blockmindset
Lesson 2 of 512 min

Sybil and Eclipse Attacks

A Sybil attack floods a network with fake identities; an eclipse attack isolates a victim's network view.

Why this matters

Network-layer attacks can delay information, assist double-spends, amplify selfish mining, or distort a node's perception of the chain.

1

The Intuition

A full node verifies what it receives, but it still needs honest connectivity to learn the best valid chain.

2

See it concretely

Concrete example

If all your news sources are secretly controlled by one propagandist, you may think you see independent reality while actually seeing one curated feed.

3

Tempting — but wrong

4

The precise version

A Sybil attacker creates many identities to influence peer selection or reputation. An eclipse attacker monopolizes a victim's inbound and outbound peers, controlling which blocks and transactions it sees. Mitigations include peer diversity, address manager hardening, feeler connections, anchors, eviction logic, monitoring, and avoiding excessive network centralization.

security \approx validationRules + honestConnectivity + peerDiversity

Check your understanding

How is eclipse different from 51%?

Click to reveal answer

Why does peer diversity matter?

Click to reveal answer

Before moving on
  • Define Sybil attack.
  • Define eclipse attack.
  • Explain honest connectivity.
  • List network-layer mitigations.
?Checkpoint

What is the core goal of an eclipse attack?