Bitcoin’s Real Supply Cap: Why It Isn’t Exactly 21 Million

Bitcoin’s issuance schedule tops out at 20,999,999.9769 bitcoin, and the number that ends up in circulation will be lower again. Everybody rounds to 21 million, including us. It’s worth knowing what gets rounded away, because the direction of the error is the interesting part.
Short Answer

The maximum is 20,999,999.9769 bitcoin, not 21 million, and the real total will land near 20,999,817 once coins that were destroyed or never claimed are accounted for. The subsidy paid to miners is calculated in whole satoshis and halves by integer division, so fractions get discarded and are never created. Rounding to 21 million is a convenience that everyone uses, and it rounds the wrong way, crediting Bitcoin with slightly more coins than can ever exist.

Bitcoin's real supply cap: 20,999,999.9769 bitcoin, and why everyone rounds it to 21 million

Where the round number came from

On 8 January 2009, announcing the first release of the software to a cryptography mailing list, Satoshi Nakamoto wrote that total circulation would be 21,000,000 coins, and set out the schedule that would get there. The round number was the stated design target from the very first day, and it has been repeated in every article, book, and conference talk since.

The code that shipped delivers something slightly different, and the reason is ordinary computer arithmetic rather than anything clever.

Bitcoin doesn’t count in bitcoin. It counts in satoshis, the smallest unit, of which there are a hundred million to the coin, and it stores them as whole numbers. The reward paid to a miner started at 50 bitcoin per block and halves every 210,000 blocks. That halving is done with a binary shift, which divides by two and discards any remainder instead of rounding it.

For the first nine halvings the arithmetic is exact. From the tenth onward it stops dividing evenly, and each time a fraction of a satoshi gets discarded it is not paid to anyone. It simply never comes into existence. Carry that through to the end of the schedule, where the subsidy falls to zero satoshis at block 6,930,000 sometime around 2140, and the total issued comes to 20,999,999.9769 bitcoin.

That figure isn’t an outside calculation. Bitcoin Core’s own test suite adds up every subsidy the schedule will ever pay and asserts the answer, in satoshis, as 2,099,999,997,690,000. The project checks its own supply cap on every build, and the number it checks against is not 21 million.

20,999,999.9769
Bitcoin the issuance schedule can ever pay out, asserted by Bitcoin Core’s own test suite as 2,099,999,997,690,000 satoshis.
Bitcoin Core, subsidy_limit_test
0.0231
Bitcoin never created, discarded by integer division. About 1.1 parts per billion of the rounded figure.
Difference from 21,000,000
182.679
Bitcoin provably destroyed or never claimed, reconciled against the live coin set at block 629,038 in May 2020.
Fabian Jahr, Bitcoin Core contributor
~20,999,817
The total once those losses are subtracted. Every correction to the round number points the same way, downward.
Schedule maximum less known losses

The part where we concede it doesn’t matter

Scale
The whole gap is a third of a block reward
0.0231 bitcoin is 2,310,000 satoshis. A single block in 2026 pays its miner 3.125 bitcoin, so the entire truncation shortfall is well under one percent of one block’s reward.

Before going further, the size of this thing. The missing 0.0231 bitcoin is about 1.1 parts per billion of the quoted total. It changes no valuation, no scarcity argument, and no decision anyone will ever make. If you have used 21 million in conversation, you were not misleading anyone, and you will keep using it, and so will we.

So this isn’t a correction anyone needs. It’s a worked example of what happens when you check a number that everyone repeats, and the checking turns up two things worth more than the number did.

The bigger number is the coins that were destroyed

The truncation gap is the small effect. The coins that were mined and then lost through mistakes are roughly eight thousand times larger, and unlike lost private keys these are visible on the chain and can be counted exactly.

In 2020 the Bitcoin Core contributor Fabian Jahr reconciled the theoretical issuance schedule against the actual set of spendable coins at block 629,038, and found the real total short by 182.67920835 bitcoin. He accounted for all of it.

What happenedBitcoinDetail
The genesis block 50 The first block’s reward has never been spendable, and the cause is stranger than a burn or a deliberate gesture. The original software skips the genesis block during validation, so its coins were never written into the set of spendable outputs at all.
Two duplicated blocks 100 Over two days in November 2010, blocks 91,842 and 91,880 were mined with coinbase transactions identical to those of blocks 91,722 and 91,812. Each duplicate overwrote the earlier entry, wiping out the older block’s 50 bitcoin. A rule change in 2012 made a repeat impossible.
Rewards never claimed 28.955 Miners who paid themselves less than they were owed, almost always through a software fault. The largest single case is block 501,726 in December 2017, which claimed nothing at all and forfeited the full 12.5 bitcoin.
Deliberate burns 3.724 Coins users sent to outputs that can never be spent. This category keeps growing, so it is a snapshot rather than a final figure.

The oddest of them is block 124,724, mined in May 2011. Its miner deliberately took one satoshi less than the rules allowed, apparently to prove a point about the network accepting an underpaid block. The gesture worked. It also went wrong, because in constructing the unusual transaction the miner failed to claim the block’s fees, turning a one-satoshi statement into a loss of 0.01000001 bitcoin. It remains the only known intentional underpayment, and every piece of supply arithmetic since has had to carry that stray satoshi.

Watch the direction
Every error runs the same way
Truncation removes coins. Destroyed rewards remove coins. Burns remove coins. There is no mechanism anywhere in the arithmetic that produces more than the schedule allows, which is why the rounded figure is the generous one.

Notice that everything in the table points in one direction. The convenient number is too high, and every refinement to it makes the supply smaller rather than larger. When a figure gets rounded in public for fifteen years you would expect the rounding to flatter whoever is quoting it. Here it does the opposite, and Bitcoin’s most enthusiastic advocates have spent those years quoting a number that slightly overstates how many coins there can be.

None of this covers coins that are merely lost, which is a different category and a much bigger one. Estimates exist, and the widely cited Chainalysis work from 2017 put the range between about 2.8 and 3.8 million bitcoin. Those are inferences drawn from how long coins have sat unmoved, they assume Satoshi’s holdings are gone for good, and the methodology is not public. The losses in the table can be verified by anyone with a node. The estimates cannot, so never add the two together.

The 21 million in the code is not the cap

Anyone who goes looking for the limit in Bitcoin’s source will find it quickly, and will probably find the wrong thing.

Did you know
There is a 21,000,000 in the code, and it isn’t the supply cap

The source defines a constant named MAX_MONEY as 21 million bitcoin, which looks exactly like the rule everyone is looking for. It isn’t one. It works as a sanity check, an upper bound that stops absurd values from propagating if an arithmetic bug ever produces one, and it does not govern issuance at all.

That guard rail exists for a reason. In August 2010 an integer overflow let a single transaction in block 74,638 create over 184 billion bitcoin. Satoshi published a patched client within hours and the corrected chain overtook the bad one within days.

The actual limit is emergent. No line anywhere states it. It falls out of the subsidy function, which knows only that the reward starts at 50 bitcoin, halves every 210,000 blocks, and is measured in whole satoshis. Add up what that produces and you get 20,999,999.9769. The cap isn’t declared, it’s the consequence of a rule about payments, which is also why the exact figure surprises people who assume it must be written down somewhere.

What actually holds the limit in place

Which leads to the claim worth being careful about. Bitcoin’s supply cap is often described as mathematically fixed, hard-coded, or impossible to alter. That overstates it, and what actually holds the limit in place is more interesting anyway.

Every full node checks each block’s reward against what the rules permit, and rejects any block paying its miner too much. The block is not appealed or corrected. It’s discarded, by each machine independently, and never passed on. So the cap holds because thousands of people run software that enforces it and would have to be persuaded to run something else. It’s a rule sustained by the people who check it, not a law of arithmetic.

The evidence for that is the 2010 overflow. The limit was broken, in production, by a bug rather than an attack, and what fixed it was not mathematics. It was a patch that node operators chose to install. The same mechanism has been tested since: Peter Todd, a respected contributor, has argued since 2022 for a permanent small issuance after the schedule ends, and returned to the argument at a conference in July 2026. It has attracted no meaningful support, and no proposal to raise the cap has ever reached the point of being implemented.

Not this
A mathematical constant that cannot be altered, or a number written into the code as the supply limit.
This
A payment rule that every node checks on every block, discarding anything that pays too much.
Which means
Changing it needs node operators, businesses, and users to adopt different software. So far they have declined.

Read that way, a live proposal to change the cap and its comprehensive rejection is not a weakness in the argument. That rejection is the enforcement, visible and working. A rule nobody has ever been asked to break tells you very little about how firmly it is held.

Why round numbers are worth checking

So keep saying 21 million. It’s accurate to five significant figures, everyone understands it, and no argument that matters turns on the difference.

What the checking bought was two things the round number was quietly hiding. The 21,000,000 sitting in the source code is a safety bound rather than the rule, which means a reader who found it and stopped there would have learned something false. And the supply cap turns out to be held in place by people choosing to enforce it, not by arithmetic that couldn’t be changed, which is a stronger claim than the one usually made because it can be tested and has been.

Neither of those was visible from the outside. Both turned up because a number that everyone agreed on got checked anyway, which is the same reason worth asking three questions about any money you hold. That’s the standard we hold every claim to here, and you can see how we think for yourself.

The figure is 20,999,999.9769, falling to roughly 20,999,817 in practice. Round it off with everyone else. Just know what you rounded.

Keep going

A supply you can count and a schedule you can read in advance are two of the qualities the gold comparison turns on. The full argument, including where gold still wins, is worth reading next.

Is gold superior to Bitcoin?

Common questions

How many bitcoin will there ever be?

The issuance schedule tops out at 20,999,999.9769 bitcoin, a figure Bitcoin Core asserts in its own test suite. The number that actually ends up in circulation will be lower, because some block rewards were destroyed or never claimed. As of a reconciliation at block 629,038 the shortfall was about 182.68 bitcoin, putting the eventual total near 20,999,817. Rounding to 21 million is a convenience, and it rounds upward.

Is the 21 million limit written into Bitcoin’s code?

Not as the supply cap. The source contains a constant called MAX_MONEY, set to 21 million bitcoin, but it works as a sanity check that bounds the damage from arithmetic bugs rather than as the issuance rule. The real limit emerges from the block subsidy function, which starts at 50 bitcoin, halves every 210,000 blocks, and is calculated in whole satoshis, so it truncates. Adding up every subsidy that schedule will ever pay produces 20,999,999.9769.

Can Bitcoin’s supply cap be changed?

It is not mathematically impossible to change, and describing it that way overstates the case. The cap holds because every full node checks each block against it and rejects blocks that pay a miner too much, so changing it would require node operators, businesses, and users to adopt different software. A proposal for permanent tail emission has been argued by a respected contributor since 2022 and has attracted no meaningful support. That rejection is what enforcement looks like.

Go deeper

Everything on this site is for educational purposes only. It is not financial, investment, tax, or legal advice. Bitcoin carries real risk. Prices move, sometimes sharply. Do your own research, think for yourself, and speak with a qualified professional before acting on anything you read here.