// document . 31.10.2008
Bitcoin: A Peer-to-Peer Electronic Cash System
The nine pages that start it all. Reference number 1: Wei Dai's b-money. Reference number 6: Adam Back's Hashcash.
On 31 October 2008, Satoshi Nakamoto posted a nine-page document to the metzdowd.com cryptography mailing list, signed with the address satoshin@gmx.com and pointing to www.bitcoin.org. It solves the double-spending problem without a trusted third party, combining digital signatures, chained timestamping and proof-of-work: the longest chain, the one carrying the most computation, is authoritative.
The document is also a map of its influences. Its very first reference is Wei Dai's b-money (1998); its reference number 6, Adam Back's Hashcash (2002). Both men are among the first people Satoshi contacted, a few weeks earlier.
The Hashcash mould
The Bitcoin whitepaper openly borrows the form of the Hashcash paper: the same kind of "academic" cypherpunk publication — an abstract, numbered sections, proof-of-work at the core, a bibliography. Satoshi didn't just reuse Adam Back's idea, he reused its presentation. Compare the two side by side:
↓ bitcoin.pdf (Satoshi, 2008, 9 pp.)↓ hashcash.pdf (Adam Back, 2002, 10 pp.)
… but not the same hand
The mould is shared; the writing is not. A textual analysis of the two PDFs brings out several clear divergences:
Hashcash · Adam Back, 2002
- spelling"favor" (American)
- registerno contractions, very formal
- avg sentence~17 words
- typesettingLaTeX (GNU Ghostscript)
Bitcoin · Satoshi, 2008
- spelling"favour" (British)
- registerfrequent contractions (they'll, can't, he's)
- avg sentence~14 words
- typesettingOpenOffice.org Writer
A measured conclusion: Satoshi clearly read, cited and reused Hashcash, down to copying its presentation. But Satoshi's British spelling against Back's American, his more direct register (full of contractions where Hashcash has none) and a radically different typesetting tool argue for two distinct authors. This is consistent with the rest of the file: Adam Back has always denied being Satoshi, and serious stylometric studies (a University of Aston team, 2014) do not point to him but rather to Nick Szabo. Usual caveat: stylometry on two short texts is not proof, but a convergence of clues.
Below, the whitepaper's abstract and references, reproduced verbatim.
Abstract. A purely peer-to-peer version of electronic cash would allow online payments to be sent directly from one party to another without going through a financial institution. Digital signatures provide part of the solution, but the main benefits are lost if a trusted third party is still required to prevent double-spending. We propose a solution to the double-spending problem using a peer-to-peer network. The network timestamps transactions by hashing them into an ongoing chain of hash-based proof-of-work, forming a record that cannot be changed without redoing the proof-of-work. The longest chain not only serves as proof of the sequence of events witnessed, but proof that it came from the largest pool of CPU power. As long as a majority of CPU power is controlled by nodes that are not cooperating to attack the network, they'll generate the longest chain and outpace attackers. The network itself requires minimal structure. Messages are broadcast on a best effort basis, and nodes can leave and rejoin the network at will, accepting the longest proof-of-work chain as proof of what happened while they were gone.archive → https://bitcoin.org/bitcoin.pdf
[1] W. Dai, "b-money," http://www.weidai.com/bmoney.txt, 1998. [2] H. Massias, X.S. Avila, and J.-J. Quisquater, "Design of a secure timestamping service with minimal trust requirements," In 20th Symposium on Information Theory in the Benelux, May 1999. [3] S. Haber, W.S. Stornetta, "How to time-stamp a digital document," In Journal of Cryptology, vol 3, no 2, pages 99-111, 1991. [4] D. Bayer, S. Haber, W.S. Stornetta, "Improving the efficiency and reliability of digital time-stamping," In Sequences II: Methods in Communication, Security and Computer Science, pages 329-334, 1993. [5] S. Haber, W.S. Stornetta, "Secure names for bit-strings," In Proceedings of the 4th ACM Conference on Computer and Communications Security, pages 28-35, April 1997. [6] A. Back, "Hashcash - a denial of service counter-measure," http://www.hashcash.org/papers/hashcash.pdf, 2002. [7] R.C. Merkle, "Protocols for public key cryptosystems," In Proc. 1980 Symposium on Security and Privacy, IEEE Computer Society, pages 122-133, April 1980. [8] W. Feller, "An introduction to probability theory and its applications," 1957.