21 million
The approximate total number of bitcoin that will ever be issued. It is slightly under, because the subsidy is halved using integer arithmetic and rounds away small amounts, and because some blocks have claimed less than they were owed. Coins with lost keys are a separate matter: they were issued and are counted, they simply cannot be moved, so the spendable supply is smaller still and nobody knows by how much. The figure is a consequence of the halving schedule rather than a parameter set independently.
Example: The final fraction of the supply is issued so slowly that the last coins are not expected until well into the next century.
51% attack
Controlling enough mining power to outpace the rest of the network and rewrite recent history. It would allow reversing recent transactions, and it would not allow creating coins, changing the supply, or spending anyone else's — those are enforced by nodes rather than by miners.
Example: The attack's realistic effect is undoing a recent payment, which is why large amounts wait for more confirmations.
Account path
The first three steps of a derivation path — m/84'/0'/0' — naming the script type, the coin, and which account. Everything a wallet shows you hangs below it: receiving addresses on one branch, change on another. It is the level an extended public key is normally exported from, so a wallet can watch a whole account without being handed anything that spends.
Example: One seed can hold several accounts — m/84'/0'/0' and m/84'/0'/1' share recovery words but behave as separate wallets with separate balances.
Address
A string encoding the conditions under which a payment can later be spent. It is derived from a public key or a script, is safe to share, and should be used once. Reading one on a screen a compromised computer controls is where address substitution gets its opportunity.
Example: Addresses beginning 1, 3, bc1q and bc1p all work; they differ in age, cost to spend, and how widely they are accepted.
Address reuse
Receiving more than once to the same address. It costs nothing technically and a great deal in privacy: every payment to that address is publicly linked to every other, permanently, and the link cannot be withdrawn later. Wallets generate a fresh address for each payment for this reason, and the gap limit exists because they do.
Example: Publishing one donation address links every contribution to it, which is the problem silent payments were designed to remove.
Address substitution
Malware that watches for something address-shaped and replaces it with the attacker's own. It breaks no cryptography and needs no privilege beyond reading your clipboard. The defence differs by direction. Receiving: derive the address on the signing device and read it there, since malware cannot change what the device computes. Sending: the device shows the destination it was handed, so if the substitution happened before the transaction was built it will display the attacker's address faithfully. There the check is against the recipient's address as confirmed through a channel the malware does not control.
Example: Receiving, the computer shows the attacker's address and the device shows yours. Sending, both show the same address, and only comparing it against the payee's own confirmed details reveals it is not theirs.
Air gap
An arrangement where the device holding keys has no electrical or radio connection to a networked machine, and data crosses by microSD card or QR code instead. It removes an attack surface rather than every attack surface: a transaction can still be signed for the wrong address if it is approved without reading the device screen.
Example: Carrying a PSBT to a signer on a microSD card preserves the air gap; plugging the same signer into the computer by USB does not.
- Security
- Hardware Wallets
- Connectivity
Anonymity
Not being identifiable at all — which bitcoin does not provide. The ledger is public and permanent, and identity attaches off-chain through exchanges, deliveries and habits. Pseudonymity is the accurate word: addresses are not names, and the link between them is often recoverable.
Example: Treating bitcoin as anonymous is the assumption behind most avoidable privacy losses.
Anti-money laundering (AML)
The framework of obligations requiring financial businesses to monitor and report activity. In practice it is the reason platforms demand identity documents, question withdrawals, and sometimes freeze accounts — and the reason a withdrawal ties your identity to specific coins.
Example: AML obligations are why a platform may ask where funds came from before releasing them.
Attack surface
The total set of places something can be attacked — code, interfaces, network connections, physical access. Reducing it is why bitcoin-only firmware, air gaps and dedicated devices exist. It is a more useful frame than asking whether something is secure, because it asks secure against what.
Example: A device supporting one asset runs less code than one supporting hundreds, which is a smaller surface regardless of either one's quality.
Attestation
A statement, signed by a build system, that a particular artifact came from a particular source. It binds a file to the repository and workflow that produced it, so a download can be checked against something more specific than a hash served from the same place as the file.
Example: An attestation records the repository as it stood when signed, so a copy downloaded before a rename verifies under the old name.
- Security
- Firmware
- Open Source
bech32
The address encoding used by native SegWit, producing lowercase strings beginning bc1q. Its checksum catches typos reliably and it is case-insensitive, which makes it easier to read aloud or transcribe than the older format. bech32m is the revised version used by Taproot.
Example: A mistyped bech32 address is almost always rejected by the sending wallet rather than accepted and sent nowhere.
BIP8
A revision of the BIP9 activation pattern that can end in mandatory activation rather than expiry, so a change is not indefinitely blockable by miners declining to signal. Which of the two patterns to use is a governance argument as much as a technical one.
Example: BIP8 exists because BIP9 let a minority of hash power veto a change that node operators wanted.
BIP9
An activation mechanism in which miners signal readiness for a soft fork within a time window, and the change locks in if enough do before it expires. It treats miner signalling as a readiness poll rather than a vote, and its weakness is that a minority of hash power can stall a change indefinitely by simply not signalling.
Example: SegWit was proposed under BIP9 and stalled, which is what led to the pressure that eventually activated it.
BIP16
The proposal that introduced pay-to-script-hash, letting an address commit to a script revealed only when spent. It made multisig and other conditions practical for ordinary users, because the sender no longer needed to know or pay for the recipient's spending conditions.
Example: Every address beginning with 3 exists because of BIP16.
BIP21
The URI scheme behind payment links and QR codes — bitcoin: followed by an address and optional amount and label. It is why scanning a merchant's code fills in the details rather than only the address, and why a wallet can be opened straight from a link.
Example: A QR code encoding a BIP21 URI can carry the amount as well as the address, removing one place to mistype.
BIP32
The standard defining hierarchical deterministic wallets: how a seed becomes a master key and chain code, how child keys are derived from parents, and the difference between hardened and ordinary derivation. Everything about paths, xpubs and watch-only wallets rests on it.
Example: BIP32 is why one backup can restore a wallet holding thousands of addresses across several accounts.
BIP39
The standard behind recovery phrases: a fixed list of 2,048 words, a rule for turning random bits into a sequence of them, a checksum that catches most transcription errors, and a key-stretching step that turns the words plus an optional passphrase into a wallet seed. Widely implemented, which is what lets one phrase restore across different software — though the derivation path still has to match.
Example: A twelve-word BIP39 phrase encodes 128 bits of entropy plus a four-bit checksum, which is why thirteen words is not a valid phrase.
- BIP39
- Backups
- Recovery
- Technical
BIP44
The standard that gave derivation paths their shape — purpose, coin type, account, change, index — and set the address gap limit at twenty. Its own purpose number, 44', now means legacy addresses specifically, while the structure it introduced is used by every later scheme.
Example: A wallet defaulting to m/44'/0'/0' derives legacy addresses beginning with 1.
BIP48
The derivation scheme for multisig wallets, which adds a script-type level to the path so that the same seed can participate in wallets of different kinds. Multisig needs it because the address depends on every co-signer's key, not only your own.
Example: A 2-of-3 native SegWit multisig typically derives its keys from m/48'/0'/0'/2'.
- Multisig
- Technical
- Recovery
BIP65 (CheckLockTimeVerify)
The opcode allowing a script to require that a given absolute time or block height has passed before an output can be spent. It is what makes inheritance paths and time-delayed recovery enforceable by the network rather than by anyone's promise.
Example: A spending path that only opens in 2030 is enforced by every node, not by the wallet displaying it.
BIP68 (relative timelocks)
Timelocks measured from when an output was confirmed rather than from a fixed date, using the sequence field. It is what allows conditions like "this key may spend, but only ninety days after the coins arrived", which is the usual shape of a decaying multisig.
Example: A recovery key that becomes usable ninety days after funding, rather than on a named date, uses a relative timelock.
- Technical
- Planning
- Multisig
BIP84
The derivation scheme for native SegWit addresses, using purpose 84' and producing addresses beginning bc1q. It is the common default in current wallets, which is why restoring an older seed into new software sometimes shows an empty wallet until the path is changed.
Example: m/84'/0'/0' is the account path most wallets create by default today.
BIP85
A scheme for deriving fresh, independent seed phrases from one master seed and an index number. The children are ordinary wallets that reveal nothing about the master or about each other, so one backup can stand behind several wallets — provided the index and word count are recorded, because nothing in a child seed identifies them.
Example: Index 0 at twelve words produces one wallet; index 1 produces an unrelated one, both recoverable from the same master.
BIP86
The derivation scheme for single-key Taproot addresses, using purpose 86' and producing addresses beginning bc1p. Support is widespread but not universal, and a wallet that cannot derive this path will not find coins held on it.
Example: A Taproot wallet at m/86'/0'/0' produces bc1p addresses that some older software cannot send to.
BIP125 (opt-in RBF)
The rule set defining when an unconfirmed transaction may be replaced by one paying a higher fee, and what the replacement must do to be accepted. Opt-in means the original had to signal it, and whether it did is usually a wallet default rather than a choice the sender made. Note that opt-in is a relay policy rather than a consensus rule, and it is no longer the only one in use: Bitcoin Core enables full replace-by-fee by default from version 28.0, under which a node will replace an unsignalled transaction too. Treat the absence of a signal as saying nothing about whether an unconfirmed payment can still change.
Example: A wallet that does not signal replaceability may still find its transaction replaced by a node running full RBF, so the recipient waits for a confirmation rather than for a signal.
BIP141 (SegWit)
The proposal defining segregated witness — moving signature data out of the transaction body, discounting it when measuring size, and fixing transaction malleability in the process. Activated in 2017 as a soft fork after a prolonged dispute.
Example: The cheaper fees on bc1 addresses trace directly to the discount BIP141 introduced.
BIP148 (UASF)
A user-activated soft fork: nodes agreeing to reject blocks that did not signal for SegWit after a set date, regardless of what miners preferred. It established the precedent that node operators, not miners, decide which rules apply — the point the block size war ultimately settled.
Example: The threat of BIP148 is widely credited with breaking the deadlock over SegWit activation.
BIP174 (PSBT)
The proposal defining the partially signed bitcoin transaction format, so that software from different vendors can pass an unsigned transaction between them and collect signatures. It is what makes air-gapped signing and multi-vendor multisig practical rather than bespoke.
Example: A PSBT built in one wallet can be signed by a device from a different manufacturer entirely.
- Technical
- Multisig
- Hardware Wallets
Bitcoin
A network of computers that agree, without a central authority, on who is entitled to spend what. Capitalised it usually means the network and the protocol; lowercase, the unit of account. The two are worth distinguishing, because most arguments about one are really about the other.
Example: You can run Bitcoin the software without owning any bitcoin the asset.
Bitcoin Core
The most widely used full node implementation, and the reference for what the consensus rules actually are. It validates the chain and manages descriptor wallets, but keeps no index of arbitrary addresses — which is why most wallets need an index server alongside it rather than talking to it directly.
Example: Specter drives Core's own wallets directly, which is why it needs Core and nothing else.
- Connectivity
- Technical
- Open Source
Bitcoin Improvement Proposal (BIP)
A numbered design document proposing a change or standard. A BIP number is a reference, not an endorsement: most are never adopted, some are withdrawn, and a few describe things now considered mistakes. Being able to cite one is how compatibility questions get settled precisely.
Example: BIP39 describes recovery phrases and BIP32 the key tree beneath them; both are implemented almost everywhere.
Bitcoin whitepaper
The nine-page 2008 paper describing a peer-to-peer electronic cash system, published under the name Satoshi Nakamoto. It sets out proof of work, the chain of blocks, and the argument that honest majority hash power settles ordering. It does not describe most of what a modern wallet does.
Example: The whitepaper explains why confirmations matter but says nothing about seed phrases or derivation paths.
Bitcoin-only
Hardware or software that supports bitcoin and nothing else. The argument is narrow and practical: less code means a smaller attack surface and fewer features whose failure modes you have to understand. Several manufacturers ship a bitcoin-only firmware edition alongside a multi-asset one, and on some devices the switch is permanent.
Example: Choosing the bitcoin-only firmware at setup removes support for every other asset, which is the point rather than a limitation.
- Firmware
- Hardware Wallets
- Security
Block
A batch of transactions accepted together, linked to the one before it. Blocks arrive roughly every ten minutes on average, which is not a schedule — gaps of forty minutes are ordinary. Space in one is finite, which is what fees bid for.
Example: A transaction is confirmed once when the block containing it is mined, and gains a confirmation with each block after.
Block explorer
A website that indexes the blockchain so transactions and addresses can be looked up. Useful for confirming a payment exists, and worth using carefully: searching for your own address tells the operator that whoever holds it visited from your connection, which is exactly the link a wallet pointed at your own node avoids creating.
Example: Pasting a receive address into an explorer to check a payment arrived also reveals that address, and your interest in it, to whoever runs the site.
Block height
How many blocks precede a given one, counting from the genesis block at zero. It is the chain's clock: halvings, difficulty adjustments and timelocks are all expressed in heights rather than dates, because heights are unambiguous and dates are not.
Example: A timelock set to a future height opens when the chain reaches it, whenever that happens to be.
Block size
How much data a block may contain. Since SegWit the limit is expressed in weight units rather than raw bytes, allowing roughly four million weight units, and it is what makes block space a scarce good that fees bid for. It was the subject of bitcoin's defining governance fight between 2015 and 2017.
Example: The limit is why fees rise during congestion rather than everyone simply being included.
Block subsidy
The new bitcoin created in each block and paid to whoever mined it. It halves every 210,000 blocks and will eventually round to nothing, at which point miners are paid by transaction fees alone. It is the entire mechanism by which bitcoin is issued.
Example: The subsidy and the fees of the included transactions together make up the block reward.
Blockchain
The ordered chain of blocks recording every transaction. It tracks amounts and spending conditions rather than people or balances, and it is public — which is the source of both its verifiability and its privacy problems. Nothing in it can be edited; history is only extended.
Example: A wallet's balance is not stored in the chain; it is computed by finding the unspent outputs its keys can claim.
Bloom filter
The older mechanism by which light wallets asked servers for relevant transactions. It was intended to be vague enough to preserve privacy and was shown not to be — a server could usually recover which addresses a wallet held. Largely superseded by compact block filters.
Example: Bloom filters are the cautionary example of privacy by obscurity in wallet design.
Brain wallet
A wallet whose key is derived from a phrase someone thought of. It fails reliably: human-chosen phrases are guessable at scale, and automated bots have swept them within minutes of funding for over a decade. Every study that has looked has found the same thing.
Example: Research checking hundreds of billions of candidate phrases against the chain found brain wallets drained almost immediately after funding.
Broadcast
Handing a signed transaction to the network by sending it to a node, which relays it onward. It is not a submission to any authority — nobody accepts or rejects it, and an unbroadcast transaction has changed nothing. Until it is mined, it sits in mempools waiting.
Example: A transaction signed on an air-gapped device does nothing until the coordinator broadcasts it.
Brute force
Trying every possibility until something works. It is why key sizes are what they are: a 128-bit secret has more possibilities than could be enumerated with any conceivable resources. It is also why a PIN is protected by an attempt counter rather than by its own length.
Example: Guessing a seed phrase is infeasible; guessing a four-digit PIN is trivial without something counting the attempts.
Byzantine fault tolerance
A system's ability to keep working correctly while some participants fail arbitrarily or behave maliciously. Bitcoin achieves it by tying influence to expended work rather than to identity, so an attacker must outspend the network rather than outnumber it.
Example: The network continues correctly even though some nodes and miners are hostile at any given moment.
Byzantine generals problem
The classic statement of coordinating parties who cannot trust each other or the messages between them, where some may actively lie. Bitcoin's answer is not better messaging but making participation expensive, so that lying costs more than it returns.
Example: The problem is why counting participants fails as a mechanism — identities are free to create, so votes can be manufactured.
Censorship resistance
The property that a valid transaction cannot be reliably prevented from confirming. Miners may decline to include one, but they cannot stop others including it, and the cost of excluding transactions indefinitely rises with the number of independent participants. It is the same property that makes payments irreversible.
Example: A transaction ignored by some miners is simply mined by others, usually within a block or two.
Chain analysis
Applying assumptions at scale to the public ledger to work out who controls what. Nobody is watching you specifically; a set of individually unremarkable inferences is applied to everyone. It works by combining weak signals rather than breaking anything, which is why the goal is raising the cost of the inference rather than achieving anonymity.
Example: An analyst combines shared inputs, change detection and timing to link addresses that were never obviously connected.
Chain code
Thirty-two bytes of additional entropy carried alongside a key, mixed into every child derivation. It is what makes a key extended: with the chain code, a whole branch can be derived from one string; without it, knowing a key tells you nothing about its siblings.
Example: An xpub is a public key and a chain code together, which is exactly what a watch-only wallet needs to derive future addresses.
Change address
An address in your own wallet that receives the remainder when a coin is spent. Coins are spent whole, so paying part of one sends the rest back to you. Change is the output nobody checks, and verifying it belongs to your wallet is what stops a compromised computer redirecting the remainder.
Example: Paying 0.01 from a 0.5 coin produces the payment and a 0.49 change output, which should be confirmed on the signing device as your own.
Change detection
Working out which output of a transaction returned to the sender. Roundness is the obvious signal — payments are round, change is the remainder — but script type, address reuse, unnecessary inputs and output ordering all give it away too. Identifying change is what turns isolated transactions into a traceable chain.
Example: Paying 0.05 from a 0.31 coin leaves an awkward remainder that is obviously the change.
Checksum
A short value calculated from a larger piece of data specifically to catch errors in it. Bitcoin uses checksums in several unrelated places: the final word of a BIP39 recovery phrase encodes a checksum of the words before it, so most (not all) transcription mistakes produce an invalid phrase rather than a silently different wallet; bech32 addresses carry a checksum strong enough to catch typos reliably; and software releases are distributed with a checksum file so a download can be verified against what the developers actually published.
Example: Before flashing a signer's firmware, a user checks the published SHA256 checksum against the file they downloaded to confirm nothing was altered in transit.
Child pays for parent (CPFP)
Speeding up a stuck transaction by spending one of its outputs in a new transaction with a high fee. Miners assess the pair together, so the child's fee effectively pays for the parent. It is the option available to the recipient, who cannot replace a transaction they did not send.
Example: Waiting on a slow incoming payment, you can spend its output to yourself at a high fee rate to pull both into a block.
Coin
Informal for a UTXO — one discrete, separately spendable chunk of bitcoin. Wallets that offer coin control use the word this way. It does not mean a physical object and does not mean a whole bitcoin.
Example: A wallet holding 0.4 BTC across three coins can choose which of them to spend.
Coin control
Choosing which UTXOs a transaction spends rather than letting the wallet decide. It is the highest-value privacy habit available, because spending coins together publicly asserts they share an owner. It is also how dust of unknown origin is kept out of transactions, by freezing it rather than reasoning about it.
Example: Paying from a single coin close to the payment amount avoids linking unrelated coins and avoids an obvious change output.
Coinbase transaction
The first transaction in every block, which creates the subsidy and collects the fees. It has no inputs, because it is where new coins come from. Its output cannot be spent for a hundred blocks, so a reorganisation cannot leave already-spent rewards behind.
Example: The genesis block's coinbase transaction carries that January 2009 front-page quotation in its input field.
CoinJoin
A collaborative transaction in which many people contribute inputs and receive equal-sized outputs, so that which output belongs to whom is not visible on-chain. It breaks the link between coins and their history rather than hiding amounts, and it cannot undo links already published.
Example: After a CoinJoin, an observer sees many indistinguishable outputs of the same size rather than one traceable payment.
Cold storage
Keeping the keys that authorise spending on a device that holds them in isolation, so they are never present on an internet-connected computer. The phrase describes where the keys live, not what product is used and not whether a cable is involved: a hardware wallet signing over USB keeps its keys isolated, while an air-gapped setup goes further and never connects at all. Both reduce exposure to malware and remote theft, and neither does anything about losing the backup or being coerced.
Example: A signing device kept in a drawer, paired with watch-only software on a laptop, is cold storage. Plugging that device into a computer to sign does not hand over the keys, which stay isolated on it. A key generated or typed on the computer itself was never cold to begin with.
- Storage
- Security
- Hardware Wallets
Collaborative custody
A multisig arrangement where a company holds one key and you hold the others, so it can help you recover without being able to spend. It buys a recovery process and an inheritance path in exchange for a fee, an identifiable relationship, and a dependency on the company still existing.
Example: In a 2-of-3 where you hold two keys, the company's participation is optional for spending and useful for recovery.
Common-input-ownership
The assumption that if a transaction spends several coins, one entity controlled all of them. It is the strongest heuristic in chain analysis, and it is right often enough that analysts treat it as a default rather than a guess. Coin control exists mostly to avoid triggering it, and PayJoin exists to make it produce wrong answers.
Example: Spending two coins together publicly asserts they share an owner, permanently and without any way to withdraw the claim.
Compact block filters
A way for a light wallet to work out whether a block concerns it by downloading a small filter per block rather than telling a server which addresses it owns. It is the privacy-preserving alternative to the older bloom filter approach, which leaked exactly what it was meant to protect.
Example: A wallet using block filters learns about its own payments without revealing which addresses it is watching.
- Privacy
- Connectivity
- Technical
Confirmation
A block containing your transaction, plus each block built on top of it. Confirmations are depth rather than a status change: nothing about the transaction is altered, but reversing it would require redoing every block since. There is no threshold at which a payment becomes official — how many to wait for is a judgement about the amount at stake.
Example: An exchange might credit a small deposit at one confirmation and a large one at six.
Consensus
Agreement across the network about which chain is valid and which transactions happened. It is produced by every node independently applying the same rules and rejecting what fails them, not by voting or by any authority. Miners order transactions; nodes decide whether the result counts.
Example: A block breaking the supply schedule is rejected by each node on its own, so no amount of hash power makes it valid.
Consensus rules
The conditions every node checks before accepting a block — the supply schedule, signature validity, transaction format, and the rest. They are enforced independently by everyone running a node, which is why no single party can change them and why running one is what makes the rule yours rather than someone's promise.
Example: A block creating more bitcoin than the schedule allows is rejected by each node on its own, not by a vote.
Consolidation
Deliberately combining many small UTXOs into one, usually while fees are low, so a later payment does not need many inputs. It saves money and costs privacy: the combining transaction asserts that every input shared an owner, permanently and in public.
Example: Consolidating a year of small purchases into one coin links them all, which may or may not matter depending on where they came from.
Coordinator
The software that watches the blockchain, tracks balances and builds transactions for one or more signing devices to sign. It holds public keys only and cannot spend. In multisig it also holds the wallet configuration, which is the part no seed phrase contains and the part people forget to back up.
Example: Sparrow acting as coordinator builds a PSBT, each device signs it in turn, and the coordinator broadcasts the result.
Counterparty risk
The risk that whoever owes you something fails to deliver — through insolvency, fraud, freezing your account, or simply ceasing to operate in your jurisdiction. It is the category of risk self-custody removes, and the reason "not your keys, not your coins" is a description rather than a slogan.
Example: Every platform failure of the last decade was counterparty risk arriving, however differently each one looked from outside.
Custodial
An arrangement where a company holds the keys and you hold a claim. The balance shown is what the company says it owes you, not an observation of the chain. It can be convenient, and it makes their solvency, access policies and continued existence part of your risk.
Example: An exchange balance is custodial until it is withdrawn to an address you control.
Cypherpunk
The movement, active from the late 1980s, arguing that privacy in a digital society requires cryptography rather than legislation, and that people should build the tools themselves. Bitcoin drew directly on its mailing lists, its prior attempts at digital cash, and its instinct that a system should not require trusting its operator.
Example: The design habit of removing the need to trust an operator, rather than regulating one, comes straight from this tradition.
Dead man's switch
An automated process that releases information if you stop checking in. Appealing in theory and unreliable in practice: services lapse, shut down, or fire early — and firing early discloses everything while you are alive and well. Worth having as one signal among several rather than as the plan.
Example: A switch that triggers during a long holiday hands over your instructions at the worst possible moment.
Decentralisation
How widely the ability to change or block things is spread. It is not one property but several — who can mine, who validates, who writes the software, who runs the infrastructure wallets rely on — and they can move in opposite directions. Running your own node is the part an individual actually controls.
Example: Mining can concentrate while validation stays widely distributed, because they are different kinds of power.
Deep cold storage
Cold storage made deliberately inconvenient — offline, geographically separated, sometimes requiring several people or a journey. The awkwardness is the feature for savings you do not intend to touch, and it is a liability if it makes verification so tedious that you never check the arrangement still works.
Example: Keys in a safe deposit box in another city are deep cold storage, and the annual check is the part people skip.
Deflationary
Applied to bitcoin, meaning the supply stops growing while coins are continually lost, so the effective total falls. Whether that is desirable is a genuine economic argument rather than a settled point, and it is separate from the technical fact of the issuance schedule.
Example: Lost coins are never reissued, so the spendable supply drifts downward regardless of price.
Derivation path
The route from a wallet's master key down to one particular key, written as numbers separated by slashes — m/84'/0'/0'/0/0. Each step picks a child key, so one seed produces completely different addresses depending on the path taken. A wallet restored on the wrong path looks empty even though the recovery words were right.
Example: Native SegWit wallets normally use m/84'/0'/0', so software expecting m/44'/0'/0' derives none of the same addresses from the same words.
Difficulty
How hard the network currently requires a valid block to be to find. It is recalculated every 2,016 blocks so that blocks keep arriving about every ten minutes regardless of how much mining power has joined or left.
Example: More miners means blocks arrive faster, until the next adjustment raises difficulty and restores the pace.
Difficulty adjustment
The recalibration, every 2,016 blocks, of how hard it is to mine one. Blocks that arrived too quickly make the next period harder, and blocks that arrived too slowly make it easier. The mechanism is a threshold a block's hash must fall below, so the numbers run backwards from the intuition: harder means a lower threshold, easier a higher one. It is what keeps the ten-minute average steady regardless of how much mining hardware joins or leaves, and what makes the issuance schedule hold to something close to its intended pace.
Example: A fortnight of blocks arriving every eight minutes ends in an adjustment that makes the next ones harder to find, pulling the average back toward ten.
Digital gold
A shorthand comparing bitcoin to gold as a scarce asset held for the long term rather than spent. The analogy holds on supply constraint and breaks on almost everything else — bitcoin is transferable over a network, verifiable at home, and confiscatable in completely different ways.
Example: The comparison is useful for the supply argument and misleading about custody, where the two behave nothing alike.
Digital signature
A value produced with a private key that anyone can check against the matching public key, proving both who authorised something and that it has not been altered since. It is the only operation a bitcoin private key ever performs.
Example: A signature commits to the exact transaction, so changing the recipient after signing invalidates it.
Dollar cost averaging
Buying a fixed amount at regular intervals rather than choosing moments. It removes timing decisions, which is most of its value. In self-custody terms it produces many small UTXOs, so it interacts with coin control and consolidation more than people expect.
Example: A year of weekly buys leaves fifty-two separate coins, each of which may cost more to spend than it did to receive.
Double spend
Attempting to spend the same coin twice. Preventing it without a trusted referee is the problem bitcoin exists to solve: the chain establishes an order everyone can agree on, so only the first spend of a coin is valid. This is why confirmations matter and why a payment is not final on broadcast.
Example: Accepting a zero-confirmation payment means trusting that no conflicting transaction is mined first.
Duress PIN
A second PIN that opens a decoy wallet, so something can be surrendered under coercion. It depends on the attacker believing you and stopping, which makes it a delay rather than a shield — and anyone informed enough to target you knows the feature exists.
Example: A decoy holding a token amount is transparently a decoy; one holding enough to be believed is enough to hurt to lose.
Dust
A UTXO so small that spending it would cost more in fees than it is worth, leaving it economically stranded. Most dust is innocent — change, faucet payouts, leftovers. Some is deliberate: a dusting attack sends a trivial amount hoping you will later spend it alongside your other coins and link them. Freezing anything of unknown origin covers both cases.
Example: A few hundred satoshis arriving unexpectedly is best frozen rather than swept up by automatic coin selection.
ECDSA
The elliptic curve signature scheme bitcoin used from the start and still uses for pre-Taproot outputs. Its notable hazard is the per-signature random value: reusing one across two signatures exposes the private key, which has drained real wallets and is why implementations now derive it deterministically.
Example: The PlayStation 3's signing key was recovered through exactly this failure in 2010.
Elliptic curve cryptography
The mathematics behind bitcoin's keys. Multiplying a fixed point on a curve by a secret number is easy; recovering the secret from the result is not. That asymmetry is what makes a public key safe to publish while the private key stays secret. Bitcoin uses the curve secp256k1.
Example: A public key is a point on the curve derived from the private key, and the derivation runs one way only.
Empty block
A block containing only its coinbase transaction. It happens when a miner starts work on a new block before validating the previous one's contents, choosing a few seconds of certain-but-empty work over a delay. Harmless and occasionally alarming to people watching an explorer.
Example: An empty block found moments after the previous one is normal behaviour, not a sign of anything wrong.
Entropy
Genuine unpredictability, measured in bits, and the raw material every wallet is built from. A seed is only as unguessable as the entropy behind it, which is why wallets are generated by a device or a physical process rather than chosen by a person. Human-invented phrases and passwords have been swept at scale for over a decade.
Example: Rolling dice produces entropy that can be checked and reasoned about, rather than trusting a device's internal generator alone.
Error correction
Encoding data with enough redundancy that damage can be detected and often repaired. Bitcoin uses detection rather than correction in most places — the BIP39 checksum and bech32 addresses catch errors and refuse rather than guessing, which is the safer behaviour when the alternative is silently producing a different wallet.
Example: A mistyped bech32 address is rejected rather than corrected, because correcting it wrongly would send money to a stranger.
Evil maid attack
Tampering with a device left unattended — a hotel room, an office, a house someone else has access to — and returning it looking untouched. It is the reason physical possession of your hardware matters, and the reason a device you have lost sight of should be treated as suspect rather than merely inconvenient.
Example: A signing device left in a hotel safe for a week should be verified or replaced rather than assumed intact.
Exchange
A business that trades bitcoin for other currencies. Most are custodial, holding coins until you withdraw; a few settle purchases directly to an address you control. The distinction matters more than any feature comparison, because it decides whether you hold bitcoin or a claim.
Example: Direct-to-wallet purchase leaves nothing to withdraw later, which removes the step people most often postpone.
Extended public key (xpub)
A public key plus a chain code, which together allow every address below a point in a wallet's tree to be derived without any ability to spend. It is what makes watch-only wallets possible. It is not secret in the way a seed is, but it reveals every address in that account, past and future, so anyone holding it can see the whole balance and history permanently.
Example: Importing an xpub into desktop software lets it track a hardware wallet's balance while the keys stay on the device.
Fee market
The continuous auction for block space. Nobody sets the price; it is whatever other people are currently bidding, and it can change by an order of magnitude within hours. As the block subsidy falls toward nothing, fees become the whole of what pays for security.
Example: A congested mempool is an auction with more bidders, not a system malfunctioning.
Fee rate
What a transaction pays per unit of the space it occupies, quoted in satoshis per virtual byte. Miners select by rate rather than by total fee, so a small transaction paying a high rate confirms ahead of a large one paying more in absolute terms. It is the number that decides how long you wait.
Example: A transaction with many inputs is physically larger, so matching someone else's fee rate costs it more in total.
Fiat currency
Money that is money because an authority declares it so, rather than because it is redeemable for something else. Every major national currency works this way. The arrangement is not inherently dishonest — it allows a supply that responds to circumstance — but it places the decision about how much exists with an issuer rather than with a fixed rule.
Example: Canadian dollars are not redeemable for any commodity; their value rests on their acceptance and on confidence in the issuer.
Finality
The point at which a payment can be treated as settled. Bitcoin has no moment where this formally occurs — confidence accumulates with depth rather than switching on. Choosing a threshold is a risk judgement about the amount, not a protocol rule.
Example: Exchanges credit small deposits at one confirmation and large ones at six for exactly this reason.
Firmware
The software running on a signing device. It decides what the screen shows and what the device will sign, so its provenance matters as much as the hardware's. Verifying a release signature before flashing defeats a substituted download; it does not tell you the vendor should be trusted.
Example: Checking a firmware signature against a key you have used for years is meaningfully stronger than against one fetched minutes ago.
Full node
Software that downloads every block and checks it against the consensus rules itself, rather than trusting anyone's summary. Running one is what lets a wallet answer questions from rules you enforce instead of a stranger's server. Installing one is not the same as using one — most wallets also need an index server alongside it before they can query addresses.
Example: A node that validates the chain in a cupboard changes nothing about privacy until the wallet is actually configured to talk to it.
- Connectivity
- Privacy
- Technical
Fungibility
The property of units being interchangeable, so that one is as acceptable as any other. Bitcoin is fungible at the protocol level — no rule treats one coin differently — and imperfectly fungible in practice, because the ledger is public and history can be traced. A coin whose past a service dislikes may be refused even though the network makes no distinction.
Example: An exchange declining a deposit because of where the coins previously sat is a failure of fungibility in practice, not in the protocol.
Game theory
The study of how participants behave when outcomes depend on each other's choices. Bitcoin's security rests on it as much as on cryptography: attacking the network is possible and unprofitable, because the cost exceeds what the attack returns and succeeding devalues what was captured.
Example: A miner with enough power to attack generally earns more by mining honestly, which is a design choice rather than an accident.
Gap limit
How many consecutive unused addresses a wallet checks before concluding there is nothing further. BIP44 sets it at twenty. It exists so restoring does not take forever, and it produces a specific failure: coins received beyond a long run of unused addresses look missing until the limit is raised and the wallet rescans.
Example: Generating dozens of addresses without using them can push a later payment past the default gap, so a restore shows a zero balance.
Genesis block
The first block, mined in January 2009. Its coinbase output is unspendable by a quirk of the original code, and its input quotes a Times front page on bank rescues — a timestamp and, most read it, a statement of purpose.
Example: Block height counts from the genesis block at zero.
Gold standard
A monetary arrangement in which a currency is redeemable for a fixed quantity of gold. It constrained issuance by tying it to something that could not be produced at will, and it was abandoned in stages during the twentieth century. It is referenced in bitcoin discussion as the nearest widely-understood precedent for a money with a supply rule.
Example: Under a gold standard a note was a claim on metal; the constraint held only while redemption was honoured.
Gossip
The relaying pattern by which transactions and blocks propagate — each node passing new information to its peers, which pass it to theirs. It spreads data quickly without any coordinator, and it is why broadcasting to a single node is enough.
Example: A block found anywhere reaches most of the network within seconds through gossip alone.
Halving
The scheduled reduction of the block subsidy by half, every 210,000 blocks or roughly four years. It is the mechanism that produces bitcoin's issuance curve and, eventually, its cap: each halving reduces new supply until the subsidy rounds to nothing. Nothing is decided at the time — the schedule was fixed at the start and every node enforces it.
Example: The subsidy fell from 6.25 to 3.125 bitcoin in 2024, the fourth such reduction.
Hard cap
The limit of just under 21 million bitcoin that will ever exist. It is not a policy anyone announces or could raise by agreement; it falls out of the halving schedule, and it holds because every node independently rejects a block that creates more than the rules allow. Changing it would require the people enforcing the rule to choose to stop.
Example: A miner producing a block with an oversized subsidy has that block rejected by the network rather than debated.
Hard fork
A rule change that loosens what is valid, so blocks made under the new rules are rejected by nodes running the old software. It splits the network unless everyone upgrades, which is why it is avoided for ordinary upgrades and why proposals that need one face a much higher bar.
Example: Raising the supply cap would require a hard fork, and nodes enforcing the old rule would simply reject the blocks.
Hardened derivation
A derivation step, written with an apostrophe as 84', that can only be performed with the private key. It exists to contain a specific leak: an extended public key plus any ordinary child private key beneath it reconstructs the parent private key. Hardening the account level makes an exported xpub safe to share.
Example: In m/84'/0'/0'/0/0 the first three steps are hardened and the last two are not, which is what lets a watch-only wallet derive addresses but never walk upwards.
Hardware security module
A dedicated device for holding keys and performing operations with them, used by institutions. A hardware wallet is the consumer version of the same idea, with the same central property: the key is used inside and never handed out.
Example: Custodians hold keys in HSMs for the same reason individuals use signing devices.
Hardware wallet
A dedicated device holding private keys and signing transactions, more accurately called a signing device since it holds no bitcoin. Its value is structural: the keys never reach a general-purpose computer, and it has a screen the computer cannot rewrite, which is where addresses and amounts should be read.
Example: The point of the device is not that it is unhackable, but that verifying an address on its own screen defeats malware on the machine driving it.
Hash
The fixed-length output of a hash function, and by extension the operation itself. Bitcoin uses hashes to link blocks, commit to transaction contents, derive addresses and measure mining work. A hash reveals nothing about its input and cannot be reversed, but recomputing it proves the input has not changed.
Example: Comparing a downloaded file's hash against a published one proves the bytes arrived intact.
Hash function
A function turning any input into a fixed-length output, where the same input always gives the same result, a tiny change gives a completely different one, and working backwards is infeasible. SHA-256 is the one bitcoin leans on hardest.
Example: Changing one character in a transaction produces an entirely different hash, which is why signatures commit to contents.
Hash rate
How much computation the network is applying to mining, and therefore how expensive rewriting recent history would be. It moves with hardware, energy prices and the bitcoin price, and the difficulty adjustment absorbs those changes so block timing stays roughly steady.
Example: A sharp fall in hash rate slows blocks until the next difficulty adjustment brings the pace back.
HD wallet
A hierarchical deterministic wallet: one seed, from which an unlimited tree of keys is derived by a fixed procedure. Deterministic is the useful half — nothing is random after the seed, so the same words rebuild the same keys anywhere. Hierarchical is why a single backup covers thousands of addresses.
Example: Because the wallet is HD, generating a fresh receiving address for every payment costs nothing and needs no new backup.
Hot wallet
A wallet whose spending keys live on an internet-connected device, usually a phone or laptop. Convenience is the point, and the trade is that anything compromising the device can reach the keys. The usual advice is not to avoid one but to bound it: keep an amount you would be annoyed rather than devastated to lose.
Example: A phone wallet used for everyday spending is a hot wallet, which is why the savings sit on separate hardware.
Immutability
The practical impossibility of changing confirmed history. Nothing forbids rewriting a block; it just requires redoing its proof of work and every block after it, faster than the rest of the network extends the chain. Immutability is therefore a matter of degree, deepening with each confirmation.
Example: One confirmation is meaningfully reversible; six is not, which is why the number varies with the amount at stake.
Index server
Software that sits beside a full node and maintains an address index so wallets can ask what a given address holds — a question Bitcoin Core is not built to answer quickly. electrs, Fulcrum and ElectrumX are the common implementations, and node distributions bundle one, which is much of why they exist.
Example: Pointing a wallet at your own node usually means pointing it at the index server running alongside it.
Inflation
A general rise in prices, equivalently a fall in what a unit of money buys. The word is used for two different things — an expansion of the money supply, and the price rises that may follow — and arguments frequently turn on which is meant. In bitcoin the supply side of that is fixed and public, which is what the term is usually invoking here.
Example: Bitcoin's issuance rate is often called its inflation rate, and it falls at every halving regardless of demand.
Inheritance plan
An arrangement letting someone reach your bitcoin after you die without letting anyone reach it before. The two requirements pull against each other, which is most of what makes the subject hard. The commonest total loss is not theft but an heir who cannot execute a technically perfect plan.
Example: Testing the plan with the person who will have to follow it is the only thing that turns a document you hope works into one you know does.
Initial block download
The first synchronisation of a new node, downloading and validating the chain from the beginning. It takes hours to days depending on hardware, and it is the point at which a node checks history for itself rather than accepting a summary. It happens once.
Example: A freshly installed node is not useful until the initial download completes and it has verified the chain itself.
Irrecoverable loss
Bitcoin that still exists on the chain and can never be spent, because the keys are gone. There is no recovery department and no appeal. It is the failure mode self-custody introduces, and the entire reason a backup that has not been restored from does not count.
Example: Coins in a wallet whose seed was never written down remain visible forever and spendable by nobody.
Key derivation function
A deliberately slow function that turns a password or phrase into a key, slowing down anyone guessing. BIP39 uses PBKDF2 with 2,048 rounds to turn a recovery phrase and passphrase into a seed — a low work factor by modern standards, so a passphrase protects you by being unguessable rather than by being expensive to test.
Example: 2,048 rounds is a speed bump; a short memorable passphrase on a compromised seed card is a delay, not a defence.
Key rotation
Moving funds to a wallet with new keys because the old ones may be compromised — a device left unattended, a backup someone may have seen, a co-signer leaving. Bitcoin has no way to revoke a key, so rotation means spending to a new wallet, which is an on-chain transaction with a fee and a new set of addresses.
Example: After a device is lost, rotating is the only way to make its key irrelevant, because it cannot be cancelled.
KYC
Know your customer — the identity checks a regulated platform performs before letting you trade. It ties your legal identity to the specific coins you withdraw, and no on-chain technique reaches backwards through that link. It is the reason privacy work is about the future rather than the past.
Example: Coins withdrawn from a verified account are associated with your identity in that platform's records regardless of what you do next.
Legal tender
A legal status meaning a currency must be accepted in settlement of a debt within a jurisdiction. It is narrower than it sounds: it governs the discharge of debts rather than compelling anyone to accept a payment, and it says nothing about whether a currency holds value. A money can be legal tender and be losing purchasing power quickly.
Example: Legal tender status obliges a creditor to accept the currency for a debt; it does not oblige a shop to price in it.
Locktime
A field stating the earliest block height or time at which a transaction may be included. Set to zero it means immediately. Wallets sometimes set it to the current height to discourage fee sniping, and that choice is one of the details that identifies which software built a transaction.
Example: A transaction with a future locktime is valid but unminable until the chain reaches it.
Low time preference
A disposition to weigh future outcomes heavily against immediate ones — saving rather than spending, building rather than extracting. The term is borrowed from economics into bitcoin discussion, where it is used both descriptively and as encouragement. Its practical form in self-custody is unglamorous: testing a backup before it is needed rather than after.
Example: Spending an afternoon rehearsing a recovery you may never use is a low time preference act.
Mainnet
The real bitcoin network, as distinct from testnet, signet or a private regtest. The word usually appears when something can run on more than one, and getting the two confused is precisely the risk that keeps testnet settings behind a warning on signing devices.
Example: A wallet must be on mainnet for its addresses to receive bitcoin of any value.
MAST
Merkelized alternative script trees — committing to several possible spending conditions in a tree so that using one reveals only that branch. Taproot builds on the idea, which is why a Taproot output can carry an unused emergency path that never becomes public.
Example: A wallet with a rarely used recovery condition publishes nothing about it while the ordinary path is used.
Master fingerprint
Eight hexadecimal characters identifying which wallet a device is holding, taken from a hash of the wallet's master public key. It reveals nothing that could spend, and appears in descriptors and partly signed transactions to record which key signed or still has to. Because it comes from the seed, adding a BIP39 passphrase changes it — which is how you confirm a passphrase was entered the way you meant.
Example: A multisig coordinator lists each cosigner by master fingerprint, so a 2-of-3 shows three eight-character identifiers rather than three extended public keys.
- Wallets
- Multisig
- Recovery
- Technical
Master key
The key at the root of a wallet's tree, derived from the seed and the ancestor of every other key in it. Everything below it can be recomputed from it, which is why it is never exported directly and why an extended public key is taken from an account below it instead.
Example: A device reports a master key fingerprint so software can confirm it is talking to the wallet it thinks it is.
Mempool
The set of valid transactions a node has heard about and is holding until one is mined. There is no single mempool — each node keeps its own, and they differ. A transaction sitting there is not stuck in any official sense; it is simply bidding below the going rate for block space, and it can be replaced or bumped rather than waited out.
Example: Checking the mempool during a busy period shows whether a pending payment is underpriced or merely recent.
Merkle tree
A structure that hashes transactions in pairs, repeatedly, until one hash summarises them all. It lets a block commit to its contents compactly, and lets a light client be shown that one transaction is in a block without downloading the whole thing.
Example: A block header carries a single Merkle root standing in for every transaction the block contains.
Metadata
Information about a transaction rather than in it — timing, amounts, which server answered a query, which addresses were looked up together. It is frequently more revealing than the contents, and it is the category that pointing a wallet at your own node addresses.
Example: A public server does not need to break anything to learn which addresses belong to one wallet; it is told.
MicroSD backup
A backup file or wallet record stored on a removable MicroSD card. Hardware wallets may use MicroSD cards to move PSBTs, export wallet data, install firmware, or save an encrypted device backup without connecting the signer directly to an online computer. What the card contains—and whether it is encrypted—depends on the device and workflow.
Example: A COLDCARD can save an encrypted backup containing its seed and settings to a MicroSD card; the backup file and its separate password are both required for recovery.
- Hardware Wallets
- Backups
- Recovery
- Storage
Mining
Repeatedly hashing a candidate block until the result falls below a target, which is expensive by design. The expense is the point: it makes rewriting history costly rather than merely disallowed, and it decides the order of transactions without anyone being in charge.
Example: A miner that finds a valid block collects the subsidy and the fees of the transactions it included.
Miniscript
A structured way of writing spending conditions that software can analyse — checking what a policy allows, what it costs to satisfy, and whether it can be signed — rather than treating the script as an opaque blob. It is what makes complex arrangements like decaying multisig practical to build and audit.
Example: A policy allowing three keys now, or two keys after a year, is expressible and checkable in Miniscript.
Mobile wallet
A bitcoin wallet running as a phone app. Most hold their own keys and are therefore hot wallets, though some operate purely as watch-only companions to a hardware signer, and some are custodial. Which of the three a given app is matters more than any feature it advertises, and is not always obvious from its marketing.
Example: The same phone can run a small hot wallet for spending and a separate watch-only wallet that tracks cold storage without being able to spend from it.
Money supply
The total quantity of a money in existence. For fiat currencies it is a policy variable adjusted by an issuer; for bitcoin it is a schedule fixed in the rules and enforced by every node. That difference — who decides — is the substance of most comparisons between the two.
Example: Bitcoin's supply is knowable years in advance because nobody has the authority to change it.
Mt. Gox
The exchange that handled most global bitcoin trading until it collapsed in 2014 with roughly 850,000 bitcoin unaccounted for. The losses accumulated over years while the business operated normally and showed customers balances that had become fiction — which is the reason a platform balance is a claim rather than an observation.
Example: Nothing visible from outside would have told a customer, which is the durable lesson rather than the amount.
Multisig
A wallet whose spending conditions require signatures from more than one key — commonly two of three. Losing one key or having one stolen changes nothing, which removes the single point of failure an ordinary wallet has. It adds a dependency in exchange: rebuilding the wallet needs its configuration as well as its keys, and no seed phrase contains that.
Example: In a 2-of-3 held across three locations, a burglary at one of them yields a key that cannot move anything on its own.
Nakamoto consensus
The specific arrangement bitcoin uses: proof of work makes producing blocks expensive, and nodes follow the valid chain with the most accumulated work. It settles ordering among participants who cannot identify or trust each other, which is the problem earlier digital cash designs could not solve without an operator.
Example: Competing chains resolve because extending the shorter one costs more work than it earns.
Network effect
The property that something becomes more useful as more people use it. It is cited both as bitcoin's main defence against alternatives and as a reason to be sceptical of arguments that a technically superior design would displace it. Descriptive rather than a guarantee.
Example: Liquidity, tooling and merchant support all improve with adoption, and all of them are switching costs.
NFC
Near Field Communication: a very short-range wireless technology that exchanges data when compatible devices are brought within a few centimetres of each other. Bitcoin devices and keycards may use NFC to transfer wallet data or approve actions, but NFC is still a communication channel and should not automatically be treated as an air gap.
Example: A user taps an NFC keycard against a phone to authorize a wallet operation without plugging in a cable.
- Hardware Wallets
- Connectivity
- Technical
Node
Software that takes part in the bitcoin network. A full node downloads every block and validates it against the consensus rules itself; a light client asks someone else and believes the answer. Which one your wallet talks to determines whether your balance is verified or reported.
Example: Running a node changes nothing until the wallet is actually configured to use it rather than a public server.
Nonce
A number used once. Two unrelated things carry the name: the random value in an ECDSA signature, which must never repeat because reusing it across two signatures exposes the private key; and the field miners increment while searching for a valid block. Only the first is a security concern for a wallet.
Example: Signature nonce reuse has drained real wallets, which is why the value is derived deterministically in modern implementations.
Not your keys, not your coins
The observation that bitcoin held by someone else is their asset and your claim. It is not an ideological slogan but a description of who bears the loss when a company fails — and of who can freeze, delay or lose your access while it operates normally.
Example: Every customer of a failed platform believed their balance was their bitcoin, and the screen was accurate until it was not.
Off-chain
Value moved without writing to the blockchain — inside an exchange's database, or across a payment channel. It can be faster and cheaper, and it reintroduces a counterparty or a set of assumptions the chain otherwise removes. Backup and recovery work differently, and often not at all the same way.
Example: A transfer between two accounts at the same exchange never touches the chain and is entirely that company's record.
On-chain
Recorded in the blockchain itself, as opposed to arrangements settled elsewhere. On-chain transactions are the ones that cost a fee, wait for confirmations, and are permanently public. Everything this site teaches is on-chain custody.
Example: A recovery that moves funds to a new wallet is an on-chain transaction, with a fee and new addresses.
Open source
Source code published under a licence that permits anyone to read, modify and redistribute it. It makes a design auditable rather than audited — publication is not review, and a backdoor introduced by a trusted maintainer sits in public code that compiles reproducibly. Meaningful, and not on its own a guarantee.
Example: A device with open firmware can have its published source compiled and compared against the binary that shipped, which closed firmware cannot.
- Open Source
- Firmware
- Security
Over the counter (OTC)
Trading directly with a counterparty or desk rather than on an order book, usually for larger amounts and to avoid moving the price. It changes who you are exposed to rather than removing exposure, and settlement terms vary considerably.
Example: An OTC desk quotes a single all-in price for the whole amount rather than filling it across an order book.
P2PKH
Pay to public key hash — the original address format, beginning with 1. Universally accepted and the most expensive to spend from, because it carries no SegWit discount. Still perfectly valid; coins sitting on these addresses are not at risk, only slightly costlier to move.
Example: An address starting with 1 is legacy, derived at m/44'/0'/0' in most wallets.
P2SH
Pay to script hash — an address beginning with 3 that commits to a script rather than a key, revealed only when spent. It made complex conditions practical and was later used to wrap SegWit for compatibility, so a 3-address may be a multisig, a wrapped SegWit wallet, or something else entirely.
Example: Wrapped SegWit wallets produce 3-addresses that older software accepts while still getting part of the SegWit discount.
P2TR
Taproot outputs, addressed in bech32m and beginning bc1p. Cheapest to spend from for simple cases, and able to hide complex spending conditions so that an ordinary-looking spend reveals nothing about the alternatives that existed. Support is broad but still short of universal.
Example: A bc1p address can conceal a multisig or timelocked fallback that is never used and never published.
P2WPKH
Native SegWit single-key outputs, addressed in bech32 and beginning bc1q. Cheaper to spend from than legacy or wrapped forms, and the common default in current wallets. Acceptance is near-universal now, though a small number of services still lag.
Example: A bc1q address derived at m/84'/0'/0' is the default for most wallets created today.
P2WSH
Native SegWit outputs that commit to a script rather than a single key, beginning bc1q but longer than the single-key form. It is the usual shape of a modern multisig wallet.
Example: A 2-of-3 native SegWit multisig pays to P2WSH addresses derived from all three co-signers' keys.
Paper wallet
A single private key printed on paper, usually with its address. An older pattern now generally discouraged: there is no way to spend part of the balance without exposing the key, the software that generated it may not have been trustworthy, and it fits none of the tooling built since. Sweep one rather than importing it.
Example: Spending from a paper wallet means moving the whole balance, because using the key at all exposes it.
Passphrase
An optional secret combined with a wallet backup to derive a different wallet. Under BIP39, every passphrase—including an empty or incorrect one—produces a valid wallet, so there is no error message that can identify the right one. The same recovery words and exact passphrase are both required to restore the intended wallet.
Example: Restoring the correct recovery words with a misspelled passphrase opens a different, usually empty wallet rather than reporting a mistake.
- Wallets
- Security
- Recovery
- BIP39
PayJoin
A payment in which the recipient also contributes an input, so the finished transaction spends coins belonging to two different people. Anyone applying common-input-ownership to it concludes one entity owned both and is simply wrong. It looks like an ordinary transaction, and every one that happens degrades the heuristic for everybody.
Example: A PayJoin also breaks amount analysis, because the visible payment amount is not the amount that changed hands.
Peer-to-peer
A network where participants connect directly to one another rather than through a central server. Every node relays blocks and transactions to its peers, so there is no address to shut down and no operator whose permission is required to join.
Example: A transaction broadcast to one node reaches the whole network by being relayed peer to peer.
Phishing
A social-engineering attack that impersonates a trusted person, company, website, or app to trick someone into revealing secrets or approving a harmful action. In Bitcoin, phishing commonly targets exchange credentials, recovery words, passphrases, wallet downloads, addresses, and transaction approvals.
Example: A fake support message sends a user to a look-alike website that asks for recovery words to ‘verify’ a wallet.
PIN
The code protecting a signing device from someone holding it. Its strength does not come from length — four digits is ten thousand guesses — but from something counting the wrong attempts and eventually acting. Where that counter lives is what a secure element is for.
Example: A device that wipes itself after a set number of wrong PINs is behaving correctly; a counter that could be reset would be worthless.
Private key
The number that authorises spending. It is not a password and is never sent anywhere — a wallet proves it holds the key by producing a signature, and the key itself stays put. Anyone who learns it can spend the coins it controls, immediately and irreversibly, from anywhere.
Example: A hardware wallet exists so the private key never touches an internet-connected computer, even while that computer builds the transaction.
Proof of keys
The practice of withdrawing from platforms to verify they can actually deliver, popularised as an annual exercise. The point is less the withdrawal than what it demonstrates: a balance you have never moved is a claim you have never tested.
Example: Withdrawing once, deliberately, is the only way to learn whether a platform's withdrawal process actually works for you.
Proof of reserves
A demonstration that a platform controls a quantity of bitcoin at a moment in time. Genuinely something, and not solvency: solvency is reserves minus liabilities, and the liabilities are the half nobody can see. It is a snapshot, it rarely proves what customers are owed, and it cannot show whether the coins are already pledged elsewhere.
Example: Coins can be borrowed for an audit and returned afterwards, which has happened.
Proof of work
Evidence that a large amount of computation was spent producing something, cheap for anyone to verify and expensive to fake. It is how bitcoin settles which history is real without a vote: rewriting a block means redoing its work and every block after it, faster than the rest of the network extends the chain.
Example: Six confirmations means an attacker would have to redo six blocks of work while competing with everyone else.
Pruned node
A full node that validates every block and then discards old block data to save disk. It enforces the same rules and is a genuine full node, but it cannot serve historical blocks — which matters if you later need to rescan for a wallet with years of history.
Example: Pruning keeps a node under a few hundred gigabytes, at the cost of being unable to rescan old blocks for an imported wallet.
PSBT
A partially signed bitcoin transaction — the file format an unsigned transaction travels in between the software that built it and the device that signs it. It carries the proposed transaction plus everything an offline signer needs to check the work independently, including the value of every input, so the device can compute the fee itself rather than believing a number the computer supplied.
Example: An air-gapped signer reads a PSBT from a microSD card, displays the amount and fee it calculated, and writes the signed version back to the card.
- Technical
- Hardware Wallets
- Multisig
Pseudonymity
Acting under a persistent identifier that is not your name. It is what bitcoin actually offers: addresses stand in for you, and they hold up only until something connects one to your identity — at which point everything linked to it connects too, retroactively and permanently.
Example: One KYC withdrawal can retroactively identify a cluster of addresses that were pseudonymous until then.
Public key
A number derived from a private key that can verify its signatures without being able to produce them. The derivation runs one way only: a public key reveals nothing usable about the private key behind it. Addresses are built from public keys, which is why sharing an address is safe and sharing a private key is not.
Example: A watch-only wallet holds public keys, so it can recognise incoming payments and build transactions but cannot sign one.
QR code
A machine-readable square used to move data optically — addresses, payment links, unsigned and signed transactions. It is one of the two transports that genuinely preserve an air gap, since nothing physical or electrical crosses. Larger transactions become animated sequences of several frames.
Example: An air-gapped signer reads a PSBT from the screen and displays the signed result back as a code.
- Hardware Wallets
- Connectivity
Quantitative easing
A central bank creating money to buy financial assets, expanding the money supply to stimulate an economy. It is frequently cited in bitcoin discussion as the concrete example of discretionary issuance, which is the thing a fixed schedule is a response to.
Example: The genesis block's newspaper headline about bank bailouts is usually read as a comment on exactly this.
Quantum computing
A computing model that would, at sufficient scale, break the elliptic curve mathematics behind bitcoin signatures. No such machine exists, and the timeline is genuinely uncertain. The usual near-term advice is to avoid reusing addresses, on the grounds that an output whose public key has never been revealed is harder to attack. That holds for the address types that commit to a hash of the key. It does not hold for Taproot, where the output itself is a public key and is on the chain from the moment it is paid.
Example: A never-spent P2WPKH output has published only a hash; a never-spent Taproot output has published a key, so the two are not in the same position under this threat.
Quorum
How many keys of how many must sign — the m and n of an m-of-n multisig. Raising the threshold protects against theft and increases the ways to lock yourself out; lowering it does the reverse. 2-of-3 is common because it survives losing one key and losing one key to someone else.
Example: A 3-of-5 tolerates two losses, at the cost of coordinating three signatures for every spend.
Receive address
A string encoding the conditions under which a payment can later be spent. Wallets generate a fresh one for each payment, because reusing one publicly links every payment to it. The only trustworthy place to read one is the screen of the device holding the keys.
Example: Verifying a receive address on the hardware wallet rather than the computer is what defeats malware that swaps addresses in the clipboard.
Recovery phrase
The twelve or twenty-four words that encode a wallet's master secret. They are the wallet, not a password to it — anyone holding them holds the coins, and no company can reset or reissue them. Order matters, the wordlist matters, and a phrase written down wrongly is a wallet that no longer exists.
Example: Restoring a phrase into different software rebuilds the same wallet, provided the derivation path and any passphrase match.
Recovery test
Deliberately restoring a wallet from its backup, before the wallet holds anything you would miss, to prove the backup works. Everything else about a backup is an assumption until this has been done once. It is the step that most reliably separates people who have custody from people who have a wallet.
Example: A backup that has never been restored is a guess, however carefully it was written.
Regulation
The rules governing businesses that handle bitcoin — registration, identity checks, reporting. It governs intermediaries rather than the protocol, and it is not consumer protection: a registered platform can still fail, and registration is not deposit insurance.
Example: Registration sets rules for how a business must operate; it did not prevent any of the major platform collapses.
Reorganisation
When nodes switch to a different chain of blocks because it carries more work, discarding one or more blocks they had accepted. Short reorgs of a block happen occasionally and harmlessly. Deep ones do not occur naturally, which is why waiting for confirmations is meaningful.
Example: A transaction confirmed once can be undone by a one-block reorg; one confirmed six times effectively cannot.
Replace-by-fee (RBF)
Replacing an unconfirmed transaction with a version paying a higher fee. It is the normal way to unstick a payment you sent. Under BIP125 the original had to signal that it was replaceable; that is no longer the network-wide condition it once was, since Bitcoin Core made full replace-by-fee its default in version 28.0, and a node running that policy will replace a transaction that never signalled anything. Whether your own wallet can build the replacement is a separate question from whether the network will relay it. A replacement is also free to change its outputs, so an unconfirmed payment is not a promise about who gets paid.
Example: A payment stuck at a low fee rate can be bumped by broadcasting a replacement paying more, which miners prefer.
Reproducible firmware
Firmware whose published source code and documented build process can be independently rebuilt to produce the same binary distributed by the vendor. Matching builds provide evidence that the released firmware corresponds to the reviewed source, but they do not prove that the source itself is bug-free or safe.
Example: Independent builders compile a hardware wallet's tagged source release and compare the resulting firmware hash with the vendor's download.
- Hardware Wallets
- Open Source
- Security
- Firmware
Reserve currency
A currency held in quantity by other countries for trade and reserves. The status brings advantages to the issuer and is historically not permanent — previous holders lost it. Arguments about bitcoin's long-term role usually turn on whether that pattern continues.
Example: Reserve status is a position in a system rather than a property of a currency, which is why it has changed hands before.
Satoshi
The smallest unit bitcoin is divisible into: one hundred millionth of a bitcoin. Amounts are stored and transmitted in satoshis, and fee rates are quoted in them. Nobody needs to own a whole bitcoin, which is worth saying because unit bias leads people to think otherwise.
Example: A fee rate of 12 sats per vByte on a 140-vByte transaction costs 1,680 satoshis.
Satoshi Nakamoto
The name attached to bitcoin's original design and first implementation. The identity behind it is unknown, and the person or people stopped participating in 2011. The absence matters practically rather than romantically: there is nobody with authority to change the rules or answer questions about intent.
Example: Disputes about protocol changes are settled by node operators, because there is no author to appeal to.
Scalability
How a system copes with more use. Bitcoin's base layer deliberately limits throughput so that validating it stays cheap enough for individuals to do at home — the constraint is a choice, trading transaction volume for the ability of ordinary people to verify rather than trust.
Example: Larger blocks would allow more transactions and make running a node more expensive, which is the whole of the argument.
Scarcity
Limited supply that cannot be increased in response to demand. Most things called scarce are merely costly to produce, so a high enough price eventually calls forth more. Bitcoin's supply does not respond to price at all: a tenfold rise in value produces no additional issuance, because the schedule is enforced rather than chosen.
Example: Higher gold prices eventually fund more mining and more gold; higher bitcoin prices fund more mining and the same issuance.
Schnorr signatures
The signature scheme introduced with Taproot. Signatures are a fixed size, and several can be combined into one that verifies as a single signature — so a multisig spend can look identical to an ordinary one, which is cheaper and more private than publishing every key involved.
Example: A cooperatively spent Taproot multisig is indistinguishable on-chain from a single-key payment.
Script
The small stack-based language that expresses the conditions under which an output can be spent. Most outputs use one of a handful of standard patterns, so "who holds this key" is the usual condition — but the language allows others, including thresholds and time delays, which is what multisig and timelocked spending paths are built from.
Example: A 2-of-3 multisig output is a script saying any two of these three keys may spend this.
Script type
Which standard spending pattern an address commits to — legacy, wrapped SegWit, native SegWit or Taproot. It determines what the address looks like, what it costs to spend from, and which derivation path a wallet uses. Restoring a seed under the wrong script type produces a valid, empty wallet.
Example: The same seed produces completely different addresses depending on whether the wallet is set to legacy or native SegWit.
Secure element
A tamper-resistant chip designed to store sensitive data and perform security-critical operations in an isolated environment. In a hardware wallet it may protect secrets, enforce PIN rules, or assist with signing, but its presence alone does not prove the entire device or firmware is secure.
Example: A hardware wallet stores key material in a secure element while its main processor handles the display and user interface.
- Hardware Wallets
- Security
- Technical
SeedQR
A recovery phrase encoded as a QR code so a camera-based signer can read it in rather than having you enter words by hand. It removes transcription errors at the cost of making the backup machine-readable — anyone who photographs it has the wallet, with no need to read anything.
Example: A SeedQR is faster to restore from and much faster for someone else to capture in passing.
- Backups
- Hardware Wallets
- Risk
SegWit
A 2017 upgrade that moved signature data to a separate part of the transaction and discounted it when measuring size. That made transactions cheaper to spend, fixed transaction malleability, and created room for later upgrades. It was activated as a soft fork, so nothing was forced on anyone.
Example: Spending from a SegWit address costs less than spending the same value from a legacy one, because the signature data is discounted.
Self-custody
Holding the keys to your own bitcoin, so no company's solvency, policy or continued existence sits between you and it. It removes counterparty risk and transfers a specific set of jobs — backups, verification, recovery, inheritance — that an institution had been doing quietly on your behalf.
Example: Self-custody means there is no password reset, which is both the cost and the entire point.
Sequence number
A per-input field originally intended for transaction replacement, now carrying two meanings: signalling that a transaction may be replaced by fee, and enforcing relative timelocks. Its value is one of the details that identifies which wallet built a transaction.
Example: A wallet setting sequence to signal replaceability is what makes fee bumping possible later.
Shamir backup
A threshold backup method, commonly implemented for wallets as SLIP39, that divides a master secret into multiple unique recovery shares. A chosen minimum number of shares can reconstruct the wallet; fewer than that threshold do not reveal the master secret. SLIP39 shares are not ordinary BIP39 recovery words and require compatible recovery software or hardware.
Example: With a 2-of-3 Shamir backup, any two of the three shares can recover the wallet, while one share alone is insufficient.
- Backups
- Recovery
- Security
- SLIP39
Side channel
Learning a secret from a system's incidental behaviour — timing, power draw, electromagnetic emissions — rather than from its output. Secure elements are built to resist these, and their absence is why keys have been extracted from general-purpose chips by manipulating supply voltage.
Example: Voltage glitching a microcontroller during boot is a side channel attack, and it recovered seeds from devices with no secure element.
- Threats
- Hardware Wallets
- Security
Signature
Proof that the holder of a private key authorised a specific transaction, verifiable by anyone holding the matching public key. It commits to the transaction's contents, so altering any detail invalidates it. Producing one is the only thing a private key is ever used for.
Example: A signing device adds its signature to a PSBT and hands it back; the key itself never leaves.
Signet
A test network whose blocks are signed by a known party, so it behaves predictably instead of suffering the erratic mining that makes testnet unreliable. It is the better option for rehearsing a workflow end to end, and it carries the same warning: never on the device holding real keys.
Example: Signet produces steady blocks, which makes practising a full send-and-confirm cycle realistic.
Signing device
A dedicated device that holds private keys and signs transactions, commonly called a hardware wallet. The name is more accurate: it does not hold bitcoin and usually cannot see the blockchain. Its value is that the keys never reach a general-purpose computer, and that it has a screen the computer cannot rewrite.
Example: The computer proposes a transaction and the signing device disposes, displaying the details on its own screen before approving.
Silent payments
A scheme letting one published address produce a unique, unlinkable on-chain output for every sender. It solves the specific problem of needing a static address — a donation page, a profile — without the address reuse that would otherwise create. The cost is that the recipient's wallet must scan blocks to find its payments.
Example: A single published silent payment address receives many payments that nothing on the chain connects to each other.
SIM swap
An account-takeover attack in which a criminal causes a mobile carrier to move a victim's phone number to a SIM or device the criminal controls. Calls and text messages—including SMS login codes—can then be intercepted, which is why SMS should not be the strongest protection on an exchange account.
Example: An attacker takes over a phone number, resets an exchange password, and receives the exchange's SMS verification code.
- Security
- Threats
- Exchanges
- 2FA
SLIP-132
A registry of alternative version bytes that make an extended key's prefix announce its intended address type — ypub for wrapped SegWit, zpub for native SegWit, and capitalised forms for multisig. The key material is identical; only four bytes of packaging differ. Descriptors were designed to make the convention unnecessary.
Example: Software rejecting a zpub usually wants the same key expressed as an xpub with an explicit derivation path.
Social engineering
Attacking the person rather than the system — fake support staff, urgent messages, convincing impersonation. It is by a wide margin the most common way people lose bitcoin. The single reliable defence is a rule rather than judgement: nobody legitimate ever needs your recovery words, and nobody who contacts you first should be trusted.
Example: A message claiming your device needs its phrase re-entered for a firmware issue is the whole attack.
Soft fork
A rule change that tightens what is valid, so blocks made under the new rules are still accepted by nodes running the old software. It is the backwards-compatible way to upgrade and how SegWit and Taproot were activated. Nobody is forced to upgrade on any particular day.
Example: A node that never upgraded still follows the chain after a soft fork, simply without enforcing the new rule.
Sound money
Money whose supply cannot be expanded at the discretion of whoever issues it. The term comes from the argument that monies fail in a repeating pattern — they work until someone discovers how to make more cheaply, at which point holders lose value they had no part in deciding. What counts as sound is a claim about who controls issuance, not about price stability.
Example: Glass beads worked as money until industrial production made them cheap to manufacture, which is the failure the term describes.
SPV
Simplified payment verification: checking that a transaction appears in a block with sufficient work behind it, without validating the whole chain. It is how most light wallets work. The trade is that you verify inclusion rather than validity, and you generally reveal your addresses to whoever answers.
Example: An SPV wallet learns that a payment was mined without checking whether the rules were followed throughout.
- Connectivity
- Technical
- Privacy
Stale block
A valid block that lost the race — two miners found one at nearly the same moment and the network converged on the other. The transactions in it are not lost; they return to mempools and are mined again. Often called an orphan block.
Example: A brief fork resolves within a block or two, leaving one of the competing blocks stale.
Store of value
One of the jobs money does: holding purchasing power across time so that work done now can be spent later. It is a claim about durability rather than about price going up, and it is the function most sensitive to issuance — anything whose supply can be expanded cheaply tends to fail at it eventually, whatever else it does well.
Example: A currency can work perfectly well for daily payments while failing as a store of value over a decade.
Supply chain attack
Compromise introduced somewhere between manufacture and use — an intercepted parcel, a counterfeit unit, or a maintainer who spent years earning the right to publish releases. The three are different problems with different answers, and only multisig across vendors survives the case where the vendor is the problem.
Example: The most costly version is not sophisticated: a device shipped with a pre-filled recovery sheet that is really the attacker's wallet.
Sweep
Moving the entire balance controlled by a key into a different wallet, rather than importing the key and continuing to use it. Sweeping is the safe response to a key whose secrecy is uncertain, because it ends that key's relevance instead of relying on it.
Example: A paper wallet or gift card should be swept into a wallet you generated, not imported and reused.
Taint
The idea that a coin's history makes it more or less acceptable. The protocol makes no such distinction — every satoshi is identical to the rules — but services sometimes act on history anyway, which makes bitcoin imperfectly fungible in practice while remaining perfectly fungible in principle.
Example: An exchange freezing a deposit because of where the coins previously sat is acting on taint, not on any protocol rule.
Tamper evidence
Packaging meant to show whether a device was opened before it reached you. Worth something and much less than its theatre suggests, since seals are manufactured goods an attacker who can source a device can usually source too. The defence that actually works is procedural: never accept a secret the device did not make while you watched.
Example: A device arriving with recovery words already filled in is compromised regardless of how intact the packaging looks.
Taproot
A 2021 upgrade introducing Schnorr signatures and a way to commit to several spending conditions while publishing only the one used. A multisig spent cooperatively can look identical to an ordinary single-key spend, which is a privacy improvement as well as a cost one.
Example: Taproot lets a wallet keep an emergency recovery path that never appears on-chain unless it is actually needed.
Test transaction
Sending a small amount along exactly the route you intend to use before committing the rest. It proves the address, the wallet, the device and your understanding of all three, at a cost of a few dollars and one confirmation. It is the cheapest point in the process at which being wrong is survivable.
Example: The test is not a ritual for the nervous; it is the only step where a mistake costs five dollars instead of the balance.
Testnet
A parallel network with coins of no value, used for testing. It uses different address formats and a different coin type in derivation paths, so a testnet wallet is genuinely a separate wallet. Signing devices generally bury the setting deliberately, because a transaction believed to be testnet can spend real coins if the device is actually on mainnet.
Example: Testnet addresses start with different characters, which is the visible sign you are not on the real network.
Threat model
A structured assessment of what you are protecting, who or what could harm it, how likely those events are, and which safeguards address them. A useful Bitcoin threat model includes digital theft, physical loss, coercion, fire or flood, user error, privacy leakage, and the people who may need to recover the wallet.
Example: Someone living alone may prioritize recoverability and inheritance differently from a public figure who faces targeted physical threats.
Timelock
A spending condition that cannot be satisfied before a stated block height or elapsed time, enforced by every node rather than by any wallet's promise. It is the mechanism behind inheritance paths that open after a delay, and behind arrangements that make immediate transfer genuinely impossible.
Example: Coins locked until a future height cannot be moved by anyone, including under coercion, until the chain reaches it.
Tor
A network that routes traffic through several relays so the destination does not learn your address. Wallets use it to reach a node without exposing a home connection, and node software can publish an index server as a hidden service so a phone can reach it from anywhere without opening anything to the internet.
Example: Connecting a phone wallet to a home node over Tor avoids both port forwarding and revealing where the queries come from.
Transaction
A signed instruction that consumes existing UTXOs and creates new ones. It does not move an object; it retires some spending conditions and writes new ones. The fee is not a field in it — it is whatever the inputs exceed the outputs by, which is why a device that cannot see input values cannot tell you what a transaction really costs.
Example: Paying someone from a single large coin produces two outputs: theirs, and the change returning to an address of your own.
Transaction fee
The difference between a transaction's inputs and its outputs, claimed by whoever mines it. It is not a field anyone sets directly, which is why a device that cannot see input values cannot tell you the true cost — and why a dishonest coordinator could otherwise show a small fee while burning a large one.
Example: Getting the fee wrong by leaving out an output has cost people substantial amounts, since the surplus goes to the miner.
Transaction malleability
The old ability to alter a transaction's identifier without invalidating it, by changing the signature encoding. It broke anything that referenced an unconfirmed transaction by id, and fixing it was one of SegWit's main motivations — separating signature data means the identifier no longer depends on it.
Example: Malleability is why Lightning was impractical before SegWit fixed it.
Trustless
Not requiring trust in a specific counterparty, because claims can be checked instead. Overstated as a word: you still trust the software, the mathematics and your own hardware. It means the set of people who must behave well is small and inspectable, rather than empty.
Example: Running a node replaces trusting someone's answer with checking the rules yourself, which is what the word actually buys.
Two-factor authentication (2FA)
Requiring a second proof of identity beyond a password, typically a code from an app or a hardware security key. It protects accounts, not bitcoin you hold yourself — there is no account to log in to in self-custody. Not all second factors are equal: codes sent by SMS can be redirected by a SIM swap and are the weakest option commonly offered.
Example: Moving an exchange account from SMS codes to an authenticator app removes the SIM swap route entirely.
Unconfirmed
Broadcast but not yet included in a block. The money has left your available balance because the inputs are committed, but nothing is settled and nothing is lost. An unconfirmed transaction is usually underpriced rather than stuck, and can be replaced or bumped.
Example: An unconfirmed payment showing on an explorer after several hours is bidding below the current fee rate.
Unit bias
Judging value by the number of units rather than what they are worth, and concluding that something priced in whole numbers is cheap. It leads people to think a whole bitcoin is the meaningful quantity. Bitcoin divides into a hundred million satoshis, and owning a fraction is the normal case.
Example: Buying twenty dollars of bitcoin is a perfectly ordinary transaction and not a consolation prize.
UTXO
An unspent transaction output — one discrete chunk of bitcoin, of a particular size, spendable by whoever satisfies the conditions attached to it. A wallet's balance is not a number held anywhere; it is the sum of the UTXOs it can spend. Chunks are spent whole, so paying part of one produces change, and choosing which chunks to spend together is what coin control means.
Example: A wallet showing 0.4 BTC might hold one UTXO of 0.35 and two of 0.025, which is why a small payment can require moving the largest of them.
UTXO set
Every unspent output in existence — the complete record of what can currently be spent. Nodes keep it in memory to validate transactions quickly, so its size is one of the real costs of running one. Every transaction consumes entries from it and creates new ones.
Example: Consolidating many small coins into one shrinks the UTXO set slightly, which is a small public good as well as a private saving.
Vanity address
An address brute-forced to begin with chosen characters. Harmless if you generate it yourself and dangerous if someone else does, since whoever produced it may have kept the key. It also encourages address reuse, because the point of a memorable address is publishing it.
Example: A vanity address supplied by a third party is a key of unknown provenance, whatever it spells.
Verification
Checking a claim yourself rather than accepting it. It is the habit the whole practice rests on: verify the address on the device, verify the download signature, verify the backup by restoring it, verify the node is actually being used. Each replaces a belief with a fact.
Example: The difference between having a backup and having a tested backup is one afternoon of verification.
Virtual byte (vByte)
The unit transaction size is measured in for fee purposes. SegWit data is discounted, so a transaction's virtual size is smaller than its raw byte count — which is the mechanism by which SegWit and Taproot addresses cost less to spend from than legacy ones.
Example: Fee estimates are quoted in sats per vByte, so the same fee rate costs less on a native SegWit input than a legacy one.
Wallet
Software or a device that manages keys and builds transactions. It holds no bitcoin — nothing is stored in it — and the word covers arrangements as different as a phone app with keys on it and a watch-only program that cannot spend. Asking what a wallet holds is more useful than asking which wallet is best.
Example: A hardware wallet and the desktop software driving it are two halves of one wallet, and only one of them can sign.
Wallet descriptor
A structured description of a Bitcoin wallet's keys, derivation paths, script type, and spending policy. Also called an output descriptor, it lets compatible software reconstruct the same addresses. Descriptors come in two forms and the difference is the whole of their handling: a public one contains extended public keys, rebuilds visibility and cannot spend, while BIP380 equally permits extended private keys, and a descriptor containing those is spending material to be treated exactly like a seed.
Example: A multisig backup includes the public wallet descriptor so compatible software can rebuild the same 2-of-3 policy and derive the same addresses; a descriptor exported with its private keys would additionally be able to move the coins.
- Wallets
- Recovery
- Multisig
- Technical
Wallet fingerprinting
Identifying which software built a transaction from the choices it makes — locktime, version number, input ordering, RBF signalling, where change is placed. The pattern is consistent per wallet and leaks without any user action. No amount of careful coin selection affects it.
Example: If the same fingerprint appears on the spending side and on one output, that output is probably the sender's change.
Watch-only wallet
A wallet that tracks addresses, balances, and transactions without holding the private keys needed to spend. It can receive funds and usually construct unsigned transactions, but signing must happen in a separate wallet or hardware device. Importing an XPUB or descriptor can create a watch-only wallet while also exposing wallet history to the software or server used.
Example: Sparrow on an online computer watches the wallet and prepares a PSBT; an offline hardware wallet reviews and signs it.
- Wallets
- Security
- Privacy
- Technical
Withdrawal
Moving bitcoin off a platform to an address you control. Until it happens, the balance shown is a claim against a company rather than coins you hold, and the platform's solvency and access policies are part of your risk. The step that makes it safe is verifying the destination address on your own device before sending the full amount.
Example: Sending a small test amount first, confirming it arrives, and only then withdrawing the balance is the routine that catches a wrong address cheaply.
Witness
The signature data separated out by SegWit. Keeping it apart from the rest of the transaction is what allowed the size discount and what removed transaction malleability, since altering a signature no longer changes the transaction's identifier.
Example: A transaction's virtual size counts witness data at a quarter weight, which is where the SegWit saving comes from.
Wordlist
The fixed list of 2,048 words a recovery phrase draws from. Each word stands for exactly eleven bits, no two share their first four letters, and the list is language-specific — the same phrase written in a different language's wordlist produces an entirely unrelated wallet. Record which language was used.
Example: Because prefixes are unique, stamping the first four letters of each word onto metal is a complete backup.
Wrench attack
An attack that bypasses cryptography entirely by coercing the owner into handing over their keys or moving funds. Also called the $5 wrench attack, after a well-known comic observing that an adversary is far more likely to threaten a person than to break their encryption. Because no key length or signing policy applies, the defences are different in kind: discretion about holdings, arrangements that make immediate transfer genuinely impossible, and keeping a small amount available to surrender.
Example: A holder is confronted at home and forced to unlock a wallet. A device login delay buys minutes rather than safety, since a backup can be restored on another signer. Only a spending policy enforced by the coins themselves, such as a timelock, makes "not tonight" true rather than inconvenient.
xprv
An extended private key: a private key packaged with the chain code needed to derive every key beneath it. Whoever holds one can spend everything in that part of the wallet, so it should never be exported, photographed, or typed into software. Its public counterpart, the xpub, derives the same addresses but cannot spend from them.
Example: Software that offers to export an xprv is offering the whole wallet — including every address it has not generated yet.
Zero-knowledge proof
A proof that a statement is true which reveals nothing beyond its truth: not the values behind it, and not how the prover knows. Bitcoin's base layer does not use them, and encountering the phrase in a bitcoin context usually means one of three things: an exchange proving reserves without publishing every address, a sidechain or rollup proving its own state, or a project whose privacy claims deserve reading closely. The mathematics is real and long-established; whether a given product needs it is a separate question.
Example: A proof-of-reserves scheme can show that customer balances are covered without disclosing which addresses hold them or what any one customer holds.
zpub
An extended public key serialised with SLIP-132 version bytes indicating native SegWit. It is the same key as the equivalent xpub, wearing a prefix that tells the receiving wallet which address type to derive. Converting between the two moves no coins and changes no keys.
Example: Importing a zpub into software that only accepts xpubs requires converting the prefix, not re-deriving the wallet.