Most arguments about Bitcoin are not arguments. They are people using one word for four different objects and then shouting past each other. One person means a unit of money. Another means a machine. A third means a rulebook. A fourth means a crowd of strangers maintaining some code. None of them is wrong. They are simply not describing the same thing.
This article answers three questions that usually get tangled together: where Bitcoin came from, how a new bitcoin is actually produced, and how you can check every number I give you without trusting me. I will not discuss price and I will not tell you what to do. I will show you the parts, where each part came from, and who pays for it.

Bitcoin is four different things sharing a single name.
Take the confusion apart first. When someone says the word, they may mean any of four things, and the four have little in common.
A coin, in the first sense, is a number in a ledger, divisible to eight decimal places. The smallest unit is one satoshi; one coin is 100,000,000 satoshis. It is issued on a fixed formula, not by a committee.
A network, in the second sense, is a set of machines that gossip transactions to one another and race to assemble the next block.
A protocol, in the third sense, is a rule set. Every node checks it independently. No single party can change a rule and force the change on everyone else, because if you alter the rules the other nodes ignore your blocks.
A project, in the fourth sense, is code plus the people who maintain it. There is no company, no foundation with authority, and no chief executive. There are maintainers who can propose changes but cannot impose them, and miners who can build any block they like as long as the nodes accept it. That is the entire governance model, and it is deliberately weak.
Keep the four apart. Most bad reasoning about Bitcoin comes from sliding between them inside a single sentence: praising the protocol while describing the coin, or attacking the coin while actually meaning the project.
| How people use the word | What it actually names |
|---|---|
| Money | A unit tracked in a ledger, divisible to eight decimal places, issued on a fixed formula. |
| Network | The machines that gossip transactions and race to produce the next block. |
| Protocol | The rule set every node checks independently and no one can change alone. |
| Project | No company, no foundation with authority, no CEO: code, maintainers who can propose but not impose, miners who build what nodes accept. |

A paper from the autumn of 2008
Now the origin, because the origin explains the design. Bitcoin did not appear fully formed. It appeared as the answer to one specific problem, stated in one document.
The document is titled “Bitcoin: A Peer-to-Peer Electronic Cash System.” Satoshi Nakamoto posted it to the cryptography mailing list on Friday, October 31, 2008, at 14:10 EDT, from satoshi@vistomail.com. The subject line was “Bitcoin P2P e-cash paper.” The original announcement is still in the public archive.
In that email he wrote, plainly, that he had been working on a new electronic cash system that was fully peer-to-peer, with no trusted third party. He listed four properties: double-spending is prevented with a peer-to-peer network; no mint or other trusted parties; participants can be anonymous; and new coins are made from Hashcash style proof-of-work, which also powers the network to prevent double-spending.
The problem the paper had to solve was double spending without a trusted third party. A digital signature proves who authorized a payment. A signature cannot stop someone from signing the same coin away twice. You still need something that can rule on order, and the obvious ruler is a central party, which is exactly what was being removed.
The abstract gives the answer: the network timestamps transactions by hashing them into an ongoing chain of hash-based proof-of-work, forming a record that cannot be changed without redoing the work, and the longest chain is proof that it came from the largest pool of computing power.
None of this was invented from nothing. Digital signatures came from the 1970s and 1980s. Hashcash was published by Adam Back in 1997 as an anti-spam measure: sending mail cost a small amount of computation. Satoshi’s email names it directly as the source of new coins. So the parts are: signatures from decades earlier, proof-of-work from that same year, a chain of timestamps, plus one genuinely new idea. The new idea is making the work itself decide order, and paying for that work with the unit being created.
New coins are made from Hashcash style proof-of-work. The proof-of-work for new coin generation also powers the network to prevent double-spending.
Satoshi Nakamoto, cryptography mailing list, October 31, 2008
Where did the first coin actually come from?
Every ledger needs a first entry. Bitcoin’s is block 0, mined on January 3, 2009. Its header timestamp is 1231006505, which is 2009-01-03 18:15:05 UTC. Nonce 2083236893. Bits 0x1d00ffff. Block hash 000000000019d6689c085ae165831e934ff763ae46a2a6c172b3f1b60a8ce26f. Merkle root 4a5e1e4baab89f3a32518a88c31bc87f618f76673e2cc77ab2127b7afdeda33b.
That block contains exactly one transaction, and its fee is zero. It pays 5,000,000,000 satoshis, which is 50 BTC, to a pay-to-pubkey output. That is the first subsidy ever created.
If you go looking for that 50 BTC today, you will not find it in the spendable set. The genesis subsidy is not in the UTXO set, so no key can ever spend it. It exists as a fact about the chain, not as money anyone holds.
Inside that first transaction is a line of text. I will quote it in full at the end. For now, note only that the first block carries a newspaper headline instead of a name.
A new coin is minted by work, not by decree.
Here is the machine. A coin does not exist until someone does the work to add a block, and the reward for that work is new coins plus fees. Walk through it in order.
- A transaction is signed by a wallet and gossiped to peers.
- Every node checks it against the rules. Valid ones wait in the node’s mempool.
- Miners assemble a candidate block, choose transactions largely by fee, and repeatedly hash the 80-byte block header looking for a hash below a target.
- The nonce is a 32-bit field, so miners also vary other header fields to keep searching.
- The winner publishes the block. Every node re-verifies it from scratch, and a block that breaks any rule is ignored no matter who mined it.
- The block’s coinbase transaction pays the miner the block subsidy, which is new coins, plus the fees of the transactions included.
Two details carry weight. First, the coinbase outputs cannot be spent for 100 blocks. This is coinbase maturity, and it exists so that a chain reorganisation cannot strand a reward that was already spent. Second, the chain with the most accumulated work wins. Nodes do not vote. They choose the chain with the most work behind it.
Work has moved from CPUs to GPUs to FPGAs to purpose-built ASICs. That is an industrial progression from a hobby chip to a factory.

Follow the schedule that prints the money.
The issuance is not discretionary. The subsidy halves every 210,000 blocks, on a timetable written into the rules.
| Epoch | Block range | Subsidy | Date |
|---|---|---|---|
| 0 | 0 to 209,999 | 50 BTC | 2009-01-03 |
| 1 | 210,000 to 419,999 | 25 BTC | 2012-11-28 |
| 2 | 420,000 to 629,999 | 12.5 BTC | 2016-07-09 |
| 3 | 630,000 to 839,999 | 6.25 BTC | 2020-05-11 |
| 4 | 840,000 to 1,049,999 | 3.125 BTC | 2024-04-20 |
| 5 | 1,050,000 to 1,259,999 | 1.5625 BTC | expected around 2028 |
Because each subsidy is truncated to a whole number of satoshis, the schedule does not add up to 21,000,000. It adds up to 20,999,999.9769 BTC, spread over 33 subsidy epochs. The last block that pays any subsidy at all is block 6,930,000.
Measured on 2026-09-29, the chain sat in epoch 4, so the subsidy was 3.125 BTC per block. The next halving is at block 1,050,000, which is 80,882 blocks away, roughly April 2028 at 600 seconds per block. Total coins issued so far: about 20,090,896 BTC.
One thing here is genuinely unresolved, and I will not pretend otherwise. The subsidy pays for security today, and every four years it halves. Eventually fees have to carry that cost. Whether fees can actually sustain security at that point is an open question. Nobody has proven it either way. Treat it as the real unsolved design question, not a settled one.
Is ten minutes a rule, or only an average?
People repeat the line that a block arrives every ten minutes as if it were law. It is not law. It is an average the protocol enforces in aggregate, and only in aggregate.
Over the most recent 105 blocks, heights 969,014 to 969,118, spanning 57,736 seconds, that is 104 intervals. The mean was 555.2 seconds. The median was 418 seconds. The minimum was negative 321 seconds and the maximum was 3,708 seconds. The 10th percentile was 44 seconds and the 90th percentile was 1,252 seconds. Of those 104 intervals, 13 were shorter than 60 seconds, 39 were shorter than 300 seconds, and 11 were longer than 1,200 seconds. Across the current 2016-block period, the average interval is 601.5 seconds against a 600-second target.

Four of those intervals are negative, and this is real, not a bug in my measurement. Block 969,045 is stamped 164 seconds before block 969,044. Block 969,056 is 290 seconds before 969,055. Block 969,092 is 321 seconds before 969,091. Block 969,117 is 83 seconds before 969,116. The protocol only requires a block’s timestamp to exceed the median of the previous 11 blocks. It does not have to exceed the block immediately before it. So “ten minutes” is a statistical target, not a rule any single block obeys.
The thermostat that enforces the average is the difficulty retarget, which happens every 2016 blocks. At the time of measurement the tip was at height 969,118, confirmed independently by two different explorers, and the tip block carried 3,463 transactions. It was closed at 2026-09-29 07:15:01 UTC. Difficulty stood at 132,757,073,449,487.52 with a network hash rate of about 946 EH/s. The next retarget was due at height 969,696 with a running estimate of about -0.18 percent; the previous retarget was +4.16 percent.
What it is not
Now the corrections, stated without decoration. Bitcoin is not anonymous. The ledger is public and permanent. Addresses are pseudonymous, and pseudonymous is not anonymous. Addresses can be linked to people by exchanges, by network analysis, and by simple reuse. If you want a private transfer, you are relying on tools that sit beside the protocol; there is a privacy sidecar that nobody has to check.
It is not free. Every transaction pays a fee, and the security of the whole chain is paid for in electricity. It is not instant. Confirmation is probabilistic and takes time, and one confirmation is not a settlement guarantee. You will also meet alarming headlines about future risk, like a quantum bill that dropped 79 percent in a week, and the honest response is to read what was actually measured before deciding whether the sky is falling.
It is not a company. And it is not a coin you happen to be holding because the network might turn out to be useful. Those are two separate claims, and advertising copy fuses them into one sentence so that you cannot argue with either half.
Verify every number yourself.
Do not trust me. Everything above can be checked from public data with no account and no special software. You can read a block yourself here and then compare it against a second source.
- Look up block 0 by its hash and read the coinbase field with your own eyes.
- Open two different block explorers and confirm that the reported height is the same on both.
- Read the subsidy the coinbase pays and check it against the epoch table above.
- Pull the last 105 block timestamps and compute the intervals yourself. The negative ones are real.
- Check the tip height and the difficulty against a second source. If the two disagree, trust neither until they agree.
A number you cannot reproduce from two independent sources is not a number you know; it is a number you have been told.
Go and read block 0. The coinbase field of that first transaction carries this line, exactly:
The Times 03/Jan/2009 Chancellor on brink of second bailout for banks
Bitcoin block 0, coinbase field, January 3, 2009
The value of this design is not that it is clever. It is that every claim inside it can be checked by a stranger with a laptop. A system you must trust is a system you cannot verify.
That is the standard I use for any machine, and it is the only reason this one is worth the time it takes to look. The count of coins, the height of the chain, the schedule of the next halving, the ten-minute myth: none of it asks for your belief. It asks for your arithmetic.







[…] around 2028. The total supply is capped near 21 million coins by this mechanism, which is why the supply limit and the ten-minute block are two consequences of the same design choice rather than two independent […]
[…] header stores. This is what allows a block to be described and checked by a single small string: the header is what miners hash, and the root is what binds the list to the […]