Glossary

Denial-of-Service Attack (DoS)

A denial-of-service attack overwhelms a system with requests or data to make it unavailable to legitimate users.

Key Takeaways

  • A denial-of-service (DoS) attack floods a system with excessive requests or data to exhaust its resources and prevent legitimate users from accessing the service. In blockchain networks, this can target nodes, the mempool, or the peer-to-peer layer.
  • Blockchain-specific DoS vectors include transaction spam that fills blocks, computational attacks using underpriced operations, mempool flooding, and network-layer bandwidth exhaustion. The 2016 Ethereum DoS attacks demonstrated how underpriced opcodes could bring nodes to a halt.
  • Bitcoin's fee market and fixed block weight limit make sustained DoS economically prohibitive: every spam transaction competes for scarce block space and must pay real fees, turning the attack into a direct cost to the attacker.

What Is a Denial-of-Service Attack?

A denial-of-service (DoS) attack is a deliberate attempt to make a computer system, network, or service unavailable to its intended users. The attacker achieves this by overwhelming the target with more traffic, requests, or data than it can process, exhausting resources like CPU, memory, bandwidth, or storage. When the attack originates from many machines simultaneously, it is called a distributed denial-of-service (DDoS) attack.

In traditional web infrastructure, DoS attacks typically flood a server with HTTP requests or network packets until it can no longer respond. Blockchain networks face a different threat model. Because they are decentralized and peer-to-peer, there is no single server to take offline. Instead, attackers target the shared resources that every node must process: transactions, blocks, and peer-to-peer messages. A successful blockchain DoS attack degrades the network for all participants by increasing confirmation times, raising fees, or forcing nodes offline due to resource exhaustion.

How It Works

Blockchain DoS attacks exploit the fact that every node in the network must validate and relay transactions and blocks. If an attacker can craft transactions or messages that are cheap to create but expensive to process, they can asymmetrically burden the network. The core vectors fall into four categories.

Transaction Flooding

The most straightforward attack: an attacker broadcasts a large volume of valid transactions to fill blocks with spam. Because block space is finite (Bitcoin's block weight limit caps blocks at 4,000,000 weight units), spam transactions compete with legitimate ones for inclusion. This drives up fees via network congestion and delays confirmation for users who cannot or will not pay the inflated rates.

In 2015, Bitcoin experienced a sustained spam attack where an attacker broadcast thousands of small-value transactions (around 0.00001 BTC each), filling blocks to their 1 MB capacity at the time. Mining pools like F2Pool mined oversized blocks attempting to clear the backlog. The attack demonstrated how transaction flooding can degrade user experience even without breaking consensus.

Computational DoS

Rather than flooding volume, a computational DoS attack crafts transactions that are individually expensive for nodes to validate. The attacker exploits operations where the cost to include in a transaction is low but the computational or I/O burden on validating nodes is high.

The most prominent example occurred on the Ethereum network in September 2016, when attackers exploited the EXTCODESIZE opcode. This instruction had a gas cost of just 20 units but required nodes to perform disk reads for each call. Attack transactions called this opcode roughly 50,000 times per block, causing geth nodes to take minutes or longer to process a single block. The Parity client, which handled I/O differently, was less affected and kept the network moving.

A second wave exploited the SUICIDE (now SELFDESTRUCT) opcode to create millions of empty accounts that bloated the state trie. By the time Ethereum deployed its Spurious Dragon hard fork in November 2016, approximately 20 million empty accounts had been added to the state.

Mempool Flooding

The mempool is the waiting area where unconfirmed transactions sit before miners include them in blocks. An attacker can flood the mempool with low-fee transactions that are valid enough to propagate but unlikely to be mined quickly. This consumes memory on every node that stores the mempool and can push legitimate transactions out if nodes enforce memory limits.

Research has shown that mempool flooding creates a secondary effect: because fee estimation algorithms look at mempool state to recommend fees, an inflated mempool tricks wallets into suggesting higher fees than necessary. Users end up overpaying even if their transactions would have confirmed at normal rates.

P2P Network Layer Attacks

Beyond transactions, attackers can target the peer-to-peer messaging layer itself. These attacks include:

  • Bandwidth attacks: flooding nodes with excessive data to exhaust their network connections
  • Connection slot exhaustion: opening many connections to a node to prevent legitimate peers from connecting
  • Eclipse attacks: isolating a node by monopolizing all its peer connections, then feeding it false or delayed information
  • Address message flooding: sending massive volumes of peer discovery messages to overwhelm a node's address management

These attacks do not necessarily appear on-chain but can degrade individual nodes or partitions of the network, potentially enabling follow-up attacks like double spends against isolated victims.

Historical Examples

Bitcoin Spam Attacks (2015)

Starting in mid-2015, Bitcoin experienced waves of transaction spam. Attackers created thousands of tiny transactions at roughly $0.08 each, filling every 1 MB block. The attacks caused fee spikes and delayed confirmations for ordinary users. While the network never went down (nodes continued validating and miners continued producing blocks), the degraded experience underscored the importance of mempool policy and fee-based prioritization.

Ethereum DoS Attacks (2016)

The Ethereum DoS attacks of September and October 2016 remain the most severe blockchain DoS incident to date. The attackers exploited under-priced EVM opcodes, particularly EXTCODESIZE and SUICIDE, to force nodes into expensive disk I/O operations. Geth nodes stalled, and many operators could not sync past the attack blocks.

Ethereum responded with two emergency hard forks. The Tangerine Whistle fork (October 2016, block 2,463,000) implemented EIP-150, which raised the gas cost of EXTCODESIZE from 20 to 700: a 35x increase. The Spurious Dragon fork (November 2016, block 2,675,000) addressed remaining issues, including deleting the millions of empty accounts created during the attack and adding replay protection via EIP-155. These forks established a precedent that resource pricing in smart contract platforms must accurately reflect the actual computational cost of each operation.

Defenses and Mitigations

Fee Markets as Rate Limiting

The most fundamental defense in proof-of-work blockchains is the fee market. Every transaction included in a block must pay a fee, and miners prioritize higher-paying transactions. This creates an economic barrier: to sustain a DoS attack that fills blocks, the attacker must continuously outbid legitimate users. As the attack drives fees higher, the cost escalates. Bitcoin's fee market has proven effective because the fixed block weight limit ensures block space remains scarce.

Ethereum's EIP-1559 fee mechanism adds a base fee that adjusts dynamically with demand. During a DoS attack, the base fee rises automatically, making spam transactions increasingly expensive. The base fee is burned rather than paid to validators, eliminating any incentive for miners to collude with attackers.

Mempool Policies

Nodes protect themselves through configurable mempool policies. Bitcoin Core implements several mechanisms:

  • Minimum relay fee: transactions below a threshold fee rate are not relayed or stored, preventing zero-cost spam
  • Mempool eviction: when the mempool exceeds its size limit (default 300 MB), the lowest fee-rate transactions are dropped first
  • Replace-by-fee (RBF): allows higher-fee transactions to replace lower-fee ones, letting legitimate users bump their transactions ahead of spam
  • Dust limits: outputs below a minimum value are considered non-standard and not relayed, preventing the creation of uneconomical UTXOs

P2P Rate Limiting

At the network layer, nodes implement rate limits and peer scoring to manage abusive connections. Bitcoin Core's defenses include:

  • Peer misbehavior scoring: nodes track peers that send invalid or suspicious messages and disconnect or ban them after a threshold (default ban score of 100)
  • Address message rate limiting: a token-bucket limiter restricts address relay to an average of 0.1 addresses per second per connection, with bursts up to 1,000
  • Compact block relay: reduces bandwidth by sending only transaction short IDs instead of full transaction data, limiting the amplification factor of relay-based attacks
  • Erlay: a transaction relay protocol that uses set reconciliation to reduce bandwidth overhead, making bandwidth-based attacks less effective

Resource Metering

Smart contract platforms defend against computational DoS through resource metering. Every operation costs gas, and each block has a gas limit that caps total computation. The key lesson from the 2016 Ethereum attacks is that gas costs must accurately reflect the real resource consumption of each operation: CPU cycles, memory access, disk I/O, and state growth. When pricing is wrong, attackers exploit the gap.

Why Bitcoin Is Resilient to DoS

Bitcoin's design makes sustained DoS attacks economically prohibitive for several reasons:

  • Fixed block weight limit: the 4,000,000 WU cap means the attacker cannot increase block sizes to overwhelm nodes. They can only compete for existing space.
  • Fee competition: spam transactions must pay market-rate fees. During congestion, fees can exceed $10 per transaction, making large-scale flooding cost thousands of dollars per block with no direct return.
  • Simple scripting: Bitcoin Script is intentionally limited. Without loops or complex state access, the computational cost of validating any transaction is bounded and predictable.
  • UTXO model: transaction validation is stateless and parallelizable. Unlike account-based models, there are no shared state lookups that can become bottlenecks.
  • Proof-of-work cost: mining blocks requires real energy expenditure, so attackers cannot produce blocks cheaply to amplify their attack

Layer-2 solutions like the Lightning Network and Spark further reduce DoS surface area by moving transactions off-chain. Because these protocols settle only final states to the base layer, they reduce the volume of on-chain transactions an attacker could use to congest the network.

DoS vs. DDoS vs. Sybil Attacks

These related attack types are often confused but target different layers:

AttackTargetMethod
DoSResource availabilityOverwhelming a system with requests from one or few sources
DDoSResource availabilitySame goal, but using a botnet of many machines for amplification
Sybil attackIdentity and reputationCreating many fake identities to gain disproportionate influence in peer discovery, voting, or routing

A Sybil attack can enable a DoS attack (e.g., using fake nodes to eclipse a target), but they are fundamentally different: DoS targets availability, while Sybil targets identity assumptions.

Risks and Considerations

While blockchain networks have proven resilient to DoS attacks over more than a decade of continuous operation, several concerns remain:

  • Fee spike collateral damage: even unsuccessful DoS attacks that merely increase mempool congestion can cause fee spikes that price out low-value transactions and users in emerging markets
  • State bloat: transaction flooding attacks leave permanent marks on the blockchain in the form of spam transactions and uneconomical UTXOs that nodes must store indefinitely
  • Asymmetric costs: despite fee markets, there are scenarios where the cost to the attacker is lower than the cost imposed on the network. Mempool flooding, for example, consumes node memory without requiring the attacker to pay any fees if the transactions are never mined
  • Griefing attacks on Layer 2: Lightning Network channels can be griefed by holding HTLCs open indefinitely, locking liquidity along routing paths without paying fees
  • New attack surfaces: as protocols add features (ordinals, inscriptions, complex scripts), new DoS vectors may emerge that existing defenses do not cover

For a deeper analysis of how fee dynamics interact with network congestion, see the research article on Bitcoin fee market dynamics and mempool congestion economics.

This glossary entry is for informational purposes only and does not constitute financial or investment advice. Always do your own research before using any protocol or technology.