Exhibit · Published research · 2015–2023 · fetched 2026-09-24
What the research says about the halving
The economists got there first. 7 papers are on this reading list — a stated list, not a census of the literature — and all 7 are quoted here, in the order they were published. All 7 bear on one question: what pays for Bitcoin's security as the block subsidy halves away. The earliest reports the expectation that transaction fees would; the three that modelled a fee-driven chain each found a problem with it. Their own words, each labelled with the version quoted, and a labelled counterpoint at the end.
The filings disclose the risk. The literature had modelled it years before. What it costs ↓
Published research2015–2023 What the research says about the halving verified 2026-09-28 Download the full report Every quote with its source address, version label and hash, the full reading list with what was left out and why, the arithmetic and the method.
The literature: fees, the subsidy and the cost of attack
verbatim · each labelled with the version quoted
Price Fluctuations and the Use of Bitcoin: An Empirical Inquiry
ECB retail-payments conference paper (June 2015) · 2015
Quoted verbatim · version labelled
The awards provide an incentive designed to support the early stage of the development of the system. As mining profits fall, it is expected that they will be replaced by transaction fees paid by users of the system (Nakamoto, 2008)
As mining profits fall, it is expected that they will be replaced by transaction fees paid by users of the system
Translation of the highlighted sentence. The excerpt above is the paper's own English.
ECB-hosted, not ECB-authored: the ECB hosted the 2015 retail-payments conference; it did not write or endorse the paper. The sentence reports the design expectation, which the authors attribute to Nakamoto (2008) — a premise, not a finding.
On the Instability of Bitcoin Without the Block Reward
ACM CCS '16 (Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security) · 2016
Quoted verbatim · version labelled
There has been an implicit belief that whether miners are paid by block rewards or transaction fees does not affect the security of the block chain. We show that this is not the case.
whether miners are paid by block rewards or transaction fees does not affect the security of the block chain. We show that this is not the case.
Translation of the highlighted sentence. The excerpt above is the paper's own English.
A model of the fees-only regime the subsidy schedule ends in — not a measurement of today's network. This sentence is quoted from the ACM Digital Library abstract page (archived copy), because the PDF merges the letters of one word.
The Economic Limits of Bitcoin and the Blockchain
NBER Working Paper 24717 · 2018
Quoted verbatim · version labelled
Together, these two equations imply that (3) the recurring, “flow”, payments to miners for running the blockchain must be large relative to the one-off, “stock”, benefits of attacking it. This is very expensive!
the recurring, “flow”, payments to miners for running the blockchain must be large relative to the one-off, “stock”, benefits of attacking it. This is very expensive!
Translation of the highlighted sentence. The excerpt above is the paper's own English.
NBER working paper 2018; published QJE 2025 (retitled, paywalled, not quoted). Budish names a constraint — the intrinsic cost of proof-of-work security. He does not endorse any fix, and nothing on this page suggests he does.
The Gap Game
ACM CCS '18 (Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security) · 2018
Quoted verbatim · version labelled
Our analysis confirms Carlsten et al.'s postulate; indeed, we show that gaps form well before fees are the only incentive, and analyze the implications on security.
Our analysis confirms Carlsten et al.'s postulate; indeed, we show that gaps form well before fees are the only incentive
Translation of the highlighted sentence. The excerpt above is the paper's own English.
Quoted from the arXiv abstract page (the authors' version); published at ACM CCS '18, whose copy could not be fetched. “Gaps” are periods when miners stop mining because fees do not cover costs. A model result, not an observation of today's network.

Beyond the doomsday economics of "proof-of-work" in cryptocurrencies
BIS Working Papers No 765 · 2019
Quoted verbatim · version labelled
Second, the transaction market cannot generate an adequate level of "mining" income via fees as users free-ride on the fees of other transactions in a block and in the subsequent blockchain.
the transaction market cannot generate an adequate level of "mining" income via fees as users free-ride on the fees of other transactions in a block
Translation of the highlighted sentence. The excerpt above is the paper's own English.
A BIS working paper: the author's views, not the BIS's. Quoted from the BIS abstract page. Auer's own remedy is to depart from proof-of-work — it is quoted in full below, so the paper is not read as backing any proof-of-work fix.
Auer's own remedy, from the same abstract — quoted in full because it points away from proof-of-work, not toward any fix of it:
Second-layer solutions such as the Lightning Network might help, but the only fundamental remedy would be to depart from proof-of-work, which would probably require some form of social coordination or institutionalisation.
The economics of cryptocurrency: Bitcoin and beyond
Canadian Journal of Economics 55(4) · 2022
Quoted verbatim · version labelled
We find that it is optimal to use seignorage rather than transaction fees to finance costly mining.
it is optimal to use seignorage rather than transaction fees to finance costly mining
Translation of the highlighted sentence. The excerpt above is the paper's own English.
Their model favours seigniorage: it finds it optimal to pay for mining with new issuance rather than fees (“seignorage” is the paper's spelling). A normative model result — the case for issuance that never ends — not a finding that fees will fail. Bitcoin's schedule takes issuance to zero; that is a fact about the schedule, not about the paper.
"Zero Cost" Majority Attacks on Permissionless Blockchains
NBER Working Paper 31473 · 2023
Quoted verbatim · version labelled
We demonstrate that a majority attacker can successfully attack with a negative cost, which shows that the protocol mechanisms are insufficient to create a secure network, and emphasizes the importance of socially driven mechanisms external to the protocol.
a majority attacker can successfully attack with a negative cost, which shows that the protocol mechanisms are insufficient to create a secure network, and emphasizes the importance of socially driven mechanisms external to the protocol
Translation of the highlighted sentence. The excerpt above is the paper's own English.
Cuts both ways. If an attack can cost less than nothing, the size of the security budget alone does not decide security — which weakens “the budget is too small” as much as “the budget is enough”. NBER working paper, not peer-reviewed.
Counterpoint — industry research, not peer-reviewed. Fidelity Digital Assets is a bitcoin custodian. Its research team's conclusion in “Bitcoin's Programmed Security: Part Two” (June 2026):
the Fidelity Digital Assets® Research team does not see Bitcoin’s issuance schedule as a sufficient basis for long-term security concerns
The same counterpoint, from “Bitcoin's Programmed Security: Part One” (June 2026):
At first glance, the declining block subsidy presents a compelling concern. However, there are multiple mechanisms in place reinforcing miner incentives and, by extension, network security.
fees ÷ (fees + subsidy), BTC terms · monthly average of daily values since 2012 · ▲ halving · the shaded band is the shortfall: to hold miner revenue where it is today when the subsidy halves at block 1,050,000, fees must reach 50% of revenue — 79× today — at a constant BTC price. Fees are drawn flat because nothing in the series implies a climb. · data through 2026-09-27 · verified 2026-09-28
The halving is the schedule. The security budget is the consequence.
The security-budget index today, against five published benchmarks for what it should be.
OPEN →What Bitcoin pays miners, live, per second — and what it stops paying at block 1,050,000.
OPEN →What has to replace the block reward as it goes to zero, and one way it could.
Quotes are short excerpts from published research and one industry research note, reproduced verbatim for commentary and criticism, each with its source and version. Author, publisher and institution names identify the works quoted and imply no affiliation or endorsement. Nothing here is investment advice. Papers fetched 2026-09-24 · figures verified 2026-09-28.
Institution marks, where used at all, via Wikimedia Commons and the institutions' own sites. Full attribution in logos/_sources.json.