Explainer · Crypto Basics
What is a blockchain, and what does it actually record?
A blockchain is a shared record book that many computers keep in sync, where each page is sealed to the one before it. Here is what that record holds, how the sealing works, and what it does not protect you from.

Quick answer
A blockchain is a digital ledger copied across many computers, usually with no central authority, where each block of records carries the hash of the block before it. NIST calls blockchains tamper evident and tamper resistant [2], which is not the same as unhackable or risk-free to invest in.
Key points
- NIST defines blockchains as tamper evident and tamper resistant digital ledgers, distributed and usually without a central authority [2].
- Each block includes the hash of the previous block, so editing an old block changes every block after it [2].
- Bitcoin uses proof-of-work to decide who adds the next block; Ethereum switched to proof-of-stake in 2022 [5].
- The ledger can be hard to change while the exchanges and wallets around it still get hacked [8].
- "Built on blockchain" says nothing about whether an investment is regulated, sound or safe.
On this page
What is a blockchain?#
Start with a ledger: a list of who sent what to whom. Traditional online payments go through a financial institution that keeps that record; Bitcoin was designed to remove that middle step [1]. A blockchain spreads copies of the ledger across many computers in a network, and they follow shared rules to agree on what gets added next.
The US National Institute of Standards and Technology (NIST) puts it formally: blockchains are tamper evident and tamper resistant digital ledgers implemented in a distributed fashion, usually without a central authority [2]. The UK FCA describes the wider family, distributed ledger technology, as a system for storing and managing information distributed across participants in a network [3]. EU law uses the same term when it defines a crypto-asset as a value or right that can be transferred and stored using distributed ledger technology [4].
What does a blockchain actually record?#
It depends on the chain. Bitcoin's ledger records payments: which coins moved, and the fee left for the block producer [1]. Ethereum also records programs called smart contracts, which let anyone create digital assets and applications that run on the network [5]. Our explainers on what is bitcoin and what is ethereum go deeper into each.
What the chain ties transfers to is keys and addresses. A wallet stores private keys, public keys and addresses [2], and the private key is what authorises a transfer [6]. The record proves that a key authorised a transfer. It does not prove who was holding that key, or whether they were tricked into using it.
| Bitcoin | Ethereum | |
|---|---|---|
| Main thing recorded | Payments of bitcoin | Transactions and smart contracts |
| Who adds blocks | Miners | Validators |
| How block producers are chosen | Proof-of-work: spending computing effort | Proof-of-stake since 2022: locking up ETH as a deposit |
| Fee paid in | Bitcoin (input value minus output value) | ETH, as a gas fee |
Sources: Bitcoin whitepaper [1], ethereum.org [5].
How do the blocks link together?#
The glue is a hash: a fixed-length fingerprint produced by running data through a hash function. Bitcoin's proof-of-work uses a hash function such as SHA-256 [1]. Feed in the same data and you always get the same hash. Change one character and you get a completely different one.
Each block stores the hash of the block before it. The Bitcoin whitepaper describes each timestamp including the previous one in its hash, forming a chain [1]. NIST spells out the consequence: if a previously published block were changed, it would have a different hash, and that would change all the blocks after it [2].
Now chain three toy blocks. Each one hashes its block number, the previous block's hash and its record. Then edit block 1 so the payment reads 50 coins instead of 5, and recompute. The table shows the first eight characters of each hash.
| Block | Record | Hash before edit | Hash after edit |
|---|---|---|---|
| 1 | A pays B 5 coins (edited to 50) | 33f4e878 | 77f47b4e |
| 2 | B pays C 2 coins | 149b8317 | d72930e4 |
| 3 | C pays D 1 coin | 9229c06f | 784fe6b5 |
Blocks 2 and 3 were not touched, yet their hashes changed because each contains the hash of the block before it. Toy chain built with SHA-256 in Python; real blocks hold far more data.
Who decides which blocks get added?#
Someone has to propose the next block, and everyone else has to agree. NIST separates two models. In a permissionless blockchain anyone can publish blocks without needing permission from any authority. In a permissioned blockchain the people publishing blocks must be authorised by some authority [2].
Public chains also need a rule for choosing between competing versions of the record. Bitcoin uses proof-of-work: block producers must spend computing effort, and the network treats the longest chain, the one with the most work behind it, as the valid record [1]. Bitcoin adjusts the puzzle difficulty every 2016 blocks to keep blocks arriving around once every ten minutes [2].
Ethereum moved from proof-of-work to proof-of-stake on September 15, 2022 [7]. Validators lock up ETH as a security deposit to earn the right to process transactions; honest ones earn rewards and dishonest ones lose part of their stake [5].
- SHA-256 hash length
- 64 charactershexadecimal output, calculated
- Characters changed in the message
- 1"5" became "50", worked example
- Hash characters that changed
- 61 of 64calculated
- Toy blocks with a new hash after editing block 1
- 3 of 3calculated
Can a blockchain be hacked or changed?#
Changing history on a large public chain is designed to be very costly, not impossible. The Bitcoin whitepaper's security rests on an assumption: as long as a majority of computing power is controlled by nodes that are not cooperating to attack the network, they will produce the longest chain and outpace attackers [1]. Each extra block added after a transaction makes an attacker's chance of catching up drop exponentially [1].
The bigger risk for most people sits around the chain, not in it. The EU's financial supervisors note that crypto exchanges and wallet providers have experienced cyber-attacks and severe operational problems [8]. The FCA lists firm failure, poor segregation of client funds and cyberattacks among the reasons you could lose all your money [3]. A perfect ledger cannot help if your login, your private key or your exchange is compromised.
Does "built on blockchain" make an investment safe?#
No. The technology describes how records are kept, not whether the thing being recorded is worth anything. The SEC calls bitcoin and ether highly speculative investments [10], and EU supervisors warned in March 2022 that most crypto-assets and related services were unregulated in the EU [8]. When a project leads with the word blockchain, work through these questions before anything else.
- Ask who can add blocks
Is the chain permissionless, or does an authority approve who publishes blocks [2]? A permissioned chain means trusting that authority.
- Ask what is actually on the chain
The ledger proves only what is written to it. Ask whether the business, any reserves or any promised returns are recorded there, or only described on a website.
- Ask who holds the keys
If a platform holds them, its security and solvency are your risk; the SEC warns you may lose access if a custodian is hacked or goes bankrupt [6].
- Check the firm with a regulator
Look the firm up with your national regulator before depositing. Our guide on is a crypto exchange safe explains how.
- Size it as money you could lose
The EU supervisors' first question is whether you can afford to lose all the money you invest [8].
Mistakes beginners make about blockchains#
- Believing "immutable" means "safe"
NIST says tamper evident and tamper resistant [2]. The record being hard to change does nothing to protect your account at an exchange.
- Thinking blockchain transfers can be undone
There is usually no bank to call. Crypto payments typically are not reversible [9], so a wrong address or a scam is usually final.
- Assuming the chain knows who you are
Transfers are authorised with a private key [6], so whoever holds the key controls the funds, whoever they are.
Frequently asked questions#
Is a blockchain the same as Bitcoin?
No. Bitcoin is one asset and network that uses a blockchain to record payments [1]. Many other networks use blockchains, and some blockchains have no public coin at all.
What is the difference between a blockchain and distributed ledger technology?
Can anyone add a block?
On a permissionless blockchain, anyone who follows the rules can publish blocks. On a permissioned one, publishers must be authorised [2].
The bottom line#
A blockchain is a shared ledger whose blocks are sealed together with hashes, so editing the past shows up immediately and costs a lot to force through. That makes the record tamper evident and tamper resistant, not tamper proof, and it protects the ledger rather than you. Exchanges get hacked, keys get lost and scams get recorded perfectly. For a short blockchain definition, see our glossary, and read the risk disclosure before putting money into anything built on one.
Sources
- Bitcoin: A Peer-to-Peer Electronic Cash System.
- NISTIR 8202 - Blockchain Technology Overview.
- Crypto: The basics | FCA (InvestSmart).
- Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets (MiCA).
- What is Ethereum? | ethereum.org.
- Crypto Asset Custody Basics for Retail Investors - Investor Bulletin.
- The Merge | ethereum.org.
- ESA 2022 15 - Joint ESAs Warning on Crypto-assets (EBA, ESMA, EIOPA).
- What To Know About Cryptocurrency and Scams.
- Exchange-Traded Products (ETPs) Providing Exposure to Bitcoin and Ether - Investor Bulletin.
Education only. This page is not investment, tax or legal advice. Trading and crypto can lose you money. See our risk disclosure.


