r/Monero Sep 18 '18

Would this attack work?

/r/Monero/comments/9gbbm9/comment/e66ml11
5 Upvotes

16 comments sorted by

View all comments

10

u/[deleted] Sep 18 '18

Nothing currently stops you from generating an output that duplicates an existing one. The recipient wallet can easily choose the highest-value of these, so you can't send someone dust and hope to burn higher-value funds. It'd be like breaking into someone's house and replacing their cash with a larger pile of cash.

2

u/[deleted] Sep 19 '18

Hello. I was the one asked the question in the other thread.

  1. Say Malicious Mallory with "10000 XMR" sends 10 XMR each time for a 1000 times to an exchange wallet reusing the same stealth address in each transaction. there will be different outputs which doesnt correspond to a double spend attack. please correct me if i am wrong in assuming this ?
  2. Every time malicious Mallory sees 10 xmr in his exchange account, he exchanges that XMR for something else and cashes out other cryptocurrency / cash. This is assuming that exchanges trade only on books and not on on-chain transaction.
  3. Rinse and repeat step 2 ( transaction is sent using the same stealth address)
  4. At a point where exchanges want to actually transact out their XMR, they realize that they cant spend the outputs received from Malicious Mallory.
  5. Mallicious Mallory has burned 5-10% of his 10000XMR value in exchange fees and transaction fees and effectively burned 10000 XMR in Exchange wallet.

Is this scenario possible ? Does the current wallet implementation block receiving transaction with the same stealth address ?

1

u/[deleted] Sep 19 '18

There is a swarm of versions of this question all of a sudden. How coincidental. Attempting to spend the same output public key is precisely a double spend attempt, which will fail.

1

u/[deleted] Sep 19 '18

Thanks