Long-Range Attack
Pronunciation: LAWNG RAYNJ uh-TAK
Definition
A long-range attack creates an alternative blockchain history beginning far in the past to deceive nodes that lack a trusted recent reference. For Long-Range Attack, an attempted action, a detected indicator, a confirmed compromise, and a realized loss are separate states that require different evidence and response. Long-Range Attack must be evaluated through its prerequisites, entry point, affected asset or trust boundary, attacker capability, observable indicators, and possible financial or operational impact.
Overview
Long-range attacks primarily concern proof-of-stake systems where former validators may recreate old signatures after their economic stake is no longer locked. An attacker builds a conflicting history that can appear valid to a new or long-offline node.
The attack exploits historical key availability and the difficulty of choosing between distant valid-looking histories. Current participants may remain unaffected while newly synchronized nodes accept the malicious branch without a recent trusted checkpoint.
Defenses include weak-subjectivity checkpoints, key evolution, slashing assumptions, finalized-state distribution, and limits on acceptable reorganization depth. Node operators should obtain recent checkpoints from reliable independent sources and avoid indefinite offline synchronization assumptions. Checkpoint distribution itself should be authenticated and resistant to single-source compromise.
A long-range attack creates an alternative blockchain history beginning far in the past to deceive nodes that lack a trusted recent reference. Long-range resistance often requires a trusted recent checkpoint because old signatures alone may not identify the socially accepted chain.
Assessment of Long-Range Attack should trace long-range attack creates an alternative blockchain history beginning far in the past to deceive nodes that lack a trusted recent reference from prerequisite and entry point through observable impact on the affected service. A theoretical weakness or scanner result involving long-range attack creates an alternative blockchain should not be reported as exploitation without corroborating logs, transactions, or configuration evidence. Prevention, detection, containment, and recovery for the Long-Range attack path should be tested against the architecture associated with long-range attack creates an alternative blockchain.
Retesting for Long-Range Attack should reproduce the Long-Range attack path involving long-range attack creates an alternative blockchain, examine adjacent paths, and verify the conditions for safely returning the affected service to normal operation.
Key Takeaway
Long-range resistance often requires a trusted recent checkpoint because old signatures alone may not identify the socially accepted chain.
Sources
- NIST Documentation: Cryptographic Standards And Guidelines — NIST (2026-07-30)