Part I of this series The Ghost in the Timechain — Who Really Built Bitcoin? Read the original forensic investigation that started this series.

You think Bitcoin is decentralised. You've been told no single person controls it. You've been told the community decides. You've been told the rules can only change if everyone agrees.

You were misled.

Not by a conspiracy. Not by a cover-up in the dark. But by something far more uncomfortable — a documented historical record sitting in the Bitcoin Wiki, in GitHub commit logs, in archived cypherpunk emails, and in the words of the people who were actually there. A record that has been publicly available since the events happened, that nobody has ever assembled into a single framework.

Until now.

Three times in Bitcoin's first thirteen months, the consensus rules were changed without telling anyone. Three times, the community woke up to a different protocol than the one they went to sleep with. Once, those who found the code were explicitly told to keep their mouths shut.

The word for what happened doesn't exist yet in Bitcoin's vocabulary.

It does now.

Part One The Vocabulary Bitcoin Never Gave You — Introducing the Backdoor Fork

Before presenting the evidence, the framework needs to be clear. Bitcoin has two established terms for protocol changes:

A Hard Fork changes Bitcoin's rules in a way that creates a chain split. Old nodes reject the new blocks. The community divides. Hard forks are loud, contentious, public. Visible to everyone because they have to be.

A Soft Fork tightens Bitcoin's rules in a backward-compatible way. Old nodes still accept new blocks. It requires majority miner support, signalling, coordination, public discussion. Soft forks are quieter than hard forks — but they are not silent. The community knows they are happening.

And now: the category nobody in seventeen years of Bitcoin journalism has formally named.

Defining The Backdoor Fork

A Backdoor Fork is a protocol rule change that: (1) Is deployed without public announcement or community knowledge. (2) Is hidden inside misleading commit messages designed to conceal what the code actually does. (3) Is enforced — when discovered prematurely — by instructing discoverers to maintain silence. (4) Gives the deployer unilateral control over the network's development trajectory. (5) Cannot be challenged, debated, or reversed by the community because the community does not know it is happening.

This is not a metaphor. This is a precise description of three documented events in Bitcoin's first thirteen months. All three are sitting in primary sources that anyone can verify right now. The Bitcoin Wiki's own documentation calls the commits "sneaky." The people who were there have been on the public record about the silence they were asked to maintain since at least 2015.

The Backdoor Fork happened. Three times. And nobody ever gave it a name — until now.

Part Two The Three Backdoor Forks — Primary Source Evidence

Backdoor Fork #1 — The Block 31,000 Time-Bomb (November 2009)

Bitcoin launched on January 3, 2009. By November 2009 it had been running for ten months. The community was tiny — a few dozen technically sophisticated people running nodes, testing the system, watching the blockchain grow block by block. They believed they understood what they were running.

They did not know that a protocol rule change was hardcoded inside the software, set to fire automatically when the blockchain reached block 31,000.

"The earliest known soft fork was implemented in Bitcoin 0.1.6 (released November 2009) and was hardcoded to activate at block 31,000, which occurred on 22 December 2009. This hardcoded height activation mechanism was used for at least one other early soft fork when most development was done by Satoshi Nakamoto." Source: Bitcoin Optech — bitcoinops.org/en/topics/soft-fork-activation/

On 21 December 2009, every person running a Bitcoin node was operating under one set of rules. On 22 December 2009, block 31,000 was mined, and the rules changed. Nobody voted. Nobody was consulted. Nobody was warned.

The mechanism was a time-bomb embedded in the code — a predetermined trigger that would fire at a predetermined moment, changing the behaviour of every node on the network, regardless of what any of those node operators wanted or knew. This is the prototype Backdoor Fork. The creator of Bitcoin established in the very first software release that protocol governance was a unilateral decision.

Backdoor Fork #2 — The Hidden 1MB Block Size Limit (July–September 2010)

This is the one that broke everything. Not immediately. Not obviously. Not in a way that anyone saw coming in 2010. But the block size limit introduced in two hidden commits in the summer of 2010 is the direct cause of the block size war — Bitcoin's most destructive internal conflict. The 2017 chain split that created Bitcoin Cash. The fee crisis. The Lightning Network's existence as a second-layer workaround. Fifteen years of governance paralysis. All of it traces to two commits with misleading titles deployed without announcement in the summer of 2010.

🔍 Forensic Exhibit — The Two Hidden Commits COMMIT HASH STATED MESSAGE ACTUAL CHANGE a30b56e "fix openssl linkage problems" Embedded MAX_BLOCK_SIZE variable 8c9479c "don't count payments until confirmed" Enforced 1MB block size at consensus
Commit Hash Stated Message Actual Change Bitcoin Wiki Label
a30b56e "fix openssl linkage problems" Embedded MAX_BLOCK_SIZE variable — July 15, 2010 "Sneaky" UASF commit #1
8c9479c "don't count payments until confirmed" Enforced block size at consensus level — Sept 7, 2010 "Sneaky" UASF commit #2
SNEAKY — The Bitcoin Wiki's Own Word

That is the official reference documentation's own characterisation. Not a critic's label. Not an opposition blogger's editorial. The Bitcoin Wiki designates both 1MB commits as "Sneaky soft-forking UASF commits." The Bitcoin Scalability FAQ states: "Neither the July nor the September commit message explains the reason for the limit."

The Suppression Order

"Satoshi never used IRC, and he rarely explained his motivations for anything. In this case, he kept the change secret and told people who discovered it to keep it quiet until it was over with so that controversy or attackers wouldn't cause havoc with the ongoing rule change." Source: Theymos, 2015 — cited in CoinTelegraph, 2017

He kept the change secret. He told people who discovered it to keep it quiet. The creator of a supposedly decentralised, trustless, community-governed protocol made a unilateral architectural decision that would define Bitcoin's scalability for the next fifteen years — hid it in commits whose titles described something else entirely — and personally suppressed its disclosure until after deployment.

The Origin of the 1MB Limit — Hal Finney's DoS Concern

"I'm the guy who went over the blockchain stuff in Satoshi's first cut of the bitcoin code. Satoshi didn't have a 1MB limit in it. The limit was originally Hal Finney's idea. Both Satoshi and I objected that it wouldn't scale at 1MB. Hal was concerned about a potential DoS attack though, and after discussion, Satoshi agreed. But all 3 of us agreed that 1MB had to be temporary because it would never scale." Source: Ray Dillinger (Cryddit), February 2015 — maxlaumeister.com

The creator of Bitcoin initially objected that 1MB wouldn't scale. He was persuaded by Hal Finney's denial-of-service argument. He then implemented the limit secretly, in misleading commits, with instructions to discoverers to stay quiet — and left the project before the community grew large enough to challenge it. A temporary emergency measure, deployed without announcement, became the permanent architectural constraint that tore the Bitcoin community in half seven years later.

Backdoor Fork #3 — The Alert Key: A Master Switch Nobody Voted For (August 2010)

On August 15, 2010, an unknown attacker exploited a critical vulnerability in Bitcoin's code. Block 74,638 contained a transaction that created 184,467,440,737 bitcoins — 184 billion, against a total supply cap of 21 million. For a brief, terrifying window, the foundational scarcity guarantee of Bitcoin had been broken.

The bug was fixed. But in the aftermath, something was added to the protocol that nobody had asked for and nobody had been told about: a master cryptographic key that could broadcast signed emergency messages to every node on the Bitcoin network simultaneously — and force those nodes into a restricted "safe mode."

3 People who held the Alert Key — a single cryptographic master switch capable of pushing every Bitcoin node on the planet into safe mode simultaneously — for six years, without public knowledge or community vote
Detail The Alert Key System
ImplementationAdded by Satoshi Nakamoto after the 184-billion BTC overflow bug — August 2010
Key HoldersThree named individuals: Satoshi Nakamoto, Gavin Andresen, Theymos
Active PeriodBitcoin 0.1 (2010) through Bitcoin 0.13.0 (2016) — six years
UsesTwelve emergency broadcasts, 2012–2014
ResolutionPrivate key published in 2018 to ensure it could never be used again
🔍 Forensic Observation A supposedly decentralised currency with no central authority had, built into its protocol without community knowledge, a cryptographic master switch that three individuals could use to push the entire global network into safe mode with a single signed message. One key. Three holders. Six years. Twelve uses. This is structurally identical to a central bank's emergency intervention power — the very kind of centralised override mechanism that Bitcoin was supposedly designed to make impossible.
Part Three Update: Gary Howland Eliminated

In the first Ghost in the Timechain report, Gary Howland — co-founder of Systemics with Ian Grigg, designer of the SOX capabilities-based payment protocol — was identified as the most credible candidate for Bitcoin's cryptographic co-author.

Subsequent research has definitively eliminated him.

Candidate Eliminated

Gary Howland died in his sleep on Saturday, March 23, 2002. This is confirmed by an obituary authored by Ian Grigg himself on his personal website at iang.org, and corroborated by R.A. Hettinga's December 2003 post on the mac_crypto mailing list, archived at doomedengineers.wordpress.com. Howland's death predates Bitcoin's known development window by at least five years. He cannot be a co-author of Bitcoin's code. His candidacy is formally withdrawn.

This elimination redirects the inquiry toward the next most credible candidate for the cryptographic author of Bitcoin's protocol layer. That candidate has been hiding in plain sight — named in the Bitcoin whitepaper itself, confirmed as the first person Satoshi Nakamoto ever contacted, identified in the 2026 New York Times investigation as the most likely Satoshi candidate, and documented in direct mailing list contact with Ian Grigg since 1997.

His name is Adam Back.

Part Four Adam Back as Bitcoin's Second Author — The Forensic Case

Adam Back is the inventor of Hashcash — the proof-of-work function that Bitcoin adopted as its consensus mechanism. He is the only person cited by name in the body text of the Bitcoin whitepaper. He is the first human being Satoshi Nakamoto ever contacted — before the whitepaper was even published.

"I got the first email that anybody got from Satoshi in August 2008 before the Bitcoin paper was released." Source: Adam Back — confirmed public statement

Five Back–Satoshi emails were published via UK court filing in February 2024, reported by Bitcoin Magazine. They confirm that Satoshi reached out to Back before reaching out to any other figure in the cryptography community — before Wei Dai, before Hal Finney, before Nick Szabo.

In April 2026, the New York Times investigation by Pulitzer Prize-winning journalist John Carreyrou — the most rigorous Satoshi identification attempt ever published by a mainstream outlet — named Adam Back as the most likely Satoshi candidate after analysing 134,308 posts from cypherpunk mailing lists. Back denied it. But the Times documented that when confronted with specific evidence, Back refused to provide the metadata attached to his early emails with Satoshi — twice.

Forensic Observation

A man with nothing to hide provides the metadata.

Forensic Criterion Adam Back's Profile
Proof-of-work mechanismInventor of Hashcash (1997) — the direct PoW predecessor Bitcoin adopted
Adversarial systems thinkingEntire career built on DoS prevention via computational cost
Cryptographic expertisePhD Distributed Systems, University of Exeter; decades of applied cryptography
First Satoshi contactConfirmed: August 2008, before the whitepaper was released
NYT identificationNamed by Carreyrou (April 2026) as highest-confidence Satoshi candidate
Whitepaper citationOnly person cited by name in the whitepaper body text
Mailing list → GriggDocumented 1997 cypherpunk thread — 11 years before Bitcoin launched
Windows VC++ environmentHashcash distributed with Microsoft Visual C++ project file — matches Bitcoin's build environment
2008–2011 public silenceDocumented lull in public-facing professional activity during Bitcoin's launch window
Refused email metadataDid not respond to two separate requests from NYT journalist Carreyrou
Part Five The Grigg–Back Partnership — And Why the 1MB Commit May Have Broken It

The Grigg Principle — What the Hidden Commit Violated

"This ensures that the Issuer of the security cannot change the terms of the contract in any way without offering to the user terms for exchange." Source: Ian Grigg — Financial Cryptography in 7 Layers, 2000 — iang.org/papers/fc7.html

This is the philosophical bedrock of Grigg's entire body of work. The Issuer — the creator of the instrument — cannot unilaterally change the rules. Any change requires offering holders an exchange. This is Bitcoin's immutability principle as Grigg articulated it in his own theoretical framework, fourteen years before the word "blockchain" became a mainstream term.

Now look at what actually happened in September 2010. The hidden 1MB block size limit was deployed unilaterally, secretly, without community knowledge, without any process, without offering anyone terms for exchange. This directly and comprehensively violates Grigg's own stated foundational principle.

⚠️ Interpretive claim — explicitly marked as such If Grigg is the economic architect of Bitcoin — the designer of its contract layer, its monetary philosophy, its governance model — then the hidden 1MB commit is not consistent with his design philosophy. It is consistent with the priorities of a cryptographer whose primary concern is network security and DoS prevention. Someone who, faced with transaction flooding attacks of mid-2010, made a rapid unilateral technical decision using the adversarial systems thinking that has defined his entire career. That is Back's decision-making profile. Not Grigg's.

The Probable Rupture

⚠️ Interpretive claim — explicitly marked as such If Bitcoin was built by a two-person partnership between Ian Grigg (economic architect) and Adam Back (cryptographic implementer), the September 2010 hidden 1MB commit represents the moment that partnership fractured. Grigg designed Bitcoin to serve ordinary users with fast, cheap, scalable transactions. Back deployed a unilateral block size cap — in secret, without community knowledge, without Grigg's published governance philosophy — as an adversarial security measure. Back made a decision that violated Grigg's architectural principles. And because the decision was made secretly, in misleading commits, there was no mechanism for Grigg to challenge it publicly without revealing who he was. The very operational security that had protected the project now made it impossible for one co-author to publicly object to the other's decision.
"Bitcoin is lost." Source: Ian Grigg (@iang_fc) — X post, March 4, 2025, reply to Cameron Winklevoss on US Strategic Bitcoin Reserve

That is not an investor's lament. That is not a developer's frustration. That is an architect watching his building get renovated into something he never intended, by forces he cannot publicly challenge without revealing who he is. Two words. Fifteen years of accumulated grief.

Bitcoin is lost.

Part Six The Block Size War Reframed — A Dispute Between Co-Authors

For fifteen years, Bitcoin's most destructive internal conflict has been described as a genuine technical debate between smart people with different visions for the network. Big blockers versus small blockers. On-chain scaling versus second-layer solutions. That framing is not wrong. But it is incomplete.

The block size war is also the story of what happens when a hidden decision — made unilaterally, secretly, without community knowledge — eventually comes into contact with a network that has outgrown it.

Satoshi himself indicated on the public record in 2010 that the 1MB limit was temporary. Gavin Andresen stated in 2014: "The plan from the beginning was to support huge blocks. The 1MB hard limit was always a temporary denial-of-service prevention measure." Ray Dillinger confirmed this. Every person who was in the room when the limit was introduced has said, on the public record, that it was never meant to be permanent.

And yet, when the time came to change it, the small-block position held. Lightning Network was built instead. Bitcoin Cash split off. The 1MB limit remained.

Who was the most prominent, most technically credible, most institutionally powerful voice for keeping blocks small? Adam Back — CEO of Blockstream, the company that employs much of Bitcoin Core's development team and whose entire product suite depends architecturally on Bitcoin's base layer remaining constrained.

⚠️ Forensic implication — explicitly marked as interpretive If Adam Back is one of Bitcoin's co-authors — the person whose security instincts drove the unilateral decision to impose the 1MB limit in the first place — then his decade of advocacy for keeping blocks small is not merely a governance position. It is a defence of his own unilateral decision. The Backdoor Fork he deployed in September 2010 became the Blockstream business model in 2014. The temporary emergency measure became a permanent revenue architecture.
"The block size war was not a community disagreement. It was the economic architect and the cryptographic implementer — separated by fifteen years of pseudonymous distance, unable to acknowledge each other in public — fighting about a decision that was made in private, in secret, in September 2010."

— Forensic interpretation, Ghost in the Timechain Part II
Part Seven The Documented Connections — Mailing List Evidence

For a two-author model to hold, Grigg and Back must have known each other well enough, and for long enough, to co-build one of the most consequential pieces of software in financial history. The cypherpunk mailing list archive provides the primary source evidence. All of the following is verifiable at mailing-list-archive.cryptoanarchy.wiki.

Grigg ↔ Back — November 1997

DateAuthorThread
1997-11-04 Adam Back [University of Exeter] Re: Copyright commerce and the street musician protocol
1997-11-06 Ian Grigg [Systemics Ltd] Re: Copyright commerce and the street musician protocol

Both posted. Same thread. Same conversation. Documented. Timestamped. Eleven years before Bitcoin's whitepaper was published.

Grigg ↔ Wei Dai — December 1998

DateAuthorThread
1998-12-11 Ian Grigg Re: alternative b-money creation
1998-12-22 Ian Grigg Re: alternative b-money creation (second post)

Wei Dai's b-money = Reference [6] in the Bitcoin whitepaper. Ian Grigg was directly discussing b-money with its creator in December 1998 — a decade before Bitcoin launched. The cypherpunk archive proves Ian Grigg knew everyone Satoshi cited — personally, by email, in active conversation.

The Alert Key — Where Both Authors' Domains Converge

The Alert Key sits at the intersection of both proposed authors' domains and is forensically revealing about the collaboration structure. In Grigg's Ricardo system, the Issuer holds emergency authority over the system — an explicit feature of his governance design. The Alert Key is Bitcoin's implementation of exactly this principle.

But implementing the key correctly — the asymmetric cryptography, ensuring it cannot be forged, ensuring it propagates correctly to every node — requires sophisticated cryptographic engineering. This is Back's domain, not Grigg's.

⚠️ Interpretive synthesis — explicitly marked Grigg designs the governance principle. Back builds the key. Together, they held it. Together, they built the mechanism that gave Bitcoin's creators continued extraordinary power over a network publicly presented as having no centre.
Part Eight The Governance Question Bitcoin Has Never Asked Itself

Bitcoin asks everyone who touches it to trust the code, not the human. The code is the law. The rules are the rules. No individual can override them.

The Backdoor Fork is the primary source evidence that this principle was not applied to Bitcoin's own creation. The rules were changed secretly, three times, in the first thirteen months. The community was not consulted. Discoverers were told to stay quiet. An emergency override key was built in without announcement and held for six years by three named individuals.

Bitcoin became decentralised eventually. It was not born that way.

The question that follows is the one Bitcoin has never seriously asked itself: if the 1MB limit was imposed through a Backdoor Fork — unilaterally, secretly, in apparent violation of the governance philosophy that Bitcoin publicly espouses — does the community have a legitimate claim to revisit it through the open, transparent, community-driven process that should have governed its introduction in the first place?

That is not a technical question. It is a governance question. And it has never been asked in the right frame — because until now, nobody had a name for what happened in September 2010.

It was a Backdoor Fork. And it changed everything.

Current Working Theory — Updated May 2026

Bitcoin was created by a team of 2+ authors 8.5 / 10
Ian Grigg was the economic architect of Bitcoin 8.0 / 10
Gary Howland — Bitcoin's cryptographic co-author ✗ ELIMINATED — Died March 23, 2002
Adam Back — most credible second author candidate 7.5 / 10 ▲ NEW
1MB hidden commit reflects Back's instincts, not Grigg's 7.0 / 10 ▲ NEW
Grigg–Back partnership fractured over the 1MB Backdoor Fork 6.5 / 10 ▲ NEW

Read the Full Investigation — Part II

The complete 16-page forensic research paper — including all primary source documentation, commit hash analysis, the full Backdoor Fork framework, the Alert Key governance analysis, and the Grigg–Back partnership rupture theory — is available below.

THE BACKDOOR FORK — Full Research Paper | Ghost in the Timechain Part II
Download PDF

Your browser doesn't support inline PDF viewing.

Click here to open the full research paper ↗

Read Part I of this series The Ghost in the Timechain — Who Really Built Bitcoin? The original forensic investigation identifying Ian Grigg and the two-author theory. Corroborated by Sergio Lerner within hours of publication.

 All forensic findings are anchored to primary sources. Every interpretive claim is explicitly marked as such. Every code exhibit is from a publicly verifiable primary source. The distinction between verified evidence and reasoned interpretation is the line between forensic journalism and conspiracy theory. This investigation does not cross it.

Niraj Sinha is the Founder of Unified Crypto Payments Identity (UCPI), a graduate of the Oxford Blockchain Strategy Programme at Saïd Business School, a former Sarbanes-Oxley Auditor at Reuters, and a working blockchain developer with hands-on experience on Bitcoin Core's wallet encryption layer — including the CKey and CMasterKey classes that define how Bitcoin's private keys are stored and protected.