본문으로 건너뛰기

제12장 – 비트코인 언리미티드

한글

책 블록 크기 전쟁의 제12장을 아래에 게재합니다. 전체 책은 Amazon에서 구할 수 있습니다. 안내 말씀으로, 종이책 판매에서 발생하는 모든 이익의 50%는 분쟁과 전염병과 재난 또는 의료 서비스에서 배제되어 영향을 받는 사람들에게 의료 지원을 제공하는 자선 단체인 Médecins Sans Frontières에 기부됩니다.*

* 참고: 다음 중 더 이른 시점까지의 판매에 적용됩니다. i. 저자의 사망, ii. 2031년 1월

비트코인 클래식이 동력을 얻는 데 실패하면서, 2016년 늦여름에 큰 블록 지지자들은 비트코인 언리미티드라고 불리는 새로운 하드포크 블록 크기 증가 클라이언트로 결집했습니다. 이 클라이언트는 단순히 블록 크기 제한 상한을 없애고 무제한 블록 크기를 허용할 것이라고 생각하기 쉽습니다. 실제로 그랬다면 비트코인 언리미티드는 훨씬 더 성공적인 제안이 되었을 가능성이 큽니다. 그러나 비트코인 언리미티드를 더 자세히 살펴보면 매우 복잡할 뿐만 아니라 기술적으로도 깊은 결함이 있었습니다. 이렇게 복잡하고 취약한 제안으로 결집한 것은 큰 블록 지지자들의 또 다른 기념비적인 전략적 실수였습니다. 작은 블록 지지자들의 진영에서는 이 전개에 기뻐하면서도 이를 조용히 유지하는 데 중점을 두었는데, 이는 큰 블록 지지자들을 이 취약한 클라이언트와 계속 연결되게 하려는 속임수였습니다. 비트코인 언리미티드는 단순한 클라이언트가 아니라 회원 제도와 회칙과 회장과 회원 투표를 갖춘 공식 조직이기도 했습니다.

비트코인 언리미티드 뒤에 있는 핵심 아이디어는 채굴자와 사용자가 블록 크기와 관련된 매개변수를 클라이언트에 추가한다는 것이었습니다. 이들은 다음과 같습니다. i. 최대 생성 MG 크기, 채굴자에게만 해당합니다. 블록을 생성하는 채굴자가 초과하지 않을 로컬 블록 크기 제한입니다. ii. 과도한 블록 크기 EB. 노드와 채굴자가 수용할 블록의 크기입니다. iii. 수용 깊이 AD. EB보다 크더라도 노드가 수용하기 전에 블록이 필요로 하는 확인 횟수입니다. 이에 대한 비판자들은 모든 사람이 각자 규칙을 정하면 네트워크가 수렴하지 못한다고 주장했습니다. 이 제안은 채굴자들이 가장 많은 작업이 축적된 유효한 체인 위에 블록을 쌓는다는 비트코인의 핵심 합의 기능에서 벗어납니다. 그에서 벗어날 뿐만 아니라 AD 개념을 도입하는데, 이에 따르면 채굴자들은 처음에는 더 짧은 유효 체인 위에 블록을 쌓으려 시도하다가 경쟁에서 지면 몇 블록 앞서 있는 더 긴 체인으로 옮겨갈 수 있으며, 그 체인은 그때 갑자기 유효해집니다. 비트코인 언리미티드에는 XT나 클래식 같은 활성화 방법이 없었고, 채굴자들이 업그레이드하면 어떻게든 새로운 비트코인이 될 것이라고 가정했을 뿐입니다. 따라서 많은 사람들에게 이전 제안들보다 더 극단적인 제안으로 여겨졌습니다.

비트코인 언리미티드에 대해 더 알기 위해 2016년 12월 초에 저는 선전(중국)에서 열린 비트코인 언리미티드 홍보 행사에 참석했습니다. 행사에서 연설하고 홍보 순회에 참여한 사람들은 비트코인 언리미티드의 열렬한 홍보자인 로저 버와 제이크 스미스와 Bitcoin.com의 여러 직원과 비트코인 언리미티드 조직의 회원들과 비트코인 언리미티드 개발자들 중 일부와 그리고 채굴 풀 ViaBTC의 최고경영자인 하이포 양이었습니다.

첫 번째 연설자는 로저 버였으며 중국어 통역이 제공되었습니다. 그는 매우 명확하고 설득력 있게 말하며 다음과 같은 요점들을 말했습니다.

  • 그는 비트코인 스타트업에 투자한 첫 번째 사람이었습니다.

  • 2009년 비트코인이 출시된 때부터 2015년까지 블록이 가득 차지 않았고 거래 수수료가 저렴했습니다. 비트코인 코어에는 블록을 가득 채우려는 의도적인 전략이 있으며, 이는 중대한 경제적 변화입니다.

  • 낮은 거래 수수료가 이 시점까지 비트코인을 성공하게 했습니다.

  • 의도는 언제나 블록 크기 제한을 높이는 것이었고 이는 모든 사람이 명시적으로 밝혔지만, 이제 새로운 사람들이 나타나 이를 막고 있습니다.

  • Reddit에서 광범위한 검열이 있으며 블록 크기 제한을 높이는 제안은 논의될 수 없습니다. 따라서 비트코인 코어는 사람들이 스스로 판단하도록 두지 않으려 합니다.

  • 비트코인 코어는 컴퓨터 코드는 이해하지만 경제 코드는 이해하지 못합니다.

  • 비트코인 코어는 비트코인이 높은 수수료의 은행 간 정산 네트워크가 되기를 원합니다. 사토시는 비트코인이 P2P 전자 현금, 즉 백서의 제목이 되기를 원했습니다.

  • 대기 중인 알트코인들이 있으며, 블록 크기가 증가하지 않으면 비트코인이 더 이상 쉽고 편리하게 사용되지 못해 이들 코인이 비트코인의 네트워크 효과를 빼앗아 갈 것입니다.

저는 로저가 이러한 요점들 중 다수를 말하는 것을 이전에 본 적이 있었습니다. 로저가 전 세계를 돌며 이러한 메시지를 반복해서 전하는 끈질김과 반복성은 놀라웠습니다. 로저는 매우 높은 확신을 가진 것으로 보였고 그의 메시지에서 분명히 매우 효과적이고 설득력이 있었습니다. 로저는 큰 블록 진영을 위한 냉혹하고 왕성한 운동가였습니다.

로저는 연설을 마치며 채굴자와 사용자가 비트코인 코어에서 비트코인 언리미티드로 전환해야 한다고 말했습니다. 그러나 그는 비트코인 언리미티드에 존재하는 새로운 작동 방식에 대한 세부 사항은 전혀 설명하지 않았습니다. 며칠 뒤 홍콩에서 비슷한 구성의 비트코인 언리미티드 행사가 있었습니다. 저는 로저가 과거처럼 외부 사람들과 새로운 상인들에게 이 분야를 홍보하는 대신 모든 힘을 이 내부 갈등에 쏟고 있는 것이 얼마나 안타까운 일인지 생각했던 기억이 있습니다.

선전에서의 다음 연설자는 제리 찬이었습니다. 제리는 이머전트 컨센서스 EC라는 아이디어에 대해 말했는데, 이는 시스템의 규칙이 위에서 개발자들에 의해 부과되는 것이 아니라 아래로부터 자연스럽게 생겨난다는 아이디어입니다. EC는 채굴자와 노드가 각자 규칙을 정하면 모두 다른 체인으로 흩어질 것이라는 우려를 다루기 위해 설계된 시스템이었습니다. 이 모형에서는 채굴자들이 블록 크기 제한을 스스로 정할 수 있으며, EC 체계 덕분에 모두 하나의 체인으로 수렴한다고 그는 설명했습니다. 제리는 자연에서 나타나는 이 과정의 여러 예를 들었습니다.

사물은 스스로 조직화될 것입니다. 자연에서 이를 볼 수 있습니다. 물 분자들은 눈송이로 조직화되는데, 왜 그럴까요, 신 때문이 아니라 물 분자들이 육각형 방식으로 스스로 정렬하여 눈송이 같은 것을 형성하도록 배열되어 있기 때문입니다. 새들을 보십시오, 앞에서 나는 새를 따르는 법을 새에게 가르치는 사람이 있습니까. 없습니다. 새들은 수백 킬로미터를 날면서 말 그대로 잠들 수도 있는데도 여전히 충돌하지 않습니다. 채굴자나 사람들이 결정하도록 두면 개같은 일이 벌어질 것이라고 코어는 여러분이 믿게 할 것입니다. 이머전트 컨센서스에서는 블록 제한이 자연스럽게 생겨날 것입니다.

물론 현재 비트코인 규칙이 위에서 비트코인 코어에 의해 부과되었다는 제리의 묘사는 작은 블록 지지자들이 시스템을 보는 방식을 잘못 전한 것이었습니다. 작은 블록의 세계에서는 규칙이 사용자들이 이미 운영하고 있는 노드들에 의해 정해졌습니다. 이러한 규칙은 매우 잘 바뀌지 않으며 이를 바꾸려면 공동체 전반의 광범위한 합의가 필요합니다. 큰 블록 지지자들은 이를 이해하지 못했거나, 자신들의 제안에 유리한 설득력 있는 논거가 되지 않았기 때문인지 이 관점을 정확히 설명하지 못하는 것처럼 보였습니다.

자연에서는 많은 체계가 그러한 계획이나 규칙에 대한 합의 없이도 수렴하거나 구조를 가진 것처럼 보인다는 견해가 비트코인에 얼마나 관련이 있는지는 분명하지 않았습니다. 이 시점에서 비트코인은 이미 매우 성공적이었고, 네트워크는 7년 동안 비교적 순조롭게 작동하며 여러 문제를 극복해 왔습니다. 이는 공동체에 어느 정도의 안일함을 낳은 것으로 보였고, 사람들은 체계의 견고성에 대해 지나치게 낙관적인 견해를 가지고 있었습니다. 비트코인 언리미티드의 잠재적 약점들에 대해 질문받으면 그 지지자들은 종종 비트코인이 안티프래자일하므로 항상 작동할 것이라고 말했습니다. 비트코인이 너무 강해서 비트코인에 잘못되거나 나쁜 일을 하는 것이 거의 불가능하므로 비트코인 언리미티드가 견고하다는 논거는 저에게는 믿기 어려울 정도로 약해 보였습니다.

세 가지 매개변수에 더해 비트코인 언리미티드에는 스티키 게이트라고 불리는 것도 있었습니다. 노드의 AD 임계값이 넘어서면 그 노드는 24시간 동안 어떤 크기의 블록도 수용했습니다. 여기서의 이유는 더 큰 블록들이 연속으로 생성되어 블록 크기가 증가한 뒤에 노드가 팁보다 AD 블록만큼 뒤처진 상태로 멈추는 것을 막기 위한 것이었습니다. 의도하지 않고 아이러니하며 역설적인 결과로, 24시간 안에 블록 크기 제한이 한 번 더 증가하면 더 낮은 블록 크기 제한 EB를 가진 클라이언트들은 더 큰 블록 체인을 따르고, 더 큰 제한을 가진 클라이언트들은 더 작은 블록 체인에 머무를 수 있었습니다. 비트코인 언리미티드는 제대로 만들어지지 않았고 여러 상황을 충분히 생각하지 않은 것처럼 보였습니다. 이는 이 시점에 큰 블록 진영이 얼마나 절박해졌는지를 보여주었습니다.

비트코인 언리미티드에는 미디언 EB 공격이라고 불리는 것을 비롯해 여러 다른 결함이 있었습니다. EB가 본질적으로 합의 규칙이었고 채굴자들이 선택한 EB 매개변수가 그들의 블록에 포함되었으므로 공격자들은 네트워크에서 EB 값들의 분포를 볼 수 있었습니다. 이는 적대적인 채굴자가 예를 들어 미디언 EB 값을 선택해 체인과 채굴 해시레이트를 임의의 크기를 가진 두 집단으로 나눌 수 있게 했습니다. 이는 치명적인 약점으로 보였습니다. 이에 대해 질문받으면 비트코인 언리미티드 지지자들은 전형적으로 채굴자들이 어리석지 않으며 이런 일이 일어나도록 두지 않을 것이라고 논거를 폈습니다. 그들은 또한 이를 막기 위해 채굴자들과 사용자들이 모두 같은 EB 값으로 수렴할 것이라고 주장하기도 했습니다. 그러나 분할을 막기 위해 채굴자들과 사용자들이 모두 같은 EB 값으로 수렴한다면 이는 하나의 규칙 집합으로 수렴한다는 작은 블록 지지자들이 옹호하는 보안 모형과 상당히 유사해 보였습니다. 비트코인 언리미티드에서 블록 크기 제한을 높이려면 EB 설정을 더 큰 값으로 옮기는 전환이 필요하고 그러면 이 취약점이 다시 열리게 됩니다.

비트코인 언리미티드는 블록 크기 제한과 직접 연결되지 않은 다른 변경 사항들도 소프트웨어에 적용했습니다. 비트코인 언리미티드 개발자들은 비트코인 코어의 compact blocks라는 유사한 체계와 대비되는 xThin이라는 블록을 더 빨리 전파하는 기술을 만들었습니다. 파이프라인에는 병렬 블록 검증과 플렉서블 트랜잭션 같은 다른 아이디어들도 있었습니다. 플렉서블 트랜잭션은 세그윗과 비슷한 새로운 거래 형식으로 거래 가단성을 고친다고도 말해졌습니다. 계획은 옛 형식의 거래를 완전히 금지하고, 즉 옛 형식 거래에 대한 블록 크기 제한을 0으로 하고, 모든 사용자가 새로운 거래 형식을 채택하도록 강제하는 것이었습니다. 아이러니하게도 이는 비트코인 언리미티드 개발자들이 반대한 세그윗의 훨씬 더 공격적인 버전이었습니다. 세그윗은 본질적으로 옛 거래에 대한 기존 1 MB 제한을 유지하고 새로운 거래를 위한 블록 공간을 더했습니다.

따라서 이러한 기능과 제안들 중 다수는 기술적 편의에 의해 추진된 것이 전혀 아닌 것처럼 보였습니다. 대신 문화와 자존심과 그리고 비트코인에 참여하고 싶은 욕망에 관한 것이었습니다. 이 시점에 대부분의 큰 블록 지지자들은 작은 블록 지지자들과 비트코인 코어 개발자들을 그저 싫어했습니다. 그들은 작은 블록 집단이 비트코인을 통제한다는 인식을 싫어했고 비트코인의 일부가 되기를 원했습니다. 더 많이 참여하고 싶은 욕망 때문에 비트코인 언리미티드는 단순한 블록 크기 제한 증가를 넘어 권한을 넓혀 여러 영역을 다루었습니다. 이는 결국 실수임이 드러났고 비트코인 언리미티드의 몰락으로 이어질 것이었습니다. 블록 크기 전쟁이 끝난 뒤 비트코인 언리미티드 공동체의 일부는 결국 이러한 오류들을 인정했습니다.

BU가 큰 블록 집단 중 가장 많은 동력을 가졌던 시절에 우리 중 몇 명은 BU가 복잡한 블록 크기 알고리즘, 이머전트 컨센서스를 공동체 전체가 채택하도록 하려 하기보다 먼저 코어 위에 단순한 블록 크기 증가에만 집중해야 한다고 생각했습니다. 우리는 또한 BU가 당분간 자체적인 약한 블록 버전을 구현하려는 시도를 중단하기를 원했습니다. 중요한 쟁점은 블록 크기를 늘리고 가능한 한 적은 방해 요소와 함께 코어에서 갈라져 나오는 것이었습니다. BU가 단순성에 집중하는 대신 복잡한 코드를 잔뜩 추가하려 고집한 것이 역효과를 내어 BU 코드에 여러 버그가 생겨 노드들이 충돌했습니다. 이는 전체 비트코인 공동체에게 BU 개발자들이 견고한 코드를 작성하거나 그들의 코딩과 테스트 역량을 고려해 야망의 규모를 적절히 조절하는 일을 신뢰할 수 없다는 인상을 주었습니다.

공동체의 다른 한 사람은 다음과 같이 말했습니다.

돌이켜보면 EC는 엄청난 실수였습니다.

놀랍게도 이러한 잠재적 보안 약점들에도 불구하고 비트코인 언리미티드는 Coinbase의 브라이언 암스트롱부터 개빈과 지한 우와 로저 버에 이르기까지 큰 블록 진영 전반의 지지를 받았습니다. 이들 중 누구도 뉘앙스와 관련된 새로운 매개변수들에 특별히 관심이 있는 것 같지 않았습니다. 그들은 그저 더 큰 블록을 원했습니다. 비트코인 언리미티드는 ViaBTC와 GBMiners와 BTC.TOP을 포함한 채굴 풀들의 지지도 얻고 있었고 노드 채택도 늘어나는 것처럼 보였습니다. 이를 처음 지지한 풀은 ViaBTC로, Bitmain에서 투자를 받았고 대체로 지한 우의 통제 아래 있는 것으로 보이는 채굴 풀이었습니다. BTC.TOP 풀도 Bitmain이 통제하는 것으로 여겨졌습니다. 2017년 초에 비트코인 해시레이트의 약 15에서 20퍼센트가 비트코인 언리미티드에 대한 지지를 표시했습니다. Bitmain은 Antpool 같은 풀도 직접 운영했는데, 이 풀은 2017년 3월에 비트코인 언리미티드에 대한 지지를 표시하기 시작했습니다. 이로써 채굴자들 사이에서 비트코인 언리미티드에 대한 지지가 45에서 55퍼센트 범위로 늘었고, 이 수준은 2017년 대부분 동안 유지되었습니다.

여러 비트코인 개발자들과 작은 블록 지지자들은 일부 채굴자들이 Bitcoin Unlimited를 지지하는 투표를 조작했다고 비난했습니다. 이들은 풀 운영자들이 여전히 블록을 생산하는 데에는 Bitcoin Core를 사용하면서도, 풀 설정을 바꾸어 블록에 Bitcoin Unlimited 관련 데이터를 추가했다고 비난했습니다. 이들은 블록 안의 트랜잭션들을 살펴봄으로써 이를 파악할 수 있었는데, 그 트랜잭션들은 Bitcoin Unlimited가 구현하지 않은 Bitcoin Core의 새로운 알고리즘을 이용해 선택된 것으로 보였습니다. 이러한 겉보기상의 가짜 투표들은 때로 거짓 깃발이라고 불렸습니다. Bitcoin Unlimited 자체를 나쁘다고 여긴 일부 작은 블록 지지자들은 이러한 가짜 깃발을 한층 더 악의적인 행위로 보았습니다. 자신들이 어떤 합의 규칙을 강제하고 있는지에 대한 채굴자들의 신호 표시는 프로토콜 규칙의 원활한 업그레이드를 보장하기 위한 장치여야 했습니다. 거짓 깃발 표시는 업그레이드를 더 위험하게 만드는 접근으로 여겨졌습니다. 실제로 Bitcoin Unlimited에 유리한 거짓 깃발 표시는 활성화 실패를 일으킬 수 있다는 점에서 Bitcoin Unlimited에 대한 공격으로 볼 수 있습니다. 큰 블록 지지자들은 이를 제대로 이해하지 못한 듯했고 Bitcoin Unlimited에 대한 해시레이트 지지가 늘어나자 흥분하며 반응했습니다. 이들에게 이는 상당한 동력이 쌓이는 것이었습니다. 그 투표들이 가짜인지 여부와 관계없이 채굴자들의 깃발 표시는 중요한 정치적 메시지였습니다.

2017년 1월 30일에 Bitcoin Unlimited를 실행하던 한 채굴자가 1 MB보다 큰 블록을 생산했습니다. 이는 충분한 작업 증명을 갖춘 1 MB 초과 블록으로는 처음 생산된 블록이었을 수 있습니다. 이 일의 배후에 뚜렷한 조율이 없었으므로 이는 아마 어떤 종류의 오류나 사고였을 것입니다. 네트워크 전반의 비트코인 노드들은 그 블록을 무효하다고 하여 거부했으며, 이는 작은 블록 지지자들에 따르면 하드포크를 실행하기 전에 사용자 합의가 필요한 이유를 보여주는 사례였습니다. Roger Ver와 같은 큰 블록 지지자들은 이 블록이 단지 스테일이 아니라 무효하다는 점을 인정하지 않은 채 스테일 블록은 항상 발생한다고 주장하면서 이 사건을 덮으려 했습니다.

2017년 3월에 Bitcoin Unlimited의 평판에 상당한 손상을 입힌 사건이 발생했습니다. 도달 가능한 Bitcoin Unlimited 노드 수가 갑자기 급격히 떨어졌습니다.

nodecounter에 따르면 GMT 기준 오후 6시경에는 776개 노드가 있어 상태가 괜찮았습니다. 그 수가 빠르게 떨어져 GMT 기준 오후 7시에는 696개 노드가 되었습니다. 오후 11시에는 182개 노드로 바닥을 쳤습니다. 다음 날 GMT 기준 오전 9시에는 626개 노드로 대부분 정상으로 돌아왔습니다. BU가 비정상적으로 빠르게 대응했다거나 100%의 노드가 돌아왔다고 말하는 것은 그다지 정확하지 않다고 생각합니다.

일어난 일은 Bitcoin Unlimited 코드의 xThin 요소에 치명적인 DoS 버그가 들어갔는데, 이는 블록 크기 제한과는 아무 관련이 없었습니다. 이 버그가 악용되어 거의 모든 Bitcoin Unlimited 노드가 다운되었습니다. 이 문제는 작은 블록 지지자들에 의해 부각되었고, 이들은 많은 암호화폐 매체들이 이 실패에 주목하도록 도왔습니다. 노드 다운은 또한 이 프로젝트를 더 넓은 큰 블록 공동체의 더 엄격한 검증 아래에 두었습니다. 많은 사람들은 그것을 일반적인 큰 블록 클라이언트로만 생각했었지만, 이제는 더 비판적인 질문들을 던지고 있었습니다. 예를 들면 이런 질문들이었습니다. 이 조직은 무엇입니까, 그리고 왜 회장이 있습니까. 블록 크기와 관련 없는 코드 부분을 왜 바꾸고 있습니까. AD 매개변수는 무엇을 위한 것입니까. 다른 치명적인 버그가 있습니까.

Bitcoin Unlimited는 2017년 3월의 사건에서 완전히 회복하지 못했습니다. 그 오류 자체는 실제로 그리 심각하지 않았지만, 작은 블록 지지자들은 그 버그를 성공적으로 활용했고, 이는 Bitcoin Unlimited의 다른 실패들에 주목을 끌었습니다. Bitcoin Unlimited 이야기는 큰 블록 지지자들에게 전쟁 기간 중 최악의 시기 중 하나였고, 아마도 그들이 차라리 잊고 싶은 시기였습니다. 작은 블록 지지자들을 매우 기쁘게 한 점은, 큰 블록 지지자들이 자아와 분노와 좌절에 이끌려 제대로 구상되지 못한 클라이언트를 지지했다는 것입니다. 다시 한번 Bitcoin Unlimited가 버려진 뒤에도 큰 블록 지지자들 중 누구에게서도 거의 반성이 없었습니다. 그들 중 누구도 책임을 지려 하거나, 그토록 많은 잠재적 약점을 가진 클라이언트를 밀어붙이는 것이 왜 비트코인에 위험하고 잠재적으로 파괴적인지 생각하는 것처럼 보이지 않았습니다.

2017년 3월까지 공동체의 긴장은 한층 더 고조되었습니다. 이제 초점은 큰 블록 지지자들이 Bitcoin Unlimited로 옮겨간 뒤 빈 블록을 채굴하고 트랜잭션이 들어 있는 모든 블록을 고아로 만들면서 원래의 작은 블록 체인을 공격할 것이라는 생각으로 옮겨갔습니다. 따라서 이 전략은 작은 블록 체인을 죽일 것이었습니다. Jihan은 비트코인을 공격한다는 생각을 공개적으로 논의하기까지 했습니다.

그것을 공격하는 것이 필요하지 않을 수도 있습니다. 그러나 그것을 공격하는 것은 항상 선택지입니다.

Gavin도 비슷한 말을 했습니다.

소수 해시레이트 포크가 어떤 트랜잭션도 확정하지 못하도록 막는 것은 좋은 생각입니다. Nakomoto Consensus != 만장일치입니다.

이 시점까지 블록 크기 전쟁에서 대체로 벗어나 있었던 초기 비트코이너 Meni Rosenfeld는 상황을 다음과 같이 설명했습니다.

Gavin Andresen, Peter Rizun 그리고 Jihan Wu는 모두 다수 해시레이트 체인이 소수를 공격할 가능성(이기적 채굴과 빈 블록 DoS를 통한)을 호의적으로 논의했습니다.

이는 수치스러운 일이며 비트코인이 대표하는 모든 것에 반대됩니다. 비트코인은 자발적인 돈입니다. 사람들은 강제되어서가 아니라 선택해서 그것을 사용합니다.

이들은 기본적으로 우리 중 일부가 현재 Bitcoin Core 프로토콜이 정한 통화를 사용하고 싶어한다면, 대신 그들의 돈을 사용하도록 꾀어내기 위해 공격을 개시해도 괜찮다고 말하고 있습니다. 그러나 아닙니다, 괜찮지 않으며 부끄럽고 도덕적으로 파탄났습니다. 그들이 성공하더라도 그들이 얻게 되는 것은 비트코인이 아니라 법정화폐입니다.

진정한 유전적 다양성은 여러 프로토콜이 나란히 공존하면서 경쟁하고 가능한 가장 강한 버전의 비트코인으로 진화할 때에만 얻을 수 있습니다.

이는 BU 대 Core의 장점에 대한 특정 논쟁을 넘어섭니다.

이는 분명히 큰 블록 지지자들의 어조 변화였습니다. 이들은 이전에는 분할도 없을 것이고 더 작은 블록 전체장부도 없을 것이라고 주장했었지만, 이제는 그런 전체장부를 적극적으로 공격하는 것을 논의하고 있었습니다. 4월 초에 저는 홍콩에서 지한의 핵심 측근 중 한 명과 대화를 나누었습니다. 그는 큰 블록 지지자들이 작은 블록 전체장부를 공격하기 위해 1억 미국 달러의 예산을 배정했다고 알려주었습니다. 계획은 이 돈을 에너지에 써서 작은 블록 전체장부에서 빈 블록을 채굴하고 거래 내역이 있는 모든 블록을 고아로 만드는 것이었습니다. 이는 본질적으로 그 전체장부를 죽일 것이라고 그는 선언했습니다. 저는 왜 작은 블록 전체장부를 죽이려 하는지 물었고, 그는 작은 블록 지지자들이 수년간 비트코인을 정체시켰고 그래서 이것이 그들이 받을 마땅한 것이라고 설명했습니다. 전쟁에서 자신의 상대에게 복수하기 위해 1억 미국 달러를 쓰는 것을 상상하는 것만으로도 이 분쟁 시점에 우리가 빠진 수렁의 규모를 잘 보여줍니다. 1억 미국 달러를 다 쓴 뒤에는 어떻게 됩니까라고 저는 물었습니다. 그러면 작은 블록 지지자들이 그들의 전체장부를 되살릴 수 있지 않습니까. 이 질문에는 확실한 답이 없는 듯했습니다. 긴 침묵 뒤에 그는 아마 더 많은 자금을 모아 다시 공격할 것이라고 선언했습니다.

2017년으로 들어가고 전쟁이 18개월째에 접어들면서 양쪽의 고통은 더욱 커졌습니다. Jihan과 대부분의 채굴 풀들은 여전히 세그윗에 대한 지지를 표시하지 않고 있었고, 95퍼센트 목표는 달성하기가 거의 불가능해 보였습니다. 큰 블록 지지자들은 세그윗의 활성화를 자신들의 패배로 보았고, 세그윗을 막는 것은 그들이 가진 중요한 통제 지렛대 중 하나였습니다. 이는 큰 블록 지지자들에게 남은 유일한 주요 협상 카드였고, 그들은 그것을 놓지 않으려 했습니다. 이는 실제로 작은 블록 지지자들 사이에 좌절을 일으켰지만, 그들이 인내하는 쪽이자 수십 년 앞을 내다보는 쪽이었음을 기억합니다. 큰 블록 지지자들에게는 어떤 일이 일어나기를 기다리는 것이 훨씬 더 고통스러웠습니다. 이 고통은 작은 블록 체인을 공격하겠다는 위협을 설명하는 데 크게 기여합니다.

영문 — Chapter 12 – Bitcoin Unlimited

Chapter 12 of the book The Blocksize War is published below. The full book is available on Amazon. As a reminder, 50% of any profits from physical book sales will be donated to Médecins Sans Frontières, a charity that provides medical assistance to people affected by conflict, epidemics, disasters, or exclusion from healthcare.*

* Note: Applies to sales up until the earlier of i. the death of the author and ii. January 2031

With Bitcoin Classic failing to gain traction, in the late summer of 2016 the large blockers converged on a new hardfork blocksize increase client, called Bitcoin Unlimited. One would think this would simply remove the blocksize limit cap and allow unlimited blocksizes. Had this been the case, Bitcoin Unlimited was likely to be a far more successful proposal. However, when one looked in more detail at Bitcoin Unlimited, not only was it highly complex, it was also deeply technically flawed. Converging on such a complicated and weak proposal was another monumental strategic error from the large blockers. In small block circles, there was delight at this development, but also an emphasis on keeping this quiet, a ploy designed to keep the large blockers associated with this weak client. Bitcoin Unlimited was not just a client, but also a formal organisation, with a membership, by-laws, a president and membership voting.

The key idea behind Bitcoin Unlimited was that miners and users add parameters to their clients related to the blocksize limit. These are: i. Maximum generation (MG) size (only for miners): a local blocksize limit, which will not be exceeded by a miner producing a block; ii. Excessive blocksize (EB): this is the size of a block that a node and miner will accept; and iii. Acceptance Depth (AD): this is the number of confirmations a block requires before a node accepts it, even if it is larger than EB. Critics of this claimed that everyone setting their own rules means the network would not converge. This proposal diverges from the core consensus feature of Bitcoin: that miners build on the most work valid chain. Not only does it diverge from this, it introduces the AD concept, where miners could first try to build on a shorter valid chain, however if they lose a race, they could then jump ahead several blocks to a longer, now suddenly valid chain. Bitcoin Unlimited had no activation methodology like XT or Classic; it was just assumed to somehow become the new Bitcoin when miners upgraded. Therefore, it was considered by many as a more extreme proposal than its predecessors.

Keen to learn more about Bitcoin Unlimited, in early December 2016 I attended a Bitcoin Unlimited promotional event in Shenzhen (China). Speaking at the event and on the promotional tour was Roger Ver, a keen promoter of Bitcoin Unlimited; Jake Smith; several employees of Bitcoin.com; members of the Bitcoin Unlimited organisation; some of the Bitcoin Unlimited developers; and Haipo Yang, the CEO of mining pool ViaBTC.

The opening speaker was Roger Ver and Chinese translation was made available. He spoke very clearly and persuasively, making the following points:

  • He was the first person to invest in Bitcoin startups;

  • From 2009, when Bitcoin was launched, until 2015, the blocks were not full and transactions were cheap. Bitcoin Core has a deliberate strategy of full blocks, which is a major economic change;

  • The low transaction fees had made Bitcoin successful up until this point;

  • The intention was always to increase the blocksize limit and this was explicitly stated by everybody, but now new people have come along and are preventing this;

  • There is widespread censorship on Reddit and proposals to increase the blocksize limit cannot be discussed. Bitcoin Core therefore does not want people to make up their own minds;

  • Bitcoin Core understands computer code, but they don’t understand economic code;

  • Bitcoin Core wants Bitcoin to be a high fee, interbank settlement network; Satoshi wanted Bitcoin to be P2P Electronic Cash, the title in the whitepaper;

  • There are altcoins waiting in the wings and, if the blocksize does not increase, these coins will take over Bitcoin’s network effect, if Bitcoin is no longer easy and convenient to use.

I had seen Roger make many of these points before. The relentlessness and repetitiveness with which Roger could repeat these messages again and again, all over the world, was remarkable. Roger appeared to have a very high degree of conviction and he was clearly very effective and convincing in his messages. Roger was a ruthless and prolific campaigner for the large block camp.

Roger ended his speech by saying that miners and users should switch from Bitcoin Core to Bitcoin Unlimited. However, he never went into any details about the new mechanisms which existed in Bitcoin Unlimited. A few days later, there was a similarly structured Bitcoin Unlimited event in Hong Kong. I remember thinking how much of a shame it was that Roger was focusing all his energy on this internal conflict, rather than promoting the space to outsiders and new merchants as he had in the past.

The next speaker in Shenzhen was Jerry Chan. Jerry spoke about the idea of emergent consensus (EC), which is the idea that the rules of the system are emergent and not imposed in a top-down way by the developers. EC was a system designed to address the concern that if miners and nodes set their own rules, they would all diverge onto different chains. Under this model, he explained, miners are free to set the blocksize limit themselves and, due to the EC system, they would all converge on one chain. Jerry gave various examples of this process from nature:

Things will self organise. You see this is nature. Water molecules organise into snowflakes, why, it’s not because of god, it’s because the water molecules are arranged in a way that they will align themselves in a hexagonal way and form something like snowflakes. Birds, does anyone teach a bird how to follow the one in front? No. They can literally fall asleep while flying hundreds of kilometers and they still wont crash. Core will make you believe that bad shit will happen if you let miners or people decide things. Under emergent consensus a block limit will naturally emerge.

Of course, the characterisation from Jerry that the current Bitcoin rules were imposed from above by Bitcoin Core, was a misrepresentation of how small blockers saw the system. In the small block world, the rules were determined by the nodes that users already run. These rules are very sticky and changing them requires widespread agreement across the community. The large blockers never seemed able to accurately articulate this view, either because they didn’t understand it, or because this did not make as compelling an argument in favour of their proposals.

As for the view that, in nature, many systems appeared to converge or have structure, without such planning or agreement on the rules, it was not clear how relevant this was to Bitcoin. At this point, Bitcoin was already very successful; the network had been operating reasonably smoothly for seven years, overcoming any issues. This appeared to have generated a degree of complacency in the community, with people having an overly optimistic view of the robustness of the system. When questioned about some of the potential weaknesses in Bitcoin Unlimited, its supporters often said that Bitcoin was antifragile and that it would always work. The argument that Bitcoin Unlimited was robust because Bitcoin was so strong, that it was almost impossible to do anything wrong or bad to Bitcoin, seemed incredibly weak to me.

In addition to the three parameters, Bitcoin Unlimited also had something called the “sticky gate”. If a node’s AD threshold was breached, then it would accept blocks of any size for a period of 24 hours. The reasoning here was to prevent a node from being stuck AD blocks behind the tip, after a blocksize increase when a string of larger blocks was produced. An inadvertent, ironic and perverse consequence of this is that a further blocksize limit increase within 24 hours could cause clients with a lower blocksize limit (EB) to follow the larger block chain, and for clients with a larger limit to stay on a smaller block chain. It appeared as if Bitcoin Unlimited had been poorly constructed and the scenarios had not been thought through. This indicated just how desperate the large block camp had become by this point.

Bitcoin Unlimited had several other flaws, including something called the “median EB attack”. Since EB was essentially a consensus rule, and the EB parameter miners chose were included in their blocks, attackers could see the distribution of EB values in the network. This could allow a hostile miner to choose the median EB value, for example, to split the chain and mining hashrate into two arbitrarily-sized groups. This appeared to be a critical weakness. When questioned about this, Bitcoin Unlimited supporters would typically argue that miners are not stupid and they would not let this happen. They also sometimes asserted that, in order to prevent this, miners and users would all converge on the same EB value. However, if miners and users all converge on the same EB value in order to prevent a split, this seemed to be reasonably similar to the security model advocated by small blockers, of convergence on one set of rules. In order to increase the blocksize limit in Bitcoin Unlimited, there would need to be a transition of EB settings to a larger value and then this vulnerability would then open up.

Bitcoin Unlimited also made other changes to the software, not directly linked to the blocksize limit. Bitcoin Unlimited developers had built a technology to propagate blocks faster, called xThin, in contrast to a similar system in Bitcoin Core called compact blocks. There were other ideas in the pipeline too, such as parallel block validation and flexible transactions. Flexible transactions were a new transaction format, similar to SegWit, which was also said to fix transaction malleability. The plan was to ban old-style transactions completely (i.e. a blocksize limit of zero for old-style transactions) and then force all users to adopt the new transaction format. This was, ironically, a far more aggressive version of SegWit, which Bitcoin Unlimited developers opposed. SegWit essentially kept the old 1 MB limit for old transactions and added more blockspace for new transactions.

It therefore appeared that many of these features and proposals were not driven by technical expediency at all. Instead, it was about culture, ego and a desire to be involved in Bitcoin. Most of the large blockers by this point simply hated the small blockers and Bitcoin Core developers. They hated the perception they had that the small block group controlled Bitcoin, and they wanted to be part of Bitcoin. Due to this desire to be more involved, Bitcoin Unlimited expanded its remit beyond simply a blocksize limit increase and covered a variety of areas. This eventually proved to be a mistake and would lead to Bitcoin Unlimited’s downfall. After the blocksize war was over, some in the Bitcoin Unlimited community eventually conceded these errors.

Back when BU had the most momentum of any big block group, there were several of us who thought that BU should focus on just a simple block size increase on top of Core first, instead of trying to get the entire community to adopt a complicated block size algorithm (“Emergent Consensus”). We also wanted BU to stop trying to implement their own version of weak blocks for the time being. The critical issue was increasing block size and forking away from Core with as few distractions as possible. BU’s insistence on adding a bunch of complex code instead of focusing on simplicity backfired, as the BU code had several bugs causing nodes to crash. This gave the overall Bitcoin community the impression that BU devs couldn’t really be trusted to write solid code or to appropriately scale their ambitions to their coding/testing skill.

Another member of the community commented:

EC has been a massive mistake in hindsight.

Amazingly, despite all of these potential security weaknesses, Bitcoin Unlimited had support from across the large blocker camp, from Brian Armstrong at Coinbase, to Gavin, Jihan Wu and Roger Ver. None of these individuals seemed particularly interested in the nuances and the new parameters involved. They just wanted larger blocks. Bitcoin Unlimited was also gaining support from mining pools, including ViaBTC, GBMiners and BTC.TOP, while node adoption appeared to be on the rise as well. The first pool to support it was ViaBTC, a mining pool which had taken investment from Bitmain and appeared to be largely under the control of Jihan Wu. The BTC.TOP pool was also believed to be controlled by Bitmain. At the start of 2017, around 15 to 20 percent of the Bitcoin hashrate flagged support for Bitcoin Unlimited. Bitmain also directly operated pools, such as Antpool, which started flagging for Bitcoin Unlimited in March 2017. This increased support for Bitcoin Unlimited among miners to the 45 to 55 percent range, a level it stayed at for most of 2017.

Several Bitcoin developers and small blockers accused some of the miners of faking votes in support of Bitcoin Unlimited. They accused pool operators of changing the pool settings to add Bitcoin Unlimited-related data to the blocks, despite still using Bitcoin Core to produce the blocks. They were able to determine this by looking at the transactions in the blocks, which appeared to have been selected by using a new algorithm in Bitcoin Core, which Bitcoin Unlimited had not implemented. These apparent “fake votes” were sometimes called false flags. Some small blockers, who regarded Bitcoin Unlimited itself as bad, viewed these fake flags as further malicious behaviour. Miner signalling about which consensus rules they were enforcing was supposed to be a mechanism to ensure smooth upgrades to the protocol rules. False flagging was considered an approach that made upgrades more dangerous. Actually, false flagging in favour of Bitcoin Unlimited can be considered as an attack on Bitcoin Unlimited, as it could cause a failed activation. Large blockers didn’t seem to appreciate this and reacted with excitement as the hashrate support for Bitcoin Unlimited increased. To them, this was building up considerable momentum. The miner flags were an important political message, whether the votes were fake or not.

On January 30, 2017, a miner running Bitcoin Unlimited produced a block larger than 1 MB. This may have been the first block produced, with sufficient proof of work, over 1 MB. This was probably some kind of error or accident, as there was no apparent coordination behind this. Bitcoin nodes across the network rejected the block as invalid, which was an example, according to smaller blockers, of why one needed user agreement before conducting a hardfork. Large blockers, such as Roger Ver, tried to brush this incident under the carpet, claiming that stale blocks occur all the time, without accepting that this block was not just stale, but invalid.

In March 2017, an event occurred which caused significant damage to the reputation of Bitcoin Unlimited. The number of reachable Bitcoin Unlimited nodes suddenly took a massive nosedive.

According to nodecounter, things were fine at about 6 PM GMT, when there were 776 nodes. That rapidly dropped, with 696 nodes at 7 PM GMT. It bottomed out at 11 PM, with 182 nodes. At 9 AM GMT the following day, things were mostly back to normal, with 626 nodes. I don’t think it’s very accurate to say that BU reacted abnormally quickly, or that 100% of nodes came back.

What happened was a critical DoS bug was introduced into the xThin element of the Bitcoin Unlimited code, which had nothing to do with the blocksize limit. This had been exploited, causing almost all the Bitcoin Unlimited nodes to crash. This issue was highlighted by the smaller blockers, who helped draw attention to the failing to many cryptocurrency media outlets. The node crash also put the project under more scrutiny from the wider larger block community. Many had just thought of it as a generic larger block client, but now they were asking more critical questions, such as: what is this organisation, and why is there a president? Why are they changing aspects of the code not related to the blocksize? What is the AD parameter for? Are there any other critical bugs?

Bitcoin Unlimited never fully recovered from the incident in March 2017. The error itself was not really that bad, however the small blockers successfully capitalised on the bug, which drew attention to other failings in Bitcoin Unlimited. The Bitcoin Unlimited saga was one of the worst periods of the war for large blockers, and one they would probably rather forget. Much to the delight of the small blockers, they had allowed themselves to be driven by ego, anger and frustration to support a poorly-conceived client. Once again, after Bitcoin Unlimited was abandoned, there was almost no contrition from any of the larger blockers. None of them appeared to take responsibility, or consider why pushing for a client with so many potential weaknesses was dangerous and potentially destructive for Bitcoin.

By March 2017, the tension in the community had elevated even further. The focus now shifted to the idea that the larger blockers would move over to Bitcoin Unlimited and then also attack the original, smaller block chain by mining empty blocks and orphaning any blocks with transactions in it. This strategy would therefore kill the smaller block chain. Jihan had even publicly discussed the idea of attacking Bitcoin:

It may not be necessary to attack it. But to attack it is always an option.

Gavin had also said something similar:

Preventing a minority-hashrate fork from confirming any transactions is a good idea. Nakomoto Consensus != unanimity.

Early Bitcoiner Meni Rosenfeld, who had largely stayed out of the blocksize war up until this point, described the situation as follows:

Gavin Andresen, Peter Rizun and Jihan Wu have all favorably discussed the possibility that a majority hashrate chain will attack the minority (by way of selfish mining and empty block DoS).

This is a disgrace and stands against everything Bitcoin represents. Bitcoin is voluntary money. People use it because they choose to, not because they are coerced.

They are basically saying that if some of us want to use a currency specified by the current Bitcoin Core protocol, it is ok to launch an attack to coax us into using their money instead. Well, no, it’s not ok, it is shameful and morally bankrupt. Even if they succeed, what they end up with is fiat money and not Bitcoin.

True genetic diversity can be obtained only with multiple protocols coexisting side by side, competing and evolving into the strongest possible version of Bitcoin.

This transcends the particular debate over the merits of BU vs. Core.

This was clearly a change in tone from the large blockers. They had previously claimed there would be no split and no smaller block chain, while now they were discussing actively attacking such a chain. In early April, I had a discussion with one of Jihan’s key associates in Hong Kong. He informed me that the large blockers had allocated a budget of US$100 million to attack the smaller block chain. The plan was to spend this money on energy, mining empty blocks on the smaller block chain and orphaning any blocks with transactions. This would essentially “kill the chain”, he proclaimed. I asked why he wanted to kill the smaller block chain, and he explained that the smaller blockers had “stalled Bitcoin for years and that this was what they deserved”. Even to contemplate spending US$100 million just to get revenge on one’s opponents in the war really illustrates the scale of the quagmire we were in at this point in the conflict. What happens once the US$100 million had been spent? I asked. Couldn’t the small blockers revive their chain then? It seemed there was no robust response to this question. After a long pause, he proclaimed they would perhaps attempt to raise more money and attack again.

As we progressed into 2017 and the war entered its 18th month, the anguish from both sides only increased. Jihan and most of the mining pools were still not flagging support for SegWit, and the 95 percent target seemed almost impossible to achieve. Large blockers saw the activation of SegWit as a defeat for their side and blocking SegWit was one crucial lever of control they had. This was the only major bargaining chip the large blockers had left, and they would not let it go. This did indeed cause frustration among the smaller blockers, however remember that they were the patient side, the side that looked decades ahead. To the large blockers, the wait for anything to happen was far more painful. This pain goes a long way to explaining the threats of attacking the smaller block chain.

링크 복사하기X에 공유페이스북에 공유쓰레드에 공유