Skip to content

Shelf 3 · Mechanics · 17 / 45

How Mining Works

Proof of Work, difficulty adjustments, hardware evolution — the full picture of Bitcoin mining.

Check this article’s sources (19)

Article brief

Miners are not digging for a hidden vein of coins. They keep changing small values in a candidate block until its hash satisfies the rules.

A useful mental model

Imagine participants worldwide producing lottery tickets that can be obtained only through computation; a winning ticket earns the chance to propose the ledger’s next page.

Where the analogy stops

Unlike an ordinary lottery, every full node independently checks the proposal and rejects an invalid block. Hashrate does not grant the power to rewrite protocol rules at will.

You will see where electricity turns into security, and why mining moved from CPUs to ASICs.

Open the glossary
Article contents10 chaptersJump to a chapter

1Key facts

Comparison table for Key facts
ItemValue
ConsensusProof of Work (double SHA-256)
Difficulty adjustmentEvery 2,016 blocks (~2 weeks); each change clamped to 1/4x–4x
Target block interval10 minutes (measured average since genesis: ~9.62 minutes)
Current block reward3.125 BTC (since the 4th halving, April 20, 2024)
Coinbase maturityMined rewards are unspendable for 100 blocks
Network hash rateAround 900 EH/s (as of August 2026, moving average)
Annual electricity use~141 TWh per the CBECI best-guess estimate (as of early August 2026)

The consensus mechanism, adjustment period, target interval, reward amount, and coinbase maturity are fixed protocol rules. Hash rate and electricity use are point-in-time estimates that move daily, so check the primary data in the sources below for current values.

2What is mining?

A miner selects transactions it considers valid, constructs a candidate block, varies block-header data in search of proof of work, and proposes a qualifying candidate to the network. The coinbase of an accepted block assigns the newly issued bitcoin and transaction fees.

Miners do not decide validity on their own. Every full node independently checks the transactions, block structure, issuance, scripts, and proof of work against the consensus rules, and rejects invalid candidates. Mining attaches cost to proposed history in an open-participation network and supports issuance and ordering by cumulative work.

The name "mining" comes from gold mining. Like gold, Bitcoin must be "mined" by putting in resources: computing power and electricity.

3Proof of Work

Proof of Work (PoW) searches for a SHA-256d hash of a block header that is numerically below the network target. “Leading zeros” is a visual shorthand; the rule compares a 256-bit integer with the target. A valid hash is probabilistic evidence of the expected search work at the current target.

Miners vary more than the nonce: coinbase extra nonce data, the transaction set, timestamps, and other permitted header inputs create further candidates. The number of trials is not fixed; it is a random variable governed by success probability and network difficulty.

A miner that finds a below-target hash broadcasts a candidate block. Other nodes cheaply recompute SHA-256d and the target comparison, then separately validate transactions, scripts, issuance, the Merkle root, and every other consensus rule. A candidate can become stale in propagation and later history can reorganize, so finding a hash is not the same as final settlement.

PoW is "hard to compute, easy to verify" and that asymmetry is the source of the network's security.

Figure 1 A simplified search loop: change the nonce or other data that affects the header and seek a numeric SHA-256d result below the target. The candidate is then broadcast, and every full node validates the proof of work and all block rules; discovery alone is not instant finality.

4Difficulty adjustment

Bitcoin is designed to produce one block roughly every 10 minutes. To hold that interval, the mining difficulty adjusts automatically every 2,016 blocks (about two weeks).

If blocks arrive too fast, difficulty rises; if too slowly, it falls. The correction is retrospective, however: the network looks at how long the previous 2,016 blocks actually took and only then sets the difficulty for the next 2,016. The rate is not "held constant" so much as allowed to drift and then pulled back toward 10 minutes. Each adjustment is clamped to a 1/4x–4x range, so difficulty moves only in steps even when hash rate swings sharply.

Because the correction lags, the measured average interval is not exactly 10 minutes. From the genesis block through block 962,733 the measured average is about 9.62 minutes, or 17 years of running slightly fast.

Difficulty is expressed as a "target hash value." The hash a miner finds must be smaller than that target, and the smaller the target, the higher the difficulty.

As of 2026, difficulty stands at roughly 130 trillion times its initial 2009 value, a measure of how far mining power has grown in 17 years (difficulty adjusts up or down every 2,016 blocks and has recently hovered around the 100-trillion-times range).

5Simultaneous discovery and stale blocks

Two miners sometimes find a valid block at almost the same moment. The network splits briefly into two branches, and as soon as the next block lands on one of them, the shorter branch is discarded. The discarded block was neither invalid nor fraudulent; it simply lost the race. Blocks like this are known as stale, or orphan, blocks, and the miner who produced one loses the reward.

The chance of producing a stale block depends on how quickly a block propagates across the network, which is why well-connected, larger miners are often said to have an edge. A strategy that deliberately exploits this asymmetry, withholding a found block for a while so that rival miners waste work, was described theoretically in 2013 as "selfish mining," though no clear instance of it being executed on Bitcoin mainnet has been documented.

This is also why confirmations matter. The most recent blocks are the ones most likely to be replaced, so larger payments are worth more confirmations. For the same reason, a mined block reward (the coinbase) cannot be spent until 100 blocks have passed, a rule that guards against exactly this kind of chain reorganization.

6How mining hardware evolved

Early Bitcoin clients contained a CPU miner. In 2010, contributors shared an SSE2 implementation that parallelized SHA-256 on Intel and AMD CPUs, followed that October by a public OpenCL miner used with ATI and NVIDIA GPUs. Open-source designs targeted FPGAs from the then-independent Xilinx and Altera in 2011, while Canaan’s SEC filing records shipment of Avalon ASIC machines in January 2013. These transitions overlapped; participants did not all switch device classes on one date.

A CPU executes broad software, a GPU parallelizes many trials, an FPGA maps the SHA-256 data path into reconfigurable logic, and an ASIC fixes it in silicon. A stable algorithm and revenue tied to hash rate against electricity and capital costs rewarded specialization. Claims that a GPU or ASIC is simply some fixed number of times “faster” hide the application, the precision, and the measurement boundary.

Competitive Bitcoin mining now centers on SHA-256 ASIC systems, but a system is more than an ASIC die: it needs controllers, boards, memory, power supplies, firmware, air or liquid cooling, networking, and a facility. System firms including Canaan, Bitmain, and MicroBT, foundries, packaging and test suppliers, pools, and operators occupy distinct roles. Intel also entered with Blockscale in 2022 but issued a product-discontinuance notice in 2023; entry by a large company and business persistence are different facts. Chip J/TH, wall-level miner efficiency, and facility efficiency are different measurements.

The full lineage, from CPU, GPU, FPGA, and ASIC through programmability, parallelism, data movement, manufacturing, and corporate roles, is covered in “Computing Hardware.”

7Mining pools

A mining pool is an arrangement in which many miners combine their computing power to raise the odds of finding blocks. Rewards are then split among the participants in proportion to the power each contributed.

For a miner working alone, the chances resemble a lottery. In a pool the payouts are small but steady.

Measured by blocks mined over the trailing month (as of August 2026), the ranking is Foundry USA 1,132, AntPool 854, F2Pool 741, SpiderPool 377, ViaBTC 361, MARA Pool 199, SECPOOL 187, and Luxor 144, with the top two pools alone accounting for roughly 45% of all blocks. Rankings and shares shift quickly as operators exit or merge and miners move, so treat these as point-in-time figures.

Pool concentration is a concern for network decentralization. If a single pool exceeds 50% of the hash rate, a 51% attack becomes theoretically possible. Participants can switch pools at any time, which is a real check, but it does not resolve the problem. Under Stratum V1, the widely used pool protocol, the pool rather than the individual miner decides what goes into a block (the block template); miners merely lend hash power. Censoring specific transactions therefore works for as long as it takes miners to notice and move. Stratum V2 is the proposal that hands template construction back to miners, and its adoption is still in progress.

8Energy consumption and the debate

Bitcoin mining's annual electricity consumption is comparable to that of some countries. On the standard reference index, the Cambridge Bitcoin Electricity Consumption Index (CBECI), the best-guess estimate is approximately 141 TWh per year as of early August 2026.

That figure is an estimate, not a measurement. CBECI models the mix of hardware miners are running, so pushing that assumption toward "everyone runs the most efficient machines" or "everyone runs the least efficient" produces a lower and upper bound spanning roughly 75–250 TWh. Numbers of this kind should always be read together with their band and their as-of date rather than as a single settled value.

Critics call it "a waste of energy," but proponents counter that it is "the necessary cost of maintaining value security."

Renewable energy use has been rising. Regions with abundant hydropower (Iceland, Canada, Norway) and flare gas mining that burns off excess natural gas have both drawn attention.

The sustainable-energy share depends heavily on who measured it and how. The Bitcoin Mining Council (BMC), an industry body, reports approximately 60%, but that figure aggregates self-reported data from member firms and covers only about half the network. Cambridge's independent estimate puts the share at roughly 52.4%. The two differ in what counts as "sustainable" (whether nuclear is included, for instance) and in how much of the network they cover, so they should be compared with their measurement conditions attached rather than quoted one at a time. Improving that mix remains a priority for the industry.

9Block rewards and fees

Miner revenue comes from two sources: ① the block reward (newly issued BTC) and ② transaction fees (the sum of the fees on the transactions in the block).

Block rewards halve at each halving. After the fourth halving in 2024, the reward is 3.125 BTC. Once all bitcoin has been issued, around 2140, fees alone will make up miner revenue.

Transaction fees rise and fall with network congestion. During peak periods in 2017 and 2021, fees sometimes exceeded $50 per transaction; the highest on record is an average of about $128 per transaction on April 20, 2024, when the fourth halving coincided with the launch of Runes (an Ordinals-derived token standard).

Whether fee revenue alone can sustain miner incentives over the long run is one of the open questions about Bitcoin's sustainability.

10Quantum computing and mining

For SHA-256 search, Grover's algorithm offers an idealized square-root query speed-up. That is not the same as a quantum miner instantly gaining majority hash power. Fault-tolerant circuits, error correction, execution rate, power, parallelism, and competition with classical ASICs are separate engineering constraints, and no practical quantum mining attack has been publicly demonstrated.

Signatures are a different surface. If a sufficiently large error-corrected quantum computer existed, Shor's algorithm would create a path from an exposed secp256k1 public key to its private key. This concerns both ECDSA and BIP 340 Schnorr. Resource estimates depend on assumptions about hardware, error rates, and circuits, so this site does not forecast a practical attack date.

Public-key exposure varies by output type, address reuse, and off-chain information such as extended public keys and descriptors; “never spent means safe” is not a general rule. The dedicated article “Can Quantum Computers Break Bitcoin?” separates the algorithms, exposure models, NIST standards, and Draft migration proposals using primary sources.

Primary sources

Read next

What is the Halving?7 min read
Share

Citation

Title
How Mining Works
Source
Bitcoin Library (bitcoin.ne.jp)
Canonical URL
https://bitcoin.ne.jp/en/learn/mining
Author
KK siiiiiixth
Topic
mining
Published
Updated
Last verified
Editorial policy
https://bitcoin.ne.jp/en/editorial-policy
About
https://bitcoin.ne.jp/en/about
License
Content reuse terms

Operator-owned article text, original diagrams, and public data may be used for citation, summarization, indexing, search, RAG, machine analysis, and AI model training. When content is presented to readers, identify Bitcoin Library and the applicable canonical URL where technically practicable.

Revision history

  1. Replaced leading-zero shorthand with the numeric 256-bit target comparison; clarified expected search work, non-nonce candidate space, full-node validation, and stale/reorganization boundaries; added Intel Blockscale entry and discontinuance with its chip-level measurement boundary; and separated Shor from Grover and signatures from mining while removing unsupported fixed dates, fixed qubit counts, and never-spent-address generalizations.
  2. Separated miner block proposal from independent full-node validation. Rebuilt the CPU, GPU, FPGA, and ASIC history around early code, contemporary OpenCL/FPGA records, and an SEC filing; removed unsupported speed ratios, the laptop claim, and current product ranking.
  3. Added a key-facts table; corrected the energy estimate to the model-based CBECI estimate with its band and as-of date, presented both BMC and Cambridge sustainability estimates, updated observed pool shares with concentration, added the all-time-high fee, and added a stale-block / selfish-mining section.