# Equihash difficulty

**URL:** <https://forum.zcashcommunity.com/t/equihash-difficulty/838>\
**Category:** Mining\
**Created:** [June 14, 2016, 11:53pm UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838 "2016-06-14T23:53:52Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Voluntary](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/voluntary/32/4343_2.png) [@Voluntary](https://forum.zcashcommunity.com/u/Voluntary)\
**Post date:** [June 14, 2016, 11:53pm UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838/1 "2016-06-14T23:53:52Z")

</div>

Does difficulty have anything to do with the size of the dataset Equihash has to process? If not, what factor(s) does difficulty relate to?

---

<div class="post-metadata">

**Author:** ![Austin-Williams](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@Austin-Williams](https://forum.zcashcommunity.com/u/Austin-Williams)\
**Post date:** [June 14, 2016, 11:59pm UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838/2 "2016-06-14T23:59:08Z")

</div>

There are two things going on with Equihash w.r.t. how hard it is to solve.

The first thing is the chosen parameters (the N and K), and those dictate how much memory space/bandwidth will be needed to find a solution. My understanding is that these are fixed (or at least changed extremely rarely).

The second thing (and more to your question) is that a solution must have at least _d_ leading zeros. This (_d_) is the parameter that can be adjusted by the network so we continually target a 10 min block time.

EDIT: So to compare to bitcoin: it works exactly the same way. We essentially just hash until we find a digest that has enough leading zeros. It’s just that our hashing algo is different in that it requires high memory bandwidth.

---

<div class="post-metadata">

**Author:** ![str4d](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/str4d/32/64_2.png) [@str4d](https://forum.zcashcommunity.com/u/str4d)\
**Post date:** [June 15, 2016, 12:02am UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838/3 "2016-06-15T00:02:58Z")

</div>

The second thing above is equivalent to what Bitcoin does, and is what is canonically thought of as the “difficulty”.

In terms of the actual hardness of the PoW, yes that is largely dictated by the size of the dataset (linked to the first thing above) - the limiting factor is sorting a list of `2^((n/(k+1))+1)` tuples. For e.g. `n = 96, k = 3`, that is `2^25` rows.

---

<div class="post-metadata">

**Author:** ![Voluntary](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/voluntary/32/4343_2.png) [@Voluntary](https://forum.zcashcommunity.com/u/Voluntary)\
**Post date:** [June 15, 2016, 12:43am UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838/4 "2016-06-15T00:43:28Z")

</div>

Thank you both. I didn’t even realise the same leading zero approach to difficulty applied to Equihash… So, when the dataset is sorted, is it then somehow reduced to a 32 or 64 bit integer which is then assessed for leading zeros? And, if / when that integer doesn’t have sufficient leading zeros, what parts of the dataset can be altered in order to try again? For eg: if a bitcoin block hash comes up short of the target difficulty, there’s a nonce field and even a data/time field that can be incremented to produce a slightly different dataset for the next hash.

---

<div class="post-metadata">

**Author:** ![str4d](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/str4d/32/64_2.png) [@str4d](https://forum.zcashcommunity.com/u/str4d)\
**Post date:** [June 15, 2016, 1:26am UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838/5 "2016-06-15T01:26:16Z")

</div>

The block header can be thought of as `Data | Nonce | Solution`. The Equihash algorithm takes as input `Data | Nonce` and outputs `[Solution_1, Solution_2, ...]` (two on average). The difficulty check takes as input the block header hash `SHA256(SHA256(Data | Nonce | Solution))` and checks for sufficient leading zeroes. The overall PoW is therefore to try different nonces, and for each nonce check each returned solution as a possibility for satisfying the difficulty check.

Because the Equihash algorithm depends on `Data` which contains a timestamp, altering the timestamp will alter the solution space in the same way altering the nonce will. Similarly for altering the coinbase, included transactions etc.

---

<div class="post-metadata">

**Author:** ![Voluntary](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/voluntary/32/4343_2.png) [@Voluntary](https://forum.zcashcommunity.com/u/Voluntary)\
**Post date:** [June 15, 2016, 1:37am UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838/6 "2016-06-15T01:37:52Z")

</div>

That was very helpful - thank you again.

---

<div class="post-metadata">

**Author:** ![Austin-Williams](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@Austin-Williams](https://forum.zcashcommunity.com/u/Austin-Williams)\
**Post date:** [June 15, 2016, 6:20am UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838/7 "2016-06-15T06:20:56Z")

</div>

Page 6 of the [Equihash paper (pdf)](https://www.internetsociety.org/sites/default/files/blogs-media/equihash-asymmetric-proof-of-work-based-generalized-birthday-problem.pdf) might shed more light if you’re interested. It might also be more detailed for what you’re looking for. Either way it’s useful reference. 🙂

---

<div class="post-metadata">

**Author:** ![zawy](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/zawy/32/11892_2.png) [@zawy](https://forum.zcashcommunity.com/u/zawy)\
**Post date:** [July 23, 2016, 7:57pm UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838/8 "2016-07-23T19:57:50Z")

</div>

How do you estimate time to finding a block? For bitcoin it is

> time to finding block = difficulty \* 2\*\*32 / hashrate
> 
> where difficulty is the current difficulty, hashrate is the number of  
> hashes your miner calculates per second, and time is the average in  
> seconds between the blocks you find.

We have a hashrate of 2/60 = 1/30 hashes/second per thread?  
Do I just divide by 4?

---

<div class="post-metadata">

**Author:** ![str4d](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/str4d/32/64_2.png) [@str4d](https://forum.zcashcommunity.com/u/str4d)\
**Post date:** [July 23, 2016, 11:44pm UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838/9 "2016-07-23T23:44:36Z")

</div>

The time to find is the same calculation as for bitcoin. We just have a slower hash rate 😄

---

<div class="post-metadata">

**Author:** ![maxwell](https://avatars.discourse-cdn.com/v4/letter/m/d07c76/32.png) [@maxwell](https://forum.zcashcommunity.com/u/maxwell)\
**Post date:** [October 26, 2016, 7:52pm UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838/10 "2016-10-26T19:52:57Z")

</div>

Sorry to resurrect an old thread… I’m getting some strange output when I perform this calculation:

Using the difficulty and network hash rate at the time of this writing for Bitcoin:  
D = 253,618,246,641  
H = 1,798,095,669 GH/s  
T = D \* 2^32 / H / 60 = ~10 minutes

This is in agreement with expectations. For Zcash, however, a difficulty of 12,000 implies that the network hash rate is 34 G/s , which is obviously incorrect:  
H = D \* 2^32 / 2.5 / 60 = 34 GH/s

If I divide this answer by 10^6, then I get reasonable numbers. Is this 10^6 factor baked in to the formula?

---

<div class="post-metadata">

**Author:** ![romanick](https://avatars.discourse-cdn.com/v4/letter/r/b5e925/32.png) [@romanick](https://forum.zcashcommunity.com/u/romanick)\
**Post date:** [December 15, 2016, 4:41pm UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838/11 "2016-12-15T16:41:09Z")

</div>

I was also interested.  
How to convert network difficulty to hasrate? Sol/s and H/s?

---

<div class="post-metadata">

**Author:** ![bitkevin](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/bitkevin/32/4950_2.png) [@bitkevin](https://forum.zcashcommunity.com/u/bitkevin)\
**Post date:** [June 14, 2017, 7:03am UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838/12 "2017-06-14T07:03:56Z")

</div>

> [@zawy](#):
>
> time to finding block = difficulty \* 2\*\*32 / hashrate  
> where difficulty is the current difficulty, hashrate is the number of  
> hashes your miner calculates per second, and time is the average in  
> seconds between the blocks you find.

ZEC find block = Difficulty \* 8192 / hashrate  
ZEC(testnet) find block = Difficulty \* 32 / hashrate

---

<div class="post-metadata">

**Author:** ![zawy](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/zawy/32/11892_2.png) [@zawy](https://forum.zcashcommunity.com/u/zawy)\
**Post date:** [September 4, 2017, 7:28pm UTC](https://forum.zcashcommunity.com/t/equihash-difficulty/838/13 "2017-09-04T19:28:49Z")

</div>

More precise:

Bitcoin hashrate = 2^32 \* sum(past 144 Difficulties) / (previous TimeStamp - TimeStamp 144 blocks ago)  
Zcash Sol/s = 2^13 \* sum(past 120 difficulties) / (previous TimeStamp - TimeStamp 120 blocks ago)

Which is easier to understand as averages:

Zcash Sol/s = 2^13 \* avg(120 D’s) / avg( 120 TS’s)

edit: more precisely Zcash equihash H/s = 2^12 \* avg(120 D’s) / avg( 120 TS’s).  
The “12” comes from the number of leading bits required in a valid hash of the header when D=1.  
In HUSH, it did not have any leading 0’s, so it’s difficulty = number of equihash runs to find a valid hash.
