Free Strategy Call

Proof of work

Proof-of-work makes block production expensive on purpose. A miner scans for a hash below a moving difficulty target, which costs real hardware and real electricity, and the chain carrying the most accumulated work is the one the network treats as canonical. Rewriting history means redoing that work and catching up while everyone else keeps extending the honest chain. The cost is external and physical, which is exactly what proof-of-stake replaces with bonded capital.

The electricity is the security model, not a side effect of it. And the consumption figure is a range rather than a number: Cambridge and Digiconomist run different methodologies and land far apart in the same week, so every single figure you see quoted has a methodology hidden behind it.

Block production, as the whitepaper sets it out01Broadcast txsent to all nodes02Collect a blockeach node buildsits own03Find the proofhash below thedifficulty target04Broadcast blockthe moment a nonceworks05Others check itvalid, and notalready spent06Build on topacceptance is thenext block

Scroll to see the full diagram

Step six is the one people miss. Nodes do not sign an approval; they express acceptance by spending money extending the chain, which is why the longest chain is the vote count.

What a miner is actually doing

Mining is a search. A node assembles pending transactions into a block, then hashes the header repeatedly with a different nonce until the result falls below a target set by current network difficulty. There is no shortcut and no partial credit. The whitepaper sets difficulty by a moving average targeting an average number of blocks per hour, so the target tightens as hardware arrives and loosens when it leaves.1

The puzzle itself is not the clever part. What it stands in for is. Proof-of-work is essentially one-CPU-one-vote, and the majority decision is represented by the longest chain, which has the greatest proof-of-work effort invested in it.1 No registry of participants is needed, because the vote is the electricity bill.

Settlement is a probability, and there is a published table

Proof-of-work settles probabilistically. The whitepaper does that arithmetic rather than waving at it: an attacker's catch-up chance follows a gambler's ruin curve, and the probability drops exponentially as honest blocks stack on top.1

The published numbers are far more useful than the folklore. To hold an attacker's success probability below 0.1 percent, an attacker holding 10 percent of hashpower takes 5 confirmations, 20 percent takes 11, 30 percent takes 24, 40 percent takes 89, and 45 percent takes 340.1 Six confirmations is not a universal constant. It is the answer to one assumption about who might be attacking you. Set your confirmation policy from the attacker share you consider plausible and the value at risk, then write both down where your finance team can find them.

The energy figure is a range, and the ranges disagree

Two publishers run continuous estimates and they do not agree. The Cambridge Centre for Alternative Finance reported an annualized best guess of 155.02 TWh as of 2 August 2026, alongside its own published scenarios of 77.36 TWh at the low end and 253.28 TWh at the high end.3 Digiconomist's index read 204.44 TWh on 3 August 2026.4

The gap is methodological. Cambridge models the mix of mining hardware and its efficiency, applies a seven day moving average to damp hashrate volatility, and assumes electricity at 0.05 USD per kWh, publishing a low, a high and a best guess rather than a point estimate.3 Digiconomist rejects that approach, deriving consumption from miner economics on the premise that miner income and costs are related, and argues that hardware mix models understate consumption because they ignore machine reliability, climate and cooling.4

So state it as it is. Bitcoin's annualized electricity draw is estimated somewhere between roughly 77 and 253 TWh depending on whose model you use and which scenario inside it, and the two most cited publishers sat about 50 TWh apart in the same week. Anyone quoting one figure as settled has picked a methodology without telling you. Worth knowing before a diligence questionnaire arrives with the number already filled in.

Annualized Bitcoin electricity estimates, same week77 TWhCBECI low155 TWhCBECI guess204 TWhDigiconomist253 TWhCBECI highTWh per year

Scroll to see the full diagram

Three of these bars come from one model and one comes from another. The spread is the finding, not a rounding problem, so cite the range and name the publisher.

The security budget is an operating expense

That electricity gets bought, and something has to buy it. The whitepaper funds the incentive with a block subsidy plus transaction fees, and states that once a predetermined number of coins have entered circulation the incentive can transition entirely to transaction fees.1 That transition is the open question in the model, not a settled detail.

The margin is thinner than most people assume. Digiconomist reported annualized miner income of about 10.5 billion dollars against estimated annualized electricity costs of about 10.2 billion, a cost ratio of 97.26 percent under its 5 cents per kWh assumption, read on 3 August 2026.4 Treat those as one publisher's model outputs, not audited accounts. The design point holds regardless: hashrate tracks revenue, so a mechanism whose subsidy steps down on a fixed schedule is a mechanism whose security budget depends on fee income growing into the gap.

Written against proof-of-stake

The honest comparison is about where the cost lives. Proof-of-work's cost is external: hardware and power bought outside the system, unforgeable, and unrecoverable if you attack and lose. Proof-of-stake's cost is internal: capital bonded in the chain's own token, destroyable by the protocol itself once misbehaviour is provable. One buys security from the physical world, the other from its own balance sheet.

Each direction carries a real weakness. Proof-of-work's expense recurs every block whether the chain is busy or idle, and producing malicious yet valid blocks consistently required over 51 percent of network mining power, a threshold that only holds while enough hardware stays pointed at the chain.2 Ethereum switched proof-of-work off in 2022 and now documents it as deprecated.2 Bitcoin did not. Two of the largest networks weighed the same tradeoff and went opposite ways, which is the clearest signal available that the answer is not obvious.

What this changes for a founder

You are almost certainly not launching a proof-of-work chain. What survives into an actual decision is narrower than the debate suggests. If your product settles on a proof-of-work chain, probabilistic finality is a product requirement rather than a footnote: pick a confirmation count off the table above and make it a function of transaction size. If any part of your token story touches mining, expect diligence to ask for the energy number, and hand over the range with both publishers named instead of the figure that flatters you.

And if a design arrives proposing a new proof-of-work network, the cryptography is not the question. Who funds the hashrate in year three is the question, along with whether the application sitting on top generates fees at anything close to the rate the security budget spends them.

Common questions

How much energy does Bitcoin mining use?

Estimates disagree, so quote the range. Cambridge's index put annualized consumption at 155.02 TWh as of 2 August 2026, with its own published scenarios spanning 77.36 to 253.28 TWh.3 Digiconomist's index read 204.44 TWh on 3 August 2026.4 Cambridge models the hardware efficiency mix; Digiconomist derives consumption from miner revenue. Name the publisher whenever you cite a figure, because a single number hides a methodology choice.

How many confirmations are enough?

That depends on the attacker share you assume and the value at risk. The Bitcoin whitepaper publishes the confirmations needed to push attacker success below 0.1 percent: 5 against a 10 percent attacker, 11 against 20 percent, 24 against 30 percent, and 89 against 40 percent.1 The familiar six confirmations rests on the mildest of those assumptions. It is a convention, not a constant.

Is proof-of-work wasteful?

Calling the electricity waste and calling it the security model are the same observation framed two ways, because the spend is what makes the ledger expensive to rewrite. The defensible statements are narrow: annualized consumption estimates span roughly 77 to 253 TWh depending on methodology, and that spend buys resistance to history rewriting rather than throughput.3 Whether the trade is worth making is a policy judgement, not a technical one.

Why did Ethereum move away from proof-of-work?

Ethereum switched proof-of-work off in 2022 and moved to proof-of-stake, and its documentation now marks proof-of-work as deprecated.2 Bitcoin did not follow. Two networks weighed the same tradeoff between an external physical cost and bonded internal capital and reached opposite conclusions, which is the clearest evidence available that this is a genuine tradeoff rather than a solved question.

See Tokenomics Design Services for how this applies in practice.

Sources

  1. Bitcoin: A Peer-to-Peer Electronic Cash System
    Satoshi Nakamoto, 2008
    Sections 4, 5, 6 and 11: difficulty as a moving average, the six step network procedure, subsidy plus fees, and the confirmation table for attacker success below 0.1 percent.
  2. Proof-of-work (PoW)
    Ethereum Foundation
    Ethereum's historical proof-of-work documentation, marked deprecated after the 2022 switch, including the over 51 percent mining power threshold.
  3. Cambridge Bitcoin Electricity Consumption Index
    Cambridge Centre for Alternative Finance, University of Cambridge, 2026
    Best guess 155.02 TWh with MIN 77.36 and MAX 253.28 TWh, as of 2 August 2026, from CCAF's own data download. Assumes 0.05 USD per kWh and a seven day moving average.
  4. Bitcoin Energy Consumption Index
    Digiconomist (Alex de Vries), 2026
    204.44 TWh annualized, plus miner income and electricity cost estimates, read 3 August 2026. Derives consumption from miner economics rather than hardware efficiency mix.

Last reviewed 2026-08

Know the terms but not sure how they apply to your project? That is what an engagement is for. We design, document, and stress-test the whole token economy inside the Tokenomics Data Room.

Book a discovery call

80+ projects advised. Complete tokenomics in 4 to 6 weeks.