Skip to content

LibraryConsensus2015Design paperCorpus record

The Bitcoin Backbone Protocol

Bitcoin Backbone. Juan Garay, Aggelos Kiayias and Nikos Leonardos.

Common prefix, chain quality and chain growth, under a synchronous network and an honest majority of hash power.

A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.

When someone says 'Bitcoin is proven secure', ask which of the three properties, under what delay, and against what fraction of hash power.

The five-minute read

The defect

Nakamoto's paper argued informally that the longest chain is safe if most hash power is honest. This paper writes the properties you can actually prove.

The rule

Common prefix, chain quality and chain growth, under a synchronous network and an honest majority of hash power.

How it is put together

Common prefix: honest parties' chains agree except for a recent tail. Chain quality: honest blocks keep appearing in that chain. Chain growth: the chain keeps getting longer.

Where the claim stops

The model is not partial synchrony and not Byzantine quorum finality.

One action, walked through

  1. The model is rounds, with a bound on how many blocks an adversary can produce.
  2. The proof tracks how often an honest party is uniquely elected.
  3. A deep confirmation is how you turn a probabilistic prefix into a decision.
  4. What fraction of hash power is assumed honest?

The argument, unpacked

Why it is still on the desk

When someone says 'Bitcoin is proven secure', ask which of the three properties, under what delay, and against what fraction of hash power.

After the text

Later work relaxed synchrony and added variable difficulty. The three property names are still the right vocabulary.

What has to be true

  • The model is not partial synchrony and not Byzantine quorum finality.
  • Honest majority is an assumption, not a measurement the paper performs.
  • It does not price bitcoin.

What happened after the paper

Later work relaxed synchrony and added variable difficulty. The three property names are still the right vocabulary.

What to check before you use the idea

  • What fraction of hash power is assumed honest?
  • How many confirmations sit outside the common-prefix tail?
  • Does the proof assume a fixed difficulty?

Terms

Common prefix
Honest chains match except for the last several blocks.
Chain quality
The adversary does not write the whole chain.

The problem the paper names

Nakamoto's paper argued informally that the longest chain is safe if most hash power is honest. This paper writes the properties you can actually prove.

What the design proposes

  • Common prefix: honest parties' chains agree except for a recent tail.
  • Chain quality: honest blocks keep appearing in that chain.
  • Chain growth: the chain keeps getting longer.

How the mechanism is specified

  • The model is rounds, with a bound on how many blocks an adversary can produce.
  • The proof tracks how often an honest party is uniquely elected.
  • A deep confirmation is how you turn a probabilistic prefix into a decision.

What this page does not treat as proven

  • The model is not partial synchrony and not Byzantine quorum finality.
  • Honest majority is an assumption, not a measurement the paper performs.
  • It does not price bitcoin.

Why a venture studio still reads it

When someone says 'Bitcoin is proven secure', ask which of the three properties, under what delay, and against what fraction of hash power.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.