How is the Merkle root built?
Start with the ID of every transaction in the block, which is itself a double SHA-256 hash. Put them in order, coinbase first. Join neighbours in pairs and hash each pair. Now you have half as many hashes. Repeat until one is left: that’s the Merkle root.
If a level has an odd number of hashes, the last one is paired with itself. Change any transaction, even by one satoshi, and every hash on its path to the top changes, root included. Try it in the demo above.
Why a tree and not one big hash?
Proofs. To show a transaction is in a block, you only need the hashes along its branch, not the whole block. A block with about 4,000 transactions needs just 12 of them, a few hundred bytes. Satoshi’s whitepaper describes light wallets that check payments this way, keeping only block headers.
It also matters for mining. When a miner changes the extra nonce in the coinbase transaction, the Merkle root changes, and the block header gets a fresh set of nonces to try.
Sources
- Bitcoin: A Peer-to-Peer Electronic Cash System · Satoshi Nakamoto, 2008
- Block chain reference: headers, Merkle trees, target · Bitcoin developer documentation
- Merkle tree · Bitcoin Wiki
Live figures on this page come from the CloudMineCrypto API and public chain data, refreshed regularly, and are labelled where they appear. Educational only, not financial advice.