← All research
Forging weight by lying about height
Fork-choice believes the heaviest chain. If a block can inflate the number it reports as its own height, it can inflate its weight — and steal the tie. The fix is one comparison, applied in the right place.
Every proof-of-work chain needs a rule for choosing between competing histories. TSN's, like Bitcoin's, is cumulative work: the branch that represents the most accumulated mining wins. The rule is only as trustworthy as the quantities it adds up — and a quantity a block gets to assert about itself is a quantity an attacker gets to lie about.
Height is not free-form
A block's height should be a fact about its position: one more than its parent's. But a header is just bytes the producer writes. If the code that admits a block into the local view takes the header's height at face value — without checking it against the parent it actually points to — then a block can claim to sit far higher up the chain than it does. And because height feeds the accounting that fork-choice trusts, a lie about height becomes a lie about weight: a light-but-tall-looking branch can outrank an honest one, or manufacture a reorg it did not earn.
The fix: check it where you have the parent
The correction is a single invariant, enforced at the moment of admission — the one place that has both the incoming block and the parent it references in hand: height == parent.height + 1. A block that fails it is rejected before it can influence anything. There is no exotic machinery here; the whole bug was that a self-asserted number was being trusted instead of derived. Once the derivation is enforced, height stops being a lever.
Any header field that feeds fork-choice — height, and the cumulative-work accounting it drives — must be validated against the parent at admission, never accepted as written. If a value that steers consensus can be set for free by the party who benefits, it will be. The defence is to recompute it from something the attacker doesn't control, at the gate.
Status
The admission check is deployed. The class of attack — inflating fork-choice weight through a self-asserted field — is the useful thing to remember, because height is only the most obvious member of that class. Every place consensus reads a number, the question is the same: who got to write it, and did we re-derive it before we believed it?
Filed under consensus · deployed. One comparison at the gate; a whole class of forgery closed.