Course mapModule 3 · Mining Pools
Crypto Mining School
19 of 36 lessons live · progress saved in this browser
M1Power On5 live What Does a Bitcoin Miner Actually Do? What Is a Hash? How Do Miners Make Money? Can You Still Mine Bitcoin at Home? CPU vs GPU vs ASIC: Why Your PC Can’t Compete
M2The Iron5 live What Is an ASIC Miner? Hashrate, Watts, and J/TH: The Only Three Numbers That Matter What Is a Bitaxe? How Loud Is an ASIC Miner, Really? How Long Does a Miner Stay Profitable?
M3The Network5 live What Is Mining Difficulty? What Is Network Hashrate (and Why Every Chart Disagrees)? Why Blocks Take 2 Minutes or 40: Luck and Variance What Is a Mining Pool? What Is the Halving (and What It Does to Miners)?
M4The Money1 live What Is Hashprice? The Mining Profitability Formula (There Is Only One)soon What Power Price Kills Your Rig?soon How Long Does It Take to Mine 1 Bitcoin?soon Transaction Fees: The Half of Revenue Nobody Modelssoon
M5The Scrypt Lane3 live What Is Scrypt Mining?soon What Is Merged Mining? (AuxPoW, Plain English) How Long Does It Take to Mine 1 Litecoin? Antminer L7 vs L9 vs L11: Which Scrypt Miner Makes Sense Can You Mine Dogecoin Directly?soon
M6Home Opssoon Amps, Breakers, and 240V: Can Your Wiring Run a Miner?soon Making a Miner Livable: Noise and Heat Controlsoon Heating Your Space With a Minersoon Buying a Used ASIC Without Getting Burnedsoon Solo Mining: The Honest Lottery Mathsoon
M7Operator Gradesoon What Is Miner Capitulation?soon Hash Ribbons: Reading Hashrate Crossessoon The Puell Multiple: Miner Revenue vs Its Own Historysoon Fee Percentiles: Forecasting Revenue Like an Operatorsoon Mining Stress and Difficulty Pressure: What Our Composites Watchsoon Timing the Iron: Buying Rigs Off the Cycle Datasoon

What Is a Mining Pool?

The real lesson is the payout scheme: PPS, FPPS and PPLNS are three answers to one question — between finds, who holds the dice?
loading live data…
A mining pool is module 1's search party, formalized: many machines pull drawers together, every find is split in proportion to drawers pulled, and the long-run average is exactly what each machine would earn solo — only the arrival shape changes. That part is settled. This lesson starts where it stopped: how the split is computed is a real choice, and every payout acronym on a pool's homepage — PPS, FPPS, PPLNS — is one question answered differently: between finds, who holds the dice — you or the pool?

What is a share? The pool's easier bar

A fair split needs receipts. The network's bar is brutally high — at today's difficulty a single pull clears it about once in 5.7 × 1023 tries (difficulty × 232; the live figure feeds the tile below) — so a pool that only counted actual finds would learn nothing about who did the work between them. The fix: the pool sets a second, far lower, private bar and accepts every pull that clears that one as a share: a receipt that you were pulling.

The definition is older than almost everything else in pooled mining — Meni Rosenfeld's 2011 analysis, still the reference text: one share = a hash that would have made a block if the difficulty were 1. Any single pull becomes a share with probability 1 in 232; every share then has probability 1 in D of also clearing the real bar, where D is the network difficulty. That known exchange rate between receipts and expected blocks is the whole trick — it is what makes any split checkable from the outside. A share is not a partial block: it contributes nothing toward finding anything. It only proves you were pulling.

Raw difficulty-1 shares would bury the pool in receipts: an S21-class machine at its 234 TH/s spec-sheet rating (manufacturer spec, not a consensus number) clears that bar roughly 54,000 times every second (2.34 × 1014 ÷ 232). So pools run variable share difficulty — vardiff — sliding each machine's private bar until its receipts land every few seconds; each pool tunes the exact cadence. A desk-sized Bitaxe gets a low bar, a rack S21 a high one, and both report on the same clock. The pool reads your hashrate as cadence × bar height, and the same bar-height bookkeeping makes a big machine's shares count proportionally more. The two cadences, side by side:

Block-level proof · S21-class, manufacturer-spec 234 TH/s
once in ~77 years
at difficulty 132,757,073,449,487 · fallback 2026-10-02
Share-level proof · the same machine
every few seconds
pool-tuned cadence — a dial, not a feed; each pool slides it

The find side repaints live from our own node's difficulty (expected hashes per block = difficulty × 232); the share side is the pool's own tuning, quoted as prose on purpose. Without the easier bar, a machine could mine honestly for decades with nothing to show between finds.

Your machine submits 40,000 shares this month and the pool finds no block with any of them. What did those shares prove?

Every payout acronym answers one question

Between finds — minutes to hours apart for a big pool, days for a small one — somebody is holding the risk that the next one comes late. Every honest payout scheme is a position on that one axis and nothing else. PPS and FPPS put the dice in the operator's hands: your shares are bought at a fixed price the moment they land, found block or not. PPLNS leaves the dice in yours: nothing is owed until the party actually finds. Which position you should want is a decision, and the decision rule — plus the how-dry-is-dry arithmetic behind it — lives on /btc/pools. This lesson is the machinery underneath, so that rule reads as arithmetic instead of vibes.

PPS FPPS PPLNS the pool holds the dice you hold the dice steady pay · higher fee lumpy pay · lower fee
Every scheme is a position on one axis. PPS and FPPS buy your receipts at a fixed price and hold the dice themselves, charging for the service; PPLNS owes nothing until a find, so you hold the dice and keep the premium. The long-run average is the same at every point on the line.

PPS: the pool buys your receipts on the spot

Pay-per-share (PPS) is a standing buy order for receipts. Every share is paid its exact expected value the instant it lands:

PPS price per share = (1 − fee) × subsidy ÷ D
2026-10-02, fee set to zero: 3.125 BTC ÷ 132,757,073,449,487 ≈ 2.4 millionths of one satoshi

The unit price looks absurd because it is quoted per difficulty-1 share — your vardiff shares are worth bar-height times more, and they arrive every few seconds. Blocks found or not, the drip is constant: you could mine a year on a PPS pool, watch it find nothing, and still be paid in full for every receipt. (3.125 BTC is the subsidy until the next halving, around April 2028 — next lesson.)

Someone still holds the dice, and under PPS it is the operator — who has effectively become a solo miner backed by the whole pool's hashrate, paying fixed salaries through every dry spell. Rosenfeld's paper calls PPS the riskiest scheme for the operator, derives the cash reserve an operator must hold to survive the swings, and shows an under-reserved PPS pool has a good chance of eventually going bankrupt. The insurance is real, so it is priced: PPS-family fees run consistently higher than variance-carrying ones. And one detail the search results reliably get wrong: classic PPS prices the subsidy only. Transaction fees are not in the formula above — folding them in is a different scheme with its own name.

FPPS: the same fixed price, with fees folded in

Full-pay-per-share (FPPS) keeps the insurance and fixes the missing-fees hole: each share is priced at subsidy plus a pro-rata estimate of transaction fees, taken from a trailing window of real blocks. Luxor, which documents its method, recomputes the rate per block height with a 144-block lookback — about a day of chain:

FPPS rate per share = (subsidy + mean fees of the trailing 144 blocks) ÷ D
2026-10: (3.125 BTC + the window's mean fee take) ÷ 132,757,073,449,487 — the subsidy leg alone is the ~2.4 millionths of a satoshi above; the fee term rides on top, re-priced block by block

The trailing mean is the honesty mechanism: you are paid an estimate of fees smoothed over the window, not the fees of whatever blocks your pool happened to find. As of 2026, FPPS is the dominant scheme among the large pools — dated deliberately, because dominance is a market fact, not a law. The lineage, roughly: proportional rounds (2010) → PPLNS (~2011) → PPS as a priced product (~2012) → FPPS (~2014–2015). One sibling in one line: PPS+ pays the subsidy PPS-style but shares fees only from blocks actually found — the halfway house.

PPLNS: you keep the dice, and the premium

Pay-per-last-N-shares (PPLNS) owes you nothing until the party finds. When a block lands, its reward is split over the last N shares submitted — in the simplest variant, each of those N shares is paid (1 − fee) × reward ÷ N. The expected value per share works out identical to the PPS price; what changes is the shape. Payouts arrive when blocks do: a lucky week pays over the odds, a dry stretch pays zero. How dry is dry for a pool of a given size is Poisson arithmetic — worked for a 1% and a 0.1% pool on /btc/pools, and not re-derived here.

Two receipts from Rosenfeld's analysis: splitting over a window of N shares cuts a miner's reward variance by roughly a factor of N compared with going solo — and even with N set to a full difficulty's worth of shares, 36.79% of shares still receive zero payment. The dice stay real. The pool, meanwhile, carries nothing: it pays out exactly what it finds, minus the fee. No insurance sold, no reserve to defend, no bankruptcy math — which is precisely why PPLNS fee schedules sit lower.

Same pool, dry fortnight — two weeks without a single find. Who feels it under FPPS, and who under PPLNS?

Why PPLNS exists: the pool-hopping story

The first pools paid proportionally per round: when a block was found, it was split across all shares since the previous find. It feels fair, and it was exploitable — because rounds are memoryless. The next find is never “due,” no matter how long a round has run, so a share submitted early in a round was worth more than one submitted late: fewer shares to split with so far, same chance the round ends right now. Rosenfeld quantified the exploit — in theory, worst case: hopping into rounds younger than ~43.5% of difficulty in submitted shares was profitable, and an always-on loyal miner could earn up to ~43% less than its fair share.

Slush's pool — announced 27 November 2010, the first publicly available pool — shipped the first scoring method deliberately built to resist hopping. Its first blocks came in mid-December 2010: web sources disagree on the exact height (97,384 vs 97,834), and our own node timestamps those blocks 2010-12-13 18:39 UTC and 2010-12-16 07:16 UTC, so mid-December holds either way — the height attribution itself is community record, not chain data. Pool hopping was finally killed by deleting the thing it fed on: PPLNS has no rounds at all. Shares earn across a sliding window of the last N, so there is no “early” left to exploit — and that same window is why joining a PPLNS pool ramps up from zero while your shares age in, and why leaving forfeits the aging shares you walk away from.

What does 97% pool luck mean?

Pools publish a luck figure, and it is the most misread number on any pool stats page. The usual convention: luck = expected shares per find ÷ the shares it actually took, × 100. Run the arithmetic once and the number stops being mysterious. Say the window's blocks should have taken 100 million shares at the pool's bar and actually took 103.1 million: 100 ÷ 103.1 = 97%. The pool spent about 3% more pulls than expected — mildly unlucky. Above 100% means the finds came early; 200% means blocks landed at half the expected shares. It never means “the pool found 97% of its blocks.”

One trap before you read any pool's page: a few stats sites print the inverse — actual ÷ expected, where above 100% is unlucky. Same data, flipped fraction. Check which way is up before comparing anything across sites.

And the hard part: luck is a scorecard, never a forecast. The dice have no memory — every hash is as likely as every other — so last month's 97% says nothing about next month, and lifetime luck drifts toward 100% for every honest pool. The distribution math behind why windows wobble at all is the previous lesson's; here is what the wobble looks like when the search party is the entire network:

BTC · target 600 s
98.2%
measured 610.84 s · fallback 2026-10-02
LTC · target 150 s
110.2%
measured 136.10 s · fallback 2026-10-02
DOGE · target 60 s
93.5%
measured 64.16 s · fallback 2026-10-02

mean of the last 200 gaps · own nodes · fallback snapshot 2026-10-02

Luck here = target interval ÷ measured interval × 100; BTC fallback: 600 ÷ 610.84 = 98.2%. Run the division on the live chips — if it doesn't reproduce the number, this page is wrong. Each measured interval is the mean of that chain's last 200 block gaps — wall-clock, roughly 33 hours of BTC blocks, 8 of LTC, 3.5 of DOGE — the same trailing means the previous lesson taught you to read, re-read as luck percentages: even the whole network — one search party holding 100% of the hashrate — never runs at exactly 100% luck. Your pool's monthly luck wobbles for the same reason, and predicts just as little.

A pool advertises 103% lifetime luck. What does that buy you, going forward?

Scheme vs fee: the price of smoothing

Now the fee schedule reads differently. Steady pay costs more because someone is selling you insurance — an FPPS operator holding reserves through dry spells is running a risk business, and the fee is its premium. Variance-carrying pays less because nobody is insuring anyone. In 2026, published schedules mostly sit around 0–4% for FPPS and 0–2% for PPLNS — ranges, hedged on purpose: schedules churn, so the only current number is the one on the pool's own page, and we print no pool-by-pool fee table. Long-run expected earnings are identical under every honest scheme. You are choosing the shape of arrival and the price of smoothing — nothing else.

One note for the scrypt seat: on Litecoin pools, the merged-mined side coins — your DOGE leg — settle PPLNS almost everywhere, even where the LTC leg is FPPS. So a slice of scrypt revenue rides pool luck whichever scheme you pick; the receipts are in the /ltc/pools payout table, and the one-hash-two-chains mechanics are the merged-mining lesson's.

PPLNS pools routinely publish lower fees than FPPS pools. What is the discount for?

FAQ

How do mining pools pay out — what do PPS, FPPS and PPLNS actually mean?
They are three answers to one question: who holds the luck between finds. PPS buys every share you submit at its fixed expected value (subsidy only), found block or not — the pool holds the luck. FPPS does the same but prices shares at subsidy plus a trailing estimate of transaction fees — still the pool's luck, and the dominant scheme among large pools today (2026). PPLNS pays only when the pool actually finds a block, split over the last N shares — you hold the luck, and the fee is lower because nobody is selling you insurance.
What is a share in mining?
A receipt that you were pulling drawers. The network's bar is brutally high; your pool sets a far lower private bar and accepts every pull that clears it as proof of work done, sliding each machine's bar (share difficulty) so receipts land every few seconds. Each share has a known small chance of also clearing the real bar, which is what makes the split checkable — shares are evidence of effort, not partial blocks.
What does 97% pool luck mean?
The pool spent about 3% more shares than expected to find its blocks over that window — mildly unlucky, by the usual convention of expected shares divided by actual shares. It is a record of the past, not a forecast: the dice have no memory, and luck trends back toward 100% over long windows. A few sites print the inverse convention, so check which way is up before comparing.
Why do PPLNS pools charge lower fees than FPPS pools?
Because you are carrying the variance instead of the pool. An FPPS pool pays a steady expected value through dry spells and prices that insurance into its fee; a PPLNS pool owes nothing until a block lands, so it has no risk to charge for. Long-run expected earnings are the same under every honest scheme — you are paying, or not paying, for the smoothing.
What is pool hopping?
The exploit that killed per-round payouts. Early pools split each block over all shares in the round, but rounds are memoryless, so early shares were worth more — hoppers mined only young rounds and loyal miners ate the loss (in theory, worst case, up to ~43%). Scoring systems and then PPLNS deleted the “early” there was to exploit by paying over a sliding window of recent shares — which is also why PPLNS ramps up from zero when you join and forfeits aging shares when you leave.
Do it now. Open /btc/pools and read who found the last week of blocks — about a thousand of them, attributed live from coinbase tags and cross-checked against our own node. Three things to spot with this lesson’s eyes: the “Unknown” slice (tags are claimed, not signed); the top pool’s share wobbling a few points day to day (that’s luck wearing a leaderboard costume, not pools speeding up); and, for any pool, what 97% monthly luck would mean — its PPLNS miners’ payouts dipped ~3%, its FPPS miners’ didn’t move. Scrypt seat: /ltc/pools shows the same table, where your DOGE leg settles PPLNS almost everywhere.
Completes automatically when you continue below — saved in this browser only, no account, no tracking.
Next lesson → Module 3 · The Network
What Is the Halving (and What It Does to Miners)?
The scheduled event that halves the block subsidy overnight.
Source: difficulty and block intervals (each the trailing mean of the last 200 header gaps) from BasinTwo’s own bitcoind, litecoind and dogecoind via the free /api/chain feeds. Payout-scheme definitions, the PPS reserve result and the hopping/variance math are Meni Rosenfeld’s “Analysis of Bitcoin Pooled Mining Reward Systems” (arXiv:1112.4980); the FPPS rate construction is Luxor’s published 144-block method. Scheme dominance and fee ranges reflect pool docs and industry guides as of 2026 and churn — verify on any pool’s own page. Slush-pool first-block timestamps are cross-checked against our own node; the height attribution is community record. Not financial advice.