Printed to order · ships from the USAFree US shipping over $75

Bitcoin White Paper Explained, a Plain-English Summary of All 12 Sections

The bitcoin white paper is a nine-page document from October 31, 2008 that describes how people can pay each other online without a bank. Here is what each of its 12 sections says, in plain English.

Updated · 6 min read

The bitcoin white paper, titled Bitcoin: A Peer-to-Peer Electronic Cash System, is a nine-page document that explains how people can send money online directly to each other without a bank, by using a shared, public record of transactions secured with proof of work. Satoshi Nakamoto announced it on a cryptography mailing list on October 31, 2008, and it is still free to read at bitcoin.org.

The paper is short, but it is dense. Below is a section by section summary in plain English, followed by a few things the white paper does not say, which surprise a lot of first-time readers.

The bitcoin white paper at a glance

  • Author: Satoshi Nakamoto, a pseudonym. The paper lists an email address and the website bitcoin.org.
  • Date: announced October 31, 2008, in an email titled Bitcoin P2P e-cash paper.
  • Length: eight pages of text plus a page of references, 12 numbered sections and 8 references.
  • The problem it solves: double spending. Digital files can be copied, so digital money needs a way to stop someone from spending the same coin twice. Until then, that meant trusting a central company to keep the books.
  • The big idea: let a network of computers agree on one public history of transactions, and make that history very expensive to rewrite.

What the white paper says, section by section

Abstract

A short opening paragraph lays out the whole plan: payments sent directly between people, a peer-to-peer network that timestamps transactions into a chain of proof of work, and security as long as honest computers control most of the computing power.

1. Introduction

Online payments depend on banks and payment companies acting as trusted middlemen. That brings costs: reversible payments, fraud, fees that make small payments impractical and merchants who must ask customers for more information than they need. The paper proposes "an electronic payment system based on cryptographic proof instead of trust." That one phrase is the seed of the whole culture of don't trust, verify.

2. Transactions

A coin is defined as a chain of digital signatures. Each owner passes it on by signing it over to the next owner's public key, and anyone can check the signatures. The catch is that signatures alone cannot prove the coin was not also sent to someone else. The usual fix is a central mint that checks every transaction, but then everything depends on the company running the mint, just like a bank. To avoid that, every transaction must be announced publicly and everyone must agree on the order they happened in.

3. Timestamp server

The building block is a timestamp: take a batch of items, hash them and publish the hash widely, proving the data existed at that moment. Each new timestamp includes the previous one, forming a chain in which every link reinforces the ones before it.

4. Proof-of-work

To run that timestamp chain without any central publisher, the paper borrows from Adam Back's Hashcash. Computers search for a number that makes a block's hash start with a required run of zeros. Finding it takes huge numbers of guesses, but checking it takes one. Changing an old block would mean redoing its work and all the work after it. The paper sums up the voting rule neatly: "Proof-of-work is essentially one-CPU-one-vote." Difficulty adjusts over time to keep the pace of new blocks steady. Our guide to how proof of work works goes deeper.

5. Network

The network runs in six steps: transactions are broadcast, nodes collect them into blocks, nodes work on proof of work, a node that succeeds broadcasts its block, others accept it only if every transaction is valid and unspent, and they show acceptance by building the next block on top. Nodes always treat the longest chain as the correct one, and temporary ties resolve once the next block arrives.

6. Incentive

The first transaction in each block creates new coins for whoever made the block. This rewards people for supporting the network and is how coins enter circulation without a central issuer. The paper compares it to gold miners spending resources to add gold to circulation, which is where the word mining comes from. Transaction fees can add to the reward, and once a set number of coins exist, fees can replace new coins entirely. The paper also argues that an attacker with lots of computing power would earn more by following the rules than by cheating.

7. Reclaiming disk space

Transactions in a block are hashed into a Merkle tree, so old spent transactions can be pruned while the block's fingerprint stays intact. A block header alone is about 80 bytes, which works out to roughly 4.2 MB per year if blocks arrive every 10 minutes. The paper notes that computers in 2008 typically shipped with 2 GB of memory, so storage should not be a problem.

8. Simplified payment verification

You don't need a full copy of everything to check a payment. A lightweight user can keep just the block headers and ask the network for proof that a transaction is included. This is convenient but weaker, because the user relies on honest nodes. The paper suggests businesses that receive frequent payments will still want to run their own nodes.

9. Combining and splitting value

Instead of handling every cent as a separate coin, transactions can have multiple inputs and outputs. A typical payment uses one or more inputs and up to two outputs: one to the recipient and one returning change to the sender, like paying with a large bill.

10. Privacy

Banks keep transactions private by hiding them from the public. Bitcoin cannot, since every transaction is announced, so privacy comes from keeping public keys separate from real identities. The paper compares it to a stock exchange's public tape, which shows trades without naming the traders, and recommends a new key pair for each transaction.

11. Calculations

This is the math section. It models an attacker racing to build a secret, longer chain to reverse a payment. Using probability tools such as the gambler's ruin problem and the Poisson distribution, it shows the attacker's chances fall exponentially as more blocks are added. A table shows, for example, that an attacker with 10 percent of the computing power has less than a 0.1 percent chance of catching up after 5 blocks. The section even includes a short piece of C code.

12. Conclusion

The paper wraps up by restating the design: electronic payments that do not depend on anyone being trustworthy, in a network where nodes vote with their computing power, accept valid blocks by building on them and reject invalid ones by refusing to.

What the white paper does not say

Several famous bitcoin facts are not in the paper at all:

  • No 21 million cap. The paper mentions a predetermined number of coins but never gives one. The limit lives in the software Satoshi released in January 2009.
  • No halving schedule and no 50 BTC block reward. Those are also in the code, not the paper.
  • No word blockchain. The paper talks about a chain of blocks and a proof-of-work chain. The single word came later.
  • Barely any bitcoin. The word appears only in the title and the website address, never in the body text.
  • No mining, as such. Miners appear only in the gold analogy; the paper simply talks about nodes doing proof of work.

The paper also cites eight earlier works, including Wei Dai's b-money, Adam Back's Hashcash, Ralph Merkle's work on hash trees and several papers on digital timestamping. Bitcoin combined existing ideas in a new way rather than inventing everything from scratch. About nine weeks after the paper appeared, the network's first block was created, a story told in our guide to the bitcoin genesis block.

Wear the paper that started it

Our White Paper tee carries the paper's subtitle in three lines of white capitals under a partly unrolled orange scroll, with 31.10.2008 in small orange numbers at the bottom. The Genesis Block tee picks up the story nine weeks later, printing the newspaper headline hidden in block 0 under a folded orange paper. And the Proof of Work tee turns section 4 into an orange pickaxe over bold white type, which reads as a work ethic slogan to everyone else. They are independent tributes, printed to order on black unisex tees.

Sources: the bitcoin white paper (PDF) and Satoshi's October 31, 2008 announcement on the cryptography mailing list.

Questions

Quick answers

What problem does the bitcoin white paper solve?

It solves double spending without a trusted middleman. Digital money can be copied, so something has to decide which payment came first. The paper replaces that central bookkeeper with a public chain of blocks that the whole network agrees on through proof of work.

Is the word blockchain in the bitcoin white paper?

No. The paper describes a chain of blocks and a proof-of-work chain, but the single word blockchain does not appear. It became popular later, as people needed a name for the data structure the paper describes.

Which earlier ideas does the white paper build on?

It cites eight references, including Wei Dai's b-money proposal, Adam Back's Hashcash, Ralph Merkle's hash tree work and research by Stuart Haber and W. Scott Stornetta on timestamping digital documents, plus a classic probability textbook by William Feller.

Where was the bitcoin white paper first shared?

Satoshi Nakamoto announced it on October 31, 2008, in an email to a cryptography mailing list, with a link to the PDF on bitcoin.org. In the email, Satoshi said he had been working on a form of electronic cash that needed no middleman at all.

Keep reading

More guides

All guides