{"@context":"https:\/\/schema.org","@type":"Periodical","version":"1.0","generatedAt":"2026-07-26T12:43:37+00:00","magazine":{"id":"7b85566a8c0c3110d8b2e7131e5149cd68ad51fec58dd400bf35285b66fba872","slug":"newsroom-magazine-on-imwald-by-laeserin-category-economy","title":"Economy","summary":"","image":null,"language":null,"pubkey":"dd664d5e4016433a8cd69f005ae1480804351789b59de5af06276de65633d319","createdAt":"2026-06-15T05:42:28+00:00","url":"https:\/\/www.decentnewsroom.com\/mag\/newsroom-magazine-on-imwald-by-laeserin-category-economy"},"categories":[{"slug":"newsroom-magazine-on-imwald-by-laeserin-category-bitcoin","title":"Bitcoin","summary":"","image":null,"url":"https:\/\/www.decentnewsroom.com\/mag\/newsroom-magazine-on-imwald-by-laeserin-category-economy\/cat\/newsroom-magazine-on-imwald-by-laeserin-category-bitcoin","articleCount":4,"articles":[{"title":"It Began at 623.216","slug":"it-began-at-623216","summary":"Why it is philosophically significant, that Bitcoin is a clock.","content":"I read a lot of economic and technical literature, leading up to my initial Bitcoin purchase, in spring of 2020.\n\nI read [The Bitcoin Standard](https:\/\/saifedean.com\/tbs), by the brilliant and principled Saifedean Ammous. I listened to Nick Szabo\u0027s detailed treatise, [Shelling Out: the Origins of Money](https:\/\/nakamotoinstitute.org\/library\/shelling-out\/), while cleaning my windows. I allowed myself to get caught up in an endless string of podcasts, by the earnest and ever-charming [Marc Friedrich](https:\/\/www.marc-friedrich.de\/).\n\nBut the thing that shook me to the core, and made me a Real Bitcoiner\u2122, was something much more literary and, ironically, anachronistic. Namely, the _Bitcoin is Time_ article, from nostr:npub1dergggklka99wwrs92yz8wdjs952h2ux2ha2ed598ngwu9w7a6fsh9xzpc\n\nnostr:naddr1qvzqqqr4gupzqmjxss3dld622uu8q25gywum9qtg4w4cv4064jmg20xsac2aam5nqyf8wumn8ghj7mn0wd68yv339e3k7mf0qyghwumn8ghj7mn0wd68ytnhd9hx2tcqpa3xjarrda5kuttfwvkhg6tdv5dlu0hd\n\nYou see, I am Catholic.\n\nNow, I am not just a little bit Catholic. I am not Catholic to make myself feel better, look better, or be more popular. I am not _comfortably and acceptably Catholic_. I\u0027m irritatingly Catholic. Nervingly Catholic. Autistically Catholic. Incorrigably Catholic. Cringingly Catholic.\n\nAnd what all cringingly Catholic people care about is _time_. Everything in the Catholic Church revolves around marking time. What day, in the liturgical year, is it? Is this Vespers or can we Compline? Does this Mass count for tomorrow? Are you after baptism, but before confirmation? \n\nThe church bells ring the _Angelus_ and the New Years\u0027 Day is dedicated to the Mother of our God. Christmas, Easter, and Pentecost allow us to celebrate the Church\u0027s major milestones, with all of the in-between pit stops on our pilgrimage through the year. We skip meat on Fridays and catch up with the Sunday roast.\n\nWe head out at 4 am, to march to our distant Mass at 4 pm. Nearly 50 km by foot. Preventing ourselves from melting into a puddle on the pavement, by counting our path up the hills with rounds of the rosary... 4 more Hail Mary\u0027s and an Our Father to the pinnacle. Don\u0027t give up! 3 more Hail Mary\u0027s...\n\nWhy this obsession with time?\n\nBecause marking the passage of time is something that marks us as humans. It is the lower animals, the brutes, and the outcasts who fail to mark their time on Earth. Who simply live into every hour of every day, as if it were interchangeable with every other. Like zombies. Like the lost, cursed to wander in the desert. As if there were no progression, no direction, no movement. It is both a Biblical curse and a sign of societal degeneracy to _fail to mark the time_.\n\nBecause our God is a god that marks the time.\n\nHe guards the time so jealousy, that He has set an entire \u2150 of our lives aside, for us to simply sit and contemplate His glory. A \u2150 of every week. Forever. And how do we know that we have reached the seventh day? By counting the days. And how do we count the days? By counting the hours, of course.\n\nnostr:naddr1qvzqqqr4typzq0s66re6t57pyfzakaug23ky8t0rm97xuprvt98kq97ddn2pv35sqyvhwumn8ghj7enjv4jkccte9eek7anzd96zu6r0wd6qzxmhwden5te0w35x2cmfw3skgetv9ehx7um5wgcjucm0d5q35amnwvaz7tm5dpjkvmmjv4ehgtnwdaehgu339e3k7mgpzpmhxue69uhkummnw3ezumrpdejqzyrhwden5te0dehhxarj9emkjmn9qythwumn8ghj7mn0wd68ytnndamxy6t59e5x7um5qyghwumn8ghj7mn0wd68yv339e3k7mgqgp3xjcnvv5kkgmm4v9uj6ungv45k6uedwejhyumfdahz6mm5946xsefdvf4j6etcdaj82uedv4ux7er4wvkkx6pdxgcz6uedxgcz6vfshvs93m\n\nClocks, in other words, make humans more human. We have a beginning. We continue on from there, until we reach our earthly End. Our existence is linear. Our focus is forward, always forward, progressing inexorably.\n\nThat Bitcoin, itself, is a clock... That Bitcoin is a _universal_ clock... That *Bitcoin starts at the beginning, goes on until the end, and then stops*, like a clock would... was confirmation for me, that Bitcoin was money designed to serve humanity, rather than humanity being bent to serve the money.\n\nBecause what is more human than keeping track of time?\n\nNothing. Nothing is more human, than that.","image":"https:\/\/bitcoinbazar.fr\/cdn\/shop\/files\/Screenshot_from_2024-09-04_18-29-09.png","pubkey":"dd664d5e4016433a8cd69f005ae1480804351789b59de5af06276de65633d319","kind":30023,"createdAt":"2026-01-01T20:19:32+00:00","publishedAt":null,"topics":["bitcoin","catholicism","christian"],"url":"https:\/\/www.decentnewsroom.com\/mag\/newsroom-magazine-on-imwald-by-laeserin-category-economy\/cat\/newsroom-magazine-on-imwald-by-laeserin-category-bitcoin\/d\/it-began-at-623216"},{"title":"Bitcoin Is Time","slug":"bitcoin-is-time","summary":"Keeping track of things in the informational realm requires keeping track of time.","content":"\u003E One luminary clock against the sky   \n\u003E Proclaimed the time was neither wrong nor right.\n\u003E\n\u003E \u2014Robert Frost, *Acquainted with the Night* (1928)\n\n\u003E Time is still the great mystery to us. It is no more than a\u00a0concept;\n\u003E we don\u0027t know if it even exists...\n\u003E\n\u003E \u2014Clifford D. Simak, *Shake\u00adspeare\u0027s Planet* (1976)\n\nTime is money, or so the saying goes. It follows that money is also\ntime: a\u00a0repre\u00adsen\u00adta\u00adtion of the collec\u00adtive economic energy stored by\nhumanity. However, the link between time and money is more intri\u00adcate\nthan it might seem at first. If money requires no time to create, it\ndoesn\u0027t work as money very well, or not for long. More profoundly, as we\nshall see, keeping track of things in the infor\u00adma\u00adtional realm always\nimplies keeping track of time.\n\nAs soon as money goes digital, we have to agree on a\u00a0*defin\u00adi\u00adtion of\ntime*, and herein lies the whole problem. You might think telling the\ntime is as easy as glancing at whatever clock is nearby, and you would\nbe right when it comes to everyday tasks. But when it comes to\nsynchro\u00adnizing the state of a\u00a0global, adver\u00adsarial, distrib\u00aduted\nnetwork, telling the time becomes an almost intractable problem. How do\nyou tell the time if clocks can\u0027t be trusted? How do you create the\nconcept of a\u00a0singular time if your system spans the galaxy? How do you\nmeasure time in a\u00a0timeless realm? And what is time anyway?\u00a0\n\nTo answer these questions, we will have to take a\u00a0closer look at the\nconcept of time itself and how Bitcoin makes up its own time: block\ntime\u2009\u2014\u2009more commonly known as *block height*. We will explore why the\nproblem of timekeeping is intimately related to keeping records, why\nthere is no absolute time in a\u00a0decen\u00adtral\u00adized system, and how Bitcoin\nuses causality and unpre\u00addictability to build its own sense of now.\u00a0\n\nTimekeeping devices have trans\u00adformed civiliza\u00adtions more than once. As\nLewis Mumford pointed out in 1934: \u0022The clock, not the steam-engine, is\nthe key-machine of the modern indus\u00adtrial age.\u0022 Today, it is again\na\u00a0timekeeping device that is trans\u00adforming our civiliza\u00adtion: a\u00a0clock,\nnot computers, is the true key-machine of the modern infor\u00adma\u00adtional\nage. And this clock is Bitcoin.\n\n## Keeping Track of Things\n\n\u003E Let the child learn to count things, thus getting the notion of\n\u003E number. These things are, for the purpose of counting, consid\u00adered\n\u003E alike, and they may be single objects or groups.\n\u003E\n\u003E \u2014David Eugene Smith, *The Teaching of Elemen\u00adtary Mathe\u00admatics* (1900)\n\nVery broadly speaking, there are two ways to keep track of things:\nphysical tokens and ledgers. You can either use real-world artifacts\ndirectly, e.g., give someone a\u00a0sea shell, a\u00a0coin, or some other tangible\n*thing*, or you can repli\u00adcate the state of the world by writing down\nwhat happened on a\u00a0piece of paper.\u00a0\n\nImagine you are a\u00a0shepherd and want to make sure that your whole flock\nreturned home. You can put a\u00a0collar on each sheep, and as soon as\na\u00a0sheep returns home, you simply remove the collar and hang it up in\nyour shed. If you have one hanger for every collar, you will know that\nevery sheep returned safely as soon as all hangers are filled. Of\ncourse, you can also count them and keep a\u00a0list. However, you will have\nto make sure to create a\u00a0new list every time you start counting, and you\nwill also have to make sure not to count a\u00a0single sheep twice (or not at\nall).\n\nMoney is essen\u00adtially a\u00a0tool to keep track of who owes what to whom.\nBroadly speaking, every\u00adthing we have used as money up to now falls into\ntwo categories: *physical* artifacts and *infor\u00adma\u00adtional* lists. Or, to\nuse more common parlance: tokens and ledgers.\n\n![](https:\/\/dergigi.com\/assets\/images\/bitcoin\/2021-01-14-bitcoin-is-time\/ledger-token.jpg)\n\nIt is impor\u00adtant to realize the inherent differ\u00adence of these\ncategories, so let me point it out explic\u00aditly: The first\nmethod\u2009\u2014\u2009a\u00a0physical token\u2009\u2014\u2009*directly* repre\u00adsents the state of\nthings. The second one\u2009\u2014\u2009a\u00a0ledger\u2009\u2014\u2009*indirectly* reflects the state\nof things. Each comes with advan\u00adtages and disad\u00advan\u00adtages. For example,\ntokens are physical and distrib\u00aduted; ledgers are infor\u00adma\u00adtional and\ncentral\u00adized. Tokens are inher\u00adently trust\u00adless; ledgers are not.\n\nIn the digital realm\u2009\u2014\u2009no matter how intensely marketing gurus try to\nconvince you of the opposite\u2009\u2014\u2009we can only use ledgers. It is an\n*infor\u00adma\u00adtional* realm, not a\u00a0physical one. Even if you call a\u00a0certain\nkind of infor\u00adma\u00adtion a \u0022token,\u0022 it is still a\u00a0malleable piece of\ninfor\u00adma\u00adtion, written down on a\u00a0hard drive or some other medium that\ncan hold infor\u00adma\u00adtion, effec\u00adtively rendering it an infor\u00adma\u00adtional\nrecord.\n\nThe ledger-like nature of all digital infor\u00adma\u00adtion is the root cause of\nthe double-spend problem. Infor\u00adma\u00adtion never repre\u00adsents the state of\nthe world *directly*. Further, the movement of infor\u00adma\u00adtion implies\ncopying. Infor\u00adma\u00adtion exists in one place, and to \u0022move\u0022 it, you have\nto copy it to another place and erase it at its origin. This problem\ndoesn\u0027t exist in the physical realm. In the physical realm, we can\nactually move things from A\u00a0to B. The infor\u00adma\u00adtional realm doesn\u0027t have\nthis property. If you want to \u0022move\u0022 infor\u00adma\u00adtion from list A\u00a0to list\nB, you have to copy it from A\u00a0to B. There is no other way.\n\nAnother way to think about it is in terms of unique\u00adness. Physical\ntokens are unique compos\u00adites of atoms whose assembly is not easily\nreplic\u00adable. Pure infor\u00adma\u00adtion does not have this property. If you can\nread the infor\u00adma\u00adtion, you can also copy it perfectly. Practi\u00adcally\nspeaking, it follows that physical tokens are unique, and digital tokens\nare not. I\u00a0would even argue that \u0022digital token\u0022 is a\u00a0misnomer. A\u00a0token\nmight repre\u00adsent secret infor\u00adma\u00adtion, but it will never repre\u00adsent\nunique, singular, uncopy\u00adable infor\u00adma\u00adtion.\n\nThis differ\u00adence in proper\u00adties shows that there really is no way to\n\u0022hand over\u0022 infor\u00adma\u00adtion. It is impos\u00adsible to pass on a\u00a0digital token\nlike you would pass on a\u00a0physical one since you can never be sure if the\noriginal owner destroyed the infor\u00adma\u00adtion on his end. Digital tokens,\nlike all infor\u00adma\u00adtion, can only be spread, like an idea.\n\n\u003E ... if you have an apple and I\u00a0have an apple, and we swap\n\u003E apples\u2009\u2014\u2009we each end up with only one apple. But if you and I\u00a0have\n\u003E an idea and we swap ideas\u2009\u2014\u2009we each end up with two ideas.\n\u003E\n\u003E \u2014Charles F. Brannan (1949)\n\nPhysical tokens\u2009\u2014\u2009what we call physical bearer assets, or\n\u0022cash\u0022\u2009\u2014\u2009are free from this dilemma. In the real world, if you hand me\na\u00a0coin, your coin is gone. There is no magical dupli\u00adca\u00adtion of the\ncoin, and the only way to give it to me is to physi\u00adcally hand it over.\nThe laws of physics do not allow you to double-spend it.\n\nWhile double-spending does exist in the non-digital realm\u2009\u2014\u2009George\nParker, a\u00a0con artist who famously \u0022double-spent\u0022 the Brooklyn Bridge and\nother landmarks comes to mind\u2009\u2014\u2009it requires elabo\u00adrate decep\u00adtion and\ngullible buyers. Not so in the digital realm.\u00a0\n\nIn the digital realm, because we are always dealing with\n*infor\u00adma\u00adtion,* double-spending is an *inherent* problem. As everyone\nwho ever copied a\u00a0file or used copy-and-paste knows, infor\u00adma\u00adtion is\nsomething that you can copy *perfectly*, and it is not bound to the\nmedium that hosts it. If you have a\u00a0digital photo\u00adgraph, for example,\nyou can copy it a\u00a0million times, store some copies on a\u00a0USB stick, and\nsend it to thousands of different people. Perfect copies are possible\nbecause infor\u00adma\u00adtion allows for flawless error correc\u00adtion, which\nelimi\u00adnates degra\u00adda\u00adtion. And to top things off, there is virtu\u00adally no\ncost to dupli\u00adca\u00adtion and no way to tell what the original was.\n\nAgain: when it comes to infor\u00adma\u00adtion, copying is all there is. There\nsimply is no way to *move* digital infor\u00adma\u00adtion from A\u00a0to B.\nInfor\u00adma\u00adtion is always *copied* from A\u00a0to B, and if the copying process\nwas successful, the original copy of A\u00a0is deleted. This is why the\ndouble-spending problem is so tricky. Absent of a\u00a0central authority,\nthere is no way to move *anything* from A\u00a0to B\u00a0in a\u00a0trust\u00adless manner.\nYou always have to trust that the original will be deleted. A\u00a0natural\nside-effect is that, when it comes to digital infor\u00adma\u00adtion, it is\n*impos\u00adsible* to tell how many copies are in existence and where these\ncopies might be.\n\nBecause of this, using digital \u0022tokens\u0022 as money can not and will never\nwork. Since tokens derive their relia\u00adbility from being hard to\nrepro\u00adduce as a\u00a0result of their unique physical construc\u00adtion, this\nadvan\u00adtage disap\u00adpears in the digital realm. In the digital realm,\ntokens cannot be trusted. As a\u00a0result of the nature of infor\u00adma\u00adtion\u0027s\nintrinsic proper\u00adties, the only viable format for digital money is not\na\u00a0token but a\u00a0ledger\u2009\u2014\u2009which brings us to the problem of time.\n\n## Tokens Are Timeless, Ledgers Are Not\n\n\u003E For the things seen are tempo\u00adrary, but the things unseen are\n\u003E everlasting.\n\u003E\n\u003E \u2014Paul of Tarsus, *Corinthians* 4:18b\n\nWhen it comes to physical tokens, the time of a\u00a0trans\u00adac\u00adtion does not\nmatter. You either have the coins in your pocket, or you don\u0027t; you can\neither spend them, or you can\u0027t. The simple act of posses\u00adsion is the\nonly prereq\u00adui\u00adsite for spending. The laws of nature take care of the\nrest. In that sense, physical tokens are trust\u00adless and timeless.\n\nWhen it comes to ledgers, physical posses\u00adsion falls to the wayside.\nWhoever is in control of the ledger needs to make sure that things are\n*in order*. What is other\u00adwise given by physical laws, namely that you\ncan\u0027t spend money that you don\u0027t have and you can\u0027t spend money that you\nhave already spent previ\u00adously, has to be enforced by man-made rules. It\nis these rules that govern the orderly opera\u00adtion and mainte\u00adnance of\na\u00a0ledger, not physical laws.\u00a0\n\nMoving from physical laws to man-made rules is the crux of the matter.\nMan-made rules can be bent and broken, physical laws not so much. For\nexample, you can\u0027t simply \u0022make up\u0022 a\u00a0physical gold coin. You have to\ndig it out of the ground. You can, however, absolutely make up a\u00a0gold\ncoin on paper. To do this, you simply add an entry to the ledger and\ngive yourself a\u00a0couple of coins. Or, in the case of central banks,\nsimply add a\u00a0couple trillion with a\u00a0few computer keystrokes. (Fancy\nfinan\u00adcial people call this \u0022Rehypoth\u00ade\u00adca\u00adtion,\u0022 \u0022Fractional Reserve\nBanking,\u0022 or \u0022Quanti\u00adta\u00adtive Easing\u0022\u2009\u2014\u2009but don\u0027t be fooled, it\u0027s all\nthe same: making up money.)\n\nTo keep ledgers and those who manip\u00adu\u00adlate them honest, regular,\nindepen\u00addent audits are required. The ability to account for every\nsingle entry in a\u00a0ledger is not a\u00a0luxury. Auditors need to be able to go\nover the books\u2009\u2014\u2009backward in time\u2009\u2014\u2009to keep ledgers honest and\nfunctioning. Without reliable timestamps, verifying the internal\nconsis\u00adtency of a\u00a0ledger is impos\u00adsible. A\u00a0mecha\u00adnism to estab\u00adlish an\nunambiguous order is essen\u00adtial.\n\nWithout an absolute sense of time, there is no way to have a\u00a0defined\norder of trans\u00adac\u00adtion. And without a\u00a0defined order of trans\u00adac\u00adtions,\nthe rules of a\u00a0ledger can not be followed. How else can you make sure\nhow much money you actually have? How else can you make sure that things\nare *in order*?\n\nThe distinc\u00adtion between tokens and ledgers highlights the neces\u00adsity\nfor keeping track of time. In the physical realm, coins are timeless\nartifacts that can be exchanged without oversight. In the digital realm,\ncoinstamping requires timestamping.\n\n## Centralized Coinstamping\n\n\u003E Time: a\u00a0great engraver, or eraser.\n\u003E\n\u003E \u2014Yahia Lababidi (b. 1973)\n\nThe common way to solve the double-spending problem\u2009\u2014\u2009the problem of\nmaking sure that a\u00a0digital transfer only happens once\u2009\u2014\u2009is to have\na\u00a0central list of trans\u00adac\u00adtions. Once you have a\u00a0central list of\ntrans\u00adac\u00adtions, you have a\u00a0single ledger that can act as the sole source\nof truth. Solving the double-spending problem is as easy as going\nthrough the list and making sure that every\u00adthing adds up correctly.\nThis is how PayPal, Venmo, Alipay, and all the banks of this\nworld\u2009\u2014\u2009including central banks\u2009\u2014\u2009solve the double-spending problem:\nvia central authority.\n\n\u003E The problem of course is the payee can\u0027t verify that one of the owners\n\u003E did not double-spend the coin. A\u00a0common solution is to intro\u00adduce\n\u003E a\u00a0trusted central authority, or mint, that checks every trans\u00adac\u00adtion\n\u003E for double-spending. \\[...\\] The problem with this solution is that\n\u003E the fate of the entire money system depends on the company running the\n\u003E mint, with every trans\u00adac\u00adtion having to go through them, just like\n\u003E a\u00a0bank.\n\u003E\n\u003E \u2014Satoshi Nakamoto (2009)\n\nIt is worth pointing out that Satoshi didn\u0027t manage to make\ninfor\u00adma\u00adtion non-copyable. Every part of bitcoin\u2009\u2014\u2009its source code,\nthe ledger, your private key\u2009\u2014\u2009can be copied. All of it can be\ndupli\u00adcated and tampered with. However, Satoshi managed to build\na\u00a0system that makes rule-breaking copies completely and utterly useless.\nThe Bitcoin network performs an intri\u00adcate dance to decide which copies\nare useful and which aren\u0027t, and it is this dance that brings scarcity\ninto the digital realm. And like with every dance, a\u00a0temporal measuring\nstick is required to dictate the rhythm.\n\nEven a\u00a0central\u00adized ledger can only solve the double-spending problem if\nit has a\u00a0consis\u00adtent way to keep track of time. You always need to know\nwho gave how much to whom and, most impor\u00adtantly: *when*. In the realm\nof infor\u00adma\u00adtion, there is no coin-stamping without time-stamping.\n\n\u003E It must be stressed that the *impos\u00adsi\u00adbility of associ\u00adating events\n\u003E with points in time* in distrib\u00aduted systems was the unsolved problem\n\u003E that precluded a\u00a0decen\u00adtral\u00adized ledger from ever being possible until\n\u003E Satoshi Nakamoto invented a\u00a0solution.\n\u003E\n\u003E \u2014Gregory Trubet\u00adskoy (2018)\n\n## Decentralized Time\n\n\u003E Time brings all things to pass.\n\u003E\n\u003E \u2014Aeschylus (525 BC -- 456 BC)\n\nTime and order have a\u00a0very intimate relation\u00adship. As Leslie Lamport\npointed out in his 1978 paper *Time, Clocks, and the Ordering of Events\nin a\u00a0Distrib\u00aduted System*: \u0022The concept of time is funda\u00admental to our\nway of thinking. It is derived from the more basic concept of the order\nin which events occur.\u0022 Absent a\u00a0central point of coordi\u00adna\u00adtion,\nseemingly intuitive notions of \u0022before,\u0022 \u0022after,\u0022 and\n\u0022simul\u00adta\u00adne\u00adously\u0022 break down. In the words of Lamport: \u0022the concept of\n\u0027happening before\u0027 defines an invariant partial ordering of the events\nin a\u00a0distrib\u00aduted multi\u00adprocess system.\u0022\n\nPhrased differ\u00adently: Who should be in charge of time if putting someone\nin charge is not allowed? How can you have a\u00a0reliable clock if there is\nno central frame of refer\u00adence?\n\nYou might think that solving this problem is easy because everyone could\njust use their own clock. This only works if every\u00adone\u0027s clock is\naccurate, and, more impor\u00adtantly, everyone plays nice. In an\nadver\u00adsarial system, relying on individual clocks would be a\u00a0disaster.\nAnd, because of relativity, it does not work consis\u00adtently across space.\n\nAs a\u00a0thought exper\u00adi\u00adment, imagine how you could cheat the system if\neveryone was in charge of keeping the time for themselves. You could\npretend that the trans\u00adac\u00adtion you\u0027re sending now is actually from\nyesterday\u2009\u2014\u2009it just got delayed for some reason\u2009\u2014\u2009thus, you would\nstill have all the money that you\u0027ve spent today. Because of the\nasynchro\u00adnous commu\u00adni\u00adca\u00adtion that is inherent in every decen\u00adtral\u00adized\nsystem, this scenario is more than a\u00a0theoret\u00adical thought exper\u00adi\u00adment.\nMessages do indeed get delayed, timestamps are inaccu\u00adrate, and thanks\nto relativistic effects and the natural speed limit of our universe, it\nis anything but easy to tell apart the order of things absent of\na\u00a0central authority or observer.\n\n\u003E Who\u0027s there? Knock knock.\n\u003E\n\u003E \u2014An Asynchro\u00adnous Joke\n\nTo better illus\u00adtrate the impos\u00adsi\u00adbility of the problem, let\u0027s look at\na\u00a0concrete example. Imagine that you and your business partner both have\naccess to your company bank account. You do business all over the world,\nso your bank account is in Switzer\u00adland, you are in New York, and your\nbusiness partner is in Sydney. For you, it is January 3^rd^, and you are\nenjoying a\u00a0beautiful Sunday evening at your hotel. For her, it\u0027s Monday\nmorning already, so she decides to buy break\u00adfast using the debit card\nof your shared bank account. The cost is \\$27. The avail\u00adable balance is\n\\$615. The local time is 8:21 am.\n\nAt the same time, you are about to pay for your stay with another debit\ncard linked to the same bank account. The cost is \\$599. The avail\u00adable\nbalance is \\$615. The local time is 5:21\u00a0pm.\n\n![](https:\/\/dergigi.com\/assets\/images\/bitcoin\/2021-01-14-bitcoin-is-time\/alice-bob-bank.jpg)\n\nSo it comes to be that\u2009\u2014\u2009at exactly the same moment\u2009\u2014\u2009you both swipe\nthe card. What happens? (Dear physi\u00adcists, please excuse my use of \u0022the\nsame moment\u0022\u2009\u2014\u2009we will ignore relativistic effects and the fact that\nthere is no absolute time in our universe for now. We will also ignore\nthat the concept of synchro\u00adnous events doesn\u0027t really exist. Bitcoin is\ncompli\u00adcated enough as it is!)\n\nThe central ledger at your bank will probably receive one trans\u00adac\u00adtion\nbefore the other one, so one of you will be lucky, the other not so\nmuch. If the trans\u00adac\u00adtions happen to arrive in the same\n*tick*\u2009\u2014\u2009let\u0027s say in the same millisecond\u2009\u2014\u2009the bank would have to\ndecide who gets to spend the money.\n\nNow, what would happen if there was no bank? Who decides who was the\nfirst one to swipe? What if it wasn\u0027t only you two, but hundreds or even\nthousands of people coordi\u00adnating? What if you didn\u0027t trust those\npeople? What if some of those people are trying to cheat, e.g., by\nsetting their clocks back so that it looks like they spent the money\na\u00a0couple of minutes earlier?\n\n\u003E A time-related tool \\[is\\] needed to estab\u00adlish a\u00a0canon\u00adical ordering\n\u003E and to enforce a\u00a0unique history in the absence of any central\n\u003E coordi\u00adnator.\n\u003E\n\u003E \u2014Giacomo Zucco, [*Discov\u00adering\n\u003E Bitcoin*](https:\/\/bitcoinmagazine.com\/articles\/discovering-bitcoin-a-brief-overview-from-cavemen-to-the-lightning-network)\n\u003E (2019)\n\nThis problem is *precisely* why all previous attempts of digital cash\nrequired a\u00a0central\u00adized registry. You always had to trust someone to\ncorrectly identify the order of things. A\u00a0central\u00adized party was\nrequired to keep the time.\n\nBitcoin solves this problem by re-inventing time itself. It says no to\nseconds and yes to blocks.\n\n## Keeping the Time, One Block at a\u00a0Time\n\n\u003E Time\u0027s glory is to calm contending kings,  \n\u003E To unmask false\u00adhood and bring truth to light,  \n\u003E To stamp the seal of time in aged things,  \n\u003E To wake the morn and sentinel the night,  \n\u003E To wrong the wronger till he render right;\n\u003E\n\u003E \u2014William Shake\u00adspeare, *The Rape of Lucrece* (1594)\n\nAll clocks rely on periodic processes, something that we might call a\n\u0022tick.\u0022 The familiar *tick-tock* of a\u00a0grand\u00adfa\u00adther\u0027s clock is, in\nessence, the same as the molec\u00adular-atomic buzzing of our modern Quartz\nand Caesium clocks. Something swings\u2009\u2014\u2009or oscil\u00adlates\u2009\u2014\u2009and we simply\ncount these swings until it adds up to a\u00a0minute or a\u00a0second.\n\nFor large pendulum clocks, these swings are long and easy to see. For\nsmaller and more special\u00adized clocks, special equip\u00adment is required.\nThe frequency of a\u00a0clock\u2009\u2014\u2009how often it ticks\u2009\u2014\u2009depends on its\nuse-case.\n\nMost clocks have a\u00a0fixed frequency. After all, we want to know the time\n*precisely*. There are, however, clocks that have a\u00a0variable frequency.\nA\u00a0metronome, for example, has a\u00a0variable frequency that you can set\nbefore you make it tick. While a\u00a0metronome keeps its pace constant once\nit is set, Bitcoin\u0027s time varies for each tick because its internal\nmecha\u00adnism is proba\u00adbilistic. The purpose, however, is all the same:\nkeep the music alive, so the dance can continue.\n\n| Clock                     | Tick Frequency                          |\n| --------------------------|-----------------------------------------|\n| Grandfather\u0027s clock       | ~0.5\u00a0Hz                                 |\n| Metronome                 | ~0.67\u00a0Hz to ~4.67\u00a0Hz                    |\n| Quartz watch              | 32768\u00a0Hz                                |\n| Caesium-133 atomic clock  | 9,192,631,770\u00a0Hz                        |\n| Bitcoin                   | 1 block (0.00000192901\u00a0Hz* to \u221e Hz**)   |\n\n\n\\* first block (6\u00a0days)   \n\\*\\* timestamps between blocks can show a\u00a0negative delta\n\n\nThe fact that Bitcoin is a\u00a0clock is hiding in plain sight. Indeed,\nSatoshi points out that the Bitcoin network as a\u00a0whole acts as a\u00a0clock,\nor, in his words: a\u00a0distrib\u00aduted timestamp server.\n\n\u003E In this paper, we propose a\u00a0solution to the double-spending problem\n\u003E using a\u00a0peer-to-peer distrib\u00aduted timestamp server to generate\n\u003E compu\u00adta\u00adtional proof of the chrono\u00adlog\u00adical order of trans\u00adac\u00adtions.\n\u003E\n\u003E \u2014Satoshi Nakamoto (2009)\n\nThat timestamping was the root problem to be solved is also apparent by\nexamining the refer\u00adence at the end of the Bitcoin whitepaper. Out of\nthe eight refer\u00adences in total, three are about timestamping:\n\n-   *How to time-stamp a\u00a0digital document* by S. Haber, W.S.\n    Stornetta (1991)\n-   *Improving the efficiency and relia\u00adbility of digital time-stamping*\n    by D. Bayer, S. Haber, W.S. Stornetta (1992)\n-   *Design of a\u00a0secure timestamping service with minimal trust\n    require\u00adments* by H. Massias, X.S. Avila, and J.-J. Quisquater\n    (May 1999)\n\nAs Haber and Stornetta outlined in 1991, digital time-stamping is about\ncompu\u00adta\u00adtion\u00adally practical proce\u00addures that make it infea\u00adsible for\na\u00a0user\u2009\u2014\u2009or an adver\u00adsary, for that matter\u2009\u2014\u2009to either back-date or\nforward-date a\u00a0digital document. Contrary to physical documents, digital\ndocuments are easy to tamper with, and the change doesn\u0027t neces\u00adsarily\nleave any tell-tale signs on the physical medium itself. In the digital\nrealm, forgeries and manip\u00adu\u00adla\u00adtions can be perfect.\n\nThe malleable nature of infor\u00adma\u00adtion makes time-stamping digital\ndocuments an elabo\u00adrate and sophis\u00adti\u00adcated process. Naive solutions do\nnot work. Take a\u00a0text document, for example. You can\u0027t simply add the\ndate at the end of the document since everyone\u2009\u2014\u2009including\nyourself\u2009\u2014\u2009could simply change the date in the future. You could also\nmake up any date in the first place.\n\n## Time is a\u00a0Causal Chain\n\n\u003E In an extreme view, the world can be seen as only connec\u00adtions,\n\u003E nothing else.\n\u003E\n\u003E \u2014Tim Berners-Lee, *Weaving the Web* (1999)\n\nMaking up dates is a\u00a0general problem, even in the non-digital realm.\nWhat is known in the kidnap\u00adping world as \u0022Authen\u00adti\u00adca\u00adtion by\nNewspaper\u0022 is a\u00a0general solution to the problem of arbitrary timestamps.\n\n![](https:\/\/dergigi.com\/assets\/images\/bitcoin\/2021-01-14-bitcoin-is-time\/proof-of-time.jpg)\n\nThis works because a\u00a0newspaper is hard to fake and easy to verify. It is\nhard to fake because today\u0027s front page refers to yester\u00adday\u0027s events,\nevents that could not have been predicted by the kidnapper if the\npicture would be weeks old. By proxy of these events, the picture is\nproof that the hostage was still alive on the day the newspaper came\nout.\n\nThis method highlights one of the key concepts when it comes to time:\n*causality*. The arrow of time describes the causal relation\u00adship of\nevents. No causality, no time. Causality is also the reason why\ncrypto\u00adgraphic hash functions are so crucial when it comes to\ntimestamping documents in cyber\u00adspace: they intro\u00adduce a\u00a0causal\nrelation\u00adship. Since it is practi\u00adcally impos\u00adsible to create a\u00a0valid\ncrypto\u00adgraphic hash without having the document in the first place,\na\u00a0causal relation\u00adship between the document and the hash is intro\u00adduced:\nthe data in question existed first, the hash was gener\u00adated later. In\nother words: without the compu\u00adta\u00adtional irreversibility of one-way\nfunctions, there would be no causality in cyber\u00adspace.\n\n![](https:\/\/dergigi.com\/assets\/images\/bitcoin\/2021-01-14-bitcoin-is-time\/sha256.jpg)\n\nWith this causal building block in place, one can come up with schemes\nthat create a\u00a0chain of events, causally linking A\u00a0to B\u00a0to C\u00a0and so on.\nIn that sense, secure digital timestamping moves us from a\u00a0timeless\nplace in the ether into the realm of digital history.\n\n\u003E Causality fixes events in time. If an event was deter\u00admined by certain\n\u003E earlier events, and deter\u00admines certain subse\u00adquent events, then the\n\u003E event is sandwiched securely into its place in history.\n\u003E\n\u003E \u2014Bayer, Haber, Stornetta (1992)\n\nIt goes without saying that causality is of the utmost impor\u00adtance when\nit comes to economic calcu\u00adla\u00adtions. And since a\u00a0ledger is nothing but\nthe embod\u00adi\u00adment of economic calcu\u00adla\u00adtions of multiple cooper\u00adating\npartic\u00adi\u00adpants, causality is essen\u00adtial for every ledger.\n\n\u003E We need a\u00a0system for partic\u00adi\u00adpants to agree on a\u00a0single history\n\u003E \\[...\\]. The solution we propose begins with a\u00a0timestamp server.\n\u003E\n\u003E \u2014Satoshi Nakamoto (2009)\n\nIt is fasci\u00adnating that all of the puzzle pieces that make Bitcoin work\ndid already exist. As early as 1991, Haber and Stornetta intro\u00adduced two\nschemes that make it \u0022diffi\u00adcult or impos\u00adsible to produce false\ntime-stamps.\u0022 The first relies on a\u00a0trusted third party; the second,\nmore elabo\u00adrate \u0022distrib\u00aduted trust\u0022 scheme, does not. The authors even\nidenti\u00adfied the inherent problems of trusting a\u00a0causal chain of events\nand what would be required to rewrite history. In their words, \u0022the only\npossible spoof is to prepare a\u00a0fake chain of time-stamps, long enough to\nexhaust the most suspi\u00adcious challenger that one antic\u00adi\u00adpates.\u0022\nA\u00a0similar attack vector exists in Bitcoin today, in the form of a\u00a051%\nattack (more on that in a\u00a0later chapter).\n\nOne year later, Bayer, Haber, and Stornetta built upon their previous\nwork and proposed to use trees instead of simple linked lists to tie\nevents together. What we know as *Merkle Trees* today are simply\nefficient data struc\u00adtures to create a\u00a0hash from multiple hashes\ndeter\u00admin\u00adis\u00adti\u00adcally. For timestamping, this means that you can\nefficiently bundle multiple events into one \u0022tick.\u0022 In the same paper,\nthe authors propose that the distrib\u00aduted trust model intro\u00adduced in\n1991 could be improved by carrying out a\u00a0recur\u00adring \u0022world champi\u00adonship\ntourna\u00adment\u0022 to deter\u00admine a\u00a0single \u0022winner\u0022 who widely publishes the\nresulting hash somewhere public, like a\u00a0newspaper. Sounds familiar?\n\nAs we shall see, it turns out that newspa\u00adpers are also an excel\u00adlent\nway to think about the second ingre\u00addient of time: unpre\u00addictability.\n\n## Causality and Unpredictability\n\n\u003E Time is not a\u00a0reality \\[*hupostasis*\\], but a\u00a0concept \\[*no\u00eama*\\] or\n\u003E a\u00a0measure \\[*metron*\\]...\n\u003E\n\u003E \u2014Antiphon the Sophist, *On Truth* (3rd century AD)\n\nWhile causality is essen\u00adtial, it is not suffi\u00adcient. We also need\n*unpre\u00addictability* for time to flow. In the physical realm, we observe\nnatural processes to describe the flow of time. We observe a\u00a0general\nincrease in entropy and call that the arrow of time. Even though the\nlaws of nature seem to be obliv\u00adious in regards to the direc\u00adtion of\nthis arrow in most cases, certain things can\u0027t be undone, practi\u00adcally\nspeaking. You can\u0027t unscramble an egg, as they say.\n\nSimilarly, entropy-increasing functions are required to estab\u00adlish an\narrow of time in the digital realm. Just like it is practi\u00adcally\nimpos\u00adsible to unscramble an egg, it is practi\u00adcally impos\u00adsible to\nunscramble a\u00a0SHA256 hash or crypto\u00adgraphic signa\u00adture.\u00a0\n\nWithout this increase in entropy, we could go forward and backward in\ntime willy-nilly. The sequence of Fibonacci Numbers, for example, is\ncausal but not entropic. Every number in the sequence is caused by the\ntwo numbers that came before it. In that sense, it is a\u00a0causal chain.\nHowever, it is not useful to tell the time because it is entirely\npredictable. In the same way that a\u00a0kidnapper can\u0027t simply stand in\nfront of a\u00a0calendar that shows the current date, we can\u0027t use\npredictable processes as proof of time. We always have to rely on\nsomething that can\u0027t be predicted in advance, like the front page of\ntoday\u0027s newspaper.\n\nBitcoin relies upon two sources of unpre\u00addictability: trans\u00adac\u00adtions and\nproof-of-work. Just like nobody can predict what tomor\u00adrow\u0027s newspaper\nwill look like, nobody can predict what the next Bitcoin block will look\nlike. You can\u0027t predict what trans\u00adac\u00adtions are going to be included\nbecause you can\u0027t predict what trans\u00adac\u00adtions are going to be broad\u00adcast\nin the future. And, more impor\u00adtantly, you can\u0027t predict who will find\nthe solution to the current proof-of-work puzzle and what this solution\nwill be.\u00a0\n\nIn contrast to the kidnap\u00adper\u0027s newspaper, however, proof-of-work is\nphysi\u00adcally linked to what happened *directly*. It is not just a\u00a0record\nof an event\u2009\u2014\u2009it is the event itself. It is the proba\u00adbilistic\ndirect\u00adness of proof-of-work that removes trust from the equation. The\nonly way to find a\u00a0valid proof-of-work is by making a\u00a0lot of guesses,\nand making a\u00a0single guess takes a\u00a0little bit of time. The proba\u00adbilistic\nsum of these guesses is what builds up the timechain that is Bitcoin.\n\nBy utilizing the causality of hash-chains and the unpre\u00addictability of\nproof-of-work, the Bitcoin network provides a\u00a0mecha\u00adnism for\nestab\u00adlishing an indis\u00adputable history of events witnessed. Without\ncausality, what came before and what came after is impos\u00adsible to tease\napart. Without unpre\u00addictability, causality is meaning\u00adless.\n\nWhat is intuitively under\u00adstood by every kidnapper was explic\u00aditly\npointed out by Bayer, Haber, and Stornetta in 1992: \u0022To estab\u00adlish that\na\u00a0document was created after a\u00a0given moment in time, it is neces\u00adsary to\nreport events that could not have been predicted before they happened.\u0022\n\n![](https:\/\/dergigi.com\/assets\/images\/bitcoin\/2021-01-14-bitcoin-is-time\/proof-of-publication.jpg)\n\nIt is the combi\u00adna\u00adtion of causality and unpre\u00addictability that allows\nthe creation of an artifi\u00adcial \u0022now\u0022 in the other\u00adwise timeless digital\nrealm. As Bayer, Haber, and Stornetta point out in their 1991 paper:\n\u0022the sequence of clients requesting time-stamps and the hashes they\nsubmit cannot be known in advance. So if we include bits from the\nprevious sequence of client requests in the signed certifi\u00adcate, then we\nknow that the time-stamp occurred after these requests. \\[...\\] But the\nrequire\u00adment of including bits from previous documents in the\ncertifi\u00adcate also can be used to solve the problem of constraining the\ntime in the other direc\u00adtion, because the time-stamping company cannot\nissue later certifi\u00adcates unless it has the current request in hand.\u0022\n\nAll the puzzle pieces were already there. What Satoshi managed to do is\nput them together in a\u00a0way that removes the \u0022time-stamping company\u0022 from\nthe equation.\n\n## Proof of Time\n\n\u003E *Causa latet: vis est notis\u00adsima.*   \n\u003E The cause is hidden, but the result is known.\n\u003E\n\u003E \u2014Ovid, *Metamor\u00adphoses*, IV. 287 (8 AD)\n\nLet us recapit\u00adu\u00adlate: to use money in the digital realm, we have to\nrely on ledgers. To make ledgers reliable, unambiguous order is\nrequired. To estab\u00adlish order, timestamps are neces\u00adsary. Thus, if we\nwant to have *trust\u00adless* money in the digital realm, we must remove any\nentity that creates and manages timestamps and any single entity that is\nin charge of time itself.\n\nIt took a\u00a0genius like Satoshi Nakamoto to realize the solution: \u0022To\nimple\u00adment a\u00a0distrib\u00aduted timestamp server on a\u00a0peer-to-peer basis, we\nwill need to use a\u00a0proof-of-work system similar to Adam Back\u0027s\nHashcash.\u0022\n\nWe need to use a\u00a0proof-of-work system because we need something that is\nnative to the digital realm. Once you under\u00adstand that the digital realm\nis infor\u00adma\u00adtional in nature, the obvious conclu\u00adsion is that\ncompu\u00adta\u00adtion is all we have. If your world is made of data,\nmanip\u00adu\u00adla\u00adtion of data is all there is.\u00a0\n\nProof-of-work works in a\u00a0peer-to-peer setting because it is\n*trust\u00adless*, and it is trust\u00adless because it is discon\u00adnected from all\nexternal inputs\u2009\u2014\u2009such as the readings of clocks (or newspa\u00adpers, for\nthat matter). It relies on one thing and one thing only: compu\u00adta\u00adtion\nrequires work, and in our universe, work requires energy and time.\n\n## Bridging Times\n\n\u003E I know it works for me.\u00a0  \n\u003E As we cross the bridge\u2009\u2014\u2009the burning bridge\u2009\u2014\u2009  \n\u003E With flames behind us,\u00a0  \n\u003E We front the line.\u00a0  \n\u003E It\u0027s you and me, baby, against the world.\n\u003E\n\u003E \u2014Kate Bush, *Burning Bridge* (1985)\n\nWithout proof-of-work, one would always run into the Oracle problem\nbecause the physical realm and the infor\u00adma\u00adtional realm are eternally\ndiscon\u00adnected. The markings on your list of sheep aren\u0027t your sheep, the\nmap is not the terri\u00adtory, and whatever was written in yester\u00adday\u0027s\nnewspaper isn\u0027t neces\u00adsarily what happened in the real world. In the\nsame manner, just because you use a\u00a0real-world clock to write down\na\u00a0timestamp doesn\u0027t mean that this is actually what the time was.\n\nPut bluntly, there simply is no way to trust that data repre\u00adsents\nreality, except if the reality in question is inherent in the data\nitself. The brilliant thing about Bitcoin\u0027s diffi\u00adculty-adjusted\nproof-of-work is that it creates its own reality, along with its own\nspace and time.\n\nProof-of-work provides a\u00a0direct connec\u00adtion between the digital realm\nand the physical realm. More profoundly, it is the only connec\u00adtion that\ncan be estab\u00adlished in a\u00a0trust\u00adless manner. Every\u00adthing else will always\nrely on external inputs.\n\nThe diffi\u00adculty to mine a\u00a0new Bitcoin block is adjusted to make sure\nthat the thin thread between Bitcoin\u0027s time and our time remains intact.\nLike clock\u00adwork, the mining diffi\u00adculty readjusts every 2016 ticks. The\ngoal of this readjust\u00adment is to keep the *average* time between ticks\nat ten minutes. It is these ten minutes that maintain a\u00a0stable\nconnec\u00adtion between the physical and the infor\u00adma\u00adtional realm.\nConse\u00adquently, a\u00a0sense of human time is required to readjust the ticks\nof the Bitcoin clock. A\u00a0purely block-based readjust\u00adment wouldn\u0027t work\nsince it would be completely discon\u00adnected from our human world, and the\nwhole purpose of the readjust\u00adment is to stop us ingenious humans from\nfinding blocks too fast (or too slow).\n\nAs Einstein has shown us, time is not a\u00a0static thing. There is no such\nthing as a\u00a0universal time we could rely upon. Time is relative, and\nsimul\u00adtaneity is nonex\u00adis\u00adtent. This fact alone makes all\ntimestamps\u2009\u2014\u2009especially across large distances\u2009\u2014\u2009inher\u00adently\nunreli\u00adable, even without adver\u00adsarial actors. (This is why timestamps\nof GPS satel\u00adlites have to be adjusted constantly, by the way.)\n\nFor Bitcoin, the fact that our human timestamps are impre\u00adcise doesn\u0027t\nmatter too much. It also doesn\u0027t matter that we have no absolute\nrefer\u00adence frame in the first place. They only have to be precise enough\nto calcu\u00adlate a\u00a0somewhat reliable average across 2016 blocks. To\nguarantee that, a\u00a0block\u0027s \u0022meatspace\u0022 timestamp is only accepted if it\nfulfills two criteria:\n\n1.  The timestamp has to be greater than the median timestamp of the\n    previous 11 blocks.\n2.  The timestamp has to be less than the network-adjusted time plus two\n    hours. (The \u0022network-adjusted time\u0022 is simply the median of the\n    timestamps returned by all nodes connected to you.)\n\nIn other words, the diffi\u00adculty-adjust\u00adment is about keeping a\u00a0constant\ntime, *not* a\u00a0constant level of security, diffi\u00adculty, or energy\nexpen\u00addi\u00adture. This is ingenious because good money *has* to be costly\nin time, not energy. Linking money to energy alone is not suffi\u00adcient to\nproduce absolute scarcity since every improve\u00adment in energy\ngener\u00ada\u00adtion would allow us to create more money. Time is the only thing\nwe will never be able to make more of. It is *The Ultimate Resource*, as\nJulian Simon points out. This makes Bitcoin the ultimate form of money\nbecause its issuance is directly linked to the ultimate resource of our\nuniverse: time.\n\nThe diffi\u00adculty adjust\u00adment is essen\u00adtial because, without it, the\ninternal clock of Bitcoin would tend to go faster and faster as more\nminers join the network or the efficiency of mining devices improves. We\nwould quickly run into the coordi\u00adna\u00adtion problem that Bitcoin sets out\nto solve. As soon as the block time falls below a\u00a0certain threshold,\nsay, 50\u00a0millisec\u00adonds, it would be impos\u00adsible to agree on a\u00a0shared\nstate, even in theory. It takes light around 66\u00a0millisec\u00adonds to travel\nfrom one side of the earth to the other. Thus, even if our computers and\nrouters were perfect, we would be back at square one: given two events,\nit would be futile to tell which event happened before and which event\nhappened after. Without a\u00a0periodic adjust\u00adment of Bitcoin\u0027s ticks, we\nwould run into the hopeless problem of solving the coordi\u00adna\u00adtion\nproblem faster than the speed of light. Time is also at the root of the\nproblem of crypto\u00adgraphic insta\u00adbility, which was outlined in Chapter 1.\nCryptog\u00adraphy works because of an asymmetry in time: it takes a\u00a0short\ntime to build a\u00a0crypto\u00adgraphic wall and a\u00a0long time to break it\ndown\u2009\u2014\u2009unless you have a\u00a0key.\n\nThus, in some sense, proof-of-work\u2009\u2014\u2009and the diffi\u00adculty adjust\u00adment\nthat goes along with it\u2009\u2014\u2009artifi\u00adcially slows down time, at least from\nthe perspec\u00adtive of the Bitcoin network. In other words: Bitcoin\nenforces an internal rhythm whose low frequency allows ample buffer for\nthe latency of commu\u00adni\u00adca\u00adtions between peers. Every 2016 blocks,\nBitcoin\u0027s internal clock readjusts, so that\u2009\u2014\u2009on average\u2009\u2014\u2009only one\nvalid block will be found every 10\u00a0minutes.\u00a0\n\nFrom an outside perspec\u00adtive, Bitcoin funnels the chaotic mess of\nglobally broad\u00adcast asynchro\u00adnous messages into a\u00a0parallel universe,\nrestricted by its own rules and its own sense of space and time.\nTrans\u00adac\u00adtions in the mempool are timeless from the point-of-view of the\nBitcoin network. Only when a\u00a0trans\u00adac\u00adtion is included in a\u00a0valid block\ndoes it get assigned a\u00a0time: the number of the block it is included in.\n\n![](https:\/\/dergigi.com\/assets\/images\/bitcoin\/2021-01-14-bitcoin-is-time\/timechain.png)\n\nIt is hard to overstate how elegant a\u00a0solution this is. Once you are\nable to create your own defin\u00adi\u00adtion of time, deciphering what came\nbefore and what came after is trivial. In turn, agreeing on what\nhappened, in what order, and, conse\u00adquently, who owes what to whom,\nbecomes trivial as well.\n\nThe diffi\u00adculty adjust\u00adment makes sure that the *ticks* of Bitcoin\u0027s\ninternal metronome are somewhat constant. It is the conductor of the\nBitcoin orchestra. It is what keeps the music alive.\u00a0\n\nBut why can we rely on work in the first place? The answer is\nthree\u00adfold. We can rely on it because compu\u00adta\u00adtion requires work, work\nrequires time, and the work in question\u2009\u2014\u2009guessing random\nnumbers\u2009\u2014\u2009can not be done efficiently.\n\n## Probabilistic Time\n\n\u003E Time forks perpet\u00adu\u00adally toward innumer\u00adable futures.\n\u003E\n\u003E \u2014Jorge Luis Borges, *The Garden of Forking Paths* (1941)\n\nFinding a\u00a0valid nonce for a\u00a0Bitcoin block is a\u00a0guessing game. It is very\nmuch like rolling a\u00a0die, or flipping a\u00a0coin, or spinning a\u00a0roulette\nwheel. You are, in essence, trying to find a\u00a0beyond-astro\u00adnom\u00adi\u00adcally\nlarge random number. There is no progress toward finding a\u00a0solution. You\neither hit the jackpot, or you don\u0027t.\n\nEvery time you flip a\u00a0coin, the chance of it coming up heads or tails is\n50%\u2009\u2014\u2009even if you flipped it twenty times before, and it came up heads\nevery time. Similarly, every time you wait for a\u00a0bitcoin block to come\nin, the chance that it will be found *this second* is \\~0.16%. It\ndoesn\u0027t matter when the last block was found. The approx\u00adi\u00admate waiting\ntime for the next block is always the same: \\~10\u00a0minutes.\n\nIt follows that every individual tick of this clock is unpre\u00addictable.\nRelative to our human clocks, this clock appears to be sponta\u00adneous and\nimpre\u00adcise. This is irrel\u00ade\u00advant, as Gregory Trubet\u00adskoy points out: \u0022It\ndoesn\u0027t matter that this clock is impre\u00adcise. What matters is that it is\nthe same clock for everyone and that the state of the chain can be tied\nunambigu\u00adously to the ticks of this clock.\u0022 Bitcoin\u0027s clock might be\nproba\u00adbilistic, but it isn\u0027t illusory.\n\n\u003E Time is an illusion,  \n\u003E lunchtime doubly so.\n\u003E\n\u003E \u2014Douglas Adams (1979)\n\nThe present moment, however, can absolutely be an illusion in Bitcoin.\nSince there is no central authority in the network, strange situa\u00adtions\ncan arise. While unlikely, it is possible that two\u00a0valid blocks are found at\nthe same time (again: apolo\u00adgies to all physi\u00adcists), which will make\nthe clock tick forward in two different places at once. However, since\nthe two different blocks will very likely differ in their content, they\nwill contain two different histo\u00adries, both equally valid.\n\nThis is known as a\u00a0chain split and is a\u00a0natural process of Nakamoto\nconsensus. Like a\u00a0flock of birds that briefly splits in two only to\nmerge again, nodes on the Bitcoin network will eventu\u00adally converge to\na\u00a0shared history after some time, thanks to the proba\u00adbilistic nature of\nguessing.\n\nNakamoto consensus simply states that the correct history is to be found\nin the heaviest chain, i.e., the chain with the most amount of\nproof-of-work embedded in it. Thus, if we have two histo\u00adries A\u00a0and B,\nsome miners will try to build upon history A, others will try to build\nupon history B. As soon as one of them finds the next valid block, the\nother group is programmed to accept that they were on the wrong side of\nhistory and switch over to the heaviest chain\u2009\u2014\u2009the chain that\nrepre\u00adsents what actually happened, by defin\u00adi\u00adtion. In Bitcoin, history\nis truly written by the victors.\n\n\u003E The payee needs proof that at the time of each trans\u00adac\u00adtion, the\n\u003E majority of nodes agreed it was the first received. \\[...\\] When there\n\u003E are multiple double-spent versions of the same trans\u00adac\u00adtion, one and\n\u003E only one will become valid. The receiver of a\u00a0payment must wait an\n\u003E hour or so before believing that it\u0027s valid. The network will resolve\n\u003E any possible double-spend races by then.\n\u003E\n\u003E \u2014Satoshi Nakamoto (2009)\n\nIn this simple state\u00adment lies the secret of the distrib\u00aduted\ncoordi\u00adna\u00adtion problem. This is how Satoshi solved the problem of the\n\u0022simul\u00adta\u00adneous payment\u0022 our ficti\u00adtious business partners encoun\u00adtered\nprevi\u00adously. He solved it once and for all, relativistic effects be\ndamned!\n\nBecause of this proba\u00adbilistic nature of Bitcoin\u0027s clock, the present\nmoment\u2009\u2014\u2009what we call the chain tip\u2009\u2014\u2009is always uncer\u00adtain. The\npast\u2009\u2014\u2009blocks buried below the chain tip\u2009\u2014\u2009is ever more certain.\u00a0\n\n\u003E The more thorough the under\u00adstanding needed, the further back in time\n\u003E one must go.\n\u003E\n\u003E \u2014Gordon Clark, *A\u00a0Chris\u00adtian View of Men and Things*, p. 58. (1951)\n\nConse\u00adquently, the Bitcoin clock might rewind from time to time, for\nsome peers, for a\u00a0tick or two. If your chain tip\u2009\u2014\u2009the present\nmoment\u2009\u2014\u2009happens to lose to a\u00a0competing chain tip, your clock will\nfirst rewind and then jump forward, overriding the last few ticks that\nyou thought were history already. If your clock is proba\u00adbilistic, your\nunder\u00adstanding of the past has to be too.\n\n\u003E Tick tock tick tock tick\u2009\u2014\u2009what is the time?  \n\u003E Tick tock tick tock... it ends in\n\u003E [c619](https:\/\/www.blockstream.info\/block\/000000000000000000095eaf76a73a7986ea2e6a3b0d190fb10ab986b683c619).  \n\u003E Are you sure this is fine? Are we probably late?  \n\u003E Absolutes do not matter: before nine there comes\n\u003E [eight](https:\/\/www.blockstream.info\/block\/0000000000000000000318291249db2c9b658d087e4f06bcd2ed24481e81533c).  \n\u003E The clock isn\u0027t exact; it sometimes goes in reverse.  \n\u003E Exact time implies center; that\u0027s the root of this curse!  \n\u003E Yet this clock keeps on ticking, tock-tick and tick-tock,  \n\u003E there\u0027s no profit in tricking; just tick-tock and next block.\n\u003E\n\u003E \u2014A Funny Little Rhyme on Bitcoin and Time (2020)\n\n## Conclusion\n\n\u003E Time is still one of the great mysteries in physics, one that calls\n\u003E into question the very defin\u00adi\u00adtion of what physics is.\n\u003E\n\u003E \u2014Jorge Cham and Daniel Whiteson: *We Have No Idea: A\u00a0Guide to the\n\u003E Unknown Universe*, pp. 117\u2009--\u2009118 (2017)\n\nKeeping track of things in the infor\u00adma\u00adtional realm implies keeping\ntrack of a\u00a0sequence of events, which in turn requires keeping track of\ntime. Keeping track of time requires agreeing on a \u0022now\u0022\u2009\u2014\u2009a\u00a0moment in\ntime that eternally links the settled past with the uncer\u00adtain future.\nIn Bitcoin, this \u0022now\u0022 is the tip of the heaviest proof-of-work chain.\u00a0\n\nTwo building blocks are essen\u00adtial for the struc\u00adture of time: causal\nlinks and unpre\u00addictable events. Causal links are required to define\na\u00a0past, and unpre\u00addictable events are required to build a\u00a0future. If the\nsequence of events would be predictable, it would be possible to skip\nahead. If the individual steps of the sequence aren\u0027t linked, it would\nbe trivial to change the past. Because of its internal sense of time, it\nis insanely diffi\u00adcult to cheat Bitcoin. One would have to rewrite the\npast or predict the future. Bitcoin\u0027s timechain prevents both.\n\nViewing Bitcoin through the lens of time should make clear that the\n\u0022block chain\u0022\u2009\u2014\u2009the data struc\u00adture that causally links multiple\nevents together\u2009\u2014\u2009is not the main innova\u00adtion. It is not even a\u00a0new\nidea, as is evident by studying the timestamp liter\u00ada\u00adture of the past.\n\n\u003E A blockchain is a\u00a0chain of blocks.\n\u003E\n\u003E \u2014Peter Todd\n\nWhat is a\u00a0new idea\u2009\u2014\u2009what Satoshi figured out\u2009\u2014\u2009is how to\nindepen\u00addently agree upon a\u00a0history of events without central\ncoordi\u00adna\u00adtion. He found a\u00a0way to imple\u00adment a\u00a0decen\u00adtralised\ntimestamping scheme that (a) doesn\u0027t require a\u00a0time-stamping company or\nserver, (b) doesn\u0027t require a\u00a0newspaper or any other physical medium as\nproof, and (c) can keep the *ticks* more-or-less constant, even when\noperating in an environ\u00adment of ever-faster CPU clock times.\n\nTimekeeping requires *causality*, *unpre\u00addictability*, and\n*coordi\u00adna\u00adtion*. In Bitcoin, *causality* is provided by one-way\nfunctions: the crypto\u00adgraphic hash functions and digital signa\u00adtures\nthat are at the core of the protocol. *Unpre\u00addictability* is provided by\nboth the proof-of-work puzzle as well as the inter\u00adac\u00adtion with other\npeers: you can\u0027t know in advance what others are doing, and you can\u0027t\nknow in advance what the solution to the proof-of-work puzzle will be.\n*Coordi\u00adna\u00adtion* is made possible by the diffi\u00adculty adjust\u00adment, the\nmagic sauce that links Bitcoin\u0027s time to ours. Without this bridge\nbetween the physical and the infor\u00adma\u00adtional realm, it would be\nimpos\u00adsible to agree on a\u00a0time by relying on nothing but data.\n\n**Bitcoin is time** in more ways than one. Its units are stored time\nbecause they are money, and its network is time because it is\na\u00a0decen\u00adtral\u00adized clock. The relent\u00adless beating of this clock is what\ngives rise to all the magical proper\u00adties of Bitcoin. Without it,\nBitcoin\u0027s intri\u00adcate dance would fall apart. But with it, everyone on\nearth has access to something truly marvelous: Magic Internet Money.\n\n---\n\nThis article first appeared on [dergigi.com](https:\/\/dergigi.com\/2021\/01\/14\/bitcoin-is-time\/).","image":"https:\/\/dergigi.com\/assets\/images\/bitcoin-is-time.jpg","pubkey":"6e468422dfb74a5738702a8823b9b28168abab8655faacb6853cd0ee15deee93","kind":30023,"createdAt":"2025-11-07T15:00:35+00:00","publishedAt":"2021-01-13T23:00:00+00:00","topics":["bitcoin","writing"],"url":"https:\/\/www.decentnewsroom.com\/mag\/newsroom-magazine-on-imwald-by-laeserin-category-economy\/cat\/newsroom-magazine-on-imwald-by-laeserin-category-bitcoin\/d\/bitcoin-is-time"},{"title":"Strategy is Just an Insurance Company","slug":"PxRKfqD2vPMFC9NFialIe","summary":"An article deconstructing Strategy\u2019s Business Model, and what Michael Saylor reinvented by mistake. ","content":"Strategy is just an insurance company. It took me sitting in a packed room at Bitcoin Conference 2026, watching Michael Sailer talk for an hour about digital credit and compressed duration, to finally see something that should have been obvious from the start.\n\nNobody said it plainly. Not Saylor. Not the analysts. Not the Bitcoin podcasters who spent hours debating whether STRC was a Ponzi, a masterstroke, or something in between. The debate inside the Bitcoin community got loud enough that people started saying: if you don\u2019t believe in STRC, maybe you don\u2019t actually believe the masses will adopt Bitcoin at all. Two camps. Neither with a clean answer.\n\nI spent months trying to find one. The answers I kept getting were the same recycled talking points: it\u2019s a speculative attack on fiat, it looks like a Ponzi because fiat is a Ponzi, it\u2019s a completely new business model, that\u2019s why it\u2019s hard to explain. All answers. None of them answered the one question that mattered:\n\n**If Saylor calls STRC a product, what is Strategy selling? And what does it cost?**\n\n**Strategy is not a Ponzi, not genius, not even an invention. It\u2019s State Farm for Bitcoiners.**\n\nHere is how I got there.\n\n-----\n\n## Before STRC, Strategy Was Not a Business\n\nWhen MicroStrategy started buying Bitcoin, the value proposition was straightforward. MSTR gave companies regulated or political barriers to direct Bitcoin exposure a way into the asset class. That access had a premium, and the premium made sense.\n\nThen the ETFs launched. Access was no longer scarce. The premium evaporated.\n\nThe only reason for MSTR to trade above its Bitcoin holdings is if it generates cashflow. A company sitting on a pile of non-revenue generating assets is not a business. It is a fund. Before STRC, that is exactly what Strategy was: a Bitcoin fund wearing a company\u2019s clothes, selling hopes and dreams at a markup.\n\nSTRC changed that. STRC is the product that turns Strategy into an actual business. And once you understand what that product is, everything else clicks.\n\n-----\n\n## What Strategy Is Actually Selling\n\nStrategy sells insurance.\n\nNot metaphorically. Not loosely. The structure of what STRC offers maps almost exactly onto what insurance companies have been selling for centuries.\n\nWhen you buy an insurance policy, you are not buying it to make money. You are buying it to lose less. You pay a premium, and in exchange, someone else absorbs the financial shock if things go wrong. The product is not the payout. The product is the reduced exposure to loss.\n\nSTRC works the same way. You hand over Bitcoin\u2019s upside in exchange for stability and yield. The product is not the 11.5% dividend. The product is the stripped-out volatility. The dramatically reduced drawdown risk. The ability to hold a Bitcoin-backed instrument without watching it drop 35% in a quarter.\n\nSome people will say: insurance does not let you get your principal back. That is true of most policies. But getting your dollars back is not the same as getting your value back. The upside you surrendered on day one does not come back with you. It stayed with Strategy.\n\nThere is a scenario where you come out ahead in the short term. If Bitcoin drops significantly during the period you hold STRC, you collected yield while everyone else absorbed losses. You beat the trade. But this is the same logic as having a car accident in the first month of your insurance policy. You paid one month of premiums and collected a payout worth far more. You won. The insurance company lost, that one time. But the insurance company wrote ten thousand policies that month. It never needed to win your individual contract. It needed to win the pool. Strategy operates the same way. At any given moment, some STRC holders will exit in profit relative to what Bitcoin did during their window. But across all holders, across all time, the house collects the appreciation. The longer you hold, the more of that appreciation you have surrendered, and the more expensive your stability becomes.\n\nThe deeper parallel is in how the risk gets absorbed. Insurance companies soften the blow using a large cash reserve and a continuous stream of incoming premiums. Strategy does the same thing, using Bitcoin appreciation as the reserve and new STRC issuance as the incoming flow. The transaction order is reversed, but the mechanism is identical. This is a centuries-old business model, and Michael \u201cSailer\u201d built it on a foundation of Bitcoin. And yes, \u201cSailer\u201d is intentional.\n\n-----\n\n## Saylor\u2019s Words, Translated\n\nAt Bitcoin Conference 2026, Saylor\u2019s slide read: \u201cStrategy transforms Digital Capital into Digital Credit.\u201d Five bullet points followed. Here is what he actually said, and what it means once you strip the jargon:\n\n|What Saylor Said                                   |What It Actually Means                                                                                                                 |\n|---------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------|\n|We **create Currency** -\u003E USD, EUR, etc.           |The policy pays out in money you can spend today                                                                                       |\n|We **reduce Risk** -\u003E Overcollateralized, Seniority|Bitcoin is the reserve. STRC is backed by more Bitcoin than it owes, the same way an insurer holds more cash than it expects to pay out|\n|We **dampen Volatility** -\u003E Par value $100         |The policy has a fixed face value. Bitcoin\u2019s swings don\u2019t change your floor                                                            |\n|We **distill Yield** -\u003E Fixed income rate %        |The premium you receive for handing over Bitcoin\u2019s upside                                                                              |\n|We **compress Duration** -\u003E Monthly cash dividends |The policy pays monthly, like a structured annuity, not a lump sum at the end                                                          |\n\nEvery single one of those bullet points is an insurance concept dressed in fintech language. Overcollateralization is a reserve requirement. Par value is a policy floor. Fixed income rate is a premium. Monthly dividends are structured payouts. Saylor built an insurance company and then described it in a way that made everyone think it was something new.\n\nIt is not something new. That is actually the point.\n\n-----\n\n## You Are Not Investing. You Are Buying.\n\nBefore we talk about price, the language needs fixing.\n\nYou are not investing in STRC. Saylor called it a product. Products have a price tag, not a return profile. When you buy car insurance, you are not investing in your insurance company. You are purchasing a service. The distinction is not semantic. It changes how you should evaluate the decision entirely.\n\nThe moment you frame STRC as an investment, you start measuring it against other investments. And it loses that comparison every time. Held against direct Bitcoin exposure, STRC will almost always underperform over a long enough window. That is not a flaw. That is the product working as designed. You paid for stability. You got stability.\n\nThe right question is not \u201cis this a good investment?\u201d The right question is \u201cwhat am I paying for this, and is it worth it?\u201d\n\nSo what does it cost?\n\nThe price is Bitcoin appreciation. All of it, for as long as you hold.\n\nYou give up Bitcoin\u2019s upside. You receive yield and stability in return. That trade might feel balanced in year one. But Bitcoin does not appreciate linearly, and the yield does not grow with it. Every year you hold STRC, you are paying with another year of potential appreciation you will never see. The yield stays fixed. Bitcoin\u2019s upside does not.\n\nInstead of buying STRC, you could buy Bitcoin directly and sell a small slice annually to generate your own income. You would keep the appreciation, control the amount you sell, and pay no implicit premium to Strategy for the privilege of stability you may not need.\n\nThis is the thing nobody says clearly about STRC: it is not an expensive product at the moment you buy it. It is a product that gets more expensive every single year you hold it. The longer your time horizon, the worse the trade becomes.\n\n-----\n\n## Who Should Actually Buy It\n\nThe house never loses. You can exit STRC at any time, but what is actually happening when you do is that another person takes your seat. STRC is almost never paying the money back. It is rotating the obligation to the next buyer. This is not a scam. It is how every liquid market works. You are not getting a refund. You are finding a buyer. The pool keeps filling. The mechanism holds as long as confidence holds, which in this case means as long as people believe Bitcoin will continue to appreciate.\n\nWhich brings us to who should actually buy it.\n\nThe answer is almost entirely about time horizon and conviction depth.\n\nSTRC makes sense for someone who needs to soften volatility in the short term. A corporate treasurer who needs stable numbers this quarter. An investor approaching retirement who cannot afford a 35% drawdown right now. Someone who wants Bitcoin-linked yield for two or three years without the emotional and financial cost of riding the volatility directly. For those people, the price of stability is acceptable because the window is short and the need is real.\n\nSTRC also makes sense for people who do not plan to hold Bitcoin for ten or twenty years. People who want exposure to the asset class without a long-term commitment. The trade works for them because they were never going to capture the long-term appreciation anyway.\n\nFor everyone else, the clock starts ticking the moment you buy.\n\n-----\n\n## The Takeaway\n\nStrategy is not a Ponzi. It is not an attack on fiat. It is not a new invention. It is a centuries-old insurance model rebuilt on a Bitcoin reserve, and the reason nobody described it that way is simple: complexity charges a premium. If Saylor stood on stage and said \u201cwe sell Bitcoin insurance,\u201d the product would be immediately understood, immediately compared to alternatives, and immediately questioned. Jargon protects margin.\n\nOthers have tried to explain Strategy using different analogies. The most common one describes MSTR as an oil refinery, taking raw Bitcoin volatility and refining it into different products for different investors. It is a useful analogy for understanding the mechanism. But it does not answer the question of what you are actually buying. A refinery describes the process. Insurance describes the product. And once you know what the product is, you can decide whether the price makes sense for you.\n\nBitcoin is the ship. STRC is the insurance policy on it. The people who benefit most from that policy are the ones who genuinely need the protection, not the ones who were going to weather the storm anyway.","image":"https:\/\/i.nostr.build\/9S07dOVklCOBIn9Q.jpg","pubkey":"9cb3545c36940d9a2ef86d50d5c7a8fab90310cc898c4344bcfc4c822ff47bca","kind":30023,"createdAt":"2026-05-05T02:31:52+00:00","publishedAt":"2026-05-05T02:31:52+00:00","topics":["bitcoin","strategy","mstr","strc"],"url":"https:\/\/www.decentnewsroom.com\/mag\/newsroom-magazine-on-imwald-by-laeserin-category-economy\/cat\/newsroom-magazine-on-imwald-by-laeserin-category-bitcoin\/d\/PxRKfqD2vPMFC9NFialIe"},{"title":"Careful, Icarus","slug":"careful-icarus","summary":"Tying identity to onchain activity is problematic in more ways than one.","content":"Yesterday I relapsed. Not alcohol, or drugs, or gambling, or anything of that\nsort. It was something worse: having an argument online.\n\nBack when twitter was still called twitter I found myself getting into many an\nargument. Not because I wanted to, but because\u2014at least back in those days\u2014the\n[algorithm encouraged it][algorithm]. A constant back-and-forth between two stubborn people\nis off-the-charts on all engagement metrics, so naturally it\u0027s what people want\nto see and do online, right? Anyway, I promised myself that I would never get\ninto a twitter argument ever again, and resorted to shitposting instead. [Bliss.][bliss]\n\n![](https:\/\/dergigi.com\/assets\/images\/bitcoin\/2026-05-20-careful-icarus\/me-before-onchain-zaps.jpg)\n\nBut yesterday[^fn-yd] I broke that promise, [getting into an argument][argument]\nwith Vitor on the topic of [\u0022on-chain zaps\u0022][onchain-zaps-proposal]. I consider\nVitor a friend, and I appreciate that he is pushing the boundary, as he always\ndoes. However, I think that encouraging users to associate on-chain activity\nwith their online identity is misguided at best, and actively harmful at worst.\n\nBefore I get into the \u0022why it\u0027s bad\u0022 part of it all I\u0027ll try to steelman Vitor\u0027s\narguments[^fn-gleason] as I understand them. In short:\n\n- Zaps are public anyway[^fn-zaps-public]\n- Lightning setup is complicated[^fn-npub-cash]\n- No setup required for on-chain, less friction for users[^fn-friction]\n- We have already built it and it works, so why not give users the option\n\nAs I\u0027ve mentioned in the [long back-and-forth thread][vitor-thread] with Vitor, I am not against\nthe *spirit* of the idea. I think that every npub should be able to send and\nreceive money with as little friction as possible, and have always been an\nadvocate for things like [npub.cash][npub-cash] \u0026 nutzaps ([NIP-60][nip-60]\/[NIP-61][nip-61]).\n\nWhat I want to speak out against is the proposed *implementation* of the idea,\nwhich encourages bad practices and has the potential to actively harm users in\nthe long run, for the sake of short-term \u0022convenience\u0022 and \u0022we can do it so why\nthe fuck not\u0022 I guess.\n\n![](https:\/\/dergigi.com\/assets\/images\/bitcoin\/2026-05-20-careful-icarus\/jp-poop.jpeg)\n\n## Careful, Icarus\n\nMy initial reaction to seeing the proposal was\n[\u0022careful, Icarus\u0022][careful-icarus] followed by [\u0022oh, that\u0027s a terrible idea\u0022][terrible-idea]\nright after - and it\u0027s my reaction still. Just because we can build something\ndoesn\u0027t mean we _should_ build something, as Jurassic Park was trying to teach us.\n\n\u003E Yeah, yeah, but your scientists were so preoccupied with whether or not they\n\u003E could that they didn\u0027t stop to think if they should.\n\u003E\n\u003E \u2014[Dr. Ian Malcolm][shit]\n\nBut why? Why did the alarm bells of my intuition go off so hard? Why can\u0027t I\nshut up about it and let Vitor and Alex have some fun to build this and play\naround with it? Because **I\u0027m pretty sure that people will end up using it and get\nterribly rekt**, that\u0027s why.\n\n\u003E I was immediately like Ummm... wtf?!! but I couldn\u0027t clearly articulate why it was so disturbing.\n\u003E\n\u003E \u2014[Silberengel]\n\nSame for me. I was incredibly disturbed, and couldn\u0027t readily articulate why\nthis supposed \u0022feature\u0022 made me so uneasy. So I am sitting down now in an\nattempt to write about it, which usually helps to structure my thoughts. And who\nknows, maybe some of the younglings will read it, or maybe some of the nostr\ndevs who don\u0027t know too much about bitcoin can learn a thing or two about [UTXOs][UTXOs]\nand stuff.\n\nLet\u0027s get into it.\n\n---\n\n## \u0022Zaps are public anyway\u0022\n\nYes, they are. Zaps are public. The balance of my lightning wallet is not\npublic, however. The history of the sats I received isn\u0027t public either, nor is\nthe future of said sats.\n\nI tried to make this point by posing the following questions: [\u0022All the zaps that\nI have received so far, what did I spend them on? Can you tell? Did I even move\nthose sats at all? Where did the sats go after I\u2019ve received them?\u0022][zap-questions]\n\nFurther, I could claim that I\u0027ve lost access to my wallet, and there wouldn\u0027t be\na way to prove that this isn\u0027t true. This type of [plausible deniability][pd]\ncompletely flies out the window in an on-chain world.\n\n## Revealing More Than Necessary\n\nTying bitcoin addresses to identities is what chainalysis companies do. And even\nthough their assumptions are based on heuristical witchcraft[^fn-anal] and should be taken\nwith a huge grain of salt, the unfortunate reality is that the legal system\ntakes said witchcraft seriously. We should make the job of chainalysis (read:\nspying on users) harder, not 100x easier.\n\n\u0022But zaps are public anyway!\u0022 Yes, they are, as I\u0027ve admitted above. But you can\nchoose to opt out, you can choose to zap privately, and your future financial\nactivity is not forever tied to your identity. All that goes away with on-chain\nzaps.\n\nI\u0027ll just go ahead and quote Lola, since she hit the nail on the head:\n\n\u003E Publicly tying your social media profile to one address forever is genuinely\n\u003E the biggest gift you could make to AML companies, ever. To get that money out\n\u003E without hurting the privacy of people you interact with you\u2018d need to jump\n\u003E through so many hoops that it defies the entire purpose of this legendary \u201eux\n\u003E upgrade\u201c in the first place.\n\u003E\n\u003E \u2014[L0la L33tz][lola]\n\nShe goes on to say, correctly, that right now, thanks to the Lightning Network, \u0022[zaps]\ndon\u0027t dox you and everyone else you interact with for the rest of eternity.\u0022 And\nas we\u0027ve already established above, \u0022when I cash out my zaps, nobody knows where\nthat money went to.\u0022\n\n\u0022Privacy is the power to selectively reveal oneself to the world,\u0022 to quote\n[a Cypherpunk\u0027s Manifesto][cypherpunk-manifesto]. Tying your identity to on-chain addresses not only nerfs\nthat power, but takes it away from the individual permanently.\n\nIn short: using on-chain addresses for zaps is a terrible idea _precisely\nbecause_ it reveals more than necessary. And to add insult to injury, it\nautomatically makes this oversharing permanent.\n\n### Bad for the Sender\n\nTo understand why \u0022on-chain zaps\u0022 are such a terrible idea you have to understand\nhow bitcoin works. And I mean how it _actually_ works. Not just a superficial\nunderstanding like \u0022my private key is my bank account\u0022 and related inaccuracies.\n\nThere is no \u0022bank account\u0022 in the first place, and there\u0027s no \u0022balance\u0022 either.\nThere\u0027s also no \u0022bitcoins\u0022 and there\u0027s no identity associated with transactions.\nThere are inputs and outputs, and some of the outputs are unspent. We call these\nunspent outputs\u2014surprise, surprise\u2014unspent transaction outputs, or [UTXOs].\nConceptually, if bitcoin would be a physical thing like gold is, you could think\nof them as lumps of material (or \u0022coins\u0022) of various sizes.[^fn-bitcoinium] All\nwe have is this unidirectional graph of transactions, and some neat cryptography\n(and [proof-of-work][pow]) to link them together. That\u0027s it.\n\nThe lack of identity in bitcoin is a feature, not a bug. Bitcoin is a\n_pseudonymous_ system by design, which means that it can be used privately if\nyou are careful about keeping your \u0022on-chain identity\u0022 separate from your other\nidentities (yes, plural[^fn-prismatic]).\n\nThe consequence of all that is the following: if I send onchain bitcoin to you in a naive way,\nyou can very easily \u0022spy\u0022 on me by following the trail of transactions. It\u0027s\nlike a loose string that you can pull on, and depending on your time, resources,\nand motivation, you might be able to unravel the whole fabric of my past\ntransactions. In other words: unless the sender is an educated bitcoin user who\nis well versed in bitcoin fundamentals and is adamant about UTXO hygiene and\n[privacy best practices], the person who is sending funds via an \u0022on-chain zap\u0022\nwill reveal _way more_ than they intended via the deceptively simple act of\n\u0022zapping\u0022 someone on-chain.\n\nAnd that\u0027s only half of the story. We only talked about unraveling the past, and\nwe only talked about the sender side. Knowing the on-chain address(es) of\nsomeone allows anyone to spy on them in perpetuity. This is a well-known issue,\nand was discussed on the [bitcointalk] forums way over a decade ago:\n\n\u003E Your inlaws can see that you\u0027re buying birth control that deprives them of\n\u003E grandchildren, your employer learns about the non-profits you support with money\n\u003E from your paycheck, and thieves see your latest purchases and how wealthy you\n\u003E are which helps them target and scam you. Poor privacy in Bitcoin can be a major\n\u003E practical disadvantage for both individuals and businesses.\n\u003E\n\u003E \u2014[Greg Maxwell][bitcointalk]\n\nYes, zaps are public, and that\u0027s the point. But what preceded a zap and what\nfollows it is _not_ public, and shouldn\u0027t be. It isn\u0027t public right now because\nzaps use the Lightning Network, which has certain privacy characteristics that\non-chain transactions do not (and will probably never) have.\n\nSo when I said that [\u0022Lightning is a sane default for zaps\u0022][sane-default]\nthat\u0027s what I meant. Lightning does _not_ allow you to spy on the financial\nactivity of the sender (or the receiver) in perpetuity.\n\nUsing on-chain addresses for zaps not only allows this, but it makes it trivial.\n\n### Bad for the Receiver\n\nYou just got zapped. Great. It was an on-chain zap. Not so great.\n\nWhat now? Well, the two basic options are \u0022do nothing\u0022 and \u0022do something.\u0022 Both\nare problematic, and here\u0027s why.\n\n**Do nothing:** If you don\u0027t move the money, everyone will see how much money\nyou have to your name, as was promptly demonstrated by \u0022[wrenchstr]\u0022, [rich list][rich-list], and other\nvibe-coded projects. You might not even know about the money, but by using\nyour nsec to sign messages (read: you simply using nostr, logging in to\nsomething, or pressing a like button here and there) proves without a shadow of\na doubt that you are still in control of your keys, i.e. the keys that can move\nthe money. Bad for users. Fantastic for criminals. A wet dream for prying eyes.\n\n**Do something:** You decide to move the money, which is to say: move the UTXOs\nthat are now associated with your nostr identity. Maybe you want to move them\nto your cold storage, or maybe you want to buy something online, or spend it at\na [merchant] directly, or maybe you want to send the money to a friend who\nisn\u0027t on nostr yet. Whatever you decide to do, absolutely everyone in the world\ncan follow the trail that these UTXOs leave behind. And some of the onlookers\nmight have the means _and_ the motivation to figure out what you did with your\nmoney, and use it against you.\n\nNone of the above is theoretical. For over a decade people have been robbed,\nextorted, kidnapped, or worse, just because other people thought (or knew) they\nhad bitcoin. I encourage you to read through the list of [known physical bitcoin\nattacks][lopp]. And since I\u0027m aware that people don\u0027t read, much less click links,\nhere are three highlights from the last ~18 months:\n\n- A couple and their 20-year-old daughter were violently held captive by a group of criminals searching for bitcoins. ([source][attack-seine-et-marne])\n- Three attackers invaded a home, tied up family, and made several bitcoin transfers. ([source][attack-la-rochelle])\n- A 38-year-old Chinese businessman was killed and found buried in the ground with his hands and feet bound with packing tape. ([source][attack-istanbul])\n\nThe list is very long. The above aren\u0027t the worst examples. I trust that you get the point.\n\n_[\u0022But zaps are already public! What are you worried about?\u0022][why-worry]_\nI hear you shouting in protest. Yes, they are, but let me paint you a picture:\nLet\u0027s say I\u0027m a criminal, and I \u0022on-chain zap\u0022 everyone on nostr. Some of my\ntargets will inevitably move their UTXOs to cold storage, potentially combining\nwhat I\u0027ve sent (and what I\u0027m now tracking) with their main stash. I have a\nscript running that notifies me of this (only if it\u0027s above a certain amount, of\ncourse). A couple of days later I get such an alert. **Jackpot.** Generational\nwealth. I rub my hands as I browse nostr for the latest posts of my unsuspecting\nvictim. Between memes and casual shitposts I find a link to a concert as well as\nan image they took on a stroll. There\u0027s a mountain range in the background. I\npaste the image into a [geolocation] engine. It matches the concert location\nalmost perfectly. I scroll further down and find multiple selfies and a photo of\ntheir dog. I now know where they live, what they look like, what their dog looks\nlike, and where they usually go to take their dog on a walk.[^fn-geolocation]\n\nDo you get it now? Do you finally understand why associating on-chain activity\nwith (nostr) identities is problematic? Do you understand why all of the above\nisn\u0027t an issue when using Lightning?\n\n![](https:\/\/dergigi.com\/assets\/images\/bitcoin\/2026-05-20-careful-icarus\/crazy-pills.gif)\n\nYes, zaps are supposed to be a public gesture (it is worth pointing out that\n[private zaps][private-zaps] do exist, however). But using on-chain for this\npublic gesture is so, so much worse. Offering it as an option to users is\nincredibly dangerous, because warning the users properly (explaining the risk\nproperly) is borderline impossible. You\u0027d have to warn them about the past.\nYou\u0027d have to warn them about the present. You\u0027d have to warn them about the\nfuture. You\u0027d have to warn them that any potential attacker has undeniable,\n_cryptographic proof_ that they, the target, are in possession of sats. You\u0027d\nhave to warn them that they can\u0027t plausibly deny this fact because of the\n[non-repudiation][nonrep] of digital signatures.\n\nI\u0027ve said it before, and I\u0027ll say it again: [plausible deniability matters.][deniability]\n\nThe fact that multiple nostr developers don\u0027t seem to get this point has me\nquestion my sanity. It also makes me question the supposed bitcoin expertise of\nsome of the people involved. I saw that some nostr users are even starting to\nquestion the intentions behind this supposed \u0022feature\u0022 in the first place, and I\ncan\u0027t blame them. I won\u0027t go there (yet), but if this nonsense doesn\u0027t stop soon\nI might be willing to.\n\nAnyway... There\u0027s more.\n\nThere\u0027s actually a third category, in addition to doing nothing or something,\nnamely _wanting to do something but not being able to_. Depending on output size\nand the current fee environment you might find yourself in a situation in which\nit\u0027s literally impossible to get rid of the money (because the UTXO you received\nis below the [dust limit][dust-limit]).\n\nThere are scenarios that make this problematic. Let\u0027s pick a ridiculous one, just\nfor fun. Imagine a mafia boss coming to your house, giving you money that was\nmade via illicit means. He vanishes instantly after, but not before leaving a\ntrail that leads directly to you. A trail that\u0027s very easy to pick up by the\npolice as well as other mafia people. To make things worse, you had no option to\nrefuse the money because the mafia boss is also a witch, and a spell was cast\nthat deposited the money directly into your soul. And even worse than _that_, he\ncast the _[Pulvis Assaultus]_ spell on top. Now the only way to rid your soul\nfrom the mafia witch dust is to throw more money at it.\n\nYes, a disappearing mafia witch is a ridiculous example, but I\u0027m trying to make a point. A more\nrealistic example would be someone sending money to you as well as to one (or\nmultiple) addresses on the [OFAC list], suggesting to law enforcement that you\nare part of a criminal network. Or publicly announcing that any money you\nreceive will be forwarded to every address on this list, possibly\nincriminating any sender (as well as yourself).\n\n### Bad for Everyone Else\n\nThe thing that triggered me most when I first saw this proposal implemented is\nthe fact that it\u0027s _mandating_ address reuse (by deriving a static address from\nan npub). Not only is this bad for the sender and the receiver, but also for\nother users that aren\u0027t even involved in this particular onchain transaction!\n\nRemember the UTXO model that we discussed above? The fact that there\u0027s actually\nno \u0022coins\u0022 in bitcoin, but only inputs and outputs? One of the consequences of\nthis model is that, given that the ledger is public, the only way to have _any_\nprivacy is to hide in the crowd.\n\nAddress reuse shrinks the crowd you can reasonably hide in.\n\nThis is bad. Really, really, really, bad. Or, to say it in a more fanciful way:\n\u0022The relationship graph in a re-used address is powerfully-linked in that\n**all** of the inputs to that address are necessarily joined (via the spending\nauthority of your private key) to all of its outputs.\u0022 That sentence has been in\nthe [bitcoin wiki] for over a decade. It goes on to say that, consequently,\n\u0022address reuse harms the privacy of not only yourself, but also others -\nincluding many not related to the transaction.\u0022\n\nIt also weakens the cryptography of the associated private key.[^fn-quantum]\n\nBad.\n\n## Removing Choice and Agency\n\nSo now let\u0027s get to the final point. \u0022We have already built it and it works, so\nwhy not give users the option?\u0022\n\nIt used to be that _curiosity killed the cat_, but in the internet age it might\nbe more accurate to say that _convenience_ killed the cat. And in today\u0027s day\nand age of vibe-coded slop (well, [slopified everything][slop], to be frank) it\nmight be more accurate to say that _velocity_ killed the cat.\n\nDon\u0027t get me wrong, I\u0027m a fan of high-agency activity and the \u0022you can just do\nthings\u0022 mentality. Always have been. But *there\u0027s a fine line between just doing\nthings and just doing damage to things*. I hate to see unsuspecting users get\nrekt, and if something insane like\nstatic-address-reuse-onchain-zaps-derived-from-npub ever gets widespread\nadoption,[^fn-adoption] we\u0027d be in a bad place.\n\nAs things are now, users are actively advertising how they can get zapped by\nputting a lightning address in their profile. What address to use is a\ndeliberate choice, and you can also choose to not have a lightning address set\nat all, effectively opting out of zaps. Users are free to put a lightning\naddress that is not under their control, and some users do, to either support\nsomeone else, or someone else\u0027s project, or a charity, etc.\n\nThis type of choice is removed entirely if clients make a deterministically\nderived address the default.\n\nI feel like a broken record when I keep saying that [money and identity aren\u0027t\nthe same thing][money-identity]. \u0022The whole point of money is to not know your\ncustomer,\u0022 to quote the [Italian comedian][italian-comedian] once more.\n\n![](https:\/\/dergigi.com\/assets\/images\/bitcoin\/2026-05-20-careful-icarus\/gigi-ln-address.png)\n\nThat said, I think it\u0027s fine to publicly state \u0022this is how you can send me\nmoney\u0022 - which is, in part, what Lightning zaps do. With the proposed\non-chain zap spec this transforms into something like \u0022this is my identity-bound\npayment info and _on top of that_ here are all my bank statements\u2014past, present, and\nfuture\u2014feel free to spy on all my financial activity forever.\u0022\n\nIn some sense this move is similar to relying _purely_ on biometrics as\nidentification, as opposed to passwords (or other secrets). Convenient, yes, but\nbiometrics are _public_, not private. They are usernames, not passwords. You\ncan\u0027t change them. Imagine someone scans your face and has deep insight into all\nyour finances. That\u0027s a problem, since changing your face is ... difficult.[^fn-ccc]\n\nI agree with Will that people who write software should abide by something like\nthe Hippocratic oath. [\u0022Primum non nocere.\u0022][hippocratic] First, do no harm.\n\nI tried to make this point with a ridiculous [\u0022surprise button\u0022][surprise]\nexample. I won\u0027t re-iterate it here.\n\nBut no, I don\u0027t think we should ship an extremely reckless feature to thousands\nand thousands of people just \u0022because we can.\u0022 That\u0027s ridiculous.[^fn-choice]\n\n## Silver Linings\n\nMy hope is that something positive will come from all of this. Tim is working on\nan [implementation that uses silent payments][tim-silent-payments], which would be a way to do this that isn\u0027t entirely insane, as I\u0027ve mentioned [over][silent-over-1] and\n[over][silent-over-2] and [over][silent-over-3] again. There\u0027s quite a bit of [prior work][prior-work] when it comes to nostr and silent payments, although the motivation and use-case for said prior work was a different one.\n\nWill, aka [jb55][jb55], aka the guy who brought zaps to nostr in the first place, made a similar point:\n\n\u003E onchain zaps don\u2019t need to be tied to an npub. You can do onchain zaps via\n\u003E silent payments (this is the proper way to do it, not the retarded current spec)\n\nHe also has a point about dust amounts:\n\n\u003E We can discourage people using dust amounts by automatically choosing lightning\n\u003E zaps for small amounts and onchain zaps over a certain limit.\n\nThat would get rid of unintended dusting, which is at least something. But it\nwon\u0027t get rid of malicious dust attacks.\n\nAt least there\u0027s some sanity to be found. The [discussion is ongoing][ants].\n\nSilent payments aren\u0027t a panacea either, mind you. They are [meant to be\nnon-interactive][non-interactive], as Calle pointed out. And on top of that they\nwill create on-chain transactions just the same, bringing fee pressure and\nbloating the UTXO set just the same.\n\nOne last thing: zaps and numerology go hand-in-hand. `21` sats here, `69,420` sats\nthere, palindrome zaps, etc. We can\u0027t do any of that if we hit the chain\ndirectly because broadcasting the exact amount would make it trivial for an\nattacker to identify the actual transaction. Which means any sane proposal would\nhave to use blinded or otherwise obfuscated amounts, destroying a large part of\nwhat makes zaps interesting.\n\nLong story short: zaps shouldn\u0027t touch the chain, and I should finally climb\ndown from [Mt. Stupid][mt-stupid] and go touch some grass. It was a nice\nexcursion. [Good night.][good-night]\n\n![](https:\/\/dergigi.com\/assets\/images\/bitcoin\/2026-05-20-careful-icarus\/mt-stupid.png)\n\n## TL;DR\n\nOn-chain zaps are bad, because:\n\n- They strongly link identity and money\n- They remove any and all plausible deniability\n- They provide full insight into a user\u0027s finances forever\n- They can\u0027t be disabled, revoked, denied, or redirected (dust)\n- They encourage horrible privacy practices for sender and receiver\n- They have negative effects on EVERYONE ELSE on the bitcoin network\n\n---\n\n[^fn-yd]: By now it isn\u0027t yesterday anymore, because it actually took me a couple of days to write this rant.\n[^fn-gleason]: The proposal is being pushed by Vitor and Alex, who are the lead developers of [Amethyst](https:\/\/opensats.org\/projects\/amethyst) and [Soapbox\/Ditto\/Shakespear](https:\/\/opensats.org\/projects\/soapbox), respectively.\n[^fn-prismatic]: [Identity is prismatic](\/names), and always will be.\n[^fn-bitcoinium]: I called this hypothetical material \u0022[bitcoinium](https:\/\/www.youtube.com\/watch?v=hq391_Vmq_E)\u0022 a very long time ago.\n[^fn-anal]: They even admit that chainalysis is [\u201cmore of an art than a science.\u201d](https:\/\/bitcoinmagazine.com\/technical\/chainalysis-investigations-lead-is-unaware-of-scientific-evidence)\n[^fn-adoption]: I\u0027m not saying that it will. Nostr doesn\u0027t have widespread adoption in the first place, and I doubt that educated users would ever use this. But then again: [how many users are educated on these esoteric topics?][educated-topics] And to make the point once more: the educated users can\u0027t even opt out of the receiving end of things.\n[^fn-quantum]: Listen to [Aaron and Sjors discuss address reuse](https:\/\/bitcoinmagazine.com\/technical\/for-better-security-do-not-reuse-bitcoin-addresses) to learn more. Quote: \u0022reusing Bitcoin addresses is a bad idea is because it opens up the possibility of some niche attacks. In certain cases, attackers could extract private keys from signatures after coins are first spent from an address \u2014 though this does require that a wallet implemented the signing algorithm incorrectly in the first place. There are also some potential future scenarios where quantum computers could extract private keys from signatures if addresses are reused. [...] attackers can potentially derive a private key from a wallet by closely monitoring how the computer that hosts the wallet behaves when signing a transaction. This attack is more plausible if addresses are reused.\u0022\n[^fn-geolocation]: Computers are really good at figuring out where a photo was taken, and have been for many years. I encourage you to [read some papers](https:\/\/scholar.google.com\/scholar?hl=en\u0026as_sdt=0%2C5\u0026q=geolocation+photos) like the one linked in the text, or simply look at [this image](\/assets\/images\/bitcoin\/2026-05-20-careful-icarus\/geolocation.png).\n[^fn-choice]: And don\u0027t hide behind the \u0022user choice\u0022 argument. It should be clear by now that onchain privacy is a rather esoteric topic with 2nd and 3rd order effects that aren\u0027t exactly easy to grasp, so how confident can we be that users would be able to make an educated choice in the first place? Would we be willing to give users the choice to switch back to plain http for everything, just because it\u0027s \u0022faster\u0022 and \u0022more convenient\u0022?\n[^fn-ccc]: The CCC showed this clearly a long time ago, by [reconstructing a fingerprint from a photograph](https:\/\/www.macrumors.com\/2014\/12\/29\/ccc-reproduce-fingerprints-public-photos\/). In short: politician waves at camera, highres photo is taken, finger can be 3d-printed. (I\u0027m simplifying, but you get the idea.)\n[^fn-zaps-public]: Vitor and Alex made this point multiple times, both on [nostr](https:\/\/ants.sh\/p\/npub1gcxzte5zlkncx26j68ez60fzkvtkm9e0vrwdcvsjakxf9mu9qewqlfnj5z?q=zaps+public) and on [github](https:\/\/github.com\/nostr-protocol\/nips\/pull\/2332#issuecomment-4409095253).\n[^fn-npub-cash]: Setting yourself up with a Lightning wallet isn\u0027t that complicated. I won\u0027t defend this point; I reject the premise. Users are free to set their lightning address to `@npub.cash` for example, which makes them zappable instantly, as [pointed out](https:\/\/njump.to\/nevent1qqs8njmr5jjcpgejzxv88pglsqps8amrfygc8t2x6zdfhzxmkfmhwzc20g899) by Calle and others.\n[^fn-friction]: As evidenced by this [response to one of my comments](https:\/\/github.com\/nostr-protocol\/nips\/pull\/2332#issuecomment-4506775013), the supposed friction that this proposal tries to reduce is added tenfold at the end of the journey, i.e. once users want to spend (or move) their on-chain funds.\n\n[terrible-idea]: https:\/\/njump.to\/nevent1qqs23jpquykrlg2psqhyhhxzn06nmf3dr6yejwvgws0733x8d9vgnugqfuqeq\n[vitor-thread]: https:\/\/njump.to\/nevent1qqstjywhdd3kt2pwxlnpd3yyd2hflkn7xqtm8lqrkqe0fv7k5dt4wwcyxsyns\n[zap-questions]: https:\/\/njump.to\/nevent1qqsfjeexuf2fctl2xsquvt4sts0zfdaml67tkemsw9x9znagz2zrslswh3ng2\n[educated-topics]: https:\/\/njump.to\/nevent1qqspgfn5rf7d3q6k3dx9rlfxdag37nxq0gt4y6xa6kyrsm6unhhlyxscnd33h\n[cypherpunk-manifesto]: https:\/\/nakamotoinstitute.org\/library\/cypherpunk-manifesto\/\n[npub-cash]: https:\/\/npub.cash\/\n[nip-60]: https:\/\/github.com\/nostr-protocol\/nips\/blob\/master\/60.md\n[nip-61]: https:\/\/github.com\/nostr-protocol\/nips\/blob\/master\/61.md\n[onchain-zaps-proposal]: https:\/\/github.com\/nostr-protocol\/nips\/pull\/2332\n[algorithm]: https:\/\/youtu.be\/4usXBGvufKg\n[argument]: https:\/\/youtu.be\/ohDB5gbtaEQ\n[italian-comedian]: https:\/\/www.youtube.com\/watch?v=zp1B_i4JlXc\u0026t=1401s\n[shit]: https:\/\/youtu.be\/nnun8y7r8_U\n[UTXOs]: https:\/\/opensats.org\/topics\/utxo\n[pow]: \/pow\n[privacy best practices]: https:\/\/jamdocs.org\/privacy\/02-best-practices\/\n[bitcointalk]: https:\/\/bitcointalk.org\/?topic=279249\n[Pulvis Assaultus]: https:\/\/opensats.org\/topics\/dust-attack\n[dust-limit]: https:\/\/bitcoinops.org\/en\/topics\/uneconomical-outputs\/\n[merchant]: https:\/\/btcmap.org\/\n[lopp]: https:\/\/github.com\/jlopp\/physical-bitcoin-attacks\n[attack-seine-et-marne]: https:\/\/www.rtl.fr\/actu\/justice-faits-divers\/info-rtl-cryptomonnaies-une-nouvelle-famille-sequestree-en-seine-et-marne-7900599500\n[attack-la-rochelle]: https:\/\/www.leparisien.fr\/faits-divers\/un-investisseur-en-cryptomonnaie-et-sa-compagne-sequestres-a-leur-domicile-de-la-rochelle-des-virements-effectues-par-les-ravisseurs-18-12-2025-KN6YFKOQ2NCCPEGXLZP2ZTYX4A.php\n[attack-istanbul]: https:\/\/en.haberler.com\/pure-chinese-torture-what-they-did-to-the-19596022\/\n[money-identity]: \/2022\/12\/02\/bitcoin-is-the-rediscovery-of-money\/#:~:text=Money%20doesn%27t%20require%20identity\n[bitcoin wiki]: https:\/\/en.bitcoin.it\/wiki\/Address_reuse#:~:text=The%20relationship%20graph%20in%20a%20re%2Dused%20address%20is%20powerfully%2Dlinked%20in%20that%20all%20of%20the%20inputs%20to%20that%20address%20are%20necessarily%20joined%20(via%20the%20spending%20authority%20of%20your%20private%20key)%20to%20all%20of%20its%20outputs.\n[ants]: https:\/\/ants.sh\/?q=%22onchain+zaps%22+OR+%22on-chain+zaps%22\n[good-night]: https:\/\/ants.sh\/?q=GN+by%3Adergigi.com\n[bliss]: https:\/\/ants.sh\/?q=%23yestr+by%3Adergigi.com\n[mt-stupid]: https:\/\/njump.to\/nevent1qqsf4mvtz8vc523esz99w367ejtwcx0uvn9g07tfux6szafk0s6qv6g74h3h5\n[OFAC list]: https:\/\/github.com\/0xB10C\/ofac-sanctioned-digital-currency-addresses\n[why-worry]: https:\/\/github.com\/nostr-protocol\/nips\/pull\/2332#issuecomment-4409095253\n[geolocation]: https:\/\/openaccess.thecvf.com\/content_ECCV_2018\/papers\/Eric_Muller-Budack_Geolocation_Estimation_of_ECCV_2018_paper.pdf\n[pd]: https:\/\/ants.sh\/p\/dergigi.com?q=plausible%20deniability\n[nonrep]: https:\/\/en.wikipedia.org\/wiki\/Non-repudiation\n\n[slop]: \/sloppypasta\n[sane-default]: https:\/\/njump.to\/nevent1qqsy77qjawrvj4u7kn9fqz2jpjx4us4yatfv5x94exzl2kjj30zshvqx0qg9k\n[Silberengel]: https:\/\/njump.to\/nevent1qqspewuufmdq0qurwdmn6d2egz2jrspvzzg0lekke44wrmsx505ls2c0a3pwy\n[wrenchstr]: https:\/\/njump.to\/nevent1qqsg3g529nmvwd82s0a2gn08t4j7t8cj0mcrk3u0encrf28u3fv2k3gqpl0uq\n[rich-list]: https:\/\/richlist.jskitty.cat\/\n[lola]: https:\/\/njump.to\/nevent1qqspwvnz2vg6dgctp8p55x2qxqgtendk6l0tlhxqspd9gxz3khhj5us65qv6e\n[silent-over-1]: https:\/\/njump.to\/nevent1qqsd78wku5u3zts6dxncuupghrwn4hcyfrw8ksf3r24kv90e092dt7qxc37e0\n[silent-over-2]: https:\/\/njump.to\/nevent1qqsyj4yfnfvuf99za5t5sznvvpvf028azp7gjdzfgfg0j3rztczf99cuckc9m\n[silent-over-3]: https:\/\/njump.to\/nevent1qqsyk4dputscupm9l6k2y9hm9ytp0738dazenhrhvucw637w8k79hwceasw8p\n[jb55]: https:\/\/njump.to\/nevent1qqsqxep0pgs27mdk9r7pq8adz0kmfzkm8y3w7myd3djaxl80z5r2qdc5zkf62\n[tim-silent-payments]: https:\/\/njump.to\/nevent1qqs9g38wpxsxj25axpgqevd8xkf4mnmkx5w5ftjvuh8rr5kas9r62csa48x96\n[prior-work]: https:\/\/njump.to\/nevent1qqsdqs3ymew7sr29tfv2ya3srd05kahu40dqs3hgvmyfqnlgxl7jyrgth0eku\n[private-zaps]: https:\/\/njump.to\/nevent1qqs88g2aj6jrg4xpk9mpm66rklxvmh3u9hjx3mymnyr6udnw9upflsqjvw388\n[non-interactive]: https:\/\/njump.to\/nevent1qyvhwumn8ghj7un9d3shjtnndehhyapwwdhkx6tpdshsz9nhwden5te0dp5hxapwdehhxarj9ekxzmny9uqsuamnwvaz7tmwdaejumr0dshsz8nhwden5te0dehhxarj94c82c3wwajkcmr0wfjx2u3wdejhgtcppemhxue69uhhjctzw5hx6ef0qyg8wumn8ghj7mn0wd68ytnddakj7qpqntkckywe3g4rnqy22ar4anykasvlcex2slukncd4q96nvlp5qe5se7u5st\n[deniability]: https:\/\/njump.to\/nevent1qqsd78wku5u3zts6dxncuupghrwn4hcyfrw8ksf3r24kv90e092dt7qxc37e0\n[careful-icarus]: https:\/\/njump.to\/nevent1qqsxyj06e8rjht0ncyhnnk97dh2x604vldd9lsjrfje9j64nfzn208spz9mhxue69uhkummnw3ezuamfdejj7q3qdergggklka99wwrs92yz8wdjs952h2ux2ha2ed598ngwu9w7a6fsxpqqqqqqzv62aje\n[hippocratic]: https:\/\/njump.to\/nevent1qqsfp2wrgxp3uf7c0vumlyynqtpzarrswdps43ed0y0tfk7dgnaphcch48299\n[surprise]: https:\/\/njump.to\/nevent1qqsfaf7sfcpvduckuypgta2cyhr5zwum2k0rezkvtjeldnmgfm7thvswl6ujz\n\n---\n\nThis article first appeared on [dergigi.com](https:\/\/dergigi.com\/2026\/05\/20\/careful-icarus\/).","image":"https:\/\/dergigi.com\/assets\/images\/on-chain-zaps.jpg","pubkey":"6e468422dfb74a5738702a8823b9b28168abab8655faacb6853cd0ee15deee93","kind":30023,"createdAt":"2026-05-22T15:40:15+00:00","publishedAt":"2026-05-19T22:00:00+00:00","topics":["nostr","lightning","writing"],"url":"https:\/\/www.decentnewsroom.com\/mag\/newsroom-magazine-on-imwald-by-laeserin-category-economy\/cat\/newsroom-magazine-on-imwald-by-laeserin-category-bitcoin\/d\/careful-icarus"}]}],"chapters":[],"stats":{"totalCategories":1,"totalArticles":4,"totalChapters":0}}