LibraryConsensus2014Design paperCorpus record
Majority Is Not Enough: Bitcoin Mining Is Vulnerable
Selfish Mining. Ittay Eyal and Emin Gün Sirer.
A miner who withholds blocks and releases them to waste honest work can earn more than their share, even below 50 percent, under the paper's propagation assumptions.
A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.
A mining-pool pitch that ignores block propagation is ignoring the variable this attack turns on.
The five-minute read
The defect
The informal claim was that a miner below half the hash power does best by publishing every block at once.
The rule
A miner who withholds blocks and releases them to waste honest work can earn more than their share, even below 50 percent, under the paper's propagation assumptions.
How it is put together
The attacker keeps a private chain. They publish when the public chain threatens to overtake. Honest miners split across the two tips and waste work.
Where the claim stops
The threshold in the paper is not a universal constant. Gamma, the propagation parameter, moves it.
One action, walked through
- Model miners as a share of hash power.
- Compare revenue under honest publication and under the withholding policy.
- The threshold depends on how quickly the attacker's block reaches the network.
- What share of hash power is assumed?
The argument, unpacked
Why it is still on the desk
A mining-pool pitch that ignores block propagation is ignoring the variable this attack turns on.
After the text
Later work studied stubborn mining and published the gamma parameter more carefully. Pools still matter because they concentrate the decision to withhold.
What has to be true
- The threshold in the paper is not a universal constant. Gamma, the propagation parameter, moves it.
- It is not a proof that bitcoin failed.
- It does not say a 51 percent attack is cheap.
What happened after the paper
Later work studied stubborn mining and published the gamma parameter more carefully. Pools still matter because they concentrate the decision to withhold.
What to check before you use the idea
- What share of hash power is assumed?
- How fast does the withheld block propagate?
- Does the deployment's relay network change gamma?
Terms
- Private chain
- Blocks the attacker has mined and not yet shown.
- Gamma
- How the rest of the network splits when two blocks race.
The problem the paper names
The informal claim was that a miner below half the hash power does best by publishing every block at once.
What the design proposes
- The attacker keeps a private chain.
- They publish when the public chain threatens to overtake.
- Honest miners split across the two tips and waste work.
How the mechanism is specified
- Model miners as a share of hash power.
- Compare revenue under honest publication and under the withholding policy.
- The threshold depends on how quickly the attacker's block reaches the network.
What this page does not treat as proven
- The threshold in the paper is not a universal constant. Gamma, the propagation parameter, moves it.
- It is not a proof that bitcoin failed.
- It does not say a 51 percent attack is cheap.
Why a venture studio still reads it
A mining-pool pitch that ignores block propagation is ignoring the variable this attack turns on.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
