WORDS is a monthly journal of Bitcoin commentary. For the uninitiated, getting up to speed on Bitcoin can seem daunting. Content is scattered across the internet, in some cases behind paywalls, and content has been lost forever. Thatâs why we made this journal, to preserve and further the understanding of Bitcoin.
Donate & Download the August 2018 Journal PDF
Remember, if you see something, say something. Send us your favorite Bitcoin commentary.
The Cost & Sustainability of Bitcoin
By Hass McCook
Posted August 1, 2018
This paper was transcribed from a .pdf and the editor did his best to make sure all charts came over in correct fashion. We wanted to include a direct download link to Hassâ paper in case youâd like to see this in the raw whitepaper form.
Foreword
To understand the nature of Bitcoin and its ties to energy (spelled with a lower-case e), one needs to understand the concept and nature of âCapital-Eâ Energy . Energy is the prevailing force in the universe - both Father Time and Mother Nature. It cannot be created or destroyed, only transformed from one state to the other. It is the finite but infinitely divisible, shape-shifting sole ingredient of the universe. Its force cannot be stopped, only harnessed through its good graces. The Big Bang can be considered the âBirth of all Energy and Laws of Natureâ. Bitcoinâs âBig Bangâ was the codified creation of 21 million coins, of which 50 were discovered in the mining of the Genesis Block . Since then, 17 million have been discovered, with the rest to be mined in a predictable manner over time.
Energy is split infinitely into units of lower-case energy and mass (calories, joules, pounds, kilograms etc.), just as Bitcoin is infinitely split into units of bitcoin â no mass, just energy . From here, the link between Energy & Bitcoin becomes evident when looking at Nature and Life, and the economic evolution of humans.
At the most primal level, the first instinct of Life is to survive. Energy is Life, and Life is sustained by energy. Plants get their energy from photosynthesis. Predators do this by consuming more calories than they used to hunt their prey. Human Civilisation has evolved to the point where we can transform Energy into a state of Power (fire, steam, coal, batteries, fuel cells, etc). This has taken us from harnessing fire to cook food millennia ago, to much more capable energy sources now. Thanks to all the energy we produce, Humans now expend their calories in the pursuit of currency and money to purchase their food calories and other things required for survival and store the rest for future use.
There are huge differences between currency and money . Money is finite, whereas currency is not, and can therefore be compared to energy, and retains its stored energy over time. When the Gold Standard was abandoned, our paper currency became backed by nothing but promises. Ever since then, the value of currency has tended to zero, and money to infinity. Currency violates the rules of Energy by being created out of nothing (aside from the comparatively infinitesimal energy used to print out currency and mint coins). Disrespecting nature has led to dangerous levels of global wealth and income inequality, and widespread social and economic suffering. No form of life has defied Energy and survived in the long term, and this has been the case for billions of years.
Cryptocurrency is the â Lifeâ of money, of which Bitcoin was âfirst-lifeâ â literally converting energy into money. It has evolved to keep meeting market needs and sprouted a thriving cryptocurrency ecosystem. Bitcoin was designed to last as long as humans do, wherever they are in the universe with a communications link. Obviously, in the distant future, if humans have stood in the face of Energy and not harnessed it in a clean and renewable way, they will perish. Therefore, as we continue to advance technologically, the Bitcoin Blockchain will be a permanent emissionless store of â monetary energyâ â money secured and proven to be both finite, and earned through hard work (literally, âProof of Workâ), using massive amounts of energy in the process.
Executive Summary and Preface
All data used in this paper is as at Block 534,240, mined on 29 July 2018. Network Difficulty was roughly 5.95 trillion. Hash Rate was roughly 42.6 EH/s. Price on the Bitfinex exchange was roughly USD$8200. The changes in mining ecosystem metrics since January 2015 are shown below:
| Metric | January 2015 | July 2018 | Change |
| $/GH | $0.65 | $0.037 | -94% |
| W/GH | 0.89 | 0.098 | -89% |
| Network Hash Rate | 295.4 | 42587.7 | 14317% |
| Price | $200 | $8,200 | 4000% |
This paper serves to update the assumptions used in a prior version of this research from February 20151, and provides a systematic methodology of modelling the environmental and economic costs of Bitcoin. Furthermore, the paper will provide a thorough discussion on the economics of Bitcoin mining to support the underlying model assumptions. Comparative data with the Gold Mining industry will also be revisited.
Based on the assumptions set forth in this paper, the model has estimated the average cost to mine one bitcoin to be roughly $6,450 . It should be noted that this research is an inductive, bottom-up estimate, with the intent to provide a ball-park estimate. A sensitivity analysis has also been undertaken to demonstrate range of costs under different scenarios, which shows a realistic range of average mining cost of between $5400 (driven by aggressive electricity price assumptions), and $7500 (driven by hash rate increase assumptions). Due to the nature of competition in the Bitcoin mining market, costs that are significantly higher than the market price of Bitcoin can generally be ignored in the short term.
Major Assumption Updates
- The previous version of this research omitted the cost and impact of air-conditioning to the network, so the tonnage of CO2 was underestimated by over a third. It also did not capture the impact of manufacturing, packaging and air-freight transportation of ASIC mining rigs, or the impact involved in the resource extraction or recycling process. The new methodology set forth in this paper captures these items, and the result is a Bitcoin network that exhales 63 million tonnes of CO2 per year â about 0.12% of global greenhouse gas emissions2,3,4 (37 Gt CO2 + 16.5 Gt CO2e). Of the 160,000 TWh of energy generated globally each year5, the Bitcoin Network chews through about 105 TWh/year (0.0661%). It should be noted that all figures include the impact of the manufacture ofASICs, which represent over 50% of all emissions generated.
- In early 2015, the fee market was almost non-existent. In 2015, the average daily minerâs fee revenue was 22.4 BTC. For the six years between 2009 and 2015, the average was only about 15 BTC. In the past 6 months, daily revenue has been very consistent, hovering at just under 50 BTC/day. To that end, this extra revenue has been accounted for in this update.
Acknowledgements
Thank you to Lena KlaaĂen for her review of my methodology and calculations.
Bitcoin Economics
Organizational decision-makers set their strategies in line with their firmâs microeconomic, macroeconomic, and global competitive contexts. In the case of a Bitcoin mining firm, the context is as follows:
- Microeconomy: All other Bitcoin mining firms
- Macroeconomy: All other Bitcoin ecosystem members
Global-Macroeconomy: All other digital and non-digital assets and global fiat monetary systems
This chapter defines the nature of competition within these three contexts and will assert that the nature of competition in the Bitcoin mining industry is perfectly competitive in the long term. This will lead into discussion on the strategic machinations of bitcoin mining firms, through comparison of empirical data and academic theory on firms in perfect competition.
Bitcoin Mining in the Global Monetary Macroeconomic Context
The Global Macroeconomy (GM) is the all-encompassing sum of all monetary systems, from traditional âanalogueâ financial systems, to digital ones like Bitcoin. All exchanges of value, legitimate or not, occur within it. Firms within the Bitcoin mining market service the Bitcoin ecosystem and depend on it being healthy and diverse in order to prosper6 .
â [Accelerated] globalization [has] yielded conditions of considerable oligopoly in the world economyâ7 . Some criticize the legacy system as the inadvertent/deliberate proprietor of global inequality8, 9, with ever-mounting barriers to entry deterring the emergence of competing monetary systems. History shows that Schumpeterian gales of creative destruction eventually blow these barriers away10 . In the case of the GM, this was the invention of The Blockchain, of which Bitcoin11 is the first and largest implementation12 . At that moment in history, the GM effectively split into the pre-2009 âanalogueâ GM, and the parallel digital one. Due to age, complexity, and nationalistic necessity, the legacy GM can only experience bursts of improvement13 and remain a âclosed ecosystemâ14,15 . In the highly competitive-yet-collaborative open-sourced decentralized digital ecosystem, anyone in the world can collaborate with others or create new or copycat ecosystems through the open-source software movement16, ensuring evolution and adaption to changing market needs.
To that end, Bitcoin mining firms operate almost exclusively within the digital Global Macroeconomy, and the Bitcoin Mining Market in particular. They have an eye towards alternative digital ecosystems that are gaining traction in the wider free market, and whether their mining equipment can also mine these alternative digital currencies. The competitive cycle between them and their peers resets roughly every fortnight17 .
Bitcoin Mining in the Bitcoin Macroeconomic Context
The Oxford Dictionary defines an economy as â the state of a country or region in terms of the production and consumption of goods and services, and the supply of moneyâ. Since âcountryâ or âregionâ do not apply to digital ecosystems, it is difficult to use traditional macroeconomics which rely exclusively on the concept of an influential controlling body to analyse them.
Bitcoinâs monetary policy is highly predictable and based on a consensus-based, cryptographically secure, selfmanaging algorithm18 . Bitcoin firms can move to the physical jurisdictions that provide the best incentives (i.e. low power, favourable business and tax laws, etc.). In the legacy global financial system, this option is only available to large multinational corporations19, with most consumer-level participants lacking the mobility to move to the jurisdiction of their choosing20 . This is inherently different in a permissionless, online, jurisdictionagnostic environment.
Bitcoinâs ecosystem is still small and fragile, but its incentive structure becomes more robust as more participants are attracted to the ecosystem6 . Rational Bitcoin miners want to see the demand for their commodity grow organically and sustainably, but this is difficult. Miners mine an intangible digital commodity whose fundamental value relies on a consensus-based economic protocol and network. Its market price is based on the whim of the market. Every shock to the ecosystem, such as failure of wallet services and product providers21, at least 36 exchanges22 including the disastrous MtGox collapse23; online drug markets24, Government crackdowns25 and auctions26; scam-coins27, developers28, even miners themselves29, and everything else in a long list of Bitcoin disasters, has in several cases caused dramatic and sudden movements in the price of the commodity30 . Considering the evidence, Bitcoin is an example of an anti-fragile31 system, with bitcoin achieving year-on-year growth in most key metrics32,33 despite the numerous aforementioned setbacks. When and if the market becomes large enough to be less vulnerable to shocks, consolidation through means of integration and merger-and-acquisition activity amongst firms will be witnessed59, as will be discussed in the next section.
Perfect Competition & Bitcoin Microeconomics
The example of âthe hypothetical firm in a perfectly competitive marketâ is taught in most introductory economics classes. A literature review of primary academic texts34,35,36,37,38,39 identifies nine conditions that define a perfectly competitive market:
| Homogeneous products | no barriers to entry or exit |
| guaranteed property rights | many buyers and sellers |
| non-increasing returns to scale | perfect information |
| zero transaction costs | no externalities |
| perfect factor mobility | Â |
When compared with real world data, the Bitcoin mining market (BMM) does not meet all aforementioned conditions of perfect competition, due to a relatively low number of ecosystem participants, currently resulting in wealth and information asymmetry. However, the BMM is trending towards becoming perfectly competitive as the wider Bitcoin macroeconomy grows, which will now be demonstrated.
As at date of writing, the BMM satisfies six criteria of a perfectly competitive market. Bitcoinâs nature as an open-source, encrypted, distributed ledger means that the blockchain guarantees property rights and homogeneity, at zero or near-zero transaction and storage cost40 . The factors of production (labour, equipment, and capital) are mobile to the extent that only a communication link and a power source is required to participate in the ecosystem. Due to its economic incentive mechanisms11, any mining entity approaching 50% of network hash rate (NHR) would experience non-increasing returns to scale, if not jeopardize its own existence, as witnessed during the GHash.io saga of 201441 . Developing on top of Bitcoin requires no permission, and if entrepreneurs have a good enough idea, securing start-up capital is not a difficult barrier to entry to overcome, with over one billion US dollars invested in Bitcoin start-ups to date42 . Low barriers are also commonplace in very young markets, with imitative entry into the market quite rampant43 . Conversely, barriers to exit are quite low for most market participants except for heavily leveraged or undiversified miners, who risk holding highly specialized computing equipment that may be unable to mine other digital commodities. This is no different to traditional undiversified commodity miners44 .
The satisfaction of the final three conditions relies solely on the growth of the network and passing of time. The current size of Bitcoinâs user base is speculative, and always will be due to its pseudonymous nature. CNBC reported45 that 8% of American adults had invested in cryptocurrency (or, 8% of 250 million people46 = 20 million). Yahoo Finance reported47 that 16.3 million Americans buy and sell bitcoin frequently. Coinbase reports that they have over 20 million users48 . Meanwhile, in some parts of Europe is estimated that an average 4% of consumers use cryptocurrency as a payment method every day as of 2016, with Eastern Europe leading the charge at 11%49 . The numbers play out as follows50:
| Country / Region | Adult Population (millions) | Users as % of Population | No. Bitcoin Users (million) |
| USA | 250.0 | 8% | 20.0 |
| Eastern Europe | 260.7 | 11% | 28.67 |
| France | 56.8 | 4% | 2.27 |
| Germany | 73.4 | 2% | 1.47 |
| UK | 57.6 | 1% | 0.58 |
| Spain | 41.5 | 2% | 0.83 |
| Switzerland | 7.6 | 2% | 0.15 |
| Benelux | 25.8 | 2% | 0.52 |
| Â | Â | Â | Total 54.5 |
Table 1 - No. of Bitcoin Users - High Estimate
When adding US and European numbers, and noting that data for Asia, Africa, Latin America, and Oceania are omitted, a high estimate of over 50 million users can be made. Although this sounds like a market with âmany buyers and sellersâ, 50 million people only accounts for 0.8% of the Worldâs adult population50 . A much lower estimate of between 2.9 million and 5.8 million has been highlighted in a very detailed assessment of the global cryptocurrency market produced by Cambridge University in April 201751 (granted, things have changed dramatically since April 2017 when price was only USD$1000, right before the âbig hypeâ of late 2017, where a significant number of new users would have come into the ecosystem).
From a commercial markets point of view, a strong case can be made that a few participants have an inordinate, albeit temporary, grip over pricing and information. The temporary nature is shown in the table below, comparing wallet balance distribution since December 2014. We can see that there has been a flatting of the distribution of coin holdings away from large wallet balances to much lower balances. As can be seen, coins held in wallets with balances containing between 0.001 to 10 BTC have grown dramatically, and it could be expected to resemble a normal distribution as the decades move on.
Dec-201452 Jun-201853
| Balance | % of all BTC | % of all BTC | Î |
| 0 - 0.0001 | 0% | 0.01% | - |
| 0.001 - 0.01 | 0.02% | 0.12% | 500% |
| 0.01 - 0.1 | 0.16% | 0.73% | 356% |
| 0.1 - 1 | 0.85% | 3.23% | 280% |
| 1 - 10 | 4.76% | 8.70% | 83% |
| 10 - 100 | 26.73% | 25.57% | -4% |
| 100 - 1,000 | 23.40% | 21.80% | -7% |
| 1,000 - 10,000 | 23.40% | 19.92% | -15% |
| 10,000 - 100,000 | 17.02% | 17.28% | 2% |
| 100,000 - 1,000,000 | 3.66% | 2.64% | -28% |
Table 2 - Distribution of Coins (by wallet balance)
Figure 1 - Distribution of Coins (by wallet balance)
It should be noted that all wallets with a balance of over 100,000 coins belong to identified exchanges / custodial wallets53 . The identifiable custodial wallets, alongside their âtotal wallet balance rankâ, is as follows:
| Rank | Custodian | Qty BTC | Rank | Custodian | Qty BTC |
| 1, 441 | Bitfinex | 175,172 | Â | Â | Â |
| 2 | Binance | 174,759 | Â | Â | Â |
| 3 | Bittrex | 117,203 | Â | Â | Â |
| 4 | Huobi | 98,042 | Â | Â | Â |
| 5 | Bitstamp | 97,848 | Â | Â | Â |
| 28 | Coincheck | 34,277 | Â | Â | Â |
| 55, 58, 117, 125, 167 | Kraken | 70,805 | Â | Â | Â |
| 177, 447 | Xapo | 8,911 | Â | Â | Â |
| 264 | AnxPro | 4,712 | Â | Â | Â |
| 353 | Bitmain | 3,372 | Â | Â | Â |
| 255 | BitX.co | 4,966 | Â | Â | Â |
| Identifiable Coins in Custody | Â | 790,067 | Â | Â | Â |
Table 3 - Bitcoin Held in Identifiable Custodial Accounts
The above table does not include coins held in custody by other major custodians such as BitMex, Poloniex, Coinbase, and others. It is expected that a lot of wallets with very large balances are custodial wallets, especially as those wallets have several hundred inputs and outputs over a short period of time, which means that the distribution may be even flatter than demonstrated above. A study of Bitcoin Unspent Transaction Outputs (UTXO) by Unchained Capital54 studying the shift of old coins into new hands over time, noted that 15% of BTC moved out of wallets that had been dormant for 2 to 5 years during the 2017 Bitcoin rally. This trend of a flattening in distribution is expected to continue, as spent bitcoin is spent forever, and needs to be earned back.
Bitcoinâs current major externality is the CO2 emitted by hardware operating and securing the network, which is discussed in depth over the next few chapters. Therefore, as the world moves towards carbon-free energy sources over the coming centuries, in additional to cleaner and more efficient mineral mining and e-waste recycling technology, Bitcoinâs CO2 emission externalities will eventually tend towards zero. Based on strong and predictable trends indicating technological improvements driving down costs of renewables55, as well as the potential for fossil fuels to be priced fairly (i.e. more expensively) under future carbon trading schemes56, we may witness a more expedient migration to renewables. As history has shown several times, the death of an incumbent technology is swift when displaced by something better57 .
Bitcoin is not perfectly competitive in its current state but is very close to becoming so. The first six of the above conditions are met in the short-term, with the last three destined to be met (if not already partially met), should Bitcoin have a âlong-termâ.
Most importantly, in a perfectly competitive environment, marginal cost to produce a good (MC) is equal to the marginal revenue from selling that good (MR), i.e., in long-term equilibrium, cost to mine will be equal to the price of a bitcoin, and in the short term, this equilibrium point will be established by the market.
Perfect Competition & Managerial Economics
The Porterâs Five (or Six) Forces58 framework is a mainstay of the MBA Curriculum. The forces within the Bitcoin mining market are illustrated below.
Figure 2 - Porterâs Five Forces Analysis of the Bitcoin Mining Industry
Mapped out, prospects look quite daunting for an industry competitor. They cannot easily protect themselves from new miners or substitute products such as other digital currencies. They are price takers with little power over their buyers, and unless they are an innovation leader in the fields of hardware manufacture and research-and-development, data centre ownership, and/or electricity provision, they have little control over their suppliers too. As mentioned previously, collaborators (i.e. other ecosystem participants) currently have equal potential for benefit and detriment whilst the market is still susceptible to shocks. Competition is stiff within the mining industry, and a prompt extinction awaits if you are not a cost or innovation leader57 . This is expected - economic profit tends to zero in long-term equilibrium in a perfectly competitive landscape34, and the marginal cost of producing and the market price oscillate around an equilibrium point34, with evolution and improvement the only way to stay in business. In such competitive markets, there is also a natural tendency for the market to be dominated by three or four players59,60 . The Pareto Principle, also known as the 80/20 rule61, states 20% of the market participants control 80% of the market. In November 2015, the 5 largest pools provided 79% of mining power. In June 2018, the largest 5 provided 70% of hash rate, with 78% of power coming from the top 6. That said, the pools are not monolithic entities.
Figure3 - Bitcoin Network Hash Rate (NHR) Distribution
In a perfectly competitive market, a firmâs decisions are predictable. All firms need to decide to start up, how to run their business as cost-effectively as possible, and whether to stay in business or not. In the Bitcoin world, the decision-making process relies on market price of bitcoin, operating expenditure, and the network hash rate, i.e., how much competing âminingâ power exists on the network. It also indirectly relies on the continued faith and investment of miners in the value of their commodity i.e. continued research, development, capital expenditure, and strategic partnerships with collaborators. Table 4 shows the relationship between hash rate and price and shows the outcomes for miners in six different scenarios.
Table 4 - Price - Hash Rate Relationship Matrix
Effectively, if price of the commodity (i.e. demand) increases well beyond the cost to mine the commodity, miners will enter the market until the price and cost are equal. If price decreases, miners leave the industry until there are only profitable miners (i.e. either cost or innovation leaders) remaining. If price is dramatically lower than cost to mine, some miners may elect to simply buy bitcoin up to the current cost to mine. If the market is flat, profit tends towards zero until the market is shaken up again. This is similar to the workings of physical commodity miners in the commodity63 and oil64 industries. The difference is that a Bitcoin firmâs decisions take hours and days to implement, and days and weeks to take effect, instead of months and years. The same is true regarding the time taken to reach equilibrium after a price shock; âtwo-to-four times the duration of the production-to-storage cycleâ (i.e. months to years) for commodities65, weeks for Bitcoin.
Trends & the Future
Since the future appears full of opportunities for the digital macroeconomy, one should expect digital microeconomies to become more perfectly competitive as time passes. Should long amounts of time, say, 50 years pass, when all bitcoins have effectively been mined, and the ecosystem is still healthy and has entered the redistribution stage, microeconomies such as the bitcoin mining market will start to resemble the textbook examples of perfect competition. In time, miners will vertically integrate backwards66 by acquiring data centres, chip fabricators, research-and-development teams, and renewable power plants; and integrate forwards by acquiring exchanges, brokers, and other places to sell what they have mined. They can horizontally integrate66 by acquiring entities that enrich the value of their commodity such as wallet hardware and other product manufacturers, financial services companies, and media outlets. 80% of the market will be controlled by the 20% of the largest and most integrated market participants61, with the other 80% providing the niche and evolving needs of the market. As time goes on, the makeup of the microeconomy will evolve until its extinction and replacement10 .
Now that you have a very thorough understanding of the market, and what is going through a minerâs mind, the focus of the paper will shift to the cost of mining Bitcoin.
The Evolution of the Bitcoin Mining Industry: January 2015 â Now
Mining Technology
Since the last analysis, Bitcoin mining technology has improved dramatically. The benchmark used back then was Bitmainâs Antminer S5. We will look at the S5 compared to its current successor, the Antminer S9i67 .
| Â | January 2015 | June 2018 | % Change |
| Network Hash Rate | 295.4 PH/s | 36346.2 PH/s | +12,200% |
| Retail-Best Miner | Bitmain Antminer S5 | Bitmain Antminer S9i | Â |
| $/GH (RRP) | $0.65 | $0.047 | -94% |
| W/GH | 0.89 | 0.098 | -89% |
Table 5 - Evolution of Mining Technology
Further to the above, one of Bitmainâs closest competitors, Canaan Creative, comes in with a lower $/GH rate ($0.044) when excluding PSU costs from both rigs, but a 15% higher W/GH value (0.109)68 . As the market will tend to gravitate towards the lowest total price available, itâs expected that Bitmain controls and ships significantly more hardware than Canaan91 .
Hash Rate Growth
The dramatic drop in $/GH and W/GH shown in Table 5 has spurred extraordinary hash rate growth. That said, this is not a new phenomenon.
Figure 4 shows hash rate growth since the Genesis Block in 200969, showing steady and consistent exponential growth of the network. One of the main drivers of investment in mining equipment is expected hash rate growth from one difficulty cycle to the next. We will explore this concept in further detail in the next chapter. Table 6 shows how consistent fortnightly hash rate growth has been over the past 6 and a half years. Network difficulty grows directly in line with hash rate growth.
| Â | 2012- Current | 2013-Current | 2014-Current | 2015-Current | 2016-Current | 2017-Current | YTD |
| Average | 9.0% | 9.9% | 7.0% | 5.3% | 5.9% | 6.8% | 7.2% |
| St Dev | 9.9% | 10.2% | 7.3% | 6.1% | 6.4% | 6.7% | 5.7% |
| Sample Size | 187 | 161 | 130 | 100 | 73 | 46 | 17 |
Table 6 - Average Difficulty Change Data
As a result of the constant hash rate increases, the difficulty cycle is rarely 14 days, and based on rough year to date data (7.2% increase per cycle), the difficulty cycle is closer to 14 days x (1 â 7.2 %) = 13 days, or 312 hours.
Should Bitcoin ever scale and reach its potential, it is almost certain that mining equipment will exponentially increase in processing efficiency in line with Mooreâs Law for at least another 5 years70 and exponentially increase in power efficiency in line with Koomeyâs Law for at least another 25 years71 .
Figure 4 - Network Hash Rate - All-time Data (Log Scale)
August 2018 Edition 10
Understanding the Cost of Bitcoin â Inputs & Drivers
Calculating the costs of Bitcoin can be modelled quite simply through the relationship of the 7 variables defined below.
Economic Cost Inputs / Drivers
CAPEX
CAPEX is the capital expenditure required to maintain a proportional share of mining rewards upon an increase in difficulty. This is typically the purchase of additional GH/s at a particular $/GH rate. This is demonstrated in the below example, assuming the average of 7.2% difficulty increase discussed above:
| Â | Current Difficulty Cycle | Next Cycle (Predicted) |
| Network Hash Rate | 1000 PH/s | 1072 PH/s |
| Hash Power Provided by Miner / Mining Pool | 300 PH/s | 321.6 PH/s |
| % of Hash Rate provided by miner | 30% | 30% |
Therefore, for the example mining pool to maintain their 30% slice of the pie, they need to bring on 21.6PH/s of hash power.
There are other elements of CAPEX whose life-cycles are much longer than mining equipment. These elements of CAPEX can also be deemed as âsunk costsâ in many cases, and donât affect future decisions. The CAPEX categories are as follows:
- Bitcoin Mining Equipment (typically last for only a few months before theyâre unprofitable)
- Power Supply Units (PSU) for mining equipment typically last as long as the mining equipment due to planned obsolesces, with hardware manufacturers regularly changing the required PSU wattage with each new generation of miner.
- Server Racking / Data Centre Construction & Fitout Costs (typically last for decades). Server Racks / Data Centres could also come under Operational Expenses (OPEX) if the Data Centre is being rented / leased. Regardless, these costs are negligible compared to the costs of electricity.
OPEX
OPEX is the expenditure required to remain operational. At scale, this is effectively just the cost of power to the mining equipment and air conditioning within a data centre. It is estimated that cooling can consume 3072 to 40%73 of overall energy consumption, with 21% a benchmark for the most efficient cooling systems74 . Technologies such as immersive cooling will reduce energy consumption as a trade-off for a large initial capital outlay. One should take in account the âIceland Factorâ, where Bitcoin mining uses as much power as all of Icelandâs homes75 due to it being cold enough for data centres to meaningfully reduce cooling costs and having clean and cheap hydro-electricity. At 840 GWh/yr., tiny Iceland would account for about 1% of the worldâs mining power. While Iceland is only a very small share of the market, miners have access to several other cold places with cheap electricity76 . For the purposes of this model, we will assume cooling contributes to 20% of the total power consumption, in line with the laws of perfect competition and the technological gravitation towards maximum efficiency.
Difficulty Cycle Length
Network difficulty changes every 2016 blocks. At a fixed hash rate, blocks will take 10 minutes (on average) to mine. This results in a difficulty cycle of 14 days. However, as the network hash rate increases 7.2% on average, blocks will be mined, on average, 7.2% quicker. Therefore, the time-period used to calculate the cost of mining a bitcoin will be the average time between difficulty changes will be taken as 13 days (14 days x 92.8% = 13.00), or, 312 hours.
Coins Mined
This is a fixed number â there are 2016 blocks of 12.5 bitcoins mined every difficulty cycle â 25,200 bitcoins. In addition to the mining rewards, mining fees are not insignificant either77 . The SegWit Wars of the first half of 2017 had fees averaging over 200BTC per day, and the fee madness during the hype cycle of December 2017/ January 2018 had a revenue average of over 550BTC per day over those two months. With the SegWit wars over, and the hype now well settled, a relatively consistent 40 BTC per day has been earned in the 6 months leading to July 31, 2018 (st dev = 35, n=180). Daily average fee revenue trends over time are shown in the table below. For this model, we will use a figure of 650 BTC collected in fees each cycle (i.e. about 50/day for the average 13-day cycle time).
| Â | 09-â12 | 2013 | 2014 | 2015 | 2016 | 2017 | 2018 | Since Halving |
| Avg | 6.57 | 43.31 | 12.92 | 22.42 | 62.38 | 273.51 | 105.45 | 177.93 |
| St Dev | 11.46 | 26.12 | 3.83 | 8.35 | 29.34 | 171.55 | 181.47 | 180.42 |
| Sample Size | 730 | 182 | 183 | 182 | 183 | 183 | 211 | 768 |
Table 7 - Daily average fee revenue over time
Power Cost & Emissions
To evaluate power costs and emissions, we donât have much of a choice but to use world-wide weighted average figures, due to the dispersion of miners all over the world. That said, thanks to the rules of perfect competition, particularly perfect factor mobility, miners will move to places with the cheapest electricity costs. The statistics are as follows78,79,80,81 . The emissions figures consider CO2 equivalents, such as methane, and nitrous oxide.
| Primary Energy Source | % Total PES | g CO2 e/kWh | Low Price ($/kWh) | High Price ($/kWh) |
| Biofuels & Waste | 9.7% | 18 | $0.06 | $0.11 |
| Coal | 28.1% | 600 - 1001 | $0.06 | $0.14 |
| Oil | 31.7% | 778 | $0.07 | $0.10 |
| Natural Gas | 21.6% | 443 | $0.04 | $0.08 |
| Nuclear | 4.9% | 66 | $0.11 | $0.18 |
| Hydroelectric | 2.5% | 13 | $0.02 | $0.19 |
| Other (Wind, Solar, Geothermal) | 1.5% | 20 | $0.03 | $0.11 |
| Weighted Average (approx.) | Â | 600 | $ 0.06 | $ 0.12 |
Table 8 - World Power Costs & Emissions by Energy Source
*Note: When using Carbon Capture Systems (CCS), CO2 emissions from Coal are reduced substantially.
Although the average rate for US industrial companies is about $0.07/kWh82, a safer assumption for Bitcoin miners would be closer to 3 or 4 cents, for the reasons mentioned above. There are several documented cases of the largest bitcoin mining operations paying $0.04/kWh83, with reports that Bitmain was receiving a $0.02/kWh rate in their Yunnan facility84, and one particular CEO claiming a cost of electricity of only 1.7 cents/kWh for their mining operation in Moses Lake, Washington, USA85 .
Mining Mix â âThe Network Average Minerâ
There are two types of miners; chip-fabricator miners, and retail miners. Retail miners can be split further into another two categories, large retail miners and small/individual miners. Small individual miners can also forego buying hardware themselves, and instead purchase mining contracts. Due to intellectual property and some economies of scale, chip-fabricators (chipfabs) can mine for significantly cheaper than retail miners. Typical gross profit margins in the semiconductor industry has averaged over 45% for a four-year period86, with the most profitable ones close to 60%. The computer hardware industry averages around 35%87 . Gross profit margins are used since operating expenses and depreciation are dealt with separately within the model. It is assumed that miners pay no tax (i.e. they retain all coins that are mined and/or asset depreciation costs are high enough to offset a large amount of tax on revenue from sold mining hardware). Due to the lack of competition in the ASIC hardware space, margins would likely be 50 to 60%. Obviously, there is a limit to the margin that can be made on mining hardware, as the customer base is quite savvy and can easily calculate profitability of their purchased miners at a particular price-point. For the purposes of this study, it will be assumed that Bitcoin ASIC manufacturers make 60% gross margin on all hardware sold.
Determining the number of non-chipfab large miners and individual miners is another area of speculation due to lack of robust market data. One half-insight can be gained from looking at the worldâs largest cloud-mining operation, Genesis Mining, who claim to have 2 million users88 . Despite its MUCH higher price per GH/s (27c/GH (including electricity costs and incidentals)89 vs Bitmainâs 3.7c/GH), it may still be practical for many miners to opt for a cloud-based solution due to its âplug-and-playâ nature, and more importantly, that it is an âinstant-onâ solution, so that you donât lose your most profitable days waiting for your miner to be shipped to you. That said, Genesis provides no data on their aggregate hash power, nor do they reveal details on the location of their server farms, or even which pools they mine on90 .
Next comes the question of chipfabs mining on their own equipment, and how much equipment has made it out into the market for large-scale and small-scale miners. According to an analysis by Sanford C. Bernstein & Co, it was estimated that Bitmain captured 75% of market share in hardware sales, Canaan Creative captured 15% of the market, and other manufacturers made up the remaining 10%91 . Bitmainâs CEO has stated that the company earned USD$2.5B in revenue for 201792, with the majority of that revenue earned through mining sales, as opposed to mining and selling Bitcoin directly. From this, we can size the market for mining hardware to be a maximum of USD$3.33bn, as some part of Bitmainâs revenue would be mining based. Based on the 2017 average price of an S9 miner of around USD$300093, this means that Bitmain shipped over 800,000 units. If Bitmainâs revenue of $2.5B was a 75% share of the market, then Canaan Creativeâs 15% share would translate into an annual revenue of around $0.5B, with the remainder of the market making up the remaining $0.33B.
Canaan sells their Avalon miners in a minimum order quantity of 40 units at a very similar price-point to Bitmain, so it is safe to assume that Canaan services medium-to-large scale miners. Putting the numbers together, it is assumed that Canaan would have shipped over 150,000 Avalon units, with the rest of the market producing 100,000 âequivalentâ units. Rounding down, one could draw the conclusion that 1 million S9equivalent mining units were shipped.
At this hash rate and price per S9i, this model estimates that roughly $115 million is invested in more mining power every difficulty cycle (see CAPEX on page 16), or around $3.25 billion per year (in line with 2017 figures). Drawing on the 80/20 rule again we can put chipfabs somewhere in the ballpark of 20% of direct hash power. That said, with Bitmain administering at least two mining pools (AntPool & BTC.com)91 providing 40.2% of hash power62, it is likely that they contribute about half of that power or more. Throw in the other chipfabs in proportion to the sales figures mentioned above, as well as any chipfabs that donât sell to the public, and we will assume that chipfabs provide at least 35% of direct hash power for this study.
Due to the laws of perfect competition discussed earlier, it can be assumed that only the most profitable miners are switched on at any given time, and that when a new generation of mining equipment is released, equilibrium is reached very quickly where all miners are operating at a similar cost basis.
| Â | Retail Miner | Chip Fabricator | Weighted Average |
| Hash Power Share % | 65% | 35% | Â |
| Discount Level | 0% | 60% | Â |
| $/GH | 0.047 | 0.019 | 0.037 |
| W/GH | 0.098 | 0.098 | 0.098 |
| $/W | 0.04 | 0.02 | 0.033 |
Table 9 - Rationalised Weighted âNetwork-Averageâ Miner
Network Hash rate
As at the date of this report, total network hash rate is 42,587,731,568 GH/s. Miners need to successfully forecast hash rate and difficulty increases when planning future capital expenditure and setting strategy and targets.
Environmental Cost Inputs & Drivers
CAPEX
To better assess the overall impact of the bitcoin mining industry, we should also consider the CO2 emissions from the manufacture and recycling of mining equipment.
A study using data from 200094 suggests that total energy to produce a PC is 895kWh. Although the data is quite dated, it sets a very conservative benchmark, as manufacturing efficiencies consistently improve in line with the laws of competition, alongside Moore & Koomeyâs laws discussed earlier.
| Â | Direct Fossil (MJ) | Electricity (kWh) | Total Energy (MJ) | Total Energy (kWh) |
| Semiconductors | 298 | 170 | 909 | 252.5 |
| Semiconductor manufacturing equipment | 392 | 29.4 | 498 | 138.3 |
| Passive Components | 109 | 10.3 | 146 | 40.6 |
| PCB | 26.7 | 7.71 | 54.5 | 15.1 |
| Bulk Materials | - | - | 770 | 213.9 |
| Silicon Wafers | 0 | 38.1 | 137 | 38.1 |
| Assembly | 35.3 | 51.2 | 220 | 61.0 |
| Transport | 338 | 3.5 | 351 | 97.4 |
| Packaging | 120 | 4.8 | 137 | 38.1 |
| Â | 1319 | 315 | 3222 | 895 |
Table 10 - Energy Required for ASIC manufacture
As 98% of electronic waste is completely recyclable95, and an estimated energy saving of 90% on the recovery of metals and silicon96, we will reduce the âBulk Materialsâ energy use by 90%, to result in a total of 703 kWh. Recycling of ASICs is a fair assumption due to the short life of mining equipment, and the value to be extracted out of quickly obsolete equipment through means of recycling.
OPEX
Environmental Impact from operations is effectively pure energy use. If miners are using cheap hydroelectricity to mine, emissions are insignificant. If miners are using dirty coal with no carbon capture, environmental impact is much higher.
It is assumed that the average miner will use power that emits a weighted average value of CO2 based on the worldâs energy mix shown in Table 8.
Calculating the Costs
Economic Costs
The following tables shows the outputs from the economic model, which is based on the assumptions set out in the section on Economic Cost Inputs / Drivers . Orange cells are variables / inputs, grey cells are calculation cells.
CAPEX
Table 11 - Bitcoinâs Economic Costs - CAPEX
OPEX
Table 12 - Bitcoinâs Economic Costs - OPEX
Total Cost of a Bitcoin
Adding the CAPEX figure of $4,337.57 to the OPEX figure of $2,077.92 results in a total cost of $6,455.49.
Environmental Costs
Table 13 - Bitcoinâs Energy Use & Emissions
Environmental Impact Factors
It is unfair to only benchmark Bitcoinâs environmental impact by CO2 emissions alone, so we will assess a few other environmental impacts to compare with the impact of Gold mining.
Eutrophication
Eutrophication, measured in tonnes of Phosphorous equivalents, is the introduction of nutrients into groundwater and other fresh water sources, having a drastic impact on water quality, the local ecology in general, and adverse economic impacts97 . Bitcoin generally has very low externalities, as it relies almost strictly on the electrical grid both to mine and produce hardware. Therefore, to determine the Eutrophication produced by the energy sources that power Bitcoin, based on a weighted world average.
Global Eutrophication stands at 126.6 million tonnes per year98, from a total 150,000 TWh/yr. of global energy produced99, therefore, 1TWh produces about 850 tonnes of PO43- equivalents. As Bitcoin uses around 105TWh/yr., 89,250 tonnes are produced.
Acidification
| Country100 | Acidification (g SO2 eq/kWh) | Energy Mix |
| Turkey | 9.79 | 43.6% Natural Gas, 28.1% Coal, 24.2% Hydro, 4.1% other (71.7% total fossil fuels) |
| Portugal | 1.22 | 22% Coal, 22% Gas, 24% Hydro, 22% Wind, 2% Solar, 6% Biowaste, 2% Oil101 (46% fossil fuels) |
| Spain | 4.93 | 22% Nuclear, 14% Coal, 20% Gas, 6% Oil, 13% Hydro, 18% Wind, 5% Solar, 2% Biofuel101 (40% total fossil fuels) |
| Belgium | 1 | 53% Nuclear, 24% Renewables, 26% Gas, 3% Coal, 0.1% Oil101 (29.1% total fossil fuels) |
| Tanzania | 4.53 | 45% Natural Gas, 42% Hydro, 13% Liquid Fuel102 (58% fossil fuels) |
| Nigeria | 0.22 | 82.2% Biomass & Waste, 10.6% Oil, 6.8% Natural Gas, 0.4% Hydro103 (17.4% fossil fuels) |
| Mexico | 6.59 | 34.45% Natural Gas, 4.89% Coal, 34.83% Oil, 15.75% Gasoline, 7.79% Renewable, 0.78% Nuclear, 1.5% other104 (89.92% Fossil Fuels) |
| Average | 4.04 | Â |
Table 14 - Bitcoinâs Environmental Impact - Acidification
As can be seen from above, countries that have high percentages of Natural Gas in their energy mix contribute greatly to acidification, while Biomass contributes insignificant amounts. Coal & Oil also have large contributions. Since the global energy mix (Table 6) consists of 81.4% fossil fuels (of which 21.6% is Natural Gas), 9.7% Biowaste, and 8.9% Nuclear & Other Renewables, using the average of around 4 g SO2 eq/kWh is appropriate due to the contribution of Biowaste, as well as the above sample countries with high acidification having a disproportionately high use of natural gas compared to the world average. At 78TWh/yr. of energy usage, the Bitcoin Network produces 312,000 tonnes of SO2 equivalents
Ecotoxicity, Carcinogenics, Non-Carcinogenics, and Respiratory Inorganics
Global per-capita data on Ecotoxicity, Carcinogenics, Non-Carcinogenics, and Respiratory Inorganics measures105 are as shown in Table 15. Population statistics106,107,108,109 are also included. All data is as at 2011.
| Â | North America | Europe | Middle East | Eurasia | Asia & Oceania | Africa | Central & South America |
| Freshwater Ecotoxicity (CTUe) | 2.72E+04 | 1.79E+04 | 3.30E+03 | 1.38E+04 | 5.42E+03 | 1.63E+03 | 1.47E+03 |
| Carcinogenics (CTUh) | 2.67E-04 | 1.48E-04 | 2.36E-05 | 1.28E-04 | 5.20E-05 | 1.70E-05 | 9.54E-06 |
| Non-Carcinogenics (CTUh) | 1.04E-03 | 6.69E-04 | 1.70E-04 | 5.75E-04 | 2.40E-04 | 6.40E-05 | 4.35E-05 |
| Respiratory Inorganics (PM2,5) | 2.66 | 1.26 | 1.29 | 2.46 | 3.72 | 0.199 | 0.443 |
| Population (millions) | 560 | 515 | 145 | 180 | 4,100 | 1,050 | 480 |
Table 15 - Ecotoxicity, Carcinogenics, Non-Carcinogenics, & Respiratory Inorganics Data (per-capita)
When per capita stats are multiplied by population figures, and the totals then divided by world energy generation (~ 150,000 TWh/yr.), then multiplying per 78TWh for energy used on the Bitcoin network, the following is found:
| Â | Freshwater Ecotoxicity (CTUe) | Carcinogenics (CTUh) | Non- Carcinogenics |
| (CTUh) | Respiratory Inorganics (PM2,5) | Population (Billion) | Â | Â | Â | Â |
| Â | Total | 5.21E+13 | 4.88E+05 | 2.13E+06 | 1.85E+10 | 7.04 |
| Â | Total/TWh | 3.42E+08 | 3.20 | 13.96 | 1.21E+05 | Â |
| Â | Bitcoin | 2.66E+10 | 249.73 | 1088.97 | 9.45E+03 | Â |
Table 16 - Bitcoin Ecotoxicity, Non-carcinogenics, Carcinogenics & Respiratory Inorganics
A comparison of these 6 indicators versus that of gold mining and recycling is discussed in the section on
Revisiting Gold on page 22.
Sensitivity Analysis
For the below sensitivity analysis, it is assumed that all aforementioned assumptions in the model are held constant, with one variable being changed at a time to see the impact on overall cost. Four scenarios are demonstrated for each of the 6 variables below, alongside the difference between the modelled cost of $6,455.49.
| Mining Mix* | CAPEX | OPEX | TOTAL | Î |
| 20/80 Chipfab to Retail | $4,876.28 | $2,266.82 | $7,143.10 | 10.65% |
| 30/70 Chipfab to Retail | $4,543.81 | $2,140.89 | $6,684.69 | 3.55% |
| 40/60 Chipfab to Retail | $4,211.33 | $2,014.95 | $6,226.29 | -3.55% |
| 50/50 Chipfab to Retail | $3,878.86 | $1,889.02 | $5,767.88 | -10.65% |
| Minerâs Margin | CAPEX | OPEX | TOTAL | Î |
| 30% | $4,959.40 | $2,077.92 | $7,037.32 | 9.01% |
| 40% | $4,765.46 | $2,077.92 | $6,843.38 | 6.01% |
| 50% | $4,571.51 | $2,077.92 | $6,649.43 | 3.00% |
| 70% | $4,183.63 | $2,077.92 | $6,261.55 | -3.00% |
| Electricity Price | CAPEX | OPEX | TOTAL | Î |
| 1c/2c Chipfab to Retail | $4,377.57 | $1,038.96 | $5,416.53 | -16.09% |
| 1c/3c Chipfab to Retail | $4,377.57 | $1,448.25 | $5,825.82 | -9.75% |
| 2c/5c Chipfab to Retail | $4,377.57 | $2,487.21 | $6,864.78 | 6.34% |
| 3c/5c Chipfab to Retail | $4,377.57 | $2,707.59 | $7,085.16 | 9.75% |
| Cooling Power % | CAPEX | OPEX | TOTAL | Î |
| 15% | $4,377.57 | $1,955.69 | $6,333.26 | -1.89% |
| 25% | $4,377.57 | $2,216.45 | $6,594.02 | 2.15% |
| 35% | $4,377.57 | $2,557.44 | $6,935.01 | 7.43% |
| 40% | $4,377.57 | $2,770.56 | $7,148.13 | 10.73% |
| Transaction Fees | CAPEX | OPEX | TOTAL | Î |
| 500 | $4,403.12 | $2,090.05 | $6,493.17 | 0.58% |
| 750 | $4,360.70 | $2,069.91 | $6,430.61 | -0.39% |
| 1250 | $4,278.27 | $2,030.78 | $6,309.05 | -2.27% |
| 1500 | $4,238.21 | $2,011.77 | $6,249.98 | -3.18% |
| Ave Difficulty Change % | CAPEX | OPEX | TOTAL | Î |
| 5.50% | $3,343.98 | $2,117.88 | $5,461.86 | -15.39% |
| 6.50% | $3,951.97 | $2,097.90 | $6,049.87 | -6.28% |
| 8.50% | $5,167.97 | $2,051.28 | $7,219.25 | 11.83% |
| 9.50% | $5,775.96 | $2,031.30 | $7,807.26 | 20.94% |
-
- a 50/50 ratio should be theoretical maximum, as risk of perception of a 51% attack becomes too high for large miners due to potential catastrophic impact on market price.
Over time, the above sensitivities will allow us to make sense of the modelâs results when compared to actual market price and tweak the model in line with new evidence.
Comparative Summary
Revisiting Gold
Since this study has considered the manufacture of ASICs in its evaluation of Bitcoinâs impact, we must now visit the environmental impact of the manufacture of mining equipment to make a like-for-like comparison. To start, we will revisit the subtotal impact of Gold mining considering current production levels. From there, we will add impacts from machinery production to the original tally. Since the previous iteration of this research in 2014 (using 2013 data), World Gold production has increased 18% from 2770 tonnes, to 3270 tonnes in 2017110 . We have also witnessed a sharp drop in the amount of recycled gold produced, going from 37% of total annual production in 2011 produced gold coming from recycled down to only 26% at 1160 tonnes in 2017.
In a very comprehensive study produced by Dell in November 2017111 showed some fascinating information on the relative sustainability of gold mining, and gold recycling. Results are shown in Figure 5 and Figure 6. It should be noted that Dellâs 15 tonne CO2/kg figures for gold mining exclude the construction and demobilisation of mine infrastructure, and site remediation. When including those, the original figure of 20 tonne CO2/kg1 that we used in 2014 was a very fair estimate. Perhaps the best observation to draw from the Dell data is just how toxic and harmful gold mining is to the planet, even though it produces less than half the amount of CO2 per kilo.
Figure 5 - Resource inputs per kilogram of gold recycled
Figure 6 - Environmental comparison of recycling vs mining 1 kilogram of gold
Now that our original assumptions for gold mining have been validated against an in-depth recent study by Dell, we can take a look at how the numbers stacked up in 2017.
| Â | Greenhouse Emissions (t CO2/kg Au) | Energy Consumption (MWh/kg Au) |
| Rate Per kg - Mining | 20.001 | 48.611 |
| Rate Per kg - Recycling | 37.00111 | 31.32111 |
| Â | Tonnes Produced110 | Greenhouse Emissions (Million t CO2) | Energy Consumption (TWh) |
| Mined | 3268.7 | 65.374 | 158.9 |
| Recycled | 1160 | 42.92 | 36.34 |
NOTE: All figures have been rationalised into MWh. 1 GJ = 0.27777 MWh. 1 MWh = 3.412 million BTU
Table 17 - Environmental Impact of Gold Mining & Recycling
The next item to assess in the impact of producing mining equipment. To do this, we can look to the worldâs largest Gold mining company, Barrick Gold, and the fleet and staff data they provide for their Pueblo Viejo112, Veladero (open-pit)113, and Barrick Nevada (Cortez114, and Goldstrike115 mine operations), which produce 107 tonnes of Gold per year116, or, about 3.3% of total supply. The aggregate of the fleet lists for the above four mines, alongside data on the weight of machinery from manufacturers are shown in Table 19 and Table 18, below. As can be seen, much less machinery is used in an underground environment as opposed to an openpit environment. Fleet data does not include the several hundred regular site-vehicles for staff use on the mine site. With an average of 42 staff per tonne of gold produced at the aforementioned mines, it is assumed that 10% of staff have vehicles for use on site, resulting in an extrapolated figure of around 15,000 site vehicles globally. 11 tonnes of CO2 to produce a vehicle117 means that 165,000 tonnes of CO2 are created. Converting this to a kWh equivalent figure, we divide 0.165 million tonne CO2 by 600 tonnes CO2/TWh (Table 8), resulting in 0.09 TWh equivalent. It is assumed site vehicles will last for 10 years (i.e. 0.009 TWh/year).
| Machine | Make | Qty | Weight (t) | Total Weight (t) |
| R-2000 RoadHeader | Alpine | 1 | 60.00 | 60 |
| 3.5 yd3 Loader | AtlasCopco | 5 | 17.27 | 86 |
| Boltec M Bolter | AtlasCopco | 16 | 21.60 | 346 |
| 120 Grader | Caterpillar | 7 | 16.88 | 118 |
| 414E loader | Caterpillar | 19 | 6.82 | 130 |
| 966 Loader | Caterpillar | 4 | 16.74 | 67 |
| AD30 Truck | Caterpillar | 11 | 30.00 | 330 |
| D4 Dozer | Caterpillar | 12 | 4.93 | 54 |
| R1600G loader | Caterpillar | 14 | 29.80 | 268 |
| DT-20N truck | DUX | 2 | 19.40 | 39 |
| DT-26N truck | DUX | 13 | 25.00 | 325 |
| A64-C/LT/SL Vehicles | Getman | 21 | 12.50 | 75 |
| Mule Pro-DXT Utility Vehicle | Kawasaki | 62 | 0.84 | 52 |
| MHT Telehandler | Manitou | 4 | 24.00 | 96 |
| Rough-Terrain Forklifts (various) | Manitou | 23 | 5.00 | 115 |
| Ultimec MF500 Shotcreter | Normet | 7 | 12.00 | 84 |
| DT721 Tunnelling Jumbo | Sandvik | 11 | 24.50 | 270 |
| Tamrock 1400 Hauler | Sandvik | 8 | 33.70 | 270 |
| Â | Total Weight | 2784 | Â | Â |
Table 18 - Underground Fleet Register for Barrickâs Nevada Mines (Cortex & Goldstrike)
| Machine | Make | Weight | Qty | Total Weight (t) |
| (t) | Â | Â | Â | Â |
| L2350 loader | Komatsu | 72.57 | 2 | 145 |
| Haul Truck, 730E | Komatsu | 146.69 | 19 | 2787 |
| Face Shovel, PC4000 | Komatsu | 362 | 2 | 724 |
| Wheel Loader, WA1200 | Komatsu | 216.4 | 3 | 649 |
| Track Dozer, D375A | Komatsu | 56.29 | 6 | 338 |
| Track Dozer, D85-EX | Komatsu | 28.1 | 1 | 28 |
| Motor Grader, GD825A | Komatsu | 29.68 | 3 | 89 |
| Backhoe, PC300LC | Komatsu | 33.8 | 1 | 34 |
| Backhoe, WB140 | Komatsu | 7.3 | 1 | 7 |
| Wheel Dozer, WD500 | Komatsu | 26.9 | 1 | 27 |
| Wheel Dozer, WD600 | Komatsu | 41.08 | 2 | 82 |
| Water Truck, 330M | Komatsu | 24.04 | 2 | 48 |
| 930E Truck (290t) | Komatsu | 210.19 | 24 | 5044 |
| HM400 Water Truck | Komatsu | 30.3 | 3 | 91 |
| 605 Truck (water) | Komatsu | 46.2 | 6 | 277 |
| 930E Water Truck | Komatsu | 505.75 | 3 | 1517 |
| Face Shovel, PC5500 | Komatsu | 490 | 2 | 980 |
| Backhoe, PC2000 | Komatsu | 204.12 | 1 | 204 |
| P&H 4100 XPB shovel | Komatsu | 1512 | 7 | 10584 |
| P&H 2800 XPB shovel | Komatsu | 1084 | 4 | 4336 |
| Liebherr T282B trucks | Liebherr | 252 | 25 | 6300 |
| Face Shovel, 996 | Liebherr | 676 | 3 | 2028 |
| Drill, SKS 12 | Reedrill | 95.58 | 2 | 191 |
| DrillTech D55SP | Sandvik | 79.33 | 12 | 952 |
| DrillTech D75K | Sandvik | 64.86 | 11 | 714 |
| Drill (Blasthole), D90K | Sandvik | 140.33 | 5 | 702 |
| Sandvik D45KS Drill | Sandvik | 47.73 | 2 | 95 |
| Sandvik DX780 Drill | Sandvik | 14.8 | 2 | 30 |
| Drill, Ranger 700 | Sandvik | 15.2 | 1 | 15 |
| DP 1500 | Sandvik | 19.2 | 2 | 38 |
| Schramm T450GT Drill | Schramm | 21.75 | 1 | 22 |
| PV271 drill | AtlasCopco | 84 | 8 | 672 |
| Flexirock D65 drill | AtlasCopco | 24 | 3 | 72 |
| MD6420 drill | Caterpillar | 95 | 1 | 95 |
| 795F trucks (345 st) | Caterpillar | 202.27 | 30 | 6068 |
| 16H grader | Caterpillar | 24.7 | 16 | 395 |
| 24H grader1 | Caterpillar | 73.34 | 7 | 513 |
| 994F Front-End Loader | Caterpillar | 243.11 | 7 | 1702 |
| D10T Track Dozer | Caterpillar | 70.17 | 20 | 1403 |
| D9T Track Dozer | Caterpillar | 48.99 | 3 | 147 |
| 834H Wheel Dozer | Caterpillar | 47.11 | 7 | 330 |
| 854K Wheel Dozer | Caterpillar | 98.49 | 7 | 689 |
| 777F Haul Truck | Caterpillar | 80 | 13 | 1040 |
| C322 Hydraulic Excavator | Caterpillar | 24.83 | 1 | 25 |
| C336 Hydraulic Excavator | Caterpillar | 30.5 | 3 | 91 |
| 349D Hydraulic Excavator | Caterpillar | 45.83 | 1 | 46 |
| 962 Support Loader | Caterpillar | 19.37 | 2 | 39 |
| 938 Support Loader | Caterpillar | 13.18 | 1 | 13 |
| 785C Haul Truck | Caterpillar | 102.15 | 6 | 613 |
| 6040 Trackhoe | Caterpillar | 397.4 | 1 | 397 |
| 992 Loader | Caterpillar | 94.93 | 5 | 475 |
| 793 Haul Truck | Caterpillar | 122.3 | 46 | 5626 |
| 385 Backhoe | Caterpillar | 84.13 | 1 | 84 |
| 345 Backhoe | Caterpillar | 45.38 | 1 | 45 |
| 988 Wheel Loader | Caterpillar | 43.37 | 4 | 173 |
| 789C / 789D Haul Truck | Caterpillar | 99.12 | 34 | 3370 |
| EX-5500 excavator | HItachi | 518 | 4 | 2072 |
| EX3600 Hydraulic Shovel | Hitachi | 362 | 2 | 724 |
| X1200 Hydraulic Excavator | Hitachi | 112 | 1 | 112 |
| Drill, DMM2 | Ingersoll Rand | 5.4 | 3 | 16 |
Total Weight (tonnes): 66128
Table 19 - Open-pit Fleet Register for Barrickâs Nevada, Pueblo Viejo and Veladero Mines
August 2018 Edition 25
Having precise data on the machinery required to produce 3.3% of the worldâs Gold, we will extrapolate the total weights found above (66128 + 2784 = 68,912 tonnes) out to the other 96.7% of the market. This results in almost 2.1 million tonnes of mining equipment, which we will conservatively assume is mostly steel for the next part of the analysis (since the energy needed to extract steel is typically lower than other materials used in vehicles, such as aluminium)118 .
1.95 tonnes of CO2 are emitted in the extraction and production of one tonne of steel119 . Data on vehicle manufacturing shows that the manufacture and transport stages of the vehicles life can vary anywhere from 5 to 20% of the energy required to extract raw materials118 . Therefore, we will say that for each tonne of manufactured and delivered construction machinery there is 2.2 tonnes of CO2 emitted (i.e. 1.95 tonnes + 10%). Multiplying this by 2.1 million tonnes of global Gold mining equipment results in 4.62 million tonnes of CO2 . We will also conservatively say that well maintained mining machinery will last for 10 years if operated 24 hours per day, 365 days per week, resulting in a yearly average emission of 0.462 million tonnes of CO2, or 0.77 TWh equivalent., towards the manufacture of new machinery.
This 210,000-tonne heap of equipment also needs to be packaged and transported each year. While there is no data on emissions from packaging an excavator, estimations can be made regarding transportation emissions. As most mines are remote, equipment must be transported using several modes â by sea to move equipment continentally and then by road. A 3000-kilometre journey is not something unusual and would even be considered very conservative considering where the major equipment manufacturers are based, and how remote these mines truly are. We will assume that 75% of the journey happens via sea freight, and 25% of the journey via truck transport. This results in 4.725 billion tonne-km by sea, and 1.575 billion tonne-km by road. With sea travel on a large container barge producing 19.6 g/CO2 per tonne-kilometre, and 62 grams for road travel120, this results in 190,000 tonnes of CO2, or 0.114 TWh equivalent.
Therefore, the total amount of energy needed to manufacture and deliver machinery to the mines is 0.77 TWh for manufacture of machinery, 0.009 TWh for site vehicles, 0.0114 TWh for transport, which equals 0.7904 TWh, or, 0.474 million tonnes of CO2 . Adding this to mining and recycling totals shown in Table 17, we have the following:
| Â | Tonnes Produced110 | Greenhouse Emissions (Million t CO2) | Energy Consumption (TWh) |
| Mined | 3,268.7 | 65.374 | 158.9 |
| Recycled | 1,160 | 42.92 | 36.34 |
| Equipment | 2,100,000 | 0.474 | 0.7904 |
| Total | Â | 108.768 | 196.09 |
Table 20 - Goldâs Environmental Impact - Energy Use & Emissions
Comparison of Yearly Energy Use
Looking at the table below, it appears that Bitcoin uses a substantial amount of energy â now closing in on the entire Gold industry, and due to its reliance on the electrical grid, CO2 emissions are high. As the electric grid moves towards renewable energy sources, Bitcoinâs figures for CO2 emissions will continue to improve, however there will be little improvement in the gold mining industry. That said, Bitcoinâs energy use will continue to grow in line with the Networkâs computing power growth, and will most likely eclipse the Gold Industry within this decade.
Another interesting statistic is that more energy goes into building Bitcoin hardware than goes to producing the worldâs gold mining equipment. But since a large part of ASIC manufacture is tied to the electrical grid (Table 10), Bitcoinâs emissions proportional to its energy use will reduce
| Â | Energy Used (kWh) | Tonnes CO2 Produced | Emission-Per-Unit Trend |
| Gold Mining + Equipment | 159.69 million | 65.85 million | Increasing |
| Gold Recycling | 36.34 million | 42.92 million | Decreasing |
| Bitcoin Mining | 105.82 million | 63 million | Decreasing |
Table 21 - Bitcoin vs. Gold - Emissions & Energy Use
Comparison of Other Environmental Indicators
As can be seen below, Bitcoin is dramatically less harmful than Gold on all indicators aside from Carcinogenics, where the Global Electric Grid, i.e., the sole unified entity powering the Bitcoin network, spews more than double that of the Gold industry. As the electric grid moves towards renewable energy sources, Bitcoinâs figures will continue to improve quite dramatically, however there will be little improvement in the gold mining industry.
| Â | Gold Mining | Gold Recycling | Total Gold (tonnes) | Bitcoin | Î |
| kg Produced | 3268700 | 1160000 | 4428.7 | Â | Â |
| Acidification (kg SO2 /kg) | 175 | 180 | 780823 | 423265 | -45.8% |
| Eutrophication (kg PO43- /kg) | 4095 | 175 | 13588327 | 89944 | -99.3% |
| Freshwater Ecotoxicity (CTUe/kg) | 22139602 | 154278 | 7.25E+10 | 3.61E+10 | -50.2% |
| Carcinogenics (CTUh/kg Au) | 0.03208 | 0.00171 | 107 | 339 | 217.1% |
| Non-Carcinogenics (CTUh/kg) | 0.93 | 0.01 | 3051 | 1477 | -51.6% |
| Respiratory Inorganics (PM2,5/kg) | 20 | 12 | 79294 | 12817 | -83.8% |
Table 22 - Bitcoin vs. Gold - Broad Environmental Impact
Discussion & Conclusion
There is no doubt that the Bitcoin Network uses large amounts of energy (yes, it uses more power than the country of Ireland121), however, as alluded to in the Foreword, this energy is necessarily required to effectively turn electricity or power into âmoneyâ. While emissions are high, this is due to the composition of the worldâs energy grid, and over time, emissions will continue to reduce proportionately to the amount of power that has been used.
Some critics have labelled Bitcoin as an environmental disaster121, however it has been demonstrated that Bitcoin is dramatically less harmful to the environment than the gold mining industry when other key environmental indicators are assessed. Others have made the very fair criticism that costs per transaction are unruly122, especially when volume of transactions (about 7 per second123) is considered in the context of the total power being used by the network. This criticism is only temporarily fair, as the Lightning Network124, which has been live and growing since March 2018, will significantly increase transaction capacity without increasing energy consumption. The Lightning Network, as of July 31, 2018, has over 2700 nodes, 7700 channels, and a network capacity of about 93 BTC125 (note, this is growth of almost 10% in node count, almost 30% in channel count, and over 30% in BTC capacity a period of only two weeks). In fortnight before that (July 1 to July 14), node-count increased over 10%, channel count by 30%, and network capacity more than tripling. It may not be unrealistic to expect a Bitcoin / Lightning Network that can process several hundred near-feeless transactions per second by the end of 2019, and potentially several thousand by the end of 2020. This would effectively allow Bitcoin to scale its transactional capacity by several orders of magnitude ahead of the next price hype-cycle.
As Bitcoinâs market capitalisation grows, letâs say two orders of magnitude to bring it in line with Goldâs $7 trillion-dollar market cap, the Bitcoin mining industry will start to drive innovation in the worldâs electrical generation market due to the sheer amount of energy that the network will demand. Judging by current profits that mining hardware manufacturers currently make, mining companies may even become large enough to vertically integrate and acquire energy companies, and to remain competitive, the energy will need to be very cheap which means a high likelihood of migrating to hydroelectricity, and other renewables that get cheaper by the kWh every year.
We have also presented some broad assumptions about the composition of the Bitcoin mining market, and the dynamics at play that affect the cost to mine a coin. As the industry grows by a magnitude or two and becomes more competitive, the market price of a bitcoin will start becoming more correlated with the cost to mine, just as is the case for traditional commodity producers.
References
- McCook, H. 2015, âAn Order-of-Magnitude Estimate of the Relative Sustainability of the Bitcoin Networkâhttps://www.academia.edu/7666373/An_Order - of -Magnitude_Estimate_of_the_Relative_Sustainability_of_the_Bitcoin_Network_ - 3rd Edition
- The World Bank, âTotal greenhouse gas emissions (kt of CO2 equivalent)â,https://data.worldbank.org/indicator/EN.ATM.GHGT.KT.CE?view=chart , (accessed 21 July 2017).
- Janssens-Maenhout, G. et al, 2017, âJRC Science for Policy Reportâhttp://edgar.jrc.ec.europa.eu/booklet2017/CO2_and_GHG_emissions_of_all_world_countries_booklet_online.pdf (accessed 21 June 2018)
- Kilvert, N., 2017, âParis agreement slipping away as record global CO2 emissions predicted for 2017â,http://archive.li/zpYnW
- International Energy Agency, 2017, âKey World Energy Statisticsâ,http://archive.is/PFlG3
- Shapiro, C., Varian, H. (1999) âInformation Rules â a strategic guide to the network economyâ Boston, Harvard Business School Press 184
- Scholte, J. âGlobal Capitalism and the Stateâ, _International Affairs_3 427-452 (1997) doi: 10.2307/2624266
- Stiglitz, J (2006) âThe Price of Inequalityâ, New York, W.W. Norton & Company 157-170 (accessed 26 February 2016) http://resistir.info/livros/stiglitz_the_price_of_inequality.pdf (21:24)
- Stiglitz, J. (2010) âFreefall â America, Free Markets, and the Sinking of the World Economyâ, New York, W. W. Norton & Company 74-86
- Schumpeter, J A. (2003) [1943] âCapitalism, Socialism and Democracyâ, London, Routledge 83
- Nakamoto, S. âBitcoin: A Peer-to-Peer Electronic Cash System.â No Publisher (2008) https://bitcoin.org/bitcoin.pdf , 19
- McKinsey & Co (2015) âGlobal Payments 2015: A Healthy Industry Confronts Disruptionâ (accessed 26 February 2016) http://www.mckinsey.com/~/media/McKinsey/dotcom/client_service/Financial%20Services/Latest%20thinking/Payme nts/Global_payments_2015_A_healthy_industry_confronts_disruption.ashx (22:44)
- Utterback, J. M. (1994) âManaging the Dynamics of Innovation. 1st editionâ Cambridge: Harvard Business School Press 145-166
- Berners-Lee, T. âLong Live the Webâ, Scientific American 303 80-85 (2010) doi: 10.1038/scientificamerican1210-80
- MĂŒller, R., Kiji, B., Martens, J. âA Comparison of Inter-Organizational Business Models of Mobile App Stores: There is more than Open vs. Closedâ, Journal of theoretical and applied electronic commerce research 2 63-76 (2011) doi:10.4067/50718-18762011000200007
- Lerner, J., Tirole, J. âThe open source movement: Key research questionsâ, _European Economic Review_4-6 819826 (2001) doi: 10.1016/S0014-2921(01)00124-6
- Bitcoin Wiki, âDifficultyâ, (accessed 27 February) (accessed 27 February 2016) https://en.bitcoin.it/wiki/Difficulty (21:33)
- Bitcoin Wiki, âControlled Supplyâ, (accessed 27 February) https://en.bitcoin.it/wiki/Controlled_supply (21:33)
- Hines, J., Rice, E. âFiscal Paradise: Foreign Tax Havens and American Businessâ, _The Quarterly Journal of Economics_1 149-182 (1994) doi: 10.2307/2118431
- United Nations (2009), âHuman Development Report 2009 â Overcoming barriers: Human mobility and developmentâ, New York, UNDP 2-3
- Plamer, D. (2015) â11 Bitcoin Startups That Went Bust in 2015â, (accessed 26 February 2016) http://www.coindesk.com/bitcoin - startup - shut - down - 2015/ (20:25)
- Parker, L. (2015) â36 bitcoin exchanges that are no longer with usâ, (accessed 26 February 2016) http://bravenewcoin.com/news/36 - bitcoin - exchanges - that - are - no - longer - with - us/ (20:26)
- Perez, Y. (2015) âMt Gox: The History of a Failed Bitcoin Exchangeâ (accessed 26 February 2016) http://www.coindesk.com/mt - gox - the - history - of - a - failed - bitcoin - exchange/ (20:27)
- Greenberg, A. (2013) âEnd of The Silk Road: FBI Says Itâs Busted The Webâs Biggest Anonymous Drug Black Marketâ, Forbes, (accessed 26 February 2016) http://www.forbes.com/sites/andygreenberg/2013/10/02/end - of - the - silk - road fbi - busts - the - webs - biggest - anonymous - drug - black - market/#103e7805347d (20:28)
- Urquhart, J. (2014), âRussian authorities say Bitcoin illegalâ, Reuters, (accessed 26 February 2016) http://www.reuters.com/article/us - russia - bitcoin - idUSBREA1806620140209 (20:29)
- US Marshalls Service (2015), âUSMS Asset Forfeiture Saleâ, (accessed 26 February 2016) http://www.usmarshals.gov/assets/2015/dpr - bitcoins/ (20:30)
- Higgins, S. (2015), âSEC Charges GAW Miners CEO Josh Garza With Securities Fraudâ, (accessed 26 February 2016) http://www.coindesk.com/gaw - faces - ponzi - scheme - charges - from - sec/ (20:31)
- Rizzo, P (2016), âMaking Sense of Bitcoinâs Divisive Block Size Debateâ (accessed 26 February 2016) http://www.coindesk.com/making - sense - block - size - debate - bitcoin/ (20:32)
- Hajdarbegovic, N. (2014) âBitcoin Miners Ditch GHash.io Pool Over Fears of 51% Attackâ (accessed 26 February 2016) http://www.coindesk.com/bitcoin - miners - ditch - ghash - io - pool - 51 - attack/ (20:33)
- Pseudonymous (Bitcoin Brother), Pseudonymous (sapiophile) (2015) âBitcoin Price Chart with Historic Eventsâ(accessed 26 February 2016) https://bitcoinhelp.net/know/more/price - chart - history (20:34)
- Nassim Taleb, N., 2012, âAnti-fragile: Things that gain from disorderâ, New York, Random House
- info, Bitcoin Market Price (USD), (accessed 26 February 2016) https://blockchain.info/charts/market price?timespan=all&showDataPoints=false&daysAverageString=1&show_header=true&scale=0&address = (20:35)
- info, âBlockchain charts - Various bitcoin charts and currency statisticsâ (accessed 26 February 2016) https://blockchain.info/charts (20:36)
- Parkin, M. (2014) âMicroeconomics â 11th Editionâ, New York: Pearson 272-296
- Mankiw, N. (2011) âPrinciples of Economics â 6th Editionâ: South-Western Cengage 291- 314
- Makowski, L., Ostroy, J. âPerfect Competition and the Creativity of the Marketâ, Journal of Economic Literature, Vol.XXXIX (June 2001) 479-535
- Stiglitz, Joseph E.;Walsh, Carl E. (2006). âEconomics (4th ed.)â, New York: W.W. Norton & Company 205-222
- Dean, J. (1951) âManagerial Economicsâ New York: Prentice Hall
- Semulson, W., Marks, J. (2012) âManagerial Economics 7th editionâ, New York: John Wiley & Sons 283-318
- Bitcoin Wiki, âTransaction Feesâ, (accessed 27 February) https://en.bitcoin.it/wiki/Transaction_fees (21:33)
- Wile, R. (14 June 2014) âToday, Bitcoinâs Doomsday Scenario Arrivedâ (accessed 26 February 2016),http://www.businessinsider.com.au/today - bitcoins - doomsday - scenario - arrived - 2014 - 6?r=US&IR=T ,(21:37)
- Pagliery, J. (2015) âRecord $1 billion invested in Bitcoin firms so farâ, (accessed 26 February 2016) http://money.cnn.com/2015/11/02/technology/bitcoin - 1 - billion - invested/ (21:38)
- Geroski, P. âThe Evolution of New Marketsâ, Oxford University Press Scholarship Online, 61-100 (2003) doi:10.1093/0199248893
- Washbourne, M. âDiversified Miners Are Best Betâ, Australiaâs Paydirt, 1.217 40 (2014)
- Guez, G. âJust 8 percent of Americans are invested in cryptocurrencies, survey saysâhttp://archive.is/Mmvqh
- US Census Bureau, Quick Facts (Accessed 11 June 2018),https://www.census.gov/quickfacts/fact/table/US/PST045217
- Hahm, M. â16.3 million Americans buy and sell bitcoin frequentlyâ (accessed https://finance.yahoo.com/news/16 - 3 million - americans - buy - sell - bitcoin - frequently - html
- Coinbase, About Page (accessed 11 June 2018) http://archive.is/3xPpy
- Statista, âShare of consumers using cryptocurrency as a payment method every day in Europe as of 2016, by countryâ,http://archive.li/czwvf
- net, âWorld Population Pyramidsâ,http://archive.li/Bq9va
- Hileman, G., Rauchs, M. âGlobal Cryptocurrency Benchmarking Studyâ, Centre for Alternative Finance, University of Cambridge, pp 10,http://archive.is/eKjmR
- BitcoinRichlist, âTop 100 Richest Wallet Balances (Dec 2014)âhttp://archive.is/yECCV
- BitcoinRichlist, âTop 100 Richest Bitcoin Addressesâ (June 2018),http://archive.is/Fx3K0
- Bansal, D. âBitcoin Data Science (Pt. 1): HODL Wavesâhttp://archive.is/l7atC
- Fraunhoffer Institute (2013) âLevelized Cost of Electricity â Renewable Energy Technologiesâ (accessed 26 February 2016)http://archive.fo/0KPll
- Ellerman, A., Convery, F., de Perthuis, C. (2010) âPricing Carbon â The European Union Emissions Trading Schemeâ, Cambridge, Cambridge University Press 85-122
- Afuah, A. (1998) âInnovation Management: Strategies, Implementation and Profits - 1st editionâ Oxford: Oxford University Press. 13-46
- Johnson, G., Scholes, K., Whittington, R. (2008) âExploring Strategy- 8th Editionâ, Essex: Pearson 59-6759 Henderson, B. (1976) âThe Rule of Three and Fourâ, s.l.: Boston Consulting Group.
- Sheth, J. N., Sisodia, R. S. (2002) âCompetitive Markets and the Rule of Threeâ, London, Ontario, Canada: Ivey School of Business.
- Pareto, V. (2014) âManual of Political Economyâ, Oxford: Oxford University Press62 Blockchain.info, âBitcoin Hash rate Distributionâ, http://archive.fo/jPsCb
- Deaton, A., Laroque, G. âCompetitive Storage and Commodity Price Dynamicsâ, _Journal of Political Economy_5 896-923 (1996)
- Kilian, L. (2006) âNot All Oil Price Shocks are Alike: Disentangling Demand and Supply Shocks in Crude Oil Marketsâ CERN Discussion Paper No. 5994 1-57
- Mackey, M. âCommodity price fluctuations: Price dependent delays and nonlinearities as explanatory factorsâ, _Journal of Economic Theory_2 497-509 (1989) doi: 10.1016/0022-0531(89)90039-2
- Colangelo, G. âVertical vs. Horiztonal Integration: Pre-emptive Mergingâ, _The Journal of Industrial Economics_3 323-327 (1995) doi: 10.2307/2950583
- Bitmain âAntminer S9i-14TH/sâ,https://shop.bitmain.com/?lang=en ,(accessed 31 July 2018)
- Canaan Creative, 2018, âAvalon 8 Series (Qty 40)- Shipping now Best valueâhttp://archive.is/SkBgK
- info, 2018, âHashrateâ,https://blockchain.info/charts/hash - rate (accessed 14 June 2016)
- Hruska, J., 2013. â Intelâs former chief architect: Mooreâs law will be dead within a decadeâ http://archive.is/9WNf8
- Koomey, J. et al., 2010. Implications of Historical Trends in the Electrical Efficiency of Computing. _IEEE - Annals of the History of Computing,_33(3), pp. 46-54.
- Johnson, P., Marker, T., 2009, âData Centre Energy Efficiency Product Profileâ,http://archive.li/ng9MO
- Song, Z., Zhang, X., Eriksson, C., 2015. âData Center Energy and Cost Saving Evaluationâhttp://archive.is/sEH60
- Ni, J., Bai, X., 2016, âA review of air conditioning energy performance in data centersâ, Renewable and Sustainable Energy Reviews, Volume 67 https://www.researchgate.net/publication/308343722_A_review_of_air_conditioning_energy_performance_in_data_c enters ( accessed 22 June 2018)
- ABC News, 2018, âIceland will soon use more energy mining bitcoins than powering its homesâ,http://archive.is/qW31p
- Malkin, S., 2018, âThe Cheapest (and Best) Places for Bitcoin Miningâ,https://cryptocurrencynews.com/daily news/mining/cheapest - places - mining - bitcoin/ (accessed 22 June 2018)
- info,2018, âTotal Transaction Feesâ,http://archive.is/ct1ZY
- International Energy Agency, 2017. âKey World Energy Statisticsâhttp://archive.is/gYYIw
- Sovacool, B. K., 2008. âValuing the greenhouse gas emissions from nuclear power: A critical survey.â _Economic Policy,_Volume 36, p. 2950. http://archive.is/EaI5W
- Moomaw, W. et al., 2011. Annex II: Methodology. In IPCC: Special Report on Renewable Energy Sources and Climate Change Mitigation, Geneva: IPCC.
- Lazard, 2017. âLevelized Cost of Energy 2017âhttp://archive.is/UwOJA
- Asciento, R. & Lawrence, A., 2013. Will energy prices power US datacenter growth or short-circuit energy efficiency? http://archive.is/RFrKU
- Meyer, D. 2018, âMining a Bitcoin Costs About as Much as Buying One These Daysâhttp://archive.is/flVWv
- Huang, Z. 2018, âThis could be the beginning of the end of Chinaâs dominance in bitcoin miningâhttp://archive.is/DWBla
- Clenfield, J. & Alpeyev, P., 2014. âThe Other Bitcoin Power Struggleâhttp://archive.li/n8qT2
- com, 2018, âSemiconductors Industry Profitabilityâ,http://archive.is/M0XV8
- com, 2018, âComputer Hardware Industry Profitabilityâ,http://archive.is/eqTiw
- Genesis Mining, 2018, âHomepageâ,https://www.genesis - com/ (accessed 14 June 2018)
- Genesis Mining, 2018, âPricingâ,https://www.genesis - com/pricing (accessed 14 June 2018)
- Genesis Mining, 2018, âCustomer Serviceâ,https://www.genesis - com/customer - service (accessed 14 June 2018)
- Malwa, S. 2018, âBitmain Considers Billion Dollar IPO after Expansion in Other Sectorsâhttp://archive.li/IzFkq
- Schmidt, B. 2018, âCryptoâs 32-Year-Old Billionaire Mining King Is Mulling an IPOâhttps://archive.li/v5uXk
- Cheng, E. 2018, âSecretive Chinese bitcoin mining company may have made as much money as Nvidia last yearâhttp://archive.is/mm1qg
- Williams, âEnergy intensity of computer manufacturing: hybrid assessment combining process and economic inputoutput methods,â Environ Sci and Technol, vol. 38, 2004, pp. 6166-6174.
- Australian Bureau of Statistics, 2013, âWaste Account, Australia, Experimental Estimates, 2013 â Electronic and Electrical Wasteâ,http://archive.is/EZHST
- Zhang, K., Schnoor, J., Zeng, E., 2012, âE-Waste Recycling: Where Does it Go from Here?â, Environment, Science, Technology, Vol 46, pp 10861-10867,http://cedar - ca/pdf/E - Waste_Recyling.pdf (accessed 20 June 2018)
- Smith, V., 2003, âEutrophication of Freshwater and Coastal Marine Ecosystems: A Global Problemâ, Environmental Science & Pollution Research, Volume 10, Issue 2, pp 126-139, https://pdfs.semanticscholar.org/057e/8da9c04b59091046e1482828760472713e30.pdf
- World Resources Institute, 2009, âSources of Eutrophication (Table 2)â,http://archive.is/9vbx6
- International Energy Agency, 2012, âKey World Energy Statisticsâ,http://archive.is/Wxlr5
- GĂŒnkaya, Zerrin & Ăzdemir, Alp & Ăzkan, Aysun & Banar, MĂŒfide. (2016). âEnvironmental Performance of Electricity Generation Based on Resources: A Life Cycle Assessment Case Study in Turkeyâ. Sustainability. 8. 1097.10.3390/su8111097. http://www.mdpi.com/2071 - 1050/8/11/1097/pdf
- International Energy Agency, âMember Countriesâ,http://archive.is/ArM1y
- com, âTanzania Energy Profileâ,https://www.tanzaniainvest.com/energy (accessed 6 July 2018)
- Energypedia, âNigeria Energy Situationâ,http://archive.is/z2lCF
- Energypedia, âMexico Energy Situationâ,http://archive.fo/PGgM4
- Laurent, A., Espinosa, N., 2015, âEnvironmental impacts of electricity generation at global, regional and national scales in 1980-2011: What can we learn for future energy planning?âhttp://www.rsc.org/suppdata/ee/c4/c4ee03832k/c4ee03832k1.pdf
- Population Reference Bureau, 2011, â2011 World Population Data Sheetâhttps://assets.prb.org/pdf11/2011population - data - pdf
- Worldometers, 2018, âWorld population by Yearâ,http://archive.fo/ACK7O
- OECD, 2013, âOECD Eurasia Competitiveness Programmeâ,http://www.oecd.org/global relations/Eurasia%20brochureweb.pdf
- Eurostat, 2011, â2011 Censusâ,http://archive.fo/wTjW1
- World Gold Council, 2013 - 2018, âGold Demand Trendsâ,http://archive.li/ioBTj
- Dell, 2017 âEnvironmental Net Benefit of Gold Recyclingâhttp://archive.is/UgzhS
- Barrick Gold Corporation, 2018 âTechnical Report on the Pueblo Viejo Mine, Sanchez Ramirez Province, Dominican Republicâ, pp 16-18 (Table 16-9)
- Barrick Gold Corporation, 2018 âTechnical Report on the Veladero Mine, San Juan Province, Argentinaâ, pp 16-23 (Table 16-11)
- Barrick Gold Corporation, 2016 âTechnical Report on the Cortez Joint Venture Operations, Lander and Eureka Counties, State of Nevada, U.S.Aâ, pp 16-14 (Table 16-6)
- Barrick Gold Corporation, 2017 âTechnical Report on the Goldstrike Mine, Eureka and Elko Counties, State of Nevada, U.S.Aâ, pp 16-5 (Table 16-2), pp 16-13 (Table 16-8)
- Barrick Gold Corporation, 2018, âAnnual Report â 2017â,https://barrick.q4cdn.com/808035602/files/annual report/Barrick - Annual - Report - pdf (accessed 16 June 2016)
- Li, S., Li, N., Li, J., Gao, Y., 2012, âVehicle Cycle Energy and Carbon Dioxide Analysis of Passenger Car in Chinaâ, 2012 AASRI Conference on Power and Energy Systems
- Klocke, F. et al, âSimplified Life Cycle Assessment of a Hybrid Car Body Partâ, 21st CIRP Conference on Life Cycle Engineering, https://ac.els - cdn.com/S221282711400479X/1 - s2.0 - S221282711400479X - main.pdf? tid=b0a3ffbd - fcb1 4da1 - b3db - 6e5c64c1bdb4&acdnat=1529169975_cf97c708ac6e9f9292741e2de1a7fe71
- De Wolf, C. et al, 2017, âMeasuring embodied carbon dioxide equivalent of buildings: A review and critique of current industry practiceâ, Energy and Buildings, Volume 140, pp 68-80
- European Chemical Transport Association, 2011, âGuidelines for measuring and managing CO2 emission from Freight Transport Operationsâ,http://archive.is/w4SLX
- Carstens, A., 2018, âMoney in the Digital Age: what role for Central Banks?â, Bank for International Settlements
- Digiconomist, 2018, âBitcoin Energy Consumption Indexâ,https://digiconomist.net/bitcoin - energy consumption#assumptions (accessed 13 July 2018)
- Bitcoin Wiki, 2014, âMaximum Transaction Rateâ,http://archive.fo/cEbfv
- network, 2018, âLightning Network â Scalable, Instant Bitcoin/Blockchain Transactionsâ,http://archive.fo/ggPPy
- Lightning Network Explorer, 2018,https://lnmainnet.gaben.win (accessed 31 July 2018)
ASIC Resistance is Nothing but a Blockchain Buzzword
By StopAndDecrypt
Posted August 5, 2018

And Changing Bitcoinâs Proof-of-Work is a Futile Endeavor
Introduction
In the wake of the recent and most _(in)_significant push to change Bitcoinâs Proof-of-Work, I thought it would be a good opportunity to score some more brownie points from the community by laying it to rest. Iâm going to discuss the broader topic of hardware specialization (âASIC Resistanceâ), the technical and logical flaws in trying to resist specialized hardware, some history around this, and then Iâll touch on what I hope to be a short lived (and fishy) motion for a Proof-of-Work algorithm change that nobody wants besides two and a half people.
Since the inception of the first alternative-cryptocurrency there has been a need for them to differentiate themselves from Bitcoin, or else it becomes obvious to the bystander (those your coin is appealing to) that itâs just a copy. Theyâre an alternative for a reason, you donât want them to think itâs just a copy because then they dismiss it for what it really isâŠa copy.
Whatâs Derp-Coin?
Oh itâs just like Bitcoin, we copied it.
Why would I use it if everyone else is using Bitcoin?
It has a better name?
Thatâs definitely not a good reason, so we need to replace that really bad reply with something better. Something that seems noteworthy or convincing, not just a new appearance. I wonât be explaining all of these, but hereâs some of the common ones that are used:
- Faster confirmation times (Litecoin)
- Larger blocks (BCash)
- Environmentally friendly (Ethereum)
- Better privacy (Monero)
- ASIC Resistant
So what is ASIC Resistance?
Itâs mining you can do, how does that sound? Does it sound good? Itâs mining designed to stop people from having an âunfair shareâ of the hashpower, so you can join in on the fun and make some money too. Furthermore, it will keep our blockchain âmore decentralizedâ, we know you donât know what that really means but itâs going to work, we promise.
Itâs all nonsense and the reason why is pretty straightforward, but to cover all angles Iâm going to give you the whole rundown.
Index
1: General Overview
- Hashing & Mining: Hash the block, check the hash like a lottery ticket
- General Purpose Processing: Your computers CPU is general purpose
- Application Specific Processing: An ASIC is one variant of this
- Intentional Complexity: Unintentional Consequences
2: Specialization Resistance Strategies
- DifferentâŠBut The Same: Alternative but equitable algorithms
- Memory Intensive Algorithms: Uses different parts of a computer
- External Oracles: Periodically changed by the developers/community
- Programmed Alternation: Periodically changed by the code
3: Where It All Began, And Why Itâs Still Around
- A Blast From The Past: A little bit of history
- When Will It End?: A Gri[m/n] future
4: Late Stage Mining Requires Low Barriers-To-Entry
- Major League Mining: The End Game
- No Lemons?: No Lemonade
5: Changing Bitcoinâs PoW Solves Nothing
- Temporary Relief For Never Ending False Alarms
- Hard-Forks Intrinsically Lack Consensus (with few exceptions)
6: Conclusion
Hashing, Mining, and Pocketknives vs. Scissors
Hashing & Mining
Hashing is the act of scrambling data. You take anything you want, put it into a box, and out comes random 0âs and 1âs. Thereâs a few functions this provides, but generally it letâs you keep the input a secret while sharing the output. Hashing algorithms are a specific set of instructions used to generate a hash. They could be as simple as multiplying by 5 and then dividing by 2. The caveat here is this is completely reversible. You just multiply by 2 then divide by 5, and computers can do this guesswork extremely fast. If you want the input to remain a secret you need something stronger and irreversible. We could add more steps, but itâs the kind of steps that matter. Remember those number pattern recognition tests in high school?

Computers are also really good at those, no matter how complex you make them. If youâre going to standardize a hashing algorithm for everyone to use you need to do more if you want the inputs to remain a secret. Making a process irreversible requires taking the numbers out of the realm of math and âplayingâ with themâŠa lot. Which brings us to Bitcoinâs hashing algorithm, the SHA256 hashing algorithm. Thereâs a lot of material out there that explains what this is but Iâd rather leave that up to you and skip straight to demonstrating it.
Go to this website and enter the following, youâll see the outputs are the same.

https://www.movable-type.co.uk/scripts/sha256.html
See how the outputs are all different? Now that you get the gist, keep adding random values after **blockdata**until the output hash begins with **aaa**. Thatâs all mining is. Itâs just guesswork via trial and error. You can find more extensive detail on what I described above in this video and you can watch someone perform the SHA256 algorithm by hand here.
General Purpose Processing
Running SHA256 on a string of data is a very simple process for a computer. The CPU in the computer youâre reading this from can do it because CPUâs are built like a multitool pocketknife, capable of performing a lot of different kinds of requests. Try and imagine each of these blue dots as a 0 or 1, and the entire machine is a CPU:

Taking the block data and hashing it doesnât require all that machinery, only specific parts. Your CPU can do it, but the rest of that space and energy is wasted, leaving a lot of room for improvement. So letâs create something more specific.
Application Specific Processing

ASIC stands for Application Specific Integrated Circuit. Itâs a type of hardware specialization, but itâs not the only kind. This is one of the causes for confusion on this subject because itâs a common misunderstanding. Itâs similar to calling all Electronic music âTechnoâ. Techno is just a single genre of Electronic music, and ASICs are just a single kind of hardware specialization.
Similarly, ASIC Resistance is just a single kind of Hardware Specialization Resistance, so from here on out I wonât be using the ASIC misnomer, Iâll be addressing it for what it is. Please ignore the title of this article, it was only meant to lure you in with your own misunderstandings.
Iâm inclined to believe that after reading up to this point and seeing the picture below youâll get the idea. Application specific hardware is designed to do one thing, and one thing well. When you get rid of all the useless bells and whistles of a CPU, you end up with much more efficient and specialized hardware.

Intentional Complexity
Complexity is the essence of The Resistance, but it doesnât always come in the same form. In contrast to a simple algorithm like the one above, the general goal of specialization resistance is to make it difficult to design a piece of hardware so that people are forced to use CPUâs or GPUâs.
Logic is as follows:
- If itâs hard to specialize, it canât be or wonât be worth specializing, forcing mining to be done on generic hardware.
- Acquiring hoards of generic hardware will be more expensive for miners looking to expand their venture.
- If mining operations expand slower, smaller ventures wonât be outcompeted, and people at home can play along as well.
- This will keep mining decentralized.
Drawing from the .gif I used above, if SHA256 only required that small aspect of the CPUâs computational abilities, then a specialization resistant algorithm would look something like this:

The issue with this, and with the logic above, is that at some point if your coin is successful enough it will be worth designing specialized hardware for it. Then you end up in a situation where the production supply for that specialized hardware is very centralized, but more on that later.

.
2: Specialization Resistance Strategies
Without getting into the technical mumbo-jumbo Iâd like to go over the different types of resistance strategies that are commonly advertised.
DifferentâŠBut The Same

This oneâs the easiest of the bunch because it explains itself. Some algorithms use the same âpartsâ of a CPU/GPU as SHA256, offering no real difference in computational difficulty, or cost to manufacture. Some other algorithms use multiple parts of the CPU, some of which may be more costly to create specific hardware for, but again this falls short in the end. The only real purpose of these is to say âthey donât make ASICS for theseâ so you can feel fine using your computer at home. Thatâs great and allâŠuntil your coin starts becoming valuable and a company does decide to make dedicated hardware. Litecoin tried this, and now they have specialized mining hardware.
The following article does a wonderful job elaborating on this and other stuff Iâm discussing here:
Memory Intensive Algorithms
I donât think this deserve its own section but itâs so commonly thrown around I need to mention it, else someone may comment saying âYou only talked about CPUâs what about things that use different parts of the computer..like RAM?â
Motherboards connect different kinds of hardware together, yes, so not all kinds of computing take place within the CPU. Some algorithms are designed to require more RAM to generate more hashes. All this does is prevent graphic cards from being used to mine. It does not prevent anyone from coming along and making dedicated hardware for it, and thatâs where it falls short. At best itâs useful as an emergency hard-fork algorithm because no one has made dedicated hardware for this kind yet. It falls short of utility in almost all other cases. The in-development coin Grin, making use of Mimblewimble privacy technology, uses this kind of algorithm, and companies will develop hardware if it ever becomes a viable cryptocurrency (or perceived and valued as such).
External Oracle
This is effectively âsame, but differentâ, except thereâs more than one algorithm, and they change at the leisure of the developers and/or the community. These can be planned ahead of time in intervals, where the new algorithm isnât decided until the last moment, or it could just be spur of the moment whenever âtheyâ feel like mining centralization has become âworryingâ.
Monero is like this. Having started with a typical resistant algorithm, Bitmain ended up developing specialized hardware for it anyway, so âtheyâ decided to spontaneously fork and change the algorithm. This is of course, fine, but the most important distinction here is this is not decentralized, at all, whatsoever, no matter what anyone tries to tell you. Anyone can be bought, blackmailed, or worse, and any sort of âvotingâ mechanism can and will be gamed if the coin becomes valuable enough. Furthermore, this canât go on forever. The network canât keep shutting down old nodes just to hard-fork to a new algorithm. You need a robust and immutable set of code moving forward so infrastructure can be built on top of the network that wonât get disabled by some spontaneous hard-fork out of desperation.
Programmed Alternation
This one takes the selection process and automates it. It doesnât matter how it automates it, all you need to know is that thereâs a set of algorithms it cycles through. All of these algorithms can have specialized hardware designed for it, and again, the only thing preventing this from happening is the price of the coin. If it becomes valuable enough, it will happen. Thereâs also the likelihood of general purpose hashing units being developed that are semi-specialized, which can immediately destroy the initial intent of the alternation without having full-blown specialized hardware developed for it yet. Ravencoin aims to do this by alternating between 16 different algorithms. Like all the other methods described above, the end result is just a system that is more difficult to specialize, not impossible.
3: Where It All Began, And Why Itâs Still Around
A Blast From The Past

https://bitcointalk.org/index.php?topic=45667.0
Intended to be the First, the Best, and remain so into the future.
WellâŠit was the first one. Tenebrix. If youâve heard of it you probably donât need to even read this section. The premise was simple, mining is getting harder and itâs unfair to those without expensive graphics cards, so letâs make something that resists against this.
A lot of people like to toss around the word âscamâ in this ecosystem, but I think it can be a bit off-putting because nobody had a clue back then and if anybody tries to tell you otherwise, well, make your own judgment. I was mining Litecoin in 2013 (made like $20). Iâm not a scammer, and neither was Charlie when he announced it only 15 days after Tenebrix announced theirs. It was just an interesting concept at a time when nobody knew where any of this was going to go.

Of course the issue here is not any particular coin, but how this trend ended up playing out. While one project may have been created out of genuine interest, others were certainly scams, then there was everything in between. This gradient of legitimacy, along with the exponential growth of this space, is important because it helps people understand why we are still seeing this concept of resistance continue to propagate today. If there is no hard line between what is a scam and what isnât, then thereâs no way to definitively move forward and away from the confusion. Some of these coins are still around, with Litecoin being the perfect example. Litecoinâs âsuccessâ is not because of its PoW algorithm, but rather because of how closely itâs managed to mirror Bitcoin, from its development process down to its community and their ideology. This image below was meant to mock another one that floated around, but thereâs some truth to it if you look closely (except LTC did have 150 premined coins, which amounted to literally nothing until very recently):

https://twitter.com/StopAndDecrypt/status/1015988742841163776
This is a testament to the gradient of legitimacy, which Bitcoin maximalists tend to outright dismiss in favor of Bitcoinâs âimmaculate conceptionâ. Itâs fine to think like that, and Iâm one of themâŠbut I wasnât always one of them. Like most people, thereâs an eventual realization that occurs, and like most most people, there are things that hold us back from making that mental switch. If you took all of these people and plotted them weâd get another gradient, a gradient of mindset. You canât expect everyone to instantly change their minds at the same time, and so long as there exists a subset of people that think there is utility in alternative algorithms then the idea is going to propagate, especially to the new waves of people entering this space. This doesnât make the entire group of people that support them scammers, although there are many scammers that exist among them.
And boy do they scamâŠ

https://web.archive.org/web/20140209050500/https://bitcointalk.org/index.php?topic=421615.0

https://bitcointalk.org/index.php?topic=999886.0
DASH (formerly DarkCoin) fanboys will deny the issue with this, but itâs partly why they re-branded, with the other reason being they are no longer pretending to be a privacy coin (dark = private). You can see these scams are multi-faceted, in that they use a âCPU onlyâ algorithm as a one of many selling points to get people interested, but they then go and pre/insta-mine millions of coins without having to worry about competition before releasing it to everyone else. BitcoinTalk is littered with sketchy coin launches just like this, so it makes sense to see one of them become a âmajorâ altcoin. It doesnât make it any more legitimate than the others, but most people just donât know better.
When Will It End?

Cryptocurrencies are not disappearing any time soon, and itâs likely there will always be minority chains that try to achieve the spotlight. While I canât predict when the trend will subside, the amount of coins in existence doubled over the last year alone. A good portion of them are ICOs, but (within the context of this article) more notably is the introduction of new blockchain security methods. The most known of the bunch is Proof-of-Stake, but then thereâs _Delegated-_PoS, Proof-of-Storage, Proof-of-Authority, Proof-of-Work w/Masternodes, Proof-of-Endorsement (??), and Directed Acyclic Graphs âŠ

https://www.coindesk.com/10-years-wont-blockchains/
The list keeps growing, and the waves of blockchain hype are slowly moving away from Proof-of-Work, particularly because itâs portrayed as a waste of energy (more on that below), yet there are still are new coins in development that market themselves as ASIC resistant. As mentioned already, Ravencoin launched recently and it advertises itself as resistant by having the protocol switch between 16 different algorithms. Then thereâs Grin, which is in development, that actually goes about this in a very interesting way. Itâs not trying to be resistant, itâs just trying to be new by using a memory intensive PoW algorithm that will be easy to mass manufacture in the future to avoid GPU farms coming in instantly and dominating the network, allowing it to grow organically the way Bitcoin did. While I donât think altcoins will disappear entirely anytime soon, the outlook for most of them medium-term is grim. I find it unlikely that ASIC resistance will continue to be a major selling point in the future, but likely that the hype-death cycle of altcoins will continue via other means of attraction.

4: Late Stage Mining Requires Low Barriers-To-Entry
In the first two sections I alluded to the underlying issue with trying to resist specialized hardware, and Iâd hope the following conclusion has already been made: You canât stop it. Instead of endlessly trying to stop something you canât, an alternative approach would be to look at the situation rationally and find a new way to think about it.
As the title of this section suggests, I want to discuss the importance of having a low barrier-to-entry into the mining market, particularly in the âend gameâ scenario where a blockchain has become massively adopted. Ultimately this is the only thing that matters, because whatâs the point in creating a temporarily semi-useful blockchain with no positive outlook to its future because only a few select entities can create the required hardware?
Major League Mining
Mining in its current state is chaotic, dirty, sort of disruptable, and there are too many blockchains to go around. Verge was 51% attacked, and it wonât be the last. Hashpower security (in the form of energy expenditure) is slowly starting to prove its necessity. Everyone has their opinion, but many refuse to think 50 or 100 years into the future when it becomes fundamentally important to have a good Proof-of-Work algorithm. If they do consider the future, they reference what we see today and claim itâll have the same issues but worse. Putting the mining skeptics aside who prefer alternative options (like Proof-of-Stake), the pro-mining critics typically point at geographical & manufacturer centralization as growing concerns and will toss around fast-and-loose solutions, like arbitrarily changing the Proof-of-Work to something âbetterâ.

https://twitter.com/CobraBitcoin/status/1014185328054239234
Bitmain doesnât have a monopoly on mining. They have a large stake in hashpower, but itâs not a monopoly. And, theyâre losing more of that stake every day to more energy efficient hardware like Halongâs new DragonMint T1, and other manufacturers that are starting to produce their own ASICs outside of China, like the Japanese Internet giant GMO. I wouldnât be surprised if others are engaging in this development in private as well, just like Halong was until the announcement, so you shouldnât be either.

https://twitter.com/KryptykHex/status/1016019655767547904

https://twitter.com/KryptykHex/status/1014283645132115970
Minings intrinsic properties imply a never-ending race to be the most energy efficient and the end result will be mining on renewable energy, which will encourage farms to grow outside of China and in close proximity of those renewable resources. Weâre already seeing this migration play out without renewable energy in locations where itâs just cheaper to cool off the hardware by being located in a colder climate. It becomes even easier to do this when you can get the hardware manufactured locally, or even do it yourself. So letâs take a step back and think, which is more difficult to manufacture? An advanced piece of hardware like a modern central processing unit, or a very specific and simple to produce chip that performs a very basic hashing algorithm?
If you donât think renewable energy is going to dominate in the future, then you should just check out this publication by the International Energy Agency. Iâll just let some of the data do the talking but add in that in just 2017 alone, renewable energy additions were 40 times the amount of energy Bitcoin mining used in the same year. Weâre going to be in such a surplus of energy that latency (transporting it) will become the energy supply bottleneck as demand grows. Do you think these power companies are going to standby and just let all the extra energy production go to waste? Theyâre going to be producing clean energy at rates faster than they can export it, so where do you think all of that is going to eventually go?


Headline: Lemonade Stand Startups Crippled By New Regulations
Probably the last headline you want to see as a Lemonade Stand entrepreneur when you wake up in the morning. In preparation for this day, you created a list of things that could potentially effect your new Lemonade business:
- Tariffs on Lemon imports (costly to import Lemons from other countries)
- Lemon farming has new regulations (reducing supply, increasing costs)
- Lemon DNA patents are created (others canât farm those kinds of lemons)
- Major Lemon farm burns down (reducing supply, increasing costs)
Wouldnât it be nice if you could just grow Lemons in your own backyard? Or rent your neighbors yard to grow Lemons for just this season, and rent then someone elseâs yard next season if they have better rates? Would you have this freedom if only a limited set of your neighbors had the right kind of soil that could grow Lemon trees? Hopefully you see where Iâm going with this.
When it comes to designing and fabricating hardware to process the PoW algorithm being used in Bitcoin, the last thing you want to see is 50 different companies trying to get the same single fabrication company to create hardware for them. Anyone can do research, but development ends with mass production, even if itâs just a single production run. The more complicated the hardware design is that you need created, the less likely you are to find a variety of chip manufacturers that can do this for you, and the ones ones that do exist may be production bottlenecked, or in some sort of binding contract.
Do you know why mining originally centralized in China? China has less regulations on hardware design, happened to have cheaper electricity (or it was easier to fraudulently get cheaper electricity), and the hardware was relatively easy to produce. Fundamentally though, it was because of the cheap electricity where they wanted to set up mining facility, and a low cost (distance) to transport from the manufacturer to the mining facility.
As renewable energy starts becoming more prominent, what do you think is a better scenario over the long term?
- Complicated hardware designs that only a select few manufacturers can produce, and mining centralizes in distance around these locations.
- Simple hardware designs that many manufacturers can produce, and mining facilities can be reasonably spread out among the globe wherever itâs convenient to use renewable energy sources.
This kind of necessary diversity/distribution/decentralization in hardware production is promoted by a Proof-of-Work algorithm that is the opposite of complicated, the opposite of resistant, and not prone to getting changed.
We went over how new startups are coming online and expanding at this very moment, and that there will be more to come, but what would happen if they were stopped in their tracks?
What would happen if you have, letâs say, 10 manufacturers, but only 2 of them have been producing long enough to see a profit, and then suddenly all of their hardware is rendered obsolete?
Would they all be able to come back from that loss?
Iâd bet 8 of them wonât, so whatâs the point in crippling all of them except the largest ones who can recover from it and just start making new hardware?
10 manufacturers versus 2, which sounds more decentralized?
If you were a startup that was looking into mining, but you made no initial investment yet, what would you do after such a thing occurred?
Would you be more likely, or less likely to keep moving forward knowing that one day all your equipment will become obsolete?
Do you really want people being scared or hesitant to invest into mining?
How would this not result in monopolization of the mining ecosystem?
Why, again, do you think a Proof-of-Work change would help the ecosystem?
5: Changing Bitcoinâs PoW Solves Nothing
Now that Iâve successfully lured you this far into my ramblings, letâs go over some recent talks about trying to change Bitcoinâs Proof-of-Work, and why it Will-Never-Work. If you donât know the difference between hard/soft-forks, hereâs a primer that should be enough for this section.
Temporary Relief For Never Ending False Alarms

This isnât an attack on Luke, itâs just that Luke is the most vocal developer that is pushing for a change, and openly makes it clear that it would have to change again at some point in the future âuntil a better solution is foundâ. This directly implies that Bitcoin doesnât work as is, which I fundamentally disagree with for all the reasons Iâve spoken about up until this point. Bitcoin PoW change advocates are only temporary relieved by their own solution and have nothing to offer that brings finality to the never ending PoW change dilemma their logic puts themselves in. Fortunately Bitcoinâs security is not dependent on our ability to hard-fork the PoW, and its security only grows as more hashpower comes online. This is effectively the External Oracle variant from the 2nd section, where the networkâs security is completely dependent on the communities ability to come to consensus and change the PoW when we all âfeel like itâs necessaryâ. Remember that thing about gradients of people? YeahâŠThen we need to come to full consensus every time we fork the PoW?
Hard-Forks Intrinsically Lack Consensus (with few exceptions)
Below are excerpts of two bitcoin-dev mailing list emails from Anthony Towns. The emails discuss upgrading Bitcoinâs signature scheme from ECDSA to Schnorr. This upgrade, like most to follow, is set to be a soft-fork (one of the benefits of the Segwit soft-fork) that allows all the old functionality to continue existing, while providing the option and incentive to switch to using the new feature. This allows the network of nodes to undergo a sort of plastic upgrade, so that your node continues to function (and not get kicked off) even if you donât upgrade. Additionally, itâs a trivial upgrade, because it doesnât break any of the underlying incentives the network assumes. The suggestion below is to include within the soft-fork a 5 year âtimerâ at which point the network will hard-fork in the upgrade that we would have (by then) already had for 5 years. The hard-fork would then remove additional complexity in the code that was required with the soft-fork to keep the network together.

https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2018-May/015951.html

https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2018-March/015838.html
The logic surrounding this hard-fork proposal is actually quite reasonable. The soft-fork upgrade isnât expected to be contentious in the slightest, it doesnât break anything, doesnât cut your own node off the network, and it only adds in a new feature. The hard-fork that is being proposed tacked on to the end of it makes a single assumption: That within 5 years, most people will have upgraded already anyway. I polled Twitter a while back and these were the anecdotal results:
I firmly consider this to be an extremely reasonable hard-fork (as far as hard-forks go) but I would never support it with results like these. If itâs split 50/50 for such a non-contestable change just because it includes a hard-fork, can you imagine ever reaching consensus on a Proof-of-Work hard-fork with an assortment of drawbacks and unknowns that may negatively affect Bitcoinâs network incentives as a result?

https://twitter.com/LukeDashjr/status/1019579851043475456

https://twitter.com/LukeDashjr/status/1019737295581261824
Unless Bitcoinâs immediate & obvious death is the only alternative, hard-forks are likely to always be contestable, and as such will always lack consensus. I donât agree with the need for a PoW change, most people I engage with donât agree that one is necessary, and thereâs really only a a select few, if not a single Core developer whoâs been pushing for it. I think itâs great that people think differently in this space, but consensus is never going to arrive on this subject, primarily because it solves nothing and only resets the board.
6: Conclusion
To wrap things up, letâs briefly summarize my arguments:
- Hardware specialization resistance is futile.
- The âsuccessâ of altcoins are not reliant on resistance.
- Proof-of-Work algorithms need to be easy to manufacture.
- New altcoins are swimming upstream and must apply 1, 2, and 3.
- Changing a coins Proof-of-Work does nothing for it long term.
- Mining will be running on 100% clean energy in the future.
- Bitcoin mining is not ideally decentralized yet, but itâs certainly improving.
- Hard-forks require predominant consensus, if not impending doom.
- Bitcoin will never change its PoW unless a life threatening vulnerability is found, because the current PoW works.
| [**StopAndDecrypt (@StopAndDecrypt) | Twitter**_The latest Tweets from StopAndDecrypt (@StopAndDecrypt). Full-Stack Social Engineer. somewhere routing around you_twitter.com](https://twitter.com/StopAndDecrypt?ref=hackernoon.com) |

still image for the url
The Bitcoin Second Layer
By Nik Bhatia
Posted August 7, 2018
- 1/4 The Bitcoin Second Layer
- 2/4 The Time Value of Bitcoin
- 3/4 The Bitcoin Risk Spectrum
- 4/4 The Lightning Network Reference Rate

Bitcoinâs antifragile protocol and its exponentially increasing network effects make it a behemoth, gradually swallowing up global economic activity. The latest of these network effects is a second layer protocol called Lightning Network, which uses bitcoinâs base layer protocol as its security. The concept of layered money is not new in monetary history. In this writing, Iâll be using gold as an analogy to describe why bitcoin will evolve in layers on its way to world reserve currency status.
Layered Money
Gold has served as money for millennia due to its unique chemical properties and its global network effects. But gold has not acted as money only in its raw physical form, or on its first layer. Gold is a perfect example of how a layered money system evolves. Letâs take a look at gold as money in a four layered example. Iâll describe the rule set, or protocol, of each gold layer so the reader can imagine similarities to bitcoinâs layered protocol approach.
The first layer of gold is the physical gold in its raw form after it is mined: gold nuggets. The protocol of goldâs base layer has only one rule. The element must adhere to the properties of the periodic tableâs 79th element. If it does, it is gold; if it does not, it is not gold. Consensus around this â79th elementâ protocol is millennia old.
The second layer of gold is raw gold that has been melted and shaped into bars and coins following a standardized protocol of purity, weights, and measures. Mints can be controlled by governments or by private enterprise, but the coinage will only be considered money by users if the â79th elementâ first layer protocol is followed.
The third layer of gold is gold certificates. These are claims issued by banks that have taken gold on deposit. Third layer banks will only use gold coins and bars that follow the consensus second layer protocol of purity, weights, and measures and only from mints that are properly following the â79th elementâ protocol. These certificates can act as money but carry counterparty risk of the issuer.
The fourth layer of gold is certificates backed by bank-issued gold certificates. A liquidity provider can issue these certificates, which would require several layers of trust by the user. Somebody accepting fourth layer gold as money has to trust that the liquidity provider has real gold certificates, which are backed by physical gold at a bank that follows a standardized purity for gold deposits.
Each layer uses the layer beneath it for consensus and security. Money will always see a multiple layered expansion as it evolves, and each layer has costs and benefits. You can mine your own gold, but this process is very expensive with a high barrier to entry. You can buy gold coins and bars easily in most parts of the world, but using them for day to day commerce is unfeasible. As a merchant, you can accept gold coins but either have to trust the purity or assay the gold yourself. Once youâre using the paper certificate layers, you now are engaged in counterparty risk, but have easier capacity for transactions. Each layer serves a different function. Base layers are for final settlement, while higher layers are for facilitation of economic activity.
Bitcoinâs First Layer
Bitcoinâs first layer, or base layer, is a protocol proposed in 2008 that has reached a global state of consensus as it approaches its tenth birthday. Bitcoinâs unit of account, also called bitcoin, has exchange rates with currencies around the world in markets that are growing in depth and liquidity. The protocol itself has added vital updates in its young life that have strengthened both security and usability. The networkâs uptime and its ability to prevent double spends are relentless.
Critics of bitcoin often incorrectly identify a feature of bitcoin, its slow speed, as a flaw. Bitcoinâs confirmation process is meant to be slow because of security reasons. The intent of bitcoin is censorship-resistant, scarce digital cash, not a speedy payments solution. The best way to think about bitcoinâs base layer protocol is as a final settlements layer. The final settlement of physical gold is also a slow, clunky, and expensive process. Imagine, for example, companies in different parts of the world settling large balances of gold by loading ships with physical gold bars and sailing fortunes hundreds of miles across seas. Not only is the delivery an arduous process, but the verification process is also quite a task. In theory, every single piece of metal would have to be tested for purity. This process should be considered as historical context for what is required to have true final settlement of scarce money. The energy consumption required to find valid blocks has dramatically increased over time which increases security, but difficulty adjustments ensure bitcoin still averages six blocks per hour.
Centralization and attack vulnerability, while both permanent concerns to owners of bitcoin, have not prevented huge sums of capital to be stored in bitcoinâs denomination. The denomination, commonly known as BTC, despite its commonly quoted exchange rates with fiat currencies, stands alone as a final settlement asset. With a secure and reliable final settlement layer firmly in place, development of higher layers can ensue: enter the Lightning Network.
Bitcoinâs Second Layer
Lightning Network is a second layer protocol on top of bitcoin. The protocol uses bitcoin as its native denomination, meaning that Lightning can only be used by those with real bitcoin. Under the hood, Lightning Network is a web of bidirectional payment channels, but the protocolâs functionality is beyond the scope of this writing. The important takeaway is that Lightning allows for the instantaneous transfer of bitcoin from peer to peer with one considerable difference from the first layer: channel balances can adjust but do not require immediate settlement on the base layer. Simply stated, Lightning transactions are unsettled bitcoin transactions.
Having unsettled bitcoin comes with risk, however. Bitcoin held in Lightning Network payment channels can be stolen by malicious actors if node operators are not properly monitoring the channels and the base layer. Malicious actors have a strong disincentive to steal, however, as fraudulent activity gives the victim ability to sweep all funds from the channel. Now that we have covered some of Lightning Networkâs basics, letâs take a look at the importance and the significance of this new layer on top of bitcoin.
The Importance of Lightning
Firstly, the Lightning Network is a zero sum, fully reserved routing network. You may only use Lightning if you bring in real bitcoin, and all routing fees earned by liquidity providers are paid for by liquidity consumers. This allows Lightning Network to operate with one of the primary features of bitcoin, its limited supply.
Secondly, Lightning does not carry the burden of base layer confirmation. This allows for bitcoin to be exchanged ad infinitum without consuming precious block space. Lightning nodes can decide to take final settlement of their bitcoin by broadcasting the correct state of a payment channel to the base layer at any time, but they donât have to.
Lastly, Lightning transactions can be interpreted as financial agreements, making Lightning Network a capital market layer. The networkâs structure is built as a market for capital and liquidity. Bitcoin can now instantaneously fly around the world without having to wait an hour for final settlement. The two core components to any financial transaction, time value and risk premium, can be derived from Lightning transactions. Opportunity cost tradeoffs can be calculated, and bitcoin can be leased on a short term basis to the network without surrendering oneâs private keys. With gold, there is no way to accrue positive interest on capital without surrendering the physical metal. This makes Lightning Network an absolute game changer for the entire concept of capital markets: income without explicit counterparty default risk.
Conclusion
Bitcoin is often referred to as digital gold, but Iâll propose a more specific analogy. Bitcoinâs base layer is like digital physical gold, while Lightning Network is like digital paper gold but without the counterparty risk. The second layer is unsettled and less secure, but infinitely more usable. Bitcoin is incredible at censorship resistance and decentralization, but frankly terrible at speed and efficiency. Critics of bitcoin completely miss the fact that speed and efficiency should take place on higher layers, NOT on the base layer. Lightningâs arrival will show the world bitcoinâs true capabilities. If gold could only be used as a physical metal, global economic activity would have been prohibitive on a gold standard. Thankfully, paper gold satisfied the liquidity and capital market layer. Lightning Network ensures bitcoinâs path to global reserve currency because it makes bitcoin come alive. Once bitcoin can be transacted around the world without the constraint of a slow confirmation process, it can graduate from reserve asset to reserve currency. Lightning Network finally frees bitcoin from its base layer shackles.
Further Reading
This article is a prelude to my previous work. I have decided to make this article Part 1 of 4 in my series âThe Lightning Network Reference Rate.â Please also check out the second and third parts of this four part series. In Part 2, âThe Time Value of Bitcoin,â I introduce the concept of LNRR, or the Lightning Network Reference Rate. In Part 3, âThe Bitcoin Risk Spectrum,â I discuss the reasons why LNRR can be a monumental innovation for bitcoin denominated capital markets. Part 4, coming soon, will be titled âThe Lightning Network Reference Rate.â
The case for central bank controlled digital currencies
By Tamas Blummer
Posted August 10, 2018
I argue in this writing that central bank controlled digital currencies will soon challenge Bitcoin. The main motivation thereby is to allow for sustained and significant negative interest rates.
Negative interest rates are needed for a continuation of demand targeting monetary policies. Implementation of negative rates is however severally restricted by the presence of paper cash that earns 0% interest.
Bets on interest rates
Borrowing or lending money is also a bet on interest rates. Rising interest rates make an earlier borrowing a good deal, since one got money cheaper than it would cost getting it now. The opposite holds for the lending. By similar argument falling interest rates benefit lenders and harm those who already borrowed.
Below chart shows that outstanding bets on interest rates are rather significant, but does not imply any net wealth effect of bets, since for every debtor there is a creditor.

We have however special creditors esp. since âQuantitative Easingâ: The central banks. The Fed and the like purchased both public and private debt in significant quantities. Purchasing debt is economically equivalent to lending the money to the debtor and becoming the creditor.

A central bank is a very special creditor since it prints the money. Printing additional money is at no cost to a central bank since it has no obligation to convert it to Gold or anything else. Absorbing loss on bets is therefore at no cost for a central bank.
The worst that can happen to the central bank is that it would need to explain a nominal loss to the government, which should not be a challenge as it is not obliged to generate profit and losses can be covered with newly printed money, also arguments how its loss benefits the rest of the economy can be easily constructed.
Profit on bets of the central bank however strengthens its position. The profit generated is a welcome source of government funding which central banks proudly offer as if it was a good measure of their work. See Ben Bernanke on QE profits here.
The securities purchased by the central bank increase its negotiation power should the central bank had an issue to settle with an indebted market participant, which is often the government. This is visible on the surface in case of the ECB that is able to relatively benefit or punish EUR governments through allocation of its asset purchases.
With the central bank we have a huge market participant that gains power with falling interest rates but is not harmed by rising rates.
Why interest rates keep falling since decades
While working at the trading desk of a big investment bank I learned the most important rule of financial markets:
Markets tend to move such that it hurts the majority.
This is simple to see on the long run: Markets do not create wealth, they distribute it. A winning majority would require additional wealth created, but there is nothing that prevents a winning minority.
It is not that simple on the short run: Inflated asset prices can create the illusion of increased wealth of the majority, until only a minority of them tries to cash out.
Back to interest rates: Since central banks are immune to losing bets, we have no longer an equal magnitude of pain associated with both directions of interest rate moves.
- Falling interest rates hurt all in debt and benefit all creditors including the central bank.
- Raising interest rates benefit all in debt but does not hurt one big creditor the central bank. A majority, those in debt, would win.
Since the majority can not win on the long run, we should see the first alternative materialize in trend (after central banks were relieved the obligation to convert money into Gold or anything else). Indeed, we have seen a trend of falling interest rates for decades, end even more since QE.

How to sustain a negative interest rate?
The zero interest rate line poses an obstacle to continuation of this trend. The problem is that there is an asset that preserves nominal value: Cash. Cash earns guaranteed 0% interest.
The central bank can drive interest rates below 0% for bank deposits, but not for paper cash. Sub zero deposit rates present a cost to banks that they can not forward to consumer, since consumer would rather take out their deposit in cash than to accept significant saving costs. Going further below zero would endanger banksâ profitability or trigger bank runs. None of them is an option that sustains the current system.
To perpetuate the current state of affairs, the central bank needs to get rid of paper cash. The war on cash is already ongoing supported with arguments of fighting tax evasion and money laundering. Those are valid arguments, but much less significant than the vested interests to perpetuate the current monetary system.
Central bank controlled digital currency
A digital currency offers the perfect tool to continue or improve on current trends:
- A distributed ledger can be designed to offer better controls of tax evasion and money laundering than paper cash. This is the case even with current Bitcoin.
- Currency in circulation could be easily audited.
- Money distribution could be better targeted (helicopter money).
- Negative interest rates on a digital currency could be implemented deterministically through a consensus rule that links token value with its age.
Since we have the technology and strong motivation of incumbents, I believe it is only a matter of time until central bank controlled digital currencies will arrive.
The road forward
Bitcoin will be challenged and the potential traction of central bank issued digital currencies should not be underestimated. We will see an intense competition of these concepts. I remain confident that Bitcoin, due to its uncompromising rule set and design, will achieve its destiny and become the global reserve currency on the long run.
A domestic or domain specific digital currency might prevail parallel to Bitcoin provided it offers even better usability in its domain. People will trade off negative interest rate for better usability and to avoid the market risk of the reserve currency.
I thank Dr. Saifedean Ammous for his feedback on this writing.
Media Coverage of Bitcoin Is Still a Total Disaster
A recent Washington Post article shows how journalists get cryptocurrency wrong
Nic Carter
August 11, 2018
I âm fed up with journalists who are either ignorant or unwilling to learn about cryptocurrency holding forth on its perceived weaknesses. Recently, the Washington Post published a piece entitled âBitcoin is still a disasterâ by economic affairs reporter Matt OâBrien, which I feel relies on mistaken assumptions to paint a misleading picture of the world. Today, Iâd like to engage with some of the claims made in the piece, and show how OâBrienâââamong many othersâââget it wrong.
Claim: Currencies are meant to be stable
âThereâs one thing a currency is supposed to do that bitcoin never has. Thatâs maintain a stable value.â
This assumes that bitcoin is a currency, and that the definition of currency is normative (âx should do yâ) as opposed to descriptive (âthings of type x have the qualities y and zâ). Iâd classify Bitcoin the protocol as a complete monetary system, and bitcoin the unit of value as a commodity money, which has the potential to become a gold-like reserve currency. Commodities fluctuateâââthatâs what they do.
Additionally, currency isnât meant to maintain a stable value. Monetary policy is used for a variety of macroeconomic objectives, including targeting GDP growth, unemployment rates, inflation, trade balances, and more. If stability was the objective, the Federal Reserve Board would target zero percent inflation rather than the two percent that it currently does. Am I moving the goalposts? Itâs matter of figuring out how bitcoin is used, and what it was intended for. Iâm not sure [bitcoin creator] Satoshi Nakamoto ever defined bitcoin as a currency. He defines it as a system for electronic transactions, a peer-to-peer version of electronic cash, and an electronic payment system. He envisions bitcoin as a protocol and a bearer digital unit of value.
The interpretation of bitcoin as a currency is mostly inferred by outsiders imposing a particular view upon the protocol. Unburdened by priors, a neutral analyst would probably describe it as something similar to gold. In fact, Satoshi described PoW (proof-of-work) with a reference to gold mining, and later discussed bitcoin as analogous to a scarce, inert, infinitely portable metal which might develop a monetary premium. He clearly saw it as a gold-like commodity which would recapture those same properties in the digital realm, and I think this the most fitting interpretation of the system.
Claim: Bitcoin was designed with volatility in mind
âWhy has bitcoinâs price been so up-and-down? Well, part of it is that it was designed that way.â
This is an odd rewrite of history, or more charitably, a very strange interpretation of bitcoinâs purpose. The impossible trinity tells that itâs impossible to have free capital flow, sovereign monetary policy, and a fixed exchange rate all at the same time. Bitcoin was designed with sovereign monetary policy and a free flow of capital. No one underwrites or backs bitcoin, so it cannot be pegged to a real-world basket of goods. Thatâs the same with gold. Both have emergent monetary premia. This canât be planned forâââit just so happened that way. Needless to say, Satoshi didnât design bitcoin to be unstable, he wanted to solve the problem of double spends with digital cash such that it didnât rely on a single validator. Its volatility is an emergent property, not a design objective.
Claim: Validating transactions is the source of its computational overhead
â[âŠ] the problem [with a decentralized network] was that the only way to do that would be for every member of that network to keep a record of every bitcoin transaction there had ever beenâââthat way they knew who had bitcoin to spendâââwhich would require_a lot _of computing power.â
This is a common misconception. PoW and mining ensures that the network deterministically converges to a shared history, without any subjectivity or off-chain coordination. The fact that the minted units have value means that miners are incentivized to behave appropriately in the short and medium term. And the fact that those units are worth $x means that miners will pay anything up to $x to obtain them. This is the source of the large quantities of computing power allocated to the networkâââthe combination of efficient mining hardware and large amounts of value at stake.
The validation and record-keeping is behavior conducted by full nodes, not miners. The cost of maintaining the bitcoin data store is an externality pushed onto full nodes through bandwidth and storage costs. This is NOT the job of miners. This is a basic distinction lost on many.
Claim: Bitcoinâs volatility is unnatural
âBut even this inbuilt volatility doesnât fully explain why bitcoin has been on such a roller-coaster ride. Something else must be going on, and that something is plain-old manipulation.â
Volatility isnât inbuilt, itâs a feature of every non-pegged economic asset. The Post should keep its fragilista-thinking to itself.
Does the Post have any proof that markets are not long-term efficient? If so, they have a Nobel prize in economics to collect.
Plain old manipulation? You really mean to tell me you think a $100 billion network was manipulated into existence? Is it so difficult to accept that bitcoin provides a differentiated, useful service to millions of people worldwide, and thatâs why it has value? Does the Post have any proof that markets are not long-term efficient? If so, they have a Nobel prize in economics to collect.
â[âŠ] what seems to still be happening in 2018 with various pump-and-dump schemes.â
Donât conflate bitcoin with random worthless altcoins. There is a lot of PND [pump-and-dump] in this industry, but it is infeasible in the extreme to PND bitcoin. If youâre part of a PND group, you target alts in the $50â$300 million range, not bitcoin.
Claim: Bitcoin is only used as a currency due to the wealth effect
âThe first is that what makes bitcoin work as a way to transfer thingsâââthe expectation that its price will keep rising.â
Thatâs not what makes it work. It works as a way to transfer things because itâs a pretty good distributed clearinghouse for value. If bitcoin were stagnant at $1000 for the next ten years, it would remain a good way to transfer things.
During the 18-month bear market that began in January 2014, people still used bitcoin. In fact, usage grew consistently the entire time.
Price (solid red line) and transaction count (shaded red area) during the 2014â16 bear market. Image: Coin Metrics
Bitcoin offers transactors a rival benefit; something they cannot find anywhere else. Itâs unique among cryptocurrencies, as it boasts the best reliability, uptime, dedicated track record, and protocol developer community. Itâs unique among monetary assets because it offers properties not instantiated by gold or the USD. Thereâs a reason people choose bitcoin.
Claim: Bitcoinâs deflationary characteristics mean that no one uses it
âWhy spend $100 worth of bitcoin today if you think itâs going to be worth $1,000 in a not-too-distant tomorrow? You wouldnât. And people arenât.â
Shameless plug: I urge you to consult my website Coin Metrics, where we make this data free and available so anyone can use it. Conservatively, bitcoin saw $2.5 billion in on-chain transaction volume yesterday. Thatâs omitting all the off-chain transactions that occur on Opendimes, on second-layer networks like Lightning, and internally at Xapo and at Coinbase.
Image: Coin Metrics
In the last year, bitcoin routinely hosted the transfer of $2B worth of bitcoin a day, up to a peak of about $16B of bitcoin a day. Thatâs a lot of fake transactions. The anticipated response to this from the skeptic is that on-chain volumes are just a clearinghouse for the multitude of exchanges worldwide, or simply a way for individuals to access the altcoin casino. The former is probably true; we have good evidence that bitcoin is mostly an industrial network dominated by exchanges and power users rather than one that caters to end-users. Using the rough heuristic that industrial users tend to batch transactions, we can see that 30â40 percent of the network is industrialized in this manner.
Thereâs nothing wrong with this. It simply means that bitcoin acts as a decentralized global settlement network for a number of endpoints that connect it to everyday economic systems, with which users transact at the individual level. This is pretty radical! A decentralized, neutral, untamperable central bank that settles flows on a continuous basis between a global network of smaller banks (exchanges, merchants, and custodians). What a concept.
As for the âbitcoin as an on-ramp to the altcoin casino view,â if this were true, then bitcoin would have cratered along with altcoins as they fell 80â90 percent over the last six months. However, bitcoin has shown great strength against altcoins during the bear market. If you look at any index, bitcoin has regained dominance. This pokes holes in the story that it is only used for access to altcoin pump and dumps.
For context, hereâs the Bletchley total market index quoted in bitcoins since December. Ever since the contraction began in January, bitcoin has strengthened against the rest of the cryptoasset market.
Image: Bletchley Indexes
You wouldnât expect this if bitcoin was only a vehicle for speculation on other cryptocurrencies. Clearly, there is demand for bitcoin in its own right.
Claim: Bitcoin is illiquid and hence manipulated
âThis lack of liquidity makes it pretty easy for a few fraudsters to push the price up quite a bit.â
This isnât the case, and relies on a flawed reading of the Tether situation. Fundamentally, bitcoin is quite liquid. It has huge volumes on listed exchanges, and probably the same amount again on over-the-counter providers like Cumberland, Circle, Genesis, and Octagon.
Much illiquid. Very manipulation. Image: Coin Metrics
Even if you subtract all Tether volume, and all volume from synthetic exchanges like BitMEX, and all swaps and futures volume from the CME and CBOE, you have robust volumes. The market for BTC â fiat (on the right in the chart below) is also quite liquid.
Image: Nomics
If you look at the market for fully-regulated futures exchanges, the picture is sunny.
CME daily volumes (contracts are for 5 BTC). Image: CME Group
Yesterday, 7077 contracts were traded at the CMEâââequivalent to $215 million. The liquidity picture is strong, and improving.
Claim: Bearer assets are dangerous and illegal
âThereâs a reason, after all, why bitcoin has attracted so many scammers: All its transactions are irreversible.â
You have to take the bad with the good. Itâs a digital bearer asset, which is completely new. Of course people want to scam with itâââitâs the best money ever invented. That USD is never used by scammers, right?
âAll of which is to say that if you steal a bitcoin, you get to keep a bitcoin.â
If you earn a bitcoin, you get to keep a bitcoin. If you mine a bitcoin, you get to keep a bitcoin. Strong property rights are a hell of a thing. This is just an incentive to build more secure wallet and custody software. Weâre halfway there already.
Claim: Bitcoin still relies on a trusted set of intermediaries
âBitcoiners think all of this is worth it. That itâs better to have a financial system that is clunkier, costlier and more vulnerable to attacks than it is to have to trust someoneâââor, more accurately, to_admit _that you have to trust someone.â
Using bitcoin doesnât rely on trust in an individual. If you run a node, use a hardware wallet or a well-concealed paper wallet, and maintain good opsec, you are pretty much set. Of course, to obtain your bitcoin, you may have to use Gemini/GDAX/Square. But no one is forcing you to hold your bitcoin on an exchange. Itâs only long-term storage on an exchange which requires significant trust in the institution. And bitcoiners universally, vociferously, encourage people not to do that.
Nothing backs bitcoin or pegs it to a basket of assets. Thatâs the point. Bitcoin was designed specifically to avoid the influence of a single authority.
More broadly, bitcoin doesnât remove trust entirely. Thatâs a straw man frequently knocked down by critics. Bitcoin reduces the need for trust in a single institution. Instead, you just have to trust that the code is well-vetted in the typical FOSS [free and open-source software] manner, that the economics that underscore mining continue to hold, and that discrete log problem is still hard. We have plenty of evidence that these things all hold, and will continue to hold. And we have plenty of evidence that, conversely, a single institution in control of the money supply will always abuse its power. If you donât believe me, just check out whatâs happening in Turkey today. Seignorage is a drugâââand itâs pretty much impossible to kick the habit.
âBitcoin exchanges require some measure of [trust] whether they realize it or not.â
Centralized exchanges do. There exist non-custodial peer-to-peer exchanges, like Hodl Hodl and Bisq, for bitcoin. LocalBitcoins is another peer-to-peer exchange that places reduced reliance on a single intermediary. Even centralized exchanges can conduct periodic proofs of solvency, if users demand it. And, as with the rest of finance, if the brokerages/exchanges/clearinghouses are regulated under functional regimes, they are strongly incentivized not to run fractional reserves or lose user funds.
The broader point here is that relying on centralized exchanges is inevitable. Many people will trade off decentralization for convenience, and we canât stop that. We can demand that exchanges behave appropriately. There are many exchanges and custodians with long histories of robustness, resilience, and integrity. There is a market for exchanges, and the badly-run ones will fail.
To sum up
The problem with this article is that the pundit in question has settled on a narrativeâââbitcoin is a poor economic systemâââand then searched for various datapoints that confirm his view. Bitcoin is volatile, yes. It is an emerging commodity-money thatâs becoming financialized and growing from a small tribe of enthusiasts to a global user base. Of course itâs volatile. Growth is not linear. Only fragilistas demand it to be so.
Nothing backs bitcoin or pegs it to a basket of assets. Thatâs the point. Bitcoin was designed specifically to avoid the influence of a single authority. Bitcoin is priced exactly where it ought to beâââthis is always true. Manipulation might work on a 15-minute time frame, but itâs just implausible in the extreme that a $100 billion-plus asset class has been manipulated into existence.
Yes, bitcoin relies on exchanges to provide exit ramps for individuals that want to reduce their reliance on sovereign currencies. Sometimes those exchanges get hacked and fail. That is entirely natural. Bitcoin continues to chug along unaffected. Itâs extremely popular; its strong assurances and settlement guarantees grant it daily volumes in the billions. It is a single order of magnitude behind Visaâs economic throughputâââthatâs right, just one 10x away. The gap will probably be closed in the next year. It has an unmatched record of reliability, resilience, and resistance to cooption. For a nine-year-old, this is a pretty good track record. If it were a human, it would be midway through the fourth grade.
Pundits will continue to ignore this; not because theyâre incapable of reading the data, but because they donât want to. They are deeply afraid of the world that bitcoin threatens to bring about. They prefer a paternalistic, easy-money regime, where occupations like punditry are profitable. Bitcoin promises accountability and a hard money standard. It threatens the existence of bailouts, moral hazard, and fiat-inflationism. In Bitcoinland, the only way to acquire wealth is to work for it. Cronyism doesnât work, as the central bank of bitcoin is entirely indifferent to politics and lobbying. This offends the sensibilities of the partisans writing for the Post.
Bottom line, the central premise of the article is wrong:
âThereâs one thing a currency is supposed to do that bitcoin never has. Thatâs maintain a stable value.â
Bitcoin isnât designed to have a stable value. That just quite frankly isnât what Satoshi set out to build, and thatâs not the system we have today. Artificial stabilityâââshorting volatilityâââleaves you destined for a blowup. That is the fate of any non-fully-backed stablecoin. Bitcoin is designed to solve the double spend problem for digital cash, and to provide a predictable monetary policy. It does that very well, it has done that for the last nine and a half years, and it will continue doing that for the foreseeable future. Demanding low volatility on top of that is farcical, and betrays deep ignorance about the tradeoffs inherent in monetary systems, and the way that financial markets work more generally.
Bitcoin is still an emerging, youthful asset. It hasnât reached maturity. It has somewhere in the realm of 50â100 million holders/users; thatâs global penetration of a percentage point or two. The base layer still hasnât been nailed down, let alone the next layers up on the stack. Development is deliberate and careful, because this is money weâre talking about, not a consumer app. Governance is hard to organize; consensus is difficult to obtain. The internet wasnât built in a day, and neither will the protocols for transmitting value trustlessly.
Since the market is constantly revising its expectations for bitcoin, amid a backdrop of growing, unsteady adoption, its exchange rate is volatile. No one is forcing you to hold it; it is totally opt-in. Bitcoin may not make sense for Westerners who live under somewhat credible monetary regimes, but it might be a good bet for an Iranian, a Venezuelan, a Turk, or anyone else who mistrusts their monetary authorities. Truthfully, mechanisms to bring bitcoin to these disempowered groups are still lacking or nonexistent. But they have the right to money that isnât controlled and minted by a hostile state. This is why bitcoiners work to make global access to this economic institution a reality.
Bitcoinâs complexity doesnât acquit these pundits for getting simple facts about bitcoin blatantly wrong. And ultimately, their ignorance hurts their bottom line. Being amateurishly wrong about basic details of a system that is widely-understood undermines their integrity and makes readers question their work. The Postâs owner Jeff Bezos should understand this and demand more from his employees.
I f any of this resonates with you, and you want to learn about this novel economic system, here are some sources I recommend for a better understanding of bitcoin:
- Coin Metrics: no-nonsense open data and charting platform informing users about the actual usage of cryptocurrencies (full disclosure: I am a Coin Metrics cofounder)
- Bitcoin Visuals: charts and visuals relating to bitcoin and the Lightning network
- Jameson Loppâs list of Bitcoin resources
- âBitcoinâs Academic Pedigree,â Arvind Narayanan and Jeremy Clark
- BitMEX research: long-form investigations into bitcoin economics, the Tether mystery, and market dynamics
Thank you to hasufly and Larry Sukernik for their feedback.
Bitcoin, Stock & Flow
By Hugo Nguyen
Posted August 15, 2018
Bitcoin is protected by a combination of stock & flow.
What is stock? And what is flow?
In general terms, flow is defined as a quantity which is measured over a period of time. Flow is the rate of change. Examples include business earnings, cash flows, national GDP, rate of depreciation, mortgage payments, number of births/deaths per year, rate of carbon dioxide extraction by plants, etc.
Stock, on the other hand, is defined as an accumulation of flows over time, and is measured at one particular moment in time. Mathematically, stock is an integral function. Stock can also be depleted with outflows (negative flows). Examples include business capital, inventory, house equity, total oil reserve, total carbon dioxide concentration in the atmosphere, etc.
In accounting terms, stock is typically represented in the balance sheet, and flow is represented in the income statement.
What does all this have to do with Bitcoin?
It turns out that Bitcoin economics is also governed by stock & flow variables.
Bitcoin: stock vs. flow
Flow in Bitcoin is the total amount of reward per blockâââwith a new block getting mined roughly every 10 minutes. During the bootstrapping phase of Bitcoin, flow consists of a nominal amount of transaction fees and a block subsidy.
When Bitcoin eventually takes off its âtraining wheelsâ (block subsidy goes away completely), flow will then consist purely of transaction fees.
Stock in Bitcoin is the specialized mining equipment, which has evolved into ASICs [1][2]. It is important to realize that mining equipment is also a manifestation of fees. They represent the potential stream of fees earned in the future, discounted back to the present. This is what we mean by âintegration of flowsâ.
Bitcoin, in essence, is protected by (i) the fees today and (ii) a stream of fees in the future (manifested in the mining equipment). A combination of stock & flow.
Understanding this basic fact helps us develop better models for understanding Bitcoin security. E.g., things such as the true cost of a majority attack.
[1]: Mining equipment is a stock as long as Proof-of-Work mining requires highly specialized & non-repurposable equipment. In some PoW cryptocurrencies, the equipment is repurposable, which makes the currencies vulnerable to rental attacks. Renting changes mining equipment from stock to flow, and potentially reduces the cost of attack for the attacker.
[2]: Mining stock provides security to the extent that it is sufficiently decentralized. A high level of mining centralization exposes Bitcoin to threats such as government takeovers, and is a legitimate concern.
The Store of Value Thesis
By Qiao Wang and Dan McArdle
Posted August 19, 2018
Introduction
One way of thinking about cryptoasset valuation says that only assets that can become a store of value (SoV) are deserving of high network value. This is a mental model that has been around for a while, and one that we largely hold when making investment decisions. So letâs unpack it.
You might think that high usage leads to high network value, i.e., if millions of people use a coin as cross-border payment or as gas for dapps, it must be valuable, right?
Generally, this can only be true if users want to hold the coin for a while, in addition to actually using it. If you want to use a coin that you donât already own, but everyone who has the coin today just wants to hang on to it, you have to offer people a high enough price for it that theyâll let go. Conversely, if users are willing to get rid of the coin right after theyâre done using it, thereâs almost always more than enough to go around and no one has to bid up the price in order to use the network.
So whether or not a cryptoasset will become a SoV boils down to the following question: why would people want to hold an asset for a long time versus a short time?
First-order properties
We believe that a cryptoasset must satisfy three properties in order to become a SoV that people are willing to hang on to.
- Immunity to theft
- Credibly low inflation
- Low cost of conversion
1) Immunity to theft
For a network to have this property, it needs to be immune from malicious actors who may wish to steal from accounts/balances. For instance, they could exploit buggy smart contracts you interact with, reverse a transaction that was sent to you, prevent you from making transactions, or obtain your private key.
2) Credibly low inflation
Not wanting to be inflated away is obvious, but the word âcrediblyâ here is key. Many monies or cryptoassets may claim to have low or no inflation, but they arenât necessarily structured so that thatâs believable. Is the network technically secure against an attacker who might try to change its rules by force? Outside of attack scenarios, who sets the monetary policy and are they incentivized to modify it?
3) Low cost of conversion
Axiomatically, a SoV is something which we donât need now but can expect to be able to convert to another product or service that we need at some point in the future. As such, itâs not a good SoV if conversion is expected to be expensive.
If you think about it, a SoV really is just a combination of three things. 1) You can store it securely. 2) It cannot be reproduced easily. 3) You can trade it or use it cheaply.
Second-order properties
Those are three first order properties of a good SoV. But we can further deduce second-order properties that lead to these first-order properties. In order words, what are the means to these ends?
1) Immunity to theft requires
- Small software attack surface. For instance, Ethereum has larger attack surface than Bitcoin does, as it can perform more complex smart contracts. As such, Ethereum holders have endured hacks like those of the DAO and Parity.
- High cost of 51% attack. The attacker could reverse a transaction that was sent to you. Hereâs a comparison of cost of attack between DCR and BTC.
- Decentralization. Similarly to the above, centralization increases the risk of transaction reversals .
- Privacy. Government or malicious individuals could physically force you to surrender your coins if they can easily identify your blockchain activity with your addresses.
2) Credibly low inflation requires
- Small software attack surface. Are there bugs that attackers can exploit to create a large number of coins?
- Decentralization. Are there one or a few powerful actors who can change the monetary policy?
- Collective commitment to low inflation. This is almost tautological, but different cryptonetworks do exhibit different levels of commitment. Early Bitcoin adoptersâ uncompromising commitment to a fixed monetary supply attract like-minded people.
3) Low cost of conversion requires
- Utility. Higher utility means there are more opportunities to directly transact in the cryptoasset, and that more people need to trade their fiat for crypto in order to use it, leading to higher market liquidity.
- Decentralization.Greater decentralization makes it harder for anyone to censor transactions that involve a conversion of SoV for something else.
As a side note, interestingly, decentralization is required for all three. This is why the crypto community values decentralization so much. It is the only obvious means by which a network can make credible statements about its properties of immunity to theft, low inflation, and uncensorable transactions.
Deeper Look at âLow cost of conversionâ
1) Immunity to theft and 2) credibly low inflation, as well as the second-order properties associated with them, appear to be commonly accepted by the community. But 3) low cost of conversion is the one that doesnât seem to have gotten much attention. Letâs take a deeper look at it and its second-order properties: utility and decentralization.
Utility
As previously mentioned, an asset is not a good SoV if the cost of conversion is high. Furthermore, there are two ways to convert cryptos to something else: indirectly via fiat or directly.
Indirect conversion cost is determined by crypto-fiat liquidity. The latter, among other things, is a function of the current utility, as one must trade fiat for the crypto to in order to use it, and the level of speculation on future utility.
But ultimately, cryptonetworks should aim for as much direct conversion as possible (e.g., purchase with BTC, run dapps with ETH), because by definition itâs cheaper than indirect conversion. And direct conversion is, indeed, current utility.
This line of reasoning suggests that utility is important for both indirect conversion and direct conversion and, by extension, SoV. As an illustrative question, will gold depreciate over time as new technologies like fiat and crypto become more widely utilized as as media of exchange? Our hunch is yes.
Decentralization
But cost of conversion doesnât have to be financial. It can also be opportunity cost or mental cost.
In both indirect conversion and direct conversion, censoring transactions and uncertain monetary policies leads to opportunity cost and mental cost. Decentralization improves censorship-resistance and monetary policy stability, thereby reducing cost of conversion.
At the extreme, if network validators can censor transactions from certain addresses indefinitely, i.e., the cost of conversion is infinite, then the owner has practically forfeited their assets.
Conclusion
We believe that value will ultimately accrue to SoV cryptoassets, and we provide a framework for thinking about SoV properties. In particular, we reason from the ground up by laying out three first-order properties, which in turn are induced by multiple second-order properties.
But the framework doesnât stop here. One can build up from these second-order properties to discover even higher-order properties. Each of these merits a essay that is beyond of the scope of this one.
Take âdecentralizationâ for instance. Higher-order properties that lead to greater decentralization include:
- Founder myth
- Gini coefficient
- Independent development teams
- Cost of operating a node
What about âutilityâ? Examples of higher-order properties that contribute to utility are:
- Programmability
- Development infrastructure
- Scalability
A second-order property could even be a third-order property associated with another second-order property. For instance, in the False Dichotomy of Utility and Store of Value, we argue that utility leads to greater decentralization and higher cost of majority attack.

In short, valuing an early-stage cryptoassets boils down to the question of how likely it will acquire and maintain the first, second, and higher-order properties of SoV described in this post. By way of example, BTC is arguably the best at immunity to theft and credibly low inflation, but will it achieve more utility than say, ETH? EOS has a shot at surpassing ETH utility-wise, but will it ever be as decentralized?
Meltem Demirors (@Melt_Dem) on X
By https://x.com/Melt_Dem
Posted August 19, 2018
Post
Post
$
$
Meltem Demirors on X: â1/ decentralization is a myth. we use âdecentralizedâ without any specificity as to what that actually means. letâs untangle the idea of decentralization. i developed a basic grid that breaks it down at the protocol, network, and app layer (dated april 2018) https://t.co/pbVd52Qgvaâ
$
Meltem Demirors@Melt_Dem1/ decentralization is a myth. we use âdecentralizedâ without any specificity as to what that actually means. letâs untangle the idea of decentralization. i developed a basic grid that breaks it down at the protocol, network, and app layer (dated april 2018)2:46 PM · Aug 19, 2018
Meltem Demirors@Melt_DemAug 19, 20182/ a good chunk of the data comes from arewedecentralizedyet.com - the brainchild of @ ummjackson - who was continuously harassed by some of the projects on his site that are⊠ummm⊠clearly not âdecentralizedâ in any manner while marketing that narrative ad nauseum

Meltem Demirors@Melt_DemAug 19, 20183/ there are many different ways to view âdecentralizationâ - @ SarahJamieLewis wrote about this as well - great tweetstorm here

Sarah Jamie Lewis@SarahJamieLewisAug 14, 2018Since many of my twitter fights devolve into people saying âbut itâs actually not centralized thoâ, letâs talk about wtf decentralization actually means. This tweetstorm has background reading. fieldnotes.resistant.tech/defensive-deceâŠ

Meltem Demirors@Melt_DemAug 19, 20184/ on a recent episode of unchained with @ laurashin, my friend and fellow absurdist @ _jillruth spoke at length about the need for more specificity and analytical rigor in the crypto ânarrative.â decentralization exists on a spectrum, not as an absolute. unchained.forbes.libsynpro.com/episode-74

Meltem Demirors@Melt_DemAug 19, 20185/ decentralization is a word that is often used as a substitute for desired end properties of systems design decentralization =/ privacy decentralization =/ security decentralization =/ self-sovereignty decentralization =/ âfairnessâ (another difficult term)

Meltem Demirors@Melt_DemAug 19, 20186/ a âdecentralizedâ system, as many users of the word envision, would provide for: a. participation (anyone can join or leave) b. diversity (doesnât allow for discrimination) c. efficiency (resource consumption) d. conflict resolution (ensuring consensus)

Meltem Demirors@Melt_DemAug 19, 20187/ the challenge is that natural systems inherently evolve towards hierarchies. we see this emergent property in cryptocurrencies and blockchain protocols as well. hierarchy is an emergent property of networks. hierarchy evolves as a result of the cost of network connections.

Meltem Demirors@Melt_DemAug 19, 20188/ this paper on computational biology is an excellent primer on the topic. the question then becomes - how do we create networks and systems that are efficient, scalable, and regular while avoiding hierarchical organization? journals.plos.org/ploscompbiol/aâŠ

Meltem Demirors@Melt_DemAug 19, 20189/ to me, this is a better goal than pursuing âdecentralizationâ as our rallying cry. specificity in defining the problem set and the desired end state solution will help us design better experiments. âmuch decentralizedâ is not a measurable outcome.
galgitron@galgitronAug 19, 2018Please update your XRP logo (attached) and stats: Currently 71 non-UNL validator nodes, with 0 entities > 50% (minivalist.cinn.app), distribution of tokens to top 100 accts = 81% (ledger.exposed/rich-stats)
/$
/$
/$
Why You Canât Shortcut Trust
By Jimmy Song
Posted August 20, 2018
Trust is one of those words that is both loaded and ill-defined. We all recognize that trust is very important for nearly all human interactions, especially trade. The actual mechanics of trust, however, are not really well articulated or understood.
How do people trust in something? Why is trust important in money? More importantly, what does this have to do with bitcoin? In this article, weâll cover how trust in a money is established.
tl;dr Trust in a money requires time, and any successful currency needs to optimize for longevity over everything else.
The Mechanics of Trust in Money
At its core, money is all about trust: enough people need to trust that the money is something that will keep its value, or else they wonât want to hold it. And if people donât want to hold it, money will tend to trade at a discount until it becomes all but worthless.

Historically, people have trusted glass beads and Rai Stones as money due to their rarity, but their desirability was lost as soon as someone figured out how to easily reproduce them. For people to trust something as money, scarcity needs to be guaranteed. But scarcity is just one of many characteristics that we want in a money.
Ideal Characteristics of Money
As many others have noted, the ideal characteristics of money are scarcity, durability, censorship resistance, recognizability, fungibility, divisibility and portability. We can broadly separate these into two different categories:
- Qualities that make money convenient or easy to transact in. Divisibility, portability, fungibility and recognizability all fit into this category.
- Qualities that make money valuable. This includes whether someone else can debase or steal your money without your permission. Scarcity, durability and bearer instrumentation all fit into this category.
Bitcoin has many of these properties, but what sets it apart from other forms of money is that Bitcoin is both digital and decentralized.

Many moneys are digital (US Dollar, World of Warcraft gold, Linden Dollars), but no digital money until Bitcoin was actually decentralized. Likewise, many moneys are decentralized (gold, silver, salt), but until Bitcoin, none was actually digital. Decentralization is actually what give Bitcoin its valueand digitization is what gives Bitcoin its convenience.
The Desire for Scarce Things
Humans have an innate desire for scarce things. This is evident in advertising. One of the easiest ways to get someone to buy a product is to convince them that itâs rare. When people are convinced something is rare, they have a tendency to want it.

The value they assign, however, depends entirely on how long they expect the item to remain scarce.
Certain goods have, as they say, a limited shelf life. When the Wii first came out, it was trading for a lot more than retail price because Nintendo didnât produce enough units. In other words, Wiis were scarce.
As production caught up, however, the price dropped. Nobody bought Wiis to hold for 5 years to sell again. They either bought to flip or they bought it to play with.
The lesson here is that in order for scarcity to work for money, it needs to stay scarce.
Two other properties required to establish trust
Long term, people must have a good reason to believe that the scarcity of a money will last. The expectation of long-term scarcity of a money is what causes people to trust in a money. Ideally, that scarcity would be immutable.
The other property is a bit more subtle: a money needs to be a bearer instrument so that third parties canât just seize the money at whim.

Whatâs important to notice about both immutability and bearer instrumentation is that a money canât have either property if thereâs a central point of failure. That is, if someone other than the nominal owner can remove its scarcity or confiscate it, then the owner needs to trust the other entity to not do those things.
This is generally not a good bet. You may trust the actions and judgment of the current central authority, but thereâs no guarantee that they will be in control forever. In fact, most centralized organizations collapse because the temptation to abuse such power eventually becomes too difficult to resist.
Keynesian Hubris
Keynesians generally try to optimize for maximum spending, and thus seek to make money as convenient to spend as possible. This is why itâs so convenient to buy nearly anything in a Keynesian system, especially on credit. Keynesians encourage impulsive spending habits as a way to keep the economy flowing. Impulsiveness tends to hurt people long-term, so in reaction, many consumers purposely make spending more difficult (freezing a credit card in an ice block is a popular method).

In that respect, Keynesians emphasize the convenienceproperties of money like divisibility, portability, recognizability and to some degree, fungibility, even at the expense of the value properties of money like scarcity, immutability and bearer instrumentation. Not coincidentally, various altcoins often tout these convenience properties as the reason for their existence.
Long Term Value
Long term value accrues to money that has scarcity, securability and durability. These properties are often at odds with the fast movement of money.

Greater portability often means centralizing operations so a single point can process transactions faster. Greater fungibility also may mean trusting that there is no mathematical exploit of certain security assumptions that privacy coins make.
The more trust has to be given, whether to central entities or to the difficulty of certain math problems, the less valuable the money is. In other words, making money especially fast or convenient is often at odds with security, scarcity and decentralization.
Ultimately, value accrues to the money that gains long term trust. No one would argue that a Wii is a great store of value because it traded for a lot of money at one point in time. Trust has to be earned, especially across time.
Time is the ultimate judge
The real test of long term value is time. A well known phenomenon called the Lindy Effect, asserts that the longer something has survived the longer it can be expected to survive. This is so termed because someone noticed that Broadway shows tend to last about as long as theyâve already lasted. That is, a show thatâs lasted 15 years, lasts another 15 on average. A show thatâs lasted 1 year lasts another 1 on average.
Money can only really gain trust with the passage of time, which means that survival matters more than anything else.

Me, hopefully, in about 20Â years
This is another reason why centralization is so terrible for long term value. Centralized entities are by their very nature, fragile. Centralized entities canât afford a mortal failure without jeopardizing everyone else that depends on it.
Conversely, a decentralized network is by nature anti-fragile: individual failures affect a much smaller group and thus, a decentralized network can afford a lot more mistakes. These mistakes in turn help all the other members of the network to learn what not to do. This in turn, makes the network stronger.
Hacking Trust
Many centralized entities try to bypass the need for long term proof by hacking trust itself. They use social signaling, hype, promises and the like to give the illusion that theyâve earned the trust, rather than actually proving worthy of that trust through time. ICOs, altcoins and hard forks have used these techniques to get people to trust them.

Unfortunately, a lot of people have been fooled by these hacks and this bear market is teaching them some expensive, but valuable lessons. At least theyâre learning now when the market is still relatively small, and the population is becoming more immune to these trust hacks.
Conclusion
The priorities of Bitcoin align with long term value. The priorities of almost everything else, much like Amway and other get-rich-quick schemes, align with short term hype. Bitcoin focuses on decentralization and immutability, which provide long-term scarcity. Almost everything else promises these things, but none have Bitcoinâs track record for delivery.

How I feel when I see coins like Tron go up in value
Bitcoin is focused on the one thing that can prove its value. Time. As the last year has proven, this is not a 6-month game. This is a 20â50 year game. As many are finding out, itâs painful to realize youâve been playing the wrong game the whole time. Itâs not too late. The game is still just starting.
Bitcoin, Chance and Randomness
By Hugo Nguyen
Posted August 25, 2018
The same rule governs this pair of dice & Bitcoin PoW
Randomness forms the cornerstone of Bitcoinâs Proof-of-Work (PoW). But how did we get here?
A brief history of the study of randomness [1]
Randomness has always been an essential part of life. Many ancient divination rituals were based on chance: the tossing of astragali (animal knucklebones) by the Greeks, Kau Cim sticks by the Chinese, Opele chain by West Africans. The use of dice-like devices in games & gambling also goes back thousands of years.
Kau Cim sticks
Yet, it was not until the 16th century that we started gaining the necessary tools and languages to really understand chance and randomness. Those tools include arithmetic concepts such as fractions and the number zero.
Our study of chance and randomness began in earnest with a man named Gerolamo Cardano [2]. Born in Italy in 1501, Cardano was a polymath and one of the most influential mathematicians of the Renaissance. He was also a notorious gambling addict. Due to his gambling problem, Cardano eventually sunk into abject poverty and obscurity. It was his experience with gambling, however, that led him to write the âBook on Games of Chanceââââthe first systematic treatment of chance and randomness. Interestingly, Cardano intended to keep the book secrets to himself. The âBook on Games of Chanceâ was published a century after it was written, long after Cardanoâs death.
Gerolamo Cardano (1501â1576)
Cardanoâs main contribution to our understanding of chance and randomness was the idea of sample space. At the most basic level, calculating the probability of an event involves the simple task of counting the number of scenarios that could lead to said event, then divide that by the total number of all possible scenarios (the âsample spaceâ), assuming all scenarios are equally likely. This assumption only holds true for problems like dice rolling, but it was a good start.
Following in Cardanoâs footsteps was Galileo and Pascal. Galileo was the perfect embodiment of the rebellious intellectual spirit of that era: going against the powerful Catholic Church and proclaim that the Earth is not the center of the universe. Galileo produced many important work. One not very well-known work, âThoughts about Dice Gamesâ, explored similar topics that interested Cardano.
Pascal, a contemporary of Fermat and Descartes, went a lot further than Cardano and Galileo did. He discovered what we now call the Pascalâs triangle. Although mathematicians in other civilizations (e.g.: Iran, China & India) had discovered the same triangle centuries before Pascal did, Pascalâs work was the most comprehensive and added novel applications, specifically in the area of probability theory. Pascal also introduced the âPascalâs wagerâ and the concept of mathematical expectation.
From the seed that Cardano, Galileo and Pascal planted, our understanding of chance and randomness gradually grew, over time becoming more sophisticated and refined. This was a common theme of the Renaissance: a few fundamental breakthroughsâââsuch as astronomy, Newtonian physics, calculus, empiricismâââlaid the scientific foundation that brought forth new branches of knowledge and major technological innovations, which eventually led to the Industrial Revolution.
List of notable milestones in our journey of cracking chance and randomness:
- Sample Space
- Permutations & Combinations
- Pascalâs Triangle
- Law of Large Numbers
- Law of Small Numbers
- Bayes TheoremâââConditional Probability
- The Bell Curve & Standard Deviations
- Regression Toward the Mean
- Random Walk
- Monte Carlo simulation
- Pseudorandomness
Normal Distribution a.k.a. the âBell Curveââââimage by Dan Kernler/ CC 4.0
Two major developments stand out: Monte Carlo simulation and Pseudorandomness. Particularly because theyâre highly relevant in todayâs world.
The invention of the computer opened the door to a brand new application of randomness: computer simulation. For the first time in history, we have a way of âpredictingâ the future or uncovering hidden truths by cheaply performing experiments, over and over again. The large number of simulations afforded to us by the machines was previously unthinkable.
The invention of Monte Carlo simulation in the early 20th century marked a major turning point in human history. Prior to the Renaissance, humans often lived in fear of randomness, of uncertainty. Leading up to the 20th century, we slowly improved to gaining a better understanding of it, but still largely let randomness dictate the flow of things. With Monte Carlo simulation, we started making randomness work for us. The apprentice has become the master.
Notable early pioneers of Monte Carlo simulation included John von Neumann and Alan Turing, the two godfathers of the modern computer.
Nowadays, Monte Carlo simulation has a large number of applications: fluid mechanics, business, finance, artificial intelligence, to name a few. The recent case of AlphaGo is the perfect example of how Monte Carlo simulation (combined with other techniques) can guide us to new discoveries: AlphaGo outplayed the best human players with moves that completely surpassed our imagination and the rich literature of Go. AlphaGo challenges the idea that machines cannot be creative, and forces us to rethink what âcreativityâ really means.
The rising popularity of Monte Carlo methods was what spurred the development of âpseudorandomnessâ (a pseudorandom process is a process that appears to be random, but itâs not), because a good simulation needs to be able to closely mirror the random nature of reality. Numbers generated by such a process are deterministic, but they pass statistical tests of what is considered ârandomâ. Pseudorandomness, in turn, became one of the building blocks of a brand new fieldâââalso a child of the computer age: modern cryptography.
Which brings us to Bitcoin.
The role of randomness in Bitcoin
One of the major innovations in Bitcoin is the use of Proof-of-Work in establishing distributed consensus. PoW provides an objective yardstick which Bitcoin network participants can rely on to come to consensus, without trusting anyone on the network. This is unlike schemes like Proof-of-Stake which relies on a subjective interpretation of consensus. This section assumes PoW is the only secure way to implement a blockchain. (For a refresher on PoW, read part 1: the Anatomy of Proof-of-Work.)
The âworkâ in Proof-of-Work involves searching for a hash output that has a minimum number of leading zeros. (There are some constraints on the hash input, such as formatting, timestamp, etc.)
Bitcoin PoW scheme uses a cryptographic hash function called SHA256. An important feature of cryptographic hash functions is that they are one-way. Meaning that it is infeasible to deduce the hash input just by looking at the hash output. And the reason they are one-way is largely due to how random the hash output is.
This turns out to be extremely critical because if the hash function doesnât generate sufficiently random (âpseudorandomâ) output, one can start with the desired output, i.e.: a string with a certain number of leading zeros, and work backward from there. This would render the proof less trustworthy at best, and useless at worst.
In simple terms, what a typical PoW scheme does is (a) it poses a problem whose solution lives in an incredibly large space, (b) there is no shortcut and (c) the only way to arrive at the solution is by brute-forcing and randomly searching the large space. Much like searching for a needle in a gigantic haystack. (The official computer science term for this is âunbounded probabilistic iterative procedureââââquite a mouthful.)
So the randomness of the hash function determines how strong the proof is.
Hashing (provides) â Randomness (backs) â Proof-of-Work
ââŠa good puzzle gives every miner the chance of winning the next puzzle solution in proportion to the amount of hash power they contribute. Imagine throwing a dart at a board randomly, with different sized targets corresponding to the mining power held by different miners.âââArvind Narayanan [3]
There is no formal proof that randomness is a mandatory requirement for PoW, but empirically, this seems to be true. Thereâs also the simple observation that any problem whose solution is non-random, tends to require as much effort to verify as to compute the solution in the first place. Any such scheme would be seriously constrained in terms of scalability (keep in mind, Bitcoin is incredibly hard to scale as-is). It would also disproportionately favor the fastest minerâââto the point where slightly slower miners earn nothing.
Another benefit of randomness-based PoW is that mining membership is highly open: miners can come and go whenever they like. It doesnât matter if they join immediately after a block has been found, or 5 minutes after, their chance of earning the next reward doesnât change.
What about hashing? Is it the only way to get randomness? Probably not. There are other known ways to simulate the process of random search besides hashing, such as integer factorization or discrete logarithm.
So itâs highly likely that hashing is not the only means to achieve randomness, while randomness is a necessary precondition for creating digital Proof-of-Work.
PoW schemes fall into two major categories:
- Compute-bound: where the random search is bound by processor speed
- Memory-bound: where the random search is bound by memory accesses
It remains to be seen whether one PoW category is materially better than the other (I personally think memory-bound is worse [4]), but the underlying mechanism is the same: a probabilistic, random search in a huge solution space, and any solution can be verified cheaply.
In summary, for as long as humans have existed, we have struggled with randomness and uncertainty. The invention of the modern computer and Monte Carlo simulation in the 20th century allowed us, for the first time, to turn randomness to our advantage. The use of randomness in Bitcoin marked another milestone in this long journey. Randomness, in short, is what backs the âproofâ in Proof-of-Work. Without randomness or really good pseudorandomness, Proof-of-Work would not work.
If Bitcoin succeeds in being money of the future, it would represent our most significant and largest-scale application of randomness thus far.
*This is part 2 of the Bitcoin Fundamentals series. Check out the full series here: part 1 , part 2 , part 3 , part 4 , and part 5 .
Acknowledgments
Thanks Steve Lee & Nic Carter for the valuable feedback.
[1]: For a detailed history of randomness, check out The Drunkardâs Walk: How Randomness Rules Our Lives , by Leonard Mlodinow.
[2]: Not to be confused with the cryptocurrency Cardano, which ironically is based on Proof-of-Stake.
[3]: Arvind Narayanan, Bitcoin and Cryptocurrency Technologies: A Comprehensive Introduction .
[4]: A couple of potential issues with memory-bound PoW schemes:
- Memory-bound PoW still requires computations, but operates under the assumption that memory technology has already plateaued, which makes memory the primary bottleneck in mining operation. But if this assumption is broken, instead of facing centralization forces on one front (ASIC), youâd potentially face centralization forces on two fronts (ASIC and memory).
- The memory used in memory-bound PoW is likely to be repurposable beyond mining. This might have a negative impact on network security because that opens up the possibility of an attacker renting memory from others (since anything repurposable would likely have an abundance of supply and occasional supply surpluses), which reduces the cost of a majority attack. Hardware repurposability in general is not desirable for Bitcoin security.
Gravity
By LaurentMT
Posted August 27, 2018
This is post 1 of 3 in a series
âLaw I: Every UTXO persists in its state, except insofar as it is compelled to change its state by force impressed.ââââIsaac Newton, Principia 2.0
Newton diffracting an UTXO with payment batching
In the last years, a lot has been written about the âhuge waste of energyâ resulting from Bitcoinâs Proof of Work (PoW). In this series of four posts, weâre going to challenge this widespread opinion by questioning the main metrics used to highlight the alleged increasing inefficiency of Bitcoinâs PoW.
In this first part, weâll first discuss the main utility of PoW in the Bitcoin protocol. Then, after a reminder of two important properties of Bitcoinâs PoW, weâll define a mathematical formalization of this utility (Bitcoin.Days Secured) and weâll use it to define two new metrics (Unit Cost and Average Cost). At last, weâll check what these metrics can teach us about the evolution of the efficiency of Bitcoinâs PoW over time.
Prologue: The Cryptopocalypse is coming
The news was on all the media a few months ago. The cryptopocalypse is coming. Bitcoinâs Proof of Work (PoW) is so bad that itâs going to destroy the world in 2020âŠ
Pot pourri
Reading a bit further, you may have noticed that most of these articles were based on the results of an analysis provided by Alex De Vries, a âfinancial economist and blockchain specialistâ working for PWC Netherlands and author of the site Digiconomist.
I must confess that I have mixed feelings about this study. My issue with De Vriesâs work isnât the estimated electricity consumption (this part has already received its âfair shareâ of criticisms) but the repeated use of a specific metrics: the electricity consumption per transaction. Donât get me wrong. In terms of communication, this metrics is pure genius especially for those eager to make a point against Bitcoinâs PoW. The figure seems so outrageously disproportionate that it prevents any further discussion. The problem is that this metrics is fundamentally wrong. For several reasons.
First, it mistakes the number of transactions with the number of payments. But letâs be fair, that doesnât radically change the actual figure. So letâs forget about that.
The second issue is that the figure is often published without specifying that thereâs no correlation between the electricity consumed and the number of transactions; or to put it differently itâs almost never acknowledged that the electricity consumed is a fixed cost with regards to the number of transactions (and not a variable cost). With technical solutions like payment channels or the Lightning Network, itâs obvious that we can radically decrease the value of this metrics as low as we want. That highlights 2 points: the metrics is easily âabusableâ and it doesnât tell us anything about future performances of Bitcoinâs PoW.
The last problem with this metrics is that it promotes a flawed understanding of the utility of Bitcoinâs PoW. Itâs no surprise that it has gained a lot of traction in a period of âBlockchain, not Bitcoinâ frenzy but we should make our best to promote rational thinking instead of an endless squabbling based on emotional reactions.
So. Arrived at this point, weâre facing the obvious questionâŠ
What is the utility of Bitcoinâs PoW ?
The âGold Miningâ theory
A first theory is that the main utility of the PoW algorithm is the issuance of new coins. Paul Sztorc has written a good post on the subject. This theory is seducing because it seems consistent with the widespread metaphor of gold mining used for explaining the mechanism.
I have sympathy for this theory and I think that it captures an important aspect of the protocol but for this series of articles, Iâm not going to consider the issuance of new coins as the main function of the PoW algorithm. To support this choice, Iâll refer to this observation: while itâs expected that the emission of new coins stops around 2140, itâs not planned that Bitcoin mining stops at the same date. That suggests that PoW plays another important role in Bitcoin.
The âSection IVâ theory
A second theory is that the answer to our question was given 10 years ago by the creator of Bitcoin. In the fourth section of the White Paper to be more specific.
Section 4
Iâm going to summarize this theory with the following sentence
The main utility of Bitcoinâs PoW is to secure an economic history.(1)
This is all well and good but in its current form this assertion isnât very useful. A mathematical model would be far better. That raises a new question: how to express the âsecurity of an economic historyâ as a mathematical equation ?
Digital Gravity
From the previous definition, we can state that our model should be able to express:
- economic values secured by the system (ideally, it should be able to do that atomically or in aggregate),
- the security provided to these economic values (or at least a good proxy metrics).
Since thereâs no such thing as a âcoinâ in the Bitcoin protocol, our model will use the concept of Unspent Transaction Output (UTXO) as the elementary object of value.We can then easily define the total economic value secured by the system by adding the economic values of all the UTXOs existing at a given moment (UTXO set). Good. We already know how to express economic values in our model.
Now we need to express security. Obviously, PoW is going to play an important role here. Thus, it seems important to recall two of its properties
Proof of Work is Global and Cumulative
In a sense, PoW is similar to Gravity (to a homogeneous gravitational field to be more specific) which has a simultaneous influence over all bodies in its field, with a cumulative effect on their individual speed.
In the case of Bitcoin:
- when a new block is mined, the security provided by its PoW is simultaneously and equally applied to all the existing UTXOs,
- an UTXO âaccumulatesâ the PoWs associated to all the blocks mined since its creation. All others things being equal, the more hashes accumulated, the more secure the UTXO.
These two properties are fundamental for studying the economics of Bitcoinâs PoW. Sadly, theyâre totally missing in the metrics used by De Vries.
Letâs make a few assumptions
Before going further, letâs make a few assumptions:
- A1: For the last 9 years, Bitcoin has been the most secure public blockchain in terms of PoW.
- A2: At any given point in time, all existing and significant computing power usable for Bitcoin mining was used to mine Bitcoin.
- A3: The marginal cost and revenue of Bitcoin mining are equal.
- A4: Fees paid to miners are negligible when compared to block rewards and they can be ignored.
While these assumptions are likely to be more or less inaccurate in the real world, they seem good enough for this preliminary investigation.
Ok. Now, letâs try to translate this idea of the âsecurity of an economic historyâ into a mathematical model.
Number of âBitcoin.Hashes Securedâ by an UTXO
Our first attempt will be straightforward. Basically, weâre going to multiply the value of the UTXO by the number of hashes it has âaccumulatedâ between its creation and a given block.

While simple, this definition captures the intuition that the system provides more utility when an UTXO has âaccumulatedâ more hashes and/or when its value is higher.
That being said, this model isnât really satisfying because the number of accumulated hashes isnât a very good proxy for measuring the security of an UTXO. The main reason is that the quantity of computing power dedicated to Bitcoin mining has greatly increased over the years. Thus, the computation of a PoW securing an old block may have required 10 minutes in 2009 but it will be computed in a fraction of that duration when done with modern ASICs.

Satoshiâs Wall (number of seconds required to compute the PoW of a past block with 100% of the average computing power used during the period between 2 difficulty adjustments)
It seems clear that we need a better model taking into account this fact.
Number of âBitcoin.Days Securedâ by an UTXO
First, weâre going to add a new item to our list of assumptions
- A5: On large enough periods of time, the average amount of computing power dedicated to Bitcoin mining monotonically increases.
Once again, we canât assert that this assumption is always true or will always be true. Anyway, it has been almost always true in the past, so letâs go with this hypothesis.
We can now define the security of an UTXO at a given block B as the number of days that would be required to rewrite the history since the creation of the UTXO, with 100% of the computing power used to mine block B.
For an individual UTXO that give us the following equation

and the following equation for the UTXO set

You may wonder why this choice of â100% of computing power used to mine block Bâ. Itâs simple. Under our current assumptions, we can consider this definition as a kind of worst case scenario (âHow long would this UTXO remain secure if all the available computing power was used to rewrite the history ?â). Moreover, while an alternative scenario (50%, 200%, N%) would change the absolute values of our results, it wouldnât change the overall evolution of the metrics over time.
Bitcoinâs PoW efficiency
All Right. Now that we have a model for the utility provided by Bitcoinâs PoW, letâs check what we can learn about its efficiency. For this, weâre going to define two metrics.
Unit Cost of a Bitcoin.Day Secured added by a given block
For this first metrics, weâre going to divide the reward associated to the block (c.f. assumption A3 about the margin costs and revenues of mining) by the number of bitcoins.days secured added to the existing UTXOs by the block.
It gives us the following equation

By definition, the sum of the values of all the existing UTXOs is the number of existing bitcoins and is equal to the sum of all past block rewards:

Thus our equation can be rewritten as

and finally simplified as

There are a few observations to be made here.
First, the Unit Cost is expressed by default in bitcoins/bitcoin.day secured but we would obtain the same result if we expressed it in USD/USD.day secured (both the numerator and denominator of our equation express the value of bitcoins at the same instant).
More importantly, itâs worth noting that the Unit Cost doesnât depend on external factors like the market price or the number of hashes computed.
The Unit Cost only depends on the rules defining the controlled supply of the currency. It is defined by design.
Letâs check the chart associated to this metrics

I guess that many people will be surprised by this chart but we can clearly observe that the Unit Cost is monotonically decreasing over time. This result can be explained by the joint influence of the deflationary model of Bitcoin(halving of rewards) and the temporary inflation caused by the creation of new coins. The situation should change when all bitcoins have been created. At this point, external factors will play a role on the evolution of the Unit Cost but itâs hard (if not impossible) to predict how things will evolve. Letâs note that the situation may also change before this date if/when fees become an important part of the mining incentive .
Average Cost of the Bitcoins.Days Secured added up to a given block
For this second metrics, weâre going to add all the costs expended on mining from the first block to the block of interest. Then, weâre going to divide this total cost by the sum of all the bitcoins.days secured created by these blocks.
Note that weâll express all costs and UTXO amounts in USD because we need to deal with the value of UTXOs at different periods of time.
That gives us the following equation

which can be rewritten as

and finally simplified as

That gives us this chart

As it was the case with the Unit Cost, the Average Cost suggests that Bitcoinâs PoW is indeed becoming more efficient over time. This result might seem counter intuitive because of the apparent increasing absolute cost of Bitcoinâs PoW but it starts to make sense when we realize that this increasing cost is counterbalanced by the increasing total value secured by the system.
Conclusion
In this first part, we have discussed why the average cost per transaction isnât an adequate metrics for measuring the efficiency of Bitcoinâs PoW and why this efficiency should be defined in terms of the security of an economic history.
Based on this observation and two important properties of Bitcoinâs PoW (its global and cumulative effects) weâve formalized the utility of PoW with a very simple mathematical formula defining the total number of bitcoin.days secured by the system.
At last, we have derived two metrics which both suggest that contrary to a widespread opinion, Bitcoinâs PoW is actually becoming more and more efficient.
In the next part of this series, weâll discuss a new metrics highlighting how the efficiency of the system has evolved under the influence of mining and hodling behaviors.
Acknowledgments
I wish to thank @Beetcoin, Pierre P. and Stephane for theirs precious feedback and their patience. :)
A great thank you to @SamouraiWallet and TDevD for theirs feedback and their unfailing support of OXT.
Notes
(1) See Kocherlakotaâs theory of âmoney [being] equivalent to a primitive form of memoryâ (R. Kocherlakota, Money is memory , 1996, Federal Reserve Bank of Minneapolis) and Luther & Olsonâs paper Bitcoin is memory (2014)
Bitcoin Security: a Negative Exponential
By Jordan McKinney
Posted August 29, 2018

Intro
Iâve long been skeptical that Bitcoin would win out as future-money, but in light of the recent increase in pro-Bitcoin sentiment on Twitter I decided I should try to figure out how Iâm wrong.
During research I ran into the question of how Bitcoin will maintain security as the block reward declines. Despite a lot of searching (and pestering people on Twitter) I was surprised at how little discussion I found, and how bad the proposed solutions seemed.
Unless Iâve completely missed something, I canât see how Bitcoin security does not decline with block rewards â which follow a negative exponential!
This problem has been discussed elsewhere (0, 1, 2, 3, 4), but I havenât found any source which lays out the problem and critically assesses the commonly proposed solutions. So, that is the purpose of this post.
If I have missed something important then this post can serve as an application of Cunninghamâs Law and someone can enlighten me.
Basics of Proof-of-Work
Value is stored on the Bitcoin network â that is its purpose.
The network uses proof-of-work (PoW) to (among other things) protect against 51% attacks. PoW protects against 51% attacks by making them expensiveto pull off â not impossible!
To successfully do a 51% you need to acquire slightly more than half the hash power of the network. If the network has a lot of hash power then this will probably be expensive because hash power has a real world cost (hardware and electricity).
The Security Budget
The security of a PoW network depends on the cost to 51% it. The cost to 51% it depends on how much money the miners are collectively spending. How much miners are spending depends on how much theyâre being paid.
Therefore the security of a PoW network depends on how much money the network is paying out to miners â which is why Iâm calling this amount the âsecurity budgetâ. The security budget directly determines security.
Simplest Example
A new ASIC-resistant, PoW cryptocurrency appears. It pays out exactly $1M/day (the security budget!) to miners regardless of total hash power etc.
At first, one person mines. Total money spent mining is low, hash power is low, difficulty is low, and they earn the entire $1M/day.
New miners join. Total money spent mining rises, hash power rises, difficulty rises, and the $1M/day is spread across more people.
As the system approaches equilibrium, the combined cost expended by miners (âtotal spendâ) approaches, but is always less than, $1M/day.
Why?
If the total spend were more than $1M/day the less efficient miners would lose money and soon quit â lowering total spend. If the total spend were much less than $1M/day new miners would join, eat those profits, and total spend would creep upward.
Now, since the size of that $1M/day pie that miners fight for depends on how much hash power they contribute, they constantly compete to output more hash power per dollar spent.
Therefore the $1M/day security budget will tend to get the network close to the maximum total hash power that can be had for $1M/day. This is good!
The Attack
Letâs attack this network. To 51% any PoW network we just need a bit more than half the hash power, right? So, how much do we need to spend?
Well, we know the protocol pays out $1M/day. So, the miners canât be spending more than $1M/day mining. Competition should squeeze them to produce close to the maximum total hash that can be had for $1M/day â but thatâs OK, itâs still capped at $1M/day.
So we can kill the network for about $1M/day.
Defense
How could our attack be prevented? Well, all you can do with PoW is make attacks more expensive, so you increase the security budget.
Suppose the network doubles the security budget to $2M/day. New miners join, total spend increases, hash power increases, and a new equilibrium is reached just like before. Now total spend is close to, but less than, $2M/day. And the network has close to the maximum hash power you can get for $2M/day.
OK. Now we can kill the network for $2M/day.
It also works in the other direction. If the amount paid to miners were halved from $1M/day to $500K/day we could kill the network for $500K/day.
Security Budget Determines Security!
We know that PoW protects against 51% attacks by making them expensive.
Now, weâve seen that the cost to attack depends on how much miners are spending, and this is capped by the amount the network pays out to miners â the âsecurity budgetâ.
Therefore, we can see that security budget determines network security.
ASIC Example
In the example above, the network was ASIC-resistant and we concluded that security budget determines security.
Does this conclusion change if we add ASICs? Bitcoin has ASICs after all, and this post is (supposedly) about Bitcoin.
â â â
A new ASIC-mined cryptocurrency appears. It pays $1M/day ($365M/year) to miners. Miners must purchase, and periodically upgrade, the ASICs used to mine on the network â this can be amortized into an annual hardware cost. They also incur an annual operating cost**(the usual electricity, etc).
Maybe it works out that miners spend $250M/year on hardware and $100M/year on operating cost. Whatever the break down is, they canât sustainably** spend *more than they earn. So, the sum of these will approach, but generally be less than, annual miner revenue â aka the annual security budget:
annual hardware cost + annual operating cost †annual security budget
As before, the pool of miners will tend to produce the maximum hash power that can be had given the security budget. To maximize hash power they must figure out how much to spend each year upgrading hardware. Miners donât like upgrading hardware, but competition eats their operating margins as hardware ages. Eventually some equilibrium hardware-spend is found.
The result of all of this is that, if the protocol spends $365M/year on miners it gets close to a âtrueâ $365M/year worth of hash power, regardless of how the hardware-spend works out. So, it all tends to work out same as before.
- *I say âsustainablyâ because if revenue were high miners might spend a lot on hardware expecting it to stay high. Then it drops and they are over-budget on hardware for this lower revenue level. But they keep mining as long as revenue exceeds operating costs. Therefore you could have $300M worth of hardware mining when current revenue only justifies $250M. This over-allocation would gradually adjust downward though as hardware is refreshed. This should take no longer than one full hardware refresh period.
The Attack
The cost to attack will vary somewhat depending on how long the hardware refresh period is. Suppose miners spend $300M/year on hardware, $65M/year ($178K/day) on operating costs, and hardware has a 3 year useful lifespan.
This means at any given time there is $900M worth of hardware mining, and itâs burning $178K/day. So, to attack the network we must spend $900M on ASICs and $178K/day.
Defense
The community anticipates our attack. How can they prevent it? Once again, all they can do is increase the security budget.
The network doubles the security budget to $2M/day. New miners buy ASICs and start mining, hash power increases, and after some time a new equilibrium is reached.
The ratio of hardware spend to operational spend should stay roughlythe same so now we can expect to spend twice as much on ASICs and twice as much per day to attack.
And, just like before this works the other way too. If the security budget were halved to $500K/day, and equilibrium were reached, we could expect to spend half as much on ASICs and half as much per day to attack.
Security Budget (Still) Determines Security
ASICs make 51% attacks more expensive â assuming we are comparing relatively short-lived attacks â but the attack cost is still bound and determined by the security budget. How could it be otherwise?
ASICs or not, the network must have a high security budget if itâs going to have high security.
Absolute Hash Rate
Notice that we didnât need to care about absolutehash rate in these examples. The ultimate determinant of cost to attack was how much miners were spending âwhich was capped by how much they were earning.
So the absolute hash rate produced by the pool of miners is not a direct measure of security â it is a sort of proxy for security, even a red herring.
Example: Imagine a network that pays out a constant $1M/day to miners no matter what, forever. It has a constant level of security â whether we attack today, or one year from now, we can expect to pay $1M/day.
But, what would the hash power graph look like for this network? It would go up and to the right. Hardware is always advancing. You can get more hashes per dollar next year than you can today.
It would be a mistake to look at the rising hash power and simply conclude that the network is becoming more secure with time (see next section for Bitcoin-specific illustration).
Cost expended (security budget!) â not absolute hash rate â determines security⊠This is why statements like the one below make no sense.
As ASICs become more efficient we can reduce the overall cost spent mining!

Bitcoin (Finally)
One more thing before getting to Bitcoinâs security budget and the problem motivating this whole post.
Absolute Hash Rate
The graph below shows Bitcoin hash rate for the past year. The graph right after shows miner revenue for the past year.

Bitcoin Hash Rate

Miner Revenue(Security Budget!)
Which graph is the better indicator of network security? Assuming an efficient mining market, the second graph is the better indicator â absolute hash rate is a red herring.
Remember the example above. Absolute hash power will always tend to increase due to hardware advancements â even if the security budget (and cost to attack) are fixed.
Hash rate only declines with time if the security budget is falling faster than the cost per hash/sec â this is bad! Even a constant hash rate indicates declining security.
Bitcoin Security Budget
OK. So weâve established that, ASICs or not, PoW networks must have a high security budget in order to have high security (I know Iâve said that 50 times).
This applies to Bitcoin (it being a PoW network), so how is Bitcoinâs security budget funded?
100% of miner revenue (the security budget) in Bitcoin comes from block rewards and transaction (tx) fees.
Bitcoin security budget = block rewards + tx fees
So if Bitcoin is going to remain secure we need to make sure block rewards + tx fees always equals a large amount of money.
The Problem
Block rewards make up ~98% of Bitcoinâs security budget at present* and they getcut in halfevery 210,000 blocks (~4 years)* until theyâre gone.
Bitcoinâs security budget, and therefore the security of the network, gets (roughly) halved every 4 years. The network becomes less secure over time!
- *Current tx fees =$200K/day, current block reward = ~$12.6M/day (at $7000/BTC). 12.6/(12.6+.2) = 0.984
- *At present 12.5 BTC are issued per block (~10 minutes). This will halve to 6.25 BTC/block sometime inMay 2020(and again in 2024 and so on)

Solutions/Responses
As the integrity of Bitcoin depends on it being resistant to 51% attack, this issue is absolutely central to Bitcoinâs very survival. Surely there is a rock-solid, game-theoretically sound, non-hand-wavey solution to this problem?
These are the responses Iâve come across. Unattributed quote blocks are either general forms of arguments Iâve heard, or me arguing against myself.
Continually Rising Price
If Bitcoin price rises as block rewards fall, then the security budget could actually remain constant, or even grow.
First of all, relying on price to increase continually at some specific cadence in order that absolute security doesnât decrease is truly terrifying. No one knows what price is going to do. We canât count on it going up.
Also, price just canât double every 4 years for very long:
- 4 doublings: $110K/BTC. OK sureâŠ
- 7 doublings: $900K/BTC. Not so sure.
- 9 doublings: $3.6M/BTC. Bitcoin market cap now exceeds world GDP.
- 12 doublings: $26M/BTC. Well into silly-territory now.
- 31 doublings (year 2140) : $15T/BTC. _
Security Factor
But it gets worse. Letâs suppose Bitcoin price (and therefore market cap) did in fact double every 4 years in pace with the block reward halving, while cost-to-attack remained constant.
Then cost-to-attack relative to overall network value would fall over time, but absolute cost-to-attack would stay constant. Seems OK?
Itâs not OK!
The cost to attack a network must be proportional to the value of the network!Networks must maintain what Iâm calling a âsecurity factorâ.
If it cost $10M to kill a network worth $100M then its security factor is 10%. Networks should maintain a constant security factor as they become more valuable â that way their security budget scales with the value of the network.
Example: Imagine you could kill Joeâs Plumbing, which does $100K/year revenue, for $1M. Probably no one would bother. Now imagine you could kill Google/Amazon/Facebook for $1M. Countless parties would happily pay that cost for many, many reasons (think competitors, nationstates, terrorists, hedge funds, even crazy rich people).
Bitcoin is worth about $100B (by market cap) and the cost to attack it is about $10B ($8.8B hardware + $6M/day electricity). So, Bitcoinâs security factor is about 10% right now (cost-to-attack/network-value).
All else equal, if BTC price doubles when the block reward halves in 2020, then the network is worth $200B while cost-to-attack is still $10B â security factor has dropped to ~5%. This keeps happening every 4 years.
Imagine the cost to spawn camp Bitcoin to death remained a constant $10B, while price, and therefore market cap, continued to rise.
You think no government/competing chain/conspiracy of banks/shorting hedge fund/etc. would be willing to pay that $10B at some point? Bitcoin would keep growing, displace fiatâs all over the world, and become the global reserve currency with a $10B un-pushed âkill-this-currencyâ button on it?
Nobody knows how big the security factor needs to be to protect Bitcoin, but it kind of seems like we are running an experiment to find out.
Rapidly Rising Price
Well, BTC price increase could actually outpace the block reward decrease. Then absolute security budget would increase.
Sure BTC price could outpace block reward decrease (for a while) â though again, it would be insane to rely on this happening â but even then we would still have a declining security factor!
Assuming fees stay constant (or increase in pace with price) the only way to have a constantsecurity factor would be to steadily increase block rewards in proportion to total supply so that Bitcoin had a constant X% inflation rate â which the community would never accept.
Transaction Fees Will Save Us
As block rewards decline transaction fees will increase to make up the difference.
As far as I can tell this is the leading solution in the Bitcoin community to this problem, even Satoshi seemed to support this solution:
In a few decades when the reward gets too small, the transaction fee will become the main compensation for nodes. Iâm sure that in 20 years there will either be very large transaction volume or no volume. â
Satoshi
But why would total fees paid suddenly increase as the block reward drops? Users always want to pay minimal fees. Based on current figures, fees would need to go up 37x to compensate for the halvening in 2020.
Maybe the fees donât need to 37x, maybe the current fee level is enough?
If fees stayed at their current level relative to market cap we would see a 98% reduction in security budget as block rewards went away. This would be equivalent to being able to kill todayâs Bitcoin for 200M â a security factor of 0.2%. Is this enough? Who knows. I wouldnât want to bet on it.
Miners will demand higher fees.
This isnât how mining works. Total fees paid is a function of user demand for block space. Miners do not control this. Miners can only push fees up if they collude to exclude low fee txâs. Surely this cannot be our security solution?
Also, the system was designed to prevent this.
If you are a miner excluding txâs that do not meet a minimum threshold fee, I can come along as a selfish miner and make more money than you by including all txâs sorted highest fee to lowest.
Miners and users alike may benefit from high security and high fees being paid to miners, but no one wants to actually pay this cost. We have a tragedy of the commons problem.
Even the Bitcoin wiki points this out:
Miners will accept transactions with any fees (because the marginal cost of including them is minimal) and users will pay lower and lower fees (in the order of satoshis)
So, miners canât enforce high feesâŠ
How about we hardcode a minimum fee into the protocol?
Not only does this just seem trulybad,but it still**doesnât solve the tragedy of the commons problem.
Transaction volume will increase and therefore generate more revenue.
Relying on an increase in tx volume to prevent a decrease in security is bad for the same reason relying on a price increase for security is bad. We canât know what tx volume will look like in the future (especially with layer-2 scaling complicating things).
Also, this seems to imply that increasing tx supply will bring in more fee revenue. But users alwayspay the lowest fee they can, and miners are selfish â they simply include as many txâs as possible sorted high to low fee. In order for users to pay more total money in tx fees there must be a true increase in demand on their side.
Even if tx revenue increases how can we know it will increase enough to protect the network?
Dontâ Worry, This is all Decades Away
Block rewards wonât go to zero until 2140!
This is maybe the second most common response Iâve heard to this problem.
First of all, saying that a problem is âfar offâ is not reassuring at all â especially when weâre talking about a long-term store of value(!). Maybe we could let things slide if this truly were not a problem at all until 2140, but thatâs not the case.
Block rewards hit zero in 2140, but in just 2 years they halve, in 10 years theyâre down 88% to 1.5625 BTC/block. In 14 years theyâre down 97% to 0.390625 BTC/block.
Just look at the chart. The blue dashes are block reward amount. We are currently on the 3rd one from the left. After 4 or 5 more halvings we are pretty much at zero block reward.

Controlled Supply
Again, the scary thing is that no one knows how big Bitcoinâs security factor (and security budget) needs to be. Apparently 10% and $10B are adequate for now. But the next halving is in 2020. Will 5% security factor be enough? What if BTC price 10xâs and some big institutions feel threatened? Then it halves again in 2024, and again in 2028âŠ
Also, itâs not like people canât look into the future and see where things are headed. How can Bitcoin holders be confident in Bitcoinâs ability to store value without a super solid, bullet-proof, economically-sound, long-term solution to security?
Dominant Assurance Contracts
I have lots of Bitcoin, so I benefit from high hash rate. Therefore I
pledge
0.1 BTC to the miner of the next block so long as the total amount pledged hits 10 BTC.
So, donations? Weâre going to fund the security of the 21st centuryâs global reserve currency via donations?
Charity Mining
Bitcoin will be so important that miners will mine at a loss.
Again, donations?!?
Some people will always be willing to mine for fun/research/good will.
Sure, some people will mine âfor freeâ. But there is no way on Earth we can relyon charity mining to provide the $10M/day (or whatever it happens to be) miner-spend that we need to secure Bitcoin â never mind maintaining a security factor.
Defensive Mining
Miners with a stake in Bitcoin may mine at a loss to defend the network.
If a well-funded attacker starts mining they are adding a bunch of hash power to the network. If the market was relatively efficient, and margins were somewhat thin, then some miners will now be losing money every second that they mine.
These miners must choose to either drop out and cut their losses, or continue mining at a loss in order to âdo their partâ and save the network. Again there is a tragedy of the commons problem here.
But even worse, if miners believe the attacker is well-funded and will probably win eventually, they should cut their losses now (and try to sell their hardware and coins) rather than mine at a loss for the next month only to give up then having spent much more money.
Ethereum has this Problem too!
This is the âyou tooâ logical fallacy since Ethereum having the same problem doesnât help Bitcoin. But I donât think the situation is as bad for Ethereum.
For one, Ethereum has not yet committed to deflationary issuance, while Bitcoin certainly has. In fact, I think Bitcoin supporters would agree that Bitcoinâs 21 million supply cap is absolutely non-negotiable at this point.
Ethereum has also long been planning to move to proof-of-stake, which should allow for greater security per dollar of security budget, and therefore lower security budget and lower issuance â though perhaps never zero issuance.
But either way, Ethereumâs security doesnât really matter to Bitcoin.
Proof of Stake?
Speaking of Ethereum, maybe proof-of-stake (PoS) can solve this problem for Bitcoin? From the Bitcoin wiki:
Some argue that methods based on Proof of Work alone might lead to a low network security in a cryptocurrency with block incentives that decline over time (like bitcoin) due to
Tragedy of the Commons
, and Proof of Stake is one way of changing the minerâs incentives in favor of higher network security.
As far as I can tell this is the only solution that seems like it could work. According to the Ethereum PoS wiki it might even be possible to have zero (or negative) issuance with PoS (donât ask me how), which would allow Bitcoin to stick to the 21 million BTC hard cap.
But is this an active area of research in the Bitcoin community? Would the community even tolerate a move to PoS? It certainly doesnât seem like it. It looks like Bitcoin is committed to PoW for the foreseeable future, for better or worse.

Conclusion
I donât have a vendetta against Bitcoin, but I also donât care if Bitcoin specifically wins the crypto-war. Nor do I care if Ethereum or Dogecoin wins.
I care that cryptocurrencies deliver on what I believe to be their tremendous potential. I hope the best, most secure, most useful one wins (and if I can spot the winner and place some bets that would be fine too :).
We should be hyper-critical of all our cherished cryptos because the last thing we need is for society-at-large to adopt one of these things only to have it blow up in their faces and set the whole field back 10 years.
As I said at the top, if Iâve missed something and this problem isnât really a problem, or there is some great solution that I completely missed, please let me know exactlywhat Iâve missed, I want to know.
That being said Iâm going to keep looking for an answer to this question until either: I find one, or Iâm blocked by every Bitcoin maximalist on Twitter due to Tweeting this post at them!
â â â
Thanks to @dinocellotti and @adampwilkinson for the feedback on this post.
My Twitter: @jordanmmck
Update:
I made a Tweetstorm for this post that resulted in a lot of interesting back and forth. The fee-market is clearly the preferred solution to this problem on the part of Bitcoiners.
(Check out this post for a more in-depth refutation of the fee-market solution to this problem.)
I did not hear any compelling arguments for why tx fee revenue as a percentage of network value should increase â so an extremely low security factor looks likely.
Nor did I hear any argument for why we should expect Bitcoin to survive with a much, much lower security factor. It looks to me like the Bitcoin community is going to more or less just hope that the fee-market is adequate.
Part II: Bitcoin Security in One Chart
Bitcoin: Disinflating to Death
By matteoleibowitz
Posted August 30, 2018

The author owns roughly equal dollar amounts of $BTC and $ETH.
Bitcoinâs disinflationary monetary policy will be its death sentence. The networkâs security will become increasingly vulnerable to attacks as honest miners become priced out, with transaction fees failing to provide necessary revenue in an increasingly competitive mining market.
The second part to this piece, coming soonâą, will explore the migration of Bitcoinâs network to an Ethereum Plasma Cash chain as a solution to the existential threat posed by a disinflationary monetary policy.
First, some context.
Bitcoinâs Value Proposition
Bitcoinâs (the asset, from here on noted as BTC) core value proposition stems from its censorship resistant properties.
Censorship resistance is significant because it allows an asset owner to resist requisition from malicious actors, often in the form of rogue governments like Putinâs Russia, Maduroâs Venezuela, and Erdoganâs Turkey.
For an in-depth discussion on the importance of censorship resistance I recommend reviewing Spencer Bogartâs thesis here.
BTCâs allure is further compounded by a core feature of its monetary policy: there will only ever be 21 million BTC in circulation.
Bitcoinâs Monetary Policy
Satoshi Nakamoto, BTCâs pseudonymous founder(s), settled upon a disinflationary monetary policy, whereby the rate of inflation would decrease exponentially until the year 2140, at which point all 21 million $BTC will have been released into circulation.

BTC Inflation Schedule (Kiran Vaidya)
This disinflationary monetary policy has two important implications:
First, it provides BTC with a characteristic of scarcity.
Scarcity does not in itself confer BTC with value, but it certainly catalyzes the accrual of value: with a static supply curve, any shift in demand should reasonably lead to a higher price level. Moreover, as a scarce asset, BTC naturally appeals to an innate anthropological desire for the rare object. It is BTCâs scarcity characteristic that lends the digital asset to credible comparisons with gold, a historical store of value with a similarly (although not identical) element of scarcity.
The second implication of BTCâs disinflationary monetary policy should be understood in its rejection of that imposed by sovereign nations over their currencies, the latter often referred to as âfiatâ.
Sovereign nations, like the United States, have monopoly power over the ability to print more currency. Currency is printed as a means to satisfy inflation targets or pay debts, and has the indirect effect of debasing the currency-denominated savings held by the population.
US monetary policy has led to a fairly low and steady rate of inflation, especially compared to more egregious suspects like Zimbabwe, which saw its dollar inflate 50%/month in 2007. However, even US Dollar (USD) inflation adds up over time, with $1 in 1900 having the equivalent purchasing power of $28.57 in 2016: thatâs a 2,757.23% rate of inflation over 116 years, or an annualized inflation rate of 2.93%.
Analysts often frame this battle between BTC, a crypto asset, and USD, fiat currency, in the context of Austrian versus Keynesian Economics, with the former school of thought advocating for deflationary monetary policy, thereby increasing the value of savings, while the latter school of thought advocates for inflation, positing that it is necessary in order to incentivize consumption, which then leads to further economic growth.
This article does not intend to advocate for either Austrian or Keynesian monetary policies, but instead seeks to address the sustainability of a disinflationary policy in the context of the Bitcoin networkâs security.
Bitcoinâs Cryptoeconomics
New BTC are minted every 10 minutes in the form of a block reward, or coinbase transaction. At the time of writing, the block reward is 12.5 BTC: it will fall to 6.25 BTC in late 2020. In simplistic terms, these newly minted $BTC are issued to the miner who first discovers and broadcasts the hash of the newest block, a process otherwise known as Proof of Work.
The block reward is at the very heart of Bitcoinâs cryptoeconomic mechanism design, in that it is a monetary incentive for miners to provide hash power to the network, which thus secures the network from malicious actors: a malicious actor has to gain 51% control over the networkâs total hash power in order to execute double-spend attacks and censorship-like behaviour. The block reward is a return on investment for the necessary hardware, electricity, real estate, and often employee expenditure required to mine.
It is this security, derived from the high levels of expenditure required to gain 51% control of hash power in a free market of economically rational actors, that provides Bitcoin with its censorship resistant properties, the very core of its value and the key differentiator from fiat currencies.
Accepting the above statement, one might reasonably question how the network can continue to incentivize miners to provide hash power without this block reward, or when the block reward has approached negligible levels. One might reasonably fear that this quadrennial distancing from the cryptoeconomic protocol will lead to undesired outcomes.
Bitcoin After the Block Reward
The answer proposed by Satoshi and his acolytes is that miners will comfortably rely on transaction fees, the fees attached to each transaction, for revenue. The key assumption here is that by 2140, if not before, the network will have permeated global society to such an extent that transaction volume, and its associated transaction fee volume, will be high enough to sustain miner profitability.
On further inspection, however, this argument lacks empirical rigor, and, moreover, largely conflicts with todayâs zeitgeist, where, as a Store of Value, merely holding BTC, i.e. refraining from transactions, is considered a legitimate use case.
Maths Behind Bitcoin Miner Revenue & Profit
Block rewards:
The current block reward for Bitcoin is 12.5 BTC.
Blocks are produced every 10 minutes.
At the time of writing, 1 BTC = ~$6,600, so each block reward has a USD value of $82,500.
144 blocks are produced/day, with the corresponding block rewards containing a USD value of $11.88m.
So miner revenue from block reward alone is $11.88m.
Now letâs calculate miner revenue from transaction fees.
Transaction fees:
Transaction fees vary depending on the speed at which the transactor wishes to have their transaction processed. They also vary on a daily basis depending on levels of demand for transactions.
At the time of writing, the cost of ânext block feeâ, â3 blocks feeâ and â6 blocks feeâ are $0.51, $0.48, and $0.24 respectively.
For this exercise I will use data from CoinMetrics, which shows that transaction fees have made up roughly 1.3% of miner revenue for the last 6 months.

Transaction fees as % of total miner revenue (CoinMetrics)
At the time of writing, there are ~250,000 tx/day.
If transaction fees make up 1.3% of total daily revenue, this equates to an average of $0.63/transaction and $156,474.16/day of transaction fee revenue. Total revenue from transaction fees and block rewards is $12,036,474.
Miner profitability:
Various estimates put mining costs at ~$3,000/BTC on the lower end and ~$5,000/BTC for less efficient mining operations. For the sake of this exercise I will take miner cost/BTC to be ~$4,000.
All this combined results in current miner profitability of $4,836,474/day: total revenue ($12,036,474) â total costs ($7,200,000). Represented as a percentage, this is 67% profit margin.
I have summarized the above in the table below (with BTC @ $6,600):

Miner revenue/cost/profit breakdown with block rewards present
Now, what does miner profitability look like when you take out the block reward, as will happen by 2140?
Bitcoin blocks at 2mb/block can contain roughly 2,500 tx. At 250,000 tx/day, blocks are not full: 144 blocks * 2,500 tx would be 360,000, or over 110,000 more tx/day than we currently see.
For the sake of this exercise I will presume that blocks are at full transaction capacity. I have made this assumption because I imagine that as Bitcoin continues to grow in stature transaction volume will increase to capacity.
So we have 360,000 tx/day, with average transaction fee at $0.63, resulting in revenue from transaction fees at $226,800.

Miner revenue/cost/profit breakdown without block rewards
You have probably noticed that $226,800 in transaction fee revenue/day falls short of mining costs/day, which we have calculated to be $4,000/BTC, or $7,200,000/day.
In fact, transaction fee revenue is just 3.15% of miner costs.
Mining Landscape
So far, this article has sought to address the state of the Bitcoin network after the block reward has disappeared.
However, it is worth noting that miner profit margins will likely fall well before block rewards disappear as the mining landscape continues to mature and professionalize.
Basic economic theory would suggest that todayâs 67% profit margins are unsustainable in the medium-long term, and new, larger players will enter the market and drive mining towards its equilibrium cost of production.
Bigger players entering the market means more hash power. And as the combined rate of hashpower increases the marginal rate of returns per hash decreases. Expected drastic global reductions in both electricity and hardware costs over time have no impact on profitability if we presume that costs will be cut for all miners. Those miners feeling the heat at todayâs average margins will be squeezed out, leading to further centralization and dissolution of censorship resistant guarantees.
Making Mining Profitable Again
So now we must look at ways in which miners can increase revenue in the absence of block rewards.
This is an existential task considering the danger that miner withdrawal from the Bitcoin network would mean for the value proposition of BTC.
There are four ways to increase revenue:
- Increase block sizes, therefore increasing transaction capacity.
- Increase transaction fees.
- A combination of increased transaction fees & increased block sizes.
- Do away with a fixed, disinflationary monetary policy.
Solution #1:Increase block sizes:
This seems unlikely to be accepted in the context of the heated SegWit2x debate of 2017. At this point it is rather clear that those left in the BTC community will do anything to avoid increasing block sizes, which they argue leads to centralization as overheads increase dramatically.
The BTC camp has instead placed their eggs in the Layer 2 basket, primarily in the form of Lightning Network (LN), an off-chain payment channel. Ironically, LN only further compounds miner revenue issues: if transactions are executed off-chain, users no longer have to pay a transaction fee to miners every time they wish to transact BTC â instead, transaction fees are directed to LN routing nodes, with one-off fees paid to miners each time the LN channel is opened and closed. As this research paper suggests, miner revenue from transaction fees with active use of LN is lower than todayâs levels until a threshold of 20 million LN users, each transacting 10 times/day, is breached. For context, Visa processes 150 million transactions per day.
An analogue solution is to decrease block times, allowing for more transactions/time. However, decreased block times comes with several disadvantages â namely increased bandwidth overheads and more orphaned blocks, which is a waste of hashpower, and ergo lower security â and is unlikely to be supported by the BTC community, which has historically been adverse to significant changes to the protocol, especially those that catalyze further centralization.
Solution #2: Increase transaction fees.
This is more politically feasible than increasing block sizes, and is likely to be the predominant response from $\BTC disciples to this piece, but nevertheless is unlikely to be sustainable in the long term.
With the emergence of LN, one might assume that the average Joe will rely on Layer 2. The problem here is that if LN is to be used in a trust-minimized way â and remember, trust-minimization/verification is at the heart of BTCâs value proposition â then users will need to broadcast their txs on Layer 1 in order to open/close channels. Perhaps even more importantly, a counterparty in an LN channel can misbehave at any point and force a user to broadcast in order to maintain access to their funds: if fees are prohibitively expensive, this essentially negates the value of L2.
Now, what might these increased transaction fees actually look like? Here I defer to Eric Budish, Professor of Economics at the University of Chicago, Booth School of Business, and author of The Economic Limits of Bitcoin and the Blockchain, who estimates necessary transaction fees to avoid network attacks post-block reward ranging from a low end of $18,700 to an upper limit of $108,700. (As several commentators have noted, Budishâs assumptions regarding cost of attack may be slightly misguided, but considering that no comprehensive rebuttal of Budishâs figures exists at present I will continue to use these numbers, albeit with a grain of salt.)
Now we must ask ourselves how attractive an $18,700 fee (on the lower end) per transactionwill be to the banks and businesses using L1 as a settlement layer, let alone average Joeâs using LN wishing to close out channels, especially considering that cheaper alternatives are likely to exist?
Moreover, we must ask how fees would ever get that high in the first place. The transaction fee market is like any other, with price derived from the intersection of supply and demand. Miners do not propose fees themselves and any attempt to artificially fix fees at a minimum of $18,700 would, as game theory dictates, lead to selfish miners including all remaining transactions in the mempool from highest to lowest fee.
And if all this wasnât alarming enough, what about the various attack vectors that open up as the structure of miner incentives changes shape?
Solution #3: A combination of increased transaction fees and increased block sizes.
This is unlikely to fly for the reasons discussed in Solution #1 â the BTC community is unlikely to ever agree to an increased block size â and Solution #2 â increased L1 transactions fees puts L2 users at risk of not being able to recover their funds.
Solution #4: Change $BTCâs monetary policy.
Reinstating a block reward after 2140 (if not before) likewise seems untenable, especially since the BTC value narrative has developed into one of âsound moneyâ, rather than simply a censorship-resistant form of value.
Moreover, BTCâs value narrative is further driven by its ability to exist without active governance, its supposed antifragility, unlike something like Ethereum, which is currently going through a rapid development process involving several significant human-made decisions. A shift away from Satoshiâs monetary policy would be a monumental event and likely split the community, perhaps even more so than the block size debate of 2017. Indeed, like its block size, a disinflationary monetary policy may rightfully be considered to be a fundamental part of BTCâs âsocial contractâ, its essence, and thus any update to the protocol should be thought of as an illegitimate claim to the BTC mantle.
Ironically, despite the inevitable resistance from BTC disciples, a change in monetary policy is likely to most reasonable and effective path to sustaining the network.
The Road Ahead:
There have been multiple times in the history of Bitcoin where miners have operated at a loss. Indeed, we can look at other assets, like silver and copper, to see that producers will operate at a loss for extended periods of time.
However, it seems reasonable to presume that miners will not operate at a loss forever. Indeed, it is mathematically impossible to operate at a loss forever â at some point you will run out of reserves and lack the necessary capital to continue operations.
So if transaction fees alone are unable to keep Bitcoin mining profitable, miners will stop mining. If miners stop mining, then combined hash power decreases.
If combined hash power decreases then the security of the Bitcoin network falls: it becomes even easier for an adversary, like a nation state, to purchase the necessary hardware and electricity . required to contribute 51% hash power and begin double spending and/or censoring transaction.
Once that guarantee of censorship resistance disappears, the Bitcoin network, and the native digital asset, BTC, collapses. And as much as I like to believe in forgiveness, it seems rather unlikely that the market or those relying on BTC as a store of value, will grant Satoshiâs masterpiece a second chance.
Pt.2, Bitcoin on Ethereum: The Only Way Forward,coming soonâą
Thanks toDaniel Goldman,David Beiner, andNic Carterfor taking time to review/provide feedback.
Sign up to CryptoChat, a weekly industry newsletter,here.
Hodlers are the revolutionaries
By Dan Held
Posted August 31, 2018

My reflections on the important role hodlers play in developing Bitcoinâs network (and other cryptocurrency networks).
âIn the beginning of a change the patriot is a scarce man, and brave, and hated and scorned. When his cause succeeds, the timid join him, for then it costs nothing to be a patriot.âââMark Twain
Satoshi published the Bitcoin white paper on 10/31/2008, one month after the collapse of Lehman Brothers sent a shockwave through the financial system. Bitcoin was incepted in a time of absolute necessity. Trust had been lost in a world that ran on trust.

âThe root problem with conventional currency is all the trust thatâs required to make it work. The central bank must be trusted not to debase the currency, but the history of fiat currencies is full of breaches of that trust. Banks must be trusted to hold our money and transfer it electronically, but they lend it out in waves of credit bubbles with barely a fraction in reserve.ââââSatoshi Nakamoto
Through intervention by central banks during the financial crisis, markets have become incredibly distorted, with risk/reward the most skewed its ever been in recorded history. Over ~ 9T of bonds trade with negative yield.
What is unique about the current period is that never before in observable history have so many countries had such long periods without sustainable surpluses. For example, the US has now run a deficit for 40 of the last 44 years (including 2012)
How do you think this plays out?
âPrior to the 20th century, ordinary people could always flee to hard currency (gold) to save themselves from the effects of the failed, inflationist, policies of the central bank. This ended across much of the world in the 20th century as gold was outlawed.âââVijay Boyapati
Never before in observable history have so many countries been off a precious metal type currency system for so long. Coming off the gold standard in 1971 helped create the conditions for almost unlimited credit and debt creation potential that would have been inconceivable through the annuls of economic history.
âSo after 41 years of global fiat currencies and an unparalleled amount of debt that is proving very difficult to shift, we really are venturing into the unknown.ââââJim Reid

Bitcoin was created to build a new financial system, one that didnât require trust, which adhered to principles of sound money. And why does sound money matter?
Money is the tool we use to signal consumer preference. By having a targeted and efficient means to relay consumer demand, producers can concentrate efforts towards goods and services the market desires most. Sound money facilitates this. With unsound money, the market loses the ability to relay its demands to producers. This is why socialism/centrally planned economies simply cannot function. The invisible hand mechanism is too profound and powerful to artificially replicate. Sound money is the catalyst to maximize the division of labour through the maximal efficiency of financial communication.
âOver and over again, the financial system was, in some narrow way, discreditedâŠ. the rebellion by American youth against the money culture never happenedââââBig Short
Satoshi built Bitcoin for the believers in new financial system, the hodlers, the revolutionaries. The ones who were disenfranchised with the existing financial system. The ones who are attracted by the prospect of sudden and spectacular change in their life.
âIn this sense, itâs more typical of a precious metal. Instead of the supply changing to keep the value the same, the supply is predetermined and the value changes. As the number of users grows, the value per coin increases. It has the potential for a positive feedback loop; as users increase, the value goes up, which could attract more users to take advantage of the increasing value.âââ Satoshi Nakamoto
Satoshi needed to bootstrap the network with an incentive mechanismâââthe block reward which (a) controlled currency supply of Bitcoin and (b) created an incentive for people to protect the network.
âHodling bootstrapped bitcoin into existence. Hodling increases value, which increases demand, hash rate, and network security, which, in turn, attracts new hodlers and devs. This self-reinforcing feedback loop drives bitcoinâs network effects, security, and value.ââ@TobiasAHuber
Early hodlers believed in Bitcoin despite overwhelming negativity and false information (ex: labeled as a currency for money launderers and drug dealers, price fluctuations). Hodlers had stronger risk appetite to weather the volatility of being a first mover. Theyâre practitioners of skin in the game
âDonât tell me what you think, show me your portfolio.â â @nntaleb
âHolding bitcoin is the exact opposite of speculation. A trade can be called speculative when the incentives for buying and selling is merely based on market sentiment. You hope to sell the product for profit despite the fact that it did not accrue any intrinsic value for society over the holding period. Holding of money does not have this downside, rather the opposite is true. By holding money you invest in the economy as a whole. Every time you choose to retain money you decrease the available amount in circulationâŠThis leads to the increase of purchasing power per unit of that money. The result is that prices fall and all participants in that economy become wealthier. By holding Bitcoin the price per unit increases. The more people hold Bitcoin in the long run, the more volatility drops towards a gradual increase in price. This convergence towards a stable increase in price makes Bitcoin more attractive to new audiences, creating a feedback loop.ââWillem_VdBergh
âThe increase in Bitcoinâs price has corresponding virality. And as it expands, hodling becomes popular with people with a lower risk appetite, pulling in more and more network effect into the Bitcoin black holeââââ@robustus
With each of those boom/bust cycles weâve seen Bitcoin redistributed from old hodlers to new hodlers via selling, decreasing the Gini Coefficient. In 2017 alone, we saw 15% of all BTC move out of old hodler hands.

âSlowly, but surely, Bitcoin creeps further and further into the psyche of those in charge âââ Vijay Boyapati
Via the Lindy Effect, the longer Bitcoin remains in existence the greater societyâs confidence that it will continue to exist long into the future.
âProtocols die when they run out of believers.â â Naval
The faith in a new financial system is what binds everything together. Bitcoin is not just a software project. Itâs a method of coordination for a large group of people who face powerful adversaries. Bitcoin isnât just a technological breakthrough, itâs also a social one.
âA stable and sustainable ideology must be the foundation of all cryptocurrencies. No amount of cryptography, or consensus protocol development will help a cryptocurrency with an unstable and bankrupt ideology. Stable ideologies allow communities to thriveâ. â Kay Kurokawa
Money is a winner-take-all technology, driven by network effects. The crypto with the most hodlers, therefore, is the most demanded by consumers and will be the ultimate winner.
â Bitcoin is digital gold in the eyes of [Hodlers]. To some extent this group already operates on a Bitcoin Standard: investments are evaluated on their ability to yield a return in Bitcoin.â @ TuurDemeester
By owning Bitcoin, you become the central bank, the backbone of the financial system. Hodling isnât about finding another buyer at a higher price someday in the future, if hyperbitcoinization occurs youâll never have to sell.
The capital markets will be rebuilt by hodlers. The annual rate of return on your Bitcoin is the risk-free rate, with additional layers of return per unit of risk. For example, the Lightning Network provides a framework to measure the time-value of Bitcoin the Lightning Network Reference Rate or âLNRR.ââââNik Bhatia
Bitcoin promises an alternative for citizens across the world to keep their savings in a form of money that can neither be confiscated nor diluted. If Bitcoin grows much larger, it may force governments to become a voluntary organization. Through hodling we may finally be free.
Those who opt-in to Bitcoin (the red pill), are trading something abundant for something scarce, trading the past for the future, trading financial dependence for financial sovereignty.
Dawn of Bitcoin from Dan Held on Vimeo.
