Tech●●●●●Difficulty 5 of 5

How does Bitcoin stop anyone from spending the same coin twice, with no bank in charge?

Digital money is just data, and data can be copied. Bitcoin's answer is a public ledger that is ruinously expensive to rewrite.

▶ Start the story

By making everyone keep the same public record, and making that record ruinously expensive to rewrite. Double-spending means paying with the same money twice. Usually a bank or payment company prevents it by checking whether a coin has already been spent, but that makes it a single point of failure. Bitcoin removes the middleman: every computer in the network keeps its own copy of the ledger, the blockchain, and checks every payment against it.

The catch is that messages reach computers at slightly different times, so two payments of the same coin could each look valid to different parts of the network. Bitcoin settles which one counts by bundling payments into blocks, and making each block costly to produce. A miner must find a number that gives the block's hash, its digital fingerprint, a value below a target, which takes an enormous number of tries but only one check to verify. Each block also contains the fingerprint of the block before it, so the blocks form a chain.

When there is a disagreement, computers follow the longest chain, the one that took the most work. To undo a payment, a cheater would have to redo the work for that block and every block after it, and outpace everyone else. The odds of a slower attacker catching up shrink exponentially with every new block, which is why merchants wait for a few confirmations.

Diagram of three Bitcoin blocks in a row; each holds the previous block's hash, a root hash of its transactions, a timestamp and a nonce, with arrows linking each block to the one before.
Each block stores the previous block's hash, so changing one block breaks every link after it. The nonce is the number miners vary to win the proof-of-work lottery.Photo: Matthäus Wander · CC BY-SA 3.0

The guarantee has limits. Anyone with more than half the network's computing power could rewrite recent history, and smaller copycat currencies have lost millions this way.

How a payment becomes hard to undo
  1. Step 1: Sign and broadcast

    You sign the payment with your private key; every node checks it.

  2. Step 2: Bundle into a block

    Miners collect payments and the previous block's hash.

  3. Step 3: Prove the work

    Find a nonce giving a hash below the target: many tries, one check.

  4. Step 4: Follow the longest chain

    Nodes accept the chain that took the most work.

  5. Step 5: Wait for confirmations

    Each block on top makes a rewrite exponentially less likely.

Quiz me

0/3

  1. 1.Why is double-spending hard to prevent without a central authority?
  2. 2.Why does waiting for more confirmations make a Bitcoin payment safer?
  3. 3.What can someone with more than half of the network's hash power do?

Recap

Longest chain wins, and every new block on top of your payment makes undoing it exponentially harder.

Surprising fact · Bitcoin's first block contains a newspaper headline about a second bank bailout.

Sources (5)

No source, no claim. Every fact in this lesson (30 claims) cites at least one of these.

  1. [1]Double-spending · Wikipedia
  2. [2]Bitcoin · Wikipedia
  3. [3]Bitcoin network · Wikipedia
  4. [4]Blockchain · Wikipedia
  5. [5]Proof of work · Wikipedia
More lessons in 💻 Tech (3) See all tech lessons →

One more light on your map.

Get one lesson like this every day, about the things you love. Free, in two or five minutes.

Get the share card for this lesson ↗