LibraryConsensus2008Design paperCorpus record
Bitcoin: A Peer-to-Peer Electronic Cash System
Bitcoin. Satoshi Nakamoto.
Publish every spend to a peer network. Let proof-of-work order the history. The longest chain of work is the ledger honest nodes extend. The first spend of a coin in that chain is the one that counts.
A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.
Read this for the problem and the sketch. Read the backbone paper before repeating 'the math says' anything about confirmations.
The five-minute read
The defect
A digital cash system that stops a coin being spent twice had needed a mint. The mint is the trusted party.
The proposal
Publish every spend to a peer network. Let proof-of-work order the history. The longest chain of work is the ledger honest nodes extend. The first spend of a coin in that chain is the one that counts.
The coin is a chain of signatures.
The mint is replaced by a race to extend a chain of hashed blocks.
The bound
The paper's majority argument is informal. The backbone papers are where the properties get named.
One action, walked through
- Broadcast a transaction.
- Miners bundle transactions into a block that extends the chain they see as having the most work.
- A node treats a spend as settled when enough work is buried on top of it.
- What is the double-spend, in the paper's own picture?
The argument, unpacked
What the paper is for
Read this for the problem and the sketch. Read the backbone paper before repeating 'the math says' anything about confirmations.
What happened after
Every later chain in this library is a disagreement with some sentence in this short paper: the puzzle, the privacy, the expressiveness, or the energy.
What has to be true
- The paper's majority argument is informal. The backbone papers are where the properties get named.
- It does not fix a block size, a fee market, or a lightning channel.
- It is not a promise about price.
What happened after the paper
Every later chain in this library is a disagreement with some sentence in this short paper: the puzzle, the privacy, the expressiveness, or the energy.
What to check before you use the idea
- What does the paper use as the vote: CPU power?
- What is the double-spend, in the paper's own picture?
- Which later paper turns the informal argument into a named property?
Terms
- Longest chain
- The chain representing the most proof-of-work, which honest nodes extend.
- Double-spend
- Two transactions that spend the same coin. The chain keeps one.
The problem the paper names
A digital cash system that stops a coin being spent twice had needed a mint. The mint is the trusted party.
What the design proposes
- The coin is a chain of signatures.
- The mint is replaced by a race to extend a chain of hashed blocks.
- Honesty is described as a majority of CPU power, informally.
How the mechanism is specified
- Broadcast a transaction.
- Miners bundle transactions into a block that extends the chain they see as having the most work.
- A node treats a spend as settled when enough work is buried on top of it.
What this page does not treat as proven
- The paper's majority argument is informal. The backbone papers are where the properties get named.
- It does not fix a block size, a fee market, or a lightning channel.
- It is not a promise about price.
Why a venture studio still reads it
Read this for the problem and the sketch. Read the backbone paper before repeating 'the math says' anything about confirmations.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
