Open any Bitcoin wallet and you see a single number: your balance. It looks exactly like a bank account. It is not one, and the difference explains almost every strange thing you will ever notice about a Bitcoin transaction.

Here is the surprising part: nowhere on the blockchain is there a line that says how much bitcoin you have. There are no accounts at all. Your wallet computes your balance by scanning the ledger for individual, unspent chunks of bitcoin that your keys can unlock, then adding them up.

Those chunks are called unspent transaction outputs, or UTXOs. Once you see them, fees, "change addresses", and slow-to-spend wallets all start making sense.

Bitcoin Has No Balances, Only Coins

The whitepaper is blunt about it. Section 2 defines an electronic coin as "a chain of digital signatures." Every transaction takes some existing outputs, consumes them, and creates new outputs locked to someone else. Each new output sits on the ledger, unspent, until its owner uses it as an input to a future transaction.

So a wallet "holding 0.08 BTC" might really be holding one 0.05 BTC output from a paycheck and one 0.03 BTC output from a friend. Two separate coins, each with its own history, each locked to a key in your wallet. The How Bitcoin Works overview introduces inputs and outputs in a single sentence. This article zooms in.

Analogy: Think of a wallet full of cash in odd denominations that cannot be torn. To pay $7, you hand over a $5 bill and a $3 bill, and the cashier hands you change. Bitcoin works the same way, except the "bills" can be any size, and you print your own change.

Anatomy of a Payment

Every transaction has the same three parts.

Inputs point to earlier outputs and unlock them. Each input names a specific previous transaction and which of its outputs is being spent, plus the proof that the spender is allowed to spend it, usually a digital signature. (How those signatures work is the subject of Private Keys and Public Keys in Plain English.)

Outputs create new coins. Each one carries an amount and a locking condition, typically "whoever can sign for this address."

The fee is not written down anywhere. It is simply the difference between what goes in and what comes out. The whitepaper puts it in section 6: if the output value of a transaction is less than its input value, the difference is a transaction fee. The miner who includes the transaction collects it.

Here is the payment from the diagram below, written out.

PartAmountWhere it goes
Input 10.05 BTCAn output you received earlier, now consumed
Input 20.03 BTCAnother earlier output, now consumed
Output 10.07 BTCThe recipient's address
Output 20.0098 BTCA change address in your own wallet
Fee (implicit)0.0002 BTC (20,000 sats)The miner who confirms it
Flow diagram of a Bitcoin transaction: two unspent outputs of 0.05 and 0.03 BTC are unlocked with signatures, combined as inputs totaling 0.08 BTC, then split into a 0.07 BTC payment output, a 0.0098 BTC change output, and a 0.0002 BTC fee left for the miner.
Inputs are consumed whole. Whatever the outputs do not claim becomes the miner's fee.

Converting those decimals into satoshis is easier with the BTC and sats converter, and it is how fees are usually quoted.

The Change Problem

The single most important rule of UTXOs: an output is always spent in full. There is no way to spend half of the 0.05 BTC coin and leave the rest sitting there. If you want to pay less than a coin is worth, you spend the whole thing and send the remainder back to yourself as a new output.

Section 9 of the whitepaper describes exactly this pattern: typically either one input from a larger previous transaction or several inputs combining smaller amounts, and at most two outputs, one for the payment and one returning the change, if any, back to the sender.

This is also where beginners have historically lost money. If you build a transaction by hand and forget the change output, the protocol does not warn you. The entire leftover becomes the fee. In the example above, dropping the change output would have handed the miner 0.01 BTC instead of 0.0002. Modern wallets handle change automatically, which is why you never see it unless you look the transaction up on a block explorer.

What Nodes Check Before Accepting a Spend

Every full node keeps its own copy of the current UTXO set, the full list of outputs that exist and have not yet been spent. When a transaction arrives, the node checks it against that list:

  1. Does every input point to an output that exists and is unspent? If not, it is either invalid or an attempted double spend.
  2. Does each input carry a valid unlocking proof? A missing or wrong signature means rejection.
  3. Do the outputs add up to no more than the inputs? Spending more than you put in would create bitcoin from nothing.

Passing those checks gets a transaction into the node's waiting area, covered in The Mempool. Once a miner includes it in a block, the spent outputs are deleted from every node's UTXO set and the new ones are added. Double spending is prevented not by tracking balances, but by the simple fact that a spent output no longer exists.

There is one special case. The first transaction in every block, the coinbase, has no real inputs: it creates the block subsidy and collects the fees. Bitcoin Core's consensus rules set COINBASE_MATURITY to 100, meaning those new coins cannot be spent until 100 more blocks have been built on top. That buffer protects the network if the block is later orphaned. What else sits inside a block is covered in What's Inside a Bitcoin Block.

Why Satoshi Chose Coins Over Accounts

Bank ledgers and some other blockchains, such as Ethereum, use an account model: one entry per user, adjusted up or down. Bitcoin's coin model has real trade-offs.

UTXO model (Bitcoin)Account model
What the ledger storesIndividual unspent outputsA running balance per account
Double-spend checkIs this exact output still unspent?Is the balance high enough, and is the ordering right?
PrivacyA fresh address for each payment and change is naturalOne account tends to collect all activity
Parallel validationIndependent outputs can be checked separatelyTransactions touching one account depend on each other
DownsideWallets must manage many coins and changeSimpler mental model for users

Privacy deserves a caveat. Section 10 of the whitepaper recommends a new key pair for each transaction, but also admits that multi-input transactions necessarily reveal that their inputs were owned by the same owner. Combining the 0.05 and 0.03 coins in our example tells anyone watching that both belonged to one wallet.

Why Small Coins Cost More to Spend

Fees are charged by data size, not by amount sent. Every input carries a reference and a signature, which makes inputs the bulkiest part of most transactions. A wallet that received fifty tiny payments must include many inputs to spend them, and pays for every byte.

That is why some wallets offer "consolidation": during quiet periods, when fees are low, they merge many small outputs into one larger output so future spends are cheaper. At the extreme, an output can be worth less than the fee needed to spend it. Such coins are often called dust, and they may never be economically worth moving.

What This Means for You

  1. Your balance is a sum, not a number on file. The wallet adds up the separate coins your keys can unlock, and each one has its own history.
  2. Change outputs are normal. Seeing a payment split into two outputs on a block explorer is expected, not a sign of a problem.
  3. Fees depend on size, not value. Sending $10 or $10 million can cost the same fee, while spending many small coins costs more.
  4. Consolidate when the network is quiet. If your wallet holds lots of small coins, merging them during low-fee periods is a common practice, with a privacy trade-off.
  5. Never hand-build a transaction without a change output. Whatever the outputs do not claim goes to the miner, permanently.

Bitcoin never asks how much you have, only which coins you can prove are yours.