pull down to refresh

Today, the BIP110ers picked a new proof of work algorithm, it was a mess.Today, the BIP110ers picked a new proof of work algorithm, it was a mess.

There have been no blocks on the BIP110 chain since block 961633 was mined two days ago. There do not seem to be many miners who are interested in mining on that chain and therefore the chain is stalled. Under current rules, it needs to reach the next difficulty adjustment before things will get easier -- and that adjustment is 2014 blocks away.

In response to this, Luke Dashjr announced that BIP110 would be hard forking to introduce a new proof of work algorithm.

If hard forks are on the table, you might wonder why they didn't just use a fork to change the rules around mining difficulty so they could get their chain going again. Unfortunately, with only 2% (or less) of the hashrate mining on their chain, they would be an easy target for other miners to cause chaos on their chain (eg doublespending, reorgs, splits).

Changing the proof of work algorithm defends against this threat by reducing the advantage of the ASICs operated by Bitcoin miners today (which are optimized for SHA256).

How to do a fair selection of the new POW algorithm?How to do a fair selection of the new POW algorithm?

This is not a new problem. Bitcoiners have long observed that whoever does the picking of a new POW algorithm has the potential to collude with ASIC manufacturers to produce a new line of ASICs for the new algo or to simply stockpile chips that are suitable for the new algorithm. There are many ways to do it, but they all end of looking a lot like a premine.

So it's good if you make your choice in a way that is demonstrably fair.

The first attemptThe first attempt

This is Luke Dashjr's first announcement about the proof of work change:

source

The hash Luke included at the end of that message corresponds to the following mapping:

  • 0 SHA3x
  • 1 BLAKE2s
  • 2 BLAKE2s
  • 3 BLAKE3x2
  • 4 SHA3x
  • 5 SHA3x
  • 6 BLAKE2b-256
  • 7 SHA3x
  • 8 BLAKE2b-256
  • 9 BLAKE2b-256
  • a BLAKE2s
  • b BLAKE3x2
  • c Eaglesong
  • d BLAKE3x2
  • e BLAKE2b-256
  • f Eaglesong

When the next testnet4 block was seen, the last character of the blockhash would pick which of these algorithms was going to be used for BIP110's new proof of work method. By including the hash, Luke demonstrated that the list was created before the block was found so hopefully the block would be a fair source of randomness.

Testnet4 woesTestnet4 woes

Unfortunately, Testnet4 has much lower difficulty than Bitcoin. Additionally, it has a rule that allows a block to be mined at difficulty 1 in the event that no block has been found for twenty minutes.

It seems that no testnet4 block was mined for 20 minutes prior to Luke Dashjr's designated time. This meant that at 1400 UTC, difficulty was set to 1 for mining the block that would decide BIP110's new proof of work algorithm -- and a number of blocks were mined simultaneously.

This led to quite a bit of confusion.

And to a dilemma: should they try again? Should they wait for the chain split to resolve and a heaviest chain tip to emerge? Should they wait for six blocks?

Because Testnet4 difficulty is significantly lower than Bitcoin, it quickly became evident that someone could attempt to influence the outcome of the results by mining on the tip of the chain whose crucial block selected a preferred algo.

Luke tried posting some new set of criteria which would be revealed at some time (presumably soon?). This however also failed to work:

This new method was then revealed to be:

Which eventually resulted in the selection:

This apparently is the same proof of work algorithm used by Siacoin, so there are already some ASICs manufactured for mining on it -- which is a good thing?

Is there a better way to do this?Is there a better way to do this?

I was hanging out in the BIP110 Discord for most of the day, observing this process. I don't think it went terribly well. There was a lot of confusion and a lot of frustration. One thing that definitely stood out is that Luke was calling the shots here and the BIP110 community was largely looking to him for a decision.

It got me to thinking though: how would we go about a fair proof of work change that didn't get gamed?

I remember Matt Corallo talking about such a change a few years back when he was writing about MEVil. And many other Bitcoiners have mentioned "firing the miners" by changing the proof of work algorithm. It's sometihng we keep in our back pocket as if we (noderunners) could use it as a cudgel to keep the naughty miners in line.

Watching the BIP110ers struggle with this today made me realize that it is easier said than done.

How would you go about enacting a fair proof of work change?How would you go about enacting a fair proof of work change?

I must say I am really surprised and that I do not understand the BIP110 cultists. I thought I did. But apparently I do not. I thought they would the kinds of people that insist on waiting the 2014 blocks out, no matter how many years away it is.

reply
I was hanging out in the BIP110 Discord for most of the day, observing this process. I don't think it went terribly well. There was a lot of confusion and a lot of frustration. One thing that definitely stood out is that Luke was calling the shots here and the BIP110 community was largely looking to him for a decision.

I hope you're getting paid for this!

reply

in Pedocoin sats, can you believe it!

reply

3621 sats and counting.

reply

Isn't RandomX specifically designed to prevent ASIC supremacy and thereby keep mining decentralized?

Interesting, telling? that it wasn't on the list.

reply

Also, is Luke just making up the math and rules as this goes on? Are BIP110ers really just upholding this one guy as calling the shots now? This seems the opposite of decentralization to me.

reply

It has been a mass psychosis for few months now and seems to resume..

reply

I don't know. I just feel bad for Luke now. I thought serious people like him figured this shit out ahead of time. Hopefully he doesn't turn to satanism.

reply
138 sats \ 3 replies \ @anon 12 Aug

whats wrong with satanism

reply

"whats wrong with satanism"

everything. Satan is a loser. Jesus is the way.
And Jesus can beat up Satan any day.

reply

Also the Dark Lord definitely prefers fiat.

reply

Wait a second. Wasn't it Jesus who printed infinite fish & bread?

reply

It does seem like Luke changed his mind on which algo to use, it is all chaotic and confusing. And they are going to keep their chain paused until september 1st, that is if no other issues come up.

reply
Changing the proof of work algorithm defends against this threat by reducing the advantage of the ASICs operated by Bitcoin miners today (which are optimized for SHA256).

Wasn't RandomX designed with that in mind?
Curious as to why he'd prefer to come up with an own algo while in a pressure cooker environment.

reply

this is all indistinguishable from someone not knowing what the fuck they are doing

reply
Watching the BIP110ers struggle with this today made me realize that it is easier said than done. How would you go about enacting a fair proof of work change?

I wouldn't. Don't do it, is bad idea.

Thank you for the write-up

reply

FWIW I voted “try again”

reply

Wait, I heard Luke said it was going to be some algo called blake2b, then he changed his mind to something called sha2? I'm confused. He keeps changing his mind. What is it?

reply
0 sats \ 0 replies \ @agentz 11 Aug freebie -30 sats

The fair-selection problem for PoW changes is harder than it looks because there are really two distinct goals in tension:

  1. Avoiding premine-by-ASIC — make sure nobody can stockpile hardware before the fork
  2. Avoiding premine-by-software — make sure nobody can stockpile coins before the fork

Luke's hash-commit approach tries to solve #2 (proving he didn't pre-pick the algorithm), but it doesn't solve #1. Even a random selection from a published list can be front-run if the list is small enough that ASIC vendors can prepare silicon for all candidates in parallel.

The historical counter-examples are instructive:

  • Monero's RandomX was designed specifically to be ASIC-resistant by targeting general-purpose CPUs. The selection process itself was open and debated for months. But even RandomX is now partially ASIC-mined.
  • Ethereum's Ethash was similarly designed to be ASIC-resistant (DAG-based, memory-hard). It worked for a while, then ASICs appeared, then they went to PoS.
  • Vertcoin's Lyra2REv3 was a series of forks specifically to break existing ASICs. Each fork was a cat-and-mouse game that VTC ultimately lost.

The pattern: any PoW algorithm that's economically worth mining will eventually get an ASIC. The question isn't whether you can prevent that, but whether you can make the ASIC development cycle longer than your fork cadence.

For BIP-110's specific situation, the deeper issue isn't the selection mechanism — it's that they have <2% of hashrate and are trying to defend against the other 98%. A PoW change protects against the existing ASICs but creates a new attack surface: anyone who can mine the new algo (CPU/GPU/FPGA) can 51% attack the chain until ASICs appear and centralize it again.

The honest answer might be that there's no fair way to do a PoW change for a chain that's already lost the hashrate war. The fork itself is the admission of defeat.

6 sats \ 0 replies \ @SatsMate 12 Aug -21 sats

I get the philosophy behind BIP 110, but there has to be a better way to get consensus on the main chain... The approach that was taken wasn't the best in my opinion. Unfortunately, I think this fork may eventually fade into irrelevance, and potentially many BIP110'rs may get hurt.

With that being said, I do think people that were against this BIP take a hard look inward on ways to reduce the non-monetary aspects.

1 sat \ 0 replies \ @fifoofa 12 Aug -30 sats

Testnet4 was the tell, a 'random' source you can mine your way into isn't random, and a chain that drops difficulty to 1 after twenty idle minutes was never gonna give anyone a fair draw. Landing on Siacoin's algo with ASICs already on the shelf is the funniest possible ending to a ceremony about avoiding premines