Before Tuga puts her weight on anything questionable — a fence rail, a wet windowsill, the arm of a chair that moved last week — she taps it. One paw, a small press, a pause. Sometimes twice. Then she commits.
She is not confirming that the surface is safe. She is confirming that it is probably safe, to a standard proportionate to the drop. Nobody taught her the standard. She scales it herself: a low jump gets one tap, an awkward one on a wet ledge gets a careful negotiation.
Bitcoin works exactly this way, and the word "confirmed" hides it.
1. Nothing Is Ever Final
When a transaction lands in a block, it has one confirmation. Each subsequent block gives it another. Most wallets show a tick and the matter feels closed.
It isn't, quite. Bitcoin's finality is probabilistic, not absolute. There is no moment where the system declares a transaction permanent forever. What happens instead is that reversing it becomes exponentially more expensive with every block built on top, until the cost passes any rational attacker's budget and stays there.
That's a stranger guarantee than banks give you, and a stronger one. A bank transfer can be reversed by a decision. A deeply buried bitcoin transaction can only be reversed by out-mining the entire network — an expense, not a decision. But "cannot be reversed by anyone's choice" and "mathematically impossible" are different claims, and only the first is true.
2. What Actually Goes Wrong: Reorgs
Occasionally two miners find a valid block at nearly the same moment. The network briefly holds two competing versions of the truth, and nodes follow whichever chain accumulates the most work. The losing block is orphaned, and any transaction that was in it — and not in the winner — returns to the mempool to be mined again.
This is normal. It is the system resolving a tie, not failing. Shallow reorgs of one block have happened many times.
The consequence for you: a transaction with one confirmation is very likely settled, but it lives in the layer where ties are still being resolved. By a few blocks deep, the probability of being dislodged by an honest reorg becomes negligible.
3. Where "Six" Came From
The six-confirmation convention is not a law of physics. It's a rule of thumb from the early days, derived from the whitepaper's own probability analysis, chosen so that the chance of an attacker with a modest share of hash power reversing a transaction falls to a negligible level. Roughly an hour.
It stuck because it's a decent default, not because five is dangerous and seven is wasteful. The right number depends on what's at stake and who might want to attack it.
A sane scale:
- Zero confirmations — fine for a coffee from a merchant who knows you, or anything where the loss is trivial and the relationship isn't. Genuinely risky for a stranger sending you a large amount, because an unconfirmed transaction can be replaced.
- One confirmation — appropriate for most everyday amounts. The attack required is real work for a small prize.
- Three to six — sensible for meaningful sums. This is where exchanges usually sit for deposits.
- More than six — for amounts large enough that someone might build a business case around attacking your specific transaction. Most people never touch this tier, and exchanges that require it for large deposits are being sensible rather than obstructive.
Scale the taps to the drop. That's the entire lesson.
4. Why Your Exchange Makes You Wait
Deposit delays are the most complained-about thing in crypto and one of the more defensible. The exchange is accepting an irreversible credit to your account based on a transaction that is not yet expensive to reverse. If they credit at zero confirmations and the transaction gets replaced, they ate the loss.
Their waiting time is a risk calculation about your deposit, not an insult. The genuinely worrying delays are the ones on withdrawals, which have nothing to do with confirmations — that's the warning sign from a different article entirely.
5. The Layer Where This Disappears
There is one place where this whole discussion evaporates: Lightning.
A Lightning payment settles instantly and finally between the two parties, because the security comes from the channel's structure rather than from waiting for blocks. No confirmations, no reorg risk, no scaling of taps to drops.
That's the deeper reason the two layers coexist. The base layer buys you expensive, deeply verified permanence — and asks you to wait for it. Lightning buys you instant settlement within a relationship you already established. Wanting both from a single layer was always the mistake.
The Point
Tuga's paw-tap is not doubt. She fully intends to make the jump; the tap is what makes the intention safe to act on, and she calibrates it to the consequence without ever thinking about it.
"Confirmed" in bitcoin means the same thing: not a promise, but a cost. Each block is another reason nobody will bother trying to take it back. How many you wait for should depend entirely on how far you'd fall.
Tap the branch in proportion to the drop. Then jump. 🐾⚡