Bitcoin’s security is based on proof-of-work: to add a block to the blockchain, miners must perform enormous computational work. The network agrees that the longest chain — the one representing the most accumulated work — is the valid one.
A 51% attack refers to a scenario where a single entity gains control of more than half of the network’s total mining power (called the hash rate). With majority control, they could theoretically direct the network to accept an alternative version of the blockchain.
What an attacker could and couldn’t do
This is where most coverage gets it wrong. A successful 51% attack is not a master key. There is a very specific list of what it enables — and a much longer list of what it does not.
Could do
- Double-spend their own previously confirmed transactions
- Prevent new transactions from being confirmed
- Reverse recent transactions they themselves sent
- Temporarily reorganize recent blocks
Could not do
- Steal bitcoin from other people’s wallets
- Create new bitcoin out of thin air
- Change the rules of the protocol
- Alter old, deeply confirmed transactions
- Access private keys or seed phrases
- Change the 21 million supply cap
The most damaging capability is double-spending: sending bitcoin to a merchant, waiting for a confirmation, receiving goods, then using majority control to rewrite the recent blockchain so the transaction never happened — effectively reversing the payment while keeping the goods. For everyday retail purchases, this is an absurd amount of effort. It becomes a theoretical concern for very large, high-value transactions.
Why it’s not a realistic threat to Bitcoin
Bitcoin has the largest proof-of-work mining network in history. The total computing power directed at Bitcoin mining — its hash rate — is measured in exahashes per second. To execute a 51% attack, an entity would need to assemble more mining hardware than the entire rest of the network combined.
And here’s the self-defeating logic: an entity capable of spending that much to attack Bitcoin almost certainly holds significant Bitcoin. A successful attack would immediately crater Bitcoin’s price and destroy the value of everything they hold. The incentive structure works against the attack.
Furthermore, the attack would be immediately visible. The entire Bitcoin community — developers, exchanges, custodians — would see an anomalous chain reorganization in real time. Exchanges would halt trading. The community could coordinate a response. The attacker would spend billions for a window of manipulation before the network responded.
Where 51% attacks have actually happened
51% attacks are not hypothetical in crypto broadly — they have happened on smaller, lower-hash-rate networks. Bitcoin Gold, Ethereum Classic, and Vertcoin have each suffered successful 51% attacks. These networks have a fraction of Bitcoin’s mining power, making majority control achievable for a fraction of the cost.
This is precisely why Bitcoin’s hash rate matters. More mining power means more security. Bitcoin’s network is by far the most secure proof-of-work blockchain in existence, and the gap between Bitcoin and every other proof-of-work network is enormous.
The 51% attack risk for everyday retail purchases is negligible. The cost of executing such an attack vastly exceeds the value of any realistic merchant transaction. Waiting for one confirmation — which OrangeTill tracks automatically — provides all the security a retail business needs. For very large transactions, waiting for additional confirmations increases security proportionally.
Security built into every payment.
OrangeTill tracks confirmation status in real time, so you always know when a payment is secure.
Try OrangeTill Free →