How Does a Double-Spend Transaction Work in the Context of a 51% Attack?
In a double-spend attack, the attacker first sends coins to an exchange and waits for a few confirmations, then sells or withdraws them. Simultaneously, the attacker secretly mines an alternative chain where the transaction to the exchange is replaced with a transaction sending the coins back to their own wallet.
Once the secret chain is longer than the public one, the attacker broadcasts it. The network adopts the longer chain, nullifying the exchange transaction and effectively "double-spending" the coins.