Overview
Proof of work (also written as proof-of-work, and abbreviated PoW) is a form of cryptographic proof in which one party (the prover) proves to others (the verifiers) that a certain amount of a specific computational effort has been expended. Verifiers can subsequently confirm this expenditure with minimal effort on their part. The concept was first proposed by Moni Naor and Cynthia Dwork in 1993 as a way to deter denial-of-service attacks and other service abuses such as spam on a network by requiring some work from a service requester, usually meaning processing time by a computer.
Extending the work of Cynthia Dwork and Moni Naor, Adam Back formally described a proof of work system called Hashcash as a protection against email spam in 1997. The term "proof of work" was coined and formalized in a 1999 paper by Markus Jakobsson and Ari Juels. The concept was adapted to digital tokens by Hal Finney in 2004 through the idea of "reusable proof of work" using the 160-bit secure hash algorithm 1 (SHA-1).
Proof of work was later popularized by Bitcoin as a foundation for consensus in a permissionless decentralized network, in which miners compete to append blocks and mine new currency, each miner experiencing a success probability proportional to the computational effort expended. PoW and PoS (proof of stake) remain the two best known Sybil deterrence mechanisms. In the context of cryptocurrencies they are the most common mechanisms.
A key feature of proof-of-work schemes is their asymmetry: the work – the computation – must be moderately hard (yet feasible) on the prover or requester side but easy to check for the verifier or service provider. This idea is also known as a CPU cost function, client puzzle, computational puzzle, or CPU pricing function. Another common feature is built-in incentive-structures that reward allocating computational capacity to the network with value in the form of cryptocurrency.
8 sources for this section
- 1Proof of work — Wikipedia, revision 1371438279
- 2Lachtar, Nada; Andrius, Abdulrahman Abu; Bacha, Anys; Malik, Hafiz (2023-10-01). "A Cross-Stack Approach Towards Defending Against Cryptojacking". IEEE Computer Architecture Letters. 19 (2): 126–129. doi:10.1109/LCA.2023.3017457 (inactive 15 March 2026). ISSN 1556-6056. S2CID 222070383.
- 3Jakobsson, Markus; Juels, Ari (1999). "Proofs of Work and Bread Pudding Protocols". Secure Information Networks: Communications and Multimedia Security. Kluwer Academic Publishers: 258–272. doi:10.1007/978-0-387-35568-9_18.
- 4Dwork, Cynthia; Naor, Moni (1993). "Pricing via Processing or Combatting Junk Mail". Advances in Cryptology — CRYPTO' 92. Lecture Notes in Computer Science. Vol. 740. Springer. pp. 139–147. doi:10.1007/3-540-48071-4_10. ISBN 978-3-540-57340-1. Archived from the original on 2017-11-26. Retrieved 2012-09-10.
- 5"RPOW - Reusable Proofs of Work". nakamotoinstitute.org. Archived from the original on 2023-06-19. Retrieved 2024-01-17.
- 6"Cryptocurrencies and blockchain" (PDF). European Parliament. July 2018. Archived (PDF) from the original on 27 June 2023. Retrieved 29 October 2020. the two best-known – and in the context of cryptocurrencies also most commonly used
- 7"Proof of Work Explained in Simple Terms - The Chain Bulletin". chainbulletin.com. Archived from the original on 2023-04-01. Retrieved 2023-04-01.
- 8"The Only Crypto Story You Need, by Matt Levine". Bloomberg.com. Archived from the original on 2023-04-07. Retrieved 2023-04-01.
Background
The concept of Proof of Work (PoW) has its roots in early research on combating spam and preventing denial-of-service attacks. One of the earliest implementations of PoW was Hashcash, created by British cryptographer Adam Back in 1997. It was designed as an anti-spam mechanism that required email senders to perform a small computational task, effectively proving that they expended resources (in the form of CPU time) before sending an email. This task was trivial for legitimate users but would impose a significant cost on spammers attempting to send bulk messages.
Hashcash's system was based on the concept of finding a hash value that met certain criteria, a task that required computational effort and thus served as a "proof of work." The idea was that by making it computationally expensive to send large volumes of email, spamming would be reduced.
It is verified with a single computation by checking that the SHA-1 hash of the stamp (omit the header name X-Hashcash: including the colon and any amount of whitespace following it up to the digit '1') begins with 52 binary zeros, that is 13 hexadecimal zeros:^([1])
Evolution of proof-of-work algorithms
Proof of work traces its theoretical origins to early efforts to combat digital abuse, evolving significantly over time to address security, accessibility, and broader applications beyond its initial anti-spam purpose. The idea first emerged in 1993 as a deterrent for junk mail, but it was Satoshi Nakamoto’s 2008 whitepaper, "Bitcoin: A Peer-to-Peer Electronic Cash System," that solidified proof of work's potential as a cornerstone of blockchain networks. This development reflects the rising demands for secure, trustless systems.
The earliest appearance of proof of work was in 1993, when Cynthia Dwork and Moni Naor proposed a system to curb junk email by requiring senders to perform computationally demanding tasks. In their paper, "Pricing via Processing or Combatting Junk Mail," they outlined methods such as computing modular square roots, designed to be challenging to solve yet straightforward to verify, establishing a foundational principle of proof of work's asymmetry.
This asymmetry is crucial to the effectiveness of proof of work, ensuring that tasks like sending spam are costly for attackers, while verification remains efficient for legitimate users.
This conceptual groundwork found practical use in 1997 with Adam Back’s Hashcash, a system that required senders to compute a partial hash inversion of the SHA-1 algorithm, producing a hash with a set number of leading zeros. Described in Back’s paper "Hashcash: A Denial of Service Counter-Measure," Hashcash imposed a computational cost to deter spam while allowing recipients to confirm the work effortlessly, laying a critical foundation for subsequent proof of work implementations in cryptography and blockchain technology.
4 sources for this section
- 1Proof of work — Wikipedia, revision 1371438279
- 10Nakamoto, Satoshi (August 21, 2008). "Bitcoin: A Peer-to-Peer Electronic Cash System". SSRN Electronic Journal. doi:10.2139/ssrn.3440802. ISSN 1556-5068.
- 11Dwork, Cynthia; Naor, Moni (1993), "Pricing via Processing or Combatting Junk Mail", in Brickell, Ernest F. (ed.), Advances in Cryptology — CRYPTO' 92, vol. 740, Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 139–147, doi:10.1007/3-540-48071-4_10, ISBN 978-3-540-57340-1, retrieved 2025-02-27
Variants
Known-solution protocols tend to have slightly lower variance than unbounded probabilistic protocols because the variance of a rectangular distribution is lower than the variance of a Poisson distribution (with the same mean).^([further explanation needed]) A generic technique for reducing variance is to use multiple independent sub-challenges, as the average of multiple samples will have a lower variance.
Finally, some PoW systems offer shortcut computations that allow participants who know a secret, typically a private key, to generate cheap PoWs. The rationale is that mailing-list holders may generate stamps for every recipient without incurring a high cost. Whether such a feature is desirable depends on the usage scenario.
1 source for this section
Proof of useful work (PoUW)
At the IACR conference Crypto 2022 researchers presented a paper describing Ofelimos, a blockchain protocol with a consensus mechanism based on "proof of useful work" (PoUW). Rather than miners consuming energy in solving complex, but essentially useless, puzzles to validate transactions, Ofelimos achieves consensus while simultaneously providing a decentralized optimization problem solver. The protocol is built around Doubly Parallel Local Search (DPLS), a local search algorithm that is used as the PoUW component.
The paper gives an example that implements a variant of WalkSAT, a local search algorithm to solve Boolean problems.
The source notesEvidence & further reading13 sources
- Proof of work — Wikipedia, revision 1371438279 Wikipedia contributors · Reference source · accessed 2026-09-22
- Lachtar, Nada; Andrius, Abdulrahman Abu; Bacha, Anys; Malik, Hafiz (2023-10-01). "A Cross-Stack Approach Towards Defending Against Cryptojacking". IEEE Computer Architecture Letters. 19 (2): 126–129. doi:10.1109/LCA.2023.3017457 (inactive 15 March 2026). ISSN 1556-6056. S2CID 222070383. api.semanticscholar.org · Reference source · link imported 2026-09-22
- Jakobsson, Markus; Juels, Ari (1999). "Proofs of Work and Bread Pudding Protocols". Secure Information Networks: Communications and Multimedia Security. Kluwer Academic Publishers: 258–272. doi:10.1007/978-0-387-35568-9_18. doi.org · Reference source · link imported 2026-09-22
- Dwork, Cynthia; Naor, Moni (1993). "Pricing via Processing or Combatting Junk Mail". Advances in Cryptology — CRYPTO' 92. Lecture Notes in Computer Science. Vol. 740. Springer. pp. 139–147. doi:10.1007/3-540-48071-4_10. ISBN 978-3-540-57340-1. Archived from the original on 2017-11-26. Retrieved 2012-09-10. wisdom.weizmann.ac.il · Reference source · link imported 2026-09-22
- "RPOW - Reusable Proofs of Work". nakamotoinstitute.org. Archived from the original on 2023-06-19. Retrieved 2024-01-17. nakamotoinstitute.org · Reference source · link imported 2026-09-22
- "Cryptocurrencies and blockchain" (PDF). European Parliament. July 2018. Archived (PDF) from the original on 27 June 2023. Retrieved 29 October 2020. the two best-known – and in the context of cryptocurrencies also most commonly used europarl.europa.eu · Reference source · link imported 2026-09-22