# Proof of work, explained without the math: why Bitcoin runs on a lottery

Proof of work produces evidence of computational effort that is much cheaper to check than to produce. Bitcoin miners repeatedly hash candidate block headers until the result is at or below the target. Nodes still validate every block’s rules and select the valid chain with the most accumulated work. Hashcash supplied a cited precursor; proof of work does not make an invalid transaction valid.

Evidence: [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf); [Hashcash - A Denial of Service Counter-Measure](https://cdn.nakamotoinstitute.org/docs/hashcash.pdf); [Block Chain (Bitcoin Developer Guide)](https://developer.bitcoin.org/devguide/block_chain.html)

Canonical: https://degreesofsatoshi.com/encyclopedia/proof-of-work-explained/
Published: 2026-09-23
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T18:22:07.965Z

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Origin:** Hashcash, proposed by Adam Back in May 1997 to throttle email spam ([Hashcash - A Denial of Service Counter-Measure](https://cdn.nakamotoinstitute.org/docs/hashcash.pdf))
- **Cited by:** The white paper, section 4: “a proof-of-work system similar to Adam Back’s Hashcash” ([Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf))
- **Announced as:** “Hashcash style proof-of-work,” in Satoshi’s 31 October 2008 email ([Bitcoin P2P e-cash paper (email to the Cryptography mailing list)](https://satoshi.nakamotoinstitute.org/emails/cryptography/1/))
- **The puzzle:** Find a header whose SHA-256 hash begins with enough zero bits ([Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf); [Proof of work](https://en.bitcoin.it/wiki/Proof_of_work))
- **The check:** One hash; verifying a solution costs almost nothing compared with finding it ([Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf); [Hashcash - A Denial of Service Counter-Measure](https://cdn.nakamotoinstitute.org/docs/hashcash.pdf))
- **The knob:** Difficulty retargets every 2,016 blocks toward one block per ten minutes ([Block Chain (Bitcoin Developer Guide)](https://developer.bitcoin.org/devguide/block_chain.html); [Proof of work](https://en.bitcoin.it/wiki/Proof_of_work))

## Proof of work is a receipt for effort that anyone can check

Imagine you could prove you had spent an hour on a task, in a way that a stranger could confirm in a second without watching you do it. That is proof of work. In Bitcoin the task is computing hashes. A hash function is a fixed recipe that turns any input into a short, fixed-length fingerprint, and a good one is unpredictable: change one character of the input and the fingerprint changes completely, with no way to steer the output except by trying inputs.

The Bitcoin white paper describes the puzzle in a sentence. The work “involves scanning for a value that when hashed, such as with SHA-256, the hash begins with a number of zero bits.” Because you cannot steer the output, the only way to find such a value is to try, and try, and try. The paper then states the property that makes the whole thing useful: the average work required “is exponential in the number of zero bits required and can be verified by executing a single hash.”

Hard to make, trivial to check. That asymmetry is the entire idea, and everything else in this article follows from it.

Evidence: [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf)

## It was invented to make spam expensive, not to make money

Proof of work predates Bitcoin by more than a decade. In a 2002 paper, the cryptographer Adam Back wrote that Hashcash “was originally proposed as a mechanism to throttle systematic abuse of un-metered internet resources such as email, and anonymous remailers in May 1997.” The problem was spam. Sending an email costs nothing, so a spammer can send millions. If every message had to carry a small proof of work, ordinary users would never notice the cost, but bulk mailers would.

Back called the general idea a cost-function, and set out what a good one looks like: “efficiently verifiable, but parameterisably expensive to compute.” Hashcash works by “finding partial hash collisions,” that is, hashing until the output starts with a run of zero bits. Back described its cost as probabilistic: minting a token has “a predictable expected time, but a random actual time,” because the searcher starts from a random point and “sometimes the client will get lucky.” Keep that phrase in mind. It is the lottery.

The paper’s list of applications ends with one that reads differently now: hashcash “as a minting mechanism for Wei Dai’s b-money electronic cash proposal, an electronic cash scheme without a banking interface.” The Bitcoin white paper cites Back’s paper directly, and Satoshi’s first public email, on 31 October 2008, listed among Bitcoin’s properties that “new coins are made from Hashcash style proof-of-work.” The lineage runs through the [cypherpunks](/encyclopedia/cypherpunks-before-bitcoin/) of the 1990s, and the site’s [origins dossier](/history/origins-of-bitcoin/) maps which component came from where.

Evidence: [Hashcash - A Denial of Service Counter-Measure](https://cdn.nakamotoinstitute.org/docs/hashcash.pdf); [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf); [Bitcoin P2P e-cash paper (email to the Cryptography mailing list)](https://satoshi.nakamotoinstitute.org/emails/cryptography/1/)

## Mining is a lottery where every hash is a ticket

Here is the whole of Bitcoin mining, without equations. A miner assembles a block and its header, a summary of 80 bytes that includes a field called the nonce, described in the developer reference as “an arbitrary number miners change to modify the header hash.” The miner hashes the header. If the result is below the current target, the block is valid. If not, the miner changes the nonce and hashes again.

Each hash is a lottery ticket. The target sets how many winning numbers exist; a lower target means fewer winners and more tickets needed on average. The Bitcoin Wiki gives a toy example: to find a variant of “Hello, world!” whose hash falls below a modest target, it took 4,251 attempts, which “on a modern computer is not very much work.” Bitcoin’s real target is set so that the entire network, buying tickets as fast as it can, wins about once every ten minutes.

Two features of a lottery carry over exactly. First, more tickets mean better odds, never a guarantee; a miner with a tenth of the network’s hashing power wins roughly a tenth of the blocks over time, but the next block could go to anyone. Second, a winning ticket is instantly checkable. You do not need to watch someone do the work; you check one hash. That is what lets strangers agree on who won without trusting each other.

Evidence: [Block Chain: Block Headers (Bitcoin Developer Reference)](https://developer.bitcoin.org/reference/block_chain.html); [Proof of work](https://en.bitcoin.it/wiki/Proof_of_work); [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf)

## Why a lottery, of all things, keeps a ledger honest

The strange part is why a lottery should keep a financial record honest. The answer is that the ledger is a chain, and every block carries its own proof of work. Once the effort has been spent on a block, the white paper says, it “cannot be changed without redoing the work,” and “as later blocks are chained after it, the work to change the block would include redoing all the blocks after it.”

Suppose you wanted to erase a payment you made an hour ago. You would need to produce a replacement for that block, then replacements for every block since, and then keep going faster than the rest of the network, which has not stopped. The white paper works through the odds and finds that the probability of a slower attacker catching up “diminishes exponentially as subsequent blocks are added.” That is why [confirmations](/encyclopedia/bitcoin-confirmations/) matter: each one is another round of the lottery the attacker would have to win.

The developer guide states the practical consequence: nodes follow the chain that is the most difficult to recreate. Not the longest by count, and not the one from the loudest source; the one with the most proven work behind it. That rule lets a computer that has been offline for a week rejoin, look at competing chains and pick the right one with no one’s help, which the white paper’s abstract describes as accepting the longest proof-of-work chain “as proof of what happened while they were gone.”

Evidence: [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf); [Block Chain (Bitcoin Developer Guide)](https://developer.bitcoin.org/devguide/block_chain.html)

## One CPU, one vote: work as the way to count heads on the internet

Proof of work also solves a problem that has nothing to do with money: how to count votes on the internet. If the network decided things by one vote per computer address, the white paper notes, it “could be subverted by anyone able to allocate many IPs.” Fake identities are free. Work is not. So, in the paper’s phrase, “proof-of-work is essentially one-CPU-one-vote,” and the majority decision “is represented by the longest chain, which has the greatest proof-of-work effort invested in it.”

This is the sense in which Bitcoin has no boss. There is no list of members and no meeting. Miners express what they accept by building on it and reject what they do not by refusing to, and the paper’s closing section says as much: nodes “vote with their CPU power.” Satoshi returned to this theme repeatedly in correspondence, collected in the site’s [proof-of-work and mining topic guide](/satoshi/correspondence/topics/proof-of-work-mining-difficulty/).

Evidence: [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf)

## What proof of work does not do

Proof of work does not decide what is valid. That job belongs to the rules every node checks: signatures, amounts, no double spends. The white paper’s network steps say nodes accept a block “only if all transactions in it are valid and not already spent,” so a block with enormous work behind it and one invalid transaction inside is rejected outright. Work decides which of several valid histories to follow; it never makes an invalid one acceptable.

It does not make blocks arrive on a timer, either. It makes them arrive on average every ten minutes, and the developer guide explains how: every 2,016 blocks the network compares the time taken against two weeks and moves the target to compensate. Individual blocks can arrive seconds apart or take far longer, because a lottery has no memory. And it does not run for free. The work is real electricity spent on real hardware, and whether that cost is worth what it buys is the argument behind most debates about Bitcoin’s energy use. The [mining article](/encyclopedia/how-bitcoin-mining-works/) picks up there.

Evidence: [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf); [Block Chain (Bitcoin Developer Guide)](https://developer.bitcoin.org/devguide/block_chain.html)

## Work selects among valid histories

The white paper often calls the preferred history the longest chain. The relevant measure is accumulated proof of work among chains that satisfy validation rules; a higher block count or extra hashing does not authorize invalid spends.

This selection provides probabilistic finality. A modelled catch-up probability is conditional on its assumptions about attacker hash power and behavior. It does not promise that any fixed confirmation count makes every payment irreversible.

Evidence: [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf)

## A valid proof of work is only one check on a block

The mining test compares the block-header hash with a target. A miner changes candidate data and tries again when the hash fails that test; finding a satisfactory header is evidence of probabilistic work, not proof that every transaction in the block is allowed.

Validation still checks the block against the rules. A block containing an invalid spend does not become valid merely because its miner did substantial work. Chain selection then compares accumulated work among the histories a node accepts as valid. Keeping these steps separate avoids the misleading idea that miners can vote invalid payments into validity.

Evidence: [Block Chain (Bitcoin Developer Guide)](https://developer.bitcoin.org/devguide/block_chain.html); [Block Chain: Block Headers (Bitcoin Developer Reference)](https://developer.bitcoin.org/reference/block_chain.html); [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf)

## Questions

### Who invented proof of work?

Adam Back proposed Hashcash in May 1997 as a way to throttle email spam, and Bitcoin’s white paper cites his 2002 paper on it. Back himself notes that Cynthia Dwork and Moni Naor had earlier proposed a CPU pricing function against junk mail, of which he was unaware at the time.

Evidence: [Hashcash - A Denial of Service Counter-Measure](https://cdn.nakamotoinstitute.org/docs/hashcash.pdf); [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf)

### What problem are Bitcoin miners actually solving?

Miners search for a block header whose double-SHA-256 hash meets the target. They can try another nonce or change other candidate data that alters the header. A successful header is quick to hash and compare with the target, but a node must also validate the block’s transactions and other rules.

Evidence: [Block Chain: Block Headers (Bitcoin Developer Reference)](https://developer.bitcoin.org/reference/block_chain.html); [Block Chain (Bitcoin Developer Guide)](https://developer.bitcoin.org/devguide/block_chain.html)

### Why does the difficulty keep changing?

To keep blocks arriving about every ten minutes as hardware and participation change. Every 2,016 blocks the network measures how long they took, compares it with two weeks, and moves the target so that faster hashing does not mean faster blocks.

Evidence: [Block Chain (Bitcoin Developer Guide)](https://developer.bitcoin.org/devguide/block_chain.html); [Proof of work](https://en.bitcoin.it/wiki/Proof_of_work)

### Is proof of work the same as mining?

Mining is the activity: gathering transactions and searching for a valid block. Proof of work is the mechanism that makes the search costly and the result cheap to verify. Bitcoin uses proof of work for mining; the same idea was used for spam control before Bitcoin existed.

Evidence: [Hashcash - A Denial of Service Counter-Measure](https://cdn.nakamotoinstitute.org/docs/hashcash.pdf); [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf)

## Claims and scope

### proof-of-work-explained-quick-answer

Proof of work produces evidence of computational effort that is much cheaper to check than to produce. Bitcoin miners repeatedly hash candidate block headers until the result is at or below the target. Nodes still validate every block’s rules and select the valid chain with the most accumulated work. Hashcash supplied a cited precursor; proof of work does not make an invalid transaction valid.

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

### proof-of-work-explained-fact-origin

Origin: Hashcash, proposed by Adam Back in May 1997 to throttle email spam

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

### proof-of-work-explained-fact-cited-by

Cited by: The white paper, section 4: “a proof-of-work system similar to Adam Back’s Hashcash”

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

### proof-of-work-explained-fact-announced-as

Announced as: “Hashcash style proof-of-work,” in Satoshi’s 31 October 2008 email

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

### proof-of-work-explained-fact-the-puzzle

The puzzle: Find a header whose SHA-256 hash begins with enough zero bits

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

### proof-of-work-explained-fact-the-check

The check: One hash; verifying a solution costs almost nothing compared with finding it

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

### proof-of-work-explained-fact-the-knob

The knob: Difficulty retargets every 2,016 blocks toward one block per ten minutes

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

## Sources

- [Hashcash - A Denial of Service Counter-Measure](https://cdn.nakamotoinstitute.org/docs/hashcash.pdf) — Satoshi Nakamoto Institute (archived copy of the hashcash.org paper). Back’s paper: the May 1997 origin against email abuse, the definition of a cost-function, partial hash collisions, probabilistic cost, and b-money among the applications. Locator: Back’s paper: the May 1997 origin against email abuse, the definition of a cost-function, partial hash collisions, probabilistic cost, and b-money among the applications.. Retrieved: 2026-10-02T15:04:11.761958+00:00.
- [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf) — bitcoin.org. Section 4 on proof of work, Hashcash, one-CPU-one-vote and difficulty; section 5 on validity; section 11 on an attacker’s odds; the abstract and conclusion on nodes rejoining and voting with CPU power. Locator: Section 4 on proof of work, Hashcash, one-CPU-one-vote and difficulty; section 5 on validity; section 11 on an attacker’s odds; the abstract and conclusion on nodes rejoining and voting with CPU power.. Retrieved: 2026-10-02T15:04:11.761440+00:00.
- [Bitcoin P2P e-cash paper (email to the Cryptography mailing list)](https://satoshi.nakamotoinstitute.org/emails/cryptography/1/) — Satoshi Nakamoto Institute (archive of the Cryptography mailing list). The 31 October 2008 announcement listing “new coins are made from Hashcash style proof-of-work” among Bitcoin’s main properties. Locator: The 31 October 2008 announcement listing “new coins are made from Hashcash style proof-of-work” among Bitcoin’s main properties.. Retrieved: 2026-10-02T14:48:36.957073+00:00.
- [Proof of work](https://en.bitcoin.it/wiki/Proof_of_work) — Bitcoin Wiki. Community reference explaining Bitcoin’s use of Hashcash-style SHA-256 proof of work, the ten-minute rate, and a worked example that took 4,251 hashes. Locator: Community reference explaining Bitcoin’s use of Hashcash-style SHA-256 proof of work, the ten-minute rate, and a worked example that took 4,251 hashes.. Retrieved: 2026-10-02T14:48:37.372666+00:00.
- [Block Chain (Bitcoin Developer Guide)](https://developer.bitcoin.org/devguide/block_chain.html) — developer.bitcoin.org. Describes the proof-of-work target, the 2,016-block retarget against two weeks, and the rule that nodes follow the most difficult chain to recreate. Locator: Describes the proof-of-work target, the 2,016-block retarget against two weeks, and the rule that nodes follow the most difficult chain to recreate.. Retrieved: 2026-10-02T14:48:36.834850+00:00.
- [Block Chain: Block Headers (Bitcoin Developer Reference)](https://developer.bitcoin.org/reference/block_chain.html) — developer.bitcoin.org. Specifies the 80-byte header, the nBits target encoding and the nonce as the number miners change to alter the header hash. Locator: Specifies the 80-byte header, the nBits target encoding and the nonce as the number miners change to alter the header hash.. Retrieved: 2026-10-02T14:48:37.089132+00:00.

## Revision history

- 2026-09-23: Initial Bitcoin encyclopedia entry at this permanent URL.
- 2026-10-02: Corrected scope or wording: below a target Revised direct answer to preserve source scope and qualifications. Clarified valid-most-work selection and probabilistic finality in historical terminology.
- 2026-10-02: Added reusable claims, explicit source locators, and matching Markdown and JSON. This publishing change does not itself establish factual verification.
- 2026-10-02: Added “A valid proof of work is only one check on a block”, clarified the search description. Independent verification is recorded separately.

## Cite this entry

Degrees of Satoshi editorial project. “Proof of work, explained without the math: why Bitcoin runs on a lottery.” Published 2026-09-23; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/proof-of-work-explained/
