Satoshi’s Abandoned Poker Experiment Returns With a Bitcoin Twist
Key Takeaways
Robin Linus published Bitcoin Poker on Sept. 6, turning Satoshi’s 2008 poker concept into a protocol.Bitcoin Poker uses 56,132 transaction-tree nodes to enforce two-player Texas Hold’em.Linus’ design needs no Bitcoin consensus changes, but its security still requires independent review in 2026.
Back in 2008, when Satoshi Nakamoto was getting ready to publish the white paper, the mysterious inventor apparently found time to sketch out a poker room inside Bitcoin’s codebase. Hidden inside Bitcoin’s earliest source code were buttons for dealing cards, folding, calling, and raising bets. There was just one problem. None of it actually played poker.
The software had the makings of a table, but no functioning game underneath. Fast-forward 18 years, and Stanford researcher Robin Linus has tackled the problem Satoshi left behind. On Thursday, Linus introduced Bitcoin Poker, a protocol that lets two people play a genuine game of Texas Hold’em using Bitcoin to enforce the rules, settle wagers and handle players who refuse to cooperate.
“Dear Satoshi, the first BitVM dispute, the SHA2-ECDSA polyglot, the Binohash madness—all just fan mail written in Bitcoin Script. None of it matters until I fulfill your original vision,” Linus wrote on X. “So I finally finished the poker client you left unfinished in Bitcoin v0.1. Hit me up for a few hands.”
Satoshi’s Forgotten Poker Room Gets a Second Life
The original Bitcoin source code contained a file called uibase.cpp, which included graphical components for a poker lobby and table. The interface carried an April 16, 2008, generator date, roughly six months before Satoshi published the Bitcoin white paper. Buttons labeled Deal Hand, Fold, Call and Raise suggested something more ambitious than a simple payment application, although Satoshi never publicly explained what he intended to do with them.
Those early fragments weren’t a functioning poker client, much less a blockchain-enforced gambling system. There was no mechanism for dealing private cards, tracking wagers or determining who should collect the winnings. Linus makes that distinction clear in his Bitcoin Poker white paper, writing, “These interface fragments were not a complete poker protocol.” Rather than resurrecting Satoshi’s abandoned software, Linus set out to build the missing machinery from scratch.

The historical backdrop makes the discovery even more interesting. Congress passed the Unlawful Internet Gambling Enforcement Act in October 2006, targeting financial transactions associated with unlawful internet gambling. Years later, federal authorities famously seized domains belonging to major online poker operators during the April 2011 crackdown known as “Black Friday.” Whether online gambling restrictions influenced Satoshi’s thinking remains unknown, but the idea of playing poker without relying on a centralized payment processor certainly fits Bitcoin’s original purpose.
Nine Cards, Two Players and No Dealer Calling the Shots
Linus, a Stanford PhD candidate, is best known for developing BitVM, a 2023 proposal for verifying complex computations through Bitcoin without changing its consensus rules. His later research includes BitVM2, BitVM3, Zerosync, and other cryptographic systems. Bitcoin Poker applies that same inventive approach to something considerably more familiar than blockchain computation.
“We describe a two-player protocol for limit Texas Hold’em on Bitcoin,” Linus’s paper explains. The game involves two participants, each receiving two private cards, while five community cards appear as betting progresses. Unlike conventional online poker, no casino server or trusted dealer determines which cards the players receive.
Instead, both participants contribute secret information to generate the cards. As Linus explains, “Only nine distinct cards are needed.” Rather than shuffle an entire 52-card deck, the system generates precisely the nine cards required for a single hand, using cryptographic commitments and zero-knowledge proofs to keep the deal fair.
The arrangement ensures neither participant can secretly control the outcome. “Neither player alone can decrypt,” the paper states, describing the jointly encrypted information used during setup. Before play begins, the protocol also checks for duplicate cards without exposing their identities. If two cards match, the entire attempt is discarded and another deal begins.
There’s a peculiar mathematical wrinkle here. A randomly generated nine-card deal has only about a 48% chance of passing the duplicate-card test. That means the system needs an average of 2.08 attempts to produce an acceptable hand. It’s an expensive way to shuffle cards, but the result is a private deal that doesn’t require trusting the person sitting across the table.
Bitcoin Becomes the Referee When Somebody Refuses to Play Ball
Dealing cards is one thing. Making sure the winner gets paid is another matter entirely, especially when neither participant has any reason to trust the other. Linus handles that problem by preparing a collection of Bitcoin transactions representing the game’s possible outcomes before the first bet is placed.
“The rules define a finite tree,” the white paper explains. Each branch represents a permitted action, including folding, checking, calling, raising, revealing cards or settling the pot. Players authorize these possibilities in advance, and Bitcoin’s existing transaction rules prevent them from improvising unauthorized moves.
“Invalid actions have no preauthorized transaction,” Linus writes. The protocol also uses adaptor signatures, which allow required card information to be recovered when particular transactions are signed. This prevents players from exploiting certain disclosure requirements to gain an unfair advantage.
But what happens when someone decides they’ve had enough and refuses to continue? Linus has an answer for that, too. “Every state waiting for a player also offers an opponent timeout spend,” the paper states. After a specified delay, the remaining participant can collect the committed pot, while the departing player’s unused balance is returned.
The researcher acknowledges an important distinction. “The protocol can force settlement, but it cannot force someone to reveal a card.” In other words, Bitcoin cannot make somebody finish playing, but it can enforce the financial consequences of walking away.
A 56,132-Node Poker Game Comes With a Catch
The design is clever, but nobody should mistake it for a lightweight mobile poker application. Linus’ reference configuration, featuring 100 big blinds per player and four bets per betting round, contains 56,132 logical nodes, along with 54,855 ordinary signatures and 1,306 card-reveal packages. Each package contains another 52 adaptor signatures.
The complete preparation snapshot weighs 8,416,186 bytes, roughly 8.4 MB. In three desktop-browser trials, preparing and saving the transaction tree took between 26.39 and 27.26 seconds. Linus cautions that “These are fixture measurements, not startup guarantees.” The figures describe a reference implementation rather than the performance users should expect from a finished product.
Fortunately, ordinary gameplay doesn’t require broadcasting that enormous collection of transactions. “The intended mode of play is off-chain,” the paper explains. Players exchange messages privately, keeping Bitcoin transactions in reserve if cooperation breaks down. The blockchain effectively serves as a referee waiting on the sidelines, ready to settle disputes when necessary.
Nearly Eighteen Years Later, Satoshi’s Poker Idea Has Real Rules
There are still limitations. Bitcoin Poker supports only two participants because additional players could secretly share information about their cards. Public showdowns can expose both hands, and the cryptographic construction still needs independent security analysis before anyone should consider it production-ready.
Linus makes no attempt to conceal those shortcomings. “It is not a formal proof of the complete malicious-party protocol,” the paper acknowledges. Existing tests using Bitcoin Core exercise important components, including payouts and timeout paths, but “Test coverage is not a security proof.”
Still, the accomplishment reaches beyond poker. Linus has demonstrated how Bitcoin’s existing scripting and signature capabilities can enforce a game involving hidden information, complicated decisions and financial payouts without changing the network’s underlying rules.
Bitcoin’s mysterious inventor left behind a poker table with buttons that didn’t do much. Eighteen years later, Linus has developed the cryptographic rules needed to deal the cards, play the hand and settle the pot. The remaining question is whether the elaborate construction can become practical enough for ordinary players to give it a whirl.
