The Zcash ArboretumThe Complete Arboretum PDF

7 The economics of the attack

The probabilities of Section 5 answer the adversarial merchant, who assumes the customer is an attacker. The paper’s §6 answers the realistic one: when is the attack worth mounting at all? Throughout this section q<p — “[o]therwise, all bets are off” (§6) — and the model is deliberately stylised; its own caveats close the section.

The attacker targets k merchants simultaneously with payments of v each, all invalidated by the same secret branch; the goods are worth α⁢v to him, 0<α≤1; he gives up after mining o blocks in vain; and each of his blocks would earn the block income B if it ended up in the accepted chain. If the attack succeeds his blocks are all accepted (he keeps goods and coins and rewards); if it fails he has paid k⁢v, keeps goods worth k⁢α⁢v, and his o orphaned blocks forfeit o⁢B. For an exact finite-stop profit calculation, r would have to be the success probability of that stopping policy. Following the paper, the tables below instead insert the unlimited-horizon r⁢(q,n) as a heuristic proxy. They are not an exact evaluation of a strategy that always stops after o=20 private blocks.

Proposition 7.1 (Profitability; Rosenfeld §6).

Given success probability r and these stipulated payoffs, the attacker’s expected profit over not attacking is

k⁢α⁢v−(1−r)⁢(k⁢v+o⁢B)=k⁢v⁢(α+r−1)−(1−r)⁢o⁢B,

positive if and only if

v>(1−r)⁢o⁢Bk⁢(α+r−1)

(when α+r>1; when α+r≤1 the modeled attack is never strictly profitable). This modeled attack is not strictly profitable whenever

v≤o⁢(1−r)⁢Bk⁢(α+r−1)⁢=α=1⁢ok⋅B⁢(1−r)r, (3)

which with the paper’s choices o=20, k=5, α=1, B=25 BTC is its equation (2), v≤100⁢(1/r−1) BTC.

Proof.

The gain k⁢α⁢v is certain (the goods are obtained either way); the loss k⁢v+o⁢B is paid exactly when the attack fails, with probability 1−r. Rearranging the positivity condition gives the threshold; substituting the paper’s constants gives 20⋅25⋅(1−r)/(5⁢r)=100⁢(1−r)/r. □

7.1 Reward-normalised exposure

The block subsidy is value issued by the protocol in a block, distinct from fees transferred by its transactions. Its scheduled component is base issuance determined by height, before any reserve payout. A funding stream is a required allocation of a share of that subsidy to a designated recipient. The coinbase is the block’s first transaction, which distributes the available subsidy and fees according to the applicable rules. The reserve is the accounting balance of funds removed from circulation and awaiting reissuance.

The income B forfeited by an orphaned block is the amount its miner would have retained: miner subsidy plus retained transaction fees, not the subsidy allocated to other recipients. Under NU7 this depends on scheduled issuance, the prior reserve balance, and the applicable fee-removal rule (Section 8.8). A universal ZEC figure would therefore hide assumptions about both chain state and unresolved draft rules.

Instead, Table 3 measures transaction value in units of the chosen block income B. With the paper’s o=20, k=5, and α=1, equation (3) becomes

vB≤4⁢1−rr.

Once a particular threat model supplies B, multiplying by it gives the corresponding monetary threshold. Treating B as constant over the attack remains a modelling assumption.

q n=1 2 4 6 8 10
5% 36 271 10,327 344,743 10,931,506 336,737,801
10% 16 67 729 6,759 59,475 508,917
20% 6 15 55 167 467 1,262
30% 2 5 11 21 35 57
40% 1 1 2 4 5 6
Table 3: The largest whole-number multiple of block income B with non-positive heuristic expected profit: ⌊4⁢(1−r)/r⌋, computed by script. The table is dimensionless: it neither fixes a ZEC subsidy nor predicts future fee income. Values inherit every assumption of the model; the caveats of Remark 7.3 apply in full.

Within the model, a handful of confirmations makes the attack unprofitable against small attackers at any plausible payment size; against a 30% attacker, six confirmations make modeled expected profit non-positive only up to about 21 times the assumed block income B. The required count grows only logarithmically in the value at stake, by the geometric decay of Theorem 5.2. These are neither exact finite-stop profit calculations nor bounds on deployed rollback risk; the deployed tie-break, changing difficulty, and rollback rails require separate modelling.

Remark 7.2 (Majority is a different problem).

At q=p, eventual strict overtake has probability 1, but the walk has zero drift; that fact alone does not give the attacker a lasting monopoly. When q>p, the economics change character entirely: the paper notes a strict majority attacker can double-spend at no cost beyond normal mining, reject every other miner’s blocks to take the whole issuance, and exclude transactions at will, driving honest miners out and entrenching himself — so a majority attack “is best seen as an attempt to destroy” the currency, motivated from outside it (a short position, a competing system), not an attempt to profit inside it. Confirmation policy is not the defence at that point; the defence is the cost of assembling the majority, which lies outside this model.

Remark 7.3 (The model’s own caveats).

The paper flags each stylisation itself. The give-up point o=20 “is a significant simplification” (an optimal attacker balances completion against compounding losses); the safe values “should be taken with a grain of salt, because of the many modeling assumptions”; and a model resting on mining costs rather than forfeited rewards would make the required confirmations linear, not logarithmic, in the transaction value — “very poor security, hence in a situation where this is relevant, we have already lost anyway” (§6). The bound’s role is the shape it reveals — logarithmic patience buys exponential safety — not its third significant digit.