A sly, roundabout way of fighting spam.
A Monetary Node validates every consensus rule a full node does — then declines to keep what isn't money. Spam is removed from the blocks themselves, not merely from the database. The spam is deleted; the hashes are saved — and the block still verifies against its own proof-of-work. Across the inscription era, 16.46% of block bytes gone: 194,863 blocks stripped, stored, and re-verified from the store alone, zero failures. Zero consensus changes.
A Monetary Node validates every block in full, then stores it without its data carriers. What it keeps is the 32-byte transaction ID of anything it touched, and that is the whole trick: a block's merkle root is computed over transaction IDs, so the data can go and the block still reconstructs to the root in its own header. Fabricate an ID and the root stops matching. It also keeps a compact record of every removed output, so those coins stay spendable, and two cryptographic fingerprints of the ledger — one of the full state, one of the clean state, bound together so neither can be faked without the other. Same chain. Same rules. Same proof-of-work.
Inscriptions, Stamps and token protocols embed arbitrary data in transactions. Every full node downloads it, validates it, then stores it forever — receiving nothing in return. It is not a spike: measured across 194,863 blocks of the inscription era, roughly one byte in eight of block data is payload no node needs in order to know who owns what.
A node cannot refuse to validate that data without leaving consensus. It can refuse to keep it.
The monetary view grows out of the legacy blockchain, block by block. Every block is fully validated as mined — then spam is discarded before it is ever written to disk.
Same blocks, same order, same proof-of-work — the top row is the blockchain as everyone sees it. A Monetary Node stores the same blocks with the red squares taken out, keeping each removed transaction's ID so the merkle root still matches the header, and fingerprints both views at every step so nothing can be misrepresented. Spends of deleted outputs remain fully valid: everything needed to validate one is kept in the filter index.
Every block is validated in full under unchanged consensus rules. Only then is it stored — with its data carriers removed from the block record itself. Across the inscription era that is 37.2 GB of carriers, 12.56% of block bytes. The 32-byte transaction ID of anything modified is retained, so the block still reconstructs to the merkle root in its own header and verifies against real proof-of-work. Detection is deterministic and syntactic; no external indexers.
Spam transactions never enter the mempool and are never relayed. A node that still holds its original block files serves them byte-identically; once those are pruned it serves other Monetary Nodes rather than legacy ones — the same shape of limitation a pruned node already has, and one the network already handles. OP_RETURN stays capped at 83 bytes, as in Bitcoin Knots.
When two valid blocks land at the same height, the tie is broken on content rather than arrival time — the cleaner block is preferred and relayed onward, for a thirty-second window after which the race is considered settled. Most-work still decides the instant either chain is extended, so no block is rejected and nothing forks. Inside that window a miner who finds a cleaner block can take the reward from a spam-heavy one. Opt-in; not yet implemented.
From block 680,000, each node computes two state hashes per block — full state and clean state — bound with the block hash into a single paired commitment. Neither view can be faked or mismatched without detection. Miners can voluntarily notarize it under proof-of-work. No fork needed for any of it.
New nodes can start from a snapshot verified against a hash committed in the software release (the same trust model as Bitcoin Core's assumeutxo) — then download and fully validate the entire chain in the background, from monetary peers or any full node. Eventually every node has checked everything itself.
Spends of deleted outputs are fully validated by reconstructing the original from local block files, or fetching the old block over the existing P2P protocol and checking it against the block hash already validated. Nothing confiscated, nothing frozen, no new infrastructure assumed.
The cheapest fully validating node wins. No prohibition, no fork — just attrition, until running a spam node is a costly eccentricity.
As Monetary Nodes spread — adopted for the disk savings alone — unconfirmed spam propagates through a shrinking subgraph of the network. In the endgame they carry the chain forward between themselves: every block, every header, every proof-of-work, with the carriers absent and each removed transaction's ID retained so nothing can be misrepresented. The spam survives in the history books and in whatever archives choose to keep it, but no node is obliged to carry it to be a full node. Bitcoin remains money because its node operators choose, one by one, to run it as money.
The full design in plain language. Everything here is also specified formally in the BIP draft.
Detection is purely mechanical — no external services, no indexers, no judgment calls. Three rules, applied to raw transaction data:
Inscriptions. Ordinals hide data inside a script branch that provably never executes: a false value followed by OP_IF ... OP_ENDIF. Since the branch can never run, it has exactly one purpose — smuggling data. The rule catches any encoding of "false" (checked by script semantics, not byte matching), so trivial evasions don't work.
Stamps. Bitcoin Stamps abuse bare multisig outputs by stuffing data where public keys should be. The rule catches keys that aren't valid points or match known data-encoding patterns.
Token markers. OP_RETURN outputs carrying registered token-protocol identifiers (BRC-20 JSON, Runes markers), from a versioned list.
Any two implementations applying these rules to the same block must reach identical answers — that determinism is what makes everything downstream possible. Operators can add stricter local filters for relay, but those never affect the shared rules. Ordinary OP_RETURN up to 83 bytes is left alone: it's already provably unspendable and never enters the UTXO set.
A Monetary Node validates every block completely — every signature, every amount, every rule, identical to Bitcoin Core. Then, as each block connects:
Deleted: the content of spam outputs — the embedded data and its script — along with the witness data of any transaction that carried a carrier. Removed from the stored block record itself. This happens continuously, including during initial sync, so spam is never written to disk at any point in the node's life. A transaction left with no monetary output at all is reduced to its ID alone.
Kept forever: every block header (which contains every block hash — about 70MB for the whole chain, same as any node); a compact filter index recording each deleted output's ID, amount, and location (~48 bytes instead of up to tens of kilobytes); and the two state fingerprints described next.
Removed from blocks, not only from the database. This is what separates a Monetary Node from a node that merely declines to relay spam. Carrier bytes are absent from the stored block record itself — 37.2 GB across the era, 48.7 GB once the witness data of modified transactions is counted. What makes that safe is that a block's merkle root is computed over transaction IDs: keep the 32-byte ID of anything modified or discarded, and the block still reconstructs to the root in its own header. A fabricated ID produces a mismatch, so the retained list cannot be forged.
The originals go. Holding both is a migration step, not a destination. While converting, a node has its old block files and the filtered store side by side, and in that window it costs more disk rather than less. Delete the originals and the filtered store becomes the archive. Under a native implementation the question never arises: stripped blocks are what gets written in the first place.
What that costs. A converted node can no longer hand a legacy node complete historical blocks, because it does not have them. It serves other Monetary Nodes instead, over a sync protocol built for the filtered format. That is the real price of the saving, it is the same shape of trade a pruned node already makes, and it is the open question the design has to keep answering: somebody, somewhere, still has to hold complete history for as long as legacy nodes need to sync from genesis.
Deleting spam creates two legitimate views of the ledger's state: the full view (what a legacy node holds) and the clean view (what a Monetary Node holds). From block 680,000 — which predates inscriptions — every Monetary Node computes a running cryptographic fingerprint of each: the legacy state root and the monetary state root, using the same incremental hashing (MuHash) that Bitcoin Core already ships.
A subtle point: the node maintains the legacy fingerprint without storing the spam. Each spam output is hashed into the legacy accumulator at validation time, an instant before deletion. The fingerprint of the full state survives even though the full state isn't kept — and it stays maintainable even in a future with no legacy nodes at all.
The two roots are then bound together with the block hash into a single paired commitment: C = SHA256d(block hash ‖ legacy root ‖ monetary root). This marriage means no one can present a clean-state fingerprint that doesn't correspond to the real full state of the real chain — mix-and-match is detectable with one 32-byte comparison.
Reading the picture top to bottom: blocks arrive and are validated in full; money outputs flow into the monetary store, spam is hashed into the legacy root and then deleted (leaving a 48-byte index entry), and the whole block is archived unmodified. Both roots are folded into commitment C every block. The dashed loop on the right is the rare path: someone spends a deleted output, the original is reconstructed from the archive, and the spend is validated exactly like any other. An existing node can adopt all of this via a reindex — replaying its own block files to rebuild the filtered store and both hashes.
Deleted outputs remain spendable — deletion is a storage decision, never a validity decision. When a block spends one, the node reconstructs the original output and validates the spend completely:
First choice: read it from local block files (the default, since blocks are kept). Fallback: request the old block from any peer using the standard getdata message that has existed since 2009, verify it against the block hash already sitting in the node's validated header chain, and extract the output. Fully trustless, no new infrastructure.
To keep block processing fast, nodes pre-fetch the needed data when they first see the spend in a transaction (before it's mined), and cap concurrent historical fetches per block so a malicious block full of ancient spam spends can only slow one node's local timing — never affect validity.
Default path — full sync. Download every block from any peer, validate everything, delete spam as you go, compute both fingerprints and the paired commitment at every height. Monetary Nodes that keep block files serve them exactly like archival nodes, so a network of mostly Monetary Nodes syncs its own newcomers. Along the way, a syncing node can compare its paired commitments against other monetary peers — a divergence exposes a bug or a liar, but peer values are advisory only and never override local computation.
Fast path — snapshot. Modeled on Bitcoin Core's shipped assumeutxo feature, with the identical trust model. Each software release can commit to the hash of a clean-state snapshot at a checkpoint height — a hash anyone can independently recompute and audit, since the software is open source. A new node fetches the snapshot from any monetary peer, checks it against the release-committed hash (which includes the paired commitment, so a fabricated clean state can't masquerade as real), and is operational in minutes. Then, mandatorily, it downloads and fully validates the whole chain in the background — from monetary peers or any archival full node — and confirms the snapshot was honest. A bad snapshot cannot survive this. Until verification completes, the node doesn't serve snapshots to others.
The common objection is that a filtering node can't bootstrap others. It can bootstrap Monetary Nodes, and that is the claim being made here — not that it can serve a legacy node. It hands over every block, every header and every proof-of-work, with the carriers absent and the transaction ID of anything modified retained, so the receiver rebuilds each merkle root and checks it against the header it already has. Nothing is taken on trust. What it cannot do is hand a legacy node complete historical blocks, because it no longer holds them.
Nothing. There is one chain. Monetary Nodes accept every block a Core node accepts, follow the same most-work chain selection, and never reject a block for containing spam. The full hashrate of the network secures a Monetary Node exactly as much as it secures any other node. The two fingerprints are bookkeeping over the same chain — not competing chains.
The friction on spam is designed to increase with every operator who switches. Each new Monetary Node is one less machine relaying spam, one less mempool accepting it, one more peer that syncs newcomers without it. Meanwhile legacy nodes grow steadily more cumbersome to run — their block storage growing with every inscription, their sync times lengthening, their hardware demands climbing — while the monetary alternative gets comparatively cheaper every year. The economics compound in one direction: Monetary Nodes make up more and more of the network not because anyone mandates it, but because running the heavier node buys the operator nothing.
Alongside the economics runs the social layer. Bitcoin has always been governed, in the last instance, by what its node operators collectively refuse to subsidize — that is how every contentious era has ultimately been settled. As monetary policy becomes the network's default posture, the social consensus hardens with it: spam is not attacked, not confiscated, not forbidden — it is soundly rejected by the culture, starved of relay, starved of storage, and faded out into oblivion.
Everything above presses on node operators. A second loop runs on miners. Two blocks are sometimes found moments apart, and for a few seconds the network holds two valid candidates at the same height. Work decides — but when the work is equal the choice is arbitrary, and nodes simply keep whichever arrived first. Nothing in consensus rests on that convention.
A Monetary Node breaks the tie on content instead: at equal work it prefers the block carrying less spam, then follows most-work as normal the moment either chain is extended. No block is rejected. Nothing forks.
The window is thirty seconds. A block arriving after it closes cannot displace what is already there — by then the race is over, the network has settled, and switching would only mean reorging onto the side that lost. Inside it the tie is still live: a miner who finds a cleaner block at that same height, in those thirty seconds, can take the reward out from under a spam-heavy one. And the spammier the block sitting at the tip, the more it pays someone else to keep racing rather than build on it.
What makes it more than a gesture is relay. A node passes on the tip it holds, so the cleaner block travels and the other stops — and at scale that shifts which block reaches miners first. Then the arithmetic does the arguing. Spam is worth its fees, a slice of a slice; an orphaned block costs the entire reward. A miner carrying spam stakes 3.125 BTC to earn a rounding error on top.
Thin margins make that bite. Mining runs on a few points of spread, and a delta that reads as negligible in an argument is decisive on a spreadsheet. The decision is also remade every ten minutes, independently, by every pool, with no contract between them. A cartel that agreed to keep carrying spam would have to hold that line indefinitely against each member’s own interest — and it would have no punishment available, because there is no way to sanction a miner for producing a cleaner block.
Nothing here asks miners to cooperate, or to agree with the premise. They optimise revenue exactly as they always have. The network simply changes what that arithmetic returns.
The endgame has to keep three things alive, and two of them are already solved without full blocks. Spends of long-deleted outputs validate from the filter index: each removed output's ID, amount, script and height are retained, which is everything needed to check a spend locally with no peer involved. Across the inscription era, 7 of 806,626 removed outputs were ever spent, and all 7 validated. Syncing a new Monetary Node runs over the filtered format directly, peer to peer, with every block still verified against its own proof-of-work.
The third is the open one. A legacy node syncing from genesis needs complete blocks, and a converted Monetary Node does not have them. For as long as legacy nodes exist, somebody has to keep a full archive — and the honest position is that this is a question the design has to answer rather than one it has answered. The legacy fingerprint itself needs no legacy nodes at all: it is maintained by the monetary network, forever, so the two views stay comparable even when nobody is storing the spam.
The end state: spam is preserved in the history books, because Bitcoin's history is immutable — but no node is obliged to carry it in order to be a full node, and no one is left who will carry it forward.
Compact block relay: because spam never sits in a Monetary Node's mempool, relaying a spam-bearing block requires one extra round trip to fetch the missing transactions — tens of milliseconds, already borne by filtering nodes today.
Miners follow fees: this proposal doesn't bind miners, and direct-to-miner submission bypasses relay filtering entirely. What it changes is what every sovereign node operator subsidizes with their own disk and bandwidth — and it makes the refusal costless. The friction on spam grows with adoption; it is attrition, not prohibition.
Classification maintenance: the token-marker list is versioned and will need updates as protocols evolve. The inscription and stamp rules are structural and evasion-resistant by design.
Reference implementation planned as a Bitcoin Knots patchset — Knots already ships the datacarrier limits and inscription filters this design extends. Changes touch policy, indexing, and peer services only; consensus code is untouched. A Bitcoin Core port is invited. Test vectors for classification and state fingerprints will be published alongside.