Skip to article
Degrees of SatoshiFollow the connections.
Degrees of Satoshi/ Encyclopedia

Encyclopedia Bitcoin basics · Entry 379

Proof of work, explained without the math: why Bitcoin runs on a lottery

Theme
Bitcoin basics
Sources
6 cited records
Reading time
About 10 minutes
Automated verification
Substantive update
In this article

At a glance

Key facts

Key facts for Proof of work, explained without the math: why Bitcoin runs on a lottery
FactDetailSource
OriginHashcash, proposed by Adam Back in May 1997 to throttle email spam[1]
Cited byThe white paper, section 4: “a proof-of-work system similar to Adam Back’s Hashcash”[2]
Announced as“Hashcash style proof-of-work,” in Satoshi’s 31 October 2008 email[3]
The puzzleFind a header whose SHA-256 hash begins with enough zero bits[2][4]
The checkOne hash; verifying a solution costs almost nothing compared with finding it[2][1]
The knobDifficulty retargets every 2,016 blocks toward one block per ten minutes[5][4]
01

Proof of work is a receipt for effort that anyone can check

Imagine you could prove you had spent an hour on a task, in a way that a stranger could confirm in a second without watching you do it. That is proof of work. In Bitcoin the task is computing hashes. A hash function is a fixed recipe that turns any input into a short, fixed-length fingerprint, and a good one is unpredictable: change one character of the input and the fingerprint changes completely, with no way to steer the output except by trying inputs.

The Bitcoin white paper describes the puzzle in a sentence. The work “involves scanning for a value that when hashed, such as with SHA-256, the hash begins with a number of zero bits.” Because you cannot steer the output, the only way to find such a value is to try, and try, and try. The paper then states the property that makes the whole thing useful: the average work required “is exponential in the number of zero bits required and can be verified by executing a single hash.”

Hard to make, trivial to check. That asymmetry is the entire idea, and everything else in this article follows from it.

02

It was invented to make spam expensive, not to make money

Proof of work predates Bitcoin by more than a decade. In a 2002 paper, the cryptographer Adam Back wrote that Hashcash “was originally proposed as a mechanism to throttle systematic abuse of un-metered internet resources such as email, and anonymous remailers in May 1997.” The problem was spam. Sending an email costs nothing, so a spammer can send millions. If every message had to carry a small proof of work, ordinary users would never notice the cost, but bulk mailers would.

Back called the general idea a cost-function, and set out what a good one looks like: “efficiently verifiable, but parameterisably expensive to compute.” Hashcash works by “finding partial hash collisions,” that is, hashing until the output starts with a run of zero bits. Back described its cost as probabilistic: minting a token has “a predictable expected time, but a random actual time,” because the searcher starts from a random point and “sometimes the client will get lucky.” Keep that phrase in mind. It is the lottery.

The paper’s list of applications ends with one that reads differently now: hashcash “as a minting mechanism for Wei Dai’s b-money electronic cash proposal, an electronic cash scheme without a banking interface.” The Bitcoin white paper cites Back’s paper directly, and Satoshi’s first public email, on 31 October 2008, listed among Bitcoin’s properties that “new coins are made from Hashcash style proof-of-work.” The lineage runs through the cypherpunks of the 1990s, and the site’s origins dossier maps which component came from where.

03

Mining is a lottery where every hash is a ticket

Here is the whole of Bitcoin mining, without equations. A miner assembles a block and its header, a summary of 80 bytes that includes a field called the nonce, described in the developer reference as “an arbitrary number miners change to modify the header hash.” The miner hashes the header. If the result is below the current target, the block is valid. If not, the miner changes the nonce and hashes again.

Each hash is a lottery ticket. The target sets how many winning numbers exist; a lower target means fewer winners and more tickets needed on average. The Bitcoin Wiki gives a toy example: to find a variant of “Hello, world!” whose hash falls below a modest target, it took 4,251 attempts, which “on a modern computer is not very much work.” Bitcoin’s real target is set so that the entire network, buying tickets as fast as it can, wins about once every ten minutes.

Two features of a lottery carry over exactly. First, more tickets mean better odds, never a guarantee; a miner with a tenth of the network’s hashing power wins roughly a tenth of the blocks over time, but the next block could go to anyone. Second, a winning ticket is instantly checkable. You do not need to watch someone do the work; you check one hash. That is what lets strangers agree on who won without trusting each other.

04

Why a lottery, of all things, keeps a ledger honest

The strange part is why a lottery should keep a financial record honest. The answer is that the ledger is a chain, and every block carries its own proof of work. Once the effort has been spent on a block, the white paper says, it “cannot be changed without redoing the work,” and “as later blocks are chained after it, the work to change the block would include redoing all the blocks after it.”

Suppose you wanted to erase a payment you made an hour ago. You would need to produce a replacement for that block, then replacements for every block since, and then keep going faster than the rest of the network, which has not stopped. The white paper works through the odds and finds that the probability of a slower attacker catching up “diminishes exponentially as subsequent blocks are added.” That is why confirmations matter: each one is another round of the lottery the attacker would have to win.

The developer guide states the practical consequence: nodes follow the chain that is the most difficult to recreate. Not the longest by count, and not the one from the loudest source; the one with the most proven work behind it. That rule lets a computer that has been offline for a week rejoin, look at competing chains and pick the right one with no one’s help, which the white paper’s abstract describes as accepting the longest proof-of-work chain “as proof of what happened while they were gone.”

05

One CPU, one vote: work as the way to count heads on the internet

Proof of work also solves a problem that has nothing to do with money: how to count votes on the internet. If the network decided things by one vote per computer address, the white paper notes, it “could be subverted by anyone able to allocate many IPs.” Fake identities are free. Work is not. So, in the paper’s phrase, “proof-of-work is essentially one-CPU-one-vote,” and the majority decision “is represented by the longest chain, which has the greatest proof-of-work effort invested in it.”

This is the sense in which Bitcoin has no boss. There is no list of members and no meeting. Miners express what they accept by building on it and reject what they do not by refusing to, and the paper’s closing section says as much: nodes “vote with their CPU power.” Satoshi returned to this theme repeatedly in correspondence, collected in the site’s proof-of-work and mining topic guide.

06

What proof of work does not do

Proof of work does not decide what is valid. That job belongs to the rules every node checks: signatures, amounts, no double spends. The white paper’s network steps say nodes accept a block “only if all transactions in it are valid and not already spent,” so a block with enormous work behind it and one invalid transaction inside is rejected outright. Work decides which of several valid histories to follow; it never makes an invalid one acceptable.

It does not make blocks arrive on a timer, either. It makes them arrive on average every ten minutes, and the developer guide explains how: every 2,016 blocks the network compares the time taken against two weeks and moves the target to compensate. Individual blocks can arrive seconds apart or take far longer, because a lottery has no memory. And it does not run for free. The work is real electricity spent on real hardware, and whether that cost is worth what it buys is the argument behind most debates about Bitcoin’s energy use. The mining article picks up there.

07

Work selects among valid histories

The white paper often calls the preferred history the longest chain. The relevant measure is accumulated proof of work among chains that satisfy validation rules; a higher block count or extra hashing does not authorize invalid spends.

This selection provides probabilistic finality. A modelled catch-up probability is conditional on its assumptions about attacker hash power and behavior. It does not promise that any fixed confirmation count makes every payment irreversible.

08

A valid proof of work is only one check on a block

The mining test compares the block-header hash with a target. A miner changes candidate data and tries again when the hash fails that test; finding a satisfactory header is evidence of probabilistic work, not proof that every transaction in the block is allowed.

Validation still checks the block against the rules. A block containing an invalid spend does not become valid merely because its miner did substantial work. Chain selection then compares accumulated work among the histories a node accepts as valid. Keeping these steps separate avoids the misleading idea that miners can vote invalid payments into validity.

Direct answers

Questions people ask

Who invented proof of work?

Adam Back proposed Hashcash in May 1997 as a way to throttle email spam, and Bitcoin’s white paper cites his 2002 paper on it. Back himself notes that Cynthia Dwork and Moni Naor had earlier proposed a CPU pricing function against junk mail, of which he was unaware at the time.

What problem are Bitcoin miners actually solving?

Miners search for a block header whose double-SHA-256 hash meets the target. They can try another nonce or change other candidate data that alters the header. A successful header is quick to hash and compare with the target, but a node must also validate the block’s transactions and other rules.

Why does the difficulty keep changing?

To keep blocks arriving about every ten minutes as hardware and participation change. Every 2,016 blocks the network measures how long they took, compares it with two weeks, and moves the target so that faster hashing does not mean faster blocks.

Is proof of work the same as mining?

Mining is the activity: gathering transactions and searching for a valid block. Proof of work is the mechanism that makes the search costly and the result cheap to verify. Bitcoin uses proof of work for mining; the same idea was used for spam control before Bitcoin existed.

Inspect the evidence

The answer and key facts have stable claim links. These records retain the scope and qualification when reused.

Proof of work produces evidence of computational effort that is much cheaper to check than to produce. Bitcoin miners repeatedly hash candidate block headers until the result is at or below the target. Nodes still validate every block’s rules and select the valid chain with the most accumulated work. Hashcash supplied a cited precursor; proof of work does not make an invalid transaction valid.

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
Origin: Hashcash, proposed by Adam Back in May 1997 to throttle email spam

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
Cited by: The white paper, section 4: “a proof-of-work system similar to Adam Back’s Hashcash”

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
Announced as: “Hashcash style proof-of-work,” in Satoshi’s 31 October 2008 email

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
The puzzle: Find a header whose SHA-256 hash begins with enough zero bits

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
The check: One hash; verifying a solution costs almost nothing compared with finding it

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
The knob: Difficulty retargets every 2,016 blocks toward one block per ten minutes

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
Revision history
  1. — Initial Bitcoin encyclopedia entry at this permanent URL.
  2. — Corrected scope or wording: below a target Revised direct answer to preserve source scope and qualifications. Clarified valid-most-work selection and probabilistic finality in historical terminology.
  3. — Added reusable claims, explicit source locators, and matching Markdown and JSON. This publishing change does not itself establish factual verification.
  4. — Added “A valid proof of work is only one check on a block”, clarified the search description. Independent verification is recorded separately.

Source register

Sources and references

Retrieval dates and locators are recorded individually.
  1. Hashcash - A Denial of Service Counter-MeasureAdam Back · 2002-08-01Satoshi Nakamoto Institute (archived copy of the hashcash.org paper)

    Back’s paper: the May 1997 origin against email abuse, the definition of a cost-function, partial hash collisions, probabilistic cost, and b-money among the applications.

    Locator: Back’s paper: the May 1997 origin against email abuse, the definition of a cost-function, partial hash collisions, probabilistic cost, and b-money among the applications. · Retrieved: 2026-10-02T15:04:11.761958+00:00Open source
  2. Bitcoin: A Peer-to-Peer Electronic Cash SystemSatoshi Nakamoto · 2008-10-31bitcoin.org

    Section 4 on proof of work, Hashcash, one-CPU-one-vote and difficulty; section 5 on validity; section 11 on an attacker’s odds; the abstract and conclusion on nodes rejoining and voting with CPU power.

    Locator: Section 4 on proof of work, Hashcash, one-CPU-one-vote and difficulty; section 5 on validity; section 11 on an attacker’s odds; the abstract and conclusion on nodes rejoining and voting with CPU power. · Retrieved: 2026-10-02T15:04:11.761440+00:00Open source
  3. Bitcoin P2P e-cash paper (email to the Cryptography mailing list)Satoshi Nakamoto · 2008-10-31Satoshi Nakamoto Institute (archive of the Cryptography mailing list)

    The 31 October 2008 announcement listing “new coins are made from Hashcash style proof-of-work” among Bitcoin’s main properties.

    Locator: The 31 October 2008 announcement listing “new coins are made from Hashcash style proof-of-work” among Bitcoin’s main properties. · Retrieved: 2026-10-02T14:48:36.957073+00:00Open source
  4. Proof of workBitcoin Wiki

    Community reference explaining Bitcoin’s use of Hashcash-style SHA-256 proof of work, the ten-minute rate, and a worked example that took 4,251 hashes.

    Locator: Community reference explaining Bitcoin’s use of Hashcash-style SHA-256 proof of work, the ten-minute rate, and a worked example that took 4,251 hashes. · Retrieved: 2026-10-02T14:48:37.372666+00:00Open source
  5. Block Chain (Bitcoin Developer Guide)developer.bitcoin.org

    Describes the proof-of-work target, the 2,016-block retarget against two weeks, and the rule that nodes follow the most difficult chain to recreate.

    Locator: Describes the proof-of-work target, the 2,016-block retarget against two weeks, and the rule that nodes follow the most difficult chain to recreate. · Retrieved: 2026-10-02T14:48:36.834850+00:00Open source
  6. Block Chain: Block Headers (Bitcoin Developer Reference)developer.bitcoin.org

    Specifies the 80-byte header, the nBits target encoding and the nonce as the number miners change to alter the header hash.

    Locator: Specifies the 80-byte header, the nBits target encoding and the nonce as the number miners change to alter the header hash. · Retrieved: 2026-10-02T14:48:37.089132+00:00Open source
How this article was made

Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.

Editorial method and corrections

Degrees of Satoshi editorial project. “Proof of work, explained without the math: why Bitcoin runs on a lottery.” Published 2026-09-23; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/proof-of-work-explained/