Hash functions: the quiet machinery under everything in crypto

·4 min read·By SSP Editorial Team
SSP Academy cover: how hash functions work in crypto

Hash functions: the quiet machinery under everything in crypto

If you strip a blockchain down to its essential parts, you find two kinds of cryptography doing almost all the work. Digital signatures decide who can spend. Hash functions hold everything else together — blocks, addresses, mining, transaction IDs, even the way a wallet decodes what you're about to sign.

Hash functions are rarely explained, because they're rarely noticed. They're worth ten minutes, because once you understand them a surprising amount of crypto stops looking like magic.

What a hash function does

A hash function takes any input — a word, a file, a whole block of transactions — and produces a fixed-size fingerprint. SHA-256, the one Bitcoin uses, always produces 256 bits, usually written as 64 hexadecimal characters, whether you feed it one letter or a gigabyte.

Three properties make it useful:

Deterministic. The same input always gives the same output. Anyone, anywhere, can recompute it and check.

One-way. Given a fingerprint, there's no practical way to work backwards to the input. The only approach is guessing inputs until one matches, and for a good hash that's hopeless.

Collision-resistant. It's infeasible to find two different inputs with the same fingerprint. Change a single character and the output changes completely and unpredictably.

That's all a hash is: a short, checkable, unforgeable fingerprint of something larger.

Where you meet hashes without noticing

Transaction IDs. A txid is simply the hash of a transaction. That's why it's unique, and why it's the thing you paste into a block explorer — it identifies exactly one transaction, and nobody can produce a different one with the same ID.

The chain itself. Every block contains the hash of the block before it. Change anything in an old block and its hash changes, which breaks the link to every block after it. That chain of fingerprints is what makes history tamper-evident.

Mining. Proof of work is a hashing lottery: miners hash block headers over and over, varying a number each time, until they find a result below a target. Because hashes are unpredictable, there's no shortcut — only more attempts, which is why proof of work costs real energy and why that cost buys security.

Addresses. Most addresses are hashes of something. A classic Bitcoin address is a hash of a public key. SSP's Bitcoin addresses are P2WSH: a SHA-256 hash of the witness script that describes the 2-of-2 spending rule. What goes on-chain before you spend is that fingerprint, not the keys themselves.

Hashes inside the wallet

Hashing isn't only a chain-level concept. It shows up in the software you use to sign.

When SSP Key decodes an Ethereum transaction before you approve it, it identifies what the call does using function selectors — the first four bytes of the Keccak-256 hash of the function's signature. transfer(address,uint256) hashes to a value beginning a9059cbb; approve(address,uint256) to one beginning 095ea7b3. When the decoder sees those four bytes at the start of a transaction, it knows which function is being called and can show you, in plain language, that you're sending tokens or granting an approval.

It's a lovely illustration of what hashes are good for: a compact, unambiguous fingerprint of something longer. It's also a reminder of their limits, because four bytes is short enough that two different functions can share a selector. That's one reason the decoder is deliberately fail-closed — anything unexpected falls back to raw data rather than a confident guess.

What hashes can't do

They don't hide small inputs. A hash is one-way, but if the input comes from a small set of possibilities, an attacker can simply hash every possibility and compare. That's why a hashed PIN or a hashed short password protects very little, and why seed phrases are long random words rather than something memorable.

They don't prove anything about meaning. A hash proves two things are identical. It says nothing about whether either one is honest. A perfectly verified hash of a malicious transaction is still a malicious transaction.

They aren't encryption. You can't "decrypt" a hash to get the original back. If something claims to reverse a hash, it's guessing.

Why this matters to you

You'll rarely compute a hash by hand. But understanding them explains several things that otherwise feel like rules to memorise:

Why a txid is proof a payment exists. Why you can't edit a confirmed transaction. Why mining consumes energy. Why an unspent address reveals a fingerprint rather than your keys. Why a long, random seed is safe and a short, clever one isn't.

Hash functions are the part of crypto that just works, quietly, billions of times a day. Knowing what they guarantee — and what they don't — is one of the cheapest ways to understand the system you're trusting with your money.

Share this article

Related articles