{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "proof-of-work-explained",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/proof-of-work-explained/",
  "collection": "bitcoin",
  "title": "Proof of work, explained without the math: why Bitcoin runs on a lottery",
  "description": "Bitcoin proof of work is a hash-target test, not a useful puzzle with a hidden solution. Separate mining effort, block validity and chain selection.",
  "aliases": [
    "proof of work explained",
    "what is proof of work",
    "how does proof of work work",
    "hashcash",
    "bitcoin proof of work",
    "PoW"
  ],
  "dates": {
    "published": "2026-09-23",
    "modified": "2026-10-02",
    "verified": "2026-10-02T18:22:07.965Z",
    "dataAsOf": null
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "Proof of work produces evidence of computational effort that is much cheaper to check than to produce. Bitcoin miners repeatedly hash candidate block headers until the result is at or below the target. Nodes still validate every block’s rules and select the valid chain with the most accumulated work. Hashcash supplied a cited precursor; proof of work does not make an invalid transaction valid.",
    "claimId": "proof-of-work-explained-quick-answer",
    "sourceIds": [
      "white-paper",
      "hashcash-paper",
      "devguide-block-chain"
    ]
  },
  "keyFacts": [
    {
      "label": "Origin",
      "value": "Hashcash, proposed by Adam Back in May 1997 to throttle email spam",
      "sourceIds": [
        "hashcash-paper"
      ],
      "id": "origin",
      "claimId": "proof-of-work-explained-fact-origin"
    },
    {
      "label": "Cited by",
      "value": "The white paper, section 4: “a proof-of-work system similar to Adam Back’s Hashcash”",
      "sourceIds": [
        "white-paper"
      ],
      "id": "cited-by",
      "claimId": "proof-of-work-explained-fact-cited-by"
    },
    {
      "label": "Announced as",
      "value": "“Hashcash style proof-of-work,” in Satoshi’s 31 October 2008 email",
      "sourceIds": [
        "whitepaper-announcement"
      ],
      "id": "announced-as",
      "claimId": "proof-of-work-explained-fact-announced-as"
    },
    {
      "label": "The puzzle",
      "value": "Find a header whose SHA-256 hash begins with enough zero bits",
      "sourceIds": [
        "white-paper",
        "wiki-pow"
      ],
      "id": "the-puzzle",
      "claimId": "proof-of-work-explained-fact-the-puzzle"
    },
    {
      "label": "The check",
      "value": "One hash; verifying a solution costs almost nothing compared with finding it",
      "sourceIds": [
        "white-paper",
        "hashcash-paper"
      ],
      "id": "the-check",
      "claimId": "proof-of-work-explained-fact-the-check"
    },
    {
      "label": "The knob",
      "value": "Difficulty retargets every 2,016 blocks toward one block per ten minutes",
      "sourceIds": [
        "devguide-block-chain",
        "wiki-pow"
      ],
      "id": "the-knob",
      "claimId": "proof-of-work-explained-fact-the-knob"
    }
  ],
  "prerequisites": [],
  "sections": [
    {
      "id": "a-receipt-for-effort",
      "heading": "Proof of work is a receipt for effort that anyone can check",
      "sourceIds": [
        "white-paper"
      ],
      "paragraphs": [
        "Imagine you could prove you had spent an hour on a task, in a way that a stranger could confirm in a second without watching you do it. That is proof of work. In Bitcoin the task is computing hashes. A hash function is a fixed recipe that turns any input into a short, fixed-length fingerprint, and a good one is unpredictable: change one character of the input and the fingerprint changes completely, with no way to steer the output except by trying inputs.",
        "The Bitcoin white paper describes the puzzle in a sentence. The work “involves scanning for a value that when hashed, such as with SHA-256, the hash begins with a number of zero bits.” Because you cannot steer the output, the only way to find such a value is to try, and try, and try. The paper then states the property that makes the whole thing useful: the average work required “is exponential in the number of zero bits required and can be verified by executing a single hash.”",
        "Hard to make, trivial to check. That asymmetry is the entire idea, and everything else in this article follows from it."
      ]
    },
    {
      "id": "born-to-fight-spam",
      "heading": "It was invented to make spam expensive, not to make money",
      "sourceIds": [
        "hashcash-paper",
        "white-paper",
        "whitepaper-announcement"
      ],
      "paragraphs": [
        "Proof of work predates Bitcoin by more than a decade. In a 2002 paper, the cryptographer Adam Back wrote that Hashcash “was originally proposed as a mechanism to throttle systematic abuse of un-metered internet resources such as email, and anonymous remailers in May 1997.” The problem was spam. Sending an email costs nothing, so a spammer can send millions. If every message had to carry a small proof of work, ordinary users would never notice the cost, but bulk mailers would.",
        "Back called the general idea a cost-function, and set out what a good one looks like: “efficiently verifiable, but parameterisably expensive to compute.” Hashcash works by “finding partial hash collisions,” that is, hashing until the output starts with a run of zero bits. Back described its cost as probabilistic: minting a token has “a predictable expected time, but a random actual time,” because the searcher starts from a random point and “sometimes the client will get lucky.” Keep that phrase in mind. It is the lottery.",
        "The paper’s list of applications ends with one that reads differently now: hashcash “as a minting mechanism for Wei Dai’s b-money electronic cash proposal, an electronic cash scheme without a banking interface.” The Bitcoin white paper cites Back’s paper directly, and Satoshi’s first public email, on 31 October 2008, listed among Bitcoin’s properties that “new coins are made from Hashcash style proof-of-work.” The lineage runs through the [cypherpunks](/encyclopedia/cypherpunks-before-bitcoin/) of the 1990s, and the site’s [origins dossier](/history/origins-of-bitcoin/) maps which component came from where."
      ]
    },
    {
      "id": "the-lottery",
      "heading": "Mining is a lottery where every hash is a ticket",
      "sourceIds": [
        "devref-block-header",
        "wiki-pow",
        "white-paper"
      ],
      "paragraphs": [
        "Here is the whole of Bitcoin mining, without equations. A miner assembles a block and its header, a summary of 80 bytes that includes a field called the nonce, described in the developer reference as “an arbitrary number miners change to modify the header hash.” The miner hashes the header. If the result is below the current target, the block is valid. If not, the miner changes the nonce and hashes again.",
        "Each hash is a lottery ticket. The target sets how many winning numbers exist; a lower target means fewer winners and more tickets needed on average. The Bitcoin Wiki gives a toy example: to find a variant of “Hello, world!” whose hash falls below a modest target, it took 4,251 attempts, which “on a modern computer is not very much work.” Bitcoin’s real target is set so that the entire network, buying tickets as fast as it can, wins about once every ten minutes.",
        "Two features of a lottery carry over exactly. First, more tickets mean better odds, never a guarantee; a miner with a tenth of the network’s hashing power wins roughly a tenth of the blocks over time, but the next block could go to anyone. Second, a winning ticket is instantly checkable. You do not need to watch someone do the work; you check one hash. That is what lets strangers agree on who won without trusting each other."
      ]
    },
    {
      "id": "why-a-lottery-keeps-a-ledger-honest",
      "heading": "Why a lottery, of all things, keeps a ledger honest",
      "sourceIds": [
        "white-paper",
        "devguide-block-chain"
      ],
      "paragraphs": [
        "The strange part is why a lottery should keep a financial record honest. The answer is that the ledger is a chain, and every block carries its own proof of work. Once the effort has been spent on a block, the white paper says, it “cannot be changed without redoing the work,” and “as later blocks are chained after it, the work to change the block would include redoing all the blocks after it.”",
        "Suppose you wanted to erase a payment you made an hour ago. You would need to produce a replacement for that block, then replacements for every block since, and then keep going faster than the rest of the network, which has not stopped. The white paper works through the odds and finds that the probability of a slower attacker catching up “diminishes exponentially as subsequent blocks are added.” That is why [confirmations](/encyclopedia/bitcoin-confirmations/) matter: each one is another round of the lottery the attacker would have to win.",
        "The developer guide states the practical consequence: nodes follow the chain that is the most difficult to recreate. Not the longest by count, and not the one from the loudest source; the one with the most proven work behind it. That rule lets a computer that has been offline for a week rejoin, look at competing chains and pick the right one with no one’s help, which the white paper’s abstract describes as accepting the longest proof-of-work chain “as proof of what happened while they were gone.”"
      ]
    },
    {
      "id": "one-cpu-one-vote",
      "heading": "One CPU, one vote: work as the way to count heads on the internet",
      "sourceIds": [
        "white-paper"
      ],
      "paragraphs": [
        "Proof of work also solves a problem that has nothing to do with money: how to count votes on the internet. If the network decided things by one vote per computer address, the white paper notes, it “could be subverted by anyone able to allocate many IPs.” Fake identities are free. Work is not. So, in the paper’s phrase, “proof-of-work is essentially one-CPU-one-vote,” and the majority decision “is represented by the longest chain, which has the greatest proof-of-work effort invested in it.”",
        "This is the sense in which Bitcoin has no boss. There is no list of members and no meeting. Miners express what they accept by building on it and reject what they do not by refusing to, and the paper’s closing section says as much: nodes “vote with their CPU power.” Satoshi returned to this theme repeatedly in correspondence, collected in the site’s [proof-of-work and mining topic guide](/satoshi/correspondence/topics/proof-of-work-mining-difficulty/)."
      ]
    },
    {
      "id": "what-it-does-not-do",
      "heading": "What proof of work does not do",
      "sourceIds": [
        "white-paper",
        "devguide-block-chain"
      ],
      "paragraphs": [
        "Proof of work does not decide what is valid. That job belongs to the rules every node checks: signatures, amounts, no double spends. The white paper’s network steps say nodes accept a block “only if all transactions in it are valid and not already spent,” so a block with enormous work behind it and one invalid transaction inside is rejected outright. Work decides which of several valid histories to follow; it never makes an invalid one acceptable.",
        "It does not make blocks arrive on a timer, either. It makes them arrive on average every ten minutes, and the developer guide explains how: every 2,016 blocks the network compares the time taken against two weeks and moves the target to compensate. Individual blocks can arrive seconds apart or take far longer, because a lottery has no memory. And it does not run for free. The work is real electricity spent on real hardware, and whether that cost is worth what it buys is the argument behind most debates about Bitcoin’s energy use. The [mining article](/encyclopedia/how-bitcoin-mining-works/) picks up there."
      ]
    },
    {
      "id": "valid-chain-and-finality",
      "heading": "Work selects among valid histories",
      "paragraphs": [
        "The white paper often calls the preferred history the longest chain. The relevant measure is accumulated proof of work among chains that satisfy validation rules; a higher block count or extra hashing does not authorize invalid spends.",
        "This selection provides probabilistic finality. A modelled catch-up probability is conditional on its assumptions about attacker hash power and behavior. It does not promise that any fixed confirmation count makes every payment irreversible."
      ],
      "sourceIds": [
        "white-paper"
      ]
    },
    {
      "id": "reading-the-evidence",
      "heading": "A valid proof of work is only one check on a block",
      "sourceIds": [
        "devguide-block-chain",
        "devref-block-header",
        "white-paper"
      ],
      "paragraphs": [
        "The mining test compares the block-header hash with a target. A miner changes candidate data and tries again when the hash fails that test; finding a satisfactory header is evidence of probabilistic work, not proof that every transaction in the block is allowed.",
        "Validation still checks the block against the rules. A block containing an invalid spend does not become valid merely because its miner did substantial work. Chain selection then compares accumulated work among the histories a node accepts as valid. Keeping these steps separate avoids the misleading idea that miners can vote invalid payments into validity."
      ]
    }
  ],
  "faq": [
    {
      "question": "Who invented proof of work?",
      "answer": "Adam Back proposed Hashcash in May 1997 as a way to throttle email spam, and Bitcoin’s white paper cites his 2002 paper on it. Back himself notes that Cynthia Dwork and Moni Naor had earlier proposed a CPU pricing function against junk mail, of which he was unaware at the time.",
      "sourceIds": [
        "hashcash-paper",
        "white-paper"
      ]
    },
    {
      "question": "What problem are Bitcoin miners actually solving?",
      "answer": "Miners search for a block header whose double-SHA-256 hash meets the target. They can try another nonce or change other candidate data that alters the header. A successful header is quick to hash and compare with the target, but a node must also validate the block’s transactions and other rules.",
      "sourceIds": [
        "devref-block-header",
        "devguide-block-chain"
      ]
    },
    {
      "question": "Why does the difficulty keep changing?",
      "answer": "To keep blocks arriving about every ten minutes as hardware and participation change. Every 2,016 blocks the network measures how long they took, compares it with two weeks, and moves the target so that faster hashing does not mean faster blocks.",
      "sourceIds": [
        "devguide-block-chain",
        "wiki-pow"
      ]
    },
    {
      "question": "Is proof of work the same as mining?",
      "answer": "Mining is the activity: gathering transactions and searching for a valid block. Proof of work is the mechanism that makes the search costly and the result cheap to verify. Bitcoin uses proof of work for mining; the same idea was used for spam control before Bitcoin existed.",
      "sourceIds": [
        "hashcash-paper",
        "white-paper"
      ]
    }
  ],
  "claims": [
    {
      "id": "proof-of-work-explained-quick-answer",
      "articleSlug": "proof-of-work-explained",
      "statement": "Proof of work produces evidence of computational effort that is much cheaper to check than to produce. Bitcoin miners repeatedly hash candidate block headers until the result is at or below the target. Nodes still validate every block’s rules and select the valid chain with the most accumulated work. Hashcash supplied a cited precursor; proof of work does not make an invalid transaction valid.",
      "sourceIds": [
        "source-0e46aca4dbc5a030",
        "source-42b702488d4e29bb",
        "source-190b9fe0eec933dc"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-0e46aca4dbc5a030",
          "locator": "Section 4 on proof of work, Hashcash, one-CPU-one-vote and difficulty; section 5 on validity; section 11 on an attacker’s odds; the abstract and conclusion on nodes rejoining and voting with CPU power."
        },
        {
          "sourceId": "source-42b702488d4e29bb",
          "locator": "Back’s paper: the May 1997 origin against email abuse, the definition of a cost-function, partial hash collisions, probabilistic cost, and b-money among the applications."
        },
        {
          "sourceId": "source-190b9fe0eec933dc",
          "locator": "Describes the proof-of-work target, the 2,016-block retarget against two weeks, and the rule that nodes follow the most difficult chain to recreate."
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:22:07.965Z",
        "reviewer": "automated independent verification agent /root/content_seo_verification",
        "notes": [
          "Read the block-header reference and validation/most-work documentation. New guide and final FAQ accurately specify double-SHA-256, nonce or other candidate changes, the target comparison, separate block validation and selection among valid histories."
        ]
      }
    },
    {
      "id": "proof-of-work-explained-fact-origin",
      "articleSlug": "proof-of-work-explained",
      "statement": "Origin: Hashcash, proposed by Adam Back in May 1997 to throttle email spam",
      "sourceIds": [
        "source-42b702488d4e29bb"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-42b702488d4e29bb",
          "locator": "Back’s paper: the May 1997 origin against email abuse, the definition of a cost-function, partial hash collisions, probabilistic cost, and b-money among the applications."
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:22:07.965Z",
        "reviewer": "automated independent verification agent /root/content_seo_verification",
        "notes": [
          "Read the block-header reference and validation/most-work documentation. New guide and final FAQ accurately specify double-SHA-256, nonce or other candidate changes, the target comparison, separate block validation and selection among valid histories."
        ]
      }
    },
    {
      "id": "proof-of-work-explained-fact-cited-by",
      "articleSlug": "proof-of-work-explained",
      "statement": "Cited by: The white paper, section 4: “a proof-of-work system similar to Adam Back’s Hashcash”",
      "sourceIds": [
        "source-0e46aca4dbc5a030"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-0e46aca4dbc5a030",
          "locator": "Section 4 on proof of work, Hashcash, one-CPU-one-vote and difficulty; section 5 on validity; section 11 on an attacker’s odds; the abstract and conclusion on nodes rejoining and voting with CPU power."
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:22:07.965Z",
        "reviewer": "automated independent verification agent /root/content_seo_verification",
        "notes": [
          "Read the block-header reference and validation/most-work documentation. New guide and final FAQ accurately specify double-SHA-256, nonce or other candidate changes, the target comparison, separate block validation and selection among valid histories."
        ]
      }
    },
    {
      "id": "proof-of-work-explained-fact-announced-as",
      "articleSlug": "proof-of-work-explained",
      "statement": "Announced as: “Hashcash style proof-of-work,” in Satoshi’s 31 October 2008 email",
      "sourceIds": [
        "source-ada4b38213b22142"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-ada4b38213b22142",
          "locator": "The 31 October 2008 announcement listing “new coins are made from Hashcash style proof-of-work” among Bitcoin’s main properties."
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:22:07.965Z",
        "reviewer": "automated independent verification agent /root/content_seo_verification",
        "notes": [
          "Read the block-header reference and validation/most-work documentation. New guide and final FAQ accurately specify double-SHA-256, nonce or other candidate changes, the target comparison, separate block validation and selection among valid histories."
        ]
      }
    },
    {
      "id": "proof-of-work-explained-fact-the-puzzle",
      "articleSlug": "proof-of-work-explained",
      "statement": "The puzzle: Find a header whose SHA-256 hash begins with enough zero bits",
      "sourceIds": [
        "source-0e46aca4dbc5a030",
        "source-065fc4ef4ea035e5"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-0e46aca4dbc5a030",
          "locator": "Section 4 on proof of work, Hashcash, one-CPU-one-vote and difficulty; section 5 on validity; section 11 on an attacker’s odds; the abstract and conclusion on nodes rejoining and voting with CPU power."
        },
        {
          "sourceId": "source-065fc4ef4ea035e5",
          "locator": "Community reference explaining Bitcoin’s use of Hashcash-style SHA-256 proof of work, the ten-minute rate, and a worked example that took 4,251 hashes."
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:22:07.965Z",
        "reviewer": "automated independent verification agent /root/content_seo_verification",
        "notes": [
          "Read the block-header reference and validation/most-work documentation. New guide and final FAQ accurately specify double-SHA-256, nonce or other candidate changes, the target comparison, separate block validation and selection among valid histories."
        ]
      }
    },
    {
      "id": "proof-of-work-explained-fact-the-check",
      "articleSlug": "proof-of-work-explained",
      "statement": "The check: One hash; verifying a solution costs almost nothing compared with finding it",
      "sourceIds": [
        "source-0e46aca4dbc5a030",
        "source-42b702488d4e29bb"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-0e46aca4dbc5a030",
          "locator": "Section 4 on proof of work, Hashcash, one-CPU-one-vote and difficulty; section 5 on validity; section 11 on an attacker’s odds; the abstract and conclusion on nodes rejoining and voting with CPU power."
        },
        {
          "sourceId": "source-42b702488d4e29bb",
          "locator": "Back’s paper: the May 1997 origin against email abuse, the definition of a cost-function, partial hash collisions, probabilistic cost, and b-money among the applications."
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:22:07.965Z",
        "reviewer": "automated independent verification agent /root/content_seo_verification",
        "notes": [
          "Read the block-header reference and validation/most-work documentation. New guide and final FAQ accurately specify double-SHA-256, nonce or other candidate changes, the target comparison, separate block validation and selection among valid histories."
        ]
      }
    },
    {
      "id": "proof-of-work-explained-fact-the-knob",
      "articleSlug": "proof-of-work-explained",
      "statement": "The knob: Difficulty retargets every 2,016 blocks toward one block per ten minutes",
      "sourceIds": [
        "source-190b9fe0eec933dc",
        "source-065fc4ef4ea035e5"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-190b9fe0eec933dc",
          "locator": "Describes the proof-of-work target, the 2,016-block retarget against two weeks, and the rule that nodes follow the most difficult chain to recreate."
        },
        {
          "sourceId": "source-065fc4ef4ea035e5",
          "locator": "Community reference explaining Bitcoin’s use of Hashcash-style SHA-256 proof of work, the ten-minute rate, and a worked example that took 4,251 hashes."
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:22:07.965Z",
        "reviewer": "automated independent verification agent /root/content_seo_verification",
        "notes": [
          "Read the block-header reference and validation/most-work documentation. New guide and final FAQ accurately specify double-SHA-256, nonce or other candidate changes, the target comparison, separate block validation and selection among valid histories."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "hashcash-paper",
      "label": "Hashcash - A Denial of Service Counter-Measure",
      "publisher": "Satoshi Nakamoto Institute (archived copy of the hashcash.org paper)",
      "author": "Adam Back",
      "issued": "2002-08-01",
      "url": "https://cdn.nakamotoinstitute.org/docs/hashcash.pdf",
      "note": "Back’s paper: the May 1997 origin against email abuse, the definition of a cost-function, partial hash collisions, probabilistic cost, and b-money among the applications.",
      "checkedAt": "2026-10-02T15:04:11.761958+00:00",
      "contentSha256": "fb8b1a6a3f8cdf48b189e77c0355e0f2ffb0f9d6d51d7f1d8c2b29f61c0d33bc",
      "locator": "Back’s paper: the May 1997 origin against email abuse, the definition of a cost-function, partial hash collisions, probabilistic cost, and b-money among the applications.",
      "recordId": "source-42b702488d4e29bb",
      "version": null
    },
    {
      "id": "white-paper",
      "label": "Bitcoin: A Peer-to-Peer Electronic Cash System",
      "publisher": "bitcoin.org",
      "author": "Satoshi Nakamoto",
      "issued": "2008-10-31",
      "url": "https://bitcoin.org/bitcoin.pdf",
      "note": "Section 4 on proof of work, Hashcash, one-CPU-one-vote and difficulty; section 5 on validity; section 11 on an attacker’s odds; the abstract and conclusion on nodes rejoining and voting with CPU power.",
      "checkedAt": "2026-10-02T15:04:11.761440+00:00",
      "contentSha256": "b1674191a88ec5cdd733e4240a81803105dc412d6c6708d53ab94fc248f4f553",
      "locator": "Section 4 on proof of work, Hashcash, one-CPU-one-vote and difficulty; section 5 on validity; section 11 on an attacker’s odds; the abstract and conclusion on nodes rejoining and voting with CPU power.",
      "recordId": "source-0e46aca4dbc5a030",
      "version": null
    },
    {
      "id": "whitepaper-announcement",
      "label": "Bitcoin P2P e-cash paper (email to the Cryptography mailing list)",
      "publisher": "Satoshi Nakamoto Institute (archive of the Cryptography mailing list)",
      "author": "Satoshi Nakamoto",
      "issued": "2008-10-31",
      "url": "https://satoshi.nakamotoinstitute.org/emails/cryptography/1/",
      "note": "The 31 October 2008 announcement listing “new coins are made from Hashcash style proof-of-work” among Bitcoin’s main properties.",
      "checkedAt": "2026-10-02T14:48:36.957073+00:00",
      "contentSha256": "ce841e8de58019749be292a0350c3f225566d276822bd3f90e03aa6662c4741c",
      "locator": "The 31 October 2008 announcement listing “new coins are made from Hashcash style proof-of-work” among Bitcoin’s main properties.",
      "recordId": "source-ada4b38213b22142",
      "version": null
    },
    {
      "id": "wiki-pow",
      "label": "Proof of work",
      "publisher": "Bitcoin Wiki",
      "url": "https://en.bitcoin.it/wiki/Proof_of_work",
      "note": "Community reference explaining Bitcoin’s use of Hashcash-style SHA-256 proof of work, the ten-minute rate, and a worked example that took 4,251 hashes.",
      "checkedAt": "2026-10-02T14:48:37.372666+00:00",
      "contentSha256": "af960d5c7226167caa64364cfcec0719407aa6d797b9a3e30bc5104076ce44dc",
      "locator": "Community reference explaining Bitcoin’s use of Hashcash-style SHA-256 proof of work, the ten-minute rate, and a worked example that took 4,251 hashes.",
      "recordId": "source-065fc4ef4ea035e5",
      "version": null
    },
    {
      "id": "devguide-block-chain",
      "label": "Block Chain (Bitcoin Developer Guide)",
      "publisher": "developer.bitcoin.org",
      "url": "https://developer.bitcoin.org/devguide/block_chain.html",
      "note": "Describes the proof-of-work target, the 2,016-block retarget against two weeks, and the rule that nodes follow the most difficult chain to recreate.",
      "checkedAt": "2026-10-02T14:48:36.834850+00:00",
      "contentSha256": "3ddf7f1164ec8d670a5fbbcf7f4aaca7549bbc10c75f0bb3dad930dbfad08a25",
      "locator": "Describes the proof-of-work target, the 2,016-block retarget against two weeks, and the rule that nodes follow the most difficult chain to recreate.",
      "recordId": "source-190b9fe0eec933dc",
      "version": null
    },
    {
      "id": "devref-block-header",
      "label": "Block Chain: Block Headers (Bitcoin Developer Reference)",
      "publisher": "developer.bitcoin.org",
      "url": "https://developer.bitcoin.org/reference/block_chain.html",
      "note": "Specifies the 80-byte header, the nBits target encoding and the nonce as the number miners change to alter the header hash.",
      "checkedAt": "2026-10-02T14:48:37.089132+00:00",
      "contentSha256": "c3f45d19a7af38328bdf5f0691644e5444bf805b6d8f4efa72062b4150db54e3",
      "locator": "Specifies the 80-byte header, the nBits target encoding and the nonce as the number miners change to alter the header hash.",
      "recordId": "source-1f428f4e78a3eded",
      "version": null
    }
  ],
  "related": {
    "articles": [
      "how-bitcoin-mining-works",
      "bitcoin-difficulty-adjustment",
      "bitcoin-hash-rate",
      "51-percent-attack",
      "cypherpunks-before-bitcoin"
    ],
    "dossiers": [
      "how-bitcoin-blockchain-works",
      "origins-of-bitcoin"
    ],
    "wallets": [
      "patoshi-pattern-early-mining-set-2009-2010"
    ]
  },
  "revisionHistory": [
    {
      "date": "2026-09-23",
      "kind": "published",
      "summary": "Initial Bitcoin encyclopedia entry at this permanent URL."
    },
    {
      "date": "2026-10-02",
      "kind": "correction",
      "summary": "Corrected scope or wording: below a target Revised direct answer to preserve source scope and qualifications. Clarified valid-most-work selection and probabilistic finality in historical terminology."
    },
    {
      "date": "2026-10-02",
      "kind": "publishing-format",
      "summary": "Added reusable claims, explicit source locators, and matching Markdown and JSON. This publishing change does not itself establish factual verification."
    },
    {
      "date": "2026-10-02",
      "kind": "content-revision",
      "summary": "Added “A valid proof of work is only one check on a block”, clarified the search description. Independent verification is recorded separately."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Proof of work, explained without the math: why Bitcoin runs on a lottery.” Published 2026-09-23; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/proof-of-work-explained/"
}
