Answers, including the unflattering ones
Questions people actually ask.
If an answer here reads like it is dodging something, that is a bug. Tell us and we will rewrite it.
- New to this The basics Depth, rings, tiers, and why none of it is a token.
- Thinking about claiming The Firstlight mint Cost, the 144 block wait, the supply, and what happens if you miss.
- Already holding one Owning one What resets depth, what a relic is, and how not to break it by accident.
- Checking our claims Trust and independence What we can switch off, what we cannot reach, and what survives us.
01 The basics
Three words carry most of the protocol.
Depth, ring, tier. Two of them are not what people expect, and the third does less than anyone assumes.
What is PATINA, in one sentence?
A way of marking one Bitcoin output as the carrier of an artifact whose depth is simply how many blocks that output has stayed unspent.
What exactly is depth?
The current block height minus the height of the block that created the carrier output. Nothing else. It is computed when you ask, never stored, and any Bitcoin node can produce it.
Why does moving it reset the depth?
Because spending an output destroys it, and a destroyed output has no age. There is no rule saying "reset on move" that somebody has to enforce. There is simply nothing left to measure. That is the part we like most about it.
What is a ring?
The permanent record of a finished stretch. When a carrier is spent, the artifact gains a ring holding the start height, the end height, the depth it reached, and the value it carried. Rings accumulate and nothing removes them. Depth resets, rings do not.
So what is the difference between depth and a ring?
Depth is the stretch that is running right now, and it grows with every block. A ring is a stretch that already ended, written at the moment the carrier was spent.
Rings never change, and their depths never add up into one figure. An artifact with four rings is not deeper than an artifact with one. It has simply been through more.
Do the tiers do anything?
They name ranges of depth, and that is all. Reaching Bronze pays nothing, grants nothing and changes nothing. A tier is a word for a number. Every tier and its arithmetic.
Is there anything above Elder?
No. Elder is the last tier, at 210 000 blocks. Past that the depth number keeps rising and the tier stays Elder. There is no rank left to climb, which is deliberate.
Is this a token?
No. There is no balance, no denomination, no ledger of holdings. An artifact is a statement about one Bitcoin output, and the way you move it is by spending that output like any other coin.
Is it an NFT, then?
It shares the idea of a unique object recorded on a chain, and it shares nothing else. There is no mint price, no supply cap, no marketplace, no royalty, and no image required for the artifact to exist.
The state is the artifact. A picture of it is a view, and a view can be redrawn by anyone from the same inputs.
Why are there no dates anywhere?
Because the protocol has no clock. Heights are exact, checkable, and identical for everyone reading the same chain.
Any calendar figure on this site is converted at ten minutes per block, which is a target and not a promise, and it is labelled as an estimate wherever it appears.
02 The Firstlight mint
One window, no price, and a day of waiting you cannot skip.
The founding cohort is claimed inside a commit window of 4032 blocks. Most of the questions we get are about the wait in the middle.
No opening height is announced on this page
This page will not tell you whether the window is open, and it will not invent a height to fill the gap. The live panels on the Firstlight page report what an indexer told them, and say so plainly when nothing answered.
What is a Firstlight Seal?
An artifact whose commit output was created inside the founding window of 4032 blocks and whose reveal confirmed by the end of the grace period. Both conditions, or it is an ordinary artifact. The founding mark is permanent and cannot be added later to anything else.
What does it cost?
Miner fees on two transactions, and nothing to us. At 25 sat per vbyte the two come to roughly 8 175 sats in total.
You also have to seal at least 100 000 sats of your own bitcoin into the carrier, and that is not a payment. It stays yours. The full fee table is on the mint page.
Is there a supply cap?
No. The cohort is whatever the window produced. A cap would create a race, and a race is exactly what the aged commit is designed to prevent.
Is it first come first served?
No. There is no rank, no serial number, and no advantage to committing early inside the window. A claim made on the last day produces the same kind of Seal as one made on the first.
Can one person claim many seals?
Yes, as many as they can fund at 100 000 sats each plus fees. The protocol cannot tell people apart, so it cannot limit anyone. Live concentration figures are published during the window, not after it.
Why do I have to wait 144 blocks?
So a claim cannot be sniped. The commit reveals nothing while it waits, and only its owner can spend it, so copying somebody's reveal is useless: an attacker would need a commit of their own that already existed a day earlier.
It also means there is no advantage to refreshing a page at the right second. A reveal that is too young confirms on Bitcoin, records SEED_COMMIT_TOO_YOUNG, and creates nothing.
Can the window be extended?
No. The heights sit in the deployment record and the chain passes them. There is no extension mechanism, and nobody holds a key that could add one.
What if my reveal does not confirm in time?
The grace period runs for another 4032 blocks after the window closes, and a reveal confirmed on the last of those blocks still counts. One block later it does not.
Missing it destroys nothing. The bitcoin in your commit output is still yours, because only your key can spend it, and a late reveal still creates an artifact if every other check passes. It is an ordinary one, held to the 10 000 sat floor, and it can never carry the founding mark.
Can I still create an artifact after the window closes?
Yes. Artifacts can be created at any time, with a carrier floor of 10 000 sats instead of 100 000. They accumulate depth and rings exactly the same way.
They are ordinary artifacts. They are not Firstlight Seals and no amount of waiting will turn them into one.
Can I do this with a hardware wallet?
For holding the carrier, yes. Once the carrier exists it is an ordinary Bitcoin output, and the protocol puts no requirement on its script type.
For the reveal you need a signer that can perform a taproot script path spend revealing a specific leaf, which most consumer devices and wallets do not expose. Work that out before the window matters to you, not during it. The operator level walkthrough covers what the signer has to do.
03 Owning one
An id, an outpoint, your own coins, and a history.
That is the whole object. Almost every question in this section follows from the outpoint, because the outpoint is the part that can be destroyed.
The rule that catches people
Every spend of the carrier ends the stretch and returns depth to zero. Selling it, consolidating it, sweeping a wallet, paying a fee out of that same output. There is no exception, and nobody can grant one.
Does owning one guarantee anything?
It guarantees that the record is readable by anyone, that the rules applied to you the same way they applied to everyone else, and that nobody can change your artifact without your key.
It does not guarantee value, a buyer, liquidity, attention, or that anyone will ever care. There is no market maker and no floor. Nothing on this site is a prediction that this will be worth something.
Does depth prove I held it the whole time?
No. It proves the outpoint did not move. Keys can be sold off chain, invisibly, at any point. A signed attestation over the artifact id and a recent block hash proves the key is alive right now, and even that could be signed by somebody who bought the key yesterday. More on this.
What does an attestation actually prove?
An attestation is a BIP-322 signature by the key that controls the carrier, over one exact string built from three parts with no separator between them.
- Tag
- The 11 characters
PTNA/attest. - Artifact id
- 64 characters of lowercase hex.
- Block hash
- 64 characters of lowercase hex, in the display order an explorer shows, from a block you pick.
The block hash is the timestamp. It cannot be predicted before that block is mined, so the signature proves somebody could sign for the carrier at or after that height. Pick a recent block, because a signature over a block from last year only proves something about last year.
It does not prove the signer is the original minter, and it does not prove the signer is the only person holding that key. It costs nothing, publishes nothing to the chain, and cannot reset depth. An artifact with no attestation is not suspicious. How to produce and verify one.
If I buy one, do I keep its depth?
Not if the sale moves the carrier, and any sale you can check on chain does. Spending it ends the stretch and starts a new one at zero, so what you inherit is the rings, meaning the record of what happened, and not the depth. Price accordingly.
A seller can hand you keys instead and leave the depth standing. The chain records nothing about that, and you are trusting them not to have kept a copy.
Is my bitcoin locked up?
No. There is no timelock on the carrier and no custody arrangement. You can spend the endowment in the very next block. Doing so simply ends the stretch and engraves a ring.
Can I move an artifact without resetting it?
No. Moving is spending, and spending resets. KEEP lets you say which output the artifact continues on, which is about control, not about preserving depth.
What is KEEP for, then?
To route the artifact deliberately when you spend a carrier, instead of letting the default rule choose. Without a KEEP entry the artifact continues on the lowest index output that is not an OP_RETURN and holds at least 10 000 sats. With one, you name the output yourself. Up to eight entries per marker. The full KEEP rules.
What if the carrier is spent to an output below the minimum?
That output is not eligible, so the artifact skips past it. A KEEP entry naming an output under the floor is void with KEEP_ENTRY_BELOW_MIN, the entry is ignored, and the default rule takes over: the lowest index output that is not an OP_RETURN and holds at least 10 000 sats.
If nothing in the transaction clears the floor, there is no successor and the artifact becomes a relic. Sats paid to the miner are not an output, so a transaction that sends everything to fees leaves the artifact with nowhere to land.
What is a relic?
An artifact whose carrier was spent with no eligible successor output, meaning nothing that was both a real output and worth at least 10 000 sats. It is terminal. The rings it already engraved stay in the record forever, and no new stretch can begin.
Can two artifacts end up on the same output, and can I split them again?
Yes to the first. Successor routing can land two artifacts on one output, and from then on they share a carrier. That is a bundle. They have the same depth, because depth belongs to the outpoint, and spending that carrier ends every one of their stretches at once.
Splitting is the awkward part. A KEEP entry names an input, and one input can name only one vout, so a single transaction sends everything on that carrier to the same place. Separating them takes a sequence of spends, and every step in that sequence resets depth for everything it touches. Plan it before a sale, not during one. How bundles behave in the state machine.
What happens if I lose my keys?
The carrier can never be spent, so the depth grows forever and the artifact can never be transferred. From the outside that looks exactly like extraordinary discipline. The chain cannot tell the difference, and neither can anyone reading it.
Does depositing one on an exchange reset depth?
Yes, twice. Your deposit spends the carrier, and the exchange spends it again when it sweeps into its own wallet. Do not deposit a carrier anywhere custodial.
How do I avoid resetting it by accident?
Keep carriers in a wallet you never sweep or consolidate, and check outpoints against the safety endpoint before you spend. The command is on the verify page. Ordinary coin selection has no idea what a carrier is.
Do I have to run anything to keep it?
No. Leave the carrier unspent. That is the whole obligation. Indexers, servers and websites exist to read the state, not to hold it.
04 Trust and independence
What is left of your artifact if we stop existing.
The honest test of a protocol is what survives its authors. These answers are the ones we would want to read about somebody else's project.
Do I need Bitcoin Universe for any of this?
No. The app is a convenience for building the two transactions. The marker format is public, the derivations are single SHA-256 hashes, and anyone can build, broadcast and index without us. Verify it yourself.
Can the team turn PATINA off?
We can turn off our own app and our own indexer. We cannot pause the protocol, freeze an artifact, reverse a spend or change anyone's depth. Markers are ordinary Bitcoin transactions. Exactly what each switch reaches.
Does Bitcoin Universe hold my keys or coins?
Never. The app builds unsigned transaction plans with a plain review summary. You sign. Nothing is broadcast without your signature and there is no account to create.
What if an indexer lies to me?
Check it against a node. An unspent output reports its confirmation count, and the block that created it counts as the first confirmation, so depth is confirmations minus one and no index is involved in the answer.
bitcoin-cli gettxout <carrier_txid> <carrier_vout> true | jq '.confirmations - 1'
Two honest indexers at the same height must agree exactly, so disagreement is a bug you can prove.
What if two indexers disagree?
One of them has a bug, and it matters. Compare state roots at the same height, bisect to the first block where they differ, and report it with the block that broke.
Disagreements get published rather than settled quietly, because an index nobody can audit is just a database with opinions. How to build a compatible implementation and compare roots.
What if Bitcoin Universe disappears?
Your artifact does not. It is derived from the blockchain by rules that are published, with golden vectors and byte level examples anyone can reproduce.
Somebody else can run an indexer, and so can you. The operator guide is written for people who are not us.
Which networks does it run on?
Regtest and signet deployment records ship in the repository. Mainnet values stay unset until activation is authorised, and the construction code refuses to build mainnet transactions until then.
Where is the code?
The protocol repository holds the specification, the reference library and the test vectors. The indexer is separate. This website is a static site with no build step, so its source is exactly what your browser downloaded.
05 Longer answers
Where each of these gets taken apart properly.
- I want the long version Documentation questions The same ground at operator depth, with reason codes, endpoints and the failure cases named.
- A word stopped me Glossary Every term these pages use, defined once. Carrier, marker, bundle, endowment, default rule.
- I want to see it move How depth works Take an artifact apart, close a stretch, and watch the rings accumulate over years.
- I want the downside Risks Minting, operational and systemic risk, plus what depth does not mean about a person.
- I want to claim one The mint Commit, wait 144 blocks, reveal. The fee table and the failure modes sit on the same page.
- I take nobody's word Verify Read depth off your own node, decode a marker by hand, and cross check two indexers.