Bitcoin's Hidden Weakness: Targeted Attack on Hosting Providers Could Bring Down Network
A recent study published on arXiv has shed light on Bitcoin's physical infrastructure resilience. Researchers Wenbin Wu and Alexander Neumueller from the Cambridge Centre for Alternative Finance analyzed 11 years of peer-to-peer network data, covering 658 submarine cables and 68 verified cable fault events.
The study found that between 72% and 92% of the world's inter-country submarine cables would need to fail simultaneously before Bitcoin suffers significant node disconnection. However, a targeted attack on five major hosting providers could achieve similar disruption by removing just 5% of routing capacity.
The researchers ran 1,000 Monte Carlo simulations per scenario across the full dataset and found that random cable removal requires a high threshold to cause fragmentation. Targeting cables with the highest betweenness centrality - those serving as continental chokepoints - drops this threshold to 20%. Targeting just five hosting providers (Hetzner, OVH, Comcast, Amazon, and Google Cloud) by node count reduces it further to 5%.
The study also found that 64% of Bitcoin nodes route through Tor, making their physical locations unobservable. However, the researchers discovered that Tor relay infrastructure is concentrated in Germany, France, and the Netherlands - countries with the densest submarine cable redundancy and the most robust terrestrial fiber connections.
Network resilience declined 22% between 2018 and 2021 as geographic concentration peaked during the East Asian mining boom. China's mining ban forced redistribution; the threshold recovered to 0.88 by 2022 before settling at 0.78 in 2025.