h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Bitcoin & Layer-1s

Anatomy of a Hash: What Bitcoin’s Miners Actually Compute

Bitcoin's network makes more than 900 quintillion SHA-256 guesses a second. Here is what a single one of those guesses actually is, and why the guessing is the whole point.

The number nobody stops to picture

On any given second in October 2026, the machines that secure Bitcoin try more than 900 quintillion times to guess a number. The industry rounds that off to a hashrate of roughly 925 to 985 exahashes per second (EH/s), depending on the window you measure, and talks about it as if it were a single physical quantity like temperature or rainfall. The CoinWarz tracker put the spot figure near 925 EH/s in early October; mining-focused outlets quoting a seven-day average had it closer to 985, a hair under a zettahash, after months spent above that line.

A year ago the number was bigger. Bitcoin’s hashrate pushed past one zettahash per second (1,000 EH/s) in September 2025 and peaked near 1.1 ZH/s in late 2025, within days of BTC setting its own record of $126,080 on 6 October 2025. Both have since come off those highs. Bitcoin trades near $82,500, roughly a third below the record, per CoinGecko, and the hashrate has spent 2026 drifting mostly sideways before climbing back toward a zettahash in the autumn.

HOGE Wire has written a great deal this year about what that number means: whether it signals a healthy network, where the machines physically sit, who owns them, and why the growth stalled. This piece asks a narrower and more literal question. When a miner adds one hash to that total, what exactly has it computed? What is inside a single guess? The answer runs from a 256-bit function designed by a US federal agency to an 80-byte string of data, and it quietly explains almost everything else about Bitcoin mining, including why it burns so much electricity and why nobody can fake it.

What a hash actually is

Start with the function. SHA-256 is a cryptographic hash function: feed it any input, from a single character to a feature film, and it returns a fixed 256-bit output, written as 64 hexadecimal characters. The same input always produces the same output, which is what makes it useful as a digital fingerprint. Change the input by a single bit and the output changes completely and unpredictably, a property called the avalanche effect. And it is one-way: given an output, there is no known method faster than brute force to find an input that produces it.

SHA-256 is not a Bitcoin invention. It is a public standard, published by the US National Institute of Standards and Technology as part of the Secure Hash Algorithm 2 family in FIPS 180-4, and it runs far outside crypto, inside the TLS certificates that protect web traffic, software-signing pipelines and password storage. Under the hood it chews through its input in 512-bit chunks, pushing each through 64 rounds of bit-shifts, modular additions and logical operations on eight 32-bit working variables. The internals matter less than the shape of the thing: a fixed amount of arithmetic, with no shortcuts and no memory of past inputs.

Bitcoin adds one wrinkle. It does not hash the block header once; it hashes it twice, computing SHA256(SHA256(header)), an arrangement often written as SHA-256d. The double pass was Satoshi Nakamoto’s choice, widely read as insurance against a class of length-extension weaknesses that affect a single SHA-256 call. For a miner it simply means that every guess is two hash computations stacked back to back, and that the thing being guessed at is the output of the second one.

The 80-byte block header is the only thing a miner hashes

Here is the part that surprises most people: a miner does not hash the block’s transactions. It hashes a compact 80-byte summary called the block header, and nothing else. Every payment the block actually carries is folded into that header through a single 32-byte field. The header has exactly six fields, and their sizes never change.

FieldSizeWhat it holdsChanges while mining?
Version4 bytesBlock version plus bits miners may reuse as scratch spaceYes (version rolling)
Previous block hash32 bytesThe hash of the block before this oneNo
Merkle root32 bytesA single hash committing to every transaction in the blockYes (via extranonce)
Timestamp4 bytesCurrent time in seconds since 1970Occasionally
Bits (nBits)4 bytesThe current target, in packed formNo (fixed per period)
Nonce4 bytesPure scratch space, incremented while searchingYes, constantly

The previous block’s hash is what chains blocks together. Because it sits inside this header and feeds the hash, you cannot alter an old block without changing every header built on top of it. The Merkle root is a single hash that commits to every transaction in the block through a tree of pairwise hashes; swap one transaction and the root changes, and so does the header. The timestamp and the bits field (the target, in a packed format we will come to) round out the real data. Then there is the nonce: four bytes of pure scratch whose only job is to be changed over and over until the whole header hashes to something acceptable. That search, repeated across the planet, is mining.

The elegance is that those 80 bytes stand in for everything. A block can hold thousands of transactions and well over a megabyte of data, yet a miner only ever hashes the fixed-size header, because the Merkle root already compresses the block’s entire contents into 32 bytes. Tamper with any transaction and the root changes, the header changes, and the hash no longer clears the target. The single number a miner hunts is therefore both a lottery ticket and a tamper-evident seal over everything the block contains, which is why securing 80 bytes is enough to secure the whole thing.

The puzzle is a number below a threshold

What counts as acceptable? The header’s hash, read as a single enormous 256-bit number, has to come out below a value called the target. Satoshi described it plainly in the 2008 white paper: the proof-of-work, he wrote, “involves scanning for a value that when hashed, such as with SHA-256, the hash begins with a number of zero bits.” A smaller number means more leading zeros, and leading zeros are rare, so the smaller the target, the more guesses you need to clear it. You can read the original framing in the Bitcoin white paper itself.

The target is stored in the header in a compressed four-byte form called bits, or nBits. It unpacks into the full 256-bit threshold using an exponent and a mantissa, roughly the way scientific notation works: the value 0x1b0404cb, for example, means 0x0404cb multiplied by 2 raised to a power set by the leading byte. From that threshold the network derives the familiar difficulty number, defined as the easiest-ever target divided by the current one. The easiest target, difficulty 1, is the constant 0x00000000FFFF0000…, a value whose top 32 bits are zero, as the Bitcoin wiki on difficulty spells out.

In October 2026 the difficulty sat around 132.72 trillion. Put concretely, a winning hash needed roughly its first 79 bits to be zero, close to twenty leading zeros when you write the 256-bit result out in hexadecimal. The chance that any single random hash clears that bar is about one in 5.7 followed by 23 zeros. That is the needle every miner is threading, and the only way through it is to try again, and again, and again.

The search: roll the nonce, hash, compare, repeat

The mining loop itself is almost disappointingly simple. Assemble a header. Hash it twice. Read the result as a number. If it is below the target, you have found a block; broadcast it and collect the reward. If not, change the nonce by one and hash again. There is no cleverness available, no way to steer toward a winning value, because the avalanche effect guarantees that nudging the nonce by one scrambles the output beyond recognition. Each attempt is an independent coin flip with astronomically long odds.

That memorylessness is why block times behave the way they do. With a fixed target and a roughly constant number of guesses per second network-wide, blocks arrive as a Poisson process: on average one every ten minutes, but with wide scatter, sometimes two in a minute, sometimes nothing for an hour. No miner is ever closer to the answer than when it started. A machine that has hashed for nine minutes without a block is exactly as likely to find one on its next attempt as a machine that just powered on. The network does not reward persistence; it rewards raw throughput, more guesses per second, which is precisely what hashrate measures.

One practical wrinkle explains how a planet’s worth of guessing stays coordinated. A single machine, even a warehouse of them, would almost never win a block on its own, so miners pool their effort. A pool hands each machine a block template plus its own slice of the search space (an extranonce range), and the machines report back not only winning hashes but near-misses, hashes that clear a much easier target the pool sets, known as shares. Shares are proof that real work is being done, and they are how a pool measures each participant’s contribution and splits the reward. It is the same hashing described above, simply parcelled out and metered so that thousands of operators can be paid in proportion to the guesses they actually made.

A worked example: hashing the first block ever

The abstraction gets concrete fast if you look at block zero. Bitcoin’s genesis block, mined by Satoshi on 3 January 2009, carries the nonce 2,083,236,893: the value that, after the header was assembled, finally produced a hash small enough to be valid. That hash, which anyone can recompute today, begins with ten zeros in hexadecimal (forty zero bits in a row), well inside the target of the era. Buried in the block’s coinbase transaction is the famous line of text, “The Times 03/Jan/2009 Chancellor on brink of second bailout for banks,” proof the block was not pre-mined before that day’s newspaper existed.

What is striking is that finding that nonce in 2009 took a laptop CPU a trivial amount of work, because the target then was enormous and almost any hash qualified. The arithmetic of a single guess is identical today; only the bar has moved. The exact same SHA-256d applied to the exact same 80-byte structure now has to clear a target more than a hundred trillion times smaller. The genesis block and a block mined this morning are the same puzzle played at wildly different stakes, which is the cleanest way to see what the hashrate really tracks: not a change in the computation, but an explosion in how many times per second the world runs it.

When 4.3 billion guesses are not enough

Here is where the simple loop collides with physics. The nonce is only four bytes, 32 bits, which gives exactly 4,294,967,296 possible values, about 4.3 billion. That sounds like plenty until you look at the machines. A current flagship rig such as Bitmain’s Antminer S23 Hydro runs on the order of 580 trillion hashes per second. At that rate it burns through the entire 4.3-billion nonce space in under ten microseconds. The nonce, the one field actually designed to be the search knob, is exhausted almost the instant mining begins.

So miners change something else to unlock a fresh batch of 4.3 billion nonces. There are two standard tricks, and together they are where the network’s real search space comes from.

Search fieldSizeEffective spaceHow it works
Nonce32 bitsAbout 4.3 billionIncremented directly; exhausted in microseconds
ExtranonceVariableEffectively unboundedArbitrary data in the coinbase transaction; changing it rebuilds the Merkle root and resets the nonce space
Version bits16 bitsAbout 65,000Reserved bits of the version field (BIP320), also used for overt AsicBoost

The first trick is the extranonce. The very first transaction in a block, the coinbase, is the one that pays the miner, and it contains a small field miners are free to stuff with arbitrary data. Changing it changes that transaction’s hash, which changes the Merkle root, which changes the header, which resets the nonce to a fresh 4.3 billion values. The extranonce is effectively unbounded, so between it and the nonce there is never a shortage of candidate headers to grind through.

The second trick lives in the version field. A 2017 standard, BIP320, set aside 16 bits of the header’s version field (the mask 0x1fffe000) for miners to use as extra scratch space, and BIP310 added the plumbing for mining pools to hand those bits to machines over the Stratum protocol. This is known as version rolling, and it powers overt AsicBoost, an optimisation now baked into essentially every current-generation ASIC. By rolling version bits a miner can reuse part of the SHA-256 computation across several candidate headers, shaving energy off each hash. It is also why the version number of modern Bitcoin blocks looks like random noise rather than a tidy integer.

The midstate trick, and why mining needs its own chips

One more optimisation is worth understanding, because it explains why mining runs on specialised silicon rather than ordinary computers. Recall that SHA-256 processes data in 512-bit chunks. The 80-byte header spans two of them: the first 64 bytes (the version, the previous block hash and most of the Merkle root) fill the first chunk, and the remaining 16 bytes (the tail of the Merkle root, the timestamp, the bits and the nonce) fill the second. While a miner is rolling only the nonce, that first chunk never changes. So hardware precomputes the result of hashing it once, a value called the midstate, and reuses it across billions of nonces, hashing only the cheap second half each time.

Optimisations like the midstate and AsicBoost are small in percentage terms, but at industrial scale they decide who survives. They are also why general-purpose chips lost the race. A CPU can compute SHA-256d, but slowly and wastefully; GPUs did better; field-programmable gate arrays better still; and then, from 2013 on, application-specific integrated circuits (ASICs) that do nothing but SHA-256d, with the function literally etched into the silicon as a deep pipeline, swept everything else off the table. The only axis of competition left is efficiency, measured in joules per terahash (J/TH), and the scramble toward sub-10 J/TH between Bitmain, MicroBT and Bitdeer is now the entire hardware story, as we traced in our breakdown of the real cost of owning a miner.

What an ASIC cannot do is make the problem smaller. Every valid block still requires, on average, that same 10^23-ish hashes, and every hash still requires a fixed slug of electricity. That is the sentence to keep in mind for everything that follows: energy is not a side effect of Bitcoin mining, it is the input being converted, hash by hash, into something the rest of the network treats as proof.

Counting the uncountable: how a hashrate is estimated

Now zoom back out. If one hash is a single draw against those one-in-5.7-followed-by-23-zeros odds, the network’s hashrate is just the rate of those draws summed across every machine on Earth. Here is the catch that gave one of our earlier pieces its headline: nobody can measure it directly. Hashes are private events happening inside millions of chips, and they are never broadcast. What the network does broadcast is blocks. So the hashrate is inferred, not observed, from how fast blocks are actually being found relative to the current difficulty.

The estimate uses a clean formula: network hashrate is approximately difficulty times 2^32 divided by 600, the target block time in seconds, as the difficulty reference notes. Plug in October’s difficulty of 132.72 trillion and it returns roughly 950 exahashes per second. Multiply the same difficulty by 2^32 and you get the other side of the coin: the network expends, on average, about 5.7 followed by 23 zeros hashes to find each block, the exact reciprocal of the one-in-that-many chance per guess. The math closes, which is the quiet satisfaction of proof-of-work: every number ties back to the single act of hashing a header.

It is worth pausing on how large that is. At roughly 950 EH/s the network performs about 9.5 x 10^20 hashes every second, and grinds through on the order of 5.7 x 10^23 of them to find each block. Numbers that size stop meaning much, so try a comparison: the world’s mining fleet runs more SHA-256 computations in a single second than there are grains of sand on every beach on Earth, many times over, and it has to, because the odds against any one guess winning are exactly that steep. The hashrate is simply the speed of that effort, and it may be the largest sustained computation humanity has ever aimed at a single problem.

Because it is derived from block timing, the estimate is noisy over short windows. A lucky streak of fast blocks reads as a hashrate spike that never physically happened. That is why serious trackers quote a seven-day or thirty-day moving average, and why single-day prints scattered from 925 to over 1,000 EH/s in October 2026 should be read as one wobbling quantity rather than a string of records. Here is the snapshot the formula produced that month.

Metric (October 2026)ValueNote
Network hashrate~925 to 985 EH/sSpot vs seven-day average; approaching a zettahash
2025 peak hashrate~1.1 ZH/sLate 2025, near the BTC price record
Difficulty132.72 trillionAbout 15% below the late-2025 record of 155.97T
Expected hashes per block~5.7 x 10^23Difficulty times 2^32
Hashprice~$40 per PH/dayUp ~45% from the June low near $27.70
BTC price~$82,500Roughly a third below the October 2025 record
Annual security budget~$14 billion450 BTC per day paid to miners, at the current price

The thermostat that keeps a hash worth ten minutes

A puzzle with permanently fixed odds would get easier or harder every time the hashrate changed. Bitcoin prevents that with a feedback loop. Every 2,016 blocks, roughly every two weeks, the network checks how long those blocks actually took and rescales the target so that, if the current hashrate held steady, the next 2,016 would take exactly two weeks. More hashrate makes blocks arrive faster, which ratchets the target down (a harder puzzle, more leading zeros required); less hashrate does the reverse. The adjustment is capped at a factor of four in either direction per period, a clamp that has never once been hit.

This is why a single hash is always worth, in expectation, the same ten minutes of network-wide effort, no matter how many machines pile in. It also made 2026 legible. Difficulty peaked near 155.97 trillion in late 2025, fell through the first half of 2026 as machines switched off or redeployed, and spent the autumn clawing back: the 3 October retarget printed essentially flat at 132.72 trillion, with the next adjustment due around 17 October. The deeper mechanics, the off-by-one quirk, the timestamp rules, the timewarp bug a soft fork is trying to close, deserve their own treatment, and we have given difficulty that elsewhere. The point here is narrower. The thermostat is what pins the value of a hash. Everything a miner earns, and everything an attacker would have to spend, is denominated in that self-correcting ten-minute unit.

Why the guessing is the entire point

It is tempting to see all this guessing as waste, a lottery dressed up as engineering. It is closer to the opposite: the guessing is the security model, not a cost of it.

A valid block hash is a receipt. It is public, anyone can check it in microseconds by hashing the header once themselves, and it could only have been produced by someone who performed, on average, that astronomical number of attempts. There is no way to shortcut it, forge it or buy it cheaply, because SHA-256 has no known back door and the only route to enough leading zeros is to keep rolling and hashing. Satoshi called the resulting system “one-CPU-one-vote”: influence over which block extends the chain is proportional to hashing done, which is proportional to energy spent. That is the whole trick, turning electricity into a cost that cannot be faked.

The asymmetry is the quiet genius of it. Producing a valid hash takes the whole network ten minutes and billions of dollars a year of electricity; checking one takes an ordinary laptop a fraction of a millisecond, because verification means hashing the header a single time and comparing the result to the target. That gap, astronomically expensive to create and nearly free to check, is what lets every node on Earth police the chain independently without trusting anyone, and what lets even a lightweight phone wallet confirm that the work behind a block was really done. The cost falls entirely on the miner; the proof is a gift to everyone else.

It is also what makes rewriting history expensive. To overwrite recent transactions, an attacker has to out-hash the rest of the network and rebuild the chain faster than it grows, the so-called 51 percent attack. At roughly 950 EH/s, that means acquiring and powering more hardware than every honest miner combined. The ongoing cost of honest mining sets the floor on that bill: at about 450 BTC minted per day and a price near $82,500, Bitcoin’s security budget runs on the order of $14 billion a year, spent so that the hash in each block stays genuinely hard to produce. Bitcoin does not secure itself with a committee or a signature threshold, the way a DAO leans on the kind of body we examined in our look at security councils; it secures itself with physics, by arranging things so the cheapest path to a valid hash is the honest one.

What a single hash costs, and who pays for it

Turn the security story around and you get the miner’s business. Every hash costs a sliver of electricity, and a miner only profits if the block rewards it eventually wins are worth more than the power it burned guessing. The industry compresses the revenue side into one number: hashprice, the expected daily revenue per unit of hashrate, quoted in dollars per petahash per day. In October 2026 it sat near $40 per PH/day, recovered roughly 45 percent from a five-year low near $27.70 in late June, according to Luxor’s Hashrate Index.

Revenue comes from two places: the block subsidy, currently 3.125 BTC per block and due to halve to 1.5625 BTC in 2028, plus transaction fees, which through 2026 have run well under one percent of the reward. The cost side is almost entirely electricity. That collision is why miners obsess over power contracts and chip efficiency, and why Fred Thiel, chief executive of the miner MARA, describes the business as a zero-sum game in which, as he put it, “margins compress, and the floor is your energy cost.”

The link between that cost and the hashrate is mechanical, and it runs straight through the thermostat. When the Bitcoin price falls below what it costs the marginal miner to produce a coin, those miners power down. JPMorgan’s Nikolaos Panigirtzoglou put the sequence crisply to TFTC: “When bitcoin trades below its production cost, higher-cost miners power down, the hashrate declines, and difficulty adjusts lower.” In 2026 that sentence ran in both directions, as a spring sell-off pushed machines off the grid and an autumn recovery coaxed them back on. Each hash, in other words, is priced, and the number of hashes the network performs is the market clearing itself in real time.

The AI pivot is a fight over the silicon that hashes

The newest pressure on the hashrate has nothing to do with cryptography and everything to do with where the electricity goes. The machines that compute SHA-256d are purpose-built and cannot run anything else, but the data centres, substations and power contracts that host them are exactly what the artificial-intelligence boom also wants. A megawatt wired into a cheap grid can feed a hall of hashing ASICs or a hall of AI accelerators, and through 2026 the AI bid has frequently been the higher one.

The result is the defining story of the mining sector this year. Public miners have signed more than $70 billion in cumulative AI and high-performance-computing deals, and CoinShares estimates that listed miners could draw up to 70 percent of their revenue from AI by the end of 2026, up from roughly 30 percent, a shift its head of research James Butterfill has called one of the most challenging periods the industry has faced. Riot Platforms, long a pure Bitcoin miner, signed a 20-year, 191-megawatt lease reported to be with the AI lab Anthropic, worth about $9.1 billion, in a deal that sent its stock up 20 percent. Every megawatt redirected that way is a megawatt not hashing, which is a large part of why the network sits below its 2025 peak by choice rather than by force.

There is a strange symmetry in it. Bitcoin’s hashrate is a market for one specific, deliberately useless computation, a number that proves only that work was done. The AI networks bidding for the same power, including the token-incentivised compute markets we covered in our piece on Bittensor’s subnet tokens, are markets for a very different kind of computation, one whose output is supposed to be useful in itself. Both are ultimately buying the same raw input, electricity turned into math, and for now they are bidding against each other for every watt of it.

What regulators make of a hash

If a hash is just a number that proves energy was spent, is producing one a regulated financial activity? In the United States the answer, as of 2026, is largely no. In March 2025 the SEC’s Division of Corporation Finance stated that proof-of-work mining on a public, permissionless network, whether solo or through a pool, does not involve the offer or sale of securities, on the reasoning that miners earn rewards through their own computational effort rather than the efforts of others. That left the act of mining outside the securities perimeter even as the agency kept a close watch on the tokens and exchanges around it.

Europe rhymes. The EU’s Markets in Crypto-Assets regime polices the service providers around crypto, the exchanges and custodians, not the act of hashing a block header, a split our guide to Europe’s rulebook moving from rulemaking to enforcement lays out in detail. The through-line is that regulators have generally treated the hash itself as a physical, computational process rather than an investment product; what they scrutinise is what happens to the coins afterward. That line may yet be tested as mining firms morph into AI landlords and raise capital in public markets, but the raw proof-of-work remains, for now, a matter of physics and electricity bills rather than securities law.

Frequently Asked Questions

What does a Bitcoin miner actually compute?

A miner repeatedly runs a double SHA-256 hash over the 80-byte block header, changing the nonce and a few other fields each time, until the resulting 256-bit number falls below the network target. Each attempt is one hash, and the hashrate counts how many such attempts the whole network makes every second.

Why is Bitcoin’s hashrate measured in exahashes and zettahashes?

Because the numbers are enormous. One exahash per second is 10^18 hashes a second and a zettahash per second is 10^21. In October 2026 the network ran at roughly 925 to 985 exahashes per second, which is more than 900 quintillion SHA-256 guesses every second.

Can the Bitcoin hashrate be measured directly?

No. Individual hashes are never broadcast, so the hashrate is estimated from how quickly blocks are found relative to the current difficulty, using the formula difficulty times 2^32 divided by 600. Short-term readings are noisy, which is why analysts rely on seven-day or thirty-day averages.

What are the nonce, extranonce and version rolling?

The nonce is a four-byte field a miner increments to produce a new hash. With only about 4.3 billion values it is exhausted by a modern ASIC in microseconds, so miners also vary an extranonce inside the coinbase transaction and roll 16 bits of the version field, a technique standardised in BIP320, to generate effectively unlimited fresh headers to try.

Does a higher hashrate make Bitcoin more secure?

Broadly yes. A higher hashrate means more computing work, and therefore more energy and hardware, stands behind each block, which raises the cost of a 51 percent attack. Bitcoin’s security budget, the yearly value paid to miners for that work, ran on the order of $14 billion in 2026.

Marcus Okafor covers Bitcoin mining and network infrastructure for HOGE Wire.

Share 𝕏 Post Telegram