21 BTC
Share this page
Discuss
History · Before Bitcoin2 min read

From Hashcash to Bitcoin: how a 1997 anti-spam idea became proof of work

In 1997 Adam Back proposed making every email cost a little computing work. Eleven years later the Bitcoin whitepaper cited it. On 23 October he tells the story in Lugano.

Every new bitcoin block requires proof of work: miners spend real electricity to find it, and anyone can check the result in an instant. The idea is older than Bitcoin. In the 1990s it was proposed as a way to fight spam. One of its authors, Adam Back, now CEO of Blockstream, tells the story on stage in Lugano.

The problem: free email

Sending an email costs nothing, so sending a million costs almost nothing too. In 1992 the computer scientists Cynthia Dwork and Moni Naor proposed making the sender do a small calculation for every message, in a paper called "Pricing via processing or combatting junk mail". A normal user would not notice the cost; a spammer sending millions of messages would.

Hashcash, 1997

On 28 March 1997 Adam Back announced an implementation of "hash cash postage" on the cypherpunks mailing list. The trick uses a hash function, which turns any input into a fixed-length string of characters that looks random:

  • the sender keeps changing a small part of the input until the hash starts with a required number of zero bits;
  • that takes many attempts, but checking the result takes a single attempt.

In his words: partial hashes "can be made arbitrarily expensive to compute (by choosing the desired number of bits of collision), and yet can be verified instantly." He also wrote: "Hashcash is free, all you've got to do is burn some cycles on your PC."

In a 2002 paper Back described Hashcash in detail and cited Dwork and Naor's earlier work.

From stamps to blocks

In 2008 Satoshi Nakamoto's whitepaper made the link explicit: "we will need to use a proof-of-work system similar to Adam Back's Hashcash". Hashcash is reference [6] in the paper.

Bitcoin uses the same trick: miners change a number in the block (the nonce) until the block's hash starts with enough zero bits. The difference is purpose. In Hashcash the work proved that a message was not cheap spam. In Bitcoin it decides who adds the next block, and makes rewriting history very expensive.

Hashcash (1997)Bitcoin (2008)
What the work protectsan inbox, from spamthe transaction history
Who checks itthe email recipientevery node
Rewardnonenew bitcoin and fees
Confirmed

Bitcoin's whitepaper cites Hashcash by name. This is one of the clearest lines from the cypherpunk movement to Bitcoin.

In Lugano

23 Oct, 10:30 Lugano / 11:30 MSK, WAGMI Stage: fireside chat "From Hashcash to Bitcoin: Adam Back's Cypherpunk Journey". Moderator: Aaron van Wirdum of Bitcoin Magazine, author of The Genesis Book, a history of the people and ideas behind Bitcoin.

Expectation, not a fact

The session is a conversation about history. We do not expect product announcements.

See more early artefacts in the Bitcoin museum and the people behind them on our People page. The museum now has an Adam Back timeline, from Hashcash (1997) to his 2024 testimony in COPA v Wright, and his profile in the "People at the origins" hall, where every post is a real quote with a link to the original.

Sources

  1. Adam Back: [ANNOUNCE] hash cash postage implementation, cypherpunks mailing list (28 Mar 1997) cypherpunks.venona.com
  2. Adam Back: Hashcash, a denial of service counter-measure (2002) hashcash.org
  3. Satoshi Nakamoto: Bitcoin, a peer-to-peer electronic cash system (2008) bitcoin.org
  4. Plan ₿ Forum agenda planb.lugano.ch

Times are Lugano (CEST, UTC+2) and Moscow (UTC+3). Not investment advice.

Found this useful? Share the article or any section (↗ next to each heading).↑ Share

Read next