Glossary

AsicBoost

AsicBoost is a mining optimization that reduces the energy needed per SHA-256 hash by reusing parts of the block header computation.

Key Takeaways

  • AsicBoost is a mining optimization that reduces SHA-256 computation by approximately 15-20% per hash by reusing the intermediate hash state (midstate) from the first chunk of the block header.
  • Two variants exist: overt AsicBoost (visible on-chain via version bits) is standard on modern ASIC miners, while covert AsicBoost (hidden in the coinbase transaction) became effectively extinct after SegWit activated in August 2017.
  • The technique sparked one of Bitcoin's most heated controversies when allegations emerged that covert AsicBoost usage motivated opposition to SegWit activation, raising questions about mining centralization and proof-of-work fairness.

What Is AsicBoost?

AsicBoost is a method for optimizing Bitcoin mining hardware to perform proof-of-work computations more efficiently. It was described in a 2016 paper by Dr. Timo Hanke and Sergio Demian Lerner, though the underlying patent was filed around 2014. The technique exploits the way SHA-256 processes Bitcoin's 80-byte block header, allowing miners to skip redundant computation and find valid blocks using less energy per hash.

While AsicBoost is a legitimate engineering optimization, its covert variant became deeply controversial. Allegations that certain mining hardware manufacturers used covert AsicBoost and opposed protocol upgrades to protect that advantage fueled years of debate within the Bitcoin community.

How It Works

To understand AsicBoost, you first need to understand how Bitcoin's double-SHA-256 proof-of-work processes the block header. SHA-256 operates on data in 64-byte (512-bit) chunks. Since a Bitcoin block header is 80 bytes, it gets split into two chunks:

  • First chunk (bytes 0-63): contains the version field, the previous block hash, and the first 28 bytes of the Merkle root
  • Second chunk (bytes 64-79, padded to 64 bytes): contains the last 4 bytes of the Merkle root, the timestamp, the difficulty target (nBits), and the 32-bit nonce

SHA-256 processes these chunks sequentially. After hashing the first chunk, it produces an intermediate hash state called the "midstate." This midstate feeds into the second chunk's computation. The key insight behind AsicBoost: if a miner can find multiple block header candidates that produce the same midstate from the first chunk, they only need to compute the first chunk once and then vary the nonce in the second chunk across all of them.

This saves approximately 15-20% of the total computation per hash, according to the original paper and analysis by Bitcoin Optech. Some sources cite theoretical gains of up to 30% under optimal conditions.

Midstate Collision Example

In simplified terms, the optimization works by finding "collisions" in the first chunk: different header inputs that nonetheless produce the same midstate output. With the midstate held constant, every nonce attempt in the second chunk benefits from the saved first-chunk computation:

Block header (80 bytes):
┌──────────────────────────────────────────┬──────────────────────┐
│          First chunk (64 bytes)          │ Second chunk (16+pad)│
│  version | prev_hash | merkle_root[0:28] │ merkle[28:32] | time │
│                                          │ nBits | nonce        │
└──────────────────────────────────────────┴──────────────────────┘

Standard mining:
  Chunk 1 → midstate_A → Chunk 2 (nonce 0..N) → hash results
  Chunk 1' → midstate_B → Chunk 2 (nonce 0..N) → hash results

AsicBoost (midstate collision):
  Chunk 1  ─┐
  Chunk 1' ─┤→ same midstate → Chunk 2 (nonce 0..N) → hash results
  Chunk 1''─┘
  (first-chunk computation shared across multiple candidates)

A miner using AsicBoost effectively gets multiple "free" first-chunk computations, reducing the average energy cost per hash attempt.

Overt AsicBoost

Overt AsicBoost achieves midstate collisions by manipulating the version field in the block header. Since the version field sits in the first chunk, changing its unused bits can produce different inputs that collide on the same midstate. This approach is called "overt" because the modified version bits are publicly visible to anyone inspecting the blockchain.

BIP 320 formalized this by reserving 16 bits (bits 13-28) of the nVersion field for general-purpose use, represented by the mask 0x1fffe000. Mining equipment negotiates which bits to use with pools via the Stratum "version-rolling" extension. This approach is fully compatible with SegWit and all protocol upgrades.

Modern ASIC miners from all major manufacturers now ship with overt AsicBoost enabled by default. It is built into the silicon and firmware of current-generation hardware like the Bitmain Antminer S19/S21 series and MicroBT Whatsminer M50 series.

Covert AsicBoost

Covert AsicBoost achieves midstate collisions by manipulating the Merkle root instead of the version field. Since the first 28 bytes of the Merkle root sit in the first chunk, a miner can rearrange transaction order or modify the coinbase transaction to produce different Merkle roots where the first 28 bytes vary (creating collisions) while the last 4 bytes (in the second chunk) remain identical.

This approach is "covert" because there is no single on-chain indicator revealing its use. However, naive implementations leave detectable patterns: unusually small blocks, specific transaction ordering, or empty blocks. These patterns can be identified through chain analysis.

The SegWit Controversy

In April 2017, Gregory Maxwell (then CTO of Blockstream and a Bitcoin Core contributor) published findings on the Bitcoin development mailing list revealing that a mining hardware manufacturer had implemented covert AsicBoost in their ASIC chips. The manufacturer was subsequently identified as Bitmain, whose CEO Jihan Wu had been a vocal opponent of SegWit activation.

The controversy centered on a critical technical detail: SegWit introduced a witness commitment in the coinbase transaction that changes the Merkle root in ways that make covert AsicBoost collision-finding impractical. In other words, activating SegWit would break covert AsicBoost.

Evidence cited at the time included AntPool (Bitmain's mining pool) producing blocks roughly 100KB smaller than comparable pools, which is consistent with covert AsicBoost functioning more effectively with fewer transactions. Maxwell argued that "the covert method of mining with AsicBoost is no longer possible if Segregated Witness activates."

Bitmain denied that opposition to SegWit was motivated by AsicBoost, though they acknowledged having the technology in their chips. SegWit ultimately activated on August 24, 2017, effectively ending covert AsicBoost usage on the Bitcoin network.

BIP 320 and Version Rolling

With covert AsicBoost no longer viable after SegWit, the community moved to standardize the overt variant. BIP 320, authored by BtcDrak, reserves 16 bits of the block header's nVersion field for general-purpose use by mining hardware. This serves a dual purpose:

  • It provides additional nonce space for miners, since modern ASICs exhaust the 32-bit nonce field in under 200 milliseconds, reducing the frequency of new job distribution from pools
  • It enables overt AsicBoost by allowing miners to roll version bits to find midstate collisions, requiring a minimum of two bits for 4-way collisions

BIP 320 leaves 13 bits available for parallel soft-fork signaling and does not require a soft fork to implement. Mining pools support version rolling via the Stratum protocol extension, making overt AsicBoost seamless for miners.

Use Cases

AsicBoost applies specifically to SHA-256-based proof-of-work mining:

  • Large-scale mining operations use overt AsicBoost to reduce energy consumption per terahash, directly improving mining profitability
  • Hardware manufacturers build AsicBoost support into ASIC chip designs at the silicon level, making it a standard feature rather than an optional add-on
  • Mining pools implement the Stratum version-rolling extension to coordinate overt AsicBoost across their connected miners
  • The technique is specific to Bitcoin and other SHA-256 coins: it does not apply to alternative hash functions used by other cryptocurrencies

For a deeper look at how mining economics shape the Bitcoin network, see the research article on Bitcoin mining economics and the analysis of Stratum V2 and mining decentralization.

Patent History and Resolution

The AsicBoost patent changed ownership multiple times before landing with Little Dragon Technology LLC. In March 2018, Little Dragon joined the Blockchain Defensive Patent License (BDPL), making the patent freely available to any manufacturer that also joins the BDPL. The BDPL is a mutual non-aggression arrangement where members license their blockchain patents to one another royalty-free.

Shortly after, Halong Mining became the first manufacturer to publicly implement overt AsicBoost in its DragonMint T1 miner. Bitmain followed by releasing overt AsicBoost firmware for its Antminer S9 line. Today, the patent is no longer a barrier to adoption: all major mining hardware manufacturers use AsicBoost freely under the BDPL.

Risks and Considerations

Centralization Concerns

Before the BDPL made AsicBoost freely available, miners with access to the optimization held a significant competitive advantage. A proprietary efficiency gain of 15-20% translates to substantially higher revenue at the same energy cost, potentially concentrating hashrate among a few manufacturers. This dynamic highlighted how hardware-level optimizations can impact mining centralization. For further analysis, see the research on mining centralization and pool risks.

Protocol Upgrade Conflicts

The SegWit controversy demonstrated how mining optimizations can create misaligned incentives around protocol upgrades. Miners benefiting from covert AsicBoost had a financial reason to oppose SegWit, regardless of its technical merits. This tension between miner incentives and network-wide improvements remains a consideration in Bitcoin Core governance and future soft-fork proposals.

Detection and Transparency

Covert AsicBoost was difficult to detect definitively, which allowed it to persist without public scrutiny. Overt AsicBoost solved this transparency problem: version-bit rolling is visible on-chain and can be monitored by any full node or block explorer. The shift from covert to overt usage represents a healthier outcome for the network, even if the underlying optimization remains the same.

Energy and Environmental Implications

From an energy perspective, AsicBoost is a net positive: it allows the same hashrate to be maintained with less electricity. At the scale of Bitcoin's global mining network, a 15-20% efficiency improvement represents a meaningful reduction in energy consumption per unit of security provided.

This glossary entry is for informational purposes only and does not constitute financial or investment advice. Always do your own research before using any protocol or technology.