Skip to content

Shelf 2 · Foundations · 13 / 45

How Blockchain Works

Blocks, hashes, consensus — an illustrated guide to the distributed ledger technology behind Bitcoin.

Check this article’s sources (5)

Article brief

Whenever a new block candidate arrives, each full node checks it independently against protocol rules and the state it has already validated.

A useful mental model

Imagine everyone holding the same ledger, with every page printing a fingerprint of the page before it. That is the useful first picture of blocks and hashes.

Where the analogy stops

A hash detects change; it does not choose the valid history by itself. Proof of work, protocol rules, and node validation work together, and blockchain designs differ.

You will be able to trace how a payment moves from a candidate transaction into shared history.

Open the glossary
Article contents10 chaptersJump to a chapter

1What is a blockchain?

A blockchain is a distributed database that groups transaction data into units known as "blocks" and links them chronologically like a "chain."

A traditional database is run by a central authority such as a bank. On a blockchain, tens of thousands of computers (nodes) across the network each hold an identical copy of the data.

That structure makes tampering with the data effectively impossible, which is why the technology is described as a way to share "truth" without a trusted third party.

2Block structure

Each block has three main elements: ① a set of transaction data, ② the hash of the previous block, and ③ a nonce. The nonce is often described as a random number, but it is really a 32-bit counter: the field a miner increments as it retries the hash.

The block header holds the version, the previous block's hash, the Merkle root (a summary hash of all transactions), a timestamp, the difficulty target, and the nonce.

Bitcoin's effective block size is about 1–4MB under the post-SegWit weight limit. How many transactions fit depends on how large each one is; recent measurements generally put the count between roughly 3,000 and 7,000 per block.

A new block appears roughly every 10 minutes. The "difficulty adjustment" mechanism holds that interval steady on its own.

Figure 1 Each block stores the previous block's hash, so editing a block in the middle changes its hash, which no longer matches what the next block recorded—the chain breaks. The illustrated leading zeros are visual shorthand for a numeric hash below the proof-of-work target; restoring an altered history as a valid chain candidate requires redoing the work.

3Cryptographic hash functions

A hash function is a one-way function that turns data of any length into a fixed-length string, its hash value. Bitcoin uses the SHA-256 algorithm.

Three properties matter: ① the same input always produces the same output (determinism); ② changing a single bit of the input changes the output completely (the avalanche effect); ③ the input cannot be worked backward from the output (one-way).

The SHA-256 hashes of "Hello" and "Hello!" are completely different. This property is the cornerstone of blockchain security.

Because each block contains the hash of the block before it, altering a past block would change the hashes of every block that follows.

On its own, though, hash chaining only reveals that something was altered. To make an alteration stick, an attacker must redo the Proof of Work for the edited block and every block after it, and rebuild that chain faster than the honest chain keeps growing. Tamper resistance therefore comes from the combination of hash chaining and the cost of redoing Proof of Work, described in the next section.

4Merkle trees

A Merkle tree, or hash tree, is a data structure for summarizing and verifying large amounts of transaction data efficiently. Ralph Merkle filed for the patent in September 1979, and it was granted as US Patent 4,309,569 on January 5, 1982.

It works by hashing transactions in pairs, then hashing those results in pairs, and repeating until a single "Merkle root" remains.

The Merkle root goes into the block header. That lets anyone check whether a particular transaction is in a block without downloading all of the block's transaction data (SPV: Simplified Payment Verification).

It is what allows lightweight devices such as smartphones to verify Bitcoin transactions.

One detail is worth noting: when a level of the tree holds an odd number of hashes, Bitcoin duplicates the last one to form a pair. That rule made it possible to build the same Merkle root from different transaction orderings, the flaw reported in 2012 as CVE-2012-2459, and Bitcoin Core now rejects blocks that contain such duplication.

5Consensus mechanisms

Consensus is how a decentralized network with no central authority agrees on "which transactions are valid."

Bitcoin uses Proof of Work (PoW). Miners perform enormous amounts of computation, and whoever first finds a hash that meets the current condition earns the right to create a block.

That computation consumes large amounts of electricity and hardware. Producing a fraudulent block costs far more than mining honestly, so the economics push participants toward honest behavior.

The longest-chain rule: when the network forks, the chain with the most cumulative computational work behind it, usually the longest one, is treated as canonical.

6The role of nodes

Figure 2 Wallets, nodes, mempools, miners and blocks play different roles. Miners select and order transactions, but each node independently decides whether the resulting block is valid.

A node is a computer that runs Bitcoin software and keeps a complete copy of the blockchain. As of 2026, roughly 20,000–30,000 "reachable" full nodes, meaning those that accept incoming connections, are observed; counting the nodes behind NAT or a firewall pushes estimates of the total anywhere from tens of thousands to around 100,000. Methodology changes the count a great deal, and since the long-standing standard tracker stopped operating in May 2026 there has been no single authoritative figure, so published numbers should be read as broad estimates.

Full nodes validate every transaction and every block. If a miner produces a block that breaks the rules, full nodes reject it, which is what keeps the network coherent.

Light nodes (SPV nodes) download only block headers and use Merkle trees to check just the transactions they care about. Mobile wallets work this way.

Anyone can run a full node, and no permission is required. This "permissionless" quality underpins Bitcoin's censorship resistance.

7How transactions work

Bitcoin transactions are based on the "UTXO (Unspent Transaction Output)" model. Instead of a bank-account-style "balance," your balance is the sum of unspent "coins" you have received in past transactions.

To send Bitcoin, you name your own UTXOs as inputs and write the recipient's address and amount as outputs. Whatever is left over comes back to you as "change."

Transactions carry a fee that goes to miners. What miners actually look at is not the absolute fee but the fee rate: the fee per unit of data (sat/vB). Block space is limited, so the transactions that pay more for the same space go first. A high-value transaction can therefore wait if it is physically large, while a small payment with a compact size and a high fee rate goes through ahead of it. It is this fee rate that rises when the network is congested.

A transaction stuck with too low a fee rate can be rescued by spending its change output in a new, high-fee transaction that drags the first one along (CPFP: Child Pays For Parent), because Bitcoin Core selects transactions using the combined fee rate of a parent and its descendants.

A transaction first enters the "mempool" and is confirmed when a miner includes it in a block. Six confirmations, about 60 minutes, are normally treated as making it irreversible in practice.

8Forks

A fork is the divergence that happens when the blockchain's protocol rules change.

Soft fork: a backward-compatible upgrade. Nodes running older versions still accept the new blocks as valid. SegWit is an example.

Hard fork: an upgrade that is not backward compatible. Older nodes treat the new blocks as invalid, so the chain splits permanently. Bitcoin Cash and Bitcoin SV are examples.

Forks are a central part of how Bitcoin is governed. Anyone can propose a code change, but it takes effect only if a majority of network participants adopt it.

9Blockchain security

The 51% attack: in theory, controlling more than half the network's computing power would allow double spending and transaction censorship. In practice, Bitcoin's computing power is so vast that the cost of the attempt is astronomical.

As of August 2026, Bitcoin's hash rate has been running around 900 EH/s on a moving average, with brief instantaneous readings above 1 ZH/s (zetahash) in early 2026 and again in June 2026. A 51% attack would mean out-building the combined computing power of every miner in the world.

Bitcoin's network has no planned downtime, and its uptime since launching in 2009 is estimated at over 99.98%. That is not the same as saying nothing has ever gone wrong. In August 2010 the value overflow bug allowed an absurdly large issuance in block 74,638, and in March 2013 an incompatibility between versions 0.7 and 0.8 split the chain in two for roughly six hours. Both were resolved within hours by rolling back to a corrected version, and an accurate account of Bitcoin's uptime should mention them.

Security rests on three pillars: cryptography, economic incentives, and decentralization. No one of them is sufficient on its own, and the strength comes from the combination.

10Messages inscribed in the blockchain

Bitcoin's blockchain holds more than transaction data: many human-readable "messages" are permanently embedded in it. Coinbase transaction input fields and OP_RETURN outputs allow arbitrary data to be recorded forever.

The most famous example is in the genesis block (block 0), where Satoshi Nakamoto inscribed the headline "The Times 03/Jan/2009 Chancellor on brink of second bailout for banks" from that day's edition. It works as a timestamp and as a criticism of bank bailouts at once, and it symbolizes why Bitcoin exists.

In 2011, Dan Kaminsky and Travis Goodspeed inscribed a memorial to the security researcher Len Sassaman on the blockchain as ASCII art. The tribute showed that the chain can serve as an "indestructible monument."

Other embedded content includes prayers, internet memes ("I LIKE TURTLES"), political messages, declarations of love, and fragments of WikiLeaks diplomatic cables. Sites such as bitcoinstrings.com let you browse them.

Embedding data this way raises questions of both technical capability and social responsibility. Once recorded, it cannot be deleted, which is a real concern where illegal content is involved. That same permanence is what makes the chain valuable as a censorship-resistant medium.

The property makes Bitcoin more than a currency system: it is an "immortal distributed database." Uses outside finance, including timestamp proofs, proofs of existence, and permanent records, keep expanding.

Primary sources

Read next

Blockchain Design — Ledger, State, Consensus, Execution, and Governance18 min read
Share

Citation

Title
How Blockchain Works
Source
Bitcoin Library (bitcoin.ne.jp)
Canonical URL
https://bitcoin.ne.jp/en/learn/blockchain
Author
KK siiiiiixth
Topic
blockchain
Published
Updated
Last verified
Editorial policy
https://bitcoin.ne.jp/en/editorial-policy
About
https://bitcoin.ne.jp/en/about
License
Content reuse terms

Operator-owned article text, original diagrams, and public data may be used for citation, summarization, indexing, search, RAG, machine analysis, and AI model training. When content is presented to readers, identify Bitcoin Library and the applicable canonical URL where technically practicable.

Revision history

  1. Added a bilingual diagram separating the roles of wallet, node, mempool, miner, and block.
  2. Corrected the uptime claim to name the 2010 value overflow and the 2013 chain split. Fixed the Merkle patent to its 1982 grant, corrected fee priority to the sat/vB fee rate and added CPFP, connected hash chaining to the cost of redoing Proof of Work, and updated per-block transaction counts and hash rate to measured values.