Proof of work is the rule that makes adding a new block to bitcoin's ledger expensive to produce but cheap to check. Miners make trillions of guesses until one of them produces a block fingerprint below a target number, and every other computer on the network can confirm the winning guess in an instant.
That simple tradeoff, hard to make and easy to verify, is what lets thousands of strangers agree on one history of payments without a bank in the middle. Below is what proof of work is, how it works step by step, where the idea came from and how it stacks up against proof of stake.
What is proof of work?
Think of a dice game. You are told to roll ten dice until the total comes in under 15. There is no trick and no shortcut: you just keep rolling. Finding a winning roll takes ages, but when you finally shout "done", anyone at the table can glance at the dice and confirm it in a second.
Bitcoin mining works the same way, with a hash function standing in for the dice. A hash function, SHA-256 in bitcoin's case, turns any input into a fixed-length string of numbers that looks random. Change one character of the input and the output changes completely. The only way to get a hash below a given target is to keep changing the input and trying again. So a valid block hash is proof that someone spent real work to find it.
How does proof of work work, step by step?
Here is the cycle a miner repeats, roughly every ten minutes across the whole network:
- Collect transactions. The miner picks waiting transactions from the mempool, usually favoring those that pay higher fees.
- Build a block header. This short summary includes a fingerprint of those transactions, a timestamp and the hash of the previous block, which is what chains each block to the one before it.
- Add a nonce. The nonce is a number the miner is free to change. It is the "roll the dice again" knob.
- Hash and compare. The header is run through SHA-256 twice. If the result is lower than the current target, the block is valid. If not, the miner changes the nonce and tries again, trillions of times per second on a modern mining machine.
- Broadcast the winner. The first miner to find a valid hash sends the block to the network.
- Everyone checks. Nodes hash the header once, confirm it beats the target, and check every transaction against the rules. If anything is wrong, they reject the block, no matter how much work went into it.
- Collect the reward. The winning miner earns the block subsidy plus the fees from the transactions inside. The subsidy has been 3.125 BTC since April 2024 and is expected to drop to 1.5625 BTC at the next halving, around April 2028. Our guide to the next bitcoin halving explains that schedule.
A proof of work example you can picture
Hashes are usually written as long strings of numbers and letters. A lower target means the hash has to start with more zeros. Asking for one leading zero is easy; asking for nineteen or twenty of them, which is the kind of hash you see in real bitcoin blocks today, means an astronomical number of attempts.
No single machine finds blocks often. Instead, miners all over the world race in parallel, and on average somebody wins every ten minutes. It is closer to a lottery than a race: a miner with twice the hardware gets roughly twice the tickets, not a guaranteed win.
The difficulty adjustment keeps the clock steady
What happens when more miners join? Blocks would start arriving faster, so bitcoin corrects for it. Every 2,016 blocks, about two weeks, each node looks at how long those blocks actually took and moves the target up or down to bring the average back toward ten minutes. More hashing power means a harder target; less means an easier one.
This is why bitcoin's issuance stays so predictable even as mining hardware improves. It is also the reason the supply schedule behind why there are only 21 million bitcoin holds up in practice.
Why proof of work secures the ledger
The white paper sums up the voting problem neatly: "Proof-of-work is essentially one-CPU-one-vote." Voting by IP address or account could be faked by anyone who creates millions of fake identities. Voting with computing power cannot, because real hardware and electricity cost real money.
Nodes follow the valid chain with the most accumulated work. To rewrite a past payment, an attacker would have to redo the work for that block and every block after it, then outpace the rest of the network going forward. That is the so-called 51% attack, and the cost of pulling it off grows with every block added on top. The deeper a transaction is buried, the safer it is.
Proof of work only proposes blocks, though. Deciding whether a block follows the rules is the job of every node that checks it, which is why miners and bitcoin nodes are two different roles.
Where the idea came from
Proof of work is older than bitcoin by more than fifteen years:
- 1992: Cynthia Dwork and Moni Naor proposed making email senders solve a small computational puzzle, so sending junk mail in bulk would become costly.
- 1997: Adam Back released Hashcash, a working anti-spam system built on a similar hash puzzle. The bitcoin white paper cites it directly.
- 1999: Markus Jakobsson and Ari Juels gave the concept its name, proof of work, in a research paper.
- 2004: Hal Finney built RPOW, reusable proofs of work, an early experiment in turning computing effort into transferable tokens.
- 2008: Satoshi Nakamoto's white paper used proof of work for something new: ordering transactions so nobody could spend the same coin twice.
Proof of work vs proof of stake
Proof of stake is the best known alternative. Instead of spending electricity, validators lock up coins as collateral, and the protocol picks who proposes the next block in proportion to the amount staked. Peercoin was the first working example in 2012, and Ethereum switched from proof of work to proof of stake in September 2022 in an upgrade called the Merge, cutting its energy use by more than 99%.
Both designs have serious engineers defending them. Here is a fair summary of the tradeoffs:
- What it costs to attack. Proof of work ties security to outside costs, hardware and power. Proof of stake ties it to coins inside the system, which validators can lose through penalties if they cheat.
- Energy. Proof of work uses a lot of electricity, which is its most common criticism. Supporters reply that the cost is the security, and point to miners using cheap or stranded power. Proof of stake uses a tiny fraction of the energy.
- Who takes part. Anyone with hardware and electricity can mine without asking permission. Staking needs coins first, and critics of both systems worry about influence pooling in a few large miners or a few large stakers.
- Track record. Bitcoin's proof of work has run since January 2009. Proof of stake is younger and has gone through more design changes.
Bitcoin has stayed with proof of work since day one, and changing that would require near universal agreement among the people who run its software.
Shirts for people who respect the work
Our Proof of Work tee pairs an orange pickaxe with the phrase in big white capitals, so miners read it as a mining joke and everyone else reads it as a work ethic. The Node Runner tee is for the other half of the system, an orange outline of a little server box with its status lights on. And Halving 2028 shows an orange coin split in two, for anyone already counting blocks to the next reward cut. Every shirt is printed when you order it and ships from the USA, and the rest of the range is on our bitcoin t-shirts page.
Sources: the bitcoin white paper, Wikipedia on proof of work and Wikipedia on proof of stake.


