The problem
Introduction · Transactions
Why digital signatures alone do not prevent a sender from spending the same funds twice.
How could people exchange digital money without a central party keeping score? Read Satoshi Nakamoto’s original proposal, then follow its argument one section at a time.
Read the original PDFSatoshi Nakamoto · 9 pages · 12 sections
Introduction · Transactions
Why digital signatures alone do not prevent a sender from spending the same funds twice.
Timestamp server · Proof of work · Network
How a chain of proof of work gives participants a way to agree on transaction order.
Incentive · Storage · Verification · Value
How rewards, compact data structures, and inputs and outputs fit the proposal together.
Privacy · Calculations · Conclusion
Where the privacy model has limits, and how the security argument depends on an honest majority of computing power.
The white paper explains the original design. Bitcoin’s implementation has evolved. Use the original paper for its argument, the October 2008 announcement for the publication record, and the code and documentation for implementation details.
If the terminology is unfamiliar, our learning path is a gentler starting point.