// document . 31.10.2008

Bitcoin: A Peer-to-Peer Electronic Cash System

Satoshi Nakamoto · 31 octobre 2008

The nine pages that start it all. Reference number 1: Wei Dai's b-money. Reference number 6: Adam Back's Hashcash.

On 31 October 2008, Satoshi Nakamoto posted a nine-page document to the metzdowd.com cryptography mailing list, signed with the address satoshin@gmx.com and pointing to www.bitcoin.org. It solves the double-spending problem without a trusted third party, combining digital signatures, chained timestamping and proof-of-work: the longest chain, the one carrying the most computation, is authoritative.

The document is also a map of its influences. Its very first reference is Wei Dai's b-money (1998); its reference number 6, Adam Back's Hashcash (2002). Both men are among the first people Satoshi contacted, a few weeks earlier.

The Hashcash mould

The Bitcoin whitepaper openly borrows the form of the Hashcash paper: the same kind of "academic" cypherpunk publication — an abstract, numbered sections, proof-of-work at the core, a bibliography. Satoshi didn't just reuse Adam Back's idea, he reused its presentation. Compare the two side by side:

↓ bitcoin.pdf (Satoshi, 2008, 9 pp.)↓ hashcash.pdf (Adam Back, 2002, 10 pp.)

… but not the same hand

The mould is shared; the writing is not. A textual analysis of the two PDFs brings out several clear divergences:

Hashcash · Adam Back, 2002

  • spelling"favor" (American)
  • registerno contractions, very formal
  • avg sentence~17 words
  • typesettingLaTeX (GNU Ghostscript)

Bitcoin · Satoshi, 2008

  • spelling"favour" (British)
  • registerfrequent contractions (they'll, can't, he's)
  • avg sentence~14 words
  • typesettingOpenOffice.org Writer

A measured conclusion: Satoshi clearly read, cited and reused Hashcash, down to copying its presentation. But Satoshi's British spelling against Back's American, his more direct register (full of contractions where Hashcash has none) and a radically different typesetting tool argue for two distinct authors. This is consistent with the rest of the file: Adam Back has always denied being Satoshi, and serious stylometric studies (a University of Aston team, 2014) do not point to him but rather to Nick Szabo. Usual caveat: stylometry on two short texts is not proof, but a convergence of clues.

Below, the whitepaper's abstract and references, reproduced verbatim.

Abstract Satoshi Nakamoto . satoshin@gmx.com . www.bitcoin.org
Abstract. A purely peer-to-peer version of electronic cash would allow online
payments to be sent directly from one party to another without going through a
financial institution. Digital signatures provide part of the solution, but the main
benefits are lost if a trusted third party is still required to prevent double-spending.
We propose a solution to the double-spending problem using a peer-to-peer network.
The network timestamps transactions by hashing them into an ongoing chain of
hash-based proof-of-work, forming a record that cannot be changed without redoing
the proof-of-work. The longest chain not only serves as proof of the sequence of
events witnessed, but proof that it came from the largest pool of CPU power. As
long as a majority of CPU power is controlled by nodes that are not cooperating to
attack the network, they'll generate the longest chain and outpace attackers. The
network itself requires minimal structure. Messages are broadcast on a best effort
basis, and nodes can leave and rejoin the network at will, accepting the longest
proof-of-work chain as proof of what happened while they were gone.
archive → https://bitcoin.org/bitcoin.pdf
References Bitcoin: A Peer-to-Peer Electronic Cash System, p.9
[1] W. Dai, "b-money," http://www.weidai.com/bmoney.txt, 1998.
[2] H. Massias, X.S. Avila, and J.-J. Quisquater, "Design of a secure timestamping service with minimal
 trust requirements," In 20th Symposium on Information Theory in the Benelux, May 1999.
[3] S. Haber, W.S. Stornetta, "How to time-stamp a digital document," In Journal of Cryptology, vol 3, no
 2, pages 99-111, 1991.
[4] D. Bayer, S. Haber, W.S. Stornetta, "Improving the efficiency and reliability of digital time-stamping,"
 In Sequences II: Methods in Communication, Security and Computer Science, pages 329-334, 1993.
[5] S. Haber, W.S. Stornetta, "Secure names for bit-strings," In Proceedings of the 4th ACM Conference
 on Computer and Communications Security, pages 28-35, April 1997.
[6] A. Back, "Hashcash - a denial of service counter-measure,"
 http://www.hashcash.org/papers/hashcash.pdf, 2002.
[7] R.C. Merkle, "Protocols for public key cryptosystems," In Proc. 1980 Symposium on Security and
 Privacy, IEEE Computer Society, pages 122-133, April 1980.
[8] W. Feller, "An introduction to probability theory and its applications," 1957.