Menu
Open wallet ↗

Crypto 101 · Research papers

White-paper-style analysis. Supply and demand, cited to primary sources.

3 min read7 primary sourcesBitcoin live price

Crypto 101 · Research papers

Bitcoin Tokenomics: A Fixed Supply Enforced by Proof of Work

Abstract

Bitcoin's monetary policy is not stored in a central bank; it is a consensus rule that every full node enforces. The block subsidy began at 50 coins, halves every 210,000 blocks and converges on a total just under 21 million. We diagram the block structure and the network, tabulate the issuance schedule, and discuss the open question the design postpones: how security is paid for once the subsidy has largely disappeared.

Keywords: Bitcoin, halving, 21 million, block subsidy, difficulty adjustment, proof of work

1. Design intent

Nakamoto described the steady addition of a constant amount of new coins as analogous to gold miners expending resources to add gold to circulation, and noted that once a predetermined number of coins have entered circulation the incentive can transition entirely to transaction fees and be completely inflation free [1]. Bitcoin therefore pairs a disinflationary issuance schedule with a security model paid for by proof of work, a cost-bearing puzzle in the tradition of Hashcash [2] and of earlier proposals for unforgeably costly bits [3].

2. Structure: blocks linked by hashes

Three blocks in sequence; each block header holds the hash of the previous header, a nonce and a Merkle root of transactions, and points back to its predecessor.Block N−1Hash of previous headerNonceMerkle root of transactionsBlock NHash of previous headerNonceMerkle root of transactionsBlock N+1Hash of previous headerNonceMerkle root of transactionsptrptrA header is valid only if SHA-256(SHA-256(header)) is below the current target.
Figure 1. Schematic block structure (not a reproduction of any published figure). Each header commits to the previous header, so rewriting history requires redoing the work of every later block. Version, timestamp and difficulty-target fields are omitted for clarity.

Each block header contains, among other fields, the hash of the previous header, a nonce and a Merkle root summarising the block's transactions. A header is valid only if its double SHA-256 hash is below the current target [4]. Finding such a nonce is expensive; checking one is cheap. That asymmetry is what lets thousands of independent nodes agree on one history without trusting each other.

3. Structure: the network

Transaction flow: a wallet signs a transaction, nodes validate and relay it, miners search for a nonce, and the new block is verified and extends the chain.Walletsigns a transactionwith a private keyPeer-to-peer networknodes validateand relay itMinerscollect transactions,search for a nonceNew blocknodes verify it andextend the best chainblock accepted; its transactions leave the pending set
Figure 2. The transaction life cycle in the original design: transactions are broadcast, collected by miners into a candidate block, the block is broadcast, and nodes accept it only if every transaction is valid and unspent.

In the protocol as described by Nakamoto, new transactions are broadcast to all nodes; each node collects them into a block and works on a proof of work; the finder broadcasts the block; nodes accept it only if its transactions are valid and not already spent, and express acceptance by building the next block on top of it [1]. Nodes treat the chain with the most accumulated work as the true one.

4. Issuance schedule

Bar chart of the Bitcoin block subsidy halving each epoch: 50, 25, 12.5, 6.25, 3.125, 1.5625, 0.78125.50125212.536.2543.12551.562560.781257Halving epoch (210,000 blocks, about four years each)Subsidy per block (BTC)
Figure 3. Bitcoin block subsidy by halving epoch. Each epoch is 210,000 blocks, roughly four years at ten minutes per block.

The consensus function that computes the subsidy starts from 50 coins and right-shifts it by one bit for every 210,000 blocks elapsed, returning zero after 64 halvings [5]. The difficulty target is retargeted every 2,016 blocks so that blocks continue to arrive about every ten minutes regardless of how much hardware is mining [6].

Table 1. Bitcoin issuance by epoch (approximate calendar years).

EpochApprox. yearsSubsidy (BTC)Issued in epochCumulative
12009-20125010,500,00010,500,000
22012-2016255,250,00015,750,000
32016-202012.52,625,00018,375,000
42020-20246.251,312,50019,687,500
52024-20283.125656,25020,343,750
62028-20321.5625328,12520,671,875

The geometric series converges: the sum over all epochs is just under 21 million, and integer rounding in satoshis makes the exact figure 20,999,999.9769 BTC [7].

5. A supply-and-demand reading

The supply of new bitcoin is inelastic with respect to price: a higher price does not create more coins, it only changes how much mining hardware competes for the fixed subsidy. That makes the demand side carry all the adjustment. Predictability is the asset's main economic feature: anyone can compute how many coins will exist at a future block height using public code.

6. What the design postpones

The subsidy currently pays for most of the network's security. As it shrinks, security must be funded by transaction fees or the incentive weakens [1]. Whether a fee market can sustain the same security budget is an empirical question the protocol leaves to users and miners. It is one reason other proof-of-work networks made different issuance choices, examined in the pages on Litecoin, Dogecoin and Monero.

References

  1. Nakamoto, S. (2008). Bitcoin: A Peer-to-Peer Electronic Cash System. Whitepaper. https://bitcoin.org/bitcoin.pdf
  2. Back, A. (2002). Hashcash: A Denial of Service Counter-Measure. Technical report; the proof-of-work construction Bitcoin builds on. http://www.hashcash.org/papers/hashcash.pdf
  3. Szabo, N. (2005). Bit gold. Essay proposing unforgeably costly bits as a basis for digital scarcity. https://nakamotoinstitute.org/library/bit-gold/
  4. Bitcoin Wiki contributors (2010). Block hashing algorithm. Bitcoin Wiki: the block header is hashed with SHA-256 applied twice and compared with the target. https://en.bitcoin.it/wiki/Block_hashing_algorithm
  5. Bitcoin Core developers (2009). GetBlockSubsidy (src/validation.cpp). Bitcoin Core source code: the consensus rule for the block subsidy (50 coins, halved every nSubsidyHalvingInterval blocks). https://github.com/bitcoin/bitcoin/blob/master/src/validation.cpp
  6. Bitcoin Wiki contributors (2010). Difficulty. Bitcoin Wiki: the target is retargeted every 2,016 blocks to hold the average block interval near ten minutes. https://en.bitcoin.it/wiki/Difficulty
  7. Bitcoin Wiki contributors (2010). Controlled supply. Bitcoin Wiki: derivation of the 21 million cap from the halving schedule. https://en.bitcoin.it/wiki/Controlled_supply

Common questions

How many bitcoin will ever exist?

Just under 21 million. Because amounts are stored in whole satoshis, the exact limit is 20,999,999.9769 BTC according to the Bitcoin Wiki's derivation of the schedule.

What happens after the last halving?

The subsidy reaches zero and miners are paid only transaction fees. Nakamoto's paper anticipated this transition; whether fees alone will suffice for security is an open economic question.

General education, not financial, tax or legal advice. Figures are schematic. Protocol parameters are cited to primary sources and can change; verify against the linked source before relying on them.