28 May 2026
How proof-of-work secures Bitcoin (and what it would cost to break it)
Bitcoin's security comes from energy: rewriting its history means out-spending the entire honest mining network on hardware and electricity, every block, forever. Here's how proof-of-work works, what a 51% attack would actually cost, and why the energy is the point.
Bitcoin’s security comes from economics making an attack irrational, not from cryptography keeping attackers out of a vault. To rewrite Bitcoin’s history, you’d need to out-compute the entire honest mining network, which means acquiring more hardware and burning more electricity than everyone else combined, continuously, for as long as the attack runs — while forfeiting tens of millions a day in legitimate rewards and destroying the value of the thing you’re attacking. That’s the whole idea behind proof-of-work, and the energy people call wasteful is the security itself — the foundation the rest of Bitcoin’s distinctive properties rest on.
What is proof-of-work, and how does it secure Bitcoin?
Proof-of-work has run Bitcoin continuously since 2009 with roughly 99.98% uptime. The security comes from energy: miners compete to produce blocks by running data through SHA-256, a cryptographic hash function that turns any input into a fixed 256-bit output,1 over and over, trillions of times a second, until one finds a valid result. The total computing power doing this is the network’s hashrate, which as of early 2026 sits around one zettahash per second — on the order of 10²¹ hashes every second.2
The work isn’t busywork; it’s what anchors history. Each block builds on the one before, so altering an old transaction means re-doing the work for that block and every block since, faster than the rest of the network is extending the honest chain. The deeper a transaction is buried, the more work would have to be redone — which is why confirmations make a payment progressively harder to reverse. Difficulty, a number the protocol tunes to keep blocks arriving about every ten minutes, stood near 146 trillion in early 2026.3
What would it actually cost to attack Bitcoin?
To rewrite history an attacker needs majority hashrate — over 500 EH/s at current scale — and that runs into three walls at once. First, hardware: Bitcoin mining runs on ASICs, purpose-built chips made by a handful of manufacturers, with lead times of 6–12 months on large orders. You can’t buy a majority of the network’s hashrate overnight.4 Second, power and infrastructure: running 500+ EH/s draws an estimated 65–75 gigawatts continuously5 — comparable to the peak demand of Germany and France combined, across thousands of warehouse-scale facilities that take years to build and can’t be hidden. Third, sustained cost: a 51% attack isn’t a one-off; you pay the electricity bill every hour it runs, on the order of $40–50 million a day in power alone,6 while also forgoing the legitimate mining revenue you’d otherwise earn — roughly $38,700 per EH/s per day, nearly $20 million a day at that scale.7
And after all that, the payoff is small. You could double-spend your own transactions or censor specific ones — real but bounded damage. You could not steal coins from other wallets, change the 21 million cap, or mint new supply. The only credible attacker at this scale is a nation-state, and even a nation-state would struggle to hide the utility connections, construction, and equipment imports involved. The economics are designed so the cost of attacking always exceeds the gain.
What happens when miners leave?
This is where Bitcoin’s difficulty adjustment proves itself. Every ~2,016 blocks (about two weeks), the network compares how long the last batch took to the target and adjusts difficulty up or down — capped at 4× per period — to hold the ten-minute rhythm regardless of how much hashrate joins or leaves.8
The stress test came in 2021, when China — then home to 65–75% of global hashrate — banned mining. Hashrate collapsed and blocks slowed, triggering the largest downward difficulty adjustment in Bitcoin’s history, a 28% drop.9 Then the system simply healed: lower difficulty made mining more profitable for everyone left, miners relocated to the US, Russia, and Kazakhstan, and hashrate recovered to pre-ban levels within about six months. No committee intervened; the protocol adapted on its own. Foundry’s Kevin Zhang described Bitcoin shrugging off what amounted to a nation-state attack.10
Isn’t all that energy wasted?
Only if you assume the energy buys nothing — but it buys the security described above, and it tends to come from sources nobody else wants. Mining is a margin business: miners survive by finding the cheapest power on earth, which pushes them toward stranded and surplus energy rather than competing with households for grid power.
The examples are striking. Companies like Crusoe capture natural gas that would otherwise be flared at oil wells and burn it for mining instead, cutting CO₂-equivalent emissions by around 63% versus continued flaring11 — a practice the Texas Railroad Commission has endorsed as emissions reduction. Bhutan has mined over 10,700 BTC using surplus hydropower, treating Bitcoin as a “strategic battery” that converts seasonal energy into a liquid reserve.12 Gridless operates at small hydro and solar sites across Kenya, Malawi, and Zambia that generate more power than local demand can absorb, acting as an anchor customer that makes the projects viable — and has helped connect over 8,000 homes to power that wouldn’t otherwise exist.13 El Salvador mines with volcanic geothermal energy.14 The aggregate picture has shifted accordingly: a 2025 Cambridge study found 52.4% of mining energy now comes from sustainable sources, with coal falling from 36.6% in 2022 to 8.9%.15 Miners aren’t taking power from the grid so much as monetising energy that would otherwise go to waste.
Could quantum computers break Bitcoin?
It’s a real future consideration, not a present threat — and it isn’t really a Bitcoin problem. Cryptographically relevant quantum computers are years away (expert estimates cluster around the early 2030s), and the same capability that could threaten Bitcoin’s signatures would also break the encryption protecting every website, bank, and government system.16 When that day comes, every digital system on earth needs upgrading; Bitcoin will be one line item on a very long list, and post-quantum signature schemes are already standardised and in development.17
There’s an asymmetry here, though, and it favours proof-of-work. On a proof-of-stake network, the keys that hold value are the same keys that validate blocks — so an attacker who could derive private keys from public ones could steal staked tokens and seize consensus at once. On Bitcoin, those functions are separate: stealing coins compromises individual holdings but grants zero hashrate, because consensus security lives in mining infrastructure, not key ownership.18 The value layer and the consensus layer have different attack surfaces.
Who can actually verify the network?
Security also depends on how many people can independently check the rules, which comes down to the cost of running a full node. On Bitcoin, a node needs about $150–400 of consumer hardware and ~715 GB of storage, with no staking or capital lockup; anyone can verify the whole chain from genesis.19 That keeps the verifying population large — roughly 18,500–24,800 reachable nodes across 181 countries, about 64.58% via Tor.20
The comparison is instructive. An Ethereum full node is heavier but still consumer-grade ($500–1,500), with around 6,000–8,000 reachable nodes; participating in consensus, though, means staking exactly 32 ETH (about $96,000) per validator — which is why staking aggregates under big providers.21 A Solana validator needs enterprise hardware costing $15,000–50,000.22 Cheaper nodes mean more independent auditors, and more auditors mean the rules are harder to quietly change. It shows up in uptime, too: Bitcoin has had no network-wide outage since 2009, while Solana has logged 80+ hours of major outages since 202123 — the kind of thing that matters a great deal if your collateral needs liquidating at 3am.
Common questions
How does proof-of-work actually secure Bitcoin? Miners spend real energy competing to produce blocks, and the valid history is the one with the most accumulated work. Rewriting it means re-doing that work faster than the entire honest network — which is prohibitively expensive, by design.
Could someone do a 51% attack on Bitcoin? Only by acquiring majority hashrate — over 500 EH/s — which needs billions in scarce ASICs and 65–75 GW of power, costs $40–50 million a day to run, and still can’t steal coins or change the supply. Realistically only a nation-state could attempt it, and not secretly.
Is Bitcoin mining bad for the environment? The energy is what secures the network, and mining increasingly runs on stranded and surplus power — flared gas, surplus hydro, off-grid renewables. A 2025 Cambridge study put sustainable sources at 52.4% of the mining mix.
Will quantum computers break Bitcoin? Not soon, and not uniquely — the same quantum capability would break banking and internet encryption too. Bitcoin has upgrade paths to post-quantum cryptography, and unlike proof-of-stake, its value keys and consensus are separate, so stealing coins wouldn’t hand over control of the network.
Footnotes
-
SHA-256 — a cryptographic hash function that converts any input into a fixed 256-bit output; one-way, collision-resistant, and deterministic. ↩
-
Bitcoin network hashrate ~992 EH/s–1.04 ZH/s as of early 2026. CoinWarz; Hashrate Index; TheMinerMag. https://www.coinwarz.com/mining/bitcoin/hashrate-chart ↩
-
Bitcoin difficulty ~146.47 trillion as of early 2026. CoinWarz. https://www.coinwarz.com/mining/bitcoin/difficulty-chart ↩
-
ASIC production is concentrated among a few manufacturers, with lead times exceeding 6–12 months on large orders. Blockware Solutions, “ASIC Supply Chain Analysis.” https://www.blockwaresolutions.com/research-and-publications ↩
-
Operating 500+ EH/s draws an estimated 65–75 GW continuously (modern ASICs at ~15–20 J/TH plus cooling overhead). Bitmain specifications; Cambridge CBECI methodology. ↩
-
Running 500+ EH/s costs roughly $40–50 million per day in electricity at industrial rates of $0.03–0.06/kWh. Cambridge CBECI methodology. ↩
-
JPMorgan (January 2026): ~$38,700 per EH/s in daily block-reward revenue. CoinDesk. ↩
-
Bitcoin adjusts difficulty every ~2,016 blocks (about two weeks), capped at 4× per period, to hold ~10-minute block times. Bitcoin Wiki, “Difficulty.” https://en.bitcoin.it/wiki/Difficulty ↩
-
When China banned mining (May–June 2021), hashrate collapsed and the July 2021 difficulty adjustment fell 28% — the largest negative adjustment in Bitcoin’s history. Cambridge Centre for Alternative Finance. https://ccaf.io/cbnsi/cbeci/mining_map ↩
-
Foundry’s Kevin Zhang, on Bitcoin shrugging off the China ban as a “nation-state attack.” CNBC; Compass Mining coverage (2021). ↩
-
Crusoe Energy — flare-gas mining reducing CO₂-equivalent emissions by ~63% vs continued flaring, across 40+ sites; Texas Railroad Commission endorsement; FLARE Act introduced April 2025. Crusoe; Texas Railroad Commission. ↩
-
Bhutan — 10,700–12,000+ BTC mined via hydropower (Druk Holding & Investments), more than 40% of GDP; described by DHI as a “strategic battery.” Arkham Intelligence; Bloomberg. ↩
-
Gridless Compute (backed by Block) — mining at stranded hydro and solar sites in Kenya, Malawi, and Zambia; 8,000+ homes connected; partner-site electricity prices down 28–60%. Block press release; Bitcoin Magazine. ↩
-
El Salvador — ~474 BTC mined since September 2021 using geothermal energy from state-owned LaGeo. Reuters. ↩
-
Cambridge Centre for Alternative Finance (2025): 52.4% of mining energy from sustainable sources; coal down from 36.6% (2022) to 8.9% (2025). https://ccaf.io/cbnsi/cbeci ↩
-
Cryptographically relevant quantum computers are estimated to be years away (expert forecasts cluster around the early 2030s); hashed, unspent addresses are protected while reused and P2PK addresses are exposed. Nic Carter, quantum-computing threat analysis. ↩
-
Post-quantum signature schemes have been standardised by NIST; Bitcoin proposals include BIP-360 (P2QRH). https://bip360.org/ ↩
-
In proof-of-stake the keys that hold value also validate blocks, so key compromise can mean consensus capture; in Bitcoin, consensus depends on mining infrastructure, not key ownership, so stealing coins grants no hashrate. ↩
-
A Bitcoin full node requires ~$150–400 of consumer hardware and ~715 GB of storage, with no staking. YCharts, “Bitcoin Blockchain Size.” https://ycharts.com/indicators/bitcoin_blockchain_size ↩
-
Bitnodes — ~18,500–24,800 reachable nodes across 181 countries, 64.58% via Tor. https://bitnodes.io/ ↩
-
An Ethereum full node runs on consumer hardware ($500–1,500), with ~6,000–8,000 reachable nodes; consensus participation requires staking 32 ETH per validator. Ethereum.org, “Run a node”; ethernodes.org. ↩
-
A Solana validator requires enterprise hardware (512GB–1TB RAM), estimated $15,000–50,000. Solana documentation. ↩
-
Solana — 80+ hours of major outages across multiple incidents since 2021. Solana Status. https://status.solana.com/ ↩