Source-linked AI summary

Analysis of Bitcoin Pooled Mining Reward Systems

Meni Rosenfeld

arXiv:1112.4980v1cs.DC

TL;DR

Bitcoin mining’s random block-finding process creates high payout variance, motivating pooled reward systems. The paper describes and analyzes reward-scoring systems and the problems they address, including pool-hopping. It concludes that some systems fall short, while hopping-proof methods offer a general framework for fair reward distribution.

  • Problem

    Random, high-variance mining rewards motivate pools, but proportional systems can be exploited by pool-hopping, reducing rewards for continuous honest miners.

  • Method

    The paper describes pooled reward systems, explains the problems each addresses, and analyzes their advantages and disadvantages, including score-based and hopping-proof methods.

  • Results

    The paper develops a general framework for hopping-proof methods and finds that some existing pool-hopping defenses are ineffective or can harm honest miners.

  • Takeaways & Limitations

    Fair pooled mining requires reward systems that account for probabilistic block finding and prevent pool-hopping from distorting participants’ rewards.

  • Takeaways & Limitations

    The analysis of proportional rewards is valid only under a fixed miner base, while pooled variance reduction is limited by miner size, intermittency, and reward-system details.

Abstract

from arXiv · show

In this paper we describe the various scoring systems used to calculate rewards of participants in Bitcoin pooled mining, explain the problems each were designed to solve and analyze their respective advantages and disadvantages.

Introduction

Bitcoin mining rewards are intrinsically high-variance because block discovery is random, motivating pools that share rewards while reducing individual payout variance. A fair pool should compensate miners in proportion to their work, after fees.

  • Motivation: Solo mining produces highly variable payouts because block finding is random, memoryless, and increasingly difficult as participation grows.A miner who waits three months without finding a block is no closer to success and must expect to wait about three more months.
  • Motivation: Variance in mining income harms financial planning, complicates verification that systems work, and can impose emotional costs.
  • Pooled mining: A mining pool combines miners’ efforts and distributes rewards according to contribution, allowing a miner’s expected payout to match solo mining while reducing variance.For a miner contributing fraction q of pool hashrate, the individual variance can be q times the miner’s solo variance.
  • Pooled mining: A fair miner payout averages (1−f)pB per submitted share, where f is the operator fee, p is share difficulty probability, and B is the block reward.
  • Pooled mining: Pooled mining can reduce variance only within limits: small miners may not realize the full potential, intermittent mining can increase variance, and reward-system details matter.These limitations do not change the average fair payout per submitted share.

Simple reward systems

Simple pooled reward systems trade off intuitive proportional sharing, resistance to pool-hopping, payment stability, and operator risk. Proportional rewards are vulnerable to strategic timing, whereas PPS offers deterministic payments by shifting variance to the operator.

  • Proportional: In proportional mining, each round’s reward is divided among miners according to their submitted shares, with expected payout per share of (1−f)pB.
  • Proportional: Proportional variance results assume a fixed miner base, and large miners’ correlated payouts prevent variance from falling below q times solo variance.
  • Proportional: Proportional payouts become less valuable as rounds lengthen, allowing miners to improve expected rewards by mining early and leaving when a round drags on.The break-even point for expected payout is 43.5% of the difficulty.
  • Proportional: Pool-hopping can theoretically reduce honest miners’ rewards by 43%, although the practical reduction depends on hopper numbers and strategy effectiveness.
  • Pay-per-share (PPS): PPS immediately pays each share its expected value, providing deterministic per-share rewards, no block-finding wait, easy verification, and immunity to pool-hopping.
  • Pay-per-share (PPS): PPS transfers all payout variance to the operator, who faces substantial losses on long rounds and bankruptcy risk without adequate fees and reserves.

Score-based methods

Score-based reward systems were developed to counter pool-hopping by changing how shares accumulate value or by removing fixed rounds. The paper presents their mathematical trade-offs, including operator risk, participant variance, difficulty-adjustment vulnerabilities, and broader implications for miners.

  • Slush’s method: Slush’s method assigns each share a time-dependent score, with later shares receiving higher scores before the round reward is distributed proportionally to score.Its exponential scoring function is s = exp(T/C), where T is elapsed round time and C is a constant.
  • Limits of fixed-round systems: The hopping immunity theorem states that a fixed per-round reward shared among round participants can be hopping-proof only by rewarding the winning share alone.That solution is equivalent to solo mining, whose high variance makes it undesirable; hopping-proof designs must instead alter the fixed-reward or round-participant premise.
  • Geometric method: The geometric method retains exponentially decaying scores while addressing weaknesses of Slush’s method within a mathematical framework.Its fee structure combines a fixed fee with an automatically granted operator score that decays like participant scores, making the variable fee larger on shorter rounds.
  • Geometric method: The geometric method’s expected payout per share is (1 −f)(1 −c)pB, while its expected fee per block is (c + f −cf)B.Here c is the average variable fee and f is the fixed fee fraction; the total average fee is c + f −cf.
  • Geometric method: Holding c + f −cf fixed while increasing c raises operator variance and lowers participant variance; allowing negative f shifts still more variance to the operator.The limiting cases range from solo-like winning-share rewards as c →0 to pay-per-share as c →1, though the stated approximate variances do not apply in the latter case.
  • PPLNS: PPLNS removes traditional rounds by paying miners who submitted shares recently, regardless of whether blocks were found during the examined period.Simple PPLNS uses the next N shares after a submitted share; increasing N reduces variance but increases maturity time, with product invariant 1.
  • PPLNS: A simple PPLNS variant is not hopping-proof when difficulty and block reward vary, because current difficulty determines contribution while future difficulty influences reward.Hoppers can exploit imminent adjustments by joining before decreases and leaving before increases; unit-PPLNS avoids this issue by measuring contribution in difficulty-adjusted units.

Attempts for risk-free pay-per-share

MPPS and its successors try to retain PPS-like payments while limiting pool-operator risk, but each introduces trade-offs in expected rewards, payment maturity, or hopping resistance.

  • MPPS: MPPS pays each participant the minimum of separate PPS and proportional balances, combining PPS accounting with pool-luck constraints.Shares increase the PPS balance, while found blocks increase the proportional balance.
  • MPPS: The minimum rule prevents operator losses and makes lucky rounds build buffers for unlucky rounds rather than producing immediate large payouts.The total proportional balance equals pool rewards, while payouts remain below that amount.
  • MPPS: MPPS pays below the fair average because it takes the minimum of two quantities whose expected values each equal the fair average.Rewards are normal in lucky rounds but below normal in unlucky rounds.
  • MPPS: MPPS is not hopping-proof because submitting shares early in rounds can raise the proportional balance and produce effectively zero-fee PPS payments.Honest miners can receive lower rewards when hopping changes the proportional balance distribution.
  • SMPPS: SMPPS replaces individual buffers with a shared pool buffer, delaying full PPS payments when the buffer is depleted.The buffer R measures block rewards earned minus the PPS value of all work performed.
  • SMPPS: When R = −500 BTC and B = 50 BTC, the average reward maturity time equals the time required to find 10 blocks.In the simplified model, maturity time is proportional to the pool’s debt measured in block rewards.
  • SMPPS: SMPPS’s buffer eventually reaches arbitrarily negative levels, potentially causing high maturity times, miner departures, and pool collapse.The paper states that participants with payment due may ultimately never receive it.

Advanced methods

Advanced reward systems preserve hopping resistance by controlling round separation and score decay, placing methods such as PPLNS, geometric, and double geometric on a common design spectrum.

  • Design principles: Hopping-proof systems maintain a steady state in which miners see the same relative history regardless of when they submit shares.The geometric method uses a variable fee to emulate missing current-round shares.
  • PPLNS: PPLNS ignores rounds and uses a fixed recent-share history, reducing share-based variance without operator risk but not pool-based variance.A longer window lowers share-based variance at the cost of increased maturity time.
  • Double geometric method: The double geometric method is hopping-proof and interpolates between geometric and PPLNS through partial round separation.Each block reduces future rewards without erasing them completely.
  • Double geometric method: The method’s parameters trade off average fee, operator variance, participant share-based variance, participant pool-based variance, and maturity time.The fixed fee f and variable fee c jointly determine average fees, while c also shifts variance between participants and operator.
  • Double geometric method: Increasing cross-round leakage o lowers participant share-based variance but increases maturity time; o = 0 gives geometric, while o = 1 gives an exponential-decay PPLNS variant.For o = 1, c must be 0 and r can be chosen freely to control decay rate.
  • Double geometric method: Changing parameters does not affect the expected payout of already submitted shares under the described method.The method description supports parameter changes during operation.
  • General framework: The general framework separates round separation from decay function, treating them as independent design attributes.It can represent round separation with step decay, exponential decay without rounds, or partial round separation.
  • General framework: Every family member is defined by a nonnegative round-separation parameter O and a decay function r(x), typically monotonic decreasing.Examples include exponential, step, and linear decay functions.

Attack vectors

Mining pools face attacks that exploit payout timing, pool state, or miners’ ability to recognize valid blocks. The paper analyzes these attacks and proposes oblivious shares to prevent block withholding by hiding block validity from miners.

  • Pool-hopping: Pool-hopping exploits changes in expected earnings, variance, or maturity time, harming continuous miners and making the pool unsustainable.Traditional hopping targets young proportional rounds; buffer-based and temporal score-based systems expose additional opportunities.
  • Block withholding: Miners can exploit Bitcoin’s current protocol by withholding or delaying blocks after recognizing them as valid.The paper identifies sabotage and lie in wait as two attack types enabled by this capability.
  • Sabotage: PPLNS distributes sabotage losses across participants, who receive (1 −f)(1 −h/H)pB per share on average.The loss equals the attacker’s share of the pool’s hashrate and may be significant, although detection is difficult.
  • Sabotage: PPS concentrates sabotage losses on the operator, whose average gain becomes (f −h/H)pB per submitted share and can turn negative.Because the fee is typically only a few percent, the attack can potentially bankrupt the pool.
  • Lie in wait: Lie in wait is profitable because a miner delays reporting a discovered block and redirects mining toward the most rewarding pool.The attack uses knowledge of an imminent block to obtain extra rewards during an ambush phase.
  • Proposed solution – Oblivious shares: Pop quizzes offer an imperfect workaround, while oblivious shares prevent miners from identifying valid blocks before submitting them.The proposed protocol uses secret values known to the operator so miners can submit shares without determining block validity.

Nonstandard reward systems

The paper generalizes pooled-mining rewards as contracts between operators and participants, then extends them to variable block rewards, customizable contracts, cash-outs, and share difficulties. These extensions require payout values and parameters to remain aligned with each share’s expected value and work.

  • General framework: Reward systems can be viewed as contracts in which operators buy shares and participants receive immediate payments or contingent future payouts.Standard reward methods are special cases distinguished by how those contracts determine participant payments.
  • Variable rewards: Variable block rewards make proportional distribution inadequate because a share’s expected value depends on the block reward at submission time.Bitcoin generation rewards halve every 210000 blocks, while transaction fees vary rapidly.
  • Hopping-proof design: Hopping-proof systems must offer each share a contract whose expected value is proportional to that share’s expected value.For PPS, the payout should be (1 −f)pB using the relevant p and B when the share is submitted.
  • Customizable contracts: A single pool can offer participants different reward contracts, but greater contract diversity increases operator variance and should affect fees.Each participant can select a reward profile without joining a separate pool.
  • Share difficulty: Higher-difficulty shares reduce server load but increase share-based variance, so difficulty must be fixed before work is assigned.Participants may use different difficulties, with rewards and score decay calculated from each share’s own difficulty.
  • Cash-out: Pools can allow occasional score cash-outs for immediate payment, typically at less than the full expected reward because of operator risk.The cash-out fee can increase if the feature is used too frequently.
  • PPS investments: PPS safety requires a reserve because the fee needed to keep bankruptcy probability low is inversely proportional to that reserve.Raising sufficient capital can therefore be challenging for operators seeking to make PPS attractive.

Conclusion

The paper surveys Bitcoin pooled-mining reward systems, evaluates their fairness and vulnerability to pool-hopping, and develops a general framework for hopping-proof methods. It also discusses possible service improvements for mining pools.

  • Conclusion: The paper introduces Bitcoin mining and explains why high reward variance creates a need for mining pools.Pooling addresses the variability of rewards associated with mining.
  • Conclusion: It examines reward-distribution methods and finds that some fall short of fair reward distribution, especially because of pool-hopping.The paper develops a general framework for methods immune to this exploit and analyzes specific examples.
  • Conclusion: The paper concludes by discussing innovative ways pools could improve the service they provide.These proposals follow the analysis of reward systems and hopping-proof methods.

Properties of proportional pools with constant hashrate

For proportional pools with constant hashrate, the paper derives expected payouts and payout variance from the distribution of shares per round. Pooling reduces per-share variance relative to solo mining, with the improvement depending on difficulty and miner participation.

  • Distribution: The number of shares in a proportional-pool round follows a shifted negative binomial distribution with stopping time 2 and failure rate p.This distribution underlies the expected payout and variance calculations for a randomly submitted share.
  • Payout moments: The expected payout per submitted share is (1−f)pB, while its variance is roughly p2B2 ln D.These results assume a fixed roster of miners with constant hashrates.
  • Variance reduction: At D = 1.5 · 106, pool variance per share is 1.13 · 105 times lower than solo-mining variance.The proportional pool’s variance improvement is approximately a factor of ln D.

Pool-hopping in proportional pools

In proportional pools, a share’s expected payout depends on the round’s current length, creating incentives for miners to join young rounds. Pool-hoppers can exploit this amplification, while honest continuous miners receive less than the fair reward.

  • Mechanism: A newly submitted share’s expected payout depends on how many shares have already been submitted in the round.The round’s eventual length is modeled with a geometric distribution, and payouts are conditioned on the current share count.
  • Mechanism: For a round with xD shares already submitted, the amplification factor is f(x) = exp(x)E1(x), decreasing toward 1 as x grows.For x near 0, f(x) is approximately −ln x −γ; for large x, it approaches 1.
  • Hopper strategy: A pool-hopper should mine proportionally when x < x0, where x0 = 0.4348182..., and otherwise mine solo or in a fair score-based pool.The threshold is where the proportional pool’s amplification equals 1.
  • Hopper strategy: Following this strategy, a pool-hopper can obtain 128% of the normal payout for the same hashrate.This assumes perfect knowledge of round age and flawless execution.
  • Multiple pools: With multiple proportional pools, the hopper chooses the youngest round and falls back to solo mining when every pool exceeds x0D shares.The minimum round age across m pools has an exponential distribution with mean 1/m.
  • Effect on honest miners: Honest continuous miners receive only 56.5% of the fair reward when infinitely many hoppers add x0D shares after each block is found.The hopper shares are added to the continuous miners’ ordinary share distribution.

Safety nets for PPS pools

PPS pools must maintain reserves because operators pay miners before receiving block revenue and can otherwise face bankruptcy. A Markov-chain and central-limit approximation yields reserve requirements and concrete bankruptcy probabilities.

  • Reserve model: PPS-pool reserves should be large enough to keep the probability of eventual operator bankruptcy low.The analysis assumes no sabotage attacks, invalid blocks, or similar disruptions.
  • Reserve model: The operator’s balance is modeled as a Markov chain whose steps correspond to submitted shares.Each step has expectation fpB and variance approximately pB^2.
  • Reserve model: The long-term balance process is approximated using the central limit theorem, preserving the process’s expectation and variance.The resulting recurrence is solved with boundary conditions representing certain bankruptcy at zero reserve and no bankruptcy at infinite reserve.
  • Reserve requirement: To maintain bankruptcy probability at most δ, the pool should keep at least the reserve specified by the derived bound.The paper presents the bound immediately before its numerical examples.
  • Examples: With B = 50 BTC, δ = 1/1000, and f = 0.05, the required reserve is approximately 3454 BTC.This example applies the paper’s reserve formula to a 5% fee and a 0.1% bankruptcy target.
  • Examples: With f = 0.01 and only 500 BTC reserved, the operator has an 81.9% chance of eventual bankruptcy.The example contrasts a low fee with an insufficient reserve.

The hopping immunity theorem

The hopping immunity theorem shows that deterministic reward methods satisfying fixed expected per-share payment and nonnegativity constraints cannot distribute rewards across multiple shares: all reward goes to the final share.

  • Theorem: If a reward method always gives each submitted share expected reward (1−f)pB, the entire round reward is assigned to its last share.The theorem assumes fixed difficulty and block reward and a deterministic function of round length and share index.
  • Proof setup: The reward for the ith share in a round of length N is represented by a function f(i, N).The proof uses the function’s fixed-total-reward and expected-value properties.
  • Proof: Induction shows that the ith share receives the full reward when N = i and zero reward when N > i.The fixed reward assumption determines the payment at N = i, while nonnegativity forces later-round payments to zero.
  • Proof: The proof uses δij as the Kronecker delta to express that only matching share and round indices receive payment.δij equals 1 when i = j and 0 otherwise.

Properties of the geometric method

The geometric method makes expected rewards independent of pool history and future difficulty or block-reward changes, thereby preventing pool-hopping. Its parameter c trades lower variance for slower reward confirmation, while high c can eliminate per-share variance.

  • Core properties: The geometric method’s expected reward is independent of pool history and future difficulty or block-reward changes, making it hopping-proof.The appendix analyzes expectation, variance, and maturity time for this method.
  • Reward mechanism: A share’s score grows as r^I during a round, and its payout is determined by the round-ending share after N total shares.The paper defines the share’s score addition and resulting payout using the round indices I and N.
  • Variance analysis: The paper derives the method’s variance using computer algebra and gives an approximate expression when the variable fee is nonzero.The appendix notes that rewards for nearby shares are correlated, so multi-share variance scales worse than linearly.
  • Reward timing: Maturity time is the average number of additional shares, measured in difficulty multiples, needed to confirm a specified amount of reward.This is the paper’s operational definition of maturity time.
  • Variance and timing: As c approaches 1, the geometric method’s variance becomes 0 per share regardless of participant hashrate.This can fall below the minimum total variance achievable in pools without operator risk.
  • Accounting: The method’s total participant rewards leave the operator with an effective score of 1.This describes the accounting identity for the total reward distribution.
  • Variance and timing: Decreasing c significantly increases variance but makes any received reward arrive more quickly.The parameter c therefore controls a variance-versus-confirmation-speed trade-off.

F.1 Expected loss in MPPS

The MPPS analysis models Alice’s payment as the minimum of her PPS balance and her proportional share of pool rewards. Because block discovery fluctuates around its average, the method can produce a stochastic reward shortfall.

  • Expected loss in MPPS: Alice’s MPPS balance after n average blocks’ worth of shares is qnB, while her proportional balance is qLB.Here q is Alice’s pool-hashrate share, B is the block reward, and L is the number of blocks the pool actually finds.
  • Expected loss in MPPS: The payment is min(n, L)qB, so it is limited by whichever is smaller: expected block production or realized pool blocks.The pool’s block count L follows a Poisson distribution with mean n.
  • Expected loss in MPPS: For integer n, the associated expected-loss expression is reduced to n.The supplied derivation continues with a reward-loss term, but the surrounding expression is fragmented.
Loading 1112.4980v1…