Skip to main content

El Salvador’s bitcoin is the most publicly auditable sovereign treasury on the planet. Roughly 7,762 BTC, deliberately split across fourteen published addresses so that no single wallet holds more than 500 coins, with a live feed from the National Bitcoin Office that anybody can read. Checking the balance takes a block explorer and thirty seconds. No permission, no account, no freedom of information request.

On 3 September 2026 the IMF announced a staff-level agreement on the combined second and third reviews of El Salvador’s Extended Fund Facility, clearing the way for roughly $140 million of a $1.4 billion arrangement. Inside it was the sentence crypto Twitter had been waiting on for a year: documentation has been provided verifying that bitcoin accumulation since the first review reflects private donations, and that no public resources were used.

Read it again. The balance was never in question; everyone could see the balance. The question was whose money bought it, and that one got settled by documents, in a room, by a lender, on a schedule, naming no donor and no amount. That is the forty-seventh unasked half of fairness.

TL;DR

  • The IMF’s staff-level agreement of 3 September 2026 unlocks about $140m and attributes all bitcoin added since 27 June 2025 to private donations, no public resources used.
  • Nobody disputed the balance: fourteen public addresses, roughly 7,762 BTC, checkable by anyone on earth. The disputed fact was the source of the money, and no blockchain records that.
  • On-chain, a donation and a self-purchase routed through a second wallet are the same object. There is no cryptographic difference between “somebody gave me this” and “I moved my own money”.
  • Compliance and breach would have produced an identical chain. When the honest state and the dishonest state look the same on the ledger, the ledger is not doing the work.
  • Satoshie proves the mechanism completely (ticket price, odds, Chainlink VRF proof, escrowed payout) and proves nothing about where a player’s stake came from. Neither does any chain, and anyone claiming otherwise is selling you a PDF with a hash on the front.

What actually happened

The Extended Fund Facility was approved in February 2025: forty months, $1.4 billion of access, and conditions that included the public sector stepping back from bitcoin accumulation. Bitcoin stopped being legal tender that same month; the reserve policy did not stop. The Bitcoin Office kept posting, the balance kept climbing, and a reasonable question formed in public: if the state agreed not to buy with public money, what is funding this?

The IMF’s answer, cutoff date 27 June 2025, is that the additions came from private donations, that El Salvador supplied documentation saying so, and that no further accumulation beyond those documented donations is expected. That is the whole of it. No donor list, no amounts, no addresses tied to names.

The half nobody asks

Every previous instalment has interrogated the resolution of something: was the number honest, was the reading checkable, was the exit yours, were your entry terms the same as everybody else’s. This one asks about the origin of the stake.

A blockchain is a custody and transfer machine. It records that an amount moved from one key to another, and it does this so well that a country can publish its treasury to the entire internet and lose nothing by it. What it does not record, at any layer, on any chain that has ever shipped, is whose money it was.

Why the chain cannot answer it, even in principle

Suppose El Salvador published every donor address tomorrow. It would settle nothing. A transfer from A to B proves that whoever controls A signed. It does not prove that A and B are different people. Self-transfer and donation are indistinguishable at the protocol level, and the distinguishing fact lives in who holds which keys, which is exactly what the chain refuses to hold on your behalf. Even a signed message from a supposed donor only proves somebody with that key was willing to sign it.

So the question left the chain the instant it was asked, and the answer came back in the only form off-chain answers ever arrive in: an attestation by an authority.

Attestation is not verification

Put the two claims side by side, because the shapes are nothing alike. The balance claim is checkable by anyone, unilaterally, forever, without the cooperation of El Salvador or the IMF or anybody else; it does not expire, and it will still be checkable in twenty years by somebody nobody has met yet.

The funding claim was checkable by exactly one party, once, against documents nobody outside that process will ever read, and it reached the rest of us as a conclusion. We do not verify it. We defer to it. That is the same shape as every “trust us” this series has spent forty-six instalments pulling apart, except this one turned up wearing on-chain clothes.

This is not an accusation

Stated plainly: there is no evidence of wrongdoing. The IMF had $1.4 billion of reasons to be strict, its staff reviewed real documentation, and donations to the loudest bitcoin advocate any government has produced are entirely plausible. El Salvador is probably telling the truth.

The point is narrower and more uncomfortable. Had it gone the other way, the chain would look exactly the same. Every address, every balance, every timestamp: identical. Compliance and breach share an on-chain signature, so the ledger is not what separates them, something else is, and you should know what that something is before you lean on it.

What this means for a gaming contract

The thing worth selling is never “everything is verifiable”. It is a specific, boring, enumerable list. Here is what Satoshie proves to anybody, before they play, without asking us for anything: the ticket price is a constant in the deployed contract; the odds are a function of the entry count and published before a single ticket is sold; the randomness comes from a Chainlink VRF request whose proof is verified on-chain before the callback runs; the coinflip payout sits with the escrow in the same transaction as that callback; and no admin key can reach into a live draw.

Here is what Satoshie does not prove and cannot: whose money paid for the ticket. Borrowed, pooled, gifted, a syndicate, a partner’s card converted an hour earlier on an exchange the contract has never heard of. It sees one payment from one address and nothing else, ever. That is not a gap in our implementation. It is the same wall the IMF walked into, and every honest operator in this industry stands on the same side of it.

The honest limits

Source of funds is an identity problem, not a cryptography problem. The twenty-first instalment covered Ireland’s AML strategy pushing source-of-funds standards onto gambling operators, and the honest answer then is the honest answer now: on-chain fairness has nothing useful to say about it. Chain-side and identity-side verification are separate disciplines and neither substitutes for the other.

Self-exclusion still defeats us. Somebody who has excluded themselves can fund a fresh address this afternoon. A VRF cannot see a human behind a key and it never will.

Our own proofs are a permission, not an act. As the twenty-fifth instalment argued, verifiability means you may check without our cooperation. It has never meant that anybody did.

Name the question your proof answers

El Salvador did the transparent thing harder than any state before it, published a treasury most finance ministries would not release under subpoena, and still needed a lender’s paperwork to answer the one question with money attached. Not because on-chain transparency failed, but because it had been answering a different question, correctly, the entire time.

That is the discipline this industry keeps skipping. Say what your proof covers and what it does not. Ours covers one question: was this game rigged? That one we answer completely, permanently, and without needing you to believe a word we say. Where your money came from is your business, your regulator’s and your bank’s, and anybody who tells you a blockchain settles it is handing you the same PDF with a hash printed on the front.

📷 Photo by Meg von Haartman on Unsplash

Valentina Ní Críonna

Author Valentina Ní Críonna

More posts by Valentina Ní Críonna