Learn the words first
These words come with pronunciation, a meaning and a sentence to try. Most arguments about bitcoin are really arguments about these words. Listen and Repeat practises them one at a time. Speaking drill opens your microphone and checks how you say them.
二十六个术语,附发音、释义和例句。关于比特币的争论,多半其实是对这些词的理解之争。点“跟读”可逐词练习,点“口语练习”会打开麦克风检查发音。
คำศัพท์ยี่สิบหกคำ พร้อมคำอ่าน คำอธิบาย และประโยคให้ลองพูด ข้อถกเถียงเรื่องบิตคอยน์ส่วนใหญ่ แท้จริงคือการเถียงกันเรื่องความหมายของคำเหล่านี้ กดปุ่มฟังแล้วพูดตามเพื่อฝึกทีละคำ หรือกดฝึกพูดเพื่อเปิดไมโครโฟนตรวจการออกเสียง
This page puts the words first on purpose. Bitcoin is full of words that sound like ordinary English but are not. A wallet holds no money. Mining digs nothing out of the ground. And a whale is a person. Learn these, and the rest of the page reads at normal speed.
Listen & Repeat reads each word, then waits for you to say it back. Speaking drill turns on your microphone and checks that the words came out clearly. On each card, say it reads the word aloud. Tell me more opens a longer explanation and a sentence to try.
🎤 Speaking drill — set 1 of 6
Press the microphone, then say all the words in the set out loud.
- A bitcoin wallet holds no coins. It holds a key that proves the coins on the ledger are yours. Why did the industry choose a word that describes the wrong thing? What does that cost a beginner?
- Pick one word from this list. It should be the word your grandmother needs first, before anything else makes sense. Now explain it out loud in sixty seconds.
- English took mining, wallet, coin and whale from the real world. Then it pointed them at something with no physical form at all. Does your first language do this too, or does it invent new words?
Two schools, a broken gold link, and the printing press
Two schools of economics have argued for a hundred years about what money is for. Keynesians say spending drives the economy. To them, the money supply is a tool that governments should use. Austrians say saving drives the economy, and that the tool itself is the problem. In one picture: Keynesians treat money like an apple, for using before it rots. Austrians want it to behave like gold, so that saving works. Rome thinned its silver coin for two hundred years, until it was copper. In 1971 the United States cut the dollar's last link to gold. That removed the limit on how much money could be made. Debt and prices have risen ever since. Did the money cause that? This is exactly what the two schools disagree about.
一个世纪以来,两大经济学派一直在争论货币的用途。凯恩斯学派认为支出驱动经济,货币供应量是政府应当使用的工具;奥地利学派认为储蓄才是动力,而那个工具本身就是问题。用一幅画来说:凯恩斯学派把货币看作苹果,趁烂之前花掉;奥地利学派要它像黄金,这样储蓄才有意义。罗马把银币掺水掺了两百年,最后只剩铜。1971年,美国切断了美元与黄金的最后联系,取消了货币创造的上限。此后债务与物价一路攀升。这是否由货币造成,正是两派争论的焦点。
สองสำนักเศรษฐศาสตร์เถียงกันมาศตวรรษหนึ่งแล้วว่าเงินมีไว้ทำอะไร สำนักเคนส์บอกว่าการใช้จ่ายขับเคลื่อนเศรษฐกิจ และปริมาณเงินคือเครื่องมือที่รัฐควรใช้ สำนักออสเตรียบอกว่าการออมต่างหากที่ขับเคลื่อน และเครื่องมือนั้นเองคือปัญหา สรุปเป็นภาพเดียว สำนักเคนส์มองเงินเหมือนแอปเปิล มีไว้ใช้ก่อนเน่า สำนักออสเตรียอยากให้เงินเป็นเหมือนทอง เพื่อให้การออมมีความหมาย โรมเจือจางเหรียญเงินของตนนานสองร้อยปีจนเหลือแต่ทองแดง ปี 1971 สหรัฐฯ ตัดสายสัมพันธ์สุดท้ายระหว่างดอลลาร์กับทองคำ ทำให้เพดานการสร้างเงินหายไป หนี้และราคาสินค้าไต่ขึ้นนับแต่นั้น ส่วนเงินเป็นต้นเหตุหรือไม่ คือสิ่งที่ทั้งสองสำนักเถียงกันพอดี
Almost every argument in The Bitcoin Standard belongs to a fight that is a hundred years older than bitcoin. Two schools of economics disagree about what money is for. Nearly everything else follows from that. Get them clear now, before section 07 asks you to judge the book.
Keynesian
- Named for
- John Maynard Keynes. His General Theory came out in 1936, in the ruins of the Great Depression.
- What drives the economy
- Spending. If everyone saves at the same time, demand falls and the economy shrinks. What people buy sets what gets made.
- What money should do
- Bend. The money supply is a steering wheel. A central bank should make it bigger in a slump and smaller in a boom.
- What to do in a recession
- Act. Cut interest rates. Borrow and spend. Pull the economy back up instead of waiting.
- Biggest fear
- Falling prices and idle factories. People stop buying, firms cut jobs, and debts get heavier.
Austrian
- Named for
- Where its founders came from — Carl Menger, Ludwig von Mises, Friedrich Hayek, and later Murray Rothbard.
- What drives the economy
- Saving, and what saving pays for. You cannot buy your way to a factory. Somebody has to go without first.
- What money should do
- Stay still. Money is a measuring stick. If nobody can make more of it, the measurement stays honest.
- What to do in a recession
- Let it happen. The slump is not the illness. It is the cure — bad investments being cleared away.
- Biggest fear
- Cheap credit. When a bank pushes rates below what savers would ask, it sends a false signal. People invest in things they should never have built. The crash then has to come.
Both sides are simplified here to fit two boxes. Real Keynesians argue with each other all the time. One of the fairest criticisms of The Bitcoin Standard is that it treats them as one solid group, and sometimes puts them with Marxists. That hides a lot of real disagreement.
The whole fight in one picture
If you remember nothing else from this section, remember this. It uses the two things section 06 will compare: an apple and a bar of gold.
Keynesians are comfortable with money that slowly loses value. To them, money is like an apple. It is for using, not for keeping. If it rots a little each year, that is acceptable — and some would say useful, because it pushes you to spend or invest instead of sitting on it. So when the economy stalls, make more of it. Critics call this "printing money".
Austrians want money to behave like gold. You work, you save, and what you put away is still worth something in thirty years. You can build a pile over a lifetime. To them, money that rots is a broken measuring stick. Making more of it is quiet theft from everyone already holding it.
One side thinks money should move. The other thinks money should keep.
Partly. A Keynesian would not use the words "print" or "rot". They would say money is built to circulate, not to sit still. Cash is a tool for buying things. If you want to store value for thirty years, you are supposed to save in something else — a house, shares, a pension — not in banknotes. On that view, money losing a little value each year is not a bug. It is the tool doing its job.
So the picture above is a shorthand, and it is the critics' shorthand. Keep it, because it holds the shape of the argument. Just remember that one side did not choose those words.
This has happened before, and Rome is the case the book leans on
The oldest version of this argument has nothing to do with central banks. It is about a coin. It is also the story The Bitcoin Standard opens with.
Under Augustus, the Roman denarius was about ninety-five per cent silver. In 64 AD, Nero cut its weight and its silver. Emperor after emperor did the same. It was about seventy-five per cent under Marcus Aurelius, and about half under Septimius Severus. By roughly 265 AD it held around five per cent silver. It was a copper disc with a thin silver coating that wore off in your hand.
Two details are usually told wrong, so get them right. The coin they ruined was the silver denarius, not a gold one. And the metal they mixed in was copper, not lead. The method is the same either way. The issuer quietly took out some of the metal and kept the difference.
Prices rose sharply during the crisis of the third century. In 301 AD, Diocletian set maximum prices by law. The penalty for charging more was death. It did not work. Goods simply left the legal market.
Ammous likes what happened next. Around 309 AD, Constantine made a new gold coin called the solidus. Nobody debased it. It kept its weight and its purity for about seven hundred years. The western empire that stopped using it fell long before. The eastern half kept the good coin — and kept going until 1453.
Nobody disputes the debasement. You can weigh the coins, and people have. But saying it caused Rome's fall is a much bigger claim, and most historians do not accept it. The same century brought two terrible plagues, almost constant civil war, and enemies the army could not hold back. The debasement may have been a symptom as much as a cause. Emperors thinned the coins because they could not pay the soldiers. And they could not pay the soldiers because of the wars and the plagues.
What survives is smaller, and still uncomfortable. The people who made the money always had a reason to quietly take metal out of it. They did so for two hundred years. And everyone holding the coins paid for it, without ever being asked. Did that end Rome? Maybe not. But it happened. And nothing about it is special to Rome.
The dollar used to be a claim on gold. Then it stopped being one.
For most of modern history, a banknote was a receipt. You could hand it in and get metal. That is not a comparison. The promise was printed on the note, and you could enforce it in court.
In 1944, at a hotel in New Hampshire, forty-four countries agreed a new system. The dollar sat at the centre. Other currencies were fixed to the dollar. And the dollar was fixed to gold at thirty-five dollars an ounce. Foreign governments could swap dollars for the metal. The dollar was a kind of ticket.
By the late 1960s, the United States had printed far more dollars than it held gold for. The Vietnam war and spending at home were the reasons. France and others began asking for the gold. On 15 August 1971, President Nixon went on television and stopped the swaps. He said it was temporary. It never came back.
Since that day, no major currency can be swapped for anything. A dollar is a claim on nothing. Gold was fixed at thirty-five dollars. It now trades above two thousand.
Ammous calls 1971 the turning point of the modern world. It really was the moment the last outside limit on making money disappeared. What you think of everything after that is the argument.
What "printing money" actually means
Almost nobody prints anything. When people say a government is "printing money", they usually mean one of two very different things. The difference matters.
The first is borrowing. A government spends more than it collects in tax. It sells bonds to cover the gap. That is debt, not new money. Someone's existing savings are being lent out.
The second is what a central bank does. It buys those bonds with money it makes by typing a number into its own accounts. No printing press. No paper. This is quantitative easing, and it is the closest thing to what people picture. The money supply grows because the central bank decided it should.
Between February 2020 and March 2022, the American money supply grew by about forty per cent. That is the fastest peacetime growth ever recorded. Inflation reached 9.1 per cent in June 2022, the highest since 1981.
Nobody asked savers, and there was no vote. Both schools agree on that part. A committee decides to grow the money supply. Everyone holding the currency pays for it, through prices they did not choose.
Here the simple story breaks. Between 2008 and 2014 the Federal Reserve grew from about nine hundred billion dollars to roughly four and a half trillion. That was a far bigger jump than anything before it. And inflation stayed at or below two per cent the whole time. Economists spent ten years explaining why the inflation everyone predicted never came.
Here is the usual explanation. In 2008 the new money mostly sat inside banks that were not lending it. In 2020 it went straight to households as cash. It arrived exactly when factories and workers could not keep up. So making money seems to be necessary for lasting inflation, and nowhere near enough on its own.
That means "printing money causes inflation" is too simple to be useful. And "printing money is harmless" was proved wrong in 2022. Anyone who gives you either sentence flat is selling something.
And then there is the debt
One thing since 1971 is easy to measure. Governments have borrowed more than at any peacetime moment in history.
The Austrian case, put fairly. Once you can make money without limit, borrowing is no longer limited by what savers will lend. Deficits become permanent, because the bill can always be pushed into the future. Everyone holding the currency pays for that delay. On this view the debt is not a mistake. It is the obvious result of removing the limit in 1971, and good intentions were never going to stop it.
What the other side says. Three things, and none of them is weak. First, Keynes told governments to run surpluses in good years. They took the half of his advice they liked and ignored the rest — which blames politicians, not the theory. Second, much of the rise is about age: older populations and health costs, which arrive whatever the money system. Third, the two steep climbs on the chart belong to a financial crisis and a pandemic. Any system would have needed emergency borrowing for those.
What nobody disputes: the debt is real, it is very large, and it now costs a lot. In 2024 the United States spent more on interest than on its army. You do not need any school of economics to read that number.
Both schools agree the money supply is a decision. They disagree about whether anyone should be trusted to make it.
Bitcoin was built into that disagreement. Its fixed supply is not just a convenient technical detail. It is one side of this argument, written into software, by someone who had clearly picked a side. Was that side right? The rest of this page keeps coming back to that question. It has no technical answer.
- Until 1971 a dollar was a claim on a fixed weight of gold. Now it is a claim on nothing. Does that change how you feel about the notes in your pocket? Should it?
- The money supply grew forty per cent in two years, and nobody voted on it. Everyone holding the currency paid for that. So who should make that decision? And how would you hold them to it?
- Britain's debt fell for forty years, then tripled after two emergencies. Is that a fault in the money, or just what a crisis does? How would you tell the difference?
One list, copied everywhere, that nobody can quietly edit
Bitcoin is a list of every payment ever made. Thousands of computers each keep an identical copy. Nobody is in charge of the list. To change an old entry, you must redo all the work that came after it. You also need more computers than everyone else put together. That is what makes the past so expensive to rewrite.
比特币是一份记录所有交易的清单,由全球数千台电脑各存一份完全相同的副本,没有任何人负责管理这份清单。要改动一条旧记录,就必须重做它之后的全部运算,而且算力要超过其他所有人之和——这正是改写过去代价高昂的原因。
บิตคอยน์คือรายการธุรกรรมทั้งหมดที่เคยเกิดขึ้น เก็บเป็นสำเนาที่เหมือนกันทุกประการในคอมพิวเตอร์หลายพันเครื่อง โดยไม่มีใครเป็นเจ้าของรายการนั้น การแก้ไขรายการเก่าหมายถึงต้องทำงานคำนวณทั้งหมดที่ตามมาใหม่ ด้วยกำลังเครื่องที่มากกว่าคนอื่นทั้งโลกรวมกัน นั่นคือเหตุผลที่การเขียนอดีตใหม่จึงแพงมาก
Take away the price charts and bitcoin is an accounting trick. It is one list. Every payment that has ever happened, in order. The trick is this: thousands of unrelated computers hold the same copy, and they agree on what it says. None of them is in charge.
That sounds small. It is not. Until 2009, nobody had solved one particular problem. Digital things copy perfectly. If money is a file, I can send you the file and keep a copy too. Then I have spent it twice. Every earlier attempt at digital money fixed this the same way. It chose somebody to keep the master list — a bank, a company, a server. That works. But it means there is a somebody. And a somebody can be pressured, hacked, bought, or told by a government whose money to freeze.
Bitcoin's answer had two parts. Make the list public. And make adding to it deliberately expensive. Anyone can add the next page. But you must burn real electricity to earn the right. The winner gets new coins for the trouble. To rewrite an old page, you must redo that work for every page since — while the rest of the network keeps racing ahead. So the past is not protected by a rule or a promise. It is protected by arithmetic and an electricity bill.
The innovation was not the coin. It was a way for strangers who do not trust each other to agree on the order things happened in.
Now put that next to section 02. Every money in that section failed the same way. Somebody could make more of it, and in the end they did. Rome could thin the denarius because Rome made it. A central bank can grow the money supply because it is the central bank. So why can nobody grow bitcoin's supply? Not because a rule says no — rules have never stopped anyone. It is because nobody is in a position to do it. The accounting trick and the money argument are the same trick, seen from two ends.
Everything else on this page follows from that one move. That includes the parts people dislike. The electricity is not waste added to the design. It is the design. A few people holding most of the coins is what happens to an open network after seventeen years. And is a thing with no income, no issuer and a fixed supply really money? Or a commodity? Or a bubble that has not burst yet? That is the argument the rest of the page sets out.
- Every payment you have ever made went through somebody's master list — a bank, a card company, a government. Name one time that helped you. Now name one time it did not.
- Bitcoin solved one problem: digital things copy perfectly. What else in your life is worse because copying is free? And what is better?
- "Nobody is in charge" is the main selling point. So when something goes wrong, and nobody is in charge, who do you go to?
Break it yourself
A hash is a fingerprint of some data. Change one letter and the whole fingerprint changes. Each block carries the fingerprint of the block before it. That is why the blocks form a chain. Mining means hunting for a number that makes a block's fingerprint start with zeros. Finding it takes enormous work. Checking it takes none. Edit any block below and watch every block after it break.
哈希就是一段数据的指纹:改动一个字母,整个指纹就完全变了。每个区块都带着前一个区块的指纹,于是区块串成了链。挖矿就是找一个数字,让区块的指纹以若干个零开头——找它极其费力,验证它却毫不费力。修改下面任何一个区块,看看它之后的每个区块如何崩坏。
แฮชคือลายนิ้วมือของข้อมูล เปลี่ยนตัวอักษรเดียวลายนิ้วมือก็เปลี่ยนทั้งหมด แต่ละบล็อกพกลายนิ้วมือของบล็อกก่อนหน้าไว้ บล็อกจึงต่อกันเป็นโซ่ การขุดคือการค้นหาตัวเลขที่ทำให้ลายนิ้วมือของบล็อกขึ้นต้นด้วยเลขศูนย์ ซึ่งหายากมหาศาลแต่ตรวจสอบง่ายมาก ลองแก้บล็อกใดก็ได้ข้างล่าง แล้วดูว่าบล็อกที่ตามมาพังทั้งหมดอย่างไร
Three ideas, in order. None of them is new on its own. The combination is.
First, the hash. A hash function takes any amount of data and gives back a fingerprint of fixed length. Bitcoin uses SHA-256, which always returns 64 characters. Two things make it useful. Change one character of the input, and the whole output changes — in a way nobody can predict. And you cannot run it backwards. Given a fingerprint, the only way to find the data is to guess.
Second, the chain. Each block of payments includes the hash of the block before it. So block 3's fingerprint depends on block 2's. Block 2's depends on block 1's. Change one letter in an old block and its hash changes. Then the next block's "previous hash" no longer matches. And so on, all the way to today. One edit breaks everything after it. That is exactly why we call it a chain.
Third, proof of work. A computer could fix a broken chain in a fraction of a second. So there is one more rule. A block is only accepted if its hash starts with a run of zeros. There is no clever way to make one. You add a meaningless number called a nonce. You hash the block. If it does not start with enough zeros, you change the nonce and try again. Billions of times a second, all over the world. The result is a puzzle that is brutally expensive to solve and instant to check. That gap is the whole point: hard to write, cheap to check.
A four-block chain, running live in this page
These are real SHA-256 hashes. Your browser works them out as you type. The difficulty here is four leading zeros. That is tiny next to the real network, and enough to show how it works. Edit the text in any block. That block will turn red, and so will every block after it. Their fingerprints no longer start with zeros, and they no longer match what the next block recorded. Now press mine on each red block, from left to right. Watch how much work it takes to make a lie look honest. Watch how that cost grows with every block you have to redo.
Reading the colours. Each block's own hash has a colour. The same colour appears again in the next block, as its previous hash. So block 1's fingerprint is the line sitting at the top of block 2. Hover over either copy to light up both. The underlined zeros at the start are what make a hash acceptable. A broken block has none. That is the fastest way to spot the failure, without comparing a single character.
Real bitcoin blocks need about nineteen leading zeros, not four. The whole network, with all its machines together, hits that about once every ten minutes.
What mining actually is
Mining sounds clever. It is not. It is guessing.
A miner takes the block and adds a meaningless number to it, called a nonce. It hashes the whole thing and looks at the answer. Does it start with enough zeros? Almost always, no. So the miner adds one to the nonce and tries again.
There is no shortcut. You cannot work out the right nonce. You cannot start from the answer you want and run backwards to find it. The only method is to try, and keep trying. That is the whole job. A miner is simply a machine that guesses very fast, and owning two machines gives you two chances instead of one.
When you press mine above, your browser does exactly that. It starts at zero and counts upward until a hash comes back with four leading zeros. It usually takes around sixty-five thousand tries, and your laptop does that in well under a second.
Why you could not do this to the real bitcoin
You have just rewritten history in four blocks. Doing it to the real network is much harder, and for three separate reasons.
The chain keeps growing while you work. You are not only redoing the old blocks. Everybody else is adding new ones the entire time. So you must redo all the old work, and catch up, and then get ahead. Nodes follow whichever chain has the most work behind it.
So you need more machines than everyone else put together. Not more than the biggest miner — more than all of them combined, for as long as the attack takes. That is the 51% attack. It is not impossible. It is expensive, and it gets more expensive every time somebody plugs in a machine.
This is the part people miss, and it matters. Every node checks every rule for itself. A block that makes coins out of nothing, or spends coins whose owner never signed for them, is thrown away — no matter how much work is piled on top of it.
Work only chooses between histories that are already valid. It cannot make an invalid one acceptable. More computing power does not buy you permission.
So what could an attacker with all that power actually do? Undo their own recent payments. That is close to the whole list. They cannot take your coins, because they cannot sign for them, and no amount of electricity produces a signature they do not have.
The network wants one block every ten minutes. Every 2,016 blocks — about two weeks — each node works out how hard the puzzle should be. It looks at how fast the last 2,016 arrived. If more miners join, the puzzle gets harder. If half of them switch off, it gets easier.
People misunderstand this more than anything else in bitcoin, and section 08 depends on it. The difficulty always moves to keep blocks ten minutes apart, however many machines are running. A million more machines do not make more blocks. They do not process more payments. They only make each block harder to find.
- Two costs, both enormous, both paid for the same thing. Miners guess a hundred billion times a second; a new node must download and check every block ever made before it can tell you your own balance, and that gets a little longer every year. What is all that effort actually buying — and who do you think is still paying it in twenty years?
- A hash is easy to check and nearly impossible to reverse. Where else in life do you rely on something being much harder to fake than to verify — a signature, a passport, a face?
- The chain protects the order of events but not you. If you lose the key, the coins stay visible on the ledger forever and nobody can move them. Is that a flaw in the design, or the whole point of it?
An anonymous author, a very specific week
Bitcoin was published in October 2008. The author used the name Satoshi Nakamoto. Lehman Brothers had collapsed five weeks earlier. Almost every part of bitcoin already existed. The cypherpunks had argued about those parts for twenty years. The first block holds a newspaper headline about bank bailouts. The author disappeared in 2011. He never spent his coins — about a million of them.
比特币白皮书于2008年10月以“中本聪”之名发表,距雷曼兄弟倒闭仅五周。它的几乎每个零件都早已存在,被密码朋克们争论了二十年。第一个区块里嵌着一条关于银行救助的报纸标题。作者在2011年消失,估计约一百万枚币至今分文未动。
บิตคอยน์ถูกเผยแพร่ในเดือนตุลาคม 2008 ในนาม "ซาโตชิ นากาโมโตะ" ห้าสัปดาห์หลังเลห์แมนบราเธอร์สล้ม ชิ้นส่วนเกือบทั้งหมดมีอยู่ก่อนแล้วและถูกถกเถียงในหมู่ไซเฟอร์พังก์มายี่สิบปี บล็อกแรกฝังพาดหัวข่าวเรื่องการอุ้มธนาคารไว้ ผู้เขียนหายไปในปี 2011 และไม่เคยแตะเหรียญราวหนึ่งล้านเหรียญของตนเลย
On 31 October 2008, someone posted a nine-page paper to a cryptography mailing list. They used the name Satoshi Nakamoto. Lehman Brothers had collapsed five weeks before. The paper was called Bitcoin: A Peer-to-Peer Electronic Cash System. Its first sentence names the enemy. Business on the internet, it says, "relies almost exclusively on financial institutions serving as trusted third parties."
Nobody knows who wrote it, and this page will not solve that. People have named many candidates over the years. Each one has either denied it or failed the simple test. That test is easy: sign a message with the keys that mined the first blocks. Nobody has.
What we do know is where the ideas came from. That part is unusually well recorded, because it all happened in public, on mailing lists you can still read today.
It is worth saying plainly what kind of story this is. The page has been building it since section 02. For two thousand years, money was quietly thinned by whoever controlled it. Somebody looked at that pattern and drew a hard conclusion. The problem was not who controlled the money. The problem was that anyone controlled it. So he built the alternative alone, under a false name. Then he gave it away, kept nothing, and disappeared before it made him famous.
As rebel stories go, that is close to perfect. And that is exactly why you should be careful with it. A story this good makes people stop checking. So the panel below lists what he was really fighting, in his own words. For each one, it asks a simple question: did it work?
Click any entry on the strip above — or tab to one and press enter — to read what it was and what bitcoin took from it.
What he was fighting — and whether it worked
Satoshi named each of these as a problem himself — in the whitepaper, in the first block, or in his forum posts. Nobody added them later. The verdict is this page's own opinion, and it is not all good news on purpose. Pick one to read it.
The scores say how far the design did what its author wanted. They do not say whether bitcoin is a good investment. That is a different question, and this page does not answer it.
The headline in the first block
The very first block holds a line of text. It does nothing technical at all. It is simply buried in the field that names the block's reward:
The Times 03/Jan/2009 Chancellor on brink of second bailout for banks
That is a real headline from the London Times that morning. It does two jobs at once. It proves the block was not made before that date. And it says clearly what the author thought was wrong. Anyone can still read it in the blockchain today.
So the why is not really in doubt, whatever you think of it. The whitepaper is a technical document. The first block is a statement. And his forum posts in 2009 and 2010 are blunt: "The root problem with conventional currency is all the trust that's required to make it work. The central bank must be trusted not to debase the currency, but the history of fiat currencies is full of breaches of that trust."
Was he right? That is section 07's argument. That this was his reason is simply on the record.
And then he left
Satoshi wrote code and forum posts through 2010. Then he handed the code over to Gavin Andresen. In April 2011 he sent one last email. He had "moved on to other things," he said. Nothing signed with those keys has appeared since.
Sergio Demian Lerner studied the earliest blocks. He found a clear pattern in the nonce values from 2009. It suggests one miner made about one million coins in the first year. Almost none of them have ever been spent.
Treat that number as a good estimate, not a measurement. There is a real method behind it, but it is still an estimate. The behaviour, though, is not in doubt. A huge early holding has sat untouched for over fifteen years, through every price peak. Whatever his reason was, it does not look like getting rich.
- The author gave away something now worth a fortune, then disappeared without spending any of it. Why would a person do that? And would bitcoin have survived if he had stayed?
- Every part of bitcoin existed before 2008. What was new was joining them together, in the month the banks were failing. Is good timing a kind of invention?
- The first block quotes a newspaper about bank bailouts. Seventeen years later, has the thing it protested against changed at all?
Everything is a store of value. Everything is a bad one.
A store of value is anything you can put work into now, and take work back out of later. Apples fail at time. Cash fails at time too, but more slowly. Houses cannot move, and they take months to sell. Gold is hard to check. Bitcoin is not stable, and it has almost no history. Nothing wins on every property. So the right question is never "which is best?" It is "best over what distance, and for how long?"
价值储存工具,就是你今天存入劳动、日后能取回劳动的东西。苹果输在时间;现金也输在时间,只是慢一些;房子输在搬不动、卖不快;黄金输在难以验真;比特币输在不稳定、也没有历史。没有一样能在所有属性上胜出,所以真正的问题从来不是“哪个最好”,而是“要跨多远、存多久”。
สิ่งเก็บมูลค่าคืออะไรก็ตามที่คุณใส่แรงงานลงไปวันนี้ แล้วดึงแรงงานกลับออกมาได้ในภายหลัง แอปเปิลแพ้เรื่องเวลา เงินสดก็แพ้เรื่องเวลาเช่นกันแต่ช้ากว่า บ้านแพ้เรื่องการเคลื่อนย้ายและการขายให้เร็ว ทองแพ้เรื่องการตรวจสอบ บิตคอยน์แพ้เรื่องความผันผวนและการไม่มีประวัติศาสตร์ ไม่มีอะไรชนะทุกข้อ คำถามที่ถูกจึงไม่ใช่ว่าอะไรดีที่สุด แต่คือดีที่สุดในระยะทางไกลแค่ไหนและนานเท่าใด
Start with the simplest possible version. You pick apples in October. You want to eat in March. The apples are a store of value — you have moved this autumn's labour into next spring — and they are a terrible one, because by March most of them are brown.
Every kind of money humans have used tries to fix that one failure. The goal is not to be useful — apples are useful, and that is not the problem. The goal is to survive the journey. There are three journeys. The economist Saifedean Ammous, whose book is section 07, calls this salability: selling across time, across space and across scale. In plain words: can it survive being kept? Can it survive being moved? And can you break it into the size of the thing you want to buy?
The list below compares five things across nine properties. The scores are judgements, not measurements, and the note says so. But the shape of each one is not really in dispute. The interesting part is that every column has a hole in it.
The starting scores are the author's judgement, from 0 to 10. They show the shape of the trade-offs; they are not data. Where a real number exists, the panel gives it instead. Your changes are kept in this browser, so they survive a reload.
Every score here is one person's opinion. Mine. Drag any of them and see what happens. When a score is different from the one this page shipped with, the page's own number stays visible beside yours, so you can always see what you changed.
- Find three you disagree with. Move them. For each one, say out loud in a single sentence why the page is wrong.
- Start with security. This page gives bitcoin 7 and cash 6. Do you agree? Which would you rather be holding in ten years, and what are you afraid of that makes you say so?
- Now argue the other side. Take the score you feel strongest about and make the best case against yourself. If you cannot, you may not understand it yet.
What the holes tell you
Nothing scores well on everything, and the failures are not random. Gold's weakness is checking it. A bar with tungsten inside looks exactly like a real one. So gold ends up locked in vaults, and people trade paper claims instead of metal. That quietly brings back the counterparty gold was supposed to remove. Cash wins on liquidity: you can spend it instantly, anywhere, at full value. It is excellent at every property but one — and that one is the property that matters over a lifetime. Real estate has something none of the others have: it pays you rent while you hold it. It pays for that by never moving, and by taking months to sell.
Bitcoin's one truly new score is verifiability. Anyone can check the whole supply, and check any coin, for free, on a laptop. There is nothing like that for gold. It pays for this with the three worst scores on the board. It has only seventeen years of history. It has had three drawdowns of about seventy-five per cent or more — three falls that deep, from a peak. And its security is weak. An asset that halves in a year did not store value that year, whatever it does over ten.
The security row is the one to argue about, and this page has changed its mind about it once already. Look at what it is really asking: will you still have this in ten years?
Against theft and your own mistakes, bitcoin is the worst thing here. Someone steals your key. An exchange fails. You type one wrong address. The coins are gone. There is no fraud department, no insurance, and no court that can move them back. Mt. Gox lost about 850,000 coins. FTX held customer balances that were never really there. Nobody got their money back. Meanwhile, stealing a house is genuinely hard.
But against everything else in that question, it is the strongest thing on the list. Nobody can freeze it. Nobody can print more of it and make yours worth less. No bank holding it can fail and take it with them. Money in an account is none of those things: it can be frozen in an afternoon, it loses a little value every year by design, and in Cyprus in 2013 depositors simply lost part of their balance to save the banks.
So bitcoin scores 7 here and cash scores 6 — but that is a judgement about which danger is bigger, not a measurement. A reader in a stable country with a good bank may reasonably flip those two around. That is exactly what the boxes below are for.
One number hides something, and the hidden part is the interesting part. Split security into two halves, and bitcoin and real estate swap places completely.
Against theft and mistakes, a house is almost unbeatable and bitcoin is the worst thing here. Against seizure, it flips exactly. You cannot hide a house. You cannot move it. And the government holds the record of who owns it. That makes it the easiest thing on this list to tax, freeze or take. A phrase in your head is the hardest. Gold sits in the middle, and has suffered both. People steal it. And the United States made owning it illegal from 1933, for forty years.
So which way should the row point? It depends entirely on what you are afraid of, and that is not a technical question at all. Fear burglars, hackers and your own carelessness, and bitcoin is the worst choice here. Fear the government where you live, or fear your savings quietly shrinking, and it is the best one. That second fear is exactly what it was built around — read the genesis block in section 05 again.
One thing on that chart is genuinely new, and it is not any single score. Look at where each asset lives. Cash, bank deposits, shares and bonds all sit inside the banking system. They are entries in somebody's ledger. That somebody can freeze them, lose them, charge you for them, or be ordered to hand them over. Gold and property sit outside the system. But you cannot carry useful amounts of gold across a border, and a house cannot move at all. For the whole of history, "outside the banking system" and "able to move" could not both be true.
Bitcoin is the first thing that is both. There is no account, no custodian, no counterparty and no form to fill in. It settles anywhere with an internet connection, in about an hour. Whatever you think about the price, that combination did not exist before. It is worth stopping to notice how strange this is. One anonymous person built it. And the answer to "who do I ask for permission?" is nobody.
This is also why the security score is 7 and not 10. Each of those missing things has a second face. No custodian also means nobody to call. No counterparty also means no insurer. No permission also means no way to get your money back. The revolutionary property and the dangerous property are not two features. They are one feature. Which name you give it depends on what happens to you.
"Store of value" is not something a thing simply is. It is a claim about a distance and a length of time. And it is false for every asset, at some distance and some length.
Which is why the honest answer is a dull one. Over a week, a bank deposit beats everything. Over thirty years, the bank deposit is the one that quietly lost the most. Over five thousand years, only gold has a record at all — and that record is the one thing bitcoin cannot have yet, and will not have in your lifetime.
- Where do you store value yourself — a bank account, a house, gold, your family, your own skills? What journey are you asking it to survive, and for how long?
- A house is the only thing here that pays you while you hold it. Gold and bitcoin produce nothing at all. Are they even the same kind of thing?
- Your grandparents' savings bought far more than the same number buys today. Was that a mistake, a design choice, or simply what money is?
Hard money, and the people who disagree
Ammous says people choose money for its hardness. Hardness means how difficult it is to make more of it. He measures it by comparing the pile that exists with the amount made each year. Gold won for five thousand years because that number was high. Bitcoin's number doubles at every halving, and in the end it has no limit. The history in the book is mostly accurate. The economics is one school arguing against most of the others. And the price model built on it has already failed a test.
阿莫斯认为,货币的胜出取决于“硬度”——增产的难度,用现存储量与年新增产量之比来衡量。黄金之所以称霸五千年,正因这个比值高。比特币的比值每次减半就翻倍,最终趋于无穷。书中的历史叙述大体准确;但其经济学属于一个学派对抗其余多数学派,而建立其上的价格模型已经被现实证伪过一次。
อัมมูสเสนอว่าเงินถูกเลือกจาก "ความแข็ง" คือความยากในการผลิตเพิ่ม วัดด้วยอัตราส่วนของกองสะสมที่มีอยู่ต่อผลผลิตใหม่ต่อปี ทองครองโลกห้าพันปีเพราะอัตราส่วนนี้สูง ของบิตคอยน์เพิ่มเป็นสองเท่าทุกครั้งที่รางวัลลดครึ่ง และสุดท้ายจะเป็นอนันต์ ประวัติศาสตร์ในหนังสือส่วนใหญ่ถูกต้อง แต่เศรษฐศาสตร์ในนั้นคือสำนักคิดหนึ่งที่เถียงกับสำนักอื่นเกือบทั้งหมด และแบบจำลองราคาที่สร้างบนมันก็สอบตกไปแล้วครั้งหนึ่ง
Wiley published The Bitcoin Standard in 2018. It is easily the most influential book about bitcoin. It is worth reading — and worth reading carefully. About two-thirds of it is the history of money. The last third is a political argument. The book does not always tell you which one you are reading.
The argument, as fairly as it can be put
His main idea is hardness. He measures it with the stock-to-flow ratio. You take the pile that already exists and divide it by the amount made in a year. If that number is high, even a very busy year of production hardly changes the total. So producers cannot flood the market and destroy everyone's savings.
His claim about history is this. Governments do not choose money by order. Money wins a competition. And societies that chose easy money were ruined by it. The examples are real, and they are the best part of the book.
The people of Yap used huge limestone discs. Cutting them on another island was slow and dangerous. Then a shipwrecked Irish-American trader arrived with modern tools and explosives. He made the stones cheaply, and they stopped being money.
West African communities kept their wealth in glass beads. Making those beads locally was slow and expensive. Then Europeans arrived with factory glass. They bought a continent's savings with trinkets.
In both cases the money did not fail because it was primitive. It failed because somebody found a cheap way to make more.
Gold won for five thousand years for two reasons. It does not rot or rust, and it is very hard to find. Miners add only about 1.5 to 2 per cent a year to all the gold ever mined. That gives a stock-to-flow of about sixty years. No gold rush in history has really watered down the pile.
Bitcoin's new supply is fixed in software, and it halves every four years. Its number has already passed gold's. And unlike gold, it does not depend on what mining companies decide. It is simple arithmetic. So on this view, bitcoin is not competing with payment systems at all. It is competing with gold — and it is winning on the one measure Ammous cares about.
Where it gets contested
Three separate objections, which are often mashed together and should not be.
A high stock-to-flow tells you that new supply cannot water down what you hold. It tells you nothing about demand. Plenty of things are extremely rare and nobody wants them. The ratio cannot tell those things apart from money.
This objection got a very clean test. In 2019 someone published a model called S2F under a false name. It matched bitcoin's price to its stock-to-flow, and predicted about a hundred thousand dollars by the end of 2021. The ratio did exactly what it was supposed to do — it is arithmetic. The price did not. The author has since agreed the model broke. The lesson is narrow and worth keeping. Hardness is a real property of an asset. It is not a price forecast.
Ammous thinks money that gains value is simply good. It rewards saving. And it forces banks to lend real savings instead of credit they invented. Most working economists disagree. Their objection is not that saving is bad. It is that debts are fixed in numbers. If money gains value every year, every borrower owes more in real terms. Their standard fear is debt deflation. Falling prices make debts heavier. People sell things to pay. That pushes prices down further still.
This is the Austrian and Keynesian views hitting each other head-on. It is a real disagreement between schools, not a question of fact. It is also where the book is least fair to the other side. Ammous treats "Keynesian" as one solid group. Sometimes he puts Keynesians and Marxists together. That hides a great deal of argument those economists have with each other. For the opposing case put properly, you will need a different book.
The later chapters push the idea a very long way. Leaving the gold standard paid for the First World War. Easy money explains why painting and architecture got worse. Paper money raises what he calls time preference — it makes people impatient — and so ruins their diet, their families and their taste. Some of this is defensible history. Some of it asks one idea to explain the whole twentieth century.
The book also dismisses every other cryptocurrency. And — this surprises people — it dismisses bitcoin as a way to buy things. Ammous expects it to move large sums between institutions, not to pay for coffee. If you have heard the book called crypto hype, that is not quite what it says.
What survives all of this. Easy money does destroy savings. The people holding it were robbed slowly instead of suddenly. That is well evidenced and hard to argue with. Currencies really have lost most of their value over a century. The Yap stones and the glass beads really happened. You can accept every one of those facts and still say no to the conclusion. A fixed-supply digital asset may not be the answer. Many careful readers end up exactly there.
- The Yap stones and the West African beads stopped being money as soon as somebody could make them cheaply. Is there anything you value that would collapse the same way?
- Ammous says money that gains value makes people patient. His critics say it makes debts crushing. Which effect would be bigger in your country?
- Two-thirds of this book is history. One-third is politics. It does not always tell you which one you are reading. How should you read a book that is right about a lot, and pushing hard on the rest?
Nobody designed a country-sized power draw. It happened anyway.
Mining uses about 150 terawatt-hours of electricity a year. That is as much as a medium-sized country. Here is the part most people get wrong. The electricity follows the price, not the number of payments. A million new users cost nothing extra. A higher price costs a lot. Ethereum changed to a system that uses a thousand times less, and it works. Bitcoin will not copy it, because that electricity is what keeps it safe.
比特币挖矿每年耗电约一千五百亿度,相当于一个中等国家。关键机制在于:耗电量跟随的是币价,而不是交易笔数——多来用户不增加一分能耗,币价上涨却会大幅推高能耗。以太坊已改用能耗仅千分之一的机制并证明可行,比特币不会跟进,因为那些电力本身就是它的安全性。
การขุดบิตคอยน์ใช้ไฟฟ้าราวหนึ่งแสนห้าหมื่นล้านหน่วยต่อปี เทียบเท่าประเทศขนาดกลาง กลไกสำคัญคือปริมาณนี้ผันตามราคาเหรียญ ไม่ใช่จำนวนธุรกรรม ผู้ใช้เพิ่มขึ้นไม่ทำให้เปลืองไฟขึ้นเลย แต่ราคาที่สูงขึ้นทำให้เปลืองมาก อีเธอเรียมเปลี่ยนไปใช้กลไกที่กินไฟเพียงหนึ่งในพันและพิสูจน์แล้วว่าได้ผล บิตคอยน์จะไม่ทำตาม เพราะพลังงานนั้นคือเนื้อแท้ของความปลอดภัย
This is the clearest thing on the page that nobody planned. Satoshi wrote "one CPU, one vote". He expected people to mine at home. Within about four years that was over. Mining moved to ASICs: chips that can do one calculation and nothing else. It moved into big sheds next to cheap power. Nobody broke a rule. The money simply pointed that way, and nothing in the design pointed anywhere else.
The mechanism people get wrong
The difficulty always moves to keep blocks ten minutes apart. So the number of users cannot change the electricity. What changes it is how much money miners can win. Miners will spend up to about the value of the reward. If the price doubles, more machines become worth running. Difficulty goes up, and so does the electricity.
Two things follow, and they point in opposite directions. A million new users add no electricity at all. So "cost per transaction" numbers mean almost nothing, even though people quote them constantly. And a higher price adds electricity with no limit. So better machines cannot fix this. Better chips make each guess cheaper. Cheaper guesses mean more guesses. More guesses raise the difficulty. The system uses whatever it can afford.
So what is all that electricity actually for? Section 02 is the answer. It is not paying for payments — those are almost free. It is buying one thing: nobody can quietly make more coins, and nobody can change the past. Is that worth a medium-sized country's electricity? That is a real question. Both answers are serious. If it seems obvious to you either way, look again at what sits on each side.
The carbon is much harder to measure than the electricity. It depends on where the machines are. That has changed a lot. China held most of the mining until it banned it in mid-2021. The industry moved to the United States, Kazakhstan and Russia. Was that better or worse? It is not clear. It lost a lot of Chinese hydropower. It gained Kazakh coal and American gas. Published estimates differ by three times, depending on which power mix the writer assumes. So anyone who gives you one confident number has picked one.
There is a real argument on the other side, and it deserves a fair hearing. A mine can be built anywhere, and it can be switched off in seconds. Very few big users of power can do both. So you can put a mine at a gas field where the gas is being burnt off and wasted. You can put one on a grid with more wind than demand at three in the morning. And when the grid needs the power back, the mine stops at once. Texas pays miners to do exactly this. Is that a real benefit to the grid, or just a good excuse? People argue about it honestly. Remember too that the industry's own green figures come from the industry itself.
In September 2022 Ethereum changed from proof of work to proof of stake. Instead of burning electricity, you lock up coins. If you cheat, you lose them. Its electricity use fell by more than 99.9 per cent. It happened overnight, on a live network holding hundreds of billions of dollars.
So nobody can say "there is no other way" any more. Bitcoin has not copied it and almost certainly never will. There are two separate reasons. The technical one: proof of stake guards the chain with the coin itself, so it protects itself with itself. Electricity comes from outside, and you cannot invent it. The social one: changing bitcoin needs almost everyone to agree. This network has never agreed on anything. And many holders are there exactly because it does not change.
There is also the hardware. An ASIC can do nothing else, so when a better one arrives the old one is rubbish. One well-known study put this at tens of thousands of tonnes of e-waste a year. The industry disagrees with how that was counted. The argument is about how long the machines really last.
Should you run a miner yourself?
Start with the machine you already own. Suppose you set an Apple laptop to mine tonight. It will run hot, the fans will scream, and it will earn you almost exactly nothing. How close to nothing is worth seeing, because it is the fastest way to feel how big this network is. Pick a machine, then drag the two prices. Those two numbers decide everything.
Three of the machines below are called ASICs, said "AY-sik". It stands for application-specific integrated circuit, and it means a chip built for one job only. Not a fast computer — a chip that can do one calculation and nothing else at all. It cannot run a game, a browser or an AI model. It cannot even be told to stop hashing. Section 08 comes back to why that trade wins so completely.
The AI workstation is a real machine on the desk here, and its processor figure comes from measuring it: one core does 559 MB of SHA-256 a second, which is about 4 MH/s, and it has twenty cores. The GPU part is an estimate, because no maintained bitcoin miner exists for that chip. Assumes the whole network is running at about 900 EH/s and that a block pays 3.125 coins. Both move — the network grows, and the reward halves again around 2028. Hashrate figures are typical published numbers for each class of machine, not measurements of one unit. Treat every result as an order of magnitude, not a quote.
Why a fast computer is not a fast miner
Try the AI workstation on the list above. It is a genuinely powerful machine, the kind used to train models, and it costs about four thousand dollars. At this job it is roughly twice as fast as a gaming graphics card. That is all it buys you.
One current mining machine does 200 TH/s. The workstation does about 2 GH/s. So a single $3,800 miner is worth roughly a hundred thousand of those workstations — about four hundred million dollars of them.
Nothing is wrong with the workstation. AI and mining ask a computer for opposite things, and seeing why explains the whole shape of this section.
An AI model is arithmetic on a huge scale. Millions of numbers multiplied together, over and over, in big blocks. That work splits perfectly: thousands of small cores each take a piece and none waits for the others. The model is also enormous, often many gigabytes, so the machine needs a lot of fast memory to hold it. Many parallel cores and wide memory are the expensive parts of that chip. For AI they are exactly the parts that matter.
Mining needs neither. A hash is a short chain of simple steps on a few bytes: shift some bits, add, mix, repeat sixty-four times. Every step needs the answer from the step before, so one hash cannot be split across cores at all. And the whole job fits in about 256 bytes. Not gigabytes. Bytes.
What the chip is actually doing
Each square is one per cent of the chip. Colour shows what that part of the silicon is for. Switch the job and the parts that job cannot use go grey.
So on the workstation, every expensive part sits idle while it mines. The memory goes unused. The decimal maths goes unused. The tensor units — the thing that makes it an AI machine in the first place — are not touched at all. You have bought a warehouse to store one envelope.
An ASIC is the opposite trade. Almost every transistor in it is a SHA-256 circuit, copied over and over. It cannot run a model. It cannot run anything else at all.
That is the whole answer. A general computer can do anything, and paying for that flexibility is what makes it lose here by a factor of a hundred thousand. The chip that wins gave up the ability to do anything else. It is why home mining ended around 2013, and why it is not coming back.
How you would actually do it
The software part is much simpler than people expect. It is five steps.
1. Get a wallet address. This is where the money would go. You do not need the coins first, and you do not need permission.
2. Choose solo or a pool. Solo means you keep a whole block when you find one, and the table above shows how long that wait is. A pool joins your machine to thousands of others. You are paid a small share every day instead of a huge amount almost never. Nearly everyone uses a pool.
3. Point the machine at the pool. You type in one address — the pool's server — and your own wallet address as the user name. That is the whole setup.
4. Watch the heat. A real miner turns almost all its electricity into heat and noise. A modern one is about as loud as a vacuum cleaner and needs 3,500 watts, which is more than most kitchen sockets will give you.
5. Get paid. The pool sends coins when your share passes its minimum.
Mining is a guessing race, and your chance of winning is simply your share of all the guessing. An Apple laptop makes perhaps 30 million guesses a second. That sounds enormous. The network makes about 900 million million million guesses a second.
Your share is therefore about one part in thirty thousand million million. At one block every ten minutes, your expected wait is hundreds of millions of years. The Earth is 4.5 thousand million years old. You would need a good fraction of that.
This is not a flaw in the laptop. It is the point of section 04: the puzzle is made expensive on purpose, and it is made expensive by everyone else trying at the same time.
The useful thing this shows is where the line falls. Below a certain electricity price, a modern machine makes money. Above it, the same machine loses money every day it is switched on. Nothing about the machine changed. That is why mining moved to Texas, Kazakhstan and Alberta, and it is the whole of section 08 in one number.
Does a miner ever pay for itself?
The calculator above is a photograph. It tells you about today. But you buy a machine once and run it for years, and two things change underneath you. More miners keep joining, so the difficulty rises and your share of the reward shrinks every month. The reward itself halves again around April 2028. Meanwhile you paid for the machine on day one. Drag the sliders and watch the line.
The line starts below zero because you have paid for the machine. It climbs while the machine earns more than it costs to run, and it bends downward as difficulty rises and after the halving. Machine prices are typical figures, not quotes. Difficulty growth has run anywhere from nothing to over 60 per cent a year; nobody knows the next four years, which is the honest reason this is a slider and not a number.
Leave the bitcoin price where it starts and most machines never pay for themselves, even on cheap electricity. Add price growth and almost everything pays back quickly. That is the whole finding, and it is worth sitting with: mining is not really a bet on the machine. It is a bet on the price.
This is why the people selling mining hardware talk about the price so much, and why a mine that was printing money one year is scrap the next. Nothing about the machine changed. The assumption did.
- A million new users cost bitcoin no extra electricity. A doubled price costs a lot. Does that change how you feel about the number? And does it change who you think is responsible?
- Ethereum cut its electricity by more than 99.9 per cent in one day, and it still works. The other way exists and it is proven. What would be a good reason not to take it?
- Your own laptop would need hundreds of millions of years to win one block. A machine in Texas needs cheap electricity to make any money at all. Who is this system actually built for now — and is that what its author wanted?
An open network, owned by very few people
A very small number of addresses hold most of the coins. But an address is not a person. One exchange address can hold the coins of millions of customers. Two university studies found real price manipulation in bitcoin's early years. The market makes it easy: it never closes, the order books are thin, and traders borrow heavily. Still, the coins are spreading out over time. And blaming whales is the easiest way to avoid a simpler truth: this asset just moves a lot.
极少数地址持有大部分供应量,但地址不等于人:一个交易所地址可能代表数百万客户。两项学术研究在比特币早期的暴涨中发现了真实的操纵行为。市场结构本身也助长操纵:没有熔断、盘口薄、杠杆重。不过集中度正在下降,而把一切归咎于“巨鲸”,也是最省事的借口——回避承认一个高波动资产本来就会剧烈波动。
ที่อยู่กระเป๋าจำนวนน้อยนิดถือครองอุปทานส่วนใหญ่ แต่ที่อยู่หนึ่งไม่เท่ากับคนหนึ่ง ที่อยู่ของกระดานเทรดเดียวอาจแทนลูกค้าหลายล้านคน งานวิจัยสองชิ้นพบการปั่นราคาจริงในช่วงราคาพุ่งยุคแรก โครงสร้างตลาดก็เอื้อ ไม่มีเบรกเกอร์ สภาพคล่องบาง เลเวอเรจสูง แต่ความกระจุกตัวกำลังลดลง และการโทษวาฬก็เป็นวิธีที่ง่ายที่สุดในการเลี่ยงยอมรับว่าสินทรัพย์ผันผวนย่อมผันผวนอยู่แล้ว
The ledger is public. So you can count exactly how much sits in each address. Almost no other market lets you do that. But you cannot count the people. That gap between the two is where most of the loose talk starts.
The concentration you can actually name
Four blocks of supply are large, identifiable and worth more than any address chart:
The coins that are gone. Between three and four million bitcoin are lost forever. Keys were thrown away. Hard drives went to the dump. Some owners died. Those coins still show in the supply, but they will never move again. So the real supply is well below twenty-one million.
Satoshi's one million or so. Nobody has touched them since 2010, as section 05 describes. If they ever moved, the price would react violently. Everyone quietly assumes they never will.
The funds. American regulators approved spot bitcoin ETFs in January 2024. They bought coins far faster than anyone expected. Together they now hold well over a million bitcoin. This changed the market. A large part of it now sits in regulated custody — held for you by a company under supervision. Ordinary pension savers own it. And the buying and selling is published every day.
The companies. One company alone holds several hundred thousand bitcoin. It bought most of them with borrowed money and by selling new shares. Its holding is so large that its money decisions move the market by themselves.
Those last two numbers change every few months, so they are left loose on purpose. Both are public. The funds report every day and the company announces what it buys. Look them up. Do not trust a number written here in 2026.
Manipulation: what has been shown, and what is folklore
Gandal, Hamrick, Moore and Oberman studied leaked trading records from the Mt. Gox exchange. They found two trading robots, called Markus and Willy. The robots bought coins without ever paying for them. The researchers link this to the price rise in late 2013, from about $150 to over $1,000. The price fell back after Mt. Gox collapsed in early 2014, losing about 850,000 coins.
Griffin and Shams studied the 2017 rise and published in the Journal of Finance. They argued that new Tether tokens were issued just after price falls. The timing looked like deliberate support, not real demand. Tether's issuer disagrees, and people still argue about it. But this is serious work in a top journal, not a blog post.
For years the industry's own numbers were simply false. A 2019 study given to American regulators found that about ninety-five per cent of reported trading volume was fake. This is called wash trading: exchanges trade with themselves to look busy. This has improved a lot, thanks to regulated exchanges and the ETFs. Few people notice that change.
The market itself makes this easy, and the reasons are simple. It never closes and nothing can pause it. The order books are thinner than the reported volume suggests — the liquidity is thin. Ordinary traders can borrow fifty or a hundred times their own money, which is called leverage. So one big sell order can force many other traders to sell too. Each forced sale is a liquidation. The price then falls much further than that first order deserved. You do not need a plot for this. You need a big order and a thin book.
There is an awkward mirror here, and the page should not walk past it. Section 02 complained about normal money. The complaint was this: a few people nobody elected decide things that change everyone's savings. Now look at sections 08 and 09. A few large holders and a few mining pools do something similar. Nobody elected them either. Bitcoin removed the committee. It did not remove concentration. Open systems concentrate — that is what seventeen years does to them. This does not disprove the main claim. Nobody can print more coins, and that was the real promise. But it is far from a network with no powerful players in it.
"The whales did it" is also the easiest story to tell. Usually there is no way to prove it wrong. People use it after the event, for a rise or a fall, whichever happened. And it is comforting. It says you lost money to a rigged game. The duller truth is that this asset often moves twenty per cent in a week for no reason at all.
Meanwhile the coins keep spreading out. Regulated funds now report their holdings every day, so the biggest holders are easier to see than ever before. Both things are true at once. The market has been manipulated. And most days it is simply volatile.
- A public ledger measures the coins exactly. It still cannot tell you how many people own them. Where else have you seen a number that looks exact but answers the wrong question?
- Three to four million coins are lost forever. Does that make the rest more valuable? Or does it tell you something about how easy the system is to use?
- "The whales did it" can explain a price going up or down. What evidence would convince you that one particular crash was manipulation, and not just panic?
The engineering is finished. The argument is not.
For seventeen years, bitcoin has done what it was built to do, without stopping. Does that make it money? That is a separate question. The answer depends on one test. Will people still hold it through ten boring years? Nothing on this page settles that. Anyone who tells you it does is selling something.
十七年来,比特币一直在做它被设计来做的事,从未停机。但这是否让它成为“货币”是另一个问题,答案取决于在它变得平淡无奇的那十年里,人们是否还愿意继续持有。本页无法给出结论,而任何声称能给出结论的人,多半是在推销什么。
สิบเจ็ดปีที่ผ่านมา บิตคอยน์ทำสิ่งที่มันถูกสร้างมาให้ทำโดยไม่เคยหยุดเลย แต่นั่นทำให้มันเป็นเงินหรือไม่เป็นคนละคำถาม และคำตอบจะมาจากว่าผู้คนยังถือมันต่อไปหรือเปล่าในทศวรรษที่มันน่าเบื่อ หน้านี้ไม่ได้ตัดสินเรื่องนั้น และใครก็ตามที่บอกว่าตัดสินได้ มักกำลังขายอะไรบางอย่างอยู่
Separate the two things one last time. Nearly every bad argument about bitcoin comes from gluing them together.
The engineering question is closed. A network with no owner has processed payments since January 2009 without stopping. Nobody has ever rewritten it. It kept running while most of the companies around it collapsed. It solved the problem it set out to solve. You tested a small version of it yourself in section 04.
The money question is wide open, and it is not technical at all. Here it is. Can a thing hold value across a human lifetime, when it has no issuer, no income, no legal status, and only seventeen years behind it? The code cannot answer that. Only behaviour can. Will people keep holding it through ten years in which nothing interesting happens? That is the one test it has never faced.
The idea this page opened with survives, but in a smaller form than people usually claim. This much is true and well evidenced. When someone could make more of the money, they did — in Rome, on Yap, in West Africa, and in every currency your grandparents saved in. It is also true that the last outside limit came off in 1971, and that debt and prices have climbed since.
But one thing does not follow from that. It does not prove that a fixed-supply digital asset is the answer. The book asks you to accept that without quite arguing for it. Getting the illness right is not the same as getting the cure right. This page has tried to keep those two apart on every claim it makes.
Gold's whole case is that people did not abandon it for five thousand years. Nobody can make that argument any faster.
This page has tried to do one thing above all: show you the joins. Which claims can you check on your own laptop? Which come from a study you can go and read? And which are somebody's opinion dressed as a fact? The coloured labels on every box are there for exactly that. If you take one habit away from this page, take that one. It works on the next thing you read about bitcoin, and the one after that. Most of them will not show you the joins.
- The system has run without stopping since 2009. Whether it is money is still an open question. What would you need to see before you called it settled, either way?
- This page labels its claims verifiable, contested or argument. Take the last article you read about anything, and label its paragraphs the same way. How much survives?
- Everything in the design worked as planned. The result is still a country-sized electricity bill and a handful of huge holders. Is that a fault in the design, or a fact about people?