Encyclopedia How the network works · Entry 391
Double spending: the problem Bitcoin was built to solve, and how it solves it
In this article
At a glance
Key facts
| Fact | Detail | Source |
|---|---|---|
| The problem stated | The Bitcoin white paper, 2008: signatures alone cannot show a coin was not spent twice | [1][2] |
| Conflict rule | Two transactions spending the same output cannot both be accepted in one valid chain; first arrival alone does not settle the winner | [1] |
| Satoshi’s advice, November 2008 | Hold a payment for perhaps an hour or more before shipping goods | [2] |
| Small purchases | A race to propagate; a processor could check for conflicts in about 10 seconds (July 2010) | [3] |
| Odds with 10% of hash power | The white paper’s model gives catch-up probability 0.0009137 for q = 0.10 and z = 5; the model’s assumptions matter | [1] |
| Odds with 30% of hash power | The paper’s model gives probability below 0.001 at q = 0.30 and z = 24 | [1] |
| Validity versus finality | A chain can reorganize while remaining valid; validity and the economic risk of reversal are different questions | [1] |
Digital money has a copying problem that cash does not
Hand someone a ten-dollar bill and you no longer have it. Send someone a digital file and you both have it. If a coin is just data, what stops the owner from paying it to one person and then paying the same coin to somebody else before the first person notices? That second payment is a double spend, and until 2008 every workable answer put a company in the middle.
The Bitcoin white paper opens with exactly this. Satoshi Nakamoto describes online commerce as relying on financial institutions to act as trusted third parties, and notes that digital signatures alone do not fix it: a payee can check that a coin was signed over to them, but cannot check that one of the previous owners did not also sign the same coin over to someone else. The usual fix was a mint, a central authority that checks every transaction for double spending. The paper’s objection is simple: the fate of the whole money system then depends on the company running the mint, “just like a bank.”
What was needed, the paper argues, was a way for the person being paid to know that earlier owners had not signed any earlier transactions. The only way to confirm that a transaction is absent is to be aware of all transactions. So Bitcoin makes every transaction public and asks the participants to agree on a single history of the order in which they arrived. For Bitcoin’s purposes, the earliest transaction is the one that counts, and later attempts to spend the same coin are simply ignored.
A valid chain resolves conflicting spends
A transaction spends an earlier output. A second transaction that tries to spend the same output conflicts with it. Nodes reject a block that spends the same output twice or otherwise violates their validation rules.
Nodes choose among valid histories using accumulated proof of work. Temporary competing tips can occur; a later reorganization can remove a transaction from the accepted chain and include a conflict. The white paper’s historical phrase “longest chain” means greatest work in its argument, not permission to accept a longer invalid chain.
The race: what a double-spend attempt looks like from a shop counter
Suppose you run a shop and a customer pays in bitcoin. The transaction reaches your node in a second or two, but it is not yet in a block. It is unconfirmed. In that window a dishonest customer can broadcast a second transaction that spends the same coins back to themselves. Now two conflicting transactions are spreading through the network at once, and whichever reaches more miners first is more likely to end up in the next block. The Bitcoin Wiki calls this a race attack.
Satoshi described the race in July 2010, in a forum thread titled “Bitcoin snack machine (fast transaction problem).” If someone broadcasts a double spend at the same time as your payment, he wrote, “it’s a race to propagate to the most nodes first,” and a slight head start spreads geometrically. He worked the example: one node, then four, then sixteen, until one version holds around 80 percent of the network and the other 20. His suggestion for vending machines and other small, fast purchases was a payment processor with connections to many nodes, one that blasts the transaction out and watches for a conflicting one, giving “good-enough checking in something like 10 seconds or less.”
The wiki lists the harder variants. In a Finney attack the customer is also a miner: they mine a block containing a transfer of the coins to themselves, keep it secret, pay you with the same coins, collect the goods, then release the block. A Vector76 attack combines the two and can reverse a payment with one confirmation, at the cost of sacrificing a block. All of them exploit the same gap: the moments before a transaction is buried under enough work to make rewriting it expensive.
Satoshi’s advice in 2008 was blunt about that gap. Receivers “will normally need to hold transactions for perhaps an hour or more” to let any such race resolve. They can re-spend the coins immediately if they like, but they should wait before doing anything irreversible, such as shipping goods.
Why confirmations matter, in the white paper’s own numbers
A confirmation is one block added to the chain at or after the block holding your transaction. Section 11 of the white paper works out what each one buys you. Picture an attacker who paid you, then secretly starts mining a rival branch in which that payment never happened. Every block honest miners find puts them one further ahead; every block the attacker finds closes the gap by one. If the attacker has less hash power than everyone else, the odds of catching up shrink exponentially with every block they fall behind.
The paper then prints a table. With 10 percent of the network’s hash power, an attacker’s chance of overturning a payment with one confirmation is about 20 percent; after three confirmations it is about 1.3 percent; after five it is below 0.1 percent. With 30 percent of the hash power, the payment needs to be 24 blocks deep before the chance drops below 0.1 percent. The lesson is not that six confirmations is a magic number. It is that the right wait depends on how much hash power you think an attacker could have and how much money is at stake.
That is where the common conventions come from. The Bitcoin Wiki gives the same 10 percent example, puts the chance at roughly 0.1 percent after six confirmations, and suggests waiting for 100 confirmations for very large payments, on the scale of a block reward. Our article on confirmations walks through what wallets and exchanges actually require and why, and the blockchain mechanics dossier explains why Bitcoin has no absolute “final” flag, only deeper and deeper burial.
What a double spend can never do, even with most of the hash power
The white paper says that even an attacker who out-mines the honest network cannot make arbitrary changes: they cannot create value out of thin air or take money that never belonged to them, because nodes will not accept an invalid transaction as payment and will never accept a block containing one. All a majority attacker can do is change one of their own recent transactions to take back money they recently spent. That is the double spend, and it is the whole of the attack.
The wiki’s majority attack page adds two facts worth knowing. No number of confirmations can stop an attacker who controls more than half of the hash rate, though waiting raises the cost. And such an attack has never been successfully carried out on the Bitcoin network, while it has been demonstrated on some small proof-of-work coins. What it takes, what it has cost elsewhere, and how close Bitcoin has come are covered in our article on the 51 percent attack.
So Bitcoin never made double spending impossible in principle. What it did was make the honest history cheap to check and expensive to rewrite, with the expense growing every block. A merchant who understands that can choose a wait to match the amount, and a customer who understands it knows why the coffee shop does not wait at all and the exchange sometimes does.
Follow the conflict at the input, not at the recipient label
Suppose one unspent output is used as an input by transaction A and also by transaction B. Both may be proposed, but an accepted valid history cannot consume that same output twice. By contrast, two payments funded from two different unspent outputs are not a double spend merely because they come from the same wallet.
The question for a recipient is which conflicting spend survives in the accepted history. Seeing a transaction first is not the same as having it included in a block, and block inclusion is not an unconditional guarantee against a later reorganization. That is why the article treats confirmation depth and attacker assumptions separately.
Direct answers
Questions people ask
Has bitcoin ever been double spent?
Conflicting unconfirmed payments and reorganizations are real categories of risk. A claim that no successful attack has ever happened is not established by the limited sources in this entry; the mechanism and risk assumptions matter more than an absence-of-reports claim.
How many confirmations stop a double spend?
It depends on the attacker’s share of hash power and the amount at stake. The white paper’s table shows an attacker with 10 percent of the network has under a 0.1 percent chance once a payment is five blocks deep, but one with 30 percent needs 24 blocks to get the same odds. Six is a common convention for ordinary amounts, and the Bitcoin Wiki suggests 100 for very large ones.
Can I spend bitcoin I have received before it is confirmed?
Technically yes, and Satoshi said so in November 2008. His advice was that receivers can re-spend coins immediately but should wait, perhaps an hour or more, before taking an irreversible action such as shipping goods, so that any competing spend has time to lose the race.
What is a race attack?
A race attack is a double-spend attempt against an unconfirmed payment. The attacker sends you a transaction and, at almost the same moment, broadcasts a conflicting one that sends the same coins elsewhere. Whichever spreads to more of the network first is likelier to be mined. Satoshi described it in July 2010 and suggested watching the network for conflicts for about ten seconds before accepting small payments.
Inspect the evidence
The answer and key facts have stable claim links. These records retain the scope and qualification when reused.
A double-spend attempt creates conflicting transactions that try to consume the same Bitcoin output. Only one can remain in a valid accepted chain. Nodes validate blocks and select the valid chain with the most accumulated proof of work; this does not guarantee that the transaction first seen by a recipient wins. Confirmations reduce reversal risk under assumptions about an attacker’s resources, but unconfirmed payments remain especially exposed.
Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.
Link to this claimThe problem stated: The Bitcoin white paper, 2008: signatures alone cannot show a coin was not spent twice
Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.
Link to this claimConflict rule: Two transactions spending the same output cannot both be accepted in one valid chain; first arrival alone does not settle the winner
Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.
Link to this claimSatoshi’s advice, November 2008: Hold a payment for perhaps an hour or more before shipping goods
Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.
Link to this claimSmall purchases: A race to propagate; a processor could check for conflicts in about 10 seconds (July 2010)
Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.
Link to this claimOdds with 10% of hash power: The white paper’s model gives catch-up probability 0.0009137 for q = 0.10 and z = 5; the model’s assumptions matter
Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.
Link to this claimOdds with 30% of hash power: The paper’s model gives probability below 0.001 at q = 0.30 and z = 24
Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.
Link to this claimValidity versus finality: A chain can reorganize while remaining valid; validity and the economic risk of reversal are different questions
Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.
Link to this claimRevision history
- — Initial Bitcoin encyclopedia entry at this permanent URL.
- — Revised direct answer to preserve source scope and qualifications. Corrected key fact: Conflict rule Corrected key fact: Odds with 10% of hash power Corrected key fact: Odds with 30% of hash power Corrected key fact: Validity versus finality Revised section: A valid chain resolves conflicting spends Corrected FAQ: Has bitcoin ever been double spent?
- — Added reusable claims, explicit source locators, and matching Markdown and JSON. This publishing change does not itself establish factual verification.
- — Added “Follow the conflict at the input, not at the recipient label”, clarified the search description. Independent verification is recorded separately.
Source register
Sources and references
Retrieval dates and locators are recorded individually.- Bitcoin: A Peer-to-Peer Electronic Cash SystemSatoshi Nakamoto · 2008bitcoin.org
Sections 1, 2 and 5 state the double-spending problem, the first-seen rule and the longest-chain rule; section 11 gives the attacker-success table by hash-power share and confirmation depth.
Locator: Sections 1, 2 and 5 state the double-spending problem, the first-seen rule and the longest-chain rule; section 11 gives the attacker-success table by hash-power share and confirmation depth. · Retrieved: 2026-10-02T15:04:11.761440+00:00Open source - Re: Bitcoin P2P e-cash paper (reply to Hal Finney)Satoshi Nakamoto · 2008-11-09Cryptography mailing list, archived by the Satoshi Nakamoto Institute
Satoshi explains that only one of several conflicting spends becomes valid, that receivers should hold transactions for perhaps an hour or more before shipping, and that the longest chain is always the valid one.
Locator: Satoshi explains that only one of several conflicting spends becomes valid, that receivers should hold transactions for perhaps an hour or more before shipping, and that the longest chain is always the valid one. · Retrieved: 2026-10-02T14:48:49.100623+00:00Open source - Bitcoin snack machine (fast transaction problem), threadSatoshi Nakamoto and others · 2010-07-17BitcoinTalk forum, archived by the Satoshi Nakamoto Institute
Satoshi describes a double spend as a race to propagate, works the geometric spread example, and proposes a payment processor giving good-enough checking in about ten seconds for small purchases.
Locator: Satoshi describes a double spend as a race to propagate, works the geometric spread example, and proposes a payment processor giving good-enough checking in about ten seconds for small purchases. · Retrieved: 2026-10-02T14:48:50.455530+00:00Open source - Irreversible TransactionsBitcoin Wiki
Defines the race, Finney, Vector76 and alternative-history attacks, gives the 10 percent attacker and six-confirmation example, and suggests 100 confirmations for very large payments.
Locator: Defines the race, Finney, Vector76 and alternative-history attacks, gives the 10 percent attacker and six-confirmation example, and suggests 100 confirmations for very large payments. · Retrieved: 2026-10-02T14:48:50.454318+00:00Open source - Majority attackBitcoin Wiki
States that no number of confirmations prevents a double spend by a majority of hash rate, that waiting raises the cost, and that no such attack has succeeded on Bitcoin though it has on small altcoins.
Locator: States that no number of confirmations prevents a double spend by a majority of hash rate, that waiting raises the cost, and that no such attack has succeeded on Bitcoin though it has on small altcoins. · Retrieved: 2026-10-02T14:48:51.169678+00:00Open source
Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.
Editorial method and correctionsDegrees of Satoshi editorial project. “Double spending: the problem Bitcoin was built to solve, and how it solves it.” Published 2026-09-23; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/double-spending/