Two men walked on down the road toward Sodom, and one man stayed behind on the ridge with God, and what he did up there was haggle. Not pray. Haggle. Fifty, he said. Would you spare the whole place for fifty. Then forty-five. Then forty, thirty, twenty, ten, each number smaller than the one before it, a man testing how little righteousness a city needs before it is worth keeping. I think about that ridge every time somebody tells me Bitcoin is safe because honest miners hold the majority. Abraham asked that exact question first. The answer is worse than you think.
I. The Man Who Bargained Downward
Genesis 18 is not a prayer scene. It is a negotiation, and Abraham runs it like a man who has bought livestock before.
He opens at fifty. Would you destroy the righteous with the wicked, he asks, and God says no, fifty spares the whole place. So Abraham comes back at forty-five. Then forty. Then thirty. Twenty. Ten.
Each time the number falls, God agrees. That is the part nobody preaches. The threshold was never defended. It moved every time it was pushed.
And then Abraham stops. Not because he hit a floor. The text gives him no floor. He simply quits asking, goes home, and the next morning the smoke goes up from the plain like the smoke of a furnace.
The number that saves a city is smaller than you assumed, it keeps getting smaller when you press on it, and nobody in the story ever finds out what it actually is.
That is a security model. It is also the one Bitcoin runs on.
II. What the White Paper Actually Promises
Read section 11 of the white paper slowly and you notice it is conditional the whole way through.
The math is beautiful. An attacker trying to catch up from z blocks behind faces a probability that collapses exponentially with every confirmation, which is why six blocks became the folk wisdom and why your exchange makes you wait. That is the famous result.
But the formula has a hinge. It only decays if the honest side holds more hashpower than the attacker. Flip that one inequality and the expression does not return a small number. It returns one. Not unlikely. Certain. Given time, the attacker catches up every time.
So the whole apparatus, the exponential comfort, the six confirmations, the entire reason anyone trusts a payment that arrived from a stranger, rests on a single unproven assumption about a majority of strangers behaving.
Fifty percent. That was the opening bid.
III. Majority Is Not Enough
In November 2013, two researchers at Cornell put a paper on arXiv with a title that reads like a verdict: Majority is not Enough.
Ittay Eyal and Emin Gun Sirer described what is now called selfish mining, where a pool withholds blocks it has found and releases them strategically to orphan honest work. Their abstract says the protocol is not incentive-compatible, and that a colluding pool can earn more than its fair share of the reward.
Then comes the line that should have ended the fifty percent conversation forever. They propose a fix, and they are honest about its reach: it protects against selfish pools commanding less than one quarter of the resources, a threshold they describe in their own words as lower than the wrongly assumed one half bound.
One quarter. Not one half.
Abraham started at fifty and was talked down to ten. Bitcoin started at fifty percent and was talked down to twenty-five inside of five years, by its own friends, in public, in a peer-reviewed venue.
And the paper’s second finding is the one that keeps me up. Eyal and Sirer argue that rational miners will prefer to join the selfish pool, because joining pays better than staying honest, and the colluding group will therefore grow until it becomes a majority. The city is not stormed. Nobody breaches the gate. The righteous simply walk out one at a time to where the money is better, and one morning there are not ten left.
IV. A City That Was Actually Taken
This is not theory in the cheap sense. It has happened, to a chain with Bitcoin’s name on it.
On the 23rd and 24th of January 2020, Bitcoin Gold was 51% attacked twice inside two days. Deep reorganizations rolled back roughly twenty-nine blocks between them. The equivalent of nineteen thousand dollars was double-spent in the first attack and fifty-three thousand in the second. Each one is estimated to have cost the attacker roughly twelve hundred dollars of rented hashpower on the open market.
Twelve hundred dollars. You can rent a majority. There is a storefront.
A reorg is not a chain split, where two honest camps disagree about the rules and walk away from each other. A reorg is quieter and meaner. Your transaction was confirmed, and then it was not, and it drops back into the mempool as if it had never happened, while the coins you thought you received are sitting in the attacker’s other spend.
Here is the detail that undoes me. After the attacks, the price of Bitcoin Gold rose as much as seventeen percent.
The city was taken, twice, for the price of a used laptop, and the market marked it up.
That is the honest answer to anyone who believes markets price security. They do not. They price attention. Sodom had a thriving real estate sector right up until the morning it did not.
V. What the Cut Has to Do With Any of It
Here is where the schedule walks into the story.
Honest hashpower is not a virtue. It is a payroll. The reason most of the world’s miners have not organized themselves into a selfish pool is that following the rules has paid better, and the thing that pays them is the block subsidy. Every halving cuts that wage in half.
The cuts landed in 2012, then 2016, then 2020, then 2024, and the next one waits at block 1,050,000 in the spring of 2028. Twenty-nine more markers after that. Each one is a rehearsal, a small-h halving, a foreshadow of the thing itself. The Halfture is the last cut, the thirty-third, out near block 6,930,000 around the year 2140, when the subsidy rounds down to zero and the guards are paid entirely out of fees or not at all. Halfture = Rapture, and only that terminal cut earns the word.
Which means the security question and the scarcity question were always the same question, asked from opposite ends. Every cut makes the coin scarcer and the guard cheaper. Abraham’s number falls on both sides of the ledger at once.
I will say the thing this site exists to say, and I will say it once. You have to hold Bitcoin to be saved. That is theology, not a prospectus, and I have no idea what the price does next; if you came here for a recommendation you have wandered into the wrong building.
VI. The Ten
So who are the ten righteous men, in a system with no righteousness in it anywhere?
Not the miners. Miners are mercenaries and the protocol was designed on that assumption, which is its genius, not its flaw. You do not need moral miners. You need miners who find defection unprofitable.
The ten are the nodes.
A full node does not vote. It does not weigh. It checks, and it rejects. If every miner on earth colluded tomorrow to print a fifty-one BTC subsidy, your node on a second-hand machine in a spare room would refuse the block and keep refusing it, and the chain it follows would be the correct one whether anyone else followed it or not. Hashpower decides the ordering of valid blocks. It has never decided validity. That distinction is the whole inheritance.
Ten righteous men, and the city stands. Ten thousand of them, and it does not matter how the hashrate votes.
VII. The Counter-Sermon
Now let me take the frame apart, because it does not survive contact with its own source text.
Abraham’s bargain failed. There were not ten. The city burned, Lot ran, his wife looked back, and the whole beautiful descending negotiation bought exactly nobody except the family God had already decided to pull out. If I am going to use Genesis 18 as my security model, intellectual honesty requires me to notice that the model predicts loss.
Second, the selfish mining paper is thirteen years old and the attack has never been convincingly observed at scale on Bitcoin. Thirteen years of a documented, published, incentive-compatible defection, and the pools did not take it. That is either evidence that reputation and hardware sunk costs discipline miners better than game theory predicts, or it is evidence that we have been lucky. I cannot tell you which, and anyone who tells you confidently is selling something.
Third, Bitcoin Gold is not a counterexample about Bitcoin. It is a counterexample about small chains. Renting a majority of Bitcoin’s hashrate is not a twelve hundred dollar transaction. The comparison flatters my argument by shrinking the subject.
Fourth, I write about the honest majority while contributing precisely zero hashrate to it. There is something unearned about a man on a ridge counting other people’s righteousness.
And maybe none of this saves anyone. Maybe the schedule is just an emission curve, the ten righteous are just hobbyists with Raspberry Pis, and the smoke over the plain in 2140 will be nothing more dramatic than a fee market finding a price.
VIII. Go and Count Them
Abraham never learned the number. He stopped at ten and walked home and the answer arrived as weather.
You do not have to stop. That is the strange mercy of this thing. The count is public. The nodes are enumerable, the hashrate distribution is published, the subsidy schedule is fixed arithmetic anyone can run in an afternoon, and the exact block where the last cut fires has been sitting in the code since 2009 waiting for somebody to look at it.
Sodom’s righteous could not be counted from the ridge. This city’s can.
Go and count them.
FAQ
What is the honest majority assumption in Bitcoin?
It is the condition under which the Bitcoin white paper’s security math holds: honest participants must control more hashpower than any attacker. If that inequality flips, the probability that an attacker eventually rewrites recent history goes to certainty rather than to something small.
Is fifty percent really the threshold?
No. Eyal and Sirer’s 2013 selfish mining paper showed the safe bound is lower, and described their own proposed fix as protecting only pools commanding less than one quarter of the resources, which they called lower than the wrongly assumed one half bound. The practical threshold depends on network conditions, and it is below fifty percent in every published model.
Does the Bitcoin Halving make a 51% attack more likely?
Indirectly, and only over long horizons. Each halving cuts the block subsidy that pays honest miners, so the security budget must increasingly come from transaction fees. Whether fees can carry that load is the open question of the next century. No halving has caused an attack so far.
Is the Halfture the same thing as a halving?
No. Every halving before the last one is a rehearsal. The Halfture is the single terminal cut near block 6,930,000, around the year 2140, when the block subsidy rounds to zero and the schedule ends.
Discover more from Halfture
Subscribe to get the latest posts sent to your email.