Dogecoin has had few miners of its own since 2014. The vast majority of its blocks are a by-product of Litecoin mining: a miner builds a Litecoin block candidate whose coinbase commits to a Dogecoin block, and each Scrypt hash they compute can then count on Litecoin, on Dogecoin, or on both. The mechanism is auxiliary proof of work (AuxPoW), first built for Namecoin in 2011 and enabled on Dogecoin in September 2014.
Why Dogecoin adopted it
Dogecoin launched in December 2013 with Scrypt proof of work, inherited through its Litecoin-derived code, and 1-minute blocks. Its early rewards fell quickly, and its hashrate was a small fraction of Litecoin's on the same hardware. That made it cheap to attack: anyone with a slice of Litecoin's hashrate could have overpowered Dogecoin. Profit-switching "multipools" made it worse, piling in when DOGE was profitable and leaving when it wasn't.
Merged mining solved both problems. It activated at block 371,337 with Dogecoin Core 1.8. Litecoin miners could now earn DOGE on top of LTC for almost no extra work, most of them started doing so, and Dogecoin's hashrate jumped to roughly Litecoin's level.
The AuxPoW idea
Normal proof of work says: hash this block's header, and the result must be below the target. AuxPoW says: show me some other block (the parent) that commits to this Dogecoin block, and whose header hash is below Dogecoin's target.
The parent is a Litecoin-format block. It doesn't have to be a valid Litecoin block, and it never has to be published on Litecoin. It only has to prove that the work was done while committing to this exact Dogecoin block.
The commitment in the parent's coinbase
The miner puts a small tag in the parent block's coinbase scriptSig:
fa be 6d 6d merged-mining magic: 0xfabe followed by "mm"
<32 bytes> aux merkle root (byte-reversed)
<4 bytes, little-endian> merkle tree size (a power of two)
<4 bytes, little-endian> merkle nonce
The aux merkle root is the root of a small Merkle tree whose leaves are the block hashes of every auxiliary chain being merged-mined, so one Litecoin candidate can commit to Dogecoin and other Scrypt chains at once. Each chain's leaf position is computed from its chain ID and the merkle nonce, so two chains can't claim the same slot.
Dogecoin's chain ID is 0x0062 (98). It's encoded in the block version, together with a flag marking the block as AuxPoW:
nVersion = (chain_id << 16) | 0x100 | base_version
= 0x00620000 | 0x100 | 0x4 = 0x00620104
What an AuxPoW block contains
A merged-mined Dogecoin block is its normal 80-byte header, then an AuxPoW structure, then its transactions:
| Field | Purpose |
|---|---|
| Parent coinbase transaction | Contains the merged-mining tag |
| Parent block hash | Legacy field |
| Coinbase merkle branch | Proves the coinbase is in the parent block (at index 0) |
| Chain merkle branch + index | Proves the Dogecoin block hash is a leaf under the aux merkle root |
| Parent block header (80 bytes) | The header whose Scrypt hash carries the work |
The Dogecoin header's own nonce is irrelevant in an AuxPoW block. The work lives in the parent header. Validation, simplified:
def check_auxpow(doge_header, aux, doge_target: int) -> bool:
# 1. The coinbase really is the first transaction of the parent block
root = merkle_root_from_branch(txid(aux.coinbase_tx), aux.coinbase_branch, index=0)
if root != aux.parent_header.merkle_root:
return False
# 2. The coinbase commits to this Dogecoin block
aux_root = merkle_root_from_branch(block_hash(doge_header), aux.chain_branch, aux.chain_index)
script = aux.coinbase_tx.vin[0].script_sig
pos = script.find(MERGED_MINING_MAGIC + aux_root[::-1])
if pos == -1:
return False
size, nonce = read_size_and_nonce(script, pos)
if size != 1 << len(aux.chain_branch):
return False
if aux.chain_index != expected_index(nonce, DOGE_CHAIN_ID, len(aux.chain_branch)):
return False
# 3. The parent header's Scrypt hash meets *Dogecoin's* target
return int.from_bytes(scrypt_pow(aux.parent_header), "little") <= doge_target
Dogecoin Core also rejects a parent block that carries Dogecoin's own chain ID and a coinbase containing more than one merged-mining tag. Both rules close off ways to reuse one piece of work ambiguously.
One hash, two chains
The mining loop is ordinary Litecoin mining with one extra comparison:
build Litecoin candidate whose coinbase commits to a Dogecoin block
for each nonce:
h = scrypt(litecoin_header)
if h <= litecoin_target: submit the block to Litecoin
if h <= dogecoin_target: submit header + AuxPoW to Dogecoin
Both chains have roughly the same hashrate, but Dogecoin wants a block every minute and Litecoin every 2.5 minutes, so Dogecoin's target is easier. Most Dogecoin blocks come from parent headers that aren't good enough for Litecoin, and in practice a merged miner's Litecoin block also clears Dogecoin's target.
For pools, Dogecoin Core exposes RPCs built for this:
# Get a Dogecoin block to commit to (returns its hash, chainid 98, target, height, ...)
dogecoin-cli createauxblock <dogecoin_payout_address>
# After a parent header meets Dogecoin's target, submit the proof
dogecoin-cli submitauxblock <block_hash> <auxpow_hex>
One detail trips up developers: a Dogecoin block's ID is the double SHA-256 of its own header, while the proof-of-work hash is the Scrypt hash of the parent's header. The block hash an explorer displays won't look like it meets any target, and that's expected.
Issuance: 1-minute blocks and 10,000 DOGE forever
Dogecoin's early rewards were randomized and halved on a fast schedule, and the original plan capped supply at 100 billion DOGE. In early 2014 the community changed course: from block 600,000, reached in mid-2015, every block pays a flat 10,000 DOGE with no end date.
blocks per year ≈ 60 × 24 × 365 = 525,600
new DOGE / year ≈ 525,600 × 10,000 = 5.256 billion
Issuance is constant in absolute terms, so the percentage rate falls every year. At the mid-2020s supply of roughly 150 billion it's about 3.5%, and lost coins offset part of it. Dogecoin went from a capped-supply design to a permanently inflationary one, on the argument that a steady reward keeps miners paid without relying on fees. Difficulty adjusts every block (DigiShield, since 2014), which keeps 1-minute blocks stable when hashrate moves.
Security trade-offs
What Dogecoin gains:
- It inherits most of the Scrypt hashrate. Attacking it takes ASIC capacity on the scale of Litecoin's, not a small rented fraction.
- Miners have no reason to switch between LTC and DOGE, since they get both, so hashrate is steadier.
- Litecoin miners earn more too. At times DOGE rewards have made up a large share of Scrypt mining revenue, which ties Litecoin's security to Dogecoin's price as well.
What it gives up:
- Shared centralization. A few large pools produce most blocks on both chains. Whoever controls a majority of Scrypt hashrate can censor or reorg both.
- Cheaper attacks for merged miners. A pool can point hashrate at a private Dogecoin fork while still earning full LTC rewards from the same hashes. It gives up only honest DOGE rewards, so an attack costs less than on a standalone chain of equal hashrate. In 2012, CoiledCoin, a small merged-mined chain, was effectively killed by one large pool this way.
- Coupled economics. If Scrypt mining stops paying, both chains lose security together.
- Heavier headers. Each AuxPoW header carries a coinbase transaction and two Merkle branches. Light clients and header-sync code written for Bitcoin must parse and verify AuxPoW, or they'll reject valid Dogecoin chains.
Summary
| Dogecoin | |
|---|---|
| Proof of work | Scrypt, usually via AuxPoW with a Litecoin-format parent |
| Merged mining since | Block 371,337 (September 2014) |
| Chain ID | 0x0062 (98), in the block version |
| Block time | 1 minute, per-block difficulty adjustment |
| Issuance | 10,000 DOGE per block, no cap |
| Main risk | Large Scrypt pools can attack both chains; merged miners can attack DOGE cheaply |
For developers: validate AuxPoW headers, don't expect a Dogecoin block's ID to satisfy its target, and set confirmation counts on the assumption that the same few pools secure both chains.
Get the weekly commit
New blockchain deep dives every week.