Definition
An eclipse attack targets a particular node or group of nodes rather than necessarily controlling the entire blockchain. The attacker surrounds the target with controlled connections or otherwise limits its access to honest network information. The victim may continue to run normally while seeing a delayed or selectively filtered version of transactions and blocks. The objective is manipulation of its view, not direct extraction of its private keys.
How It Works
A distorted network view can interfere with timely transaction relay, block propagation, or a service’s interpretation of payment status. In some circumstances it can support other attacks, but isolation alone does not make invalid signatures or invalid blocks pass correct local validation. The effects depend on the node’s role, client behavior, peer selection, and the surrounding protocol. A slow connection by itself is not evidence of deliberate eclipse activity.
Key Considerations
Node operators can reduce exposure through diverse peer connections, robust peer-management logic, network monitoring, and independent checks where appropriate. Diversity should include actual infrastructure and routes, not just many addresses controlled by one provider. Keeping client software updated matters as defenses evolve. An eclipse attack differs from a general Sybil attack: many identities may help create isolation, but the defining result is a target’s restricted network view. It also differs from a 51% attack, which concerns control of consensus resources rather than just the target’s connections.