关键人物

中本聪是谁?比特币匿名创造者的证据梳理

公开记录中真正能确认的中本聪信息:2008 年白皮书、2009 年 1 月的网络启动、2011 年 4 月的消失、约 110 万枚从未移动的比特币,以及为何至今没有任何身份主张被证实。

中本聪(Satoshi Nakamoto)是 2008 年 10 月 31 日发表比特币白皮书、2009 年 1 月 9 日发布第一版比特币软件、并于 2011 年 4 月停止通信的个人或团体所使用的化名。这个名字背后的真实身份从未被确认,也从未有任何候选人用中本聪已知的密钥签署过消息。

1. 中本聪是谁?公开记录里有什么

  • 背景与经历: 关于中本聪,一切可核实的信息都来自约 32 个月里留下的一串数字痕迹。bitcoin.org 域名于 2008 年 8 月 18 日通过一家保护匿名的注册商注册。两天后的 8 月 20 日,中本聪写邮件给英国密码学家 Adam Back,询问 Hashcash 的引用格式;8 月 22 日,在 Back 的提示下,他又写信给戴维(Wei Dai),询问 b-money 的发表年份。2008 年 10 月 31 日,白皮书《Bitcoin: A Peer-to-Peer Electronic Cash System》被发布到 metzdowd.com 的密码学邮件列表。此后留下的全部材料包括:这篇论文、源代码、bitcointalk.org 论坛上约 500 条帖子,以及一批后来由收件人公开的私人邮件。P2P Foundation 网站上的个人资料填写的出生日期是 1975 年 4 月 5 日、所在地为日本,但没有任何其他证据支持这两项。其文字使用英式拼写与习语("colour"、"bloody hard"),代码是熟练且防御性很强的 C++,出自一个精通密码学、网络与经济学,却不熟悉当时若干开源惯例的人之手。

2. 主要贡献:中本聪究竟造了什么

  • 主要贡献:
    • 白皮书(2008 年 10 月 31 日): 九页纸描述了一套不需要可信第三方的支付系统。其八条参考文献包括戴维的 b-money、Adam Back 的 Hashcash、Ralph Merkle 1980 年的协议论文,以及 Stuart Haber 与 Scott Stornetta 关于密码学时间戳的三篇论文。
    • 双花问题的解法: 更早的数字现金系统靠中心服务器防止双重支付。中本聪用工作量证明加最长链规则取代了这台服务器,使改写历史必须重做全部工作量。这是真正新颖的部分:不是哈希链,不是数字签名,而是让匿名参与者之间对交易顺序的共识变成自我强制执行的经济机制。
    • Bitcoin v0.1 与创世区块: 中本聪于 2009 年 1 月 3 日 18:15:05 UTC 挖出区块 0,并在其中嵌入当天伦敦《泰晤士报》关于银行救助的头条,随后在 1 月 9 日发布客户端。
    • 发行计划: 总量固定 2100 万枚,区块奖励每 210,000 个区块减半。这些参数至今从未改动。
    • 第一笔交易: 2009 年 1 月 12 日,中本聪在区块 170 中向 Hal Finney 发送 10 BTC,这是第一笔点对点比特币支付。
    • 退出本身: 2010 年 12 月,中本聪把源代码控制权交给 Gavin Andresen;2011 年 4 月 26 日又移交了网络警报密钥。把创始人从系统中移除,实际上是一项与任何一行代码同等重要的设计决定。

3. 中本聪在区块链历史中的位置

  • 影响力评估: 中本聪的角色更适合被理解为"组装"而非纯粹"发明"。哈希链接的时间戳 1991 年就有了,工作量证明 1997 年就有了,数字签名 1976 年就有了,不可追踪的数字现金 1982 年就有了。当时不存在的,是让它们在没有管理员的情况下协同运转的方法。2008 年的白皮书解决了这个协调问题,而网络上线的时间比邮件列表上大多数读者预期它能跑起来还要早一个月。此后的每一条链,从以太坊到随后成千上万的代币,其基本假设都继承自这套设计。

  • 重要观点: 2009 年 2 月 11 日,中本聪在 P2P Foundation 论坛上用政治而非技术的语言描述这个项目:"传统货币的根本问题在于让它运转所需要的全部信任。中央银行必须被信任不去让货币贬值,但法定货币的历史充满了对这种信任的辜负。"白皮书本身的表述则更收敛也更精确:一套"基于密码学证明而非信任"的电子支付系统。


4. 身份问题:候选人与证据现状

  • 争议与批评:
    • 举证标准: 中本聪的早期币停在已知地址上,PGP 密钥与论坛账号也都有记录。用其中任何一把密钥签一条消息,几秒钟就能定案。至今没有任何候选人做到这一点,这就是为什么所有身份认定都停留在旁证层面。
    • Nick Szabo: 因 Bit Gold 与比特币结构相似、且文体分析发现相似之处而被反复提及。他一直否认。
    • Hal Finney: 运行了除中本聪之外的第一个节点并收到第一笔交易,而且巧合地与一位法定姓名为 Dorian Satoshi Nakamoto 的人住在同一个小镇。Finney 生前明确否认,且他与中本聪之间的往来邮件是存在的。
    • Dorian Nakamoto: 2014 年 3 月 6 日被《新闻周刊》点名,理由是他的本名与工程背景。他否认任何关联,次日沉寂已久的 P2P Foundation 账号发帖称"我不是 Dorian Nakamoto"。
    • Craig Wright: 唯一公开宣称自己是中本聪并诉诸法庭的人。2024 年 3 月 14 日,在 COPA 诉 Wright 案庭审结束时,英格兰及威尔士高等法院的 Mellor 法官当庭宣布:Wright 不是白皮书作者,不是 2008 至 2011 年间使用该化名的人,也没有创造比特币系统。2024 年 5 月 20 日公布的完整判决书认定 Wright "大规模"伪造文件。2024 年 12 月,他因违反随之而来的禁令被判藐视法庭,处 12 个月监禁、缓刑两年。
    • Peter Todd 与 Adam Back: HBO 纪录片《Money Electric》(2024 年 10 月)指向开发者 Peter Todd,本人予以否认。2026 年 4 月 8 日,《纽约时报》刊出记者 John Carreyrou 历时一年的调查,对密码朋克邮件列表的 134,308 条帖子做文体分析,认定 Adam Back 是与中本聪语言特征最接近的人。Back 在文章内外反复否认,理由是他在这些主题上的发帖量异常之高,任何此类分析都会因此产生偏差。与此前每一次一样,这次认定同样没有密码学证据支撑。
    • 从未动过的币: 由 Sergio Demian Lerner 最早发表的早期挖矿模式分析,把约 110 万枚 BTC 归于一个被推定为中本聪的早期矿工。这些币从未移动。它们的沉寂,是目前最有力的旁证:掌握密钥的人要么已经去世,要么丢失了密钥,要么选择了永久的克制。

5. 时间线与现状

  • 2008 年 8 月 18 日: bitcoin.org 域名注册。

  • 2008 年 8 月 20-22 日: 已知最早的邮件,发给 Adam Back 与戴维。

  • 2008 年 10 月 31 日: 白皮书发布到密码学邮件列表。

  • 2009 年 1 月 3 日: 创世区块被挖出。

  • 2009 年 1 月 9 日: Bitcoin v0.1 发布。

  • 2009 年 1 月 12 日: 第一笔人对人交易,向 Hal Finney 转账 10 BTC。

  • 2010 年 12 月 12 日: 最后一条公开论坛帖子。

  • 2010 年 12 月: 开发权移交给 Gavin Andresen。

  • 2011 年 4 月 23 日与 26 日: 已知最后的邮件,收件人为 Mike Hearn 与 Gavin Andresen("我已经转向别的事情了")。

  • 2024 年 3 月: 英国高等法院裁定 Craig Wright 不是中本聪。

  • 2026 年 4 月: 《纽约时报》调查点名 Adam Back,本人否认。

  • 现状与未来: 中本聪已沉默逾十五年,相关地址上的币始终未动。身份问题如今更像是新闻与取证层面的课题,而非技术问题:比特币的运行并不依赖答案,协议在没有作者任何参与的情况下已完成多轮升级。唯一能改变局面的事件——一条签名消息,或早期币的一次转移——尚未发生。

常见问题

Who is Satoshi Nakamoto?

Satoshi Nakamoto is the pseudonym used by the person or group who published the Bitcoin white paper on October 31, 2008, released the first Bitcoin software on January 9, 2009, and maintained the project until late 2010. The name is attached to about 500 forum posts, the original source code, and a set of private emails. No verified information about the person behind it exists, and the identity has never been established.

Has Satoshi Nakamoto ever been identified?

No. Several candidates have been proposed, including Nick Szabo, Hal Finney, Dorian Nakamoto, Peter Todd, and Adam Back, and all have denied it. Every identification so far has rested on circumstantial evidence such as writing style or technical background. Satoshi's PGP key and early Bitcoin addresses are public, so a signed message would settle the question immediately. No candidate has ever produced one.

How much Bitcoin does Satoshi Nakamoto own?

Analysis of early mining patterns, first published by Sergio Demian Lerner and known as the Patoshi pattern, attributes roughly 1.1 million BTC to a single miner presumed to be Satoshi. None of those coins have ever been spent. The 50 BTC reward from the genesis block is separately unspendable, because its output was never added to the transaction database that nodes check against.

When did Satoshi Nakamoto disappear?

Satoshi's last public forum post was on December 12, 2010, and the handover of source control to Gavin Andresen followed that month. The final known private emails were sent on April 23, 2011 to Mike Hearn and April 26, 2011 to Gavin Andresen, the second of which transferred the network alert key and said: "I've moved on to other things and will probably be unavailable." There has been no verified communication since.

Is Craig Wright Satoshi Nakamoto?

No, according to the High Court of England and Wales. On March 14, 2024, at the end of the COPA v Wright trial, Mr Justice Mellor declared that Wright is not the author of the white paper, did not operate under the pseudonym between 2008 and 2011, and did not create the Bitcoin system. The written judgment of May 20, 2024 found that Wright had forged documents on a grand scale. He was later found in contempt of the resulting injunction.

Is Adam Back Satoshi Nakamoto?

Adam Back says he is not. On April 8, 2026, The New York Times published an investigation by John Carreyrou that analyzed 134,308 cypherpunk mailing-list posts and identified Back as the closest stylometric match to Satoshi's writing. Back denied it in the article and afterwards, arguing that his unusually high posting volume on these exact topics biases any similarity analysis. No cryptographic proof accompanied the identification.

参考资料