A block can hold thousands of transactions, yet its header commits to all of them in a single 32-byte merkle root: hash them in pairs, then hash the pairs, up to one value. The reward is the merkle proof: to prove a transaction is in the block you reveal only the handful of sibling hashes on its path to the root. A phone can verify a payment against a header it trusts, without ever downloading the block. That's SPV. Click any transaction below to see its proof.
Odd levels duplicate the last hash. Try 5 or 7.
The siblings a light wallet needs: just these, not the block.
Change one bit of the selected transaction and the proof no longer rebuilds the committed root.
An SPV wallet keeps only block headers (80 bytes each). To trust a payment it asks a node for a merkle proof and checks it against the header's root: verification without the data.
A block of a thousand transactions needs a proof of about ten hashes. The cost of proving inclusion grows with the depth of the tree, not its width.
The same primitive shows up wherever one hash must vouch for many records. Exchange proof-of-reserves builds a Merkle tree of customer balances so each user can verify their inclusion in the audited total.