₿ BTC Loading... via Binance
Showing posts with label Bitcoin 101. Show all posts
Showing posts with label Bitcoin 101. Show all posts

Monday, July 6, 2026

Bitcoin Has a 21 Million Cap. The Claims Against It Don't.

BitBrainers - Bitcoin paper claims explainer

By BitBrainers Editorial

Bitcoin has a hard cap of 21 million coins. That number is enforced by consensus, secured by energy and cryptography, and cannot be changed without the agreement of the entire network. Satoshi built this constraint into the protocol in 2009 and it has held ever since.

What Satoshi did not build is a constraint on the number of claims that can be created against those 21 million coins. That problem belongs to the financial system, not the protocol. And the financial system is already working on it.

What FTX Actually Proved

In November 2022, FTX collapsed and roughly one million users discovered that the Bitcoin in their accounts did not exist. FTX had lent customer funds to its sister trading firm Alameda Research, which had lost them. The accounts showed balances. The coins were gone.

The popular read was "crypto is risky." The more precise read was: an exchange created claims against Bitcoin it did not hold, nobody audited those claims in real time, and users had no way to know the difference between an IOU and an actual coin.

That is the paper Bitcoin problem in its most extreme form. FTX was not an anomaly. It was a demonstration of what happens when the mechanism is left unchecked.

Every Exchange Balance Is an IOU

When you buy Bitcoin on an exchange and leave it in your account, you do not own Bitcoin. You own a contractual claim against the exchange for Bitcoin. The distinction matters enormously.

If the exchange is solvent and honest, the claim is worth exactly one Bitcoin. If the exchange is insolvent, over-leveraged, hacked, or operating fraudulently, the claim is worth whatever a bankruptcy court decides. That is not the same as holding a private key.

Most exchanges hold actual Bitcoin in reserve to back their customer balances. Most is not all. And reserve levels are not publicly verified on a real-time basis for most platforms. You are trusting an audit that may be months old, conducted by a firm with limited access.

ETFs Are Closer to Bitcoin. They Are Still Not Bitcoin.

The spot Bitcoin ETFs that launched in January 2024 are a genuine improvement over exchange IOUs. For several of the largest US funds, the custodian is Coinbase Custody, holding actual Bitcoin on-chain segregated from other assets.

But the custody chain introduces counterparty risk that does not exist with self-custody. The ETF share is a financial instrument, not a coin. The fund can be lent to authorized participants during the creation and redemption process. The holder has no ability to convert shares into actual Bitcoin or verify that the underlying coins are intact without trusting the custodian and the auditor.

For most institutional investors that tradeoff is acceptable. It is worth knowing it exists.

The protocol is sound. The system around it is not automatically.

We cover what the headlines skip. Every Monday, free.

Subscribe Free

Rehypothecation: The Same Bitcoin in Two Places

Bitcoin-backed lending is growing. Institutions borrow against Bitcoin collateral, just as they borrow against securities or real estate. The problem is rehypothecation: using the same collateral to secure multiple obligations simultaneously.

In traditional finance, securities rehypothecation is legal and common. A stock pledged as collateral at a prime broker can be lent out to a short seller, who delivers it to a buyer, who pledges it somewhere else. The original owner still "has" their shares. So does everyone in the chain. More claims than assets.

Bitcoin rehypothecation is less transparent than traditional finance because it is not subject to the same reporting requirements. There is no central registry of which Bitcoin has been pledged where. The protocol itself is sound, as we covered in our white paper breakdown, but that soundness does not prevent financial layer opacity.

Derivatives: Bitcoin Price Exposure With No Bitcoin

CME Bitcoin futures are cash-settled. When a contract expires, the counterparties exchange dollars based on the settlement price. No Bitcoin changes hands. The price is influenced by instruments that have zero connection to actual coin supply.

This is not unique to Bitcoin. Oil futures, gold futures, and stock index futures are all traded in volumes that dwarf the underlying physical market. But it means a significant portion of Bitcoin "demand" expressed in price discovery is demand for financial exposure, not demand for actual coins.

As derivatives markets deepen, this gap widens. Price can be set by participants who hold no Bitcoin and have no intention of ever holding any.

How Big Is Paper Bitcoin? Nobody Knows.

This is the honest answer. There is no public aggregate figure for total Bitcoin claims versus actual circulating coins. Glassnode estimates roughly 3 to 4 million BTC are permanently lost to forgotten keys. Circulating supply is approximately 19.8 million. Claims through exchanges, ETFs, lending desks, and derivatives are not audited in aggregate anywhere.

What we do know: exchange reserves have been falling for years and now sit at a seven-year low of 2.21 million BTC. That means less Bitcoin is sitting on exchanges than at any point since 2017. Whether that reflects genuine self-custody adoption or simply migration to different custodial structures is not clear from on-chain data alone.

What This Means in Practice

Bitcoin's protocol is not broken. The 21 million cap is real and mathematically enforced. Saylor is right on this. But the financial system building around Bitcoin is creating leverage, opacity, and periodic credit risk that the protocol was never designed to prevent.

Gold went through the same process. Banks created paper gold through fractional reserve systems for centuries before the gold standard was formally abandoned. The underlying commodity remained scarce. The claims against it did not.

Saylor's own view is more optimistic than this reads. He sees the financial layers forming around Bitcoin as ultimately strengthening it, the same way gold became more useful when banks and credit markets developed around it. The risk section of his manifesto is a warning about how those layers can go wrong, not an argument against them existing. This post is that warning in plain language.

The practical implication is straightforward. The closer your Bitcoin is to the base layer, meaning a private key you control with coins verified on-chain, the more actual Bitcoin exposure you have. The further you get from that, the more you are holding a financial instrument whose value depends on counterparty solvency, not protocol integrity.

Not every holder needs to self-custody. But every holder should understand what they actually own.


Sources

Michael Saylor / Strategy: Bitcoin Evolves by Not Changing — on paper Bitcoin risk
CoinDesk: FTX bankruptcy filing and customer fund misuse — November 2022
Glassnode: Exchange reserve data and on-chain supply metrics
CME Group: Bitcoin futures contract specifications — cash settlement

Disclosure: This article is for informational purposes only and is not financial advice. We may earn commissions from affiliate links. Always do your own research before making investment decisions.

Sunday, July 5, 2026

Most People Have Read the Bitcoin White Paper. Almost Nobody Understood Section 11.

BitBrainers - Bitcoin white paper Section 11 math explained

By BitBrainers Editorial

The Bitcoin white paper is nine pages. Most people who claim to have read it understood eight of them. Section 11 is where Nakamoto stops arguing and starts proving. It is also where most readers quietly stopped following the math and decided to trust the conclusion instead.

This is an honest walkthrough of what Section 11 actually says, what problem it solves, and why the answer to that problem is the reason you wait for six confirmations before treating a Bitcoin transaction as final.

What the First Ten Sections Actually Do

Sections one through ten build the argument. Nakamoto describes the problem with double-spending, introduces the concept of a chain of proof-of-work, explains how nodes reach consensus without a central authority, and walks through the incentive structure that keeps miners honest.

It is a compelling design document. Every piece fits logically. But by Section 10, Nakamoto has only argued that the system should work. Section 11 is where he proves it cannot be broken, mathematically, given a specific assumption about the attacker's share of hash power.

The Problem Section 11 Is Solving

Imagine you receive a Bitcoin payment. The sender broadcasts the transaction, it gets included in a block, and the block gets added to the chain. You ship the goods. Then the sender quietly mines an alternative version of the chain that does not include your transaction, catches up to the honest chain, and broadcasts it. Your payment disappears. The sender has their Bitcoin back.

This is the double-spend attack. It is the fundamental threat Nakamoto needed to make practically impossible for the system to work.

The question Section 11 answers is precise: if an attacker controls q percent of the network's total hash power and the honest chain is already z blocks ahead, what is the probability the attacker ever catches up?

The Gambler's Ruin Problem

Nakamoto frames this as a version of the gambler's ruin problem. A gambler with finite resources plays against a casino with infinite resources. Even if the gambler has a near-even chance of winning each hand, the casino will eventually bankrupt them because the casino can absorb losses and the gambler cannot.

In Bitcoin, the honest chain is the casino. It has more hash power than the attacker by assumption, so it mines blocks faster on average. The attacker is the gambler, trying to close the gap against a chain that keeps moving forward.

Nakamoto models the number of blocks the attacker mines using a Poisson distribution. The Poisson distribution is the right tool here because it models the number of times a random event occurs in a fixed interval when that event has a known average rate. Mining a block is exactly that kind of event.

The attacker mines blocks at rate q. The honest chain mines blocks at rate p, where p plus q equals 1 and p is greater than q. For each block the honest chain adds, Nakamoto calculates the probability the attacker closes the gap entirely and overtakes the chain.

What the Formula Produces

BitBrainers - Nakamoto Section 11 attack probability by confirmation

The result is this: the probability the attacker ever catches up from z blocks behind drops exponentially as z increases. Not linearly. Exponentially. Each additional confirmation multiplies the difficulty of a successful attack.

Nakamoto runs the numbers in Section 11 for a specific scenario. If the attacker controls 10 percent of hash power and the recipient waits for 0 confirmations, the attacker succeeds roughly 45 percent of the time. Wait for 1 confirmation and that drops to around 20 percent. At 6 confirmations with a 10 percent attacker, the probability of a successful double-spend is approximately 0.024 percent — two hundredths of one percent.

At 30 percent attacker hash power, the same 6 confirmations holds the probability in the low double digits, around 10 to 12 percent. It is only when the attacker approaches or exceeds 50 percent that the math breaks down fundamentally, because at that point the expected value of the attack becomes positive.

Six confirmations is not an arbitrary convention. It is the point at which the attack probability becomes economically irrational for any attacker controlling a realistic share of hash power.

This also explains why different participants use different thresholds. A merchant accepting a small payment might accept one or two confirmations — the potential loss is too low to justify waiting. An exchange receiving a large transfer might wait for 20 or 30. Six became the industry default because it represents the rational threshold for a realistic attacker, not because Nakamoto mandated it.

Bitcoin basics without the hand-waving.

Every Monday we break down what actually matters in markets and on-chain. No hopium, no noise.

Subscribe Free

Why This Was a Genuine Intellectual Achievement

Nakamoto did not invent the Poisson distribution or the gambler's ruin problem. Both are classical probability theory. What he did was recognize that these tools mapped precisely onto the double-spend problem and apply them correctly in nine pages.

The insight is that you do not need to prevent attacks from being attempted. You only need to make them unprofitable. The math in Section 11 proves that with honest majority hash power, the cost of a successful double-spend attack grows faster than the potential gain as confirmations increase.

That is the security model. Not cryptography alone. Not decentralization alone. A probability calculation that makes cheating economically self-defeating.

What It Means Today

The model holds as long as no single entity controls more than 50 percent of hash power. That assumption has been under pressure as mining has concentrated in large pools. Two or three major pools coordinating would theoretically cross the threshold.

In practice, the economics still work in Bitcoin's favor. A successful 51 percent attack would destroy the value of the asset the attacker spent resources to mine. The incentive to attack is undermined by the attack's own success. Nakamoto noted this too, in Section 6.

But the honest read is that the security guarantee in Section 11 is a probabilistic one, not an absolute one. Six confirmations makes attack economically irrational under normal conditions. It does not make attack physically impossible.

That distinction is what most white paper summaries quietly omit. Nakamoto did not omit it. He put the exact numbers in a table and let the math speak.

The One Line Worth Remembering

Section 11 closes with this: "We can see that the probability drops off exponentially with z."

That sentence is the entire security argument in eleven words. Every six-confirmation standard, every exchange policy, every custody procedure in the industry is downstream of that one observation. Most people who have "read" the white paper read around it.

Now you have not.


Sources

Satoshi Nakamoto: Bitcoin: A Peer-to-Peer Electronic Cash System (2008)
Bitcoin Wiki: Confirmation — security model and confirmation thresholds
Bitcoin Wiki: Double-spending — attack mechanics and historical context

Disclosure: This article is for informational purposes only and is not financial advice. We may earn commissions from affiliate links. Always do your own research before making investment decisions.

The 21M Debate Is Asking the Wrong Question.

By BitBrainers Editorial Every few years, someone with credentials proposes changing Bitcoin's supply cap. The community erupts. ...

The 21M Debate Is Asking the Wrong Question.