Experiments · Nobody Owns Money · Chapter 3
What Satoshi Nakamoto solved: a double spend against the longest chain
Everything is computed in your browser; nothing is sent anywhere.
About this experiment
On 31 October 2008 Satoshi Nakamoto sent cryptographers a text of nine pages. Almost nothing in it was new: proof of work came from Adam Back’s Hashcash, the idea of money kept by the whole network from Wei Dai’s b-money. What was new was a way to put these parts together so that strangers who do not trust one another agree among themselves which version of a shared record is the right one.
Every participant keeps the same book of payments. New payments are gathered into a block, and to attach it to the book you have to solve a computational puzzle. Each block refers to the one before, and the network picks the chain with the most work spent on it. To spend one coin twice, a cheat would have to redo every block after his payment faster than the rest of the network.
Below, the merchant waits a few blocks on top of the payment while the cheat quietly builds his own chain in which the coins never left him. The figure under the sliders comes from the formula in section 11 of the whitepaper; the button runs the race block by block.
Who Satoshi was is still unknown. In December 2010 he left his last message on the forum, and after the spring of 2011 nobody heard from him again. In 2014 Newsweek named Dorian Satoshi Nakamoto, who denied it. In March 2024 the High Court in England ruled that Craig Wright was not Satoshi. An HBO film in October 2024 named Peter Todd, who called it nonsense. About a million bitcoins attributed to Satoshi have not moved since.
From the book
Nobody Owns Money · Chapter 3
The Idle God
To rewrite history and spend one coin twice, a crook would have to recompute all the blocks after his payment faster than the rest of the network computes them, that is, to have more computing power than all the honest participants put together. The central bookkeeper was no longer needed. He was replaced by a crowd of strangers, each of whom burned electricity for the reward and thereby guarded the record against all the others.
By the rules, no more than 21 million coins could ever appear. The block reward started at 50 coins and halved every four years. No central bank could print any extra.