- Home
- Crypto & Tokens
- How does a blockchain work, step by step?
Crypto & TokensExplainer
How does a blockchain work, step by step?
A blockchain is a shared ledger where each block carries a fingerprint of the one before it. See hashing, mining and consensus explained with real examples.

Quick answer
A blockchain is a ledger copied across many computers. New transactions are grouped into blocks, and each block includes a digital fingerprint (hash) of the previous one. Changing an old entry changes every later fingerprint, so tampering is easy to spot. A consensus rule decides who adds the next block.
Key points
- NIST defines blockchains as tamper evident and tamper resistant digital ledgers kept without a central repository and usually without a central authority.
- A hash is a short digital fingerprint of data; changing even one character of the input produces a completely different hash.
- Each block contains the hash of the block before it, so editing an old block breaks the link to every block after it.
- A consensus model — such as proof of work or proof of stake — decides which participant may add the next block.
- A blockchain records transfers reliably; it does not make the assets on it valuable or safe to own.
On this page
- What problem does a blockchain solve?
- What is a hash, and why does it matter?
- How are blocks chained together?
- Who decides which block comes next?
- How does a transaction get onto the chain?
- What can a blockchain not do?
- What mistakes do beginners make?
- What else do beginners ask?
- What is the bottom line?
- Sources
What problem does a blockchain solve?#
Digital files are easy to copy. If money were just a file, you could send the same "coin" to two people. Bitcoin's original white paper names this the double-spending problem: the person receiving a payment cannot verify that an earlier owner did not spend the same coin twice[1]. Banks solve it by keeping one master ledger. A blockchain tries to solve it without a single keeper.
The U.S. National Institute of Standards and Technology (NIST) describes blockchains as tamper evident and tamper resistant digital ledgers implemented in a distributed fashion — without a central repository — and usually without a central authority such as a bank, company or government[2]. Tamper evident means changes are easy to detect. Tamper resistant means they are hard to make. Distributed means many computers, called nodes, each keep a copy.
What is a hash, and why does it matter?#
A hash is a fixed-length fingerprint of any piece of data. NIST explains that hashing applies a cryptographic hash function to data and calculates a relatively unique output, called a digest, for an input of nearly any size[2]. The key property: even the smallest change to the input, such as a single bit, results in a completely different digest[2].
Bitcoin's white paper uses SHA-256, a widely used hash function, as its example[1]. You can see the effect yourself. We ran two almost identical sentences through SHA-256 in code. Only one character differs, yet the fingerprints share nothing recognisable.
Worked example
Worked example: one character changes the whole fingerprint
First 16 characters of each SHA-256 digest (the full digest is 64 characters). Computed with Python's standard hashlib library.
| Input text | SHA-256 digest (first 16 characters) |
|---|---|
| Ana pays Ben 5 | f499016c4463c3ee |
| Ana pays Ben 6 | 21dde871d24a906e |
Figures computed in code from the stated inputs; rounded to the nearest cent or tenth.
How are blocks chained together?#
Transactions are grouped into blocks. NIST describes a block as having a header with metadata about the block, and block data containing a set of transactions[2]. Crucially, every block header except the very first contains a cryptographic link to the previous block's header[2]. That link is the previous block's hash.
Now the tamper evidence becomes clear. NIST spells it out: if a previously published block were changed, it would have a different hash, which would cause all subsequent blocks to have different hashes as well, since each includes the hash of the block before it[2]. We built a three-block toy chain in code to show it. Each block's fingerprint is the hash of the previous fingerprint plus its own data.
| Block | Data | Fingerprint (original) | Fingerprint after editing block 1 |
|---|---|---|---|
| Block 1 | Ana pays Ben 5 (edited to 50) | c88ab4ea5140ce13 | cc7a51de3d1df058 |
| Block 2 | Ben pays Cara 2 | a582a136877ed336 | 4c37eab00e9798ce |
| Block 3 | Cara pays Dev 1 | 1f28316bf5149d37 | a0f1a8d11493220e |
Computed with SHA-256 in scratch/writer-digital-assets/calc_how_blockchains_work.py; first 16 characters shown. Blocks 2 and 3 were not touched, yet their fingerprints changed.
How each block points to the one before it
Who decides which block comes next?#
If anyone could append blocks freely, people would publish conflicting versions. A consensus model is the rule for who may add the next block and which version everyone accepts. NIST describes two common ones[2]:
- Proof of work — participants publish a block by being the first to solve a computationally intensive puzzle. Bitcoin uses this; its nodes are called miners[3].
- Proof of stake — the chance to add a block depends on how much of the network's own token a participant has committed, on the idea that the more stake a user has invested, the more they want the system to succeed.
Bitcoin's white paper describes the puzzle as scanning for a value that, when hashed, produces a hash that begins with a number of zero bits[1]. Finding such a value takes many tries; checking it takes one. Our toy version below asks for hashes starting with zeros in hexadecimal. Each extra zero makes the search about 16 times longer on average.
| Leading zeros required | Tries it took in our run | Average tries expected |
|---|---|---|
| 1 zero | 10 | about 16 |
| 2 zeros | 255 | about 256 |
| 3 zeros | 748 | about 4,096 |
| 4 zeros | 54,153 | about 65,536 |
One run of calc_how_blockchains_work.py; luck varies, so single runs land above or below the average. Real networks require vastly more work.
Where versions conflict, Bitcoin's rule is that the majority decision is represented by the longest chain, the one with the greatest proof-of-work effort invested in it[1]. Rewriting history would mean redoing that work faster than everyone else — which is also why NIST lists a "51% attack", by someone obtaining enough computing power, as a known limitation[2].
How does a transaction get onto the chain?#
Here is the life of a payment on a proof-of-work blockchain, following the sequence in Bitcoin's white paper, which begins: new transactions are broadcast to all nodes, and each node collects new transactions into a block[1].
You sign a transfer
Your wallet uses your private key to sign a message moving tokens from your address. NIST notes that an address is derived from the user's public key with a hash function[2].
The transfer is broadcast
Your wallet sends it to nodes, which pass it along to others.
Nodes gather it into a block
Waiting transactions are bundled into a candidate block.
Consensus picks the block
Under proof of work, the first node to solve the puzzle broadcasts its block.
Others check and build on it
Nodes verify the transactions are valid and unspent, then start the next block on top of it.
NIST describes a full node as one that stores the entire blockchain and ensures transactions are valid[2]. The private key in step 1 is the part you must protect — see our private key definition.
What can a blockchain not do?#
A blockchain is good at one narrow job: keeping a shared record that is hard to rewrite. It does not check whether the information put on it is true, whether a token's issuer will keep a promise, or whether a price is fair. It also cannot undo mistakes. NIST notes that if a user loses a private key, any digital asset associated with it is lost, because it is computationally infeasible to regenerate the same key[2].
NIST also distinguishes permissionless blockchains, where anyone can read and write without authorization, from permissioned ones that limit participation to specific people or organizations[2]. Public crypto networks such as Bitcoin are permissionless, which is why anyone can join — scammers included. Read the risks of crypto investing and Bitcoin basics next, or keep the short blockchain definition handy.
What mistakes do beginners make?#
Thinking "on the blockchain" means "true"
The chain proves a record has not been altered since it was added. It says nothing about whether the record was honest in the first place.
Confusing the network with the asset
A working blockchain does not make every token on it valuable. Judge each token separately.
Expecting a reversal button
There is no central operator to cancel a mistaken or fraudulent transfer on a permissionless chain. Double-check addresses and amounts before you sign.
Assuming all blockchains work the same way
Consensus models, speeds, fees and who may participate differ from network to network.
What else do beginners ask?#
Is a blockchain the same thing as Bitcoin?
No. Bitcoin is one network that uses a blockchain. NIST's overview covers blockchains in general, including permissioned ones run by specific organizations[2].
Can a blockchain be hacked?
Rewriting a large proof-of-work chain is very hard, but NIST lists a 51% attack as a possible weakness[2]. A sound ledger also does nothing about stolen keys, scams or failing platforms, which are separate risks.
Why do blockchains need so much computing power?
Is everything on a public blockchain visible?
Transactions and balances by address are visible. Bitcoin's white paper says the public can see that someone is sending an amount to someone else, but without information linking the transaction to anyone[1].
What is the bottom line?#
A blockchain is a shared ledger where each block carries the fingerprint of the one before it, and a consensus rule decides who writes next. That design makes old records hard to change without detection. It does not make the assets recorded on it safe, valuable or reversible — those questions need their own answers.
Sources
Numbers in brackets in the text point here. Grade A = primary source (regulator, statistics agency, law or official document).
- 1
- 2
- 3