The nonce
The number miners change, over and over, until the hash falls below the target.
Step 6 of 143 min readUpdated October 5, 2026
The one field miners are free to change#
Once the transactions are chosen, the header of a candidate block is almost fixed. Hashed as is, it gives one hash, and that hash is almost certainly above the target. So the header has a field reserved for trial and error: the nonce, a number between 0 and 4,294,967,295.
Change the nonce, and the hash changes completely. Each nonce is a new draw.
Try it on a real block#
Below is the real header of block 969,985. Increase the nonce one step at a time, or let your browser try 20,000 in a row: the hashes stay far above the target. Then try the nonce its miner actually found.
Real header of block 969,985. Only the nonce changes; the transactions stay fixed.
0
002142566c581eb200a7eb85533a1db33080b635ecedc9d514fe0642544746c5Above the target · 2 leading zeros
- Nonces tried
- 0
- Best so far
- …
20,000 attempts take your browser a fraction of a second. The miner of this block found its winning nonce among roughly 570 sextillion expected attempts across the whole network.
Hard to find, instant to check#
Finding a valid nonce takes an enormous number of attempts; checking it takes one. Anyone who receives the block hashes its header once and sees that the result is below the target. That asymmetry is the proof of work: the block carries its own evidence that the work was done.
When the nonces run out: the extranonce#
The nonce is only 32 bits: about 4.3 billion values. A mining machine goes through them in a few milliseconds; a browser at a million hashes per second, in a little over an hour. Then the miner changes something else in the block and starts the nonces again from zero.
The usual lever is the extranonce, a few bytes inside the coinbase transaction. Changing it changes the coinbase, hence its txid, hence the Merkle root, hence the whole header: a fresh set of 4.3 billion nonces. The loop is always the same: nonce, then extranonce, then a new Merkle root, then the nonces again.
Real coinbase of block 969,985, with its real Merkle branch. Change 8 bytes of the coinbase and everything above it changes.
- Coinbase txid
20ae4ae8348e450fb0fc5dc94b7303ab31ff9b5297229095cb790fec5985fbfd- Merkle root
b4ae947d0bc7aa9aab59604cfd9024f69a65b87faa2a1a157d18ba41215d68fd- Header hash, same nonce
000000000000000000006823c66adca44d6d8172d657bca08c3e83498ade8b1f
Identical to the published block.
Which bytes this pool used is not public; any byte of the scriptSig has the same effect.
Technical details
With a pool speaking Stratum, the extranonce has two parts. Extranonce1 is set by the pool when the connection opens (mining.subscribe); the miner cannot change it. Extranonce2 is chosen by the miner, in the size the pool imposes.
In a classic pool, every coinbase pays the pool, so extranonce1 is what keeps two miners from hashing the same header. In a solo pool like the one Mini Miner uses, your coinbase already pays your own address, so your headers differ from everyone else’s anyway; extranonce1 still separates two connections on the same address.
The other levers: the timestamp (nTime) can move within limits set by the network; some bits of the version field, only if the pool allows it (“version rolling”). The choice of transactions belongs to the pool, not to the miner.