Under the neon glow of a late-night fintech accelerator in Austin, Texas, blockchain security specialist Elena Vargas was performing a controlled red-team exercise for a high-profile cryptocurrency payment processor. The team had identified a merchant node accepting instant confirmations for high-value digital-asset transfers.
During the simulation, the attacker first created a private transaction that credited a large sum of tokens to their own controlled wallet and immediately included it in a newly mined block.
Moments later, the attacker broadcast a second conflicting transaction that spent the exact same tokens toward the merchant's address. The merchant's system, relying on a single confirmation, immediately processed and delivered the digital goods. Only after the goods were released did the attacker publish the privately held block containing the original self-credit transaction, causing the merchant's transaction to be rejected by the network.
What type of blockchain attack is being demonstrated in this scenario?