Skip to content

Module 4 · The Bitcoin Machine / 4.6

What the work protects.

A real cost, a specific kind of security, and honest limits.

Suppose someone pays a merchant, receives the goods, and then tries to make a conflicting payment win instead.

A signature cannot settle that disagreement alone. Both instructions might be signed by the same key. The network needs a way to settle which valid history it will follow.

Work makes competing histories costly.

Bitcoin full nodes first apply their validity rules. Among competing valid chains, they follow the one with the most accumulated proof of work. “Most work” matters only after “valid.”

To replace recent accepted history, an attacker needs to produce a competing valid branch with enough work to overtake it. Meanwhile, other miners continue producing blocks. More confirmations generally increase the work that a replacement must overcome.

The protection comes from the difficulty of acquiring and operating enough hashing capacity, together with validation and network assumptions. Electricity is an important operating cost. It is not the only ingredient in security.

Work does not turn a false outside-world statement into truth. It helps participants choose and defend an ordered transaction history without appointing one company to write it.

The upper branch has more illustrated work, but violates the reward rule. It is rejected.

More work can choose between valid histories. It cannot erase a validity rule.

A majority is powerful in particular ways.

An attacker with a sustained majority of hash power can make recent-history replacement and transaction censorship much more reliable. This is often called a 51% attack. Some attacks can succeed with less than a majority; 51% is not a magic switch between zero risk and total control.

The attacker might reverse their own payment by arranging a conflicting spend to become accepted. They might keep particular transactions out of blocks. That is serious power.

It does not reveal other people’s private keys. It does not let the attacker create a block with an excessive subsidy and have unchanged full nodes accept it. Those nodes still apply their rules.

Honest mining may be more profitable than attacking, and a successful attack may damage the asset’s value. These are deterrents, not proof that an attacker must care about profit. A state, a competitor or someone with a different payoff can have different motives.

Nor does an accepted reorganization automatically undo itself when an attacker stops. The result depends on which valid history subsequent work extends.

Cheap power is not the same as harmless power.

Miners have incentives to seek low-cost electricity. Sometimes this is surplus hydroelectric power, otherwise-curtailed generation, or gas that might have been flared. Sometimes it comes from a grid or generator with substantial emissions.

The environmental result depends on the actual alternative: what generation would have run, who else needed the power, and what happened to the fuel. A low electricity bill alone answers none of those questions.

Some mining operations can reduce demand quickly when a grid needs relief. That flexibility can have value under suitable conditions. It does not prove that every location, contract or mining expansion benefits its neighbours.

Keep three measures separate: electricity consumed, emissions associated with producing it, and the usefulness people assign to the service. A country-sized electricity comparison may convey scale, but it does not by itself settle emissions or social value.

Security has an ongoing budget.

As the block subsidy shrinks, transaction fees become a more important part of mining revenue. Future prices, fees, technology and competition will affect the resources miners can afford. None is fixed by the halving schedule.

Proof of stake uses a different design: validators put assets at risk rather than compete through the same work race. We will examine its penalties and assumptions in the Ethereum module. It would be wrong to say that every decentralized system must copy Bitcoin’s energy use.

The useful question is therefore specific: what attack does this design make difficult, what does that protection cost, and which assumptions could fail? You can value a service while still asking whether its costs are justified.

The idea to keep

Proof of work helps defend the ordering of valid Bitcoin transactions. Its resource cost is real, its capabilities are bounded, and its future security budget is worth examining without pretending the answer is settled.

Make it yours

A moment to try it.

Take your time. Explain the reason, not only the answer.

1 of 4

A miner controls most hash power and proposes a block paying itself more than the subsidy and fees allow. What should unchanged full nodes do?

Choose the best explanation

Use examples only—never enter recovery words, keys, account details, or real balances. Loading saved answers…

Loading your saved progress…

Up next · Lesson 4.7The rules, and who can change them.
Sources & a little more detail

Illustrative stories and example numbers teach the mechanism. They are not forecasts or live market quotes.