본문으로 건너뛰기

제10장 – 더 다오

한글

아래에는 책 The Blocksize War의 제10장을 게재합니다. 전체 책은 Amazon에서 구할 수 있습니다. 안내 말씀으로, 종이책 판매 수익의 50%는 분쟁, 전염병, 재난 또는 의료 서비스 배제로 영향을 받는 사람들에게 의료 지원을 제공하는 자선 단체인 Médecins Sans Frontières에 기부됩니다.

2016년 여름, “The DAO”(분산형 자율 조직)라는 프로젝트가 암호화폐 커뮤니티 안의 많은 사람들의 관심을 끌기 시작했습니다. The DAO는 이더리움 위에 구축된 스마트 계약이었고 스스로를 일종의 자율 투자 펀드라고 내세웠습니다. 낡고 경직된 하향식으로 운영되는 투자 펀드와 달리, The DAO는 사용자의 투표로 결정되는 대로 투자를 집행하고 법이 아니라 스마트 계약의 코드에 따라 운영될 것이었습니다.

이더리움은 2013년에 초기 비트코이너인 비탈릭 부테린에 의해 처음 구상된 코인이었습니다. 이 프로젝트는 2014년에 코인 공모로 자금을 모았고 이더리움은 마침내 2015년 여름에 가동을 시작했습니다. 이 시점에 이더리움은 겨우 한 살이었고 커뮤니티는 이미 꽤 야심 찬 프로젝트들에 참여하고 있었습니다. 비탈릭은 처음에는 자신의 스마트 계약 플랫폼을 비트코인 위에 구축하기를 원했다고 전해집니다. 그러나 비트코인은 그가 원하는 일을 하기에 충분히 유연하지 않았습니다. 이러한 유연성을 잠재적인 보안 위험으로 본 것은 비트코인의 코드와 구조만이 아니라 그레고리 맥스웰과 루크 대시주니어 같은 작은 블록 지지자들을 포함한 커뮤니티이기도 했습니다. 따라서 자연스럽게 비탈릭과 대부분의 이더리움 커뮤니티는 큰 블록 지지자들의 편에 서는 경향을 보였습니다.

블록 크기 전쟁은 사실상 이더리움에게 핵심적인 모집관 역할도 했습니다. 이더리움 커뮤니티는 비트코인을 오래된 기술로, 유연하지 못하고 작은 1 MB 블록에 갇혀 있다고 그릴 수 있었습니다. 반면 이더리움은 훨씬 더 유연한 접근 방식을 취했고, 채굴자들이 조정할 수 있는 동적인 블록 크기 제한을 두었습니다(이더리움에서는 이것을 gas limit이라고 부르며, 이 제한은 사용되는 데이터의 양이 아니라 블록 안의 여러 기능을 처리하는 데 필요한 연산력과 관련됩니다). 비트코인에서는 거래 수수료가 오르기 시작하는 동안 이더리움 수수료는 매우 낮았습니다. 이더리움의 이러한 마케팅 전략은 매우 성공적인 것으로 입증되었고, 많은 비트코이너들이 이더리움이 미래의 젊고 역동적인 코인이라고 믿으면서 관심을 이더리움으로 옮겼습니다.

일부 큰 블록 지지자들에게, 비트코이너들이 이더리움으로 옮겨 가는 것은 작은 블록 지지자들이 일으킨 문제였습니다. 작은 블록 지지자들은 믿을 수 없을 정도로 고집이 세서 사람들이 인내심을 잃고 떠나게 되었습니다.61 비트코인은 이제 시장 점유율을 잃게 되었습니다. 상인들은 결국 이더리움을 받아들일 것이고, 그러면 비트코인은 반드시 실패할 것이었습니다. 블록 크기 제한이 일부 사람들을 비트코인에서 떠나게 하고 있었다는 것은 사실이지만, 이것이 대안 코인들의 성공의 유일한 이유는 아니었습니다. 돈을 벌 기회가 이러한 흐름의 주요 동인이었습니다. 이더리움의 성공은 모방자들과 새로운 코인 공모의 물결을 몰고 왔습니다. 이들 코인은 비트코인의 소위 널리 알려진 확장성 문제를 자주 부각하고 자신들의 새로운 코인이 이러한 문제를 해결했다고 주장했습니다. 작은 블록 지지자들은 이를 전혀 개의치 않는 듯했습니다. 그들은 변혁적인 화폐 시스템에 관심이 있었습니다. 초당 40,000건의 거래를 처리한다고 주장하는 대안 코인들은 그 목표와는 관련이 없어 보였습니다.

역설적이게도, 이러한 대체 코인들은 일부 큰 블록 지지자들에게 좌절의 원인이었지만, 그들에게는 또한 유혹적으로 다가왔습니다. 지루한 싸움을 계속하기보다는 비트코인을 포기하고 이러한 대체 코인들로 관심을 옮기는 편이 그들에게는 더 쉬웠습니다. 작은 블록 지지자들이 이러한 흐름에서 얼마나 큰 혜택을 얻었는지 아무리 강조해도 지나치지 않습니다. 이러한 위기 동안 대체 코인 분야는 빠르게 성장했으며, 그 지지자들은 코인 공모로 자금을 모으고 코인 가격 상승으로 수익을 얻는 데 집중했습니다. 이러한 출구가 이 사람들에게 마련되어 있지 않았다면, 그들은 비트코인에 남아 블록 크기 전쟁을 이어갔을지도 모르며, 큰 블록 지지자들의 압도적인 수는 극복하기에 너무 컸을 것입니다. 전쟁이 이어진 2년의 기간 동안 생태계에는 근본적인 변화가 일어났으며, 비트코인 중심의 영역에서 암호화폐 중심의 영역으로 바뀌었습니다. 그러한 환경에서는 비트코인이 모든 사람을 위해 타협해야 한다는 주장이 설득력을 잃었습니다. 사람들의 필요에 맞는 코인은 항상 있었습니다.

어쨌든 The DAO 이야기로 돌아갑니다. The DAO 크라우드세일은 2016년 4월 30일에 시작되어 2016년 5월 25일까지 계속되었습니다. 그것은 엄청난 관심을 끌었고 그 펀드를 위해 US$150백만을 넘는 자금을 모았습니다. 이것은 당시 이 영역에서는 믿기 어려운 금액이었습니다. 존재하는 모든 이더리움의 14퍼센트를 넘는 분량이 The DAO로 흘러들어갔습니다. 투자한 이더리움을 원하면 언제든 펀드에서 되찾을 선택권이 항상 있다고 여겨졌기 때문에 일부 투자자들은 그것을 무위험이라고 여겼습니다.

이더리움이 너무 젊었기 때문에 The DAO처럼 복잡한 것을 감당할 준비가 전혀 되어 있지 않았습니다. 그러나 이더리움 커뮤니티는 실험하고 새로운 것을 시도하기를 좋아했습니다. 이것이 그들이 애초에 이더리움에 끌린 이유의 일부입니다. 그들은 보수적인 비트코이너들에게 싫증이 나 있었습니다.

알고 보니 The DAO는 여러 차원에서 근본적으로 결함이 있었습니다. 새로운 투자 프로젝트의 생성은 결국 새로운 종류의 DAO 토큰을 만들어내게 되어 있었고, 각 종류는 서로 다른 위험과 보상을 갖게 되었습니다. 이는 DAO 토큰이 대체 가능하지 않고 서로 다른 가격에 거래되어야 함을 의미했고, 이는 거래소와 커뮤니티가 제대로 이해하지 못한 문제였습니다. 이 프로젝트의 경제적 유인 구조도 거의 말이 되지 않았습니다. 예를 들어 투자 결정에 있어서는 투자 제안에 “반대”로 투표할 유인이 거의 없었습니다. “반대” 투표자도 승인된 프로젝트에 투자된 상태가 되는 반면, 기권한 사람들은 전혀 노출을 얻지 못했기 때문입니다. 또한 성공한 프로젝트가 수익을 The DAO에 다시 기여하도록 강제하는 명시된 장치가 없었고, 스마트 계약의 코드는 설명되거나 의도된 바를 항상 구현하는 것처럼 보이지 않았습니다. 토큰 판매가 끝난 지 몇 주 뒤인 2016년 6월 17일에,62(암호화폐 역사에서 또 하나의 중요한 날짜입니다) 해커가 코드에서 허점을 찾아 The DAO의 이더리움 자금에 접근하여 그 일부를 “child DAO”라고 불리는 것으로 빼돌렸고, 해커는 그 child DAO에 대해 잠재적으로 상당한 통제권을 갖게 되었습니다.

이 해킹 사건은 이른바 “DAO 전쟁”의 시작을 알렸고, 해커에게서 “도난당한” 이더리움을 되찾기 위한 싸움이 벌어졌습니다. 안타깝게도 이는 성공하지 못하는 듯했고, 그래서 이더리움 커뮤니티와 개발자들은 아이디어를 내놓았습니다. 자금을 되찾는 데 도움이 되도록 이더리움 프로토콜을 바꿀 수 있다는 것이었습니다. 일부 사람들에게 이는 매우 논란이 많은 발상이었습니다. 구제 금융으로 여겨졌고 커뮤니티의 많은 사람들이 반대하는 것이었습니다. 많은 사람들이 암호화폐 영역에 들어온 이유 중 하나는 2008년과 2009년의 은행 구제 금융 같은 구제 금융이 있는 체제를 피하고 싶었기 때문이었습니다. 결국 왜 하필 The DAO만 특별히 선택되었습니까? 이더리움 위의 더 작은 많은 프로젝트와 스마트 계약의 투자자들이 이전에 돈을 잃었는데 왜 이 프로젝트가 구제되었습니까? 아마도 The DAO는 “너무 커서 실패할 수 없는” 존재였거나, 프로토콜을 통제하고 The DAO에 큰돈을 투자한 영향력 있는 개발자들과 이더리움 커뮤니티 구성원들의 자기 이익 때문이었을 것입니다. 많은 사람들에게 이러한 문제들은 그들이 벗어나고 싶어 했던 전통 금융 체제의 부패와 다른 문제들을 그대로 비추는 것처럼 느껴졌습니다.

2016년 6월 24일에 이더리움이 해커의 자금을 동결하기 위해 소프트포크를 실시하자는 제안이 나왔습니다.63 그로부터 약 4일 뒤에 이 소프트포크 제안에 결함이 있어 네트워크를 심각한 DoS 공격에 잠재적으로 노출시킬 수 있다는 점이 발견되었습니다. 따라서 소프트포크는 폐기되었고 자금을 되찾는 유일한 방법은 하드포크라는 결론이 내려졌습니다. 비트코인이 전쟁 한가운데에 있던 바로 그때 일어난 꽤 주목할 만한 반전입니다. Bitcoin Classic이 여전히 논쟁적인 하드포크로 떠오른 상황에서 이더리움은 자체적인 논쟁적 하드포크를 계획하고 있었습니다. 비트코인의 블록 크기 전쟁은 모두가 이더리움에 집중하면서 몇 달 동안 사실상 중단되었습니다. 하드포크에 대한 지지 수준을 가늠하기 위해 코인 투표가 실시되었습니다. 사람들은 자신이 가진 코인으로 하드포크를 지지하는지 여부를 투표할 수 있었습니다. 투표 결과는 압도적이었고 하드포크 찬성이 95퍼센트를 넘었습니다.64 그러나 이 여론 조사가 대표성이 없다는 비난도 있었습니다. 주로 하드포크를 지지하는 사람들이 주도했고 반대한 사람들은 투표하지 않았을 수 있기 때문입니다. 이에 더해 이더리움 보유자들의 참여율은 낮았고 아마도 6퍼센트 정도였습니다.65 채굴자들에게도 의견을 물었고 90퍼센트를 넘는 채굴자들이 하드포크를 지지한다고 전해졌으며 이는 강력한 다수였습니다.

하드포크는 2016년 7월 20일 수요일로 예정되었습니다. 그 사건을 놓치고 싶지 않아서 저는 당일과 다음 날 휴가를 냈습니다. 또한 새 컴퓨터를 구입해서 두 이더리움 클라이언트를 모두 실행할 수 있는 충분한 로컬 자원을 확보했습니다. 하나는 하드포크용으로 업그레이드한 것이고 하나는 구버전이었습니다. 잠재적 분할이 다가오자 진정한 암호화폐 열성팬답게 저는 집에 앉아 두 노드를 모두 실행했고, 사건이 전개되는 동안 실시간 이더리움 가격을 보기 위해 거래소 주문 장부를 보여주는 웹사이트들을 여러 탭으로 열어 두었습니다. 저를 포함한 많은 암호화폐 애호가들은 이더리움 블록 높이가 1,920,000에 도달하여 하드포크가 일어나기를 간절히 기다렸습니다.66

처음에는 하드포크가 성공적으로 일어난 것처럼 보였습니다. 업그레이드된 규칙 체인이 연장되는 동안 원래 규칙 체인에는 블록이 전혀 없었습니다. 일부 큰 블록 지지자들은 이미 승리를 선언하기 시작했고 이것이 비트코인에 대한 교훈이라고 주장했습니다. 논쟁적인 하드포크는 분할을 일으키지 않는다고 그들은 선언했습니다. 포크 약 1시간 뒤에 원래 규칙 체인이 연장되기 시작했습니다. 그러고 나서 원래 규칙 체인에서 난이도가 하향 조정되자(비트코인보다 훨씬 빠른 조정입니다) 더 빠른 속도로 연장되기 시작했습니다. 처음에는 하드포크 체인이 약 98퍼센트의 해시레이트를 가진 것처럼 보였지만 균형이 바뀌기 시작했고 원래 규칙 체인이 추진력을 얻기 시작하여 아마도 5퍼센트에서 10퍼센트의 해시레이트를 달성했습니다. 그러자 원래 규칙 체인에 이름이 필요해졌습니다. Bitcoin Classic이 있었으니 Ethereum Classic이라고 부르면 어떻겠습니까?

분할 약 3일 뒤에 거래소들이 Ethereum Classic을 상장하기 시작했습니다. 당시 선도적인 대안 코인 거래소 중 하나인 Poloniex가 2016년 7월 23일에 Ethereum Classic을 상장했습니다.67 그러자 거래소에서 Ethereum Classic의 가격이 오르기 시작했습니다. 기억으로는 이더리움 가치의 약 2퍼센트 수준에서 거래되기 시작했고 7월 25일에 정점을 찍어 이더리움 가격의 50퍼센트를 넘는 수준에 이르렀습니다. Ethereum Classic은 매우 큰 변동성을 보이는 것으로 입증되었습니다. 더욱이 채굴자들은 가격을 따랐습니다. 정확히 완벽한 상관관계는 아니었지만, Ethereum Classic의 가격이 오르자 더 많은 채굴자들이 늘어난 블록 보상을 챙기기 위해 그것을 채굴했습니다. 그러자 작은 블록 지지자들은 상황이 큰 블록 지지자들이 주장했던 것보다 복잡하다고 주장하기 시작했습니다. 어쩌면 채굴자들이 프로토콜을 정하는 것이 아니라 수익을 극대화하기 위해 거래자와 투자자를 따른다는 것이었습니다.

Ethereum Classic의 가격이 오르자 점점 더 많은 추진력을 얻었습니다. 채굴자들은 그저 돈을 따르고 싶어 하는 것처럼 보였습니다. 이때 많은 사람들이 하드포크와 논쟁적 분할이 해시레이트와 컴퓨터 과학이라는 두 가지 문제만이 아니라 금융 시장과도 관련됨을 깨닫기 시작했습니다. 이러한 사건은 코인들 사이를 오가며 거래할 수 있는 금융 투기꾼과 거래자들에게 기회였습니다.

이 영역에서 Ethereum Classic을 지지한 핵심 인물 중 한 명은 배리 실버트였습니다. 배리는 작은 블록 지지자가 아니었습니다. 그는 순전히 돈을 벌려고 Ethereum Classic을 사는 것처럼 보였습니다.

비트코인이 아닌 첫 디지털 통화를 샀습니다…Ethereum Classic (ETC). $0.50에 위험과 수익이 적당하게 느껴졌습니다. 그리고 철학적으로 동의합니다.68

배리는 1년 전에 Digital Currency Group을 설립했고 이 영역에서 가장 큰 투자자 중 한 명이었습니다. 배리는 또한 미국 당국이 다크넷 시장인 Silk Road에서 압수한 비트코인을 구입하기 위한 경매에서 낙찰받은 것으로 커뮤니티에 잘 알려져 있었습니다. 배리는 이야기의 후반부에 더 등장할 것입니다. 그러나 지금으로서는 그는 우연히 작은 블록 측을 돕는 것처럼 보였습니다.

Ethereum Classic이 너무 많은 추진력을 얻어 해시레이트에서 이더리움을 앞지른 뒤 모든 하드포크 노드가 Classic 체인으로 전환하게 될 위험은 없었습니다. 비탈릭은 그 정도로 어리석지 않았습니다. 이더리움 하드포크는 체크포인트를 두는 방식으로 구성되어 어느 체인이 더 많은 작업을 가졌는지에 관계없이 분할의 양쪽이 모두 존재하도록 깔끔하게 단절되었습니다. 이것은 때로 “와이프아웃 보호”라고 불리며 분할 전에 이더리움 개발자들과 직접 신중하게 확인했던 점입니다. 와이프아웃 보호를 포함하지 않기로 한 Bitcoin Classic의 결정은 이제 더욱 순진해 보였습니다.

Coinbase는 2016년 7월 21일에야 이더리움 지원을 추가했습니다,69 아이러니하게도 분할이 일어난 바로 다음 날이었습니다. 이 회사는 비트코인 클래식의 지지자였으며 CEO인 Brian Armstrong은 이더리움 하드포크가 분할 없이 성공할 것이라고 믿었고, 아마도 하드포크가 채굴자들의 강력한 지지를 받았기 때문이었습니다. 이러한 믿음 때문에 Coinbase는 이 판단이 틀린 것으로 드러날 경우에 대비해 고객 자금을 보호하기 위한 적절한 조치를 취하지 못한 것으로 보였습니다. 그 결과 Coinbase는 이른바 “리플레이 공격”에 취약한 상태가 되었습니다. 분할 이후 처음 며칠 동안 Coinbase에서 이더리움을 인출할 때 Coinbase가 이 거래의 두 가지 버전을 보낼 가능성이 있었습니다. 하나는 이더리움에서, 다른 하나는 이더리움 클래식에서였습니다. 이와 달리 Kraken과 Poloniex 같은 동종 업체들은 코인을 분할하고 이를 방지하기 위한 조치를 취했습니다. 이 분야의 일부 노련한 트레이더들은 Coinbase의 이러한 실수를 이용해 이익을 얻을 수 있었습니다. 그들은 자신의 코인을 직접 이더리움 클래식과 이더리움으로 분할한 뒤 이더리움을 Coinbase에 입금할 수 있었습니다. 거래 없이 이더리움을 Coinbase에서 인출할 수 있었고, 트레이더는 리플레이가 일어나 이더리움 클래식을 무료로 받기를 기대했습니다. 당시 저는 이러한 “거래”를 성공적으로 해내 상당한 수익을 올렸다고 주장하는 여러 사람과 이야기를 나누었습니다. 결국 Coinbase는 오류를 알게 되었고, 어떤 형태의 리플레이 보호 조치를 도입했으며 자체 자산으로 손실을 메웠습니다.

DAO 전쟁에 관해서는, 하드포크 덕분에 분할의 이더리움 측에서 “도난당한” 자금을 회수하는 데 성공했습니다. 분할의 클래식 측에서의 “도난당한” 자금에 관해서는 상황이 더 복잡했고, DAO 전쟁은 계속되었습니다. 분할의 클래식 측에서 다양한 버킷과 자식 DAO 안에 있는 회수된 DAO 토큰을 누가 가져야 하는지와 같은 다른 문제들도 있었지만, 이는 이 이야기의 범위를 벗어납니다.

2016년 7월 말, 비트코인 채굴자들과 개발자들 사이에 또 다른 회의가 마련되었고, 이번에는 캘리포니아에서 열렸습니다. 다시 밀실에서 합의에 이르렀다는 비난의 함정에 빠지지 않으려는 마음에, 모든 참석자는 참석하기 위해 다음 성명에 서명해야 했습니다:

참석자들은 비트코인 합의 규칙이 사용자가 실행하기로 선택한 소프트웨어에 따라 사용자들에 의해 결정되기 때문에, 제안된 변경은 전체 비트코인 커뮤니티의 의견을 받아 공개적으로 논의되어야 한다는 것을 인정합니다. 이러한 이유로 이번 행사에서는 어떠한 합의나 원탁 합의도 나오지 않을 것입니다.70

저는 이 회의에 참석하지 않았다는 점을 밝혀둡니다. 다만 비트코인 개발자 Bryan Bishop이 제공한 회의 기록이 있습니다.71 Bryan은 블록 크기 전쟁의 많은 사건과 논의를 기록하는 뛰어난 작업을 했습니다. Jihan Wu가 개발자들을 만나기 위해 미국까지 날아와 3일간의 행사에 참석했습니다. 기록은 발언을 특정 이름에 귀속시키지 않지만, 이 분야의 주요 인물들에 익숙한 사람들에게는 많은 경우 누가 발언자인지 파악할 수 있습니다. 행사의 시기는 우연이 아니었습니다. 홍콩 합의에 따르면 하드포크 코드가 공개되기로 된 바로 그 시점인 7월 말로 예정되어 있었습니다.

이 회의에서는 이더리움 분할이 비트코인의 가능한 하드포크에 미친 영향이 분명했고, 논의의 많은 부분은 어떤 교훈을 얻을 수 있는지에 관한 것이었습니다. 참석자들은 이제 하드포크가 분할을 일으키는 것은 거의 불가피하다고 주장하고 있었습니다:

이더리움에서의 이번 분할 때문에 비트코인의 하드포크가 가질 수 있는 미래에 대한 선례가 됩니다. 비트코인에게 하드포크에는 두 가지 선택지만 있을 수 있습니다. 한쪽은 여러 체인과 여러 방향에서의 여러 공격을 받아들여야 하고, 아니면 우리는 그냥 메인 체인에 머물며 포크들과 소수 체인을 없애려 시도해야 합니다. 가능한 경우는 두 가지뿐일 수 있습니다.

그다음 한 개발자가 상황을 설명하고, 홍콩 합의에도 불구하고 단기적으로 하드포크가 있을 것 같지 않은 이유를 설명하려 했습니다:

[홍콩] 합의 서명자 중 많은 이들이 [뉴욕]에서 일주일을 보냈습니다. 우리는 많은 설계 작업을 했습니다. 하드포크를 올바르게 구성하는 방법에 대해 이야기했습니다. 최근 이더리움이 겪은 것과 같은 위험을 갖지 않는 방식으로 이를 수행하는 방법에 대해 이야기했습니다. 우리는 [홍콩]에서 비트코인이 통합된 상태로 유지되는 것이 얼마나 중요한지, 그리고 그것이 비트코인의 장기적인 가치에 얼마나 중요한지에 대해 이야기했습니다. [홍콩]에서도, 그리고 [뉴욕]에서도 논란이 될 만한 일을 하려는 바람은 없습니다. 일어날 수 있는 어떤 종류의 하드포크에 대해서도 합의가 필요할 것입니다. 그것은 매우 논란이 없는 것이어야 합니다. 그러한 연구와 논의의 많은 부분이 더 널리 공개되어야 한다는 것은 확실히 사실이지만, 이 방 밖에 있는 사람들 사이에서도 하드포크에 대해 그 수준의 합의를 얻는 것은 매우 어려울 것이라는 우려가 지금 확실히 많습니다. 하드포크는 시장에 매우 큰 혼란을 준다는 점을 지적하고 싶었습니다. 그것들은 상인들과 시장들, 전체 생태계에 혼란을 줍니다. 우리는 이를 고려해야 합니다. 하드포크를 할 압도적으로 강력하게 정당화된 이유가 없는 한, 비용이 이익을 웃돕니다. 우리는 하드포크 없이 비트코인의 이러한 문제들을 해결할 방법을 찾아왔습니다.

합의 서명자 중 한 명이었던 Luke Dashjr는 그다음 자신이 약속을 지켰고 가능한 하드포크를 위한 코드를 작성했다고 설명했습니다.72

참석한 개발자 중 한 명은 아마도 홍콩에 있지 않았던 것으로 보이며, 하드포크를 위한 코드를 만들려는 개발자들의 노력을 약화시킨 것에 대해 사과했습니다. 그 사람은 일부 채굴자들이 세그윗을 막겠다고 말하는 상황에서 하드포크 작업을 하는 것은 적절하지 않다고 느꼈다고 말했습니다. 그 사람은 하드포크가 세그윗에서의 블록 크기 증가에서 주의를 분산시킬 것을 우려하고 있었습니다. 그는 또한 하드포크를 얻기 위해 세그윗을 막겠다는 공개 발언에 대해 불만을 표했고, 그것이 본질적으로 위협이며 하드포크를 더 어렵게 만드는 긴장에 기여한다고 말했습니다.

여러분과 개발자들에게, 약속과 관련해 여러분을 위해 이 자료를 만들려는 그들의 노력을 약화시킨 것에 대해 사과하고 싶습니다. 뉴욕에서의 그들의 노력이 하드포크와 관련해 세그윗을 막겠다는 일부 공개 발언 바로 뒤에 나왔기 때문에 그렇게 했습니다. 그런 분위기에서 하드포크 제안들이 세그윗을 통한 비트코인의 확장을 늦추는 것에 대해 매우 불편하게 느꼈습니다. 제 발언이 만든 분위기를 후회합니다. 그것과 제 발언에 대해 죄송합니다.

그다음 이 발언에 대한 답변이 있었고, 아마도 Jihan Wu의 답변이었으며, 그는 양측이 빠진 나쁜 소통의 악순환을 통찰력 있게 지적했습니다. Jihan은 그다음 자신도 위협을 느꼈다고 암시했고, 따라서 위협이 양쪽에서 오고 있었다는 뜻을 전했습니다.

이것을 분명히 할 필요가 있다고 생각합니다. [그] 세그윗 블록도 [홍콩] 합의가 존중받지 못할 것이라는 [생각]에서 나옵니다. 나쁜 소통이라는 면에서 우리가 빠진 매우 나쁜 악순환입니다. 아마 양측 모두 압박 속에서 뭔가를 하고 싶어 하지 않습니다. 아마 양측 모두 위협하고 싶어 하지 않습니다.

행사 후에 저는 회의에 참석한 잘 알려진 작은 블록 지지자와 이야기를 나누었습니다. 그는 Jihan이 세그윗이 공개되면 이를 활성화하는 것을 도우려 하기로 합의했고, 채굴자들이 이더리움에서의 사건들에 겁을 먹어 위험한 것을 시도하려 하지 않았다고 말했습니다. 세그윗을 활성화하겠다는 약속에 관해서는 이것이 낙관적이었을 수 있고 Jihan은 이러한 사건들에 대해 다른 설명을 했을 수 있습니다. 추가적인 소통 문제가 있었을 수 있다고 상상하는 것은 어렵지 않습니다.

이더리움 분할은 블록 크기 전쟁에서 결정적인 순간이었고, 당혹스러운 Craig Wright 사건보다도 더 그랬습니다. 그것은 주도권을 작은 블록 지지자들에게 넘겨주었습니다. 채굴자들은 이제 비트코인에서 비슷한 사건이 일어날 것을 두려워하고 있었습니다. 이더리움 분할 이전에 채굴자들은 그저 뭔가를 시도해보려는 의지가 강했습니다. 이제 시각이 바뀐 것으로 보였습니다. 비트코인 클래식은 이제 단기적으로 활성화될 가능성이 낮아 보였습니다. 아이러니하게도 대부분의 작은 블록 지지자들이 이를 인정하려 하지 않겠지만, 이더리움이 비트코인을 구했을 수 있습니다. 하지만 전쟁은 끝나려면 아직 멀었습니다. 이 분야의 사람들은 기억이 짧았고, 이더리움으로부터의 교훈은 점차 기억에서 사라질 것이었습니다.

61

https://www.reddit.com/r/btc/comments/4u0cuq/congratulation_small_blockers_this_is_a_direct/

62

http://archive.is/76EZY

63

http://archive.is/7UUrY

64

https://futurism.com/the-dao-heist-undone-97-of-eth-holders-vote-for-the-hard-fork

65

https://medium.com/coinmonks/the-dao-is-history-or-is-it-47a6f457338a

66

http://archive.is/PaGgM

67

http://archive.is/xfvMY

68

https://twitter.com/BarrySilbert/status/757628841938472961

69

https://blog.coinbase.com/coinbase-adds-support-for-ethereum-b8046cf486d0

70

https://www.coindesk.com/no-scaling-agreements-industry-bitcoin-meetup

71

https://diyhpl.us/wiki/transcripts/2016-july-bitcoin-developers-miners-meeting/cali2016/

72

https://github.com/luke-jr/bips/blob/bip-mmhf/bip-mmhf.mediawiki

영문 — Chapter 10 – The DAO

Chapter 10 of the book The Blocksize War is published below. The full book is available on Amazon. As a reminder, 50% of any profits from physical book sales will be donated to Médecins Sans Frontières, a charity that provides medical assistance to people affected by conflict, epidemics, disasters, or exclusion from healthcare.

In the summer of 2016, a project called “The DAO” (Decentralized Autonomous Organization) began to grab the attention of many inside the cryptocurrency community. The DAO was a smart contract built on Ethereum and styled itself as a kind of autonomous investment fund. Rather than stodgy, old top-down-managed investment funds, the DAO would make investments as determined by votes from its users and would be governed by the code in the smart contract, rather than the law.

Ethereum was a coin first conceived in 2013 by early Bitcoiner, Vitalik Buterin. The project raised funds in 2014 in a coin offering and the Ethereum finally went live in the summer of 2015. At this point, Ethereum was just a year old and the community was already engaging in some pretty ambitious projects. Vitalik was said to have wanted to initially build his smart contract platform on top of Bitcoin, however Bitcoin was not flexible enough to do what he wanted. It was not just the code and structure of Bitcoin, but also the community – smaller blockers such as Gregory Maxwell and Luke Dashjr – who saw this flexibility as a potential security risk. Therefore, naturally, Vitalik and most of the Ethereum community tended to side with the large blockers.

The blocksize war was, in effect, also a key recruiting sergeant for Ethereum. The Ethereum community could paint Bitcoin as old technology, inflexible and stuck with small 1 MB blocks. Ethereum, on the other hand, had a much more flexible approach, a dynamic blocksize limit which miners could adjust (in Ethereum, this is called the gas limit and the constraint relates the computational power necessary to process various functions within the blocks, not the amount of data used). While transaction fees were starting to increase on Bitcoin, Ethereum fees were very low. This marketing strategy from Ethereum proved very successful, and many Bitcoiners switched their focus to Ethereum, believing that Ethereum was the young, dynamic coin of the future.

To some of the large blockers, Bitcoiners switching over to Ethereum was a problem caused by the small blockers. Small blockers had been so incredibly stubborn that people lost patience and were driven away.61 Bitcoin was now set to lose market share. Merchants may eventually adopt Ethereum, and then Bitcoin was sure to fail. While it is true that the blocksize limit was driving some people away from Bitcoin, this wasn’t the only reason for the success of alternative coins. The opportunity to make money was the primary driver of this trend. The success of Ethereum had driven a wave of copycats and new coin offerings. These coins would often highlight Bitcoin’s supposed and well-publicised scalability problems and claim their new coin solved these issues. The small blockers did not seem to mind this at all. They were interested in a transformational monetary system; alternative coins claiming to do 40,000 transactions per second didn’t seem relevant to that objective.

Ironically, although these alternative coins were a source of frustration to some of the larger blockers, they also found them tempting. It was easier for them to give up on Bitcoin and switch their focus to these alternative coins, rather than continue a tiresome battle. I cannot stress enough how much the small blockers benefited from this trend. The alternative coin space grew rapidly during this crisis, with their proponents focused on raising money in coin offerings and making money from coin price appreciation. Had this outlet not been available to these people, they may have stayed in Bitcoin fighting the blocksize war, and the sheer weight of numbers of large blockers would have been too large to overcome. During the two-year period of the war, there was a fundamental change in the ecosystem, from the Bitcoin space to the cryptocurrency space. In that environment, the argument that Bitcoin had to compromise for everyone made less sense. There was always a coin to suit people’s needs.

Anyway, back to The DAO. The DAO crowdsale launched on April 30, 2016 and lasted until May 25, 2016. It was attracting a huge amount of attention and raised more than US$150 million for the fund. This was an incredible amount of money in the space back then; more than 14 percent of all Ethereum in existence poured into The DAO. Some investors considered it risk-free, as one was always supposed to have the option to redeem the invested Ethereum from the fund if one wanted.

With Ethereum being so young, it was not at all ready for something as complicated as The DAO. But the Ethereum community liked to experiment and try new things. This is part of the reason they were attracted to Ethereum in the first place. They were bored of the conservative Bitcoiners.

As it turns out, The DAO was fundamentally flawed on several levels. The creation of new investment projects would have ended up creating new classes of DAO tokens, such that each class was entitled to different risks and rewards. This meant that DAO tokens would not be fungible and should trade at different prices, an issue poorly understood by exchanges and the community. The economic incentive model of the project also made little sense. For example, when it came to decisions on investments, there was little incentive to vote “no” on investment proposals, since “no” voters became invested in approved projects, while those who abstained never got exposure. Additionally, there was no stated mechanism for forcing successful projects to contribute profits back into The DAO and the code in the smart contract did not always appear to implement what was described or intended. A few weeks after the conclusion of the token sale, on June 17, 2016,62 (another key date in cryptocurrency history) a hacker found an exploit in the code that allowed them to access The DAO’s Ethereum funds and drain some of it into something called a “child DAO”, over which the hacker potentially had significant control.

This hacking event marked the start of the so-called “DAO Wars”, a battle to recover the “stolen” Ethereum from the hacker. Unfortunately, this was not proving successful, so the Ethereum community and developers came up with an idea: they could change the Ethereum protocol to help recover the funds. To some this was extremely controversial. It was seen as a bailout, something many in the community opposed. Part of the reason many joined the cryptocurrency space was that they wanted to avoid a system with bailouts, such as those of the banks in 2008 and 2009. After all, why was The DAO singled out? Why was this project rescued when many investors in smaller projects and smart contracts on Ethereum had lost money before? Perhaps The DAO was “too big to fail” or perhaps it was due to the self-interest of the influential developers and members of the Ethereum community, who had control over the protocol and who had invested large sums of money in The DAO. To many, these problems felt like a mirror image of the corruption and other problems in the traditional financial system they were keen to escape from.

On June 24, 2016, it was proposed that Ethereum conduct a softfork to freeze the hackers funds.63 Around four days later, it was discovered that this softfork proposal was flawed and would potentially expose the network to critical DoS attacks. Therefore, the softfork was abandoned and it was decided the only way to recover the funds was a hardfork. This is quite a remarkable turn of events, right when Bitcoin was in the midst of a war. With Bitcoin Classic still looming as a possible contentious hardfork, Ethereum was planning on a contentious hardfork of its own. Bitcoin’s blocksize war was essentially paused for a few months as everyone focused on Ethereum. To gauge the level of support for the hardfork, there was a coin vote: people could vote with their coins on whether or not they supported the hardfork. The vote was overwhelming, with more than 95 percent support for the hardfork.64 However, there were accusations that the poll was not representative, since it was primarily pushed by those who supported the hardfork and those who opposed may not have voted. In addition to this, participation from Ethereum holders was low, perhaps around six percent.65 Miners were also asked on their views and more than 90 percent were said to support the hardfork, a strong majority.

The hardfork was scheduled for Wednesday July 20, 2016. Keen not to miss the event, I booked the day and the following day off work. I also purchased a new computer, so that I would have enough local resources to run both Ethereum clients: one upgraded for the hardfork, and one older version. As the potential split approached, like a true cryptocurrency fanatic, I sat at home running both nodes, with many web tabs open on websites following the exchange order books, to see the live Ethereum prices as events unfolded. I, along with many other cryptocurrency enthusiasts, eagerly awaited the Ethereum block height to reach 1,920,000 and for the hardfork to occur.66

Initially, the hardfork appeared to happen successfully. The upgraded rules chain was extended, while the original rules chain had no blocks at all. Some of the larger blockers already started to declare victory and assert this was a lesson for Bitcoin: a contentious hardfork does not cause a split, they proclaimed. Around an hour after the fork, the original rules chain started to become extended. Then, as the difficulty adjusted downwards (a much faster adjustment than in Bitcoin) in the original rules chain, it started extending at a faster rate. While initially the hardfork chain appeared to have around 98 percent of the hashrate, the balance started to change and the original rules chain started to gain in momentum, achieving perhaps five percent to 10 percent of the hashrate. The original rules chain then required a name. Well, there was Bitcoin Classic, so why not call it Ethereum Classic?

Around three days after the split, exchanges started listing Ethereum Classic. Poloniex, one of the leading alternative coin exchanges at the time, listed Ethereum Classic on July 23, 2016.67 The price of Ethereum Classic then started to increase on the exchange. From memory, it started trading at around two percent of the value of Ethereum and peaked on July 25 at more than 50 percent of the price of Ethereum. Ethereum Classic was proving to be extremely volatile. What’s more, the miners were following the price. Not a perfect correlation exactly, but as the price of Ethereum Classic increased, more miners mined it in order to scoop up the increased block rewards. Small blockers then started to argue that the situation was more complex than the large blockers had argued: perhaps miners did not define the protocol, but instead followed traders and investors to maximise their profits.

As the price of Ethereum Classic increased, it gained more and more momentum. Miners, it appeared, just wanted to follow the money. This is when many people started to realise that a hardfork and contentious split was not just about two issues, hashrate and computer science, but financial markets too. This kind of event was an opportunity for financial speculators and traders, who could trade between the coins.

One of the key characters in the space supporting Ethereum Classic was Barry Silbert. Barry was no small blocker; it appeared he was buying Ethereum Classic purely to try and make money.

Bought my first non-bitcoin digital currency…Ethereum Classic (ETC). At $0.50, risk/return felt right. And I’m philosophically on board.68

Barry had founded Digital Currency Group a year earlier and was one of the largest investors in the space. Barry was also well known in the community for having won the auction to purchase the Bitcoin which US authorities had confiscated from the darknet marketplace, the Silk Road. Barry will feature more in the story later on. However, for now he inadvertently appeared to be assisting the small block side.

There was no danger of Ethereum Classic gaining too much momentum, overtaking Ethereum in hashrate and then causing all the hardfork nodes to switch over to the Classic chain. Vitalik was too smart for that. The Ethereum hardfork was structured such that it had a checkpoint, a clean break, so that both sides of the split would exist no matter which chain had more work. This is sometimes called “wipeout protection” and is something I had carefully clarified with Ethereum developers before the split. Bitcoin Classic’s decision not to include wipeout protection now looked even more naive.

Coinbase only added support for Ethereum on July 21, 2016,69 ironically just one day after the split. The company was a supporter of Bitcoin Classic and its CEO, Brian Armstrong, believed that the Ethereum hardfork would succeed without a split, presumably because the hardfork had strong support from the miners. As a result of this belief, Coinbase appeared to fail to take appropriate action to safeguard customer funds in case this judgement proved to be false. Coinbase was therefore vulnerable to something called the “replay attack”. In the first few days after the split, when withdrawing Ethereum from Coinbase, there was a chance that Coinbase would send out two versions of this transaction: one on Ethereum and one on Ethereum Classic. In contrast to this, Coinbase’s peers, such as Kraken and Poloniex, had taken measures to split their coins and prevent this. Some sophisticated traders in the space were able to capitalise on this oversight by Coinbase. They could split their coins themselves into Ethereum Classic and Ethereum, then deposit the Ethereum to Coinbase. Without trading, the Ethereum could be withdrawn from Coinbase, and the trader would hope to get replayed and get sent Ethereum Classic for free. I was speaking to several people at the time who were claiming they had successfully pulled off this “trade”, making significant profits. Eventually, Coinbase found out about the error, implemented some form of replay protection and covered the losses from its own balance sheet.

As for the DAO Wars, due to the hardfork, the recovery of the “stolen” funds on the Ethereum side of the split was successful. As for “stolen” funds on the Classic side of the split, this was more complicated, and The DAO wars continued. There were also other issues, such as who should get the recovered DAO tokens on the Classic side of the split, inside the various buckets and child DAOs, but this is beyond the scope of our story.

At the end of July 2016, there was another meeting arranged between the Bitcoin miners and developers, this time taking place in California. Keen to avoid the trap of being accused of reaching an agreement behind closed doors again, all participants were required to sign the following statement in order to attend:

Participants recognize that because bitcoin consensus rules are decided by the users based on the software they choose to run, so proposed changes must be discussed in public with input from the whole bitcoin community. For these reasons, there will be no agreements or roundtable consensus coming out of this event.70

Please note that I was not present at this meeting. However, meeting notes have been provided by Bitcoin developer Bryan Bishop.71 Bryan did an exceptional job transcribing many of the events and discussions in the blocksize war. The three-day event was attended by Jihan Wu, who had flown over to the US to meet the developers. The transcript does not attribute comments to particular names, however for those familiar with the main characters in the space, in many cases it is possible to determine who the speaker is. The timing of the event was no accident: it was scheduled for the end of July, right when the code for the hardfork was due to be released, according to the Hong Kong agreement.

At this meeting, the impact of the Ethereum split on Bitcoin’s possible hardfork was evident, and much of the discussion was about what lessons could be learnt. Participants were now claiming it was almost inevitable that a hardfork would cause a split:

Because of this split in Ethereum, it sets a precedent for Bitcoin for the possible future of hard-forks. For bitcoin, a hard-fork there can only be two options. One side must accept multiple chains, multiple attacks from multiple vectors, or we just stay on the main chain and try to kill the forks and the minority chains. There can only be two possibilities.

One of the developers then attempted to explain the situation and why it did not seem likely there would be a hardfork in the short term, despite the Hong Kong agreement:

Many of the [Hong Kong] agreement signers spent a week in [New York]. We did a lot of design work. We talked about how to properly construct a hard-fork. We talked about how we would do this in a way where we would not have the same risks that Ethereum has recently experienced. We talked about in [Hong Kong] how it is important for Bitcoin to remain unified and how it is important to the long-term value of Bitcoin. In [Hong Kong], and in [New York], there’s no desire to do anything that would be controversial. We would need consensus around any kind of hard-fork that would happen. It would have to be incredibly non-controversial. While it’s certainly the case that a lot of that research and many of those discussions should be made more broadly available, there’s certainly a lot of concern now that even from people outside this room that it would be very difficult to get that level of consensus around a hard-fork. I wanted to point out that hard-forks are very disruptive to markets. They are disruptive to merchants, to markets, to entire ecosystems. We have to take this into account. Unless there is an overwhelmingly strongly justified reason to do a hard-fork, then the costs outweigh the benefits. We have been looking at ways to solve these problems in Bitcoin without having a hard-fork.

Luke Dashjr, who was one of the signatories to the agreement, then explained that he had kept his commitment and written some code for a possible hardfork.72

One of the developers present, who presumably was not present in Hong Kong, apologised for undermining the efforts of the developers to produce code for the hardfork. The individual said that they felt it was not appropriate to work on the hardfork, when some miners were saying they would block SegWit. This individual was expressing concern that a hardfork would distract from the blocksize increase in SegWit. He also complained about public comments on preventing SegWit in order to get a hardfork, and that this was essentially a threat, a contribution to tension which made a hardfork more difficult.

I would like to apologize to you, and to the developers, for undermining their efforts to produce this material for you regarding their commitments. I did so because their efforts in New York came right after some public comments about blocking segwit regarding a hard-fork. In that environment, I felt very uncomfortable about hard-fork proposals slowing the scaling of bitcoin through segwit. I regret the climate that my comments created. I am sorry for that and for my comments.

There was then a response to this comment, presumably from Jihan Wu, in which he perceptively highlighted the bad communication spiral which both sides had gotten into. Jihan then implied that he also felt threatened, and that the threats were therefore coming from both sides.

I think I need to clarify this. [The] Segwit block also comes from the [idea] that the [Hong Kong] agreement would not be respected. It’s a very bad spiral that we have got into, in terms of bad communication. Maybe both parties don’t want to do something under pressure. Maybe both parties don’t want to be threatening.

After the event, I spoke to a well-known small blocker who was present at the meeting. He told me that Jihan had agreed to help to try and activate SegWit once it was released, and that miners were scared by the events in Ethereum and didn’t want to try anything risky. As for the commitment to activate SegWit, this may have been optimistic and Jihan may have had a different account of these events. It is not hard to imagine that there could have been further communication issues.

The Ethereum split was a pivotal moment in the blocksize war, even more so than the embarrassing Craig Wright saga. It handed the initiative to the small blockers. The miners were now terrified of a similar event occurring in Bitcoin. Prior to the Ethereum split, miners were keen to just try something; now the view seemed to have changed. Bitcoin Classic now looked unlikely to activate in the short term. Ironically, although most small blockers won’t like to admit this, Ethereum may have saved Bitcoin. However, the war was far from over. People had short memories in the space, and the lessons from Ethereum would gradually fade from memory.

61

https://www.reddit.com/r/btc/comments/4u0cuq/congratulation_small_blockers_this_is_a_direct/

62

http://archive.is/76EZY

63

http://archive.is/7UUrY

64

https://futurism.com/the-dao-heist-undone-97-of-eth-holders-vote-for-the-hard-fork

65

https://medium.com/coinmonks/the-dao-is-history-or-is-it-47a6f457338a

66

http://archive.is/PaGgM

67

http://archive.is/xfvMY

68

https://twitter.com/BarrySilbert/status/757628841938472961

69

https://blog.coinbase.com/coinbase-adds-support-for-ethereum-b8046cf486d0

70

https://www.coindesk.com/no-scaling-agreements-industry-bitcoin-meetup

71

https://diyhpl.us/wiki/transcripts/2016-july-bitcoin-developers-miners-meeting/cali2016/

72

https://github.com/luke-jr/bips/blob/bip-mmhf/bip-mmhf.mediawiki

링크 복사하기X에 공유페이스북에 공유쓰레드에 공유