Possibly PIP32 Atomic Swaps vunerable to double spend attack by Bob

Started by Skybuck, November 14, 2022, 08:30:43 AM

Previous topic - Next topic

Skybuck

Short version:

Bob could perform a double spend attack basically detecting TXN2 and send back his 1 BTC.
Then there would be two BTC transactions one from Bob and one from Alice, who will win ?

Longer version:

This feature seem vunerable to a double spend.

The problem begins at step 6 which reads:
"
6.   Bob creates a BTC transaction TXN1 with output:

Pay 1 BTC to A if
  (x for H(x)=CODE and signed by A) OR
  (Signed by B after two weeks from now)
"

The problem also begins at:
"Once Alice detects TXN1 on the BTC chain, she immediately spends it's outputs via a TXN2 to her own wallet.
She thus takes possesion of the 1 BTC, revealing SECRET in the process."

The hint "immediately" gave away there is a problem.

Let's assume that Bob can also detect TXN2... which could be possible...
Then Bob can try and perform a double spend by re-issueing a new BTC transaction... re-taking his 1 BTC with a new transaction.
Since both transactions will now be in the mempool it is unsure which BTC transaction will go through:
Possibility 1: Alice BTC transaction
Possibility 2: Bob BTC transaction
Basically the problem is with "immediately" Bitcoin does not really work with "immediately" it takes quite some time,
at least 6 blocks before one can be sure that a transaction truely/thoroughly happened !

Skybuck

From Discord:

herman
—
11/17/2022 11:25 PM
No, the "immediately" is to ensure Alice spends the coin BEFORE Bob's time-lock expires. Because if she doesn't spend it and the time-lock expires, it means Bob can spend it.

herman
—
11/17/2022 11:26 PM
Bob can only do this AFTER the time-lock has expired, which is why there is a time-constraint for Alice to spend. She should spend the coins as soon as she learns about the key.

Skybuck
—
11/18/2022 2:20 AM
There might be a second weakness in this protocol.
If alice can undo her sale, cancel it, delete it, transfer the account somehow, deprive it of coins, etc
Or re-direct back to her self/modify it or make a new sale.
@herman, your first statement would imply the Bob's BTC is "locked up" on the blockchain and is no longer his possession... hmmm...
Let's suppose nothing happens, it says (Signed by B after two weeks from now) how does Bob exactly get his BTC back ? what he have to do ? Make a new BTC transaction or something ? I guess so... he then signs the new transaction proving that he had the private keys...
Bitcoin indeed has locking mechanisms interesting 🙂
https://learnmeabitcoin.com/beginners/output_locks

herman
—
11/18/2022 2:31 AM
Yes it is time-locked, still his possession but cannot use it. Only Alice can use it during timelock, but she needs the secret to unlock it.

Skybuck
—
11/18/2022 2:35 AM
Kinda funny, so if Bob makes a mistake he could accidently lock his coins for 1 million days or 1 million years ! 😄
Hmm the link I posted does not mention anything about a time lock... still investigating...
Little bit better link:
https://en.bitcoin.it/wiki/Timelock

herman
—
11/22/2022 9:23 AM
Yes, which is why time-lock durations are generally not a user-input. Depending on the configuration, a time-lock should last for 1.25 times the duration of the "atomic swap period". The extra 0.25 time buffer is required to prevent attack where Bob reveals secret on first chain moments before expiration which doesn't give Alice enough time to exclusively redeem it on the second chain (allowing Bob to claim back his coins moments after the expiration, thus keeping both). By granting Alice 0.25 buffer it means that if Bob reveals secret 1 second before expiration on first chain, there is still reasonable time for Alice to redeem the coins on the counter-chain using that secret without fear of Bob or anyone preempting her.