Bitcoin's security budget has a scheduled expiry date.
That is the uncomfortable premise behind a talk Peter Todd gave at bitcoin++ in Toronto, published on 14 August 2026. His proposal is that Bitcoin should keep paying miners forever, and that if the network will not accept new coins to do it, it should tax the existing ones instead.
The reaction was immediate. Adam Back, whose Hashcash Todd cites as ancestry for proof of work, called the framing a trap. Below is what Todd actually argued, what the numbers support, and where the objections land.
The claim that proof of work was never about making coins
Todd opens with a concession about his own past. He says that when he was, in his words, trying to be Satoshi and invent Bitcoin, he completely got this wrong, and that Adam Back did too. Both of them thought of proof of work primarily as the mechanism that creates coins.
His current position is that issuance is a byproduct. Proof of work exists to produce consensus, to make the network agree on which block comes next. Paying miners in new coins is one way to fund that, not the point of it.
This reframing does the load-bearing work in everything that follows. If the subsidy is just a funding mechanism, then removing it raises an engineering question rather than a moral one. If the 21 million cap is the product itself, the question never gets asked.
Where the security budget actually stands
Fees are a rounding error in miner revenue. As of August 2026 they account for roughly 0.69 percent of it, a ten-year low. Rafael Schultze-Kraft, co-founder of Glassnode, pointed out that Bitcoin last traded below 400 dollars when the fee share was this depressed. Capriole Investments called it the least discussed concerning development in Bitcoin this year.
The arithmetic of replacing the subsidy is unforgiving. At current throughput of roughly five transactions per second, covering a block reward worth about 200,000 dollars would require every transaction on the network to pay something near 66 dollars. Blocks today collect on the order of 1,000 dollars in fees.
Todd's read on the fee spikes is that they do not last. Inscriptions and Runes drove real fee revenue in 2024, briefly pushing average fees to around 127 dollars, and then the inscription community moved to smaller payloads and the revenue evaporated. He describes these episodes as a flash in the pan.
The subsidy falls to 1.5625 BTC at the next halving in April 2028. The final satoshi arrives around 2140, but the trajectory is the issue, not the endpoint.
Why a fixed tail emission converges
The counterintuitive part of Todd's case is that a permanent block reward does not mean permanent inflation.
Coins are lost. People die without passing on keys, drives fail, passphrases are forgotten. The rate of loss is proportional to the supply rather than a fixed quantity, because losing coins is a probability applied to holdings, not a headcount. Todd's framing is that whether you hold one coin or ten does not change your odds of a boating accident.
Set a fixed number of new coins per block against a proportional loss rate and the supply converges. In his 2022 essay he writes it as a differential equation, dN/dt = k - λN, which settles at k/λ, the point where coins are created exactly as fast as they disappear.
In the talk he skips the calculus for a leaky bucket. Water pours in at a constant rate, and the hole at the bottom drains faster as the water rises. Below equilibrium the level climbs, above it the level falls, and it ends up in the same place either way.
Monero is the working example, adopting tail emission in 2022 at what amounts to roughly 0.9 percent apparent inflation. Todd is careful not to endorse the reason Monero needed it, which was its dynamic block size design, and he notes there are scenarios where that design fails on consensus grounds.
The number Todd has not pinned down
The convergence argument is mathematically sound and practically incomplete, and the gap is worth stating plainly.
Convergence tells you a stable point exists. It does not tell you where. That depends entirely on the real loss rate, which nobody can measure. Todd concedes this directly, comparing it to dropping a golf ball: he does not need to know the height to know it lands.
His own numbers have moved. The 2022 essay uses roughly 1 percent per year. In the Toronto talk he suggests something closer to 0.1 percent. Secondary coverage of the debate has attributed a 0.5 percent figure to him. That is an order of magnitude of spread on the one input that determines whether the policy is trivial or expensive.
He supplies the cost framing himself. Compounded over a 50 year saving life, 1 percent per year erodes about 64 percent of a holding, while 0.1 percent costs about 5 percent. His argument is that paying 5 percent of your savings to keep those savings secure is a reasonable trade, and that Bitcoin's price volatility swamps the difference anyway.
Whether 64 percent also counts as reasonable is a different conversation, and it is the one his critics are having.
Demurrage as the soft fork workaround
Todd does not expect tail emission to happen. He asked the Toronto room to raise hands for anyone who thought a hard fork was likely within five years, and treated the response as settling the matter.
So he proposes reaching the same place without minting anything. Inflation, he argues, is a tax on savings, redistributing purchasing power from holders to whoever receives the new units. If that is what tail emission does economically, then a direct tax on holding coins does the same job without touching the supply cap.
The mechanism works on coin-days destroyed. For each block, sum the value of the transaction outputs being spent, multiply by how long each has existed, and apply a rate. That product becomes a tax the block owes. A new consensus rule requires the coinbase transaction to assign that amount to a fund, and miners may withdraw only a capped percentage of that fund per block, which spreads the payout over time instead of handing it to whoever mines next.
No coins are created. The rule only constrains how existing value moves. That, in Todd's framing, makes it a soft fork.
The case against
Adam Back rejects both the mechanism and the framing. He has characterised the pitch as an attempt to mislead people with a flawed narrative in service of proposals he considers dangerous and undesirable, and he points at BIP-110 as the practical answer. That data-filtering soft fork drew about 2.53 percent miner support in 2026. Back's argument is that if a modest soft fork could not clear the bar, a change touching the supply cap has no path at all.
Michael Saylor's objection is about neutrality. Bending consensus rules to solve a funding problem sets the precedent that consensus rules bend for funding problems.
The sound money objection is the oldest and the least technical. It surfaced in November 2025, when the same talk circulated after Todd delivered an earlier version at the Hoover Dam conference.
That position treats the fixed supply as the product rather than a parameter of it. On that reading, a network that taxes holdings to pay for its own security has already lost the argument it was built to win, whatever the security budget looks like afterwards.
Todd's reply set the tone for much of what followed.
There is also a narrower technical objection to the soft fork label. A rule that reduces what existing holders can spend changes the economic position of every coin, whether or not the supply cap moves. Calling that a soft fork is accurate about the code and contested about the substance.
The pushback Todd accepted
The most useful part of the talk is the Q&A, because Todd concedes more there than in the presentation.
Asked to justify the convergence claim, he defends the direction but not the destination, and admits he does not know the numbers.
Asked whether an inflation tax and a demurrage tax are genuinely equivalent, he answers yes, absolutely, they are not. His use of equivalent means approximately, and he offers a hypothetical 50 percent demurrage rate to show where the equivalence breaks. He goes further and allows that demurrage may be the better instrument precisely because the rate is settable, where a tail emission's effective rate is whatever the loss rate happens to be.
He also cuts off an argument he does not want. Demurrage has a long history in economics as a way to force spending and discourage hoarding. Todd says that tradition is irrelevant to his case, describes himself as relatively speaking an Austrian economist, and frames demurrage strictly as a funding mechanism for a public good.
What the fight is actually about
Strip out the monetary politics and a narrower argument remains, and it is the one that gets the least attention.
The reorg concern is not that Bitcoin dies. Todd allows that a fee-only chain with occasional reorganisations might be survivable if people simply wait for more confirmations. The cost he cares about is who gets to mine.
Reorganising the chain to capture a fee-rich block is only rational if you have enough hash power to expect consecutive blocks. A miner in a garage has effectively zero chance and treats any block as a windfall. A miner at 49 percent has real opportunities. Cooperative structures like P2Pool cannot coordinate a reorg at all, which means that in a high fee-variance world they would be structurally disadvantaged against pools that can.
Fee variance is not hypothetical either. Block discovery is a Poisson process, so long gaps between blocks are normal, and each long gap stacks up transactions bidding against each other. Todd cites Marathon's Slipstream as evidence miners will build machinery to capture marginal revenue, while noting he does not consider Slipstream itself a significant threat.
The academic footing predates all of this. Carlsten, Kalodner, Weinberg and Narayanan published the fee-only instability result at ACM CCS 2016, showing that the variance of fee-based rewards makes forking a wealthy block attractive and produces an equilibrium with bad properties, and in some conditions no equilibrium at all.
Andrew Poelstra's line, which Todd quotes, holds up better than either side's rhetoric. The subsidy going to zero is a scary phase change. Bitcoin works well in the regime it has always operated in, and it is marching toward one where no proof of work network has ever operated at scale.
Todd's answer is to pay for consensus permanently. His critics answer that a Bitcoin which taxes its holders to buy security is no longer the thing worth securing. Neither side can produce the evidence that would settle it, because the experiment has not run yet.
I work in the crypto self-custody space, and the part I would not wave away is the decentralisation argument. The 21 million debate will get decided politically, probably by nobody doing anything. Whether fee variance quietly pushes mining toward the operators large enough to reorg is a question with a technical answer, and it arrives long before 2140.
