November 2018
Although Bitcoin was intended to be a decentralized digital currency, in practice, mining power is quite concentrated. This fact is a persistent source of concern for the Bitcoin community.
We provide an explanation using a simple model to capture miners’ incentives to invest in equipment. In our model, n miners compete for a prize of fixed size. Each miner chooses an investment qi, incurring cost ciqi, and then receives reward qαi∑jqαj, for some α≥1. When ci=cj for all i,j, and α=1, there is a unique equilibrium where all miners invest equally. However, we prove that under seemingly mild deviations from this model, equilibrium outcomes become drastically more centralized. In particular, (a) When costs are asymmetric, if miner i chooses to invest, then miner j has market share at least 1−cjci. That is, if miner j has costs that are (e.g.) 20% lower than those of miner i, then miner j must control at least 20% of the emph{total} mining power. (b) In the presence of economies of scale (α>1), every market participant has a market share of at least 1−1α, implying that the market features at most αα−1 miners in total.
We discuss the implications of our results for the future design of cryptocurrencies. In particular, our work further motivates the study of protocols that minimize “orphaned” blocks, proof-of-stake protocols, and incentive compatible protocols.