frstrtr 2026
Abstract. A purely peer-to-peer mining pool divides a block reward in proportion to recent work without a trusted operator. The accepted solution, a share chain, requires each unit of work to reference the current tip; work that references a stale tip is discarded, though its proof was never false, and only work meeting the share-chain difficulty is counted at all. We propose separating the two functions a share performs, ordering and evidence, so that the chain orders only carriers while work is accounted from self-contained receipts the carriers embed. A receipt is bound, within its own proof of work, to the pool, to the worker who is to be paid, and to a settled block of the underlying chain, so that it cannot be forged, transferred, replayed, or backdated, and it depends on no predecessor. The referenced block acts as a timestamp server, and work is placed in time by when it was performed rather than when it arrived. Time is divided into layered bins — a present that accepts work, a settled past that decays and coarsens, and a reserved future — so that age is at once the order of settlement, the resolution of storage, and the weight of work. The same accounting serves many underlying chains at once, each a lane sharing one set of workers, so a worker mining several chains is one account owed across all. Work below the consensus difficulty is credited by the same rule as all work, the difficulty of the target it met, so the credit is exact in expectation and cannot be improved by splitting a worker into many identities. Accounting is kept separate from payment, so an unbounded number of contributors may be owed while a bounded coinbase pays them in turn. The record is a deterministic function of the underlying chain and is held identically by every node, so participants may join and leave without permission, and what a worker has earned stays owed until a block has room to pay it.
Errata, 4 October 2026. Section 9, and the parts of the abstract and of Sections 10 and 14 that rely on an owed balance, are withdrawn. An independent review showed that a pool with no custodian cannot owe some miners without overpaying others, and the overpayment is never recovered. A revised Section 9 will describe paying each block's window in full, in that block. Section 3 is narrowed: work done on a tip of the underlying chain that had already been passed earns nothing.
Mining pools exist to reduce the variance of mining income. A centralized pool keeps the accounting of recent work on a trusted server, which can misreport, withhold, or fail. A decentralized pool replaces the server with a share chain: a chain of low-difficulty blocks recording who did recent work, among which a found reward is divided. This removes the operator but introduces two problems that have persisted since the share chain was first proposed.
First, a share couples two unrelated functions. It is evidence of work, and it is a position in an order. To take a position it must reference the current tip; if latency causes it to reference a tip no longer current, the share is rejected and its proof of work is discarded with it, although that proof was never false. At low individual hash rate this lost work is a material fraction of the total.
Second, the share-chain difficulty that keeps the chain advancing is also the threshold below which work is not counted. A participant whose hardware rarely meets that threshold is either excluded or paid at a variance that makes participation pointless.
We address both by observing that a unit of work need not be ordered to be counted.
A receipt is a proof of work whose hashed message is bound to the pool and chain, to the worker who is to be paid, and to a settled point of the underlying chain. None of these bindings can be altered without redoing the work, and the receipt is bound to no predecessor: it stands alone, and its order of arrival does not matter.
The chain need not order receipts. We let it order only carriers, which are ordinary shares, and let each carrier embed a bounded number of receipts. A receipt is accounted from inside whatever carrier transmits it. A worker therefore proves work without winning an ordering race. The same receipt presented twice is rejected by a short record of those recently seen; one held back loses its value as its committed block ages, and expires; one offered to another pool is invalid there by its binding.
A share that became stale is then simply a receipt whose work met the share target. It is carried in the worker's next share and counted in full. No re-attestation, no branching chain, no per-worker ordering, and no record of orphans is required.
To account work by when it was performed, a clock is needed that no participant controls. A clock derived from worker-reported time is not such a clock. Each receipt already commits to a block of the underlying chain, which is a distributed timestamp server: its blocks are fixed by proof of work and spaced widely enough that races within the share chain cannot blur them. We account a unit only once its committed block is buried beyond reorganization, and take that block's height as the time of the work. The clock runs a fixed distance behind the present and is the same for every node; no later reorganization moves a time once accounted. Work that arrives late is placed at the time it was done and ages from there, as if it had not been late.
Time, so taken, is divided into bins. The recent bins are open: the present, accepting on-time work and the receipts that credit work already done. As a bin ages it is settled — frozen into an immutable past — and thereafter held more coarsely the older it grows. The bins not yet reached are the future, kept as a reserved slot and excluded from payment. This layered placement of work in time, on a clock taken from the underlying chain, is the hybrid evaluation: one structure serves at once as the order of settlement, the resolution of storage, and the measure of age. A unit's weight falls with the age of its own bin, so recent work weighs more than old; and because a unit is placed by the time it was performed, late work decays exactly as if it had never been late, which accounting by time of arrival cannot do.
The Monero lane, as first released, is an exception to Sections 3 and 4, and to the matching clauses of Sections 2 and 15. A receipt is placed in the bin of the block it would become and is ordered as it arrives; a bin closes when the next block's template passes it, not at burial; a receipt that arrives late takes the youngest place in the window rather than the place of its bin; and weight decays with that place, so the window is the fixed count of receipts of Section 6. A receipt older than a bounded number of blocks is refused. Because every receipt meets one target, a unit is paid the same expectation whenever it arrives, so lateness gains nothing, but late work is not aged as if it had been on time. The clock of Sections 3 and 4, and the summaries of Section 12, are its planned form.
A hash below a target is a proof of expected work. We take the work of a unit to be a function of the target it was required to meet, not of the value its hash reached, so that two units meeting the same target are credited equally and the accounting is neutral to luck. The amount by which a hash falls below its target cannot serve as a payment weight — a single fortunate hash would dominate a reward, defeating the variance reduction that is the purpose of pooling — and it is not needed: a hash that met a lower target is itself a unit of work at that target, so work below the pool's difficulty is counted by the same rule (Section 8).
We account work in a window of recent time. Each unit contributes its work value, reduced by a decay in the age of its bin, so that a worker who stops contributing fades from the window. The accounting is maintained so that a unit, once recorded, is not recomputed as time passes: adding work takes constant time, and the divided reward is read in time proportional to the number of active workers, not to the length of the window. All arithmetic is integer and truncating, in fixed point, applied in the order the work was performed, so the result is a function of the chain alone and is identical on every node.
The window is a fixed count of recent units, all meeting one target, so every unit in it is the same work and each is equally likely to be the one that finds a block. A worker who raises its rate fills the window faster and moves the older work of the others out of view sooner, but blocks are found correspondingly faster, so the expected payment for a unit of work does not depend on when it was done or on what others do: pulsing, hopping and withholding gain nothing in expectation, and change only how a small worker's payments are spread over blocks. A window denominated in time, widening as the pool's share of the network's work falls, keeps a steadier span in view, but its total weight follows the pool's recent rate while blocks follow its present rate, so work done just before a rise in the pool's rate is paid more than work done just after it; such a window is adopted only with a rule that removes that bias. A worker who contributes steadily is credited in full, while one who mines only briefly, to depart, keeps only what its own work earned — without any judgement of identity.
A pool need not serve a single chain. One accounting serves many underlying chains at once, each held as a separate lane and all sharing one set of workers. A unit of work is credited against the target of every chain it satisfies, each evaluated against that chain's own difficulty, so a worker who mines several chains at once is credited on each and penalised on none. Work done under unlike proof-of-work functions is made comparable by counting each unit as the work its target expected, so chains of different difficulty and different function meet in one record under one identity. A worker is thus a single account owed across every chain it serves, and a chain may be added or retired without disturbing the others.
Section 2 recovers work that met the share target but lost its position. We now credit work that never met it. Between shares a worker produces many hashes meeting a low difficulty used to measure its rate, ordinarily discarded. We carry them as receipts, served at that low target so that every one is seen. Each such hash is credited, as a share is, the work its own target expected, never the value it reached: a worker's credit for an interval is the number of its hashes that met the low target times that target's work, shares included, in place of its shares alone. The credit is a sum over hashes, so it is exact in expectation and the same whether a worker mines under one identity or many; no hash is counted twice. The credit is not priced once. It enters the window of Section 6 as weight spread evenly over the positions of the interval in which it was earned, decays with age as shares there would, and is paid in every block found while it remains in the window, each block's reward being divided over the shares and this weight together. Per unit of work it therefore earns what a share earns, whatever the rate at which blocks are found, and in expectation a worker gains nothing by publishing a share or by withholding it. A worker who withholds a share found early in its interval moves that work to the interval's mean position; the gain is at most the decay across half the interval, about 0.2% of that share at twelve units per interval, and a share found late loses as much (test v37_xmr_drops_income_kat). The threshold below which a worker was invisible is removed for accounting while retained for ordering: carriers still meet the share target, and the chain still advances at a steady rate.
Withdrawn on 4 October 2026; see the errata at the top.
The reward is paid in the coinbase of a found block, of bounded size, which cannot contain an output for every worker. We separate accounting from payment. The decayed weights of Section 6 give each worker's share of the current reward; a second record holds the amount owed to each worker, which only grows as rewards are divided and only shrinks when a payment is made. It is committed with the rest of the state, held by every node, and may owe any number of workers at no cost in coinbase space. A reward enters the owed record, and a payment leaves it, only once the relevant block is buried beyond reorganization, so a block orphaned before then need never be undone and no amount is paid twice. The share of a block is taken from the window as the pool's latest block already buried beyond reorganization fixed it, so every node that checks a block, or a share that could become one, holds the same inputs; a pool's first blocks, before any is buried, pay their finder. When a block is found, the coinbase pays each worker of the window its share of that block while the block has room for an output, however small the share; a share becomes a balance only when the block has no room for it or cannot yet fund it. Balances are paid oldest first: the balance that has waited longest is paid first, ties broken by a canonical order that no participant can choose, so that every node selects the same set, until a fixed budget of outputs is reached. A balance paid in full leaves the queue and joins its end when the worker next earns. Where an output costs more to spend than a small amount is worth, amounts worth spending are paid before such amounts when the block is full; the share of a worker that does not fit is divided among the workers paid in the same block, and its work stays in the window to earn in the next. No payment runs ahead of the work that earned it, so no balance is negative, and a worker credited below the share target is paid as the others are, in the block, rather than at the back of a queue whose payment depends on the pool outliving the wait.
The protocol takes no fee, and no output is reserved for an operator. A node may run two settings that reduce what its own miners receive, each bound into the miner's own receipt and reported to the miner by the node it connects to. The first gives a part of each receipt's weight to the author of the software; it is 0.1% by default and optional, and any node may set it to 0. The second makes a share of the node's jobs pay the node's owner. The author's donation output is present in every block as a marker, carrying what the receipts gave it and otherwise nothing; what the owed pass and the current block's own workers leave in a coinbase goes to it, and it is never burned.
Because each unit is accounted as provable work, and the record is identical on every node and committed to the underlying chain, the work a worker has delivered is a quantity any party may verify without trust. A worker may therefore contract to deliver work to another, the delivery measured by the record itself and credited to the other's account, with no operator and no market-maker standing between them. The long tail of balances too small to pay in a block need not only wait in the queue of the previous section; it may settle through such exchange beside the block, so that the coinbase carries the present while accumulated and contracted work settles alongside it.
The standing work that earns a reward can price other scarce things. A worker may carry a signed message in its own share; its right to be carried, and to remain visible, follows from the work that worker holds in the window, so that the resource which pays for a message is hashing and nothing else, and a message fades as its author's work decays, with no operator to permit or refuse it. Whatever can be priced in standing work may be carried the same way.
The window of recent work is small, but the complete record would grow without bound. The settled past of Section 4 is held in levels, each covering a span a fixed multiple longer than the level below it. The total work and the per-worker composition of each summary are preserved exactly; only the ability to address a single unit within a summary, and only for old work, is given up. The whole history of a chain is held in a number of summaries that grows with the logarithm of its age, in a few megabytes, while the exact divided reward of any past span remains recoverable.
The committed state is the root of a Merkle tree whose leaves are the workers' balances, beside a digest of the rest of the state, and it is committed in the coinbase of the underlying chain, fixed by that chain's proof of work. A device holding only the headers of the underlying chain can verify a balance, without holding the share chain, by following a header to its coinbase through the block's tree of transactions, the coinbase to the committed root, and the root to the leaf, with a proof whose size grows with the logarithm of the number of transactions and of workers; the balance so proved is the one settled beneath that block. The summaries of Section 12 are to join the leaves. The payments themselves are verified by every node rather than trusted to the one who builds a block: from the committed state each node recomputes the coinbase a block must carry, and the coinbase of every share that could become a block, and a share that pays otherwise is refused. A block that pays otherwise is booked against the one who built it: what it paid is charged to its payees, and nothing it would have credited is owed, so a builder gains no more than the block it found.
The record, the window, and the balances are a function of the share chain and nothing else; every node computes the same record, so no node holds anything uniquely. A node that leaves removes one of many identical copies; a node that joins needs no permission and reconstructs the record from the chain, or from its recent part and the committed root. A worker that leaves has its weight in the window decay and evict, while whatever it has earned remains owed and whatever it has done remains in the summarized history. An owed balance too small to be worth spending is paid whenever a block has room for it; only one that finds no room while its worker stays away is written off, after a long grace and alike on every node, and the write-off lowers only what the pool owes. Nothing else honest is lost to the coming and going of nodes or of workers.
A worker cannot forge a receipt, for a receipt is itself proof of work; nor transfer one, for the payee is inside the hashed message; nor replay one, for receipts are deduplicated within the window in which they are valid; nor backdate one, for the committed block fixes its time and expires it. It cannot inflate its credit below the share target, for each hash is credited only the work of the target it met, and splitting its work across identities changes neither the expectation nor the spread of what it is paid. It gains nothing by withholding a good share to report it only as a receipt, for the credit is the same while the share could also have advanced the chain; and it gains nothing by mining in bursts or briefly to depart, for every unit is paid the same expectation whenever it was done (Section 6). The honest strategy, to work continuously and transmit one's receipts, is the one that maximizes pay.
We have proposed a system for accounting the work of a decentralized mining pool that does not discard honest work. We separated ordering from evidence, so the chain orders carriers while work is accounted from self-contained receipts; we used the underlying chain as a timestamp server and placed work in layered bins of time, so work is accounted by when it was performed and ages soundly; we let one accounting serve many chains under one identity, and let delivered work be verified and settled beside the block as well as within it; we credited work below the ordering difficulty by the target it met, as all work is, exactly and whatever the number of identities; we separated accounting from payment, so an unbounded set of workers is owed while a bounded coinbase pays them in turn; and we made the record a function of the chain, held identically by every node, so participants join and leave without permission and without loss of what they earned. The work that was discarded was never false, and it is kept.
[1] S. Nakamoto, "Bitcoin: A Peer-to-Peer Electronic Cash System," 2008.
[2] F. Voight, "p2pool: a peer-to-peer Bitcoin mining pool," 2011.
[3] A. Back, "Hashcash — a denial of service counter-measure," 2002.
[4] R. C. Merkle, "Protocols for public key cryptosystems," in Proc. IEEE Symposium on Security and Privacy, 1980.
[5] M. Rosenfeld, "Analysis of Bitcoin pooled mining reward systems," 2011.