The analysis ahead needs four tools: memoryless clocks (to model block discovery), a reduction from continuous time to a coin sequence, the negative binomial distribution (to count the attacker’s progress), and one normalisation lemma about races. Their foundations are the Math Guide’s: probability spaces, conditioning, independence, random variables, and expectation are constructed there from the definition of probability onward (§“Probability, asymptotics, and computation”), and the extension beyond finite spaces — countable additivity, continuity along monotone events, density-defined laws, and infinite sequences of independent trials — is its §“Beyond finite spaces: countable additivity, limits, and densities”. What no lower volume owns are the four instruments themselves; each is constructed here on that base, only as far as the critical path requires.
A random variable is exponential with rate if for all — a law defined by the density on in the sense of the Math Guide’s density definition, with mean .
An exponential satisfies for all : having waited without success teaches nothing about the remaining wait.
. □
Let and be independent exponentials with rates and . Then
and the winning time is exponential with rate .
Integrating over the time at which fires,
For the minimum, . Moreover, the joint density that wins at time factors as
and similarly for . Thus the winner is independent of the winning time. □
Model the honest network and attacker as independent exponential clocks with rates and , restarting when either fires (Section 4). Successive block attributions form an infinite sequence of independent, identically distributed Bernoulli trials in the Math Guide’s sense: attacker with probability , honest network with probability , independent of all earlier attributions and all elapsed times.
By Lemma 3.3 the first block is the attacker’s with probability . When a block is found, the finder’s clock restarts by construction, and the loser’s remaining wait is distributed as a fresh clock by Lemma 3.2; the state after each block is therefore probabilistically identical to the start, independent of the past. The density factorisation in Lemma 3.3 also makes each winner independent of that race’s elapsed time. The claim follows by induction. □
Proposition 3.4 is the paper’s bridge (its §3, with footnote 1 supplying the clock rates) from physical time to combinatorics: since the question “does the attacker ever get ahead?” concerns only the order of block discoveries, not their times, every result below is a statement about a / coin sequence, and the time constant disappears from the answers. Where the exponential model itself comes from — and how well Zcash’s Equihash fits it — is a deployment question, taken up in Section 8.3.
In an attribution sequence with attacker probability , let be the number of attacker blocks found strictly before the honest network’s -th block. Then
— the negative binomial distribution.
The event fixes the first trials exactly this far: the -th trial is honest (the -th honest success), and among the first trials exactly are the attacker’s, in any of orders. Each such order has probability . □
In the same sequence, let be the event that the honest network reaches blocks before the attacker does, and the reverse. Then and partition the sample space, and
Among the first trials one side already has successes, so the race terminates; a tie is impossible because block counts advance one at a time. The event says the -th honest block arrives while the attacker holds ; summing Proposition 3.5 over those gives the first sum, and is the same computation with the roles of and swapped. □
The exponential model is itself a limit, not an axiom. A miner’s work is modelled as a stream of candidate evaluations, each an independent Bernoulli trial with a tiny success probability; the number of trials to the first success is geometric, and a geometric law with small success probability, viewed at the scale of its mean, converges to the exponential of Definition 3.1. The step that matters is progress-freeness: a candidate that fails must carry no information usable by the next one. Whether Zcash’s Equihash satisfies this is examined with the deployed parameters in Section 8.3.