LibraryData and agents2015Design paperCorpus record
On Bitcoin as a Public Randomness Source
Bitcoin as a beacon. Joseph Bonneau, Jeremy Clark and Steven Goldfeder.
The paper asks when a proof-of-work block hash is a safe public beacon, and how a miner can bias it by withholding or grinding.
A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.
An on-chain lottery that uses the next block hash has to price the miner's option to throw the block away.
The five-minute read
The defect
Contracts want a public coin that no one can bias. Bitcoin's block hashes were being used as that coin without a theorem.
The proposal
The paper asks when a proof-of-work block hash is a safe public beacon, and how a miner can bias it by withholding or grinding.
A beacon that a miner can reject by discarding a block is not uniform.
The cost of bias is the cost of throwing away work.
The bound
The paper does not bless a particular gambling contract.
One action, walked through
- Take a future block hash as the candidate random value.
- Ask how many blocks a miner would withhold to move that value.
- Compare that cost with what the application pays an attacker who succeeds.
- What is the value at stake relative to the block reward?
The argument, unpacked
What the paper is for
An on-chain lottery that uses the next block hash has to price the miner's option to throw the block away.
What happened after
VDFs and RANDAO-style beacons are later designs aimed at the bias this paper names.
What has to be true
- The paper does not bless a particular gambling contract.
- It is not a verifiable delay function. Those are a later answer.
- Header chains that are not proof of work do not inherit the argument.
What happened after the paper
VDFs and RANDAO-style beacons are later designs aimed at the bias this paper names.
What to check before you use the idea
- Who can withhold the block that supplies the randomness?
- What is the value at stake relative to the block reward?
- Is the chain even proof of work?
Terms
- Beacon
- A public random value later parties should not be able to bias.
- Grinding
- Retrying a puzzle or a header until the random value is favourable.
The problem the paper names
Contracts want a public coin that no one can bias. Bitcoin's block hashes were being used as that coin without a theorem.
What the design proposes
- A beacon that a miner can reject by discarding a block is not uniform.
- The cost of bias is the cost of throwing away work.
- Applications that need one bit and applications that need many bits are different.
How the mechanism is specified
- Take a future block hash as the candidate random value.
- Ask how many blocks a miner would withhold to move that value.
- Compare that cost with what the application pays an attacker who succeeds.
What this page does not treat as proven
- The paper does not bless a particular gambling contract.
- It is not a verifiable delay function. Those are a later answer.
- Header chains that are not proof of work do not inherit the argument.
Why a venture studio still reads it
An on-chain lottery that uses the next block hash has to price the miner's option to throw the block away.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
