Coins & networks

What Is a Double Spend?

Basics Also known as what is a double spend double spending problem 51 percent attack can bitcoin be double spent

In short

A double spend means using the same funds twice. This was the problem that made digital money impossible before blockchain: a file can be copied, and a copied coin is indistinguishable from the original. Solving it is the reason the entire structure exists.

The problem and the solution

Why it was hard

Physical cash solves double spending by being physical. Hand over a banknote and you no longer have it.

Digital money has no such property. Send a file and you keep a copy, so any digital currency needs somebody keeping a record of who holds what. Banks did this, which is why digital payments worked and required a bank.

Removing the bank means the record has to be kept by participants who do not trust each other, and they have to agree on the order of events. That ordering is the whole difficulty, and it is what a blockchain provides.

How consensus prevents it

Every transaction is broadcast, verified against the sender’s balance, and included in a block by a validator or miner. Blocks chain together, each referencing the last.

Send the same funds twice and both transactions reach the mempool. Only one can be included, because including both would produce an invalid state that every other participant would reject. The other is discarded.

Rewriting history to undo a confirmed transaction means rebuilding every block after it and outpacing the entire rest of the network while doing so.

Why confirmations exist

This is where the abstract becomes practical.

A transaction with zero confirmations has been broadcast and not yet included. At that point a competing version can still win. One confirmation makes reversal expensive; six makes it absurd.

So the confirmation threshold a merchant sets is a double-spend risk decision, expressed as a number. Crediting an order on zero confirmations means accepting that the payment might be replaced.

Replacement is not always an attack

Worth separating, because the mechanics look identical.

Replace-by-fee lets a sender rebroadcast a transaction with a higher fee, replacing the original. This is a legitimate feature for unsticking a transfer, and it is also the mechanism a malicious sender would use: broadcast a payment, let the merchant see it, then replace it with one paying themselves.

The defence is the same in both cases, which is to wait for a confirmation. Accepting zero-confirmation payments is a choice about convenience against risk, reasonable for a coffee and not for a laptop.

The 51 percent attack

Controlling a majority of a network’s mining power or stake allows an attacker to build a longer chain and reverse recent transactions.

This has happened. Ethereum Classic and Bitcoin Gold both suffered such attacks, with funds double-spent against exchanges. Both are smaller chains where acquiring majority power was affordable.

On Bitcoin the economics make it irrational: the hardware and electricity needed exceed anything recoverable, and succeeding would devalue the asset being stolen. Smaller networks lack that protection, which is a reason to require more confirmations on them.

Frequently asked

Not once confirmed. Zero-confirmation transactions can be replaced.

Yes, on smaller chains including Ethereum Classic and Bitcoin Gold.

One for retail amounts, six for large ones.

No, it is a legitimate feature. It can be abused against zero-confirmation acceptance.

By making participants agree on transaction order without a central record keeper.

Was this article helpful?

See also