Research story · Computing, economics & law

Who stays in
the mining pool?

A mining pool can coordinate computing power supplied by many independent businesses. To assess what that pool could sustain, follow the contributors as well as the coordinator: what keeps them there, what could make them leave, and how quickly can their decisions change the capacity available?

My published paper, Legal Deterrence in ‘Permissionless’ Consensus, examines this organisational problem alongside the economics of enforcement. It extends a protocol-only security benchmark by asking how a pool retains contributed hash power and when an identifiable operator faces consequences outside the protocol.

The distinction matters for a double-spend scenario. An analysis needs to specify both the resources initially available and the conditions under which those resources remain committed. The businesses supplying machines have their own earnings, alternatives and exposure. Their decisions can change the coordinator’s position while an attempted attack is still unfolding.

Separate the coordinator from the capacity

The model distinguishes computing power owned by the pool operator from power allocated by outside providers. The operator coordinates block production; contributors decide whether the return from remaining compares favourably with the return from switching. That creates an ongoing participation condition.

A pool’s nominal size adds those resources together. Its effective retained capacity also accounts for contributor exit. The difference becomes important when the activity that benefits a coordinator worsens the terms on which other businesses are willing to participate.

Identifying the decision-maker is therefore part of specifying the security model. A pool’s public identity, its own equipment and the equipment supplied by its members describe different things. Likewise, attribution of a coordination business does not establish where every contributing machine is located or prove a particular contributor’s knowledge of misconduct.

Two reasons to leave

The first exit channel concerns earnings. Diverting resources into a hidden activity can reduce or delay ordinary payouts. A contributor observing worse performance may move to another pool without knowing what caused the shortfall. The mechanism depends on the attractiveness and availability of that outside option.

The second channel concerns expected liability and capital risk. Once suspected misconduct becomes visible, remaining with the pool may expose a provider to additional contractual, legal or commercial losses. In the model, that expected exposure can make departure worthwhile even where the immediate payout comparison alone would have favoured staying.

These channels require different evidence. Payout records and switching behaviour help investigate the first. The second also requires evidence about attribution, applicable duties, the provider’s conduct and the consequences it actually expects. Participation in a pool does not, by itself, establish legal liability. The paper supplies an incentive framework within which those questions can be examined.

Enforcement has a participation condition too

The legal term in the paper depends on detection, attribution, effective sanction and the cost of pursuing enforcement. It is set to zero where the model’s expected benefit from enforcement fails to cover that cost. A legal remedy can exist while invoking it remains uneconomic in the circumstances being modelled.

This preserves a useful boundary for the protocol-only benchmark. Where external enforcement has no expected effect, security must be assessed using the remaining mechanisms. Where a sufficiently valuable, attributable claim makes enforcement worthwhile, the expected consequences enter the calculation.

The paper illustrates that boundary with alternative parameter combinations. Its resulting transaction-value thresholds range from about US$1.05 million to US$4.21 million. Those figures are conditional calculations, not statutory thresholds or measured points at which authorities begin to act. Different enforcement costs, attribution probabilities or available sanctions change the result.

The practical research question is consequently more specific than whether law applies in principle. It is which actor can take which action, on what evidence, at what expected cost and within what relevant period. The answer may vary across organisations and jurisdictions.

Read the simulation with its denominator

The paper’s member-exit simulation begins with a pool supplying 252 exahashes per second, of which 25 are assumed to be proprietary. Outside providers supply the remainder. The experiment assigns contributors differing sensitivities to payout deterioration, then introduces legal and capital-risk exposure and network friction.

Under the full illustrative specification with a quadratic exit function, mean effective pool capacity after 24 hours is 67.5 exahashes per second, or 26.8 per cent of its starting level. The experiment reports 1,000 Monte Carlo replications and compares alternative exit functions. It shows the behaviour of a specified mechanism under declared choices.

Several choices are explicitly parametric: the proprietary share, the number and size distribution of contributors, their exit response, the observation window, the detection lag and the diversion schedule. The reported paths therefore do not establish how an actual pool would respond, or how quickly a real attack would fail.

The denominator also needs care. The starting pool is 31.5 per cent of the simulation’s illustrative network; 26.8 per cent retained means a fraction of that pool’s original capacity. It is not a network-wide share. A majority-attack assessment must separately specify the attacking coalition, the honest remainder and how switching changes each side.

Turn the mechanism into a research programme

The next empirical task is to measure the participation relationship. Which resources are proprietary? How do contributors observe performance? What contracts and switching costs constrain them? How does a documented change in expected exposure alter their behaviour? Those measurements would help distinguish a plausible channel from a calibrated account of its strength.

This connects organisational economics with distributed-systems security. Protocol rules determine how computing work contributes to a chain. Contracts and commercial alternatives help determine who continues supplying that work. Enforcement affects expected payoffs only where attribution and institutions make it credible.

The contribution is a more explicit object of analysis: a coalition that must continue to hold together. Assessing its resources at one moment is a starting point. Explaining why those resources remain available over the relevant horizon is part of the security question.

Blockchain & technologyGovernance, law & accountabilityRelated story: what does a miner stand to lose?