The Nonce Lottery
Proof of work with real SHA-256 in the browser: starting at nonce 0, a block of transactions searches for the number that makes its hash start with 1 to 5 zeros. The hash field flickers; counters set the tries against the expected 16^k, and the browser time against a laptop doing one million hashes/s. A chart shows that one more zero costs sixteen times as many tries and that each single case is a lottery. Verifying costs one hash. In chain mode, tampering with block 1 breaks the arrow to block 2.
CryptographyTry it