What is the double-spending problem?

Short answer

The double-spending problem is that a digital coin can be copied, so its owner can pay two sellers with the same file. For years the only fix was a middleman who keeps a shared list and crosses out spent coins, which is just a bank inside a computer. Bitcoin replaced the middleman with a network where rewriting the payment history costs more than taking part in it honestly.

Mikhail Savchenko

Why money as a file doesn’t work

When, at the end of the twentieth century, money finally became a record in a computer, the record turned out to have an unpleasant feature: it can be copied. A song or a book in electronic form gets sent on endlessly, the sender keeps it, the recipient gets an exact duplicate, and the copy cannot be told from the original. With a song, that is a disaster for record companies. With money, it is the end of money. If a coin is a file, its owner can send the same file to two sellers and pay twice (chapter “A Stone at the Bottom of the Sea”).

Programmers called this the double-spending problem. You can see how it plays out in the experiment “One coin, two sellers”: first you pay both sellers with one coin that is a file, then you try the same through a bookkeeper who keeps a shared list.

The middleman solution

For many years the problem had one solution. You need someone in the middle who keeps a shared list and crosses out a spent coin before accepting it from the next person. That is, a bank, only in a computer. Every digital currency without a central bookkeeper ran into this wall, and every one that accepted him became yet another bank (same chapter).

Even the most elegant pre-bitcoin answer worked this way. In 1982 David Chaum presented the blind signature: the bank signs a coin without seeing its number, and when the coin comes back it checks its list to make sure nobody has spent that number yet. Double spending defeated, and the bank cannot link the coin to the payer. But a bank still issued the money, and in 1998 Chaum’s company DigiCash went bankrupt (chapter “The Spectre of Crypto Anarchy”). E-gold and Liberty Reserve also had an owner, a server and an address, which meant there was someone to arrest and something to switch off (same chapter).

How Satoshi solved it

Satoshi Nakamoto gave the shared list to everyone at once. Every participant keeps the same book of payments from the very beginning. New payments are gathered into a block, and to attach it to the book you have to solve a heavy computational puzzle. Each block refers to the previous one, and if two participants find a solution at the same time, the network eventually picks the chain with the most work spent on it (chapter “The Idle God”).

To spend a coin twice, a crook would have to recompute all the blocks after his payment faster than the rest of the network, which means having more computing power than all honest participants combined. The central bookkeeper was no longer needed. He was replaced by a crowd of strangers, each burning electricity for the reward and thereby guarding the record against everyone else (same chapter). How an attacker with less power falls behind the honest chain is shown in the experiment “A double spend against the longest chain”, and the puzzle itself is explained in the answer on proof of work.

Why it still matters

Ordinary money works on one condition: someone keeps the main ledger, and everyone else trusts them or has no choice. Your bank knows how much money you have because it wrote it down, and it can also freeze your line or refuse a payment (chapter “A Stone at the Bottom of the Sea”). For more than twenty years cryptographers trying to do without such a ledger kept running into double spending. In 2010 I looked at Satoshi’s solution with the delight an engineer feels for someone else’s solution that he could have come up with himself and didn’t.

More questions

Can a bitcoin be spent twice?
Only by rewriting the payment history faster than the rest of the network, which means having more computing power than all honest participants put together.
How was double spending prevented before bitcoin?
Through a middleman who keeps a shared list and crosses out spent coins. David Chaum’s DigiCash and ordinary banks worked this way, and without that middleman the money did not work.
Nobody Owns Money

Book

Nobody Owns Money

The real history of crypto

Satoshi’s invention was real. Its first customers were the people banks turned away.