Larger-scale Nakamoto-style Blockchains Don't Necessarily Offer Better Security

Jannik Albrecht, Sebastien Andreina, Frederik Armknecht, Ghassan Karame, Giorgia Marson, Julian Willingmann

IEEE Symposium on Security and Privacy 2024 · Day 2 · Continental Ballroom 6

Overview

The prevailing intuition in blockchain security suggests that increasing the number of nodes in a network inherently leads to greater security due to enhanced decentralization and a reduced risk of a majority of nodes being corrupted. This talk challenges this fundamental assumption, presenting a detailed analysis that reveals a critical flaw in existing security models and demonstrates that, under certain conditions, adding more nodes to a Nakamoto-style blockchain can paradoxically weaken its security guarantees. The research, a collaborative effort from Ruhr University Bochum and NEC Labs Europe, introduces a novel security metric that reconciles the competing forces of increased network delay and distributed power, offering a more comprehensive understanding of blockchain robustness at scale.

Watch on YouTube

Visual summary for Larger-scale Nakamoto-style Blockchains Don't Necessarily Offer Better Security by Jannik Albrecht, Sebastien Andreina, Frederik Armknecht, Ghassan Karame, Giorgia Marson, Julian Willingmann
Visual summary for Larger-scale Nakamoto-style Blockchains Don't Necessarily Offer Better Security by Jannik Albrecht, Sebastien Andreina, Frederik Armknecht, Ghassan Karame, Giorgia Marson, Julian Willingmann

Key moments

  1. 0:00 Welcome and motivation: security vs. network scale
  2. 1:50 Identified gap and reconciliation of opposing forces
  3. 2:00 Motivating security increase due to distributed power
  4. 4:00 Defined security model and adversary capabilities
  5. 4:40 Introducing F, G functions and main security theorem
  6. 6:20 Characterizing network delay (Delta) as function of scale
  7. 7:00 Large-scale simulation setup and Simlock modifications

Larger-scale Nakamoto-style Blockchains Don't Necessarily Offer Better Security

Speakers: Jannik Albrecht, PhD student, Ruhr University Bochum; Sebastien Andreina, NEC Labs Europe; Frederik Armknecht, University of Mannheim; Ghassan Karame, Ruhr University Bochum; Giorgia Marson, NEC Labs Europe; Julian Willingmann, Ruhr University Bochum

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=qTHto97H2hc

Overview

The prevailing intuition in blockchain security suggests that increasing the number of nodes in a network inherently leads to greater security due to enhanced decentralization and a reduced risk of a majority of nodes being corrupted. This talk challenges this fundamental assumption, presenting a detailed analysis that reveals a critical flaw in existing security models and demonstrates that, under certain conditions, adding more nodes to a Nakamoto-style blockchain can paradoxically weaken its security guarantees. The research, a collaborative effort from Ruhr University Bochum and NEC Labs Europe, introduces a novel security metric that reconciles the competing forces of increased network delay and distributed power, offering a more comprehensive understanding of blockchain robustness at scale.

Jannik Albrecht, a PhD student at Ruhr University Bochum, presented this work, highlighting a significant gap in how the security of growing blockchain networks is typically assessed. The paper identifies two opposing forces: while an increased number of nodes theoretically reduces the likelihood of adversarial control, it simultaneously exacerbates network delays, which existing security models indicate can degrade security. The core contribution is a theoretical framework and empirical evaluation that quantifies these forces, demonstrating that for many real-world blockchain deployments, there exists a "turning point" beyond which network expansion actively undermines security.

This research carries profound implications for the design and scalability of Nakamoto-style blockchains like Bitcoin, Ethereum Classic, Cardano, and Monero. It compels architects and developers to reconsider the simplistic notion that "more nodes equal more security," urging a more nuanced approach that factors in the practical constraints of block propagation delays and the specific characteristics of gossip protocols. The findings underscore the importance of robust network protocols and configuration choices in maintaining security as these decentralized systems strive for larger user bases and higher throughput.

Background

▶ Watch: Welcome and motivation: security vs. network scale (0:00)

The motivation behind this work stems from a perceived disconnect between intuitive understanding and formal security models regarding blockchain scalability. Traditionally, a larger network with more nodes is assumed to be more secure because it becomes statistically harder for an adversary to corrupt a significant fraction of participants. This distributed power is a cornerstone of Nakamoto-style consensus. However, existing theoretical security conditions, such as the one proposed by Demou et al. at CCS'22, present a contradictory picture.

The Demou et al. security condition, which evaluates the maximum adversary power (rho_adv) relative to honest user power (rho_honest), features the maximum internal network delay (Delta) in the denominator of its right-hand side. Mathematically, this implies that increasing Delta — a common consequence of adding more nodes and thus increasing network diameter and traffic — directly leads to weaker security guarantees. This creates a fundamental tension:

  1. Decreasing Security due to Increasing Delays: As the network grows (N increases), block propagation delays (Delta) tend to increase. According to established security conditions, this rise in Delta directly diminishes the network's security.
  2. Increasing Security due to Distributed Power: Conversely, a larger network (N increases) means the same fixed number of corrupted nodes or a fixed individual corruption probability (P_star) represents a smaller fraction of the total network power, making it harder for an adversary to achieve majority control. This intuitively should increase security.

The critical observation made by the authors is that existing security models primarily capture the first force (delay-induced insecurity) but largely fail to account for the second force (security gain from distributed power). This gap leaves a crucial aspect of blockchain robustness at scale unaddressed, leading to potentially misleading conclusions about the security implications of network growth. The paper aims to reconcile these two opposing forces through a rigorous theoretical framework and an extensive empirical evaluation.

Key Findings

▶ Watch: Motivating security increase due to distributed power (2:00)

The research yielded several significant findings that challenge conventional wisdom regarding blockchain security and scalability:

  1. Reconciliation of Opposing Forces: The authors successfully reconciled the conflicting effects of increasing network delays and the security benefits of distributed power through a novel theoretical analysis. They introduced a security metric P(n) that accurately captures both phenomena, providing a more holistic view of blockchain security as a function of network scale n.
  2. Empirical Characterization of Network Delay: Through extensive large-scale simulations, the paper empirically determined that the maximum network delay Delta(n) can be approximated as a logarithmic function of the network scale n, specifically Delta(n) = A * log(n) + B. This characterization is crucial for integrating real-world network behavior into the theoretical security model.
  3. The "Turning Point" Phenomenon: A surprising and critical finding is the existence of a "turning point" in network scale. For many blockchain deployments, security initially increases with the number of nodes, but beyond a certain threshold (the turning point), adding more nodes actually impairs and eventually reduces the network's security. This contradicts the common intuition that larger networks are always more secure. For example, the Cardano deployment showed a turning point at approximately 20,000 nodes, after which security degraded significantly.
  4. Vulnerabilities in Specific Deployments: The analysis revealed that Cardano and Ethereum Classic deployments are particularly vulnerable. They exhibit relatively small turning points and can become insecure against adversaries capable of corrupting individual nodes with a success rate (P_star) larger than 29% when the network size exceeds 10^6 nodes.
  5. Impact of Gossip Protocol: The study conclusively demonstrated that the choice of gossip protocol has a high impact on how significantly real-world delays increase with network scale and, consequently, on the network's overall security. Different protocols (advertisement-based, direct push, hybrid, compact block) lead to vastly different delay characteristics and turning points.
  6. Robustness of Bitcoin's Compact Block Relay: In contrast to Cardano and Ethereum Classic, Bitcoin's implementation using the compact block relay (BIP 152) significantly increases the network's robustness. For Bitcoin, the turning point was found to be "out of bounds" for reasonable network sizes, indicating that its security is less likely to be impaired by adding nodes. Even with an adversary having a P_star of 47% or higher and a network larger than 10^9 nodes, Bitcoin could still remain secure under certain conditions.
  7. Real-World Attacks Can Break Security: The comparison of empirically measured delays under state-of-the-art network attacks (delaying block propagation by 1 to 5 block times, or 600 to 3000 seconds) against the maximum tolerable delays derived from the security metric revealed a concerning reality. For certain P_star values (e.g., 0.3 or 0.4), the measured delays under attack conditions can exceed the tolerable limits, indicating that some networks face serious issues that break their security guarantees.

Technical Deep Dive

▶ Watch: Defined security model and adversary capabilities (4:00)

The core of the paper's technical contribution lies in its refined security model and the empirical methodology used to characterize network behavior.

Security Model Refinement

The authors start by introducing a security model that builds upon existing work but incorporates the probabilistic nature of adversarial node corruption and the impact of network scale.

  1. Individual Node Corruption: Each node in the network is initially considered honest. An adversary attempts to corrupt each node individually, succeeding with a success rate P_star. This P_star is assumed to be independent of the network scale n.
  2. Adversary's Power (rho_adv): Unlike some models that bound adversarial power, this model allows rho_adv to be technically unbounded, meaning an adversary could corrupt the entire network if P_star is sufficiently high.
  3. Network Attacks: The adversary is allowed to leverage state-of-the-art network attacks to delay block propagation. Previous research has shown that such adversaries can delay block propagation by up to five block times, or even more. This crucial factor directly influences the Delta parameter.

Theoretical Analysis: Reconciling Forces

To reconcile the two opposing forces (delay vs. distributed power), the authors introduce three key functions:

  1. Function F(i, n): This binomial probability function denotes the probability of an adversary corrupting exactly i out of n nodes in the network, given the individual corruption probability P_star.

F(i, n) = C(n, i) (P_star)^i (1 - P_star)^(n-i)

where C(n, i) is the binomial coefficient. This function captures the effect of distributed power.

  1. Function G(n): This function represents an upper bound on the number of corrupted nodes that the network can tolerate while still remaining secure. G(n) is derived by rearranging the security condition by Demou et al. (CCS'22). It consists of two parts:
  • n_val: The number of valid data entries in the network.
  • rho_adv_max: The maximum fraction of power that the adversary can corrupt, which is directly a function of the network's delay Delta.

Crucially, G(n) incorporates Delta, thereby capturing the effect of decreasing security due to increasing delays.

  1. Security Metric P(n): The main theorem of the paper states that the probability of a Nakamoto-style blockchain being secure, P(n), is the sum of F(i, n) for all i from 0 up to G(n).

P(n) = Σ_{i=0}^{G(n)} F(i, n)

This function P(n) serves as the security metric, effectively combining both opposing forces: the likelihood of corruption (F) and the network's tolerance for corruption (G, which depends on Delta).

Characterizing Delta(n)

A critical step was to characterize Delta(n) (the expected maximum delay) as a function of the network scale n. Through theoretical analysis, the authors showed that Delta(n) can be approximated by a logarithmic function:

Delta(n) = A * log(n) + B

where A and B are constants that depend on various parameters of the specific blockchain deployment (e.g., block size, block rate, network topology, gossip protocol).

Large-Scale Simulations with SimBlock

To determine the constants A and B empirically and to evaluate P(n) in various settings, the authors utilized the SimBlock simulator. SimBlock is an open-source Java-based simulator designed for evaluating block propagation in real-world blockchain networks. Recognizing its scalability limitations for very large networks (originally capped at ~70,000 nodes), the authors implemented several significant modifications and extensions:

  1. Difficulty Parameter Accuracy: Bypassed issues with difficulty parameter accuracy by encoding only the relative block generation power of each node instead of absolute power, allowing for larger-scale simulations.
  2. Gossip Protocol Extensions: Extended the simulator to include the hybrid and direct push gossip protocols. They also revised the implementation of the compact block protocol to accurately consider transaction transmission time, which was previously overlooked.
  3. Network Layer Attacks: Incorporated network layer attacks by adding arbitrary delays to inter-node communication, simulating realistic adversarial conditions.
  4. Performance Optimizations: Optimized memory usage and the event timeline within the simulator to handle significantly larger network sizes and longer simulation durations.

These modifications allowed them to simulate networks far beyond SimBlock's original capabilities, enabling the empirical determination of A and B for different blockchain deployments.

Blockchain Deployments and Gossip Protocols Analyzed

The analysis compared the security of four common Nakamoto-style blockchain deployments, each employing distinct gossip protocols for inter-node communication and block propagation:

  1. Cardano: Uses a variant of the advertisement-based block propagation. A node receiving a block first advertises its existence to neighbors. Neighbors then explicitly request the block if they don't have it.
  2. Monero: Utilizes a variant of the direct push block propagation. A node receiving a new block directly forwards it to all its neighbors.
  3. Ethereum Classic (ETC): Deploys a hybrid push block propagation. A node checks if a neighbor is part of a "specific subset"; if so, it directly pushes the block. Otherwise, it uses the advertisement-based protocol.
  4. Bitcoin: Employs another variant of the advertisement-based propagation, but critically, it uses the compact block mode (BIP 152). This involves advertising a compact form of the block, allowing nodes to reconstruct it with fewer data transfers, significantly reducing bandwidth and propagation delay.

By analyzing these diverse protocols, the study could pinpoint how specific design choices impact network delay characteristics and, consequently, overall security at scale.

Demo / Proof of Concept

▶ Watch: Characterizing network delay (Delta) as function of scale (6:20)

The "Demo / Proof of Concept" section of this talk was represented by the extensive empirical evaluation conducted using the modified SimBlock simulator. The researchers performed a series of large-scale simulations to measure real-world delays and then used these measurements to parameterize and validate their theoretical security metric P(n).

First, the team empirically evaluated the maximum delay in networks of various sizes. For each network size, they conducted simulations of Nakamoto-style blockchain networks and determined the maximum delay by averaging over 100 blocks. Based on these measurements, linear regression was used to interpolate Delta as a function of the network scale n.

The results were visually presented, showing the delay Delta as a function of network scale n for the four chosen blockchain deployments. A key observation from this plot was the stark difference in delay increase: for instance, the delay for the Cardano deployment increased much more steeply than for the Bitcoin deployment. A table accompanying this plot presented the determined coefficients A and B for each deployment, allowing Delta(n) = A * log(n) + B to be fully characterized for each blockchain. For example, Bitcoin's A and B values resulted in a much flatter Delta(n) curve compared to Cardano's.

Next, the researchers evaluated their security metric P(n) by plugging the empirically derived Delta(n) into the theoretical formula. For the Cardano deployment, assuming P_star = 12.5% and an adversary leveraging network attacks to delay blocks by up to five block times, a critical observation emerged:

  • Security initially increased with network scale, as intuition would suggest.
  • However, a "turning point" was reached at approximately 20,000 nodes.
  • Beyond this point, security eventually degraded with increasing delays until it reached zero. This was a "very surprising" finding, indicating that adding nodes to networks of reasonable size can impair and even reduce their security.

Comparing P(n) across all four blockchain deployments further highlighted the impact of protocol design. The turning points for Cardano and Ethereum Classic were significantly smaller than expected, indicating their vulnerability at relatively modest scales. In contrast, the turning points for Bitcoin and Monero were "out of bounds" for the shown plot, suggesting that adding nodes to these networks might not impair security for much larger, more reasonable network sizes. This difference was attributed to the specific gossip protocol, block size, and block rate of each deployment.

Finally, the talk presented a crucial comparison between empirically measured real-world delays and the upper bound of tolerable delays derived from the security metric P(n).

  • Solid lines represented measured delays when inter-node block propagation was delayed by 600 seconds (one block time) and 3,000 seconds (five block times) due to state-of-the-art network attacks.
  • Dashed lines denoted the maximum network delays the system could tolerate while remaining secure, considering an adversary with P_star equal to 0.3 and 0.4.

The plot revealed a shocking reality: for an adversary delaying block propagation by 600 seconds, the measured delays exceeded the tolerable delays when P_star was larger than 0.3, meaning the network could no longer be considered secure. Similarly, for a 3,000-second delay and P_star = 0.4, the measured delays again surpassed the tolerable limits. These results "shockingly reveal that some networks are facing serious issues that are breaking the security guarantees when being attacked by state-of-the-art Network layer attacks." This empirical evidence directly demonstrated that the theoretical vulnerabilities identified by the model translate into concrete security failures under realistic attack scenarios.

Defensive Implications

▶ Watch: Large-scale simulation setup and Simlock modifications (7:00)

The findings from this research provide critical insights for blockchain developers, network operators, and security professionals aiming to build and maintain robust Nakamoto-style blockchains.

  1. Re-evaluate Network Scaling Strategies: The most significant implication is the necessity to abandon the simplistic assumption that "more nodes always equals better security." Defenders must understand that for many blockchain designs, there exists a "turning point" in network scale beyond which adding more nodes can actively reduce security. Scaling strategies should therefore be informed by a detailed analysis of Delta(n) and P(n) for their specific deployment.
  2. Prioritize Gossip Protocol Optimization: The choice and implementation of the gossip protocol are paramount. Protocols like Bitcoin's compact block relay (BIP 152) demonstrated superior robustness, significantly mitigating the increase in Delta with network scale. Developers should invest in optimizing block propagation mechanisms, potentially adopting or adapting highly efficient protocols to ensure scalability does not come at the cost of security.
  3. Harden Against Network Layer Attacks: The empirical results clearly show that state-of-the-art network layer attacks that delay block propagation (e.g., by 600 or 3000 seconds) can push measured delays beyond tolerable limits, thereby breaking security guarantees. Defenders must implement robust network-level defenses, including:
  • DoS/DDoS mitigation: To prevent attacks that flood the network and cause delays.
  • Peer-to-peer network monitoring: To detect and isolate malicious or slow nodes.
  • Network topology awareness: To optimize peer connections and minimize propagation paths.
  • Redundant connectivity: To ensure block propagation even if some paths are compromised.
  1. Continuous Security Monitoring and Re-evaluation: As blockchain networks evolve and grow, their Delta(n) characteristics and P(n) security metric should be continuously monitored and re-evaluated. Changes in block size, block rate, network topology, or the underlying peer-to-peer protocol can all shift the "turning point" and impact security. Regular simulations or real-world measurements are crucial.
  2. Understand P_star Thresholds: Defenders need to understand the individual node corruption success rate (P_star) that their network can tolerate at different scales. For networks like Cardano and Ethereum Classic, P_star values as low as 29% can lead to vulnerabilities at large scales (e.g., > 10^6 nodes). This highlights the need for strong node security (e.g., secure hardware, robust software, operator best practices) to keep P_star as low as possible.
  3. Consider Trade-offs in Decentralization: While decentralization is a core tenet, this research suggests there might be practical limits or trade-offs between the number of nodes and the overall security posture, especially if network infrastructure or protocol efficiency cannot keep pace. A larger network that is slow and vulnerable to delays might be less secure than a slightly smaller, more efficient, and resilient one.

Key Takeaways

  • Existing blockchain security models have a critical gap, failing to fully capture the increase in security gained from distributed power as a network grows, while overemphasizing the detrimental effect of increased network delays.
  • There exists a "turning point" in network scale for many Nakamoto-style blockchains: security initially improves with more nodes but eventually degrades significantly as network delays become dominant.
  • The choice of gossip protocol is a primary determinant of how network delay scales and profoundly impacts the network's overall security, with some protocols performing much better than others.
  • Cardano and Ethereum Classic deployments were shown to be vulnerable to adversaries capable of corrupting individual nodes with P_star > 29% when network sizes exceed 10^6 nodes, due to their less efficient block propagation.
  • Bitcoin's compact block relay (BIP 152) significantly enhances network robustness, allowing it to maintain security even with very large network sizes (e.g., 10^9 nodes) and higher individual node corruption rates (P_star > 47%).
  • Empirical measurements confirm that state-of-the-art network layer attacks, which delay block propagation by 1 to 5 block times, can cause real-world delays to exceed the maximum tolerable delays, thereby breaking the security guarantees of some blockchain networks.

About the Speaker(s)

The paper "Larger-scale Nakamoto-style Blockchains Don't Necessarily Offer Better Security" was a collaborative effort by researchers from Ruhr University Bochum in Germany and NEC Labs Europe. The presentation was delivered by Jannik Albrecht, a PhD student at Ruhr University Bochum. His work, and that of his co-authors — Sebastien Andreina, Frederik Armknecht, Ghassan Karame, Giorgia Marson, and Julian Willingmann — focuses on deeply understanding the fundamental security properties and scalability challenges of decentralized systems, particularly Nakamoto-style blockchains. Their research combines theoretical analysis with extensive empirical simulation to provide practical insights into the robustness of these critical technologies.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research directly challenges the fundamental, simplistic notion that more nodes inherently lead to better blockchain security. By introducing a novel security metric and empirically characterizing network delays, the authors expose a critical "turning point" where network expansion paradoxically degrades security. This is a must-see for anyone serious about designing or securing large-scale Nakamoto-style systems.

Heather Calloway (CISO) — STRONG ACCEPT

This research critically challenges the intuitive assumption that more nodes inherently increase blockchain security, revealing a 'turning point' where network expansion paradoxically weakens guarantees due to propagation delays. It provides essential, evidence-based guidance for architects and security leaders on optimizing protocol design and scaling strategies to mitigate significant institutional risk and redefine accountability.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024