The Truth About Bitcoin Security: Beyond Hash Power, Law is the Bottom Line

marsbitXuất bản vào 2026-03-20Cập nhật gần nhất vào 2026-03-20

Tóm tắt

The article "The Truth About Bitcoin Security: Beyond Hash Power, Law is the Bottom Line" by Craig Wright challenges the common narrative that Bitcoin operates outside legal frameworks. It argues that the standard economic model, which assumes anonymous miners and a lawless environment, is outdated and inaccurate for large-scale transactions. Bitcoin mining is now dominated by industrialized, identifiable entities—large, publicly-listed companies and regulated mining pools—not anonymous actors. For small transactions (e.g., under a few million dollars), pure protocol security (proof-of-work) suffices, as legal action is economically unfeasible. However, for large transactions, legal and organizational mechanisms become critical. A double-spend attack by an identifiable mining pool would trigger legal consequences, including criminal charges, asset seizures, and reputational damage, making such attacks economically irrational. The mining industry’s structure—reliant on specialized ASICs, long-term capital investments, and relationships with regulated entities—creates inherent disincentives for attacks. Mining pools would face capital destruction, contributor defection, and legal sanctions if they attempted fraud. Thus, Bitcoin’s security is not solely based on computational cost but also on legal accountability and economic deterrence. The conclusion is that Bitcoin’s security relies on a dual mechanism: protocol-level security for small transactions and legal-institutiona...

​Written by: Craig Wright

Compiled by: Luffy, Foresight News

There is a standard narrative about Bitcoin and the law: Bitcoin was designed to operate outside of governments, replacing institutional trust with mathematical trust. It is permissionless, anyone can participate, and there is no central authority in control. The system relies on the cost of attack itself for security. The law is optional, external, something Bitcoin was meant to circumvent.

This narrative is wrong, yet not entirely false; it contains some truth. But as a description of how Bitcoin actually operates in real-world, high-value transactions, it is a fairy tale. And it is this fairy tale that distorts the understanding of blockchain security among economists, regulators, and even the crypto industry itself.

The Economic Version

The most rigorous version of this narrative comes from economics, not cypherpunk forums. Its core argument is concise: in a permissionless system without the rule of law, the only thing preventing a double-spend attack is the cost of amassing enough hash power to surpass the honest chain. Security is a matter of cost: the network must continuously invest enough resources to make attacks unprofitable. If the value that can be stolen exceeds the attack cost, the system is insecure.

This is a valid conclusion; its math is correct under the given assumptions. But it leads to an uncomfortable corollary: securing large-value transactions on a proof-of-work blockchain requires massive, ongoing resource consumption proportional to the value at risk. If you want to settle a billion-dollar transaction, the network must consume enough electricity and hardware to make a billion-dollar attack unprofitable. This is costly, seemingly wasteful, and appears to be a fundamental economic limit.

But note this crucial premise: *in the absence of the rule of law*. The entire conclusion rests on an assumption: the attacker operates in a legal vacuum, anonymous, untraceable, and faces no consequences beyond the direct cost of the attack itself. This is not an insignificant simplification; it is the core assumption. And in the real world, for all economically significant Bitcoin transactions, this assumption does not hold true.

Who Mines Bitcoin

The story of anonymous miners in basements ended years ago. Bitcoin mining is an industrial-scale activity, organized through mining pools that coordinate block creation, capture block rewards, and distribute earnings to participants providing hash power according to contractual rules.

As of March 2026, the top five mining pools control over 70% of Bitcoin's hash rate. The top two pools, Foundry USA and AntPool, together hold nearly half the share. They are not secret, anonymous entities: Foundry USA is a subsidiary of Digital Currency Group; MARA Pool is operated by Nasdaq-listed MARA Holdings, whose latest annual report discloses ownership of 400,000 mining machines, 53 EH/s of hash rate, and Bitcoin reserves worth over $4 billion. These are named companies with addresses, stock tickers, auditors, banking relationships, and legal counsel.

The coordination layer of Bitcoin mining (the entities actually responsible for creating blocks and distributing rewards) is highly concentrated in a few jurisdictions. Pools associated with the US account for about 42% of the hash rate; those associated with China about 41%; Singapore, Japan, the Czech Republic, and Slovenia account for most of the remainder. Pools that cannot be identified via Coinbase tags, corporate filings, or public operators represent less than 2% of the hash rate.

This is not a picture of operating outside the law, but an oligopolistic industry: a few identifiable entities operating within reach of the law. When economists model Bitcoin attackers as anonymous, legally unreachable agents, they are describing not the real industry, but a fantasy the industry itself abandoned a decade ago.

What a Real Attack Looks Like

A double-spend attack on Bitcoin is not abstract. The process is: an attacker sends Bitcoin to a counterparty (e.g., to an exchange for dollars), while secretly mining an alternative chain that does not contain that transaction. If the attacker's secret chain becomes longer than the public chain, it replaces it, and the original transaction vanishes. The attacker gets the dollars and keeps the Bitcoin.

For such an attack to be significant, the attacker needs to control a majority of the hash rate for an extended period. In today's network, that means mastering over 400 EH/s. An individual cannot do this. The only feasible attack path is through the pool layer: either a single large pool deviates from honest mining, or multiple pools collude.

Now ask: what happens to that pool after the attack?

The attacker (a named public company or well-known pool brand) has just defrauded an exchange. The double-spend victim knows it was cheated; the blockchain record will show which pool built the attack chain (the Coinbase tag clearly identifies it). The defrauded exchange has legal counsel, insurance, and regulatory relationships, and the pool itself relies on these exchanges to convert mining revenue into fiat currency.

The attacker is not anonymous, the victim is not helpless, and the system connecting them is not outside the law.

The Law Enforcement Participation Constraint

The standard economic narrative is only half right. For small transactions—a $5 coffee, a $20 online purchase—no one will sue; legal costs exceed the loss. Hiring a lawyer costs more than the coffee. In this range, the law is indeed irrelevant, protocol security is everything, and the pure economic model applies.

But the irrelevance of law is inversely proportional to the transaction amount. A $5 million double-spend against an identifiable pool, involving asset freezes and exchange balance seizures, is a different matter entirely: this is wire fraud, computer fraud, a case prosecutors would take, insurers would pursue, and exchanges would cooperate with.

The real question is not whether laws against double-spending exist—they do. It's whether anyone is willing to invoke them. For small amounts, no; for large amounts, yes. There is a threshold, which can be called the law enforcement participation constraint: below this line, legal costs exceed the expected recovery; above it, legal action becomes worthwhile.

Recent enforcement actions in the crypto industry roughly indicate this threshold: Binance paid $4.3 billion to settle with the DOJ, FinCEN, and OFAC; BitMEX settled for $100 million.

These were compliance violations, not double-spend attacks. A deliberate double-spend would trigger not only civil liability but also criminal charges leading to prison time and asset forfeiture.

The conclusion is straightforward: the "no law" model applies to small transactions; it does not apply to large ones. The dividing line is not at the billion-dollar level but in the few million dollar range, depending on the jurisdiction, the victim institution's capabilities, and the attacker's identifiability. For pool-led attacks, identifiability is close to 100%.

Why Coordinated Attacks Fail

Even ignoring the law, pool attacks have structural weaknesses the standard model overlooks: pools rely on others' machines.

The pool operator coordinates block creation, but much of the actual hash power comes from external contributors: companies and individuals who connect their machines to the pool for a share of the rewards. These contributors can leave at any time; they join the pool to make money. If the pool's earnings decline, they move to a competitor.

A covert double-spend attack degrades earnings quality: the pool diverts hash power from honest mining to a secret chain, earning nothing if it fails. Contributors see lower, more volatile earnings and more invalid blocks. They don't need to know an attack is happening; they just see this pool performing worse than others and leave.

If the attack is detected or suspected, a further exodus occurs. Remaining contributors face risks associated with fraud: hardware could be flagged, exchange accounts scrutinized, hosting contracts affected. For companies with hundreds of millions in dedicated mining hardware, the rational choice upon a pool's public involvement in an attack is to leave immediately and distance themselves.

Another often-overlooked point: if the attack fails (the honest chain remains longer), the attacker loses all investment in building the secret chain. Honest miners need do nothing special; they just keep mining. The Nakamoto protocol's longest-chain rule automatically applies: if honest hash power exceeds attack hash power, the attack chain is orphaned. The protocol itself is a rejection mechanism. Honest miners aren't联盟ed; they aren't defending; they are just doing their normal work. The attacker, conversely, must act abnormally and sustain it, all while their coalition bleeds participants.

The result: an attacking pool's hash power is not fixed but continuously erodes during the attack. Simple simulations show: a pool starting with 31% of the network's hash power could lose the vast majority of its external contributed hash power within hours if the earnings distortion is observable, eventually being left with only its own hash power. For most pools, this is only a small fraction of their total stated power. An attack that seems nominally feasible becomes infeasible as contributors flee.

The Capital Problem

The standard model completely ignores a deeper issue: capital specificity.

Bitcoin mining hardware, ASICs, are not general-purpose equipment. A Bitcoin ASIC does one thing: compute SHA-256. It cannot mine Ethereum, cannot be a web server, cannot run machine learning. Once excluded from profitable Bitcoin mining, the hardware is worthless—just scrap metal with a power cord.

Large pool operators own billions of dollars in ASICs, hosting contracts, power agreements, and Bitcoin reserves. MARA Holdings alone discloses over $5 billion in combined ASIC miners and Bitcoin assets. Foundry USA aggregates the hash power of dozens of companies, each with significant capital exposure. A successful double-spend might yield tens of millions, but the capital risk from being identified, sanctioned, and excluded is measured in billions.

This is no longer a flow cost problem; it's a stock cost problem. The attacker risks not days of mining revenue, but the entire productive value of irreversible capital with no alternative use. This fundamentally changes the economics.

In the standard model, security requires ongoing investment proportional to the value at risk; in reality, for identifiable, capital-heavy pool operators, security is backed by the threat of permanent capital destruction.

Ironically, the original economic critique itself acknowledges that stock cost deterrence, if it existed, would be extremely powerful. It just argued proof-of-work lacks this deterrence because attack hash power can be rented, deployed, and discarded. This was roughly true in 2012, but it is absolutely not true in 2026. Mining is a heavy-capital industry with fixed infrastructure, long-term power contracts, and hardware that cannot be repurposed. Stock costs are real; the economic models just haven't caught up.

Two Mechanisms, One System

What we get is not a refutation of the economic model, but a localization of its application. Bitcoin does not have one security mechanism, but two operating simultaneously:

  • For small transactions: Pure protocol security is effective. Individual transactions are too small to warrant legal action. The system relies on the cost of assembling attack hash power for security. This mechanism works, fits the standard model description, and supports high throughput. Millions of small payments can run entirely on the protocol layer, with very low per-transaction security cost.
  • For large transactions: Legal + organizational mechanisms take over. The attacker's payoff is no longer determined solely by protocol costs but is significantly reduced by legal sanctions, exchange freezes, liquidation friction, reputational ruin, capital impairment, and the self-destruction of the attack coalition as contributors flee. Under this mechanism, the pure flow cost model overestimates the attack payoff because it ignores all the consequences the identifiable attacker faces after the on-chain action concludes.

The two mechanisms are not in conflict but complementary: the protocol layer handles volume; the legal layer handles value. Combined, they create a security environment far more robust than any single mechanism could be.

The Real Revelation

The deeper conclusion is not about Bitcoin specifically, but about how we view technology and institutions.

The cypherpunk narrative frames law and protocol as substitutes—choose one, and Bitcoin's point is to choose protocol. The economic critique accepted this framework and then questioned whether the protocol alone could suffice. Both are trapped in the same false dichotomy.

In reality, protocol and law are complements:

  • The protocol provides the base layer: transaction ordering, immutability, censorship resistance, using cost to deter casual attacks.
  • The law provides the upper layer: identity, accountability, sanctions, recovery, using severe penalties to deter heavyweight attackers.

Neither layer alone is sufficient; together they cover the full spectrum.

This should not be surprising. No valuable economic system in history operates entirely outside a legal framework. Banking, securities, insurance, telecommunications, even the internet itself—once proclaimed to be beyond government—do not. The question was never *if* law would come to Bitcoin, but when and through which channels. The answer is: law is already deeply embedded, through the industrial structure of mining itself.

Miners did not need to be forced into compliance by regulation. They moved towards a legally identifiable state driven by the basic economic logic of pooling, specialization, and scale. The very forces that made mining efficient (pooling for risk-sharing, ASIC capital investment, exchange relationships for liquidation) are the same forces that made mining legally identifiable.

Bitcoin's security does not depend on operating outside the law, but on being embedded within it. The protocol handles small matters; the law handles large ones. The industrial structure of mining is the bridge connecting the two. This structure was not imposed by regulators; it evolved naturally from the economics of mining itself. This is the most fundamental misjudgment in the standard economic critique of Bitcoin security.

Câu hỏi Liên quan

QAccording to the article, what is the fundamental flaw in the standard economic narrative about Bitcoin security?

AThe fundamental flaw is that the standard economic model assumes attackers are anonymous and operate in a legal vacuum, which is not true for economically significant Bitcoin transactions. In reality, the mining industry is highly concentrated among identifiable, legally reachable entities in regulated jurisdictions.

QWhat is the 'enforcement participation constraint' mentioned in the article?

AThe 'enforcement participation constraint' is a threshold value. Below this line, the cost of legal action exceeds the expected recovery amount, so the law is irrelevant. Above this line, legal action becomes worthwhile to pursue. For large-value transactions, legal mechanisms are activated.

QWhy would a mining pool attempting a double-spend attack likely see its hash power decrease?

AExternal contributors (hash power providers) join a pool to earn stable rewards. An attack would lead to lower, more volatile, or invalid block rewards. Contributors, noticing the poor performance, would rationally leave for a more profitable pool. If the attack is detected, contributors would also flee to avoid association with fraud and potential legal or reputational risks.

QHow does the article describe the relationship between protocol and law in securing Bitcoin?

AThe article describes protocol and law not as substitutes but as complementary mechanisms. The protocol provides the base layer security for small-value, high-volume transactions. The law provides an upper layer of identity, accountability, and sanctions for large-value transactions, deterring major attacks from identifiable actors.

QWhat key factor, besides legal consequences, deters large mining pools from attempting attacks?

AThe massive capital specificity of their investment deters them. Mining ASICs are worthless for any other purpose. A successful attack might yield millions, but the risk of being identified and sanctioned could lead to the destruction of billions of dollars in capital value from specialized hardware, frozen assets, and lost business relationships.

Nội dung Liên quan

Đối thoại với Ray Dalio: Chúng ta đang ở trong bong bóng AI, 1% danh mục đầu tư của tôi là Bitcoin

Ray Dalio, người sáng lập Bridgewater Associates, trong một cuộc phỏng vấn đã chỉ ra rằng thế giới hiện tại đang trong một "AI bubble" (bong bóng AI) cổ điển, với giá tài sản tăng vọt và đầu cơ quá mức. Ông cảnh báo bong bóng có thể vỡ do lãi suất tăng, nguồn cung cổ phiếu dư thừa hoặc khi nhà đầu tư cần tiền mặt trả nợ, dẫn đến suy thoái kinh tế. Đồng thời, Dalio mô tả một "chu kỳ lớn" kéo dài khoảng 80 năm, bao gồm ba động lực chồng chéo: khoảng cách giàu nghèo và xung đột nội bộ, thâm hụt ngân sách chính phủ khổng lồ và thay đổi địa chính trị. Ông nhấn mạnh rằng Mỹ và Anh đang đối mặt với những thách thức trong giai đoạn suy yếu này. Để bảo vệ của cải, Dalio khuyến nghị đa dạng hóa danh mục đầu tư với cổ phiếu, vàng, trái phiếu, bất động sản thay vì chỉ giữ tiền mặt. Ông tiết lộ khoảng 1% danh mục của mình là Bitcoin, nhưng vẫn ưa chuộng vàng vật chất hơn do tính ổn định và vai trò tiền tệ dự trữ. Về tác động của AI, Dalio cho rằng nó không chỉ thay thế lao động chân tay mà còn cả tư duy, làm trầm trọng thêm bất bình đẳng thu nhập. Con người cần phát huy trí tuệ cảm xúc và trực giác - những thứ AI chưa có - và học cách hợp tác với AI. Cuối cùng, ông phân tích những rủi ro của thuế tài sản và xu hướng thế giới có thể trở nên "khu vực hóa" hơn, với các khối như châu Mỹ và châu Á - Thái Bình Dương, trong bối cảnh sự thống trị toàn cầu của Mỹ đang suy yếu.

marsbit2 giờ trước

Đối thoại với Ray Dalio: Chúng ta đang ở trong bong bóng AI, 1% danh mục đầu tư của tôi là Bitcoin

marsbit2 giờ trước

Hơn 7.2 nghìn tỷ won trong một ngày, ngoại hải nước ngoài mua ròng kỷ lục vào thứ Sáu! Phố Wall: Cơn gió ngược về mặt vốn của thị trường chứng khoán Hàn Quốc đã tan biến

Dòng vốn nước ngoài đổ mạnh vào thị trường chứng khoán Hàn Quốc (KOSPI) với mức mua ròng kỷ lục 7,2 nghìn tỷ won chỉ trong ngày 31/7, đánh dấu sự đảo chiều rõ rệt sau nhiều tháng bán ròng mạnh. Theo báo cáo từ Citigroup, áp lực bán từ dòng vốn nước ngoài đã giảm đáng kể, với mức bán ròng tháng 7 thu hẹp còn 9,8 nghìn tỷ won so với mức 48,4 và 44,5 nghìn tỷ won trong tháng 6 và tháng 5. Đồng thời, các quỹ hưu trí và quỹ đầu tư trong nước cũng chuyển sang vị thế mua ròng 1,0 nghìn tỷ won trong tháng 7. Một yếu tố hỗ trợ khác là quy định mới từ Ủy ban Dịch vụ Tài chính Hàn Quốc (FSC), có hiệu lực từ 31/7, siết chặt điều kiện đầu tư vào các ETF có đòn bẩy đối với nhà đầu tư cá nhân. Quy định này đã ngay lập tức làm giảm khoảng 50% khối lượng giao dịch của các ETF này, góp phần kỳ vọng giảm bớt biến động cho thị trường. Citigroup duy trì mục tiêu chỉ số KOSPI ở mức 10.000 điểm, dựa trên các yếu tố thuận lợi như ngành chip bán dẫn ổn định, định giá thị trường thấp, nền tảng kinh tế vững mạnh và các chính sách hỗ trợ. Họ nhận định áp lực dòng vốn ngược chiều đang giảm dần, tạo điều kiện cho các yếu tố cơ bản và chính sách tích cực phát huy tác dụng.

marsbit2 giờ trước

Hơn 7.2 nghìn tỷ won trong một ngày, ngoại hải nước ngoài mua ròng kỷ lục vào thứ Sáu! Phố Wall: Cơn gió ngược về mặt vốn của thị trường chứng khoán Hàn Quốc đã tan biến

marsbit2 giờ trước

Làm thế nào để khiến bản thân trở nên không thể bị thay thế bởi trí tuệ nhân tạo

**Tóm tắt: Làm thế nào để trở nên không thể bị thay thế bởi AI** Bài viết phản đối việc than vãn về AI và thay vào đó đề xuất một giải pháp căn cơ: trở thành một "siêu cá nhân" không thể bị thuê mướn. Mối đe dọa thực sự không phải là AI, mà là tình trạng "nô lệ lương thưởng" – phụ thuộc hoàn toàn vào người khác để sinh tồn, làm công việc nhàm chán mà không có mục đích. Để thoát khỏi vòng luẩn quẩn này và phát triển mạnh trong kỷ nguyên AI, bạn cần trau dồi 5 yếu tố then chốt: 1. **Tính tự chủ:** Khả năng hành động mà không cần chờ chỉ thị. 2. **Khiếu thẩm mỹ:** Khả năng nhận biết điều gì thực sự có giá trị. 3. **Khả năng thuyết phục:** Thu hút sự chú ý và sự công nhận. 4. **Sự kiên trì:** Không sợ thất bại, xem đó là bài học. 5. **Khả năng lặp:** Điều chỉnh dựa trên phản hồi để tiến tới mục tiêu. Giải pháp là đầu tư vào sự nghiệp của chính mình. Trong khi AI giỏi tạo ra "tài sản" (nội dung, code), nó không thể thay thế được khả năng phân biệt thứ gì đáng để tạo ra, làm cho mọi người quan tâm và kiên trì theo đuổi. Trong hai kỹ năng đòn bẩy mạnh mẽ là **Code (Lập trình)** và **Media (Nội dung)**, bài viết nhấn mạnh **Nội dung** quan trọng hơn. Giá trị của nội dung là chủ quan và đòi hỏi sự am hiểu, trải nghiệm mà AI khó có được, tạo không gian cho các cá nhân sáng tạo thực sự. **Cách bắt đầu (Bài tập 15 phút):** 1. **Khai thác nguyên liệu thô của bạn:** Xác định chủ đề bạn am hiểu sâu, vấn đề bạn tự giải quyết được, hay sở thích đặc biệt từ nhỏ. 2. **Xác định "trục phản biện" của bạn:** Tìm ra quan điểm độc đáo của bạn – những điều bạn tin là đúng nhưng số đông lại sai trong lĩnh vực của mình. 3. **Xuất bản ý tưởng đầu tiên:** Kết hợp câu trả lời từ bước 1 và 2, tạo ra một nội dung (bài đăng, video) và đăng nó lên. Hành động này mang lại phản hồi thực tế, bắt đầu quá trình học hỏi, lặp lại và phát triển kỹ năng thuyết phục. Bằng cách xây dựng một sự nghiệp xoay quanh con người thật, trải nghiệm thật và góc nhìn độc đáo của mình thông qua nội dung, bạn có thể tạo ra giá trị mà AI không thể sao chép, từ đó trở nên không thể thay thế.

marsbit4 giờ trước

Làm thế nào để khiến bản thân trở nên không thể bị thay thế bởi trí tuệ nhân tạo

marsbit4 giờ trước

Nhờ việc tung xúc xắc, chìa khóa Bitcoin được lưu trữ offline, nhưng không phải ai cũng muốn làm điều này

Cảm biến từ cuộc tranh cãi gần đây xung quanh lỗ hổng trong ví phần cứng Coldcard, bài viết thảo luận về phương pháp tạo seed (cụm từ khôi phục) cho ví Bitcoin bằng cách xúc xắc vật lý. Mỗi lần xúc xắc công bằng cung cấp khoảng 2,6 bit entropy (thước đo tính ngẫu nhiên). Để đạt mức entropy an toàn cho một seed 12 từ (128 bit), cần khoảng 50 lần xúc xắc; Coldcard khuyến nghị 99 lần để đạt mức bảo mật cao hơn. Lợi thế chính của phương pháp này là tách biệt hoàn toàn với bất kỳ lỗi phần cứng hoặc phần mềm nào trong trình tạo số ngẫu nhiên của thiết bị, từ đó bảo vệ seed chính của ví. Tuy nhiên, bài viết cảnh báo rằng trong sự cố Coldcard, các chức năng phụ khác của thiết bị (như tạo ví giấy, khóa đa chữ ký, mật mã phiên USB) vẫn có thể bị ảnh hưởng nếu chúng dựa vào trình tạo số lỗi, ngay cả khi seed chính được tạo an toàn bằng xúc xắc. Nhược điểm lớn của việc dùng xúc xắc là quá trình thủ công, dễ xảy ra sai sót, tốn thời gian và không thực tế cho đa số người dùng mới. Người dùng có thể ghi chép sai, sử dụng xúc xắc gian lận, hoặc để lộ chuỗi kết quả. Do đó, mặc dù có nền tảng toán học vững chắc, phương pháp này đòi hỏi sự tỉ mỉ cao và không phải là giải pháp khả thi cho việc áp dụng Bitcoin rộng rãi. Bài viết kết luận rằng mục tiêu dài hạn vẫn là phát triển phần cứng/phần mềm tạo số ngẫu nhiên mạnh mẽ và đáng tin cậy, trong khi vẫn giữ phương pháp thủ công như một tùy chọn cho người dùng có kinh nghiệm. Cuối cùng, bài viết đưa ra khuyến nghị cho chủ sở hữu Coldcard: cập nhật firmware, kiểm tra các chức năng phụ đã sử dụng và xem xét các biện pháp bảo mật bổ sung như ví đa chữ ký kết hợp nhiều nhà sản xuất để giảm thiểu rủi ro từ một điểm yếu đơn lẻ.

cryptonews.ru7 giờ trước

Nhờ việc tung xúc xắc, chìa khóa Bitcoin được lưu trữ offline, nhưng không phải ai cũng muốn làm điều này

cryptonews.ru7 giờ trước

Giao dịch

Giao ngay
活动图片