Bitcoin Institute

Dan Kaminsky's Bitcoin security analysis

A silhouetted figure studies a glowing code panel through a magnifying glass while nine numbered red arrows converge on it from every side, one intercepted by a stamped seal.

From “The Crypto-Currency” by Joshua Davis, The New Yorker, October 10, 2011:

Earlier this year, Dan Kaminsky, a leading Internet-security researcher, investigated the currency and was sure he would find major weaknesses.

“When I first looked at the code, I was sure I was going to be able to break it,” Kaminsky said.

“The way the whole thing was formatted was insane. Only the most paranoid, painstaking coder in the world could avoid making mistakes.”

He quickly identified nine ways to compromise the system and scoured Nakamoto’s code for an insertion point for his first attack. But when he found the right spot, there was a message waiting for him. “Attack Removed,” it said. The same thing happened over and over, infuriating Kaminsky.

“I came up with beautiful bugs,” he said. “But every time I went after the code there was a line that addressed the problem.”

“He’s a world-class programmer, with a deep understanding of the C++ programming language,” Kaminsky said of Bitcoin’s creator. “He understands economics, cryptography, and peer-to-peer networking.”

“Either there’s a team of people who worked on this,” he said, “or this guy is a genius.”

Kaminsky also presented his Bitcoin analysis at Black Hat USA 2011 in Las Vegas, where he separately revealed an ASCII-art memorial to Len Sassaman that he had embedded in the Bitcoin blockchain following Sassaman’s death four weeks earlier.

Six weeks later, Wired’s “The Rise and Fall of Bitcoin” returned to Kaminsky for a second guess at authorship, this time more specific: “I suspect Satoshi is a small team at a financial institution. I just get that feeling. He’s a quant who may have worked with some of his friends.”

In 2013, he told CoinDesk that “the core technology actually works, and has continued to work, to a degree not everyone predicted.” The New Yorker put the code Nakamoto released in January 2009 at “thirty-one thousand lines of code.” When Forensicxs published a line-by-line walkthrough of the Bitcoin v0.1 source in 2024, it counted 31,794 lines — a similar figure, but one that includes the GUI project file and makefiles: this archive’s own analysis of Satoshi’s source puts v0.1.0 at roughly 19,901 lines, growing to 31,909 lines only by v0.3.19 in December 2010.

Kaminsky was famous for discovering a critical DNS vulnerability in 2008. He passed away on April 23, 2021.