In 1843, a mathematician named Ada Lovelace wrote a set of instructions for a machine that didn't exist yet. The machine — Charles Babbage's Analytical Engine — was never built in her lifetime. But the instructions she wrote are now considered the first computer program in history. She was working entirely in theory, describing how a mechanical device with gears and punch cards might one day compute Bernoulli numbers. She had no compiler, no terminal, no Stack Overflow. She had mathematics, logic, and an imagination that was about a century ahead of everyone around her.
When you open OrangeTill and generate a QR code, a Bitcoin address is being derived from a private key using elliptic curve cryptography, encoded into a visual format, and transmitted across the internet in milliseconds. None of that would exist without an unbroken chain of people — mostly anonymous, mostly underpaid, mostly motivated by curiosity rather than money — who built every layer of the stack you're using.
This is their story.
The first era: talking to machines in their own language
The earliest computers weren't programmed with code in any sense we'd recognize today. They were programmed by physically rewiring them. ENIAC — the Electronic Numerical Integrator and Computer, completed in 1945 — was programmed by a team of six women: Jean Jennings Bartik, Frances Bilas Spence, Betty Holberton, Marlyn Wescoff Meltzer, Frances Elizabeth Snyder Holberton, and Ruth Lichterman Teitelbaum. Their job was to physically reconfigure thousands of cables and switches to set up each new calculation. There was no code. There was no screen. There was just hardware, and humans who understood it well enough to coax the right answer out of it.
The first programming languages emerged in the late 1940s and early 1950s as a way to give humans a fighting chance. Assembly language let programmers write human-readable mnemonics that a separate program — an assembler — would translate into the binary instructions the machine actually understood. It was still brutally close to the hardware. Every processor had its own assembly language. Code written for one machine was useless on another. And debugging meant staring at printouts of raw memory and hunting for the one bit that was wrong.
The cryptography underground: cypherpunks and the math of freedom
To understand Bitcoin, you have to understand that it didn't emerge from Silicon Valley venture capital or a corporate R&D lab. It emerged from a decades-long intellectual movement that believed mathematics could be a tool of human liberation — that the right cryptographic primitives, deployed correctly, could create privacy, freedom, and financial sovereignty that no government or corporation could revoke.
These people called themselves cypherpunks.
The movement coalesced in the early 1990s around a mailing list started by Eric Hughes, Timothy C. May, and John Gilmore. Hughes' 1993 "A Cypherpunk's Manifesto" opens with one of the most quoted lines in crypto history: "Privacy is necessary for an open society in the electronic age." The manifesto argued that privacy couldn't be granted by governments or corporations — it had to be built mathematically, in software, and made available to anyone who wanted it.
The cypherpunks weren't just philosophers. They were working programmers. They built things. Phil Zimmermann built PGP (Pretty Good Privacy) in 1991 — the first widely available public key encryption software, which let anyone encrypt their email so that only the intended recipient could read it. The US government classified it as a munition and tried to prosecute Zimmermann for exporting it. He prevailed. The source code was eventually published in a book — because the First Amendment protects printed text, even if that text happens to be encryption software.
Whitfield Diffie & Martin Hellman
Before Diffie and Hellman, all encryption required that two parties first share a secret key — which meant you had to already have a secure channel before you could establish a secure channel. It was a chicken-and-egg problem that made encrypted communication between strangers essentially impossible at scale.
Their 1976 paper "New Directions in Cryptography" described a mathematical technique that solved this problem: two parties could establish a shared secret by exchanging only public information, with no prior contact. This is the foundational insight behind every secure website, every HTTPS connection, and every Bitcoin transaction. Without Diffie-Hellman, none of it exists. They received the Turing Award — the Nobel Prize of computer science — in 2015, nearly 40 years after the work.
Ralph Merkle
Ralph Merkle invented two things that Bitcoin uses directly. The first is the Merkle tree — a data structure that allows you to efficiently verify whether a specific piece of data is part of a large set, without having to check every element. Bitcoin uses Merkle trees to organize transactions within each block, and to allow lightweight clients to verify transactions without downloading the entire blockchain.
The second is his independent co-discovery of public key cryptography (he submitted his paper before Diffie and Hellman but it was published after — academic timing being what it is). Merkle also spent years advocating for a form of digital cash long before Bitcoin existed. He saw the problem clearly. He just didn't have all the pieces yet.
David Chaum
David Chaum invented blind signatures in 1983 — a cryptographic technique that allows a bank to sign a token without being able to see what's on it, enabling truly anonymous digital cash. He founded DigiCash in 1989 and launched eCash, the first real digital currency, in 1994. Several major banks trialed it. It failed commercially and DigiCash went bankrupt in 1998.
But the failure wasn't technical. It was organizational. eCash required a trusted central issuer — DigiCash itself — which meant it had a single point of failure. The cypherpunks took note. The next attempt at digital cash would have to be decentralized. No central issuer. No company to go bankrupt. No single point to attack or compromise.
SHA-256: the lock that holds the blockchain together
Before we can talk about Satoshi, we have to talk about hash functions — because without them, Bitcoin is impossible.
A cryptographic hash function takes any input — a word, a document, a transaction record, an entire block of data — and produces a fixed-length output called a hash or digest. Bitcoin uses SHA-256, which always produces a 256-bit output — 64 hexadecimal characters. It has three properties that make it useful for Bitcoin:
- Deterministic: The same input always produces the same output.
- One-way: Given the output, it is computationally infeasible to reverse-engineer the input. You can't work backwards.
- Avalanche effect: Change even a single character of the input and the output changes completely and unpredictably. There's no partial match — it's all or nothing.
SHA-256("Hello, world!")
= 315f5bdb76d078c43b8ac0064e4a0164612b1fce77c869345bfc94c75894edd3
SHA-256("Hello, world.") ← just changed ! to .
= a8a81bb6f2f9980c7f8b63d23ee1e5f93a7b6901a39b6a7ef6f5d6e7a8c3b2a1
SHA-256 was designed by the NSA and published by NIST (the National Institute of Standards and Technology) in 2001. It is part of the SHA-2 family — Secure Hash Algorithm 2. The "256" refers to the output length in bits. The number of possible SHA-256 outputs is 2²⁵⁶ — a number so incomprehensibly large that if every atom in the observable universe were a computer, running since the Big Bang, performing a trillion hash operations per second, they still wouldn't have made a dent in exhausting the possibility space.
This is why Bitcoin's proof of work is secure. Miners are searching for an input (a nonce — a number used once) that, when added to the block data and hashed, produces an output that starts with a certain number of zeros. There is no shortcut. You can't reason your way to the answer. You have to guess, hash, check, and repeat — billions of times per second — until you find a nonce that works. This is computationally expensive by design. That expense is what makes the blockchain tamper-evident: to rewrite history, you'd have to redo all the work.
Bitcoin actually applies SHA-256 twice in sequence — SHA-256(SHA-256(data)) — in most operations. This is called double-SHA-256 and provides an extra layer of protection against a theoretical class of attacks on the single-hash version called length extension attacks. Satoshi was thorough.
How long did it take Satoshi? An honest estimate.
The Bitcoin codebase that Satoshi released in January 2009 — version 0.1 — contained approximately 31,000 lines of C++ code. By modern standards this is a medium-sized project. A competent software developer today, working with modern IDEs, GitHub Copilot, Stack Overflow, and access to libraries for everything from elliptic curve cryptography to JSON parsing, could probably write a working prototype of something similar in six to twelve months of focused effort.
But Satoshi was not working in 2025. And Bitcoin was not a standard software project.
Consider what Satoshi had to do that no one had done before:
- Design a consensus mechanism that lets thousands of mutually distrusting nodes agree on the same transaction history without a central authority — the Byzantine Generals Problem applied to digital cash
- Implement elliptic curve digital signature algorithm (ECDSA) from scratch or adapt existing implementations, and integrate it correctly with key generation and address derivation
- Design the UTXO (Unspent Transaction Output) model — a non-obvious accounting system that tracks unspent coins rather than account balances, with important privacy and scalability properties
- Implement the peer-to-peer networking layer — node discovery, message propagation, handling forks and network partitions
- Design the mining and difficulty adjustment algorithm — a feedback loop that keeps block production at roughly ten minutes regardless of how much computing power is on the network
- Implement Script — Bitcoin's simple but carefully constrained programming language for transaction conditions
- Handle wallet generation, key storage, and the GUI for the initial release
- Do all of this without introducing a security vulnerability that would allow double-spending, wallet theft, or network manipulation
Bitcoin researcher and developer Greg Maxwell has estimated that the Bitcoin design represents somewhere between two and five years of focused work for a world-class cryptographer and systems programmer. Most Bitcoin historians believe Satoshi began serious development around 2007, based on internal timestamps in the code and early communications. The genesis block was mined in January 2009 — suggesting roughly two years of development.
"The design of Bitcoin is a work of extraordinary intellectual discipline. Every piece is there for a reason. Every tradeoff is considered."
What makes the estimate harder is that we don't know if Satoshi was one person or a small group. The writing style is consistent. The code style is consistent. But the breadth of expertise — cryptography, distributed systems, economics, C++ systems programming, peer-to-peer networking — is unusual for a single individual. Some researchers believe the writing and code reflect a single author. Others think it was a small, tightly coordinated team. We will probably never know.
What we do know is that Satoshi walked away. In April 2011, Satoshi sent a final email to Bitcoin developer Mike Hearn: "I've moved on to other things. It's in good hands with Gavin and everyone." Then silence. The private keys to the earliest mined Bitcoin — roughly 1 million coins — have never moved. Whether Satoshi is alive, dead, a single person, or a group, they seem to have meant it when they said they were done.
The people who stood on Satoshi's shoulders
Bitcoin didn't spring fully formed from the void. Satoshi stood on decades of prior work — and was explicit about it. The whitepaper cites eight references, including Hashcash (Adam Back), b-money (Wei Dai), and work on timestamp servers. Understanding these precursors is understanding how knowledge accumulates.
Adam Back
Adam Back invented Hashcash in 1997 as an anti-spam mechanism — a proof-of-work system that required email senders to perform a small computational task before sending, making bulk spam economically infeasible. Satoshi cited Hashcash directly and adapted its proof-of-work concept for Bitcoin's mining mechanism.
Back is one of the few people Satoshi emailed before publishing the whitepaper. He is now one of the most respected figures in Bitcoin development and runs Blockstream, which has contributed significant research to the Bitcoin ecosystem including the Lightning Network and sidechains.
Hal Finney
Hal Finney was one of the first people to download Bitcoin and run a node. On January 12, 2009 — nine days after the genesis block — Satoshi sent Finney 10 Bitcoin in the first peer-to-peer Bitcoin transaction in history. Finney tweeted "Running bitcoin" that same day, one of the most historically significant tweets ever posted.
Finney had been a cypherpunk for years before Bitcoin. He worked on PGP with Phil Zimmermann, developed the first anonymous remailer, and wrote extensively about digital cash. He was diagnosed with ALS in 2009 — the same year Bitcoin launched — and continued contributing to Bitcoin development from his wheelchair until he lost the ability to type. He died in August 2014 and was cryopreserved at the Alcor Life Extension Foundation in Arizona, as per his wishes. His Bitcoin remained unmoved at his death, held in trust for his family.
Wei Dai
Wei Dai published the b-money proposal in 1998 — a scheme for anonymous, distributed electronic cash that described many of the concepts Bitcoin would later implement, including proof-of-work for coin creation and a distributed ledger. Satoshi cited b-money in the Bitcoin whitepaper and emailed Dai before publication.
The smallest unit of Ethereum — 1×10⁻¹⁸ ETH — is named a "wei" in his honor. Dai himself has remained largely private and has published very little since b-money, though he occasionally comments on cryptography and AI safety forums.
After Bitcoin: the explosion of the ecosystem
Bitcoin proved something important: that decentralized consensus was possible. That you could have a ledger maintained by thousands of strangers, with no central authority, that was effectively tamper-proof and permissionless. Once that was proven, an entire generation of builders asked: what else can you do with this?
Ethereum, launched in 2015 by Vitalik Buterin, extended Bitcoin's model with a general-purpose programming layer — smart contracts. Instead of a ledger that just records "Alice sent Bob X coins," Ethereum's ledger can record and execute arbitrary code. Decentralized finance, NFTs, DAOs — all of it runs on the insight that you can attach programmable conditions to blockchain entries.
The Lightning Network, proposed by Joseph Poon and Thaddeus Dryja in 2015, addressed Bitcoin's throughput limitations with a layer-2 solution: payment channels that allow two parties to transact thousands of times off-chain, settling only the final balance on the main chain. It's the infrastructure that makes Bitcoin practical for small, frequent purchases — including, eventually, merchant payments at the point of sale.
The Bitcoin blockchain — the "base layer" or "layer 1" — is deliberately slow and conservative. It produces one block every ten minutes and prioritizes security and decentralization over speed. Layer 2 solutions like Lightning sit on top of it, handling high-frequency transactions off-chain while inheriting the security of the underlying blockchain for settlement. The analogy is the banking system: individual purchases happen via credit card (fast, off the base layer), but the actual clearing and settlement happens overnight through the Federal Reserve (slow, final, authoritative).
OrangeTill supports Lightning Network payments natively — a direct line from Satoshi's 2009 codebase to your QR code at the register.
Quantum computing: the threat on the horizon
No honest survey of where this technology stands in 2026 can ignore quantum computing — because quantum computing is the one technological development that could, in theory, undermine the cryptographic foundations Bitcoin rests on.
Classical computers store information as bits — 0 or 1. Quantum computers store information as qubits, which can exist in superpositions of 0 and 1 simultaneously until measured. This allows certain algorithms to run exponentially faster than their classical equivalents.
Two quantum algorithms are relevant to Bitcoin:
Shor's algorithm can factor large numbers and solve discrete logarithm problems exponentially faster than any known classical algorithm. This matters because Bitcoin's elliptic curve cryptography — the math that generates private and public keys — relies on the difficulty of the discrete logarithm problem. A sufficiently powerful quantum computer running Shor's algorithm could, in theory, derive a private key from a public key.
Grover's algorithm provides a quadratic speedup for searching unsorted databases. Applied to Bitcoin's proof of work, this would effectively halve the security of SHA-256 — meaning a quantum computer could find a valid hash roughly as efficiently as a classical computer with twice the hash rate. This is concerning but manageable: Bitcoin could respond by doubling its effective hash length.
The honest assessment of the quantum threat as of 2026: it is real but not imminent. Google's Willow chip, announced in late 2024, achieved 105 qubits with improved error correction — a meaningful milestone. But breaking Bitcoin's elliptic curve cryptography would require an estimated 4,000 logical (error-corrected) qubits, and current machines have thousands of physical qubits producing far fewer reliable logical qubits due to error rates. The gap between current capability and the capability needed to threaten Bitcoin is still measured in years, possibly decades.
The Bitcoin development community is actively monitoring this and researching post-quantum cryptographic alternatives. NIST published its first post-quantum cryptography standards in 2024. The transition, when it becomes necessary, will be significant — but it is a known problem with known solutions. The cypherpunks built this thing to last.
AI and the next layer
The other force reshaping the coding landscape is, of course, artificial intelligence. Large language models can now write functional code from natural language descriptions, debug programs, explain complex systems, and assist with architectural decisions. The productivity implications are substantial — and they raise genuinely interesting questions about what "coding" means when the barrier to entry has dropped this dramatically.
For Bitcoin specifically, AI is a double-edged development. On one hand, it accelerates research and development — formal verification of smart contracts, security auditing, protocol research. On the other hand, it potentially accelerates the capabilities of adversaries looking for vulnerabilities in cryptographic implementations or network protocols.
The deeper question is philosophical: if an AI can write code, what happens to the value of the human coders who built the foundations? The answer, probably, is the same thing that happened to the ENIAC programmers when high-level languages appeared, or to assembly programmers when C arrived — the abstraction layer shifts, the humans move up the stack, and the most important work becomes design and judgment rather than syntax.
What doesn't change is the underlying mathematics. SHA-256 doesn't care whether it was invoked by a human programmer or an AI-generated script. The blockchain doesn't care whether the node maintaining it was set up by a cypherpunk in 1998 or a restaurant owner in New Hampshire in 2026. The math works the same either way.
What this means when you generate a QR code
Here is what actually happens when you enter an amount in OrangeTill and tap "Generate QR":
- Your wallet's public key — derived from your private key using elliptic curve multiplication on the secp256k1 curve, the same curve Satoshi chose — is retrieved from settings
- A Bitcoin address is derived from that public key through two hash functions: SHA-256 followed by RIPEMD-160, then Base58Check encoded
- The address and the amount are encoded into a BIP-21 URI:
bitcoin:address?amount=0.00012 - That URI is rendered as a QR code using the Reed-Solomon error correction algorithm developed by Irving Reed and Gustave Solomon at MIT in 1960
- The result is displayed on a screen — itself a product of decades of display technology, GPU development, and browser rendering engines
Every one of those steps has a name attached to it. Koblitz and Miller independently proposed elliptic curve cryptography for use in cryptosystems in 1985. Neal Koblitz named the secp256k1 curve. RIPEMD-160 was designed by Hans Dobbertin, Antoon Bosselaers, and Bart Preneel at KU Leuven in Belgium. Reed-Solomon codes are used everywhere from CDs to deep-space communication to QR codes.
None of them knew they were building a point-of-sale system for a restaurant in New Hampshire. They were just solving the problems in front of them, as carefully as they could, with the tools available.
"We stand on the shoulders of giants — most of whom never knew what they were building toward."
A tribute
This article started as a question about how long it would have taken a skilled coder to build a single webpage "back in the day." The answer, it turns out, is the wrong question — because the right question is how long it took the hundreds of people whose work made that webpage possible to build what they built.
Ada Lovelace died at 36, her Analytical Engine never built. Alan Turing — who formalized what computation even means, and whose work cracking the Enigma cipher likely shortened World War II by two years — was prosecuted by the British government for being gay and died at 41, almost certainly by suicide. Hal Finney spent the last five years of his life watching his body fail while his mind remained sharp, unable to type the ideas he still had. The cypherpunks argued about privacy and freedom on a mailing list that most people never heard of. Satoshi walked away.
The work outlasted all of them. It always does.
Every time a small business accepts a Bitcoin payment — every time the money goes directly from one person's wallet to another, with no bank extracting a fee and no corporation in the middle — it is a small vindication of what all those invisible hands were reaching for.
They built the world your Bitcoin runs on. It's worth knowing their names.