The probabilities of Section 5 answer the adversarial merchant, who assumes the customer is an attacker. The paper’s §6 answers the realistic one: when is the attack worth mounting at all? Throughout this section — “[o]therwise, all bets are off” (§6) — and the model is deliberately stylised; its own caveats close the section.
The attacker targets merchants simultaneously with payments of each, all invalidated by the same secret branch; the goods are worth to him, ; he gives up after mining blocks in vain; and each of his blocks would earn the block income if it ended up in the accepted chain. If the attack succeeds his blocks are all accepted (he keeps goods and coins and rewards); if it fails he has paid , keeps goods worth , and his orphaned blocks forfeit . For an exact finite-stop profit calculation, would have to be the success probability of that stopping policy. Following the paper, the tables below instead insert the unlimited-horizon as a heuristic proxy. They are not an exact evaluation of a strategy that always stops after private blocks.
Given success probability and these stipulated payoffs, the attacker’s expected profit over not attacking is
positive if and only if
(when ; when the modeled attack is never strictly profitable). This modeled attack is not strictly profitable whenever
| (3) |
which with the paper’s choices , , , BTC is its equation (2), BTC.
The gain is certain (the goods are obtained either way); the loss is paid exactly when the attack fails, with probability . Rearranging the positivity condition gives the threshold; substituting the paper’s constants gives . □
The block subsidy is value issued by the protocol in a block, distinct from fees transferred by its transactions. Its scheduled component is base issuance determined by height, before any reserve payout. A funding stream is a required allocation of a share of that subsidy to a designated recipient. The coinbase is the block’s first transaction, which distributes the available subsidy and fees according to the applicable rules. The reserve is the accounting balance of funds removed from circulation and awaiting reissuance.
The income forfeited by an orphaned block is the amount its miner would have retained: miner subsidy plus retained transaction fees, not the subsidy allocated to other recipients. Under NU7 this depends on scheduled issuance, the prior reserve balance, and the applicable fee-removal rule (Section 8.8). A universal ZEC figure would therefore hide assumptions about both chain state and unresolved draft rules.
Instead, Table 3 measures transaction value in units of the chosen block income . With the paper’s , , and , equation (3) becomes
Once a particular threat model supplies , multiplying by it gives the corresponding monetary threshold. Treating as constant over the attack remains a modelling assumption.
Within the model, a handful of confirmations makes the attack unprofitable against small attackers at any plausible payment size; against a attacker, six confirmations make modeled expected profit non-positive only up to about times the assumed block income . The required count grows only logarithmically in the value at stake, by the geometric decay of Theorem 5.2. These are neither exact finite-stop profit calculations nor bounds on deployed rollback risk; the deployed tie-break, changing difficulty, and rollback rails require separate modelling.
At , eventual strict overtake has probability , but the walk has zero drift; that fact alone does not give the attacker a lasting monopoly. When , the economics change character entirely: the paper notes a strict majority attacker can double-spend at no cost beyond normal mining, reject every other miner’s blocks to take the whole issuance, and exclude transactions at will, driving honest miners out and entrenching himself — so a majority attack “is best seen as an attempt to destroy” the currency, motivated from outside it (a short position, a competing system), not an attempt to profit inside it. Confirmation policy is not the defence at that point; the defence is the cost of assembling the majority, which lies outside this model.
The paper flags each stylisation itself. The give-up point “is a significant simplification” (an optimal attacker balances completion against compounding losses); the safe values “should be taken with a grain of salt, because of the many modeling assumptions”; and a model resting on mining costs rather than forfeited rewards would make the required confirmations linear, not logarithmic, in the transaction value — “very poor security, hence in a situation where this is relevant, we have already lost anyway” (§6). The bound’s role is the shape it reveals — logarithmic patience buys exponential safety — not its third significant digit.