Corrections
What we got wrong, and what we changed.
The manifesto promises that when we get something wrong, we publish the correction in public. This is that list.
It covers factual errors in pages that were already live: wrong numbers, dates, names and history, sources that never existed, and entries we retired because they described the wrong thing. Typo fixes and rewording are not listed. Every change is also in the content repo's git history, linked from each entry.
Spot something wrong? Open an issue on GitHub or email hello@learnbitcoin.com. If you raised it in public, we credit you by handle.
207 corrections so far, 5 credited to readers who caught them in public.
October 2026
-
Node Autoban
Was: The entry described Bitcoin Core as still scoring misbehaving peers and banning their IP addresses for 24 hours at 100 points. It said consensus-invalid transactions earned a small, additive score, listed repeated or nonexistent data requests as offenses, said bans can be extended if abuse persists, and said the system makes denial-of-service attacks expensive.
Now: Automatic bans ended with 0.20.1 in 2020, when discouragement replaced them, and 28.0 (2024) dropped the score, so one offense means disconnection and discouragement. Under the old system a consensus-invalid transaction cost the full 100 points, and since 30.0 it is not punished at all. Bans are set only by hand, and Bitcoin Core's code says neither bans nor discouragement protect against denial of service.
-
Peer Bookmark
Was: The entry told readers to combine -addnode or -connect with the -whitelist setting to exempt those peers from rate limits and ban scoring, and said this pairing avoids default policy throttles.
Now: By default -whitelist applies only to incoming connections, so it does nothing for peers added with -addnode or -connect unless its out flag is set. Those peers are already never disconnected or discouraged for misbehavior, and current Bitcoin Core has no ban score.
-
Peer Management
Was: The entry said a misbehaving peer's score rises until it triggers disconnection and a temporary ban, and that autoban kicks in for repeated invalid data or spam. It also said Bitcoin Core picks outbound peers from different ASNs using a bundled asmap file, and from different geographies.
Now: There is no score or automatic ban: a peer that breaks certain protocol rules is disconnected after one offense and its address discouraged, and bans are set only by hand. Outbound peers are limited to one per address group (/16 for IPv4) and spread across reachable networks. Grouping by network operator needs -asmap, which stays off by default even though 31.0 embeds the map, and nothing selects peers by geography.
-
Bitcoin Client
Was: The entry described Bitcoin Knots as consensus-compatible with Bitcoin Core.
Now: Knots releases up to May 8, 2026 do not include BIP-110, a temporary limit on data in transactions. Releases from May 9, 2026 on enforce it, and nodes running them left Bitcoin's main chain on August 8, 2026. In September 2026 Knots shipped a hard fork that moved that chain to a BLAKE2b proof of work.
-
Bitcoin Knots
Was: The entry said Bitcoin Knots is consensus-compatible with Bitcoin Core, so a Knots node sees the same chain and accepts the same blocks, and that the two differ only in relay policy.
Now: Knots releases up to 29.3.knots20260507 (May 8, 2026, UTC) follow the same chain as Core. Releases from 29.3.knots20260508 (May 9, 2026, UTC) on enforce BIP-110, a temporary limit on data in transactions, and nodes running them rejected the main chain's blocks from August 8, 2026 and split off. Knots 29.4.1, released September 2, 2026, is a hard fork that gives that chain a BLAKE2b proof of work.
-
Decentralization
Was: The chapter called Bitcoin Knots an independent implementation of Bitcoin, alongside btcd and Libbitcoin, and its metrics table counted Knots among "4+" independent clients.
Now: Knots began as a modified version of Bitcoin Core, merging in Core's code for each release. Its releases from May 9, 2026 on enforce BIP-110, a temporary limit on data in transactions, and nodes running them left Bitcoin's main chain on August 8, 2026. A September 2026 release moved that chain to a different proof of work. btcd and Libbitcoin are the separately written implementations.
-
Fork Watcher
Was: The entry said forkmonitor.info runs Bitcoin Knots and libbitcoin nodes alongside Bitcoin Core and btcd, and publishes alerts to RSS, Twitter and mailing-list feeds.
Now: As of October 2026 the site runs several versions of Bitcoin Core plus btcd and bcoin, compares the chains they follow, and keeps a list of stale blocks. It names Localhost Research as its sponsor.
-
Full Node
Was: The entry said full nodes almost always run Bitcoin Core and offered Bitcoin Knots as an alternative, without saying that newer Knots releases no longer follow Bitcoin's main chain.
Now: Bitcoin Core runs on most nodes, about 87% in one October 2026 estimate. Knots releases from May 9, 2026 on enforce BIP-110, a temporary limit on data in transactions, and nodes running them left Bitcoin's main chain on August 8, 2026.
-
Node Operator
Was: The entry listed Bitcoin Knots alongside Bitcoin Core and btcd as software you can download to run a Bitcoin full node.
Now: Only Knots releases made before May 9, 2026 run on Bitcoin's main chain. Later releases enforce BIP-110, a temporary limit on data in transactions, and nodes running them left the main chain on August 8, 2026.
-
Resource Exhaustion Attack
Was: The entry said the discard threshold protects nodes from mempool spam by evicting low-fee transactions. It also said Bitcoin Core keeps a ban score and bans peers automatically once their misbehavior adds up, said SegWit's BIP 143 fixed slow quadratic signature hashing outright, and listed limits on chains of unconfirmed transactions as a protocol rule.
Now: Each node's mempool has a size cap, 300 MB by default in Bitcoin Core. When it is full, the node evicts the lowest-fee-rate transactions and raises its minimum fee. Bitcoin Core keeps no ban score: a peer that breaks certain rules is disconnected and its address discouraged, and bans are set only by hand. BIP 143's faster hashing covers only SegWit inputs, and chain limits are relay policy, not consensus.
-
Autopilot (Lightning)
Was: The entry said LND's autopilot tries to rebalance or close channels that are not working out.
Now: LND's autopilot, which is off by default, only opens channels. It works within a budget, by default up to 60% of the wallet's funds across at most five channels, and its hook for closing a channel does nothing.
-
BIP 66
Was: The entry said BIP 66 eliminated signature malleability. It also called Mt. Gox the most famous victim of malleability and said malleability was part of the story of the exchange's 850,000 BTC loss.
Now: BIP 66 left one signature tweak open: flipping a signature's S value gives another valid signature and a new txid, which Bitcoin Core blocks only as relay policy. Mt. Gox blamed malleability in 2014, but a study of more than a year of network data found at most about 386 BTC could have been taken that way.
-
Block Time
Was: The entry contrasted Bitcoin's 10-minute target with "1 minute like Litecoin" and "15 seconds like Ethereum".
Now: Litecoin targets 2.5 minutes per block. Ethereum has produced blocks in 12-second slots since the Merge on September 15, 2022, and still did as of October 2026.
-
Discard Threshold
Was: The entry defined the discard threshold as the minimum fee rate a transaction must pay to stay in a Bitcoin Core node's mempool when memory runs short.
Now: In Bitcoin Core, the discard threshold is the smallest change output the wallet will create. Smaller change is added to the fee instead. The wallet works it out from its -discardfee rate, 10 sat/vB by default. The mempool's minimum fee is a separate rule.
-
Hal Finney's Running Bitcoin
Was: The entry said Hal Finney corresponded with Satoshi by email about bugs and improvements through much of 2009.
Now: Hal's own 2013 account says the emails covered the first few days after he started running Bitcoin in January 2009, mostly him reporting bugs that Satoshi then fixed.
-
Lightning Channel
Was: The entry said a channel's capacity is fixed at open time and that rebalancing through swap services like Loop In/Out, or splicing, is required for more.
Now: The funding transaction sets a channel's capacity, split between the two sides. Swap services like Loop In/Out shift that split, refilling or emptying one side, but the total stays the same. Only splicing, which replaces the funding transaction, changes a channel's capacity.
-
Liquid Federation
Was: The entry said the federation had roughly 65 members, that each member ran a functionary node, and that a malicious majority of the federation could steal the pegged BTC.
Now: The federation had 87 member companies as of May 2026, but only 15 functionaries, each run by one member, sign blocks and hold the 15 multisig keys to the pegged BTC. Each block and each peg-out needs 11 of the 15 signatures, so in normal operation signing the pegged BTC away would take 11 functionaries colluding or having their keys stolen. A software bug can also drain the peg, as the September 2026 exploit showed.
-
Liquid Network
Was: The entry described the federation as a consortium of around 65 entities and said a majority of federation members could steal the pegged BTC by signing a malicious peg-out. It also named PAXG, a gold token issued on Ethereum, among the assets issued on Liquid.
Now: The federation had 87 member companies as of May 2026. Fifteen functionaries, each run by one member, take turns proposing blocks, and each block needs 11 of their 15 signatures. Signing the pegged BTC away would take 11 of those 15 functionaries colluding or having their keys stolen, and a software bug can also drain the peg, as the September 2026 exploit showed. The asset examples are now Tether's USDT, the Brazilian-real stablecoin DePix and tokenized securities.
-
Merkle Block
Was: The entry said a merkle block message contains the transactions in the block that match the wallet's Bloom filter.
Now: A merkle block carries the block header and a partial Merkle tree holding the matching transactions' hashes. The full node sends the matching transactions themselves right after it, as separate tx messages.
-
Mt. Gox
Was: The entry said Mark Karpeles was convicted in 2019 for manipulating data rather than for stealing the coins, and that he was acquitted of stealing them.
Now: A Tokyo court convicted Karpeles in 2019 of falsifying Mt. Gox's records to inflate its holdings, and acquitted him of the more serious charges, including a charge that he embezzled about $3 million of customers' money.
-
Peg-Guard
Was: The entry said Liquid's federation members refuse to sign a peg-out if a sidechain bug looks like it is draining the reserve, and that an individual member can refuse to sign and stop a peg-out.
Now: Liquid has no separate check at peg-out time that the reserve still matches the L-BTC in circulation. The functionaries rely on the sidechain's own validation, and a peg-out needs 11 of 15 functionary signatures, so one refusal cannot block it. In September 2026 a bug let about 3,996 BTC be paid out against unbacked L-BTC.
-
Peg-out
Was: The entry said that in an SPV-validated peg, sidechain validators approve a peg-out by checking SPV proofs of mainnet activity, and called the design rarely deployed at scale.
Now: In the SPV peg proposed in the 2014 sidechains paper, Bitcoin itself releases the locked coins when shown an SPV proof that they were sent back on the sidechain. Bitcoin's script cannot check such proofs without a soft fork, so the same paper proposed a federated peg in the meantime.
-
Spot Bitcoin ETF
Was: The entry presented all eleven funds as spot products that launched on day one, said eight of them held their bitcoin at Coinbase Custody in a concentration not structurally addressed, and called GBTC's 1.50% fee a legacy of its days before conversion.
Now: Hashdex's DEFI held bitcoin futures until March 27, 2024. In annual reports filed in 2026, Coinbase Custody was a custodian for nine of the eleven but the only one for five, and several funds had added custodians such as Anchorage Digital and BitGo. GBTC's fee was cut from 2.0% to 1.5% when it converted in January 2024.
-
Tracking Error
Was: The entry listed cash drag as a source of tracking gap, saying creation cash sits idle until the fund buys bitcoin and calling it a real headwind when the price rises. It also said Coinbase Custody held the bitcoin for 8 of the 11 US spot ETFs.
Now: At the iShares Bitcoin Trust, the authorized participant pays the difference when the fund pays more for bitcoin for a cash creation than the price used for NAV, so a price rise in between does not cost the fund. Custody arrangements differ by fund, so the entry no longer gives a count.
-
Air-gapped
Was: The entry said a single hardware wallet is air-gapped by design where its keys are concerned, and named Foundation Passport among the devices designed for air-gapped use.
Now: A hardware wallet used over USB or Bluetooth is not air-gapped, though it still keeps its private keys on the device. Foundation's air-gapped model, Passport Core, is discontinued, and its successor, Passport Prime, is not air-gapped by design.
-
BIP 125 (Replace-by-Fee)
Was: The entry's list of the five BIP 125 rules left out the rule that the original transaction must signal, and added a higher-feerate rule that BIP 125 does not contain. It also said opt-in RBF was Bitcoin Core's default only through version 23.
Now: The list now gives BIP 125's own five rules, starting with the signaling rule, and notes where Bitcoin Core has since moved away from them. Opt-in RBF was Core's default from 0.12 (2016) through 27.x, and 28.0 made full RBF the default in 2024.
-
BIP 159
Was: The entry's summary said BIP 159 proposed a NODE_FILTERS service bit for Bloom or compact filters, and its key points called it filter-related and not widely implemented.
Now: BIP 159 defines the NODE_NETWORK_LIMITED service bit, which lets a pruned node announce that it serves at least the last 288 blocks. The BIP is marked Deployed, and Bitcoin Core has signaled the bit since version 0.16.0 and connected to such peers since 0.17.0.
-
BIP 66
Was: The entry said BIP 66 was the first soft fork activated with the BIP 9 miner-signaling mechanism.
Now: BIP 66 reused the version-number switchover from BIP 34, so once 950 of the previous 1,000 blocks were version 3, version 2 blocks became invalid. BIP 9 came later, and its first deployment was the CSV soft fork of 2016.
-
Bitcoin Dev Kit (BDK)
Was: The entry listed Mutiny Wallet, which shut down in 2024, and Cake Wallet's Bitcoin module among the notable wallets built on BDK in 2026.
Now: The examples now come from the list BDK keeps of projects built on it. As of October 2026 that list includes the Bitkey, Proton Wallet, Bull Bitcoin and Liana wallets, Foundation's Envoy app, and infrastructure such as Fedimint and LDK Node. Cake Wallet is not on it.
-
Bitcoin Pizza Day
Was: The entry said Laszlo Hanyecz posted his offer of 10,000 BTC for two pizzas on May 22, 2010.
Now: Laszlo Hanyecz posted the offer on the Bitcoin Talk forum on May 18, 2010. Four days later, on May 22, Jeremy Sturdivant (jercos on the forum) took him up on it and had two pizzas delivered.
-
Block Time
Was: The entry said a block takes over an hour to arrive a few times a year.
Now: At a 10-minute average, the chance that a block takes over an hour is about 0.25%. That comes to about 130 blocks a year, or two or three a week.
-
Blockchain
Was: The entry put the chain at about 600 GB, growing by about 150 GB a year.
Now: The chain held about 775 GB of block data as of October 2026 and grows by roughly 80 GB a year.
-
BOLT
Was: The entry's example of different Lightning software working together described the Phoenix wallet as running Eclair.
Now: Phoenix runs on lightning-kmp, a separate ACINQ implementation, so the example now starts with an Eclair node opening a channel to a Core Lightning node.
-
Core Lightning (c-lightning)
Was: The entry said Eclair powers the Phoenix mobile wallet and is strong on mobile uses, and named Mutiny, which shut down in 2024, as an app built on LDK.
Now: Eclair is aimed at servers such as routing nodes. ACINQ's mobile wallet runs on lightning-kmp, a separate ACINQ implementation, and the entry's LDK examples are now Cash App and Alby Hub.
-
Decentralization
Was: The chapter said no single contributor's commits made up more than a few percent of Bitcoin Core's code.
Now: One developer has written more than a tenth of Bitcoin Core's commits, even with merge commits left out. The chapter now says only that Bitcoin Core has had over a thousand contributors since 2009.
-
Discard Threshold
Was: The entry said mempool.space's next-block fee estimate shows the discard threshold, and gave about 1 sat/vB as the floor in calm periods.
Now: mempool.space shows the mempool's fee floor on its dashboard as 'Minimum fee', relabeled 'Purging' when it rises above the relay minimum. Bitcoin Core 29.1 (September 2025) lowered the default relay minimum from 1 to 0.1 sat/vB. The entry's definition was itself corrected on 10 October 2026: in Bitcoin Core the discard threshold is a wallet setting for dropping tiny change, not the mempool floor.
-
Double Spend
Was: The entry said reversing a payment after six confirmations would take more than half the global hash rate, and that even a sustained majority would succeed only some of the time.
Now: A smaller attacker can still succeed, with odds that shrink with each confirmation. Meni Rosenfeld's 2012 analysis puts the chance after six confirmations at about 1 in 1,700 for an attacker with 10% of the hash rate and about 1 in 6 for one with 30%. An attacker with more than half is sure to win eventually.
-
Double-Blind Marketplace
Was: The entry listed AgoraDesk, a peer-to-peer trading site, among the Bitcoin-native double-blind marketplaces running in 2026.
Now: AgoraDesk wound down in 2024 and its site has been taken offline, so the entry no longer lists it.
-
Elliptic Curve
Was: The entry listed Taproot, along with P2WPKH, as an address type that keeps the public key hidden until the coins are spent, which gives some protection against a future quantum computer. A caveat added in June 2026 still called Taproot only a partial exception.
Now: Taproot gives none of that protection, because a Taproot address holds the tweaked public key itself, with no hash in front. The entry now gives P2WPKH as the example of a type that keeps the key hashed until the coins are spent.
-
Fee Bumping
Was: The entry said RBF requires the original transaction to signal that it can be replaced, with full RBF as an exception, and told senders whose transaction didn't signal to use CPFP or wait.
Now: Since Bitcoin Core 28.0 (October 2024), Core nodes on default settings run full RBF and accept a replacement whether or not the original signaled. A wallet may still refuse to bump a transaction that didn't signal; Bitcoin Core's own wallet did until 30.0 (October 2025).
-
Fee Rate Escalation
Was: The entry put the April 2024 fee spike down to the halving, saying fees rose as miners' subsidy income dropped.
Now: The spike came from the launch of the Runes token protocol, which switched on at block 840,000, the same block as the halving. Two blocks later the median fee rate in mined blocks passed 500 sat/vB, and it stayed above that for nearly 11 hours straight.
-
Fork Detection
Was: The entry said routine reorgs of one or two blocks happen a few times a year.
Now: Near-simultaneous block finds leave dozens of stale blocks each year. The public bitcoin-data/stale-blocks dataset counts between 28 and 93 a year from 2022 through 2025, and reorgs two blocks deep are rare.
-
Full Node
Was: The entry said a full node needs about 600 GB of disk for the chain, growing by about 150 GB a year.
Now: The chain came to about 775 GB of block data as of October 2026 and grows by roughly 80 GB a year. Bitcoin Core 31's setup screen asks for at least 870 GB.
-
Full RBF
Was: The entry said Bitcoin Core made full RBF its default in version 26 (late 2023), and its summary still called full RBF a proposal.
Now: Bitcoin Core added full RBF as an option in version 24 (late 2022), made it the default in 28.0 (October 2024) and removed the option in 29.0 (April 2025). Every Core node from 29.0 on runs full RBF.
-
Hal Finney's Running Bitcoin
Was: The entry said Bitcoin Core v0.1 was posted to the cypherpunks mailing list and that Hal Finney received block 70's reward of 10 BTC from Satoshi. It also said his coins, roughly 200,000 BTC or more, had never moved. We found no source for that figure.
Now: Satoshi announced Bitcoin v0.1 on the Cryptography Mailing List on January 8, 2009, and sent Hal 10 BTC in block 170 on January 12. In a 2013 forum post, Hal wrote that he mined several blocks in the first days and later moved his coins to an offline wallet for his heirs.
-
Hash
Was: The entry said addresses are hashes of public keys, which keeps the public key private until you spend.
Now: Most addresses are hashes of a public key or a script, which keeps the key or script private until you spend. Taproot addresses carry a public key directly instead of a hash of one.
-
Lightning Channel
Was: The entry opened by saying both parties lock funds into a channel's shared output, and its walkthrough mentioned funding by one side only as a variant.
Now: Usually the side that opens a channel puts up all of the bitcoin. A newer option, dual funding, lets the other side add funds too.
-
Lightning Channel Splicing
Was: The entry said splicing reached production in 2024, implemented in Phoenix and Core Lightning through a BOLT extension.
Now: ACINQ added splicing to eclair in April 2023 and to its mobile wallet that July. Core Lightning shipped an experimental version in August 2023 and LDK completed its support in August 2025. Splicing was merged into the Lightning specification in March 2026.
-
Lightning Network
Was: The entry's note on BOLT 12 offers said they support recurring payments.
Now: Offers were merged into the Lightning specification in September 2024 without the built-in recurring payments of earlier drafts. An offer can be reused because each payer's wallet uses it to ask for a fresh invoice.
-
Lightning Network Daemon (lnd)
Was: The entry said Eclair is optimized for mobile and powers the Phoenix wallet, and named Mutiny, which shut down in 2024, as an LDK user. It also called LND's watchtowers eltoo-style, after a channel design that would need a change to Bitcoin's rules.
Now: Eclair is aimed at servers such as routing nodes, and ACINQ's mobile wallet runs on lightning-kmp, a separate ACINQ implementation. An LND node can run a watchtower for others or hand one encrypted penalty transactions for its own channels, so a cheating partner can still be punished while the node is offline.
-
Lightning Routing
Was: The chapter's closing summary said the number of public nodes and channels had been shrinking since 2022.
Now: Public channels have fallen by more than half since their 2022 peak. Public node counts are flat or down depending on the tracker: about level with 2022 on mempool.space, well below it on Bitcoin Visuals.
-
Longest Chain Rule
Was: The entry said only an attacker with more than half of the hash rate could overturn a transaction with six confirmations.
Now: Smaller attackers can too, with odds that fall as more blocks are added. By Meni Rosenfeld's 2012 analysis, an attacker mining in secret with 10% of the hash rate would succeed about once in 1,700 attempts, and one with 30% about once in six. Only an attacker with more than half can count on it.
-
Merkle Block
Was: The entry said BIP 37 did not anticipate the privacy leak from Bloom filters when it was written in 2012, and that most modern mobile wallets, Phoenix and Mutiny among them, use the newer compact block filters.
Now: BIP 37 expected clients to hide their addresses by choosing a looser filter at the cost of extra bandwidth. A 2014 study found that a wallet using fewer than 20 addresses could still reveal almost all of them. Phoenix and Mutiny never used compact block filters, and the entry now says only that some mobile wallets do.
-
Mining Pool
Was: The entry said a miner with 0.1% of the global hash rate would find a block about every 70 days on average.
Now: At 0.1% the average is about one block a week. The example now uses 0.01%, which works out to about one block every 70 days, with some quarters bringing three blocks and some none.
-
Mt. Gox
Was: The entry said creditor repayments began in July 2024, more than a decade after the collapse.
Now: Creditors reported the first repayments, in yen, at the end of 2023. Repayments in bitcoin started in July 2024, more than ten years after the collapse.
-
Mt. Gox to FTX: The Custody Graveyard
Was: The chapter said Mt. Gox creditors did not start getting repaid until July 2024.
Now: The first repayments came at the end of 2023, when creditors reported receiving payments from the Mt. Gox trustee in yen. Repayments in bitcoin started in July 2024, more than ten years after the collapse.
-
Node Headcount
Was: The entry's key points said node counts miss Tor-only setups, and the entry said scanners such as Bitnodes sweep the IPv4 and IPv6 address space.
Now: Crawlers such as Bitnodes start from a few seed nodes, keep asking peers for more addresses, and count every IPv4, IPv6, Tor and I2P node that accepts inbound connections. Of the 25,514 reachable nodes bitnodes.io counted on October 9, 2026, about half were Tor addresses.
-
Node Synchronization
Was: The entry said a new node downloads around 600 GB of blocks, and that pruning cuts disk use to a few GB.
Now: The block data came to about 775 GB as of October 2026. At the prune setting its desktop app suggests, Bitcoin Core 31 estimates a pruned node at about 16 GB.
-
Nonce
Was: The entry said modern mining ASICs compute about 100 trillion hashes per second per chip.
Now: Speeds like that belong to a whole mining machine, which is built from many ASIC chips. One machine released in 2024 is rated at 234 trillion hashes per second.
-
Ordinals
Was: The entry called the last satoshi ever mined the 100-trillionth, which did not match the full number printed beside it (about 2.1 quadrillion). It also said a Legendary sat comes every four halvings.
Now: The last satoshi, due around 2140, will be ordinal 2,099,999,997,689,999. A Legendary sat is the first one of each cycle of six halvings, when a halving and a difficulty adjustment fall on the same block.
-
Orphan Block
Was: The entry said two miners finding a block at almost the same moment, which briefly splits the network, happens a few times a year on average.
Now: Near-simultaneous finds that briefly split the network happen dozens of times a year. The public bitcoin-data/stale-blocks dataset counts between 28 and 93 stale blocks a year from 2022 through 2025.
-
P2WPKH (Pay to Witness Public Key Hash)
Was: The entry said P2WPKH was the main format for new addresses only until about 2023, and that by 2026 many wallets had moved their defaults to Taproot for further fee savings. It also called single-use P2WPKH addresses quantum-safe.
Now: P2WPKH has been Bitcoin Core's default address type since version 0.20.0 in 2020. In September 2026 it made up about 53% of new outputs, against about 5% for Taproot, and for single-key use Taproot's fees come out about even with P2WPKH. The hashed key gives some cover against a future quantum computer, but only until the first spend reveals the key.
-
Poisson Process
Was: The entry said the wait for a block runs past an hour a few times a year.
Now: About 0.25% of blocks take over an hour at a 10-minute average, which is roughly 130 a year, or two or three a week.
-
Price Discovery
Was: The entry gave Coinbase's BTC-USD price, a single exchange's market, as an example of the multi-exchange reference rates that ETFs use as official prices.
Now: The examples are now the CME CF Bitcoin Reference Rate, its New York variant and the Fidelity Bitcoin Reference Rate. Fidelity's spot Bitcoin ETF tracks the last of these, which is built from prices on several spot markets.
-
Pruning Mode
Was: The entry compared a pruned node's 15 to 25 GB with about 600 GB for a fully archival node.
Now: Bitcoin Core 31 estimates that a fully archival node needs at least 870 GB.
-
Satoshi Nakamoto
Was: The entry said none of the roughly 1.1 million BTC that Satoshi mined had ever been spent.
Now: Researcher Sergio Lerner, who estimates Satoshi mined close to 1.1 million BTC in 2009 and early 2010, found in 2019 that 99.9% of those blocks' rewards were unspent. The best-known coins Satoshi did move are the 10 BTC from block 9's reward sent to Hal Finney in block 170 on January 12, 2009.
-
Security
Was: The entry said Bitcoin had never had a double spend that overturned confirmed transactions.
Now: A confirmed payment was double spent during the March 2013 chain split, which a software bug made possible. BIP 50, the developers' write-up of that split, records at least one large double spend.
-
Spot Bitcoin ETF
Was: The entry said the funds strike NAV against the CME CF Bitcoin Reference Rate at 4:00 PM London time, and put WisdomTree's BTCW fee at 0.50%.
Now: NAV is struck as of 4:00 PM New York time. Several funds, including the iShares Bitcoin Trust, use the New York variant of the CME CF Bitcoin Reference Rate, built from trades between 3:00 and 4:00 PM. BTCW charges 0.25%, inside the 0.19% to 0.25% range most funds give in their annual reports filed in 2026.
-
Stale Block
Was: The entry said brief block-finding collisions that leave a block stale happen several times a year.
Now: Near-simultaneous finds leave dozens of stale blocks each year. The public bitcoin-data/stale-blocks dataset lists between 28 and 93 a year from 2022 through 2025.
-
Tracking Error
Was: The entry said NAV is struck at 4 PM London, listed WisdomTree's BTCW fee as 0.50% and VanEck's HODL as 0.25%, and said spread and slippage on cash creations and redemptions flow into the fund.
Now: NAV is struck as of 4:00 PM New York time. Per the funds' annual reports filed in 2026, BTCW charges 0.25% and HODL 0.20%. At the iShares Bitcoin Trust the authorized participant, not the fund, covers any shortfall when the fund's bitcoin trade comes in at a worse price than the one used for NAV.
-
Transaction Finality
Was: The entry said an attacker's chance of reversing a payment falls off roughly as q^N, where q is the attacker's share of the hash rate and N the number of confirmations. By that formula a 10% attacker would have a 1 in a million chance after six. It also said 1-block reorgs happen a few times a year.
Now: Below half the hash rate, an attacker's chance shrinks exponentially with each confirmation. Meni Rosenfeld's 2012 analysis puts it at about 1 in 1,700 for a 10% attacker after six. One-block reorgs happened dozens of times a year from 2022 through 2025, and two-block reorgs were rare.
-
Transaction Index (txindex)
Was: The entry compared the index's size with about 600 GB of archival block data.
Now: The archival block data came to about 775 GB as of October 2026.
-
ASIC (Application-Specific Integrated Circuit)
Was: The entry said a single mining ASIC chip does about 100 trillion hashes per second on tens of watts, about 100,000 times a CPU. It also said most mining power comes from stranded or low-cost sources.
Now: A whole 2024 mining machine, built from many chips, is rated at 234 trillion hashes per second on 3,510 watts, about seven million times the 33 million a second of a high-end 2011 desktop CPU. Cambridge's 2025 survey found miners got 52.4% of their power from renewables and nuclear, with natural gas the largest single source at 38.2%.
-
Be Your Own Bank
Was: The chapter told readers to check a bc1 signature with Bitcoin Core's verifymessage, which accepts only addresses starting with 1, and said a signed message is anchored in time. It also said customers' funds are gone when an exchange goes bankrupt, and described the Jade hardware wallet as having a secure element.
Now: It explains that wallets sign for bc1 addresses in other formats, such as BIP 137 or BIP 322, so the check needs a wallet that supports the same format, and that a signature carries no timestamp. Mt. Gox, which collapsed in February 2014, began repaying creditors in bitcoin in July 2024, and Jade uses a PIN server that Blockstream calls a virtual secure element in place of a secure-element chip.
-
BOLT 11
Was: The entry called the description optional, described an encoded invoice as a relatively short string, and said paying an invoice a second time would either fail or be a fraud signal.
Now: Every invoice must carry a note or a hash of a longer description, and invoices typically run to a few hundred characters, past the 90-character limit of bech32 addresses. Once a payment settles, its preimage is no longer secret, so a node on the original route could keep a second payment to the same invoice that passes through it.
-
CME CF Bitcoin Reference Rate
Was: The entry said US spot Bitcoin ETFs strike their NAV against the BRR at 4:00 PM London, that the SEC cited the BRR's robustness in its 2024 approval order, and that CME uses the BRR for daily as well as final futures settlement. Its constituent list still named itBit and left out Bullish and Crypto.com.
Now: Several US spot Bitcoin ETFs, including the iShares Bitcoin Trust, use the New York variant (BRRNY), measured from 3:00 to 4:00 PM New York, and the unsupported SEC claim is gone. CME futures settle to the BRR only at expiry, and the list as of August 2026 is Bitstamp, Bullish, Coinbase, Crypto.com, Gemini, Kraken and LMAX Digital, with itBit suspended in July 2026.
-
Corrupted Chain State
Was: The entry said -reindex does not require re-downloading the chain and told readers to delete the chainstate folder by hand if -reindex-chainstate failed. It also tied version-related corruption to upgrades and listed wildly wrong balances as a symptom.
Now: On a pruned node, -reindex downloads the whole chain again and -reindex-chainstate cannot be used. The -reindex-chainstate option wipes the chainstate itself, so there is no need to delete it by hand first. The documented version problem is downgrading, which the 0.15.0 release notes said needs -reindex-chainstate, and the symptoms listed are startup errors such as 'Corrupted block database detected' or blocks failing to validate.
-
Creation / Redemption (Cash vs In-Kind)
Was: The entry said cash-only creation passed realized gains through the fund and gave up the ETF tax advantage, and that in-kind ETFs suit tax-sensitive long-term holders better. It also cited a stated rationale from Gary Gensler for cash-only, and said Chair Paul Atkins approved in-kind as the new SEC's first major crypto-friendly policy shift.
Now: The iShares Bitcoin Trust, a grantor trust, expects gains on BTC sold for a cash redemption to fall on the redeeming shareholder, and an investor who trades shares on an exchange is taxed the same way under either model. The January 2024 approval order gives no reason for cash-only, which most applications switched to during the SEC's review, and in-kind came by a Commission vote on July 29, 2025.
-
How Bitcoin Works
Was: The confirmations table said it showed a 30% attacker, but its odds fit no standard model and fell to 0.025% after six confirmations. The chapter also called difficulty adjustments exact, put the chain at about 600 GB, and said rewriting old history would take as long as the chain has been running.
Now: The table uses Meni Rosenfeld's 2012 figures for a 10% attacker, about 0.06% (1 in 1,700) after six confirmations, and says a 30% attacker still has about a 16% chance after six. One difficulty adjustment is capped at a factor of four either way, the chain is about 775 GB as of October 2026, and redoing all of its work would keep every mining machine busy for a little over three years at October 2026 hash rates.
-
Inscriptions
Was: The entry said Casey Rodarmor introduced inscriptions in January 2023, and that inscription demand has been a major driver of fee levels since 2023.
Now: The first inscription was confirmed in block 767,430 on December 14, 2022, and inscribing caught on in the first months of 2023. The fee effect is dated to 2023, when Glassnode estimated that text inscriptions paid between 30% and 60% of all transaction fees during the May wave.
-
Lightning Anchor Commitment
Was: The entry said a channel's commitment transaction is pre-signed when the channel opens, that anchor outputs became standard in the BOLT specs around 2021-2022, and that force-closes during fee storms work reliably.
Now: Both sides sign a fresh commitment every time the channel balance changes. Anchors entered the spec in 2020 and became LND's default in June 2021, and force-closes are far more reliable, though they depend on the node having on-chain bitcoin for the fee bump and can still be hit by pinning attacks.
-
Lightning Invoice
Was: The entry called an invoice's description optional, presented proof of payment as something each routing node gets without naming the payer, and said BOLT 12 offers support recurring payments.
Now: BOLT 11 requires every invoice to carry a short description or a hash of a longer one, and the preimage the payer ends up holding is its proof of payment. Offers were merged into the spec in September 2024 without the recurring payments that earlier drafts included.
-
Lightning Node
Was: The entry said eclair powers the Phoenix mobile wallet, listed Phoenix among custodial wallets, and named Mutiny (shut down in 2024) and Mercury Layer as LDK users, though LDK's own case studies list neither. It also said only weeks of downtime start to cause problems.
Now: Phoenix is a self-custodial wallet built on lightning-kmp, a separate ACINQ implementation, and LDK's case studies list users such as Cash App, Bitkit and Alby Hub. If a peer broadcasts an old channel state, a node offline past the channel's dispute window can lose funds. LND sets that window by default at about a day to two weeks, depending on channel size, and payments forwarded through a node have shorter deadlines, often a matter of hours.
-
M-of-n
Was: The entry said legacy multisig hard-caps at 15 cosigners because of the OP_CHECKMULTISIG opcode, and that MuSig2 or FROST aggregation hides any M-of-N structure on chain.
Now: The opcode accepts up to 20 keys, the 15-key cap applies only inside P2SH, P2WSH allows 20, and Bitcoin Core's Taproot multi_a descriptor allows up to 999. MuSig2 hides the structure only when all N cosigners sign, and FROST, which covers any M of N, is still a draft BIP as of October 2026.
-
Multisig
Was: The entry said classical multisig is capped at 15 cosigners by the design of the OP_CHECKMULTISIG opcode, and that an attacker has to compromise two keys of a 2-of-3 at the same time.
Now: The opcode accepts up to 20 keys. P2SH tops out at 15 compressed keys because its whole script has to fit in one 520-byte data element, P2WSH allows the full 20, and Taproot script paths use OP_CHECKSIGADD, which lifts the 20-key cap. A key stolen months earlier still counts toward the two unless the funds have moved to new keys.
-
Native SegWit
Was: The entry put native SegWit's saving over wrapped SegWit at roughly 10-15%, said Taproot adds slightly more savings, and said native SegWit has identical security properties.
Now: A native SegWit input takes about 68 vbytes against about 91 wrapped (roughly 25% less), and a simple one-input, two-output payment about 141 against 166 (roughly 15% less). For a single-key wallet, Taproot's fees come out about even. The script version, P2WSH, uses a 32-byte hash where P2SH uses 20 bytes, because BIP 141's authors judged that finding two scripts with the same 20-byte hash was within reach.
-
Sovereignty
Was: The chapter said to keep the multisig wallet descriptor separate from any seed and never told readers to store it with their seed backups, though two seeds alone cannot rebuild a 2-of-3 wallet. It also gave about 700 GB of chain growing 50 GB a year, a few hundred MB of RAM, and a Raspberry Pi 5 with a 1 TB SSD that syncs in a day or two.
Now: It says to keep a copy of the descriptor with each seed backup, since it records all three public keys and can show the balance but cannot spend. The chain held about 775 GB as of October 2026 and grows about 80 GB a year, Bitcoin Core 31 asks for at least 870 GB of disk and uses a gigabyte or two of RAM, and the Pi 5 option has a 2 TB drive and a first sync of several days.
-
Using Bitcoin
Was: The chapter said a fee bump with RBF requires the original transaction to signal that it is replaceable, that a low-fee backlog usually clears within hours, and that Lightning payments complete in milliseconds.
Now: Since Bitcoin Core 28.0 (October 2024), nodes on default settings accept a higher-fee replacement without that signal, though a wallet may still refuse to bump a transaction that lacks it. From early November 2023 to mid-July 2024 every mempool.space reading showed a backlog bigger than a full day of blocks, and Lightning payments usually complete within seconds.
-
Wallet Import Format (WIF)
Was: The entry said BIP 38 encrypted private keys start with 'p2' and called them a passphrase-protected WIF. It also said importing a paper wallet's key into a modern wallet moves the coins to its HD addresses.
Now: BIP 38 keys start with '6P' and are a related format, separate from WIF. Sweeping the key is what moves the coins, in a new transaction to the wallet's HD-managed addresses.
-
What Bitcoin Actually Is
Was: The chapter presented the 21 million cap as part of the whitepaper and said Satoshi sent the paper to the cypherpunks mailing list as an attachment. It also said the network had one outage in its first eight months and none since, and that reversing a payment after six confirmations is effectively impossible.
Now: The paper, linked from an email to the Cryptography Mailing List, says only that a predetermined number of coins will enter circulation; Satoshi announced the 21 million total and four-year halvings with the software in January 2009. The chapter covers the 2010 inflation bug and the 2013 chain split, each repaired within a day, and gives an attacker with a tenth of the mining power about a 1-in-1,700 chance after six confirmations.
-
Why Money Is Broken
Was: The chapter said CPI had been re-weighted since the 1980s in ways that reduce the headline number, and that every fiat currency in history has lost most of its purchasing power. It also said Bitcoin has run without interruption since 2009, and four cells of its inflation table were miscalculated, so 5% inflation over 20 years showed a 64% loss instead of 62%.
Now: It cites the Bureau of Labor Statistics, which puts the effect of a 1999 method change at less than 0.3 percentage points a year and says a 1983 change in counting homeowners' costs at first made the index's shelter component rise faster. The claim is narrowed to the dollar since 1971, the table is recomputed, and the chapter notes the 2010 and 2013 software bugs that forced the network to throw out part of its record, each repaired within a day.
-
BIP 9 (VersionBits)
Was: The entry said BIP 9 was used to activate BIP 65 (CLTV), and that Taproot was activated with BIP 8 "speedy trial" with a fallback to user-enforced activation.
Now: BIP 9's first deployment was the CSV soft fork in 2016, and CLTV used the older IsSuperMajority method. Taproot used Speedy Trial, a modified BIP 9 deployment with a 90 percent threshold and no fallback, which would simply have failed without miner signaling.
-
Chain Flag Day
Was: The entry said Taproot's Speedy Trial combined miner signaling with a fallback flag day.
Now: Speedy Trial had no fallback flag day. It ran about three months of signaling at a 90 percent threshold and would have failed if miners had not signaled; they did, and Taproot activated at block 709,632 in November 2021.
-
Deployment Threshold (Soft Fork)
Was: The entry said Speedy Trial activates Taproot "either at threshold or at the height, whichever comes first".
Now: The minimum activation height only set the earliest block where Taproot could take effect, to give nodes time to upgrade. Speedy Trial could still fail if miners did not reach 90 percent signaling within about three months.
-
Asymptote
Was: The entry called 20,999,999.9769 BTC an asymptote that the supply approaches but never reaches, and said the inflation rate reaches zero only in the limit.
Now: Because rewards are counted in whole satoshis, the schedule reaches exactly 20,999,999.9769 BTC with the last 1-satoshi subsidy in block 6,929,999, and issuance is exactly zero from block 6,930,000. Only the pure math, without rounding, approaches 21 million as an asymptote.
-
BIP 30
Was: The entry paired the duplicate coinbase blocks as 91722/91812 and 91842/91880.
Now: Block 91,842's coinbase repeated the txid of block 91,812's, and block 91,880's repeated block 91,722's. Each duplicate overwrote an unspent 50 BTC output, making 100 BTC unspendable, and BIP 30 names those two blocks as its only exceptions.
-
BIP 42
Was: The entry said BIP 42 codified the 21 million cap, that Pieter Wuille discovered the bug, and that issuance would have restarted around the year 2214.
Now: BIP 42 forces the subsidy to zero once 64 halvings have passed; without it, issuance would have restarted at block 13,440,000, around 2263. Wuille wrote the BIP in April 2014, and the fix was merged into Bitcoin Core that month.
-
Block Reward
Was: The entry said fees usually make up 3 to 10 percent of the block reward, and that per-byte fees keep rising in line with the design.
Now: Fees were about 0.6 percent of miner revenue in the year to October 2026 (about 6.5 percent in 2024), and the median fee rate in mined blocks fell from about 11 to 12 sat/vB in 2024 to about 1 sat/vB in 2026. Whether fees can replace the subsidy is an open question.
-
Block Subsidy
Was: The entry said fees are typically 3 to 10 percent of the block reward.
Now: Fees were about 0.6 percent of the total in the year to October 2026, and about 6.5 percent in 2024.
-
Difficulty
Was: The entry said the network had adjusted difficulty roughly 400 times and that difficulty had grown by 13 orders of magnitude since the genesis block.
Now: Difficulty changed more than 460 times between the genesis block and October 2026, and its growth from 1 to about 1.3 x 10^14 is about 14 orders of magnitude.
-
Disinflation
Was: The entry said Bitcoin's inflation rate reaches zero "asymptotically".
Now: Issuance reaches exactly zero at block 6,930,000, around 2140, because the subsidy is counted in whole satoshis.
-
Grover's Algorithm
Was: The entry said that finding a public key behind a P2PKH or P2WPKH address with Grover's algorithm would still face about 2^128 security, and that Aggarwal et al. found mining resistant to quantum speedup "over a multi-decade horizon".
Now: For a 160-bit hash Grover's algorithm needs about 2^80 steps, which have to run largely in sequence. The 2017 paper's forecast covered the next 10 years, roughly 2017 to 2027.
-
Halving (Halvening)
Was: The entry said the network had weathered five halvings.
Now: As of October 2026 there have been four, in 2012, 2016, 2020 and 2024.
-
Halvings
Was: The chapter said five halvings had happened, dated the fourth to April 19, 2024, and credited ordinals and inscriptions for that block's fees. It also projected rising fee shares into the 2030s and said the trend so far fit the idea of fees replacing the subsidy.
Now: There have been four halvings; block 840,000 was mined at 00:09 UTC on April 20, 2024, and most of its 37.6 BTC in fees came from Runes, which launched at that block. Fees were about 0.6 percent of miner revenue in the year to October 2026, so the projections were removed and the chapter calls fee-funded security an open question.
-
Hash Rate
Was: The entry put the hash rate at about 700 EH/s "as of mid-2026", said it had grown 13 orders of magnitude since 2009, and said a brief reorg attack would cost billions of dollars a day.
Now: The June to August 2026 average was about 910 EH/s, and growth since 2009 is about 14 orders of magnitude. The unsourced cost figure was replaced with what an attacker would actually need, more mining hardware than every other miner combined.
-
Inflation
Was: The entry put Bitcoin's circulating supply at about 19.9 million BTC, which was out of date; the schedule passed 20 million in March 2026.
Now: The schedule had issued 20,093,750 BTC through block 969,999 (October 5, 2026), for a rate of about 0.82 percent a year, roughly half the 1.5 to 1.7 percent growth in gold's above-ground stock in 2025.
-
Key Space
Was: The chapter said the number of possible keys is bigger than the number of atoms in the observable universe "by many orders of magnitude", and that a 256-bit key doubles the strength of AES-128. It also named Grover's algorithm as the quantum threat to keys, and its brute-force example did not state how many computers it assumed.
Now: At about 1.2 x 10^77, the key space is smaller than every estimate of the atom count (10^78 to 10^82), and a 256-bit elliptic-curve key gives about 128-bit security, the same class as AES-128. The quantum threat to keys is Shor's algorithm, and the brute-force example spells out its fleet of 10 billion computers.
-
Longest Chain Rule
Was: The entry put Bitcoin's hash rate at about 700 EH/s, an out-of-date figure.
Now: The hash rate averaged about 910 EH/s from June to August 2026.
-
Mainnet
Was: The entry said mainnet is secured by about 700 EH/s of hash power, an out-of-date figure.
Now: Mainnet averaged about 910 EH/s from June to August 2026.
-
Mining
Was: The chapter said, as plain fact, that fee revenue will grow to take the subsidy's place in the 2030s and beyond, and that the US is the largest mining country, without a source or date.
Now: It calls fees replacing the subsidy a hope and an open question. The US accounted for about 75% of the mining activity reported in Cambridge's April 2025 survey of 49 firms.
-
Mining
Was: The entry put the global hash rate at around 700 EH/s and each block at about 4 x 10^23 hash attempts.
Now: The hash rate averaged about 910 EH/s from June to August 2026, which works out to about 5 x 10^23 attempts per block.
-
Mining Subsidy
Was: The entry gave 2026 issuance as about 0.83% a year against "the ~19.7M circulating", and its table labeled the zero-subsidy period era 33, which by the table's own numbering is the last era that still pays 1 satoshi.
Now: About 20.1 million BTC had been issued by October 2026, for about 0.82% a year. Era 33 (blocks 6,720,000 to 6,929,999) pays 1 satoshi per block, and the subsidy is zero from block 6,930,000.
-
Mnemonic Entropy Bits
Was: The entry said Grover's algorithm would cut a 12-word seed to about 64-bit security, "the edge of expensive but doable", and pointed to 24 words as the defense. It also said a wrong word would "almost certainly" fail the checksum.
Now: Grover's steps have to run largely one after another, which NIST calls difficult in practice, and the bigger quantum risk is Shor's algorithm against exposed public keys, which a longer seed does not help with. The checksum catches a wrong word about 15 times in 16 for a 12-word seed and 255 times in 256 for a 24-word seed.
-
Revenue per TH/s
Was: The entry's 2026 example used about 0.3 BTC in fees per block and a 700 EH/s hash rate, giving $0.04 to $0.06 per TH/s per day, and it put the electricity cost of a 15 J/TH machine at $0.029 per day.
Now: With June to August 2026 averages, about 0.02 BTC in fees per block and about 910 EH/s, hashprice was about $0.03 per TH/s per day. A 15 J/TH machine uses about $0.018 of electricity per TH/s per day at $0.05/kWh.
-
Reward Era
Was: The entry called Bitcoin's issuance deflationary, labeled the whole first era as CPU mining, and listed era 33 as the era with zero subsidy.
Now: Issuance is disinflationary, GPU mining began in 2010, and era 33 (blocks 6,720,000 to 6,929,999) still pays 1 satoshi per block. The subsidy is zero from block 6,930,000, in era 34.
-
Seed Backup Strategies
Was: The chapter said writing words 1 to 12 and 13 to 24 of a seed on separate papers "drastically reduces the brute-force space" of the missing half.
Now: For a 24-word seed the missing half still leaves about 2^124 possibilities, so the real problems are no redundancy and half the seed exposed to whoever finds one paper. Only a 12-word seed split the same way becomes weak, at about 2^62.
-
The Inflation Bug Postmortem
Was: The chapter said Pieter Wuille noticed the BIP 42 bug in 2014 and that after enough halvings the subsidy would "wrap around to a large positive value".
Now: A developer called ditto-b opened the fix as a pull request in March 2014, BIP 42 credits Gregory Maxwell with proposing it, and Wuille wrote the BIP. At the 64th halving the bit shift becomes undefined in C++, and on the platforms Bitcoin Core supported in 2014 the subsidy would have jumped back to 50 BTC.
-
The Supply Schedule
Was: The chapter gave the supply in the middle of the current era as 19,867,581 BTC, which does not match the schedule (about 20,015,625 BTC at that point), and said fees had been growing as a share of miner revenue for years. It also said the economics work out "as long as Bitcoin is being used at all".
Now: The schedule had issued 20,093,750 BTC through block 969,999 (October 5, 2026), for an inflation rate of about 0.82 percent a year. Fees were about 0.6 percent of miner revenue in the year to October 2026, and the chapter treats fee-funded security as an open question and adds the BIP 30 and BIP 42 history.
-
Transaction Fee
Was: The entry said fees are about 3 to 10 percent of block reward revenue, and that next-block fees touched 500+ sat/vB during an early-2024 Ordinals surge.
Now: Fees were about 0.6 percent of miner revenue in the year to October 2026 (about 6.5 percent in 2024). The big 2024 spike came when the Runes protocol launched at the halving block on April 20, 2024, and the median fee rate in mined blocks averaged more than 1,000 sat/vB for several hours.
-
What Bitcoin Actually Is
Was: The chapter dated the fourth halving to April 19, 2024, and said the last fractional satoshi will be mined around 2140.
Now: Block 840,000 was mined on April 20, 2024 (UTC). Bitcoin counts in whole satoshis, so the subsidy reaches exactly zero at block 6,930,000, around 2140.
-
ML-DSA / Dilithium (FIPS 204)
Was: The entry called ML-DSA the leading candidate to replace ECDSA and Schnorr signatures in Bitcoin.
Now: ML-DSA is one of the options discussed. Bitcoin's post-quantum work has mostly focused on hash-based signatures, such as the SHRINCS draft BIP posted in 2026.
-
Quantum and Bitcoin
Was: The chapter called ML-DSA the leading candidate for Bitcoin's post-quantum signatures and presented BIP-360's P2MR without the other output designs under discussion.
Now: Bitcoin Optech reports that Bitcoin's post-quantum work has mostly focused on hash-based signatures, such as the SHRINCS draft BIP posted in 2026, while lattice schemes like ML-DSA remain part of the discussion. P2MR is described as one of several output designs being weighed.
-
The BIP Process
Was: The chapter said Luke Dashjr was the only BIP editor for roughly a decade and that the role became a team in February 2024. Its count of six editors went out of date in August 2026.
Now: Dashjr became editor in January 2016 and Kalle Alm joined in 2021. The list was rewritten in April 2024, adding five editors and dropping Alm, and Dashjr was removed in August 2026, leaving five.
-
OP_RETURN
Was: The entry called 80 bytes the OP_RETURN standardness limit, said an OP_RETURN output creates a small dust output, and listed Liquid as a user of OP_RETURN commitments.
Now: Relay limits are policy: Bitcoin Core relayed 40 bytes from 0.9 (2014) and 80 from 0.11 (2015), and 30.0 (October 2025) raised the default to 100,000 bytes. An OP_RETURN output never enters the UTXO set and is not dust, and the Liquid example was replaced with documented users such as Omni, Counterparty, VeriBlock and Runes.
-
Decentralization
Was: The chapter said the mining pool GHash.io "approached 51%" of the hash rate in 2014 and that miners left it "within weeks".
Now: GHash.io held 51 percent of the hash rate for a few hours on 13 June 2014, and miners moved their hash power to other pools within days.
-
Privacy on Bitcoin: What Works and What Doesn't
Was: The chapter implied that tracing the coins through the chain is what found the bitcoin stolen from Bitfinex.
Now: Investigators followed the coins for years, but the private keys turned up in files in one of the suspects' online accounts, reached with a search warrant. The chapter says the graph pointed to the people and records kept by services did the rest.
-
Bear Market
Was: The entry gave rounded, unsourced drawdowns, including -82% for 2013-2015 and -78% for 2022, said bear markets take 70 to 85 percent off the peak, and said "Bitcoin is dead" articles cluster near the bottom.
Now: Measured on Coin Metrics daily closing prices, the falls were -93% in 2011, -85% in 2013-2015, -84% in 2018 and -77% in 2022. Searches for "Bitcoin is dead" are what spike near the bottom.
-
Bitcoin and Energy
Was: The chapter said mining uses about 173 TWh a year, roughly three quarters of one percent of global electricity, and put the sustainable share of its energy in the mid-50s to mid-60s percent. It also said Bitcoin uses half as much as gold mining and less than the world's tumble dryers.
Now: Cambridge's own figures give about 140 to 175 TWh, half to two-thirds of one percent (updated on 10 October 2026 to about 140 to 160 TWh, roughly half of one percent), and sustainable-mix estimates run from about a quarter to 60 percent, with Cambridge's 2025 survey at 52.4 percent. The gold figure was corrected to roughly equal, and the tumble-dryer line was dropped because Cambridge's own comparison did not support it.
-
Difficulty Retargeting
Was: The entry said each difficulty adjustment is clamped at +/-300%.
Now: Bitcoin Core limits each adjustment to a factor of four either way, so at most +300% up or -75% down in one step.
-
Energy FUD
Was: The entry put Bitcoin's mining draw "in the high tens of TWh per year".
Now: Cambridge's figures put it at about 140 to 175 TWh a year depending on method, roughly half to two-thirds of one percent of the world's electricity, a range that was itself updated on 10 October 2026 to about 140 to 160 TWh, roughly half of one percent.
-
FTX
Was: The entry said FTX claims were valued as of 11 November 2022, "when bitcoin was around $16,000".
Now: The bankruptcy estate's own conversion table priced bitcoin at $16,871 for that date, and the entry uses that figure.
-
FUD (Fear, Uncertainty, Doubt)
Was: The entry said China had "banned" Bitcoin "roughly 16 times since 2013", a count with no source.
Now: It lists the formal notices from Chinese regulators in 2013, 2017, 2021 and 2026, and quotes a CoinShares executive's 2021 joke that it had to be "the 20th time".
-
Geographic Mining Distribution
Was: The entry said China banned mining outright in May-June 2021, and gave the US share of hash rate as about 35-40% with no date.
Now: The crackdown came in stages: a State Council order in May, provincial shutdown orders in June, and a September declaration that crypto trading was illegal, with a plan to phase out mining. The US share is dated to January 2022, about 38%, the last month in Cambridge's country data.
-
Inflation Bug
Was: The entry dated the disclosure of CVE-2018-17144 to 18 September 2018 and said patched releases for all supported branches shipped within 24 hours. It called the 2018 bug the canonical example without mentioning the 2010 bug that actually created coins.
Now: The bug was reported on 17 September, Bitcoin Core 0.16.3 fixed it on 18 September, full disclosure came on 20 September, and the older branches were patched on 28 September. The entry names the affected versions, 0.15.0 to 0.16.2, and opens with the August 2010 overflow bug.
-
Intrinsic Value
Was: The entry said Warren Buffett had made the no-intrinsic-value argument against Bitcoin "every year since" 2013.
Now: We found no dated Buffett remarks on bitcoin for several of those years, including 2015, 2016 and 2023 to 2025, so the entry says he has made the argument repeatedly since 2014.
-
Lightning Routing
Was: The chapter's closing summary said Lightning fees are essentially free and that capacity "keeps growing as more nodes open more channels".
Now: Fees are tiny but never quite zero. Public capacity hit a record in late 2025 and then fell back in 2026, while the number of public nodes and channels had been shrinking since 2022, a claim that was itself corrected on 9 October 2026.
-
Mining
Was: The chapter put mining at about 173 TWh a year, roughly three quarters of one percent of global electricity, cited "two decades of empirical evidence" for a system launched in 2009, and said geographic dispersion had roughly doubled, without a source.
Now: By Cambridge's methods mining draws about 140 to 175 TWh a year, half to two-thirds of one percent of the world's electricity, a range that was itself updated on 10 October 2026 to about 140 to 160 TWh, roughly half of one percent. The evidence is dated from 2009, and the unsourced dispersion claim was removed.
-
Mt. Gox to FTX: The Custody Graveyard
Was: The chapter said FTX claims were valued as of 11 November 2022, "when bitcoin was around $16,000".
Now: The bankruptcy estate's conversion table priced bitcoin at $16,871 for that date, and the chapter uses that figure.
-
Quantum and Bitcoin
Was: Two passages still quoted an older snapshot (about 30.5 percent of all BTC exposed, 1,063,006 BTC always exposed) after the chapter's chart had moved to newer data. The chapter also described the best machines as hundreds of noisy physical qubits with single-digit logical qubits, and repeated BIP-361's description of its 2027 to 2030 window as coming from academic roadmaps.
Now: Both passages match the chapter's current snapshot, and the hardware line follows published results: physical qubits in the hundreds to low thousands, and logical qubits in the dozens at best. The 2027 to 2030 window is credited to the report BIP-361 actually cites for it, McKinsey's Quantum Technology Monitor 2025.
-
The Inflation Bug Postmortem
Was: The chapter put the August 2010 events at the wrong times (the bad transaction at 19:13 UTC, the first forum report at 19:50), said the bad block held several transactions, put the reorg at 19 hours, and called the fix a hard fork. It also quoted Satoshi with a line we could not find in the record.
Now: The bad block's timestamp is 17:05 UTC, Jeff Garzik's first report came at 18:08, the fix was committed at 21:35 and announced at 23:48, the block held two transactions, and the patched chain overtook about 15 hours later. The fix was a soft fork, as the Bitcoin Wiki records, and the quote was replaced with one from the forum thread.
-
Tulip Mania
Was: The entry said the tulip comparison had been used against Bitcoin since 2011, put the 2013-2015 drawdown at about 86 percent, and said Jamie Dimon in 2025 let "any client" buy bitcoin.
Now: The earliest uses we can document are from 2013, the drawdown measured on daily closes is about 85 percent, and in May 2025 Dimon said JPMorgan would let clients buy it.
-
Bitcoin Obituaries
Was: The entry dated the first obituary to 15 December 2010, listed Paul Krugman's "Bitcoin Is Evil" among the famous entries on 99Bitcoins' list, and said obituaries pile up in the year after each top.
Now: The first entry is a blog post from November 2010; 99Bitcoins dates it by its archived copy. Krugman's piece was never on that list, and obituaries cluster around each top and through the crash, with 113 of 2017's 124 coming before the December top.
-
Intrinsic Value
Was: The entry said the US "ended convertibility to gold" on 15 August 1971, which skipped the 1933-34 and 1968 changes that had already ended it for everyone but foreign governments and central banks.
Now: No one, not even a foreign central bank, has been able to redeem dollars for gold since 15 August 1971, when the US closed the last gold window.
-
Why Money Is Broken
Was: The chapter said Nixon ended dollar convertibility to gold in 1971, and that a 1971 dollar had "the purchasing power of roughly $0.13 in 2025", which states the comparison backwards. One line still said 13% after the 2020 to 2025 figure had been corrected to 20%.
Now: Ordinary Americans lost gold convertibility in 1933-34, and the window Nixon closed in August 1971 was open only to foreign governments and central banks. By 2025 a dollar bought about what 13 cents bought in 1971, and the 2020 to 2025 loss reads 20% throughout.
-
Lightning Routing
Was: The onion routing animation on this page, and its text description, showed the payment preimage at the center of the onion.
Now: The innermost layer carries the receiver's payment instructions, the amount and a payment secret. The receiver already holds the preimage and reveals it to get paid, and the animation was re-rendered to show that.
-
Lightning Sphinx
Was: The onion routing animation on this page, and its text description, showed the payment preimage at the center of the onion.
Now: The innermost layer carries the receiver's payment instructions, the amount and a payment secret. The receiver already holds the preimage and reveals it to get paid, and the animation was re-rendered to show that.
-
Onion Routing (Lightning)
Was: The onion routing animation on this page, and its text description, showed the payment preimage at the center of the onion.
Now: The innermost layer carries the receiver's payment instructions, the amount and a payment secret. The receiver already holds the preimage and reveals it to get paid, and the animation was re-rendered to show that.
-
Asmap
Was: The entry said asmap data is shipped or downloaded separately from Bitcoin Core, credited the main data source to Sjors Provoost and Pieter Wuille without support, and implied asmap is in use by default.
Now: Since Bitcoin Core 31.0 a map built from RPKI, IRR and Routeviews data ships inside the release, and asmap stays off unless asmap=1 is set. The unsupported attribution was removed.
-
BIP 158
Was: The entry said compact block filters add up to several megabytes for a year of blocks, and named Phoenix and Mutiny as wallets that use them.
Now: A year of filters is about 1 GB and the whole chain about 13 GB as of 2026, by our own sample of filters downloaded from nodes; Bitcoin Core's release notes put the total at about 4 GiB in 2019. Phoenix and Mutiny never used them, so the entry no longer names them.
-
Bitcoin Core RPC
Was: The entry called the interface JSON-RPC 1.0, named rpcauth as the preferred login, and recommended JSON-RPC over Tor for managing a node remotely.
Now: Bitcoin Core uses the older 1.1-style protocol and, since 28.0, JSON-RPC 2.0 when a request asks for it, and the cookie file is the default and preferred login. Core's own docs say not to expose RPC to the internet, even through Tor, and point to a VPN or SSH tunnel.
-
Dust Attack
Was: The entry gave Binance's 2019 dust attack as its main example without saying it happened on Litecoin, and credited Sparrow with the "Do Not Spend" flag, which was Samourai Wallet's name for the feature.
Now: The Bitcoin example is Samourai Wallet's October 2018 warning to its users that addresses were being dusted. The freezing feature is described under each wallet's own name.
-
Dust Limit
Was: The entry said default Bitcoin Core nodes never relay a transaction with a dust output.
Now: Since Bitcoin Core 29.0 there is one exception, ephemeral dust: a zero-fee transaction may carry one dust output if a child transaction relayed with it spends that output. The thresholds the entry gave were right.
-
JSON-RPC over Tor
Was: The entry said security "stays solid" when a node's RPC is exposed through a Tor onion service, and called it the right pattern for remote access.
Now: Bitcoin Core's docs say not to expose RPC to the internet at all, warn that even an onion service could open it to attacks, and recommend a VPN or SSH tunnel. The setup steps were also corrected, since Tor needs no rpcbind or rpcallowip change.
-
PSBT (Partially Signed Bitcoin Transaction)
Was: The entry said PSBT version 2 (BIP 370 / BIP 371) adds Taproot support, and that Bitcoin Core and every major hardware wallet speak version 2 natively.
Now: Taproot fields come from BIP 371, a separate spec that works with either version, while version 2 (BIP 370) lets inputs and outputs be added after creation. Support for version 2 is uneven, and Bitcoin Core merged it in 2026 for version 32.0.
-
Silent Payments
Was: The entry listed two BIP-352 authors, said wallet support started on a hardware signer, and described BIP-375 and BIP-392 as proposals for light clients.
Now: Sebastian Falbesoner joined josibake and Ruben Somsen as a co-author in 2026, and the first wallet support came in a mobile wallet in May 2024. BIP-375 covers sending through PSBTs and BIP-392 covers descriptors.
-
Genesis Block
Was: The entry's Wikipedia and Wikidata references pointed at the general articles on blockchain, not at the genesis block.
Now: The Wikidata reference points at the genesis block's own item, and the Wikipedia link to the blockchain article was removed. The Bitcoin Wiki page on the genesis block remains.
-
What Bitcoin Actually Is
Was: The chapter said the genesis block came 68 days after the whitepaper, and that the whitepaper came 68 days after the 2008 financial crisis peaked.
Now: The whitepaper was announced on October 31, 2008, 64 days before the genesis block on January 3, 2009, and about six weeks after Lehman Brothers collapsed. Two "fifteen years later" phrases were also removed.
-
Why Money Is Broken
Was: The chapter said France "famously sent a warship" to collect its gold, quoted Nixon's "worth just as much tomorrow" line without its condition, and said a dollar had the purchasing power of about 87 cents in 2020 dollars.
Now: We found no primary record of the warship. The chapter says instead that France kept converting its dollars into gold, and a Federal Reserve staff report records a further $191 million sale of US gold to France in early August 1971. The Nixon quote keeps its condition, and by BLS annual averages a dollar in 2025 bought about what 80 cents bought in 2020, a 20 percent loss.
-
Branch and Bound (BnB)
Was: The entry said Bitcoin Core ran Branch and Bound first, with Knapsack as the fallback, from version 0.17 through 0.21.
Now: That arrangement lasted through version 22.0. From 23.0 the wallet runs every algorithm on each spend and keeps the lowest-waste result.
-
CoinJoin
Was: The entry left Wasabi out of the CoinJoin tools still in use and did not say that JoinMarket's original repository had been archived. It described the Samourai founders' charges without their outcome.
Now: Wasabi still works with independently run coordinators, and JoinMarket development continues in joinmarket-ng after the original repository was archived in April 2026. The Samourai founders pleaded guilty to the money transmitting count only and were sentenced in 2025 to five and four years.
-
PayJoin
Was: The entry said async PayJoin (BIP 77) runs over Nostr or similar relays, and that both sender and receiver consolidate coins.
Now: BIP 77 passes messages through an untrusted directory server reached over Oblivious HTTP, and only the receiver consolidates. The receiver's main benefit is that the amount paid is hidden.
-
UTXOs
Was: The chapter put the P2WPKH dust limit at 546 sats, said Bitcoin Core picks coins with Branch and Bound and falls back to Knapsack, and put the UTXO set at 85 to 110 million outputs. It also called UTXOs statelessly validatable.
Now: Bitcoin Core's default dust limit is 294 sats for P2WPKH and 546 for P2PKH, and since version 23.0 Core runs several coin selection algorithms and keeps the lowest-waste result. The UTXO set held about 165 million outputs as of October 2026, and since validation needs that set, the stateless claim was removed.
-
Lightning Routing
Was: The chapter said Sphinx is the same construction Tor uses, that the onion carries the payment preimage to the receiver, and that the public graph has hundreds of thousands of channels. It also said one failed chunk sends a whole multipath payment back, and that the last hop knows the receiver for certain.
Now: Tor builds its circuits one hop at a time while Sphinx packs the whole route into one packet, the receiver already holds the preimage and reveals it to get paid, and the public graph has tens of thousands of channels. Failed chunks are retried on other paths, the last hop can often guess the receiver but cannot be sure, and the BOLT 7 fee formula and gossip details were also corrected.
-
The Mempool
Was: The chapter said CPFP needs the recipient, called each block a sealed-bid auction, and said the mempool grew to 100 to 500 MB in 2023 and 2024.
Now: The sender can also use CPFP by spending a change output, and the fee auction is open, since every bid sits in public view. The 100 to 500 figure is in vMB of waiting transactions, and default nodes, capped at 300 MB of memory, were dropping the cheapest ones.
-
Mining
Was: The chapter said that as long as Bitcoin is used, fees "will be sufficient" to pay for its security, and that fees were "growing faster than the network needs them to".
Now: Fees were about 0.6% of miner revenue in the year to October 2026. The chapter says nobody knows yet whether fees alone will pay for enough security, which matches the energy chapter.
-
Mining
Was: The chapter said each difficulty adjustment is clamped at +/-300% and that difficulty had grown about 10^13 times since 2009. It also put fees at 3 to 10% of miner revenue and mining at 0.5% of global electricity.
Now: Bitcoin Core caps each adjustment at a factor of four, so at most +300% up or -75% down, and difficulty has grown about 10^14 times. Fees were about 0.6% of miner revenue in the year to October 2026, and the energy share was changed to about 0.75%, a figure that was itself corrected on 5 October 2026.
-
Bitcoin Governance
Was: The entry listed a Bitcoin Wiki page on governance as an external reference. That page does not exist, and we found no record that it ever did.
Now: The reference is BIP 3, the document that sets out how Bitcoin Improvement Proposals are handled.
-
Decentralization
Was: The chapter said the SegWit2x hard fork was cancelled three days before its planned activation, and its source was a Bitcoin Magazine URL that does not exist.
Now: Mike Belshe's cancellation email went out on November 8, 2017, nine days before block 494,784, where the fork was set to happen. The chapter cites an archived copy of that email.
-
Inscriptions
Was: The entry listed a Wikipedia article on the Ordinals protocol as an external reference. That article does not exist, and we found no record that it ever did.
Now: The reference is the inscriptions chapter of the Ordinal Theory Handbook.
-
Miner Signaling
Was: The entry listed a Bitcoin Wiki page on version bits as an external reference. That page does not exist, and we found no record that it ever did.
Now: The reference is BIP 9, the specification for version bits signaling.
-
Ordinals
Was: The entry listed a Wikipedia article on the Ordinals protocol as an external reference. That article does not exist, and we found no record that it ever did.
Now: The reference is the Ordinal Theory Handbook, the project's own documentation.
-
P2SH (Pay to Script Hash)
Was: The entry listed a Wikipedia article on pay to script hash as an external reference. That article does not exist, and we found no record that it ever did.
Now: The link was removed. The Bitcoin Wiki pages and BIP 16 remain as references.
-
BIP 170 (TxOut Proof)(entry retired)
Was: The entry, carried over from the old Drupal glossary, described BIP 170 as a 2013 proposal for proving a transaction is in a block, and linked a spec file that does not exist.
Now: There is no BIP 170, so the entry was retired and its URL returns 404.
-
BIP 36 (merkle block request)(entry retired)
Was: The entry, carried over from the old Drupal glossary, described BIP 36 as an early proposal for light clients to request parts of blocks.
Now: BIP 36 is Custom Services, a closed proposal by Stefan Thomas. The entry described a different proposal, so it was retired and its URL returns 404.
-
BIP 40 (Alerts Avoid Replay)(entry retired)
Was: The entry, carried over from the old Drupal glossary, described BIP 40 as a fix to stop old network alerts being replayed, and linked a spec file that does not exist.
Now: BIP 40 is a number set aside for the Stratum wire protocol, and no text was ever published under it. The entry was retired and its URL returns 404.
-
Schnorr Signature
Was: The entry said a 5-of-5 multisig under MuSig2 shows up as a single signature without saying that this aggregation happens among the cosigners of one output, not across a transaction's inputs.
Now: A transaction with five Taproot inputs still carries five signatures, and combining signatures across inputs would need another soft fork. The entry says so.
Source The change Caught by Danish Ali (BitcoinTalk)
-
Signature Aggregation
Was: The entry explained how cosigners combine their signatures into one but never said this happens within a single input, which left room to read it as aggregation across a whole transaction.
Now: Bitcoin has no cross-input aggregation. A transaction that spends five Taproot outputs still carries five signatures, one per input, and combining them would take another soft fork.
Source The change Caught by Danish Ali (BitcoinTalk)
-
BIP 50
Was: The entry said the March 2013 chain fork took six hours to resolve.
Now: From the triggering block to the reorganization took 7 hours 41 minutes, and the 0.8 chain's 25 blocks were abandoned. The rewritten entry also explains the 10,000-lock database limit in older versions that caused the split, and cites its sources.
-
Chain Split
Was: The entry called the March 2013 split a 24-block fork.
Now: The abandoned chain was 25 blocks long, and the split lasted 7 hours 41 minutes before the chain that every version could follow overtook it.
-
Fork Detection
Was: The entry described the March 2013 fork backwards, as a bug that made some nodes accept an invalid block.
Now: Version 0.8 accepted a block that older versions rejected because of an accidental database limit, and the network was split for nearly eight hours.
-
How Bitcoin Works
Was: The chapter said the deepest accidental reorg in Bitcoin's history was 4 blocks, in 2010.
Now: The deep reorgs came from software bugs. The chain was rolled back 53 blocks in August 2010 to undo the inflation bug, and 25 blocks in March 2013, when two versions of the software disagreed about a valid block.
-
Transaction Finality
Was: The entry named the March 2013 split as the most famous of Bitcoin's deep reorgs and then said no reorg had ever overturned a transaction with six or more confirmations "in normal network operation", without saying that this one had.
Now: The 25-block reorganization that ended the 2013 fork reversed a payment with more than six confirmations, a double spend of about $10,000 against the payment processor OKPay. The money was returned the next day, and the entry says so.
September 2026
-
How Taproot Actually Works
Was: The quantum section said 'a Taproot output is the public key itself'. A reader pointed out that what sits in the output is the tweaked key, not the owner's original key, so the line could be read as contradicting the chapter's own construction section.
Now: It was reworded to say a Taproot output holds the tweaked output key rather than a hash of one. It also adds a point athanred made in the same thread, that anyone who could derive that key's private key could spend the coin by key path alone, the same position as old pay-to-public-key outputs.
Source The change Caught by ABCbits (BitcoinTalk)
-
Joinstr
Was: The entry called Joinstr a niche proof of concept, said every public release was labeled experimental or pre-alpha, and named only a pre-alpha Electrum plugin, an experimental Rust library and documentation as its public output.
Now: By September 2026 Joinstr had shipped an Electrum plugin, an Android app and an Umbrel app, and its documentation says it can be used on mainnet; the rewritten entry says so and adds that its usage is still small and unmeasured. A dead mailing-list source link was replaced with an archive mirror.
-
Quantum and Bitcoin
Was: The chapter put quantum-exposed bitcoin at about 30.5 percent of supply and said the gap to BIP-361's figure of more than 34 percent came from different counting rules, with ChainQuery as the lower bound and BIP-361 as the upper bound. It also attributed a redeem-script counting rule to BIP-361 that the BIP does not contain.
Now: ChainQuery's June 23, 2026 methodology update fixed a second bug that had dropped about half of the old uncompressed-key P2PK coins. With that fix applied, the chapter gives about 35.6 percent (7,142,979 BTC at block 967,001, September 14, 2026), in line with Wicked Smart Bitcoin's independent count of 35.2 percent at block 961,000. The gap is described as measurement bugs rather than methodology, and the opening animation and its text description were updated from 25 to 36 percent the same day.
-
BECH32m
Was: The entry said Pieter Wuille discovered the bech32 weakness in 2020 and that Bitcoin's soft-fork upgrade model accommodated the fix.
Now: Jonathan Knowles found and reported the weakness in May 2019, and because address encoding is a wallet convention rather than a consensus rule, the fix needed no soft fork. The corrected entry also describes the actual bug, in which inserting or deleting q characters just before a final p leaves the checksum valid.
-
BIP 341 (Taproot)
Was: The entry said a key-path witness is 'exactly 64 bytes', called Speedy Trial an 'extended' signaling period, and said key-path and script-path spends look identical on the wire.
Now: BIP-341 allows a 64-byte signature, or 65 bytes when a non-default sighash type is appended, and it set the Speedy Trial signaling window to run only from April 24 to August 11, 2021. The corrected entry says both, and says it is the P2TR outputs that look identical until they are spent, not the two kinds of spend.
-
BIP 342 (Tapscript)
Was: The entry said OP_CHECKMULTISIG was 'deprecated' in Tapscript and that 'a few opcodes' were removed, and it described adding an opcode to legacy Script as a matter of reinterpreting a version field.
Now: BIP-342 disables OP_CHECKMULTISIG and OP_CHECKMULTISIGVERIFY, so executing either fails the script, and they are the only two opcodes it lists as disabled. The corrected entry says so, explains the OP_SUCCESS opcodes reserved for future soft forks, and notes that legacy upgrades had to repurpose OP_NOP opcodes.
-
Merkleized Abstract Syntax Tree (MAST)
Was: The short definition called MAST 'a Taproot-based technique.'
Now: MAST was discussed in Bitcoin from 2013 and had its own proposals, such as BIP-114, before it reached Bitcoin through the Taproot soft fork in November 2021. The definition was changed to describe it as a technique deployed through Taproot.
-
MuSig
Was: The entry blamed the original MuSig's problem on a key-cancellation attack and said MuSig2 nonces can be reused across signing sessions.
Now: The original two-round MuSig had a flawed security proof and could be attacked across concurrent signing sessions, which is why it moved to three rounds; key cancellation is a separate attack its design already handled. The corrected entry says this and that each MuSig2 nonce is single-use.
-
MuSig2
Was: The entry said MuSig2's first-round nonces can be 'reused across signing sessions', and that the original MuSig needed its commit-reveal round to stop a key-cancellation attack.
Now: BIP-327 warns that signing twice with the same nonce exposes the secret key, so each nonce must be used exactly once, and the corrected entry says so. It also explains that the extra round in the original MuSig blocked forgeries across concurrent signing sessions, which is a different problem from key cancellation.
-
Schnorr Signature
Was: The entry said Claus Schnorr's patent expired in 2008, said Schnorr signatures are unique for a given key and message, and listed MAST among the features built on Schnorr.
Now: US patent 4,995,082 was filed in February 1990 and expired in February 2010, more than a year after Bitcoin launched, and BIP-340 says plainly that it is not a unique-signature scheme. The corrected entry says both and names MuSig2 key aggregation and Taproot key-path spends in place of MAST.
-
Signature Aggregation
Was: The entry credited MuSig2 to 'Blockstream researchers' and described a nonce-commitment exchange as a step of MuSig2 signing.
Now: MuSig2 was designed by Jonas Nick and Tim Ruffing of Blockstream with Yannick Seurin of ANSSI, the French cybersecurity agency, and it has no nonce-commitment round; that round belonged to the original MuSig. The corrected entry says so and names software that ships MuSig2.
-
Taproot
Was: The entry said most major wallets default to Taproot addresses for new receive operations, and that every Taproot spend, whatever the script behind it, is just a 64-byte signature against a 32-byte key.
Now: The corrected entry says most major wallets, Bitcoin Core among them, still hand out native SegWit bc1q addresses by default as of 2026 and offer Taproot as an option. It also says only the outputs look alike, since a script-path spend reveals the script that was used.
-
Privacy on Bitcoin: What Works and What Doesn't
Was: The chapter said that because the Samourai case ended in a plea, no court ever ruled on whether a non-custodial coordinator is a money transmitter, and it left out the August 2025 jury verdict against Tornado Cash developer Roman Storm under the same money transmission statute. It also said a PayJoin 'looks exactly like an ordinary payment.'
Now: The chapter adds the Storm verdict as the nearest thing to a ruling and says the question is being litigated rather than settled. The PayJoin passage says it looks ordinary only at the level of inputs and outputs, and a new tip explains how wallet fingerprints can reveal whose inputs were whose.
Source The change Caught by ObeyKnock (BitcoinTalk), Antidote47k (BitcoinTalk)
-
Silent Payments
Was: The entry credited Silent Payments to Chris Belcher, said BIP-352 was 'formally adopted in 2023', and cited no sources.
Now: The rewritten entry says the idea was proposed on the bitcoin-dev mailing list in March 2022 and written up as BIP-352 by josibake and Ruben Somsen, and that the BIP was merged into the BIPs repository in May 2024. It now cites the BIP, Bitcoin Optech and two other sources.
-
Sovereignty
Was: The chapter's list of privacy basics named Wasabi and JoinMarket as 'the leading implementations' of CoinJoin, although the company behind Wasabi had shut down its coordinator on June 1, 2024, weeks after US prosecutors charged the founders of Samourai Wallet over theirs.
Now: The item was rewritten to say the CoinJoin landscape changed in 2024, when the operators of one coordinator were arrested and the other major coordinator shut itself down, while the decentralized designs survived. It sends readers to the Privacy on Bitcoin chapter before they use any of the tools.
July 2026
-
BIP (Bitcoin Improvement Proposal)
Was: The entry gave the BIP status path as Draft, then Proposed, then Final, the scheme from BIP-2, as if it were still in force.
Now: It now gives the BIP-3 statuses that replaced BIP-2 in January 2026 (Draft, Complete, Deployed and Closed) and describes the older nine-status scheme as history.
-
Bitcoin SV (BSV)
Was: The entry described nChain as Craig Wright's company, and said that in the 2018 hash war each side pointed its mining power at the other side's chain.
Now: It now describes Wright as nChain's chief scientist. It says each side poured mining power into its own chain, while Wright's camp threatened attacks on the rival chain.
-
Block Size War
Was: The entry called BIP-101 the first concrete proposal to raise the limit, though BIP-100 was assigned eleven days earlier, and it told the March 2017 BIP-148 user-activated soft fork as a response to the New York Agreement signed that May. It also said SegWit 'locked in and activated at block 481,824', although lock-in came about two weeks earlier, at block 479,808.
Now: The entry now calls BIP-101 the flagship proposal and places BIP-148 before the agreement. It says miner signaling crossed SegWit's threshold in early August 2017 and that SegWit went live at block 481,824 on August 24, 2017.
June 2026
-
Quantum and Bitcoin
Was: The chapter said 5,071,264 BTC, or 25.3 percent of circulating supply, sat at quantum-exposed addresses. It put the 9-point gap to Wicked Smart Bitcoin's independent count of 34.55 percent down to scripts that never reveal a public key.
Now: The chapter was corrected to about 30.5 percent after ChainQuery's methodology v1.1 found roughly 1.04 million BTC at reused nested-segwit (P2SH-wrapped) addresses that its first count had skipped. That cut the gap to about 4 points, and the chapter then said the remaining gap is not explained by such scripts, which hold only tens of BTC. The chapter was corrected again in September 2026 to adopt ChainQuery's v1.2 fix of June 23, 2026.
May 2026
-
The Mempool
Was: The chapter said 'the default Bitcoin Core mempool' keeps unconfirmed transactions for up to two weeks, which read as a fixed rule rather than a setting each node operator can change. Its eviction bullet also did not say what happens to the coins a dropped transaction tried to spend.
Now: It now says two weeks is Bitcoin Core's default for the -mempoolexpiry setting (336 hours) and that node operators can shorten or extend it. It also says the coins an evicted transaction tried to spend stay unspent on the chain under the sender's keys, and the transaction can be rebroadcast at a higher fee.
Source The change Caught by RetiredAvocado (Reddit)
-
Bitcoin Pizza Day
Was: The entry said 'a user in the UK' took up Laszlo Hanyecz's offer and ordered the two pizzas.
Now: It now names the buyer as Jeremy Sturdivant, known on Bitcoin Talk as jercos, and adds jercos's own account of the trade, quoted with his permission.