Crypto Researcher Hasu Flags Attack That Could Bring 'Purge'-Style Mayhem to Bitcoin

Like the dystopia of the "Purge" movies, a newly uncovered potential attack on bitcoin would permit users to rob each other for a short period of time.

AccessTimeIconFeb 6, 2020 at 3:30 p.m. UTC
Updated Sep 13, 2021 at 12:15 p.m. UTC
10 Years of Decentralizing the Future
May 29-31, 2024 - Austin, TexasThe biggest and most established global event for everything crypto, blockchain and Web3.Register Now

Pseudonymous researcher Hasu has discovered a new twist on a well-known potential attack on the bitcoin network.

The researcher posted a description of the attack, which he named "Purge" after the B-movie franchise, to the bitcoin developer email list last week. It's a variation on the so-called sabotage attack, in which malicious miners try to wreak havoc on bitcoin for the sake of wreaking havoc, rather than for profit.

“Purge attacks probably don’t constitute a bigger risk than other known forms of sabotage attacks, but seem like an interesting spin," he wrote.

In the dystopia of the "Purge" films, the U.S. government legalizes all crime for one night every year to unleash a sort of national catharsis. Hasu said he chose the name "because the attacker doesn’t (primarily) steal money himself, he makes theft legal in the network for a short period of time."

In short, the attack opens the possibility that in very particular circumstances some users could spend their bitcoins more than once, something the unique technology behind bitcoin is supposed to prevent.

To be clear: The scenario is hypothetical, like many others bitcoin researchers have identified in their efforts to steel the network against real-world sabotage attempts. Anticipating the danger is a first step toward preventing or at least mitigating it.

Undermining trust

In order to execute a purge attack, a rogue miner would replace an already accepted block with an empty one, pushing transactions that were previously seen as final back into the "mempool," which is like a waitlist for transactions. Then, anyone who sent a transaction during that time can spend the same coin twice.

The new type of sabotage could be used to "undermine trust in bitcoin's assurances," such as the assurance that transactions are after a time "final," meaning irreversible. "Possible attackers could include nation-states hostile to bitcoin as well as terrorist organizations," Hasu added.

Further, Purge is different from other sabotage attacks because the users who are suddenly allowed to double-spend could get incentive to go along with the attack.

"Because Purge gives normal users a way to benefit from the attack, the attacker hopes that it will be harder to coordinate a response quickly because whoever benefited from the attack has an incentive to defend the attack chain," Hasu told CoinDesk.

But while Purge is a new idea, it’s not necessarily worse than other known attacks. Hasu also points to a couple of lines of defense: One, the risk to the attacker of losing block rewards, which are expensive to win and could decline in value if the attack shakes confidence in bitcoin; and two, the “strength of bitcoin’s pre-coordination.”

The full report (on bitcoin futures exchange Deribit's blog) dives into much more detail.


Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.

Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to to register and buy your pass now.