Skip to content

LibraryConsensus2002Design paperCorpus record

Hashcash: A Denial of Service Counter-Measure

Hashcash. Adam Back.

The client finds a partial hash collision. The server checks it cheaply. The stamp is the cost.

A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.

When a chain says its puzzle is Hashcash, the part that is Hashcash is the cheap-to-check partial collision. The chain of stamps is a different paper.

The five-minute read

The defect

A server that accepts unbounded anonymous requests will be drowned. Pricing the request with a small proof of work was the proposal, years before a chain of blocks.

The proposal

The client finds a partial hash collision. The server checks it cheaply. The stamp is the cost.

The puzzle is minted by the client, not by a miner race.

Double-spending the stamp matters for mail. A ledger of stamps is a later invention.

The bound

Hashcash is not Bitcoin. There is no longest chain in this note.

One action, walked through

  1. Choose a challenge, often the resource name and a date.
  2. Search for a nonce whose hash has the required leading zeros.
  3. The verifier recomputes one hash.
  4. Can the stamp be replayed?

The argument, unpacked

What the paper is for

When a chain says its puzzle is Hashcash, the part that is Hashcash is the cheap-to-check partial collision. The chain of stamps is a different paper.

What happened after

Bitcoin cites Hashcash as the puzzle. The ledger, the difficulty adjustment and the incentive are not this document.

What has to be true

  • Hashcash is not Bitcoin. There is no longest chain in this note.
  • It does not price electricity for a national network.
  • A stamp that can be replayed against many servers has not bound the resource.

What happened after the paper

Bitcoin cites Hashcash as the puzzle. The ledger, the difficulty adjustment and the incentive are not this document.

What to check before you use the idea

  • What is the challenge bound to?
  • Can the stamp be replayed?
  • Who bears the search cost?

Terms

Partial collision
A hash with a run of leading zeros.
Stamp
The proof a client attaches to a request.

The problem the paper names

A server that accepts unbounded anonymous requests will be drowned. Pricing the request with a small proof of work was the proposal, years before a chain of blocks.

What the design proposes

  • The puzzle is minted by the client, not by a miner race.
  • Double-spending the stamp matters for mail. A ledger of stamps is a later invention.
  • The difficulty is a parameter of annoyance, not of monetary policy.

How the mechanism is specified

  • Choose a challenge, often the resource name and a date.
  • Search for a nonce whose hash has the required leading zeros.
  • The verifier recomputes one hash.

What this page does not treat as proven

  • Hashcash is not Bitcoin. There is no longest chain in this note.
  • It does not price electricity for a national network.
  • A stamp that can be replayed against many servers has not bound the resource.

Why a venture studio still reads it

When a chain says its puzzle is Hashcash, the part that is Hashcash is the cheap-to-check partial collision. The chain of stamps is a different paper.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.