Race Attack

Last Updated Sep 24, 2026

In One Sentence

A race attack attempts to exploit the time before a payment is confirmed by presenting conflicting transactions to different participants.

Definition

A race attack is a double-spending attempt focused on unconfirmed payments. A recipient sees one transaction and may deliver goods or credit an account, while a conflicting spend competes to become the accepted transaction. The attack relies on treating early network observation as completed settlement. It does not require that two conflicting spends remain valid in the same final blockchain history.

How It Works

Transaction information does not reach every participant simultaneously, and nodes can initially have different views of pending activity. If the transaction favorable to the attacker confirms instead, the recipient’s observed payment may never settle. The outcome depends on network behavior and the relevant protocol rules. This is distinct from rewriting an already established history with sustained majority mining power, although both relate to double-spending risk.

Key Considerations

Merchants and services should choose confirmation or finality policies appropriate to payment value and network conditions. Conflict monitoring and additional information may help assess pending payments but cannot turn an unconfirmed transaction into guaranteed settlement. Transaction replacement can also be used legitimately to adjust fees, so a replacement alone does not prove malicious intent. Avoid relying on a screenshot, a wallet notification, or one unconfirmed explorer entry as final proof of payment. A race attack is a specific payment-timing concept and should not be confused with the broader software category of race-condition vulnerabilities.