The Hacker Who Tried to Break Bitcoin — and Couldn't

Dan Kaminsky spent months trying to break Bitcoin. Nine attack ideas later, the legendary security researcher reached a very different conclusion.
BY JASON VISCOSI8 MIN READ

Live Bitcoin market data

Bitcoin network withstands security testing inspired by researcher Dan Kaminsky
Security researcher Dan Kaminsky spent months testing Bitcoin for a fatal vulnerability and ultimately concluded that its design held.
Dan Kaminsky expected Bitcoin to break.
That mattered because Kaminsky was not a casual skeptic. The security researcher had become famous after discovering a fundamental flaw in the internet's Domain Name System in 2008 and helping coordinate an industry-wide fix before the weakness could be widely exploited.
So when Kaminsky turned his attention to Bitcoin in 2011, he approached Satoshi Nakamoto's software the way a professional attacker approaches a target: find the assumptions, identify the weak points and make the system fail.
Bitcoin was young. Its code was public. It moved real money. Its creator was anonymous. And the network was exposed to anyone on the internet who wanted to attack it.
Kaminsky came up with nine potential ways to compromise Bitcoin. Then something happened that he did not expect.

Nine attacks, nine dead ends

Joshua Davis reported in The New Yorker in 2011 that Kaminsky spent time in the basement of his mother's San Francisco home building a mental model of the Bitcoin network and looking for places to attack it.
When he traced his first attack idea through the code, he found a message near the place he expected to exploit: “Attack Removed.”
Then it happened again. Kaminsky kept developing promising attacks, only to discover that the underlying problem had already been considered in the code.
The important point is what did not happen. Bitcoin did not notice Kaminsky attacking it and rewrite its own source code. The defenses he was finding were already there. The software had been designed by people thinking about how an adversary might try to break it.
THE KAMINSKY TEST
Kaminsky did not prove Bitcoin can never be hacked. He showed something more defensible: an elite security researcher arrived expecting fatal mistakes and repeatedly found that attack paths he imagined had already been anticipated.

“It didn't fall”

Four years later, Kaminsky described the experience in his own words during a CNN interview with Morgan Spurlock. He said he initially thought Bitcoin would “fall immediately” and spent a couple of months trying to show where its problems were.
It didn't.
Kaminsky explained that each time he thought he had found Bitcoin's fatal failure, he could see that the issue had already been identified and removed. His eventual description was striking for someone whose profession was breaking systems: Bitcoin was “a beautiful system.”
He also made a crucial distinction. Problems had occurred in what he called the metacode around Bitcoin — exchanges, applications, wallets and supporting infrastructure — without breaking the core system itself.

Bitcoin being hacked is not the same as bitcoin being stolen

An exchange can be compromised. Malware can steal a private key. A user can reveal a seed phrase. Wallet software can contain a bug. A custodian can fail. None of those events, by themselves, mean an attacker changed Bitcoin's consensus rules or broke the cryptographic system that validates ownership.
That is why a headline claiming “Bitcoin was hacked” requires a second question: what, exactly, was hacked?
In 2011, The New Yorker noted that attackers had disrupted exchanges and websites that stored bitcoin even though they had not broken Nakamoto's underlying code.

Why public code can make Bitcoin stronger

Bitcoin's source code being visible is not a security accident. Researchers and attackers can inspect it, criticize it and attempt to break it.
Bitcoin has never depended on nobody discovering how it works. Developers can propose fixes and improvements, while independent nodes choose which software and rules they enforce.
This does not make bugs impossible. Kaminsky himself later participated in public Bitcoin security discussions. In a 2012 Full Disclosure exchange, he emphasized how difficult meaningful exploitation remained despite an unusually hostile attack surface: internet-facing software, custom networking, C++ code and a direct financial reward for anyone who could break it.

What about a 51% attack?

A 51% attack occurs when one miner or coordinated group controls a majority of a proof-of-work network's hash power. That can enable transaction-ordering attacks and some double spending, but it does not reveal other people's private keys or grant arbitrary power to create bitcoin.
Kaminsky's security discussion matters because he did not pretend Bitcoin was invulnerable. He discussed real attack classes while emphasizing how constrained the attacker's options remained.

Could quantum computing change the equation?

Potentially — but that is a different threat from the one Kaminsky was testing. Powerful fault-tolerant quantum computers could someday threaten the digital signatures used to authorize Bitcoin transactions.
Bitcoin Almanack's quantum-computing analysis examines that threat separately, including how post-quantum signatures could change Bitcoin's security model.

Why Kaminsky's experiment still matters

Kaminsky's attempt happened when Bitcoin was barely two years old. The network has now spent more than 17 years operating in an environment where successful attacks can be worth enormous amounts of money.
That history does not prove the next vulnerability will never exist. It proves something more useful: Bitcoin has been subjected to an unusually long, public and financially incentivized security test.
Its code can be inspected. Its transactions can be observed. Its rules are enforced across a distributed network. Researchers can attack it without asking permission.
And when one of the world's best-known security researchers went looking for the easy fatal flaw, he did not find what he expected.

Why Bitcoin remains the monetary network to beat

Bitcoin's strongest claim to leadership is not that its code is perfect or that its price always rises. It is that no competing digital monetary network can recreate Bitcoin's history retroactively.
Whether Bitcoin ever becomes a worldwide currency is ultimately a question markets and users will answer. But any system trying to replace it would have to compete not only with Bitcoin's technology and network effects, but with something that cannot be copied overnight: its record of surviving attack.
BITCOIN TERMS IN THIS STORY

Kaminsky’s technical scrutiny belongs to a broader history of colorful security figures around cryptocurrency. Our opinion column on John McAfee’s Bitcoin legacy examines the very different incentives created by fame, fear and software security.

Jason Viscosi
Founder and accountable editor of Bitcoin Almanack.
Sources, standards & corrections
Sources are linked inline. Read our editorial information, AI disclosure and corrections policy, or report an error.