// case file . 1976-2026

Who wrote Bitcoin ?

The story of an invention, and the forensic investigation into the ghost who signed it.

$ whois bitcoin.org _

On 31 October 2008, an unknown figure posts nine pages to a mailing list of cryptographers. Eighteen years later, Bitcoin is worth trillions of dollars and its author still has no face. But he left traces: e-mails, code, a whois, timestamps, verbal tics. This site gathers them, in order, from the cryptographic foundations to the Sakura House lead.

summer 2008

It is July 2008. The world is going through an unprecedented financial crisis.

In the United States, high-risk home loans, the infamous subprimes, have poisoned the entire banking system. In the spring, the investment bank Bear Stearns, more than eighty years old, collapsed over a single weekend and was bought for a pittance. In July, it is the bank IndyMac that goes under. Markets plunge, and savers, shareholders, entire pensions watch their savings go up in smoke.

Somewhere in the world, a computer scientist watches this shipwreck and asks himself a simple question: how, exactly, does money work? He starts searching, reading, understanding. And what he finds staggers him.

Money is thin air. Most of the money in circulation is not printed by a state: it is created on demand by banks, every time they grant a loan. A loan is signed, and the sum appears, out of nothing, through a simple bookkeeping entry. When the loan is repaid, that money disappears. The money supply is only a promise, inflated or deflated according to confidence, and it is precisely that confidence which has just collapsed.

Going back in time, he also discovers that it was not always this way. For decades, currencies rested on the gold standard: each banknote was a promise, exchangeable for a precise quantity of gold. Citizens thus had the guarantee that their national currency was backed by a real metal, scarce, impossible to manufacture at will. The Bretton Woods agreements, in 1944, had even built the entire post-war system on this anchor: the dollar remained convertible into gold at a fixed price, and other currencies were pegged to the dollar.

Then, on 15 August 1971, the American president Richard Nixon suspended that convertibility. Within a few years, over the course of the 1970s, the link between money and gold was severed for good. Since then, no major currency has been guaranteed by anything tangible: its value rests solely on confidence and on the decree of the state. This is what is called fiat money, and it is fiat money that the 2008 crisis lays bare.

He then decides to offer the world another solution. A currency that would depend on no state and no bank. A currency whose every transaction would be recorded publicly, and therefore traceable, but where the users would be only pseudonyms, and therefore anonymous. A currency that anyone could create, not by granting loans, but by putting their computer to work.

The Bitcoin program

The first official version of the software appears in January 2009. On 3 January, the computer scientist engraves in the very first block, the genesis block, a headline from the London Times published that same day: "The Times 03/Jan/2009 Chancellor on brink of second bailout for banks": the chancellor on the verge of bailing out the banks a second time. The message is crystal clear: while states prepare to save the system with money conjured from thin air, he proposes the opposite. Six days later, on 9 January 2009, version 0.1 of the program is released.

This first program is rudimentary and fascinating. To find other participants, it connects to the discussion server IRC chat.freenode.net and joins a channel called #bitcoin: each node publishes its IP address there, encoded in base58 as a pseudonym, and reads those of the others to link into the network. Once connected, the computer runs the calculations, and each block solved then earns 50 BTC for whoever found it.

$ bitcoin :: connecting chat.freenode.net / JOIN #bitcoin ... node found / block solved +50.00 BTC _
Main window of the Bitcoin v0.1 client: balance and transactions The Send Coins box of the Bitcoin v0.1 client
The original v0.1 client: the main window and the "Send Coins" box. wxWidgets interface, on Windows. You send coins to a Bitcoin address or directly to an IP address.

Sissa's chessboard, in reverse

To understand how bitcoins come into being, you need to know an old Indian legend. One clarification first: Sissa did not really invent chess — the origin of the game, somewhere in sixth-century India, remains unknown — but the legend credits him with a famous request for a reward. A bored king demanded a game to entertain himself; he was presented with the chessboard, and he offered the sage Sissa the reward of his choice. Sissa asked for something modest in appearance: one grain of wheat on the first square, two on the second, four on the third, and so on, doubling on each square. The king agreed with a smile... before discovering the scale of the calculation. On the 64th and final square, 2^63 grains would have to be placed, and the total reaches 2^64 - 1 grains, more than millennia of the world's harvests. That is the dizzying power of doubling.

64 squares. You double on each square: from 1 grain to 2^63, that is 2^64 - 1 grains in total. Bitcoin applies the reverse operation.

Sissa · ×2 (we multiply)

  • square 011 grain
  • square 642^63 grains
  • total2^64 - 1 = 18 446 744 073 709 551 615

Bitcoin · ÷2 (we divide: halving)

  • start50 BTC = 5 000 000 000 sat
  • halving 321 satoshi
  • halving 330 → issuance ended
  • total21 000 000 BTC, and not one more

Bitcoin takes up exactly this principle, but in reverse. Where Sissa multiplies by two, Bitcoin divides by two. The reward per block starts at 50 BTC, then it is halved every 210 000 blocks, roughly every four years: 50, then 25, then 12.5, then 6.25... These events are called halvings. And Satoshi's code allows for at most 64 halvings: 64, like the 64 squares of the chessboard.

But in practice, we will never reach 64. Because a bitcoin is not infinitely divisible: its smallest unit is the satoshi, one hundred-millionth of a bitcoin. The starting reward, 50 BTC, is therefore worth 5 000 000 000 satoshis, a number that just fits within 33 bits. Now, each halving is nothing other than an integer division by two. Starting from five billion satoshis and dividing each time, you reach the smallest possible value, 1 satoshi, by the 32nd halving. The next halving, the 33rd, would round that last satoshi down to zero: issuance stops. So the reward can really only be divided 32 times, far short of the 64 squares, and the very last satoshi will be mined around 2140.

All these rewards added together converge toward a strict limit: 21 million bitcoins. It is the answer of an anonymous computer scientist to a world where money could be created endlessly, out of thin air.

Why 21 million? This number appears nowhere in the original code. Version 0.1 fixes only three values: a 50 BTC reward, a halving every 210 000 blocks (the line nSubsidy >>= (nBestHeight / 210000)) and divisibility down to one hundred-millionth (COIN = 100000000). The total follows mechanically: 210 000 × 50 × 2 = 21 000 000. It is not a value set directly, but the sum of these three settings, which Satoshi himself described as an educated guess. The number is neither half of 42 nor an allusion to blackjack: it results from the geometric series of the halving. Set against the world population of 2008, roughly 6.7 billion people, it represents nearly 0.003 BTC, or some 313 000 satoshis, per person, far from the "1 specialdollar per person" sketched under Szabo's banknote.

timeline

  1. 1976Diffie-Hellman, public-key cryptography
  2. 1982David Chaum, untraceable payments (eCash)
  3. 1986The Mentor, the Hacker Manifesto in Phrack
  4. 1993Eric Hughes, A Cypherpunk's Manifesto
  5. 1996e-gold: a digital currency backed by gold
  6. 1997Adam Back, Hashcash, the proof of work
  7. 1998Wei Dai, b-money . Nick Szabo, bit gold
  8. 1999Elon Musk founds X.com, the future PayPal
  9. 2007PayPal, Visa, Mastercard, American Express dominate online payments and take a commission on every transaction
  10. 200818 August: bitcoin.org registered via AnonymousSpeech
  11. 200831 October: the whitepaper on the metzdowd list
  12. 20093 January: genesis block, "Chancellor on brink of second bailout"
  13. 2011"I've moved on to other things." Satoshi disappears
  14. 2024High Court of London: Craig Wright is not Satoshi

chapters

01 1976 . 1997 Cryptography, the foundations Public keys, hash functions, digital signatures. Without these three building blocks, no electronic money is possible. 02 1994 . 2002 Paying online: the commercial attempts CyberCash, e-gold, X.com, PayPal. While the cypherpunks dream of anonymity, online commerce invents digital payment, but always through a trusted third party. 03 1988 . 1993 The cypherpunk manifesto A mailing list, libertarian mathematicians, and one conviction: privacy is defended with code, not with laws. 04 1997 Hashcash, the proof of work Adam Back wants to fight spam by making each email slightly costly to produce. Bitcoin will turn it into its consensus engine. 05 1998 b-money, Wei Dai's plan A short text, posted on the cypherpunks list, that describes almost everything: money created by computation, a distributed ledger, pseudonyms. 06 1998 . 2005 Bit gold, Nick Szabo's gold Timestamped chains of proofs of work, ownership recorded in a distributed way. The plan closest to Bitcoin. 07 2008 The cryptography list and the whitepaper On October 31, 2008, an unknown person posts nine pages on the metzdowd list. No one knows who he is. No one ever really will. 08 18.08.2008 Forensics: bitcoin.org and AnonymousSpeech The domain is registered ten weeks before the whitepaper, through an anonymization service. The whois points to Sakura House in Tokyo, and the technical contact to Osaka. 09 2003 . 2016 The shadow provider: AnonymousSpeech & Vistomail Registrar, emails, cash payment: all of Satoshi's anonymity tooling passes through one and the same Japanese ecosystem, and one and the same man, Michael Weber. 10 2009 . 2026 Stylometry, time zones, candidates Double spaces, British English, sleeping hours, omitted citations. What the clues say, and what they do not.