How much bitcoin does Satoshi own, and has any of it moved?
Since 2020, 28 coins mined in Bitcoin's first 16 months have woken up, and each time the headlines asked whether the founder was finally spending. The checks that did happen leaned on published lists, and the last published spend count — one line in a 2022 essay — predates every awakening since. We rebuilt the fingerprint behind them from the raw blocks, graded all 54,316 blocks of the era, and followed every coin to 1 September 2026, down to the satoshi.
Just after half past six on the morning of 20 September 2024, universal time, five bitcoin wallets began to wake up, one after another across three quarters of an hour. Each held 50 bitcoin. Each had been still since the winter of 2009, when Bitcoin was a few weeks old, almost nobody had heard of it, and its inventor was mining most of its blocks alone. About $16 million crossed the chain before breakfast, and the same question ran through every feed that covers this industry: was this Satoshi Nakamoto, finally spending?
It was a checkable question, and one person checked it that afternoon: Jameson Lopp, who has dug deeper than almost anyone into the fingerprint those early blocks carry, posted that none of the five blocks sit in it. Then the story moved on. No publication ran the comparison, and the last published spend count, one aggregate line in a 2022 essay of Lopp's, predates every awakening since.
We rebuilt the whole thing from scratch and ran the comparison without leaning on anyone's list. On 4 of the 5 coins we agree with Lopp. On the fifth the answer is less tidy, and that fifth coin is a good introduction to what this audit is about: once you can grade every early block yourself, a better question opens up than the one the headlines ask. How much bitcoin does the founder's mining actually cover, and has any of it, ever, moved?
The evidence that lets anyone talk about Satoshi's fortune is a fingerprint in Bitcoin's earliest blocks, found in 2013 by the researcher Sergio Demián Lerner and known since as the Patoshi pattern. Bitquery indexes the complete Bitcoin chain, so instead of quoting the literature we rebuilt the fingerprint from the raw blocks and graded every block of the era by how confident the pattern is. We locked that answer, committing its file hash before comparing it with anyone else's. Then we audited every coin the pattern covers, down to the satoshi (the smallest slice of a bitcoin), as of this month. One caution belongs this early: what the pattern identifies is a machine. The link from that machine to the name Satoshi Nakamoto rests on the pattern starting at the network's birth and on two early payments the inventor is known to have sent. It is strong, and it is circumstantial, so where precision matters we write "the Patoshi miner".
01 — The fingerprintA counter nobody knew they were leaving
Bitcoin mining is organised guessing. A mining program runs through candidate numbers, called nonces, until one makes its block valid. The 2009 software kept two such numbers: a small one it cycled through quickly, and a spare counter, the extranonce, that ticked up each time the small one rolled over. The extranonce was written into every block it helped mine, it climbed for as long as the program stayed running, and it fell back to near zero whenever the program restarted.
Most miners' software restarted all the time. One miner's did not. In the chain's first year there is a machine whose counter climbs in long, steady, unbroken lines, day after day, pausing every four to six days, a rhythm consistent with someone stopping to back up their wallet. The same machine had a second habit: the small number it reported always sat in a few narrow bands, where everyone else's ranged over the whole space. Together the two habits mark thousands of blocks as the work of one machine.
Lerner noticed the lines in 2013 and estimated the machine had mined about a million bitcoin, refining the count years later. Others rebuilt it independently: BitMEX Research, arguing the later months were too messy to attribute and the defensible floor was lower; Whale Alert, with the most generous count; a university team; and Jameson Lopp. Their answers disagree by half a million coins, and the disagreement has never been explained in one place. The popular trackers made it worse: the figure most net-worth pages carry today matches, to within 52 BTC, a table whose own authors wrote that it overestimated, in a post arguing for a smaller number. Live trackers like Arkham do follow the balances continuously, but over inherited lists; re-deriving the attribution itself, coin by coin, is the part nobody had redone.
Grading every block before looking at the answer
Reproducing someone's conclusion by copying their block list proves nothing, so our classifier never read one as input: the only list-derived blocks it ever saw were the 21 pre-registered anchor test blocks, 19 expected in and 2 expected out, used to select thresholds. The block-level comparison with public lists happened only after our labels were finished and their file hash committed. The first run's settings were written down before it ran, and its result, far fewer blocks than the public list carries, is in the table below, because everyone in this field tunes their method and almost nobody shows the before. Every change made after that first run is logged, including the one that mattered most, a lower floor on line slope that the earliest weeks of mining turned out to need, worth roughly a sixth of the final total. The full strictness sweep is published alongside the article. The frozen result carries a grade on every block.
The raw material was rebuilt from sources that cannot quietly disagree with each other. Block headers came from the Bitcoin network itself, each verified by the unbroken chain of hashes that links every block to the next, and the mining scripts came from our own index, spot-checked at random against independent public explorers. The grading held up under three checks. Our highest grade agrees with the public list on 99 of every 100 blocks. Its highest grade reproduces the strangest known property of the true set: across thousands of consecutive pairs of high-grade blocks, the clock never once runs backwards, where bystander blocks inserted the same way would be expected to produce dozens of reversals. The blocks only our list contains do produce reversals where they meet the rest, at about double the background rate, exactly what splicing unrelated blocks into a sequence does, and one more reason to keep them away from positive verdicts. And the share of each grade that was ever spent climbs exactly as trust falls, which is what it should do if the grades mean anything, because the one thing everyone agrees on is that this miner did not spend. The pre-registered anchor blocks, the ones whose status every earlier study agrees on, came back 18 of 19 with neither known negative admitted; the single miss, one of the coins the miner himself gathered up in 2010, is a false negative we report rather than repair.
| First run, pre-registered settings | 15,803 blocks |
| Frozen set | 23,466 blocks — 8,329 high / 6,662 medium / 8,475 low |
| Strictness sweep, full range | 17,708 – 23,466 blocks |
| Agreement with the public list, high grade | 99.2% |
| Timestamp inversions, high grade | 0 in 5,836 height-adjacent pairs, 0 in all 8,328 successive pairs |
| Pre-registered anchor blocks recovered | 18 of 19, 0 negative-anchor hits; the miss, block 15,625, is a known false negative |
| Header hashes vs our index | 120,001 of 120,001 identical |
| Explorer spot-check of mining scripts | 80 of 80 exact |
The rules, the thresholds, the first-run number, the full strictness sweep and the per-block output are published alongside the dataset, and every change made after the first run is in the log.
03 — The auditFollowing every coin
A block reward from this era is a single coin of 50 BTC that has either been spent, once, or never. So the fortune can be audited the way an accountant audits anything: line by line, with nothing estimated. We joined every coin in the set against every spend in Bitcoin's history.
In our set, 1,023,352 BTC has never moved, about $79 billion at the 1 September price of $77,582. On the public list the share is even higher: 1,096,102 of its 1,097,652 BTC, which is 99.86%, about $85 billion. Through year after year of bull markets, crashes, hacks, forks and repeated waves of "Satoshi is moving" headlines, the catalogued fortune has not gone anywhere.
What has ever left it fits in one table.
The early rows are the known story: the first test payment to Hal Finney in January 2009, a handful of experiments that spring, the payment to the developer Mike Hearn in April. The night of 17 May 2010 is less told. In two transactions, an hour apart, the miner gathered up the rewards of a dozen old blocks. The university team's paper names the first transaction and the ten rewards it swept; the second, which swept two more, we have not found described anywhere. It changes nothing about the total and something about the picture: this was deliberate housekeeping, done at the keyboard two weeks after the machine mined its last attributed block. The keys outlived the mining.
The rows after 2010 look different. Eleven more coins trickled out over the following seven years, at the pace and in the pattern of unrelated early miners cashing in. Ten come from the list's weakest region, which is the strongest everyday evidence that the list's edges, everyone's edges, carry other people's coins. The eleventh, an early 2009 block our grading rates highly, is a place where we part company with the most thorough earlier sweep of spent rewards: Whale Alert examined every spent block reward that matched the pattern, kept 19 as confidently the miner's, and set the rest aside as probable look-alikes, a sieve this block, spent in 2011, would have fallen into. Our line evidence cuts the other way, it sits dead on a long line that carries two of the anchor blocks, so we publish the disagreement rather than resolve it. The last of them moved in December 2017. Since then the public list has sat entirely still, through the 2021 mania and through the record highs that followed.
The table also settles, at transaction level, a dispute the literature has carried for years. Lerner's page counts about 550 BTC paid out to other people as donations; Whale Alert counted 907 spent; Lopp wrote that fewer than 20 rewards ever moved. Each was a reading of a different slice of the same ledger, a different era or a different confidence filter, and none was published transaction by transaction. The full accounting is above, and it is short.
04 — The awakenings28 coins, every headline, one check
Which brings back the coins that keep making the news. Since the start of 2020, exactly 28 rewards from before the machine went quiet have been spent, 1,400 BTC in all. Ten of the 28 sit past the public list's edge, where attribution is weakest either way; the other 18 fall squarely inside its coverage. Each cluster produced its round of speculation. Here is each one against the fingerprint.
| Coin mined in | Woke up | BTC | Public list | Our verdict |
|---|---|---|---|---|
| Block 3654 | 2020-05-20 | 50 | not on list | cleared |
| Block 54171 | 2020-12-27 | 50 | beyond list coverage | cleared |
| Block 49645 | 2021-01-03 | 50 | not on list | cleared |
| Block 49711 | 2021-01-03 | 50 | not on list | cleared |
| Block 49709 | 2021-01-03 | 50 | not on list | cleared |
| Block 49664 | 2021-01-03 | 50 | not on list | cleared |
| Block 49428 | 2021-01-03 | 50 | not on list | cleared |
| Block 49258 | 2021-01-03 | 50 | not on list | cleared |
| Block 53784 | 2022-02-04 | 50 | beyond list coverage | cleared |
| Block 27811 | 2022-04-07 | 50 | not on list | cleared |
| Block 27749 | 2022-04-07 | 50 | not on list | cleared |
| Block 27742 | 2022-04-08 | 50 | not on list | borderline (low) |
| Block 27694 | 2022-04-08 | 50 | not on list | cleared |
| Block 27693 | 2022-04-08 | 50 | not on list | borderline (low) |
| Block 50153 | 2023-04-22 | 50 | beyond list coverage | cleared |
| Block 52871 | 2024-03-14 | 50 | beyond list coverage | cleared |
| Block 52565 | 2024-04-15 | 50 | beyond list coverage | cleared |
| Block 2247 | 2024-09-20 | 50 | not on list | cleared |
| Block 2401 | 2024-09-20 | 50 | not on list | cleared |
| Block 2455 | 2024-09-20 | 50 | not on list | borderline (medium) |
| Block 2486 | 2024-09-20 | 50 | not on list | cleared |
| Block 2690 | 2024-09-20 | 50 | not on list | cleared |
| Block 51604 | 2025-07-31 | 50 | beyond list coverage | cleared |
| Block 53338 | 2025-07-31 | 50 | beyond list coverage | cleared |
| Block 53607 | 2025-07-31 | 50 | beyond list coverage | cleared |
| Block 53698 | 2025-07-31 | 50 | beyond list coverage | cleared |
| Block 53087 | 2025-07-31 | 50 | beyond list coverage | cleared |
| Block 45711 | 2025-12-02 | 50 | not on list | cleared |
The five coins of that September morning: Lopp called all of them clear the same day. Our independent rebuild agrees with him on four. The fifth, block 2455, is the most interesting cell in the table. Our re-derived set contains it at the middle grade; the public list does not carry it, and neither did his call. Under the rule we fixed before any of this ran, calling a movement Satoshi's requires our highest grade, agreement from at least one independent list, and outside verification of the spend. Block 2455 fails two of the three, so the verdict is borderline. It may be a false positive of ours; our classifier is known to over-collect in that region. Two commonsense checks agree with that reading. The five coins moved one after another within three quarters of an hour, the way one owner moves one wallet, and four of the five are clear; and block 2455 carries one of the loosest line fits in the whole set. The two borderline blocks from April 2022, which share a single circle in Figure 4, sit in the same category, at the lowest grade. The line that carries them is mostly made of coins spent long ago, which is the signature of other people's mining. The grades exist so cases like these can be reported as boundary cases rather than forced into a verdict.
Everything else clears. The six coins of one January day, the summer sweep of five rewards through a single block, the miner who surfaced last December after a decade and a half of stillness, all of them sit outside every list, ours and everyone's. Their owners are, as far as the fingerprint can say, the other people who were there: hobbyists who mined at the very beginning, held longer than almost anyone in the asset's history, and finally sold. The awakened coins moved to fresh addresses with no exchange label in our directory. We checked only that first hop and traced no further.
05 — The numberSo how much bitcoin does Satoshi own?
The answer is a range with a firm top. Run strictly, the fingerprint covers a little under a million bitcoin. Loosening the rules raises the count, and our frozen reading of 1.17 million is the most generous setting that still rejects both of the known test negatives, so strictness only ever moves the total down from it. That lands just above the top of the published cluster, and close to every serious estimate since the first. Of that, 1,023,352 BTC provably has not moved, at any point, through the first of September. At the day's price that is roughly $79 billion sitting exactly where it was mined, the figure behind every Satoshi Nakamoto net worth estimate, and enough to place the Patoshi miner among the richest few dozen people on earth, on the strength of work done on one computer over 16 months.
Whether it will ever move is not a data question. What the data says is narrower and firmer: it has not, about two-thirds of the little that ever moved was the miner's own housekeeping in 2009 and 2010, and of the 28 awakened coins that fuelled 6 years of speculation, not one meets the standard of evidence the question deserves.
Lerner, who found the pattern, deliberately declined to publish his own block list, writing that digging further would enter Satoshi's privacy, and this audit takes the line seriously even as it publishes a sharper dataset. The files here map blocks to grades and spend status, and stop there. We did no address clustering and no identity work, and nothing in the dataset connects the pattern to a person beyond the two payments history already records. If anything, the finding runs the other way: of the 28 awakened coins that headlines have hung on the founder, this audit clears 25.
The record
- The first payment
- f4184fc596403b9d638783cf57adfe4c75c605f6356fbc91338530e9831e9e16Block 9's reward to Hal Finney, January 2009 — the transaction that ties the pattern to the person
- 17 May 2010, tx 1
- 499d0f5d452891ebe18a8c23cc0a554459a0ba3341ef021f3fae15926a977ffd10 rewards gathered in one transaction, named in the 2022 university study
- 17 May 2010, tx 2
- 028ad2c836163295e4723a49dd418ee8fb55a14613b1186675f01124b60fb7632 more rewards, an hour later — described nowhere we can find
- The September 5
- 2247 · 2401 · 2455 · 2486 · 2690The 5 blocks whose rewards woke on 20 September 2024; only 2455 is flagged at all, by our set alone, at the middle grade
- The dataset
- patoshi-audit-dataset.csvAll 54,316 blocks: grade, public-list membership, spend status and spending transaction — the audit in one file
- The sweep
- classifier-sweep.tsvEvery configuration tried, with anchor results — the sensitivity curve behind Figure 2
- The receipts
- method-changelog.md · anchors.tsvThe complete change log with the freeze commitment hash, and the 21 pre-registered anchor blocks behind Table 1
- The public list
- github.com/bensig/patoshi-addresses21,953 blocks reconstructed from Lerner's research; the list our audit is graded against
Method
How this was measured
Headers for blocks 0 through 120,000, all 120,001 of them, were fetched from the Bitcoin peer-to-peer network and verified by their hash chain; the copy in Bitquery's index, the same one behind our audit of what fills Bitcoin's blocks, agreed on every hash and every timestamp. Coinbase scripts, the note a miner writes into the transaction that creates each block's reward, were checked against two public explorers on a random sample with no disagreements, and every one from the era decoded cleanly. The classifier is the published pattern run as written rules: the nonce bands, plus ascending constant-slope extranonce lines found by a seeded, deterministic fit, with the first run's settings written down before it ran, every later change logged before any list comparison, and a strictness sweep published instead of a chosen point. Blocks are graded high, medium or low (high means a line of at least 200 blocks, a residual within 30 counts and a height below 20,000, which is late July 2009; the exact formula ships with the dataset). The thresholds were selected on the 21 pre-registered anchor blocks, and the grades were then tested out of sample against list agreement, spend behaviour and the timestamp ordering test in Table 1.
The spend audit joins every block reward of the era against every spending input in Bitcoin's history, to block 965,051 on 1 September 2026, so "never moved" is a statement about the complete chain rather than a sample. The method has two limits. First, attribution weakens after mid-2009 and is weakest past block 49,973; verdicts there are labelled as such wherever they appear. Second, applying the same rules beyond the era's end, where the pattern should find nothing, still collects about 4,300 blocks, and that false-positive rate is measured and reported here rather than hidden: that measured rate sits behind three design choices: the grades, the verdict bar, and a range instead of a point estimate. The same construction sets the method's floor: a continued operation shorter than about 50 blocks on a single line would be invisible to it. The same questions can be put to the same data through Bitquery's MCP server or the Bitcoin API.
Take the false-alarm rate measured beyond the era and scale it to the era itself: it predicts three to four thousand look-alikes inside the frozen set, enough to account for every block we flag that the public list does not, and the per-grade counts match as well. So the additions beyond the list are candidates rather than discoveries, and the defended core of this audit is the 19,928 blocks where the two constructions agree. Shuffling the counter column into noise and running the same pipeline still flags about two-thirds as many blocks, which is why no single flag, ours or anyone's, is evidence on its own. Little of this reaches the unmoved total. The candidate blocks contribute 28,200 BTC of the 1,023,352 that has never moved, because most of them were spent long ago, and the agreed core alone accounts for 995,152 BTC of it. Two smaller notes for anyone working from the dataset: the beyond-the-era measurement can only produce low-grade flags, because the higher grades require an early height by definition; and published residuals are measured against each line's final merged fit, so a block can carry a residual above the fitting tolerance that admitted it, block 2455 being the loudest example.
Questions people ask
Run it yourself
Every figure above is a query against the public chain. Ask the same questions of the live index through the Bitquery MCP server, or start from the Bitcoin API examples.