The Bitcoin whitepaper explained – section by section
Satoshi Nakamoto’s nine pages from 2008 in plain words: all twelve sections explained clearly, with links to the original and to translations.
In short~32 sec
- 01The whitepaper ‘Bitcoin: A Peer-to-Peer Electronic Cash System’ was published on 31 October 2008: nine pages, twelve sections, eight references.
- 02Core idea: a peer-to-peer network prevents double spending by putting transactions into a fixed order with computing work (proof of work) – no bank in between.
- 03The chain with the most computing work counts. Playing by the rules is meant to pay off more for miners than cheating.
- 04Not in the whitepaper: the 21 million, the halving and the word ‘blockchain’.
- 05The original and translations into many languages are freely available on bitcoin.org.
Good to read firstWhat is Bitcoin?
Bitcoin began with a text: nine pages by Satoshi NakamotoGlossarySatoshi NakamotoPseudonym of the person or group who invented Bitcoin. Satoshi published the whitepaper in 2008, launched the network in 2009 and withdrew in 2011. Who is behind the name remains unknown to this day.In the glossary → on how money can work on the internet without a bank. This article goes through the whitepaperGlossaryWhitepaper (Bitcoin whitepaper)The nine-page founding document in which Satoshi Nakamoto introduced Bitcoin on 31 October 2008. It explains how payments can work without a bank and how double spending is prevented.In the glossary → section by section.
Reading the original
Satoshi sent the link to the paper to a cryptography mailing list on 31 October 2008, subject line ‘Bitcoin P2P e-cash paper’.[5]
- Original (English): bitcoin.org/bitcoin.pdf[1]
- Translations: overview on bitcoin.org, including a German PDF by Daniel Deckner[3],[2]
- In your browser: HTML version from the Satoshi Nakamoto Institute[4]
The reference list names eight sources, including Wei Dai’s ‘b-money’ (1998), Adam Back’s ‘Hashcash’ (2002) and papers on digital timestamps and Merkle trees.[1] What was new was the combination: timestamps without a trusted party, secured by computing work.
The problem: trust and double spending
Abstract
The paper promises electronic cash that works purely peer-to-peerGlossaryPeer-to-peer (P2P)‘Between equals’: participants exchange data or money directly with one another, without a central intermediary. In Bitcoin, nodes pass transactions and blocks directly to each other.On the learning path: Stage 1 · Step 3 – How does Bitcoin work? →In the glossary →: payments directly between two parties, without a financial institution. Digital signatures alone don’t stop someone from spending the same money twice. That is the job of a network that timestamps transactions and writes them into a chain of computing work.[1]
1. Introduction
Online commerce relies almost entirely on financial institutions as trusted third parties. Because they mediate disputes, payments are never completely final. That makes them more expensive, makes very small payments impractical and forces merchants to ask customers for more information. Satoshi’s alternative rests on cryptographic proof instead of trust and is secure as long as honest participants control more computing power than any group of attackers.[1]
2. Transactions
An electronic coin is defined as a chain of digital signatures: whoever pays signs a hash of the previous transaction and the recipient’s public key. This lets anyone check the chain of ownership – but not whether the payer has already spent the same coin. Satoshi’s solution without a central authority: all transactions are made public, all participants agree on one order, and only the earliest spend counts.[1]
Quick check
Which problem does the whitepaper mainly solve?
Signatures alone don’t prevent double spending. The peer-to-peer network sets the order with timestamps and proof of work – without a bank.
The solution: timestamps and computing work
3. Timestamp server
A timestamp server takes a hash of a block of data and publishes it. Each timestamp includes the previous one, forming a chain in which every new entry reinforces the older ones.[1] That is the idea behind today’s ‘blockchain’.
4. Proof of work
To make this work without a central authority, Satoshi uses proof of workGlossaryProof of workThe method by which miners prove that they have done real computing work for a new block. It lets the network agree on the valid chain without a central authority, and makes rewriting old blocks extremely expensive.On the learning path: Stage 1 · Step 3 – How does Bitcoin work? →In the glossary → modelled on Hashcash: the task is to find a block whose hashGlossaryHash (hash value)A fixed-length digital fingerprint that a hash function calculates from any data. Even the tiniest change produces a completely different value, and the original data can’t be worked out from the hash.On the learning path: Stage 1 · Step 3 – How does Bitcoin work? →In the glossary → (with SHA-256GlossarySHA-256A standardised cryptographic hash function that calculates a 256-bit fingerprint from any data. Bitcoin uses it for mining and identifiers – and even hashes the block header twice in a row.On the learning path: Stage 1 · Step 3 – How does Bitcoin work? →In the glossary →, for example) begins with a certain number of zero bits. To get there, a number in the block, the nonceGlossaryNonceA 4-byte number in the block header that miners change over and over during proof of work until the hash of the block header is less than or equal to the target. Each new value is a new attempt.On the learning path: Stage 1 · Step 3 – How does Bitcoin work? →In the glossary →, is changed until it fits. Anyone who wants to change a block later has to redo this work – and that of all later blocks.[1]
Proof of work also settles who decides when there is disagreement: not one vote per IP address (easy to game with many addresses), but one vote per unit of computing power (‘one-CPU-one-vote’). The longest chain counts, meaning the one with the most computing work. The difficulty adjusts so that the same number of blocks is created per hour on average.[1]
In the hash lab, your browser counts the nonce up until the SHA-256 hash starts with enough zeros – section 4 in miniature. Mining & proof of work explains how mining works today.
SHA-256
…
- Nonce
- 0
- Attempts
- 0
- hashes/s
- –
Change a single character – the hash looks completely different. When mining, your browser appends a number (nonce) and counts up until the hash starts with enough zeros. Each extra zero means 16× more attempts on average. Simplified: Bitcoin hashes the block header twice with SHA-256 and requires a value below a target.
5. Network
The network runs in six steps:[1]
- New transactions are broadcast to all nodesGlossaryNodeA computer that runs Bitcoin software and exchanges transactions and blocks with other nodes. Together, the nodes form the Bitcoin network; full nodes check every rule themselves.On the learning path: Stage 1 · Step 3 – How does Bitcoin work? →In the glossary →.
- Each node collects them into a block.
- Each node works on finding the proof of work for its block.
- Whoever finds it broadcasts the block to everyone.
- The others accept it only if all transactions in it are valid and not already spent.
- They show their acceptance by building the next block on top of it.
If two blocks arrive at the same time, each node keeps working on the one it received first and saves the other. As soon as one branch is longer, everyone switches to it.[1]
Incentives and efficiency
6. Incentive
The first transaction in each block creates new coins for whoever found the block. This brings coins into circulation without a central issuer – like gold miners adding gold to circulation, except that the resources spent are computing time and electricity. Transaction fees come on top. Once a predetermined number of coins is in circulation, the incentive can shift entirely to fees, with no inflation at all.[1]
The incentive can also help keep participants honest: anyone with more computing power than all honest nodes combined should earn more from new coins than from fraud that undermines the system and the value of their own holdings.[1]
7. Reclaiming disk space
A block’s transactions are hashed in a Merkle tree; only its root goes into the block hash. Old, spent transactions can therefore be deleted without breaking the chain. A block header is about 80 bytes – with one block every ten minutes, that is around 4.2 MB per year. Given the 2 GB of RAM typical of computers in 2008, Satoshi considered this no problem.[1]
8. Simplified payment verification
Anyone who stores only the block headers of the longest chain can use a ‘Merkle branch’ to check whether a transaction is in a block – without running a full node. This is reliable as long as honest nodes control the network, but more vulnerable if an attacker overpowers it. Businesses that receive frequent payments would therefore probably still want to run their own nodes.[1] Why this still holds today: Nodes & decentralisation.
Splitting value and privacy
9. Combining and splitting value
So that each coin doesn’t have to be sent individually, transactions have multiple inputs and outputs: usually one larger input or several smaller ones, and at most two outputs – the payment and, if needed, the change back to the payer.[1] The principle still applies today – more in Transactions & fees.
10. Privacy
Banks protect privacy by withholding information; Bitcoin has to make all transactions public. Privacy comes from public keys not being tied to any person – as on a stock exchange, where the time and size of trades are visible but not the parties. Satoshi recommends a new key pair for each transaction and warns that transactions with several inputs reveal that those inputs belong to the same owner.[1] More in Privacy with Bitcoin.
Calculations and conclusion
11. Calculations
An attacker can neither create coins out of thin air nor take other people’s money – honest nodes reject such blocks. All the attacker can try is to take back one of their own payments by building a parallel chain that overtakes the honest one. Satoshi models this as a race: the chance of success falls exponentially with every block the attacker has to catch up.[1]
From his table: with 10% of the computing power, the attacker’s chance drops below 0.1% after five blocks; with 30%, only after 24 blocks.[1] That is why people wait for several confirmationsGlossaryConfirmationA transaction has one confirmation as soon as it is in a block; each further block adds one. With every confirmation, it becomes harder to displace the payment after the fact.On the learning path: Stage 5 · Step 4 – First withdrawal →In the glossary → before accepting larger amounts.
12. Conclusion
The result: a payment system that works without relying on trust. The network is robust precisely because it is so simple. Nodes can leave and rejoin, and then accept the chain with the most work. They vote with their computing power – building on valid blocks and refusing to work on invalid ones. That is enough to enforce all the rules needed.[1]
What isn’t in the whitepaper
Some things that belong to Bitcoin today were only set in the program code or added later:
| Topic | In the whitepaper (2008) | Today |
|---|---|---|
| Money supply | ‘predetermined number of coins’, no figure[1] | just under 21 million BTC, set by the issuance schedule in the code[6]; 20,093,887 BTC issued so far |
| Halving | not mentioned | block reward halves every 210,000 blocks, currently 3.125 BTC per block[6] |
| The word ‘blockchain’ | doesn’t appear – only ‘chain’[1] | common term |
| Difficulty | moving average targeting a number of blocks per hour[1] | adjusted every 2,016 blocks, roughly every two weeks[7] |
| Confirmations | probability depending on the attacker’s strength[1] | rule of thumb: at least six confirmations for large amounts[8] |
| Storage | 4.2 MB per year, block headers only[1] | block headers still 80 bytes each[9]; the full blockchain with all transactions around 770 GB (as of September 2026)[10] |
More: The halving & the 21 million and – on how rules get changed – Forks & controversies.
Quick check
Is the number 21 million in the whitepaper?
Section 6 only mentions a ‘predetermined number of coins’. The cap follows from the code: a 50 BTC starting reward, halved every 210,000 blocks – just under 21 million BTC in total.
What’s next?
Frequently asked questions
Who wrote the Bitcoin whitepaper?
It is signed ‘Satoshi Nakamoto’. Who is behind the pseudonym has never been proven. For Bitcoin it doesn’t matter: the rules are public and anyone can check them.
Do I need to have read the whitepaper to use Bitcoin?
No. But if you want to understand the basic idea first-hand, it is a short text of nine pages.
Is it available in other languages?
Yes. bitcoin.org lists translations into many languages, including a German PDF by Daniel Deckner. The links are in the article.
Is everything in the whitepaper still accurate?
The basic principles still apply. Details have evolved, such as the difficulty adjustment every 2,016 blocks. The 21 million and the halving aren’t in the whitepaper but in the program code.
Your knowledge blockchain
Every article you complete becomes a block in your personal chain – stored only in your browser.
Sources10 sources · 6 publishers
The superscript numbers in the text refer to these sources.
- Bitcoin: A Peer-to-Peer Electronic Cash System – Satoshi Nakamoto, 31.10.2008 (accessed 28/09/2026)
- Bitcoin: Ein elektronisches Peer-to-Peer-Cash-System (German translation, PDF) – bitcoin.org (translation: Daniel Deckner) (accessed 28/09/2026)
- Bitcoin whitepaper – overview of translations – bitcoin.org (accessed 28/09/2026)
- Bitcoin: A Peer-to-Peer Electronic Cash System (HTML version) – Satoshi Nakamoto Institute (accessed 28/09/2026)
- Bitcoin P2P e-cash paper (Cryptography mailing list) – Satoshi Nakamoto via metzdowd.com, 31.10.2008 (accessed 28/09/2026)
- Bitcoin Core source code: validation.cpp (GetBlockSubsidy) – Bitcoin Core (accessed 28/09/2026)
- Bitcoin Developer Guide: Block Chain – Bitcoin Project (accessed 28/09/2026)
- Bitcoin Developer Guide: Payment Processing – Bitcoin Project (accessed 28/09/2026)
- Bitcoin Developer Reference: Block Chain (Block Headers) – Bitcoin Project (accessed 28/09/2026)
- Blockchain.com Charts: Blockchain Size – Blockchain.com, 27.09.2026 (accessed 28/09/2026)
This article is for education only and is not investment, tax or legal advice.