ZenGo researchers on July 2, 2020 disclosed a family of wallet-software weaknesses they called BigSpender, showing how certain versions of Ledger Live, BRD and Edge could continue displaying bitcoin from an unconfirmed transaction after the sender replaced or canceled it.
The development mattered because a wallet’s interface mediates what users believe the Bitcoin network has settled. A misleading balance could persuade a merchant that payment had arrived or interfere with the wallet’s ability to construct a later transaction. The researchers and affected vendors disagreed over whether every demonstrated scenario should be called a “double spend,” but they agreed that transaction status or balance handling required attention.
The weakness involved unconfirmed payments
Bitcoin’s Replace-by-Fee policy allows a sender to replace an unconfirmed transaction with another transaction spending the same inputs and paying a higher fee. The mechanism helps users move transactions that might otherwise remain pending. It does not reverse a transaction already confirmed in Bitcoin’s blockchain.
ZenGo found that the tested wallet versions did not always remove a replaced transaction from the displayed balance or transaction history. An attacker could send a low-fee, replaceable payment, allow the recipient’s wallet to display the incoming amount, and then replace that payment with one returning the bitcoin to the attacker. If the recipient treated the interface as proof of final settlement, goods or services could be released without a confirmed payment.
The researchers also described an amplification scenario in which the same funds were repeatedly used to create an increasingly inaccurate displayed balance. A separate denial-of-service scenario arose when wallet software attempted to select canceled transaction outputs that no longer existed. That could cause “send all” or other outgoing transactions to fail even though the user’s valid coins remained on the blockchain.
These were demonstrated software behaviors and attack models. The reviewed July 2 records did not identify confirmed victim losses, quantify affected installations or establish that exploitation had occurred in the wild.
Fixes and vendor disagreements
ZenGo’s event-day table reported that the issue found in BRD version 4.2.4 was fixed in version 4.3.1 and that the Ledger Live behavior found in version 2.0.1 was fixed in version 2.7.0. It listed Edge version 1.15.1 as affected and not yet fixed, while noting that resynchronizing the wallet corrected the displayed balance.
Ledger’s own July 2 security bulletin independently confirmed that Ledger Live could add an unconfirmed transaction to a user’s balance and fail to reduce the balance when that transaction was canceled. Ledger said the problem could mislead a recipient and block the maximum-send feature. It identified version 2.7.0 as the end-user fix and credited ZenGo researchers Tal Be’ery and Oded Leiba.
Contemporaneous reporting added important limits. Ledger characterized the problem as a user-interface issue and said its hardware wallets were unaffected. BRD said ZenGo had not demonstrated a conventional double spend against its wallet and described the relevant impact as a denial-of-service condition possible under contrived circumstances. Edge acknowledged a pending-transaction synchronization issue while emphasizing that its interface distinguished pending payments.
Why the disclosure mattered
BigSpender did not compromise Bitcoin’s consensus rules, forge signatures or spend confirmed coins without their owner’s authorization. It exposed a boundary between network state and wallet presentation: software could possess the correct keys while still presenting an inaccurate account of which transaction outputs were usable.
The July 2 record therefore supported a narrower conclusion than the most alarming descriptions. Multiple wallets mishandled some replaced, zero-confirmation transactions; vendors implemented or planned corrections; and users could not safely equate a displayed incoming balance with blockchain confirmation. The surviving evidence did not establish the scale of exposure or prove widespread financial loss.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

