Bitcoin
The first cryptocurrency — a peer-to-peer electronic cash system sealed by proof of work, capped at 21 million coins, and the fifteen-year argument over what to call it.
Bitcoin is a digital currency proposed in a nine-page white paper published on 31 October 2008 under the pseudonym Satoshi Nakamoto. It lets payments travel directly between parties without a financial institution, replacing the trusted third party with a peer-to-peer network that timestamps transactions into a proof-of-work chain. Nodes that validate the chain are rewarded with newly created bitcoins; the reward started at 50 BTC and is halved every 210,000 blocks, so the supply approaches but never exceeds 21 million. Launched in 2009, bitcoin remained a niche of cryptography enthusiasts until prices and media attention surged in 2013 — the year of its first documented all-time high of $1,240 on 4 December. Regulators followed: the IRS treats virtual currency as property (2014), the CFTC called bitcoin a commodity (2015), the ECB published two reports on virtual currency schemes (2012, 2015) and the BIS devoted a chapter of its 2018 Annual Economic Report to the technology's limitations. After a federal court vacated its Grayscale order, the SEC approved 11 spot bitcoin exchange-traded products on 10 January 2024. El Salvador made bitcoin legal tender in 2021. Volatile market figures in this article carry the date of the source that recorded them.
Setting: what bitcoin is and why it matters
Bitcoin is a purely peer-to-peer version of electronic cash, designed so that online payments can be sent directly from one party to another without going through a financial institution.1 The system was proposed in a nine-page white paper published on 31 October 2008 under the pseudonym Satoshi Nakamoto.1 The concept of permissionless cryptocurrencies was set out for the case of Bitcoin in that paper by an anonymous programmer or group writing under the same pseudonym, who proposed a currency based on a specific type of distributed ledger: the blockchain.2
NIST records that blockchain technology became widely known in 2009 with the launch of the Bitcoin network, the first of many modern cryptocurrencies.3 The Chicago Fed dates the launch to 2009 as well, describing a digital currency that had recently attracted much attention.4 The protocol fixes the supply in order to counter debasement: no more than 21 million bitcoins can exist.2
Within a decade of the paper, more than 1,000 cryptocurrencies were developed, among them Ethereum, Ripple and Litecoin.5 A 2016 survey in IEEE Communications Surveys & Tutorials observed that bitcoin, besides attracting a billion-dollar economy, revolutionised the field of digital currencies and influenced many adjacent areas.6 The Bitcoin Core project maintains and releases the client software, a direct descendant of the original program released by Satoshi Nakamoto after he published the white paper.7
Before bitcoin: digital cash and the double-spending problem
To confirm the absence of a double-spend without a trusted party, the payee needs proof that the majority of nodes agreed a transaction was the first received.1 The white paper opened from an electronic coin defined as a chain of digital signatures, in which each owner transfers the coin by signing a hash of the previous transaction and the public key of the next owner.1 It then added a timestamp server: each timestamp includes the previous timestamp in its hash, forming a chain in which every additional timestamp reinforces the ones before it.1
The usual alternative, a trusted central mint through which every transaction passes like a bank, was rejected on the ground that the fate of the entire money system would depend on the company running the mint.1 The proposed replacement was a peer-to-peer network that timestamps transactions by hashing them into an ongoing chain of hash-based proof of work, forming a record that cannot be changed without redoing the work.1 Nodes may leave and rejoin the network at will, accepting the longest proof-of-work chain as proof of what happened while they were gone.1
Decentralised settlement has a hard boundary: as the BIS notes in the words of the original paper, a cryptocurrency can overcome the double-spending problem in a decentralised way only if honest nodes control a majority of computing power.2 For its part, the Chicago Fed's primer notes that bitcoin does not rely on a single recordkeeper.4
Callout: what a blockchain is
Blockchains are tamper-evident and tamper-resistant digital ledgers implemented in a distributed fashion, without a central repository and usually without a central authority such as a bank, a company or a government.3 NIST attributes to them an append-only record of full transactional history, so that, unlike traditional databases, transactions and values are not overridden.3
In Bitcoin's own documentation, the block chain provides the public ledger: an ordered and timestamped record of transactions.8 Each block stores the hash of the previous block's header, and that is what chains the blocks together.8
How a payment works: keys, addresses and UTXOs
Every bitcoin transaction has at least one input and one output, and each input spends the satoshis paid to a previous output.9 Each output then waits as an unspent transaction output, a UTXO, until a later input spends it.9 What a wallet reports as a 10,000 satoshi balance is really 10,000 satoshis waiting in one or more UTXOs.9
Bitcoin uses the Elliptic Curve Digital Signature Algorithm (ECDSA) with the secp256k1 curve, and secp256k1 private keys are 256 bits of random data.9 Ownership is expressed in scripts: an output pays an amount in satoshis to a conditional pubkey script, and anyone who can satisfy those conditions can spend up to the amount paid to it.9 A single transaction can create multiple outputs, but each output of a particular transaction can be used as an input only once in the block chain.8
Payments can be verified without running a full network node, by keeping a copy of the block headers of the longest proof-of-work chain and the Merkle branch linking a transaction to the block it is timestamped in.1 Privacy rests on keeping public keys anonymous: the public can see that an amount is sent from someone to someone else, but without information linking the transaction to anyone.1 The paper likens this to a stock exchange's tape, where the time and size of individual trades are published without naming the parties.1 NIST sums up the operation: users digitally sign and transfer rights to information representing electronic cash, and the blockchain records the transfer publicly so that all participants can independently verify its validity.3
The engine room: mining, proof of work and difficulty
Proof of work involves scanning for a value that, when hashed, begins with a number of zero bits; the average work required is exponential in the number of zero bits, but a single hash is enough to verify it.1 Once that effort has been spent, a block cannot be changed without redoing the work, which would include redoing all the blocks chained after it.1 Proof of work is essentially one-CPU-one-vote, and the majority decision is represented by the longest chain, the one with the greatest proof-of-work effort invested in it.1 Spent transactions can eventually be discarded to save disk space, because transactions are hashed in a Merkle tree with only the root included in the block's hash.1
Difficulty compensates for faster hardware and varying interest in running nodes: a moving average targets an average number of blocks per hour, and the difficulty increases if blocks are generated too fast.1 Nodes accept a block only if all transactions in it are valid and not already spent, and they always consider the longest chain correct, working to extend it.1 When two versions of the next block circulate, the tie breaks when the next proof of work is found and the miners of the losing branch switch over.1
Every ten minutes, in the Chicago Fed's plain-language account, the nodes called miners gather recently broadcast transactions and try to add them to the universal ledger of bitcoin transactions.4 Mining software sends an 80-byte block header to mining hardware, an ASIC, along with a target threshold, and the hardware returns the header with the successful nonce when a hash below the target is found.10 Pooled mining sets a target far easier than the network's, so miners return many shares proving they checked a share of the possible hash values, and the shares that also fall below the network target go to the network.10 Solo mining keeps the whole block reward and the transaction fees, at the cost of large but high-variance payments with longer gaps between them.10
Issuance: the 21-million cap and the halving
By convention, the first transaction in a block is a special transaction that starts a new coin owned by the block's creator, which rewards nodes and provides a way to distribute coins initially, since there is no central authority to issue them.1 That reward started at 50 bitcoins and is halved every 210,000 blocks, about every four years at six blocks per hour, so the total number of bitcoins approaches but never exceeds 21 million.4 The unit is divisible to eight decimal places, which enables its use in any kind of transaction regardless of value; the smallest unit is 0.00000001 BTC.11
Transaction fees supply the rest of the incentive: the difference between a transaction's output value and its input value becomes the fee, and once a predetermined number of coins have entered circulation the incentive can shift entirely to fees and be completely inflation free.1 Since entry to mining is free, the value of the resources spent on mining tends toward the market value of the bitcoins produced, whose number per day does not depend on the size of the network.4 The paper's security argument is economic: a greedy attacker ought to find it more profitable to play by the rules and be favoured with more new coins than to undermine the system and the validity of his own wealth.1
Milestones: dated events in bitcoin's history
The documented record begins with the white paper of 31 October 2008 and the network launched the following year.1 The first central-bank report followed in October 2012.11 The first spot bitcoin ETP approvals came more than a decade later, on 10 January 2024.12
| Date | Event | How it is documented |
|---|---|---|
| 31 October 2008 | The white paper proposing peer-to-peer electronic cash is published1 | Nine-page paper signed Satoshi Nakamoto1 |
| 2009 | The Bitcoin network launches as the first of many modern cryptocurrencies3 | NIST: the first blockchain-based cryptocurrency3 |
| October 2012 | The ECB publishes the first central-bank report on virtual currency schemes11 | Definition of virtual currency; bitcoin studied as the main case11 |
| 11 March 2013 | An erroneous software update splits the network into two blockchains for several hours2 | BIS: reversed by centralised coordination of the miners2 |
| 4 December 2013 | Bitcoin's first documented all-time high, at $1,24013 | Recorded in the ECB report of 201513 |
| December 2013 | The Chicago Fed measures a young market: about 11.8 million coins and $1 billion in total value4 | Chicago Fed Letter No. 317, Bitcoin: A Primer4 |
| February 2014 | The world's biggest bitcoin exchange closes13 | ECB: among the episodes behind swings in attention and price13 |
| March 2014 | The IRS rules that virtual currency is property14 | Notice 2014-21 states the treatment for federal tax purposes14 |
| February 2015 | The ECB publishes a further analysis of virtual currency schemes13 | Follow-up report: innovation and risks13 |
| 17 September 2015 | The CFTC finds for the first time that bitcoin and other virtual currencies are commodities15 | Order against the Coinflip/Derivabit options platform15 |
| 2015 | MIT founds the Digital Currency Initiative16 | First university group focused on bitcoin16 |
| 24 June 2018 | The BIS devotes a chapter of its Annual Economic Report to cryptocurrencies2 | Chapter V: Cryptocurrencies: looking beyond the hype2 |
| October 2018 | NIST publishes Blockchain Technology Overview3 | NISTIR 8202: definitions and bitcoin's place as the first blockchain-based cryptocurrency3 |
| June 2021 | El Salvador legislates bitcoin as legal tender alongside the dollar17 | International Trade Administration report17 |
| 10 January 2024 | The SEC approves 11 spot bitcoin ETPs12 | Rule 19b-4 approvals after a court vacated the Grayscale order18 |
Institutions respond: central banks, tax authorities and regulators
The ECB's 2012 report defined a virtual currency as a type of unregulated, digital money, issued and usually controlled by its developers, and used and accepted among the members of a specific virtual community.11 It classified bitcoin as a type 3 scheme, one with bidirectional flows that behaves like any other convertible currency and can be used to buy virtual and real goods and services.11 The report called bitcoin probably the most successful, and probably the most controversial, virtual currency scheme to date.11 It noted the absence of a central authority in charge of the money supply, of a central clearing house and of financial institutions in the transactions, since users perform those tasks themselves.11
The follow-up report of February 2015 confirmed that virtual currency schemes can support financial innovation and provide additional payment alternatives for consumers, but said they also entail risks.13 It analysed bitcoin as an example of a decentralised scheme, in contrast with issuer-controlled centralised schemes.13

For United States federal tax purposes, the IRS treats virtual currency as property, and the general tax principles for property transactions apply.14 The guidance describes virtual currency as a digital representation of value that functions as a medium of exchange, a unit of account or a store of value, without legal tender status in any jurisdiction.14 It gives bitcoin as an example of a convertible virtual currency that can be digitally traded between users and bought or exchanged for dollars, euros and other currencies.14 In September 2015 the CFTC found for the first time that bitcoin and other virtual currencies are properly defined as commodities, in an order against a bitcoin options platform.15
For the SEC the road was longer: beginning under Chair Jay Clayton in 2018 and through March 2023, the Commission disapproved more than 20 exchange rule filings for spot bitcoin ETPs.18 A federal appeals court then found that the SEC had failed to adequately explain its disapproval of Grayscale's proposed ETP, vacated the order and remanded the matter.18 The Commission approved the listing and trading of a number of spot bitcoin exchange-traded product shares on 10 January 2024, a step Gensler called the most sustainable path forward.18 Gensler stressed that the action was cabined to ETPs holding one non-security commodity, bitcoin, and should not signal a willingness to approve listing standards for crypto asset securities.18 Commissioner Uyeda concurred with the approval, but wrote that the order invents a novel, previously unarticulated standard, and objected that the Commission had made it virtually impossible for an exchange to establish that the relevant bitcoin futures market is of significant size.19 The Congressional Research Service recorded 11 spot Bitcoin ETP applications approved under Rule 19b-4, the first spot bitcoin ETPs after proposals had circulated for more than a decade.12
The adoption edge case is El Salvador's: in June 2021 the country legislated that bitcoin become legal tender within 90 days, alongside the dollar.17 The government announced a state wallet named Chivo, with an initial $30 in bitcoin to stimulate its use.17
In their own words
The paper states the trust assumption plainly: the system is secure as long as honest nodes collectively control more CPU power than any cooperating group of attacker nodes.1
A purely peer-to-peer version of electronic cash would allow online payments to be sent directly from one party to another without going through a financial institution.
Satoshi Nakamoto, Bitcoin: A Peer-to-Peer Electronic Cash System, 2008
today's Commission action is cabined to ETPs holding one non-security commodity, bitcoin. It should in no way signal the Commission's willingness to approve listing standards for crypto asset securities.
Gary Gensler, SEC Chair, 10 January 2024
a virtual currency is a type of unregulated, digital money, which is issued and usually controlled by its developers, and used and accepted among the members of a specific virtual community
European Central Bank, Virtual Currency Schemes, October 2012
While there is a lot of excitement surrounding Bitcoin and other virtual currencies, innovation does not excuse those acting in this space from following the same rules applicable to all participants in the commodity derivatives markets.
CFTC director of enforcement, Release 7231-15, 17 September 2015
Fiduciary currencies—in contrast with commodity-based currencies (such as gold coins or bank notes redeemable in gold)—have no intrinsic value and derive their value in exchange either from government fiat or from the belief that they may be accepted by someone else.
Federal Reserve Bank of Chicago, Bitcoin: A Primer, December 2013
a cryptocurrency can overcome the double-spending problem in a decentralised way only if "honest nodes control a majority of [computing] power"
BIS Annual Economic Report 2018, quoting the original white paper
An ordered, timestamped record of transactions that participants verify independently is the thread running through the quotations above.8
Money, asset or speculation? The economics debate
The BIS frames the question through the three functions of money: a unit of account, a medium of exchange and a store of value.2 To fulfil those functions, money needs to have the same value in different places and to keep a stable value over time.2
The Chicago Fed's primer classes bitcoin as a fiduciary currency: in contrast with commodity-based currencies such as gold coins, it has no intrinsic value and derives its value in exchange from the belief that it may be accepted by someone else.4 At the primer's December 2013 vintage, total balances held as bitcoins stood at around $1 billion, against $1,200 billion circulating in United States currency.4 The December 2013 count of coins was around 11.8 million.4
A 2016 survey in IEEE Communications Surveys & Tutorials judged that bitcoin attracted a billion-dollar economy while revolutionising the field of digital currencies and influencing many adjacent areas.6 A 2019 paper in Frontiers in Energy Research complained that the scientific literature offered only rough and incomplete estimates of the current and future energy consumption of the Bitcoin network, and proposed a scenario model to estimate mining power demand.5 The research response followed: MIT founded the Digital Currency Initiative in 2015 as the first university group focused on bitcoin, advancing the security, scalability and privacy of digital currency systems.16 The older literature had its own version of the question: in a 1918 treatise on monetary value, Benjamin M. Anderson argued that the value of money is a quality of money itself, the quality it shares with other forms of wealth.20
Criticisms and open problems: volatility, energy and illicit use
For users, the ECB listed drawbacks: lack of transparency, clarity and continuity; high dependency on IT and on networks; anonymity of the actors involved; and high volatility.13 Its 2015 report also recorded the all-time high of $1,240 on 4 December 2013, reached as media attention grew during the Cyprus banking crisis of March–April 2013.13 It added the February 2014 closing of the world's biggest bitcoin exchange to the episodes behind swings in attention and price.13
At the time of its 2018 chapter, the BIS reported that the total electricity use of bitcoin mining equalled that of mid-sized economies such as Switzerland.2 The Bitcoin blockchain was then growing at around 50 GB per year and stood at roughly 170 GB.2 It argued that, much in contrast to bitcoin's original promise, many users who turned to cryptocurrencies out of distrust in banks and governments wound up relying on unregulated intermediaries.2 As evidence that demand was not entirely wholesome, it cited bitcoin's strong market reaction to the shutdown of Silk Road, a major marketplace for illegal drugs, suggesting a non-negligible fraction of demand from illicit activity.2 The chapter also warned that a cryptocurrency can simply stop functioning, resulting in a complete loss of value.2
The scale critique is older than the price record: the Chicago Fed's primer counted about 30 bitcoin transactions per minute, against an average of 200,000 per minute for Visa, in its December 2013 reading.4 The trust record has an awkward entry: on 11 March 2013 an erroneous software update split the network into two blockchains for several hours, and the episode was undone by centralised coordination of the miners.2
Bitcoin in numbers
The supply ceiling of 21 million bitcoins is the one figure in this article that never changes.4 Every other number below is a dated snapshot, and the newest entry is the approval of 11 spot ETPs in January 2024.12
| Figure | Value | As of |
|---|---|---|
| Maximum supply | 21,000,000 BTC4 | 2013 primer4 |
| Initial block reward | 50 BTC, halved every 210,000 blocks4 | 2013 primer4 |
| Smallest unit | 0.00000001 BTC, eight decimal places11 | 2012 ECB report11 |
| Coins in circulation | ≈11.8 million4 | December 20134 |
| Total value held | ≈$1 billion, against ≈$1,200 billion in United States currency4 | December 20134 |
| Average price | a little over $1004 | six months to December 20134 |
| Transaction rate | ≈30 per minute, against ≈200,000 per minute for Visa4 | December 20134 |
| Documented all-time high | $1,240 on 4 December 201313 | ECB report of 201513 |
| Blockchain size | ≈170 GB, growing ≈50 GB per year2 | 2018 BIS chapter2 |
| Mining electricity | equal to a mid-sized economy such as Switzerland2 | 2018 BIS chapter2 |
| Spot bitcoin ETPs approved in the United States | 1112 | January 202412 |
Timeline: from the 2008 white paper to spot bitcoin ETPs
The Bitcoin white paper is published
An anonymous author writing as Satoshi Nakamoto publishes a nine-page paper, Bitcoin: A Peer-to-Peer Electronic Cash System, proposing payments sent directly between parties without a financial institution.
The Bitcoin network launches
NIST records that blockchain technology became widely known in 2009 with the launch of the Bitcoin network, the first of many modern cryptocurrencies; the Chicago Fed dates bitcoin's launch to 2009 as well.
The ECB publishes the first central-bank report on virtual currency schemes
The European Central Bank defines virtual currency as unregulated digital money issued and usually controlled by its developers, and studies bitcoin as its main case — probably the most successful, and most controversial, scheme to date.
A version split is undone by miners' centralised coordination
An erroneous software update splits the network into two blockchains for several hours; the BIS remarks that the episode was noteworthy because it was undone by centralised coordination of the miners — counter to the idea of achieving trust by decentralised means.
The Chicago Fed measures a small but growing market
Asked to explain the currency, the Federal Reserve Bank of Chicago counts around 11.8 million bitcoins worth about $1 billion in total, with roughly 30 transactions a minute and an average price a little over $100 over the preceding six months.
Bitcoin's first documented all-time high
The ECB's 2015 report records an all-time high of USD 1,240 on 4 December 2013, reached amid heavy media attention that had grown during the Cyprus banking crisis of March–April 2013.
Mt. Gox closes
The closing of Mt. Gox, described by the ECB as the world's biggest exchange for Bitcoin, becomes one of the episodes that shaped swings in media attention and prices.
The IRS rules that virtual currency is property
Notice 2014-21 states that, for federal tax purposes, virtual currency is treated as property; a taxpayer who receives it as payment must include its fair market value in U.S. dollars as of the date of receipt.
The ECB publishes a further analysis
Based on work by Eurosystem central banks during 2014, the follow-up report reiterates that virtual currency schemes can support innovation and extra payment options but entail risks — including high volatility and the anonymity of the actors involved.
The CFTC calls bitcoin a commodity
In an order against the Coinflip/Derivabit options platform, the CFTC for the first time finds that Bitcoin and other virtual currencies are properly defined as commodities covered by the Commodity Exchange Act.
MIT founds the Digital Currency Initiative
The MIT Digital Currency Initiative is founded as the first university group focused on Bitcoin, later expanding to blockchain protocols, central bank digital currencies and other digital assets.
The BIS examines cryptocurrencies in its Annual Economic Report
Chapter V, Cryptocurrencies: looking beyond the hype, records electricity use equal to a mid-sized economy such as Switzerland, a blockchain of roughly 170 GB growing at 50 GB a year, and the limits of decentralised trust.
NIST publishes Blockchain Technology Overview
NISTIR 8202 defines blockchains as tamper evident and tamper resistant digital ledgers implemented in a distributed fashion and usually without a central authority, and explains Bitcoin's role as the first blockchain-based cryptocurrency.
El Salvador legislates bitcoin as legal tender
The U.S. International Trade Administration reports that bitcoin will become a legal tender in 90 days alongside the U.S. dollar, with a state wallet called Chivo and an initial $30 in bitcoin to stimulate use.
The SEC approves the first spot bitcoin ETPs
After a court vacated its earlier Grayscale order, the SEC approves 11 spot Bitcoin ETP rule filings; Chair Gensler stresses the action is cabined to ETPs holding one non-security commodity, bitcoin.
Frequently asked questions
What is bitcoin?
Bitcoin is a purely peer-to-peer version of electronic cash that lets payments be sent directly between parties without going through a financial institution.1 It was proposed in 2008 and launched in 2009, and it was the first blockchain-based cryptocurrency.3
Who created bitcoin?
It was laid out in a white paper by an anonymous programmer or group writing under the pseudonym Satoshi Nakamoto.2 The paper is dated 31 October 2008 and runs to nine pages.1
How many bitcoins will ever exist?
No more than 21 million, because the protocol states the cap and the block reward halves over time.2 The reward started at 50 bitcoins and is halved every 210,000 blocks, about every four years at six blocks per hour, so the total approaches but never exceeds the ceiling.4
How does bitcoin prevent double-spending?
The white paper proposes a peer-to-peer network that timestamps transactions by hashing them into an ongoing chain of hash-based proof of work.1 Decentralised settlement still depends on one condition: honest nodes must collectively control a majority of computing power.2
How are new bitcoins created?
The first transaction in a block starts a new coin owned by the block's creator, because there is no central authority to issue coins.1 That reward started at 50 bitcoins and is halved every 210,000 blocks.4
Are bitcoin payments anonymous?
They are pseudonymous rather than anonymous: the public can see that an amount is sent from someone to someone else, but without information linking the transaction to anyone.1 The paper compares the record to a stock exchange's tape, where trades are published without naming the parties.1
Bitcoin at a glance
Sources & citations
Every factual claim in this article is drawn from the sources below. Bracketed numbers in the text link to the corresponding source.
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20