Exhibit · Published research · 2015–2023 · fetched 2026-09-24

What the research says about the halving

The economists got there first. 7 papers are on this reading list — a stated list, not a census of the literature — and all 7 are quoted here, in the order they were published. All 7 bear on one question: what pays for Bitcoin's security as the block subsidy halves away. The earliest reports the expectation that transaction fees would; the three that modelled a fee-driven chain each found a problem with it. Their own words, each labelled with the version quoted, and a labelled counterpoint at the end.

The filings disclose the risk. The literature had modelled it years before. What it costs ↓

Published research
2015–2023
What the research says about the halving verified 2026-09-28
Download the full report Every quote with its source address, version label and hash, the full reading list with what was left out and why, the arithmetic and the method. PDF · 6 pages · A4 · 445 KB ↓
Of the 7 papers on this reading list
7 / 7 address it
a stated reading list, not a census of the literature — what was left out, and why, is in the report
Next halving— daysProjected—The cut, per block$131,911
80,949 blocks to 1,050,000 · 3.125 → 1.5625 BTC · at the 2026-09-27 price
Fees, share of miner revenue · 12 mo
0.63%
Best month ever22.9%2017-12Last full month0.67%2026-08· 24 of 31 days
THE SUBSIDY PAYS 99.37%
0%50%100%
9 minof every 24 hours is what fees pay for
▣ MAGNIFIED 50×
the first 2% of the bar
snapshot · tip 969,051 · trailing 14-day interval 9.87 minfee and price data through 2026-09-27 · verified 2026-09-28· 365-day window: 358 of 365 days observed
01 The papers
Exhibit · 7 papers · 7 sheets · in order of publication

The literature: fees, the subsidy and the cost of attack

source: the papers themselves · publisher or official open copy
verbatim · each labelled with the version quoted
Polasik et al.
Conference paper as hosted by the ECB (the open official copy)
Michal Polasik, Anna Iwona Piotrowska, Tomasz Piotr Wisniewski, Radoslaw Kotkowski, Geoffrey Lightfoot
Price Fluctuations and the Use of Bitcoin: An Empirical Inquiry
ECB retail-payments conference paper (June 2015) · 2015
Quoted verbatim · version labelled
The awards provide an incentive designed to support the early stage of the development of the system. As mining profits fall, it is expected that they will be replaced by transaction fees paid by users of the system (Nakamoto, 2008)

As mining profits fall, it is expected that they will be replaced by transaction fees paid by users of the system

Translation of the highlighted sentence. The excerpt above is the paper's own English.

ECB-hosted, not ECB-authored: the ECB hosted the 2015 retail-payments conference; it did not write or endorse the paper. The sentence reports the design expectation, which the authors attribute to Nakamoto (2008) — a premise, not a finding.

Read the source (POLA15) ↗p. 12 (printed; PDF p. 12) · sha-256 of the fetched document a6de1fec135a
Version of record (ACM Digital Library PDF, CCS '16), fetched via its Wayback snapshot because dl.acm.org refuses non-browser fetches
Miles Carlsten, Harry Kalodner, S. Matthew Weinberg, Arvind Narayanan
On the Instability of Bitcoin Without the Block Reward
ACM CCS '16 (Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security) · 2016
Quoted verbatim · version labelled
There has been an implicit belief that whether miners are paid by block rewards or transaction fees does not affect the security of the block chain. We show that this is not the case.

whether miners are paid by block rewards or transaction fees does not affect the security of the block chain. We show that this is not the case.

Translation of the highlighted sentence. The excerpt above is the paper's own English.

A model of the fees-only regime the subsidy schedule ends in — not a measurement of today's network. This sentence is quoted from the ACM Digital Library abstract page (archived copy), because the PDF merges the letters of one word.

Read the source (CARL16) ↗abstract · sha-256 of the fetched document b17d875feb2f
NBER working paper 2018; published QJE 2025
Eric Budish
The Economic Limits of Bitcoin and the Blockchain
NBER Working Paper 24717 · 2018
Quoted verbatim · version labelled
Together, these two equations imply that (3) the recurring, “flow”, payments to miners for running the blockchain must be large relative to the one-off, “stock”, benefits of attacking it. This is very expensive!

the recurring, “flow”, payments to miners for running the blockchain must be large relative to the one-off, “stock”, benefits of attacking it. This is very expensive!

Translation of the highlighted sentence. The excerpt above is the paper's own English.

NBER working paper 2018; published QJE 2025 (retitled, paywalled, not quoted). Budish names a constraint — the intrinsic cost of proof-of-work security. He does not endorse any fix, and nothing on this page suggests he does.

Read the source (BUDI18) ↗abstract · sha-256 of the fetched document 162c9af0dd92
Preprint: arXiv 1805.05288 abstract page (author version); version of record is the ACM DL, doi:10.1145/3243734.3243737 (refuses non-browser fetches, no Wayback copy)
Itay Tsabary, Ittay Eyal
The Gap Game
ACM CCS '18 (Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security) · 2018
Quoted verbatim · version labelled
Our analysis confirms Carlsten et al.'s postulate; indeed, we show that gaps form well before fees are the only incentive, and analyze the implications on security.

Our analysis confirms Carlsten et al.'s postulate; indeed, we show that gaps form well before fees are the only incentive

Translation of the highlighted sentence. The excerpt above is the paper's own English.

Quoted from the arXiv abstract page (the authors' version); published at ACM CCS '18, whose copy could not be fetched. “Gaps” are periods when miners stop mining because fees do not cover costs. A model result, not an observation of today's network.

Read the source (TSAB18) ↗abstract · sha-256 of the fetched document 28adf886c86e
Working paper (BIS WP 765, January 2019); also issued as Dallas Fed Globalization Institute WP 355
Raphael Auer
Beyond the doomsday economics of "proof-of-work" in cryptocurrencies
BIS Working Papers No 765 · 2019
Quoted verbatim · version labelled
Second, the transaction market cannot generate an adequate level of "mining" income via fees as users free-ride on the fees of other transactions in a block and in the subsequent blockchain.

the transaction market cannot generate an adequate level of "mining" income via fees as users free-ride on the fees of other transactions in a block

Translation of the highlighted sentence. The excerpt above is the paper's own English.

A BIS working paper: the author's views, not the BIS's. Quoted from the BIS abstract page. Auer's own remedy is to depart from proof-of-work — it is quoted in full below, so the paper is not read as backing any proof-of-work fix.

Read the source (AUER19) ↗abstract · sha-256 of the fetched document 7d45b6e53718

Auer's own remedy, from the same abstract — quoted in full because it points away from proof-of-work, not toward any fix of it:

Second-layer solutions such as the Lightning Network might help, but the only fundamental remedy would be to depart from proof-of-work, which would probably require some form of social coordination or institutionalisation.
Read the source (AUER19) ↗abstract · sha-256 of the fetched document 7d45b6e53718
Chiu & Koeppl
Version of record, abstract only (full text paywalled; abstract via the Crossref record)
Jonathan Chiu, Thorsten V. Koeppl
The economics of cryptocurrency: Bitcoin and beyond
Canadian Journal of Economics 55(4) · 2022
Quoted verbatim · version labelled
We find that it is optimal to use seignorage rather than transaction fees to finance costly mining.

it is optimal to use seignorage rather than transaction fees to finance costly mining

Translation of the highlighted sentence. The excerpt above is the paper's own English.

Their model favours seigniorage: it finds it optimal to pay for mining with new issuance rather than fees (“seignorage” is the paper's spelling). A normative model result — the case for issuance that never ends — not a finding that fees will fail. Bitcoin's schedule takes issuance to zero; that is a fact about the schedule, not about the paper.

Read the source (CHIU22) ↗abstract · sha-256 of the fetched document 7ff2bd455969
NBER working paper, July 2023 (revised August 2023); not peer-reviewed
Joshua S. Gans, Hanna Halaburda
"Zero Cost" Majority Attacks on Permissionless Blockchains
NBER Working Paper 31473 · 2023
Quoted verbatim · version labelled
We demonstrate that a majority attacker can successfully attack with a negative cost, which shows that the protocol mechanisms are insufficient to create a secure network, and emphasizes the importance of socially driven mechanisms external to the protocol.

a majority attacker can successfully attack with a negative cost, which shows that the protocol mechanisms are insufficient to create a secure network, and emphasizes the importance of socially driven mechanisms external to the protocol

Translation of the highlighted sentence. The excerpt above is the paper's own English.

Cuts both ways. If an attack can cost less than nothing, the size of the security budget alone does not decide security — which weakens “the budget is too small” as much as “the budget is enough”. NBER working paper, not peer-reviewed.

Read the source (GANS23) ↗abstract · sha-256 of the fetched document 122e4f1fb187

Counterpoint — industry research, not peer-reviewed. Fidelity Digital Assets is a bitcoin custodian. Its research team's conclusion in “Bitcoin's Programmed Security: Part Two” (June 2026):

the Fidelity Digital Assets® Research team does not see Bitcoin’s issuance schedule as a sufficient basis for long-term security concerns
Read the source (FIDA26B) ↗web page, Conclusion · sha-256 of the fetched document d089312d3f01

The same counterpoint, from “Bitcoin's Programmed Security: Part One” (June 2026):

At first glance, the declining block subsidy presents a compelling concern. However, there are multiple mechanisms in place reinforcing miner incentives and, by extension, network security.
Read the source (FIDA26A) ↗web page, Conclusion · sha-256 of the fetched document e8d23ee409f2
quotes re-checked byte-for-byte against the archived papers on every rebuildpapers fetched 2026-09-24
02 What they are describing
0%10%20%30%40%50%▲ 2012▲ 2016▲ 2020▲ 202450% — what fees must reachnext halvingthis much fee revenuewould have to appearDecember 2017 · 22.9% — best month ever2024-04-20 · 75% in one day (Runes) — one day, not a monthSeptember 2026 · 0.61%0%25%50%▲ 202450% — what fees must reachnext halvingthis has toappearSeptember 2026 · 0.61%

fees ÷ (fees + subsidy), BTC terms · monthly average of daily values since 2012 · ▲ halving · the shaded band is the shortfall: to hold miner revenue where it is today when the subsidy halves at block 1,050,000, fees must reach 50% of revenue — 79× today — at a constant BTC price. Fees are drawn flat because nothing in the series implies a climb. · data through 2026-09-27 · verified 2026-09-28

Fees today
0.63%
of miner revenue, last 12 months
Fees needed at the next halving
50%
to hold today's budget: today's fees + half of today's subsidy
The gap
79×
best month ever was 22.9% · a higher BTC price can substitute for fees; this arithmetic does not assume one
03 The consequence

The halving is the schedule. The security budget is the consequence.

OPEN →
0.82%
What Bitcoin pays for security

The security-budget index today, against five published benchmarks for what it should be.

OPEN →
$38.7M / day
The clock

What Bitcoin pays miners, live, per second — and what it stops paying at block 1,050,000.

OPEN →
2140
The second subsidy

What has to replace the block reward as it goes to zero, and one way it could.

Quotes are short excerpts from published research and one industry research note, reproduced verbatim for commentary and criticism, each with its source and version. Author, publisher and institution names identify the works quoted and imply no affiliation or endorsement. Nothing here is investment advice. Papers fetched 2026-09-24 · figures verified 2026-09-28.
Institution marks, where used at all, via Wikimedia Commons and the institutions' own sites. Full attribution in logos/_sources.json.