A 51% attack is a failure of economic security, not a hacker discovering a master password. It becomes possible when one miner or coordinated group gains enough control over a proof-of-work network’s recent block production to build a competing chain faster than the rest of the network.
The name is convenient but imprecise. Majority hash power makes an attack reliable; some reorganisations can succeed with less, depending on luck, duration and the victim’s confirmation policy. The practical risk is highest where hash power is cheap to rent, concentrated among a few pools, or small relative to hardware available on a larger chain using the same mining algorithm.
What an attacker can—and cannot—do
A majority miner can privately build blocks, spend coins on the public chain and later reveal a longer competing history in which that payment never occurred. If nodes accept the longer valid chain, the earlier transaction is reversed. The attacker may keep both the purchased asset and the original coins: a double-spend.
The same control can delay or selectively exclude transactions and destabilise confidence in confirmations. It does not let the attacker create coins outside the protocol rules, forge another holder’s signature or spend funds without the corresponding private key. Full nodes still verify every block against consensus rules.
Bitcoin market risk is separate from consensus risk. Bitcoin’s developer documentation explains that changing old transaction history requires reproducing the proof of work after the targeted block; controlling a majority makes that race dependable. The Bitcoin block-chain guide also notes that attacks below 50% can have a non-zero chance of success. The original Bitcoin paper models the probability of an attacker catching up as confirmations accumulate.
Why rented hash power changes the calculation
Mining marketplaces allow buyers to direct compatible hardware at a pool for a limited time. They do not manufacture hash power; they make existing capacity easier to coordinate. For a small chain, the relevant comparison is therefore not only its own market capitalisation or named miners. It is the rentable capacity for its algorithm, the depth of marketplace supply and the value that could be extracted from an exchange before the attack is detected.
A chain can be vulnerable even when the rental cost appears high. The attacker’s budget is offset by normal block rewards, and a successful double-spend may target a deposit far larger than the rental bill. Conversely, a theoretical calculator can exaggerate danger if it assumes that all advertised hash power is instantly available, stable and able to connect without alerting pools or exchanges.
Signals that deserve scrutiny
- Low absolute hash rate: a modest amount of outside hardware can materially alter block production.
- Shared mining algorithm: equipment securing a larger network can switch to the smaller one.
- Pool concentration: apparent decentralisation among machines may still depend on a handful of block-template operators.
- Thin exchange controls: large deposits credited after few confirmations create an attractive exit route.
- Unusual reorganisations: deep chain reorgs, repeated orphaned blocks or sudden hash-rate spikes require investigation.
- Weak incident response: a project that cannot coordinate monitoring, checkpoints or exchange communications may suffer repeated attacks.
Confirmations are a risk decision
There is no universal safe number of confirmations. A wallet receiving a small retail payment and an exchange crediting a large, immediately withdrawable deposit face different loss limits. Confirmation policies should consider transaction value, observed network security, reorganisation history and the time needed to respond.
Exchanges can raise confirmation requirements dynamically, cap withdrawals after fresh deposits and pause a market when chain behaviour becomes abnormal. Networks can make attacks more expensive through broader hash participation and better monitoring. Some introduce checkpoints or finality mechanisms, but those measures add governance assumptions and should be described honestly rather than marketed as free security.
The useful question for investors and operators
“Has this chain ever been attacked?” is not enough. Ask how much independent work currently secures it, who constructs blocks, whether compatible hash power exists elsewhere, how exchanges size their exposure and what happens after a deep reorganisation. Proof of work converts energy and hardware into a cost of rewriting history; it does not make that cost infinite.

