Bitcoin has been declared dead, banned, and out-competed more times than anyone has counted.
This page takes every credible risk on its own terms — and asks what would have to be true for each one to become a real threat.
Bitcoin is seventeen years old. In that time it has been declared dead several hundred times, banned outright by China in six escalating rounds, and challenged by thousands of cryptocurrencies promising to do what it does, only better. It is still here. As of 2026 it accounts for the overwhelming majority of all the hash power devoted to proof-of-work networks combined — more security than every rival chain put together, by a wide margin.
Yet Bitcoin is not just here. A thing subjected to seventeen years of attacks, bans, crashes, forks, and well-funded competition does not merely survive by luck. It survives, and thrives, because of its particular properties, its singular credibility, and a growing network of participants — users, miners, node-runners — and it grows structurally stronger as it does: more hash power securing it on average over time, a longer chain of accumulated proof-of-work behind it, and, by the simple logic of the Lindy effect, a longer track record with every year that it persists. Bitcoin is not merely resilient but antifragile, and in this it stands close to alone.
The way to test that claim is not to wave the risks away but to state each one in its strongest form and ask what it would actually take to make it real. So that is what follows: ten risks, grouped into four categories, each given the strongest version a thoughtful critic would make, followed by a careful reply — including, where appropriate, the admission that the question is not yet settled. Every section ends the same way: the observable markers that would tell us the risk is becoming credible. Not reassurance — specifics.
One pattern recurs often enough to name up front. Bitcoin has tended to survive its threats not by adapting to them — not by twisting and re-engineering itself each time it is challenged — but by refusing to change at all. Its inertia is not a weakness it has failed to fix. It is, as the sections below keep finding, the immune system itself.
The attacks from outside — the state, and the physical world.
The case. States have the means and the precedent. In 1933, Executive Order 6102 confiscated American gold by decree. A government that wanted bitcoin gone could criminalize mining, ban custody, cut exchanges off from the banking system, and prosecute holders — and a coordinated bloc of major economies acting together could, in principle, choke the on-ramps that connect bitcoin to the rest of the economy. This is the risk every other risk borrows its fear from: not that Bitcoin breaks, but that the people who run the financial system simply decide it is not allowed.
The reply. China has banned Bitcoin — six separate times over seventeen years, escalating from a 2009 ban on virtual-currency payments to Circular 42 in February 2026, which reaffirmed a total ban on mining and trading. The most aggressive attempt, in mid-2021, ordered every mining operation in the country to shut down at once, on pain of strict penalties. Global hash power fell by roughly half in a matter of weeks. It was the closest thing to a kill-shot any nation has tried.
Yet within roughly six months, hash power had fully recovered. Some of the miners relocated abroad; some simply came back online inside China. And by most estimates a substantial share of mining — by various estimates on the order of 15–20% of the global total — quietly operates inside the country to this day, through stranded energy and distributed sites, despite the ban. The most determined ban by the most centralized and capable administrative state on earth did not end bitcoin mining; it dispersed it, temporarily, and then watched a meaningful fraction grow back.
The reason is structural. Gold could be confiscated because confiscation was practical: it is heavy, it sits in vaults, and the state could seize the physical metal. Bitcoin inverts those properties. A ban does not destroy the coins; it relocates the capital — easily, seamlessly, and quickly — to more Bitcoin-friendly jurisdictions, of which there are always many, by simple game theory. There is no winning hand to be had from a nation-state banning bitcoin: the wealth and the productive activity simply leave for the country that declined to join the ban, which is then rewarded for declining. A ban cartel is a game in which every member has a standing incentive to defect. This is why a 6102-for-bitcoin is not merely difficult to enforce but self-defeating: it exports the very thing it meant to capture.
And the attempt itself carries a quieter implication, which belongs here only after the threat has been taken seriously: the very act of a state moving to ban bitcoin inadvertently underscores that bitcoin is a credible threat to the legitimacy of that state's own fiat money. A government does not expend force prohibiting what does not concern it. The ban is a tell.
A counter-trend runs the other way, and is worth noting. Increasingly, governments recognise that miners provide real value — jobs, flexible load-balancing for power grids, and tax revenue — and are becoming embedded contributors to local and national economies rather than targets for prohibition.
The case. Bitcoin needs electricity and the internet. A sufficiently large catastrophe — a Carrington-class solar storm of the kind that struck in 1859 and narrowly missed in 2012, a high-altitude electromagnetic pulse, or a sustained shutdown or partition of the global internet — could knock out power and connectivity across whole continents for months. Mining would stop. Transactions would stop. Nodes would go dark. And in a more mundane version of the same worry, raised often: Bitcoin relies on the internet, so what happens if the internet goes away?
The reply. This risk turns on a distinction the rest of the page uses too: the difference between Bitcoin's operation and Bitcoin's record. A blackout or a partition threatens the network's ability to process new transactions while it lasts. It does not threaten the ledger of who owns what.
Three facts carry the point. First, solar storms damage long conductors — transmission lines and grid transformers — not the small electronics in a drawer. And critically, they do not touch unpowered storage at all: a hardware wallet sitting in a drawer holds its keys whether or not it ever powers on again, and a seed phrase stamped in steel, or even just written on paper, is wholly indifferent to space weather. To answer the hardware-wallet question directly: your coins are not in the device; the device holds the keys that prove ownership of coins recorded on a ledger replicated worldwide. Destroy every hardware wallet on earth and the coins still exist on the chain, recoverable by anyone who kept their seed phrase. (This is often confused with nuclear EMP, a different and more localized phenomenon — and even that does not reliably erase unpowered storage.) Second, the worst effects of such events are regional and hemispheric, not uniform and global. Third, and decisively, the blockchain is not stored anywhere in particular: it is replicated in full across tens of thousands of nodes on every inhabited continent, with offline archives and satellite broadcast besides. The network needs exactly one surviving copy to restore the complete record, and ownership is proven by keys that exist independently of any copy. Bitcoin does not die in such an event. It pauses, and resumes wherever the power resumes, with every balance intact.
Compared to what? A disaster physically capable of destroying every copy of bitcoin's ledger on every continent at once would have destroyed the banking system's records long before it reached bitcoin. Bank ledgers live in a relative handful of concentrated data centres; there is no seed phrase in a drawer for your checking account. By the standard of monetary records, a ledger replicated across the entire planet is among the most catastrophe-resistant ever built. There is a residual case, of course: a true years-long collapse of electrical civilization would render bitcoin unusable in the interim — though that is not so likely, and were it to happen, one would have much larger problems, in a world where guns, ammunition, and tins of food have become the higher priorities. That is not a risk to bitcoin in particular. It is a risk to everything.
The attacks from inside — the incentives that secure the network.
The most substantive critique on this page — and the one still genuinely contested.
The case. This one comes from economists, not cynics. Eric Budish's "The Economic Limits of Bitcoin and the Blockchain" formalizes it. Bitcoin's security is "memoryless": the chain is only as safe at any moment as the hash power actively defending it right then. To make a 51% attack irrational, the recurring payments to honest miners must continually exceed the one-off prize an attacker could seize — which means security spending scales with the value secured. Meanwhile the block subsidy, bitcoin's main payment to miners, halves every four years, asymptotically toward zero. Transaction fees are meant to take up the slack. Princeton researchers (Carlsten et al.) showed that a fee-only regime can become unstable on its own: when fees dominate, miners face incentives to "undercut" — to fork a fee-rich block rather than build on it — degrading the finality the whole system depends on.
The reply. Start with the part that is true: it is reasonable to suggest this is a problem worth watching. But the framing of a sudden cliff is wrong. There is no binary transition from subsidy to no-subsidy — only a subsidy that declines smoothly over decades to the point where it becomes increasingly less relevant, and the erosion of that block-subsidy incentive is expected to be balanced by increases in the monetary value of the asset it pays out in. Several mechanisms point that way.
First, the empirical floor: blocks have already been mined in which transaction fees exceeded the block subsidy. The fee-dominant world is not a theoretical regime the network has never seen; it has happened, during periods of heavy demand, and the chain kept producing blocks. Second, structure. As base-layer block space grows scarce relative to demand, most everyday transactions move to second layers like Lightning, while the base layer increasingly settles large, batched transactions among major institutions — a single settlement carrying a large fee while costing each of the many users batched within it very little. High aggregate security revenue, low individual burden. Third, and most easily missed: a fee that is even a modest percentage of the value transacted throws off ever-larger absolute revenue as bitcoin's value rises. Fees need not grow as a share of each transaction; if bitcoin's monetary value compounds, a flat percentage produces a rising security budget in dollar terms on its own.
The proposed protocol-level responses — tail emission, fee-routing sidechain designs, demand engineered onto the base layer — are real and actively debated. But the network likely does not need a redesign so much as the thing it was already built to produce: a deep fee market at a high valuation. The question resolves in public, one halving at a time, over the coming decades, and the mechanisms above are reasons to think the resolution is favourable.
The case. Bitcoin's defense is distributed by design, but its production has concentrated. A handful of mining pools coordinate most of the network's hash power — the top three command roughly 60% between them — and because pools build the block templates, they decide which transactions are included. That is a censorship surface: a concentrated set of pools could be pressured to filter transactions, and a single pool approaching half the network reintroduces the 51% spectre from the inside.
The reply. The deepest point is that bitcoin mining has remarkably few structural economies of scale. What a profitable mine actually needs is cheap, otherwise-wasted energy; a cool climate (to minimize equipment cooling costs); and a jurisdiction that permits it — and no company, and no country, holds a monopoly on those conditions. They are scattered across the planet by geography and accident, which is precisely why, when China expelled its entire mining industry, the hash power did not collapse into a cartel; it dispersed across continents and grew back. The tendency toward some consolidation exists, but the scale economies are simply not significant enough to drive the kind of concentration seen in many other industries that genuinely benefit from scale. Access to better hardware pricing or rack space confers a marginal edge, not a moat.
A second point answers the censorship surface specifically: pools are coordination, not ownership. The individual miners pointing hash power at a pool can leave in hours, and have, whenever a pool has misbehaved — the hash power is rented to the pool, not owned by it. (This is also a live incentive for pools to behave economically rationally rather than entertain censorship, which would drive their hash power away.) And the industry is closing even the template-control gap: Stratum V2 moves transaction selection back to the individual miner rather than the pool operator, and has been adopted across a large share of the network. Concentration at the pool layer is real; ownership of the hash power is not, and the censorship lever is being engineered away.
The case. Centralized custody recreates the very thing that made gold seizable. The spot-ETF era has re-intermediated a large and growing share of bitcoin into a tiny number of custodians — one firm alone safeguards the overwhelming majority of US spot-ETF coin, amounting to a meaningful fraction of all bitcoin in existence. A state that wanted to seize or freeze that bitcoin would not need a house-to-house search; it would need one subpoena. This would essentially be a 6102-style attack of bitcoin, and the conditions for it have a modern-day equivalent now in a way they did not before.
The reply. The concentration is real — Paper Bitcoin maps it in full — but for nearly every user, in nearly every case, custody is a choice made anew each time, not a structural trap. Nothing prevents an individual from holding their own keys; the people locked into custodians are mostly locked there by artificial constructs — pension structures that cannot buy bitcoin directly and so must hold an ETF for price exposure alone, for instance — rather than by anything intrinsic to bitcoin. For most holders, in most cases, any custody risk can be overcome easily and immediately by moving one's bitcoin to cold storage and keeping possession of one's own keys; this is not a limitation but an open pathway.
And there is a property here no other monetary asset of comparable value possesses: bitcoin can be self-custodied at scale. It is impractical to take personal physical custody of a billion dollars in gold — let alone move it across a border at will — without security details, logistics, and exposure to capital controls. A billion dollars' worth of bitcoin can be held in a memorized phrase and moved anywhere on earth, to anyone, at the speed of the network. Third-party custody risk is, by some users, seen as a convenience worth the trade; the solution — "get your bitcoin off exchanges" — is an open pathway for everyone, and a holder who leaves coins with a custodian that then fails has no one to blame but themselves.
The thing itself breaks — the code, the consensus, the cryptography.
The case. It has already happened — twice. In August 2010, an integer-overflow bug let an attacker create 184 billion bitcoin in a single transaction, out of nothing. In 2018, a vulnerability (CVE-2018-17144) sat latent in Bitcoin Core that, if exploited, would have let a miner inflate the supply by spending the same input twice. Bitcoin's defining promise — 21 million, no more — was broken once and nearly broken again. And nearly all the network runs a single software implementation, Bitcoin Core: a monoculture in which one consensus bug threatens everything at once.
The reply. Read for how they ended, these two incidents are among the strongest evidence on the page. The 2010 overflow was caught and patched within about five hours; developers coordinated a corrected chain that overtook the exploited one, and the 184 billion phantom coins were erased from history by a reorganization the network agreed to confirm. The 2018 bug was never exploited at all: developers ran a quiet, staged disclosure — shipping the fix described only as a minor denial-of-service patch until enough of the network had upgraded, then revealing the true severity. Both times, the 21-million cap held.
What held it was not the immutability of the code — the code had the bug. It was the social layer: developers, node operators, miners, and exchanges coordinating, fast and competently, to reject an invalid history and confirm the monetary rule. This is the part critics miss when they call the cap "just software." The cap is enforced by tens of thousands of independent parties who each validate every block and reject any chain that violates the rule, however much work backs it. The monoculture is a genuine fragility and the network knows it; the defense is the same one that worked twice already — the rule lives in social consensus, not only in the binary, and that consensus has been tested under live fire and held.
The case. This risk cuts both ways, and both edges are sharp. If Bitcoin cannot change, it cannot fix itself — a fatal flaw the day a change becomes genuinely necessary (a quantum migration, say; see the next section). If Bitcoin can change too readily, it can be captured — whoever controls the upgrade process controls the money. A system has to thread between paralysis and capture, and a sufficiently determined, well-funded faction — a coalition of the largest miners and companies — might force through a change the users never wanted, or block one they needed.
The reply. Bitcoin has already survived its constitutional crisis, and the outcome defined how its rules change for good. During the Blocksize War of 2015–2017, a coalition representing more than 80% of hash power and many of the largest companies in the industry tried to force a block-size increase through the New York Agreement. They lost. They lost to a user-activated soft fork — node operators, the economic majority, announcing they would reject the miners' blocks — and to a market that priced the small-block chain far above the big-block alternative in live trading before the split. The lesson was permanent: miners propose, but users running their own nodes dispose. No cartel of hash power can impose a rule the economic majority refuses to run.
What that episode proved is that Bitcoin's default state is extreme inertia, and that this inertia is a foundational feature, not a bug. A money whose rules can be changed easily by whoever holds the most resources is a money that can be captured; Bitcoin's resistance to change is exactly what makes its 21-million cap and its censorship-resistance credible — these are non-negotiable. The risk does not vanish — it relocates to the genuinely hard case, the one the next section raises: what happens if a change is not merely contentious but security-necessary, and the same inertia that repels capture also repels the fix. That is the real test, and it has not yet come.
The one risk with a clock on it.
The case. Bitcoin's ownership is protected by a kind of cryptography — elliptic-curve signatures — that a large enough quantum computer running a known algorithm (Shor's) is, in principle, built to break. If such a machine could derive a private key from a public key, it could forge the signatures that authorize spending and steal coins. In March 2026, Google Quantum AI published resource estimates well below prior work, suggesting the hardware needed might be roughly an order of magnitude smaller than once thought. A meaningful share of all bitcoin sits in addresses whose public keys are already exposed on the chain — the earliest coins, and any address that has been reused — which a future machine could, in theory, target.
The reply. Take the threat at full strength, then locate it precisely. The exposure is to signatures, not to mining: Bitcoin's mining algorithm (SHA-256) is only mildly weakened by quantum methods, and the difficulty adjustment absorbs the rest. The danger is to keys — and here several facts cut the fear down to a manageable, watchable size.
First, and most importantly: we will not be taken by surprise. Bitcoin's elliptic-curve cryptography is far from the weakest cryptography securing the modern world — the encryption protecting banks, governments, and the internet's plumbing uses schemes that a quantum computer would, in many cases, break first. Long before a machine capable of cracking a bitcoin key exists, it would have cracked easier targets, in public, with enormous consequences and enormous warning. The world gets a fire alarm, not a silent break-in. Second, the most exposed coins are the oldest ones: Satoshi-era addresses use an early key format that is more exposed than the formats wallets use today, so those would be the warning shots — not an ordinary holder's modern, unreused address. And Satoshi's holdings are not one great honeypot but a very large number of separate 50-bitcoin coinbase rewards (50 was the block reward in those years), scattered across many addresses rather than pooled in one tempting target. Third, the defense already exists in draft: post-quantum signature standards were finalized in 2024, and quantum-resistant address designs are specified and waiting; a holder can move coins to a fresh, unexposed address today, and to a quantum-safe one when the upgrade ships.
The genuinely hard part is not cryptographic but the consensus problem of the previous section. Migrating the network means a coordinated upgrade, and a decision about the millions of old, exposed coins whose owners are gone or silent: leave them, and a future attacker might eventually reach them; freeze them, and the network violates the property-rights absolutism that is its whole point. There is no comfortable answer, and this is where the limits of changing Bitcoin's rules get their real examination. But the timeline is long, the warning signs are public, and the defense is already on the shelf.
The case. Bitcoin's ledger is fully public, which makes it unusually traceable. Every transaction is permanent and visible; analytics firms cluster addresses into likely identities using well-understood techniques; and the moment coins touch a regulated exchange, the pseudonym can attach to a name. A transparent monetary network, the worry runs, is a surveillance tool waiting to be finished — and the tools that try to restore privacy have seen their developers prosecuted.
The reply. The transparency is real, and the ledger is pseudonymous rather than anonymous — but that same transparency buys the one property bitcoiners will not trade away: anyone can audit the 21-million supply. Every node verifies, from plain arithmetic, that not a single coin was created out of turn. That is exactly the check that caught the 2010 overflow and would catch the next one. The strongest base-layer privacy upgrades — the kind that hide transaction amounts — trade this away: once amounts are encrypted, proving that no inflation has occurred shifts from simple public arithmetic to complex cryptography, and a single hidden bug could let counterfeit coins be created with no visible trace, as has happened on other chains. The choice is therefore deliberate: keep the base layer transparent and auditable, and build privacy at higher layers, where a cryptographic failure cannot silently break the supply. The auditability of the cap is foundational; trading it for base-layer privacy would remove the very property that let bitcoin survive its worst bugs.
Nobody attacks — people simply leave.
The case. No attack is required for bitcoin to fail; indifference would do. Two versions. The first: a technically superior successor — quantum-resistant from genesis, fairer in its mining, faster by design — out-innovates an ossified incumbent the way every technology eventually yields to a better one. The second needs no rival at all: demand simply decays. Bitcoin's price has leaned on a few committed institutional buyers; if they reach their limits or change their minds, the marginal buyer evaporates. Governments need not ban it — they can contain it, with punitive bank-capital rules, with a tax code that treats every coffee bought in bitcoin as a taxable disposal, with state-blessed stablecoins and digital currencies offering the convenience without the property.
The reply. Take the successor argument first, because it sounds the most modern and is the most mistaken about what bitcoin is. Monetary goods do not compete on features. The Blocksize War already ran this experiment at full scale: a better-specified, higher-throughput fork, backed by most of the industry, lost to the original because monetary credibility, not throughput, is the product — and the market priced it that way in live trading. The deeper reasons compound. As Adam Back puts it, bitcoin was discovered more than invented: it sits in a design space so narrow that improving any one property — more speed, more privacy, more flexibility — degrades another and breaks the whole. It solved the double-spend problem and the Byzantine generals problem, and there is no credibility to be won by re-solving foundational problems that are already solved; the credibility goes to the network that solved them first and has run untouched since. (Our Trilemma page makes the structural version of this case: bitcoin's trade-offs are the correct ones, not an accident waiting to be improved upon.) It is, today, the longest chain with the most accumulated proof-of-work in existence — the literal foundation any successor would have to out-build from zero. And in theory every would-be successor arrives with a tell: a founding team and a pre-mine, a concentration of coins and control at genesis that destroys the very credibility it would need to displace a money with no owner. Bitcoin has taken hold the way SMTP took hold for email or TCP/IP for the internet — technically superior replacements have existed for years and go unused, because the value was never in the features; it was in the universal, entrenched, trusted standard.
The decay argument is more serious, because it needs no villain. But containment is policy, policy is set jurisdiction by jurisdiction, and jurisdictions compete: the same game theory that destabilizes a ban cartel erodes a containment regime, as the economy that taxes bitcoin into uselessness exports its activity, and its associated prosperity, to the one that does not. The friction is real today — the absence of a small-transaction tax exemption genuinely suppresses everyday use — but it is contingent, legislative, and reversible, not structural. And the demand case rests on a claim about human preference that the last seventeen years have steadily undercut: each cycle of supposed disinterest has been followed by a wider base of holders, not a narrower one. As for the superior-successor threat, it was talked about far more during the Cambrian explosion of "crypto" in years like 2017 than it is now; Bitcoin's dominance has only become more assured since, and the idea of a "Bitcoin 2.0" is, in practice, getting competed away rather than competing bitcoin away.
The obituaries and the maximalists make the same mistake from opposite directions: one insists bitcoin is already dead, the other that it cannot die. Neither grades the risks. Here is the grade.
The state ban — China ran it six times, hardest in 2021, and the hash power recovered in months. The protocol bug — twice, in 2010 and 2018, and the 21-million cap held both times. Consensus capture — attempted in 2017 by 80% of hash power, and defeated by the users. These are not hypotheticals the page is reassuring you about; they are attacks that happened and failed.
The security budget — still contested, resolving over decades, with real mechanisms pointing toward a deep fee market. Quantum — the one with a clock, defensible on a long and public timeline, hard in its politics more than its math. Custody concentration — trending the wrong way at the institutional layer, fully optional at the individual one. These are the risks worth actually watching, by the markers each section named.
Infrastructure collapse on a civilization-ending scale would take bitcoin down with everything else — which makes it a risk to money as a category, not to bitcoin in particular.
Notice the shape of the list. The risks that have actually been tested are the ones Bitcoin survived — and it survived them not by adapting but by refusing to bend, growing in adoption, security, and size as it did. The risks that remain genuinely open are open precisely because they have not yet been tested in full. That is what it looks like when resilience is a property rather than luck: the thing keeps being attacked, in new ways, and keeps coming through. The seventeen years of obituaries have, in the end, simply been a boy who cried wolf far too many times.
Every page on this site has been improved by someone pushing on it. Ask a question, flag an error, or suggest what’s missing — it goes straight to the author, never published.