How much will transaction fees eventually be?



Some people keep evangelizing that Bitcoin transaction fees are much lower than in PayPal or with credit cards.

However, once nearly all 21 million bitcoins have been mined, the network will still have to be secured.

But "miners" can then no longer be rewarded by newly minted bitcoins. They will have to be rewarded by transaction fees.

I read that the market will find the equilibrium how much these transaction fees will be.

Are there any estimates or more concrete calculations about that? Is it even possible to foresee, as the "degree of network security" is a rather nebulous incentive for most (casual) users? Will they thus be enforced by the software? Will these fees better be absolute or relative to the amount of a single transfer?


Posted 2011-09-11T11:02:44.390

Reputation: 3 377

It's a long way to go , dont' worry, the first production drop will come at the end of 2012. We'll see what's going to be then. for now , if you can wait, the fee can be 0, like the deepbit does. – None – 2011-09-11T12:40:32.807

1It's not too long to go - the vast majority of bitcoins will be mined within our lifetimes. – kmoe – 2014-10-10T14:48:17.373

I think we need new replies on this, most of the answers are "the btc is too new to know what will happen" but this is 7 years old, I think is more mature now. Is there any estimate or solution to the fee problem when everything is mined? – Enrique – 2018-05-29T17:33:44.180

Yes it seems I assumed no blockspace limit back then. Today the question would be relevant more for a hypothetical bcash or btc unlimited SE. ;) (fwiw, if there'd really be a race to the bottom nullifying security then would be a debate worth to have, I saw some discussions popping up here and there about it, but nothing conclusive.) – herzmeister – 2018-10-10T13:13:04.880



I read that the market will find the equilibrium how much these transaction fees will be.

It will not. This is perhaps the biggest flaw in Bitcoin at the moment: once mining rewards end there is no direct linkage between the amount of hashpower needed to secure the network and the incentive to mine.

True, there is a limit on the blocksize, so if the transaction volume in a block window (approximately 10 minutes) exceeds the block size you can expect a miniature "auction" where transactions fight for space in the block by bidding up the minimum transaction fee needed to get in. However this isn't really a closed-loop adjustment: the maximum blocksize is an arbitrarily chosen number, and there's no reason to believe the maximum blocksize is small enough to ensure that transaction fees are high enough to incent enough miners to mine to keep the system secure. Unlike the difficulty and the USD/BTC exchange rate it does not respond to market activity. It also has the negative side effect of capping the worldwide Bitcoin transaction throughput since other parts of the protocol rely on the assumption that blocks are created -- in the long run -- no more than once every ten minutes.

Compare this to the current situation with mining rewards: the more valuable a bitcoin is the more incentive there is for somebody to try to overwhelm the "good guys" by gaining 50%+1 hashpower. However, the more valuable a bitcoin is the more miners will mine! It isn't perfect, but the important point is that the demand for security increases the incentive to mine. Note that although the difficulty will go up, that simply ensures that the reward granted every ten minutes is an approximately constant number of BTC -- the number of terahashes/sec fighting over that amount of BTC is free to respond to changes in their changing value (as measured in terms of all other goods in the world, including other currencies).

As the mining reward is reduced this "direct coupling" between the network's need for security and the incentive to mine becomes progressively more diluted.

I worry a lot about what will happen to Bitcoin once we decouple those two forces. I think the developers ought to at least come up with a story on how this will be solved so people can start testing it.


Posted 2011-09-11T11:02:44.390

Reputation: 746

slight amendment: the network will move towards an equilibrium point due to difficulty adjustments where transaction fees barely cover mining costs. The unknown question is whether that difficuly will be high enough to secure the network from a well-heeled attacker. – lemonginger – 2011-09-16T19:14:22.757

7@lemongignger, it's the other way around: difficulty will adjust to whatever amount of mining can be paid for using the money people choose to "donate" via transaction fees . The (voluntary) transaction fee determines the difficulty, not the other way around. There is no incentive for miners to exclude a transaction whose fee was too small yet still nonzero. This "tragedy of the transaction fee commons" is a separate (but related) issue from what OP is asking about. – eldentyrell – 2011-09-19T05:58:34.347

@eldentyrell: "There is no incentive for miners to exclude a transaction whose fee was too small yet still nonzero." I've just had an idea for such an incentive: as long as enough miners representing >50% of the hashing power can agree on a minimum fee, they have the power to orphan the blocks produced by non-compliant miners! – None – 2011-09-24T21:39:51.343

1@Wim: "as long as enough miners representing >50% of the hashing power can agree on a minimum fee"... easier said than done. How is this negotiation performed? I'm not saying your idea won't work; I'm just saying that is much more complicated than you make it seem. – eldentyrell – 2011-09-26T20:10:50.240

@eldentyrell: things are simplified by the fact that miners already cooperate in large pools. Right now only the 3 operators of deepbit, btcguild and slush would have to agree. After that, all mining pools would have to follow the agreement and it would become impossible even for deepbit to ignore or change the rules on its own. – None – 2011-09-27T10:06:57.907

3@Wim, people join pools to reduce the variance, not as a way to collude. I, for one, would pull out of the pool and mine on my own if I found out that my pool was colluding with others. I think you fundamentally misunderstand how pooled mining is not a form of collusion or agreement; it is a way of reducing variance and nothing more. If pools make some "agreement" between themselves and it is possible to profit by breaking the agreement (i.e. accepting transactions with too-small-but-nonzero fees), people will leave the "agreement" pool en masse. – eldentyrell – 2011-09-27T19:23:13.070

@eldentyrell. Nobody can ophan a transaction. Not with 51% of hashing power, not with 99%, not with 99.99999999%. As long a single node (maybe even just the 2 people involved in the transaction) are willing to include the transaction it eventually will be included ina block.

If 100% of the network includes your transaction in the next block then your average confirmation time is 10 minutes.

If 50% of the network includes your transaction then confirmation is ~20 minutes on average.

etc. – DeathAndTaxes – 2011-10-06T20:47:22.533

1@eldentyrell: as I explained, it would not be possible to break the agreement because the rule would be enforced by orphaning non-compliant blocks. It would effectively establish a minimum fee in a democratic way because >50% of the miners (by hashing power) need to agree. The point is to establish a Nash equilibrium where it is impossible to lower the fees without >50% of the miners agreeing to that. – None – 2012-01-11T17:38:20.433

2@eldentyrell: And BTW, I understand perfectly that pools are intended to solve the variance problem. That doesn't mean that this organizational structure cannot be used for other purposes. If you really hate the idea of "colluding" pools that much, it might be possible to build "minimum fee votes" into the blocks instead. The end result is the same. – None – 2012-01-11T17:45:35.727

5@DeathAndTaxes, regarding "nobody can ophan a transaction", that's exactly my point. Nobody can keep too-low-fee transactions out of the chain. There will be a "race to the bottom". Whichever pools exclude too-low-but-nonzero-fee transactions are donating money (forgone transactions) to the pools that don't. I wouldn't expect an arrangement like that to be stable for long. – eldentyrell – 2012-01-12T06:48:50.083

2@Wim, sure, and pigs might fall out of the sky too. Hypothesize all you like, but if the incentives are wrong reality is not likely to unfold the way you want it to. – eldentyrell – 2012-01-12T06:53:35.093

1@eldentyrell: you still seem to think that such an agreement is unstable once it is established, because individual miners could profit by leaving it. I thought I addressed that with my proposal to orphan non-compliant blocks, resulting in a stable situation where miners can't ignore the rules unless the majority of the hashing power agrees. The only reason that it wouldn't work is if the majority of miners doesn't care about the long term viability of bitcoin, resulting in >50% defection. – None – 2012-01-12T11:37:47.023

4@Wim, no, because your proposal cannot be implemented without forking the chain. Merely getting 51% of the miners to agree is not enough to keep those transactions out of the chain. You must convince everybody on the entire network to upgrade their clients; if you don't do that, the chain will fork. The fact that your proposal causes a chain-fork makes it incredibly unlikely to ever be implemented by even a minority of the miners. They risk losing a lot of money by mining on the "wrong side" of the fork (whichever side that may be). – eldentyrell – 2012-01-13T03:33:21.180

2@eldentyrell: my proposal doesn't require any client upgrades. The current bitcoin clients already resolve forks by accepting the longest chain (as in, the one representing the most computation). And if the agreement has >50% of the hashing power backing it, it will always produce the longest chain. – None – 2012-01-13T10:51:33.140


@Wim, you are mistaken. You write that "the rule would be enforced by orphaning non-compliant blocks". The only way to orphan blocks is to make a chain-forking alteration to the block validity rules. This has not happened since the days before mining first became profitable, back when people mined only for fun; see Miners who adopt chain-forking alterations to the block validity rules risk losing massive amounts of money.

– eldentyrell – 2012-01-14T02:20:26.790

@eldentyrell Just because the risks miners take in the future are complex to model doesn't mean the incentive goes away. People are still setting their transaction fees and while the fragmented temporal groupings will vary in return on investment, the aggregate demand for network wide security will be realized incrementally as people unable to perform market actions increase their transaction fees drastically to ensure next time it goes through. – Kristopher Ives – 2012-08-09T04:32:55.877

@eldentyrell, Re "here is no direct linkage between the amount of hashpower needed to secure the network and the incentive to mine"; couldn't the reward be changed? – Pacerier – 2017-10-25T13:56:30.283


It's impossible to say for sure right now, because according to Gavin, Bitcoin's transaction fee structure will be redesigned at some point:

bitcoin's fee structure isn't right either, and fixing it to create a market between miners and clients is high on the TODO list

Chris Acheson

Posted 2011-09-11T11:02:44.390

Reputation: 1 813

This needs high priority. Looking at this link shows that costs per transaction are likely NOT sustainable long term.

– Brad Thomas – 2014-04-08T01:41:56.930

your link is dead – Dale – 2012-03-19T22:52:15.113

3@user8077 It still works for me. – Chris Acheson – 2012-03-20T02:35:50.203


"Reworking Bitcoin Transaction Fees" Proposal

– osmosis – 2013-01-05T21:11:05.087


There are a lot of unknowns because the network is so young and transaction volume is so low.

Currently the block reward is worth about $13.1 million annually. If fees stabilized at 0.1% of transaction volume (compare that to 3%+ for cc/debit/paypal) it would require a transaction volume of ~ $13 billion for fees to someday generate the same global revenue as current block rewards. To put that into perspective, credit & Debit cards have an annual transaction volume of ~ $2.5 trillion. Paypal has ~ $80 billion in transactions per year so this level of transaction volume is certainly possible.

The larger issue is that under current protocol rules fees will never stabilize at 0.1% (or any other meaningful percentage) of transaction volume. The reason is that currently there is no disincentive for a miner to exclude any paying transaction unless the block is already full of higher paying transactions. A transaction can become a paying transaction by merely including 1 satoshi with every transaction which even on a 1 BTC transaction is only 0.0000001% not 0.1%. For larger transactions it becomes infinitesimally small.

There is no method to create granularity because fees can be arbitrarily small and miners should logically not exclude a paying transaction. The current transaction fee system is simply not viable once block rewards (subsidies) are removed.

One way to look at it is the current network costs about $13 million per year to run or roughly $20 per block per TerraHash (TH). That cost is paid via subisides but that isn't a viable long term strategy. Someday it will need to be paid for with fees. If the amount of fees collected are higher than the network will be larger/stronger. If the amount collected is smaller then the network will be smaller/weaker.

Remember Moore's law doesn't make the network stronger. As miner's hardware becomes more efficient so does attacker's hardware. The network needs to generate sufficient fees to remain strong not just increase nominal hashing power due to efficiency gains. The current transaction fee system doesn't achieve that goal. It will need to be changed.


Posted 2011-09-11T11:02:44.390

Reputation: 8 409

i wonder if difficulty could be factored in to ensure that the network remains strong once all new blocks have been mined... – mulllhausen – 2013-09-12T06:40:00.330


In theory, as deflation continues and mining blocks becomes more efficient, the transaction cost will approach .00000001BTC/ 1 Satoshi and will stop multiple times on its way down at the point slightly above where profitability reaches cost. It is also possible that the transaction fee will approach zero.

The reason this happens is competition will drive the price down to the point that only the most efficient miners will be in business. The price reduction is further amplified by the deflation in Bitcoin. We will find the exact stopping point from the most efficient miners who are willing to take the lowest profit margin.

This will also be a floating point because as transaction volume increases so will profitability allowing miners to further reduce their fee.

To further answer some of your questions:

1)Are there any estimates or more concrete calculations about that? A: None that I can find. My prediction is that transaction fees will have a multi-tier approach where the most efficient miners will offer "dual" processing fees one of which would be 0BTC. The miners would split their processing power(a percentage based on profitability and a simple maximization problem) and include only transactions that met the highest payment tier would be included.

For example, if you include a 0 Satoshi fee you will only get 5% total processing power. If you include a 1 Satoshi fee you will get 10% processing power.

2)Is it even possible to foresee, as the "degree of network security" is a rather nebulous incentive for most (casual) users? A: The degree of network security will be improved if users provide their own processing power but, this will not be necessary as mining will be profitable to the most efficient miners.

3) Will they thus be enforced by the software? A: Fees will be enforced by miners not including transaction with too low of a fee into the block chain. This will cause a significant delay in the speed of your transaction. In the worst case scenario, where EVERYONE on the network requires a fee, you will have to mine your own block to get your transaction processed.

4)Will these fees better be absolute or relative to the amount of a single transfer? A: A miner can choose to accept a transaction and include it into a block based upon any criteria that they see fit. It will be interesting to see how miners choose to tier their pricing.

Justin Weeks

Posted 2011-09-11T11:02:44.390

Reputation: 353

1What's the incentive for accepting 0 fee transactions in your proposed "multi-tier approach"? I think there is none. – None – 2011-09-11T20:06:42.463

There would be no direct monetary compensation for accepting zero fee transactions.It would be a goodwill gesture to the community.The goodwill gesture could increase miners overall profitability in transaction fees by allowing users to connect their clients to just them so they get the "first shot" at processing the transaction.The miner could also choose not to broadcast the transaction and solve it themselves in that case. Those who need faster processing would pay a fee and those who don't care would wait.Users would choose this option if they feel like the miner provides better service. – Justin Weeks – 2011-09-11T20:20:57.633

1You say : "competition will drive the price down to the point that only the most efficient miners will be in business" If that becomes true, doesn't that open the door to collusion ? As the barrier of entry to being a miner increases, their number will diminish, and collusion will become increasingly feasable. What could prevent this ? – Max L. – 2013-04-12T14:38:01.247

You don't pay server costs with goodwill. – o0'. – 2011-09-22T09:57:25.043

No but you drive out competition by offering a multi-tier approach. Those who don't care about speed choose your free option. Others who need speed choose your fee option. – Justin Weeks – 2011-09-23T23:22:09.413

2@Lohoris no you don't BUT if you have vested interest in bitcoin thriving (like say you are Mt Gox and you personal wealth in directly related to Bitcoin adoption) then it may be worth it to indirectly donate some server capacity to handle "charity transactions". – DeathAndTaxes – 2011-10-06T20:49:23.387


In any P2P currency, there are only 3 choices, or combination of them.

  1. You fund miners from savers.
  2. You fund miners from spenders.
  3. You let the government provide the mining. A public need so the economy doesn't stop.

1 is not available to Bitcoin long-term, because debasement is halving every four years.

2 penalizes economic activity, which is more important than burying money, ahem saving. Also it doesn't scale, unless it is uniform in the protocol. Gavin wrote making it uniform won't work in the market.

3 is thus the outcome for Bitcoin. (as designed by Satoshi)

Shelby Moore III

Posted 2011-09-11T11:02:44.390

Reputation: 663

Your number 2 choice potentially penalises spenders less than credit card costs do, provided that retailers pass their cost savings on to their customers. This means that spenders can pay fees and still do better than they are now. Remember, Bitcoin isn't just a currency; it's a payment method. – Highly Irregular – 2013-03-27T08:46:34.070

@HighlyIrregular Sure it scales now that we have the revelation that the mega-corporations will do the mining as a loss-leader to monopolize. But the 3% for credit cards will be nothing compared to the 100% or more once there same monopoly controlling both processing and retailing. Before at least the retailers were fighting the credit cards, now they will be one in same and we will become absolutely slaves and destitute. You Bitcoin developers are not thinking clearly. – Shelby Moore III – 2013-03-27T09:04:11.240


That would give room in the cryptocurrency space for an alternative to take over. Remember most retailers need to provide their product at a competitive price, or another business will undercut them. And I'm not a Bitcoin developer (as least not yet)... I'm more interested in the theory, so far.

I note that a new structure for transaction fees is in the works too:

– Highly Irregular – 2013-03-27T09:19:24.817

1@HighlyIrregular Retailers won't be numerous (competitive) after the reverse takeover of our economy reset coming 2017. Gavin's proposal is a red-herring-- it doesn't scale. The only correct way to keep it decentralized is to never stop the debasement. That is why I knew that Satoshi was doing something evil and intentional. – Shelby Moore III – 2013-03-27T09:22:03.493

+1 But new crypto-currencies might remove the need for mining altogether. And I guess this will be the way. – Stéphane Gimenez – 2013-04-17T14:40:09.813


Most likely the fees asked for will be based on the transaction numbers. The miner's rig will need to be paid for (electricity, replacement parts, etc) for cost assumption is kind of hard to figure out until such a time as we know how many transactions will be going through once mining is complete.

Jason Marsh

Posted 2011-09-11T11:02:44.390

Reputation: 29


I would like to point out another macroeconomic related issue for the time all bitcoins are mined. The money is accumulating to the ones who know how to make the money to make more money. If the economy is not able to produce more coins, it will either fall into loan trap, deflation spiral which will reach quickly smallest fraction of coin or a global war will happen that resets the system. So bitcoin needs a way to raise the upper limit. Would it be possible to couple the hash algorithm with date so that in the beginning of hash more choises will be possoble than 0000000 today? And maybe also more slow algorithms to be used for the time pure energy is running quantum math?

My second macroissue would be related to populatipn growth. Monetary system needs to adapt to it. Deflation is hard to happen because of greed, but hunger will raise if jobless is caused by missing or standing money. Someone needs to find a way to inject money into system. Same does apply for seasional need for money when corn needs to be processed- othetwise it will rot because of no money to pay the bill e.t.c. There is a reason why gold is no more base currency.

Peeter Vois

Posted 2011-09-11T11:02:44.390

Reputation: 1

1Welcome Peeter. You make an interesting point, however, this answer you posted doesn't fit the question that was asked and is throwing out some questions of its own. Perhaps you could create your own question from your thoughts here? Please refer to [ask]? – Murch – 2013-11-24T02:14:25.177


At the moment, miners seem happy with a reward of B25 per block (and no fee auction seems to be happening with such a reward). You'd need to see how many transactions or how many bitcoins in average are usually contained in one block, and split those B25 over all the transactions.

So I don't think it will get very high anyway, so by itself the absence of fixed reward can be easily compensated by moderate fees.

What worries me more than the absence of fixed reward, and I think will have more impact, is the increase in the number of transactions: if blocks are mined at a constant rate, and their size is fixed, but the number of transactions keeps getting higher, it means that blocks will be more and more crowded and people start "fighting" (with fees) to get their transactions included. But again, this will be due to the number of transactions, not the presence or absence of a reward.

David Ammouial

Posted 2011-09-11T11:02:44.390

Reputation: 1 590


The long-term miners 'fee' for validating transactions might eventually come to be interpreted as some sort of interest rate.

Traditionally the interest rate is defined as the opportunity cost of holding on to currency. Right now, there is a benefit to holding on to a bitcoin, but come the day when they are few and far between mined, and more and more 'validated' that validation will be the opportunity cost of not discovering a new bitcoin, and thus some sort of interest rate (i.e. not having a bitcoin).


Posted 2011-09-11T11:02:44.390

Reputation: 184

Yet, unlike an interest rate the transaction fee is neither applied relative to the balance, nor invoked at passing of certain time intervals. The comparison is not very apt. – Murch – 2013-12-06T14:51:33.347

I'm not talking about a yield (such as the interest paid on a bond or debt instrument), but rather the long term rate of interest in an economy. – user10263 – 2013-12-06T18:29:48.663


When all bitcoins will be mined, if Bitcoin believers will still have faith in it i.e. Bitcoin can retain its value and don't collapsed to zero or negligible then:

  1. Bitcoin miners will be known as Bitcoin brokers.
  2. Reward to brokers will be very low, in form of transaction fee, therefore hashing difficulty will be zero or negligible.
  3. Only efficient brokers will remain in the Bitcoin network and their number will be low and vary to maintain a equilibrium in which the reward per broker will be just reasonable all the time, so, that they can just remain in business. If Bitcoin's value and thus the transaction fee increases, more brokers will pump in to maintain the equilibrium and vice versa.
  4. A very low amount of brokers in the Bitcoin network will increase the threat of a "51% attack" and thus believers (and thus value) of Bitcoin will go down which will further reduce the transaction fee and create a vicious cycle.
  5. To counter a "51% attack", a combination of the following could happen:
    1. Believers of Bitcoin can make an organisation and plant 10000 genuine broker nodes (not for profit but to secure the network) so that attackers should have at least 10001 nodes.
    2. Believers of Bitcoin can decide to carry forward all Bitcoin transaction/possession data to an entirely new algorithm/protocol (like carry forward of movies from obsolete tapes to CDs) which would be “51% attack” free. Such a system could be made centralized if necessary. Bitcoin generation limit coudld be extended, so that Bitcoin mining can be started again.


Posted 2011-09-11T11:02:44.390

Reputation: 1

While there are some good thoughts in this answer, it makes a lot of assumptions it could provide more evidence for. – Murch – 2016-08-06T08:42:39.687