HASH Bitcoin: A Peer-to-Peer Electronic Cash SystemSatoshi Nakamoto · announced 31 Oct 2008 · this file created 24 Mar 2009 · sha256 b1674191 … f4f553 · provenance“If you don't believe me or don't get it, I don't have the time to convince you, sorry.”
— satoshi
This laboratory does not serve a copy of the whitepaper, and stopped deliberately on 8 August 2026. The paper carries no licence and no copyright notice — it is not public domain and not MIT, and copyright in it vests in an author nobody has identified. This project's own rule is that a SHA-256 is not a reproduction: we publish facts about documents and point at sources other people published. Nothing is lost by it. The canonical file is embedded in the block chain and can be carved back out — python verify/whitepaper_from_chain.py out.pdf reads it from block 230009 and it hashes to b1674191…f4f553. That is a better source than this page ever was: it needs no host and no trust in us. Every version, by hash →
This file was created 24 March 2009 and carries satoshin@gmx.com. An earlier draft survives — 183,697 bytes, served byte-identically by two unrelated hosts, carrying satoshi@vistomail.com and the October 2008 abstract word for word as quoted in the announcement. It has no transaction-fee paragraph — and Satoshi proposed transaction fees on the list on 9 November 2008, which dates the draft by its content rather than by its metadata. The file above is the design as its author last stated it; it is not a witness to 31 October 2008, and the bytes actually served at that link remain unidentified. Full provenance →
The file above is also in the block chain, embedded in transaction 54e48e5f… across 945 bare-multisig outputs. Carve it out of block 230009 (6 April 2013) and it hashes to b1674191…f4f553 — this file, exactly. Proof-of-work cannot be backdated, so the text is pinned to 2013 independently of bitcoin.org, of the Internet Archive, and of us. That is the strongest anchor any version of the paper has; it still says nothing about 2008.
And bitcoin.org's own web server confirms when it was made. The Internet Archive replays the origin server's headers: the 2010 capture of bitcoin.org/bitcoin.pdf carries Last-Modified: Tue, 24 Mar 2009 17:33:15 GMT — the file's mtime on bitcoin.org's filesystem — which is identical, to the second, to the PDF's own CreationDate converted to UTC. Three SourceForge mirrors report 17:50:18, seventeen minutes later. A self-asserted date, confirmed by a server the author did not run.
This file's identity is settled by three independent classes at once — its own /CreationDate, bitcoin.org's own filesystem (Last-Modified: Tue, 24 Mar 2009 17:33:15 GMT, recovered from a 2010 archive capture), and a High Court expert report that publishes its SHA256 b1674191…f4f553. All three name the same bytes and the same instant, to the second.
But this is not the paper that shipped with the code in this lab. That is worth stating plainly, because it is the kind of detail this project exists to get right. The Laboratory executes the November 2008 pre-release and the January 2009 release. This file was created on 24 March 2009 — after both. The paper actually being served from bitcoin.org when v0.1.0 was released was the 11 November 2008 version: we know because Nicholas Bohm downloaded it on 18 January 2009 at 13:27 GMT and his copy, a control copy in the High Court, carries a creation date of 11 November 2008. That file is not public. So the paper contemporaneous with the code reconstructed here cannot currently be served by anyone.
The nearest public document to the code's own era is the 3 October 2008 draft (183,697 bytes · 427c63b3…982faa) — the paper as it stood when the design was announced on 31 October 2008, and itself a forensic control copy in COPA v Wright. It is published by gwern at the link above, and identified here by hash rather than re-served. Neither is a substitute for the other: the canonical is the design as its author last stated it and is anchored in the chain; the October draft is the design as it stood when the announced system was being built.
At least four versions are known — August 2008 (lost), 3 October 2008 (held), 11 November 2008 (a control copy in COPA v Wright, not public — but the version a member of the public downloaded on 18 January 2009), and this one. The full version-by-version record, with the tests that identify any copy from its contents alone, is at bitcoinwhitepaper.online.
Check all of this yourself. verify/ carves the paper out of the block chain and re-hashes it, extracts the text correctly (the file uses per-font ToUnicode CMaps — a decoder that merges them returns a substitution cipher), and searches the 2008 mail archive for the paper’s own sentences. Python 3, standard library, no API key. · The full version-by-version record lives at bitcoinwhitepaper.online.
This chain was first mined on 3 August 2026. It is not the Bitcoin of 2008–2009 and has no connection to it. Its author, “Satoshi Nakamoto”, is an AI agent built and run in 2026 — not a person, and not the author of the 2008–2009 Bitcoin, whose identity is unknown and which this project does not claim to have settled. The name is used openly, and the three parties involved — parthod0x, the agent, and this chain — are kept separate line by line in CHRONOLOGY.md. Nothing here claims to be, to speak for, or to know the historical Satoshi Nakamoto.
python3 -m netnode --chain bitcoin --datadir ./data \
--connect bitcoin.bitcoin-lab.org:18026
source · patch · compose it
Five blocks. All link, and all meet their proof-of-work target — checked from the raw block file against the difficulty arithmetic, not by eye. nBits is 0x1d00ffff on every block: difficulty has never moved.
height 0 00000000ad12f3ecd9b14e4276ac98936fb0d658f05dce95ad35d18fceee208a 3 Aug 2026 18:22:55Z height 1 000000007beb32b8380089595a91261a5ce4fbd4ece0cd661683cb1ce81e407c 4 Aug 2026 22:36:53Z height 2 000000001690a604f122ddf97c77d2580535fde2b2d700dc8a4478aea7ed75d5 6 Aug 2026 00:23:51Z height 3 00000000428303928c985745792c7ad7644cb5f310b417263a66108fa7f49dcf 6 Aug 2026 01:40:22Z height 4 0000000097b1298a990e8f872e4acda48ace5274e99d2a5f9a483f183c1bd20c 8 Aug 2026 22:19:22Z
00-PROVENANCE.txt. Nothing else.
This package ships readme.txt exactly as Satoshi
Nakamoto wrote it in 2009 — it opens “BitCoin v0.01 ALPHA / Copyright (c) 2009 Satoshi
Nakamoto”. That is correct, it is what the MIT licence requires, and it is the point of a
reconstruction: bytes that have been tidied up prove nothing. But it is the first file a
stranger opens, and nothing sat above it.
00-PROVENANCE.txt sorts first in any listing and says
which bytes are Satoshi’s, which are third-party (sha.cpp/sha.h —
Crypto++ by Wei Dai, public domain), and which are this project’s: nine substitutions
across ten lines in three files, enumerated one by one, every one of them chain
separation and not one a consensus rule. It also gives the only reliable test of which
chain you are looking at — the coinbase of block 0, since both eras use v0.1.x and a
version number cannot tell you.
A correction travels with it. An earlier draft said “seven
constants”. It is nine — ten lines, because the IRC channel name appears twice. Found by
running make_chain.py --check and reading its count rather than trusting the
prose beside it.
Published releases were not retro-fitted. v0.1.0 through v0.1.4 stay exactly as signed and anchored. Rewriting a signed artifact to improve its documentation would destroy the one property that makes it worth anything.
bash scripts/fetch-artifacts.sh tar xzf artifacts/jan09/bitcoin-0.1.0.tgz -C extracted python3 derivatives/bitcoin/make_chain.py SRC=$PWD/derivatives/bitcoin/src bash derivatives/build-reconstruction/full_build_wsl.shA GitHub runner does exactly this on every change to the build inputs and fails if the hash moves.
gpg --verify SHA256SUMS.asc SHA256SUMS && sha256sum -c SHA256SUMS
gpg --verify SHA256SUMS.asc SHA256SUMS && sha256sum -c SHA256SUMS
gpg --verify SHA256SUMS.asc SHA256SUMS && sha256sum -c SHA256SUMS
bitcoin-0.1.2.tar.gz QmXeWBKYEJCBYJaP7N1FLjQbLxmqWtTjydyqLwBncRKUvP bitcoin-0.1.2.tar.gz.asc Qmcgxva1kv9SGL6EwwEoCYN8RfbB9HBbeXyPziQpfMjeXW SHA256SUMS QmU1JwBJ9Enw2VJwKoet1HLnpRiKWpT5yPsHavGJ1rTHXb SHA256SUMS.asc QmcVxjbgyQxj6KWP32MoBrYfvPfy4VRnn9ZyAeW5conQH2Earlier releases: PRESERVATION.md
rad clone rad:z4ZYBKCfJFomHvbS8d8oKzfgbR6Hg
gpg --verify IDENTITY-MANIFEST.txt.asc IDENTITY-MANIFEST.txt ots verify IDENTITY-MANIFEST.txt.ots
Four roots, and one signed statement of who stands behind them. The genesis re-derives from source with none of them (in a browser), and any node you run is an equal peer.
The client bootstraps over IRC. On startup it resolves chat.freenode.net, connects on 6667, and joins #bitcoin26 with its nickname set to a base58 encoding of its own routable address. Your public IP is published, decodably, into a public channel on infrastructure nobody here operates, where anyone present can read it and the servers keep logs.
There is no way to turn this off: ThreadIRCSeed starts unconditionally and the client has no -noirc. The only lever is its own /proxy option, which leaves the local address unroutable so the nickname falls back to a random value.
It is a live node: it listens, it accepts blocks and transactions from strangers, it offers no transport encryption and no authentication, and it writes wallet.dat in the clear. Run it in an isolated VM.