Reposting my post from Medium (https://medium.com/@rajeshbhaskar/algorand-may-be-broken-d1d2c2542064)
Algorand is one of the most interesting projects in the blockchain space, with a lot of promise. I really like the maths and cryptography behind it, but I think the overall blockchain schema is theoretically broken, however — you decide. I am also working on a solution, inspired by Algorand itself.
In the blockchain space, Algorand is quite well known as the one “without incentives”.
Quoting from Coindesk report from Apr 4, 2017:
“Can you say anything about incentives in Algorand?”
That question was directed to Silvio Micali, an MIT professor who had just delivered a keynote on his theoretical proof-of-stake (PoS) system at the Financial Cryptography and Data Security conference in Malta, yesterday. And the Turing-award winner’s answer set a few back on their heels.
“Incentives are the hardest thing to do,” Micali said.
As he explained, when you put incentives out there, people learn how to use those incentives for making money in ways that are nearly impossible to predict.>
I agree. I also submit that the Algorand “theoretical proof of stake” is also flawed for the same reason. Even without Algorand incentives.
Supposing, for example:
Clearly, (750 of) the 5000 corrupt accounts of one single (in possibility 2 above) Adversary, together have a high probability (much greater than 5*10^-9 expected in the whitepaper) of being chosen to form the committee. They can even get 2/3rds majority with at least 670 votes and override the remaining committee members.
All that is remaining is to transfer out money from A201–10000 (≤ 700M USD) and also the 50M used to fund the attack.
The cost of funding this attack using a single Adversary, however, is quite high at 50M USD (although only 5% of the total money [1B USD] in the system).
I reached out to the Algorand team, including Dr Micali, who responded quite graciously. He assured me that while it is plausible, the probability of this scenario (slightly modified and made more precise from the version sent to him) is negligibly low. Hopefully I did not miss out something very simple!!
There are some ways of working around this problem in current Algorand with its PoS. Keeping a minimum staking amount, restricting validators to a small set etc may be a few ideas here. Such solutions will impact decentralization and scalability and probably make Algorand somewhat as good as Tendermint with its PoS.
I really am impressed with the Algorand BA* self-selection method for choosing proposers and verifiers and would really like it to work. But, as mentioned by Dr Micali himself, even a theoretical proof of stake is “all about the money” and that remains a potential problem, especially in Algorand.
My team and I are working on a (theoretical) solution for Algorand without the PoS element and hopefully that will resolve the matter. It is upto Algorand to be open to adopt it and defeat the Adversary!
— Cheers! (Rajesh Bhaskar)
(*) The purpose of publishing this article is to educate, clarify and thwart any loopholes in Algorand and also to study alternatives.
(-) Please read the Algorand White Paper to know who/what is the Adversary and how it works.
(+) If you liked this article and would consider donating to my independent blockchain research efforts to build a better blockchain, please do so to the wallets below:
ETH: 0x058503afffd50303e1e49623c67e8760f50d304d
BTC: 3PrR945zHeTPh7kmUiftUUwmxUV2jkuy4M