Back to Glossary

Entry · Investing

51% Attack

A 51% attack happens when one party controls more than half of the computing power (the "hash rate") that secures a proof-of-work blockchain, which is a shared digital ledger where miners compete to add the next page of records. That majority lets the attacker rewrite recent transactions and spend the same coins twice.

It is the central security weakness of proof-of-work networks.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

Proof-of-work blockchains agree on history by majority: the chain with the most accumulated work is treated as the true one. An attacker who controls more than half of the mining power can secretly build a longer private chain and reveal it later, replacing transactions that everyone thought were settled.

The classic payoff is double spending. The attacker sends coins to an exchange on the public chain, trades them for another asset and withdraws it, then releases the private chain in which the original deposit never happened.

What the attacker cannot do matters as much. They cannot forge other people's digital signatures, take coins out of arbitrary wallets or easily change deeply buried old blocks.

The attack rewrites the recent edge of the ledger, not the whole book. Cost is the main defence.

On very large networks, buying or renting majority hash power would take enormous spending on hardware and electricity, which makes an attack irrational. Smaller coins with thin mining bases have suffered real attacks, and markets that rent out hash power by the hour make a temporary majority far cheaper to assemble.

Exchanges and merchants protect themselves with confirmation requirements: the larger the deposit, the more blocks they wait for before crediting it. Each extra block buries the transaction deeper under work that an attacker would have to redo.

For a non-finance manager, the idea reaches beyond crypto. Any system whose truth is decided by majority can be captured by whoever assembles that majority cheaply, and shareholder votes, review platforms and standards committees all share the same family resemblance.

In practice

Real-world examples.

1

Example

An attacker deposits coins on a cryptocurrency exchange, trades them for another asset, withdraws it, and then releases a longer private chain that erases the original deposit. The exchange is left holding nothing in exchange for the assets it paid out.

2

Example

An online gaming company credits player accounts after a single confirmation to keep purchases fast. After an attack it moves to thirty confirmations and caps deposit sizes, accepting slower credits in return for safety.

3

Example

A jeweller accepts a cryptocurrency for a $10,000 ring and waits for many confirmations before handing the ring over. For a $20 accessory, the same shop accepts a single confirmation because the loss would be small.

Formula

Calculation

Attacker profit = value of the double-spent coins - cost of controlling a majority of hash power for the attack period. Worked example (illustrative figures): an attacker rents majority hash power on a small coin for $15,000 per hour and needs 6 hours to complete the attack. Cost of the attack: $15,000 x 6 = $90,000. The attacker deposits and withdraws $400,000 of value from an exchange before the reorganisation erases the deposit. Profit: $400,000 - $90,000 = $310,000. Now suppose the exchange caps each user's unconfirmed deposits at $50,000 and waits for many confirmations on large amounts. The most the attacker can take is $50,000 against the same $90,000 cost: $50,000 - $90,000 = -$40,000. The defence works by pushing the attack cost above the value at risk.

Case study

Seen in the real world.

This case study is fictional and illustrative. Pixelforge Games is an invented online game studio that accepts a mid-sized cryptocurrency for in-game purchases and credits player accounts after one confirmation to keep the experience snappy. A developer warns that the payment flow is only as strong as the coin's mining base, but the feature ships anyway because conversion numbers look wonderful.

On a quiet Sunday a wave of large deposits arrives, followed by fast withdrawals into other assets and then a chain reorganisation that erases the deposits. The studio loses $200,000 before payments are halted, and the post-mortem is simple: one confirmation on a thin chain is hope, not settlement. The rebuilt system waits for thirty confirmations, caps deposit sizes and monitors hash rental prices, pausing deposits automatically when renting a majority would cost less than the value at risk. The developer who raised the warning now runs payments, and the number she reports to the board is not the coin's price but the cost of rewriting its history.

Watch out

Common mistakes.

  • Believing an attacker can steal any coins. They can only reverse their own recent transactions and block new ones, because they cannot forge other people's signatures.
  • Assuming all blockchains carry the same risk. Attack cost rises with the honest mining base, so small coins are far more vulnerable than the largest networks.
  • Treating one confirmation as final. Confidence in settlement grows with each block, which is why exchanges require more confirmations for larger deposits.

Questions

People also ask.

What can a 51% attacker actually do?

They can reverse their own recent transactions to double spend and can block new transactions, but they cannot steal from other wallets or rewrite ancient history.

Has a 51% attack really happened?

Yes, several smaller proof-of-work coins have suffered genuine double-spend attacks, while the scale of the largest networks makes one impractical.

How do exchanges defend against it?

They require more confirmations for larger deposits and monitor the cost of renting hash power, so any rewrite attempt would have to redo far more work than it could profit from.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%

Related

Keep reading.

BlockchainCryptocurrencyBitcoinProof of WorkDouble SpendingHash RateConsensus MechanismCryptocurrency Mining
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.