Onpode
Cover art for Why proof-of-work creates a cost to lying — the mechanism behind Bitcoin's security model

Why proof-of-work creates a cost to lying — the mechanism behind Bitcoin's security model

October 7, 2026 · 13 min

Juniper Vale & Mark Delaney

Bitcoin's proof-of-work security is measured in electricity, not headcount: an attacker must outspend the honest network's entire hash rate — currently costing hundreds of thousands of dollars per day — with no refund if they fail. That unrecoverable energy cost is what makes rewriting the ledger economically irrational at Bitcoin's scale.

Nakamoto consensus is the protocol introduced by pseudonymous inventor Satoshi Nakamoto in the 2008 Bitcoin white paper to enable decentralized agreement on a shared transaction history without a central authority. Its core mechanism is proof of work (PoW): miners compete to produce a valid block by finding a cryptographic hash that falls below a network-set difficulty target.

0:0012:39
Get the next episode on Crypto →

Follow it free — new episodes land in your feed.

Or make your own — any topic, in minutes

More Onpode episodes on Crypto →

About this episode

Bitcoin's security model rests on a single strange idea: make lying expensive. Not illegal, not detectable by identity — just economically ruinous. This episode traces exactly how that works, and where it gets more complicated than the headline version suggests. The mechanism is Proof of Work: finding a valid block costs enormous computational energy, but verifying one takes almost no time. The Longest-Chain Rule then says the chain with the most accumulated work is the real one — no votes, no authority, just math. As long as honest miners control more hash rate than any attacker, rewriting history costs more than it could ever pay. But the episode doesn't stop there. The 51% attack threshold — the number everyone cites — turns out to be more of a useful shorthand than a hard guarantee. Research from Eyal and Sirer showed profitable deviation can start around 25% of hash power through selfish mining strategies. Pool concentration adds another wrinkle: a record-high total hash rate controlled by a handful of pools isn't the same security as that same hash rate spread widely. The attacks on Bitcoin Gold and Ethereum Classic aren't treated as failures of the model — they're treated as proof it's real. Low hash rate meant the rental cost to beat those honest networks dropped into a range where someone simply did the math and acted. The episode closes on the PoW vs. proof-of-stake question honestly: whether Bitcoin's energy spend is the irreducible price of permissionless, identity-free security, or an artifact of how Satoshi designed it in 2008, that argument is still open.

Frequently asked

How does proof-of-work prevent double-spending in Bitcoin?

Bitcoin's proof-of-work prevents double-spending by requiring an attacker to redo the computational work of every block they want to rewrite, plus all blocks added afterward, while outpacing the honest network that keeps adding new blocks continuously. The energy burned is permanently gone whether the attack succeeds or not.

What is a 51% attack and how much does it cost?

A 51% attack means controlling more than half of a blockchain's hash rate to rewrite recent transactions. On Bitcoin, matching the honest network's hash rate costs hundreds of thousands of dollars per day in electricity. Bitcoin Gold was successfully attacked in May 2020 because its hash rate was low enough to rent cheaply.

Can you attack Bitcoin with less than 51% of hash rate?

Yes. Researchers Emin Gün Sirer and Ittay Eyal showed in 2013 that selfish mining — withholding discovered blocks to build a secret lead, then releasing them to orphan honest miners' work — can be profitable at around 25% of hash rate, well below the commonly cited 51% safety threshold.

What is the difference between proof-of-work and proof-of-stake security?

Proof-of-work burns external energy that can never be recovered, making attacks costly outside the system. Proof-of-stake destroys an attacker's on-chain capital through slashing. Ethereum switched to proof-of-stake without collapsing, but the two models represent different bets on what irreversibility actually requires — not a straightforward upgrade.

Why did Bitcoin Gold and Ethereum Classic get 51% attacked if they use the same proof-of-work as Bitcoin?

Bitcoin Gold and Ethereum Classic use identical proof-of-work code to Bitcoin, but their total hash rates were so low that renting enough compute to overpower the honest network cost only a manageable daily fee. The mechanism didn't fail — the chains simply lacked the scale that makes Bitcoin's version of the same mechanism economically prohibitive to attack.

Grounded in 12 sources
Mitigating 51% Attacks in Blockchain Systems Through ... ↗ · arxiv.org
Deep-Dive Analysis of Selfish and Stubborn Mining in Bitcoin and Ethereum ↗ · arxiv.org
Twisted by the Pools: Detection of Selfish Anomalies in Proof-of-Work Mining ↗ · arxiv.org
Resisting Selfish Mining Attacks in the Bicomp ↗ · arxiv.org
Bitcoin's Carbon Footprint Revisited: Proof of Work Mining for Renewable Energy Expansion ↗ · arxiv.org
Decentralization in Bitcoin and Ethereum Networks ↗ · arxiv.org
Selfish Mining in Ethereum ↗ · arxiv.org
[PDF] An Empirical Analysis of Chain Reorganizations and Double-Spend ... ↗ · dci.mit.edu
Bitcoin's Security Budget at the Subsidy-to-Fee Transition ↗ · papers.ssrn.com
Understanding Bitcoin: A Summary of Satoshi Nakamoto’s Revolutionary White Paper | by Benjamin Ghajiga | Medium ↗ · medium.com
A Proof of Stake Design Philosophy | by Vitalik Buterin | Medium ↗ · medium.com
What Is the Nakamoto Consensus? ↗ · coinmarketcap.com
Read transcript

Mark Delaney: Hey — cold out there, long commute, kinda glad to just sit down and think about something genuinely weird for a while.

Juniper Vale: Ha — same. And this one qualifies. I want to start with something that I think most people get wrong about Bitcoin before we even get into how it works.

Mark Delaney: Okay, what's that?

Juniper Vale: The security has nothing to do with how many people are mining. It's measured in electricity. In hash rate — the total computational power pointed at the network. Satoshi Nakamoto laid this out in 2008, and I think people nod at it without really absorbing how strange that is.

Mark Delaney: Huh — so like, a million tiny miners could be less secure than ten enormous ones if the total hashes per second are lower?

Juniper Vale: Exactly that. And it comes down to what Nakamoto was actually trying to solve, which is the double-spending problem. You know — digital money is just data, data can be copied, so how do you stop someone from spending the same coin at two different places? Without a bank in the middle?

Mark Delaney: Right, and the answer is — make it cost so much work to rewrite the ledger that it's not worth it.

Juniper Vale: And specifically, Proof of Work is the mechanism. Miners have to find a cryptographic hash below a target the network sets — it's enormously expensive to solve, but any node can verify it's correct in basically zero time. That asymmetry is the whole thing.

Mark Delaney: Hard to fake, easy to check.

Juniper Vale: Hard to fake, easy to check. And then the Longest-Chain Rule says: whatever chain has the most accumulated proof-of-work difficulty, that's the real one. No identity, no voting, no central authority deciding. Just work.

Mark Delaney: That's the part that gets me. The network just — defers to whoever did the most math. There's no 'trust me, I'm legitimate.'

Juniper Vale: None. And the question hanging over all of it — which we're going to keep pulling on — is whether burning electricity is actually what makes that trustworthy, or whether it's just the way Satoshi happened to build it.

Mark Delaney: And that question — the burning electricity thing — I think the way to actually feel why it works is, uh, picture a stadium scoreboard keeper. Old school, chalk. Their whole job is writing game stats in real time.

Juniper Vale: Okay, I'm with you.

Mark Delaney: If you wanted to sneak in and change one old line — say, swap a score from the third inning — you can't just erase that one line. You'd have to re-chalk every single line written after it. And you'd have to do it faster than the keeper is still writing new ones. That's it. That's Nakamoto consensus.

Juniper Vale: That's actually the whole mechanism in two sentences.

Mark Delaney: Because rewriting history on Bitcoin means — wait, no, let me say this right — it's not just redoing the block you want to change. You have to redo that block's computational work AND every block after it, and you have to outpace the honest network that is still adding new blocks the whole time you're doing that.

Juniper Vale: And the Difficulty Adjustment is what keeps that race from ever slowing down on the honest side. The puzzle automatically recalibrates so blocks keep arriving at a steady rate no matter how much hash rate joins or leaves. So the keeper never stops writing.

Mark Delaney: So you can't even wait for a quiet moment.

Juniper Vale: There is no quiet moment. And the miner who wins each round — who finds the valid hash first — they get a block reward. Newly created Bitcoin, right there. That's the economic reason honest mining is worth doing at all. The incentive and the security are the same mechanism.

Mark Delaney: Huh — so you're not just punished for cheating, you're actively paid to not cheat.

Juniper Vale: You know, that's the sunk cost part that I think people underestimate. The energy you burned trying to rewrite history — it's gone whether you succeed or not. Honest mining gives you a block reward. Attacking gives you a bill and maybe nothing.

Mark Delaney: Which is why hash rate is the actual security number to watch. An attacker has to acquire more of it than the honest network has — proportionally. And Bitcoin's hash rate is kinda... enormous. Bitcoin Gold's wasn't. Ethereum Classic's wasn't. And those chains actually got rewritten by people who did exactly this math.

Juniper Vale: And that's where the scoreboard analogy stops being cozy — because those attacks weren't theoretical. Someone ran the numbers, rented enough hash power, and it worked. That's what low hash rate actually means in practice.

Mark Delaney: And not just 'worked' in some small way — Bitcoin Gold in May 2020, someone actually rented enough hash power to pull it off. Didn't have to own a single ASIC long-term. Just rented it, flipped the network, reversed transactions, double-spent, walked away.

Juniper Vale: That rental part is what makes it land for me. Because the sunk cost logic — the whole reason this security model works — it only bites if acquiring the hash rate is permanently expensive. If you can rent it for a day and return it, the sunk cost shrinks to almost nothing.

Mark Delaney: Wait — so the model kind of assumes you have to build the hardware?

Juniper Vale: It assumes the cost is real and unrecoverable. And for Bitcoin, it still is — we're talking hundreds of thousands of dollars a day to match its hash rate, rented or owned. But Bitcoin Gold's hash rate was so low that the rental cost dropped into a range where someone could just... do the math and go for it.

Mark Delaney: Ethereum Classic got hit multiple times for the same reason, right? Like, it wasn't a fluke the first time.

Juniper Vale: Multiple times, yeah. And that's the bitter irony — Ethereum Classic and Bitcoin Gold both use proof of work. Same mechanism, exactly. The mechanism didn't fail. What failed was that they didn't have enough hash rate behind it. The security isn't in the design, it's in the scale.

Mark Delaney: So the same code that protects Bitcoin leaves a smaller chain completely naked.

Juniper Vale: Exactly that. The mechanism is identical. A 51% attack on Bitcoin Gold meant building a longer alternative chain faster than honest miners — reversing transactions, double-spending — same playbook. But on Bitcoin, to do that you'd need to outspend an honest network burning hundreds of thousands of dollars of electricity every single day, with no way to get that energy back if you fail.

Mark Delaney: And on Bitcoin Gold — I mean, uh, the honest network was spending what, a tiny fraction of that? So your daily rental bill to beat it was just... manageable.

Juniper Vale: Manageable enough that someone calculated it, decided yes, and did it. That's the whole story. Hash rate is the only number that matters — not how clever the protocol is, not how long the chain has existed.

Mark Delaney: Although — and I don't want to get too far ahead — the 51% threshold being the clean safety line, I'm not sure that story holds up as tightly as we're making it sound right now. There's a wrinkle coming that kinda breaks the framing.

Juniper Vale: Yeah, we'll get there. But even just sitting with this — the attacks on Bitcoin Gold and Ethereum Classic aren't evidence the model is wrong. They're evidence the model is real. You want the model to be wrong? Point hash rate at it.

Mark Delaney: But that's actually — okay, the 51% thing. I've been sitting on this and it's bothering me, because the number itself might be kind of... a useful lie? Like, in 2013, Emin Gün Sirer and Ittay Eyal showed that you don't need 51%. You need, uh — around 25%.

Juniper Vale: Wait, 25? That's — yeah, that's the selfish mining thing.

Mark Delaney: Right. So the attack is — instead of racing the honest network head-to-head, you find a block and you just... don't tell anyone. You sit on it. Keep mining secretly on top of it while everybody else is still working on the old tip.

Juniper Vale: And because you've got a head start, you can release your private chain at exactly the moment it overtakes theirs. The Longest-Chain Rule kicks in, the honest miners' work gets orphaned, and you just claimed their block rewards on top of your own.

Mark Delaney: Which is — I mean, that's not a hypothetical math trick. Sirer and Eyal actually modeled this. Twenty-five percent of hash power. Profitable. That's way below the number we've been saying makes Bitcoin safe.

Juniper Vale: And that's the part that genuinely unsettles me, because the 51% threshold — it's measuring something real, but it's not measuring the only thing that matters. Selfish mining exploits network propagation delays. Honest miners sometimes find competing blocks at nearly the same time just because of latency, and that's enough of a gap for a strategic withholder to wedge into.

Mark Delaney: So the Longest-Chain Rule only holds with high probability, not like — absolutely.

Juniper Vale: High probability. Not a guarantee. And then you layer the pool concentration on top of that, and — you know, Foundry USA, Antpool, a handful of others, they control enormous chunks of Bitcoin's hash rate. So the 'identity-free, distributed work' story gets complicated fast.

Mark Delaney: Because if profitable deviation starts at 25%, and a couple of pools are already sitting at, what, 15, 20% each — wait, does that mean the 51% number is just... a floor we agreed to talk about?

Juniper Vale: I think it's more like a useful shorthand that hides a messier reality. Mining decentralization matters independently of total hash rate. A huge pile of hash rate controlled by three pools isn't the same security as that same hash rate spread across thousands of independent miners — even if the total number looks identical.

Mark Delaney: So we could have a record-high hash rate and still be more fragile than the headline suggests. That's kinda uncomfortable.

Juniper Vale: Yeah, and I don't think there's a clean answer. The 51% threshold isn't wrong — it's just not the whole picture. Selfish mining, pool concentration, propagation delay — they all chip at the edges of it. The honest version is probably: Bitcoin is very secure, and the number we keep citing is more of a useful reference point than an airtight guarantee.

Mark Delaney: And then Ethereum just — I mean, they looked at all of this and said, uh, what if we skip the electricity part entirely. Proof of stake. Slashable staked capital instead of burned energy. The deterrent is still economic, it's just — you destroy someone's ETH instead of their electric bill.

Juniper Vale: And they did it. Multi-trillion-dollar network, switched over, didn't collapse. If Ethereum can secure that much value without the electricity bill, what exactly is Bitcoin's energy buying?

Mark Delaney: Eh, but — I don't think they're actually the same threat model, though. Like, slashing destroys capital that still exists inside the system. Proof of work burns energy that was never in the system to begin with. Those aren't the same thing.

Juniper Vale: No, that's exactly the distinction. The irreversibility is doing different work in each case. With PoW, the energy is gone — full stop, outside the system, can't be clawed back. With slashing, you're destroying someone's stake, but that capital existed on-chain. An attacker who's also very wealthy can — I mean, it's a different calculation.

Mark Delaney: So it's not a clean upgrade. It's a different bet.

Juniper Vale: A different bet on what the real deterrent is. And nobody's settled it — that's the honest answer. Whether Bitcoin's energy is the irreducible price of permissionless, identity-free security, or just a costly artifact of how Satoshi designed it in 2008, that argument is still live.

Mark Delaney: Which brings us back to where we started, kinda. You said at the top — the security has nothing to do with how many people are mining, it's measured in electricity. And I think that's still true. But now it feels heavier than it did an hour ago.

Juniper Vale: Yeah. It felt like a feature when we said it. Now it also feels like the thing that's hardest to defend.

Mark Delaney: The same fact, just — rotated a little.

Juniper Vale: That's probably a good place to stop. Thanks for chewing through this one with me — it got genuinely uncomfortable in the middle there, which I think means we were doing it right.

Why proof-of-work creates a cost to lying — the mechanism behind Bitcoin's security model · Onpode