BestChange News
Best Change news

Invisible threat to blockchain: what you need to know about an Eclipse attack

Advanced Hype Crypto for newbies Crypto security
An Eclipse attack is a hidden threat to blockchain networks that can disrupt their operation and even lead to serious financial losses. Let’s examine what an Eclipse attack is, how it is carried out, why it is dangerous, and what risks it poses to decentralized systems.

General overview of an Eclipse Attack

In the blockchain ecosystem, there are many threats — from a “51% attack”* to vulnerabilities in smart contracts. However, the most dangerous are those that are difficult to detect. One of these is the Eclipse attack.
* A 51% attack is a type of attack on a blockchain network in which a single entity or a coordinated group gains control over the majority of the hash rate (computational power) in PoW (Proof-of-Work) networks or a controlling share of the stake (locked funds) in PoS (Proof-of-Stake) networks. This allows them to reorganize the blockchain, selectively confirm or reject transactions, and carry out double spending.
An Eclipse attack is a type of cyberattack in which attackers isolate individual nodes (network nodes) — such as miners or validators* — and redirect all their incoming and outgoing traffic through nodes controlled by the attackers.
* Validators are nodes in a blockchain network that participate in the consensus process by verifying transactions and creating new blocks. In PoS (Proof-of-Stake) systems, validators are selected based on the size of their stake (locked assets) and may bear economic responsibility (penalties, slashing — forced deduction of part of funds) for incorrect behavior.
The name “Eclipse attack” comes from the analogy with a lunar eclipse: just as a celestial body falls into shadow, a network node becomes “cut off” from the real network.
The term was introduced in 2015 by researchers from Boston University in the paper “Eclipse Attacks on Bitcoin’s Peer-to-Peer Network.”
In the same year, one of the researchers demonstrated a practical implementation of an Eclipse attack using a botnet (a network of infected devices) of more than 4,500 IP addresses, which allowed isolating a mining node for several hours.
Eclipse attacks are often compared to Sybil attacks*, where an attacker creates many fake nodes. In essence, an Eclipse attack is considered a specific case of a Sybil attack.
* A Sybil attack is a class of attacks on distributed systems in which an attacker creates and controls multiple pseudonymous identities (nodes) to break the assumption of participant independence. This enables manipulation of message routing, voting mechanisms, and reputation systems, and creates conditions for more complex attacks.

How an Eclipse attack works — step by step

The process of carrying out an Eclipse attack includes several stages:

Target selection

The attacker identifies a specific node — for example, a miner or validator — to attack. Typically, nodes with high importance to the network are chosen.

Infrastructure preparation

The attacker deploys a large number of controlled nodes and IP addresses, often using a botnet. This is necessary to “surround” the target node with their own connections.

Capturing incoming connections

The attacker attempts to occupy all available inbound connection slots of the target node. Since the number of connections in blockchain networks is limited, legitimate participants can no longer connect once these slots are filled.

Intercepting outgoing connections

At the same time, the attacker influences outgoing connections, for example through:
  • substituting addresses in the list of known nodes;
  • using outdated or pre-prepared records;
  • manipulating routing tables.
As a result, the node begins to “see” only the attacker’s nodes.

Full isolation (eclipse)

After taking control of all communication channels, the node becomes completely isolated from the real network. All incoming and outgoing data pass exclusively through the attacker’s controlled infrastructure.

Data manipulation

The attacker starts sending distorted or selective information to the victim:
  • hides real transactions;
  • shows outdated or fake blocks;
  • creates an alternative network state.
At the same time, the isolated node continues to broadcast this data, believing it to be correct.

Why is an Eclipse attack dangerous?

An Eclipse attack is considered one of the most complex and dangerous because it operates invisibly. Node operators do not see the real state of the network and continue working with falsified data.
Main consequences of an Eclipse attack:
  1. Double spending — a situation where the same digital assets are used twice. A similar incident occurred with Ethereum Classic in 2019. Attackers replaced real network nodes and gained control over connections, allowing them to spend ETC coins twice and cause more than $1 million in damage.
  2. Disruption of the consensus mechanism — an Eclipse attack can affect PoW (Proof-of-Work) and PoS (Proof-of-Stake) algorithms, leading to network failures or even a complete shutdown.
  3. Selfish mining — a strategy where miners hide discovered blocks to gain an advantage. Attackers build a private chain and reveal it at the right moment, overtaking the main chain. As a result, honest participants lose rewards, the network slows down, and trust in the system decreases.
  4. Preparation for larger-scale attacks — once nodes are isolated, attackers can move on to more serious scenarios, such as a 51% attack.

How to protect against an Eclipse attack

It is impossible to completely eliminate the risk of an Eclipse attack, but it can be significantly reduced. Key protection methods:

Network scale

The more nodes in the network, the harder it is to carry out an Eclipse attack. Large networks like Bitcoin and Ethereum have tens of thousands of nodes, making such attacks extremely costly.

Random node selection

If network participants are selected randomly, attackers have a harder time predicting targets. Such mechanisms are used in modern networks, including Ethereum, Elrond, and TON.

Technical measures:

  • increasing the number of TCP connections between nodes;
  • node filtering (e.g., using whitelists);
  • node verification by all participants;
  • continuous network monitoring;
  • analysis of suspicious activity patterns;
  • improving infrastructure: traffic routing, bandwidth, and consensus algorithms.
Exchanger Rate Min. Max. Reviews
Open this exchange direction on the monitoring website