Bitcoin security risks rise when block fees fluctuate wildly

Discussions regarding Bitcoin’s security budget typically focus on a single aggregate metric: the total transaction fees miners gather as the block subsidy diminishes.

A July 2026 NBER working paper authored by Fabian Schär, Dario Thürkauf, and David Yermack highlights a second critical factor. Examining data spanning from 2017 to 2025, the researchers discovered that wider fee discrepancies between consecutive Bitcoin blocks correlate with an increased frequency of competing blocks at the same height, alongside extended wait times for subsequent blocks.

While this observational evidence establishes a network-level pattern without confirming specific miner intentions or the exact catalysts behind any single block race, the insight provides wallets, miners, and users with a concrete metric. It demonstrates that Bitcoin’s security incentives react to how fees fluctuate from block to block, rather than solely to cumulative earnings over time.

Fee gaps create a different mining incentive

At present, the Bitcoin network compensates miners with a static subsidy of 3.125 BTC per block, accompanied by the transaction fees enclosed within that block. As these periodic subsidy reductions continue, transaction fees will inherently carry a larger long-term role in miner remuneration.

A daily metric from Glassnode on August 26 indicated that transaction fees accounted for roughly 0.70% of total miner revenue. Similarly, a report published by BTC.network for the week of August 14 to August 21 calculated a fee share of 0.67%. Although these two figures represent distinct windows, both position fees below the 1% threshold.

Related Reading

Bitcoin is getting too expensive to mine profitably: What breaks first?

On a block-by-block scale, data can reveal far more pronounced disparities than these broad averages. For instance, a Blockchain.com snapshot from August 26 recorded 0.0077 BTC in fees for block 964,120, compared to 0.0536 BTC for block 964,121—representing an almost seven-fold difference between adjacent blocks. This contrast highlights how wildly fee rewards can swing between consecutive blocks, even if raw fee amounts alone do not explicitly dictate miner actions.

Such rewards directly influence the scenario outlined in Bitcoin Optech’s analysis of fee-sniping. A miner can choose to build upon the newest block to capture pending transactions sitting in the mempool. Alternatively, a miner can attempt to recreate a highly lucrative prior block, absorb its fees, and subsequently propagate an alternative chain.

This undertaking initiates behind the current network tip, and its financial appeal grows significantly when the fees of the preceding block dwarf the projected earnings of a standard tip-extending block. Because hash-rate distribution, network propagation, and reactions from competing miners dictate success, the incentive remains probabilistic. Variable fee structures can skew these payoff calculations even during intervals when the network’s overall fee income stays minimal.

The aforementioned working paper examines whether this economic logic manifests in historical network operations. In a co-author commentary detailing the project, Thürkauf defines a block race as the appearance of rival blocks at an identical height, noting that the researchers linked larger fee gaps between neighboring blocks to a higher volume of such races.

Additionally, the study documents a decreased likelihood of the subsequent block emerging within the initial seconds following a substantial fee gap—a temporal pattern that aligns with hash power potentially being diverted to contest the preceding height. Because the underlying analysis relies on observational data, the findings confirm a network-level correlation while leaving the specific motivations of individual miners undetermined.

This distinction alters how analysts measure network security: monthly or annual fee sums reflect Bitcoin’s general security funding, whereas adjacent-block fee disparities spotlight brief windows when reverting to a prior height could yield exceptional financial returns.

Signal Security relevance Interpretive limit
Fee gap between adjacent blocks Approximates the extra prize in a valuable prior block Miner intent remains unknown
Competing blocks at the same height Shows that multiple versions briefly existed Routine network behavior can also produce a race
Delay in the next block’s first seconds Matches the timing window highlighted by the study A single delay has multiple possible causes
Fee share of miner revenue Measures aggregate reliance on transaction fees Fee distribution remains outside the aggregate measure

Infographic showing Bitcoin fee share snapshots, the choice to extend the chain tip or contest a valuable prior block, observed fee-gap associations, and partial anti-fee-sniping defenses.

Bitcoin wallet protections shrink the prize unevenly

Through the use of lock fields, Bitcoin transactions can mitigate the temptation for miners to target a prior block. Wallets can apply a lock that delays a transaction’s eligibility for inclusion until the block immediately following the current tip, thereby barring it from any attempt to replace that tip.

Widespread adoption of this practice alters the economics of fee sniping. If a miner tries to reconstruct an earlier height, they forfeit access to a portion of the freshest pending transactions, diminishing the total revenue obtainable in their alternative block. While this safeguard reduces the size of the potential prize, chain reorganization attempts remain technically feasible.

According to Bitcoin Optech’s technical review, developers view current defensive mechanisms as incomplete. Their effectiveness hinges heavily on which specific wallets and transaction-building frameworks implement the fields, how dependably they apply them, and the categories of transactions they encompass.

BIP 326 outlines anti-fee-sniping protocols for Taproot transactions utilizing nLockTime or nSequence parameters. Currently an informational draft proposal, wallets can incorporate this strategy incrementally within established consensus guidelines, meaning real-world deployment depends entirely on individual implementation decisions.

An open Bitcoin Core GitHub issue from April 2026 highlights a concrete discrepancy in this regard. The report notes that the send RPC alongside the graphical user interface wallet workflow configures nLockTime close to the prevailing block height, whereas paths such as createrawtransaction and walletcreatefundedpsbt default to zero. The proposed standardization remains under discussion.

This variance means that Bitcoin Core’s built-in defenses against fee sniping are applied inconsistently across various transaction creation workflows. Gauging the overall network impact would necessitate precise data concerning the transaction volume handled by each path—metrics that the GitHub issue does not supply.

Consequently, implementation scope must be factored into security-budget evaluations. A protective measure can be technically viable, yet its actual impact on the network relies on the proportion of pending transfers that utilize it. More expansive and uniform application of lock fields would strip away the lucrative fees that motivate miners to rebuild past heights.

Miners also navigate a coordination hurdle, because the profitability of contesting a block relies partly on whether peers choose to build upon the recognized tip. Conversely, a broad shift toward protective transaction drafting alters potential payouts organically under existing consensus rules without demanding direct collaboration among miners.

Signals to watch before the next subsidy cut

While the upcoming subsidy reduction offers a valuable point for observation, its ultimate security ramifications will be dictated by fee demand, distribution patterns, miner actions, network propagation speeds, and the adoption rate of defensive measures.

Four distinct signals offer a clearer analytical perspective than aggregate revenue metrics on their own:

  1. Adjacent-block fee gaps. Persistent or extreme disparities mark intervals where a prior block holds an exceptionally high secondary reward.
  2. Competing-block frequency. Shifts in same-height races reveal evolving network dynamics, even if the primary cause remains ambiguous.
  3. Immediate next-block timing. The moments directly following a high-fee block represent the exact vulnerability window flagged by the research.
  4. Lock-field coverage. More uniform integration across diverse wallet platforms and automated transaction generation interfaces can diminish the revenue available within a reconstructed block.

Every signal addresses a different facet of the incentive framework: fee gaps gauge the prize, block races and timing indicate network performance, and lock-field deployment measures defensive strength.

Bitcoin’s fee market is capable of generating occasional outlier blocks even when fees constitute a minor fraction of overall miner income. These outliers demand close attention because mining incentives materialize continuously with every single block interval, whereas monthly revenue charts tend to obscure short-lived extremes.

Anastasia Viktorova
Anastasia Viktorova
Anastasia Viktorova is a seasoned Web3 and crypto communications specialist, known for crafting clear, impactful press releases that elevate blockchain projects and decentralized initiatives.

Latest articles

Related articles

Leave a reply

Please enter your comment!
Please enter your name here