IOTA is designed as a transaction settlement and data transfer platform specifically for the Internet of Things (IoT). Unlike traditional blockchain systems that use miners and blocks, IOTA operates on a structure called the Tangle, a Directed Acyclic Graph (DAG). In the Tangle, each new transaction must confirm two previous transactions, which improves security and efficiency. This means that as the number of transactions increases, the network can process transactions faster. IOTA's design eliminates the need for transaction fees, making microtransactions feasible. It also relies on lightweight Proof of Work (PoW), which is a small computational task, to add transactions to the Tangle, enabling the network to maintain decentralization as it grows.
The IOTA project was conceptualized and initially developed in 2015. Here are the key details related to its founding:
Founders:
IOTA Foundation: The IOTA Foundation, the body supporting the project, was legally established in November 2017 and is based in Berlin, Germany.
These elements collectively outline the formation and foundational background of the IOTA project, highlighting the expertise and industry entry of its founders.
Yes, you can stake tokens in the IOTA project. Here is a breakdown of the staking process:
This mechanism supports enhancing the utility and liquidity within the IOTA ecosystem through staking.
The IOTA project has experienced notable security incidents:
Trinity Wallet Hack (February 2020): The official IOTA desktop wallet, Trinity, suffered a security breach due to a vulnerability in a third-party library used for QR code generation. This incident led to unauthorized access and theft from some users' wallets. The IOTA Foundation responded promptly by advising users to enhance their security and released a patched version of the Trinity wallet to address the issue.
Curl Hash Function Vulnerability (2017): IOTA initially used a proprietary hashing function called Curl, which was found to have vulnerabilities identified by researchers from MIT and Boston University. The discovery prompted IOTA to switch to more widely-accepted cryptographic standards, highlighting the importance of rigorous peer-review in cryptographic implementations.
It's important to note that these events occurred outside the native protocol itself and pertain to components associated with the ecosystem like the wallet or specific algorithm choices.
The IOTA project implements several security measures, many of which are unique to its structure and technology. These include:
The Tangle: Instead of traditional blockchain, IOTA uses a Directed Acyclic Graph (DAG) known as the Tangle. Each transaction must approve two previous transactions, ensuring continuous validation and fostering a faster, scalable, and more efficient network. This reduces the chances of a single point of failure and enhances security.
Decentralized Identity: IOTA has introduced a decentralized identity framework. It is built on standards like W3C's Decentralized Identifiers (DIDs), allowing secure, verifiable credentials and interactions. By anchoring cryptographic proofs on-chain, it maintains privacy and security while supporting applications in finance, supply chain, healthcare, and more source.
IOTA Rebased Upgrade: This upgrade aims to switch from the existing system to a Delegated Proof of Stake (dPoS) model, enhancing decentralization with 150 validator slots and low transaction fees. It also plans to replace the Mana system with a fee-based transaction model, making the network more resilient and less susceptible to congestion and bottlenecks source.
Coordicide Project: A significant part of IOTA's future security architecture involves removing the "Coordinator," thereby fully decentralizing the network. While not yet complete as of early 2025, this upgrade aims to mitigate the risks associated with any centralized control component.
Despite these security measures, IOTA has faced vulnerabilities:
Seed Phrase Vulnerabilities: In 2018, users lost funds due to compromised online seed-phrase generators, leading to a loss of over $11 million MIOTA tokens source.
Coordinator Reliance: Although the Coordinator is intended as a temporary measure, its necessity for network operation has led to security risks. For instance, a temporary shutdown in 2020 after a breach left the network non-functional until it was restored source.
Criticisms from MIT: In 2017, MIT critiqued IOTA for security vulnerabilities, which were reportedly followed by threats of legal action from IOTA against MIT, demonstrating tensions over its security architecture source.
These security features and vulnerabilities reflect IOTA's unique approach and the challenges of maintaining a secure DAG-based network.
The IOTA project has undergone several audits over the years. Here are the notable audits, listed in chronological order starting with the most recent: