The Written History of Bitcoin: The First Shots of the Bitcoin Civil War
By Kurt Wuckert Jr.
The Soup
On a Saturday in late January 2013, in a federal office building in Baltimore, a man covered his face in cream of mushroom soup and lay down on a bathroom floor.¹
The soup was his wife's idea. She had been told to bring cleaning products and chicken stars, but the kitchen pantry that morning was thin, and what she had was a can of Campbell's. She emptied it onto his face, his neck, his chest. She put a little on the tile so the puddle looked right. He posed. He drowned the way the script needed him to drown. They took ten photos. The federal agents standing in the bathroom approved.
The man on the floor was Curtis Clark Green. He was forty-seven years old, ran a cat-rescue out of Spanish Fork, Utah, and had been working part-time as a customer-service moderator for an online drug market accessible only through Tor. The agents standing over him with the camera were employees of the Drug Enforcement Administration and the United States Secret Service. They sent the photos to Green's boss, a man known on the other side of the network as Dread Pirate Roberts.
DPR replied within hours.
"I've received the picture and deleted it. Thank you again for your swift action."²
Then he wired the price. Eighty thousand dollars, paid in Bitcoin, to the man who had brokered the contract. Half in advance. Half on delivery.
The man receiving the bitcoin was Carl Mark Force IV, a fifteen-year DEA veteran assigned to the Baltimore Silk Road task force. The contract he had just been paid for was a murder he had staged on a bathroom floor with chicken soup. The targeted victim was alive in the next room, and Carl Force was about to deposit the money into his own account.³

That is where Part 5 starts.
Part 4 ended with the libertarian bookstore kids in Austin arguing about Rothbard at Garrison Hall and a senator named Chuck Schumer demanding the federal government shut down the marketplace they had inspired. Part 4B ended with twenty-one million dollars in venture capital, a Manhattan townhouse, and a private island. The gatekeepers were coming.
Part 5 is where they arrive.
It is also where the libertarian dream that animated Austin in 2011 hits the wall it cannot climb. The marketplace gets seized. The exchange gets vaporized. The Bitcoin reputation in the press collapses from "the future of money" to "the currency of drug dealers and Mt. Gox." And in the rubble, a small group of developers will quietly take possession of the most important piece of open source infrastructure in the world and start rewriting what it is allowed to do.
By December 2015, two magazines on two continents will publish on the same day. An empty house in a Sydney suburb will be raided by the Australian Tax Office. A man with a supercomputer claim and a dead business partner will already be on a plane or maybe in a bus station bathroom hiding out. And the civil war that defines the next decade of bitcoin will have its opening battle.
This is that story.
Follow along in the live video presentation after March 29, 2026.
The Library
The library version is the one everyone knows.
On October 1, 2013, FBI agents arrested Ross William Ulbricht in the science fiction section of the Glen Park branch of the San Francisco Public Library.⁴
We told the arrest story in Part 4.
The seizure that followed pulled approximately 144,000 BTC off Silk Road servers and the laptop, with the FBI's reported total at 144,342 BTC.⁵ At October 2013 prices that was approximately thirty-three million dollars. By the time the Department of Justice auctioned the bitcoin off in tranches across 2014 and 2015, it would be worth a great deal more, and the buyers, particularly Tim Draper and the Pierce-adjacent Binary Financial fund, would walk away with positions that defined their careers.
Federal prosecutors alleged that Ulbricht, or someone who shared admin credentials with him, had paid approximately seven hundred and thirty thousand dollars in murder-for-hire deals targeting at least five people.⁶ The targets were people who had threatened to dox him or expose the marketplace. The contracts were paid in bitcoin. The killings, in every case the government investigated, never actually occurred. He was charged for the murder-for-hire counts in a separate sealed indictment in the District of Maryland that was never tried. The trial in the Southern District of New York convicted him on seven counts of distributing narcotics, conspiracy, money laundering, and running a continuing criminal enterprise. Evidence of the murder-for-hire was introduced at trial as character context for the sentencing.⁷
On May 29, 2015, Judge Katherine B. Forrest of the Southern District of New York sentenced Ross Ulbricht to five sentences served concurrently, including two life sentences and forty additional years.⁸ No parole. Forrest's stated reason was deterrence. She wanted other people who imagined building a Silk Road to know what it cost.
The libertarian bookstore in Austin felt very far away.
There was something else the press did not lead with. Two of the federal agents who investigated DPR were stealing on the side.
Carl Mark Force IV was a Special Agent with the Drug Enforcement Administration assigned to the Baltimore task force.⁹ Operating as "Nob," he had built a months-long relationship with DPR posing as a top-tier drug broker. He used that relationship to do real undercover work, including the Curtis Green staged-death operation that DPR commissioned. He also used it to do unreal work. In August 2013, Force, still posing as Nob, convinced Ulbricht to pay him fifty thousand dollars in bitcoin in exchange for fictional intelligence about the federal investigation. The intelligence was real, because Force was inside it. The transaction was the bribe.
He then adopted a second persona, "French Maid," and used it to extort additional bitcoin from DPR by selling him information about his own investigation. Force channeled more than four hundred thousand dollars in cryptocurrency into his personal bank accounts during the operation.¹⁰
Shaun Bridges was a Special Agent with the United States Secret Service on the same Baltimore task force.¹¹ Bridges used admin credentials he had obtained during the investigation to drain customer accounts on Silk Road, then framed the theft on a moderator named "Flush." The theft was approximately twenty thousand bitcoin, worth around three hundred and fifty thousand dollars at the time. He then sold a separate batch of bitcoin into a Mt. Gox account and watched the value climb. Later, after the bureau had already begun investigating him, he stole an additional 1,606 BTC from a government-controlled wallet he had been entrusted with as part of the post-arrest seizure.¹²
Force pleaded guilty in 2015 and was sentenced on October 19, 2015, to seventy-eight months in federal prison.¹³ Judge Richard Seeborg, on the bench in San Francisco, described the scope of his betrayal as "breathtaking."
Bridges pleaded guilty separately and was sentenced on December 7, 2015, to seventy-one months. He pleaded guilty again, after additional theft was uncovered, and received another twenty-four months consecutive.¹⁴ Combined, he served nearly eight years.
The murder-for-hire that opened this article had three layers. There was DPR, who authorized it. There was Carl Force, who staged it. And there was the bitcoin that paid for it, which Force pocketed and Ulbricht thought had bought a death.
Two of those three layers were a federal agent committing felonies.
There is a clean version of the Silk Road takedown where the FBI, the DEA, and the Secret Service do their jobs, and a kid in Texas who built a drug market goes to prison forever. There is a dirty version where two of the agents on the case are committing their own crimes while building the case. Both are true. The clean version is what got Ross Ulbricht sentenced to two life sentences. The dirty version is what got him pardoned ten years later.
On January 21, 2025, President Donald Trump granted Ross Ulbricht a full pardon.¹⁵ Not a commutation. A pardon. Trump had promised a commutation at the Libertarian National Convention in May 2024. He delivered something stronger.
But that is the end of the Silk Road thread. We are still in October 2013, watching the marketplace fall.
The price of bitcoin on the day of Ulbricht's arrest was approximately $123. By November 2013 it would peak at $1,242 on Mt. Gox.¹⁶ And then Mt. Gox ceased to be a reliable exchange, to say the least...
Tokyo
On February 7, 2014, Mt. Gox halted Bitcoin withdrawals.¹⁷
The announcement was technical. An alleged bug in the protocol called transaction malleability, the exchange claimed, was preventing it from tracking which withdrawals had completed. Karpelès would later expand on the explanation in a press conference and in court filings. Customers, the announcement implied, should be patient. The exchange was working with developers to fix the issue.
The explanation had the texture of plausibility. Transaction malleability was a real, documented quirk in the Bitcoin protocol. A third party could rebroadcast a transaction with a different transaction ID by modifying the signature without invalidating it. An exchange that tracked withdrawals by transaction ID rather than by destination address could be tricked into thinking a withdrawal had failed and re-issuing it. Several other exchanges had been affected.¹⁸
An old friend and colleague named Jon Southurst was on the scene to look into it. He's the man filming this now infamous video.
The explanation also was, in the words of one developer who had been warning about Gox internally for years, "a fucking lie."
People who were paying attention weren't shocked by the quote...

Behind the scenes, the exchange was insolvent. It had been insolvent for years. The first significant theft had occurred in 2011 under Jed McCaleb's ownership, before he sold the exchange to Mark Karpelès in March of that year.¹⁹ By October 2011, approximately eighty-five thousand bitcoin had already been drained from Gox cold storage. The exchange had continued operating, taking deposits, publishing quoted prices, and processing what looked like withdrawals while the deficit grew.
By February 2014, the deficit was approximately 850,000 bitcoin.²⁰ Of those, roughly 750,000 belonged to customers. The remaining 100,000 belonged to the exchange itself. At the November 2013 peak, those bitcoin would have been worth more than a billion dollars. At the February 2014 spot price, around 450 million dollars. Either way, it was the largest theft of any kind in the short history of digital currency.
On February 24, 2014, a document leaked to a Bitcoin entrepreneur named Ryan Selkis and was published on a blog called The Two-Bit Idiot.²¹ The document was titled "Crisis Strategy Draft." It laid out the exchange's options for managing the insolvency, including a controlled liquidation. It also confirmed the missing balance. Selkis published. The community read.
The exchange stopped trading the same day.
On February 28, 2014, Mt. Gox filed for civil rehabilitation, the Japanese equivalent of Chapter 11, in the Tokyo District Court.²² Reported liabilities were 6.5 billion yen, approximately sixty-five million dollars at the time. Assets were 3.84 billion yen. By April 16, 2014, the court had abandoned the rehabilitation plan and converted the case to a liquidation. On March 20, 2014, the exchange had announced it had located approximately 199,999 BTC in an old wallet that had not been swept since June 2011. The discovery, and the timing, made many in the community suspect Karpelès had known where it was the whole time.²³
Mark Karpelès himself was arrested in Tokyo on August 1, 2015.²⁴ He was charged with falsification of corporate records, fraud, and embezzlement. In March 2019, the Tokyo District Court found him guilty of falsifying records and gave him a suspended two-and-a-half-year sentence. He was acquitted on the embezzlement and breach of trust charges. He has maintained, in every public statement since, that the bitcoin was stolen, not taken by him.
The community had a phrase by then for the exchanges. "Not your keys, not your coins." It had not been the operating principle of any major exchange in 2013. It became the operating principle of the survivors.

Eight hundred and fifty thousand bitcoin. Gone.
The price did not survive the news. It had peaked above twelve hundred dollars in late November 2013. By April 2014 it was in the high three hundreds. By the end of 2014 it was below three hundred. By January 2015 it was around two hundred. It would not see another four-figure print until the very end of 2016.²⁵
The press had a new story now. Bitcoin was the currency of drug dealers and incompetent Japanese exchanges. The "currency of the future" framing of 2011 and 2013 disappeared. Mainstream coverage in 2014 and 2015 was almost uniformly negative.
The private narrative, however, was something else entirely. Inside the offices of legacy finance, inside venture capital, inside the network we mapped in Part 4B, the people who had been waiting for a buying opportunity had one. The price was off ninety percent from peak. The reputation was in ruins. The retail buyers were panicking out. The infrastructure was orphaned and cheap. If you wanted to acquire a meaningful position in bitcoin without moving the price, 2014 was the year to do it. And if you wanted to acquire a meaningful position in the developers who decided what bitcoin was allowed to do, 2014 was also the year for that.
You already know who was paying them. We traced that money to Little Saint James Island in Part 4B.
Catch up here, if you aren't familiar with the deep connections to Jeffrey Epstein:
The Long Winter
Most of what is now called the "Bitcoin Civil War" took place between late 2014 and late 2017. But the long winter that preceded it, the bear market and the narrative collapse of 2014, is what created the conditions for the war.
While the price was draining and the retail traders were leaving, three things were happening that the casual reader did not see.
The first thing was that builders were still building. Not in the marketplaces, not on the exchanges, but on the protocol itself. Tokens. Trading cards. Provably fair gambling. Data layers. The "Bitcoin 2.0" wave of applications that wanted to do more with the blockchain than just send money.
The second thing was that the people who were the de facto controllers of the codebase, a handful of developers with commit access to Bitcoin Core, were starting to make decisions about what Bitcoin would be allowed to do. They were not decisions made by Satoshi. Satoshi had been gone for nearly three years. They were decisions made by a small number of developers whose individual philosophies about what Bitcoin should be diverged sharply from one another, and whose technical disagreements were about to become the central conflict of the next decade.
The third thing was that a man in Sydney had been writing academic papers about Bitcoin since 2008 or 2010 or 2011 or 2013, depending on who you ask. He had a list of Australian companies. He had an accounting background, a cybersecurity background, a theology background, a telecom background, a Microsoft background, and a gambling industry background. He had a business partner who was bound to a wheelchair, edited white papers, handled digital forensics, and was the first expert technical witness in Jeffrey Epstein's first court case. Together, they were leaving a public breadcrumb trail that would later lead two American magazines to publish stories about them on the same day.
We will get to them later.
First, the builders.
The Builders in the Rubble
In April 2012, an American libertarian named Erik Voorhees launched a website called Satoshi Dice.²⁶
The premise was clean. A user sent bitcoin to one of several published addresses, each with a different payout multiplier. The site's server, using a published seed, determined whether the bet won or lost. Winning bets were paid back to the sending address automatically. Losing bets stayed with the house. The entire process happened on the Bitcoin blockchain with no account, no signup, and no custody.
At its peak in early 2013, Satoshi Dice was responsible for more than half of all transactions on the Bitcoin network.²⁷
On July 17, 2013, Voorhees announced that he had sold Satoshi Dice for 126,315 BTC, approximately 11.5 million dollars at the time.²⁸ It was the first major bitcoin company acquisition. It was also a demonstration. The Bitcoin network had handled millions of micropayment-style transactions for a gambling site, run by a single person, with no scaling crisis, no fork, no protocol change. The capacity was there. The capacity had been there from the start. Satoshi had said so, and people were proving it with their business ideas!
In January 2014, three developers named Robby Dermody, Adam Krellenstein, and Evan Wagner launched a platform called Counterparty.²⁹ It was an asset-issuance system built directly on top of Bitcoin. It used a Bitcoin transaction feature called OP_RETURN to embed metadata. That metadata defined tokens, asset transfers, and the rules of decentralized exchanges. Counterparty did not run a separate blockchain. It used Bitcoin as the transaction, settlement, and the data layer.
Every Counterparty transaction was a Bitcoin transaction.
The launch was funded in an unusual way. From January 2 to February 3, 2014, anyone could send bitcoin to a provably unspendable Bitcoin address. In return, they received the platform's native unit, XCP, at a published ratio. The community called this "proof of burn." Approximately 2,140 BTC, worth between 1.6 and 2 million dollars at the time, were destroyed in the burn. The destruction was not a fee paid to insiders. It was math. Counterparty was launched without a founder allocation and without a presale to friends.
Within a year, Counterparty had become the first platform to put serious tokens on Bitcoin. A Swiss studio called EverdreamSoft used the platform to issue a trading card game called Spells of Genesis.³⁰ Other projects, including LTBcoin (run by the podcaster Adam B. Levine) and Storj (a decentralized storage project), built on Counterparty. The Omni Layer, which had launched in 2013 as Mastercoin and run the first ICO, used the same family of techniques.³¹
If you had been watching the Bitcoin protocol in 2014, you would have seen a Cambrian explosion in the early stages. The blockchain was a settlement layer for payments. It was also a settlement layer for trading cards, prediction markets, tokenized assets, file storage receipts, identity claims, and a hundred other experiments. The line between "data" and "money" was not a line the protocol enforced. The protocol enforced unspendable destinations, valid signatures, and the proof-of-work consensus that ordered the ledger. Everything else was application.
Bitcoin in 2014 was on its way to becoming an everything-platform.
That is when the rug got pulled.
The Zealot with Commit Access
To understand the next part, you have to understand a developer named Luke Dashjr.³²
Luke Dashjr lives in Florida. He has been a contributor to Bitcoin Core since 2011. He created the Eligius mining pool, one of the earliest pools, in 2011 as well. He is a devout traditional Catholic. He holds sedevacantist views, meaning he believes the post-Vatican II popes are not legitimate.³³ He has publicly expressed geocentric views, meaning he believes the sun revolves around the earth.³⁴ He has, in publicly archived statements over the years, framed his belief that animals exist for human use, including using pets as food.³⁵

He is also the most consequential developer in the history of OP_RETURN.
Eligius, his pool, became famous for one specific operational decision. When users submitted Bitcoin transactions that Luke regarded as "spam," Eligius refused to include them in the blocks it found.³⁶ The criteria were Luke's criteria. Transactions that embedded non-financial data, transactions that paid below his preferred fee threshold, transactions that referenced specific known applications he objected to. The pool was running its own censorship policy years before the rest of the Bitcoin Core ecosystem started talking about "transaction filtering" as a virtue.
Eligius foreshadowed the philosophy. Bitcoin's job, in Luke's framing, was monetary savings. Anything else was waste. Anything else was spam. The blockchain should not be allowed to carry it, and a mining pool that helped suppress it was doing the network a favor.
This is not a hidden view. Luke has stated it explicitly in conference talks, on the Bitcoin developer mailing list, in his Bitcoin Knots fork release notes, and on Twitter for more than a decade. He believes the Bitcoin blockchain should carry monetary transactions, period, and that anything else is "abuse" of the network.³⁷
He's very direct on his beliefs.
The man who runs the most aggressive transaction filtering policy in Bitcoin's history also has commit access to the most important open source project in cryptocurrency. In fact, for many years, he was the sole "BIP Editor."
That combination, in March 2014, produced the rug-pull.
The OP_RETURN Rug-Pull
OP_RETURN is a Bitcoin script opcode. In the original Bitcoin protocol, it allowed a transaction to embed arbitrary data inside an unspendable output. That output was provably unspendable, which meant it would never be carried in the UTXO set, the running database of who could spend what. The UTXO set is the hot, in-memory state that every full node maintains. Keeping it manageable is important. OP_RETURN was the elegant solution. You could embed data on chain, the data would be in the historical blockchain forever, and the running node state would not grow.
In Satoshi's original implementation, OP_RETURN had no specific byte limit other than the general transaction size limit. Multiple early applications used it freely.
On February 25, 2014, pull request #3737 was opened to reduce the standard OP_RETURN data size from 80 bytes (which was the proposed standard in the upcoming Bitcoin Core 0.9.0 release) to 40 bytes.³⁸ The pull request was merged two days later, on February 27, 2014. The change shipped in Bitcoin Core 0.9.0 on March 19, 2014.
The pull request itself was opened by Jeff Garzik. It was merged by Gavin Andresen. The political pressure behind it, and the loudest voice in the public discussion thread on GitHub, was Luke Dashjr.³⁹
Luke's framing of the issue is on the record in the PR comments themselves. When a developer named gidgreen asked why a feature was being added that users were not supposed to use, Luke wrote:
"OP_RETURN is being added because some people insist on abusing the blockchain. This gives them a less painful way to do it. An analogy would be a rape victim not-resisting to try to minimise the damage."
Pretty grim...
The other Core developer who chimed in to support the framing was Pieter Wuille, then a recent Bitcoin Core committer, who wrote that OP_RETURN was "still abuse, it just hurts a bit less if you use OP_RETURN" in the same thread. Gavin Andresen, who merged the change, eventually pushed back on the language, writing that "words like 'abuse' and 'rape' aren't helpful." But the merge had already gone through.
The rationale Luke and his ideological allies articulated, repeatedly across forum posts, mailing list threads, and conference talks over the following years, was that data on the blockchain was wasteful. Allowing larger data carriers, in his framing, encouraged exactly the kind of "non-financial" use cases he had been excluding from Eligius blocks. Forty bytes was enough to hold a hash, and a hash was enough to anchor a document or a state root, so applications that needed more data could keep that data off-chain and just anchor it. Eighty bytes, in his view, allowed too much.
The downstream effect was immediate.
Counterparty, which had launched in January 2014 and had been actively building on the OP_RETURN field, was forced to scramble.⁴⁰ Several Counterparty transaction types embedded metadata that exceeded the new 40-byte limit. Within weeks of the 0.9.0 release, those transaction types stopped propagating across the network. Some Counterparty applications, including early versions of Spells of Genesis, had to be re-architected to use multi-output workarounds, additional fees, and protocol changes that the Counterparty team did not control.
Mastercoin, now Omni, had the same problem.⁴¹
Colored coins implementations had the same problem.
A small but real subset of the "Bitcoin 2.0" wave migrated.⁴² Some projects pivoted to Litecoin. Some, including a Counterparty-adjacent project called Storj, would eventually migrate to Ethereum once Ethereum existed.

The applications did not crash. They just stopped working because someone was able to change a major property of bitcoin.
On November 16, 2014, a pull request was opened to raise the OP_RETURN limit back up.⁴³ It was merged on February 4, 2015, and shipped in Bitcoin Core 0.10. The new limit was 80 bytes. The 40-byte limit had lasted exactly one release cycle.
In the public framing of the Bitcoin Core team, this was simply iterative engineering. A conservative parameter had been set. Real-world usage had demonstrated that the parameter could be relaxed. The community had asked. The community had been heard.
In the private experience of every team that had been building on Counterparty, Mastercoin, or colored coins in February 2014, this was a developer with commit access using that access to break the live businesses of his competitors and ideological adversaries. The fact that the limit was raised eleven months later did not undo the damage. The Counterparty team did not get back the eleven months. The Omni team did not get back the user base that had migrated. The downstream developers who had spent 2014 working around a limit that did not need to exist did not get back the year.
And here is the part that matters for everything that comes next. Once Luke had successfully restricted the OP_RETURN field, the Bitcoin Core development culture absorbed the principle that the codebase could be used to restrict non-monetary uses. The block size argument that was about to dominate the next four years was downstream of the OP_RETURN argument. If a developer with commit access could declare what data Bitcoin transactions were allowed to carry, then a developer with commit access could also declare how many transactions a block could carry, what kinds of transactions were "spam," and what kinds of applications were allowed to use the network at all.
Bitcoin, in 2014, stopped being a permissionless protocol in any meaningful sense. It became a protocol that ran under the discretion of the developers who controlled the reference implementation as if it was the protocol spec.
Satoshi had warned about this, in his own way, before he left. He had said the protocol was set in stone after version 0.1. He had handed governance to a process he could not have foreseen. The process was now in the hands of Luke Dashjr and three or four other developers who had been around long enough to be trusted with the commit bit.
And one of them, in a different time zone, was about to be paid.
The Forum Satoshi Built
In the spring of 2011, before he disappeared, Satoshi Nakamoto handed administrative control of bitcoin.org to a developer with the username Theymos.⁴⁴
Theymos is Michael Marquardt.⁴⁵ He is American, lives somewhere in the Midwest (his physical address has been doxed and re-doxed across forums he later moderated), and was one of the most active users of the original Bitcoin forum from approximately 2010 onward. His user number on bitcointalk is 35. He was, in the cohort of people Satoshi knew, a trusted hand. He moderated. He cleaned spam. He kept the forum running. When Satoshi went silent, Theymos was holding the keys.
By 2014, Theymos had been holding those keys for three years. The forum had grown enormously in that time. Bitcointalk, the place where the forums had moved, had become the central archive of the early protocol, a place where Satoshi's posts, the early developer discussions, the Hal Finney threads, the original 2009 conversations about block size and SPV, were still searchable. It was the closest thing the Bitcoin community had to a national archive.
It was also the recipient of approximately 5,300 bitcoin in community donations, given when bitcoin was worth pennies and intended to fund the upgrade of the forum's software from the aging SMF (Simple Machines Forum) installation it ran on.⁴⁶ By 2014, those donations were worth several million dollars at spot, and more than that at the November 2013 peak. They were earmarked for a custom forum software project called Epochtalk, which Theymos commissioned and paid for. Epochtalk was never delivered to bitcointalk.⁴⁷ The funds, the contractors, the audit trail, and the eventual disposition of the bitcoin became the subject of years of community demand for transparency that has never been fully answered.
The forum kept running on the same old SMF software. The donations kept appreciating. The questions kept getting moderated.
In August 2015, with the block size debate finally erupting into open warfare on the developer list, Theymos made his move.
On August 16, 2015, he announced that discussion of alternative Bitcoin clients was no longer welcome on r/bitcoin (which he moderated) or bitcointalk.org (which he owned).⁴⁸ The specific term he used to justify the policy was that any client that did not follow Bitcoin Core's exact consensus rules was, by definition, not Bitcoin. It was an "altcoin." Altcoins were off-topic. Discussion of altcoins on a Bitcoin forum was a moderation violation.
The "altcoins" in question were proposed upgraded node clients for running Bitcoin produced by Bitcoin's own developers... Namely, this client was called "Bitcoin XT," which had been released the day before, on August 15, 2015, by Mike Hearn and Gavin Andresen.
Theymos's policy applied to XT and to every other proposed client that challenged any of the gospel written in Bitcoin Core. All clients. All of them, retroactively and prospectively: "altcoins."
Banned.
He stated the principle openly in a moderator post that became one of the most-quoted documents of the entire civil war.
"If 90% of /r/Bitcoin users find these policies to be intolerable, then I want these 90% of /r/Bitcoin users to leave."⁴⁹
He got close to his wish. In the weeks following the policy announcement, dozens of accounts were banned from r/bitcoin. Posts were deleted in real time. Threads about Bitcoin XT, about alternative scaling proposals, about big-block proposals of any kind, vanished within minutes of posting. Documented bans were issued to users including SatoshisGhost (banned for mentioning Bitcoin XT), Jackten (a seven-day ban for attempting to discuss it), and dnivi3 (banned outright).⁵⁰ Moderator BashCo would later admit, on the record, that the moderation had "regrettably escalated to censorship."
Theymos also threatened to ban Coinbase, then one of the largest US exchanges, and its CEO Brian Armstrong personally, for the offense of writing a corporate blog post supporting BIP 101.⁵¹
The community response, eventually, was the creation of r/btc as a censorship-free alternative.⁵² Roger Ver, who had been one of the earliest bitcoin investors, became its most visible patron. The community split that mapped to the block size positions also mapped to the subreddit split. The civil war had its information geography.
But here is the part the story usually skips. Theymos's authority to set those policies, on those forums, came from one place. Satoshi had given it to him.

The forum Satoshi built was now banning people for quoting Satoshi.⁵³
The 180-Degree Turns
If you had asked Adam Back in the summer of 2015 whether Bitcoin should have larger blocks, his answer was on the record. Yes. He had proposed a specific schedule. Two megabytes immediately, four megabytes in two years, eight megabytes in four years.⁵⁴ The proposal had a name in the community. The "2-4-8" plan. He had pitched it publicly, on the Bitcoin Knowledge podcast with Trace Mayer, and in technical discussions with Gavin Andresen.⁵⁵
If you had asked Pieter Wuille in 2013 or early 2014 whether the block size could be raised, he had been on the record in technical discussions arguing for the technical feasibility of larger blocks. Bitcoin Core developers, including Wuille, had openly explored block sizes of multiple megabytes as part of normal protocol planning.⁵⁶
If you had asked Andreas Antonopoulos in 2014, just after his book "Mastering Bitcoin" came out, what Bitcoin was, his answer was unambiguous. Bitcoin was peer-to-peer electronic cash. It was the future of payments. It was the displacement of Western Union, the unbanking of remittances, the end of the merchant credit card fee, the rails for the global digital economy.⁵⁷
Now look at the same three people two years later.
Adam Back, by 2016, no longer supported raising the base block size. He supported second-layer scaling. He supported sidechains. He supported Lightning Network. He supported the architecture Blockstream was building.
Pieter Wuille, in December 2015, proposed Segregated Witness at Scaling Bitcoin Hong Kong.⁵⁸ SegWit was a clever protocol change that would increase the effective transaction throughput of a Bitcoin block without raising the base block size. The block remained one megabyte. The "witness" data, the signatures, got moved outside the canonical transaction structure and only counted as a quarter of their bytes for block size accounting. Effective capacity went up. Nominal block size did not.
Andreas Antonopoulos, by 2018, was talking publicly about Bitcoin's potential as a store of value, a digital gold, and a savings instrument.⁵⁹ The Western Union framing was still in his older talks but no longer in his new ones. His new framing accommodated the position that Bitcoin's main job was to be held, not spent. The payments framing had been demoted to a second class use case among several. The micropayments framing was gone.
The dates are what matter.
Blockstream's seed round closed on November 17, 2014.⁶⁰ Reid Hoffman, Khosla Ventures, Real Ventures, and the rest of the cohort we traced in Part 4B wired twenty-one million dollars to a Canadian company employing most of the people who wrote Bitcoin Core. The Series A closed on February 17, 2016, at fifty-five million dollars, with AXA Strategic Ventures, the venture arm of the world's largest insurance company, as a co-lead.
The 2-4-8 megabyte plan that Adam Back proposed publicly was in August and September 2015. That was after the seed round. It was also before the Series A. By 2016, Back was running Blockstream's strategy in the opposite direction. Whatever the unfunded Adam Back believed about block sizes in August 2015 was, by definition, not the position the funded company was taking.
Wuille proposed SegWit on December 6, 2015. That was three months before the Series A closed. SegWit became the cornerstone of the small-block roadmap.
Antonopoulos's pivot is the murkiest, because he was never directly funded by Blockstream. But the social structure of the small-block camp, where the major podcasts, the influential conferences, the verified Twitter accounts, the speaking gigs, and the book deals all routed through people who were friendly to Blockstream's roadmap, applied social pressure that did not need a wire transfer to be effective. Antonopoulos pivoted into the position that paid in invitations to speaking gigs. The payments framing pivoted out.
The money arrived in November 2014. The positions changed before 2015 was over.

If you want the names of the people who paid them, they are in Part 4B. There is no need to repeat the list here.
Blockstream
Blockstream was incorporated in Canada in late 2014.⁶¹ The seed round was announced on November 17, 2014. The company had eleven co-founders. Five of them were active Bitcoin Core contributors at the time of founding: Pieter Wuille, Matt Corallo, Gregory Maxwell, Mark Friedenbach, and Jorge Timón. The other six were Adam Back, Austin Hill, Jonathan Wilkins, Alex Fowler, Francesca Hall, and Erik Svenson.⁶²
The press release named the co-founders alphabetically. The corporate structure was something else.
Austin Hill was the founding chief executive officer. Hill was a Canadian technology entrepreneur. He had founded Zero-Knowledge Systems in 1997, an early privacy-focused Internet company that had raised significant capital from major venture funds in the late 1990s. Zero-Knowledge had pivoted, then died with the dot-com bust, but Hill had walked away with a reputation as a person who could fundraise and assemble teams. He was the business architect. He was the person who knew how to talk to Reid Hoffman, to Khosla, to the AXA executives, to the Bilderberg-adjacent network that became Blockstream's investor base.⁶³ He was the dealmaker.
He was also the person who, in private email correspondence that became public years later through DOJ disclosures of Jeffrey Epstein's records, took the call from Reid Hoffman in 2014 directing him to increase the Kyara Investments III allocation in the seed round from fifty thousand dollars to five hundred thousand dollars. Epstein's vehicle was being slotted into Blockstream's cap table at Hoffman's instruction. Hill complied. Some of Hill's co-founders objected, not over Epstein's crimes, but over his proximity to Stellar.
Hill noted their objections in the email. The allocation was accepted. We covered this in Part 4B.
Gregory Maxwell was the technical architect and the eventual Chief Technology Officer. Maxwell had been a long-time Bitcoin contributor, profiled in Part 4. His Wikipedia editing history, his work on Mozilla, his confrontational personality, and his deep technical fluency had made him one of the most influential developers on the project. At Blockstream, he was the one defining the technical roadmap. Sidechains. Liquid. The architecture that would later produce SegWit. The push toward second-layer scaling. The hostility, frequently public, to on-chain scaling as a solution.
Adam Back was the credibility play.
Back's name appears in the Bitcoin whitepaper. It is the first citation in the reference list. Adam Back's 1997 paper on Hashcash, the proof-of-work system for fighting email spam, was the direct technical antecedent of the proof-of-work mechanism in Bitcoin. Back had corresponded with Satoshi in August 2008, when Satoshi had emailed him to confirm the Hashcash citation in the draft whitepaper.⁶⁴ Back had pointed Satoshi toward Wei Dai's b-money proposal as a closer match to what Satoshi was building.
That correspondence is the entire documented relationship between Adam Back and Bitcoin before 2013.
Back has acknowledged, on the record, that he did not begin actively using or paying close attention to Bitcoin until approximately 2013.⁶⁵ "I had questions about its sustainability," he told one interviewer. "It was 2009, there was no exchange, no value." He missed the early mining window. He did not appear on the bitcointalk.org forum during the 2009-2012 development period. He did not contribute code to Bitcoin Core until after Blockstream's founding.
He became Blockstream's CEO formally on October 3, 2016, replacing Austin Hill.⁶⁶ Before that, he was the company's most visible face, the figure at the conferences, the founder cited in the press releases, the credentialed cryptographer whose presence reassured outside investors that the company was technically serious.
There is a dynamic in the way Blockstream presented Back, throughout the 2014-2018 period and continuing today, that is worth naming directly. Back is cited in the whitepaper. Blockstream is the company most directly identified with stewardship of the Bitcoin protocol. The combination of those two facts produced, in the public Bitcoin imagination, a steady murmur of speculation. Maybe Adam Back is Satoshi. Maybe the Hashcash inventor, who corresponded with Satoshi about the whitepaper, is the man behind the pseudonym. Maybe Blockstream's authority over Bitcoin's protocol is not just engineering authority. Maybe it is hereditary.
Back has denied being Satoshi.⁶⁷ Blockstream has denied that Back is Satoshi. The denials are direct and on the record. They are also delivered in a register that has never quite extinguished the speculation, and the company has consistently benefited from the ambiguity. Every time a journalist or a podcaster floated the theory, Blockstream's reputational standing as the steward of Bitcoin's protocol got a small lift. Back is a serious cryptographer. He has done foundational work. The question is whether the company's leadership structure was designed to leverage that ambiguity, and the documented timeline says it was.
The other names in the co-founder roster have their own stories.
Samson Mow would not join Blockstream until 2017, when he took the position of Chief Strategy Officer. Mow had founded a Shanghai-based game studio called Pixelmatic in 2011, which produced a multiplayer online game called Infinite Fleet.⁶⁸ Before Pixelmatic, he had worked in the gaming industry. From 2015 to 2017 he served as Chief Operating Officer of BTCC, the Chinese exchange run by Bobby Lee.⁶⁹ At Blockstream he became the most aggressive social media voice in the small-block camp. He was the lead amplifier of the "NO2X" campaign that defeated the proposed SegWit2x hard fork in late 2017. He left Blockstream in 2022 to found JAN3, an El Salvador-aligned Bitcoin company focused on adoption infrastructure.⁷⁰
Warren Togami, who joined Blockstream in 2014, was the founder of the Fedora Linux project at the University of Hawaii in 2002.⁷¹ He had been an engineer at Red Hat for many years before pivoting to Bitcoin in 2013. His role at Blockstream began as Technical Project Manager and grew over the next decade. He was not one of the publicly-named co-founders in the November 2014 press release, but he was an early hire and a long-tenured executive at the company. And also highly toxic on social media.
The company culture, by every account from employees who left in the next several years, was technically elite, intellectually combative, and ideologically committed to a specific theory of Bitcoin that prioritized base-layer minimization and second-layer scaling. Critics of that theory who worked for Blockstream did not stay long. Critics outside the company who proposed alternatives were treated as enemies of Bitcoin, and ruthlessly bullied out of conferences, forums and anything even bordering on "official" from a narrative standpoint.
The investor list, traced in Part 4B, gave the company the resources to act on that worldview. The codebase, captured through the hiring of Wuille, Corallo, Maxwell, Friedenbach, and Timón, gave them the means.
By the end of 2014, the most important open-source project in the history of money was being maintained by a roster of developers most of whom drew paychecks from a single Canadian company funded by Reid Hoffman, Khosla Ventures, the Yahoo and Google founders, Jeffrey Epstein's vehicle, and shortly after, the world's largest insurance company.

This was the architecture that walked into the Bitcoin Civil War.
The Vacuum and the Teenager
While Bitcoin's developers were debating whether OP_RETURN should be forty bytes or eighty bytes, a nineteen-year-old in Toronto was writing a whitepaper.
His name was Vitalik Buterin. He had co-founded Bitcoin Magazine in 2011 at the age of seventeen, alongside the Romanian developer Mihai Alisie.⁷² He had been writing about the Bitcoin protocol for two years. He had been thinking about what was missing from it.
In late 2013, Buterin published a whitepaper titled "Ethereum: A Next-Generation Smart Contract and Decentralized Application Platform."⁷³ The thesis was direct. Bitcoin had proved that a decentralized ledger was possible. The next generation should be a decentralized ledger that ran arbitrary computation. Tokens, applications, contracts, anything a developer could imagine, executed in a deterministic virtual machine and recorded immutably on chain.
It was the thing Bitcoin's developers were arguing about whether to permit.
From July 22 to September 2, 2014, Ethereum ran an initial coin offering. Forty-two days of public sale. The terms were generous to early buyers: two thousand ETH per BTC, declining to thirteen hundred and thirty-seven ETH per BTC by the end. The sale raised approximately 31,000 BTC, worth roughly 18.4 million dollars at the time.⁷⁴ More than 60 million ETH were sold.
The Ethereum mainnet, codenamed Frontier, launched on July 30, 2015.⁷⁵ The launch was barebones. The interface was a command line. The applications were minimal. But the platform was live, the virtual machine was deterministic, and the early developer community that had been camped out around Counterparty and the Bitcoin tokens ecosystem began to migrate.
The migration was the cost of the OP_RETURN restriction. It did not happen all at once. It did not happen because of any single decision. It happened because, in 2014 and 2015, the Bitcoin community was sending a message to anyone who wanted to build something other than payment software, and the message was: not here. Not on this protocol. Not anymore.
Ethereum existed because Bitcoin's developers refused to host the use cases Vitalik Buterin wanted to build. And so a nineteen-year-old, with an ICO and a few million dollars, built the chain himself.
Some of the people who would later work on Ethereum had been Bitcoin developers. Some of the people Blockstream eventually pushed out of Bitcoin Core would land at Ethereum projects. But that is a later story.

For now, in the summer of 2015, Bitcoin had lost its application layer to a competitor that did not exist eighteen months earlier.
Satoshi's Ghost
On March 7, 2014, a Newsweek cover story by Leah McGrath Goodman identified Dorian Prentice Satoshi Nakamoto, a sixty-four-year-old Japanese-American engineer living in Temple City, California, as Bitcoin's pseudonymous creator.⁷⁶ The story was thin. The evidence was circumstantial. The man's middle name was Satoshi. He was reclusive. He had a background in classified work. The cover photo, taken without his consent, showed him in his driveway.
Hours later, an account on the P2P Foundation forum, dormant since approximately 2012, posted a single sentence:
"I am not Dorian Nakamoto."⁷⁷
The account was the one Satoshi had used to introduce Bitcoin to the world in February 2009. The email registered to it was satoshin@gmx.com. No PGP signature accompanied the new post. No blockchain-signed proof. Just the sentence, on the same account, from the same email, six years later.
The community wanted to believe it.
Six months later, on September 8, 2014, at approximately 9 PM UTC, Theymos received an email from satoshin@gmx.com.⁷⁸ The email was menacing and confused. Theymos forwarded it to a small circle of Bitcoiners. By the next morning, the consensus was that the email account had been compromised.
The hacker's method was simple. GMX's password reset flow used a security question. Satoshi's security question was his date of birth. The hacker tried the password reset every eight hours, trying birth dates, until one worked.
Once the email was in his hands, the rest fell open. The same email had been used to log into Satoshi's SourceForge account, which controlled the Bitcoin source repository before it had migrated to GitHub. The same email had been used to administer Satoshi's P2P Foundation profile. The hacker had access to all of it. Briefly, the SourceForge Bitcoin page redirected to an anti-Bitcoin troll site called "Buttcoin."⁷⁹
A message went up on the P2P Foundation account. Satoshi's "dox, passwords and IP addresses are being sold on the darknet," the message read. The hacker, signing as "jeffq" in some communications, was demanding a ransom and threatening to release the credentials and the personal information.⁸⁰
There were no early emails to be found. The GMX server had mostly been swept clean, possibly by Satoshi himself in 2011 when he disengaged. There was nothing for the hacker to publish that anybody could prove was original. But the account was now in the hands of someone other than Satoshi, and that someone could post in Satoshi's voice on Satoshi's accounts. Who knows what else he compromised...
Hold that thought.
On August 15, 2015, the day Bitcoin XT was released, a post appeared on the bitcoin-dev mailing list and the bitcointalk.org forum from an account using the same email signature that had been on the original Satoshi posts.⁸¹ The message was sharply critical of Bitcoin XT. It argued that Bitcoin had been designed to require near-unanimous agreement for protocol changes, that the developers attempting to fork to larger blocks were betraying the original architecture, that the project should be "protected from the influence of charismatic leaders." The post was timed, almost exactly, to coincide with the most heated week of the scaling debate thus far.
Was it Satoshi? Was it the hacker who had owned satoshin@gmx.com for a year? For longer? Was it Theymos, given that he had received the original hack message and almost certainly had means and motive? Was it a coordinated effort? The community has never resolved the question.
The post was treated by the small-block camp as authoritative because it fit their narrative. Whether it was the real Satoshi or not, it was used to argue the small-block position.
There would be a third post from the same account a few months later, denying a different identity claim. We will get to that one in its proper place.⁸²
Two posts in two years from an account that had not posted in three years before that. Each on the same compromised email. Each timed to a major event in the public Satoshi mystery. Each aligned with a specific narrative.
You can pick the explanation that fits your priors. Maybe Satoshi posted them. Maybe the hacker posted them. Maybe one was real and one was not. Maybe it was someone else entirely.
The forum Satoshi built was now hosting messages from an account that no one in the community could verify.
The alert key, the master signing key Satoshi had personally handed to Gavin Andresen in 2011 and that we discussed in Part 3, was a separate question.⁸³ It was a real cryptographic key. It could broadcast network-wide warnings or, in the original design, potentially halt spends across the entire network. As of 2014, several people had held it: Gavin Andresen, who had received it from Satoshi, and later a small handful of trusted Core developers. Whether the key had been used to sign anything in 2014 or 2015 is not in the public record. Whether the same hacker who owned satoshin@gmx.com could have, through any chain of access, gotten to the alert key is also not in the public record.
What is in the public record is that the alert system was formally retired in 2016, after the Core developers concluded that the centralization risk was too great.⁸⁴ The key, by then, had been around for too long, in too many hands, and the trust assumption it required had broken in part because of the loss of control of Satoshi's email account.

This is the part of the story where you stop reading and ask yourself how many of the public-facing artifacts of "Satoshi" between 2010 and 2016 were actually Satoshi.
I do not know. Neither does anybody else.
Well, someone probably knows, but he isn't talking.
The Man from Down Under
In a suburb of Sydney called Gordon, on the leafy north shore of the harbor, a man had been writing academic papers, IT security books and many other things for many, many years.
He was in his early forties. He was a forensic accountant by trade and a forensic computer scientist by training. He had over a dozen degrees, including doctoral work, from Australian institutions. He had worked for the accounting firm BDO Sternberg and consulted with Australian government agencies on digital forensics, secure networking, and cybersecurity. He held a long string of professional certifications.⁸⁵
He had also been building companies. DeMorgan Limited. Panopticrypt. Hotwire PE. Coin Exchange. Strasan. Denariuz. Cloudcroft... Across these entities he had been applying to the Australian Tax Office for substantial research-and-development tax incentives related to computing, security, Bitcoin and general cryptographic research. The largest application, filed by DeMorgan in 2014, sought tens of millions of Australian dollars in R&D cash rebates for the 2014/2015 financial year.⁸⁶
He had a business partner in Florida.
The partner's name was Dave Kleiman. Kleiman was a forty-six-year-old American computer forensics expert who had worked for years in the Palm Beach County Sheriff's office in Florida. He had co-authored books on Microsoft Windows forensics. He had spoken at security conferences. In 1995 he had been in a motorcycle accident that left him paraplegic. He had used a wheelchair for the rest of his life.⁸⁷
Kleiman died in his home in Palm Beach Gardens, Florida in late April 2013. The body was found on April 26. The official cause was complications from a long-running MRSA infection. Contemporary reporting on the scene described bottles of bourbon, prescription benzodiazepines, and a bullet hole in the wall that was deemed not connected to the cause of death by any subsequent investigation, but remains a distinct curiosity. The Australian had lost his Florida partner.⁸⁸
Six months later, in October 2013, while the FBI was arresting Ross Ulbricht in San Francisco, the Australian was drafting a trust document. The document, dated 2011 but apparently signed in 2013, established what would later be called the Tulip Trust.⁸⁹ The trust purported to hold approximately 1.1 million bitcoin. The two named principals were the Australian himself and the late Dave Kleiman. The trust's terms included a so-called "bonded courier" delivery mechanism: the private keys to the trust's bitcoin holdings would be delivered to the Australian by a courier in January 2020.
The authenticity of that document has been disputed in every venue that has examined it. The Kleiman estate has called it a fraud. Courts have demanded its production and received documents whose forensic markers do not match their stated dates. The bonded courier did, by the Australian's own account, arrive in early January 2020. Whether the courier brought any usable key material is unknown and also disputed.
The Australian cohorted in business ventures that brought him into the business of Bitcoin with two people in particular.
One was an Australian gambling business executive named Stefan Matthews.⁹⁰ Matthews had known the Australian for ten years, since they had worked together at an online company called Centrebet in the early 2000s. By 2015 Matthews was the chief technology officer of an offshore poker company. He had remained in contact. He believed the Australian's various claims based on his own first-hand knowledge of events that will be clarified later. He was trying to find investors who would help the Australian commercialize them in the Bitcoin space.
The other was a Canadian named Robert MacGregor.⁹¹ MacGregor ran an offshore corporate services firm called nTrust, based in Antigua. He had a financial-services background and a willingness to bet on high-risk, high-return ventures. Matthews had introduced the two men. MacGregor had a plan. The plan, as it was eventually documented by a journalist named Andrew O'Hagan, was to bring the Australian to London, set up a research and development center for him with a staff of around thirty, complete his patents and inventions from his various Australian companies, and sell the whole package, branded as the unmasking of Satoshi Nakamoto, for upwards of a billion dollars.
The journalist O'Hagan was the only outsider given full access to the operation. He had refused payment. He had refused to sign a nondisclosure agreement. He was embedded, but he remained independent. His resulting essay, "The Satoshi Affair," would run in the London Review of Books in June 2016 at thirty-five thousand words.⁹² It is, to this day, the single most detailed contemporaneous account of what was going on inside the Australian's circle in 2015.
A cryptography legend named Ian Grigg, the inventor of the Ricardian contract and one of the elder statesmen of the digital currency movement, was also writing about the Australian in late 2015. His blog posts at Financial Cryptography asked, in the careful language of a cryptographer who knows the difference between proof and indication, whether the Australian had what he claimed and whether the Bitcoin community was ready for what he was about to do.⁹³
The Australian was not yet known publicly. His name was not in the press. His face had not yet been televised. He existed, in the autumn of 2015, as a figure in the periphery of a small circle of people who believed his stories and observed his evidence and a slightly larger circle of people who were skeptical but watching.
That was about to end.
Bitcoin XT and the Opening Battle
Mike Hearn had been a Bitcoin developer since 2010.⁹⁴ He was British, a former Google engineer, and one of the architects of the original Bitcoin SPV protocol, the lightweight client design that allowed wallets to verify transactions without running a full node. He had also been one of Satoshi's last documented correspondents, exchanging emails with him in early 2011 about the protocol's long-term direction.
By 2015, Hearn had concluded that Bitcoin Core's resistance to increasing the block size was a project-ending choice. Together with Gavin Andresen, who still held the alert key Satoshi had given him in 2011, Hearn built a new client called Bitcoin XT.
On August 6, 2015, Bitcoin XT was released with BIP 101 implemented.⁹⁵ BIP 101 increased the maximum block size to 8 megabytes immediately, with a doubling every two years thereafter. The activation threshold was 75 percent of the last 1,000 blocks mined under XT's version bits. The public release date for adoption was August 15, 2015.
The reaction from the small-block camp was immediate and brutal.
Theymos banned discussion of Bitcoin XT on r/bitcoin and bitcointalk.org the next day, August 16, with the policy described above. The community split followed.
Bitcoin XT nodes were attacked.
Hearn would later document that approximately one-third of all Bitcoin XT nodes that came online during August and September 2015 were targeted by DDoS attacks that took them off the network.⁹⁶ Some were small operators running nodes at home. Some were larger datacenter deployments at hosting providers. The attacks were widespread, sustained, and never publicly attributed. Hearn's framing in the post-mortem he would write the following January was direct: "anyone who supported bigger blocks, or even allowed other people to vote for them, would be assaulted."
Death threats were issued. Most went to Hearn, to Andresen, and to Coinbase CEO Brian Armstrong, who had publicly supported the XT direction. Documentation of the threats survives in private correspondence, in screenshots posted to news outlets at the time, and in Hearn's own later writing. Some of the threats were vague. Some were specific to the family members of the targets. The volume was high enough that it became a significant operational issue for the developers involved.⁹⁷
We are not going to publish Mike Hearn's farewell letter in this article. He has not written it yet, by the chronology of this story. It will appear in January 2016 and it will detonate Part 6.
But we are inside the events the letter would describe.
The Scaling Bitcoin conference in Montreal, held September 12-13, 2015, was an attempt to broker peace.⁹⁸ Developers from every camp presented technical proposals. Big-block proposals from Andresen and Hearn. Small-block proposals from Wuille and Maxwell. Hybrid proposals from a handful of attendees. The conference produced no agreement. It produced a follow-up.
The follow-up was the Scaling Bitcoin conference in Hong Kong, held December 6-7, 2015.⁹⁹ At this conference, Pieter Wuille presented Segregated Witness for the first time. SegWit was the small-block roadmap's answer to scaling. By restructuring how signatures were stored in transactions, it would increase effective throughput without increasing the nominal block size. The big-block developers in the room had a counter-proposal from Jeff Garzik called BIP 102, a simple two-megabyte hard fork. The conference ended again without agreement, but with both sides claiming progress.
Two months later, on February 21, 2016, in a roundtable session also held in Hong Kong's Cyberport, mining executives controlling more than eighty percent of the network's hashrate met with Bitcoin Core developers to negotiate a settlement.¹⁰⁰ The session reportedly ran most of a day. The signatories from the mining side included AntPool, A-XBT, BitFury, Bitmain, BTCC, F2Pool, Genesis Mining, and GHash.io. The signatories from the Core side included Cory Fields, Johnson Lau, Luke Dashjr, Matt Corallo, and Peter Todd. Adam Back signed for Blockstream, listed as the company's President.
The agreement was specific. The miners would activate SegWit when Core released it. The Core developers would, within three months of SegWit's release, deliver a hard fork to two megabytes as a follow-on.
The agreement was signed in February 2016.
The same month, Blockstream closed its 55 million dollar Series A round with AXA Strategic Ventures as a co-lead.
The hard fork to two megabytes that the Core developers had promised in Hong Kong was never delivered. SegWit shipped. The two-megabyte hard fork did not.
That is the agreement that would, by the autumn of 2017, break the chain in half. But that is a Part 7 story. We are not there yet.
In November 2015, while the developers were arguing in Montreal and preparing for Hong Kong, a different drama was reaching its climax in a quiet suburb on the north shore of Sydney harbor.
The Unmasking
On December 8, 2015, two publications published on the same day.
The first was Wired magazine. The article was written by Andy Greenberg and titled "Bitcoin's Creator Satoshi Nakamoto Is Probably This Unknown Australian Genius."¹⁰¹ Greenberg had been working the story for months. His sources included leaked emails, archived blog posts, a copy of the alleged Tulip Trust document, and personal communications between the Australian and several intermediaries who had been part of the nCrypt operation. The article identified Craig Steven Wright by name, with a photograph, with biographical detail, and with the suggestion, framed carefully but unmistakably, that he was Satoshi Nakamoto.
The second was Gizmodo. The article was written by Sam Biddle and Andy Cush, titled "This Australian Says He and His Dead Friend Invented Bitcoin."¹⁰² Gizmodo's sourcing was different but overlapping. The publication had been working its own version of the story. The simultaneous publication was, by all accounts on both sides, not coordinated.
The two articles appeared within hours of each other, which is more than curious.
Craig Wright was the Australian.
He had been the man in Sydney since the beginning of this article. He had been the figure with the accounting background and the massive academic record. He had been the partner of Dave Kleiman, the paraplegic forensics expert who had died under some bizarre circumstances in Palm Beach Gardens. He had been the principal of DeMorgan and Cloudcroft and Panopticrypt. He had been the subject of Andrew O'Hagan's embedded reporting. He had been the obsession of Ian Grigg's blog posts. He had been the breadcrumb trail that two American magazines had been following for months.
And on the same day that Wired and Gizmodo published, the Australian Federal Police, acting on a warrant from the Australian Tax Office, raided his home in Gordon, New South Wales.¹⁰³
The raid was filmed by Australian media that had been tipped off by the publication of the magazine articles. The footage shows a quiet residential street, a comfortable suburban house with a tile roof, federal agents in body armor moving through the front door. They were looking for evidence related to the DeMorgan R&D tax claims, which the ATO had been investigating since March 2015. They were also looking for documents related to the bitcoin holdings the journalists had been writing about. The raid extended to Wright's business premises in Ryde, several kilometers away.
The house was empty.
Wright had left Australia hours before the publication. He had been tipped off, according to accounts later given to O'Hagan, by Stefan Matthews and Robert MacGregor. They had moved him out of the country. They were already negotiating the next phase of the operation, the move to London, the construction of the R&D facility, the unmasking and the IP sale, the billion-dollar plan.
It would later be claimed by Wright that he had moved out much earlier. It is unclear where the truth stands on his whereabouts at the time.
The ATO agents searched a house that no longer contained the man they were looking for. They took boxes. They took drives. They took whatever paper was on the desks. There was no Craig Wright. There was no Tulip Trust ledger. There were no private keys.

The house was empty, but his claims and the Bitcoin Civil War are just in their opening phase, and things are about to get much, much worse.
That is where Part 5 ends.
Part 6 is the war itself. It is the letter Mike Hearn published on January 14, 2016, that declared bitcoin a failed experiment. It is the cascade of departures from the Bitcoin Core team. It is the proof Craig Wright tried to give in May 2016, on the BBC, in a London conference room, that fell apart in front of the cameras. It is the Sartre post. Eventually, it will be the Kleiman trial, the COPA lawsuit, and more. It is the breaking of the Hong Kong Agreement, the New York Agreement, and the August 2017 fork that splits the chain forever.
Part 6 is where the gatekeepers we met in Part 4B use the keys we tracked in Parts 4 and 5 to take possession of the protocol Satoshi handed off to a process he could not have foreseen.
You read this far. You can guess where it goes from here.
But the receipts, as always, are in the footnotes. Read them.
Footnotes
¹ The Curtis Green staged-death operation has been documented in multiple sources, including Curtis Green's own subsequent interviews. The "Campbell's Chicken & Stars soup" detail comes from contemporary reporting on the federal criminal case against Carl Force IV. The DEA staged the photo as part of an elaborate operation to maintain Force's undercover identity with DPR. See "Investigating The Staged Assassinations Of Silk Road", Bitcoin Magazine, and "Three Staged Assassinations", BitMEX Research.
² Direct quote from DPR-to-Nob communications, entered into evidence at the Ulbricht trial in the Southern District of New York. United States v. Ulbricht, 2nd Circuit, 2017.
³ Carl Force complaint and plea agreement, United States v. Force, Northern District of California, 2015.
⁴ Federal Bureau of Investigation, "Ross Ulbricht, aka Dread Pirate Roberts, Sentenced in Manhattan Federal Court to Life in Prison," FBI New York press release, May 29, 2015.
⁵ U.S. Marshals Service auction records and Department of Justice asset seizure filings, 2014-2015.
⁶ Charging documents and trial filings, United States v. Ulbricht, Southern District of New York.
⁷ The Maryland murder-for-hire charges were filed in a separate sealed indictment that was never brought to trial. See Wikipedia, Ross Ulbricht, with citations to court filings.
⁸ Sentencing transcript, United States v. Ulbricht, May 29, 2015.
⁹ "Corrupt Silk Road DEA Agent Carl Force Gets Over 6 Years in Prison", NBC News, October 19, 2015.
¹⁰ "DEA Agent Gets Prison Time for Stealing Bitcoins in Silk Road Probe", Fortune, October 22, 2015. The figure of $400,000+ in misappropriated cryptocurrency comes from the plea agreement.
¹¹ "Secret Service Agent Gets Six-Year Sentence for Bitcoin Theft", CoinDesk, December 7, 2015.
¹² "Former Secret Service Agent Sentenced in Scheme Related to Silk Road Investigation", U.S. Department of Justice Office of Public Affairs.
¹³ Sentencing of Carl Mark Force IV, Northern District of California, October 19, 2015.
¹⁴ Sentencing of Shaun Bridges, Northern District of California, with consecutive sentence for additional thefts.
¹⁵ "Trump pardons Ross Ulbricht, creator of the Silk Road dark web marketplace", NPR, January 21, 2025. The pardon was granted on the second day of Trump's second presidential term and was a full pardon, not a sentence commutation as initially promised.
¹⁶ Mt. Gox historical price data and CoinDesk Bitcoin Price Index archive.
¹⁷ Mt. Gox press release, February 7, 2014, archived at multiple cryptocurrency news outlets. See Wikipedia, Mt. Gox, citing primary sources.
¹⁸ The transaction malleability issue is documented in BIP 62 and in technical discussions on the bitcoin-dev mailing list throughout 2014. The Mt. Gox attribution of its losses to malleability was widely disputed at the time.
¹⁹ Jed McCaleb originally founded Mt. Gox in 2010 as a Magic: The Gathering Online Exchange. He sold the platform to Karpelès on March 6, 2011. See Wikipedia, Mt. Gox.
²⁰ The total deficit was reported as approximately 850,000 BTC, of which 750,000 belonged to customers and 100,000 to the exchange. See NPR, "Mt. Gox Files For Bankruptcy", February 28, 2014.
²¹ The "Crisis Strategy Draft" document leaked to and was published by Ryan Selkis on his blog The Two-Bit Idiot in late February 2014. See contemporary coverage at CoinDesk, February 28, 2014.
²² Tokyo District Court civil rehabilitation filing, February 28, 2014.
²³ Mt. Gox announcement, March 20, 2014, recovery of approximately 199,999 BTC from an old wallet.
²⁴ Arrest of Mark Karpelès, August 1, 2015, in Tokyo. Conviction on falsification of records charges, March 2019. See Wikipedia, Mt. Gox.
²⁵ Bitcoin price data, CoinDesk Bitcoin Price Index, 2013-2017.
²⁶ Erik Voorhees on Wikipedia and contemporary Bitcoin Magazine coverage.
²⁷ At its peak in early 2013, Satoshi Dice transactions were estimated to comprise more than 50 percent of all Bitcoin transactions. See Bitcoin Magazine.
²⁸ Sale announcement, July 17, 2013, 126,315 BTC. See "Bitcoin company acquisitions begin: Gambling site SatoshiDice sells for $11.5 Million", CoinDesk, July 18, 2013.
²⁹ Counterparty on Wikipedia. Founders Robby Dermody, Adam Krellenstein, and Evan Wagner.
³⁰ EverdreamSoft, the Geneva-based studio that produced Spells of Genesis, used Counterparty for the issuance and trading of in-game cards. The studio's history is documented at Decrypt, "What Is Counterparty?".
³¹ Mastercoin, founded by J.R. Willett, ran the first initial coin offering in July 2013, raising roughly 5,000 BTC. It was renamed Omni Layer in 2015.
³³ Luke Dashjr's traditional Catholic views are documented in multiple interviews and forum posts. See "Inside the Mind of Luke Dashjr, Bitcoin's Most Polarizing Developer", Blockspace Media.
³⁴ Dashjr has expressed geocentric views in public statements and Twitter discussions. The position is documented in third-party profiles.
³⁵ Dashjr's statements regarding animals existing for human use, including consumption, were made on Twitter in 2021 and reported by Decrypt: "The hot new trend in Bitcoin Maximalism is...eating house pets?". While the specific tweets are from a later period than this article covers, they illustrate the philosophical framework Dashjr had been articulating publicly for more than a decade.
³⁶ Eligius mining pool, founded by Dashjr in 2011, is documented at weusecoins.com. Its transaction filtering policies were widely discussed on bitcointalk.org and the bitcoin-dev mailing list throughout 2012-2014.
³⁷ See, for example, Luke Dashjr's Bitcoin Knots release notes and his statements on Twitter regarding "spam" transactions, including direct discussion of OP_RETURN: "The OP_RETURN discussion is not new and dates back to 2014...".
³⁸ Bitcoin Core pull request #3737, "script: reduce OP_RETURN standard relay bytes to 40," opened February 25, 2014, merged February 27, 2014 in preparation for Bitcoin Core 0.9.0. Author: Jeff Garzik (jgarzik). Merged by: Gavin Andresen. See GitHub PR #3737.
³⁹ Luke Dashjr's "rape victim" analogy and broader framing of non-financial blockchain data as "abuse" is in the PR thread itself. Pieter Wuille's "still abuse, it just hurts a bit less" comment and Gavin Andresen's pushback on the rhetoric are also in the thread. See the comments on GitHub PR #3737.
⁴⁰ Counterparty was forced to restructure portions of its protocol to accommodate the 40-byte OP_RETURN limit during 2014. See Bitcoin Magazine, "Counterparty Has Reached Its Millionth Transaction".
⁴¹ Omni Layer (formerly Mastercoin) faced the same constraints. The Omni team had to implement multi-output workarounds.
⁴² A subset of Bitcoin 2.0 developers migrated, with Ethereum becoming the principal destination once it launched in 2015.
⁴³ Pull request to restore OP_RETURN to 80 bytes was opened November 16, 2014 and merged February 4, 2015, shipping in Bitcoin Core 0.10. See "OP_RETURN 40 to 80 bytes".
⁴⁴ Satoshi Nakamoto granted Theymos administrative roles on bitcoin.org and the bitcointalk.org forum during 2010-2011. See cryptoanarchy.wiki, Michael Marquardt.
⁴⁵ Michael Marquardt has been doxed multiple times over the years on adversarial forums; his identity is widely known in the community.
⁴⁶ Bitcointalk forum donations are documented at BitHope.org's BitcoinTalk support campaign archive and in numerous community-archived threads.
⁴⁷ The Epochtalk project was paid for from forum donations and never deployed to bitcointalk. The contractors and final disposition of the bitcoin remain a community grievance.
⁴⁸ Theymos's August 16, 2015 moderation policy announcement on r/bitcoin and bitcointalk.org. Documented in "A (brief and incomplete) history of censorship in /r/Bitcoin", John Blocke, Medium.
⁴⁹ Direct quote, Theymos, r/bitcoin moderator post, August 16, 2015. Archived at multiple community sources.
⁵⁰ Documented user bans, see John Blocke history of r/bitcoin censorship, op. cit.
⁵¹ "Coinbase CEO Objects Reddit Bitcoin Censorship", Cointelegraph.
⁵² The r/btc subreddit was created in 2015 in response to r/bitcoin's censorship policies.
⁵³ Satoshi's posts at bitcointalk.org from 2009-2010 are archived in their original location on the same forum that, in 2015, began banning users for quoting them.
⁵⁴ Adam Back's 2-4-8 megabyte block size proposal is documented in multiple contemporary sources, including "Notable Bitcoin Core Contributors Now Open To Increasing Block-size Limit To 2 Or 4MB", Bitcoin Magazine, September 2015.
⁵⁵ "Dr Adam Back and Gavin Andresen discuss a block size increase", Bitcoin Knowledge Podcast, September 2015.
⁵⁶ Pieter Wuille's early technical positions on block size are scattered through bitcoin-dev archives and conference talk transcripts. His later proposal of SegWit is documented in BIP 141.
⁵⁷ Andreas Antonopoulos's "Mastering Bitcoin" was published by O'Reilly in December 2014. Earlier talks emphasized peer-to-peer payments and remittance use cases.
⁵⁸ Pieter Wuille's SegWit presentation at Scaling Bitcoin Hong Kong, December 6-7, 2015. Conference transcripts available at scalingbitcoin.org.
⁵⁹ "Andreas Antonopoulos: Bitcoin can become a store of value", Cryptonomist, December 12, 2018.
⁶⁰ Blockstream seed round announcement, November 17, 2014. See Blockstream on Wikipedia.
⁶¹ Blockstream incorporated in Canada in 2014.
⁶² Blockstream's eleven co-founders are listed in the company's official press release of November 17, 2014.
⁶³ Austin Hill's prior company Zero-Knowledge Systems is documented at IQ.wiki.
⁶⁴ Adam Back and Satoshi Nakamoto correspondence, August 2008. See "The Genesis Files: Hashcash Or How Adam Back Designed Bitcoin's Motor Block", Bitcoin Magazine.
⁶⁵ Adam Back, on his own delayed engagement with Bitcoin: "I had questions about its sustainability. It was 2009, there was no exchange, no value." Quoted in Bitcoin Magazine's "Genesis Files" series.
⁶⁶ Adam Back appointed CEO of Blockstream, October 3, 2016. See Blockstream press release.
⁶⁷ Blockstream and Back have repeatedly denied that Back is Satoshi Nakamoto. See Kurt Wuckert Jr., "Carreyrou Adam Back Satoshi Nakamoto Rebuttal", for an analysis of the most recent NYT-driven version of the claim and Blockstream's response.
⁶⁸ Samson Mow founded Pixelmatic in Shanghai in 2011 and remains its CEO. See TradersUnion biography.
⁶⁹ Samson Mow served as COO of BTCC from 2015 to 2017.
⁷⁰ Mow founded JAN3 in 2022 after leaving Blockstream.
⁷¹ Warren Togami founded the Fedora Project as a Computer Science academic project at the University of Hawaii in 2002. See Fedora Project Wiki, User.
⁷² Bitcoin Magazine was co-founded by Vitalik Buterin and Mihai Alisie in 2011. First print issue published May 2012.
⁷³ Vitalik Buterin's Ethereum whitepaper was published in late 2013. See Ethereum history at ethereum.org.
⁷⁴ The Ethereum ICO ran from July 22 to September 2, 2014, raising approximately 31,000 BTC (~$18.4 million at the time).
⁷⁵ Ethereum Frontier mainnet launched July 30, 2015.
⁷⁶ Leah McGrath Goodman, "The Face Behind Bitcoin," Newsweek cover story, March 6, 2014 (cover date March 14). The article identified Dorian Prentice Satoshi Nakamoto as Bitcoin's creator.
⁷⁷ "I am not Dorian Nakamoto" post on the P2P Foundation forum, March 7, 2014. See "'Real' Satoshi Claims He Is Not Dorian Nakamoto", TechCrunch.
⁷⁸ Satoshi's GMX email compromised September 8, 2014. See "Satoshi's GMX Email Hack: 2014 Bitcoin History", BitMEX Research.
⁷⁹ The SourceForge Bitcoin page briefly redirected to an anti-Bitcoin troll site during the compromise window. See "Hacker Hijacks Satoshi Nakamoto's Email, Threatens to Reveal All", CoinDesk.
⁸⁰ Hacker handle and ransom messaging documented in CoinDesk and BitMEX coverage, September 2014.
⁸¹ Anti-Bitcoin XT post attributed to Satoshi on the bitcoin-dev mailing list, August 15, 2015. Authenticity disputed. See "Satoshi Nakamoto Speaks?", Cointelegraph.
⁸² A third post appeared on the same P2P Foundation account on December 11, 2015, denying that Satoshi was the Australian named in the Wired and Gizmodo articles. The post used the same compromised email infrastructure. Discussed further in Part 6. See Hacker News discussion of the post.
⁸³ The Bitcoin alert system, designed by Satoshi and originally transferred to Gavin Andresen in 2011, was retired in 2016. See Bitcoin Core release notes for the formal retirement.
⁸⁴ Alert system retirement, Bitcoin Core 0.13.1, November 2016.
⁸⁵ Craig Wright's academic credentials and Australian professional history are documented in court filings from Kleiman v. Wright and in Andrew O'Hagan, "The Satoshi Affair," London Review of Books, Vol. 38 No. 13, June 30, 2016.
⁸⁶ DeMorgan R&D tax incentive applications and ATO audit history. See "What We Know: Alleged Bitcoin Creator Craig Wright's Tax Troubles", CoinDesk.
⁸⁷ Dave Kleiman biography at Wikipedia and contemporary reporting.
⁸⁸ Dave Kleiman's death and the conditions in which his body was found are documented in Modern Consensus, "Cocaine, benzos, booze and a bullet hole" and in court testimony from Kleiman v. Wright.
⁸⁹ Tulip Trust documents and disputes. See "Craig Wright Lawsuit: Tulip Trust and Bonded Courier Questions Remain", Bitcoinist.
⁹⁰ Stefan Matthews' relationship with Craig Wright dating to their time at Centrebet, documented in Andrew O'Hagan, "The Satoshi Affair".
⁹¹ Robert MacGregor of nTrust/nCrypt, documented in O'Hagan, op. cit.
⁹² Andrew O'Hagan, "The Satoshi Affair," London Review of Books, Vol. 38 No. 13, June 30, 2016. Thirty-five thousand six hundred and twelve words of embedded reporting on Wright, Matthews, MacGregor, and the operation.
⁹³ Ian Grigg, "Bitcoin and Gresham's Law" and additional posts, Financial Cryptography blog, 2015-2016.
⁹⁴ Mike Hearn's early Bitcoin development work and correspondence with Satoshi are documented in archived emails and contemporary Bitcoin Foundation records.
⁹⁵ Bitcoin XT release, August 6 and 15, 2015. BIP 101 implementation. See Bitcoin Wiki, Bitcoin XT.
⁹⁶ DDoS attacks on Bitcoin XT nodes are documented in Hearn's January 14, 2016 Medium post and in contemporary reporting. Hearn's framing: approximately one-third of XT nodes were attacked.
⁹⁷ Death threats against big-block advocates including Hearn, Andresen, and Coinbase CEO Brian Armstrong are documented in contemporary screenshots, news coverage, and Hearn's later writing.
⁹⁸ Scaling Bitcoin Montreal 2015, September 12-13, 2015. Transcripts at scalingbitcoin.org.
⁹⁹ Scaling Bitcoin Hong Kong 2015, December 6-7, 2015. SegWit presented by Pieter Wuille.
¹⁰⁰ Hong Kong Agreement, February 21, 2016. Signatories from mining and Bitcoin Core developers. See "Bitcoin Miners and Core Developers Release SegWit, Hard Fork Agreement", Bitcoin Magazine, and the Bitcoin Roundtable Consensus statement on Medium.
¹⁰¹ Andy Greenberg, "Bitcoin's Creator Satoshi Nakamoto Is Probably This Unknown Australian Genius," Wired, December 8, 2015.
¹⁰² Sam Biddle and Andy Cush, "This Australian Says He and His Dead Friend Invented Bitcoin", Gizmodo, December 8, 2015.
¹⁰³ Australian Federal Police raid on Craig Wright's home in Gordon, NSW, December 9, 2015. See CoinDesk and contemporary Australian media coverage.
Be good to each other. And read the footnotes.
Kurt Wuckert Jr. is the world's foremost Bitcoin Historian. The Written History of Bitcoin is published one installment at a time at kurtwuckertjr.com.