← All research articles

Research article · Blockchain and Bitcoin

Are six confirmations really enough?

Six blocks are often treated as a seal. They are not: Bitcoin offers probabilistic settlement, and the useful number of confirmations depends on the risk being modelled. Here is the exact calculation—and what it cannot establish.

One-sentence conclusion

There is no universal six-confirmation threshold: in the ideal race studied here, catch-up probability at z=6z=6 is 0.0591% for an assumed adversarial hash share q=10%q=10\%, but 15.645% for q=30%q=30\%; a defensible policy must therefore state qq, its risk target, and the model’s limits.

1. The problem and definitions

A confirmation means that the transaction appears in a block of the chain selected by the observing node; every block added on top increases its depth. This does not turn the transaction into an irreversible object. A reorganisation—the replacement of the chain tip by a branch with more accumulated proof of work—can remove that block from the selected history.[1][5]

A double spend here means a precise strategy: a payer broadcasts a transaction to the recipient while privately mining a competing branch that reallocates the same outputs. After the recipient has waited for a number of confirmations and delivered the asset, the attacker tries to make the private branch prevail.

We seek Pz(q)P_z(q), the probability that this branch catches the public chain after honest miners have produced zz blocks. The symbol qq is the attacker’s constant share of hash power and p=1−qp=1-q is the rest of the network. Values of qq below are scenarios, not network measurements or forecasts.

2. Search and source selection

The search was conducted on 2 October 2026 across the Bitcoin white paper, Bitcoin developer documentation, arXiv, the IACR ePrint Archive, ACM/IEEE proceedings, and publisher pages. Queries combined “Bitcoin confirmations”, “double spend race”, “negative binomial”, “common prefix”, “asynchronous network”, “stale block”, and “attack profitability”.

Eleven central references were retained: the foundational paper; three direct mathematical analyses of the race; one tutorial reconstruction with simulation; one operational guide; three formal or quantitative consensus models; one fast-payment study; and one economic analysis. Unsourced posts, opaque calculators, point-in-time hash-power estimates, and variants of other chains were excluded.

Accessible full texts were used to verify formulae, conventions, and assumptions. Official documentation was used only to establish operational practice around six confirmations. Every number in this article is recomputed by the supplied script; no observed rate or historical incident is extrapolated.

3. The exact model

Assume 0<q<120<q<\tfrac12. Honest and adversarial block discoveries are independent, memoryless processes at constant rates proportional to pp and qq. The attacker starts the competing branch when the payment is broadcast and never gives up. A tie in branch length is counted as adversarial success: conservative for tie-breaking, but not a bound on every real scenario.[1][3]

Let KK be the number of blocks found by the attacker before honest miners reach zz blocks. Then KK follows a negative-binomial distribution. It integrates over variability in the time required for zz confirmations instead of replacing that time by its mean.

The model deliberately excludes propagation delay, stale blocks, network eclipses, difficulty changes, changing hash power, relay policies, and economic abandonment. It answers one narrow question exactly: the catch-up probability in an ideal two-rate race.

Pr⁡(K=k)=(z+k−1k)pzqk,k=0,1,2,…\Pr(K=k)=\binom{z+k-1}{k}p^zq^k,\qquad k=0,1,2,\ldots

4. Step-by-step derivation

Step one: when honest miners find their zzth block, the attacker has found kk. The factor (z+k−1k)\binom{z+k-1}{k} counts the possible orderings of the first z−1z-1 honest successes and kk adversarial successes, with the final event fixed as the zzth honest block.

Step two: if k≥zk\ge z, the adversarial branch has already caught up under our convention. If k<zk<z, its deficit is z−kz-k. Gambler’s ruin for a biased random walk gives catch-up probability (q/p)z−k(q/p)^{z-k} when q<pq<p.[2]

Step three: weight every conditional probability by its negative-binomial mass and add. Simplification yields the finite sum below. It is equivalent to the regularised incomplete beta function I4pq(z,12)I_{4pq}(z,\tfrac12).[3]

The script evaluates this sum by recurrence, without a statistics library. It checks the result independently using Pz(q)=2Pr⁡{B≥z}P_z(q)=2\Pr\{B\ge z\} for B∼Binomial(2z−1,q)B\sim\mathrm{Binomial}(2z-1,q). Across z=1,…,60z=1,\ldots,60 and q∈{5%,10%,20%,30%,40%}q\in\{5\%,10\%,20\%,30\%,40\%\}, the largest absolute difference between the two calculations is 5.08×10−155.08\times10^{-15}.[4]

Pz(q)=1−∑k=0z−1(pzqk−qzpk)(z+k−1k),p=1−qP_z(q)=1-\sum_{k=0}^{z-1}\left(p^zq^k-q^zp^k\right)\binom{z+k-1}{k},\qquad p=1-q

5. What six confirmations represent

The same confirmation count covers very different risks under different assumed adversarial hash shares. At six blocks, probability ranges from roughly 12 successes per million races in the 5% scenario to almost one chance in two in the 40% scenario.

These frequencies merely restate theoretical probabilities; they are not observed attack counts. They make scale readable but predict neither an actor’s intent nor how often an attack is attempted.

Catch-up probability in the ideal model after six confirmations.
Assumed adversarial share qExact probability at z = 6Equivalent per million
5%0.001160%11.6 / 1,000,000
10%0.059141%591 / 1,000,000
20%2.330841%23,308 / 1,000,000
30%15.644958%156,450 / 1,000,000
40%49.300374%493,004 / 1,000,000
Logarithmic catch-up probability curves by confirmation count for five assumed adversarial hash shares.
The horizontal axis is depth zz in blocks; the vertical axis is a dimensionless probability on a logarithmic scale. Curves are exact under the stated model.

If a risk target is set first, the minimum confirmation count follows from the model rather than from a magic number:

Minimum confirmation count for three target risks.
qAt most 0.1%At most 0.01%At most 0.0001%
5%458
10%6812
20%131828
30%324469
40%133186294
Reproduce or auditCalculation script (.mjs)Figure results (.csv)Assumptions and thresholds (.json)

Explore risk, one parameter at a time

What changes if you wait for twelve confirmations instead of six? What if the assumed adversarial hash share increases? Change the parameters below: the result, both curves, and the minimum confirmation count update together. The risk target applies to the ideal race defined above.

The initial example uses six confirmations and an assumed adversarial share of 30%: the exact calculation gives about 15.64%, compared with 13.21% under Nakamoto’s approximation. A 0.1% target then requires 32 confirmations. Change only the adversarial share to 10%: six confirmations meet that same target in the model.

The block containing the transaction counts as one confirmation. Each block added on top adds another. Choose an integer between 1 and 5,000.

The share of computing power a coordinated attacker would control, between 0 and 50%. This is an assumption: a pool’s observed share of blocks does not directly measure its ability to coordinate an attack.

Choose the maximum catch-up probability you want to examine. The calculation finds the first confirmation count that meets this target.

Exact catch-up probability

15.645 %

Approximately one chance in 6.39.

This is a theoretical frequency conditional on an attempt satisfying the model; it does not describe the frequency of attacks on the network.

Nakamoto’s approximation
13.2111 %
Confirmations to meet the target
32 blocks

The calculated risk exceeds the chosen target.

How risk changes with confirmations

How risk changes with confirmationsRisk curves for the selected adversarial share. The solid line shows the exact calculation, the dashed line Nakamoto’s approximation, and the dotted line the risk target. The point marks your confirmation count. The horizontal axis counts confirmations. The vertical axis shows a probability as a percentage on a logarithmic scale: each marked interval divides risk by 100. For a fixed adversarial share, more confirmations reduce risk; a larger adversarial share raises it. Curves are clipped at 0.000001% to remain readable: reaching the bottom of the chart does not mean zero risk.10010.010.00010.000001110203040Confirmations z (blocks)Catch-up probability (%)
Exact calculationNakamoto’s approximationRisk targetYour choice
The horizontal axis counts confirmations. The vertical axis shows a probability as a percentage on a logarithmic scale: each marked interval divides risk by 100. For a fixed adversarial share, more confirmations reduce risk; a larger adversarial share raises it. Curves are clipped at 0.000001% to remain readable: reaching the bottom of the chart does not mean zero risk.

Results update the article’s formulae; this is not a live estimate of the Bitcoin network. Ties count as adversarial success, rates are constant, and the attacker never gives up. The displayed count is the minimum for this scenario, with no guarantee for risks excluded from the model.

6. From calculation to decision rule

A coherent policy does not begin with six; it begins with tolerable harm and assumptions one is prepared to defend.

  1. Define what is protected: a large one-off payment, a repeated flow, a platform withdrawal, and a zero-confirmation payment are different problems.[5][8]
  2. Set a risk target ε\varepsilon and an explicit scenario for qq. The table then gives the smallest zz such that Pz(q)≤εP_z(q)\le\varepsilon in the ideal model.
  3. Add risks excluded from the model: connectivity, full-node observation, mining concentration, propagation, recoverable value, and the ability to pause or reverse delivery.[6][9]
  4. Review the rule when assumptions change. A confirmation count without a date, scenario, or loss threshold is not a complete risk measure.

7. Objections and limitations

  • “Exact” means exact under the declared assumptions, not exact for Bitcoin as a whole. Common-prefix and consistency models show that network delay, block rate, and adaptive adversarial behaviour matter too.[6][7]
  • The scenario assumes a known, constant adversarial hash share. In practice it is uncertain, can change, and does not translate automatically into coordinated attack capacity. This article does not estimate it.
  • Counting a tie as adversarial success simplifies the model and is conservative on that point. Propagation, publication advantage, and topology can nevertheless change the probability of winning after a tie in either direction.
  • A low success probability does not imply that an attack is profitable; conversely, attack economics depend on value, block rewards, opportunity cost, and a stopping threshold. Probability and incentive are separate questions.[11]
  • Zero-confirmation payments are primarily about propagation and detection of conflicting transactions. They should not be evaluated solely with the formula for a transaction already included in a block.[10]
  • The mathematical question is resolved within the model: six is neither necessary nor sufficient in general. The operational question remains open until recipient type, threat, risk target, and network conditions are specified.

8. Conclusion

Confirmations are not binary certificates; they accumulate probabilistic assurance. Six remains a readable convention, but it carries no self-contained guarantee.

The defensible answer is therefore conditional: state qq, choose a threshold ε\varepsilon, compute zz, then handle network risks and economic incentives separately. In the scenarios studied here, six confirmations meet a 0.1% objective when q≤10%q\le10\%; they do not meet it at q=20%q=20\%.

9. Central references actually consulted

Each note states the source’s actual role. Links lead to the full text, archive, or official publisher page.

  1. S. Nakamoto (2008). Bitcoin: A Peer-to-Peer Electronic Cash System. Foundational protocol paper, sections 5 and 11.

    Introduces the proof-of-work chain, the double-spend problem, and the Poisson approximation used as the comparison point.

  2. M. Rosenfeld (2014). Analysis of Hashrate-Based Double Spending. arXiv:1402.2009 [cs.CR].

    Models adversarial block arrivals with a negative-binomial law and connects probability, stopping thresholds, and attack economics.

  3. C. Grunspan & R. Pérez-Marco (2018). Double Spend Races. International Journal of Theoretical and Applied Finance 21(8), 1850053.

    Derives the exact closed form, corrects Nakamoto’s timing approximation, and proves exponential decay with confirmation depth.

  4. A. P. Ozisik & B. N. Levine (2017). An Explanation of Nakamoto’s Analysis of Double-spend Attacks. arXiv:1701.03977 [cs.CR].

    Reconstructs Nakamoto’s reasoning step by step and uses simulation to identify the Poisson approximation as the main source of error.

  5. Bitcoin Developer Documentation (consulted 2026). Payment Processing — Verifying Payment. Bitcoin developer guide.

    Documents operational confirmation practice and explicitly calls six somewhat arbitrary, recommending risk analysis for sensitive cases.

  6. J. A. Garay, A. Kiayias & N. Leonardos (2015). The Bitcoin Backbone Protocol: Analysis and Applications. EUROCRYPT 2015, LNCS 9057, 281–310.

    Replaces informal irreversibility with common-prefix, persistence, and liveness properties under honest-majority and synchrony assumptions.

  7. R. Pass, L. Seeman & A. Shelat (2017). Analysis of the Blockchain Protocol in Asynchronous Networks. EUROCRYPT 2017, LNCS 10211, 643–673.

    Shows how consistency guarantees depend on bounded network delay and block-production rate, assumptions absent from the elementary calculation.

  8. Y. Sompolinsky & A. Zohar (2016). Bitcoin’s Security Model Revisited. arXiv:1605.09193 [cs.CR].

    Separates guarantees for repeated payments, large one-off payments, and lightweight clients, limiting what a single probability can establish.

  9. A. Gervais, G. O. Karame, K. Wüst, V. Glykantzis, H. Ritzdorf & S. Čapkun (2016). On the Security and Performance of Proof of Work Blockchains. ACM CCS 2016, 3–16.

    Incorporates propagation, stale blocks, adversarial strategy, and consensus parameters into a richer model than the ideal two-rate race.

  10. G. O. Karame, E. Androulaki & S. Čapkun (2012). Double-Spending Fast Payments in Bitcoin. ACM CCS 2012, 906–917.

    Experimentally studies zero-confirmation payments and shows why their risk differs from that of a transaction already buried in the chain.

  11. C. Grunspan & R. Pérez-Marco (2021). On Profitability of Nakamoto Double Spend. Probability in the Engineering and Informational Sciences 35(4), 984–1007.

    Separates success probability from economic profitability and studies a finite stopping strategy rather than unlimited adversarial persistence.

Educational article about a probabilistic security model. Hash shares are synthetic scenarios; this is neither a network measurement nor financial or operational advice.