Bitcoin's network security is funded by miner revenue — block subsidy plus transaction fees. The subsidy halves every four years (3.125 BTC in 2026, ~1.5625 by 2028, ~0.78 by 2032, effectively zero by 2140), so over the long horizon fees must replace subsidy or security will decline. The structural critique, formalized in Eric Budish's 2018 The Economic Limits of Bitcoin and the Blockchain and engaged by BIS and academic voices, is that nothing guarantees fees will be sufficient: revenue is spiky, and sustained insufficiency could lower hashrate, drop attacker break-even cost, and raise reorg risk. The defensible response: security has been adequate across four halvings, fees spike during demand events, the budget scales BTC-denominated against BTC-denominated value secured, and Lightning settlement, MEV-like dynamics, and covenant uses may provide sustained on-chain demand. The genuinely open question is whether those mechanisms produce sustained multi-year fee revenue or leave long stretches of low-fee, low-security operation; the 2028 and 2032 halvings are the key data-generating events.
Why this note matters
The long-term security budget is the most-engaged-with structural critique of Bitcoin from serious academic sources. Unlike short-horizon critiques (Bitcoin will collapse next year), this critique operates on a multi-decade horizon and turns on empirical questions that future evidence will resolve. The note matters because:
- It establishes the mechanics of how Bitcoin’s security is funded and how the subsidy decline interacts with fee revenue
- It engages the academic critique (Budish, Lewis-Pye, BIS) at higher resolution than mainstream coverage typically reaches
- It surfaces the specific uncertainty — fee-market sustained-revenue capacity over multi-year horizons — and the specific evidence that will resolve it (the 2028 and 2032 halving cycles)
- It articulates the range of possible futures — from “fee market matures and provides sustained security funding” through “periodic security crises during low-demand periods” to “structural protocol change becomes necessary” — and the conditions under which each becomes likely
The defensible position: this is the strongest long-horizon technical critique of Bitcoin and deserves serious sustained engagement. Holders should track empirical fee-revenue trends carefully and recognize that the question is not yet resolved by the empirical record.
The critique
Bitcoin’s network security depends on miners expending computational work (proof-of-work) to add blocks. Miners are compensated through:
- Block subsidy — newly-issued BTC per block. The current (2026) subsidy is 3.125 BTC per block. The subsidy halves every 210,000 blocks (~4 years). By 2028 it becomes ~1.5625 BTC; by 2032, ~0.78 BTC; by 2140, effectively zero.
- Transaction fees — Bitcoin paid by users for transaction inclusion. Currently varies widely; averages perhaps 5-15% of total miner revenue across recent years, with spikes much higher during congestion periods.
The structural concern:
- Total miner revenue funds network security. A 51% attack requires the attacker to control >50% of hashrate, which requires comparable economic investment to current miners. Higher miner revenue → higher hashrate → higher attack cost → stronger security.
- As subsidy declines, fees must rise to maintain miner revenue. If fees don’t rise enough, miner revenue declines, hashrate declines, attack cost declines, security declines.
- The fee market is structurally unreliable. Fees are determined by user demand for block space, which varies enormously with market conditions, Lightning adoption, and broader payment activity. There is no mechanism that guarantees fees will rise as subsidy falls.
Budish’s 2018 paper formalises the concern as a structural economic problem: in equilibrium, the cost of attacking Bitcoin equals the present value of miner revenue. If miner revenue declines, attack cost declines proportionally. For Bitcoin to remain secure long-term, fee revenue must sustainably replace subsidy revenue at a level proportional to the value being secured.
The further concern: the security budget needs to be large relative to what an attacker would gain from attacking. As Bitcoin becomes more valuable, the value an attacker could extract increases; the security budget must scale accordingly. Subsidy decline cuts in the opposite direction.
Key proponents
The critique is advanced by serious academic and institutional voices, not primarily by Bitcoin opponents:
- Eric Budish (University of Chicago Booth) — The Economic Limits of Bitcoin and the Blockchain (NBER Working Paper, 2018) — the canonical academic articulation; argues the security-budget problem is structural
- Andrew Lewis-Pye and Tim Roughgarden — Resource Pools and the CAP Theorem (2021) and related work on consensus-economics
- Bank for International Settlements (BIS) — various papers on cryptocurrency security economics, including critical engagement with the fee-market sustainability question
- Joseph Bonneau (NYU) — academic work on Bitcoin security economics
- Hasu and other within-crypto analysts — substantive engagement with the question from various positions
- Some Bitcoin developers — Nic Carter, Jameson Lopp, others have engaged the question publicly with non-dismissive responses; Adam Back has discussed it
- Critics including Frances Coppola and David Gerard have cited the security-budget problem as a long-horizon concern
The critique is technical and economic; it is not primarily ideological. Many serious Bitcoin proponents acknowledge it as a real open question rather than dismissing it.
What’s right about the critique
Several factual and theoretical points are correct:
The subsidy decline is mechanical. The halving schedule is in the protocol; subsidy will decline as scheduled. By 2032 it is half of current levels; by 2040 it is ~25% of current; etc.
Fee revenue is currently a small fraction of miner revenue. Across most blocks, fees represent 5-15% of total miner revenue. To replace subsidy entirely, fees would need to grow approximately 6-10x relative to subsidy at the current ratio.
Fee revenue is highly variable. Empirically, fee revenue spikes during demand events (2017 bull market; 2021 bull market; 2023-2024 Ordinals/Inscriptions activity) and falls to low baselines between events. There is no demonstrated mechanism that produces sustained high fee revenue.
Lightning Network reduces on-chain transaction demand. As more transactional activity moves to Lightning (see Lightning privacy properties), the on-chain demand for block space at any given price decreases. This is the intended Lightning function; it has the side effect of reducing on-chain fee pressure.
The security budget must scale with secured value. A higher-value Bitcoin produces stronger incentives for attack. The security budget needs to keep pace; subsidy decline reduces the security budget’s natural growth.
The empirical record is short. Bitcoin has experienced four halvings (2012, 2016, 2020, 2024); each was followed by hashrate growth and price appreciation. But the post-subsidy era is decades away, and the empirical record at low-subsidy levels is non-existent.
The Bitcoin-side response
The response operates on several layers.
The empirical track record
Bitcoin’s security has been adequate across four halvings. Hashrate has grown roughly 4-6 orders of magnitude since 2012; no 51% attack has succeeded; no sustained period of declining security has occurred. The empirical evidence so far is favourable to the “fee market will sustain security” hypothesis.
This evidence is not conclusive because the post-subsidy era hasn’t started. But “the system has worked through the first 60% of the subsidy decline” is non-trivial empirical support.
Fee-revenue spikes as evidence of capability
The 2023-2024 Ordinals/Inscriptions activity produced sustained periods where fees were 30-60% of total miner revenue, demonstrating that the fee market can produce substantial revenue when demand exists. The question is whether such demand becomes sustained rather than episodic.
The optimistic argument: as Bitcoin becomes more valuable and more types of activity emerge on-chain (Lightning-channel opens; MEV-like activity; covenant-based applications; ordinals-style use cases), structural demand for block space grows.
The pessimistic counter: each of these demand sources is itself uncertain. Lightning could reduce on-chain demand if it captures the bulk of payment activity. Ordinals-style demand could be transient (regulatory pressure, fashion change). MEV-like dynamics in Bitcoin are less developed than in Ethereum.
The BTC-denominated security budget
A key reframing from Nic Carter, Antonopoulos, and others: the security budget should be measured in BTC, not USD. If BTC appreciates in USD terms, the USD-value security budget can grow even as the BTC-denominated subsidy declines.
The argument: an attacker needs to deploy enough resources to control >50% of hashrate. The cost of doing so scales roughly with the USD value of mining equipment + electricity needed. If BTC appreciates significantly, the USD-revenue from mining grows enough to support sustained hashrate even at declining BTC subsidy.
This is a defensible argument but it assumes sustained BTC appreciation. If BTC value stagnates or declines, the USD-denominated security budget shrinks with the BTC-denominated subsidy.
Lightning-driven demand for on-chain finality
The Lightning Network requires on-chain transactions for channel opens and closes. As Lightning grows, these channel-management transactions create structural demand for block space — demand that is largely insensitive to fee levels (channel operations have to happen on-chain regardless of fee).
If Lightning captures meaningful payment volume globally, the on-chain demand from channel operations alone could provide sustained fee revenue. This is an optimistic scenario; the empirical question is whether Lightning grows large enough fast enough for this to matter at scale.
Block space as a structural demand
Beyond Lightning, several other use cases create structural demand for block space:
- Self-custody onboarding — every new self-custodied wallet requires at least one on-chain transaction
- Multisig operations — multi-signature wallets require on-chain transactions; the institutional-custody growth pattern (per Custody concentration risks) increases this demand
- Cross-chain bridges and wrapped Bitcoin operations — produce on-chain transaction demand
- Time-locked covenants and inheritance operations — once covenant proposals (BIP-119 CTV, OP_CAT, others) deploy, they could produce new on-chain demand patterns
- MEV-like dynamics — Bitcoin doesn’t have Ethereum’s smart-contract MEV but does have transaction-ordering and time-sensitive uses that may produce fee premiums
The optimistic case: the cumulative demand from these sources produces sustained fee revenue.
Bitcoin’s hashrate-economics flexibility
A nuance: a temporary decline in hashrate doesn’t necessarily produce a security crisis. Bitcoin’s difficulty adjustment recalibrates every 2,016 blocks; if hashrate drops, difficulty drops, marginal miners become profitable again, and equilibrium re-establishes at a lower hashrate level. Network security would be reduced but not catastrophically.
A 51% attack at lower hashrate is cheaper but the attacker’s gain from the attack is also typically bounded (double-spending finite UTXOs; censoring transactions for a limited window). The attack-cost / attack-gain ratio doesn’t change as dramatically as hashrate alone suggests.
Counter-arguments and tensions
”The empirical record from four halvings doesn’t generalize to the post-subsidy era”
The tension: The four halvings so far have happened during periods of strong BTC price appreciation; each was followed by a new bull market. The post-subsidy era is decades away and will operate under different conditions; extrapolating from the first four halvings is uncertain.
Response: Valid concern. The empirical record provides directional evidence but not conclusive evidence. The 2028 and 2032 halving cycles will be more informative — by 2032 the subsidy is ~25% of current, and the fee market will need to be ~3x more productive in relative terms to maintain miner revenue. Watch carefully.
”Lightning hurts the fee market”
The tension: Lightning is designed to move payments off-chain. If it succeeds, it dramatically reduces on-chain transaction demand and thus on-chain fees. This is intentional from Lightning’s perspective but pessimistic for the security budget.
Response: Partially valid; the trade-off is real. Mitigations: (1) Lightning channel operations themselves require on-chain transactions; large-scale Lightning use produces sustained channel-operation demand; (2) Lightning makes Bitcoin more useful, which increases its value, which (per the BTC-denominated argument) sustains miner revenue; (3) on-chain settlement of large transactions remains valuable even with Lightning. The Lightning-vs-security tension is real but not unidirectional.
”Ordinals-style demand is fashion, not structure”
The tension: The 2023-2024 fee-revenue spike from Ordinals/Inscriptions/BRC-20 activity was a transient fashion. Once the novelty wore off and regulatory and community pushback grew, the demand declined. Treating this as evidence of fee-market viability is misleading.
Response: Partially valid. Ordinals demand has been variable and the regulatory pushback is real. But the Ordinals episode demonstrated that fee revenue can be substantial when use cases emerge; the question is whether new use cases continue to emerge over time. Several adjacent activities (rollups proposals; covenant-based applications; new transaction patterns) could substitute as the demand evolves.
”Bitcoin’s protocol-evolution constraints limit structural responses”
The tension: If the fee market proves insufficient, structural changes could help (tail emission; demurrage; soft-forks that increase block-space value). But Bitcoin’s calcification (see Protocol-evolution constraints) makes such changes hard. The security-budget problem could materialize without the development community having tools to respond.
Response: Real concern. The interaction between this critique and the protocol-evolution-constraints critique is genuinely concerning. Some mitigations within current protocol — covenant-based applications, Lightning growth, structural-demand cultivation — don’t require contentious soft-forks. But fundamental changes (tail emission, supply-cap modification) face very high hurdles within Bitcoin’s community values.
”The critique applies to all proof-of-work systems but Bitcoin’s value scale makes it unique”
The tension: The security-budget problem isn’t unique to Bitcoin; it applies to any proof-of-work blockchain with a declining subsidy schedule. Other chains (Bitcoin Cash, Litecoin, etc.) face the same issue and are exhibiting it now. The fact that Bitcoin is the largest doesn’t exempt it.
Response: True, but Bitcoin’s scale produces different dynamics. The absolute USD value of mining revenue is much higher; the fee-market activity is much higher; the network effects driving on-chain demand are stronger. Other proof-of-work chains have weaker fee markets in absolute terms. Bitcoin’s scale produces a different fee-market viability profile.
Verdict: Genuinely open; the next two halvings (2028, 2032) are the key data-generating events
The long-term security budget is the strongest long-horizon technical critique of Bitcoin. The mechanics are real; the empirical evidence is favourable so far but limited; the question of sustained fee-market viability is unresolved.
A serious assessment:
- Short-horizon (next 8 years, through 2032 halving): probably fine. Subsidy remains material; fee-market dynamics may produce spikes; security adequate by historical standards.
- Medium-horizon (2032-2040): genuinely uncertain. Subsidy declines to ~10-25% of current; fee market needs to be 3-10x more productive to maintain miner revenue at current BTC price levels.
- Long-horizon (2040-2060+): depends on whether (a) BTC value has grown enough to sustain USD-denominated security budget at lower BTC-subsidy, (b) Lightning and adjacent uses produce sustained on-chain fee demand, (c) structural protocol changes become possible if needed.
- Tail-risk horizon (post-2100): speculation; the subsidy is essentially zero; the system must run on fees entirely.
This is the critique most worth tracking actively, and it should be held open honestly: nobody can prove today how the fee market of 2040 behaves. But open is not the same as adverse, and the asymmetry runs Bitcoin’s way. The security budget is denominated in dollars, not coins — a subsidy that falls in BTC terms can hold or grow in purchasing power if Bitcoin’s value rises, which is the same monetization the critics concede elsewhere has run since 2009. The budget has more than one path to sufficiency — price appreciation, sustained fee demand from settlement and Layer-2 traffic, and, as a floor, the fact that a network securing trillions in value can change its own parameters if it must, because the thing being protected is worth protecting. The 2028 and 2032 halvings will tell us more, and the honest posture is to watch them. But the burden the critique carries is to show why the one monetary network that has repeatedly grown into each subsidy cut will fail to do so precisely when it matters most — and that is a forecast about a curve that stops, which the critic needs and the mechanics do not supply.
Open questions for further development
- What is the right metric for tracking fee-market viability? Total fee revenue per block? Fee revenue as fraction of total miner revenue? Sustained fee-revenue trend across multiple years?
- The 2028 halving will be a key data point. What conditions (BTC price, Lightning adoption, Ordinals-style activity continuation) are the dominant variables for the post-halving fee market?
- How do covenant-based applications (BIP-119, OP_CAT discussions) interact with fee-market dynamics? Some proposals could create new structural demand for block space.
- Is there a defensible “tail emission” or other structural change that the Bitcoin community could plausibly accept if the fee market proves insufficient? Most current discussion treats this as outside the acceptable design space, but circumstances could change.
- How does the long-term security budget interact with the Quantum computing threat to Bitcoin migration? Both are long-horizon issues with overlapping timelines.
- Mining centralization (per Mining centralization concerns) affects the attack-cost calculation; how do the two critiques interact at multi-decade horizons?
Canonical sources for this note
The canonical academic critique:
- Budish, Eric — The Economic Limits of Bitcoin and the Blockchain (NBER Working Paper 24717, 2018)
- Budish — Trust at Scale: The Economic Limits of Cryptocurrencies and Blockchains (various subsequent updates)
Adjacent academic work:
- Lewis-Pye, Andrew and Roughgarden, Tim — Resource Pools and the CAP Theorem (2021)
- Bonneau, Joseph — Bitcoin Security Economics papers
- Various BIS (Bank for International Settlements) working papers on cryptocurrency security
Bitcoin-side engagements:
- Carter, Nic — various essays on Bitcoin’s long-term security model
- Antonopoulos, Andreas — Mastering Bitcoin sections on long-term security and mining economics. See Mastering Bitcoin - Andreas Antonopoulos.
- Adam Back — various technical talks engaging the question
- Lopp, Jameson — practitioner perspective on long-term security trade-offs. See Jameson Lopp.
- Hasu — Bitcoin’s Security and the Halving and related essays
Within-Bitcoin debates:
- Recurring Bitcoin Talk and bitcoin-dev mailing-list threads on tail emission proposals (consistently rejected)
- BitMEX Research on mining economics
- Various Lopp, Carter, Antonopoulos podcast appearances engaging the critique
Critic context:
- Coppola, Frances — engages the security-budget question; see Frances Coppola
- Gerard, David — broader crypto-skeptical engagement; see David Gerard
- White, Molly — broader crypto-skeptical engagement; see Molly White
As of 2026-05-15: the 2024 halving has produced the third post-halving fee-market data point; sustained Ordinals-driven fee activity has been variable; the empirical question remains open. The 2028 halving is the next major data-generating event.
Related notes
Within the Criticisms section:
- Quantum computing threat to Bitcoin — adjacent long-horizon technical critique
- Consensus-layer attack theories — the attack-mechanics this budget critique connects to
- Mining centralization concerns — mining-economics adjacency
- Protocol-evolution constraints — the response-execution question if structural change becomes necessary
- Criticisms of Bitcoin — the section sub-MOC
Technical foundations section:
Mining section:
Economics-section adjacency:
- Bitcoin fixed supply and issuance schedule — the subsidy schedule this critique engages
- The halving - Mechanism — the specific halving event
- Halvings - History — empirical record across four halvings
Adjacent thinker pages:
- Nick Carter — substantive engagement with the critique
- Jameson Lopp — practitioner perspective
- Andreas Antonopoulos — long-term security treatment
The sub-MOC home: