How do miners use the nonce?
A miner builds a block header, sets the nonce to 0 and hashes it. If the hash is above the target, it sets the nonce to 1 and tries again, then 2, and so on. The name is short for “number used once”.
No nonce is better than another. The hash can’t be predicted, so every try has the same tiny chance of winning. That’s what makes mining fair: more tries a second means more chances, and nothing else helps.
What happens when the nonce runs out?
Four bytes only hold 4,294,967,296 values. A modern machine gets through all of them in well under a thousandth of a second. So miners change something else in the block and start the nonce over.
The miner’s loop
- 01
Try every nonce
0, 1, 2 and on up to 4,294,967,295. That’s all the values 4 bytes can hold.
- 02
Run out, fast
A single 100 TH/s machine gets through all of them in about 43 millionths of a second.
- 03
Change the extra nonce
The miner edits a spare field in its own reward transaction (the coinbase).
- 04
New merkle root
That transaction changed, so the merkle root changes and every nonce gives fresh hashes again.
The usual choice is the extra nonce, a spare field in the coinbase transaction. Changing it changes the Merkle root, which gives a whole new set of headers to try. Miners can also nudge the timestamp and, on many machines today, roll a few bits of the version field.
Sources
- Nonce · Bitcoin Wiki
- Block hashing algorithm · Bitcoin Wiki
- Block chain reference: headers, Merkle trees, target · Bitcoin developer documentation
Live figures on this page come from the CloudMineCrypto API and public chain data, refreshed regularly, and are labelled where they appear. Educational only, not financial advice.