A malicious cryptominer managed to carry out a “double-spend” attack on the Bitcoin Gold (BTG) network last week, something that BTG’s communications director had predicted and reported in a post on the currency’s official forum. The attack was carried out against a cryptocurrency exchange on May 18.
What does double-spend mean?
Double-spend is a flaw that exists in decentralized cryptocurrencies like BTG, which allows an existing amount to be used more than once. This is possible because a virtual token can be copied or forged. In the case of cryptocurrencies, hypothetically speaking, a malicious miner could reverse a transaction if they held more than 50% of the network's total hashing power.
This is what an unknown miner did, as he managed to accumulate 51% of the total hashing power of the BTG network, which gave him temporary control of the blockchain.
After taking control of the blockchain, the miner began transferring large amounts of BTG to an exchange, while also trying to send the same amount of coins to his own wallet. Under normal circumstances, the blockchain would only “pass” the first transaction, i.e. the one intended for the exchange, but the attacker was able to cancel part of the transaction as he had 51% control of the network, fooling the exchange. Essentially, the exchange accepted a large amount and credited it to the attacker’s account. Immediately afterwards, the attacker canceled the transaction, while the already credited amount remained in his account.
One of the addresses involved in the attack has received approximately 388 thousand BTG.
The last attack took place on May 18, but theoretically it could be repeated if someone still has access to such a large percentage of the total network.
