Maya Chen: Jonathan, long week — but I've been in a weird rabbit hole, and I think you're going to have strong feelings about what I found.
Jonathan Ingles: Strong feelings, sure. What's the rabbit hole?
Maya Chen: So I was trying to actually understand — like, what does it cost to attack Bitcoin? And the number you get first is enormous. Outspend the entire honest network's electricity, every hour, continuously. The thermodynamic security pitch is basically: it's physically impossible to fake the work, so the chain is safe. And that sounds, mm, almost like a law of nature.
Jonathan Ingles: It's designed to sound that way. That's the point.
Maya Chen: Wait, is that — I mean, is that unfair? The energy-as-security model, the whole proof-of-work idea, it goes back to Satoshi Nakamoto's original design. One-CPU-one-vote. There's something genuinely elegant about grounding consensus in physical cost rather than trust.
Jonathan Ingles: Elegant until Ethereum Classic gets hit three separate times in 2020 by attackers who didn't own a single piece of mining hardware. They rented hash power — rented it — achieved majority control, and double-spent against exchanges. That's not a flaw in execution. That's the system working exactly as designed, except the cost of attack turned out to be 'rental price for 51% of a smaller network's hash rate.' Which is a very different number than the physics story implies.
Maya Chen: So the security guarantee is only as strong as the market for hash power — not the laws of thermodynamics.
Jonathan Ingles: And mining pools concentrate that market into a handful of decision-makers. The threat model quietly became: can you compromise a pool operator? Not: can you outspend the entire network?
Maya Chen: But wait — before we get to the pool operators, I want to back up one step, because I think listeners need the click. Like, *why* is the energy itself the thing? Not a side effect, the actual thing.
Jonathan Ingles: Picture a lock that can only be opened by physically lifting a million-pound weight. You can't pick it. You can't fake-lift it. The laws of physics are the lock. That's Bitcoin. The SHA-256 puzzle has no mathematical shortcut — miners are doing brute-force guessing, billions of attempts per second, until one of them gets lucky. The work is brutal to produce. Trivial to verify. That asymmetry is the entire security guarantee.
Maya Chen: So the energy bill isn't a side effect — it's literally what you're paying for security.
Jonathan Ingles: Fidelity Digital Assets put it explicitly: reducing energy use without reducing security is structurally impossible. Because the energy *is* the security. Not correlated with it. Not funding it. It's the mechanism. Satoshi Nakamoto's one-CPU-one-vote design — that's what solved the Byzantine Generals Problem. Consensus bought with physics, not trust.
Maya Chen: Mm. The Byzantine Generals Problem — I mean, can you make that concrete? Because I hear 'distributed consensus among strangers' and my eyes glaze a bit.
Jonathan Ingles: Say it's 2009, Bitcoin launches, and you're a stranger with coins you want to spend. There's no bank. No ledger you both trust. The question is — actually, no, the question Satoshi solved is: how do strangers agree on what happened without a referee? And the answer is: you make lying *expensive*. Computationally expensive. Someone rewrites history, they redo all that proof-of-work. The honest chain, accumulating work every ten minutes, is always longer. Catching up requires outpacing everyone else on Earth simultaneously.
Maya Chen: Which is what makes the Ethereum Classic attacks so jarring — someone *did* outpace everyone else. In 2020.
Jonathan Ingles: On a smaller network. The math held. The *market* didn't. The cost of renting enough hash power was lower than the value you could double-spend. That's not a physics failure — that's a price discovery problem.
Maya Chen: So the thermodynamic guarantee is real, but it scales with how big the network is — and Ethereum Classic just... wasn't big enough.
Jonathan Ingles: Not big enough — and that's the number that should haunt people. Hash rate is the actual variable. It sets the dollar cost per hour of a 51% attack. Ethereum Classic's hash rate was low enough that the rental price came in below what you could extract from double-spending against an exchange. The physics is identical to Bitcoin's. The market just priced attack at a discount.
Maya Chen: Wait — so picture this. Someone's sitting at, I don't know, a laptop in a data center in 2020, no mining rigs, no hardware of their own, just a browser tab open to a hash power rental market — and they're pointing rented compute at Ethereum Classic. That's actually what happened?
Jonathan Ingles: That is exactly what happened. Multiple times that year.
Maya Chen: And the chain just — rewrites? Like, transaction history that people thought was settled gets erased?
Jonathan Ingles: That's a double-spend. You spend coins at an exchange, the exchange credits your account, you rewrite the chain so the original transaction never happened — you've now got the coins and the exchange credit. PoW's energy cost is specifically supposed to make that economically irrational. On Ethereum Classic in 2020, it wasn't. The rental fee was the attack budget.
Maya Chen: So PoW security isn't a binary — it's a price. And prices fluctuate. A chain that's secure today at a certain hash rate is — wait, actually, what happens if miners leave? The hash rate drops, the rental cost drops, and suddenly the same attack is cheaper next Tuesday than it was this Tuesday.
Jonathan Ingles: Difficulty adjustment smooths block production time, but it cannot manufacture hash rate out of thin air. If miners leave, the attack cost falls with them. That's not a bug the protocol can patch. It's a continuous variable set by hardware availability and electricity prices and whoever decided mining was profitable that week.
Maya Chen: So thermodynamic security is real — just, conditional. The physics holds, the market might not.
Jonathan Ingles: And the part that makes this worse is still ahead of us — mining pools, the block subsidy cliff, and whether the real attack surface is eventually just a negotiation with a handful of pool operators rather than an electricity bill at all.
Maya Chen: Okay but the pool operator thing — that's almost scarier to me than the rental market. Because at least renting hash power still costs real money. But a pool operator with 20% of Bitcoin's hash rate is — wait, I'm trying to picture what coercing that person actually looks like. Is it a legal threat? A bribe? A hack?
Jonathan Ingles: All three. And that's the point. Satoshi Nakamoto's one-CPU-one-vote design assumed the hash power was held by thousands of independent actors. Pools shattered that. A few operators now control large fractions of Bitcoin's total hash rate. You don't need to out-mine the network. You need to flip three or four humans.
Maya Chen: That's — the physics didn't change but the threat model did.
Jonathan Ingles: Quietly. While everyone was debating electricity consumption. Mining pools exist because solo mining is a lottery — you might run hardware for a year and win nothing. Pools aggregate hash power, smooth the income, everyone gets a cut. Rational economic decision. But the consequence is that operational control — which blocks get built, which transactions get included — concentrates into a handful of operators. That's not distributed security anymore. That's a committee.
Maya Chen: And then there's the block subsidy question, which I think is — actually, can you connect these two things? Because it feels like one makes the other worse.
Jonathan Ingles: They compound. Bitcoin's block subsidy declines on a fixed schedule — it halves roughly every four years. Eventually, transaction fees have to replace it entirely as the miner incentive. If fee revenue isn't sufficient, miners leave. Hash rate drops. And a 51% attack that costs X billion dollars today costs a fraction of that once the hash rate falls. The attack surface shrinks with the economics. This isn't speculation — it's the arithmetic of the protocol.
Maya Chen: Which is what proof-of-stake tries to solve — right? Like, Ethereum's Merge was essentially saying: we don't want security tied to miner economics anymore. Validators stake assets, they lose them if they cheat — slashing — and the threat model shifts to economic incumbency rather than thermodynamics.
Jonathan Ingles: It shifts, not disappears. PoS concentrates influence among whoever holds the most staked capital. That's its own centralization dynamic. The Merge is real — Ethereum pulled it off — but trading physics for economic incumbency is a different bet, not a free upgrade. You've solved the energy problem and inherited a wealth-concentration problem.
Maya Chen: So PoW versus PoS isn't secure versus insecure. It's — which threat model do you trust more? A handful of pool operators or a handful of large validators.
Jonathan Ingles: That's exactly the frame. It's threat model selection, not a safety ranking. And honestly, we still don't know which threat materializes first — because the block subsidy hasn't run dry yet. The fees haven't had to carry the weight alone.
Maya Chen: That's the part that sort of — won't leave me alone. Bitcoin's security holds as long as hash rate stays high enough that a 51% attack costs more than it pays. That's a real guarantee. It's just... contingent on a market condition we haven't stress-tested without the subsidy propping it up.
Jonathan Ingles: We started with physics. We ended with an open question about 2028 fee revenue. That's where the answer actually lives.
Maya Chen: Mm. Not a bad place to sit with it.
Jonathan Ingles: Appreciate the rabbit hole.