What is a hash in blockchain and crypto
Published: October 4, 2026
Also available in:EspañolРусский繁體中文
A hash, in plain terms, is a short fingerprint of data. A hash function takes a text, a file or a record of any size and returns a string of fixed length; the same data always gives the same hash, and changing one character changes all of it. A blockchain rests on this: every block and every transaction has its own hash, and even a wallet address is produced by hashing. We run notrace.exchange, a mixing service, and on 4 October 2026 we recomputed the hashes of a real block and of real transfers on three networks ourselves, to show where they come from and what they let anyone see.
What a hash is
The definition in the Internet Security Glossary (RFC 4949) describes a hash function as "A function H that maps an arbitrary, variable-length bit string, s, into a fixed-length string". The output is called a hash, a hash value or a digest.
It is easier to show. Take SHA-256, the function Bitcoin runs on, and hash the five characters 1 BTC:
174b3310 11288fd7 53a83579 1557e1b3 591b2326 96b01f33 ce4f6f7d f9cd8c4b
Now change one digit and hash 2 BTC:
f8d78110 583c3ebd 82c5e630 d6191b71 f0e9cce8 bf144e54 677566b2 73125e6c
The spaces are ours, for readability; a real SHA-256 hash has none, it is 64 characters in a row made of digits and the letters a to f. The two inputs differ by one character, yet the hashes agree in only 3 positions out of 64, and 131 of the 256 bits changed. You can repeat this in any SHA-256 calculator: the result will be the same down to the last character.
The length of a hash does not depend on the size of the input. We repeated the string 1 BTC a million times, which makes five megabytes of text, and its hash again took 64 characters: 14a2c3a5…f0c8.
Three properties everything rests on
- Same input, same hash. Otherwise there would be nothing to compare.
- There is no way back. The original data cannot be computed from the hash. The standard that describes SHA-256 calls the function secure precisely because it is "computationally infeasible" to find a message that corresponds to a given digest (RFC 6234).
- Two different inputs with one hash cannot be found. The same document names this as the second condition of security. Such a match is called a collision.
Functions age. On 23 February 2017 Google announced the first collision found for the older SHA-1 function (Google Security Blog); we know of no collision found for SHA-256.
Two caveats that are often missed. Hashing is not encryption: there is no key, and nothing to decrypt a hash with. And one-wayness does not protect short, predictable data: the hash of a phone number or a simple password is found by trying every option.
A block hash: checking it ourselves
In Bitcoin every block has a header 80 bytes long. According to the developer documentation it has six fields: the version, the hash of the previous block header, the merkle root of the transactions, the time, the encoded difficulty target and the number that miners vary (the nonce); the header is hashed with SHA-256 twice.
We took block 969,824, closed on 4 October 2026 at 09:43:54 UTC with 6,083 transactions in it, downloaded its 80 bytes, applied SHA-256 twice and reversed the byte order, as is the convention for display. The result:
00000000 00000000 00021913 7ce6b558 da3de58c 6e9dce0d bc734a06 77b10188
That is, character for character, the hash under which explorers show the block, for example Blockstream. The check took a fraction of a second on an ordinary computer.
Two things are visible right in that string.
The zeros at the start. There are nineteen of them, and that is no accident. The original Bitcoin paper describes proof of work as "scanning for a value that when hashed, such as with SHA-256, the hash begins with a number of zero bits". Miners change the nonce and hash again until the result is small enough; in our block the number that worked was 3,347,284,606. At a difficulty of 132.7 trillion one block takes about 570 sextillion attempts on average (5.7 × 10²³), while the result, in the paper's words, "can be verified by executing a single hash".
The link to the past. The "previous block header hash" field holds 00000000 00000000 0001f159…bcc9, which is exactly the hash of block 969,823. Change one transaction in an old block and its hash changes, stops matching the entry in the next block, and so on to the very end of the chain. More on the chain itself in what is blockchain and what it shows.
What a transaction hash (TXID) is
A transaction hash is the transaction's identifier, also called a transaction ID, TXID or tx hash. It is not handed out in sequence like an order number: it is computed from the record itself. So nothing in a transaction can be changed while keeping the old hash.
Each network computes it in its own way, and we checked all three.
- Bitcoin. The TXID is a double SHA-256 of the transaction in the form in which it is relayed between nodes (documentation). We recomputed the transfer that the Bitcoin Wiki lists as the first Bitcoin transaction,
f4184fc5…9e16in block 170 (275 bytes), and a fresh transaction from block 969,824. Both hashes matched. - Ethereum. The transaction hash is the Keccak-256 function of the signed transaction. In block 26,118,233 (09:56:23 UTC) we recomputed the first twelve transactions: all twelve matched.
- Tron. The identifier is SHA-256 of the transaction's content, without the signature. Block 86,811,707 (09:56:27 UTC) held 372 transactions, and all 372 matched.
A finding along the way. The ethereum.org glossary says Keccak-256 "was standardized as SHA-3". In practice the Keccak-256 that Ethereum uses and the SHA3-256 found in standard libraries give different results: from the same string 1 BTC we got aa5c8c0c…b3ef and a87d1e9a…c3e7. To check Ethereum hashes you need Keccak-256 itself.
A transaction hash looks the same everywhere: 64 characters, with the 0x prefix on Ethereum. In a wallet it sits in the history of operations, on the line called "hash", "transaction ID" or "TXID".
What a transaction hash shows
A hash hides nothing. It is a pointer: paste it into a block explorer and the whole record opens.
Open the link to the transfer in block 170 and you see what anyone sees: one input of 50 BTC, two outputs of 10 and 40 BTC, the addresses on both sides, the block number and the time. There are no names in the record. A transfer made today is no different: its hash shows the sender's address, the recipient's address, the amount, the fee, the time and the number of confirmations.
Three practical consequences.
- A transaction hash is safe to show in the sense that it gives no access to the coins. Nothing can be spent with it.
- But showing a hash means showing the whole transfer. Along with the amount, the other person learns your address, and an address reveals its balance and its whole history. On Bitcoin that includes the change address, which is one more address of yours.
- A hash is a receipt. It proves that a transfer of this amount to this address was written into a block. The dispute "I sent it, you did not get it" is settled with it in a minute.
What your address gives away to strangers is covered in what is a wallet address, and how records are followed from one transfer to the next in is Bitcoin traceable.
An address is a hash too
No office issues a wallet address: it is computed from a public key. For classic Bitcoin addresses the public key is hashed with SHA-256, the result with RIPEMD-160, and the outcome is encoded with a checksum (Bitcoin Wiki). We took the public key written into the first Bitcoin block, went through those steps and arrived at 1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa, the very address that received the reward for the first block.
On Ethereum the address comes from "taking the last 20 bytes of the Keccak-256 hash of the public key and adding 0x to the beginning" (ethereum.org).
Because hashing is one-way, a key cannot be computed from an address, and the same word "hash" in a wallet can mean different things. A transaction hash is the record of a transfer; an address is where transfers go. How a key, a phrase and an address are related is covered in seed phrase vs private key.
What hash rate is
Hash rate is the number of hashes the miners of a network compute per second. It cannot be measured directly; it is estimated from the difficulty, and the Bitcoin Wiki gives the formula. For our block it comes to about 950 exahashes per second, that is 950 quintillion attempts every second. The higher the hash rate, the more it costs to rewrite past blocks: all of that work would have to be done again.
Common questions
Can the original data be recovered from a hash? Not if the data is long and unpredictable. Short and typical data is found by trying every option.
Can two different transactions have the same hash? SHA-256 has two to the power of 256 possible values, and we know of no collision found. In practice a transaction hash is unique.
Are a hash and an address the same thing? No. An address shows where coins were sent; a transaction hash shows which particular record was made of it. One address can have thousands of transactions, each with its own hash.
What if a transfer is "stuck"? Find it by its hash in an explorer. If the record is there with zero confirmations, the transfer is waiting to be included in a block. If there is no record at all, the wallet never sent it.
Is the hash of one transfer the same on different networks? No. Every network has its own ledger and its own records; why the same USDT on two networks is two different tokens is explained in TRC20 vs ERC20.
Where we stand
Hashes show up in two places in our service, and both can be checked.
- On the order page each of the two payouts gets a transaction hash with a link to the explorer of its network. That is your receipt: the transfer is read the same way we read other people's.
- The letter the order offers before you pay begins with the lines
-----BEGIN PGP SIGNED MESSAGE-----andHash: SHA512. The signature is made not over the text itself but over its hash: that is how an OpenPGP signature works (RFC 9580). Change one character in the letter and the check on our PGP key page fails.
The rest in brief. The payout leaves in two transfers to two addresses of yours, each with its own delay of 0 to 6 hours. While a delay runs, the funds are held by the service: section 8 of the terms names it the custodian for that time. Our fee on 4 October 2026 was 0.5%; the current figure is always on the FAQ page.
Four coins have a dedicated page that opens the form in that coin with its live minimum: the bitcoin mixer, Ethereum, Solana and USDT.
Where to start
Take the hash of your latest transfer and paste it into the network's explorer: you will see exactly what anyone you show that hash to will see. And to get a feel for the function itself, open a SHA-256 calculator, type 1 BTC, then 2 BTC, and compare the output with our strings above. What cryptocurrency itself is and who issues it is covered in what is cryptocurrency, in plain terms.