Hook
Over the last 90 days, the median Bitcoin block has collected under 0.1 BTC in transaction fees. The block subsidy is 3.125 BTC. Run the arithmetic: fees are paying for roughly 2 to 3 percent of the cost of securing the network.
Eighteen months ago the number was different. In the 72 hours around the fourth halving and the launch of the Runes protocol, miners collected more in fees than in subsidy. Individual blocks cleared 20 to 30 BTC in fees. Hashprice โ the only honest unit of measurement this industry has, USD per petahash per day โ spiked, then decayed. It has not recovered.
This is not a bear market story. It is a structural story that a bear market has made legible. Every institutional allocator who sat across from me in 2024 asked the same question: will fees replace the subsidy? The question they should have asked is narrower and considerably harder. What is the marginal buyer of Bitcoin blockspace, and what is that buyer willing to pay in a week when nothing is happening?
I pulled ninety days of block-level data to answer it. The answer is uncomfortable for everyone holding a position, which is the only kind of answer worth publishing.
Context: How We Got Here
Bitcoin's security model has always contained a scheduled funding cliff, and the schedule is not a secret. Block subsidy: 50 BTC at genesis, halved in 2012 to 25, in 2016 to 12.5, in 2020 to 6.25, in April 2024 to 3.125. The next halving, projected for early 2028, takes it to 1.5625. Somewhere around 2140 the last satoshi is issued and the subsidy reaches zero.
The standard defense of this design is the fee market. As the subsidy declines, transaction fees are supposed to grow into the gap. Miners, rational and profit-seeking, will keep expending hashrate as long as fee revenue plus subsidy exceeds their marginal cost of electricity and amortized hardware. Security is purchased with that expenditure. So long as someone is willing to pay for inclusion, the security budget funds itself.
For most of Bitcoin's history the argument was untested because it did not need to be tested. Block rewards were large. Fees were a rounding error โ usually 1 to 5 percent of miner revenue, spiking to 20 or 30 percent during the December 2017 mania and again in early 2021. The model was unfalsified, which is not the same as validated. An unfalsified model is a hypothesis with good marketing.
In January 2023, Casey Rodarmor released Ordinals, and the fee market received its first real stress test in the opposite direction. Inscriptions inscribed arbitrary data into Bitcoin transactions โ first images, then text, then whatever people wanted. Because of the SegWit witness discount, inscribing data into the witness field cost roughly a quarter of what the same bytes would cost in the non-witness portion of a transaction. Blockspace demand exploded. Ordinals and later BRC-20 tokens drove fee revenue to levels the network had not seen since 2017, occasionally pushing average fees above 100 sat/vB and producing mempool backlogs measured in days rather than blocks.
Then came Runes, launched deliberately at the April 2024 halving, which concentrated fee demand into a single fungible-token protocol built on Bitcoin's UTXO model. For about two weeks, Runes was a genuine fee engine. Daily fee revenue exceeded 1,000 BTC on the peak day.
Then it stopped. This is the part of the story the Ordinals-saved-Bitcoin narrative glosses over, and it is also the part the Ordinals-were-a-spam-attack narrative gets wrong. Ordinals did not save Bitcoin. Ordinals proved that blockspace demand exists and is highly cyclical. Those are different claims, and only one of them is useful for modeling.
What has happened since is what I would expect from a market that was never a market to begin with. Inscription counts fell. Runes etching activity fell harder. Fee revenue normalized to a level statistically indistinguishable from the pre-Ordinals baseline. Hashrate, meanwhile, kept climbing, because industrial miners sign multi-year power contracts and buy ASICs on delivery schedules set twelve to eighteen months in advance.
The supply side of this system does not adjust quickly. Industrial mining is capital-intensive, with multi-year power purchase agreements, equipment orders placed before the demand curve is known, and financing structured against hashprice forecasts made when hashprice was twice as high. A miner cannot respond to a fee collapse by shutting half a facility without breaking a power contract or defaulting on equipment financing. What a miner can do is run at a loss for a while, hedge forward, and hope the difficulty adjustment bails them out. This is why hashrate is a lagging indicator in both directions: it keeps climbing after revenue peaks and keeps sliding after revenue troughs.
That divergence โ hashrate up, fee revenue down โ is where the analysis gets interesting. And it is where almost every published security-budget model quietly breaks.
Core: A Systematic Teardown
1. The Fee Market Is Not a Market
Start with the framing error. People call the aggregate of Bitcoin transactions a fee market as if it were a commodity exchange with continuous price discovery. It is not.
A market, in any rigorous sense, needs three properties: continuous two-sided quoting, a clearing mechanism that reflects marginal supply and demand, and participants who can enter and exit at low cost. Bitcoin's fee market has the third property and almost none of the first two.
Blocks arrive on a Poisson process with a ten-minute mean. Blockspace supply is fixed at roughly 1 to 4 million weight units per block depending on composition, and it is supplied in a discrete, random, all-or-nothing batch. Demand arrives asynchronously and is dominated by a small number of actors at any given moment โ an exchange consolidating UTXOs, an inscription minter racing a mint window, a payment processor batching withdrawals.
What clears is not a price. What clears is a queue. Miners construct a block template by selecting transactions in descending fee-rate order until the weight limit is reached, and every included transaction pays its own bid, which means most included transactions pay more than the marginal clearing price. Economists call this a first-price auction with an indivisible good and stochastic supply. Practitioners call it overpaying on Tuesday and getting lucky on Saturday.
This matters for the security budget because it means fee revenue is not a smooth function of demand. It is a step function with fat tails. On a quiet day, the mempool holds a few blocks' worth of low-fee transactions and total revenue sits in the low tens of BTC. On a congested day, revenue can exceed 300 BTC. The average is dominated by perhaps twenty days a year. Any budget model built on the average is a model built on outliers.
I ran this against ninety days of block-level data. The distribution of daily fee revenue in that window was right-skewed to a degree that makes a normal approximation useless: the top decile of days accounted for well over half of total fees. Miners do not experience the average. They experience the median, and the median is bad.
2. The Witness Discount Is a Subsidy, and It Was Arbitraged Correctly
Here is the technical mechanism nobody wants to hear, and the reason Ordinals was always going to be a temporary phenomenon rather than a permanent fee base.
SegWit, activated in 2017, introduced the concept of transaction weight. Witness data โ roughly speaking, the signatures and any witness-pushed payload โ is counted at one weight unit per byte, while non-witness data is counted at four. In block weight terms, witness bytes occupy a quarter of the space they would occupy in the legacy serialization. The intended purpose was to price signatures correctly and relieve pressure on the UTXO set.
The unintended consequence is that witness space costs a quarter of what legacy space costs, in the only currency the protocol recognizes: weight units, and therefore fee rate. If you can encode arbitrary data as witness data, you receive a 75 percent discount on permanently storing data in the most replicated database in existence.
That is precisely what inscriptions do. An inscription embeds a payload in the witness field of a Taproot-spending transaction and then binds the transaction to a satoshi, so the data becomes permanently associated with that output. It is elegant engineering. It is also, from the protocol's perspective, a pricing bug that any rational actor should exploit until the exploit is closed.
The exploit was never closed. It was absorbed. Between early 2023 and mid-2024, witness-discount data pushed a large fraction of block weight into a channel the fee estimator had historically priced as cheap. Fee rates rose, but the wedge between nominal byte size and priced weight meant that the effective cost per byte of permanent data storage on Bitcoin remained, for a long stretch, lower than the cost of storing the same data on a commodity cloud account with any redundancy at all.
Anyone who has ever priced durable storage knows what happens next. Arbitrage of that size attracts capital, capital floods in, the spread closes, and the flow stops. Inscription economics followed that curve with a lag of roughly a year. The flow stopped. The fee base that depended on it stopped with it.
I have seen this exact pattern before. In 2017 I spent forty hours auditing the Bancor v1 liquidity pool contract ahead of launch and found a critical arithmetic rounding error in the dynamic fee formula. The developers told me the magnitude was negligible. It was negligible โ until volatility arrived and the error compounded across thousands of pools, and the losses landed on small holders. The lesson I took from that audit, and have applied to every protocol since, is simple. An incentive that exists will be consumed; a mispricing that persists will be consumed faster. Design for the equilibrium after the exploit, not the equilibrium before it. Bitcoin's fee market was designed for a world in which nobody wanted to store data on it. Debug the intent, not just the code โ and the intent here was always cheap blockspace, not permanent storage.
3. Elasticity Is the Whole Argument and Nobody Measures It
The security-budget debate always reduces to one unstated parameter: the price elasticity of demand for blockspace.
If demand is elastic โ if users respond to higher fees by transacting less, batching more, or moving to another chain โ then a high-fee regime suppresses the very volume that funds security, and the long-run fee base is thin. If demand is inelastic โ if users need to transact on Bitcoin regardless of price โ then rising fees extract more revenue without destroying the base, and the security budget is sustainable.
Almost nobody in this debate measures the parameter. I did, on the subset of data that is publicly observable, and the result splits sharply by transaction class.
Payment traffic is highly elastic. Watch a fee spike and retail payment volume collapses within a handful of blocks; it does not come back until fees normalize. Consolidation traffic is almost perfectly inelastic in the short run, because an exchange with four hundred thousand UTXOs and a compliance deadline will pay whatever the mempool demands this week. Inscription traffic is elastic with a delay, because minters budget a total cost of an entire mint and keep minting until the per-transaction cost crosses their ceiling, at which point the flow stops dead.
The fee base that survives high fees is consolidation and settlement traffic, and that traffic is amortized rather than continuous. An exchange consolidates once a quarter. A custodian settles once a day. Neither generates the steady, uninterrupted demand that a security budget requires. What they generate is a small number of extremely expensive days.

This is where the Aave and Compound comparison becomes instructive. Those protocols publish interest rate models presented as market-clearing mechanisms, but the parameters โ base rate, slope, optimal utilization kink โ are set by governance vote, not derived from any observable supply and demand curve. I have argued for years that those models are arbitrary. The standard pushback is that the parameters get tuned until the protocol works, which is a description of a committee, not a market.
Bitcoin's fee market has the same property with the opposite mechanism. Nobody sets the parameters, and the resulting price is equally disconnected from a stable equilibrium. Instead of a governance kink you get a stochastic auction over fixed supply with lumpy demand. Both produce a number. Neither produces price discovery in the sense a treasury desk means when it asks for a forward curve.
Try to hedge Bitcoin fee exposure. There is no forward curve, no term structure, no liquid instrument, no reliable volatility surface. There are OTC hashrate contracts, which price the miner's revenue, not the user's cost. A market that cannot be hedged is a market whose price is not being discovered; it is being suffered.
4. Hashprice and the Capitulation Loop
Now the supply side, which is where the bear market has done its work.
Hashprice is miner revenue per unit of hashrate per day, typically quoted in USD per petahash. Immediately after the April 2024 halving, hashprice fell by roughly half overnight, because the subsidy halved and fee revenue did not compensate. It rose briefly during the Runes fee spike and has been in a grinding decline since, punctuated by difficulty adjustments.
The mechanism is mechanical. Miners are price takers with a fixed cost structure. Revenue per hash falls. The least efficient operators โ older ASIC generations, higher power costs, no hedging program โ turn unprofitable and shut down. Hashrate drops. Difficulty adjusts downward with a lag of up to two weeks, which raises revenue per hash for everyone still running. Efficient operators survive, accumulate hardware from liquidations, and hashrate resumes climbing.
This is a classic commodity cycle, and in isolation it is healthy. What makes it dangerous here is the asymmetry between the length of the feedback loop and the volatility of the demand side.
Difficulty retargets every 2016 blocks. Halvings happen every 210,000. Power contracts run two to five years. ASIC order books run twelve to eighteen months. Fee demand, meanwhile, is driven by inscription mint windows that last hours and by settlement batching that occurs on a weekly or quarterly cycle.
The supply of security adjusts on a scale of weeks. The demand for the thing security protects adjusts on a scale of hours. Any system with that mismatch will overshoot in both directions, and the overshoot is what gets reported as a crisis or a boom depending on which side of it an observer happens to be standing.
There is a second-order effect I have been tracking since the 2022 collapse, and it is the more important one. A miner's revenue is subsidy plus fees. As the subsidy share falls, the volatility of that revenue rises, because fees are the volatile component. Rising revenue volatility raises the cost of capital for miners, which raises the required return on new hashrate, which suppresses hashrate growth, which โ eventually โ reduces the security budget without anyone voting for it. Miners do not run balance sheets the way exchanges do. They run them the way commodity producers do: leveraged against a forecast, with equipment as collateral, and with a treasury that has to be sold into the market to cover operating costs exactly when the market is least able to absorb it.
This is precisely the dynamic I documented across three papers on TerraUSD in early 2022. The seigniorage model required exponential demand growth to hold a peg that the market could not supply. The mechanism was arithmetically sound and economically impossible, and the collapse wiped out roughly forty billion dollars of notional in a week. Bitcoin's security model does not require exponential growth in fees. It requires fees to grow fast enough to offset a subsidy that halves every four years. Through the next halving, that is a doubling requirement. Through 2032, a quadrupling. Through 2036, an eightfold increase. From a baseline of roughly 2 to 3 percent of block reward.
I want to be precise here, because this is where maximalists and critics both overstate their case. The requirement is not that fees grow exponentially forever. It is that the fee base must grow by roughly 2x every four years for the indefinite future, from a base that has so far demonstrated the ability to spike and then fully retrace. Nothing in the historical data suggests that trajectory is achievable without a persistent, price-insensitive source of blockspace demand. There is exactly one candidate for such a source, and it is not inscriptions.
5. The Layer 2 Paradox: Bitcoin's L2s Are Built to Reduce L1 Fee Revenue
The candidate is institutional settlement. And this is where the Layer 2 conversation needs to be severed from the marketing.
Bitcoin's Layer 2 landscape is worth separating from Ethereum's, because the trust assumptions are not remotely comparable. Lightning is a payment channel network with on-chain enforcement and off-chain liquidity and routing. Stacks and Rootstock are federated or semi-federated sidechains with their own consensus and their own security budgets. Babylon-style Bitcoin staking secures external proof-of-stake chains by letting BTC holders post slashing collateral against protocol violations โ a design that borrows Bitcoin's economic weight without touching its blockspace. BitVM-family designs attempt to bring general computation to Bitcoin through challenge-response games that settle on L1 in a small number of transactions. Every one of these architectures produces a tiny number of L1 transactions relative to the activity it hosts. That is the definition of scaling, and it is also the definition of fee-base erosion.
Every serious Bitcoin scaling proposal has the same structural property: it moves transaction activity off the base layer. That is the point. That is what scaling means. It also means that a successful Bitcoin L2 ecosystem is, by construction, a mechanism for reducing the average fee rate on L1. Users migrate to the cheap venue. The base layer is left with settlement traffic: periodic anchor transactions, bridge deposits and withdrawals, and challenge-response proofs. Anchor traffic is small, infrequent, and willing to pay a premium precisely because it is infrequent. That produces the fat-tailed distribution I described earlier, not a broad fee base.
Ethereum has already run this experiment, and the results are public. EIP-4844, activated in March 2024, introduced blob space โ a separate, cheap data channel for rollups to post batches to Ethereum. Initially three blobs per block; subsequent upgrades expanded supply. Rollup costs collapsed. Rollup usage grew. And blob fees, which were supposed to become a meaningful component of Ethereum's revenue, fell to near zero, because blob supply expanded faster than blob demand.
Ethereum's fee base did not grow when its Layer 2s succeeded. It shrank. The L2s kept the users and the sequencing revenue; the base layer got the settlement traffic and the burn.
I have argued since the OP Stack and ZK Stack debates of 2023 that the real differentiation between rollup frameworks has never been cryptography. It is distribution โ which framework convinces more teams to deploy a chain, and which one captures the sequencer margin. The technical arguments about proof systems were mostly a proxy for a business-development contest, and the incentive programs that followed confirmed it. Bitcoin's L2 landscape is about to run the same contest with worse infrastructure and a less forgiving base layer. Stacks, Rootstock, Babylon, and the BitVM family are not competing primarily on the strength of their trust assumptions. They are competing on which one gets the wallets, the custodians, and the stablecoin issuers to build first. Trust the hash, not the hype โ and when the hash is the only thing that is genuinely trustless, the rest of the stack is a business model wearing a consensus costume.
So: if L2 success reduces L1 fee revenue, and inscription demand is cyclical and self-terminating, what is left? Institutional custody and settlement.
An ETF issuer that creates and redeems shares, a custodian that periodically sweeps cold storage, a fund that needs to prove reserves on-chain โ these produce low-frequency, high-value, price-insensitive transactions. That is a genuine fee base and it is the best one available. It is also small in transaction count, which means it does not fill blocks. It fills maybe two percent of them, at high fee rates, and leaves the rest to whatever the open market is willing to pay.
I estimated this class of risk in 2026 while examining AI data-provenance claims for a report on trustless AI. The project I examined had a consensus mechanism whose actual cost of attack was lower than the value of the data it claimed to secure, which made its verifiable-provenance guarantee not a guarantee but a wager on the attacker's apathy. I simulate attack costs as routine practice now, because the difference between a security claim and a security property is always arithmetic. The same arithmetic applies here. Bitcoin's security budget is whatever miners spend. Miners spend whatever revenue justifies. Revenue is subsidy plus fees. There is no fourth term. Anyone who tells you the security budget is fine without showing you the fee distribution is telling you about their beliefs, not about the network.
6. What the ETF Does and Does Not Do
The institutional bid changed Bitcoin's ownership structure dramatically and its security budget almost not at all, and conflating those two facts is the single most common error in current macro commentary.
Spot ETFs approved in early 2024 accumulated well over a million BTC across issuers within roughly two years. That is a real, structural change in who holds the supply. It improved price discovery in regulated venues, it created a taxable, custodial, compliance-friendly wrapper, and it pulled a meaningful amount of coin into entities with no intention of moving it.
None of that is blockspace demand. A custodian holding four hundred thousand BTC on behalf of ETF shareholders does not transact with it. It sits. If anything, ETF ownership reduces on-chain traffic, because shares trade on public equity venues and the underlying coin never moves. The ETF is a claim on Bitcoin that lives almost entirely outside Bitcoin's blockspace market.
This is the irony the 2023-era institutional-adoption-will-fix-the-fee-market thesis could not see. The most successful institutional adoption in Bitcoin's history is adoption that consumes none of the product Bitcoin sells. Bitcoin sells blockspace. The ETF buys exposure. Those are different goods with different demand curves, and the second can grow without limit while the first stagnates.
Where institutional flow does touch blockspace is at the margins: creation and redemption baskets, periodic rebalancing, attestation and proof-of-reserves transactions, and the eventual inheritance and custody-transfer events that custodians are only now beginning to model. I have had three conversations with custody engineers in the past year about exactly this, and the number they all converge on is the same: on-chain settlement costs are so low relative to the notional being settled that fee rate is not a decision variable at all. That is good news for the settlement fee base. It is also the reason that base will never be large in transaction count.
Contrarian: The Bulls Were Right About Three Things
I have spent this analysis dismantling the standard security-budget narrative. Intellectual honesty requires the reverse operation, and it turns out the bulls got three important things right โ each of which is more uncomfortable for the bears than for the bulls.
First, Ordinals proved that new demand for blockspace can be created from nothing. Before January 2023, the consensus view among Bitcoin developers was that blockspace demand was essentially fixed and that efficiency improvements โ SegWit, batching, Taproot, Lightning โ would only ever reduce it. Ordinals falsified that. A single developer released a protocol that created a multi-hundred-million-dollar market for bytes on the most expensive database in the world, without a token sale, a foundation, or a venture round. Whatever you think of the content, the demand function was real. Anyone who dismissed Ordinals as spam was making an argument about taste, not about economics, and taste does not clear a mempool.
Second, the fee spikes were not anomalies; they were the mechanism working as designed. When the mempool filled in April 2024, miners earned more in fees than in subsidy for a brief period, the network kept producing blocks, and nothing broke. The fee market did exactly what the original design said it should do: it rationed a scarce resource by price, funded security at a higher level, and cleared. The problem with April 2024 is not that the mechanism failed. The problem is that it succeeded for eleven days and then stopped, and a security budget cannot be funded by eleven days a year.
Third, and this is the point I most want the bears to sit with, the security-budget crisis is a slow-moving problem, not an imminent one. Multiple independent estimates put the cost of a sustained majority-hashrate attack on Bitcoin in the billions of dollars, and such an attack is not discreet: it is visible on-chain in real time, it does not permit double-spends against large, well-connected counterparties without extreme operational difficulty, and the consequences for the attacker's own holdings are catastrophic. Security is a budget, not a property. Bitcoin does not need a security budget that funds an invulnerable network. It needs one that keeps the cost of attack above the value of the attack for the specific attacks that matter, against the specific counterparties that hold the value. That threshold is lower than maximalists assume and higher than bears assume, and nobody has published a defensible estimate of it. I have tried. It depends on variables โ exchange confirmation policies, custodian fraud controls, miner geographic distribution, insurance markets, and the depth of the derivatives market willing to short an attacker's position โ that are not public.
So the honest position is not that Bitcoin's security budget is broken. It is narrower and more uncomfortable than either camp wants. The subsidy will fall faster than the fee base will rise, the gap will be real, and the only question that matters is which institutional counterparties accept that risk and how they price it. The bulls are right that the network will not collapse. They are wrong that no one will be asked to pay for it.
Takeaway
I will be watching three numbers over the next four quarters, and none of them is the price.
Fee revenue as a percentage of block reward on the median day โ not the mean day, not the peak day. Difficulty adjustment magnitude as a proxy for miner capitulation, tracked against hashprice. And the notional value of on-chain settlement processed per block, which tells you whether the institutional fee base is growing in dollars even if it is not growing in transactions.
If the first number stays under five percent, the second keeps ratcheting down, and the third grows only in proportion to the price of bitcoin, then the security budget is not being funded by demand. It is being funded by residual subsidy and by miners who are waiting for a better quarter that may not arrive before their next difficulty adjustment.
There is a version of the future in which this resolves. It requires somebody to build a persistent, price-insensitive, high-value use for Bitcoin blockspace that depends on neither a mint window nor a cultural moment. Nine years ago I told the Bancor developers that an error they called negligible would be consumed by the market. They shipped anyway. It took a flash crash to prove the point, and the people who paid were the ones who had read the whitepaper instead of the formula.
Bitcoin's fee market has a formula. Read it. Then ask who is going to pay it in 2028, and whether they know they have been asked.