The Written History of Bitcoin: The Bitcoin Civil War Heats Up
By Kurt Wuckert Jr.
The Button
"...Allowed buyers to take back payments they'd made after walking out of shops, by simply pressing a button."¹
That is not a description of a bug.
That is a "feature." It was deliberately added to Bitcoin in early 2016 by a small group of developers who, according to one of the protocol's most senior early architects, "don't care what other people think."²
The line comes from a letter. The letter was published on January 14, 2016, by a British software engineer named Mike Hearn, who had spent more than five years writing Bitcoin code used by millions of people. He had talked about Bitcoin on the BBC. He had explained it to the SEC. He had been one of Satoshi Nakamoto's last documented correspondents. And on that January morning he sat down and wrote the most damning document in the history of open source governance, a public autopsy of a system he had helped build, and then he did the thing that turned the letter from an opinion into an event.
He sold all of his coins.³
Part 5 ended in a quiet suburb on the north shore of Sydney harbor, with the Australian Federal Police walking through the front door of a house in Gordon, New South Wales, looking for a man named Craig Wright. The house was empty. We told you then that we were not going to publish Mike Hearn's farewell letter in that article, because by the chronology of the story he had not written it yet. We told you it would appear in January 2016, and that it would detonate Part 6.
Here we are. The fuse has burned down.
This is the story of the year and a half that broke Bitcoin in half. It is the story of an anonymous man who said his day job was intelligence and who paid a developer to make Bitcoin's payments reversible. It is the story of how a piece of software quietly became a government. It is the story of the most senior developer Satoshi ever trusted getting locked out of the building Satoshi built, within hours of saying the wrong name out loud. It is the story of a man who walked to a microphone in London, tried to prove he was Satoshi Nakamoto, failed in front of the cameras, and was later found upstairs bleeding from a self-inflicted wound across his neck.
And it is the story of a peace treaty signed by companies controlling more than eighty percent of the network, strangled in its crib by the handful of people who refused to sign it.
By August 1, 2017, the chain splits.
You already know which side kept the name. Let's find out how.
Watch the video if you prefer to watch rather than read!
The Farewell Letter
Mike Hearn titled it "The Resolution of the Bitcoin Experiment."⁴ He did not bury the thesis.
"Why has Bitcoin failed? It has failed because the community has failed. What was meant to be a new, decentralised form of money that lacked 'systemically important institutions' and 'too big to fail' has become something even worse: a system completely controlled by just a handful of people."⁵
That is the whole next decade in two sentences. The promise of Bitcoin, the entire reason it was interesting, was that no small group of people could control it. Hearn's claim, from inside the room, was that by January 2016 a small group of people controlled all of it.
He was specific about the size of the group.
"Bitcoin has no future whilst it's controlled by fewer than 10 people."
And he was specific about why the situation was worse than it looked from outside. He said the network itself, not the companies and exchanges around it but the protocol at the center, was breaking.
"the network is on the brink of technical collapse."

To understand why a man who had given five years of his life to this project was now declaring it dead, you have to understand who he blamed. And here Hearn named a name we have been tracking since Part 3.
"One of them, Gregory Maxwell, had an unusual set of views: he once claimed he had mathematically proven Bitcoin to be impossible."⁶
Maxwell was, by 2016, the Chief Technology Officer of Blockstream, the Canadian company we traced through its investor list in Part 4B, the company funded by Reid Hoffman, by the venture arm of the world's largest insurer, and by a vehicle controlled by Jeffrey Epstein. Hearn's account of how Maxwell's company changed the views of the developers it hired was blunt. He said Maxwell "founded a company that then hired several other developers," and that "not surprisingly, their views then started to change to align with that of their new boss."
And what was the boss's view? Hearn quoted it. Maxwell, he wrote, had concluded that Bitcoin should stop being a payment network and become instead "a sort of settlement layer for some vaguely defined, as yet un-created non-blockchain based system."⁷
Hold onto that phrase, "settlement layer." It is going to come back, and when it comes back it will be wearing a different costume and answering to a different name. But the idea is already here, in January 2016, stated plainly: stop letting people use Bitcoin as cash, and turn it into a slow, expensive base that other systems settle against occasionally. Every architectural fight in the rest of this article is downstream of that single idea.
Then Hearn described the war that had been fought to install it.
You will remember from Part 5 that in August 2015, Hearn and Gavin Andresen released a bigger-block Bitcoin client called Bitcoin XT, and that the nodes running it were knocked off the internet by distributed denial-of-service attacks. What Hearn documented in the letter was the scale of those attacks, and it is genuinely difficult to read in 2026 and remember that this was a fight over the size of a data structure.
"It was a massive DDoS that took down my entire (rural) ISP. Everyone in five towns lost their internet service for several hours last summer because of these criminals."⁸
Five towns. Not five websites. Five towns lost their internet because someone wanted a node offline.
He went further.
"entire datacenters were disconnected from the internet until the single XT node inside them was stopped. About a third of the nodes were attacked and removed from the internet in this way."
And he named the message that the attacks were designed to send.
"the mining pool that had been offering BIP101 was also attacked and forced to stop. The message was clear: anyone who supported bigger blocks, or even allowed other people to vote for them, would be assaulted."
Alongside the denial-of-service attacks ran the censorship campaign we documented in Part 5, the one administered by the forum operator Theymos. Hearn's framing of it was that an open community had been converted into a closed one in under a year.
"Massive numbers of users were expelled from the forums and prevented from expressing their views."⁹
"Dissenting views are being systematically suppressed."
He noted that Coinbase, then the largest Bitcoin company in the United States, had been "erased from the official Bitcoin website for picking the 'wrong' side and banned from the community forums." He quoted the governing philosophy of the people running those forums, a line that should make the hair on your neck stand up if you ever believed Bitcoin was about freedom: "One of the great things about Bitcoin," they said, "is its lack of democracy."¹⁰
This is the part that turned practical, and it is the source of the cold open of this article.
In February 2016, a change shipped in Bitcoin Core version 0.12 called opt-in Replace-by-Fee.¹¹ We will get into the politics of who paid for it shortly. The function of it is what matters here. Before this change, when you sent a Bitcoin transaction and it was sitting in the mempool waiting to be confirmed, a merchant could reasonably treat it as a payment in progress. Replace-by-Fee let the sender flag that transaction as replaceable, and then replace it with a different transaction, one that sent the money back to himself.
Hearn described it without mercy.
"Bitcoin Core has a brilliant solution to this problem: allow people to mark their payments as changeable after they've been sent, up until they appear in the block chain."¹²
"in fact their change also allows people to change the payment to point back to themselves, thus reversing it. At a stroke, this makes using Bitcoin useless for actually buying things."
That is the button. You walk out of the shop with the goods, you press the button on your phone, and the payment that was on its way to the merchant turns around and comes home to you. Bitcoin was designed to be electronic cash that could not be reversed. This change, shipped into the reference software, made it reversible by default for anyone who opted in. And when the community objected, Hearn said, it did not matter.
"It was massively condemned by the entire Bitcoin community but the remaining Bitcoin Core developers don't care what other people think, so the change will happen. If that didn't convince you Bitcoin has serious problems, nothing will."
Gavin Andresen and Jeff Garzik, two of the most senior developers in the project, had already published a piece with a title that said the quiet part out loud: "Bitcoin Is Being Hot-Wired for Settlement."¹³ There is that word again. Settlement. The thing Maxwell wanted Bitcoin to become, the developers were now hot-wiring it to be, against the wishes of the people who used it.
Hearn closed the experiment for himself in one sentence.
"I will no longer be taking part in Bitcoin development and have sold all my coins."¹⁴
He took a job at a bank consortium called R3.¹⁵ The price of Bitcoin, which had been clawing back from the Mt. Gox collapse, dipped on the news and then kept going.¹⁶ The community he was leaving celebrated his departure. They called him a quitter, a sore loser, a man who had failed to win an argument and rage-quit on his way out the door.
He sold all his coins.
What almost nobody did, in January 2016, was ask the most obvious question raised by the letter. If a handful of people now controlled Bitcoin, who was paying them, and what did the people paying them want? We answered the funding half of that question in Part 4B. But there is a second patron in this story, and he never appeared on any cap table, because he said his job was "Intelligence."
The Shadow Behind Peter Todd
In 2013, a Bitcoin developer named Peter Todd received a series of emails from a man calling himself John Dillon.¹⁷
Dillon was not his real name. It was a pseudonym, and the person behind it has never been publicly identified. What we have is an archive of the correspondence, PGP-signed emails that later leaked and circulated on the developer forums, and what is in that archive is documented, not speculated.¹⁸ I am going to be careful here to separate the two, because this is exactly the kind of story where a sloppy writer turns an inference into a headline and discredits the whole thing.
Here is what Dillon wrote about himself, verbatim.
"my day job involves intelligence, and I'm in a relatively high position."¹⁹
He aligned himself, in the same correspondence, with Edward Snowden and Julian Assange, and he said there would be consequences for him if his Bitcoin activities became known to his employer.²⁰ What he did not do, anywhere in the archive, is name an agency. He did not write CIA. He did not write NSA. Secondary write-ups over the years have filled in that blank for him. What is in the text is a man who said his day job was intelligence, at a relatively high position, and who then spent money.
What did he spend it on?
He funded Peter Todd's work on Replace-by-Fee, the reversible-payments feature from the open of this article.²¹ He funded, and publicly endorsed, a video called "Keep Bitcoin Free," a piece of advocacy arguing that the one-megabyte block size limit was essential to Bitcoin's decentralization, the exact argument that would justify everything Blockstream wanted.²² He was careful, in the emails, to draw a line about that one: "Keep Bitcoin Free! is Peter's project, not mine," he wrote. "I only contributed funds and offered to let him use my name publicly as a supporter."²³
And he funded a bounty for a privacy technology called CoinJoin. The structure of that bounty is the ugly part. There was a competing project, a privacy wallet called Dark Wallet, built by an anarchist developer named Amir Taaki and his collaborators. Dillon's money went to Gregory Maxwell's CoinJoin implementation instead, 5.11 BTC of it, and the emails show Dillon was, in his own words, "rather pissed off" at Taaki's "attempt to grab" the bounty.²⁴ The funds were routed away from the anarchists and toward the developer who would soon be Blockstream's CTO.

Amir Taaki has not been quiet about what he concluded when those emails leaked. In two separate posts, years apart, he laid it out. He and his team, he said, "were broke but worked on Bitcoin because we believed in it. Peter Todd was our friend. I later found out from his leaked emails he was helping a self identified agent to prevent us receiving funding. They staged an event by moving money around."²⁵ And in blunter terms, he called Todd "an absolute unapologetic intel-collaborating scumbag."²⁶
This is documented proof that an anonymous person who said his job was intelligence paid a Bitcoin Core developer to build a feature that made Bitcoin payments reversible, paid for a propaganda video defending small blocks, and steered privacy-tech funding away from anarchists and toward the man who would become Blockstream's CTO. The patron called himself intelligence, and the checks cleared.
There is even a competing theory that makes it stranger, not cleaner. In 2024, the filmmaker Cullen Hoback, in an HBO documentary about Bitcoin's origins, argued that Peter Todd wrote the John Dillon emails himself, that there was no intelligence asset, that the whole correspondence was Todd talking to a sock puppet.²⁷ Todd denies it. If Hoback is right, there is no government agent in this story at all, just a developer who invented one. I do not know which version is true.
Now, how does a feature that "the entire Bitcoin community" condemned ship anyway, into the software that everyone runs, over everyone's objection? To answer that you have to understand a thing that happened so quietly that most people never noticed it. The reference software stopped being a tool. It became a government.
Bitcoin Core, the Accidental Government
Here is a question that sounds simple and is not. What is Bitcoin?
Not the coin or the network... The rules. When two computers disagree about whether a transaction is valid, what is the authority that settles it? Where is the document you can point to that says what Bitcoin is and is not allowed to do?
Other than the white paper, which is written too generally to serve as a spec in any but the most generic regard, there is no such document.²⁸ There is no protocol specification maintained separately from the code. There is only the reference implementation, the software originally called Bitcoin-Qt and renamed "Bitcoin Core" in March 2014 with the 0.9.0 release.²⁹ Whatever that software accepts as valid, that is what Bitcoin is. Whatever it rejects, that is what Bitcoin is not. But that leaves some serious gray areas to be exploited by the people who manage the software.
Satoshi had warned about this in his own way, back when he said the protocol was set in stone after version 0.1 and handed the project to a process he could not have foreseen. By 2016 that process had a name, the BIP process, Bitcoin Improvement Proposals, and it ran entirely through Core's infrastructure.³⁰ A proposal could be written, numbered, debated, and formally accepted as a document, and still never become real, because becoming real meant being merged into Core's code, and the people with the authority to merge were a handful of maintainers.³¹ Roughly a dozen people have ever held commit access over the whole history of the project. From April 2014 onward, the lead maintainer was a Dutch developer named Wladimir van der Laan.³²
Think about what that means structurally. The maintainers of Bitcoin Core are not elected. There is no constituency that chooses them, no term of office, no recall mechanism, no accountability to users or miners or anyone else. They were not appointed by any legitimate authority, because there is no legitimate authority to appoint them; Satoshi left. They simply hold the commit bit, and the commit bit, in a system where the code is the protocol, is the closest thing Bitcoin has to sovereignty.
You can run another client, sure, but look what happened to Hearn and the other people who tried.
This is the thing the OP_RETURN fight in Part 5 was really about, and the block size fight, and the Replace-by-Fee fight, and every other fight in this article. It was never really about forty bytes versus eighty bytes, or one megabyte versus eight. It was about whether a handful of unelected developers, most of them drawing paychecks from a single venture-funded company, had the authority to decide what Bitcoin was allowed to do, and to enforce that decision on everyone who ran the software.
Hodlonaut, of all people, eventually came around to this, and Hodlonaut spent years as one of my most committed opponents. When even your adversaries start describing Bitcoin Core's role the way you have been describing it for a decade, the description is probably accurate.
Defenders of the arrangement say it is fine, because the maintainers cannot force anyone to run their code. That is technically true and practically false. We will see exactly how false in a moment, when SegWit ships as a soft fork specifically engineered so that you cannot meaningfully refuse it. For now, sit with the basic shape of the thing. The most important open-source project in the history of money was governed, by 2016, by a small group of people who answered to no one except, in many cases, their employer.
No one elected them. No one could un-elect them.
And one of the things they decided, in the same window, was to make Bitcoin's payments reversible. Let's watch them do it, and let's watch them buy time while they did.
Replace-by-Fee and the Art of the Stall
Opt-in Replace-by-Fee merged into Bitcoin Core 0.12.0, which was released on February 23, 2016.³³ It was, as Hearn said, condemned across the community, and it shipped anyway. That is the proof of the previous section. The code is the law, and the lawmakers do not take public comment seriously.
But February 2016 is worth slowing down on, because three things happened that month, and the timing of them, when you line them up, stops looking like coincidence.
On February 3, 2016, Blockstream closed its Series A funding round, fifty-five million dollars, co-led by AXA Strategic Ventures, the venture arm of one of the largest insurance companies on earth.³⁴ We traced that money and its conflicts in Part 4B; I am not going to repeat the cap table here, except to remind you that an insurance company's entire business is protecting assets, and a peer-to-peer cash system that disintermediates the global payment networks is, to an insurer, an interesting asset class to get involved with.
On February 21, 2016, eighteen days later, in a marathon session at Cyberport in Hong Kong, a group of miners controlling most of the network's hashrate sat down with a group of Bitcoin Core developers and signed what became known as the Hong Kong Agreement.³⁵ We covered the signing in Part 5. The deal was specific: the developers would get SegWit activated, and in exchange they would deliver a hard fork to roughly two megabytes, with code available "within three months after the release of SegWit."³⁶ Five Core developers signed it as individuals, Cory Fields, Johnson Lau, Luke Dashjr, Matt Corallo, and Peter Todd, and Adam Back signed it as the President of Blockstream.³⁷
And on February 23, 2016, two days after the Hong Kong handshake, Replace-by-Fee shipped.

The two-megabyte hard fork that the developers promised in Hong Kong was never delivered.³⁸ SegWit eventually shipped. The block size increase that was supposed to come with it did not. The Core developers who had signed as individuals took the position that they could not bind the broader project, and the broader project, led by Gregory Maxwell, who had pointedly not signed, rejected the deal.³⁹ One of the miners who had signed, Gang Wu of HaoBTC, put it plainly when it became clear the other half of the bargain would never arrive: "Developers have unilaterally torn up the agreement to force the adoption of segwit."⁴⁰
This is the pattern. It repeats, and once you see it, you cannot unsee it.
The pattern is: agree, buy time, renege. When the pressure for bigger blocks built to the point where it threatened to fork the network, the small-block side did not win the argument on the merits. It bought time. It went to conferences. It signed agreements. It promised that the increase was coming, just not yet, just after this next technical milestone, just once everyone calmed down. And then, once the political moment had passed and the bigger-block client had lost momentum, the promise evaporated.
Hearn watched this happen in real time and described the mechanism in his letter. The "Scaling Bitcoin" conferences, two of them, in Montreal and Hong Kong in the second half of 2015, were sold as good-faith venues for working out a compromise. Hearn's assessment was that they were a stalling tactic, and a devastatingly effective one.
"When talking to miners and startups, 'we are waiting for Core to raise the limit in December' was one of the most commonly cited reasons for refusing to run XT."⁴¹
"this tactic was devastatingly effective. The community fell for it completely."
Remember that sentence when we get to the New York Agreement in 2017, because the New York Agreement is the same trick, run one more time, at a larger scale, with higher stakes, and the same outcome. Agree to everything. Deliver the half you wanted. Bury the half you didn't.
Replace-by-Fee was BIP 125, authored by David Harding and Peter Todd.⁴² It was one of a cluster of consequential changes in this window. SegWit itself was BIP 141, by Eric Lombrozo, Johnson Lau, and Pieter Wuille.⁴³ The version-bits signaling mechanism that would be used to activate soft forks was BIP 9.⁴⁴ Jeff Garzik's simple two-megabyte proposal, BIP 102, was written and never merged, which tells you everything about who held the pen.⁴⁵ These were not neutral technical documents floating in a vacuum. They were the instruments through which a few people redefined what Bitcoin was, and the instrument that mattered most, the one that would finally split the chain, was about to be unveiled by a man in Sydney walking back into the light.
The Man from Sydney Returns
When we left him, the house in Gordon was empty.
Craig Steven Wright had been identified, on December 8, 2015, by Wired and Gizmodo on the same day, as the probable creator of Bitcoin, and the Australian Tax Office had raided his home the next day, and he was already gone.⁴⁶ He surfaced in London over the following months, inside the operation that the journalist Andrew O'Hagan documented from the inside, the one that was going to unmask Satoshi Nakamoto and sell the package for a billion dollars.
On May 2, 2016, he tried to prove it.
The day had three parts, and they were coordinated. First, a blog post. Wright published a piece on his site titled "Jean-Paul Sartre, Signing and Significance."⁴⁷ The choice of Sartre was the argument. Sartre famously declined the Nobel Prize in 1964, refusing to let an institution's authority define his work, and Wright's point, wrapped in a great deal of philosophy, was that proof of identity should not require submission to external authority. The post also contained what was presented as cryptographic proof: a digital signature that supposedly demonstrated Wright controlled a private key associated with the earliest days of Bitcoin.
Second, the press. Wright gave interviews to the BBC, the Economist, and GQ, timed to the post.⁴⁸ The BBC's technology correspondent, Rory Cellan-Jones, filmed him.⁴⁹ Wright said the thing that everyone remembers, the line that reads very differently depending on whether you believe him:
"I don't want money. I don't want fame. I don't want adoration. I just want to be left alone."⁵⁰
Third, and this is the part that mattered most to the people who actually understood Bitcoin, the private demonstrations. Before the public post, Wright had sat down privately in London with Gavin Andresen, the developer Satoshi had personally handed the project to in 2011. Andresen has described the session: Wright signed a message that Gavin chose, on a laptop, with software they verified, and the message was checked against a key associated with one of the earliest blocks.⁵¹ Which block is itself disputed; Gavin's own later sworn testimony said block 1, "if I recall correctly," while most contemporary press said block 9, the block whose coins went to Hal Finney.⁵² Whatever the block, Gavin walked out of that room convinced, and he wrote it down, publicly, the same day Wright went public. Under oath, Andresen explained that, out of an abundance of caution, he also opened a sealed laptop to demonstrate a second signing with even more variables controlled, and stated this about the sessions:
"I believe Craig Steven Wright is the person who invented Bitcoin."⁵³
That endorsement, from that man, should have been the end of the story. It was instead the beginning of a very bad week.
Because while Gavin had been convinced by a private signing he controlled, the public proof in the Sartre blog post was something anyone could check, and within hours, people checked it, and it fell apart.
Was that the point? Do we have to understand Sartre to "get it?"
The "signature" in the blog post was not a new signing of the Sartre text at all. It was a signature lifted from a Bitcoin transaction Satoshi had made back in 2009, already public, already on the blockchain, dressed up to look like fresh proof.⁵⁴ The mechanism was a trick involving Bitcoin's double-hashing: Wright presented an intermediate value from the old 2009 transaction in a way that, when run through standard verification tools, appeared to validate, but validated nothing about Sartre and nothing about Wright possessing the key. A developer named Patrick McKenzie wrote the cleanest takedown, a public repository walking through the deception line by line, and his summary was withering: "Wright's post is flimflam and hokum which stands up to a few minutes of cursory scrutiny."⁵⁵ The security researcher Dan Kaminsky published his own analysis the next day under a title that became the verdict: "The Cryptographically Provable Con Man."⁵⁶ His conclusion was not hedged: "Yes, this is a scam. Not maybe. Not possibly."
And Gregory Maxwell, as he had in December when the Wired and Gizmodo stories broke, had a detailed technical rebuttal out within hours.⁵⁷ I want you to notice that, because we are going to come back to it. Twice now, in December 2015 and May 2016, a complex cryptographic claim about Satoshi's identity surfaced, and within hours, not days, the CTO of Blockstream had a thorough, technical, public demolition ready to go. File that away.

What happened next is documented in a sworn deposition Gavin Andresen later gave in the Kleiman v. Wright lawsuit, and I report it the way he reported it, as something told to him, not something he witnessed. According to Gavin's testimony, in the days after the failed proof, as the plan to do a more convincing demonstration collapsed, Wright "disappeared upstairs and then was found bleeding with cuts to his neck, and then was taken to the hospital in an ambulance with an apparent suicide attempt."⁵⁸ Gavin got the news in an email from one of Wright's associates, who said Craig was "bleeding badly in the washroom."⁵⁹
On May 5, 2016, Wright posted one more time, a short piece titled "I'm Sorry," and then took his blog down.⁶⁰ The verified text of it is one of the strangest documents in this entire saga, because it is either the confession of a fraud who lost his nerve or the breakdown of a real but broken man who could not face what proving his identity would cost him. It reads the same either way: pure tragedy.
"I believed that I could do this. I believed that I could put the years of anonymity and hiding behind me. But, as the events of this week unfolded and I prepared to publish the proof of access to the earliest keys, I broke. I do not have the courage. I cannot."⁶¹
He added a line about the two men who had vouched for him. "I know that this weakness will cause great damage to those that have supported me," he wrote, "and particularly to Jon Matonis and Gavin Andresen... They were not deceived, but I know that the world will never believe that now."
He was right about that last part. The world did not believe it.
And Ian Grigg, one of the most respected cryptographers in the history of digital cash, the inventor of the Ricardian contract, had posted his own confirmation the same day Wright went public, May 2, in language that staked his professional reputation on it. We are going to spend the next section on Grigg, because he is the part of this story that does not fit any of the easy explanations.
But before we leave the timeline, there is a loose end to tie off, one we promised you in Part 5. Back in December 2015, when Wired and Gizmodo named Wright, a post appeared on the Bitcoin development mailing list from an email address associated with the original Satoshi account, denying it: "I am not Craig Wright. We are all Satoshi."⁶² We told you in Part 5 that there would be a third post from that compromised account, and that we would get to it in its proper place. This is its proper place. The account had been hijacked back in September 2014, as we documented, its password reset through a birthday guess.⁶³ So when "Satoshi" denied being Craig Wright in December 2015, the honest answer to who actually typed that sentence is that nobody knows, except for the hacker who controls the account.
Maybe he will email me to discuss...
Either way, speculation rules the day: maybe Satoshi wrote it. Maybe the hacker wrote it. Maybe someone else entirely. Pick the explanation that fits your priors. The forum and the inbox that everyone trusted had stopped being trustworthy, and we have to live with that for now.
The Australian Circle
Let me start with the man who has the most to lose by being wrong.
Ian Grigg is not a hype man. He invented the Ricardian contract, the design that links a legal agreement to a cryptographic record, and he has spent decades as one of the genuine elders of financial cryptography.⁶⁴ When Craig Wright went public on May 2, 2016, Grigg could have done absolutely nothing about it, but he published a post on his long-running, well-respected blog Financial Cryptography, and he did something cryptographers almost never do. He put his name and his community standing behind the claim.
"Craig Wright has just outed himself as the leader of the Satoshi Nakamoto team. I confirm that this is true, both from direct knowledge and a base of evidence. CARS."⁶⁵
That last word is not a typo. CARS stands for CAcert Assurer Reliable Statement.⁶⁶ It is a formal mechanism inside the CAcert identity-verification community, and what it means is that Grigg was not just offering an opinion. He was subjecting himself to a formal community dispute process if the statement turned out to be unreliable. He explained it himself in the comments: if the community "finds the statement unreliable they can file a dispute into the forum of dispute resolution." He was staking his reputation, formally, on the record.⁶⁷
And then, in the same post, he did the opposite of what a hype man does. He told you not to expect a god.
"Satoshi was a vision, but Craig is a man. The two are not equal, not equivalent, not even close."⁶⁸
"But please, don't dump your visionary expectations onto one man. He's not up to it, you're not going to like the result, and it's inhuman."
A year later, in May 2017, after the London operation had collapsed into what Grigg called a "circus," he wrote again, and the second post is even more useful, because Grigg was angry by then, angry at the people who had stage-managed the reveal, and angry people are often more honest. He described the volume of evidence he had personally examined.
"the volume of material that I have seen, documents, personal testimony, discussions in person, added up cannot be forged."⁶⁹
He described the structure of what Satoshi had actually been.
"Satoshi Nakamoto was a team. The members haven't all been named... Having said that, CSW was in."⁷⁰
He explained, in a single passage, the thing that has bothered careful readers about Satoshi's writing for fifteen years, the strange unevenness, the polish of the paper against the roughness of the man.
"the team worked on writing the paper, and, managing the communications. Both. Did you ever wonder why the communications and the paper were so concise, well written, literate, on point? The reason was that it wasn't a person: it was a team, and it was deliberately, carefully, painstakingly set up that way."
And he refused, again, to make Craig into a hero.
"Craig is not the god you wanted. Like most geeks of extraordinary talent, he didn't get there by working on his social skills; he's your average grade-A certifiable techno arsehole, when you get to know him."
He titled a section of that post "RIP Satoshi Nakamoto 2005 - 2016," dating the project's birth to 2005, three years before the whitepaper. And he ended on a note that I have never been able to shake, four years of covering this story later.
"People died for Bitcoin, folks, people died."
I don't know what that means. Figurative? Literal? Who died for bitcoin? Dave? Who?!
What I do know is that Grigg is not a fabulist, and he did not have to write any of it.

Now let me introduce the part of this circle that I am going to treat lightly, on purpose, because it deserves to be treated lightly.
In late 2016, a New Zealand programmer named Phil Wilson, who used the handle Scronty, published a long document called "Bitcoin Origins," and later sat for a seven-hour interview about it.⁷¹ His claim is that there were three creators of Bitcoin, that he was one of them, and that the company they formed was originally going to be called WW&K, for Wilson, Wright, and Kleiman. He says he asked to be removed from the name: "If there's two W's in the company title then folks will know there's a third person to hunt down. Please remove me from the name and use only W&K."⁷² The company that was actually registered, in February 2011, was W&K Info Defense Research.
Wilson's document contains a lot of vivid, specific detail. He says Craig brought him an early whitepaper and that it was scrapped: "My original white paper has been completely thrown out now," he quotes Wright as saying, "and two-thirds of the code I'd developed has been binned." He says the name Nakamoto came from the Nakamoto Corporation in Michael Crichton's novel "Rising Sun," chosen to send identity-hunters chasing a Japanese man who did not exist. He says the development project was code-named Prometheus, after the myth of stealing fire from the gods.
And here is why I am treating it lightly: Wilson himself tells you not to believe it.
"There is no verification of truth here. There is absolutely no evidential proof that I had any part in the project. All evidence was purged in late 2011... Take this as just a fictional story if you wish."⁷³
Nobody knows which parts of Phil Wilson's story are true. He has no proof, and says so. Craig Wright denies him outright, and has called him a scammer who "knew nothing at all about bitcoin before 2011."⁷⁴ Martti Malmi, Bitcoin's second developer, flatly denied Wilson's claim about helping with a logo: "Never happened. Also: signature or GTFO."⁷⁵ CoinDesk, which investigated the logo question, attributed the orange B to an anonymous forum user called bitboy and called Wilson's account "extensive fan fiction."⁷⁶ I will add one detail from my own reporting that has always nagged at me. When Craig Wright once talked to me about Wilson, he did not call him "Phil." He called him "Scronty," the hacker handle, and he said, "Scronty was just a security guard at a place where I was working." I found it interesting that Craig reached for the handle instead of the name, but immediately knew who I was asking about.
Make of that what you will. It is not evidence of anything. It is a texture that always made me curious.
There are others in the orbit. Uyen Nguyen, a young Vietnamese-American woman who became a director of W&K Info Defense Research and was named in connection with the Tulip Trust, and who deleted her social media accounts in the first week of May 2016 as the reveal collapsed.⁷⁷ Joseph Vaughn-Perling, a director of the New Liberty Dollar, who claims he met Craig Wright at a hacker conference called What the Hack in 2005, wearing a name badge that read "Satoshi Nakamoto," three years before the whitepaper, and who was subpoenaed in Kleiman v. Wright.⁷⁸ Their stories do not perfectly agree. Vaughn-Perling's badge story has never been independently corroborated.⁷⁹ Nguyen's authority documents were alleged in court to be forged.⁸⁰ I also won't be naming my source, but I've been told in no uncertain terms that JVP has an unbreakable connection to Nguyen and the rest of the story that I won't go into any further, but there's a reason they are both so hard to find today...
So here is what I want you to do. Stop trying to decide, claim by claim, who is telling the truth, because that is a maze with no exit and I am not going to pretend I have walked out of it myself.
Step back instead, and look at the shape of the thing.
A cryptographer with a decades-long reputation stakes it publicly, formally, on a record. A New Zealand programmer writes a hundred and twenty thousand characters of detailed testimony and sits for seven hours of recorded interview, then tells you he has no proof. A New Liberty Dollar director gets subpoenaed in a federal lawsuit, and doesn't show. A dead computer-forensics expert who died under some level of mystery around a bullet hole in the apartment had an estate which filed a billion-dollar claim. A Vietnamese-American trust director scrubs her accounts and vanishes. And an Australian polymath with a trail of companies and academic papers and tax filings going back years sits in the middle of it. Eventually, it will attract a mole who uses Mossad and IDF-adjacent firm Black Cube to, according to some reports, stage a hostile take-over of Wright's company to exfiltrate or destroy evidence. And this wasn't a hostile take-over in the board-room and paperwork sense, but allegedly, more like a combat operation.
We will get to that story later...
Either way, the stories coming from and about Wright contradict each other. The evidence is mixed; some of it is compelling, some of it is problematic, and some of it is absurdly bad. So bad, in fact, that Craig's own evidence has lost him more than one court case. If this were a coordinated fabrication, it would be more consistent, not less. Coordinated lies get their story straight. This is a constellation of people who saw something, or know something, and got their stories crossed in the haze of it all.
None of them needed to be here. None of them needed to be involved, but their stories are public.
That is the question this section leaves you with, and I am not going to answer it, because the honest answer is that I cannot. Why would any of these people exist, in these roles, telling these overlapping and contradictory stories, if there were nothing at the center of it? In my experience, you do not get a crowd this strange around an empty space.
Gavin Loses His Keys
Now return to May 2, 2016, the day Gavin Andresen wrote "I believe Craig Steven Wright is the person who invented Bitcoin." Watch what happened to him for writing it.
Within hours, his commit access to the Bitcoin Core repository was revoked.⁸¹ Peter Todd announced it publicly: "FYI, @gavinandresen's commit access just got removed; Core team members are concerned that he may have been hacked."⁸² The stated reason was security. The concern, officially, was that Gavin's account might be compromised, that no real Gavin would endorse Craig Wright, so the endorsement itself was treated as the evidence of a hack.
Wladimir van der Laan, the lead maintainer, explained the decision. After seeing the endorsement, he wrote, "the prudent thing to do was to revoke his ownership of the 'bitcoin' organization on github, under which the Bitcoin Core repository currently lies, immediately."⁸³ Prudent. The word does a lot of work.

Yet again, I want to be careful and fair about the mechanics, because Gavin had already stepped back from day-to-day maintenance by 2016, and his commit access was in some sense ceremonial.⁸⁴ Removing it did not change who was writing most of the code. But it changed something more important than code. It changed the symbolism, and in a system with no formal authority, symbolism is most of what there is.
Gavin Andresen was the man Satoshi Nakamoto personally handed the project to. He held the alert key, the master signing key Satoshi gave him in 2011 that we tracked across Parts 3, 4, and 5.⁸⁵ He was the closest thing Bitcoin had to a designated heir. And he was, not coincidentally, the most senior voice in the project who still believed Bitcoin should scale on-chain as cash, the way the whitepaper described.
Within hours of saying the wrong name, the designated heir was locked out.
The last man Satoshi trusted was locked out of the building Satoshi built and entrusted with him.
And the thing about that, the thing that should make you stop, is that it tells you the scaling fight and the identity fight were never two separate fights. They were the same fight. The reason Gavin's endorsement of Craig Wright was intolerable was not that the proof was bad; and maybe it was. It was that Gavin was a big blocker, and Craig Wright was a big blocker, and if the man Satoshi appointed vouched for a big blocker as Satoshi, then the small-block project had a problem it could not technically argue its way out of. So the endorsement could not be allowed to stand, and the man who made it had to be removed from the building, and the official reason was that he might have been "hacked."
Which raises the question that the next section exists to answer. Why was Craig Wright so dangerous? Other people have claimed to be Satoshi. Other people have been floated as Satoshi by journalists, media outlets and professional documentaries. None of them got this treatment. What was different about this one?
Why Craig Wright Is an Existential Threat
Let me show you which Satoshis are allowed, and which one is not.
Adam Back is allowed. Back is the inventor of Hashcash, the proof-of-work system cited in the Bitcoin whitepaper, and he is the CEO of Blockstream. He has been floated as a Satoshi candidate for years, by the Financial Times, by John McAfee, by an HBO documentary, and most recently by a 2026 New York Times investigation from the reporter who broke the Theranos story, which I took apart at length elsewhere.⁸⁶ Notice what the Back theory does. If Adam Back is Satoshi, then Satoshi is the CEO of the company that funds Bitcoin Core and champions small blocks and Bitcoin Treasury Companies, and Satoshi's vision is identical to Blockstream's roadmap. The speculation does not threaten the small-block narrative. It crowns it. So it is allowed to persist, even with Back's passing public resistance, and the company has never quite killed it, because the ambiguity flatters them.
Hal Finney is allowed. Finney received the first Bitcoin transaction Satoshi ever sent, in January 2009, and he was a brilliant cryptographer and a genuine cypherpunk.⁸⁷ He is a perennial candidate. He is also dead; he died of ALS in August 2014.⁸⁸ A deceased Satoshi is the safest Satoshi of all, because a deceased Satoshi cannot give an interview, cannot sign a message, cannot walk onto a stage and demand bigger blocks. Finney can be Satoshi forever, and he will never contradict anyone.
Nick Szabo is allowed. Szabo designed Bit Gold, and he was explicit that he was trying to "mimic as closely as possible in cyberspace the security and trust characteristics of gold."⁸⁹ Szabo is the intellectual father of the "Bitcoin is digital gold" frame, the exact frame that justifies a small, scarce, expensive settlement layer that you hold and do not spend. If Szabo is Satoshi, the store-of-value thesis has its creator's blessing. He is safe.
Now look at the one who is not allowed.
Craig Wright is a big blocker. He believes Bitcoin was designed to scale on-chain to enormous size, to carry the whole world's transactions, to function as cash and as a data layer and as everything the small-block roadmap declared to be spam. If Craig Wright is Satoshi, then the entire small-block project is not a careful stewardship of Satoshi's vision. It is a deviation from it. It is a coup. And that is intolerable in a way that has nothing to do with whether his evidence is good.

This is why the response to Wright has never been proportionate to the official story about him. If Craig Wright were simply a scammer, as they will tell you; a delusional fabulist with bad documents, the correct response would be to ignore him. Scammers starve without attention. Instead, Craig Wright became the most litigated, most investigated, most attacked Satoshi candidate in the history of the subject. The Crypto Open Patent Alliance, founded by Block and joined by Coinbase, Kraken, MicroStrategy, Blockstream, and later Meta, spent years and a fortune litigating a single negative declaration in a London court, that this one man is not Satoshi, a case that ended in March 2024 with Justice Mellor ruling the evidence "overwhelming" against him.⁹⁰ He has been sued and counter-sued across three jurisdictions: Kleiman in Florida, McCormack and COPA in London, Hodlonaut in Norway.⁹¹ No other Satoshi candidate has faced a single such proceeding. Adam Back has never been dragged into court to prove he is not Satoshi. Nobody has spent a dollar litigating Hal Finney's estate.
And remember Gregory Maxwell's rebuttals, the ones that appeared within hours of each Wright event, in December 2015 and again in May 2016. I am not going to tell you that proves coordination. I am going to ask you to consider how fast a detailed, thorough, technical demolition of a complex cryptographic claim actually comes together, if you are starting from scratch, surprised, on the day of. And then I am going to ask you to consider how fast it comes together if the material was prepared in advance, because the threat was known in advance, because the threat was always the same threat. I do not have the receipts to close that loop. I have the timing, and the timing is striking, and I will leave it there.
Here is the reframe, and it is the thesis of this whole article. Stop asking whether Craig Wright is Satoshi Nakamoto. I am not asking you to believe that he is; I have spent this entire series refusing to declare it, and I am not going to declare it now. Ask the other question instead, the one the behavior of the small-block establishment actually answers.
Ask why they are so afraid that he might be Satoshi, that they spend time, money, personal capital and marketing resources to make sure the official record is so specifically tailored to their needs about this one man?
SegWit, the Accounting Trick
Now we come to the weapon. Segregated Witness, SegWit, was proposed by the Blockstream developer Pieter Wuille at the Scaling Bitcoin conference in Hong Kong in December 2015.⁹² It is the most consequential change in the history of BTC, and to understand the fight you have to understand what it actually does, because it was designed to be hard to understand.
A Bitcoin transaction has two parts: the data that says who is paying whom, and the signature that proves the payer authorized it. The signature is called the witness. SegWit separates the witness from the rest of the transaction and moves it into a new structure, and then it changes the accounting. Instead of a one-megabyte block size limit, SegWit introduces a "block weight" limit of four million weight units, where the main transaction data costs four weight units per byte but the witness data costs only one.⁹³ The witness gets a seventy-five percent discount. The practical effect is that a block can now hold something approaching 4 megabytes of actual data, under utopian circumstances, while the base block size technically stays at one megabyte.
That is the trick, and it is the whole fight in miniature. The block size limit did not go up. The block weight limit went up, witness data got discounted, and the net effect was a capacity increase achieved through a redefinition of how you count bytes.
Mike Hearn, in the farewell letter, named it exactly. He called the proposal "an anemic 60% capacity increase only through an accounting trick (not counting some of the bytes in each transaction)."⁹⁴ That is the phrase. An accounting trick. Jeff Garzik made a related criticism, that SegWit's opt-in nature meant it provided no predictable added capacity at all.⁹⁵ The simple thing, the thing the big blockers had been asking for since 2015, was to change one number, the one-megabyte limit, to a bigger number. SegWit was the spectacularly complicated thing you build instead of doing the simple thing, and it required changes to nearly every wallet, exchange, and piece of Bitcoin software in the world to support the new transaction format.

Why build something so complicated to achieve so little? Two reasons, and both of them are a problem.
The first is governance, and it connects straight back to the accidental-government section. SegWit was implemented as a soft fork, not a hard fork. A hard fork changes the rules in a way that requires everyone to actively participate in the upgrade, which means it requires broad consensus, which means the big blockers would have had a veto. A soft fork is backward-compatible; it tightens the rules rather than loosening them, so old nodes keep working without validating the new stuff, and it can be activated on a miner-signaling threshold without the whole community agreeing. In fact, they don't even have to know! Passivity defaults to support. SegWit was deliberately designed as a soft fork specifically so that it could be activated over the objection of the people who wanted bigger blocks. The architecture was the politics.
The second reason is the one that pays the bills, and it takes us back to Part 4B. SegWit "fixed" a long-standing quirk called transaction malleability, the same quirk Mt. Gox had blamed for its collapse in Part 5.⁹⁶ Fixing malleability was pitched as a genuine technical good. It was also a prerequisite. You cannot build reliable payment channels, you cannot build the Lightning Network, on top of a base layer where transactions can be malleated. SegWit fixed malleability, which unlocked Lightning, which was Blockstream's Layer 2 product.
So follow the logic all the way through. Constrain the base layer so it cannot scale as cash. Call the constraint a virtue. Ship a complicated change that fixes malleability and unlocks a second layer. Sell the second layer. We laid out the business model in Part 4B and compared it to the McDonald's ice cream machine, the one the franchisee is contractually forbidden from repairing, so that corporate can sell the maintenance contract. SegWit is the broken machine. Lightning is the maintenance contract. And the developers who shipped it were, in many cases, paid by the company selling the contract.
There was just one problem with activating SegWit. The miners did not want it. And in the spring of 2017, Gregory Maxwell figured out why, and the reason had nothing to do with ideology.
ASIC Boost and the Real Reason
On April 5, 2017, Gregory Maxwell posted to the Bitcoin development mailing list with a discovery.⁹⁷ He had, he said, reverse-engineered a mining chip, and he had found something hidden in the silicon.
"Reverse engineering of a particular mining chip has demonstrated conclusively that ASICBOOST has been implemented in hardware."⁹⁸
ASIC Boost is a mining optimization, and the technical details matter just enough to explain the incentive. Bitcoin mining works by running a block's header through a hash function over and over, looking for a winning number. A brute-force lottery. The header gets processed in two chunks. ASIC Boost is a trick for reusing the computation on one of those chunks across many attempts, which saves energy, somewhere between fifteen and twenty percent of it.⁹⁹ In a business with margins as thin as mining, a fifteen-to-twenty percent energy edge is the difference between winning and bankruptcy.
There are two ways to do it. Overt ASIC Boost manipulates a visible field in the block header, where anyone can see it. Covert ASIC Boost manipulates the transactions in the block to achieve the same effect, and it is very hard to detect from the outside. And here is the detonator: covert ASIC Boost is incompatible with SegWit.¹⁰⁰ The way SegWit restructures the block, with its new commitment to the witness data, breaks the covert trick. If SegWit activates, covert ASIC Boost stops working.
Do you see it now?
Maxwell had just handed everyone a financial motive for the miners' opposition to SegWit that had nothing to do with the size of blocks or the soul of Bitcoin or the vision of Satoshi. He turned miners into greedy tricksters, from a narrative standpoint. If a major miner was using covert ASIC Boost, then SegWit would cost that miner its energy edge directly, and that miner would fight SegWit to protect its margins.
The miner everyone pointed at was Bitmain, the largest manufacturer of mining hardware in the world, run by Jihan Wu.¹⁰¹ Bitmain's response was a careful denial. Jihan Wu acknowledged that the ASIC Boost capability existed in their chips and that they held a patent on it, but he said they had only tested it on a testnet and had never used it in production on the main Bitcoin network, and he demanded that accusers "provide direct evidence."¹⁰² The most sober analysis of the whole affair, from BitMEX Research, concluded that while the circumstantial case was suggestive, "the evidence is not conclusive."¹⁰³
I am giving you both sides on purpose, because this is a place where it would be easy to overclaim. What is certain is this: the technical fact that covert ASIC Boost and SegWit are incompatible is real, and it means at least some miners had a concrete financial reason to oppose SegWit, on top of and entirely separate from the ideological scaling debate. The scaling war was never only about ideas. It was also about money, and energy, and silicon, and the people pretending it was a pure philosophical disagreement were, on both sides, leaving out the part where their own incentives lined up with their principles a little too neatly.
That is the board, set for the biggest single event of the entire war. In May 2017, almost everyone who mattered in Bitcoin signed a treaty. And then the people who refused to sign it killed it.
The New York Agreement and the Biggest Backstab in Bitcoin
On May 23, 2017, on the sidelines of the Consensus conference in New York, Barry Silbert of Digital Currency Group announced an agreement.¹⁰⁴ We mapped DCG's investors in Part 4B, MasterCard and Western Union and CME and New York Life, the incumbents of the system Bitcoin was built to disrupt. Silbert convened the room, and the room was enormous.
The New York Agreement was signed by fifty-eight companies, representing, by the announcement's own accounting, 83.28 percent of the network's hashrate.¹⁰⁵ The signatories were a who's-who: Bitmain, Coinbase, Xapo, Blockchain, BitPay, Circle, BitFury, ShapeShift, BitGo, Bloq.¹⁰⁶ The deal was a compromise that was supposed to end the war. It had two parts, and it was called SegWit2x. First, activate SegWit. Second, within roughly six months, hard fork to two-megabyte blocks.¹⁰⁷ Both halves. SegWit for the small blockers, bigger blocks for the big blockers. Peace.
There was one group conspicuously absent from the signature page.
Blockstream did not sign. The Bitcoin Core developers did not sign.¹⁰⁸ The people who controlled the reference implementation, the people who actually held the commit bit, the accidental government from earlier in this article, refused to be party to the agreement that more than eighty percent of the network's hashpower had just endorsed. Think about what that refusal means in a system where the code is the law. Eighty-three percent of the miners and the biggest companies in the industry could agree on something, and it did not matter, because the dozen people who could merge the code had not agreed, and they were not going to.

Watch the sequence, because it is the February 2016 pattern again, run at maximum scale.
Step one: deliver the half the small blockers wanted. The SegWit half of the agreement, conveniently, activated first. After a complicated dance involving a user-activated soft fork threat that I will come back to, SegWit locked in and then activated on the BTC network at block 481,824 on August 24, 2017.¹⁰⁹ The small blockers had their accounting trick. They had Lightning's prerequisite. They had won their half.
Step two: kill the other half. The two-megabyte hard fork was scheduled for around November 16, 2017, at block 494,784.¹¹⁰ And in the months between August and November, the signatories who had pledged to deliver it came under a sustained pressure campaign to break their word. The campaign had a brand, NO2X, and a uniform. Samson Mow, by then the Chief Strategy Officer of Blockstream, produced and distributed hats, and wearing the hat at a conference became a public loyalty test, a way of proving your allegiance to the small-block side by putting merchandise on your head.¹¹¹ The companies that had signed the New York Agreement were pressured, shamed, and threatened until, one by one, they began to peel away.
Step three: announce the surrender. On November 8, 2017, eight days before the hard fork was scheduled to activate, Mike Belshe, the CEO of BitGo, sent the email that ended it.
"Our goal has always been a smooth upgrade for Bitcoin. Although we strongly believe in the need for a larger blocksize, there is something we believe is even more important: keeping the community together. Unfortunately, it is clear that we have not built sufficient consensus for a clean blocksize upgrade at this time."¹¹²
The email was co-signed by Wences Casares of Xapo, Jihan Wu of Bitmain, Jeff Garzik who had led the SegWit2x software, Peter Smith of Blockchain, and Erik Voorhees of ShapeShift.¹¹³ Barry Silbert, who had convened the whole thing, did not sign the cancellation.¹¹⁴
So tally it up. The small blockers got SegWit, the thing they wanted, activated in August. The big blockers got nothing, the hard fork they were promised suspended in November, eight days before it would have happened. The largest coordinated agreement in the history of Bitcoin, signed by companies representing more than eighty percent of the network, was defeated by a combination of social pressure, hats, and the structural reality that the people who controlled the reference implementation had never agreed to it and never would.
They got SegWit. The big blockers got nothing.
And I want to put one more frame on this, because it is the frame that the official history works hardest to hide. The winning side told a story about itself, and the story was a populist uprising.
The user-activated soft fork I mentioned, BIP 148, was proposed by a pseudonymous developer called shaolinfry, and it was sold as a revolt of the people against the miners, the ordinary node-runners rising up to force SegWit through whether the big mining cartels liked it or not.¹¹⁵ August 1, 2017 was branded "Bitcoin Independence Day."¹¹⁶ The hats, the slogans, the language of a general strike, all of it cast the small-block side as the grassroots, the scrappy users, the anti-corporate resistance.
Now look at who was actually funding each side. The small-block side, the side wearing the costume of the street, was bankrolled through Blockstream, funded by AXA, one of the largest insurance companies on the planet, as well as funds downstream of MasterCard, Western Union, CME, and New York Life.¹¹⁷ The big-block side was funded by Bitcoin-native interests: miners, the entrepreneur Roger Ver, Bitmain, Coinbase, BitPay.¹¹⁸ The "anti-corporate" uprising was the better-funded side, and its money came from the exact incumbents whose businesses Bitcoin-as-cash would destroy.
I have seen this movie before, in other contexts. A movement dresses itself in the language of the powerless and the organic and the grassroots, while the actual funding flows from the institutions that benefit most from the movement winning. The costume is the street. The checks are from the boardroom. It is one of the oldest plays in the book, and in 2017 it worked perfectly, and most of the people wearing the hats never knew whose interests they were serving.
Arnhem and the Vision That Got Away
Six weeks before the chain split, on June 30 and July 1, 2017, the big-block side held a conference in Arnhem, a small Dutch city that had embraced Bitcoin payments.¹¹⁹ It was the last gathering before the fork, and two men on that stage tell you everything about what was about to happen and what was about to be lost.
The first was Amaury Séchet, a French software engineer who had spent years at Facebook before leaving to work on Bitcoin full-time in early 2017.¹²⁰ At Arnhem he gave a talk called "Back to Basics," and he unveiled a new Bitcoin client called Bitcoin ABC: a clean implementation with eight-megabyte blocks and no SegWit.¹²¹ Séchet was about to become the lead developer of the chain that would split off in August, the self-described benevolent dictator of Bitcoin Cash. Remember his name. He will matter enormously in Part 7, and not in the way the Arnhem audience expected.
The second was Craig Wright. The man who had broken down in London a year earlier, who had taken his blog dark and written "I do not have the courage," walked onto the Arnhem stage and delivered the opposite of an apology. His talk was titled "The Future of Bitcoin is Unlimited," and contemporaries described it as somewhere between a manifesto and a rant.¹²² He argued for radical on-chain scaling with no artificial limit, gigabyte blocks and beyond, Bitcoin as the transaction and data layer for the entire planet. "SegWit is NOT scale," he said. "I want every single person on this globe using not altcoins, not whatever else, I want them using Bitcoin." And he drew the line that would define the next phase of the war: "you're with us, or you're against us." The room applauded in places and sat baffled in others.

While the big blockers argued about how to escape the one-megabyte cage, the builders had already started leaving, and this is the cost of the civil war that almost never gets counted.
Ethereum had launched in 2015, in the vacuum the OP_RETURN restriction created, as we covered in Part 5. By 2017 it was a tidal wave. The initial coin offering boom raised somewhere between five and six billion dollars in 2017 alone, and by August of that year, ICOs were raising more money than all early-stage venture capital combined.¹²³ A year earlier, in the summer of 2016, Ethereum had survived the DAO hack and then done the thing Bitcoin Core swore could never be done: it rewrote its own history, reversing the theft with a hard fork that split the chain into Ethereum and Ethereum Classic.¹²⁴ The precedent was set. The "immutable" ledger turned out to be exactly as immutable as its community decided it should be.
Every one of those ICO projects, every token, every smart contract, every data application, was a thing that could in principle have been built on Bitcoin, if Bitcoin's developers had not spent three years declaring such things to be spam and engineering the protocol to forbid them. The builders did not stop building. They built somewhere else. They went to Ethereum, and then to EOS and Cardano and a hundred other chains, and the entire altcoin economy that crypto skeptics now point to as evidence that the whole space is a casino is, in significant part, the externality of one decision: the decision to keep Bitcoin small, and to drive everyone who wanted to build anything else off the platform.
The brain drain was not an accident of the civil war. It was a product of it. And it is still being paid for.
The Split
On August 1, 2017, at around 12 in the afternoon UTC, a Bitcoin miner found block 478,558.¹²⁵
It was the last block the two chains would ever share.
The big-block side had given up on changing BTC from the inside. SegWit was going to activate. The New York Agreement's hard fork was already looking shaky and would be dead by November. So instead of fighting for the existing chain, they forked off and started a new one, with the rules they believed Satoshi had intended: eight-megabyte blocks, no SegWit, and a new signature scheme called SIGHASH_FORKID that provided replay protection, so transactions on one chain could not be accidentally replayed on the other.¹²⁶ They called it Bitcoin Cash.
The first Bitcoin Cash block, number 478,559, was mined by the pool ViaBTC roughly six hours after the chains diverged, the delay caused by the new chain launching with BTC's full mining difficulty and very little hashpower pointed at it.¹²⁷ The block was 1.9 megabytes, almost twice what BTC could hold, and it carried 6,985 transactions, and the miner wrote three words into the coinbase: "Welcome to the world."¹²⁸

The price of Bitcoin Cash on its first day was chaos, because liquidity was nearly zero and every exchange was scrambling. The most-cited opening figure is around two hundred and forty dollars, but in the first hours it traded anywhere from under a hundred to nine hundred depending on the exchange and the minute.¹²⁹ Roger Ver, the early investor the community had once called Bitcoin Jesus, threw the full weight of his Bitcoin.com platform behind the new chain, arguing that it, and not BTC, was the real continuation of the peer-to-peer electronic cash described in the whitepaper.¹³⁰
And then, on November 8, the SegWit2x hard fork on the BTC side died too, the Belshe email landing eight days before it would have activated. So when the dust settled in November 2017, the scoreboard read like this. The small blockers had BTC, with SegWit, the original ticker, the network effect, the press, the exchanges, and the name. The big blockers had a brand-new minority chain, a fraction of the price, and the conviction that they were carrying the original vision into exile.
Block 478,558 was the last block they shared.
What Was Lost
The Bitcoin Civil War did not just split a blockchain. A blockchain splitting is a technical event, and technical events are recoverable. What split in 2015 through 2017 was something harder to put back together.
A community split. The people who had built Bitcoin together, who had argued on the same forums and shipped the same code and shared the same improbable dream of money without masters, ended up on opposite sides of a line they would never cross back over. Friendships ended. Careers ended. Mike Hearn left for a bank. Gavin Andresen retired from Bitcoin after he was locked out of the project he inherited from Satoshi. The builders who wanted to build anything other than a settlement layer left for other chains, some of them direct variations of Bitcoin, and never came back, and the altcoin economy grew up in the vacuum they left behind. The whole world now mistakes that vacuum-born casino for the thing Satoshi actually designed.
And here is the part that I think history will judge most harshly, once it gets far enough away to see clearly. The side that won did not win on the merits. It did not win a technical argument about throughput, or a philosophical argument about decentralization, or a democratic vote of the community. It won by controlling the reference implementation, by being funded by the incumbents who feared what Bitcoin-as-cash would do to them, by censoring the forums of open communication, by knocking dissenting nodes off the internet, and threatening dissenters with death (according to some accounts), by dressing corporate money in the costume of a grassroots revolt, and by signing agreements it had no intention of keeping. It won the name, the ticker, the network effect, and the narrative.
Small blockers, through pure guile, won almost everything.
They did not win the argument because nobody can win an argument that they refused to have.
The big blockers got a fork and a fight that was not over. And the man from Sydney, the one who walked off the Arnhem stage telling the room "you're with us or you're against us," was not done either.
Part 7 is the fork wars. Bitcoin Cash has its own civil war coming, and it is uglier and stranger than the one you just read, because this time the fight is not between the people who wanted big blocks and the people who wanted small ones. It is between the people who wanted big blocks and believed in Satoshi's vision for bitcoin, and it will tear them apart. Out of that wreckage will come the chain that the whole blockchain economy will unanimously fight against, despite (or perhaps because) its goal was simply to restore Satoshi's vision. The "benevolent dictator" from Arnhem will become a tyrant. The man from Sydney will pick up a hash war and a courtroom. And the original vision of Bitcoin, peer-to-peer electronic cash that scales on-chain without permission from anyone, will have to be carried the rest of the way by a minority chain while the small blockers get cozier with what I call the trifecta of "Big Banks, Big Tech and Big Gov!"
You read this far. You can guess where it goes from here.
But the receipts, as always, are in the footnotes. Read them.
Footnotes
¹ Mike Hearn, "The Resolution of the Bitcoin Experiment," blog.plan99.net, January 14, 2016. The "walking out of shops" description of opt-in Replace-by-Fee is the article's signature example. Text confirmed against a full mirror of the original essay.
² Hearn, "The Resolution of the Bitcoin Experiment," op. cit. The phrase "the remaining Bitcoin Core developers don't care what other people think" appears in his description of the Replace-by-Fee change.
³ Hearn, op. cit.: "I will no longer be taking part in Bitcoin development and have sold all my coins." Reported across Fortune, CoinDesk, and others, January 14-15, 2016.
⁴ Hearn, "The Resolution of the Bitcoin Experiment," op. cit. Published January 14, 2016. Hearn was a Google engineer, an architect of Bitcoin's SPV protocol, and one of Satoshi Nakamoto's documented correspondents.
⁵ Hearn, op. cit.
⁶ Hearn, op. cit.
⁷ Hearn, op. cit. Hearn's rendering of Gregory Maxwell's stated view that Bitcoin should become a settlement layer.
⁸ Hearn, op. cit.
⁹ Hearn, op. cit.
¹⁰ Hearn, op. cit., quoting the forum administrators (Theymos).
¹¹ Opt-in Replace-by-Fee (BIP 125) shipped in Bitcoin Core 0.12.0. Bitcoin Core 0.12.0 release notes, February 23, 2016.
¹² Hearn, op. cit.
¹³ Jeff Garzik and Gavin Andresen, "Bitcoin Is Being Hot-Wired for Settlement," December 2015. Title cited by Hearn; see Bitcoin Magazine coverage of the op-ed.
¹⁴ Hearn, op. cit.
¹⁵ Hearn joined R3 CEV, a bank-backed distributed-ledger consortium, after leaving Bitcoin. CoinDesk, January 15, 2016.
¹⁶ Bitcoin price data, CoinDesk Bitcoin Price Index, January 2016.
¹⁷ The Todd-Dillon correspondence, PGP-signed emails from 2013, leaked and circulated on Bitcoin forums. Primary archive: agorism.dev/petertodd-emails.txt. Discussed on Bitcointalk, topic 335658.
¹⁸ Ibid. The archive spans April 23 to October 26, 2013.
¹⁹ John Dillon to Peter Todd, August 5, 2013, agorism.dev/petertodd-emails.txt. Verbatim: "my day job involves intelligence, and I'm in a relatively high position." Dillon names no specific agency anywhere in the archive.
²⁰ Ibid. Dillon described himself as sympathetic to Snowden and Assange and cited fear of professional consequences.
²¹ Secondary syntheses of the archive attribute a roughly 0.5 to 1 BTC bounty from Dillon to Todd specifically for Replace-by-Fee work; the archive documents ongoing financial support. RBF later shipped as BIP 125 in Core 0.12.0.
²² "Why the blocksize limit keeps Bitcoin free and decentralized," posted by Peter Todd (handle "retep"), Bitcointalk topic 208200, May 17, 2013; companion site keepbitcoinfree.org. Video: youtu.be/cZp7UGgBR0I.
²³ John Dillon, Todd email archive, op. cit.: "To clarify Keep Bitcoin Free! is Peter's project, not mine. I only contributed funds and offered to let him use my name publicly as a supporter."
²⁴ Todd email archive, op. cit. Dillon sent 5.11 BTC to Gregory Maxwell for CoinJoin and expressed anger at Amir Taaki's "attempt to grab" the bounty for the competing Dark Wallet project.
²⁵ Amir Taaki (@Narodism on X), October 2024, x.com/Narodism/status/1844397475571826763.
²⁶ Amir Taaki (@Narodism on X), a separate post; reported by Gate News and CryptoNews, January 2026. The two Taaki quotes are from different posts and should not be read as a single continuous statement.
²⁷ Cullen Hoback, "Money Electric: The Bitcoin Mystery," HBO, 2024, argued Peter Todd authored the Dillon persona. Todd denies it. See Fortune, October 8, 2024.
²⁸ On the absence of a separate Bitcoin protocol specification and Core as the de facto standard, see SFOX, "Bitcoin Governance" and Bitcoin Core.
²⁹ Bitcoin-Qt was renamed "Bitcoin Core" with the 0.9.0 release, March 19, 2014. Proposed in GitHub issue #3203 by Wladimir van der Laan to "reduce confusion between the Bitcoin network and the reference client software."
³⁰ The Bitcoin Improvement Proposal process is documented in BIP 1 and BIP 2. A BIP can be accepted as a document yet never merged into Core, and is then effectively dead.
³¹ On commit access and maintainership concentration, see Bitcoin Core governance discussions and contemporary analyses.
³² Wladimir van der Laan became lead maintainer on April 8, 2014, succeeding Gavin Andresen, and served until 2022. Bitcoin Wiki.
³³ Bitcoin Core 0.12.0 release notes, February 23, 2016.
³⁴ Blockstream Series A, $55 million, announced February 3, 2016, co-led by AXA Strategic Ventures, Horizons Ventures, and Digital Garage. Blockstream press release; CoinDesk. On AXA and its conflicts, see Part 4B.
³⁵ Hong Kong Roundtable, February 21, 2016, Cyberport. "Bitcoin Roundtable Consensus," Medium, February 21, 2016. Covered in Part 5.
³⁶ Ibid. The agreement committed to a hard fork recommendation "within three months after the release of SegWit," increasing non-witness data to roughly 2MB with total size no more than 4MB.
³⁷ Ibid. Individual Core-developer signatories: Cory Fields, Johnson Lau, Luke Dashjr, Matt Corallo, Peter Todd. Adam Back signed as President of Blockstream.
³⁸ The 2MB hard fork promised in Hong Kong was never delivered. See Bitcoin Magazine, "The Status of the Hong Kong Hard Fork".
³⁹ Gregory Maxwell did not sign the Hong Kong Agreement and rejected it; the broader Core team treated the individual signatures as non-binding. CCN.
⁴⁰ Gang Wu (HaoBTC), quoted in CCN.
⁴¹ Hearn, "The Resolution of the Bitcoin Experiment," op. cit.
⁴² BIP 125, Opt-in Full Replace-by-Fee Signaling, David A. Harding and Peter Todd, assigned December 4, 2015. GitHub.
⁴³ BIP 141, Segregated Witness, Eric Lombrozo, Johnson Lau, Pieter Wuille, assigned December 21, 2015. GitHub.
⁴⁴ BIP 9, Version bits with timeout and delay, Pieter Wuille, Peter Todd, Greg Maxwell, Rusty Russell. GitHub.
⁴⁵ BIP 102, Block size increase to 2MB, Jeff Garzik, assigned June 23, 2015; never merged. GitHub.
⁴⁶ Andy Greenberg, "Bitcoin's Creator Satoshi Nakamoto Is Probably This Unknown Australian Genius," Wired, December 8, 2015; Sam Biddle and Andy Cush, "This Australian Says He and His Dead Friend Invented Bitcoin," Gizmodo, December 8, 2015. ATO raid December 9, 2015. Covered in Part 5.
⁴⁷ Craig Wright, "Jean-Paul Sartre, Signing and Significance," drcraigwright.net, May 2, 2016 (later deleted). On the Sartre framing and the failed proof, see Errata Security, "Satoshi: how Craig Wright's deception worked", May 3, 2016.
⁴⁸ Wright gave interviews to the BBC, the Economist, and GQ on May 2, 2016. Al Jazeera, May 2, 2016.
⁴⁹ Rory Cellan-Jones, BBC Technology Correspondent, filmed Wright (the interview was filmed in late April; reporting went live May 2, 2016).
⁵⁰ Craig Wright to the BBC, May 2, 2016. "Mr Bitcoin: 'I don't want money, I don't want fame!'", BBC News.
⁵¹ Gavin Andresen described a private London signing session on a clean laptop with freshly downloaded software. See CoinMarketCap, "Satoshi Files: Gavin Andresen".
⁵² The signing block is disputed: Andresen's sworn deposition in Kleiman v. Wright recalled block 1 ("if I recall correctly"); most contemporary press reported block 9 (Hal Finney's block). See Bitcoin.com.
⁵³ Gavin Andresen, "Satoshi," gavinandresen.ninja, May 2, 2016. In a 2023 revision Andresen added that trusting Wright "was a mistake."
⁵⁴ The public proof reused a signature from a 2009 Satoshi transaction already on the blockchain. Errata Security, May 3, 2016; Jordan Pearson and Lorenzo Franceschi-Bicchierai, Motherboard/VICE, May 2, 2016.
⁵⁵ Patrick McKenzie, patio11/wrightverification, May 2, 2016: "Wright's post is flimflam and hokum which stands up to a few minutes of cursory scrutiny."
⁵⁶ Dan Kaminsky, "The Cryptographically Provable Con Man," dankaminsky.com, May 3, 2016.
⁵⁷ Gregory Maxwell produced detailed technical rebuttals within hours of both the December 2015 Wired/Gizmodo reveal and the May 2016 proof. See CoinDesk, December 10, 2015, and hacking distributed, "Extraordinary Satoshi Claims", May 2, 2016.
⁵⁸ Gavin Andresen, sworn deposition, Kleiman v. Wright (S.D. Fla.), 2020: "Craig disappeared upstairs and then was found bleeding with cuts to his neck, and then was taken to the hospital in an ambulance with an apparent suicide attempt." Reported by CryptoPotato and Cointelegraph. Andresen's knowledge was second-hand, relayed via email and a later call.
⁵⁹ Ibid.
⁶⁰ Craig Wright, "I'm Sorry," drcraigwright.net, May 5, 2016 (subsequently deleted). The Register, SiliconAngle, and NPR, May 5, 2016.
⁶¹ Wright, "I'm Sorry," op. cit., verbatim as reproduced by contemporaneous outlets.
⁶² Post to the Bitcoin-dev mailing list from satoshi@vistomail.com, December 10-11, 2015: "I am not Craig Wright. We are all Satoshi." Hacker News thread; CoinDesk. The account was widely considered compromised.
⁶³ The satoshin@gmx.com account was hijacked in September 2014 via a password reset, as documented in Part 5 and BitMEX Research.
⁶⁴ Ian Grigg is the inventor of the Ricardian contract and a veteran of financial cryptography.
⁶⁵ Ian Grigg, "Satoshi is dead, long live Satoshi," Financial Cryptography, May 2, 2016. Confirmed verbatim from the live page.
⁶⁶ CARS = CAcert Assurer Reliable Statement. Grigg defined it in the comments of the same post.
⁶⁷ Ian Grigg, comments on "Satoshi is dead," op. cit.
⁶⁸ Grigg, "Satoshi is dead," op. cit.
⁶⁹ Ian Grigg, "Oh no, not another bloody Satoshi sighting," Financial Cryptography, May 4, 2017. Confirmed verbatim from the live page.
⁷⁰ Grigg, "Oh no, not another bloody Satoshi sighting," op. cit.
⁷¹ Phil Wilson ("Scronty"), "Bitcoin Origins," vu.hn/bitcoin origins.html, first posted to Reddit November 1, 2016. The seven-hour interview is Steve Patterson's "Patterson in Pursuit," Episode 94, youtu.be/_OPCVeo1u20, September 2, 2018.
⁷² Wilson, "Bitcoin Origins," op. cit. W&K Info Defense Research LLC was registered February 16, 2011.
⁷³ Ibid. Wilson's own disclaimer.
⁷⁴ Craig Wright has denied any collaboration with Wilson and called him a scammer. Wright's statements reported in contemporaneous coverage; see also Bitcoin.com.
⁷⁵ Martti Malmi (Sirius), denial of Wilson's logo claim, quoted in CoinDesk, "About That Orange B", May 18, 2019.
⁷⁶ Ibid. CoinDesk attributed the orange "B" logo to an anonymous user "bitboy" (November 2010) and characterized Wilson's account as "extensive fan fiction."
⁷⁷ Uyen Nguyen, director of W&K Info Defense Research; reportedly controlled Wright's Twitter in 2015-2016 and deleted her accounts in early May 2016. Bitcoin News. Court testimony places her in her early twenties at the time of the directorship.
⁷⁸ Joseph Vaughn-Perling, director of the New Liberty Dollar (founded by Bernard von NotHaus), claimed in Bitcoin Magazine (May 2016) to have met Wright at "What the Hack 2005" wearing a "Satoshi Nakamoto" badge. Subpoenaed in Kleiman v. Wright, 2019.
⁷⁹ Bitcoin Magazine noted it could not independently corroborate Vaughn-Perling's account. Ibid.
⁸⁰ Documents purporting to grant Nguyen authority over W&K were alleged in court to bear signatures dated after Dave Kleiman's death. WizSec, February 2018.
⁸¹ Gavin Andresen's Bitcoin Core commit access was revoked on May 2, 2016. CCN.
⁸² Peter Todd, public announcement, May 2, 2016: "FYI, @gavinandresen's commit access just got removed; Core team members are concerned that he may have been hacked." Peter Todd on Twitter.
⁸³ Wladimir van der Laan, on revoking Andresen's GitHub ownership: "the prudent thing to do was to revoke his ownership of the 'bitcoin' organization on github... immediately." Bitcoinist; NewsBTC.
⁸⁴ Andresen had stepped back from lead maintainership in 2014; his commit access by 2016 was largely ceremonial, which makes the symbolic weight of the revocation the point.
⁸⁵ On the alert key Satoshi transferred to Gavin Andresen in 2011, see Part 3 and Part 5.
⁸⁶ On Adam Back as a recurring "safe" Satoshi candidate and the 2026 New York Times investigation by John Carreyrou, see my rebuttal: Kurt Wuckert Jr., "John Carreyrou Spent a Year Hunting Satoshi Nakamoto and Found a Hyphen." Earlier Back speculation: Financial Times (2016), John McAfee (2018), HBO's "Money Electric" (2024).
⁸⁷ Hal Finney received the first Bitcoin transaction from Satoshi, January 12, 2009. On the recurring Finney theory, see Kurt Wuckert Jr., "Finding Satoshi: Not Even a Fresh Guess."
⁸⁸ Hal Finney died of ALS complications on August 28, 2014.
⁸⁹ Nick Szabo on Bit Gold: "I was trying to mimic as closely as possible in cyberspace the security and trust characteristics of gold." Szabo was named in a 2014 Aston University linguistic study and an earlier "Skye Grey" analysis; he has denied being Satoshi.
⁹⁰ The Crypto Open Patent Alliance (COPA) was founded by Square (now Block) in September 2020; members include Coinbase, Kraken, MicroStrategy, Blockstream, Chaincode, and Meta (which joined January 2022, not at founding). COPA v. Wright: Justice James Mellor's oral ruling, March 14, 2024, found the evidence "overwhelming" that Wright is not Satoshi; written judgment May 20, 2024, found forgery "on a grand scale." See UK Judiciary, COPA v. Wright and Part 4B.
⁹¹ Kleiman v. Wright (S.D. Fla., verdict December 6, 2021); Wright v. McCormack (UK, 2022); Granath v. Wright / "Hodlonaut" (Oslo, 2022); COPA v. Wright (UK, 2024). No other Satoshi candidate has faced comparable litigation.
⁹² Pieter Wuille presented Segregated Witness at Scaling Bitcoin Hong Kong, December 6-7, 2015. Scaling Bitcoin.
⁹³ SegWit introduces a block weight limit of 4,000,000 weight units; base transaction bytes count as 4 weight units, witness bytes as 1, a 75% discount, yielding effective capacity of roughly 1.7-2MB. Bitcoin Magazine, "Witness Discount"; SegWit, Wikipedia.
⁹⁴ Hearn, "The Resolution of the Bitcoin Experiment," op. cit.: "an anemic 60% capacity increase only through an accounting trick (not counting some of the bytes in each transaction)."
⁹⁵ Jeff Garzik argued SegWit "does not provide any amount of predictable added capacity, due to the opt-in nature." Garzik, Medium.
⁹⁶ SegWit fixed transaction malleability (the same issue Mt. Gox blamed in 2014, see Part 5), a prerequisite for the Lightning Network. On the constrain-base-layer-then-sell-Layer-2 business model, see Part 4B.
⁹⁷ Gregory Maxwell, "Inhibiting a covert attack on the Bitcoin POW function," bitcoin-dev mailing list, April 5, 2017.
⁹⁸ Ibid., verbatim.
⁹⁹ On ASIC Boost mechanics and the ~15-20% efficiency gain, see Bitcoin Optech, "ASICBoost" and Bitcoin Magazine, "Breaking Down the ASICBoost Scandal".
¹⁰⁰ Covert ASIC Boost is incompatible with SegWit because SegWit's witness commitment breaks the fixed-chunk trick. Bitcoin Optech.
¹⁰¹ Bitmain, run by Jihan Wu (co-founder and co-CEO with Micree Zhan), was the largest mining-hardware manufacturer and the focus of the allegations.
¹⁰² Jihan Wu / Bitmain response: the capability exists in hardware and is patented, but was only tested on testnet, "never used it on main net in production." CCN.
¹⁰³ BitMEX Research, "An Overview of the Covert AsicBoost Allegation": "the evidence is not conclusive."
¹⁰⁴ Barry Silbert (Digital Currency Group), "Bitcoin Scaling Agreement at Consensus 2017," Medium, May 23, 2017. On DCG's investors, see Part 4B.
¹⁰⁵ Ibid. 58 companies, 83.28% of hashing power, as of the May 25, 2017 count.
¹⁰⁶ Ibid. Signatories included Bitmain, Coinbase, Xapo, Blockchain, BitPay, Circle, BitFury, ShapeShift, BitGo, and Bloq.
¹⁰⁷ Ibid. Terms: activate SegWit at an 80% threshold (bit 4), then a 2MB hard fork within six months ("SegWit2x").
¹⁰⁸ Blockstream and the Bitcoin Core developers did not sign the New York Agreement. Bitcoin Magazine.
¹⁰⁹ SegWit locked in August 9, 2017, and activated at block 481,824 on August 24, 2017. Bitbo; learnmeabitcoin.com.
¹¹⁰ The SegWit2x hard fork was scheduled for block 494,784, around November 16, 2017. segwit2x.github.io.
¹¹¹ Samson Mow, by then Chief Strategy Officer of Blockstream, produced and distributed NO2X hats; wearing them functioned as a public loyalty signal. Bitsonline.
¹¹² Mike Belshe (CEO, BitGo), SegWit2x suspension email, November 8, 2017. CoinDesk; TechCrunch.
¹¹³ Ibid. Co-signers: Wences Casares (Xapo), Jihan Wu (Bitmain), Jeff Garzik (Bloq), Peter Smith (Blockchain), Erik Voorhees (ShapeShift).
¹¹⁴ Barry Silbert, who convened the New York Agreement, did not sign the cancellation email.
¹¹⁵ BIP 148 (User Activated Soft Fork) was authored by the pseudonymous "shaolinfry," March 2017. GitHub. The chain-split risk was defused by James Hilliard's BIP 91, which activated SegWit signaling before the August 1 deadline.
¹¹⁶ August 1, 2017 was branded "Bitcoin Independence Day." Bitbo.
¹¹⁷ On Blockstream's AXA funding and DCG's MasterCard, Western Union, CME, and New York Life investors, and their conflicts of interest with peer-to-peer cash, see Part 4B and Kurt Wuckert Jr., "BTC Was Hijacked, Everyone Knows It."
¹¹⁸ The big-block side was funded primarily by Bitcoin-native interests, including the investor Roger Ver and the miner/manufacturer Bitmain.
¹¹⁹ "The Future of Bitcoin" conference, Arnhem, Netherlands, June 30 - July 1, 2017. thefutureofbitcoin.com.
¹²⁰ Amaury Séchet, French software engineer, formerly at Facebook, left to work on Bitcoin full-time in early 2017. IQ.wiki.
¹²¹ Séchet's Arnhem talk was titled "Back to Basics"; he unveiled Bitcoin ABC, an 8MB client without SegWit. Bitsonline; Bitcoin Magazine.
¹²² Craig Wright, "The Future of Bitcoin is Unlimited," Arnhem, June 30, 2017. Notes and coverage: GitHub gist; Bitsonline; Bitcoinist.
¹²³ 2017 ICOs raised roughly $4.9-6 billion and surpassed early-stage venture funding by August 2017. CNBC; Crunchbase News.
¹²⁴ The DAO hack (June 17, 2016, ~3.6 million ETH) led to Ethereum's hard fork on July 20, 2016, splitting ETH and Ethereum Classic. CoinDesk. On Ethereum as the destination for builders driven off Bitcoin, see Part 5 and Kurt Wuckert Jr., "What Is the Difference Between Bitcoin and Ethereum?"
¹²⁵ Last common block 478,558, found approximately 12 UTC on August 1, 2017. Bitcoin Magazine, "The Birth of BCH"; Bitcoin Cash, Wikipedia.
¹²⁶ Bitcoin Cash parameters: 8MB blocks, no SegWit, SIGHASH_FORKID replay protection, and an Emergency Difficulty Adjustment. Reference.cash.
¹²⁷ First Bitcoin Cash block, 478,559, mined by ViaBTC approximately six hours after the split. Bitcoin.com.
¹²⁸ Ibid. The block was approximately 1.9MB with 6,985 transactions; the coinbase read "Welcome to the world."
¹²⁹ Initial BCH price discovery was chaotic, with a most-cited figure near $240 and a first-day range from under $100 to roughly $900 depending on exchange. sFOX.
¹³⁰ Roger Ver and Bitcoin.com backed Bitcoin Cash as the continuation of peer-to-peer electronic cash. Bitcoin Cash, Wikipedia.
Be good to each other. And read the footnotes.
Kurt Wuckert Jr. is the world's foremost Bitcoin Historian. The Written History of Bitcoin is published one installment at a time at kurtwuckertjr.com.