The scarcity of gold is a geological gamble. No one knows how much is still underground, and whenever it's worth digging more, they dig deeper, grind poorer rock, and sift through old waste. Supply responds, with a few years' delay. It happened with gold, it happened with silver, and it happened, brutally, with the cowrie shells from the previous module.

Bitcoin replaced the gamble with a rule, and the rule is simple. Whoever closes a block can create a set amount of bitcoins for themselves, and this amount halves every 210,000 blocks, which is about four years. It started at fifty. It dropped to twenty-five in November 2012, twelve and a half in July 2016, six and a quarter in May 2020, and 3.125 in April 2024. The next drop is scheduled for 2028, and it's not by anyone's decision: it's by block count.

Add up this series and it stops. Fifty times 210,000, plus twenty-five times 210,000, and so on, gives just under 21 million — 20,999,999.97, because the calculation is done in whole numbers and the division truncates the remainder. Around 2140, creation reaches zero and no new bitcoins are ever born again. The limit is not a stock stored somewhere. It's the end of a sum.
The unit that truly exists isn't even the bitcoin. It's the satoshi: each bitcoin has one hundred million of them, and it's in satoshis that the network counts everything. "Bitcoin" is just the way to write large numbers of satoshis, like "kilometer" is the way to write meters. This answers the most common objection against a money that cannot grow: it doesn't need to grow in units, because the unit is tiny. Dividing it further one day would be possible — but it would mean changing a rule, and changing rules is the subject of the next lesson.
The important part is missing, and this is where this lesson answers the question left open by the first module. That module listed the properties that make something work as money and said that scarcity is the most decisive. What it couldn't say is how someone verifies scarcity. With gold, you trust geologists' estimates. With state currency, you trust a central bank's report. With Bitcoin, you don't trust: you verify.
Each network node recalculates on its own how much the miner was entitled to create in that block and rejects the entire block if the number doesn't match. It's not an annual audit done by a hired firm. It's a verification done by tens of thousands of computers, every ten minutes, since the first block. It's the same rule that broke the chain of 184 billion bitcoins in Lesson 3, and it's the entire difference between promised scarcity and verifiable scarcity.

The rule cuts both ways. In December 2017, a miner assembled a block where they charged nothing: neither the creation they were entitled to nor the transaction fees they included. The network accepted the block without complaint, because charging less doesn't break any rule. Those bitcoins simply never came into existence.
Two honest criticisms fit here. The first is distribution. In the early years, mining cost almost nothing and almost no one was watching, so a large slice of the total ended up with very few people. This is a fact of the design, not a detail. The second is what happens when creation ends: the network's security will have to be paid for solely by fees, and whether they will be enough, no one knows. It's a legitimate question, seriously discussed, and there are more than a hundred years left for the answer.

And there's the most direct objection of all: 21 million is an arbitrary number. It is indeed. Satoshi chose it and did not justify it. What matters is not the number — it's who can change it. That's the next lesson.