The Defence That Halves

2026-07-26 · 3,669 words · Singular Grit Substack · View on Substack

A chain is only as hard to rewrite as this fortnight’s electricity bill. That bill is set by a subsidy that halves every four years, against an attack cost that halves every eighteen months. =

The Defence That Halves

A chain without large transaction bills is only as hard to rewrite as this fortnight’s electricity bill. That bill is set by a subsidy that halves every four years, against an attack cost that halves every eighteen months. The two clocks are not close.


I. Nothing is stored

There is a sentence that gets repeated so often it has stopped being examined: proof of work makes the ledger expensive to attack.

It is the wrong way round. Proof of work makes nothing expensive. It converts an expense into a defence, and the expense comes from somewhere else entirely.

Consider what difficulty actually does. Every 2,016 blocks — roughly a fortnight — the network measures how fast blocks arrived and adjusts the target so that the next 2,016 arrive at ten-minute intervals. Whatever hashpower is present, the interval is restored. If half the miners switched off tomorrow, blocks would come slowly for a fortnight and then resume at ten minutes with half the hashpower behind them. Nothing about the protocol would be violated. Confirmations would look identical. Every cryptographic property would hold.

What would change is the cost of rewriting history, and it would fall by half.

So the expenditure is not produced by the algorithm. It is produced by the payment. Miners spend what they are paid, competed to the margin by free entry: positive profits attract hashpower, difficulty rises, profits vanish. In aggregate, expenditure equals revenue. Halve the revenue and you halve the expenditure, halve the hashpower, and halve the cost of overwriting the chain — while the block interval sits exactly where it was.

The formal version is a rent-seeking contest. A miner holding some share of total hashpower wins blocks in that proportion and pays a flow cost proportional to what she holds. Setting the derivative of her profit to zero and letting the number of participants grow gives the marginal condition: revenue divided by hashpower equals unit cost. Multiply through and aggregate expenditure equals aggregate revenue. Difficulty appears nowhere in that calculation. It enters only as a proportionality constant linking the target to total hashpower, and it drops out. The algorithm determines the block interval. It does not determine the spending.

This means difficulty is not a store. It is a readout. It tells you what miners are being paid right now, refreshed every two weeks. There is no accumulated security in a chain, no reservoir filled by fifteen years of hashing. There is only this period’s spending, repeated. A chain mined for a decade is not harder to rewrite than one mined for a month at the same rate.

One qualification, and it runs in the conservative direction. Miners are not identical. Some have cheaper power, better hardware, older debt. Under heterogeneous costs the zero-profit condition binds only at the margin, and inframarginal operators earn rents that never become expenditure. So aggregate spending is less than aggregate revenue, and every figure below overstates what the network actually lays out in its own defence.

Which raises the only question that matters: what is the payment, and where is it going?

II. What was actually specified

The payment has two parts. One of them is scheduled to disappear.

The block subsidy halves roughly every four years and terminates. This is not an accident or a bug or a thing that might be revisited. It is the issuance schedule, and it is the mechanism by which twenty-one million becomes a hard number rather than an aspiration.

Satoshi was explicit about what replaces it. Section 6 of the white paper says that once a predetermined number of coins have entered circulation, the incentive can transition entirely to transaction fees. Not partly. Not as a supplement. Entirely.

That is a specification, and it is worth reading it as one. The subsidy was scaffolding. The fee market was the building. The design contemplates a network paid by the people who use it, with the subsidy as a temporary bridge from a network nobody uses to a network everybody does.

It is also, read carefully, a throughput specification that was never written down as one. If the terminal incentive is fees, and fees are paid per transaction, then the security budget in steady state is the number of transactions multiplied by what each pays. Satoshi named the mechanism and left the magnitude unstated. The magnitude is what the arithmetic below supplies, and it is the reason the sentence matters more than it looks.

So the question of whether BTC can fund its own security is not a question about market conditions or adoption curves. It is a question about whether the fee market arrived. And the fee market did not arrive, because in 2010 a limit was placed on how large a block could be, and that limit has never been removed.

III. The decision that has already been made

The one-megabyte cap entered the codebase as a temporary measure against spam. It has been in place for fifteen years.

Retaining it is not a neutral act. Fee revenue can rise in exactly two ways: more transactions, or a higher price per transaction. The cap forecloses the first by construction. And the second is foreclosed by what a fee actually purchases.

A transaction fee does not pay for security, and it does not pay for value transferred. It pays for a position in a queue. When blocks are full, users bid against each other for inclusion, and what they are bidding on is delay. The formal treatment — Huberman, Leshno and Moallemi in the Review of Economic Studies — shows that total fee revenue depends on capacity, congestion, and the distribution of how much users dislike waiting. It does not depend on the exchange rate. Easley, O’Hara and Basu reach the same comparative static from an entirely different model of miner and user strategy.

Sit with what that means. A ledger securing one trillion dollars and a ledger securing one billion face the same congestion market. The fee does not rise because the thing being protected became more valuable. It rises when the queue is long and falls when it is short, and the queue length is bounded by a constant set in 2010.

There is a further consequence people skip. Because the fee prices delay rather than value, the ceiling on what anyone will pay is set by the outside option — how much worse it is to settle somewhere else — and not by how much is at stake. Push the fee high enough and users do not pay grudgingly; they leave, and the base leaves with them. So raising the level does not raise the revenue past a point. It relocates the users.

This is why the “we could just raise the limit” response does not do the work people expect. It is not that the option is unavailable in principle. It is that the option has already been exercised, and the answer was no.

The capacity question was the central dispute of 2015 to 2017, and it was not settled by argument. It was settled by separation. The chains that raised the limit forked away in August 2017 and again in November 2018. The chain that kept the limit is the one now trading under the ticker. The people who wanted larger blocks did not lose a vote and stay; they left, and they took their capacity with them.

So the population holding BTC today is precisely the population that chose the limit with both options in front of it, and has maintained that choice for eight further years through visible backlogs and fee spikes that made the constraint impossible to miss. Whatever else you think of that process, its outcome is a revealed preference at exactly the decision point in question, expressed by fork rather than ballot, and repeated.

And the scale of the reversal now required is not the scale that was declined in 2017. Funding the 2036 requirement from fees needs 894 transactions a second at a fifty-dollar fee, or 44,720 at a dollar. Those are 134 and 6,705 times the present limit — blocks of 134 megabytes and 6.7 gigabytes. By 2045 the multiples run from eight thousand to four hundred thousand. Segregated witness, the change that did happen, delivered a factor of two to four. What would be needed is not an amendment to the design. A chain processing gigabyte blocks is a different system running the same ticker.

The declared roadmap since has been off-chain. Which brings us to the part that runs backwards.

IV. Layer two subtracts

Payment channels are presented as the answer to capacity: transactions move off the base layer, throughput rises, everyone is served.

For the security budget this is not neutral. It is negative.

A transaction settled in a channel is a fee that never reaches a miner. The value being moved still rests on base-layer security — that is the entire point of anchoring — but the payment for that security has gone somewhere the miners cannot collect it. Layer two relocates the transactions that would have funded the defence without relocating what needs defending.

So the scaling story and the security story are in direct conflict. Every transaction successfully moved off-chain is a subtraction from the fee base that was supposed to replace the subsidy. Scaling by these means shrinks the security budget rather than growing it, which is the opposite of what the fee transition requires.

It is worth being precise about why anchoring does not rescue this. A channel is opened and closed on-chain, so it pays two fees for an arbitrary number of transactions in between. That is the efficiency claim, and it is true. But it is also the problem: the ratio of value settled to fees collected rises without limit, which is exactly the direction that starves the defence. The more successful the layer, the smaller the budget protecting what it depends on.

V. Moore’s law is about cost

Now the other clock.

Moore’s law is usually recited as a statement about speed. It is a statement about cost: the same money buys a more capable machine, with capability per dollar roughly doubling every eighteen months.

Apply that to a chain. The honest network’s fleet was accumulated over years, at the prices prevailing when each machine was bought. An attacker assembling equivalent hashpower buys today, at today’s prices. So the dollar cost of matching the installed fleet falls by half every eighteen months, entirely without anyone doing anything.

Standing still therefore costs more every year. To keep the chain exactly as hard to attack as it was, the fleet has to double every eighteen months just to offset the falling price of the hardware that would attack it.

Does the electricity double too? Only if energy per hash improves more slowly than cost per hash — and it does. Dennard scaling ended in the mid-2000s. Transistor density and cost per operation kept improving; power per transistor stopped. That gap is the whole mechanism, and it is worth being blunt that it is the one assumption the argument rests on. If energy per hash fell at the full cost rate, the electricity requirement would be flat and none of what follows would hold.

There is a second feature worth naming, because it is where the asymmetry lives. Cheaper hardware does not lower the miner’s bill. Miners spend what revenue permits and no more. What falling prices buy them is a larger fleet at the same electricity spend — not a smaller spend. The improvement flows to the attacker as a discount and to the defender as volume.

VI. The numbers

Take the most generous price path anyone seriously defends: one million dollars a coin in 2030, thirteen million in 2045. That is 18.65 per cent a year, compounded for seventeen years.

Set the electricity share of miner outlay at sixty per cent, power at four cents a kilowatt-hour, and index security to 1.00 in 2028, just after the next halving.

year price coins/yr revenue electricity needed security 2028 $0.71m 82,125 $58.3bn 875 TWh 875 TWh 1.0000 2030 $1.00m 82,125 $82.1bn 1,232 TWh 2,205 TWh 0.5587 2032 $1.41m 41,062 $57.8bn 867 TWh 5,556 TWh 0.1561 2036 $2.79m 20,531 $57.3bn 859 TWh 35,280 TWh 0.0244 2040 $5.53m 10,266 $56.8bn 851 TWh 224,017 TWh 0.0038 2045 $13.00m 5,133 $66.7bn 1,001 TWh 2,257,949 TWh 0.0004

Look at the revenue column first. It does not move. Eighteen years, a coin appreciating eighteenfold, and miner revenue oscillates between fifty-six and ninety-seven billion dollars.

The reason is arithmetic. Price grows at 18.65 per cent a year. Issuance decays at 17.33 per cent a year. Net growth is 1.3 per cent. The price path and the halving schedule very nearly cancel, and what is left is a flat line with a sawtooth in it.

Now look at the last column. Security falls to 0.42 by 2031, then 0.156, then 0.024, then 0.0038, then 0.0004. By 2045 the chain is roughly two thousand times cheaper to attack than it was in 2028 — on a price path that made the coin eighteen times more valuable.

Every four years the halving takes another factor of two off the top, and price growth of 18.65 per cent cannot make it back before the next one arrives. It is a staircase with no landing above the previous step.

VII. The other branch is not expensive. It is impossible.

There is, formally, a second outcome. The chain could simply spend what is required.

Holding security at 1.00 means the budget doubles every eighteen months: $222bn a year by 2032, $1,411bn by 2036, $90,318bn by 2045. At four cents a kilowatt-hour those are 5,556 TWh, 35,280 TWh, and 2,257,949 TWh.

World generation is about 31,734 TWh and rises by roughly 822 TWh a year — a real quantity, built by physical projects with permits and lead times, growing at around two per cent.

So the requirement is 14.8 per cent of world electricity in 2032, 86.5 per cent in 2036, and forty-seven times world generation in 2045. The curves cross in 2036.

That is not an expensive branch. It is a branch that does not exist. And the crossing is remarkably insensitive to how you project the denominator: hold generation flat and it is 2035.8, compound it at three per cent and it is 2036.5. Under a year of variation, because the requirement grows at 58.7 per cent annually while no plausible denominator grows above three.

So the branch where the chain stays as hard to attack as it is today is unavailable, and what remains is the declining column.

VIII. Renting

The first objection anyone raises: why buy hardware when you can rent it?

It deserves a real answer, because the two metrics give wildly different results. Rental prices track the current cost of hashing, so on a pure-rental measure the Moore term cancels entirely and the security index is roughly flat. Buying and renting differ by a factor of 2,580 by 2045. That is not a detail to be waved past.

The numbers are stark. Renting a majority share for a day costs around $82 million in 2028, against $121 billion to purchase the same share — cheaper by a factor of 1,481. Measured against what is being protected, the rental figure is 5.7 parts per million of market capitalisation in 2028, and 0.34 parts per million by 2045.

If those figures were attainable, the argument here would be understated rather than wrong. A ledger holding $271 trillion that can be attacked for $93 million is not a borderline case.

What stops it is depth, not price. Rentable hashpower is a small fraction of network hashrate, and an attacker trying to assemble a majority would move the rental price against himself long before getting there. The binding constraint on renting is quantity; the binding constraint on buying is capital. And for any attack shorter than a month, capital dominates flow cost by better than ninety-nine to one — a one-day attack is 99.98 per cent capital.

So the purchase metric is the right one, and it is also the one most favourable to the chain. It is the reading under which security is highest and the decline slowest. The rental route says something worse.

Which carries a condition worth stating plainly: this result depends on rental depth staying thin. A market deep enough to supply a majority would collapse the cost of attack to the flow figures above, immediately and independently of anything about subsidies or halvings — and would be a more urgent problem than the one described here.

IX. Where the money goes

Set the security question aside and follow the cash.

Proof of work produces no output. The computation has no use beyond being expensive; hashes are a cost signal and nothing else. Nothing is manufactured. Five to seven transactions a second are the occasion for the expenditure, not its product.

Miners receive that revenue and must sell coins to pay for electricity and hardware. So the revenue is forced selling, absorbed each year by new buyers. Since nothing is produced, aggregate holder gains equal aggregate later-entrant payments minus what miners consume. There is no third source of return.

Between 2028 and 2045, on the path above, $1,335 billion moves from new entrants to miners, of which $801 billion is burned as electricity. It is effected by the sale of 626,203 newly issued coins at an average absorption price of $2.13 million — and that inflow is required simply to hold the price level.

Two magnitudes have to be kept apart here, and conflating them is how this argument usually goes wrong.

Against the pool, the outflow is small and shrinking: 0.411 per cent of market capitalisation in 2028, falling to 0.025 per cent by 2045 as issuance halves against a capitalisation rising from $14.2 trillion to $271 trillion. A quarter of a basis point a year. Trivial.

Against what it buys, the same outflow is enormous. Security falls from 1 to 0.0004 across the identical window. By 2045 the system consumes a quarter of a basis point of its own capitalisation every year and receives four ten-thousandths of the defence it had in 2028.

On the payment structure: of the three elements by which a Ponzi arrangement is ordinarily identified, one holds and two do not. Payment of earlier participants from the funds of later ones follows exactly from the identity above. But there is no promoter and no representation that returns arise from a business, so the term does not apply in its statutory sense and should not be used. What is shared is the payment structure alone. What differs is that the outflow here is a published protocol parameter rather than an operator’s discretionary cut — mandatory, visible, and the very mechanism by which the arrangement is supposed to be secured.

X. The lower path is worse

Anyone reading thirteen million dollars a coin as absurd is entitled to that view. It is worth knowing what it costs them.

Lower the terminal price and security gets worse, not better. A slower path delivers less revenue growth against an unchanged requirement. At a five-million terminal, the 2045 index is 0.00019 rather than 0.00044. Flat from 2030 onward, it is 0.00005.

Discard the million-dollar anchor entirely and grow today’s price forward at twenty per cent a year, and 2045 arrives at $1.86 million with an index of 0.00054. At ten per cent: $374,000 and 0.00012. Held flat at today’s price: 0.00002.

The aggressive path was chosen because it is the most favourable of the set. Reject it, and you inherit a worse number.

What the price scenario actually determines is the date of the crossing and the level of the electricity columns — not whether the index collapses. That happens on every path.

XI. One dichotomy, no interior

The energy debate and the security debate have been conducted separately for a decade. One is about externalities; the other about incentives after the subsidy ends.

They are one object seen twice. The electricity is what leaves the system. The security is what it was meant to purchase.

And what remains is a dichotomy with nothing between the horns.

Either the fee base grows with the requirement — which needs throughput the design forbids and the community has twice declined to provide — or security declines at the rate in the table.

There is no third option, because there are only two terms that can raise fee revenue. Capacity is fixed by the block limit. Price is bounded by the delay the marginal user will tolerate, and that bound does not widen when the ledger becomes more valuable.

A chain that will not scale cannot fund its own defence. The arithmetic sets the rate.


Full derivations, proofs, sensitivity grids over the doubling interval and hardware efficiency, the attack-cost bracket, and the replication package: zenodo.org/uploads/21585743


References

Budish, E. (2025). Trust at scale: the economic limits of cryptocurrencies and blockchains. Quarterly Journal of Economics, 140(1), 1–62.

Carlsten, M., Kalodner, H., Weinberg, S. M., & Narayanan, A. (2016). On the instability of Bitcoin without the block reward. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, 154–167.

Dennard, R. H., Gaensslen, F. H., Yu, H.-N., Rideout, V. L., Bassous, E., & LeBlanc, A. R. (1974). Design of ion-implanted MOSFETs with very small physical dimensions. IEEE Journal of Solid-State Circuits, 9(5), 256–268.

Easley, D., O’Hara, M., & Basu, S. (2019). From mining to markets: the evolution of bitcoin transaction fees. Journal of Financial Economics, 134(1), 91–109.

Gill, M., Stinner, J., & Tyrell, M. (2026). Bitcoin’s productivity trap. Energy Economics, 161, 109505.

Huberman, G., Leshno, J. D., & Moallemi, C. (2021). Monopoly without a monopolist: an economic analysis of the Bitcoin payment system. Review of Economic Studies, 88(6), 3011–3040.

Moore, G. E. (1965). Cramming more components onto integrated circuits. Electronics, 38(8), 114–117.


← Back to Substack Archive