribute the wealth, you know what I’m saying? I thought this was something for the small people.”

You wanting and you needing are different things, you know what I’m saying ?

Bitcoin is what you need, so it’s exactly what you’re getting.

If that makes it “unfair,” well, too bad, so sad.


  1. Schneider appears to be of the opinion that journalism and reporting are about talking to people who want to talk to him, not people he wants to talk to. Nathan, and any other “journalists” out there, for future reference, the people who matter in Bitcoin are on IRC.↩
  2. Though it’s not necessary to be first, being a fast follower appears to yield the best rewards. Certainly this is the case in Bitcoin, where the 2009-2010 cohort is dead and gone, and the 2011-2012 cohort is running the show.↩
  3. From Eric Naggum (cached) : It is a truism that “that which does not kill you makes you stronger”, but the summary of evolution and natural selection is all wrong: It is not “survival of the fittest”, a phrasing that has prevented billions of people from grasping the mechanism, it is “death of the unfit”, by which is, of course, meant that which failed to deal with a particular accident, which means that those individuals or groups that had less surplus than was required to stay alive long enough to recover after an accident had wiped some of them or their stored resources out, strengthen the group and the survivability of all fit individuals by dying. Therefore, each individual is not only morally obliged to overproduce if it wants to stay alive, it is morally obliged to underconsume, i.e., not consume all that it can.↩
  4. On the differences between fiat and Bitcoin, this pretty much says it all : One of the best examples of inflation being transparent is the percentile system, such as Bitcoin enforces. So, if one day I own 1% of all the goods in the world, and the next day I only own 0.5% of all the goods in the world, my position has factually erroded, and this means there was an inflation of goods in the world. This is the subtle meaning of owning say one thousand Bitcoins : you know that come Hell or high water, you will still own 1/20`000 of everything that there is. No matter what happens, you’ve got your 0.005% stake of everything. Of everything. If today that means you own five women out of ten billion people and tomorrow they manage to find better ways to pack the species up like sardines and the population jumps to 100 bn, that means your own harem headcount will also jump to 50. Just so, and just by itself – you won’t have to do anything whatsoever. Just sit there and it just comes to you, by virtue of you being the modern equivalent of an aristocrat, and all new good things that happen have to be given to you in proportion to your aristocracy. Jus Primae Noctis is no joke, it’s a policy as far as Bitcoin goes. Now conversely, in a fiat system, where there’s no fixed relation between the mass of money and the world itself, having any sum of money simply means you have to keep running, or else you’re getting erroded by those still willing to run. And even if you do keep running, you’ll still be erroded, by all those running faster – or, what’s worse, by all those running smarter. For instance if you’re the sort of idiot that runs the hard track of trying to get value out of reality you’re in for a sore beating at the hands of those who know the most productive sort of running is running to mommy government to bitch and whine. So mommy prints money, diluting your ownership of the world, to give it to these guys that are apparently smarter than you, because instead of beating reality into submission they coddle and compliment mommy to orgasm. Obviously the first system has the disadvantage that it encourages serenity (you know what Pascal said) and ossifies society, whereas the second has the disadvantage that it encourages activity. Or pollution. Either make the atmosphere unbreathable, to be frank. In any case, it’s all about progress, which is to say the constant degradation of the quality of life on the wharf by constant import of filthy, unworthy louts that have to also be fed and clothed and given yachts. So wouldn’t you make do with a small rowboat instead, this way a hundred thousand more idiots you never met and never would care to meet can also have their own boats, and be cool just like you ? We’ll issue you yacht certificates for your boats, of course, so nobody can say you don’t own a yacht anymore. We’ll even make it illegal for anyone to laugh at how stupid you are. Deal ? via The basics of banking. A discussion. pe Trilema.↩
  5. Bitcoin isn’t “unsustainable” despite the bemoaning of envirotards. Bitcoin is very sustainable and will grow up until it consumes 50.1% of the world’s electrical power resources.↩

Bitcoin as a rival digital commodity good: A supplementary comment

By Konrad S. Graf

Posted March 11, 2015

POST HEADER

POST BODY

Japanese commodity money before the eight century. Source: Wikimedia Commons, PHGCOM.One of the challenges of interpreting bitcoin has been whether it can be classified under certain existing conceptual rubrics such as “money” or “commodity” for purposes of economic analysis. Could it be some strange new kind of “commodity money”? Most people immediately and intuitively dismiss this as a possibility because it is not a physical “thing,” which they feel is a defining characteristic of commodity-ness.

Resort to a word such as “token” seems a convenient escape valve from this situation. However, this could also be misleading. A token in a “token money” context derives its value from having a fixed exchange rate against something else—a 100 pennies for a dollar, a plastic chip for a euro, etc. Bitcoin, in contrast, is traded directly as itself, with utterly no sign of any fixed exchange or substitution rates (see my “

My newest paper, “Commodity, scarcity, and monetary value theory in light of Bitcoin” in The Journal of Prices & Markets (Winter 2015) explores some of these issues in detail from a formal conceptual standpoint to check such immediate and intuitive responses. The paper takes the time to define and then apply core economic-theory concepts, including goods, scarcity, and rivalry, as well as classical lists of “commodity money” characteristics, to understanding bitcoin in terms of monetary theory.

True, commodities are usually tightly associated with materiality. However, an economic-theory sense of commodity ought to be differentiable from a physical-descriptive sense. Economics begins with the study of choice and action, as distinct from issues addressed in physical sciences. It may be that the presence of materialness in commodities has just been assumed due to the nature of the available historical examples.

For a supplemental “reality check” beyond the obscure economics library, I thought to simply go and read the Wikipedia article on “Commodity.” This should be reasonably unlikely to represent any arcane or partisan definitions from one school of economics rather than another, and should first of all represent a general-purpose range of typical current understandings of the term.

I extracted some economic-theory elements from the entry, omitting illustrative examples. The examples are mostly material items, but this is to be expected due to the overwhelmingly pre-bitcoin scope of economic history so far. Indeed, part of my argument is that bitcoin may be the first rival digital commodity good (defined in the paper), which would mean precisely that it is unprecedented, a new type of example. Between the few excerpts below, I relate these presumably mainstream characterizations of commodity-ness to bitcoin.

Extracts from Wikipedia entry on “Commodity”

The exact definition of the term commodity is specifically used to describe a class of goods for which there is demand, but which is supplied without qualitative differentiation across a market. A commodity has full or partial fungibility; that is, the market treats its instances as equivalent or nearly so with no regard to who produced them. As the saying goes, “From the taste of wheat it is not possible to tell who produced it, a Russian serf, a French peasant or an English capitalist.”

No one generally considers which mining pool mined the block that a bitcoin originated in when deciding whether to accept payment. 50 Cent, for example, is unlikely to refuse bitcoin payments for his albums from anyone using coins mined by pools other than 50 BTC.

In the original and simplified sense, commodities were things of value, of uniform quality, that were produced in large quantities by many different producers; the items from each different producer were considered equivalent.

Multiple producers: All the various Bitcoin miners produce interchangeable new coins.

One of the characteristics of a commodity good is that its price is determined as a function of its market as a whole. Well-established physical commodities have actively traded spot and derivative markets.

There are numerous bitcoin spot markets and even some derivatives markets.

Commoditization occurs as a goods or services market loses differentiation across its supply base. As such, goods that formerly carried premium margins for market participants have become commodities, such as generic pharmaceuticals and DRAM chips. There is a spectrum of commoditization, rather than a binary distinction of “commodity versus differentiable product”. Few products have complete undifferentiability.

Coin tracking is sometimes cited as a risk for weakening the completeness of bitcoin fungibility, so while fungibility largely holds, there is some risk of entering onto a “spectrum of commoditization” in which some differentiation could creep in under certain circumstances.

Overall, I thought the entry was surprisingly clear in defining commodity in terms of economic rather than material concepts. While most of the examples of commodity were material, the economic meaning was conceptually independent of materiality. As should be expected, the discussion was about economic issues such as quality differentiation, pricing, market organization, and trading patterns—not chemistry. If we are using a term in economic analysis, a strictly economic definition should be most suitable.

POST FOOTER

/post

/content-wrapper


Revolutionary Syndicalism of Bitcoin

By BTCtheory

Posted March 19, 2015

Buried deep in the annals of history we find the powerful revolutionary praxis of syndicalism. Originally a radical movement for trade unions; syndicalism pulled its principles from “Reflections on Violence,” by Georges Sorel. In this revolutionary text, Sorel explores violence and how it can help humanity save itself from the barbarism it finds itself stuck within. The influence of this text helped create the largest working class movement in France and around Europe in the early 20th century.

During the October Revolution in Russia when the bolsheviks seized power, it was the anarcho-syndicalist, armed with these teaching, who valiantly fought both the corrupt communist army of the bolsheviks and the imperialist white army of the West. In the 1920s the fascist vulgarize syndicalist teachings to give themselves powerful, personalized mythos, in which they anointed themselves with divine right to rule over all as emperors. As dangerous as this praxis may be, it also may hold the key to liberation from the tyranny of our time. If we are to take the teaching of syndicalism and imbue them into cyberspace, we may develop one of the most powerful modes of organization ever conceived: The Digital Federation.

Revolutionary Syndicalism

The profound power of Syndicalism arises out of the nihilistic tradition of taking the mantel of God for oneself. Those that are of the Syndicalist’s teachings seek spiritual meaning, and a bond with one’s own God for which they fight: themselves and their communities.

This is not some imaginary, castrated god found stapled up on sticks; pathetic and defiled, to be made an example of. Not a god of religions or institutions, but the God**that lives inside of us and insists that we forge a better world. The is a personal spiritual meaning that can only be found inside of ourselves; a personal knowledge that our struggle is righteous and meaningful. In many ways syndicalism is the jihad of the working class, and the General Strike is the apocalypse of the ruling class. Sorel, who has been called ‘the most powerful socialist since Marx’ is widely unknown today. This is mostly because of the spectacular conclusion in which Sorel presents his theory of The General Strike:

“Syndicalism conceived the transmission of power not in terms of the replacement of one intellectual elite by another but as a process diffusing authority down into the workers’ own organizations. Those organizations, unlike a system of political democracy replete with Rousseauian baggage, provided a pattern of genuine and effective representation. Most importantly, the violence employed by the proletariat in the course of the general strike bore no relationship to the ferocious and bloodthirsty acts of jealousy and revenge that characterized the massacres of The Reign of Terror.”

Sorel unapologetically embraced that we must understand violence as a tool that the state has monopolized for themselves to create the oppression we experience today. The Revolution can only be created through direct struggle against the illegal transgressions of the state unified with capitalism. It is only from demanding from ourselves, and our communities that we can build a true, and radical change that does not allow for the putrid slime of politicians and capitalists to keep a foothold in our systems of government.

A Breif History of Anarcho-Syndicalism

The power message of syndicalist can and is easily be vulgarized to serve national socialist, and their racist, authoritarian, ignorant perspectives. Fascism is the greatest form of government for the weakest and most sniveling cowards of democracy. This is what happened in Italy in 1924, Germany in 1932, and Spain in 1936 where the fascist seized power because of the cowardice of pathetic democratic governments that could not stand against them.

The fascist were able to come into power through this mystical perspective they carefully constructed with sinister propaganda that created the cult of the Great Leader. However, each of these seizure of power were valiantly resisted by the people on their own accords. The largest anarcho-syndicate ever created fought a long and bloody civil war with the fascist in Spain from 1936-39. The blasting cap of syndicalism finds its praxis in direct action, personal liberation, and knowledge that the revolution must be built and fought for. When Franco seized power in a coup in 1936, the CNT–the Spanish Anarcho-Syndicalist–rose to the occasion and heroically fought the fascist for three long and bloody years. Great citizens from around the globe answered the call of justice, and fought shoulder to shoulder with men and women of all nationalities, including 2,800 brave Americans. With the defeat of the CNT, and with the most powerful anarchist having been killed or jailed, anarchism moved underground to be forgotten for another age when the people would be ready to struggle again. That age is now upon us, and the spectre of anarchism has risen from its shallow grave to haunt the digital realm until its prophecy is realized.

The Digital Federation

The time is upon us to create the organizations that can lead a new way forward. We have the technology, and we have the will power–now we must organize. Over the coming years we will find one another in the streets, and on digital forums spread through cyberspace. We will organize from the shadows, and will strike out viciously from the night, only to abscond back into the digital sphere where we are Sovereign. Using the powerful ideology of revolutionary syndicalism we can create the digital-political organizations that shall allow for us to break the state, crush their capitalist allies, and build a new way forward. We openly declare that our ends can be attained only by the subversive overthrow of all existing social conditions through the empowerment of all people within the digital sphere. Let the ruling classes tremble at the revolutionary power of bitcoin, the personal empowerment of privacy through crypto, and the auto-didactic nature of the internet itself. There is nothing to left to lose but our chains, and there is a whole world to liberate.

—

Next: The Reappropriation of Our Economic System


Bitcoin’s seasonal affective disorder

By Mike Hearn

Posted March 23, 2015

In the past couple of years Bitcoin has been settling into a regular seasonal growth pattern, in which growth stops during the summer and we add users during the autumn/winter months (in the northern hemisphere).

It’s a little hard to see on this 2-year graph because Bitcoin traffic is easily affected by press cycles and the accompanying bubbles. When the price is skyrocketing a lot of coins move in/out of exchanges and this results in a volume spike.

However the pattern has been getting clearer with time. After the late 2013 bubble traffic grew steadily from January 2014 to around March, then fell a bit and then didn’t do very much over the summer. Starting around August 2014 traffic started to grow steadily again throughout the autumn and winter months with a sharp and obvious drop for Christmas, before steadying out again around March at around 100,000 transactions per day (1.15 txns/sec average)

Assuming a quiet summer I suspect we’ll see a slight fall as we head into April/May and organic growth will resume around August.


Double spending in Bitcoin

By Mike Hearn

Posted March 28, 2015

Double spending

in Bitcoin

and how to make it harder

In this article I will discuss double spending against merchants in Bitcoin, analyse a couple of real cases and describe several proposed schemes to make it harder. I’ll also explain the plan we’re implementing in the bitcoinj project that I lead.

This article is intended for Bitcoin wallet developers and payment processors.

First off, how big of a problem is double spending?

Double spending in the real world

GHash.io

There are several ways to do double spending in Bitcoin. One is to get a miner to unwittingly help you commit fraud. Another is to actually be such a miner. In November 2013 it was discovered that the GHash.io mining pool appeared to be engaging in repeated payment fraud against BetCoin Dice, a gambling site. Dice sites use one transaction per bet and don’t wait for confirmations.

GHash.io claimed they had investigated and found a rogue employee who had been doing the double spending, who was fired. However no evidence supporting this was provided and the incident left a permanent cloud hanging over the pool. Regardless, it didn’t seem to hurt their market share much: most miners probably never heard about the incident at all.

Eligius

The Eligius pool implements a transaction check called “is notorious” on top of the normal “is standard”. A notorious transaction is one that sends money to addresses associated with things that the pool’s owner (Luke Dashjr) considers to be “non-transactional data spam”. The list of addresses that trigger this can be found here. When it finds a notorious transaction the pool ignores it and acts like it was never broadcast: this means that by making a transaction that spends to both a merchant and a notorious address simultaneously, the mempool becomes inconsistent between Eligius and everyone else. A double spend can then be submitted directly to Eligius and if they find the block, the original transaction will be killed.

This exploit has been used to engage in double spending against a merchant that was performing a kind of quasi-exchange service. After the merchant implemented a recursive dependency check that detected the “notorious” transactions, the fraudster tried a couple more times, then gave up and went away.

The Eligius operators don’t actually want to help criminals commit payment fraud. The fact that they do is due to the way the transaction filtering patches were implemented. Luke Dashjr has told me he would accept code to fix this but isn’t going to fix it himself. Unlike most pools, Eligius and Luke are serious about decentralisation and are working on the getblocktemplate system, which lets miners pool without giving up control over transaction selection policies. So it’s possible that this policy will fade away over time, unless Eligius’ miners decide collectively to continue enforcing it as a group.

The above two cases are the ones I am most familiar with. The details of the second have been elided at the request of the parties involved. There’s probably more double spending going on that isn’t publicly discussed, but it seems rare enough to not be a major topic as of March 2015. I check in with payment processors and other merchants every so often to ask them about double spending: they tell me it’s not a problem for them right now.

There are plenty of double spend attempts happening on the Bitcoin network. But it seems like lots of them are tests, or people trying to bump the fees on their own transactions (the correct fix for this is child-pays-for-parent).

But let’s assume it gets worse and look at a series of proposed solutions for the double spending problem:

  1. Risk analysis of transactions
  2. Payment channels
  3. Countersigning by a trusted third party
  4. Remote attestation
  5. ID verification
  6. Waiting for confirmations
  7. Punishment of double spending blocks

1. Protocol risk analysis

It’s worth noting that the second case of double spending using Eligius is based on a protocol exploit: Eligius doesn’t use the same memory pool code as everyone else, but the rules it does use are public and quite easy to check for.

There were two giveaways that something was wrong:

  1. A chain of transactions with a free transaction at the bottom. This ensures that there is as much time as possible for Eligius to find a block.
  2. A transaction that pays to a “notorious” dice address.

Both of these things are easily checked for by quite simple code, which is why the merchant was able to kick the fraudster out so quickly.

This trick generalises: most memory pool differences between miners are due to version skew. Bitcoin Core releases a new version that changes the rules, and some miners upgrade quickly whilst others are slower. In the intervening time it becomes possible to exploit these differences. But the differences are often in quite obscure details that don’t crop up in regular usage. Wallets that are being kept up to date can detect transactions that are hitting the rule change and flag them as needing confirmations.

Given the types of double spending that seem to be reported today, I think it’s likely that protocol risk analysis could detect virtually all of them.

Double spend relaying

The best way to learn about a double spend is of course to see it for yourself. If you see it quickly enough, you can abort the trade before handing over anything of value.

That’s why Gavin Andresen and Tom Harding have implemented double spend relaying. This is a change to Bitcoin that makes nodes relay the first double spend of any given transaction that they see (but not others, in order to conserve bandwidth).

Both the Bitcoin Core wallet and the next release of the bitcoinj wallet know how to inform the user of conflicting unconfirmed transactions. BitcoinJ already tells you when an unconfirmed transaction is “killed” by a double spend getting confirmed, but informing the user as soon as the double spend is broadcast will go a lot further.

Double spend relaying didn’t get into Bitcoin Core because of endless arguments about whether attempting to fight double spending is pointless, but I integrated it into my Bitcoin XT patch set so anyone who wants to help relay double spends can help out by using XT instead of Core. Just make sure you stay up to date.

Bitcoin XT is still new and I haven’t done any promotion of it yet. There are deterministic code signed builds for Windows, Mac and Linux. They share data directories so if you can run Core you can easily switch back and forth: re-downloading the chain is not required.

The next major release of BitcoinJ has support in it for finding and connecting to Bitcoin XT nodes specifically, so people building on this library will be able to very quickly get access to an improved view of double spends on the network.

Risk analysis in bitcoinj

Most wallets don’t do protocol risk analysis today. BitcoinJ has some code to do it, but it’s not exhaustive. For instance it does not check for attempts to exploit Eligius.

It would make sense for someone to build a standalone server that uses this framework to risk analyse unconfirmed transactions and export the results over HTTP (using JSON-RPC, protobufs or both). If built on top of bitcoinj then we would have merchant-oriented hot wallets and client side SPV wallets using the same code to perform their risk analysis, and the pooled effort would be much more effective.

Call to action:If anyone is interested in this project, please join the bitcoinj mailing list and ask about it. I will be happy to point you in the right direction.

2. Payment channels

A payment channel is a construct using a contract protocol that I described in 2011, with later tweaks from Jeremy Spilman. The original description doesn’t use the channel terminology: I think that is something I started using later when myself and Matt Corallo built an implementation of the scheme in bitcoinj.

Briefly, the idea behind a payment channel is that you lock up some value in a multi-sig contract with the seller, in such a way that all the value starts out by being sent back to yourself. This step involves broadcasting a transaction on the Bitcoin network. Then you begin a negotiation in which you send progressively better transactions (for the seller) privately without using the P2P network. The typical use case is micropayments: each time you buy a micro-service like a kilobyte of bandwidth or second of someone’s time you send them a new transaction that allocates slightly more money to them than before. Eventually the buyer signals to the seller that they’re done negotiating and the channel should be settled on the P2P network: the final state is broadcast and the channel is closed.

It was observed early on that this scheme allows for a kind of hub-and-spoke system in which networks of channels between payment processors route payments between entities without needing to touch the block chain. From there it’s easy to observe that if you have a payment channel pre-established some time ago you can’t double spend as the transaction which opened the channel is already confirmed.

I’m a big fan of payment channels for micropayments and in fact have implemented a demo of using them to pay for file downloads. I am less keen on the idea of using them to fight double spends for these reasons:

  1. The payment channel protocol is complicated. Making a basic implementation is not too bad, but handling all the edge cases is a lot of work. The code in bitcoinj handles cases like one of the parties disappearing during the contract without formally closing the channel, serialising the state of the channel to disk so it can survive app restarts and so on. So far I believe that only bitcoinj has a production-ready implementation of payment channels. Asking all wallets to implement this protocol seems extreme: wallet authors are already maxed out just handling the complexities of the current Bitcoin protocol, let alone complex multi-step contract protocols on top.
  2. Worse: even once all the protocol edge cases are handled, users don’t want to know about the details of how their payments are being handled. So build, usage and teardown of channels all has to be entirely transparent in the user interface. That adds even more complexity.
  3. If only some wallets implement this scheme rather than all of them, the merchant still wants to accept plain old broadcast transactions. So payment fraudsters would just claim to be using a wallet that doesn’t support that feature, and it’d have little impact.
  4. If you don’t have a payment channel with the merchant or payment processor, or a path through the hub-and-spoke network, then you would have to build such a channel first. This would require waiting for a confirmation (otherwise why bother) and so in practice, the user would sometimes still end up waiting. Avoiding waits is the goal of accepting unconfirmed transactions.
  5. Payment channels tie up the users funds in ways that can be unintuitive. If you have money sitting in a channel and then want to use it to buy something from a non-channel-using merchant, you must close the channel, which requires going back to the first entity and asking them to close the channel for you. If they’re gone or unresponsive, now you have to wait for the channel to naturally expire. Explaining what’s happening to users in this case is 
. difficult.

It’s also worth noting here that payment channels are subject to a malleability attack. However fixing transaction malleability is already being worked on: because payment channels are so complex, by the time any implementation of it had interesting levels of deployment I think the anti-malleability work would be done already.

3. Countersigning by a trusted party

GreenAddress.it has proposed a scheme whereby multi-signature coins are owned by a combination of the user and a trusted wallet server. When a payment is made the wallet server signs a statement asserting that it won’t allow double spending of the used outputs.

In practice this means signing the BIP 70 Payment message with some key that is identifiable as coming from a particular trusted third party (TTP); the PKI is a good way to do this.

Whilst this technique is simple and would work, it effectively brings back elements of the old banking model with its known disadvantages:

  1. Users who don’t have a relationship with a TTP would be out of luck.
  2. The coins must be 2-of-2 because if the user could sign with a key they exclusively controlled, the extra protection wouldn’t work. GreenAddress tries to mitigate this by providing time locked transactions so if they go away or blacklist you, you will eventually get the coins back. This is a neat solution. But it’s something no other provider has adopted and I’m not sure how the tools situation looks.
  3. Merchants have to learn about and evaluate TTPs. They must then configure their system to recognise those TTPs. Then Bitcoin users must also find a TTP, evaluate them, pick one and configure their coins. This is sticky and would give existing incumbents an inertial advantage.
  4. Ideally there would be a way to automatically distribute a fraud proof and revoke the TTP if it misbehaved, but this isn’t specced.

This approach is in some ways like a network of non-anonymous miners that use regular signatures instead of PoW-style “signatures of effort” (Blockstream calls them “dynamic membership multi-party signatures”). But the current Bitcoin structure has quite a few advantages, namely that mining is a very liquid market. Ideally we’d do our best to keep that and fall back to the more traditional scheme only if we can’t make Satoshi’s more novel approach work reliably.

4. Remote attestation

A variant of the GreenAddress scheme is to use trusted computing with remote attestation instead of a trusted wallet company.

Trusted computing is a feature of modern chipsets. The CPU or TPM chip signs a statement saying “I am a real piece of hardware manufactured by X and I am running software Y”. Remote attestation is a complex technology and I’m glossing over a lot of details, but to sum up — it would allow your computer to prove to another that it’s not double spending.

In effect, the manufacturer of your computer becomes the trusted third party, except one that doesn’t even know it’s doing so because the entire process is run entirely locally with no servers required.

The problem with TC is that the implementations shipped by AMD, Intel and ARM all suck, and actually building a computer capable of remote attestation is an exercise in frustration. The technology is currently targeted only at the server market and requires exceptionally good systems programming skills to utilise.

Intel are working on a new iteration of the idea called SGX. SGX is looking a lot more promising than the existing technologies based on the documentation they’ve published so far. Unfortunately, SGX is currently vapourware: beyond some technical docs, a scientific paper from Microsoft and a handful of blog posts nothing else about it is available. It seems likely to be several years before an SGX based solution becomes workable. And unfortunately whilst ARM TrustZone is widely deployed in mobile phones it apparently can’t do remote attestation. So it seems likely that only desktop wallets will be able to pull off this trick in the forseeable future.

Even if implemented this scheme has the same problem as all the others: if not all users can do it, then payment fraudsters will just pretend they don’t have the right setup and double spend with plain old transactions. Unless almost all transactions were being counter-signed in this way it wouldn’t be feasible to restrict regular old-style transactions and the benefits wouldn’t appear.

5. ID verification

A very simple approach to fighting double spending is to just do what credit card accepting merchants already do: incrementally more aggressive ID verification of buyers depending on how much of a fraud problem there is. For example some payment processors in the credit card space use IP address profiling, billing/delivery address matching, Javascript, evercookies etc to try and catch repeat fraudsters. In extreme cases users can be blocked outright, or asked to submit documents.

This approach is simple and well tested, but of course, highly inconvenient for the buyer. Sufficiently advanced technology can make it much less inconvenient, but ideally this will never be needed because regular transactions will work well enough.

6. Waiting for confirmations

This one might seem too obvious to mention. If you can wait for confirmations, ideally you would. Unfortunately often merchants don’t do so, even in cases you’d intuitively expect would be possible like shipping items from a warehouse.

I suspect the main reason is that existing business workflows are based on the assumption that payments take only a few seconds and double spending is revealed weeks or months later. This is the model used by credit cards. It’s not unheard of for chargebacks to roll in 4 or 5 months after the original payment, long after the goods have shipped. Delays of many weeks are more common as it takes time for people to get and check their statements. So outside of things like holidays or flight tickets, most merchants just have to accept credit card double spending as a business risk and price it in: they can’t usually undo a sale before the goods or services have been provided because credit cards are too slow.

So paradoxically even though Bitcoin can reveal that a double spend took place within minutes rather than months, these businesses cannot use the new information as they have no tools or procedures in place to do so. By the time the block chain makes a decision the merchant was already informed of the payment, databases have been updated, the orders dispatched to the warehouses, the email receipt has been sent etc. Being able to undo a purchase requires software and procedures they don’t have.

Businesses could fix that by making the user sit on the invoice screen for a couple of blocks, but that interrupts the users flow and would make Bitcoin feel much slower than credit cards, even though in a sense it’s actually much faster. So they just accept unconfirmed transactions via BitPay or Coinbase and enjoy the fact that double spending against them is still very rare anyway.

7. Punishment of double spending blocks

The purpose of mining is to prevent double spending by recording the chronological order of transactions as accurately as possible. Miners that execute Finney attacks to defraud sellers are not doing that; they’re charging the collective Bitcoin community money via the inflation subsidy for a service they aren’t actually providing.

Normally when an entity charges you for something and then doesn’t provide it, there are consequences. The consequence for a miner trying to fork the chain and undo confirmed transactions is that they stand a good chance of losing the electricity (i.e. money) they used to mine: this is a good incentive to behave. For Finney attacks there are no consequences.

Tom Harding has been researching the possibility of identifying blocks that appear to be engaging in Finney attacks and making a slight alteration to the first seen rule for blocks. Of course, this rule is critical for Bitcoin’s operation so changes to it are not to be taken lightly at all. He has written a paper on his proposed change to the rules which features a lot of analysis of the potential impacts. His goal is to give more certainty for transactions after about thirty seconds has passed.

I have not had time to thoroughly read or analyse this proposal and so have no strong opinion on it. That said, it’s unclear to me that 30 seconds is significantly better than ten minutes: I suspect the utility dropoff after about 5–10 seconds is dramatic given the desired “guy in queue paying for coffee” type user experience. 30 seconds is probably OK on the web but it would still make us far slower than EMV contactless credit cards for in person transactions.

Breaking 0-conf transactions

There’s a school of thought that says if something cannot be done perfectly, maybe it should not be done at all. If unconfirmed transactions are not bulletproof, these people reason, perhaps they should be entirely useless so nobody relies on them and then gets burned.

This line of thinking is one of the reasons that double spend relaying is not integrated into Bitcoin Core and has to be made available via Bitcoin XT instead.

The problem is that in the entire history of money there have been no fraudless payment systems, ever. Bank wires get reversed, credit cards are charged back, cheques bounce, bank notes are counterfeited and blocks are reorganised. If people were being routinely “protected” from imperfect payment systems they would be unable to trade at all. So in practice all trade involves double spending risk and businesses learn how to manage that risk with acceptable overheads.

Bitcoin is no different: it just involves a different sets of risks and management techniques. As of 2015, many merchants have decided that the risk:reward ratio of accepting unconfirmed transactions is worth it. So trying to break them in order to protect people makes about as much sense as forging $100 bills to educate merchants about the dangers of paper money. Not only is it logically nonsensical and harmful to innocent people, it’s also illegal.

But this idea fails for another reason. Although it’s always tempting to deal with potential problems by simply scrapping the feature that has them, this isn’t an option for Bitcoin:

  1. Almost all online merchants today are accepting unconfirmed transactions, because that’s the default for BitPay, Coinbase, Coinify and other payment processors.
  2. Physical shops need them.
  3. Newer apps are often hiding or reducing the visibility of confirmations as a concept, because it’s hard to explain what this actually means to end users.

Based on my own experience of buying and selling things with Bitcoin the only sellers that make you wait for blocks are exchanges.

So whether we like it or not, the block chain algorithm as currently specified is not a solution for all payments and denying that won’t get us anything except market irrelevance. Finding ways to optimise the current system in backwards compatible ways is a reasonable and pragmatic path forward 
 and nobody will blame us for trying our best.


Replace by fee

By Mike Hearn

Posted March 28, 2015

A counter argument

Lately I have been asked about the replace by fee (RBF) patch by Peter Todd, and the “scorched earth” policy he proposed to go along with it.

I think RBF is a badly thought out idea that won’t work, doesn’t do what it’s claimed to do and would be harmful for Bitcoin if adopted.

In this article I will argue the case against RBF. I am not alone in thinking that this proposal is a bad idea and I hope after reading this you will agree with us:

Repeating past statements, it is acknowledged that Peter’s scorched

earth replace-by-fee proposal is aptly named, and would be widely

anti-social on the current network

— Jeff Garzik

Coinbase fully agrees with Mike Hearn. RBF is irrational and harmful to Bitcoin. — Charlie Lee, engineering manager at Coinbase

Replace-by-fee is a bad idea. — Gavin Andresen

I agree with Mike & Jeff. Blowing up 0-confirm transactions is vandalism.

— Adam Back (a founder of Blockstream)

In a second article, I discuss double spending in general and other proposed solutions for making it harder.

What is it?

Replace-by-fee-scorched-earth is an attempt to fix perceived problems with unconfirmed transactions and make double spending harder.

Since day one Bitcoin has had a rarely discussed but fundamental rule called the first seen rule. The first seen rule says that given two transactions or blocks that build off the same dependency, whichever one the node saw first wins.

This rule is not something that can be enforced via the block chain itself, but it’s still critical for how Bitcoin works. In the case of choosing which block to mine on, it’s what incentivises people to start building on top of the new block when one is found rather than trying to split the chain by finding another block that’s somehow “better”. In the case of transactions, it’s what allows us to buy things in shops and make payments in seconds rather than hours.

The RBF patch replaces this rule with a new one that says given two transactions, whichever one pays the highest fee wins. It doesn’t propose changing the first seen rule for blocks, although as we will see in a moment, the broken logic that drives RBF applies to blocks just as easily as it does transactions, so this inconsistency makes little sense.

The primary effect of adopting RBF would be to make double spending of unconfirmed transactions very easy. Todd wants wallets to have an undo button in them that broadcasts a double spend transaction with a higher fee that returns the money back to the users wallet.

Scorched earth

This leads to an obvious problem — being able to send money in seconds rather than waiting for blocks is a highly desirable feature. It’s absolutely essential for buying stuff in shops. A currency that can’t be used to buy a newspaper on the street is not going to be seen as a real currency by the man on that street.

So Todd argues for a second thing: what he calls “scorched earth”. It’s actually an idea proposed by a pseudonymous author who called himself John Dillon, although apparently he did not describe this in any public post.

It relies on a second change called child pays for parent. This change was originally proposed years ago (by whom has now been lost in the mists of time), and has been implemented by Luke Dashjr in the Eligius pool. It makes a lot of sense by itself and is hopefully going to be integrated into the next Bitcoin Core release. Child-pays-for-parent means that miners will consider the fees of transaction graphs as a whole rather than just the individual components. Intuitively, it means if there is a transaction with no fee sitting around waiting to be confirmed, then another transaction that spends the first and does have a fee will increase the priority of the free transaction. This makes sense for miners as otherwise there would be stranded money they could take blocked up behind a free transaction, and it makes sense for users and merchants as they can now bump the fee on a transaction that’s taking too long to confirm, by adding a spend-to-self transaction on top.

The idea behind “scorched earth” is that if someone buys something with an unconfirmed transaction, when they walk out of the shop and press undo they double spend the original output to themselves with a higher fee, but the merchant sees this and then adds a spend-to-self transaction on top of their original payment with a slightly higher fee, and then the fraudsters wallet does the same to bump the fee on his chain of transactions, and so on and so on until the entire payment has been consumed in fees. The fraudster gets the goods, the payment is now going to a miner instead of the merchant, and the merchant is left with nothing.

Game theory and rationality

John Dillon argued that by making the initial transaction pay much more money than the actual price of the thing they’re buying (with the merchant sending the difference back to the buyer in a second transaction), an attempt to double spend will result in the buyer losing more money than the product was actually worth and so double spending in this way becomes irrational. Thus unconfirmed transactions would become safe.

Note: this means people will get money stuck in their wallet that’s difficult to spend, because buying something would require committing more money to the transaction than the item actually costs. That would be a severe usability problem, but I’ll ignore it for the purposes of this article.

Additionally, RBF advocates argue that adoption of RBF-SE is inevitable because any rational miner wishes to maximise his income from fees, and as nothing in the Bitcoin protocol enforces the first seen rule it will be abandoned in order to maximise short term profit.

These arguments sound good because they seem to only rely on game theory, a careful arrangement of incentives and some small technical tweaks to the protocol. Also they come with large helpings of cleverness — guaranteed to appeal to Bitcoiners.

The problem is both arguments rely on extremely dodgy definitions of rationality. If rationality is misdefined then arguments based on game theory can result in garbage conclusions.

The first argument sounds good until you remember that the merchant still lost their product to the fraudster, and the miner gained more than the price of the goods in question. This situation is stable right until the moment miners and fraudsters realise they can team up and split the earnings. That is easy to implement: miners running the patch set just have to add another patch that picks the output which was double spent and then sends some of the double spent value to it (say a quarter). Now the fraudster got the stolen goods and half their money back, so they effectively only paid half price and can now fence the goods for a bit more than that to yield a reliable stream of profit.

In other words, replace-by-fee-scorched-earth collapses completely with only a tiny extra step.

But it gets worse! Even if this collaboration doesn’t happen, the merchant has still lost the goods that were effectively stolen from them. This means any rich company can simply double spend a small competitor into oblivion by repeatedly stealing goods from them. This is much more powerful than market dumping because it works even if the competitor has better products that would otherwise resist below-cost pricing.

In practice, of course, neither outcome would hurt merchants much at all for a stunningly obvious reason: faced with this type of payment fraud they would just abandon Bitcoin and go back to banking. Credit cards might well have chargebacks, but they are ordinary trade disputes and merchants win the case about 40% of the time. It’s easy to forget this in the middle of entertaining but abstract arguments about game theory. Our competition is not some academic ideal, it’s consensus-by-mainframe. If we’re worse than that Bitcoin won’t get adopted.

There’s one final problem. The code Peter Todd is pushing does not implement this system and thus using it would not result in the outcome he suggests, even if we ignore the gaping holes in the underlying reasoning. Specifically he hasn’t implemented the wallet side of the protocol anywhere, not even in obscure wallets, and so in reality nobody would notice the second double spend and start the scorched earth mechanism. They would just lose the entire amount and it’d cost the fraudster one satoshi.

In the end, all this code actually does is make fraud easier. That helps nobody.

The inevitability of failure

RBF advocates tend to argue that replace by fee is inevitable even if it leads to lots of double spending, because a rational miner will always want to take the transactions with the highest fees and nothing in the block chain algorithm stops them from doing so.

This argument also relies on a ridiculous definition of rational.

Whilst rational economic actors do attempt to maximise their profit, the argument ignores that this takes place in the context of varying time windows. In effect it argues that it’s “rational” to take a tiny increase in profit today even if that destroys your business and all the potential long term profits you could obtain tomorrow and the day after. This definition is absurd and no actual business works that way.

In reality businesses attempt to maximise profit over some kind of time period, which is almost always longer than the time it’d take merchants to abandon Bitcoin and go back to credit cards (probably on the order of weeks or days). If we saw massive double spending then large numbers of merchants would find the hassle of accepting Bitcoin to be much greater than the benefits, would stop accepting it, and the resulting loss of confidence would kill the BTC price. That in turn would cripple miner profits and send many of them underwater on their investments.

Only in a world where most miners have literally nothing to lose and have absolute confidence that BTC will be worthless tomorrow would it make sense for them to collectively wreck their businesses like that. Yet the argument for replace-by-fee states that this outcome is inevitable! That’s not showing much confidence in the future of Bitcoin!

Of course, from time to time there will be a miner who has much shorter time horizons than the others. Perhaps they suddenly have an unexpected need for cash, or perhaps they receive notice mining is being banned in their country, or perhaps a bad insider without any stake in the business decides to scam some merchants and run with the money. Bitcoin is designed to tolerate a minority of dishonest miners and a small amount of payment fraud against unconfirmed transactions is tolerable by merchants. What cannot work is a global change to the rules that makes every miner behave this way by default.

RBF for blocks

One problem with the definition of replace-by-fee is that whilst Peter’s patch only implements the logic for unconfirmed transactions, if miners are expected to ignore the rule for new broadcasts it stands to reason they would ignore it for confirmed transactions as well.

Put simply, if a miner sees a broadcast double spend of a confirmed transaction that would result in fees higher than the expected cost of forking the chain, miners implementing the RBF policy completely would then start work on forking the chain from that point. And as they would all do it simultaneously, this would then incentivise broadcasts of yet more double spends against already confirmed transactions that have only tiny fee increases — but as miners are working on a rewrite of the timeline anyway, it costs them nothing to go back and include other double spends as well.

So RBF taken to its logical conclusion not only results in unconfirmed transactions becoming useless, but confirmed transactions too!

This is why the abstract to Satoshi’s paper states:

As long as a majority of CPU power is controlled by nodes that are not cooperating to attack the network, they’ll generate the longest chain and outpace attackers.

Both a plain reading of Satoshi’s paper and common sense will tell you that going back in time and double spending is an attack on the network.

Quoting Satoshi again:

In this paper, we propose a solution to the double-spending problem using a peer-to-peer distributed timestamp server to generate

computational proof of the chronological order of transactions

. The system is secure as long as honest nodes collectively control more CPU power than any cooperating group of attacker nodes.

Making miners ignore the “chronological order of transactions” by default converts them all into dishonest attackers, which would break the system completely.

Is Bitcoin really protected by honesty?

Although Satoshi’s paper used the term honest where these days we would say rational, sometimes people have trouble with the idea that Bitcoin is reliant on lots of people sticking to the rules rather than pure mathematics.

I suspect the belief that Bitcoin is protected by pure maths has its roots in the word cryptocurrency, which is a false friend. After all, everyone knows that nobody can crack an encrypted message no matter how many people agree it should be done. So it stands to reason that cryptocurrency would give the same hardness to money that cryptography gives to messages. But nothing in Bitcoin is encrypted. All it does is produce a couple of documents — the ledger and an audit log showing how the ledger got into that state. The interpretation of those documents is and always will be up to people, who can ignore them entirely or selectively whenever they want to.

So: money is not a mathematical construct. It’s a social construct. The fact that Bitcoin uses some fairly basic maths to coordinate social decisions over the internet doesn’t change that.

Is RBF happening already?

Occasionally someone claims that RBF is already in use by miners and so this policy is already here and we might as well just deal with it. In fact there’s a guy named Tom Harding who monitors the Bitcoin network for double spends. He has observed attempts at exploiting RBF and discovered that for transactions spaced 10 seconds apart it only works about 1% of the time. This is higher than the ideal of zero, but with a 10 second gap some of that can be explained just through slow propagation and anyway, wallets can watch out for a propagating double spend and tell the merchant to abort the transaction. So in practice it’s easy to avoid losses due to this type of attack. 10 seconds is still a lot better than 10 minutes.

Conclusion

  • The current replace by fee patch is incomplete, as it doesn’t implement the protocol in any wallets. So it doesn’t provide the outcome the author claims it does.
  • Even if it had more implementations, the underlying logic requires a tortured form of game theory that doesn’t match the real world. It fails as soon as miners and payment fraudsters start collaborating.
  • Even if it worked in the way it claims to work, it would allow big companies to crush smaller competitors very easily, just by double spending against them.
  • It requires people to have more money than in their wallet than they can actually spend in shops. Good luck explaining this to the ordinary people we want to adopt Bitcoin.
  • Making unconfirmed transactions useless would break Bitcoin, cause merchant abandonment, crush the price and push many miners underwater on their investments. It’d be highly irrational for miners to get on board with this.
  • The RBF policy directly contradicts the definition of Bitcoin given in the white paper. It would logically apply to blocks as well as unconfirmed transactions given high enough fees and low enough inflation rewards. Bitcoin cannot operate at all with such a policy.
  • Given all of the above, RBF is not implemented widely and attempts to exploit it virtually always fail. RBF is in no way inevitable and miners that adopt it are just shooting themselves in the foot.

Categories:

Updated: