Non Dubito Essays in the Self-as-an-End Tradition
| | 日本語 | Français | Deutsch | Español | 한국어
← 凿构周期律·经济系列 ← Chisel-Construct Cycle: Economics
凿构周期律 · 经济
Chisel-Construct Cycle · Economics
第 22 篇,共 23 篇
Essay 22 of 23

第二十二篇 中本聪与加密货币:不必被信任的账本,还是要有人拿去用

Essay 22: A Ledger No One Has to Honor — Somebody Still Has to Use It

Han Qin (秦汉)

一 密码朋克要写代码

九十年代初,一份后来被称作密码朋克宣言的文本里有一句话:密码朋克要写代码。

这句话的意思不是技术乐观。它的意思是:不要向政府,公司或者任何公共权威去讨还隐私,要直接把制度写进软件。

同一个圈子里,另一份叫加密无政府主义宣言的文本,写下了一句方向完全不同的预言:在匿名的网络互动中,声誉将居于中心位置。

两句话出自同一个传统。前一句是纲领,后一句是预言。

要留意后一句的位置。它不是外面的批评者说的,不是后来的失败者说的,也不是监管机构说的。它出自这个传统内部,而且写在最激进的那一份文本里。一个要把匿名推到极致的人,顺手写下了匿名之后会发生什么。

而后面这一整段历史,是前一句被实现到极致,同时后一句被应验到极致。

前二十一篇里,构一直在做同一件事:把塞不进同一把尺子的东西压进去,让账做平;而每一次都有塞不进去的部分溢出来,构再想办法处理它。处理的办法出现过十种。

这一次不一样。

这一次要做的不是处理余项,是取消余项的来源。

那个来源有一个名字,叫信任。

这个诊断本身是准的。前面二十一篇里那些溢出来的东西,追到底几乎都落在同一处:总要有人被相信,而被相信的人会出错,会偏心,会收钱办事,会在最要紧的时候关门。神庙可以改规矩,官府可以不认自己发的纸,评级机构可以拿发行人的钱,交易所可以在一夜之间倒掉。既然麻烦都出在这里,那就把这里去掉。

前面二十一篇里,每一本账最后都要有人认。第二篇里泥板上的债要靠神庙的位阶去认,第六篇里的交子要靠官府认,第十七篇里的美元要靠一群人愿不愿意继续认账,第十八篇里那台机器停下来的时候靠国家出面说我认。

而 2008年出现的那份方案要做的,是让这个动作不再必要。

它的第一句话就把问题说得很直白:网上支付如果还要经过金融机构,主要的好处就丧失了。它要找的是一种不需要信任的电子现金。

2009年二月,作者在一个网络论坛上把目标说得更干脆:这套东西完全去中心化,一切都建立在密码学证明上,而不是建立在信任上。

这是整个系列走到这里,构做出的最大胆的一次尝试。

它不打算给余项一条轨道,不打算把它划到门外,也不打算要求它出示凭据。

它打算让余项无处产生。

这是一个非常干净的思路,而且它比前面十种办法都更彻底。前十种都是在余项已经出现之后动手:松开它,改它的名,不去问它,把它折算掉,把边界收回来,给它一条轨道,要它出示凭据,把它归到它自己头上,不让它上账,或者去改造那个会溢出的源头。这一次要做的是从源头上不让它有。

二 驯化还是消灭

这套方案不是凭空出现的。有研究者概括得很准确:它几乎所有的技术部件,在八十年代到九十年代的学术文献里都能找到前史;真正的创新不是某一个零件,而是把这些零件用一种此前没人成功做到的方式拼起来。

这条谱系值得走一遍,因为每一步都在同一个问题上让了一点或者进了一点。

最早的一步在 1983年。一位密码学家提出了一种叫盲签名的技术,用来做不可追踪的支付。他在文章里已经把自动化支付系统和个人隐私之间的冲突摆了出来,并试图用密码学去保护支付的匿名性。

而这套电子现金的难处也恰恰在这里:它保护了付款人的隐私,却仍然离不开一个中心化的发行者或者银行式的服务器。

也就是说,它没有消灭可信的第三方。它只是试图驯化它。

驯化和消灭之间的差别,是这一整条谱系的主轴。每一步都在往消灭的方向挪一点,而每一步都还剩下一样东西没挪掉。看这条线的时候,不必看谁更聪明,只要看每个人剩下的那一样是什么。

到九十年代初,那个圈子把问题往前推了一步。有人设想不可追踪的网络互动和匿名化的市场,而且他自己明说,这会让某些极其恶劣的市场成为可能;国家会因此试图阻止这套技术扩散,而这些担忧里很多都会是真的。

这一点要记住:这不是后来的批评者附会出来的阴暗面。它写在原始文献里,是当事人自己算出来的成本。

这一点要记住,因为它决定了后面该怎么评价这件事。一项技术如果它的坏处只有反对者看得见,那可以说是设计者疏忽;而这里的坏处是设计者自己先写下来的,并且在写下之后仍然认为值得做。这就不是疏忽的问题,是一次明知代价的取舍。

1997年到 2002年之间,另一位研究者把工作量证明从政治愿景推进成了可操作的工具。

那套东西原本是用来反垃圾邮件和反滥用的:发信的人必须先做一段可以被验证,但在计算上相当昂贵的工作,服务器才放行。

他自己在文章里打过一个比方,说这种代价函数可以被看成是在铸造实体货币。

这个比方里已经能看见后来那套东西最核心的冲动:把原本由社会判断,机构筛查或者定价体系承担的那部分门槛,改写成统一的算力成本。

接下来有几条几乎直接通往结果的支线。有人提出过去中心化数字货币的轮廓;萨博构想的比特黄金,几乎把后来的框架拆开摆在了桌上:先生成一串挑战,再求出工作量证明,再做安全的时间戳,再写进分布式的产权登记簿,并由前一串生成下一串的挑战。

而萨博自己直说,这个体系仍然有薄弱处:时间戳服务和产权登记簿所需要的信任,只能被分散化,不能凭空消失。

还有一种尝试想让工作量证明的代币可以重复使用,而它依靠的是可以被远程验证的专用服务器,仍然保留着一个服务端的核心。

所以在那份方案出现之前,数字现金已经走到了一个很清楚的岔路口。

要么保留一个中心的发行者。要么只把计算成本当成一张门票。要么把工作量证明往货币的方向推,却还没有真正摆脱时间戳,登记簿或者服务器这一类薄弱环节。

每一条路上都还剩着同一样东西没有被解决掉。

而它剩下来的位置,每次都比上一次更小,也更硬。

更小是因为一代一代的人确实在往里收。更硬是因为剩下的那一点,往往正是最难处理的那一点:总得有人来说这笔在前,那笔在后;总得有人来保管那本登记簿;总得有一台机器在某处应答。把大的部分砍掉不难,难的是最后剩的那一小块。

三 十分钟

那份方案的出发点很朴素。

数字签名可以证明是谁把币转给了谁,却单独解决不了另一个问题:同一枚币被花两次怎么办。

在从前的电子货币设计里,常见的办法是引入一个中心化的铸造方或者清算方,由它来检查每一笔交易。

而这一次的办法是不用可信的第三方,改用点对点的网络,时间戳,和工作量证明,把交易的顺序钉下来。

谁先被写进那个被全网承认的公共历史,谁就算数。

这句话把一个古老的问题换了个位置。第二篇里,泥板上写着谁欠谁多少,而谁的泥板算数,要看它压在哪座神庙的库房里。这里不问它压在哪里,只问它写得早不早,以及它后面跟着多少工作量。顺序取代了权威。

机制上它做了三件事。把交易打包成区块。让参与计算的人为区块头去寻找满足难度目标的哈希值。让节点接受累计工作量最大的那条链作为有效的历史。

这三件事里,第三件最容易被略过,而它才是要害。前两件是技术,第三件是一条规矩:遇到分歧时,认哪一边。所有的账本都要回答这个问题,而从前的答案都是某个人或者某个机构说了算。这一次的答案是,谁背后堆的力气多,认谁。

只要诚实的节点掌握多数算力,要篡改旧账就得把它之后的所有工作重做一遍,而成本会迅速上升。

方案里还写明了两个决定制度节奏的参数:新区块平均每十分钟产生一次;难度每两千零一十六个区块调整一次,以稳定出块的速度。

而这里最值得看清楚的,不是去中心化这四个字。

是它对共同尺度的处理。

前面所有的尺子,量的都是别的东西:一石粮,一天工,一亩地,一盎司金,一次点击。这一把尺子量的是把这笔账记下来所花掉的力气本身。它不去量世界上的任何一样东西,它量的是记账这个动作的成本。

那套反滥用机制原本只是一张门票。而这一次它被推进了一步:工作量证明不再只是进入系统的资格,它直接成了发行机制本身。

新区块的奖励,把算力,电力和时间直接折算成新的币。

于是工作量成了货币史上一种非常少见的东西:一把被统一公开计量的铸币标尺。

作者后来在论坛上解释稀缺性时说,最终最多只有二千一百万枚。

到这里,货币的供给,支付的排序,结算的最终性和防伪的成本,被压进了同一条计算逻辑里。

第十四篇里说过,金本位说服人的方式不是它更方便,也不是它更精确;它说服人的方式是,这不是谁定的,这是黄金的重量,而黄金在地底下,不听任何一个政府的话。

这一次的说法是同一个形状,只换了一样东西。

这不是谁定的,这是算出来的。

这句话的说服力比前一句更强,而强的地方在可核对性。黄金的重量要有人称,而称的人可能作弊;哈希值不用称,任何人在任何一台机器上重算一遍,得数完全相同,而且几秒钟就能验完。第三篇里那些验戳的人,在这里第一次真的不需要了。

而算出来这三个字比黄金的重量走得更远。黄金还需要有人去挖,去验成色,去存进金库,去在两国之间用船运,而每一步都要有人经手。哈希值不需要。它可以被任何一台机器在任何一个地方独立地重算一遍,得数完全相同。

它没有回到金属。它把代价本身抽象成了哈希运算,专用硬件,电价和难度调整。

四 账本的第一行

2009年一月三日,第一个区块被写下来。

区块里嵌进了当天泰晤士报的一条标题,大意是财政大臣正处在对银行进行第二轮救助的边缘。

这条标题有两个作用。它是一个时间戳,证明这个区块不可能在那一天之前被造出来。它同时是一种姿态:把起点钉在全球金融危机和银行救助的那个时刻。

这个区块的五十枚奖励,后来被证明是不可花费的。

把这两件事放在一起,能看出一件在整个系列里独一份的东西。

前二十一篇里,每一本账的第一行都是一笔账。一石大麦,一头牛,一笔欠款,一份契约,一个人的名字后面跟着一个数目。

而这一本账的第一行不是一笔交易。

是一句话。

而且这句话旁边那五十枚币,永远不能被花掉。

这五十枚的处境值得多看一眼。它们在账上,任何人都能查到它们存在;而它们出不去,也进不了任何一次交易。一本以流通为全部目的的账,它的第一笔永久地不流通。这不是技术上的疏忽,后来的分析普遍认为那是设计使然。开账的人把第一笔留成了一个不能动的标记。

一本账在开篇就声明了自己是为了对抗什么而设的,然后把开篇那一笔永久地留在原处,不参与流通。

构在这里第一次公开承认,自己是一个反构。

而这个承认已经是它后来命运的伏笔。一样东西如果只是一件工具,它可以被谁都拿去用,谁都不觉得有立场;而一样东西如果开篇就宣布了自己反对什么,它就从第一天起有了敌人,有了信众,也有了它必须一直配得上的那个姿态。

而价值是怎么第一次有了数的,同样值得看。

2009年十月,一个早期的网站给出了美元兑换率,用的是一套电力成本公式:以美国居民的平均电价,一台机器的年耗电量,和过去三十天这台机器产出的币数来推算卖价。

最早公开的汇率大约是一美元兑一千三百零九点零三枚。到 2009年十二月二十八日,那个页面上的数字变成了一美元兑一千五百七十八点七七枚。

这两个数目本身不要紧。要紧的是它们是怎么算出来的。

价值不是先来自商誉,不是先来自税收,也不是先来自国家的令状。它先被系在一套可以逐度电核对的生产成本上。

第十一篇里那条把价值系在劳动上的思路,在这里有了一个技术版本,而且是一个比当年精确得多的版本:社会必要劳动时间是一个要靠统计才能逼近的量,而一台机器三十天用了多少度电,电表上写着。

而这个锚后来完全松掉了。价格离开了电力成本,再也没有回去过。

一把尺子最初的刻度是怎么定的,和它后来量出什么,常常没有关系。

这一条在前面出现过,只是没有这样清楚。第三篇里的币,起初的分量对应着一份实在的金属,后来对应的是发行者的信誉;第十七篇里那个共同分母,起初对应着黄金的重量,后来对应的是几个国家肯不肯继续认账。刻度立起来的时候总要靠着一样看得见的东西,而立稳之后,那样东西常常就被撤走了。

五 顶多算怀疑式接待

时间线值得走一遍,因为它把一件常被讲成传奇的事,压回到了具体的展开过程里。

2008年十月三十一日,方案被发到一个密码学的邮件列表上。

2009年一月三日,第一个区块。一月八日,第一版软件发布,公告里写着完全去中心化,没有服务器,也没有中央权威。

一月十二日,第一笔链上转账。芬尼后来回忆,他是中本聪之外第一个运行这套软件的人,挖到了七十多号区块,并收到中本聪发来的十枚测试转账。

二月十一日,那段关于完全去中心化和密码学证明的话。

2009年十月五日,第一个美元报价。

2010年五月二十二日,有人用一万枚换了两张披萨,按当时的估值大约四十一美元。这通常被视作第一笔著名的现实商品交易。

2010年七月十七日,一家交易平台上线。这套东西从邮件列表和点对点的阶段,进入了交易平台的阶段。

2010年十二月十一日,当维基解密可能采用这套货币的时候,中本聪表示了担忧。他写下一句后来常被引用的话:捅了马蜂窝,蜂群正朝我们飞来。

2011年四月二十三日,他给一位开发者写信说,我已经转去做别的事了,它在他们手里。

这一句作为退场是罕见的。前二十一篇里,立起一把尺子的人几乎都留了下来:留下来解释,留下来修补,留下来在别人质疑时出来说话,或者留下来分好处。而这一次,写方案的人在它刚站住的时候就走了,并且此后没有回来说过一句话。

这条线里有两个细节特别要紧。

第一个是芬尼的那句回忆。他说 2008年底邮件列表上的反应,顶多算怀疑式的接待。

也就是说,这不是一份一出手就征服同行的方案。在一群见惯了宏大计划的密码学老手那里,它先遭到的是冷眼。

第二个是价格。早期的价格并不是被广泛的市场共识一下子发现出来的。它是先由极少数参与者,通过电力成本的推算,论坛上的换物和简陋的交易平台,一点一点摸索出来的。

货币成为共同尺度,不是自然发生的事。它是反复试算,反复争吵,反复出价之后才勉强站住的。

这一条对整个系列很有用。

前二十一篇里立起来的每一把尺子,在它立起来的那一刻,大概都经过同样狼狈的一段。只是那些事情太久远,记录太少,后人看到的只是它已经立稳之后的样子,于是很容易以为它一开始就该是这样。

这一次不同。这一次全过程都有记录:哪一天有人第一次问它值多少,谁第一次拿它换了实物,第一个报价是怎么算出来的,以及有多少人在一开始并不看好。

一把尺子的诞生现场,很少这样完整地被留下来。

而留下来的那份记录,几乎每一处都在拆前二十一篇容易生出的那种错觉:以为一把尺子是因为它对才被采用的。这里能看到的是另一回事:它先被冷眼,再被少数人试着用,再被算出一个不太可靠的价,再被拿去换了两张披萨,然后才一点一点有了别人。

还有那句马蜂窝也要单独摆一下。

一个宣称完全去中心化,不依赖任何人的系统,它的创造者在担心它会被谁盯上。

这句话说明,他很清楚这套东西并不真的在社会之外。它要活下去,还得看外面那些他没法用代码约束的东西怎么反应。

这一层从第一天起就在。一套完全不需要许可就能运行的东西,仍然要在某些国家能不能开交易所,能不能连银行,能不能买到机器,电价高不高这些事情上,受制于它管不着的地方。代码可以规定链上的一切,规定不了插头在谁手里。

六 信任去了哪里

支持者最强的一种说法,是把它理解成第一次比较成功地实现了这样一件事:陌生人之间,不预设身份,没有可信的第三方,仍然能够转移价值。

相关的学术综述也是这样描述它的。在这个意义上,它确实填补了某种空白。

这一点不能被打折,因为前二十一篇里那些账本,没有哪一本做到过。它们全都要求先知道你是谁,或者先有一个大家都认的机构站在中间。

这件事的分量,要放到前面几篇的具体处境里才看得清。第十三篇里那些说不出凭据的人,第十六篇里不在名单上的人,第二十一篇里信用上看不见的人,他们被挡住的方式各不相同,而共同点是一样的:总有一道门要先验明你是谁。而这一次,那道门被取消了。它不问你是谁,它只看那串签名对不对。

而另一种解释强调,这里的不需要信任始终是有边界的。

有研究者把它称作一种试图把货币从社会生活里抽离出来的机械化货币想象。另有研究者对社区的观察发现,使用它的人并没有真的生活在一个零信任的世界里;他们是在围绕着技术比人更可信这样一种共同信念,重新建构了信任。

换句话说,所谓不需要信任,在实践中往往不是信任的消失。

是信任对象的转移。

从银行家,国家和公司,转向协议,代码库,节点的分布,矿工的激励,以及围绕这些技术对象形成的共同信念。

转移不等于没有变化,这一点要说公道。相信一份公开的代码,和相信一家不公开账目的机构,不是同一件事:代码可以被任何人读,机构的内部谁也进不去。转移之后可核对的部分确实多了。而可核对不等于人人都会去核对,读得懂那份代码的人,在使用它的人里始终是极少数。

经济学上的批评又把问题推进了一层。

有中央银行的研究文章说得很尖锐:加密货币对信任的防腐处理,是以便利性为代价的。如果我们真的生活在一个完全没有机构信任的世界里,这套东西也许会占优;而在现实里,人们往往愿意相信支付机构和中央银行,因此既有的体系仍然更方便。

另一位研究者则从成本结构上攻击这套设计。他的判断是:维持这种匿名的,去中心化的信任,代价很大,而且会随着系统里的赌注扩大而线性上升。要想在更大的规模上保持可信,就必须付出相应更高的安全成本。

这一条对框架很要紧,所以要把含义说清楚。

省掉的那部分信任,并没有变成零。

它变成了一条电费单。

剑桥的一个指数和美国的能源统计机构都指出,挖矿的电力需求已经达到了足以进入国家级统计和政策讨论的规模。

也就是说,不需要信任这件事本身是有价格的,而且这个价格被明明白白地记在了另一本账上。

这也是这套东西一个很少被强调的诚实之处。从前那些账本把成本藏在别处:兑付的承诺不记账,救助的可能不记账,一个国家的信誉值多少也不记账,它们只在失效的那一天才一次结清。这一次的成本每天都在电表上走,谁都看得见。它更贵,而它不赖账。

从前那些账本要靠人去认,认这个动作不花钱,只是不可靠。这一次不必有人认了,而代价是每十分钟都要有一批机器把电烧掉。

第十四篇里那把尺子把兜底挪到了金属和几家央行身上。这一次它挪到了电力和算力上。

而没有被收进这把尺子的东西,一直在外面冒头。

交易确认要等多久。手续费什么时候会涨。链堵的时候怎么办。密码忘了找谁。法币怎么进,怎么出。矿机的产能在哪几家手里。矿池之间怎么协调。

这些没有一样写在协议里。

把上面那串问题和第十八篇那条被切成七段的链子放在一起看,形状是一样的。那里是一笔按揭被拆成七个环节,每个接头处都留着一点必须靠信任才过得去的地方;这里是一笔转账被拆成协议内和协议外两截,而协议外那一截同样有七八个接头。差别只在于,那一次拆链子是为了把风险卖出去,这一次拆是因为协议只管得了它管得了的那一段。

协议管的是链上的顺序。而一个人要用它,得先穿过这十来样东西,而这十来样东西里的每一样,都要他相信点什么。

七 谁来改协议

信任回流最鲜明的通道是交易所,而且这条通道的标本非常完整。

协议本身也许不要求你信任某一家银行来清算你的付款。但只要你想把法币换成币,把币换回法币,或者只是嫌自己保管私钥太麻烦,你就会落到托管平台,支付处理商和钱包服务商的手里。

2014年破产的那家交易所正是这个过程的标本。它一度成了这套货币的脸面,是人们看价格,做交易,出入金的主要入口。

它在 2014年二月二十八日的公告里承认,大约七十五万枚客户的币和大约十万枚自有的币消失了;公司称它们极有可能被盗,同时银行账户上还出现了大约二十八亿日元的差额。

到三月二十日,公司又说在旧钱包里找回了大约二十万枚,因此估计实际失踪的数量降到大约六十五万枚。

后来的调查把失窃的时间线追溯到 2011年到 2014年之间的反复被盗。

这里发生的事情,不是协议层面的双重支付危机。

是使用者把一笔号称不需要信任的资产,重新交给了一个必须被信任的中介。

于是多年的等待,资金的冻结,赔付的诉讼和身份的核验,全都回来了。

有通讯社在回顾里写得很清楚:这家交易所的崩溃暴露出,那个社群自由放任,反对监管的理想,必须和金融服务所要求的稳定操作,合规与客户需求碰撞。

而这不是偶发的偏离,是结构性的回流。

金融稳定委员会在讨论去中心化金融的风险时指出,所谓的去中心化金融与中心化的交易和借贷平台之间,存在整体性的连接;很多参与者正是通过这些平台,在链上的体系和法币的世界之间来回切换。它还特别点出,这些治理框架往往不清晰,不透明,未经检验,或者容易被操纵,实际的去中心化程度差异极大。

第二条回流通道更根本,而且它是全篇的核心。

有研究者做过一个区分:由基础设施进行的治理,和对基础设施进行的治理。

前者是协议自动执行规则。这一部分做得很成功。

而后者是另一回事:协议本身怎么改,谁来修那些错误,链分叉的时候听谁的,节点该不该升级。

这些问题不能被协议自己消灭。

另一位研究者进一步指出,现实中的区块链治理仍然依赖人的判断,影响力和非正式的治理;她甚至用了一个描述个人魅力型支配的说法,来形容其中的一类权威。

后来的区块大小之争,隔离见证的激活,以及由使用者发起的软分叉,都说明使用者,矿工,核心开发者和企业,并没有被密码学抹平成完全对等的粒子。

所谓共识,经常是技术参数,经济激励,话语权和舆论动员共同构成的结果。

到这里可以给出那条反哺了。

构可以规定一切,除了谁来改这些规定。

这一条前二十一篇里没有出现过,原因很简单:前面那些构从来没打算把自己写死。它们都留着一个可以修改的位置,而那个位置上通常坐着人,坐着议会,坐着央行,坐着专员,坐着评级委员会。

这一次是构第一次试图把那个位置也取消掉。

而取消不掉。规则可以自动执行,改规则不能。

这一条可以和第十七篇对着看。那份国际协定的正文里印着一条几乎从不使用的条款,而那条款的存在本身,就是构在自己的文本里给修改留出的一个位置。前面那些构都留了这样一个位置,而且通常还写明了谁有资格坐上去。这一次没有留。

第三条回流通道是创始人的声望。

这套货币有一点很特殊:创始人的退出,某种意义上削弱了后续干预的可能,也给很多支持者留下了一个没有皇帝的神话空间。

而整个加密史并不都是这样。

2016年,一个建在另一条链上的自治投资组织被人转走了大约六千万美元的代币,社区随后选择硬分叉,把那件事的影响回滚,于是留下了两条链。

这说明代码即法律这句话,在足够大的损失面前,可以被社区政治推翻。

再往后,2022年一种稳定币和它的配对代币崩盘,监管机构和调查报道的焦点,直接落在创始人和公司如何靠反复陈述建立信任,又如何在脱锚之后造成巨额损失上。

更极端的一例,几乎是这整个传统的反面:一家中心化交易所的创始人,以个人声望和品牌叙事聚拢了大批人的信任,最后被认定为挪用,欺诈与非法混用客户的资金。

这一点和当年那句预言形成了一种奇怪的呼应。

匿名的体系没有废除声誉。它把声誉放到了更危险的位置。

因为在缺少传统审计,存款保险,明确的公司治理和成熟救济机制的地方,创始人,核心开发者,交易所老板,审计的神话和社区的文化,都会得到超额的意义负载。

声誉不再只是附属物。它成了把匿名货币重新接回社会世界的那座桥。

而第二十一篇说过,声誉自己也想闭合,它并不天然比货币更宽厚。

在这里可以再补一句:当一样东西周围的正式制度越少,落在声誉上的重量就越大;而重量越大,它出问题时砸下来的东西也越多。

八 不可修复

关于这一整段历史,争论至今没有合拢,而且分歧不在口味上。

第一组是解放性的去中心化,还是投机性的新中介。支持者强调,它第一次让陌生人在没有银行,没有清算所,没有预设身份的条件下转移了价值,是对金融危机,资本管制,支付审查和法币膨胀的一种技术回应。批评者则指出,现实中交易量的大头长期集中在交易所和投机场景里;有研究者直接写道,今天规模最大的加密活动,恰恰是通过那些可信的金融中介完成的,因此并没有真正用上匿名与去中心化信任的好处。

第二组是不需要信任究竟是制度事实,还是宣传语言。原始文献无疑把用密码学证明取代信任放在了中心位置;而另一些研究认为,这种说法忽视了围绕代码,社区和共同信念形成的社会性信任。分歧不在于它是否消灭了某些旧的中介,而在于:消灭了旧中介之后,剩下的那部分依赖,该不该还叫信任。

第三组是技术治理能不能替代政治治理。乐观的一侧认为,协议规则,开源代码,节点选择和市场竞争可以构成一套足够强的自组织秩序。怀疑的一侧指出,公共链的实际运行总要依赖少数核心开发者,矿池,基础设施商和舆论领袖;分叉不是漏洞,而是结构性的结果。

第四组是它究竟更像货币还是更像投机性资产。支持者会举出从十枚测试转账到一万枚披萨的那段历史,说明它确曾作为支付手段被试出来;批评者则指出,后来围绕它形成的社会实践,更常以囤积,交易,杠杆和价格叙事为中心。有研究者给过一个很尖锐的判断:如果它按照自己的意识形态目标完全成功,它反而会在现实的货币功能上失败。

这里不裁决。

不裁决的理由这一次特别清楚:四组争论问的不是同一件事。第一组问的是实际用途落在哪里,第二组问的是一个词该怎么定义,第三组问的是制度设计的可能性边界,第四组问的是一样东西的性质。把它们揉成加密货币到底行不行,得到的不会是答案。

而在这四组争论之外,还有一件事可以说得比较确定,它接的是上一篇的结尾。

第二十一篇里说过,每一套评分系统最后都会长出一个叫作修复的机制;而修复这两个字是一份供词,它承认一个人可以改变,而记录是过去的压缩,两者之间有一段差。

这一套系统的设计正好相反。

它以不可修复为荣。

交易一旦被写进那条链,就不可逆。私钥丢了,币就没了,没有任何人能替你找回来。链上没有申诉的窗口,没有客服,没有一个可以被说服的人,也没有谁有权改掉已经写下的哪一行。

这不是它的缺陷。这是它全部安全性的来源。

一本账之所以可以不需要任何人去认,前提正是没有任何人能够动它。

可以动就得有人有权动;有人有权动,就得有人被信任。

所以不可修复和不需要信任是同一件事的两面,不能只要一面。

而 2016年那一次,在损失足够大的时候,门被撞开了。

社区讨论,投票,硬分叉,把那笔转走的代币回滚。而回滚不是协议自动完成的,是一群人开会决定的。

那次之后留下了两条链:一条接受了回滚,一条坚持原来的历史不能被改。

这两条链后来都还在跑。

也就是说,那次争论并没有产生一个答案,它产生的是一个分岔。一部分人选择了可以修复的世界,一部分人选择了不可修复的世界,而两边都没能说服对方。

这个分岔本身比任何一方的胜利都更说明问题。它意味着不可修复不是一个可以被论证出来的立场,它是一个选择;而选择就得有人来选,有人来选就回到了原点。构走了一整圈,想把人从账本里请出去,而在最要紧的那一次,请出去的人又被请了回来,而且是被请进去做决定的。

中本聪要做的事情,可以用一句话说完:让一笔钱从一个人手里到另一个人手里,不必有任何一个人被相信。

他做成了很大一部分。那条链今天仍然按十分钟一格往前走,谁也没有停下它,谁也没有改掉已经写下的那些行。

而人要用它,还得在某个地方把法币换成币,还得把私钥放在某个地方,还得相信写钱包程序的那些人没有留后门,还得在链堵的时候相信手续费明天会降下来,还得在这套东西要改的时候,听某几个人说该怎么改。

这些都不在协议里。协议管的是账,不管用账的人怎么走到账跟前。

一本账可以做到不需要任何人认它。

它做不到不需要任何人用它。

而只要有人用,就会有人出错,有人被偷,有人在半夜丢掉一串字符,有人在一次崩盘之后要求把事情倒回去。到那一天,总得有人出来决定倒还是不倒。

前面二十一本账,都在自己身上开了一扇叫修复的门,而且规定了要走多久,交什么,做到什么程度才算走完。

这一本没有开那扇门。它把不能修复写成了自己全部安全的来源。

而门还是被撞开过一次。

撞门的不是协议。是一群人开会。

账还没有算平,它仍旧在记。

1. The Source Called Trust

In the early 1990s, a text that would come to be known as A Cypherpunk's Manifesto contained a single sentence that has outlived everything around it: "Cypherpunks write code."

The sentence was not a piece of technological optimism. It meant something narrower and more combative: stop petitioning governments, corporations, or any public authority for the right to privacy, and write the arrangement directly into software instead, where no one need grant it.

From the same milieu, a second text, The Crypto Anarchist Manifesto, set down a prophecy pointed in an entirely different direction: that in anonymous network interactions, reputation would come to occupy the central place.

The two lines come out of the same tradition. The first is a program. The second is a prophecy.

The position of that second line deserves attention. It was not spoken by an outside critic, not by some later casualty of the project, not by a regulator. It came from inside the tradition, and it sat inside the most radical of its founding texts. A man bent on pushing anonymity to its limit paused, in the same breath, to write down what would happen once anonymity got there.

Everything that follows is the record of the first sentence carried out to its extreme, and the second fulfilled to its extreme, at the same time.

Across the previous twenty-one essays in this series, the construct has kept doing one thing: forcing whatever will not fit on a single scale onto that scale anyway, so the books can be made to balance — and every time, something refuses to fit, spills over, and the construct has had to find some way of managing what spilled. Ten such ways have appeared so far.

This time is different.

This time the aim is not to manage the remainder. It is to eliminate the source that produces it.

That source has a name. It is trust.

The diagnosis is accurate. Trace the overflow in any of the previous twenty-one essays back far enough and it lands, almost without exception, in the same place: somebody had to be trusted, and whoever is trusted eventually gets it wrong, plays favorites, takes money to look the other way, or shuts the door at the worst possible moment. Temples can rewrite the rules. Governments can refuse to honor the very paper they issued. Rating agencies can be paid by the very issuers they are supposed to be grading. Exchanges can vanish overnight. If the trouble keeps originating in the same place, the obvious answer is to remove that place.

In each of the previous twenty-one essays, every ledger, in the end, needed somebody to honor it. In Essay 2, the debt written on a clay tablet had to be honored through the temple's hierarchy. In Essay 6, the jiaozi note had to be honored by the government. In Essay 17, the dollar depended on whether a group of people remained willing to keep honoring the account. In Essay 18, when the machine finally seized up, it took the state stepping forward to say: I honor this.

What appeared in 2008 was a proposal designed to make that act unnecessary.

Its opening lines put the problem without any padding: commerce on the internet had come to rely almost exclusively on financial institutions serving as trusted third parties, and what it wanted instead was, in its own words, "an electronic payment system based on cryptographic proof instead of trust." What it was building was a purely peer-to-peer electronic cash, one that would let online payments move directly from one party to another without ever going through a financial institution.

In February 2009, its author put the goal even more bluntly on an internet forum: "It's completely decentralized, with no central server or trusted parties, because everything is based on crypto proof instead of trust."

Of everything this series has tracked, this is the boldest attempt the construct has made.

It did not plan to give the remainder a track of its own to run on, did not plan to draw a line excluding it, did not plan to demand that it present credentials.

It planned to make sure the remainder had nowhere left to be produced.

It is a remarkably clean idea, and more thoroughgoing than any of the ten methods that came before it. All ten of the earlier ones went to work only after a remainder had already appeared: loosen it, rename it, decline to ask about it, discount it, pull the boundary back in, hand it a track of its own, demand it show credentials, assign it to itself, keep it off the books, or redesign the source that keeps overflowing. This time the plan was to strike at the source itself, so that nothing would ever be left over to deal with.

2. Tame It, or Kill It

This scheme did not appear out of nowhere. Researchers have summarized its lineage precisely: nearly every one of its technical components can be traced to the academic literature of the 1980s and 1990s; the real innovation was not any single part but the particular way of assembling those parts that no one before had managed to bring off.

That lineage is worth walking through in full, because at every step something was either conceded or gained on the very same question.

The earliest step falls in 1983. A cryptographer proposed a technique called the blind signature, meant for untraceable payment. His paper already laid bare the conflict between automated payment systems and personal privacy, and it tried to use cryptography to protect the anonymity of a payment.

The difficulty with this early electronic cash lay exactly here: it protected the payer's privacy, yet it still could not do without a centralized issuer or a bank-like server standing behind it.

Which is to say: it had not eliminated the trusted third party. It had only tried to tame it.

The difference between taming and killing is the axis the whole lineage turns on. Every step moves a little further toward killing, and every step still leaves one thing untouched. Watching this line unfold, the point is not to rank who was cleverer. The point is to notice, each time, exactly what got left behind.

By the early 1990s, that same circle pushed the question a step further. Someone imagined untraceable network interactions and anonymized markets, and said outright that this would make certain deeply ugly markets possible; that states would try to stop the technology from spreading; and that many of those fears would turn out to be justified.

This is worth remembering: it is not a dark underside that later critics read into the project after the fact. It is written into the primary sources, a cost the author had already calculated for himself.

It is worth remembering because it determines how the whole episode should be judged. A technology whose harms are visible only to its opponents can be chalked up to the designer's oversight. Here, the harm was written down by the designer first, and after writing it down, he still judged the thing worth building. That is not oversight. That is a trade-off made with open eyes.

Between 1997 and 2002, another researcher carried proof-of-work from a political vision into a working tool.

The mechanism had originally been built against spam and abuse: before a server would let a message through, the sender first had to complete a chunk of work that was cheap to verify but expensive, computationally, to produce.

He himself offered an analogy in his own paper: this cost function, he wrote, could be understood as minting a physical coin.

Already visible in that analogy is the core impulse of everything that followed: taking a threshold that had once been the job of social judgment, institutional screening, or a pricing system, and rewriting it as a uniform cost in computing power.

What came next were several threads leading almost directly to the outcome. Someone sketched the outline of a decentralized digital currency; Szabo's proposal for bit gold laid out, almost piece by piece, the framework that would come later: generate a challenge string, solve a proof-of-work puzzle for it, apply a secure timestamp, write the result into a distributed title registry, and let that string generate the next challenge in turn.

And Szabo said outright that the system still had a weak point: the trust required by the timestamp service and the title registry could be distributed, but it could not be made to vanish.

There was also an attempt to make proof-of-work tokens reusable, which depended on a specialized server that could be verified remotely — still keeping a server-side core at its heart.

So by the time that proposal appeared, digital cash had already arrived at a clear fork in the road.

Either keep a central issuer. Or treat the computational cost as nothing more than an entry ticket. Or push proof-of-work toward becoming money itself, while still failing to shake off timestamps, registries, or servers as the weak link.

On every one of those roads, the same thing was still left unresolved.

And the spot where it was left kept shrinking each time, and kept getting harder each time.

Smaller, because generation after generation really had been closing in on it. Harder, because what remained was often the single hardest part to deal with: somebody still had to say this transaction came before that one; somebody still had to keep the registry; some machine still had to be standing by, somewhere, to answer. Cutting away the large part is not difficult. What is difficult is the small piece left at the very end.

3. Ten Minutes

The proposal's starting point was unpretentious.

A digital signature can prove who transferred a coin to whom, but it cannot by itself answer a separate question: what happens when the same coin gets spent twice.

In earlier designs for electronic money, the usual fix was to bring in a centralized mint or clearinghouse to check every transaction.

This time the fix dispensed with any trusted third party and used a peer-to-peer network, timestamps, and proof-of-work instead, to pin down the order in which transactions occurred.

Whichever version got written first into the public history the whole network agreed on — that was the one that counted.

That sentence relocates a very old problem. In Essay 2, what was owed to whom was written on a clay tablet, but whether a given tablet counted depended on which temple's storeroom it happened to be sitting in. Here, nobody asks where it is sitting. The only question is whether it was written early, and how much work has piled up behind it since. Order replaced authority.

Mechanically, it did three things. It packed transactions into blocks. It had the people doing the computing search for a hash value that satisfied a difficulty target set for the block's header. And it had every node accept, as the valid history, whichever chain carried the greatest accumulated proof-of-work.

Of the three, the third is the one most easily skipped over in the telling, and it is the one that matters most. The first two are engineering. The third is a rule: when there is a disagreement, which side does the network recognize. Every ledger has had to answer that question, and until now the answer had always been that some person or some institution got to decide. This time, the answer is: whichever side has more raw effort piled up behind it is the one that gets recognized.

As long as honest nodes control the majority of the computing power, rewriting an old entry would require redoing all the work done since, and the cost of doing that rises fast.

The proposal also fixed two parameters that would set the whole system's rhythm: a new block on average every ten minutes, with the difficulty recalculated every 2,016 blocks to keep that pace steady.

What is most worth seeing clearly here is not the word decentralization.

It is what happened to the idea of a common measure.

Every scale that came before this one measured something else — a picul of grain, a day's labor, a mu of land, an ounce of gold, a single click. This scale measures the effort spent on writing the entry down in the first place. It measures nothing out in the world. It measures the cost of the act of bookkeeping itself.

The anti-abuse mechanism it borrowed from had originally been nothing more than an entry ticket. This time it was pushed one step further: proof-of-work stopped being merely the price of admission to the system and became the issuance mechanism itself.

The reward attached to each new block converts computing power, electricity, and time directly into new coin.

Work, in other words, became something monetary history had almost never seen before: a minting standard that was uniform and publicly measurable by anyone.

Explaining scarcity on a forum some time later, its author said that the total would eventually top out at twenty-one million coins.

By this point, the supply of money, the ordering of payments, the finality of settlement, and the cost of preventing forgery had all been compressed into a single computational logic.

Essay 14 argued that the gold standard never persuaded people because it was more convenient, or more precise. It persuaded them by saying: nobody decided this, this is the weight of gold, and gold, sitting underground, answers to no government.

This time the claim takes the same shape and swaps out a single term.

Nobody decided this. This was computed.

That sentence carries more force than the one it echoes, and the extra force comes from verifiability. Gold's weight has to be taken by someone, and whoever takes it might cheat. A hash needs no weighing at all — anyone, on any machine, can recompute it and get exactly the same number, and check it in a matter of seconds. The coin-checkers who appeared back in Essay 3 are, for the first time, genuinely unnecessary.

And computed reaches further than the weight of gold ever did. Gold still has to be mined, assayed, stored in a vault, shipped by boat between two countries, and every one of those steps needs somebody to handle it. A hash needs none of that. It can be recomputed independently, by any machine, anywhere, and it will come out exactly the same.

It did not return to metal. It abstracted the cost itself into hash computation, dedicated hardware, the price of electricity, and a periodically adjusted difficulty.

4. The First Line of the Ledger

On the third of January, 2009, the first block was written.

Embedded in it was that day's headline from The Times of London: "Chancellor on brink of second bailout for banks."

That headline did two things at once. It served as a timestamp, proving the block could not have been produced before that date. And it was a gesture, pinning the whole enterprise's origin to the exact moment of the global financial crisis and the bank bailouts that followed it.

The fifty coins awarded for that block were later shown to be unspendable.

Set these two facts side by side and something appears that has no parallel anywhere else in this series.

In each of the previous twenty-one essays, the first line of every ledger was a transaction. A picul of barley, an ox, a debt owed, a contract, somebody's name followed by a number.

The first line of this ledger is not a transaction.

It is a sentence.

And the fifty coins sitting beside that sentence can never be spent.

Those fifty coins are worth a second look. They sit on the ledger, and anyone can confirm they exist; and yet they cannot leave, cannot enter into any transaction at all. A ledger whose entire reason for being is circulation has, as its very first entry, something that will never circulate. This is not commonly read as a technical accident — the later consensus is that it was deliberate. Whoever opened this account left the first entry as a mark that could never be moved.

A ledger announces, on its opening page, exactly what it was built to oppose — and then leaves that opening entry permanently in place, taking no part in circulation.

Here, for the first time in the series, the construct openly admits that it is an anti-construct.

And that admission is already a foreshadowing of what would happen to it later. A thing that is merely a tool can be picked up by anyone, and nobody feels they are taking a side by using it. A thing that announces, on day one, exactly what it stands against acquires, from that same day, enemies, believers, and a posture it will have to keep living up to.

How value first acquired a number is equally worth examining.

In October 2009, an early website published a dollar exchange rate using an electricity-cost formula: the average residential electricity price in the United States, a machine's annual power draw, and how many coins that machine had produced over the preceding thirty days, combined to derive a selling price.

The first published rate was roughly one dollar to 1,309.03 coins. By the twenty-eighth of December, 2009, the figure on that same page had moved to one dollar to 1,578.77 coins.

Neither number matters in itself. What matters is how they were arrived at.

Value did not first come from goodwill, did not first come from taxation, did not first come from a state's decree. It was first tied to a production cost that could be checked, kilowatt-hour by kilowatt-hour.

The line of thought from Essay 11, which tied value to labor, gets a technical version here — and a far more precise one than it ever had before: socially necessary labor time is a quantity that can only be approximated statistically, while how many kilowatt-hours a machine burned in thirty days is written plainly on its meter.

That anchor later came completely loose. Price drifted away from electricity cost and never went back.

How a scale's first graduations get set often has nothing to do with what it goes on to measure.

This has come up before, if never quite this clearly. In Essay 3, a coin's weight first corresponded to a real quantity of metal, and later corresponded to the issuer's credit. In Essay 17, the common denominator first corresponded to the weight of gold, and later corresponded to whether a handful of countries were still willing to honor it. A scale, when it is first set up, always leans against something visible — and once it is standing steadily, that visible thing is very often quietly taken away.

5. At Best, a Skeptical Reception

The timeline is worth walking through in full, because it compresses something usually told as legend back down into the concrete, unglamorous process by which it actually unfolded.

On the thirty-first of October, 2008, the proposal was posted to a cryptography mailing list.

On the third of January, 2009, the first block. On the eighth of January, the first version of the software was released, with an announcement declaring it "completely decentralized, with no server or central authority."

On the twelfth of January, the first transfer on the chain. Finney later recalled that he was the first person besides Satoshi Nakamoto to run the software, that his own mining had reached block numbers in the seventies, and that he received a test transfer of ten coins sent to him by Satoshi Nakamoto.

On the eleventh of February came that statement about complete decentralization and cryptographic proof.

On the fifth of October, 2009, the first dollar quote.

On the twenty-second of May, 2010, someone traded ten thousand coins for two pizzas, worth around forty-one dollars at the time by that valuation. This is usually treated as the first well-known transaction for a real-world good.

On the seventeenth of July, 2010, a trading platform went live. The whole enterprise moved out of the mailing-list-and-peer-to-peer stage and into the exchange stage.

On the eleventh of December, 2010, when it looked as though WikiLeaks might adopt the currency, Satoshi Nakamoto expressed alarm, writing a line that has been quoted often since: "It would have been nice to get this attention in any other context. WikiLeaks has kicked the hornets' nest, and the swarm is headed towards us."

On the twenty-third of April, 2011, he wrote to one developer to say that he had moved on to other things, and that it was now in good hands with the rest of them.

As an exit, that line is rare. In each of the previous twenty-one essays, whoever had set up a scale tended to stay: staying to explain it, staying to patch it, staying to answer when others raised doubts, or staying to divide up the proceeds. This time, the person who wrote the proposal walked away just as it was beginning to find its feet, and never again came back to say another word.

Two details in this timeline matter more than the rest.

The first is Finney's own recollection. He said that the reaction on the mailing list at the end of 2008 amounted, at best, to a skeptical reception.

That is: this was not a proposal that conquered its peers on first contact. Among a group of cryptography veterans who had seen more than their share of grand schemes, it was met at first with a cold shoulder.

The second detail is price. The early price was not something a broad market consensus simply discovered all at once. It was groped toward, gradually, by a handful of participants, through electricity-cost arithmetic, barter on forums, and a crude trading platform.

Money becoming a common measure is not something that happens by itself. It is something that barely manages to stand, after repeated trial calculations, repeated arguments, and repeated bids.

This point turns out to be useful for the series as a whole.

Every scale erected in the previous twenty-one essays probably went through an equally undignified stretch at the moment of its founding. It is only that those episodes lie too far back, and too little of them was recorded, so that later readers see the scale only after it has already found its footing, and easily assume it must have looked that way from the start.

This time is different. This time the entire process is on the record: the day someone first asked what the thing was worth, who first traded it for something real, how the first quoted price was actually calculated, and how many people simply did not think much of it at the outset.

The birth of a scale is rarely preserved this completely.

And nearly every part of the record that survives dismantles an illusion the previous twenty-one essays make easy to fall into: the idea that a scale gets adopted because it is correct. What can be seen here is something else entirely. It was met first with cold indifference, then tried out by a small number of people, then assigned an unreliable price, then traded for two pizzas, and only after all of that did it slowly begin to acquire anyone else.

The line about the hornets' nest deserves to be set apart on its own.

Here was a system claiming to be completely decentralized, dependent on no one — and its own creator was worried about who might come looking for it.

That worry shows he understood perfectly well that the thing did not actually stand outside society. For it to survive, it still depended on how the parts of the world he could not bind with code would choose to react.

This layer was there from day one. Something that needs no one's permission to run at all remains, even so, subject to whether particular countries would allow exchanges to open, whether it could connect to banks, whether the machines needed to run it could be bought, and how high electricity prices happened to be — matters entirely outside its own control. Code can dictate everything that happens on the chain. It cannot dictate who holds the plug.

6. Where the Trust Went

The strongest claim made on its behalf is to understand it as the first relatively successful case of something specific: strangers, with no assumed identity and no trusted third party standing between them, nonetheless managing to transfer value to one another.

The relevant academic surveys describe it the same way. In that sense, it genuinely did fill a gap that had been sitting empty.

This cannot be discounted, because none of the ledgers in the previous twenty-one essays ever managed it. Every one of them required knowing who you were first, or required some institution everyone already recognized to stand in the middle.

The weight of this only becomes clear against the specific situations described in earlier essays. The people in Essay 13 who could produce no credentials, the people in Essay 16 who were not on the list, the people in Essay 21 who were invisible to any credit system — each was shut out by a different mechanism, but the mechanisms shared one thing: there was always a door, and something at that door had to verify who you were before you could pass. This time, that door is removed. It does not ask who you are. It only checks whether the signature is valid.

A different reading insists that this trustlessness always had a boundary.

One line of scholarship has called it a mechanized imagination of money, an attempt to lift currency bodily out of social life. Other researchers, observing the communities that actually use it, have found that their members do not really live in a zero-trust world; rather, they have rebuilt trust around a shared conviction that the technology is more trustworthy than people are.

In other words, so-called trustlessness, in practice, is very often not the disappearance of trust at all.

It is a change in what trust is placed in.

Away from bankers, states, and companies, and toward the protocol, the codebase, the distribution of the nodes, the incentives facing miners, and the shared convictions that form around these technical objects.

It is only fair to note that a change is still a change. Trusting a piece of code that anyone can inspect is not the same thing as trusting an institution whose books stay closed: the code can be read by anybody, while no outsider can walk into an institution's back office. After the shift, more of the system genuinely became checkable. But checkable is not the same as checked — among the people who actually use it, those capable of reading that code remain a small minority.

The economic critique pushes the question a level further still.

One central-bank research paper put the point sharply: cryptocurrency's embalming of trust comes at the cost of convenience. If people genuinely lived in a world with zero institutional trust, this design might well win out; but in reality, people are generally willing to trust payment institutions and central banks, and so the existing system remains the more convenient one.

Another researcher attacked the design from the angle of its cost structure, concluding that sustaining this kind of anonymous, decentralized trust is expensive, and that the expense rises linearly as the stakes riding on the system grow larger. Staying trustworthy at greater scale requires paying a correspondingly higher security bill.

This point matters enormously for the framework, so its implication is worth spelling out plainly.

The portion of trust that got cut out did not become zero.

It became an electricity bill.

A Cambridge index and one of the United States' own energy-statistics agencies have both noted that mining's electricity demand has grown large enough to enter national statistics and policy debate in its own right.

Which is to say, trustlessness itself carries a price, and that price is recorded, in plain sight, on a different ledger entirely.

This is also one of the design's least remarked-upon virtues: its honesty. The old ledgers hid their costs elsewhere — a promise of redemption goes unrecorded, the possibility of a bailout goes unrecorded, what a country's credibility is actually worth goes unrecorded, and all of it gets settled, once, only on the day the whole thing fails. This time the cost runs on the meter every single day, visible to anyone who cares to look. It is more expensive. And it does not default.

The old ledgers needed somebody to honor them; honoring costs nothing, it is merely unreliable. This one needs nobody to honor it — at the price of a fresh batch of machines burning electricity every ten minutes.

Essay 14's scale moved the backstop onto metal and a handful of central banks. This one moved it onto electricity and computing power.

And whatever this scale failed to absorb kept surfacing anyway, outside its boundaries.

How long a confirmation takes. When fees are about to rise. What to do when the chain is congested. Who to call when a password is forgotten. How fiat money gets in, and how it gets back out. Which handful of companies control the mining hardware supply. How mining pools coordinate with one another.

None of this is written into the protocol.

Set that string of questions beside the chain of seven links from Essay 18 and the shape is identical. There, a single mortgage was broken into seven segments, and every joint between them still needed a little trust to get across. Here, a transfer is split into an on-protocol half and an off-protocol half, and that second half has just as many joints — seven or eight of them. The only difference is why the split happened: there, the chain was cut apart to sell the risk off; here, it is cut apart because the protocol only governs the part it is actually capable of governing.

The protocol governs the order of things on the chain. And before a person can use it, they must first pass through this dozen or so other things, and every single one of them asks them to trust something.

7. Who Gets to Amend the Rules

The clearest channel by which trust flows back in is the exchange, and this particular channel has left behind an unusually complete specimen.

The protocol itself may not require anyone to trust a bank to clear a payment. But the moment someone wants to convert fiat currency into coin, convert coin back into fiat, or simply finds the trouble of guarding their own private key too much to bear, they fall straight into the hands of custodial platforms, payment processors, and wallet providers.

The exchange that collapsed in 2014 is exactly that specimen. For a time it had become the public face of the whole currency, the main gateway through which people watched prices, made trades, and moved money in and out.

In its announcement of the twenty-eighth of February, 2014, the company admitted that roughly seven hundred and fifty thousand customer coins and about one hundred thousand of its own coins had disappeared. It said they had most likely been stolen, and its bank accounts showed a further discrepancy of around 2.8 billion yen.

By the twentieth of March, the company said it had located roughly two hundred thousand coins in an old wallet, which brought its estimate of the actual shortfall down to around six hundred and fifty thousand.

Later investigation traced the theft back through a pattern of repeated intrusions running from 2011 to 2014.

What happened here was not a double-spending crisis at the level of the protocol.

It was users handing an asset billed as requiring no trust back over to an intermediary that had to be trusted completely.

And so everything came back: years of waiting, frozen funds, lawsuits over compensation, and the verification of identity.

One wire service put it plainly in its retrospective: the exchange's collapse exposed how that community's laissez-faire, anti-regulatory ideal was bound to collide with the stable operation, compliance, and customer protection that financial services actually require.

And this was not a one-off deviation. It was a structural pattern of return.

The Financial Stability Board, discussing the risks of decentralized finance, has pointed out that so-called decentralized finance is thoroughly interconnected with centralized trading and lending platforms, and that many participants pass through exactly these platforms to move back and forth between the on-chain system and the world of fiat currency. It has also specifically noted that governance arrangements in this space are frequently unclear, opaque, untested, or open to manipulation, and that the actual degree of decentralization varies enormously from one case to the next.

The second channel of return runs deeper, and it sits at the very center of this essay.

One researcher has drawn a distinction between governance by infrastructure and governance of infrastructure.

The former is the protocol automatically enforcing its own rules. This part has worked remarkably well.

The latter is an entirely different matter: how the protocol itself gets changed, who fixes its mistakes, whose side gets taken when the chain forks, and whether the nodes ought to upgrade.

None of these questions can be made to disappear by the protocol on its own.

Another researcher has gone further, arguing that blockchain governance, in practice, still depends on human judgment, personal influence, and informal arrangements — and she has even reached for a term describing charismatic personal rule to characterize one variety of authority found within it.

The later disputes over block size, the activation of Segregated Witness, and the soft fork initiated by users all demonstrate that users, miners, core developers, and companies were never actually flattened by cryptography into perfectly equal particles.

So-called consensus is very often a result jointly produced by technical parameters, economic incentives, rhetorical power, and the mobilization of public opinion.

This is the point at which the line owed to this series can finally be repaid.

A construct can specify everything except who gets to change the specifications.

This did not come up in the previous twenty-one essays, for a simple reason: none of the earlier constructs ever intended to fix themselves permanently in place. Each of them left a position open for revision, and someone usually sat in that position — a person, a parliament, a central bank, a commissioner, a ratings committee.

This is the first time a construct has tried to eliminate that position too.

And it could not be eliminated. Rules can execute themselves automatically. Amending them cannot.

This can be read against Essay 17. The text of that international agreement carries a clause almost never invoked, and the mere existence of that clause is the construct leaving, in its own text, a seat open for amendment. Every earlier construct left such a seat, and usually specified who was entitled to occupy it. This time, no seat was left at all.

The third channel of return is the founder's own reputation.

There is something unusual about this currency: its founder's disappearance, in a sense, weakened the odds of any later intervention, and it also left many of its believers with a mythic space in which there was no emperor at all.

But the history of cryptocurrency as a whole does not all read this way.

In 2016, an autonomous investment organization built on a different chain had roughly sixty million dollars in tokens drained away by someone, and the community responded by choosing to hard-fork, rolling back the effects of that event — leaving, from that point on, two separate chains.

This shows that the maxim code is law can, in the face of a large enough loss, be overturned by the politics of a community.

Later still, in 2022, a stablecoin and its paired token collapsed, and the attention of regulators and investigative journalists landed directly on how its founder and company had built trust through repeated public statements, and how, once the peg broke, that same trust produced enormous losses.

A still more extreme case stands almost as the reverse of this entire tradition: the founder of one centralized exchange, having gathered the trust of enormous numbers of people through personal reputation and brand storytelling, was ultimately found to have misappropriated, defrauded, and illegally commingled customer funds.

This forms an odd echo of that old prophecy from decades earlier.

The anonymous system did not abolish reputation. It moved reputation into a more dangerous position than before.

Because in a space lacking conventional audits, deposit insurance, clear corporate governance, and mature remedies, founders, core developers, exchange owners, the mythology of audits, and the culture of the community all end up carrying far more meaning than they can safely bear.

Reputation is no longer a mere accessory. It has become the bridge that reconnects anonymous currency back to the social world.

And Essay 21 already said this: reputation, too, wants to close its own books, and it is no more generous by nature than money is.

One thing can be added here: the fewer formal institutions surround a thing, the more weight falls onto its reputation — and the greater that weight, the more it crushes underneath it when something finally goes wrong.

8. Unfixable, Until It Wasn't

The argument over this whole stretch of history has never come together, and the disagreement is not a matter of taste.

The first fault line runs between liberating decentralization and speculative new intermediation. Its defenders emphasize that, for the first time, strangers moved value between each other with no bank, no clearinghouse, and no presumed identity — a technical answer to financial crisis, capital controls, payment censorship, and the debasement of fiat currency. Its critics point out that in practice the great bulk of trading volume has settled, for years, into exchanges and speculative activity; some researchers have written directly that today's largest concentrations of activity run precisely through those same trusted financial intermediaries, meaning the supposed benefits of anonymity and decentralized trust were never really used at all.

The second fault line asks whether trustlessness is an institutional fact or a piece of marketing language. The original documents undeniably put the replacement of trust with cryptographic proof at the very center of the design; other research holds that this framing overlooks the social trust that forms around code, community, and shared belief. The disagreement is not over whether some of the old intermediaries were eliminated. It is over whether whatever dependency remains, once those intermediaries are gone, still deserves to be called trust.

The third fault line asks whether technical governance can substitute for political governance. The optimistic side holds that protocol rules, open-source code, the choices nodes make, and market competition can add up to a self-organizing order strong enough to stand on its own. The skeptical side points out that any public chain's actual operation always ends up depending on a small number of core developers, mining pools, infrastructure providers, and opinion leaders — and that a fork is not a bug, but a structural outcome.

The fourth fault line asks whether the thing more closely resembles money or a speculative asset. Its defenders can point to the history running from a ten-coin test transfer to a ten-thousand-coin pizza, evidence that it really was tried out, at least once, as a means of payment. Its critics point out that the social practice which formed around it afterward has more often centered on hoarding, trading, leverage, and price narrative. One researcher offered a particularly sharp judgment: if it fully succeeds by its own ideological standards, it will, by that very success, fail at the ordinary functions of money.

No verdict will be rendered here.

The reason for withholding one is unusually clear in this case: the four disputes are not actually asking the same question. The first asks where actual use has landed. The second asks how to define a word. The third asks about the outer limits of what institutional design can achieve. The fourth asks about the nature of the thing itself. Mash them together into a single question — does cryptocurrency work or not — and no answer comes out the other end.

Beyond these four disputes, though, there is one further thing that can be said with more confidence, and it picks up directly where the previous essay left off.

Essay 21 said as much: every scoring system, eventually, grows a mechanism called repair, and the word repair is itself a confession — it admits that a person can change, that a record is only a compression of the past, and that a gap opens up between the two.

This system's design runs in exactly the opposite direction.

It takes pride in being unfixable.

Once a transaction is written into that chain, it cannot be reversed. Lose the private key and the coin is simply gone; no one can ever retrieve it. There is no window on the chain for an appeal, no customer service line, nobody who can be persuaded, and no one with the authority to alter a single line already written.

This is not a defect. It is the entire source of the system's security.

A ledger can be freed from needing anyone to honor it only on one condition: that no one is able to move it.

If it can be moved, somebody has to have the authority to move it. And if somebody has that authority, somebody has to be trusted.

So unfixability and trustlessness are two faces of one single thing. You cannot keep one and discard the other.

And in 2016, when the loss finally grew large enough, the door was broken open anyway.

The community talked it over, voted, and hard-forked, rolling back the transfer of those stolen tokens. The rollback was not carried out automatically by the protocol. It was decided by a group of people, in a meeting.

What was left afterward were two chains: one that accepted the rollback, and one that insisted the original history could not be altered.

Both chains are still running today.

Which is to say, that argument did not produce an answer. It produced a fork. Some people chose a world that could be repaired; others chose a world that could not; and neither side managed to convince the other.

The fork itself says more than either side's victory ever could. It means that unfixability is not a position that can be argued into place — it is a choice. And a choice requires someone to make it, which brings the whole question back to where it started. The construct went all the way around a full circle trying to usher people out of the ledger, and at the single moment that mattered most, the people it had ushered out were ushered straight back in — brought back in for the specific purpose of deciding.

What Satoshi Nakamoto set out to do can be stated in a single sentence: move money from one person's hand into another's without requiring that anyone be trusted.

He accomplished a great deal of it. That chain still advances one block every ten minutes, to this day; no one has stopped it, and no one has altered a single line already written into it.

But to use it, a person still has to convert fiat money into coin somewhere, still has to keep a private key somewhere, still has to trust that whoever wrote the wallet software left no back door, still has to trust, when the chain is congested, that the fees will come back down tomorrow, and still has to listen, whenever the system itself needs to change, to what a handful of people say about how it should change.

None of that is written into the protocol. The protocol governs the books. It does not govern how the people who use the books actually get to them.

A ledger can be built so that it needs no one to honor it.

It cannot be built so that it needs no one to use it.

And as long as somebody is using it, somebody will make a mistake, somebody will be robbed, somebody will lose a string of characters in the middle of the night, and somebody, after some future crash, will demand that things be put back the way they were. On that day, somebody will have to step forward and decide whether to put it back or not.

Each of the previous twenty-one ledgers opened, within itself, a door called repair, and specified exactly how long the process would take, what had to be paid, and what standard had to be met before it counted as finished.

This one never opened that door. It wrote unfixability into itself as the entire source of its security.

And the door got broken open anyway, once.

It was not the protocol that broke it open. It was a group of people, in a meeting.

The ledger has not yet balanced. It is still being kept.