A detailed explanation of the 51% attack, one of the most discussed security threats to Proof-of-Work blockchains like Bitcoin, and how it can enable.

A fundamental security principle of a Proof-of-Work (PoW) blockchain like Bitcoin is that no single entity should control more than half of the network's mining power. A 51% attack, also known as a majority attack, occurs when a single miner or a coordinated group of miners gains control of over 50% of the network's total hashing power.
This control enables attackers to undermine the blockchain's integrity. They can halt new transactions from being confirmed and most critically, reverse their own transactions that were in the process of being confirmed. This scenario is often referred to as a double-spend attack.
In a Proof-of-Work system, the "longest chain" is regarded as the authentic, valid chain due to the fork choice rule. Miners use computational power (hashrate) to compete for the next block. As finding a block is probabilistic, the miner with the most hashrate typically discovers the most blocks over time.
An entity that controls more than half of the hashrate can statistically build a new chain more rapidly than the rest of the network combined. This capability enables the execution of a double-spend attack.
Here's a detailed example of how an attacker could apply a 51% attack to double-spend their coins:
Setup: The attacker secures a majority of the network's hashrate and possesses a significant amount of cryptocurrency they wish to spend twice.
First Transaction (Public): The attacker broadcasts a transaction to the public network, sending their coins to a merchant (such as a cryptocurrency exchange) in exchange for goods or another currency (like USD). An honest miner includes this transaction in a block on the public chain.
Private Chain Mining: At the same time, the attacker mines a secret, private version of the blockchain using their majority hashrate. In this secret chain, they create a different transaction that sends the identical coins back to a wallet they control. With the majority hashrate, they can generate blocks for their private chain faster than honest miners can for the public chain.
Waiting for Confirmation: The attacker waits for the merchant to consider their initial transaction finalized. Typically, exchanges require several block confirmations before crediting a deposit. While the honest network continues to add blocks to the public chain, the attacker is secretly adding blocks more quickly to their private chain.
Revealing the Secret Chain: After the merchant has accepted the payment and delivered the goods, the attacker's secret chain is now longer than the public chain. The attacker then broadcasts this longer, private chain to the network.
Reorganization (Re-org): Adhering to the "longest chain" rule, all nodes in the network recognize this new, longer chain and accept it as the valid history. They discard the original public chain they were working on.
Final Outcome: The initial transaction to the merchant becomes part of an orphaned chain and is effectively erased from history. The attacker's second transaction, sending the coins back to themselves, is now part of the canonical chain. The attacker successfully received goods from the merchant while retaining their original coins, effectively achieving double-spending.
Recognizing the boundaries of a 51% attack is essential.
An attacker CAN:
An attacker CANNOT:
While a 51% attack represents a significant threat, carrying one out on a large, established blockchain is exceptionally challenging and costly.
| Cost Factors |
Details|
------------------------|
-------------------------------------------------| | Hardware Costs | An attacker must acquire an extensive amount of specialized mining hardware (ASICs). For Bitcoin, this often means obtaining more hardware than currently exists in the entire global network. This operation can be prohibitively expensive and logistically impossible to conduct secretly. | | Energy Costs | The electricity required to power this hardware would be exceedingly expensive. | | Economic Disincentive | If successful, news of the attack would likely cause the cryptocurrency's price to plummet. This devaluation would impact the very coins the attacker is attempting to double-spend and the costly mining equipment they acquired, rendering the attack economically irrational. |
Due to these factors, smaller Proof-of-Work cryptocurrencies with lower total network hashrates are far more susceptible. Documented cases of successful 51% attacks have occurred on smaller coins like Ethereum Classic, Verge, and Bitcoin Gold, where acquiring the necessary hashrate proved feasible for determined attackers.
Yes, although the mechanics differ. In a PoS network, an attacker must acquire over 50% of the total staked cryptocurrency. PoS protocols typically include a defense mechanism called "slashing." This feature allows the protocol to automatically detect attempts to compromise the network (for instance, by validating two different blocks at the same height) and destroy a significant portion of the attacker's staked funds. This makes the attack costly and self-defeating.
Mining operates as a probabilistic game. An attacker with 49% of the hashrate could theoretically find several blocks in sequence, but statistically, this outcome is highly unlikely. Controlling over 50% of the hashrate guarantees an attacker the statistical ability to build a longer chain over time.
No, the Bitcoin network has never been successfully attacked in this manner. The scale and expense associated with its mining network render it one of the most secure blockchains in existence.
What is the greatest risk associated with a 51% attack? While double-spending is frequently mentioned, the most significant danger is the loss of trust. A successful 51% attack on a major blockchain would severely undermine its perceived immutability and security, leading to a substantial drop in its value and utility.
Explore more guides and career playbooks