$NAT the second subsidy

A market-funded second subsidy for Bitcoin — $NAT.

$NAT is a Bitcoin meta-protocol token. Since block 885,588 (Feb 25 2025), every Bitcoin block automatically credits a fixed amount of NAT to that block's own coinbase address — a per-block reward decoded from the block header's bits field and auto-credited. It does not halve. The campaign frame: NAT is one proposed market answer to Bitcoin's long-term security-budget problem — a reward that miners earn on top of the block subsidy.

START HERE

The two that explain the rest

the problem, then the answer
01THE PROBLEM

Is the security-budget problem even real?

Yes — the math is not in dispute. The subsidy halves toward zero, fees are a small and volatile share of the reward, and for fees alone to replace it they would have to rise over ~100× and hold there. The people who run the industry now say it on camera.

BLOCK SUBSIDY · HALVING STAIRCASE → ~0 BY 2140
2009 2140
→ 0SUBSIDY BY ~2140
0.64%FEES TODAY, SHARE OF MINER REVENUE
~75%CLOSEST FEES EVER CAME · ONE DAY, APR 2024
ON CAMERA · 2026 — ONE OF 19 ON THE WALL
“Look at the whole security budget of Bitcoin … transaction fees were meant to compensate miners for the halving. Well, that isn't happening.”

Translation

Fred Thiel
CEO, MARA Holdings · Coin Stories · Jul 2026
▶ CLIP
SO WHAT'S THE FIX?
02THE ANSWER

What does “Bitcoin's security, tokenized” mean?

The reward is read out of Bitcoin, not bolted onto it — no fork, no custodian, no off switch. What gets tokenized is the security budget. Not the coins.

1

Security was always the product

Miners spend energy and get paid to defend the chain. Every block since 2009.

2

Tokenizing gives it a unit and a price

A token you can hold, quote, and pay for — without a fork.

3

A unit means a market

Anyone who wants Bitcoin secure can fund it — credited to the miner, every block.

SECURITY PER $1 OF MARKET CAP — NAT VS BTC · STEPS UP EVERY HALVING
12× 20× 35× 61× 110× 198× 2026 2028 2032 2036 2040 2044 2048

How it works (and how to check)

1
Read the block header's bits field as a number

Every Bitcoin block carries a 4-byte bits field (the difficulty target). Read as an integer it decodes to a NAT amount via NAT = s×2²⁴ + c — currently ~386,022,593 NAT per block.

2
That NAT is auto-credited to the block's own coinbase address

Since block 885,588, an open TAP Protocol indexer applies this rule to every block and credits the amount to the address that mined it. No claim transaction, no opt-in — the credit is computed from data already on Bitcoin.

3
It is not merged mining and nothing the miner runs

It is decoded from each block's own bits field and auto-credited to the coinbase address — not a second chain or sidechain, and nothing the miner has to run. An open TAP indexer computes it off-chain from the existing Bitcoin block data.

4
Verify it yourself

Open any recent block on mempool.space (or any explorer), take its bits value, and run the decode above. Cross-check the per-block amount and the crediting start at block 885,588 — don't take our word for it.

Estimated
NAT credited this block ~386,022,593
Cumulative since miner crediting began
tokens only · no USD, no price · verify tip

What $NAT is NOT

×Not merged mining

Miners don't point hashpower at a second chain. The reward is read from Bitcoin's own block data.

×Not a new chain, sidechain, or L2

There is no separate blockchain. NAT is an accounting layer (a meta-protocol) computed from Bitcoin itself.

×Nothing the miner has to run

No new software, no opt-in, no extra work for miners. The credit lands at the coinbase address automatically.

×Not a consensus or Bitcoin change

No fork, no BIP, no change to Bitcoin's rules. Bitcoin nodes neither know nor care that NAT exists.

×Not a claim that it "fixes" security

NAT is one market-funded experiment among several proposals — not a proven or complete solution.

×Not a dollar-denominated guarantee

NAT does not "secure $X of Bitcoin." Its security contribution is whatever miners can sell it for — and that is not guaranteed.

×Not a staking yield

Staking pays the token to holders of the token — the yield funds nothing outside itself. NAT is paid to miners for work that secures Bitcoin. Staking pays you to hold; NAT pays for security.

×Not a presale or insider allocation

First-come open mint (Nov 2023, block 817,709). No presale, no VC tranche, no team allocation, no unlock cliffs — no insider supply waiting to unlock.

Why not just wait for the price? ≈6× today → ≈200× by 2048
Why tokenize security rather than change Bitcoin — or wait for the price?
Part 1 · a higher price doesn't buy more safety
Price growth raises the budget and the prize together

A higher Bitcoin price does raise the security budget — the subsidy is paid in BTC, so doubling the price doubles what miners earn. But it doubles something else at the same moment: the value an attacker is trying to capture. Budget and prize move as one, so the ratio between them — the thing that actually decides whether an attack is affordable — barely moves. Price growth is a treadmill: you spend more defending a proportionally bigger target.

A dollar of NAT market cap moves one side only. It raises what miners earn without raising what an attack on Bitcoin would capture, because the prize is denominated in BTC, not NAT. And per dollar it moves that side harder: for every unit of market value, NAT already funds about more block security than Bitcoin does. Price sits on both sides of that fraction and cancels, so what's left is issuance over supply — protocol math, not a forecast.

And it does not stay at 6×. Bitcoin's subsidy halves every four years. NAT's emission doesn't halve at all. So the ratio steps up at every halving — about 1.8× each time — and nothing has to go right for it to happen: it's the halving schedule doing the work on one side while a formula does something far gentler on the other. (NAT's per-block amount isn't flat either: it drifts down about 1.3% a year as difficulty rises. It just never halves.) The same comparison that reads today reads about 12× after the 2028 halving and near 200× by 2048.

Security per $1 of market cap — NAT vs BTC× multiple at each halving
12×
20×
35×
61×
110×
198×
2026202820322036204020442048
Log scale. Same model as the explorable's Security per $1 readout — NAT emission held at today's difficulty, BTC subsidy on its real halving schedule; price cancels on both sides. Drag the explorable's year slider to check any point yourself.

The same arithmetic, read the other way. That multiple is issuance over supply on both sides — so it is also NAT's dilution rate measured against Bitcoin's. NAT issues about 5.2% of its supply a year; Bitcoin issues about 0.8%. Six times the security funding per dollar is the same fact as six times the supply growth, and a holder pays for the first with the second. We would rather state that than have it found: it is the honest price of an emission that never halves, and it is why the open question in the risks below is demand — never issuance.

Part 2 · a market needs nobody's permission
Consensus changes are one-shot and permanent. A market is continuous and revisable.

Every other fix on the board runs through Bitcoin's consensus. A tail emission breaks the 21M cap and needs a fork. A fee-market redesign needs one too. Those are all-or-nothing decisions: they require near-universal agreement, they take years of political fighting, and if the answer turns out to be wrong it is written into the protocol.

A market is the opposite shape. No vote, no BIP, nobody's agreement — anyone who wants Bitcoin defended can fund it today, at any size, and stop whenever they like. It is continuous where a fork is one-shot, revisable where a fork is permanent, and it can be tried now rather than after a decade of debate. And if it fails, it fails on its own balance sheet: Bitcoin is left exactly as it was, because nothing was ever added to it.

There is a harder difference than governance, though. The fee-side proposals — smaller blocks, fee smoothing, blockspace redesign — all change how fee income arrives. None of them adds a satoshi to what miners are paid. Three ways to manage thin fees; zero ways to make more. A market is the only option on the board that can put new revenue into the budget instead of rearranging the revenue already there.

One thing that board doesn't ask. Its six non-negotiables are all harm-avoidance tests — no fork, no dilution of BTC, market-funded, decentralization-safe, no UX cost, available today. None of them asks whether a fix raises enough. NAT is the only all-green row because it is the only harmless one, not because it is proven sufficient. Which is what the bound below is about.

The honest bound: a consensus change, if it ever passed, would be guaranteed funding. A market's funding is voluntary, so it may deliver very little. And the scale required is large — the section below puts a number on it, and that number is orders of magnitude from here. $NAT is a bounded supplement, not a fix. The trade is guaranteed-but-unattainable against attainable-but-uncertain, and our judgement is that an uncertain fix you can actually try beats a certain one that never ships. A judgement, not a proof.
How much of the gap can this fill? $52M a year at $1B · ~$54.3B to close today's gap
How much of Bitcoin's security gap could NAT actually fill?
Part 1 · the gap, and where the floor comes from
Bitcoin's security has a price, and it currently falls short of the floor

Miner revenue is a flow; what it protects is a stock. So the honest way to ask whether Bitcoin pays enough for its own security is to put one over the other: annualised miner revenue over market capitalisation. Today that is about 0.82%. The ratio is a proxy for the thing that actually matters — the flow an attacker must out-spend, against the stock they could capture (Budish, 2018). If you would rather run cost-to-attack directly, the 51% questions below do it that way.

One percent is not this page's number. It sits inside the range published by the people who use this ratio. Lyn Alden puts a healthy security spend at 0.5%–1.5% of market cap a year. James McAvity put it at 1–1.5% as of October 2023. Hasu defined the ratio in exactly these terms on stage in 2020 — “the ratio of this block reward and the network value” — and measured it at 2% at the time.

They do not agree on where the floor belongs, and one of them says so outright: “there clearly is a Goldilocks zone somewhere, but we really don't know where it is.” What is not in dispute is the measurement or the direction. So treat one percent as a heuristic inside that spread rather than a derived threshold — which is why Part 4 is the part that matters: it needs no floor at all.

The difference between what Bitcoin pays and one percent is $2.82B a year. About $7.7M a day, roughly $53,742 a block. That is the gap, and everything below is about how much of it a market-funded reward could fill — check the ratio yourself, annualised miner revenue over market cap, both public.

Move the floor and every number below moves with it. At the bottom of Alden's band, 0.5%, there is no gap today at all. There is one from ~April 2028 — see Part 4, which is the part of this that does not depend on picking a floor.

Part 2 · it is a dial, not a threshold
Every dollar of market cap fills part of the gap. There is no threshold it has to cross first.

This is the part most people get backwards, so it is worth saying plainly: NAT is not waiting to reach some size before it counts. It is credited on every block today, and just over half of pool hashrate moves it — what it contributes is already real, small but real, and it arrives whether or not anyone believes the rest of this page.

NAT issues about 5.2% of its supply a year to miners — the same 5.2% as the dilution figure in the section above, so at any price it is 5.2% of its market capitalisation reaching miners. That makes coverage arithmetic rather than rhetoric, and it makes it linear: double the market cap, double the share of the gap it fills. No cliff, no minimum viable size. It is a dial, and it is already turning.

What a given market cap credits to Bitcoin's minersshare of the $2.82B/yr gap it fills
NAT market cap
Credits miners (at market)
Fills
$29.9M today
$1.6M / yr
0.055%
$500M
$26M / yr
0.92%
$1B
$52M / yr
1.8%
$5B
$260M / yr
9.2%
$10B
$520M / yr
18.4%
$25B
$1.3B / yr
46.0%
$54.3B
$2.8B / yr
100%
Coverage = market cap × 5.2% ÷ the $2.82B/yr gap. Not a forecast and not a target — a conversion between two market capitalisations, which is the only thing this arithmetic can honestly produce. Credited to every block's miner; today just over half of pool hashrate actually moves it, so realised payout is a little over half this ladder until adoption rises. And these are credits valued at the market price: every dollar on this ladder has to be bought by someone, every year. Basis: the last 1,008 blocks annualised at spot. On a trailing-year basis the gap is $1.58B–$2.17B and the top of the ladder $30B–$42B; all three are set out below this section, and none of them closes the gap. Figures as of 2026-09-06; they move with the next pull.

Read the middle of that table rather than the bottom. At $1B — the milestone the public conversation keeps naming — NAT would credit Bitcoin's miners about $52M a year, roughly 1.8% of the gap and a little over half of the yearly average Bitcoin earns in fees. That is not a solution. It is also not nothing, and “not nothing, arriving every block, costing Bitcoin no change at all” is the entire claim.

The denominators, since a table of dollars is worthless without them: 5.2% is about 20.3T NAT issued a year against roughly 390T circulating, and today's $29.9M is a last-trade mark on a thin market — not a bid you could hit for $29.9M.

Part 3 · the gap is not a fixed number
Fees and a market-funded reward are not rivals. Whatever fees do, NAT's job gets smaller.

Everything above assumed fees stay where they are, at 0.64% of miner revenue. They have not always been there. Bitcoin has recorded much higher fee months, and in every one of them the gap was smaller — so the market capitalisation that would fill it was smaller too. Each row below is a fee share Bitcoin has actually recorded, held flat in dollars, with nothing forecast.

If fees were at a level Bitcoin has already reachedthe gap today, and what would fill it
Fee share of miner revenue
The gap today
NAT cap to fill it
0.64% today
$2.82B / yr
$54.3B
17.92% Runes month, May 2024
$61.5M / yr
$1.2B
21.24% January 2024
closed
26.19% January 2018, the record
closed
Each row asks what the gap would be today if fees had held at that level, with the subsidy at today’s 3.125 BTC and price and market cap at spot. The post-halving figures are in Part 4, not here. “Closed” means fees at that level would cover the whole 1% floor on their own. Holding fee dollars flat is the reading kinder to fees; holding the fee share flat would halve them alongside the subsidy. A fee level above anything Bitcoin has recorded would change this table, and nothing here says that cannot happen.

The middle row is the one to sit with. May 2024 was not a thought experiment — Runes pushed fees to 17.92% of miner revenue for a month. At that level the gap is $61.5M a year instead of $2.82B, and the market capitalisation that would fill the remainder is $1.2B. The same $1B that fills 1.8% of today's gap covers 85% of that one.

Two of those months were inscription waves that much of Bitcoin calls spam, and all three came with fees that priced ordinary users out — which is rather the point. The only times fees have closed the gap, they did it by making Bitcoin worse to use.

That is the honest relationship, and it runs the opposite way to how this argument is usually staged. A market-funded reward is not competing with the fee market; it is what covers the shortfall while the fee market is not delivering. If fees arrive, NAT's number collapses. If they do not, the shortfall is left to market-funded rewards. Neither has to be right for the other to help.

Part 4 · the part that does not depend on picking a floor
In ~April 2028 Bitcoin's ratio falls below every published band — and no price assumption enters

Everything up to here rests on two choices: a 1% floor and one way of measuring the ratio. This does not. Today's 0.82% splits into a subsidy component that halves on schedule and a fee component that does not. That fee component is held flat against market cap at spot, the same convention the table above uses, so the two parts are on one footing. Run the arithmetic and Bitcoin's ratio lands at 0.41% after the ~April 2028 halving — below the 0.5% bottom of Alden's band, and below any floor anyone has published. No price forecast enters that calculation, because price is in the numerator and the denominator and cancels. It is the halving schedule and nothing else.

Hasu ran this arithmetic on stage in 2020, when the ratio was just under 2%: “in four years it could be below 1%… in eight years it will be below half a percent.” Eight years from that talk is 2028, and 0.41% is where this page's own figures land. His own answer to it was that Bitcoin must grow a fee market, not that it should look elsewhere. The descent is his; the conclusion drawn from it here is not. Keep going and the ratio reaches 0.21% after the ~2032 halving, then 0.11% — the two levels McAvity named as the point where “it's just a different system. It's a different protocol.”

That is the strongest claim on this page, and it has nothing to do with NAT. It is also why the fee scenarios above do not settle the question: take January 2018, the best fee month in Bitcoin's history at 26.2% of miner revenue — a level that closes the gap outright today — hold it forever, and after 2028 the shortfall is still $4.80B a year, needing a NAT capitalisation of about $92B. (The Dec 2017 peak day was higher still; a day is not a budget.)

Two figures sit behind that. Fees at January 2018's 26.2%, held flat in dollars, leave the $92B above; fees at today's 0.64%, held the same way, need $180B. Both understate it deliberately, because both hold NAT's emission at today's 5.2% of supply while the rate falls as supply grows, to about 4.8% by 2028. Corrected for that taper they are nearer $100B and $195B.

Fees alone would need to reach about 18% of miner revenue permanently to close today's gap to 1% — roughly 28x today's level. (That is a different question from replacing the subsidy outright, which is the ~100× figure elsewhere on this page.) Bitcoin's longest stretch above 20% is 40 days. Changing consensus or ending the 21 million cap would work too, and both cost Bitcoin something it cannot spend. This arithmetic is not NAT's, either: any asset credited to the block's miner can be sized the same way. What differs is what each one asks of the miner and of Bitcoin.

The honest bound. This page quotes what the gap costs and what a given market capitalisation would cover. The one figure here that is NAT’s own, today’s $29.9M, is a last trade on a thin market, reported so the ladder has a floor you can check, not offered as a valuation. Nothing here forecasts that NAT reaches any figure on it, and none of this is a price target — it is arithmetic about Bitcoin's security budget, not a claim about a token's future. The circularity is real: a market-funded reward is worth what a market says, and that market's interest depends on the very security it is meant to fund. There is no proof here that resolves it. What there is: a gap nobody disputes, a dial that is already turning, and one option that can fail without taking anything with it.

Why it might matter

Bitcoin pays for its security with the block subsidy (currently 3.125 BTC/block), which halves roughly every four years toward ~0 by about 2140. The intended replacement is transaction fees — but today fees are only about 0.64% of miner revenue and are volatile and unreliable. That long-run gap is the security-budget problem. The gap itself is not in dispute; what is open is which fix closes it.

$NAT is one market-funded answer: a perpetual, non-halving reward that miners earn alongside the subsidy, paid for by whoever values NAT in the market. It sits alongside other proposals — not instead of them. These are competing and complementary ideas, and none has a monopoly on the answer:

Higher transaction fees Tail emission Merged mining Other external rewards $NAT (a market-funded reward)

Whether any of these — including NAT — meaningfully closes the gap is unproven. NAT's case is that a market is already willing to pay miners something extra, today, with no change to Bitcoin.

The security-budget fix menu — the full board

Every proposed fix, graded on six non-negotiables, with the reasoning under every mark. This is the same board embedded in the one-pager — opened alone, at full width, in your selected language.

← Back to the one-pager / FAQ

The Security-Budget Fix Menu

The NATpaper weighs the failing fee-reliance status quo against the fixes it surveys — on-chain scaling, a consensus switch, monetary-policy changes like tail emission — plus the nation-state “who foots the bill” scenario. Each is graded on six non-negotiables. A fix has to clear all six to work without changing what Bitcoin is. Only one row is green all the way across.

Proposed fix No hard fork? No holder dilution? $Market-funded? Preserves decentralization? Preserves user experience? Available today? Worst case
Fee-Reliancethe failing status quo — not a fix no protocol change no new issuance fees are bid & paid by the market no central operator high fees → congestion; prices out small txns & mints already here & failing — fees <1% of rewards Bitcoinsecurity budget slowly bleeds
On-chain Scalingbigger / faster blocks → stronger fee market block-size / block-time limits → hard fork no new issuance still market-paid fees ~bigger blocks raise node costs → centralizes more capacity → lower fees, less congestion contentious, not deployed Bitcoinprotocol permanently changed
Consensus ShiftPoW → PoS or PoA replaces consensus → hardest fork PoS staking rewards = new issuance → dilutes stake / authority, not a market subsidy paper: raises centralization & trust concerns new security model → erodes store-of-value trust not deployed on Bitcoin Bitcoinno longer Bitcoin
Tail Emissionmonetary-policy bucket — also demurrage / burn-dormant breaks 21M cap · needs fork prints new BTC → dilutes protocol-minted, not market ~keeps miners, alters issuance breaks the 21M cap → erodes store-of-value trust not deployed Bitcointhe 21M cap is broken
Nation-State Subsidy“who foots the bill” — a government funds security no protocol change no new issuance state-funded, not market a state controls hashrate state-funded security → erodes store-of-value trust ~plausible, not committed Bitcoincaptured by a state
NATall ✓market-priced second subsidy no fork · uses existing consensus 21M cap untouched priced & paid by the market pay-per-block · no controller scales infinitely · no fee pressure on users live since block 885,588 $NATjust doesn’t go up — Bitcoin untouched
 meets the requirement
 fails the requirement
~ partial / conditional
 not applicable

Why NAT is the only all-green row

Every alternative the paper surveys fails at least one non-negotiable.

  • Fee-reliance is the failing baseline, not a fix — it's already here, with fees under 1% of miner rewards.
  • On-chain scaling (bigger / faster blocks) needs a consensus-rule hard fork and pushes node costs up, squeezing decentralization.
  • A consensus shift to PoS or PoA is the most contentious fork of all; the paper says it “raises centralization and trust concerns,” and its PoS staking rewards are new issuance that dilutes holders.
  • Tail emission — standing in for the whole monetary-policy bucket (demurrage, burning dormant coins) — breaks the 21M cap and dilutes holders.
  • A nation-state subsidy answers “who foots the bill” by trading the funding problem for a control problem: it isn't market-funded and it kills decentralization.
  • NAT alone is no-fork, dilutes no holders, market-funded, preserves decentralization (pay-per-block, no central operator), and scales with no fee pressure on users — already live since block 885,588.
The non-negotiables: the 21M supply cap (tail emission breaks it → requires a hard fork); funding that comes from the market, not a state; preserved decentralization (no single controller of hashrate); and a fix that exists today, not in proposal form.  ·  NAT is no-fork, market-funded, and live (since block 885,588, Feb 2025).  ·  Sources: NATpaper — the alternatives it surveys (on-chain scaling enhancements; consensus shifts to PoS / PoA; monetary-policy alterations: tail emission, demurrage, burning dormant coins) plus the nation-state “who foots the bill” scenario and the failing fee-reliance status quo, vs. the NAT it proposes.
Cell judgments are an editorial reading of the paper's argument for this concept mock.

安全预算修复方案菜单

NAT 白皮书将正在失败的“依赖手续费”现状,与它考察的各种修复方案逐一权衡——链上扩容、共识切换、诸如尾部发行的货币政策变更——再加上国家级“谁来买单”的情景。每项都按六条不可让步的标准评分。一个方案必须六项全过,才能在不改变比特币本质的前提下奏效。只有一行从头到尾全绿。

提议方案 无需硬分叉? 不稀释持有者? $市场资助? 保全去中心化? 保全用户体验? 当前可用? 最坏情况
依赖手续费正在失败的现状——并非修复方案 无协议变更 无新增发行 手续费由市场竞价并支付 无中央运营者 高手续费 → 拥堵;挤出小额交易与铸造 已在此且正在失败——手续费 <1% 的奖励 比特币安全预算缓慢失血
链上扩容更大 / 更快的区块 → 更强的手续费市场 区块大小 / 出块时间限制 → 硬分叉 无新增发行 仍是市场支付的手续费 ~更大的区块抬高节点成本 → 趋于中心化 更多容量 → 更低手续费、更少拥堵 存在争议,尚未部署 比特币协议被永久改变
共识切换PoW → PoS 或 PoA 替换共识 → 最艰难的分叉 PoS 质押奖励 = 新增发行 → 稀释 质押 / 权威,而非市场补贴 论文:引发中心化与信任顾虑 新的安全模型 → 侵蚀价值存储信任 未在比特币上部署 比特币不再是比特币
尾部发行货币政策类——亦含滞币费 / 销毁休眠币 突破 21M 上限 · 需要分叉 印发新 BTC → 稀释 协议铸造,而非市场 ~保留矿工,但改变发行 突破 21M 上限 → 侵蚀价值存储信任 尚未部署 比特币21M 上限被打破
国家级补贴“谁来买单”——由政府出资保障安全 无协议变更 无新增发行 国家出资,而非市场 由国家控制算力 国家出资的安全 → 侵蚀价值存储信任 ~看似可行,但未作承诺 比特币被国家俘获
NAT全 ✓按市场定价的“第二补贴” 无分叉 · 沿用现有共识 21M 上限不受触动 由市场定价并支付 按区块支付 · 无控制者 无限扩展 · 不向用户施加手续费压力 自区块 885,588 起已上线 $NAT只是不上涨 — 比特币毫发无损
 满足要求
 不满足要求
~ 部分 / 有条件
 不适用

为何只有 NAT 这一行全绿

论文考察的每个备选方案都至少在一条不可让步的标准上失败。

  • 依赖手续费正在失败的基线,并非修复方案——它已身处此地,手续费不足矿工奖励的 1%
  • 链上扩容(更大 / 更快的区块)需要一次共识规则硬分叉,并推高节点成本,挤压去中心化。
  • 共识切换至 PoS 或 PoA 是其中争议最大的一次分叉,且如论文所言,“引发中心化与信任顾虑”;其 PoS 质押奖励属于新增发行,会稀释持有者
  • 尾部发行——代表整个货币政策类(滞币费、销毁休眠币)——突破 21M 上限并稀释持有者。
  • 国家级补贴对“谁来买单”作出的回答,是用一个控制问题换掉了出资问题:它并非由市场资助,而且会扼杀去中心化
  • 唯有 NAT 无需分叉、不稀释任何持有者、由市场资助、保全去中心化(按区块支付,无中央运营者),无限扩展且不向用户施加手续费压力,且已经上线——自区块 885,588起运行。
不可让步的几条:21M 供应上限(尾部发行会突破它 → 需要硬分叉);来自市场而非国家的出资;保全的去中心化(无单一算力控制者);以及一个当前就存在、而非停留在提案阶段的修复方案。  ·  NAT 无需分叉、由市场资助、已上线(自区块 885,588,2025 年 2 月起)。  ·  数据来源:NAT 白皮书——它考察的备选方案(链上扩容增强;共识切换至 PoS / PoA;货币政策变更:尾部发行、滞币费、销毁休眠币)加上国家级“谁来买单”情景与正在失败的“依赖手续费”现状,对比它所提议的 NAT。
各单元格的判定,是为本概念示意图对该论文论点所作的编辑性解读。

セキュリティ予算の解決策メニュー

NAT ホワイトペーパーは、失敗しつつある「手数料依存」の現状を、そこで検討される解決策——オンチェーンスケーリング、コンセンサスの切り替え、テールエミッションのような通貨政策の変更——さらに国家による「誰が費用を負担するのか」のシナリオと一つずつ比較します。それぞれが六つの譲れない基準で採点されます。ある解決策がビットコインの本質を変えずに機能するには、六つすべてを満たさなければなりません。最初から最後まで緑である行はただ一つだけです。

提案された解決策 ハードフォーク不要? 保有者の希釈なし? $市場が資金負担? 分散性を維持? ユーザー体験を維持? 現在利用可能? 最悪の場合
手数料依存失敗しつつある現状——解決策ではない プロトコル変更なし 新規発行なし 手数料は市場が入札して支払う 中央運営者なし 高い手数料 → 混雑;少額取引や発行を締め出す すでにここにあり失敗中——手数料は報酬の <1% ビットコインセキュリティ予算がじわじわ出血
オンチェーンスケーリングより大きい / 速いブロック → より強い手数料市場 ブロックサイズ / ブロック時間の制限 → ハードフォーク 新規発行なし 依然として市場が払う手数料 ~より大きいブロックはノード費用を上げる → 中央集権化 容量増 → 手数料低下、混雑減少 論争的で、未導入 ビットコインプロトコルが恒久的に変わる
コンセンサスの切り替えPoW → PoS または PoA コンセンサスを置き換える → 最も困難なフォーク PoS のステーキング報酬 = 新規発行 → 希釈 ステーク / 権威であり、市場の補助金ではない 論文:中央集権化と信頼の懸念を高める 新たな安全モデル → 価値保存の信頼を損なう ビットコインに未導入 ビットコインもはやビットコインではない
テールエミッション通貨政策の枠——デマレッジ / 休眠コイン焼却も含む 21M 上限を破る · フォークが必要 新規 BTC を発行 → 希釈 プロトコルが発行、市場ではない ~マイナーは保つが発行を変える 21M 上限を破る → 価値保存の信頼を損なう 未導入 ビットコイン21M 上限が壊れる
国家による補助金「誰が費用を負担するのか」——政府がセキュリティに資金を出す プロトコル変更なし 新規発行なし 国家が資金を出す、市場ではない 国家がハッシュレートを支配 国家が資金を出す安全 → 価値保存の信頼を損なう ~もっともらしいが、確約されていない ビットコイン国家に捕捉される
NATすべて ✓市場価格が付く第二の補助金 フォークなし · 既存のコンセンサスを使用 21M 上限は不変 市場が価格を付け支払う ブロックごとに支払い · 支配者なし 無限に拡張 · ユーザーへの手数料圧力なし ブロック 885,588 から稼働中 $NATただ上がらないだけ — ビットコインは無傷
 要件を満たす
 要件を満たさない
~ 部分的 / 条件付き
 該当なし

なぜ NAT だけが全行緑の唯一の行なのか

論文が検討する代替案はいずれも、譲れない基準の少なくとも一つで失敗します。

  • 手数料依存失敗しつつあるベースラインであって解決策ではありません——すでにここにあり、手数料はマイナー報酬の 1% 未満です。
  • オンチェーンスケーリング(より大きい / 速いブロック)はコンセンサスルールのハードフォークを必要とし、ノード費用を押し上げて分散性を圧迫します。
  • PoS や PoA へのコンセンサスの切り替えはその中で最も論争的なフォークであり、論文の言葉を借りれば「中央集権化と信頼の懸念を高め」、さらにその PoS のステーキング報酬は新規発行であって保有者を希釈します
  • テールエミッション——通貨政策の枠全体(デマレッジ、休眠コインの焼却)を代表する——は 21M 上限を破り、保有者を希釈します。
  • 国家による補助金は「誰が費用を負担するのか」に答える一方で、資金の問題を支配の問題に置き換えます:市場が資金を負担せず、分散性を殺します
  • NAT だけが、フォークなし、いかなる保有者も希釈せず、市場が資金を負担し、分散性を維持し(ブロックごとに支払い、中央運営者なし)、無限に拡張しユーザーへの手数料圧力もなく、すでに稼働中です——ブロック 885,588から運行しています。
譲れない条件: 21M の供給上限(テールエミッションはこれを破る → ハードフォークが必要);国家ではなく市場から来る資金;維持された分散性(単一のハッシュレート支配者なし);そして提案段階ではなく現在存在する解決策。  ·  NAT はフォークなし、市場が資金負担、稼働中ブロック 885,588、2025 年 2 月から)。  ·  出典:NAT ホワイトペーパー——そこで検討される代替案(オンチェーンスケーリングの強化;PoS / PoA へのコンセンサス切り替え;通貨政策の変更:テールエミッション、デマレッジ、休眠コインの焼却)に加え、国家による「誰が費用を負担するのか」のシナリオと失敗しつつある「手数料依存」の現状を、そこで提案される NAT と対比。
各セルの判定は、このコンセプトモックのために論文の論旨を編集上解釈したものです。

보안 예산 해결책 메뉴

NAT 백서는 실패하고 있는 "수수료 의존" 현상을, 그것이 검토하는 해결책들 — 온체인 확장, 합의 전환, 테일 이미션 같은 통화정책 변경 — 그리고 국가 차원의 "누가 비용을 내는가" 시나리오와 하나씩 견줍니다. 각각은 여섯 가지 양보 불가 기준으로 채점됩니다. 어떤 해결책이든 비트코인의 본질을 바꾸지 않고 작동하려면 여섯 가지 모두를 통과해야 합니다. 처음부터 끝까지 초록인 행은 단 하나뿐입니다.

제안된 해결책 하드포크 불필요? 보유자 희석 없음? $시장 자금? 탈중앙화 보전? 사용자 경험 보전? 현재 이용 가능? 최악의 경우
수수료 의존실패하고 있는 현상 — 해결책이 아님 프로토콜 변경 없음 신규 발행 없음 수수료는 시장이 입찰해 지불 중앙 운영자 없음 높은 수수료 → 혼잡; 소액 거래와 발행을 밀어냄 이미 여기 있고 실패 중 — 수수료가 보상의 <1% 비트코인보안 예산이 서서히 출혈
온체인 확장더 크고 / 빠른 블록 → 더 강한 수수료 시장 블록 크기 / 블록 시간 제한 → 하드포크 신규 발행 없음 여전히 시장이 내는 수수료 ~더 큰 블록은 노드 비용을 높임 → 중앙화 용량 증가 → 낮은 수수료, 혼잡 감소 논쟁적이며 미배포 비트코인프로토콜이 영구히 변경됨
합의 전환PoW → PoS 또는 PoA 합의를 교체 → 가장 어려운 포크 PoS 스테이킹 보상 = 신규 발행 → 희석 지분 / 권위, 시장 보조금이 아님 백서: 중앙화와 신뢰 우려를 키움 새로운 보안 모델 → 가치 저장 신뢰를 약화 비트코인에 미배포 비트코인더 이상 비트코인이 아님
테일 이미션통화정책 범주 — 디머리지 / 휴면 코인 소각 포함 21M 한도를 깸 · 포크 필요 신규 BTC 발행 → 희석 프로토콜이 발행, 시장이 아님 ~마이너는 유지하되 발행을 바꿈 21M 한도를 깸 → 가치 저장 신뢰를 약화 미배포 비트코인21M 한도가 깨짐
국가 차원의 보조금"누가 비용을 내는가" — 정부가 보안에 자금을 댐 프로토콜 변경 없음 신규 발행 없음 국가가 자금을 댐, 시장이 아님 국가가 해시파워를 통제 국가가 자금을 댄 보안 → 가치 저장 신뢰를 약화 ~그럴듯하나 확약되지 않음 비트코인국가에 포획됨
NAT전부 ✓시장 가격이 매겨지는 두 번째 보조금 포크 없음 · 기존 합의를 사용 21M 한도 그대로 시장이 가격을 매기고 지불 블록당 지불 · 통제자 없음 무한히 확장 · 사용자에게 수수료 압박 없음 블록 885,588부터 가동 중 $NAT그저 오르지 않을 뿐 — 비트코인은 그대로
 요건 충족
 요건 미충족
~ 부분 / 조건부
 해당 없음

NAT만 전부 초록인 유일한 행인가

백서가 검토하는 모든 대안은 양보 불가 기준 중 적어도 하나에서 실패합니다.

  • 수수료 의존실패하고 있는 기준선이지 해결책이 아닙니다 — 이미 여기 있고, 수수료는 마이너 보상의 1% 미만입니다.
  • 온체인 확장(더 크고 / 빠른 블록)은 합의 규칙 하드포크가 필요하며 노드 비용을 끌어올려 탈중앙화를 압박합니다.
  • PoS나 PoA로의 합의 전환은 그중 가장 논쟁적인 포크이며, 백서의 표현대로 “중앙화와 신뢰 우려를 키우는” 데다, 그 PoS 스테이킹 보상은 신규 발행이어서 보유자를 희석합니다.
  • 테일 이미션 — 통화정책 범주 전체(디머리지, 휴면 코인 소각)를 대표하는 — 은 21M 한도를 깨고 보유자를 희석합니다.
  • 국가 차원의 보조금은 “누가 비용을 내는가”에 답하면서 자금 문제를 통제 문제로 맞바꿉니다: 시장이 자금을 대지 않으며 탈중앙화를 죽입니다.
  • 오직 NAT만이 포크가 없고, 어떤 보유자도 희석하지 않으며, 시장이 자금을 대고, 탈중앙화를 보전하며(블록당 지불, 중앙 운영자 없음), 무한히 확장하고 사용자에게 수수료 압박을 주지 않으며, 이미 가동 중입니다 — 블록 885,588부터 운행하고 있습니다.
양보 불가 항목: 21M 공급 한도(테일 이미션은 이를 깸 → 하드포크 필요). 국가가 아니라 시장에서 나오는 자금. 보전된 탈중앙화(단일 해시파워 통제자 없음). 그리고 제안 단계가 아니라 현재 존재하는 해결책.  ·  NAT는 포크 없음, 시장 자금, 가동 중(블록 885,588, 2025년 2월부터).  ·  출처: NAT 백서 — 그것이 검토하는 대안들(온체인 확장 강화, PoS / PoA로의 합의 전환, 통화정책 변경: 테일 이미션, 디머리지, 휴면 코인 소각)과 국가 차원의 "누가 비용을 내는가" 시나리오 및 실패하고 있는 "수수료 의존" 현상을, 그것이 제안하는 NAT와 대비.
각 셀의 판정은 이 콘셉트 목업을 위해 백서의 논거를 편집상 해석한 것입니다.

Das Lösungsmenü für das Sicherheitsbudget

Das NATpaper wägt den scheiternden Status quo der Gebührenabhängigkeit gegen die Lösungen ab, die es untersucht — On-Chain-Skalierung, einen Konsenswechsel, geldpolitische Änderungen wie Tail Emission (dauerhafte Restemission) — dazu das Nationalstaaten-Szenario „wer zahlt die Rechnung“. Jede wird an sechs nicht verhandelbaren Kriterien gemessen. Eine Lösung muss alle sechs bestehen, um zu funktionieren, ohne zu verändern, was Bitcoin ist. Nur eine einzige Zeile ist durchgehend grün.

Vorgeschlagene Lösung Kein Hard Fork? Keine Verwässerung der Halter? $Marktfinanziert? Erhält die Dezentralisierung? Erhält die Nutzererfahrung? Heute verfügbar? Schlimmster Fall
Gebührenabhängigkeitder scheiternde Status quo — keine Lösung keine Protokolländerung keine neue Emission Gebühren werden vom Markt geboten und gezahlt kein zentraler Betreiber hohe Gebühren → Überlastung; preist kleine Transaktionen und Mints aus schon da und scheitert — Gebühren <1% der Belohnung BitcoinSicherheitsbudget blutet langsam aus
On-Chain-Skalierunggrößere / schnellere Blöcke → stärkerer Gebührenmarkt Blockgrößen- / Blockzeit-Limits → Hard Fork keine neue Emission weiterhin vom Markt gezahlte Gebühren ~größere Blöcke erhöhen die Node-Kosten → zentralisiert mehr Kapazität → niedrigere Gebühren, weniger Überlastung umstritten, nicht ausgerollt BitcoinProtokoll dauerhaft verändert
KonsenswechselPoW → PoS oder PoA ersetzt den Konsens → härtester Fork PoS-Staking-Belohnungen = neue Emission → verwässert Stake / Autorität, keine Marktsubvention Paper: wirft Zentralisierungs- und Vertrauensbedenken auf neues Sicherheitsmodell → untergräbt das Vertrauen als Wertspeicher auf Bitcoin nicht ausgerollt Bitcoinist nicht mehr Bitcoin
Tail Emissiongeldpolitische Kategorie — auch Demurrage / Verbrennen ruhender Coins bricht die 21M-Obergrenze · braucht einen Fork druckt neue BTC → verwässert vom Protokoll geprägt, nicht vom Markt ~hält die Miner, verändert die Emission bricht die 21M-Obergrenze → untergräbt das Vertrauen als Wertspeicher nicht ausgerollt Bitcoindie 21M-Obergrenze ist gebrochen
Staatliche Subvention„wer zahlt die Rechnung“ — ein Staat finanziert die Sicherheit keine Protokolländerung keine neue Emission staatlich finanziert, nicht vom Markt ein Staat kontrolliert die Hashrate staatlich finanzierte Sicherheit → untergräbt das Vertrauen als Wertspeicher ~plausibel, aber nicht zugesagt Bitcoinvon einem Staat vereinnahmt
NATalle ✓vom Markt bepreiste zweite Subvention kein Fork · nutzt den bestehenden Konsens 21M-Obergrenze unangetastet vom Markt bepreist und gezahlt Zahlung pro Block · kein Kontrolleur skaliert unbegrenzt · kein Gebührendruck auf Nutzer live seit Block 885,588 $NATsteigt einfach nicht — Bitcoin unangetastet
 erfüllt die Anforderung
 erfüllt die Anforderung nicht
~ teilweise / bedingt
 nicht zutreffend

Warum NAT die einzige durchgehend grüne Zeile ist

Jede Alternative, die das Paper untersucht, scheitert an mindestens einem nicht verhandelbaren Kriterium.

  • Gebührenabhängigkeit ist die scheiternde Basislinie, keine Lösung — sie ist schon da, mit Gebühren unter 1% der Miner-Belohnung.
  • On-Chain-Skalierung (größere / schnellere Blöcke) braucht einen Hard Fork der Konsensregeln und treibt die Node-Kosten hoch, was die Dezentralisierung unter Druck setzt.
  • Ein Konsenswechsel zu PoS oder PoA ist der umstrittenste Fork von allen; das Paper sagt, er „wirft Zentralisierungs- und Vertrauensbedenken auf“, und seine PoS-Staking-Belohnungen sind neue Emission, die Halter verwässert.
  • Tail Emission — stellvertretend für die gesamte geldpolitische Kategorie (Demurrage, Verbrennen ruhender Coins) — bricht die 21M-Obergrenze und verwässert Halter.
  • Eine staatliche Subvention beantwortet „wer zahlt die Rechnung“, indem sie das Finanzierungsproblem gegen ein Kontrollproblem tauscht: sie ist nicht marktfinanziert und sie tötet die Dezentralisierung.
  • NAT allein kommt ohne Fork aus, verwässert keine Halter, ist marktfinanziert, erhält die Dezentralisierung (Zahlung pro Block, kein zentraler Betreiber) und skaliert ohne Gebührendruck auf Nutzer — bereits live seit Block 885,588.
Die nicht verhandelbaren Kriterien: die 21M-Angebotsobergrenze (Tail Emission bricht sie → erfordert einen Hard Fork); Finanzierung, die vom Markt kommt, nicht von einem Staat; erhaltene Dezentralisierung (kein einzelner Kontrolleur der Hashrate); und eine Lösung, die es heute gibt, nicht nur als Vorschlag.  ·  NAT ist fork-frei, marktfinanziert und live (seit Block 885,588, Feb 2025).  ·  Quellen: NATpaper — die Alternativen, die es untersucht (Verbesserungen der On-Chain-Skalierung; Konsenswechsel zu PoS / PoA; geldpolitische Änderungen: Tail Emission, Demurrage, Verbrennen ruhender Coins) plus das Nationalstaaten-Szenario „wer zahlt die Rechnung“ und der scheiternde Status quo der Gebührenabhängigkeit, gegenüber dem NAT, das es vorschlägt.
Die Zellbewertungen sind eine redaktionelle Lesart der Argumentation des Papers für diesen Konzeptentwurf.

Меню решений для бюджета безопасности

NATpaper сопоставляет нынешнюю опору на комиссии, которая не работает, с решениями, которые он рассматривает — ончейн-масштабирование, смена консенсуса, изменения монетарной политики вроде хвостовой эмиссии (tail emission), — плюс государственный сценарий «кто оплатит счет». Каждое оценивается по шести безусловным требованиям. Чтобы решение сработало, не меняя сути биткоина, оно должно пройти все шесть. Зеленая от начала до конца только одна строка.

Предлагаемое решение Без хардфорка? Без размытия держателей? $Финансируется рынком? Сохраняет децентрализацию? Сохраняет пользовательский опыт? Доступно сейчас? Худший случай
Опора на комиссиистатус-кво, которое не работает, — не решение без изменений протокола без новой эмиссии рынок назначает и платит комиссии нет центрального оператора высокие комиссии → перегрузка; цена вытесняет мелкие транзакции и минты уже здесь и не работает — комиссии <1% вознаграждения Биткоинбюджет безопасности медленно истекает кровью
Ончейн-масштабированиеболее крупные / быстрые блоки → более сильный рынок комиссий лимиты размера блока / времени блока → хардфорк без новой эмиссии по-прежнему комиссии, оплачиваемые рынком ~более крупные блоки поднимают расходы на ноды → централизация больше пропускной способности → ниже комиссии, меньше перегрузок спорно, не внедрено Биткоинпротокол изменен навсегда
Смена консенсусаPoW → PoS или PoA заменяет консенсус → самый жесткий форк вознаграждения за стейкинг в PoS = новая эмиссия → размытие стейк / полномочия, а не рыночная субсидия NATpaper: опасения по поводу централизации и доверия новая модель безопасности → подрывает доверие к статусу средства сбережения не внедрено в биткоине Биткоинбольше не биткоин
Хвостовая эмиссиякатегория монетарной политики — также демередж / сжигание спящих монет ломает лимит 21M · нужен форк печатает новые BTC → размытие выпускается протоколом, а не рынком ~удерживает майнеров, но меняет эмиссию ломает лимит 21M → подрывает доверие к статусу средства сбережения не внедрено Биткоинлимит 21M сломан
Государственная субсидия«кто оплатит счет» — государство финансирует безопасность без изменений протокола без новой эмиссии финансируется государством, а не рынком государство контролирует хешрейт безопасность за счет государства → подрывает доверие к статусу средства сбережения ~правдоподобно, но обязательств нет Биткоинзахвачен государством
NATвсе ✓вторая субсидия по рыночной цене без форка · использует существующий консенсус лимит 21M не тронут цену задает и платит рынок оплата за блок · никто не контролирует масштабируется бесконечно · без давления комиссий на пользователей работает с блока 885,588 $NATпросто не растет — биткоин не тронут
 соответствует требованию
 не соответствует требованию
~ частично / условно
 неприменимо

Почему NAT — единственная полностью зеленая строка

Каждая альтернатива, которую рассматривает NATpaper, не проходит хотя бы одно безусловное требование.

  • Опора на комиссии — это базовый уровень, который не работает, а не решение: она уже здесь, и комиссии составляют меньше 1% вознаграждения майнеров.
  • Ончейн-масштабирование (более крупные / быстрые блоки) требует хардфорка правил консенсуса и поднимает расходы на ноды, сжимая децентрализацию.
  • Смена консенсуса на PoS или PoA — самый спорный форк из всех; по словам NATpaper, она «вызывает опасения по поводу централизации и доверия», а вознаграждения за стейкинг в PoS — это новая эмиссия, которая размывает держателей.
  • Хвостовая эмиссия, которая здесь представляет всю категорию монетарной политики (демередж, сжигание спящих монет), ломает лимит 21M и размывает держателей.
  • Государственная субсидия отвечает на вопрос «кто оплатит счет», меняя проблему финансирования на проблему контроля: ее финансирует не рынок, и она убивает децентрализацию.
  • Только NAT обходится без форка, не размывает держателей, финансируется рынком, сохраняет децентрализацию (оплата за блок, нет центрального оператора) и масштабируется без давления комиссий на пользователей — и уже работает с блока 885,588.
Безусловные требования: лимит предложения 21M (хвостовая эмиссия ломает его → нужен хардфорк); финансирование, которое идет от рынка, а не от государства; сохраненная децентрализация (никто единолично не контролирует хешрейт); и решение, которое существует сейчас, а не в виде предложения.  ·  NAT — без форка, финансируется рынком, уже работаетблока 885,588, февраль 2025).  ·  Источники: NATpaper — альтернативы, которые он рассматривает (улучшения ончейн-масштабирования; смена консенсуса на PoS / PoA; изменения монетарной политики: хвостовая эмиссия, демередж, сжигание спящих монет), плюс государственный сценарий «кто оплатит счет» и статус-кво с опорой на комиссии, которое не работает, — против NAT, который он предлагает.
Оценки в ячейках — это редакционное прочтение аргументации NATpaper для данного концептуального макета.
Six non-negotiables, every proposed fix. Hover or tap any mark for its note. Only one row is green all the way across. FULL BOARD + DETAILS ↗
Hover or tap any mark — its note appears here.

The honest risks

!Reflexivity (the big one)

NAT's security contribution is proportional to its market price, which is reflexive and procyclical — it tends to be high when Bitcoin is already secure and low exactly when extra security would matter most.

!Depends on continued BTC adoption

The whole premise rests on Bitcoin's ongoing adoption and the diffusion of meta-protocols like TAP. If that stalls, so does the demand that funds the reward.

!Winner-take-most risk

Meta-protocols may consolidate around one or two survivors. There is no guarantee NAT is the one that endures.

!Early & unproven

Miner crediting began in 2025. It has not been tested across a full market cycle or a real security stress event.

!Adoption is partial (just over half)

Just over half of pool hashrate currently mines blocks that actively move NAT — it is not universal, and the rest accrues unclaimed.

!Not a dollar security guarantee

NAT’s live figures are in tokens. Any dollar figure on this page sizes Bitcoin’s bill at today’s spot — not how many dollars of security NAT will provide, which depends entirely on the market.

FAQ · 26 questions

On this page
READER PATHS

Pick your path — or browse everything

straight answers, every claim checkable

That's the path. Everything else is below ↓

MOST ASKED:
§1 · The problemsecurity budget & attacks
Is the security-budget problem even real?EVIDENCE

Yes. The math is not in dispute. The facts: Bitcoin's security spend is dominated by a subsidy that halves every four years toward ~0 by ~2140, and fees today are a small, volatile fraction of the reward. Serious people disagree about whether fees grow into the gap: optimists point to scarce blockspace and a century of adjustment time; the concern side notes that a fee-only chain is theoretically less stable and that "the market will provide" is a hope, not a mechanism. For fees alone to replace the subsidy they would have to rise over ~100× — and hold there — a level at which nobody transacts. They have come close exactly once: on 20 April 2024, the day Runes launched, fees were 75% of what miners were paid — more than the subsidy itself — and collapsed back within days. December 2017 is the runner-up at 43%. So what is open is not whether the gap exists but which fix closes it — and anyone claiming certainty about the fix is selling something.

Watch the episodeThe Reverse Rainbow rrJun 28
DON'T TAKE OUR WORD FOR ITraised in 2010, still unresolved in 2026 — in their words:
THE PREMISE · 2010
“In a few decades when the reward gets too small, the transaction fee will become the main compensation for nodes.”

Translation

Satoshi Nakamoto
bitcointalk.org · Feb 2010
source ↗
THE RESEARCH · 2018
“the recurring, 'flow', payments to miners for running the blockchain must be large relative to the one-off, 'stock', benefits of attacking it.”

Translation

Eric Budish
NBER Working Paper 24717 · Jun 2018
source ↗
THE OPERATORS · 2026
“Look at the whole security budget of Bitcoin … transaction fees were meant to compensate miners for the halving. Well, that isn't happening.”

Translation

Fred Thiel
CEO, MARA Holdings · Coin Stories · Jul 2026
source ↗ ▶ CLIP
THE WALL19 sourced statements — Satoshi to peer review.See the full record →
Why not a tail emission — or just higher fees?EVIDENCE

That's exactly what the board above grades. The short version: a tail emission funds security by printing new BTC forever — it breaks the 21M cap and needs a fork, politically the least likely change in Bitcoin. Higher fees are the status-quo bet: nothing changes, but fees currently cover a small fraction of the reward, and "fees will grow" is a hope with no fallback. NAT's lane is narrower than either — nothing about Bitcoin changes, and the funding is whatever a market volunteers. The full board (link above) grades every option on six non-negotiables.

Watch the episodeThe Fix Menu fmJul 7 Watch the episodeE2 - The Fee-Reliance Trap e2Jul 10
THE CONTROL GROUPthe chain that chose tail emission, in its own docs:
MONEROPEDIA · TAIL EMISSION
“If mining is not profitable due to a high cost and low reward, miners lose their incentive and will stop mining, reducing the security of the network.”

Translation

Monero Project
getmonero.org · Moneropedia · “Tail Emission”
source ↗
Related
Has a 51% attack ever actually happened?EVIDENCE

Not to Bitcoin — repeatedly to smaller chains. Bitcoin has never suffered a successful 51% double-spend: the budget defending it has always out-priced the attack. Chains with thin security budgets are a different story — Ethereum Classic and Bitcoin Gold were both reorged by rented hashpower, and in August 2025 rented hashrate pushed past half of Monero and reorged six blocks. No exploit, no bug: the defense budget was simply smaller than the attacker's wallet. That's why the size of the budget — not just the elegance of the protocol — is the security.

THE RESEARCHthe mechanism, stated plainly:
THE RESEARCH · 2019
“Bitcoin's ‘security budget’ is the total amount of money we pay to miners … When this value is low, 51% attacks are cheap.”

Translation

Paul Sztorc
Truthcoin · “Security Budget in the Long Run” · Feb 2019
source ↗
Could a billionaire — or a state — buy 51% of hashrate?

A lone buyer: close to impossible. A coordinated actor: the realistic version. For an individual, ASIC output is capped and spoken for, deployment takes datacenters and years, the network grows while you buy — and honest mining with that much hardware pays better than crashing your own holdings. Coordinated or state actors change the math: rented hashrate, acquired pools, and political rather than financial motives. That's the version that has actually happened to smaller chains (see above). Raising what miners earn raises the budget any attacker must out-spend — that is NAT's entire argument here, and it only holds to the extent the market values NAT.

Watch the episodeThe Fix Menu fmJul 7
How exactly would NAT raise the cost of an attack?

By raising the revenue an attacker must out-spend — at the margin. The cost of attacking a proof-of-work chain tracks what its honest miners earn: out-spending them is the attack. Security is bought at the margin — the miners closest to shutting down are the hashrate the network loses first, and a second income stream matters most, proportionally, exactly there. More miner revenue → more surviving hashrate → a more expensive attack. The honest asterisk: NAT's contribution is proportional to its market price, which is reflexive — it can be smallest when needed most. That risk is owned above, not hidden.

Watch the episodeWhile You Were Arguing f7Jul 21
§2 · Mechanicshow it works
Is this just merged mining?

No. Merged mining means pointing hashpower at a second proof-of-work chain. NAT has no second chain — the reward is decoded from each Bitcoin block's own bits field and credited to that block's coinbase address by an open TAP Protocol indexer. The miner does nothing extra and runs nothing new.

The practical difference: merged mining pays a miner in a second chain's coin, on that chain's security assumptions and with that chain's software to run. NAT pays in an asset that lives on Bitcoin, with nothing extra running — which is why, as far as we can tell, it is the first tokenization of Bitcoin's security with a market native to Bitcoin. See the featured card above for how that compares with hashrate rentals, fee-driven metaprotocols and tokenized hashrate notes.

Does it change Bitcoin / need a fork?

No. There is no soft fork, hard fork, or BIP. Bitcoin's consensus rules are untouched and Bitcoin nodes are entirely unaware of NAT. It is an off-chain accounting layer (a meta-protocol) that interprets data already on Bitcoin.

Do miners have to do anything?

No. The NAT credit is computed automatically from each block's header and assigned to the coinbase address that mined it. There is no opt-in, no claim transaction, and no software to install. A miner can ignore NAT entirely and still accrue it.

Watch the episodeThe Pool Dilemma c1Jun 19
How do I verify the per-block amount?

Open any recent block on mempool.space or another explorer and read its bits field. Decode it as an integer using NAT = s×2²⁴ + c (with s the high byte and c the remaining value). Today that yields ~386,022,593 NAT — constant within each ~two-week difficulty epoch and resetting at every retarget, so re-read it after each one. The amount drifts down as difficulty rises — about 1.3%/yr averaged since 2009, though it has barely moved in the last five years. It never halves. Crediting began at block 885,588.

Watch the episodeVerify It Yourself ep2Jun 13
Does it rely on a trusted oracle or indexer?

No oracle — and the indexer is checkable. The NAT credit is a deterministic read of data already on Bitcoin: take any block's bits field, apply the formula, and you have the amount; the block's own coinbase address is the owner. An open TAP Protocol indexer computes this off-chain, and anyone can run their own and get byte-identical results. Nothing is fed in from outside — no price feed, no committee, no API you have to trust. Don't take our word for it: run the decode yourself (see "How it works" above).

Watch the episodeVerify It Yourself ep2Jun 13
Can the team switch it off or rug it?

There is no switch in the emission rule. The credit is math on public block data — every block's amount and owner follow from the block itself, and anyone can compute it independently. Since the miner-redirect went live at block 885,588 it has credited every block with no human intervention. There was also no insider supply to dump: no presale, no VC tranche, no team allocation (see the premine question below). The honest caveat: NAT still depends on people continuing to run indexers and a market continuing to care — that's an adoption risk, not a switch.

Watch the episodeNo Off Switch g1Jul 15
§3 · The tokenissuance & distribution
It never stops issuing — isn't that just inflation?

The issuance is real — and here is the number. NAT issues about 5.2% of its supply a year (roughly 20.3T tokens against about 390T circulating). Bitcoin issues about 0.8%. That is the honest figure and it is the one that matters to a holder. We publish it because the same arithmetic is what makes NAT fund about 6× more security per dollar of market cap — one fact, two readings, and you are entitled to both.

What the formula removes is not the size of the issuance but the discretion. Arbitrary issuance means someone decides when and how much; NAT's is read from Bitcoin's own bits field, so no vote can change it and no team can print it. One number is often confused with the other: the per-block amount drifts down about 1.3% a year as difficulty rises — that is the decline in each block's credit, not the supply-growth rate above. It never halves, but it never spikes either. Whether the market absorbs a perpetual, formula-driven supply is the real question — a demand question, owned honestly in the risks above, not a discretionary-printing question.

Why does the per-block amount fall over time?

Because difficulty rises. The per-block amount is decoded from the bits field — Bitcoin's difficulty target. As the network gets stronger the target tightens, and the decoded amount drifts down — about 1.3% a year historically, resetting at each two-week retarget. A stronger network → a smaller number, by formula. That's the opposite of an emissions committee: nobody chooses it, and you can verify every step from public block data. (It also never halves — the drift is gentle, not a cliff.)

Watch the episodeBreaking: 53% b1Jun 16
Was there a premine? Who got the early supply?

No premine — an open mint. NAT began as a first-come public mint in November 2023 (block 817,709): no presale, no VC tranche, no team allocation, no vesting cliffs — there is no insider supply waiting to unlock, because there were no insiders. Since block 885,588 (Feb 2025), every block's NAT goes to the miner of that block. The difference between a premine and an early adopter is whether the rule was the same for everyone. Here it was — and the chain is public, so you can check.

Is NAT just a memecoin?EVIDENCE

It keeps the meme energy — and adds what memecoins lack. A memecoin has exactly one source of demand: attention. When attention fades, the bid fades. NAT has that layer too — fair mint, a mascot, three years of culture — but stacks two more underneath: it is paid to the miners securing Bitcoin, every block, and its issuance is a formula read from Bitcoin's own headers, not a decision. Culture is the megaphone — not the foundation. Whether the market keeps valuing those layers is not guaranteed; see the risks above.

Watch the episodeRhodium: The Physical $NAT rhJul 18
THE OBJECTIONS, METthe mechanism has been argued in public — answered claim by claim:
Watch the episodeAdam Back vs NAT abJul 23
THE DATA ROOMOne number, every day since 2009: what share of Bitcoin’s market value is spent securing it — with the published benchmarks beside it.Open the data room →
How is NAT different from ORDI, Runes, and other meta-tokens?

One difference: who gets paid. Most meta-protocol tokens mint to whoever clicks fastest — collectors, snipers, whoever was watching the mempool that day. NAT is credited to block-winners only: the miner who actually secured the chain earns it, every block, automatically. That makes it the only meta-token whose distribution is itself a payment for Bitcoin's security. Everything else — indexing on TAP, living on Bitcoin L1 — it shares with its peers. The claim isn't that NAT is better tech; it's that it does a different job.

§4 · The marketselling & demand
Miners sell it every block. Who buys, and why would you?

Selling is the mechanism. The only question is whether demand exceeds it, and that is the question Bitcoin answers every day. Bitcoin's miners are paid about 450 BTC a day and sell most of it to pay for power. By the “miners just dump it” logic BTC should be worthless; it isn't, because the bid absorbs that supply and then some. NAT reaches the market the same way: the credit is structural, the buyers are not, and we say so. So what is the bid buying? Something that did not exist before. Until NAT, Bitcoin's security was a cost miners carried and a public good everyone else enjoyed for free, with no unit you could own and so no price; NAT is the first market for it, on Bitcoin itself (the mechanism is the featured card What does “Bitcoin's security, tokenized” mean? at the top). What you hold is a claim on Bitcoin's security budget that funds about six times more block security per unit of market value than Bitcoin itself, by protocol math, and the gap widens every halving because one emission halves and the other doesn't. Bitcoin's security has to be paid for by something: inflate BTC past 21M, hope fees alone cover it, or route outside value to miners through a complementary asset. The first two are graded in Why not a tail emission? above; NAT is the third. It is held the way a market holds gold, not consumed like fuel: no insider tranche waits to unlock, every unit reaches a miner at zero cost, and the selling you see is the subsidy being paid out, not proof that nobody wants it. What a given market cap actually pays miners is in the coverage table above. Whether that demand proves durable is the open question; only a full cycle will show it.

Watch the episodeThe Divergence b5Jun 29
Related
NAT's share of the budget is ~0 today. Why care?

Because the comparison that matters is per unit of value — and it's protocol math. Ask: for every unit of market value, how much block security does an asset fund? The price sits on both sides of that fraction, so it cancels. What's left is issuance over supply, set by protocol. On that measure NAT already funds about six times more security per unit of market value than Bitcoin does today — and the gap widens every halving, because one emission halves and the other doesn't. Today's absolute share is small, and we say so. The direction is the argument here; what the level actually comes to is sized in How much of the gap can this fill? above.

Watch the episodeThe BSI verdict bsiJul 19
Related
Doesn't it need an endless stream of new buyers?

The emission is structural; buyers aren't — and we say so. That framing cuts both ways. NAT doesn't need perpetual new believers to function mechanically — the credit happens every block regardless — but its security contribution is only as real as the demand behind it. What it doesn't have is the classic exit-liquidity structure: no insider allocation waiting to unlock, and the miners who receive it get it at zero marginal cost, every block. The test that matters is durable adoption and turnover across a full cycle — see "What would prove this wrong?" below.

Watch the episodeThe Divergence b5Jun 29
Related
Isn't this just a staking yield?

Same printer, opposite machine. A staking yield pays the token to holders of the token — the emission loops back into itself and funds nothing outside the system. NAT's emission is paid to miners for real, external work: hashrate, hardware, energy — the things that actually secure Bitcoin. Staking pays you to hold. NAT pays for security. And unlike stake-based systems, where attacking means simply buying more of the token, the security NAT supports stays exogenous — energy and physics, not balance sheets.

Related
"Paying miners isn't a use case."

Paying the people who secure Bitcoin is the point. In proof-of-work, security is never free — someone funds it, and today that is overwhelmingly the halving block subsidy. NAT's proposed demand is monetary: you hold it the way a market holds gold — a focal asset tied to funding Bitcoin's security — you don't consume it like gas. That is infrastructure utility, the same category Bitcoin's own value lives in, not app utility. Whether that demand proves durable is the open question — the market decides, and we make no guarantee.

Watch the episodeSecurity, Tokenized a5Jun 23
Related
Does Bitcoin now depend on NAT?

No — and the direction of the dependence matters. NAT is read out of Bitcoin; nothing was added to Bitcoin, so it cannot be harmed by NAT existing, and it would keep operating unchanged if NAT disappeared tomorrow. What the protocol guarantees on its own is liveness — blocks keep coming as miners leave and difficulty adjusts — not an optimal level of security. The security budget is already funded by markets outside the protocol. NAT is one market-funded supplement to that budget — a bounded supplement, not a dependency and not a fix.

Related
§5 · Honestywhat we won't claim
Who made it?

The creators are doxxed, not anonymous: Will and Iman (TheBlockRunner), working with the Digital Matter Theory framing, and BennyTheDev (the developer behind TAP Protocol), which is the indexing layer NAT is built on.

What would prove this wrong?

A fair question every experiment should answer. The falsification test: years of flat pool adoption and dead market turnover — an emission with no one on the other side. If the second subsidy can't attract durable demand across a full cycle, the thesis fails, and this page will say so. What would not disprove it: price swings in either direction — the mechanism is measured in adoption and hashrate, not in a chart.

Watch the episodeFluke. Signal. Pattern. b2Jul 25
If security is now ownable, who controls it?

A bid, not a vote. Buying $NAT expresses demand and nothing else. It carries no governance rights over Bitcoin — no vote on consensus, no say over miners, no claim on anyone's coins, and it introduces no new decider anywhere in the system. That is the difference between this and every patronage or foundation model: money that funds security without acquiring authority over it.

It is also checkable rather than promised. There is no mechanism through which a NAT holder could steer Bitcoin, because nothing was added to Bitcoin — the credit is read out of blocks that already exist. And NAT is not redeemable for anything: it is not a claim on the security budget, it is a market's way of paying into it.

Is this financial advice?

No. This page is an explainer, not advice. There are no price targets, no price projections, and nothing here is a recommendation to buy, sell, or hold anything. NAT is an experiment; it could fail. Do your own research and verify every claim independently.