Compartir este artículo

Crypto Researcher Hasu Flags Attack That Could Bring 'Purge'-Style Mayhem to Bitcoin

Like the dystopia of the "Purge" movies, a newly uncovered potential attack on bitcoin would permit users to rob each other for a short period of time.

Actualizado 13 sept 2021, 12:15 p. .m.. Publicado 6 feb 2020, 3:30 p. .m.. Traducido por IA
Like the dystopian regime of the "Purge" movies, a newly uncovered potential attack on bitcoin would permit users to steal from each other for a short period of time. (Image: Shutterstock)
Like the dystopian regime of the "Purge" movies, a newly uncovered potential attack on bitcoin would permit users to steal from each other for a short period of time. (Image: Shutterstock)

Pseudonymous researcher Hasu has discovered a new twist on a well-known potential attack on the bitcoin network.

STORY CONTINUES BELOW
No te pierdas otra historia.Suscríbete al boletín de The Protocol hoy. Ver todos los boletines

The researcher posted a description of the attack, which he named "Purge" after the B-movie franchise, to the bitcoin developer email list last week. It's a variation on the so-called sabotage attack, in which malicious miners try to wreak havoc on bitcoin for the sake of wreaking havoc, rather than for profit.

“Purge attacks probably don’t constitute a bigger risk than other known forms of sabotage attacks, but seem like an interesting spin," he wrote.

In the dystopia of the "Purge" films, the U.S. government legalizes all crime for one night every year to unleash a sort of national catharsis. Hasu said he chose the name "because the attacker doesn’t (primarily) steal money himself, he makes theft legal in the network for a short period of time."

In short, the attack opens the possibility that in very particular circumstances some users could spend their bitcoins more than once, something the unique technology behind bitcoin is supposed to prevent.

To be clear: The scenario is hypothetical, like many others bitcoin researchers have identified in their efforts to steel the network against real-world sabotage attempts. Anticipating the danger is a first step toward preventing or at least mitigating it.

Undermining trust

In order to execute a purge attack, a rogue miner would replace an already accepted block with an empty one, pushing transactions that were previously seen as final back into the "mempool," which is like a waitlist for transactions. Then, anyone who sent a transaction during that time can spend the same coin twice.

The new type of sabotage could be used to "undermine trust in bitcoin's assurances," such as the assurance that transactions are after a time "final," meaning irreversible. "Possible attackers could include nation-states hostile to bitcoin as well as terrorist organizations," Hasu added.

Further, Purge is different from other sabotage attacks because the users who are suddenly allowed to double-spend could get incentive to go along with the attack.

"Because Purge gives normal users a way to benefit from the attack, the attacker hopes that it will be harder to coordinate a response quickly because whoever benefited from the attack has an incentive to defend the attack chain," Hasu told CoinDesk.

But while Purge is a new idea, it’s not necessarily worse than other known attacks. Hasu also points to a couple of lines of defense: One, the risk to the attacker of losing block rewards, which are expensive to win and could decline in value if the attack shakes confidence in bitcoin; and two, the “strength of bitcoin’s pre-coordination.”

The full report (on bitcoin futures exchange Deribit's blog) dives into much more detail.

Más para ti

Protocol Research: GoPlus Security

GP Basic Image

Lo que debes saber:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

Más para ti

New React bug that can drain all your tokens is impacting 'thousands of' websites

Hacker sitting in a room

Attackers are using the vulnerability to deploy malware and crypto-mining software, compromising server resources and potentially intercepting wallet interactions on crypto platforms.

Lo que debes saber:

  • A critical vulnerability in React Server Components, known as React2Shell, is being actively exploited, putting thousands of websites at risk, including crypto platforms.
  • The flaw, CVE-2025-55182, allows remote code execution without authentication and affects React versions 19.0 through 19.2.0.
  • Attackers are using the vulnerability to deploy malware and crypto-mining software, compromising server resources and potentially intercepting wallet interactions on crypto platforms.