Skip to content

LibraryData and agents2015Design paperCorpus record

On Bitcoin as a Public Randomness Source

Bitcoin as a beacon. Joseph Bonneau, Jeremy Clark and Steven Goldfeder.

The paper asks when a proof-of-work block hash is a safe public beacon, and how a miner can bias it by withholding or grinding.

A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.

An on-chain lottery that uses the next block hash has to price the miner's option to throw the block away.

The five-minute read

The defect

Contracts want a public coin that no one can bias. Bitcoin's block hashes were being used as that coin without a theorem.

The proposal

The paper asks when a proof-of-work block hash is a safe public beacon, and how a miner can bias it by withholding or grinding.

A beacon that a miner can reject by discarding a block is not uniform.

The cost of bias is the cost of throwing away work.

The bound

The paper does not bless a particular gambling contract.

One action, walked through

  1. Take a future block hash as the candidate random value.
  2. Ask how many blocks a miner would withhold to move that value.
  3. Compare that cost with what the application pays an attacker who succeeds.
  4. What is the value at stake relative to the block reward?

The argument, unpacked

What the paper is for

An on-chain lottery that uses the next block hash has to price the miner's option to throw the block away.

What happened after

VDFs and RANDAO-style beacons are later designs aimed at the bias this paper names.

What has to be true

  • The paper does not bless a particular gambling contract.
  • It is not a verifiable delay function. Those are a later answer.
  • Header chains that are not proof of work do not inherit the argument.

What happened after the paper

VDFs and RANDAO-style beacons are later designs aimed at the bias this paper names.

What to check before you use the idea

  • Who can withhold the block that supplies the randomness?
  • What is the value at stake relative to the block reward?
  • Is the chain even proof of work?

Terms

Beacon
A public random value later parties should not be able to bias.
Grinding
Retrying a puzzle or a header until the random value is favourable.

The problem the paper names

Contracts want a public coin that no one can bias. Bitcoin's block hashes were being used as that coin without a theorem.

What the design proposes

  • A beacon that a miner can reject by discarding a block is not uniform.
  • The cost of bias is the cost of throwing away work.
  • Applications that need one bit and applications that need many bits are different.

How the mechanism is specified

  • Take a future block hash as the candidate random value.
  • Ask how many blocks a miner would withhold to move that value.
  • Compare that cost with what the application pays an attacker who succeeds.

What this page does not treat as proven

  • The paper does not bless a particular gambling contract.
  • It is not a verifiable delay function. Those are a later answer.
  • Header chains that are not proof of work do not inherit the argument.

Why a venture studio still reads it

An on-chain lottery that uses the next block hash has to price the miner's option to throw the block away.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.