RUN NODES
Be an independent
part of the network.
Run publicly listening nodes. Make them reachable on IPv4, Tor, and I2P. More independently operated peers give the network more real choices.
BITCOIN NETWORK RESEARCH / 2024—2026
Bitcoin counts reachable nodes.
But who’s on the other end?
A two-year experiment exposing the gap between IP diversity and operator diversity in Bitcoin’s peer-to-peer network.
Different IPs. Different subnets. Different autonomous systems. On the surface, a diverse set of Bitcoin peers.
Behind them, one person. The experiment tested a simple assumption: that diversity in network addresses translates into diversity in control.
Distinct IPv4 subnets
AS12029 · AS29798 · AS401199
Separate address-group boundaries
ASMAP groups addresses by autonomous system. It does not establish who operates the peers.
Historical experiment addresses. Each /24 sits inside a different /16.
45.40.98.0/24103.47.56.0/24173.46.87.0/24206.206.109.0/2489.106.27.0/24174.140.231.0/24184.174.95.0/24216.107.135.0/2466.163.223.0/24103.246.186.0/24123.100.246.0/24203.11.72.0/24
Built with refurbished hardware and a familiar infrastructure stack. Thirty-six full node instances served 3,042 public endpoints.
THE ACTUAL HARDWARE THE COST OF LOOKING DECENTRALIZED
Reported operating cost. One person running the entire operation.
Architecture and cost estimates: Joe Antek. Hardware purchases and owned IP blocks are capital assets, separate from monthly operating cost.
The network treated the endpoints as separate peers. The connection data exposed how concentrated those relationships could become.
Operator-reported measurements. The 80,526 / 35,127 connection snapshot is dated 30 March 2026.
653 source IPs had at least eight connections to this infrastructure. Joe reported intervals when some peers’ outbound connections all reached his nodes.
Connection counts alone do not establish a complete eclipse: one source IP can represent multiple nodes, and other connection types may exist.
Download reported metricsOf all clearnet reachable nodes, according to Bitcoin Core developer darosior’s December 2025 estimate. Reachability was measurable. Independent ownership was not.Read the original discussion
Researchers were investigating in 2025. BIP 110 signalling brought wider public attention in March 2026. Community observation made the common operator visible.
One /24. A question about peer identity.
darosior investigates misbehaving nodes.
instagibbs spots “dont-spam-me-bro” nodes.
Network monitors record the expansion.
Peer selection and eclipse resistance.
Followed by wider public attention in late March.
// A discussion about outbound peer selection
jonatack: yes, he does seem quite confused about how all of this work, but i must hand it to him that i expected us to be more robust than that and his mainnet experiment demonstrated it to me
I think this guy could cause some damage if he withheld blocks, even if only for 10 minutes...
Definitely
<darosior>Some background for this is that this summer i looked into an entity that was spinning up a large number of fake nodes (see https://antoinep.com/posts/misbehaving_nodes/). I and a few others are now in discussion with the guy running this operation. He has since then scaled up and now controls 3000 reachable nodes, which is about 30% of all clearnet reachable nodes. As a result when you spin up a new nodes nowadays it would most of the time have around 3 outbound connections to this guy. We've had multiple reports of this happening. So all this to say my concern is not purely theoretical, there is an entity actively trying to demonstrate it, which is reasonably successful so far. This is discussed at b10c's https://bnoc.xyz/ forum. See https://bnoc.xyz/t/increase-in-the-number-of-reachable-ipv4-nodes-bitprojects-io/45/9 and https://bnoc.xyz/t/satoshi-29-1-0-dont-spam-me-bro-nodes/40/18
Timeline: BTC Helsinki presentation. Initial investigation ↗ · BNOC monitoring thread ↗
The infrastructure went offline on 31 March 2026.
Thousands of peers had to find a different other end.
Reported inbound connections → experiment offline


b10c reported approximately 220 additional IPv4 peers across his monitors after the shutdown.
Read the shutdown observationsThe goal: always have a connection to at least one honest node.
These are directions for stronger peer diversity and further research.
RUN NODES
Run publicly listening nodes. Make them reachable on IPv4, Tor, and I2P. More independently operated peers give the network more real choices.
CONNECT TO HONEST NODES
Maintain a connection to an independently operated, honest node. Add Tor and I2P connections for network diversity, and look beyond IP counts when assessing your peers.
USE A BEACON
Develop in-band probes that help detect when different endpoints lead to the same node or entity. A beacon is a research proposal for ongoing measurement.
Joe proposes increasing outbound connections from 12 to 48–64. The capacity cost and effects on the network graph need evaluation; a higher count alone does not guarantee independent peers.
Follow the discussionJOE ANTEK / BITPROJECTS
Independent research. Real infrastructure. Public findings.
Available for publicly disclosed research and engineering engagements.

Original files extracted without modification. Appendix captures reflect different observation times; their counts may differ from the reported summary.
Server rack photograph SLIDE 04 / image.jpeg
Shutdown: outbound to bitprojects SLIDE 07 / image.png
Shutdown: inbound on monitors SLIDE 07 / image2.png
Project QR code SLIDE 08 / image3.png
Connection threshold snapshot SLIDE 09 / image2.jpeg
30 March connection snapshot SLIDE 10 / image3.jpeg
Full server rack photograph SLIDE 11 / image4.jpeg
Traffic flow Sankey SLIDE 12 / image4.png
Traffic by transit and country SLIDE 13 / image5.png
Traffic overview SLIDE 14 / image6.png
Reachable nodes by ASN SLIDE 15 / image7.png
Traffic distribution SLIDE 16 / image8.png
Traffic distribution SLIDE 17 / image9.png
Traffic distribution SLIDE 18 / image10.png
Aggregate traffic SLIDE 19 / image11.png
Traffic detail SLIDE 20 / image12.png
Traffic detail SLIDE 21 / image13.png
Traffic peak detail SLIDE 22 / image14.png
Traffic event detail SLIDE 23 / image15.png
Traffic flow Sankey SLIDE 24 / image16.png
Traffic flow Sankey SLIDE 25 / image17.png
Terminal connection snapshot SLIDE 26 / image18.png
Terminal connection snapshot SLIDE 27 / image19.png
Terminal connection snapshot SLIDE 28 / image20.png