Byzantine Quorum Manipulation
Malicious validators vote for conflicting blocks or withhold votes to break safety or liveness. In BFT protocols this typically requires one-third of stake; in longest-chain protocols it can be done with a fraction of hash power or delegated stake.
The attacker splits their stake across two validator sets. In a BFT round they sign both PREVOTE and PRECOMMIT messages for conflicting blocks and broadcast them selectively. Without equivocation detection and slashing, honest nodes see different quorums and commit different forks. In PoW the attacker builds two private chains and releases the heavier one after the victim acts on the lighter one.
Safety failure: two conflicting blocks are finalized. Liveness failure: votes are withheld and rounds time out indefinitely. Economic finality evaporates.
- Adversary controls ≥ fault-tolerance threshold of voting power
- Votes are not aggregated into accountable quorum certificates
- Slashing conditions are absent or economically weaker than the attack payoff
Accountable safety proofs, slashing for equivocation, quorum certificate verification, and a fault tolerance below the adversarial threshold.
- Theoretical for most major BFT chains; practical for smaller PoS networks and sidechains.
- Several bridge hacks have exploited weak finality assumptions after a re-org or validator compromise.