Skip to content

LibraryConsensus2017Design paperCorpus record

Merged Mining: Curse or Cure?

Merged mining. Aljosha Judmayer, Alexei Zamyatin, Nicholas Stifter, Artemios G. Voyiatzis and Edgar Weippl.

Merged mining lets the same proof of work stamp a child chain. Security is not transferred for free: the parent miners may not validate the child, and an attack on the child can be cheap in attention even when hash power is large.

A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.

A sidechain pitch that says 'secured by Bitcoin miners' has to say whether those miners validate the sidechain.

The five-minute read

The defect

A small chain that borrows a large chain's miners looks protected. The paper asks what the parent miners actually commit to.

The rule

Merged mining lets the same proof of work stamp a child chain. Security is not transferred for free: the parent miners may not validate the child, and an attack on the child can be cheap in attention even when hash power is large.

How it is put together

The parent proof does not mean the parent miners executed the child. A child chain can be rewritten if its own miners are a thin slice of attention. Namecoin is the running example, not a general law.

Where the claim stops

The paper is not a ban on merged mining.

One action, walked through

  1. A miner includes a commitment to the child in the parent block.
  2. The child treats that commitment as a stamp.
  3. Whether the miner checked the child is outside the proof of work.
  4. Do parent miners validate the child block?

The argument, unpacked

Why it is still on the desk

A sidechain pitch that says 'secured by Bitcoin miners' has to say whether those miners validate the sidechain.

After the text

Later work on one-way pegs and blind merged mining returns to the same gap. The stamp and the check are different.

What has to be true

  • The paper is not a ban on merged mining.
  • It does not measure every modern auxiliary chain.
  • Hash power on the parent is not the same object as honest validation of the child.

What happened after the paper

Later work on one-way pegs and blind merged mining returns to the same gap. The stamp and the check are different.

What to check before you use the idea

  • Do parent miners validate the child block?
  • What fraction of parent hash power even includes the commitment?
  • Can the child reorg without a parent reorg?

Terms

Auxiliary proof
A parent proof of work that also stamps a child chain.
Validation
Checking the child, which the proof of work does not do by itself.

The problem the paper names

A small chain that borrows a large chain's miners looks protected. The paper asks what the parent miners actually commit to.

What the design proposes

  • The parent proof does not mean the parent miners executed the child.
  • A child chain can be rewritten if its own miners are a thin slice of attention.
  • Namecoin is the running example, not a general law.

How the mechanism is specified

  • A miner includes a commitment to the child in the parent block.
  • The child treats that commitment as a stamp.
  • Whether the miner checked the child is outside the proof of work.

What this page does not treat as proven

  • The paper is not a ban on merged mining.
  • It does not measure every modern auxiliary chain.
  • Hash power on the parent is not the same object as honest validation of the child.

Why a venture studio still reads it

A sidechain pitch that says 'secured by Bitcoin miners' has to say whether those miners validate the sidechain.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.