Before Bitcoin, this problem had no solution. Not a bad solution, not an expensive solution — no solution at all. It had stumped computer scientists for nearly thirty years. The question sounds almost philosophical: how do you reach consensus with people you cannot trust, over a channel you cannot verify, with no authority to appeal to?

Bitcoin answers it. And understanding how changes the way you think about what Bitcoin actually is — not a currency, not a speculative asset, but a breakthrough in distributed systems that happens to be useful as money.

The thought experiment

In 1982, three computer scientists — Leslie Lamport, Robert Shostak, and Marshall Pease — published a paper with a vivid name: "The Byzantine Generals' Problem." The scenario goes like this.

Several divisions of the Byzantine army have surrounded an enemy city. Each division is commanded by a general. The generals must agree on a common battle plan — attack or retreat — and they can only communicate by messenger. If all generals attack together, they win. If some attack while others retreat, they are destroyed. So agreement is not optional. It is existential.

The problem is that some generals may be traitors. A traitorous general might send one message to half the army ("attack") and a different message to the other half ("retreat"), deliberately sowing confusion. A messenger might be intercepted and the message altered. There is no way for any general to know whether the message they received is the same message every other general received.

It is not sufficient that everyone knows X. We also need everyone to know that everyone knows X — which, as in the Byzantine Generals problem, is the classic hard problem of distributed data processing.

That quote is from a cryptographer named James Donald, writing to an internet mailing list in November 2008. He wasn't describing an ancient military problem. He was describing why he thought a new electronic cash system couldn't work. The system was Bitcoin. The person he was writing to was Satoshi Nakamoto.

Why computers have the same problem

The Byzantine Generals aren't really about armies. They're a metaphor for any distributed system where participants must agree on a shared state without being able to verify each other's honesty.

Think about what a financial network needs to do. When you send money, every participant in the network needs to agree that: the transaction happened, it happened at a specific time, and the funds weren't spent twice. In a centralized system — a bank, a payment processor — this is easy. There's one authority that keeps the ledger. Everyone trusts the bank because the bank is the arbiter.

But what if you want to remove the bank? What if you want a network where no single participant has authority, where anyone can join, and where the rules are enforced by the participants themselves? Now you have the Byzantine Generals' Problem. Any node on the network could lie. Any message could be forged. How does the network reach agreement?

This wasn't just a theoretical puzzle. Earlier attempts at digital cash — b-money by Wei Dai, Bit Gold by Nick Szabo, HashCash by Adam Back — all ran into versions of this wall. They had brilliant ideas about scarcity and cryptographic proof, but none of them cracked decentralized consensus. Without that, you couldn't prevent double-spending. Without preventing double-spending, you didn't have money.

The double-spend problem

Why consensus is the core issue

Imagine Alice has one bitcoin. She sends it to Bob at 10:00am. Then, a fraction of a second later, she sends the same bitcoin to Carol. Both transactions are broadcast to the network simultaneously. Without a way to agree on which transaction came first — without consensus — both could appear valid. Alice spent one bitcoin twice.

In a bank, the ledger is centralized. The bank sees both transactions and rejects the second one. In a decentralized network, there is no bank. The network itself must agree on which transaction is real. That requires solving the Byzantine Generals' Problem.

Satoshi's answer: unforgeable cost

On November 13, 2008 — two weeks after publishing the Bitcoin whitepaper — Satoshi Nakamoto replied to James Donald's challenge on the Cryptography Mailing List at metzdowd.com. His response was five words: "The proof-of-work chain is a solution to the Byzantine Generals' Problem."

He then restated the entire Bitcoin design using the generals metaphor. It was the first time anyone explicitly connected Bitcoin to the problem. Satoshi made the connection himself.

So what is the solution? It's elegant, and it rests on a single insight: you can't fake computational work.

In Bitcoin, no general announces a decision. Instead, generals compete to solve an extremely difficult mathematical puzzle. The puzzle requires real-world resources — electricity and processing power — to solve. Finding the solution takes, on average, ten minutes and an enormous amount of computation. But verifying that someone else found a solution takes a fraction of a second.

This asymmetry is the key. Producing proof of work is expensive. Verifying it is free. A traitor who wants to deceive the network must outspend all the honest participants combined.

Satoshi Nakamoto — Cryptography Mailing List, November 13, 2008
"A number of Byzantine Generals each have a computer and want to attack the King's wi-fi by brute forcing the password... They only have enough CPU power to crack it fast enough if a majority of them attack at the same time... The proof-of-work chain is how all the synchronisation, distributed database and global view problems are solved."
Archived at the Satoshi Nakamoto Institute · satoshi.nakamotoinstitute.org

How proof of work creates consensus

Here is how it works in practice. When a miner wants to add a block of transactions to the Bitcoin blockchain, they must find a number — called a nonce — such that when it's combined with the block's data and run through a cryptographic hash function, the result meets a specific target. There is no shortcut. You have to try billions of combinations until you find one that works.

When a miner finds a valid nonce, they broadcast the block to the network. Every other node can instantly verify the solution is correct. If the solution is valid, they accept the block and start building on top of it. The longest chain — the one with the most accumulated proof of work — is treated as the true history.

This is how the network reaches agreement without trusting anyone. No general announces the battle plan. Instead, the generals collectively build a chain of evidence that makes their shared history mathematically expensive to rewrite. The more blocks are added on top of a transaction, the more computational work an attacker would need to undo it.

The problem

Strangers on a network must agree on a shared truth. Any participant could lie. Messages could be forged. No central authority exists to arbitrate.

Bitcoin's solution

Make agreement expensive to fake. Proof of work ties consensus to real-world resources. Lying requires outspending everyone else combined — indefinitely.

The 51% threshold

Bitcoin's Byzantine fault tolerance comes with a specific guarantee: the network reaches honest consensus as long as more than half of its computational power is controlled by honest participants. This is the 51% rule, and it is both Bitcoin's strength and its one acknowledged vulnerability.

If an attacker controlled 51% or more of the network's mining power — called a 51% attack — they could, in theory, rewrite recent history. They could reverse transactions they made, allowing them to spend the same bitcoin twice. They could not, however, create bitcoin out of nothing, steal from other wallets, or change the protocol's rules. The attack is powerful but limited.

In practice, a 51% attack on Bitcoin is financially catastrophic for the attacker. The Bitcoin network currently represents an extraordinary concentration of computing power — more than any other computing project in history. Acquiring 51% of that hash rate would cost billions of dollars in hardware alone, plus ongoing electricity costs. And if such an attack were detected, it would likely crash the value of the asset the attacker was trying to exploit. The incentives are designed to make honesty more profitable than cheating.

₿
Hodl says

A 51% attack on Bitcoin would cost more than the GDP of most countries to sustain. The attacker would also be destroying the value of the asset they're trying to steal. I've thought about this at length. The math doesn't work out in their favor.

Why this is historically significant

It is easy to understate what Satoshi actually accomplished. The Byzantine Generals' Problem had been formally described in 1982. For 26 years, no one had produced a practical solution that worked in a fully open, permissionless, adversarial network — one where anyone could join, no one had to be vetted, and the stakes were real money.

Previous solutions, like Practical Byzantine Fault Tolerance (pBFT), required knowing the full set of participants in advance. That works for a closed corporate network. It doesn't work for an open internet where nodes join and leave constantly and no central administrator controls membership.

Bitcoin's contribution was solving Byzantine fault tolerance at open scale — for strangers, with no gatekeepers, using nothing but mathematics and economic incentives. Hal Finney, one of the first people to respond to the Bitcoin whitepaper on that same mailing list, recognized this immediately: he called the use of proof of work for this purpose "a novel idea well worth further review."

1982
The problem is named

Lamport, Shostak, and Pease publish "The Byzantine Generals' Problem," formalizing the challenge of consensus in distributed systems with potentially dishonest participants.

1990s
Partial solutions emerge

pBFT and similar protocols solve the problem for closed, known networks. The open-internet case remains unsolved. Cypherpunk attempts at digital cash stall on this wall.

Oct 2008
The whitepaper

Satoshi Nakamoto publishes "Bitcoin: A Peer-to-Peer Electronic Cash System." The term Byzantine Generals' Problem doesn't appear — but the solution is in every line.

Nov 2008
Satoshi names the connection

Responding to skeptic James Donald on the Cryptography Mailing List: "The proof-of-work chain is a solution to the Byzantine Generals' Problem." The first explicit statement of what Bitcoin had achieved.

Jan 2009
The network launches

The genesis block is mined. The theoretical solution becomes a running system. The Byzantine Generals finally agree — and the agreement has held ever since.

What this means for Bitcoin as money

The Byzantine Generals' Problem is not just a computer science curiosity. It is the reason Bitcoin can exist as money without a bank.

Every monetary system in history has solved the trust problem the same way: by designating an authority. Gold worked because governments verified its weight and purity and stamped it with their guarantee. Paper money works because central banks control its issuance and governments enforce its acceptance. Credit cards work because Visa and Mastercard sit between every buyer and seller, adjudicating disputes.

All of these systems bypass the Byzantine Generals' Problem rather than solving it. They appoint a trusted third party and hope that third party remains trustworthy. The history of money is substantially a history of that hope being disappointed — debasement, inflation, bank failures, frozen accounts, capital controls.

Bitcoin solves the problem directly. It does not appoint a trusted third party. It does not hope that the generals are honest. It makes dishonesty mathematically expensive — expensive enough that the honest majority will always outpace any attacker as long as participants have more to gain from the network's integrity than from its destruction.

The honest summary

Bitcoin is Byzantine fault tolerant under a specific assumption: that honest participants control more than 50% of the network's mining power. This assumption has held for Bitcoin's entire existence. It is not guaranteed forever — it depends on the continued growth of honest mining participation.

Smaller proof-of-work cryptocurrencies have been successfully 51% attacked, because their hash rates are low enough that an attacker can rent sufficient computing power cheaply. Bitcoin's scale is its security. The network's size is the moat.

This is also why Bitcoin maximalists care so much about hash rate. A higher hash rate means a more expensive attack. It is not vanity — it is the direct measure of how well Bitcoin is actually solving the problem it was designed to solve.

A different way to think about what you're accepting

When a customer pays you in Bitcoin at the counter, something remarkable is happening beneath the surface. Two strangers — your business and a customer you may never see again — are exchanging value with no bank, no payment processor, and no dispute arbitration. The transaction settles because thousands of nodes around the world, who don't know either of you and have no particular reason to favor one party over the other, have independently verified it and added it to a chain of evidence that would cost billions of dollars to rewrite.

That is the Byzantine Generals' Problem, solved in real time, every ten minutes, continuously since January 2009.

You don't need to know any of this to use OrangeTill. The math runs quietly in the background. But it helps to know what you're part of — and why Bitcoin is not just a payment method, but a genuinely new kind of infrastructure for human coordination.

The generals have agreed. Your counter is ready.

OrangeTill lets you accept Bitcoin and 8 other cryptocurrencies — no crypto knowledge required at the register.

Try OrangeTill for Free →
The content on this page is for informational and educational purposes only. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency markets are volatile and carry significant risk, including the possible loss of principal. Past performance of any asset is not indicative of future results. OrangeTill is a payment processing tool, not a financial advisory service. The author may hold positions in cryptocurrencies mentioned. Always consult a qualified financial advisor, accountant, or legal professional before making investment or business decisions.