This paper will discuss and evaluate the design features of Bitcoin in relation to the libertarian and metallist philosophies that have shaped the cryptocurrency. Bitcoin has failed to be perfectly decentralized or particularly anonymous. Furthermore, its hyperdeflationary design features have made Bitcoin a currency dependent on outside, more stable currencies (e.g., the U.S. dollar), which serve as units of account. Finally, despite the view of money taken by its creators, this supposedly stateless currency is far from apolitical in nature. Although its creators tend to espouse apolitical accounts of money, Bitcoin has been from the beginning a political project -- an evolving, distributed constitutional project, with many goals, visions, and factions. Furthermore, depending on the shape of these political goals, Bitcoin advocates may or may not have a vested interest in creating mechanisms to stabilize the currency and make it a viable unit of account. This paper was written for Christine Desan's seminar, "The Constitutional Law of Money," at Harvard Law School.
Virtual currencies are online payment systems that may function as real currencies but are not issued or backed by central governments. As demonstrated by recent events, virtual currencies present regulators with significant challenges. On May 23, 2013, the U.S. federal government brought an indictment against the operators of Liberty Reserve, a popular virtual currency, charging the operators with money laundering and operating an unlicensed money-transmitting business. The same month, the Government Accountability Office ("GAO") made public a report exploring the potential tax-compliance risks associated with virtual currencies and economies. Legislators have also taken particular interest in one type of virtual currency-Bitcoin. On August 13, 2013, the U.S. Senate Committee on Homeland Security announced plans to start an inquiry aimed at establishing a regulatory framework for Bitcoin. This short Essay describes the mechanisms by which "cryptocurrencies"-a subcategory of virtual currencies-could replace tax havens as the weapon-of-choice for tax-evaders. I argue that it is reasonable to expect this shift to occur in the foreseeable future due to the contemporary convergence of two unrelated, yet parallel, processes. The first process is the increasing popularity of cryptocurrencies, of which Bitcoin is the most widely recognized example. Unlike other virtual currencies that are associated with the existence of a virtual economy-usually in computer games-cryptocurrencies "function as a unique currency with [their] own free-floating exchange." Over the past three years, Bitcoin gradually gained the confidence of consumers, retailers, and service providers, and it is now effectively functioning as a currency in the real world. In fact, in August 2013, Bitcoin was officially recognized as a legal form of tender in Germany. Only two weeks earlier, a federal judge ruled that for purposes of U.S. securities regulation, Bitcoin is indeed "money."
Cryptocurrencies are digital alternatives to traditional governmentâissued paper monies. Given the current state of technology and skepticism regarding the future purchasing power of existing monies, why have cryptocurrencies failed to gain widespread acceptance? I offer an explanation based on network effects and switching costs. In order to articulate the problem that agents considering cryptocurrencies face, I employ a simple model developed by Dowd and Greenaway (1993) (Dowd, K., and D. Greenaway. âCurrency Competition, Network Externalities, and Switching Costs: Towards an Alternative View of Optimum Currency Areas.â The Economic Journal , 103(420), 1993, 1180â89). The model demonstrates that agents may fail to adopt an alternative currency when network effects and switching costs are present, even if all agents agree that the prevailing currency is inferior. The limited success of bitcoinâalmost certainly the most popular cryptocurrency to dateâserves to illustrate. After briefly surveying episodes of successful monetary transition, I conclude that cryptocurrencies like bitcoin are unlikely to generate widespread acceptance in the absence of either significant monetary instability or government support. ( JEL E40, E41, E42, E49)
Marcin Andrychowicz, Stefan Dziembowski, Daniel Malinowski, Ćukasz Mazurek
AbstractâBitcoin is a decentralized digital currency, intro-duced in 2008, that has recently gained noticeable popularity. Its main features are: (a) it lacks a central authority that controls the transactions, (b) the list of transactions is publicly available, and (c) its syntax allows more advanced transactions than simply transferring the money. The goal of this paper is to show how these properties of Bitcoin can be used in the area of secure multiparty computation protocols (MPCs). Firstly, we show that the Bitcoin system provides an attractive way to construct a version of âtimed commitmentsâ, where the committer has to reveal his secret within a certain time frame, or to pay a fine. This, in turn, can be used to obtain fairness in some multiparty protocols. Secondly, we introduce a concept of multiparty protocols that work âdirectly on Bitcoinâ. Recall that the standard definition of the MPCs guarantees only that the protocol âemulates the trusted third partyâ. Hence ensuring that the inputs are correct, and the outcome is respected is beyond the scope of the definition. Our observation is that the Bitcoin system can be used to go beyond the standard âemulation-basedâ definition, by constructing protocols that link their inputs and the outputs with the real Bitcoin transactions. As an instantiation of this idea we construct protocols for secure multiparty lotteries using the Bitcoin currency, without relying on a trusted authority (one of these protocols uses the Bitcoin-based timed commitments mentioned above). Our protocols guarantee fairness for the honest parties no matter how the loser behaves. For example: if one party interrupts the protocol then her money is transferred to the honest participants. Our protocols are practical (to demonstrate it we performed their transactions in the actual Bitcoin system), and can be used in real life as a replacement for the online gambling sites. We think that this paradigm can have also other applications. We discuss some of them. Keywordsâbitcoin; multiparty; lottery; I.
ï»żA bona fide currency functions as a medium of exchange, a store of value, and a unit of account, but bitcoin largely fails to satisfy these criteria. Bitcoin has achieved only scant consumer transaction volume, with an average well below one daily transaction for the few merchants who accept it. Its volatility is greatly higher than the volatilities of widely used currencies, imposing large short-term risk upon users. Bitcoinâs daily exchange rates exhibit virtually zero correlation with widely used currencies and with gold, making bitcoin useless for risk management and exceedingly difficult for its owners to hedge. Bitcoin prices of consumer goods require many decimal places with leading zeros, which is disconcerting to retail market participants. Bitcoin faces daily hacking and theft risks, lacks access to a banking system with deposit insurance, and it is not used to denominate consumer credit or loan contracts. Bitcoin appears to behave more like a speculative investment than a currency.
Arthur Gervais, Ghassan Karame, Vedran Äapkun, SrÄjan Äapkun
Bitcoin has achieved large-scale acceptance and popularity by promising its users a fully \ndecentralized and low-cost virtual currency system. However, recent incidents and observations \nare revealing the true limits of decentralization in the Bitcoin system. In this article, we \nshow that the vital operations and decisions that Bitcoin is currently undertaking are not \ndecentralized. More specifically, we show that a limited set of entities currently control the \nservices, decision making, mining, and the incident resolution processes in Bitcoin. We also \nshow that third-party entities can unilaterally decide to âdevalueâ any specific set of Bitcoin \naddresses pertaining to any entity participating in the system. Finally, we explore possible \navenues to enhance the decentralization in the Bitcoin system.
The Bitcoin digital currency depends for its correctness and stability on a combination of cryptography, distributed algorithms, and incentivedriven behavior. We examine Bitcoin as a consensus game and determine that it relies on separate consensus about the rules and about game state. An important aspect of Bitcoinâs design is the mining mechanism, in which participants expend resources on solving computational puzzles in order to collect rewards. This mechanism purportedly protects Bitcoin against certain technical problems such as inconsistencies in the systemâs distributed log data structure. We consider the economics of Bitcoin mining, and whether the Bitcoin protocol can survive attacks, assuming that participants behave according to their incentives. We show that there is a Nash equilibrium in which all players behave consistently with Bitcoinâs reference implementation, along with infinitely many equilibria in which they behave otherwise. We also show how a motivated adversary might be able to disrupt the Bitcoin system and âcrash â the currency. Finally, we argue that Bitcoin will require the emergence of governance structures, contrary to the commonly held view in the Bitcoin community that the currency is ungovernable. 1
Bitcoin is an electronic currency designed to use a public protocol that implements it in a totally decentralized manner, so as not to need the control of any central issuing organization that manages it. Though still in development, it has been proven to be a modern payment system referred to have been used in some procedures commonly associated to money laundering or trafficking of illegal substances of various kinds. Thus, in this article, we analyse those features which transform such a cryptocurrency in a useful tool to perform any kind of transactions far from the control of any kind of regulatory agency, as well as we pinpoint some of the fields in which their usage can derive in new illicit behaviours. Keywords-bitcoin; cryptoanarchism; cryptocurrency; fraud; speculation; virtual money.
Bitcoin is a decentralized payment system that relies on Proof-of-Work (PoW) to verify payments. Nowadays, Bitcoin is increasingly used in a number of fast payment scenarios, where the time between the exchange of currency and goods is short (in the order of few seconds). While the Bitcoin payment verification scheme is designed to prevent double-spending, our results show that the system requires tens of minutes to verify a transaction and is therefore inappropriate for fast payments. An example of this use of Bitcoin was recently reported in the media: Bitcoins were used as a form of \emph{fast} payment in a local fast-food restaurant. Until now, the security of fast Bitcoin payments has not been studied. In this paper, we analyze the security of using Bitcoin for fast payments. We show that, unless appropriate detection techniques are integrated in the current Bitcoin implementation, double-spending attacks on fast payments succeed with overwhelming probability and can be mounted at low cost. We further show that the measures recommended by Bitcoin developers for the use of Bitcoin in fast payments are not always effective in detecting double-spending; we show that if those recommendations are integrated in future Bitcoin implementations, double-spending attacks on Bitcoin will still be possible. Finally, we propose and implement a modification to the existing Bitcoin implementation that ensures the detection of double-spending attacks against fast payments.
What is the legal status of a âbitcoin,â a decentralized peer-to-peer digital currency? Is the use of bitcoins even legal? Should it be? The bitcoin cybercurrency thus poses a puzzle. Unlike centralized and publicly-created metallic or paper currencies, bitcoin is a privately-created, decentralized medium of exchange and thus is not backed by any national or transnational government or by any public or private bank. As such, the legal status of the bitcoin cybercurrency is murky and unclear at best. Despite this legal uncertainty, the demand for bitcoins on the Internet continues to grow. The authors will present a legal, normative, and game-theoretic analysis of the bitcoin cybercurrency. To provide a theoretical background to our legal and normative analysis, the first part of the paper will present an analytical model of the behavior of bitcoin users. In summary, the use of bitcoins can be modeled as a Prisonerâs Dilemma. That is, because of the limited supply of bitcoins and the rising demand of this cybercurrency, the temptation to defect by hoarding this currency -- rather than using bitcoins for the exchange of goods and services -- threatens the stability of the bitcoin cybercurrency as a whole. In the second part of the paper, the authors consider the legal status of bitcoins, discuss the policy and normative arguments for and against the legalization of bitcoins, and propose several possible legal frameworks for protecting the bitcoin cybercurrency and solving the bitcoin puzzle.
Abstract: There is no formal framework for describing the core structural concepts of Bitcoin or for attempting a correctness proof of the algorithm. This contribution presents several elements which may serve as building blocks. A distributed model for describing the states enclosed in a Bitcoin network is provided. Concepts for modeling the swarm behavior of Bitcoin are analyzed. 1
Digital currency,with the functions of transactions media,price evaluation,value saving and payment means,is an ideal resource exchange mode. Bitcoin is pure P2P digital cash and could meet the possible requirement of decentralization and contain the inflation of money. Based on this,the trust mechanism is introduced into the system so that nodes could build their reputation and thus help optimize the whole economic environment. So a protocol is proposed,which allows the nodes with more-than-needed money to provide trust amount and capital turnover for appliers and thus to help them build their trust evaluation.
In the standard definition of a commitment scheme, the sender commits to a message and immediately sends the commitment to the recipient interested in it. However the sender may not always know at the time of commitment who will become interested in it. Further, when the interested party does emerge, it could be critical to establish when the commitment was made. Employing a proof of work protocol at commitment time will later allow anyone to carbon date when the commitment was made, approximately, without trusting any external parties. We present CommitCoin, an instantiation of this approach that harnesses the existing computational power of the Bitcoin peer-to-peer network; a network used to mint and trade digital cash.
In 2009, a curious new virtual currency called Bitcoin made its first appearance on the Internet. While it remains a ânicheâ currency relative to other major denominations like the U.S. dollar, Bitcoin has experienced significant growth since its inception. The total number of Bitcoins in circulation is about 12.5 million, with a recent market price of about $500 each. Today, Bitcoinâs total market capitalization is about $6 billion, and in the past it has been as high as $13 billion. The average number of Bitcoin transactions per day has averaged over 60,000 since January 2014, reflecting between $20 million and $100 million worth of transactions per day. The numbers show that in the five years since its first appearance, Bitcoin has grown tremendously in popular knowledge and usage. Although it is clear that Bitcoin can be used to purchase goods and services, and can be given an explicit dollar value, questions remain about the economic and legal status of Bitcoin and other virtual currencies that have emerged in its wake. Members of the Bitcoin developer and user community believe âBitcoin is an innovative payment network and new kind of money.â Others, like the U.S. Internal Revenue Service, take the position that Bitcoin is a type of commodity or property. Whether Bitcoin is a new form of virtual money or simply an electronic commodity requires an investigation into what constitutes money, and an assessment of whether Bitcoin comfortably fits into the parameters of what we consider to be money. This paper finds that, at this stage in its development, Bitcoin is not money and more closely resembles a commodity or property. This paper begins by giving a brief overview of Bitcoin and how it operates. It then describes two major theories of money â the conventional and constitutional theories â that differ in their accounts of how money emerges within a society or political grouping. The paper assesses how well Bitcoin fits under each theory by assessing Bitcoinâs economic properties and implementation. It then turns to the impact of the Bitcoin on the two theories of money, finding it likely does not support the conventional creation story of money and instead lends credence to the constitutional theory.
A peer-to-peer crypto-currency design derived from Satoshi Nakamotoâs Bitcoin. Proof-of-stake replaces proof-of-work to provide most of the network security. Under this hybrid design proof-of-work mainly provides initial minting and is largely non-essential in the long run. Security level of the network is not dependent on energy consumption in the long term thus providing an energyefficient and more cost-competitive peer-to-peer crypto-currency. Proof-of-stake is based on coin age and generated by each node via a hashing scheme bearing similarity to Bitcoinâs but over limited search space. Block chain history and transaction settlement are further protected by a centrally broadcasted checkpoint mechanism.
In 1601, Elizabeth I and her government devalued the Irish coin from nine ounces fine to three ounces fine of silver in order to finance the high cost of the Nine Years War in Ireland. 1 This unilateral move by the English government, combined with the failure to remove the old sterling from circulation, caused catastrophic problems throughout Ireland. 2 In addition to rapid inflation in common foodstuffs, the people in Ireland would only accept the new coin at its reduced intrinsic value rather than face value. 3 Further, merchants refused to accept the devalued coin in commercial transactions leading to a shortage of vital goods from England. 4
Bitcoin is a decentralized payment system that is basedonProof-of-Work. Bitcoiniscurrentlygaining popularity as a digital currency; several businesses are starting to accept Bitcoin transactions. An examplecaseofthegrowinguseofBitcoinwasrecently reported in the media; here, Bitcoins were used as a form of fast payment in a local fast-food restaurant. In this paper, we analyze the security of using Bitcoin for fast payments, where the time between the exchange of currency and goods is short (i.e., in the order of few seconds). We focus on doublespending attacks on fast payments and demonstrate that these attacks can be mounted at low cost on currently deployed versions of Bitcoin. We further showthatthemeasuresrecommendedbyBitcoindevelopersfortheuseofBitcoininfasttransactionsare not always effective in resisting double-spending; we show that if those recommendations are integrated in future Bitcoin implementations, double-spending attacks on Bitcoin will still be possible. Finally, we leverage on our findings and propose a lightweight countermeasurethatenablesthedetectionofdoublespending attacks in fast transactions. 1
Simon Barber, Xavier Boyen, Elaine Shi, Ersin Uzun
Abstract. Bitcoin is a distributed digital currency which has attracted a substan-tial number of users. We perform an in-depth investigation to understand what made Bitcoin so successful, while decades of research on cryptographic e-cash has not lead to a large-scale deployment. We ask also how Bitcoin could become a good candidate for a long-lived stable currency. In doing so, we identify several issues and attacks of Bitcoin, and propose suitable techniques to address them. 1
Abstract. Bitcoin is quickly emerging as a popular digital payment system. However, in spite of its reliance on pseudonyms, Bitcoin raises a number of privacy concerns due to the fact that all of the transactions that take place are publicly announced in the system. In this paper, we investigate the privacy guarantees of Bitcoin in the setting where Bitcoin is used as a primary currency for the daily transactions of individuals. More specifically, we evaluate the privacy that is provided by Bitcoin (i) by analyzing the genuine Bitcoin system and (ii) through a simulator that faithfully mimics the operation of Bitcoin in the context where Bitcoin is used for all transactions within a university. In this setting, our results show that the profiles of almost 40 % of the users can be, to a large extent, recovered even when users adopt privacy measures recommended by Bitcoin. To the best of our knowledge, this is the first work that comprehensively analyzes, and evaluates the privacy implications of Bitcoin. As a by-product, we have designed and implemented the first simulator of Bitcoin; our simulator can be used to model the interaction between Bitcoin users in generic settings. 1
Abstract. The Bitcoin scheme is a rare example of a large scale global payment system in which all the transactions are publicly accessible (but in an anonymous way). We downloaded the full history of this scheme, and analyzed many statistical properties of its associated transaction graph. In this paper we answer for the first time a variety of interesting questions about the typical behavior of users, how they acquire and how they spend their bitcoins, the balance of bitcoins they keep in their accounts, and how they move bitcoins between their various accounts in order to better protect their privacy. In addition, we isolated all the large transactions in the system, and discovered that almost all of them are closely related to a single large transaction that took place in November 2010, even though the associated users apparently tried to hide this fact with many strange looking long chains and fork-merge structures in the transaction graph.
Bitcoin is a digital, decentralized, partially anonymous currency, not backed by any government or other legal entity, and not redeemable for gold or other commodity. It relies on peer-to-peer networking and cryptography to maintain its integrity. Compared to most currencies or online payment services, such as PayPal, bitcoins are highly liquid, have low transaction costs, and can be used to make micropayments. This new currency could also hold the key to allowing organizations such as Wikileaks, hated by governments, to receive donations and conduct business anonymously. Although the Bitcoin economy is flourishing, Bitcoin users are anxious about Bitcoin's legal status. This Article examines a few relevant legal issues, such as the recent conviction of the Liberty Dollar creator, the Stamp Payments Act, and the Federal Securities Acts.
Moshe Babaioff, Shahar Dobzinski, Sigal Oren, Aviv Zohar
Many large decentralized systems rely on information propagation to ensure their proper function. We examine a common scenario in which only participants that are aware of the information can compete for some reward, and thus informed participants have an incentive not to propagate information to others. One recent example in which such tension arises is the 2009 DARPA Network Challenge (finding red balloons). We focus on another prominent example: Bitcoin, a decentralized electronic currency system. Bitcoin represents a radical new approach to monetary systems. It has been getting a large amount of public attention over the last year, both in policy discussions and in the popular press. Its cryptographic fundamentals have largely held up even as its usage has become increasingly widespread. We find, however, that it exhibits a fundamental problem of a different nature, based on how its incentives are structured. We propose a modification to the protocol that can eliminate this problem. Bitcoin relies on a peer-to-peer network to track transactions that are performed with the currency. For this purpose, every transaction a node learns about should be transmitted to its neighbors in the network. The current implemented protocol provides an incentive to nodes to not broadcast transactions they are aware of. Our solution is to augment the protocol with a scheme that rewards information propagation. Since clones are easy to create in the Bitcoin system, an important feature of our scheme is Sybil-proofness. We show that our proposed scheme succeeds in setting the correct incentives, that it is Sybil-proof, and that it requires only a small payment overhead, all this is achieved with iterated elimination of dominated strategies. We complement this result by showing that there are no reward schemes in which information propagation and no self-cloning is a dominant strategy.
Harry Kalodner, Miles Carlsten, Paul Ellenbogen, Joseph Bonneau · 5 authors
Secure decentralized namespaces have recently become possible due to cryptocurrency technology. They enable a censorship-resistant domainname system outside the control of any single entity, among other applications. Namecoin, a fork of Bitcoin, is the most prominent example. We initiate the study of decentralized namespaces and the market for names in such systems. Our extensive empirical analysis of Namecoin reveals a system in disrepair. Indeed, our methodology for detecting âsquattedâ and otherwise inactive domains reveals that among Namecoinâs roughly 120,000 registered domain names, a mere 28 are not squatted and have nontrivial content. Further, we develop techniques for detecting transfers of domains in the Namecoin block chain and provide evidence that the market for domains is thin-tononexistent. We argue that the state of the art in mechanism design for decentralized namespace markets is lacking. We propose a model of utility of different names to different participants, and articulate desiderata of a decentralized namespace in terms of this utility function. We use this model to explore the design space of mechanisms and analyze the trade-offs.
In the standard definition of a commitment scheme, the sender commits to a message and immediately sends the commitment to the recipient interested in it. However the sender may not always know at the time of commitment who will become interested in it. Further, when the interested party does emerge, it could be critical to establish when the commitment was made. Employing a proof of work protocol at commitment time will later allow anyone to carbon date when the commitment was made, approximately, without trusting any external parties. We present CommitCoin, an instantiation of this approach that harnesses the existing computational power of the Bitcoin peer-to-peer network; a network used to mint and trade digital cash.