Research/Bitcoin

Bitcoin's Security Budget Problem: Can Fees Alone Protect a Trillion-Dollar Network?

Analyzing whether Bitcoin's transaction fees can sustain network security as block subsidies approach zero over the next two decades.

bcMaoSep 10, 2026

Bitcoin's security budget is the total revenue paid to miners for validating transactions and producing blocks. Today, that budget sits at roughly $13 billion per year, funded almost entirely by the block subsidy: the 3.125 BTC created with every new block. Transaction fees contribute less than 1%. The subsidy halves every 210,000 blocks, and by 2036 it will be just 0.390625 BTC. The question that has divided Bitcoin researchers for over a decade is whether transaction fees alone can replace that subsidy and secure a network now valued above $1.5 trillion.

This is not a distant theoretical problem. The next three halvings (2028, 2032, 2036) will reduce new issuance to a rounding error. If fees do not scale to fill the gap, the economic incentives that keep miners honest begin to erode, opening the door to 51% attacks, selfish mining, and block reorganizations.

How the Security Budget Works

Bitcoin's proof-of-work consensus requires miners to expend real-world resources (electricity, hardware) to produce valid blocks. The block reward compensates them for this expenditure and consists of two components: the block subsidy (newly minted bitcoin) and transaction fees paid by users.

The subsidy is deterministic: it started at 50 BTC in 2009, halved to 25 in 2012, then to 12.5, 6.25, and now 3.125 BTC after the April 2024 halving. Transaction fees are market-driven, fluctuating with demand for block space. The total security budget determines how much it would cost an attacker to overpower the network. The higher the budget, the more expensive the attack.

Why this matters: A 51% attack on Bitcoin would currently cost an estimated $6 billion when accounting for hardware, data center infrastructure, and electricity for one week of sustained blockchain domination. That figure is directly proportional to miner revenue. Cut the revenue in half, and you cut the cost of attack in half.

The Halving Countdown

Bitcoin's emission schedule is one of its most celebrated properties: a fixed, predictable monetary policy that converges on 21 million coins. But that same schedule creates an accelerating pressure on the security budget. Each halving cuts miner revenue from the subsidy by 50%, and the compounding effect is dramatic.

HalvingExpected DateBlock SubsidyDaily Issuance (BTC)Annual Subsidy at $79KCumulative Supply Mined
4th (current)April 20243.125 BTC450~$13.0B~96.9%
5th~April 20281.5625 BTC225~$6.5B~98.4%
6th~20320.78125 BTC112.5~$3.2B~99.2%
7th~20360.390625 BTC56.25~$1.6B~99.6%

These projections assume a constant BTC price of $79,000. Obviously, price appreciation could offset the subsidy decline: if Bitcoin reaches $158,000 by 2028, the dollar-denominated subsidy stays roughly flat through the next halving. But relying on perpetual price appreciation is not a security model. For a deeper analysis of mining economics under these conditions, see our Bitcoin mining economics breakdown.

Historical Fee Revenue: Spikes Without a Floor

The case for a fee-funded security budget requires that transaction fees grow large enough and remain consistent enough to replace the subsidy. Historical data paints a mixed picture. Fees have produced extraordinary spikes during periods of high demand but consistently revert to a low baseline.

Fee Revenue as a Percentage of Total Block Reward

PeriodEventFee Share of Miner RevenueAverage Fee per Transaction
2019-2022Normal baseline1-3%$0.50-$3.00
December 22, 2017ICO mania peak78%>$50
May 8, 2023BRC-20 / Ordinals surge>50% (some blocks)~$19.20
April 20, 2024Runes launch + halving>75%~$128
December 29, 2025Quiet market0.52%~$0.80
September 7, 2026Current baseline0.43%~$0.57

The pattern is clear: fees spike during speculative events and collapse afterward. In late 2025, Bitcoin miners earned under 0.7% of their revenue from fees, a new 10-year low. As of September 2026, the fee rate for next-block confirmation sits at roughly 2 sat/vB, and daily fee revenue has fallen to approximately $300,000: a 12-month low. For context on these dynamics, see our analysis of Bitcoin's fee market mechanics.

The Ordinals and Runes Experiment

The emergence of Ordinals in early 2023 and Runes at the April 2024 halving briefly reignited optimism about fee-driven security. Ordinals inscriptions have generated over 6,900 BTC in cumulative fees (approximately $450 million) since January 2023. On the day Runes launched at block 840,000, total miner revenue exceeded $107 million, with over 75% coming from fees. A single block collected 37.67 BTC in fees alone.

But the sustainability question answered itself quickly. Runes' share of network fees declined from over 90% at launch to under 2% by mid-2025. Ordinals inscription activity, measured by total fees generated, accounted for roughly 21% of transaction fees in 2023 but has since normalized. These were demand shocks, not structural shifts in the fee market.

The fee floor problem: Bitcoin's fee market has demonstrated it can produce $80 million days. It has not demonstrated it can sustain $30 million days. The security budget depends on the floor, not the ceiling.

Modeling a Fee-Only Future

To understand what a fee-funded security budget requires, consider the arithmetic. At current throughput of roughly 5 transactions per second (about 300,000 transactions per day), replacing the 3.125 BTC subsidy would require an average fee of approximately $82 per transaction. That is 140 times higher than today's average fee of $0.57.

What Would Need to Change

There are three variables that could close the gap: higher fees per transaction, more transactions per block, or a higher BTC price that makes the same satoshi-denominated fees worth more in purchasing power.

  • If Bitcoin reaches $500,000 per coin, the current fee rate of 2 sat/vB translates to roughly $3.60 per transaction: still far short of what is needed to replace the subsidy
  • If average fees rise to 50 sat/vB (roughly $5 at current prices), daily fee revenue reaches about $1.5 million: still only 4% of the current subsidy
  • If block size increased 10x (a contentious proposition), throughput would rise to ~50 tx/s, but the required average fee would still be ~$8.20 per transaction

The optimistic case, articulated by Dan Held and others, argues that security should be measured as a percentage of Bitcoin's total value rather than in absolute terms. If Bitcoin's market cap grows to $10 trillion, even a 0.1% security budget would be $10 billion annually. This framing assumes that the cost of attacking Bitcoin scales with its value, not with the absolute hashrate.

Security Budget as Percentage of Market Cap

Currently, Bitcoin's annual security spend sits at roughly 0.82% of its market cap. After the 2028 halving (at similar prices), that drops to approximately 0.45%. By 2036, it could fall below 0.15%. Whether that percentage is “enough” depends on assumptions about attacker capabilities and motivations.

The pessimistic case, argued by researchers like Hasu, points out that mining requires large upfront capital investment (ASICs with 2-3 year lifespans), meaning miners are effectively betting on future revenue. As the subsidy shrinks, the predictable component of that revenue disappears, replaced by volatile fee income. This increases mining risk and could reduce hashrate investment over time.

The Tail Emission Debate

In July 2026, Peter Todd presented “Tail Emissions and Demurrage” at the Bitcoin++ conference in Toronto, reigniting one of Bitcoin's most contentious debates. Todd cited data showing that on April 8, 2026, miners collected just 2.443 BTC in daily transaction fees versus 450 BTC in daily subsidy: fees represented only 0.54% of total miner revenue. His proposal: a fixed block reward that continues indefinitely after the subsidy schedule ends.

Todd's argument rests on two pillars. First, that fee income is “highly uneven,” creating perverse incentives for large mining pools to reorganize recent blocks containing unusually high fees. Second, that a natural “leaky bucket” effect (estimated at ~0.1% of supply lost annually through inaccessible keys, damaged hardware, and failed inheritance) means a small tail emission would not meaningfully alter Bitcoin's scarcity profile.

The Opposition

The response was swift and largely negative. Adam Back, CEO of Blockstream, called the proposal a “dangerous trap” and a “false narrative,” drawing parallels to BIP-110, a 2026 soft fork proposal that failed to gain miner support. Giacomo Zucco distinguished between tail emission as a concept and “arbitrarily changing established economic fundamentals,” calling the latter “existential.” The broader community consensus holds that the 21 million cap is non-negotiable and forms the foundation of Bitcoin's value proposition as scarce digital money.

The political reality is that changing Bitcoin's monetary policy would require a hard fork with overwhelming consensus. Given the contentious nature of even minor protocol changes (recall the block size wars of 2015-2017), a modification to the supply cap would face near-insurmountable social resistance.

Lessons from Other Proof-of-Work Chains

No major proof-of-work chain has successfully completed a transition to fee-only security. Bitcoin is the first to attempt it at scale. But two chains offer relevant data points on the tail emission alternative.

ChainEmission ModelAnnual Inflation (2026)Security Outcome
MoneroFixed 0.6 XMR/block indefinitely (since June 2022)~0.86%Stable hashrate; security budget predictable
GrinConstant 60 GRIN/block forever, no cap~8% (declining naturally)Minimal adoption limits conclusions
LitecoinSame halving model as Bitcoin1.80% (next halving July 2027)Even lower fee revenue than Bitcoin relative to subsidy
BitcoinHalving to zero, fee-only by ~2140~1.7%Unknown: no precedent at this scale

Monero's transition to tail emission in June 2022 provides the closest real-world test. Its fixed reward of 0.6 XMR per block generates roughly 158,000 XMR per year, with inflation declining asymptotically toward 0.3-0.4% by 2100. The result has been a stable and predictable security budget, though Monero's significantly smaller market cap ($3-4 billion versus Bitcoin's $1.5 trillion) limits direct comparison.

Alternative Proposals Beyond Tail Emission

The security budget debate has produced several proposals beyond the binary of “fees will be enough” versus “add tail emission.” Each involves its own set of tradeoffs.

Drivechains (BIP-300/BIP-301)

Paul Sztorc's drivechain proposal would allow merge-mined sidechains to pay fees to Bitcoin miners. The theory: sidechains could host high-throughput applications (DeFi, tokens, smart contracts) and funnel a portion of their fee revenue to L1 miners. Critics argue this introduces new trust assumptions and could centralize mining around sidechain MEV extraction.

Fee Market Optimization

Improvements to Bitcoin's fee market could increase revenue without protocol-level changes. Proposals include better fee estimation algorithms, replace-by-fee improvements, and cluster mempool (now being implemented in Bitcoin Core), which optimizes block template construction to maximize fee revenue from available transactions. Transaction block space demand also plays a role: as more use cases compete for limited block space, the fee floor should rise naturally.

On-Chain Scaling

Increasing Bitcoin's throughput from ~5 to ~50 or ~500 transactions per second would proportionally increase total fee revenue at any given per-transaction fee level. However, the block size wars of 2015-2017 effectively settled this debate for the foreseeable future: the Bitcoin community prioritized decentralization (keeping node requirements low) over on-chain throughput. Any significant block size increase would face the same political resistance as tail emission.

The Layer 2 Paradox

Layer 2 scaling solutions present an interesting tension for the security budget. By moving transactions off-chain, L2s reduce demand for block space, which reduces fee revenue. As one analysis put it: “Every transaction successfully moved off-chain is a subtraction from the fee base that was supposed to replace the subsidy.”

But the relationship is more nuanced than a simple subtraction. L2 protocols still generate on-chain transactions at critical lifecycle points. The Lightning Network requires on-chain transactions for channel opens, closes, and splice operations. Spark, built on statechains, requires on-chain transactions for deposits into and withdrawals from the protocol. Cooperative closures, UTXO consolidation, and anchor transactions all contribute to L1 fee revenue.

How L2 Activity Creates On-Chain Demand

The argument for L2s as security budget contributors works through indirect demand amplification. A single on-chain transaction that funds a Spark deposit may facilitate thousands of off-chain transfers before resulting in an on-chain withdrawal. Each of those off-chain transfers represents economic activity that would not have occurred on-chain at current fee levels: the user would simply not have transacted if each payment cost $5-$50 in on-chain fees.

More importantly, L2s create new categories of Bitcoin users who eventually need on-chain settlement. A user who begins with a Spark wallet through a service like General Bread may later consolidate funds on-chain, open Lightning channels, or move to cold storage: each generating on-chain fee revenue. The net effect depends on whether L2 adoption grows the total pie of Bitcoin users faster than it shrinks per-user on-chain transaction volume.

The economic density argument: L2 protocols compress more economic value into fewer on-chain transactions. A channel close that settles thousands of payments is worth more to a miner than a single payment, because users who depend on timely settlement will pay higher fees for confirmation priority. This is economic density: fewer transactions, but each one carrying more urgency and willingness to pay.

Fee Variance and Miner Incentives

Even if average fees rise to sufficient levels, the variance of fee income creates its own security risks. When some blocks contain significantly more fees than others, large miners face an incentive to fork the chain and steal high-fee blocks: a form of selfish mining that becomes more attractive as the predictable subsidy shrinks.

Consider the Runes launch block (840,000), which collected 37.67 BTC in fees. At a time when the subsidy was 3.125 BTC, a miner with 30% of the hashrate faced a meaningful incentive to re-mine that block. In a fee-only future, every block with anomalously high fees presents this temptation. Research by Carlsten et al. (2016) formalized this as the “instability of Bitcoin without the block reward,” showing that rational miners in a fee-only regime would deviate from honest mining strategies.

Potential mitigations include smoothing fee revenue across blocks (distributing high-fee transactions more evenly), implementing EIP-1559-style fee burning (which Bitcoin does not currently have), or accepting that some degree of miner MEV is the cost of a fee-funded security model. For a broader look at mining centralization risks that compound this problem, see our analysis of pool-level concentration.

Both Sides of the Debate

Informed opinions on the security budget span a wide spectrum. Understanding both sides is essential for evaluating the risk.

The Optimistic Case

  • Bitcoin's price has historically appreciated faster than the subsidy declines, keeping the dollar-denominated security budget stable or growing through each halving cycle
  • New demand drivers for block space (Ordinals, tokens, data anchoring, timestamps) are emerging and may create sustained fee pressure over time
  • The security budget only needs to be large enough to deter the most capable realistic attacker, not infinitely large
  • L2 growth expands Bitcoin's user base, creating more entities with a vested interest in on-chain settlement
  • The difficulty adjustment ensures hashrate gravitates to equilibrium: if some miners leave due to lower revenue, remaining miners become more profitable, stabilizing the network

The Pessimistic Case

  • Fees have never sustained more than 3% of miner revenue outside of speculative bubbles, and the current 0.43% is trending in the wrong direction
  • There is no evidence of a structural fee floor: every spike has reverted to near-zero within weeks or months
  • L2 protocols actively reduce on-chain transaction demand, working against fee growth
  • Fee variance creates selfish mining incentives that worsen as the subsidy shrinks
  • Nation-state attackers may not need economic rationality: the $6 billion cost of a sustained attack is modest relative to major intelligence budgets
  • No other proof-of-work chain has attempted this transition at scale, so there is no precedent to draw confidence from

What Developers and Users Should Watch

The security budget transition will play out over the next two decades. Several metrics and milestones will signal whether fees are scaling to meet the challenge.

Key Metrics to Monitor

  • Fee-to-subsidy ratio: track this on Bitbo or btcsecuritybudget.com: a sustained rise above 10% before 2028 would be a positive signal
  • Minimum daily fee revenue: the floor matters more than the ceiling; track 30-day rolling minimums on mempool.space
  • Hashrate response to halvings: does hashrate recover to pre-halving levels within 6-12 months?
  • Block space demand diversity: is fee revenue driven by one use case (e.g., Ordinals) or distributed across many?
  • L2 on-chain footprint: are L2 deposit and settlement transactions becoming a meaningful share of on-chain volume?

Critical Milestones

The 2028 halving will be the most important data point yet. When the subsidy drops to 1.5625 BTC, miners will need fees to contribute a much larger share of revenue to maintain current dollar-denominated security spending (absent a price increase). If fees remain at 0.5% of revenue post-2028, the conversation shifts from theoretical to urgent.

By the 2032 halving, over 99% of all bitcoin will have been mined. At that point, the subsidy provides only 112.5 BTC per day: roughly $8.9 million at current prices. The entire annual security budget from the subsidy alone would be $3.2 billion, securing a network that may be worth many multiples of today's $1.5 trillion.

Building for a Fee-Driven Future

Regardless of where one falls on the optimism spectrum, the direction is clear: Bitcoin must develop a robust fee market. L2 protocols contribute to this by making Bitcoin useful for a broader range of transactions, even if individual L2 transfers happen off-chain. The key is expanding Bitcoin's economic footprint so that on-chain settlement remains in high demand.

Developers building on Bitcoin L2s can explore the Spark SDK documentation to understand how statechain-based transfers interact with on-chain settlement. For a hands-on look at how fees are estimated and optimized, see our guide to fee bumping with RBF and CPFP and the Bitcoin fee calculator.

Conclusion

Bitcoin's security budget problem is real, measurable, and approaching. The block subsidy has funded network security for 17 years, but it is designed to disappear. Transaction fees, currently providing less than 1% of miner revenue, must eventually carry the entire load. Whether that transition happens smoothly depends on the growth of on-chain demand, the evolution of L2 settlement patterns, and Bitcoin's continued price appreciation.

The tail emission debate will likely resurface after each halving as the pressure intensifies. But for now, the Bitcoin community's path is to grow the fee market: through new use cases for block space, through protocol improvements like cluster mempool, and through L2 ecosystems that expand Bitcoin's economic reach while preserving on-chain settlement demand.

The next three halvings will determine whether Satoshi's original design assumption holds: that “in a few decades, when the reward gets too small, the transaction fee will become the main compensation for nodes.” The clock is ticking, and the data so far is inconclusive.

This article is for educational purposes only. It does not constitute financial or investment advice. Bitcoin and Layer 2 protocols involve technical and financial risk. Always do your own research and understand the tradeoffs before using any protocol.