You're auditing a wallet. Block 9, 50 BTC, an address that received coins before most people had heard the word "blockchain." No private key. No seed phrase. No recovery court, no customer support line, no override mechanism of any kind. The coins sit there, held by a lock that no one on earth can open. They will never move. And yet, in a narrow technical sense, something keeps happening to them.
Not to the coins themselves. To the question of what they mean.
The Lock That Outlasts Its Owner
Every bitcoin output is protected by a script. The most common version, P2PKH (Pay-to-Public-Key-Hash), states a simple condition: to spend this output, prove you control the private key corresponding to this address. No proof, no spend. The network enforces this absolutely.
When no one controls the private key, the output becomes what researchers call "provably unspendable," or more loosely, permanently lost. The UTXO (unspent transaction output) remains in every full node's UTXO set, dutifully tracked, forever unspent. It doesn't decay. It doesn't expire. Bitcoin has no garbage collection.
Satoshi Nakamoto's early mining addresses are the most cited example. Hundreds of thousands of coins from the network's first months sit in addresses bearing the fingerprints of the original mining software, and they have never moved. Whether Satoshi is unable or simply unwilling, nobody knows. That ambiguity matters, and we'll get to it.
So What About Fees?
This is the part that trips people up.
Bitcoin outputs don't accumulate fees the way a savings account accumulates interest. There is no passive accrual, no rent collected on dormant UTXOs, no money flowing into locked addresses. If you have read otherwise, the claim requires unpacking, and the unpacking is not flattering to the claim.
Fees are created at the moment a transaction is broadcast: the sender constructs inputs that exceed the outputs, and the difference is claimed entirely by whichever miner includes that transaction in a block. One reading of the "lost coins accumulate fees" confusion is that people conflate the block reward with some notion of passive accrual. Another is that they're thinking of OP_RETURN outputs or deliberate burn patterns, where small amounts are intentionally rendered unspendable. Neither mechanism involves fees flowing into locked addresses. The real economic story is different, and considerably more interesting than the myth.
The Deflationary Pressure Nobody Voted For
Bitcoin's protocol caps supply at roughly 21 million coins, baked into an issuance schedule that halves every 210,000 blocks. But the circulating supply, the coins that could actually move tomorrow, is meaningfully smaller than that cap.
Estimates are hard to pin down. Credible blockchain analytics firms have placed the figure of coins unmoved for a decade or more at somewhere between 3 and 4 million BTC. Some belong to long-term holders who are simply patient. Some belong to the dead. Some belong to people who forgot a password. And some belong to addresses where the controlling key never existed in any recoverable form.
Those coins act as a permanent, involuntary reduction in effective supply. Think of it like a river delta silting up: the channel looks the same on the map, but the navigable water keeps narrowing. Every new coin entering circulation, whether from mining rewards or from a long-dormant wallet finally waking up, gets absorbed by a market already operating against a tighter-than-advertised float.
Nobody designed this. It emerged from the combination of perfect scarcity and imperfect humans, and it is, in my reading, the most underappreciated structural feature of bitcoin's economics.
Two Buyers, One Block, Very Different Outcomes
Consider two people who each acquired one bitcoin at the same moment and moved it to self-custody. Call them Priya and Marcus. Priya wrote her seed phrase on paper, laminated it, and stored it in a fireproof safe. Marcus memorized his, confident he would never forget it, and told no one.
Five years later, Priya's coins are exactly where she left them, retrievable on demand. Marcus suffered a serious illness that erased that particular memory. His coins are gone: not gone from the blockchain, gone from the reachable economy. The UTXO still exists in every node on the network. It simply cannot be touched.
The blockchain recorded both positions identically. It cannot distinguish between Marcus's lost wallet and Priya's cold storage. That is the fundamental opacity at the center of this problem, and it is precisely why any published estimate of "lost bitcoin" deserves to be read as inference, not measurement.
The Honest Caveat
Here is what serious analysts will tell you: you cannot prove a coin is permanently lost from the outside. You can only observe that it has not moved, and assign probability to that silence.
A coin unmoved for thirteen years is probably lost. A coin unmoved for two years might be cold storage held by a very patient institution. The longer the silence, the higher the probability of loss, but that probability never reaches certainty until the owner is confirmed dead with no heirs and no backup. And even then, if someone finds a paper wallet in a drawer twenty years from now, those coins will move.
Ask yourself: how many estate lawyers have clients who don't know what they inherited? The tails on this distribution are long.
The OP_RETURN case is cleaner. Outputs with OP_RETURN in their script are provably unspendable by design, used to embed data on-chain or to execute a deliberate burn. Those can be counted with something approaching certainty. Everything else is inference, and honest analysis should say so plainly.
What Miners Actually Collect
To be precise about the mechanism: miners collect the arithmetic difference between transaction inputs and outputs, plus the block subsidy from new issuance. That is the complete list. They are not drawing from any pool of locked coins, and no locked coin contributes so much as a satoshi to any miner's revenue.
The economic consequence of permanent coin loss runs through a different channel entirely. As more coins become unreachable, effective scarcity increases beyond what the protocol alone produces. Each halving tightens new issuance. Each lost coin tightens existing supply. Both forces move in the same direction, but only one of them was planned. The other is a byproduct of human fallibility operating inside a system with no error correction.
If you run a full node, you are carrying every one of those locked UTXOs in your database right now. A network of thousands of computers faithfully maintaining a record of money that will never move again, not because the protocol requires the sentiment, but because bitcoin simply does not know how to forget.