
Published on Szabo’s Unenumerated blog on May 28, 2011, this is the first long-form public statement Szabo wrote about Bitcoin after its launch. The timing is significant — it appeared roughly a month after Satoshi’s final private email to Gavin Andresen and during the year Bitcoin first reached parity with the US dollar. The post operates on two levels: a retrospective on why the digital-cash idea took thirteen years to ship between bit gold (1998) and Bitcoin (2009), and an architectural comparison between bit gold and Bitcoin written by the designer of a precursor system.
The “why so long” argument. Szabo’s first claim is that the difficulty was sociological, not technical:
Quote from: Nick Szabo on May 28, 2011While the security technology is very far from trivial, the “why” was by far the biggest stumbling block — nearly everybody who heard the general idea thought it was a very bad idea.
In Szabo’s own account, the resistance came from economic intuition: he recalls being told, again and again, that money had to be either commodity-backed (the metallic tradition) or sovereign-issued (the chartalist tradition), so a scarce digital token belonging to neither category was dismissed by nearly everyone who heard the idea. Szabo connects this to a misreading of Menger and Mises that he says he encountered repeatedly when discussing bit gold in the late 1990s.
The libtech mailing list disclosure. The post contains the first public confirmation that the late-1990s digital-cash work happened on a specific private channel:
Quote from: Nick Szabo on May 28, 2011Only a few people had read of the bit gold ideas, which although I came up with them in 1998 (at the same time and on the same private mailing list where Dai was coming up with b-money — it’s a long story) were mostly not described in public until 2005, although various pieces of it I described earlier, for example the crucial Byzantine-replicated chain-of-signed-transactions part of it which I generalized into what I call secure property titles.
This identifies “libtech” as the venue where Wei Dai’s b-money and Szabo’s bit gold were developed in parallel during 1998. The parallel development on a closed list — rather than independent inventions in isolation — is a structural fact that recurs in later identification analyses (the Wei-Dai-Satoshi hypothesis and the Szabo-Satoshi hypothesis both build on it).
The bit gold vs. Bitcoin comparison. The architectural section identifies two specific improvements Bitcoin made over bit gold:
Quote from: Nick Szabo on May 28, 2011Nakamoto improved a significant security shortcoming that my design had, namely by requiring a proof-of-work to be a node in the Byzantine-resilient peer-to-peer system to lessen the threat of an untrustworthy party controlling the majority of nodes and thus corrupting a number of important security features.
Instead of my automated market to account for the fact that the difficulty of puzzles can often radically change based on hardware improvements and cryptographic breakthroughs (i.e. discovering algorithms that can solve proofs-of-work faster), and the unpredictability of demand, Nakamoto designed a Byzantine-agreed algorithm adjusting the difficulty of puzzles. I can’t decide whether this aspect of Bitcoin is more feature or more bug, but it does make it simpler.
Szabo’s own vocabulary here — “Byzantine-resilient peer-to-peer system,” “Byzantine-agreed algorithm” — echoes the exact framing Satoshi adopted answering James A. Donald on the cryptography mailing list two and a half years earlier; the archive’s account of that exchange traces how Satoshi turned Donald’s classical label into the King’s wi-fi analogy this same proof-of-work chain answers.
The first improvement — using proof-of-work as the gate to network participation rather than as a separate coin-generation function — is the structural innovation that makes Bitcoin’s security model work. The second — the difficulty-adjustment algorithm replacing an automated market — Szabo frames as a trade-off rather than an unambiguous improvement: the algorithm makes the system simpler at the cost of removing market-based price discovery for proof-of-work costs. This concession is one entry in the archive’s wider record of what others said about Satoshi — the rare case of a conceptual precursor’s own designer weighing in on the design that succeeded his.
The improvement Szabo names here, requiring the work in order to be a node at all, is the property the proof-of-stake designs later replaced with a deposit; the proof-of-work versus proof-of-stake comparison traces that line from bit gold’s designer to the Merge.
Tone and identification debate. The post is written in Szabo’s characteristic register — historical-economic prose interleaved with the engineering points, dismissive asides about “common arguments coming ironically from libertarians” — and reads as the work of someone with substantial intellectual investment in the design space. This register is part of why the stylometric analyses of 2013 and the Popper NYT investigation of 2015 returned Szabo as a leading identification candidate. Szabo has denied being Satoshi; the post stops short of confirming or denying anything beyond his role as the original bit gold designer.
Position in the origins corpus. Alongside Wei Dai’s b-money announcement, Adam Back’s hashcash announcement, and Hal Finney’s RPOW announcement, this 2011 retrospective fills in the design genealogy from the inside — written by the precursor designer who is also a candidate for the identity of the creator of the system that actually shipped. Together these four documents map the design genealogy behind Bitcoin, and the Bitcoin design lineage entry traces the whitepaper’s reference list in full: only Hashcash and b-money are cited; bit gold and RPOW sit just outside its references.














