iolinked
⌂ home
iolinked · a living data story

Bitcoin, from first principles.

The balance in your banking app is an IOU on one company's books. Here we rebuild money as a record held by about 20,000 computers — every idea live and playable. Real fingerprints of data, real signatures, real coins moving. Nothing faked. Thirteen lenses, one machine: pick one and poke it until it clicks.
◈ the whole picture · 12 live lenses

Bitcoin, from every angle

Cryptography, the coin, the math, the market — thirteen angles on one object, like walking around a sculpture. Jump in anywhere.

Somewhere, someone presses send. A heartbeat later that payment is racing machine to machine, hunting for a seat in the next block — the next page of the shared record.

illustration · not live
how to read it: each drifting dot is a payment crossing the network from the left; gold = more value moving. They funnel into the next block (the grid on the right) until it fills and flashes gold — sealed, one page turned. The record's first page, from January 3, 2009, permanently embeds that day's Times headline about a bank bailout. This one is a picture of the idea; the real, live block is just below ↓
◈ 01 · The network — live transactions
The illustration ends here. Now watch it happen — real payments landing right now on mainnet: the live network itself, not a test copy.

One block, forming

Read it like an airport departures board: every square is a real Bitcoin payment that just happened, landing this second. Nothing is staged.

These are real transactions streaming off the network as you watch. Each square is one payment: size = data, and a single payment is a few hundred bytes. Colour = the money moving: cool blue for small amounts, warming through violet and amber to gold. They pile into the next block: the next page of the shared record, like seats on a train that leaves about every 10 minutes. A miner, a machine that competed for the right to write that page (lens 08 shows how), seals it. The whole thing flashes gold, settles, and a fresh page starts forming.

connecting to the live network…
the next block
How to read the block
  • each square is one real transaction that just landed on the network.
  • size = data (virtual bytes): more inputs and outputs takes more room.
  • colour = the money moving: cool blue for tiny amounts, warming to gold for the biggest.
  • a gold ring = a whale: a transaction moving 10+ BTC.
A block holds about 1 million virtual bytes (lens 10 remeasures this same cap in finer weight units). That is roughly 2,000–4,000 transactions every ~10 minutes. For the entire planet, that is about 3–7 payments per second. And ten minutes is only an average: about 1 block in 20 takes over half an hour. Scarce on purpose: exactly why a fee auction exists, and lens 10 runs it live.
◈ 02 · Markets — the order book
Value just moved across that live block. But what is one bitcoin worth? Nobody sets the number — two lists argue it out, tick by tick.

The order book

An airport kiosk buys currency at one price and sells at another. The gap is its protection. Below, the same two numbers, with thousands of rivals competing that gap almost to zero.

An exchange is a marketplace app where people trade dollars for bitcoin. Every buyer posts the most they'll pay (a bid). Every seller posts the least they'll take (an ask). The gap between the best of each is the spread: the kiosk's cushion, competed thin. Whichever side has more coins waiting is the imbalance. And this is one exchange's book, live. Not the price, just a price.

$—BTC/USDT · live · Bybit
spread
best bid
best ask
buyers
— ₿
sellers
— ₿
the bar leans toward whoever holds more BTC near the price
— spread —
◀ buyers want it cheaper  ·  the amber gap in the middle is the SPREAD  ·  sellers want it dearer ▶
the taller each wall, the more BTC waiting: the gold ₿ numbers show how much
How to read the book
  • the green wall is demand: a running total of bids, adding up as price steps down. Taller = more buyers waiting.
  • the coral wall is supply: the running total of asks as price steps up. Where it climbs steeply, sellers are thick.
  • the gap in the middle is the spread: what it costs to cross from buyer to seller instantly.
  • the imbalance bar shows which side has more coins waiting near the price. That waiting stock is the book's depth.
When a big buyer eats through the coral wall, the price jumps. When sellers pile on, it sags. No oracle, no committee — just this auction, running every millisecond. And there is no single Bitcoin price: every exchange's book makes its own, and the number quoted elsewhere is usually an index averaging several.
What a $100M desk watches — the tells

The book shows intentions, and intentions can be faked. Here's how professional desks read what's really happening in the numbers above: the signals that separate noise from a real move. (Market education, not financial advice.)

The wall that runs
A giant order sits just ahead of price like a fortress — then vanishes the instant price nears. That was never real supply. It's a spoof, posted to scare you into acting. The tell: a wall that holds under pressure is real support; one that flees is theatre.
The wall that won't break
Price hits a level again and again and it doesn't move. Someone large is quietly absorbing every order thrown at it. That calm often comes before a reversal. When the aggressors exhaust themselves against the hidden buyer, price snaps the other way.
The level that keeps refilling
You watch a level get eaten — and it reappears, same size. Eat it again. It's back again. That's an iceberg: one large order hidden behind a small visible tip, feeding in slice by slice. It marks where serious institutional money has drawn its line.
Imbalance is a current
When one side stacks far deeper, price tends to drift toward the thin side, the path of least resistance. Watch the imbalance bar above. But beware: a sudden, extreme lean is often the spoof itself.
When the spread yawns
A calm market has a razor-thin spread. When it widens, the market makers (professionals paid to keep standing offers on both sides) are stepping back because they expect turbulence. It's the kiosk widening its gap: protection, arriving exactly when fear does. Big moves tend to follow.
The tape can't lie
The book can be bluffed. Executed trades cannot. A market order takes whatever price is available right now. When aggressive market orders chew straight through the asks, that's real money moving the real price. Desks trust the tape (what actually filled) over the book (what's merely posted). The book whispers. The tape shouts.
Go deeper

For the fans who want the whole story: tap any question to open it up.

What an order book actually is
Strip away the charts and a market is a notice board with two columns: everyone willing to buy, with the price they'll pay (the bids), and everyone willing to sell, with the price they'll accept (the asks). A "price" is simply the last handshake between the two lists. Everything else (candlesticks, indicators, headlines) is downstream of this one running auction. When you watch the book above, you're watching a price being made, not reported. It never stops, and it belongs to no one.
Why the spread is the market's honesty test
The spread (the gap between the best bid and best ask) is what it costs to change your mind instantly. In a deep, confident market it's a rounding error. The moment uncertainty arrives, market makers widen it to protect themselves, exactly like the airport kiosk widening its gap. So the spread is a live confidence meter. Tight means calm and liquid: plenty waiting to trade near the price. Wide means the market isn't sure of itself and is bracing for a move. Watch it before you trust a quiet chart.
The hidden game — spoofing, absorption & icebergs
Because posting an order costs nothing until it fills, the book is a stage for bluffing. Spoofers post huge fake walls to nudge you, then pull them before they fill. Absorbers quietly soak up everything at a level, hiding their true size until the other side gives up. Icebergs show only a sliver and refill forever. Telling a real wall from a fake one is most of the skill. And the tape (the trades that actually executed) is the lie detector the bluffers can't beat. One calm fact: in US-regulated futures markets, spoofing has been a federal crime since the 2010 Dodd–Frank Act, and traders have served prison time for it. Most crypto exchanges sit outside those rules.
How a single trade moves the whole price
Buy out every cheap ticket to a concert, and "next available" jumps a whole price tier. A market buy does exactly that: it takes the cheapest ask, then the next, then the next, climbing the ladder until it's filled. If the asks above are thin, a modest order can leap the price. If they're stacked thick, even a huge one barely nudges it. That's why depth (how much is waiting near the price) matters more than the order's size. The same buy can be a firecracker or a dud, depending entirely on what's waiting above it. The depth chart above is that ladder, drawn.
Why the ticker says USDT, not USD
One simplification to unwind: this book doesn't trade actual dollars. USDT (Tether) is a stablecoin: a digital token issued by a private company and designed to hold the value of one US dollar. It usually trades within a fraction of a percent of $1, so reading the price as dollars is close enough here. Exchanges like Bybit (the one whose book you're watching) quote in it because a token can move between crypto markets around the clock. Real bank dollars, meanwhile, keep banking hours. So the pair above is bitcoin priced in a dollar stand-in, and that token's $1 promise depends on the issuing company holding real reserves behind it.
◈ 03 · Markets — the prediction model
The order book you just watched prices Bitcoin this second, tick by tick. The harder question: can anything honest see seven days out?

The honest oracle

Your weather app's "70% chance of rain" is an honest machine forecast: re-run every morning, graded against the sky. This oracle is exactly that for one narrow Bitcoin question, built on free public data, coin-flip baseline and all.

A decision tree is a 20-questions flowchart: price rising? Swings widening? Each answer branches until a call drops out. Boosting stacks shallow trees, each new one trained on the last one's mistakes. That stack is a gradient-boosted forest reading 22 signals: momentum, volatility, distance from the long-run average price, and the network's vitals. Two of those, hashrate (the network's guessing speed) and difficulty (how hard that guessing is made), are unpacked at lenses 08 and 11. Its one daily question: over the next seven days, is the wind at Bitcoin's back or in its face? The call is LONG, or stand in cash. Every number below is out-of-sample, scored only on days it had never seen.

Act I

Today's call

This is the live signal, straight from the oracle. It is not advice. It's a forecast you can grade in real time, the way you grade the weather app against the sky.

reaching the oracle…
— — —
A LONG call means the model puts the odds of a higher price seven days out above 50/50. FLAT means it would rather hold cash than bet. The probability is its 70%-chance-of-rain: how sure it is. It is rarely very sure, and that honesty is the point.
Act II

The track record — measured, not promised

Anyone can draw a line that fits the past. The only score that matters comes from days the model has never touched, and two terms need unpacking. Sharpe is return per unit of rollercoaster: higher means a smoother ride for the same gain (a simplified reading, but the right instinct). Drawdown is the worst peak-to-valley fall you would have sat through.

53.5%
7-day direction, called right
coin-flip = 50.0%
1.50
strategy Sharpe
buy & hold = 1.16
−76%
worst drawdown
buy & hold = −85%
Read it honestly: 53.5% is barely better than a coin flip. For scale, the most successful quantitative trading fund in history is reported to have been right on only just over half its trades. A real edge is small, or it isn't real. That sliver, compounded and kept out of the worst crashes, is what lifts the Sharpe above buy-and-hold's.
Act III

Why you can trust the number — walk-forward

A backtest is a rehearsal on past data, and the easiest way it lies is by letting the model peek at the future. This one can't. Three rules, enforced by the code itself:

  • 1 · No lookahead. Every feature on a given day is built from data up to that day only — rolling windows and backward differences, never a value from the future.
  • 2 · Only resolved labels. The model trains only on days whose 7-day outcome had already happened. It is never taught the answer to a question still open.
  • 3 · Strictly unseen. Each prediction is made on a day after the last it trained on, and scored on the return that actually followed. No day is ever both a lesson and a test.
This is walk-forward validation, the past-papers rule. Train on old exam papers, then be graded only on the exam you have never seen. It's why the numbers above are modest: a dishonest backtest is always spectacular, and always fake.
Act IV

It retrains every day — here's exactly when

Bitcoin never sleeps, and neither does the data. Once a day, just after the network's UTC daily close, the oracle wakes, pulls the fresh day, and re-runs the entire walk-forward pipeline, 2009 to now. The close is when blockchain.com finalizes yesterday's on-chain numbers: the figures read straight from the shared record. Today's call is trained on everything up to yesterday, and not one minute more.

daily retrain · 00:30 UTC
in your time zone, that's
next retrain in
Why just after midnight UTC? Because that's when the day's on-chain figures (the hashrate, the fees, the active addresses the model leans on) are finalized. Retrain any earlier and you'd feed it a half-written day. The model waits for the shared record to settle, then reads it.
◆ go deeper · the machine behind the call
Why gradient-boosted trees, and not a neural network?
Because since 2009 there are only about 6,000 daily rows of Bitcoin data: even at 22 signals each, fewer numbers than the pixels in one phone photo. That is tiny by machine-learning standards. A deep network would memorize it and call the noise a pattern. A forest of shallow trees (depth 3), heavily regularized (penalized for every extra branch it grows), is forced to find only the coarse, repeatable structure. It also hands you permutation importances, an honest ranking of which signals actually earned their keep, so the model can explain itself. Interpretable and hard to overfit beats clever and opaque, every time, on data this scarce.
What does "out-of-sample" actually protect you from?
From the oldest lie in quantitative finance: fitting the past. Give a flexible model the full history and it draws a perfect line through it — then falls apart the moment real, unseen data arrives. Out-of-sample means the score you see was earned only on days the model had never been shown when it made the call. It's the difference between "here's how it would have done" (worthless) and "here's how it did, blind" (the only thing worth trusting).
Why seven days, and why only long-or-cash?
Seven days is long enough for a real on-chain shift to express itself, short enough to stay a directional question rather than a macro guess. And long-or-cash, never short. That's because the honest edge here is small and asymmetric. The model is better at spotting "probably not a good week to be exposed" than at timing a fall to profit from it. When it isn't confident, it steps aside. Doing nothing is a position, and often the right one.
Not financial advice — a transparent experiment. The point was never to beat the market. It's to show, end to end, how an honest model is built on free data, and how modest a genuine edge looks when nobody's allowed to cheat. Believe the small number. Distrust the big one.
◈ 04 · On-chain — following the money
The model learned from public data: the whole ledger is readable by anyone. Now read it yourself: pick a wallet and follow the money.

Bitcoin flow

Every coin is a serial-numbered banknote with every hand-off logged. Paste a wallet address (a wallet holds keys, not coins) and follow the money: in, out, and how long it has sat still.

Your bank statement is private: you and the bank. Bitcoin inverts that — every balance and every move is public, forever, names swapped for addresses. An address is a generated name, not an account: no signup, no bank (lens 06 shows what generates it). The box below holds history's first address: Satoshi's, the pseudonymous creator's, from the genesis block, Bitcoin's very first, of January 3, 2009.

↓ Enter any address: its whole life story, like a car-history check
try: Satoshi's genesis address · Binance cold wallet · Bitfinex cold wallet (a cold wallet is an exchange's vault address)
↓ in = money arrived from another address. ↑ out = money left for one. The counterparty is that other address. Amounts are in BTC; time is how long since it confirmed, meaning written into a block. Every move is a permanent, public fact. The 10,000 BTC that bought two pizzas on May 22, 2010, the first documented real-world purchase, is still traceable in data like this.
The "held for" line is the life of those coins: how long they have sat unmoved. Years dormant is a holder's conviction made visible. Moving hourly is an exchange at work. And the genesis address is the extreme case: a quirk in the original code left its first 50 BTC unspendable. Yet tribute keeps arriving, so the balance only ever grows.
◈ 05 · Cryptography — the Merkle tree
A payment becomes a permanent, public fact. Permanent how? Start with how one block seals thousands of payments under a single fingerprint.

A thousand payments, one fingerprint

The last digit of a debit-card number is computed from the others. Change one digit and the check fails. Scale that check to 32 bytes and it works on any data at all. That's a hash: a fixed-size fingerprint of the data itself. Bitcoin's hashing recipe is named SHA-256. Change one letter, the whole fingerprint changes, and nothing runs backwards. That one tool will seal thousands of payments, and let a phone verify one without downloading the blockchain.

The structure is a Merkle tree, and it runs like a tournament bracket. Hash the payments in pairs, then hash the pairs, then the pairs of pairs, until one champion remains — the Merkle root. That root is stamped into the block's 80-byte cover sheet, where lens 08 will make it ruinously expensive to change. Below: build the tree and tamper with it, then prove a single payment is inside, using almost nothing.

Act I

The seal — and how tampering shows

Here are eight payments. Each one is hashed into a leaf. Every pair of leaves is hashed together, and so on up to the root, the bracket's champion. Tap any payment to tamper with it: change who got paid. Then watch its fingerprint, and every hash on the path above it, flip red all the way to the root. One altered payment can't hide.

▲ tap any bottom transaction to tamper with it
Eight payments, sealed into one root. Nothing tampered yet.
Only the hashes on the path from the changed leaf to the root recompute. That's about log₂(n) of them, the number of doublings it takes to reach n. For eight leaves, that's three. But it's enough: the root changes, and the root is what every checking computer compares. To make a forged payment fit, you'd have to re-earn the block's proof-of-work: the energy seal on the cover sheet, built properly in lens 08.
Act II

The proof — prove one, download almost nothing

Now the payoff. To convince someone that your payment is in this block, you don't hand them all eight. You hand them a small branch: one sibling hash from each level. It's the tournament move: proving you played by showing only your own results, round by round. With those few hashes they re-climb the tree from your leaf and arrive at the exact root the block already published. Tap the payment you want to prove.

▲ tap a transaction to see the gold sibling hashes that prove it
Tap a payment above to build its proof.
This is a Merkle proof, and it's why light wallets work. Your phone never stores the blockchain. It holds only the block headers: the 80-byte cover sheets, each carrying its root. To confirm a payment cleared, it asks a full node (a computer that stores and checks everything, met properly in lens 09) for the branch. Then it recomputes the root and checks it against the root in the header. Trustless is the exact word: a fake branch can't hash to the real root, so you needn't trust the node you asked.
Act III

Why the proof stays tiny

The tree's power is the logarithm. Double the number of payments and the proof grows by just one hash. Slide the block up toward a million payments and watch the proof crawl to twenty.

1,024
transactions
10
hashes to prove any one
32 bytes
to commit to them all
A block of a million transactions needs a proof of only ~20 hashes (about 640 bytes) to prove any single payment is inside. That's the whole invention: log₂(1,000,000) ≈ 20. Verification cost barely moves while the block grows without limit. One 32-byte root at the top, a 20-hash ladder to reach any leaf. Enormous commitment, tiny proof.
◆ go deeper · the tree of hashes
Where does the Merkle root actually live?
Inside the block header: the compact 80-byte cover sheet that miners hash in the proof-of-work lottery of lens 08. The header holds the previous block's hash, a timestamp, the difficulty target (how hard the lottery currently is), and the nonce (the counter miners keep changing to re-roll). It also holds the Merkle root of all the block's transactions. Because mining hashes the header, and the header contains the root, the proof-of-work commits to every transaction at once. Change any payment and the root changes, the header changes, and the block's hard-won hash is void. The tree is the bridge between "thousands of transactions" and "one number worth mining over."
So how does a phone verify a payment without the whole chain?
It's called SPV, Simplified Payment Verification. A light wallet downloads only the chain of headers, 80 bytes each. Every header since 2009 (the cover sheets of all history) totals under 100 MB, so a phone can hold the skeleton of the entire chain. To check that a payment confirmed, the wallet requests a Merkle branch for that transaction from a full node. It recomputes the root from the leaf up, and confirms it equals the root in the header it already holds. It never sees the other transactions, and it can't be lied to: a fake branch simply won't hash to the published root. A boarding pass scanned at the gate: verified against the manifest without downloading the airline's database.
Why hash in pairs instead of one big hash of everything?
Because a single hash of the whole blob would be all-or-nothing: to check that one transaction is inside, you'd need all of them to recompute the hash. The pairwise tree buys the compact proof. Splitting and re-hashing means the path from any leaf to the root touches only log₂(n) hashes, so a handful of siblings proves membership instead of the entire set. The tree trades a small amount of extra hashing for a proof that shrinks from everything to almost nothing. That trade is the entire reason the structure exists.
What happens when there's an odd number of transactions?
A binary tree wants pairs. So when a level has an odd count, Bitcoin simply duplicates the last hash and pairs it with itself, making the count even again. It's a small, pragmatic patch. And a famous early bug (a way to craft two different transaction lists that produced the same root) came from a subtle flaw in exactly this duplication rule. It was later fixed by tightening the validity checks. A reminder that in cryptography the edge cases are where the danger hides, and the odd-node corner is a classic one.
What can a Merkle proof NOT tell you?
It proves inclusion — that a transaction sits in a block with a given root — and nothing more. It does not prove the transaction was valid: that its signatures check out, that the coins weren't already spent, that the amounts add up. Those are checked by full nodes, the everything-checking computers of lens 09, which validate every rule for every transaction. A light wallet leans on the assumption that the most-worked chain is made of valid blocks, because miners won't waste energy sealing invalid ones. So a Merkle proof answers "is it in there?" with certainty, and defers "is it legitimate?" to the nodes that verify everything. Knowing that boundary is knowing what SPV really trusts.
◈ 06 · Cryptography — keys & digital signatures
The block proves what's inside it. But what proves a payment was yours to make?

One number — and it's yours forever

Tap your debit card. The chip inside just proved it holds a secret, without revealing one bit of it. Bitcoin's ownership runs on the same trick, except now you hold the chip: one secret number, and whoever knows it owns the coins. No password reset. Just math.

We've followed coins between addresses anyone can look up. So one question is overdue: if the world can see your address, what stops it spending from it? A pair of keys. A private key you never reveal, a public key anyone can check, and a one-way street between them that no computer can walk backwards. Seeing costs nothing. Spending takes a signature only the private key can produce. Keeping that key yourself, like cash with no company in the middle, is self-custody. Everything below is real cryptography running in your browser right now. Roll a key, sign a message, then try to forge it.

did you knowThere are 2²⁵⁶ possible private keys: about 1.16 × 10⁷⁷, more than the estimated atoms in a million galaxies like ours. Guessing someone's key isn't hard. It's physically impossible.
Act I

The keypair

Press roll. Your browser picks a random 256-bit number: 256 coin flips, a number up to 78 digits long. That's your private key. One step of elliptic-curve arithmetic turns it into your public key: an arithmetic where forward is a single move and backward has no known shortcut. Hashing that gives your address. Down the ladder is easy. Nobody has ever climbed back up.

a brand-new identity, every press
🔑 private key never sharerolling…
↓  multiply a point on an elliptic curve · one-way
📢 public key share freely
↓  hash it down · one-way
🏷 address your public name
The private key is just a number between 1 and about 2²⁵⁶, the same 1.16 × 10⁷⁷ possibilities from the factoid above. A space that size needs no registry. Pick a random number offline, with no server and no permission, and the chance anyone else ever lands on it is as close to zero as physics gets. Own the number, own the coins.
Act II

The signature

Now spend. Type a message and sign it with your private key. Out comes a signature: a scramble only your key could have produced for this exact message. Compare that to a password: a password must be shown to the checker, so the checker must be trusted. A signature is verified against your public key, and the secret never leaves your side.

— press sign to produce a signature —
The signature is checked against your public key. If it matches, the network knows the message truly came from the holder of the private key.
Notice: sign the same message twice and the signature looks different each time — yet both verify. Every signature carries a fresh dash of randomness, and that dash is load-bearing. Sony reused it across PS3 signatures, and in 2010 hobbyists extracted the console's master key with schoolbook algebra. Fresh randomness each time, and your key can sign forever without ever leaking.
Act III

The forgery that can't happen

Here's the flip no wax seal ever managed. A signet ring pressed in wax leaves a recognizable mark, but the mark says nothing about the letter beneath it, and wax can be forged. This seal is computed from the message itself. Change one character, Bob into Rob or 0.5 into 5.0, and the check instantly fails. That's why a payment can cross an open, hostile internet and nobody can tamper with a cent of it.

— sign a message in Act II first —
The signature and public key never change here: only the message does. Match the original exactly and it's VALID; nudge a single byte and it's FORGED. No middleman decides this. The math does, identically, on every machine on Earth.
◆ go deeper
So a wallet doesn't actually hold coins?
Correct, and this trips up almost everyone. The coins live on the blockchain, as entries that say "these are controlled by address X." Your wallet is really a keychain: it stores the private keys that can sign a valid instruction to move whatever those addresses control. Lose the key and the coins don't vanish — they're visible to all, forever — but they become unspendable, frozen in plain sight. "Not your keys, not your coins" is not a slogan; it's the literal mechanics.
How can the public key be public and still be safe?
Because the link runs one way only. Deriving the public key from the private key is a single multiplication on an elliptic curve — fast. Going backwards (the "discrete-log problem") means undoing that multiplication, and the best-known method would take longer than the age of the universe on all the computers ever built. So you can hand out your public key and address to the whole planet, and your secret stays secret. Easy one way, hopeless the other: the same asymmetry that powers mining powers ownership.
Two keys? A padlock has one. Why the split?
Older ciphers are symmetric: a single secret key both locks and unlocks, so both sides must already share it. That just raises a harder question: how did you deliver that secret safely in the first place? The breakthrough was asymmetric cryptography: a pair of keys where the public one is derived from the private one. Your private key stays with you alone; your public key can be shouted from the rooftops. Anyone can use the public half to verify your signatures or send you funds, but only the private half can spend. Bitcoin is asymmetric to its core. That's the entire reason you can publish an address to the world and still be the only one who can move the coins.
How did two strangers ever agree on a secret in the open?
This is the 1976 idea that made all of it possible: the Diffie–Hellman key exchange. Ada and Charles, who have never met, each pick a private number they never reveal. They swap a couple of public numbers completely in the clear: roughly A = ga mod p and C = gc mod p. Then each raises the other's number to their own secret. By a tidy property of modular arithmetic they both land on the same shared secret, while an eavesdropper who copied every message sent still cannot compute it. Point that same one-way math at proving identity instead of hiding messages and you get digital signatures. And Diffie–Hellman gets its own lens just below.
Bitcoin uses "secp256k1" — what is this page using?
Straight answer: this lab uses P-256, the elliptic curve that ships built into every browser (crypto.subtle), so the signing and verifying you see are 100% real with zero downloads. Bitcoin uses a sibling curve called secp256k1: same idea, same one-way math, different constants chosen so the numbers are a touch faster to compute. The lesson is identical on either curve: a secret scalar (your private number), a public point, an unforgeable signature. When you graduate to a real wallet, it's the same three boxes on Act I's ladder.
Isn't signing the same as encryption?
No — opposite jobs. Encryption hides a message so only the intended reader can open it. Signing does the reverse: it leaves the message in the clear but wraps it in proof of who wrote it and that nobody edited it. Bitcoin payments aren't secret (every one is public on the ledger); they just have to be unforgeable. That's why the whole system leans on signatures, not encryption.
What is a seed phrase, then?
Twelve or twenty-four words you may have seen written on a card. They are a human-friendly spelling of one master secret: from that single number your wallet derives every private key it will ever use. Each word comes from a fixed list of 2,048, so a person can copy the whole secret without a typo. Anyone who reads the words can rebuild every key and take everything, which is why they're guarded like the crown jewels. One number, many disguises.
Wait — my debit card already does this?
Yes, on every tap. The chip on a modern debit card (the standard is called EMV) holds a private key that never leaves the chip. The terminal sends a fresh random challenge, the chip signs it, and the terminal checks the signature against the card's public key. That's why chips killed card cloning: the old magstripe showed its secret to every reader it touched, while the chip shows nothing and only proves. Bitcoin uses the same challenge-and-sign pattern, with one difference in who holds the key. Your bank issued the card's key and can revoke it. A Bitcoin key is rolled by you, on your own machine, and answers to no issuer at all.
◈ 07 · Cryptography — the Diffie–Hellman exchange
Signatures lean on something stranger still — two strangers minting a secret in the open.

Two strangers. One secret. In full view.

Alice and Bob have never met. They shout numbers at each other across a crowded room, and an eavesdropper writes down every word. By the end, the two of them hold a shared secret she cannot compute. Nothing was whispered. Nothing travelled hidden. In three acts, we build the trick with our own hands — then attack it ourselves.

One honest note before we start: Bitcoin does not run this exchange. It stands on the same one-way wall, and this is where that wall was first built — Diffie and Hellman, 1976, working in the open. The wall is a single lopsided operation: trivial to do forwards and hopeless to undo backwards. Build it by hand below. Then watch two people mint a shared key over an open wire, and try, and fail, to break it.

Act I

The one-way operation

Everything hinges on modular exponentiation: pick a base g, raise it to a power x, and keep only the remainder after dividing by a prime p — written gx mod p. Picture a clock with p hours. Counting forward is easy. But landing on hour 14 tells you nothing about how far you walked. Why a prime? The short answer — simplified, and flagged as such: a prime clock with a well-chosen base spreads the leaps across the whole ring, while a poor setup collapses the walk into a short repeating loop an attacker could map. Drag the power and watch the result leap around the ring with no pattern at all — even though each leap is a single cheap multiplication.

p = 23 · a 23-hour clock
Forwards is one multiply. Backwards is the wall. Handed only the landing spot gx mod p, recovering the power x is the discrete logarithm problem. After fifty years of open attack, nobody has found a shortcut meaningfully faster than searching. With p at twenty-three, you could check every power by hand. Make p a few hundred digits long and that same search outlives the sun. That gap — cheap one way, ruinous the other — is the hinge the entire exchange swings on.
Act II

The exchange

Now the exchange itself. g and p are public — everyone, eavesdropper included, knows them. Alice picks a private power a. Bob picks a private power b. Each announces only the result of their one-way walk. In clock terms: each says which hour they landed on, never how far they walked. Then each takes the hour they received and walks it forward by their own secret. They land on the same place. Change any dial and watch every number recompute.

Alice

picks a private power a
→ sends A across the open wire

Bob

picks a private power b
→ sends B across the open wire
👁 everything the eavesdropper sees
…and from those four public numbers, no known method recovers the shared secret.
the shared secret they both computed
Alice computes  Ba mod p  =  (gb)a mod p  =  gba mod p
Bob    computes  Ab mod p  =  (ga)b mod p  =  gab mod p
and because raising a power to a power multiplies the exponents,  gab = gba — one number, reached from two directions. Neither of them ever had to send it.
Read that again, because it is the entire idea: the secret gab is never transmitted. Alice knows a and the number Bob sent. Bob knows b and the number Alice sent. The eavesdropper knows g, p, A and B — but to finish the sum she would need a or b, and those sit behind the discrete-log wall from Act I.
Act III

Let the eavesdropper try

She holds g, p, A, B. Her only path to the secret is to crack one private power out of a public number — to solve gx mod p = A for x. Below, actually let her brute-force it. On a toy prime she wins in a blink. Switch to real scale and the same attack falls off a cliff.

She'll walk the powers one by one, hunting for the exponent that reproduces A.
On p = 23 there are only twenty-two powers to try — of course she cracks it. That is the point: small numbers are toys. Every extra digit of p multiplies her workload by ten. At real sizes, with primes hundreds of digits long, the count of guesses dwarfs the roughly 10⁸⁰ atoms in the observable universe. Her fastest machine would still be searching after the sun burns out. Same math, unbreakable — purely by scale.
◆ go deeper · the mathematics
Why do the two sides land on the exact same number?
Try it with paint first. Alice and Bob start from one public base colour. Each stirs in a secret tint and they swap the mixtures. Then each stirs their own tint into the can that arrived. Both cans end the same colour, because stirring order does not matter — and un-mixing paint is hopeless. Now the same fact in symbols. One law of exponents does all the work: raising a power to a power multiplies the exponents. Alice: B^a = (g^b)^a = g^(b·a) Bob: A^b = (g^a)^b = g^(a·b) and a·b = b·a → g^(a·b) = g^(b·a) Both people compute g raised to the same product a·b, just in the opposite order — and multiplication does not care about order. So they must meet at one value. The remainder wrapping never breaks the equality, because arithmetic mod p respects multiplication. Two roads, one destination, and the destination was never spoken aloud.
What exactly is a discrete logarithm, and why is it hard?
An ordinary logarithm undoes exponentiation on the number line: from 10^x = 1000 you smoothly reason "x is 3," and if the target were 1001 you'd know x is a hair over 3. The order is preserved, so you can home in. A discrete logarithm asks the same question after everything has been folded through mod p: given g, p, and y = g^x mod p, find x. But the mod wrapping shreds the ordering — consecutive powers scatter all over the ring (you saw it in Act I). There's no "warmer / colder," no slope to follow, no way to bisect. The best general methods still take roughly the square root of p steps. For a 256-bit prime that is about 2¹²⁸ guesses — and checking a trillion per second on a billion machines at once, you would need roughly ten billion years. For scale, the universe is about 13.8 billion years old. Easy to make, catastrophic to invert: that asymmetry is the raw material of modern cryptography.
Is this the same math that protects Bitcoin?
It's the same shape of math, upgraded — which is the honest sense in which Bitcoin "uses" this lens. Everything here lives in numbers under mod p, where the one-way operation is exponentiation and the hard problem is the discrete logarithm. Bitcoin (and most of the modern web) swaps that playground for points on an elliptic curve — Bitcoin's curve is named secp256k1. There the one-way operation is adding a point to itself a secret number of times, and the hard problem is the elliptic-curve discrete logarithm — the same trapdoor shape, easy to fall through and effectively impossible to climb back, but so much stronger per digit that a 256-bit curve key rivals a 3,072-bit classical one. Your Bitcoin private key is exactly the "secret power". Your public key is the point you reach. And the signature that proves a coin is yours is this identical asymmetry, pointed at proving authorship instead of sharing a secret.
Why must the secret powers be random and never reused?
The wall only stands if the attacker has to search the whole space. If your secret is small, predictable, or drawn from a habit, she doesn't brute-force p possibilities — she checks the few thousand likely ones and walks straight in. Worse, in the signing cousin of this scheme, reusing the one-time random value across two different messages leaks the private key outright through simple algebra — two equations, one unknown, solved. That is not hypothetical: in 2013, a flawed random-number generator on Android phones repeated those one-time values, and thieves ran that very algebra to recover private keys and drain real Bitcoin wallets. So real systems draw fresh secrets from a high-quality source of randomness for every operation. In cryptography, predictability is the vulnerability; a secret is only as strong as it is surprising.
Could a future computer ever break it?
Against today's machines, no — the discrete-log wall holds by sheer scale. But a large-enough quantum computer changes the game: a known quantum algorithm — Shor's, published in 1994 — solves the discrete logarithm (and its elliptic-curve form) efficiently, collapsing the wall this whole scheme leans on. No machine of the needed size exists, and one may not for a long while. But the risk is real enough that cryptographers are already standardising post-quantum methods built on entirely different hard problems (lattices, hashes, codes) that quantum computers don't obviously crush. The one-way idea survives; only the particular lock changes.
Have I ever used this exchange myself — and who found it first?
You used it loading this page. Nearly every https connection — the padlock in your address bar — opens with a key exchange of exactly this shape, usually the elliptic-curve version. Your device and this server minted a shared secret over the open internet, then encrypted everything else with it. Act II is not a museum piece; it runs billions of times a day. The history carries a quiet twist, too. Mathematicians at GCHQ, Britain's signals-intelligence agency, had found the same mathematics by 1974, and it stayed classified until 1997. Diffie and Hellman reinvented it independently in 1976 and published. That is why the open world got secure channels at all, and why the method carries their names.
◈ 08 · Cryptography — SHA-256 & proof-of-work
That same one-way math decides who earns the right to write the next page of history.

The lottery that seals every block

With no boss, someone still has to write the next page of the record. Bitcoin's answer is a raffle whose tickets cost electricity: more guesses, more chances. The winner writes the page and collects the block reward: a payout of newly created bitcoin. Machines now guess several hundred quintillion times a second, and a win still takes about ten minutes.

The raffle runs on SHA-256, the fingerprint machine from lens 05, where one 32-byte fingerprint stood for every payment in a block. Now we need its stranger habits. The same input always lands on the same fingerprint. Yet nobody can run it backwards, and nobody can steer it toward an output they want. The three parts below let you feel both facts — and feel why guess-and-check is the only way anyone has found to win.

right nowThe whole network is making several hundred quintillion guesses every second (10²⁰-plus hashes), and it still needs about ten minutes to win once. That pace is set by the difficulty: the count of leading zeros a winning fingerprint must show, re-tuned every 2,016 blocks. Lens 11 shows how.
Act I

The fingerprint

Type anything. Watch its 256-bit fingerprint appear: each of the 256 squares is one bit, lit if it's a 1. The same words always give the same tapestry, and a machine anywhere on Earth agrees to the last square.

256 bits means 2²⁵⁶ possible fingerprints: about 1.16 × 10⁷⁷ of them. In 25 years of open attack, no two different inputs have ever been found that share one. Yet the same message always lands on the exact same fingerprint, on every machine on Earth, forever. That is what "deterministic" means, and it is why a fingerprint can stand in for the thing itself, just as the Merkle root did in lens 05.
Act II

The avalanche

Now change the tiniest thing — one letter — and watch. About half the 256 bits flip (≈128), scattered everywhere, no pattern. Each output bit behaves like an independent coin-flip, so any change at all reshuffles roughly half of them. This is the avalanche effect. It means there is no "warmer, colder" to follow toward a goal. Nobody can steer a fingerprint toward a value they want. The only move left is to try, look, and try again.

0 of 256 bits flipped from a change of
Make one edit above (a letter, a capital, a space) and the amber squares show every bit that changed.
Act III

The lottery

A miner hashes the block header. That's 80 bytes holding the Merkle root, the previous block's fingerprint, and a spare number called the nonce. To win, the header's fingerprint must start with a run of zeros, the top-left squares all dark. That is 256 coin flips where the first few must all come up 0: no memory, no steering, only another nonce. Drag difficulty up by one and the target gets 16× rarer. Hit mine and feel the search.

2 leading zeros · 1 in 256
0 attempts 0 hashes/sec nonce 0
Here you need only a few zeros. Real Bitcoin currently demands about 19 to 20, for odds near 1 in 10²³ per try. (The "run of zeros" is a small simplification: the full rule reads the fingerprint as one huge number and requires it to fall below a target. Leading zeros are that same test made visible.) Finding a winner takes that mountain of guesses. Checking one is a single hash, like checking a finished sudoku. That gap — brutally hard to make, trivial to verify — is proof-of-work. SHA-256 has faced open attack since 2001, and the fastest known way to find these zeros is still guess-and-check.
How to read the tapestry
  • each of the 256 squares is one bit of the fingerprint: read left→right, top→bottom. Hue follows its row, so you can see where in the hash a bit lives.
  • a dark square is a 0; a lit square is a 1.
  • amber = a bit that just flipped from your last change (the avalanche).
  • the gold frame is the target zone: in mining these squares must all be 0 to win.
◈ 09 · Consensus — the blockchain
Win the lottery, seal a block — then chain it to every block before it, and dare anyone to rewrite the past.

The ledger nobody can rewrite

Your bank balance is a row in one company's database, and correcting it is a customer-service call. A bitcoin balance is agreed on by roughly 20,000 independent computers, and changing it against the rules is not a phone call. It's an energy bill.

A blockchain is a list of blocks, and each block is stamped with the fingerprint of the block before it — the same 32-byte fingerprint from lens 05. That one trick welds the list in order: alter any past entry and every stamp after it breaks, in plain view of the whole world. And each of those 20,000 computers keeps its own copy of the list, accepting only the version backed by the most work. So to rewrite history you would have to out-compute the entire planet, live, for as long as the lie must hold. Touch the blocks below and break it yourself.

Act I

How money is kept today — and how Bitcoin flips it

Your bank's ledger is one master copy in a vault, edited by one company. Bitcoin's ledger is roughly 20,000 matching photocopies, one per node: an ordinary computer running the free Bitcoin program. Each node holds the full ledger and checks every rule on every payment it hears. No node is in charge. Truth is whatever the honest copies agree on.

The vault

banks · card networks · today
  • One master ledger, held privately by the institution.
  • They can edit, freeze, or reverse any entry.
  • You must trust them — and their security, and their solvency.
  • Open 9–5, borders apply, a single point of failure.
  • Your access can be revoked by one decision.

The network

bitcoin · ~20,000 nodes · always-on
  • Every node holds a full copy of the same ledger.
  • Entries are append-only — written in pen, new lines only, no erasing.
  • You trust math and a majority of work — not a vote, not any one party.
  • 24/7, borderless, no single point to seize or shut.
  • If you hold the key, no one can freeze you out.
Same job, an honest list of who owns what, solved two opposite ways. The bank centralises trust. Bitcoin replaces it with proof — proof anyone can check personally: a Raspberry Pi can run a full node and re-verify every transaction since 2009. Everything below is that proof, made touchable.
Act II

The unrewritable ledger

Here's a tiny chain of four blocks, each already sealed: its fingerprint starts with three zeros, exactly the proof-of-work from lens 08. Each block also carries the previous block's hash, so they're welded in order. Now tamper. Change any block's data — turn Bob's 2.0 into 20.0 — and watch every block after it turn red. You just rewrote history, and the whole chain shows it.

All four blocks are sealed and linked. Edit any data field to tamper with the past.
re-mining every block is the only way to repair a tamper
Why the cascade? Each hash is computed from the block's data plus the previous hash. Change block 2 and its hash changes. Block 3 was stamped with block 2's old hash, so block 3 breaks, which breaks block 4, and so on to the tip. A blockchain is a building where every floor is poured on the one below: a deep edit means re-pouring every floor above it, faster than the whole world keeps pouring new floors on top.
Act III

Why every miner must agree

Thousands of nodes hold this chain. When two versions exist, the rule is mechanical: follow the chain with the most accumulated work, the "heaviest" chain. Notice what "majority" means here. It's a majority of guessing work, not a vote of people, and the honest side is always extending the real chain. So your tampered chain isn't just broken — it's in a race it cannot win unless you personally out-hash the rest of the planet. Drag the attacker's share of the world's mining power:

30%
51% line
This is the famous "51% attack." Below half, the honest chain outruns you and your rewrite never becomes truth — the probability of catching up falls off a cliff the deeper your target sits. Above half, you could in theory. But renting that much hardware and power would cost far more than almost any theft is worth, and would torch the value of the very coin you stole. The system pays honesty better than cheating.

And underneath all of it sits one piece of math — the reason a lie is astronomically expensive to write but trivial to catch.

1 hash
Verifying a block
your phone, instantly
~10²³ hashes
Forging a block
the whole planet, ten minutes
SHA-256 has no shortcut: the only way to find a fingerprint with the required zeros is to guess and check, over and over. Finding one takes on the order of 10²³ tries; checking a proposed answer takes exactly one. That gap — impossibly hard to make, instant to verify — is what lets a billion strangers agree on the truth without trusting each other. It is the whole invention.
◆ go deeper · the cryptography
What actually stops me spending the same coin twice?
The "double-spend" problem is why digital money was impossible for decades — a file can be copied, so what stops you paying two people with the same coin? Bitcoin's answer is the ledger itself. Every spend points at a specific earlier receipt: an unspent output, or UTXO if you meet the term elsewhere. The network accepts each receipt once. Send two conflicting spends and miners will only ever bake one into a block. The other is rejected by every honest node. There's no central referee — the shared, append-only history is the referee.
What is "the math" behind a one-way function?
A hash like SHA-256 is built to behave like a random oracle: feed it any input and it returns 256 bits that are fully determined yet look like a coin-flipped scramble. Two properties make it a lock: easy: hash(x) → y (one pass, microseconds) hard: find x such that hash(x) starts with N zeros There is no algebra to invert it and no "warmer / colder" gradient to climb — the avalanche effect from lens 08 means one flipped input bit reshuffles about half the output bits. So the only known method is brute force. To hit N leading hex zeros you expect about 16N attempts; to check a claimed answer is a single hash. Difficulty is just the network dialling N up or down to keep blocks ~10 minutes apart.
How do prev-hashes actually weld the blocks together?
Each block's fingerprint is taken over its contents and the fingerprint of the block before it: hash(block N) = SHA256( data_N + hash(block N-1) + nonce_N ) Because hash(N) depends on hash(N-1), and hash(N+1) depends on hash(N), the fingerprints form an unbroken chain back to the very first block (the "genesis" block). Alter anything in block N and its hash changes, which invalidates the stamp inside N+1, which invalidates N+2… all the way to the tip. That's the cascade you triggered in Act II — tamper-evidence for free, from a single line of math.
How is this different from a bank's database?
A bank database is mutable and permissioned: rows can be changed, and a small set of admins are trusted to change them correctly. It's fast and convenient, but it rests entirely on trusting the institution — and one breach, order, or bankruptcy can rewrite or erase your balance. Bitcoin's ledger is append-only and permissionless: new lines in pen, no eraser, and anyone can verify the whole thing from scratch on hardware as small as a Raspberry Pi. You trade the bank's convenience and reversibility for censorship-resistance and finality. Different tools for different fears.
If it's all public, how is anything private?
The ledger shows addresses, not names — a payment reads "address A sent 0.5 to address B," never "Alice paid Bob." That's pseudonymity: every transaction is visible forever, but the link between an address and a human isn't written on the chain. It can often be inferred (exchanges, reused addresses, analysis), which is why privacy is an active field — but the base layer's transparency is a feature: it's exactly what lets anyone audit that no coins were forged and no ledger rule was broken.
◈ 10 · The network — the mempool
That chain guards the past. But every payment starts short of it, waiting in a crowd, bidding for a seat in the next block.

The waiting room

Stamps price the envelope's weight, never the cheque inside. Bitcoin fees work the same way: they price bytes, not value. And the queue below sorts itself by price per byte, live.

Bitcoin makes one block about every ten minutes, with room for roughly 4 million "weight units". That's lens 01's "1 million virtual bytes," just counted in finer units. Everyone waiting sits in the mempool, and miners fill each block highest fee-per-byte first. So it's a live auction for seats: surge pricing, except the algorithm is published. Below is the real mempool right now, and you can drop your own transaction in and watch where it lands.

connecting to the live network…

Drop your transaction in

Your fee is quoted in sat/vByte: satoshis per virtual byte of payment size. A satoshi is Bitcoin's smallest unit: 100,000,000 of them make one bitcoin. Set yours, and watch which block you board and how long you'd wait. This is the choice every wallet makes for you, every time you send.

20 sat/vByte
How to read the queue
  • each card is one upcoming block — one ~10-minute train, ~4M weight units of seats (4 units ≈ 1 virtual byte). The left-most is the next block.
  • colour = the fee tier paid inside it — grey cheap, teal normal, amber priority, red urgent. Fare classes on the same train.
  • the big number is that block's median fee (sat/vByte) — the middle payment's fee; below it, the fee range, transaction count, and the miner's fee reward.
  • the gold "you" tag shows the block your transaction would fall into at the fee you set.
This is the fee auction lens 01 promised: about 2,000–4,000 payments fit per block, one every ~10 minutes, so on busy days you're out-bidding everyone else for a seat. And every winning fee goes to the miner who seals the block. In April 2020, about $1.1 billion moved in one transaction for a fee under a dollar. When it's quiet, even 1 sat/vByte gets in: a few hundred satoshis, whatever you send.
◈ 11 · The protocol — difficulty retargeting
Those seats open every ten minutes — held to time by a clock with no clockmaker.

The ten-minute heartbeat

No one is in charge, yet a new block lands roughly every ten minutes: this year, last year, a decade ago. Miners flood in and vanish, hardware gets faster every season, and the puzzle is now more than 100 trillion times harder than in January 2009. Still ten minutes. How does a network with no conductor keep time?

The answer is a thermostat with no owner. More computing power would make blocks arrive faster. So every 2,016 blocks the network measures how fast it actually went and retunes the difficulty, dragging the pace back to ten minutes. Nobody decides it. Every machine computes the same setting from the same shared blocks, so the planet agrees without a meeting. The beat matters: it keeps settlement predictable, and the coin-minting schedule in the next lens counts on it. Play the thermostat, work the retarget sum, then watch the real pulse.

Act I

The thermostat with no owner

Block time depends on two things. The first is how much hashpower is searching: guesses per second, summed across every mining machine on Earth. The second is how hard the puzzle is set. Add miners and blocks come faster. Raise the difficulty and they slow down. Crank the hashpower and watch the pace shoot past the ten-minute mark. Then hit retarget and watch difficulty rise to chase it back to centre.

1.0×
This is negative feedback, the same idea as a thermostat or cruise control. Push the system one way and it automatically pushes back. The remarkable part is that no one runs it: each node computes the same adjustment from the same shared blocks. So the whole planet lands on the new difficulty without a meeting, a vote, or a boss.
Act II

The retarget, every 2016 blocks

Every 2,016 blocks (about two weeks, a window called the difficulty epoch) the network does one sum. Those blocks should have taken exactly 20,160 minutes (2,016 × 10). It compares that ideal to how long they really took and scales difficulty by the ratio. Slide the real average block time and watch the next difficulty jump compute itself.

9.0 min
The ratio is clamped: difficulty can rise at most or fall to ¼ in a single retarget. So no fluke fortnight can whipsaw the network. Notice the self-correction: run fast and difficulty goes up (harder, so you slow down); run slow and it comes down (easier, so you speed up). Always dragging the average back toward ten minutes.
Act III

The live pulse

Right now, the network is somewhere inside its current difficulty epoch, running a little fast or a little slow. The next retarget is already taking shape. This is the real heartbeat, straight from the chain: the countdown to the moment difficulty next changes.

reading the chain…
avg block time now
next difficulty change
blocks until retarget
through this epoch
The network is running slightly fast (difficulty about to rise) or slightly slow (about to fall). Over its whole life it has averaged about 9.6 minutes per block, a touch quick, because hashpower usually grows mid-epoch. That is why every halving so far has arrived weeks or months early. Within a couple of weeks the beat snaps back toward ten minutes — a clock that winds itself.
◆ go deeper · keeping time without a clock
Why ten minutes — why not one, or sixty?
It's a deliberate compromise. When a block is found it has to travel to every node on Earth before the next one starts. Otherwise two miners build competing blocks and the network briefly splits (an "orphan"). Too short an interval and blocks are found faster than they can spread: wasted work and constant forks. Too long and payments take forever to confirm. Ten minutes sits comfortably above global propagation time while still settling transactions within the hour. It's slow on purpose. The slowness is what keeps everyone agreeing on one history.
What actually is "hashrate"?
It's the number of guesses the whole network makes per second in the mining lottery. Each guess is one full SHA-256 hash, the same fingerprint function you met in the Merkle lens, checked to see if it clears the target. Today that figure is measured in exahashes: on the order of 10²⁰ guesses every second. That's more than the number of grains of sand on Earth, each second. Hashrate is the raw muscle behind the chain, and the thing the difficulty is forever measuring itself against. More muscle would mean faster blocks, so difficulty rises to absorb it and hold the beat.
Why retarget every 2016 blocks, not every block?
Stability. If difficulty lurched after every block, a few lucky or unlucky finds in a row would send it swinging wildly, and miners could game the noise. Averaging over 2016 blocks (~two weeks) smooths out the randomness so the adjustment reflects a real change in hashpower, not a statistical blip. It's the same idea as an average-speed camera zone: judge the window, not the instant, so a lucky streak doesn't read as a change of pace. The price is responsiveness: a sudden drop in miners isn't fixed until the window ends. That is exactly what the next question is about.
What if half the miners suddenly quit?
Blocks slow down: with half the hashpower, they'd arrive every ~20 minutes instead of ten. And they stay slow until the current 2016-block window finishes, which now takes longer to reach. When it does, the retarget sees the sluggish pace and cuts difficulty, and the beat returns to ten minutes. People sometimes fear a "death spiral" where slow blocks trap the chain forever, but the math doesn't allow it: slower blocks simply guarantee an easier next retarget. The system is self-healing; it just heals on a two-week clock.
How does the network measure time with no trusted clock?
Each block carries a timestamp set by the miner, and the retarget uses the gap between the first and last block of the window. No miner is trusted individually. The rules only accept a timestamp that is greater than the median of the last eleven blocks, and not more than two hours ahead of the network's rough time. Those bounds stop anyone from faking the elapsed time to swing difficulty in their favour. So "time" here isn't a wall clock; it's a loosely-agreed number the whole network polices together. That's good enough to keep a ten-minute beat across a planet with no shared clock.
One word, two meanings — so it never blurs. Bitcoin has two epochs. The difficulty epoch is 2,016 blocks (~2 weeks) — the heartbeat you just felt, retuning the puzzle. The halving epoch, or "era," is 210,000 blocks (~4 years) — the one that meters out new coins, and the one we turn to next.
◈ 12 · Monetary policy — the 21M cap
That same rhythm mints new coins — on a schedule that counts down to zero.

Twenty-one million. Never one more.

Walk toward a wall by covering half the remaining distance each step. You never arrive. Bitcoin's supply works the same way: each era mints half what the last one did, closing on a ceiling it can never cross: 21 million. A dollar's supply is set by a committee's decision and can grow at will. Here is where the countdown stands, live, right now.

Every currency before this one shared a flaw: whoever ran it could always make more, and eventually did. Bitcoin's answer is to write the entire issuance schedule into the code, forever. Issuance means the minting of new coins. Its monetary policy, the rules for how much money exists, is a formula, not a committee. New coins arrive only as the mining reward, that reward halves every four years, and the halves add up to a hard ceiling of 21 million. Watch the schedule, feel the halving, and see how little is left to mine.

the far futureThe very last satoshi — the hundred-millionth-of-a-coin unit you met pricing fees in the mempool — will be mined around the year 2140. After that the block reward is zero forever, and miners are paid entirely by transaction fees.
Act I

The schedule, carved in code

New bitcoin enters the world one block at a time, and the amount per block is not a policy anyone votes on. It's a formula. It starts at 50 BTC per block and is cut in half every 210,000 blocks. Each such stretch is a halving era, the four-year cousin of the difficulty epoch you just left. Drag through the decades and watch the curve rush up, then flatten hard against the ceiling. That's because most of the coins that will ever exist already do.

reading the chain…
2025
≈ era
3.125
BTC per block
19.69M
total mined
93.8%
of 21M
Look at the shape: it's nearly all uphill in the first two decades, then a long, flat crawl toward the ceiling it never quite touches. More than nine in ten bitcoin were mined in the first sixteen years. The scarcity isn't a promise about the future — it's mostly already happened.
Act II

Why the halves add up to exactly 21 million

Here is the wall from the top of the page, in numbers. The first era mints 10.5 million coins. The second mints half that, 5.25 million, and the third 2.625 million. Every era covers half the distance that remains. And a walk that only ever halves the gap can never arrive. Reveal the eras one by one and watch the running total climb toward a number it can never pass.

era 1 = 10.5M21,000,000 ceiling →
20.34M
This is a geometric series: 10.5M + 5.25M + 2.625M + … Halve a number again and again and the pieces sum to twice the first piece. And twice 10.5 million is 21 million. The ceiling isn't enforced by a rule that says "stop at 21M." It falls out of the halving itself, the way ½ + ¼ + ⅛ + … can only ever reach 1.
Act III

How little is left

Set against every dollar, peso, and pound, bitcoin's issuance is a closing door. All of them can be, and are, expanded by decision. Below is the live tally: how much has been mined, how little remains, and how slowly the last of it will trickle out over the next century.

bitcoin mined so far
left to ever mine
new BTC / day now
next halving
At the start, mining minted 7,200 new bitcoin a day. Today it's a fraction of that, and every four years it halves again. The first 20 million coins took about seventeen years to mine. The final million takes roughly 114 years more, ending with the last satoshi around 2140. A dollar's supply is a decision. Bitcoin's is a countdown. That is what "hard money" means.
◆ go deeper · the hardest money
Why 21 million — why that number?
It isn't a number anyone picked for its own sake. It's the output of two simpler dials: start the reward at 50 BTC and halve it every 210,000 blocks. Do the arithmetic and the total is forced: 210,000 blocks × (50 + 25 + 12.5 + 6.25 + …) BTC = 210,000 × 100 = 21,000,000 The infinite halving series in the brackets sums to exactly 100, so the ceiling is 21 million. Set those two dials differently and you'd get a different cap. But once they were fixed in 2009, the final figure was already decided, down to the last satoshi.
What happens when the last bitcoin is mined?
Around 2140, the block reward (halved 33 times) finally rounds to zero, and issuance stops for good. Mining doesn't stop, though: miners keep sealing blocks and defending the chain, now paid entirely by the transaction fees users attach to their payments. The system was designed to hand the baton from new-coin subsidy to fees gradually over more than a century. So by the time the printing ends, a fee market has long since grown up to keep miners in business.
Why does a halving happen every ~4 years?
Two numbers multiply into it. Blocks are mined about every 10 minutes (the difficulty adjusts to hold that pace), and the reward halves every 210,000 blocks. So: 210,000 × 10 minutes ≈ 4 years. It's not a calendar date: it's a block count, which is why the exact day drifts. So far it has always drifted early: blocks average about 9.6 minutes over Bitcoin's life, so every halving has landed weeks or months ahead of its four-year anniversary. Each one roughly halves the rate of new supply overnight, which is why halvings are watched so closely.
Could the 21 million cap ever be raised?
Only if nearly everyone agreed to abandon it. And they won't, because the cap is the entire point. The limit isn't guarded by one authority you could lobby. It is checked independently by every full node on Earth. Each node validates that every block creates no more than the schedule allows, and rejects any block that tries to mint extra. This has been tested once, for real: on August 15, 2010, an overflow bug let a single transaction mint 184 billion BTC. Within hours a corrected version of the software was out, and the network abandoned the chain carrying those coins — every one of them erased. To lift the cap today you'd have to convince every holder to run new software that dilutes their own money. The rule is enforced not by trust, but by millions of copies all refusing to bend — and in 2010, they didn't.
What makes it "the hardest money"?
Economists measure hardness by stock-to-flow: how big the existing pile is versus how much new supply arrives each year. Gold is prized because its flow is tiny: you can't easily dig up much more. Bitcoin is a mine whose total contents were published on day one. Gold is scarce because digging is hard. This is scarce because the bottom of the mine is written down. Every halving doubles the stock-to-flow, and no discovery can breach the ceiling. A currency that can be printed has a flow set by whoever holds the press. Bitcoin's flow shrinks on a fixed schedule toward zero. That combination — predictable, diminishing, and finally capped — is what "hard" means, taken to its logical end.
◈ 13 · Signal — the live feed
The schedule is settled to the last satoshi. And the world answers back — minute by minute.

Bitcoin, right now

Twelve lenses of rules that hold still. Now, everything that moves: live headlines shaping sentiment (the market's mood).

loading the latest…
The coloured chip is the source; each source keeps its own colour so you can spot who's saying what at a glance. Time is how long ago it broke. Tap any headline to read the full story at the source.
Bitcoin has no CEO, no headquarters, no press office, so every headline below is the world reacting to rules that will not react back. Aggregated live from the public feeds of CoinDesk, Cointelegraph and Bitcoin Magazine. In production this can run through our own cached endpoint, so a single source being down never breaks the feed.