Bitcoin Graffiti

a museum of data stored in the blockchain work in progress

Metaprotocols On Bitcoin

A metaprotocol is a second protocol layered on top of Bitcoin: it tracks its own ledger — user-issued assets, transfers, exchange orders, notarizations, identities — by hiding that state inside ordinary Bitcoin transactions. Bitcoin nodes ignore the extra bytes; only a separate metaprotocol parser reads them. This is the bridge between one-off graffiti and structured on-chain data, and a direct ancestor of later OP_RETURN tokens and inscriptions.

timeline

Earliest On-Chain Footprint Of Each Protocol

18 protocols

Each protocol’s earliest known transaction, in chronological order. The Mastercoin and Counterparty births are plain payments to special addresses and carry no readable marker, so their first decodable message comes weeks later (see their sections). Protocols that embed no marker — like OpenTimestamps, which commits a bare 32-byte hash — cannot be identified on-chain, so they cannot be enumerated here and are not listed. Click a protocol name to jump to what it is and everything else we know. Identifications are cross-checked against Bartoletti & Pompianu (2017).

ProtocolMarkerCategoryEventDateBlockTx
Proof of Existence DOCPROOF Notary Address-encoded genesis 2013-06-01 238,958 7b2fba67f0e2…
Mastercoin / Omni omni Assets Exodus fundraiser genesis 2013-07-31 249,498 546a406a1310…
Counterparty (XCP) CNTRPRTY Assets Proof-of-burn genesis 2014-01-02 278,319 685623401c3f…
Open Assets OA Assets First OA colored-coin marker 2014-05-04 299,079 1cbcd3bdb11e…
Blocksign BS Notary First Blocksign document 2014-08-04 313,954 c94037aa5038…
University of Nicosia UNicDC Credentials First academic-certificate batch 2014-09-12 320,303 88272f605d1f…
ascribe ASCRIBE Digital art First ascribe registration 2014-12-19 334,920 c405ee00f260…
CoinSpark SPK Assets First CoinSpark transaction 2014-12-25 335,857 598c213f0aa0…
Blockai 0x1f00 Digital art First Blockai registration 2015-01-09 338,235 a5ca4a0caa8d…
Stampery S1–S5 Notary First Stampery anchor 2015-03-09 346,882 6bc8560e54d9…
Eternity Wall EW Publishing First EW message 2015-06-24 362,372 a3b3af21514b…
Monegraph MG Digital art First Monegraph registration 2015-06-27 362,832 43648d91d589…
Colu (Colored Coins) CC Assets First Colu colored-coin 2015-07-09 364,548 3e2a994eaa06…
Blockstore (Blockstack / Onename) id Identity First on-chain id: registration 2015-07-26 367,001 a06998de2693…
Factom Fa Data anchoring First Factom anchor (Fa marker) 2015-08-26 371,653 91811e2993e0…
Stacks (STX) id$ → X2 Consensus First STACKS token transfer 2018-10-04 544,406 2023a1dc2901…
Runes OP_13 Assets First runestone — the etching of Z•Z•Z•Z•Z•FEHU•Z•Z•Z•Z•Z 2024-04-20 840,000 2bb85f4b004b…
pwm1 pwm1: Messaging First message — "Hello World!" 2026-05-07 948,283 8e9e7ff3817b…

† genesis predates the marker detected here; the date shown is the earliest occurrence within the scanned blocks (100000–399999). Every protocol is also browsable in Archive → OP_RETURN protocols.

address → OP_RETURN

Proof of Existence

Notary

Marker DOCPROOF · first seen 2013-06-01 (block 238,958) · 7b2fba67f0e2…

Proof of Existence (Manuel Aráoz & Esteban Ordano) is a pure notarization protocol: it proves a document existed at a given block time by anchoring the document’s SHA-256 on-chain, while the document itself stays off-chain.

It actually predates OP_RETURN. The original 2013 genesis (block 238958, 2013-06-01) had no data output at all — it split the 32-byte document hash across two 1-satoshi pay-to-pubkey-hash addresses (12 bytes + 8 zero-padding in one, 20 bytes in the other). A clean run of 115 such transactions spans 2013-06 to 2014-02.

It stops exactly when the service migrated to the cleaner DOCPROOF OP_RETURN format (first seen block 296884, 2014-04-20) once OP_RETURN became relay-standard: the marker DOCPROOF followed by the 32-byte document hash.

↳ 2014-04-20 (block 296,884) — First DOCPROOF OP_RETURN notarization · 0df78936daca…

Class A/B/C

Mastercoin / Omni

Assets

Marker omni · first seen 2013-07-31 (block 249,498) · 546a406a1310…

The idea came first in writing: J.R. Willett’s January 2012 "The Second Bitcoin Whitepaper" argued that a richer protocol — user-issued currencies, a distributed exchange, savings, betting — could be layered on top of Bitcoin without changing Bitcoin itself, simply by encoding the new protocol’s data inside ordinary transactions.

It went live on 2013-07-31 (block 249498), when the Exodus address 1EXoDusjGwvnjZUyKkxZ4UHEf77z6A5S4P received its first funds. Sending bitcoin to Exodus during the month-long fundraiser minted Mastercoin (MSC); roughly 5000 BTC was raised. That transaction is the earliest metaprotocol footprint on Bitcoin .

Mastercoin tried three encodings in turn: Class A spread bytes across several send-to-address outputs, Class B used bare-multisig fake public keys, and Class C — once OP_RETURN was standardized — used a clean data output. Only Class C carries a human-readable marker, which is why the earliest text-detectable hit ("Mastercoin encoding v3-test", block 292316, 2014-03-24) is eight months later than the real genesis. The first Class A and Class B transactions remain unlocated — their payloads are XOR-obfuscated with a key derived from the sender’s address, so they are indistinguishable from random noise without a dedicated Mastercoin decoder.

Mastercoin rebranded to Omni Layer in 2015. Its most consequential tenant was Tether (USDT): the largest stablecoin first launched on Omni in late 2014, so for years the dominant dollar token on any blockchain lived inside Bitcoin transactions as Omni metaprotocol data.

↳ 2014-03-24 (block 292,316) — First plaintext OP_RETURN marker ("Mastercoin encoding v3-test") · 20f5f386bf6a…

See also: Exodus genesis
P2FMS / OP_RETURN

Counterparty (XCP)

Assets

Marker CNTRPRTY · first seen 2014-01-02 (block 278,319) · 685623401c3f…

Counterparty launched on 2014-01-02 (block 278319) with a "proof of burn": there was no premine and no sale, so to create the native token XCP people sent bitcoin to the provably-unspendable address 1CounterpartyXXXXXXXXXXXXXXXUWLpVr. Over the burn window (2014-01-02 to 01-12) about 2140 BTC were destroyed in exchange for XCP. The very first burn is the genesis entry here.

Protocol messages followed days later. Counterparty marks its data with the 8-byte magic CNTRPRTY (first seen block 280091, 2014-01-12), originally tucked into bare-multisig outputs and later moved to OP_RETURN; payloads are lightly obfuscated with ARC4. On top of this it built user asset issuance, a fully on-chain decentralized exchange, dividends, broadcasts/oracles, and betting.

Culturally it mattered far beyond finance. The first notable assets built on top of Counterparty are catalogued here in order of issuance:

FoldingCoin (FLDC, block 320237, 2014-09-12) rewards contributors to the Folding@home distributed computing project with a Counterparty token — an early example of using a blockchain token as an incentive mechanism for scientific computing.

Spells of Genesis (FDCARD, block 347173, 2015-03-11) is the first blockchain trading card in a video game. EverdreamSoft and FoldingCoin jointly issued 300 FDCARD tokens on Counterparty; players could earn cards by sharing compute power, then trade them as provably-scarce assets on the Counterparty DEX.

Rare Pepe (RAREPEPE, block 428919, 2016-09-09) — the Nakamoto Card, Series 1 Card 1 — is the first of 1,774 cards in the Rare Pepe Directory, a curated collection of Pepe the Frog meme art issued as Counterparty tokens. 300 editions were created by an anonymous artist known as "Mike." One sold for $500,000 on OpenSea in 2021. Rare Pepe is widely regarded as the direct ancestor of the NFT art market.

Age of Chains (GUARDIANCARD, block 440240, 2016-11-23) issued "Woodcoin’s Guardian" as the first of its sci-fi trading card game series — 777 copies, non-divisible, on Counterparty. All four of these predate Ethereum’s ERC-721 standard (2018) and are, in a real sense, the original NFTs.

↳ 2014-01-12 (block 280,091) — First CNTRPRTY protocol message (bare multisig) · 1c20d6596f6b…

OP_RETURN

Open Assets

Assets

Marker OA · first seen 2014-05-04 (block 299,079) · 1cbcd3bdb11e…

Open Assets (Flavien Charlon) is the original colored-coins protocol on OP_RETURN: a marker output (prefix OA) "colors" specific satoshis so they represent issued or real-world assets — shares, tokens, vouchers — tracked by an Open Assets parser rather than by Bitcoin itself.

Arriving just after OP_RETURN was standardized, it was the first widely-used pure-OP_RETURN asset layer, and a template many later asset protocols (including Colu) refined.

OP_RETURN

Blocksign

Notary

Marker BS · first seen 2014-08-04 (block 313,954) · c94037aa5038…

Blocksign signs and timestamps documents on-chain — one of the earliest document-notary services. Each transaction carries the BS prefix followed by a document hash, proving a specific file was signed at a given block time.

OP_RETURN

University of Nicosia

Credentials

Marker UNicDC · first seen 2014-09-12 (block 320,303) · 88272f605d1f…

The University of Nicosia (Cyprus) was the first university to anchor academic certificates on Bitcoin. Certificates for its DFIN-511 "Introduction to Digital Currencies" MOOC — the first university course on cryptocurrency — are batched into a Merkle tree whose root is published in an OP_RETURN marked UNicDC (later a CRED-wrapped format), with the individual certificates kept off-chain.

It is more than a notary: beyond issuance (the Merkle-root anchor), the protocol manages a full credential lifecycle — it can revoke previously issued certificates and record other certificate-management operations on-chain — so notarization is just its underlying primitive. The system later grew into the spin-out Block.co.

The earliest UNicDC batch on-chain is block 320303 (2014-09-12), matching the protocol’s documented genesis; the run continues with the certificates CoinDesk reported a few days later.

OP_RETURN

ascribe

Digital art

Marker ASCRIBE · first seen 2014-12-19 (block 334,920) · c405ee00f260…

ascribe registers and transfers ownership of digital artworks, giving creators on-chain provenance and limited editions. Marked ASCRIBE, it later formalized its scheme as the SPOOL (Secure Public Online Ownership Ledger) standard.

OP_RETURN

CoinSpark

Assets

Marker SPK · first seen 2014-12-25 (block 335,857) · 598c213f0aa0…

CoinSpark layered two things on top of ordinary Bitcoin transactions: user-issued assets, and encrypted peer-to-peer messaging attached to a payment. Its transactions carry the SPK marker.

OP_RETURN

Blockai

Digital art

Marker 0x1f00 · first seen 2015-01-09 (block 338,235) · a5ca4a0caa8d…

Blockai offered copyright registration for digital creators, anchoring a content hash to prove authorship and time. Unusually, its payload leads with the raw bytes 0x1f00 rather than an ASCII marker.

OP_RETURN

Stampery

Notary

Marker S1–S5 · first seen 2015-03-09 (block 346,882) · 6bc8560e54d9…

Stampery notarizes batches of documents by anchoring a single Merkle root on-chain, so one transaction can certify thousands of files. Its marker is "S" plus a version digit — S1 through S5 over time — followed by two bytes identifying the broadcasting server, then the 32-byte root.

Its Blockchain Timestamping Architecture (BTA) later generalized across multiple chains, but it began here on Bitcoin.

OP_RETURN

Eternity Wall

Publishing

Marker EW · first seen 2015-06-24 (block 362,372) · a3b3af21514b…

Eternity Wall is the simplest protocol of all — permanent short public text messages with an EW prefix. It shows OP_RETURN used not as protocol plumbing but as a direct publishing carrier: a public wall where anyone can leave a permanent, censorship-resistant message.

OP_RETURN

Monegraph

Digital art

Marker MG · first seen 2015-06-27 (block 362,832) · 43648d91d589…

Monegraph registers ownership and provenance of digital media. It was co-founded by Kevin McCoy — who in 2014 created "Quantum", generally recognized as the first NFT — with writer and entrepreneur Anil Dash. Its transactions carry the MG marker followed by a media fingerprint.

OP_RETURN

Colu (Colored Coins)

Assets

Marker CC · first seen 2015-07-09 (block 364,548) · 3e2a994eaa06…

Colu’s redesigned Colored Coins scheme (open-sourced June 2015) is a compact OP_RETURN encoding marked CC that references bulk metadata via torrent files. It was a higher-throughput, more expressive successor to Open Assets and one of the busiest OP_RETURN protocols of its era.

OP_RETURN

Blockstore (Blockstack / Onename)

Identity

Marker id · first seen 2015-07-26 (block 367,001) · a06998de2693…

Blockstore — the forerunner of Blockstack (now the Stacks project) and the Onename directory — registers decentralized identities and human-readable usernames on-chain, in the form "id:alice.id". It is the ancestor of an entire decentralized-identity ecosystem.

† The documented genesis (2014-12) used a binary marker (0x5888 / 0x5808) that falls into the scan’s "other" bucket; the readable id: form shown here begins 2015-07.

The same "id" magic later carried the STACKS token under a new opcode, and was eventually replaced by the "X2" marker of Stacks 2.0 — see Stacks (STX) below.

OP_RETURN

Factom

Data anchoring

Marker Fa · first seen 2015-08-26 (block 371,653) · 91811e2993e0…

Factom maintains a separate chain of structured data entries and periodically anchors their Merkle roots to Bitcoin, letting applications publish large datasets cheaply while inheriting Bitcoin’s security for the anchor.

† Factom’s genesis (2014-04, "Factom!!" marker) used a "Factom!!" marker; the shorter "Fa" marker shown here begins in 2015-08.

OP_RETURN

Stacks (STX)

Consensus

Marker id$ → X2 · first seen 2018-10-04 (block 544,406) · 2023a1dc2901…

Stacks is what Blockstore above grew into: a separate blockchain that keeps its consensus on Bitcoin rather than merely notarizing into it. Its two generations are visible here as two different markers, which is why one protocol appears under two names in the scan.

Stacks v1 (2018) kept Blockstack’s original "id" magic and simply added an opcode. Name operations use "id:" / "id+" / "id?"; the token uses "id$", and it is that opcode which dates the STACKS token’s arrival on Bitcoin — 12,437 transfers, the first at block 544406 (2018-10-04). The payload is self-describing: a 16-byte consensus hash, the token type right-aligned as ASCII (literally "STACKS"), an 8-byte amount, then a free-text memo. The very first one carries 100 units and the memo "multi-sig testing", so the token’s on-chain debut is, fittingly, someone testing it.

Stacks 2.0 (2021) replaced that with its own 2-byte magic "X2" plus a 1-byte opcode, and moved from naming to mining: "[" leader block-commit, "^" leader key register, "p" pre-stx, "$" transfer-stx, "x" stack-stx, "#" delegate-stx. This is Proof of Transfer — a miner bids by spending BTC, and instead of burning it the bid is paid to holders who have locked their STX. A block-commit is therefore easy to recognise from its shape alone: the OP_RETURN, then two equal-value outputs to those stackers. The first one, at block 666057, pays 27,781 satoshis to each of two addresses.

That marker makes Stacks the largest identified metaprotocol on Bitcoin by transaction count: hundreds of thousands of operations since block 666057, more than Counterparty and Omni combined.

One curiosity is visible in the OP_RETURN burns tab. Between 2022-12 and 2023-03, 25,679 block-commits placed value directly on the OP_RETURN output itself rather than leaving it at zero — destroying 1.41 BTC outright, mostly in fixed 5,500-satoshi amounts, across many different miners. Why the coins went there rather than to the usual reward outputs is not settled.

↳ 2021-01-14 (block 666,057) — Stacks 2.0 mainnet — first Proof-of-Transfer block-commit · cca5fae2322a…

OP_RETURN

pwm1

Messaging

Marker pwm1: · first seen 2026-05-07 (block 948,283) · 8e9e7ff3817b…

Nearly every protocol on this page exists to track ownership — of tokens, names, documents, or blocks on another chain. pwm1 tracks a conversation. It is mail: two correspondents writing to each other in OP_RETURN outputs, addressing each other in email form (bitcoin@proofofwork.me, satoshin@proofofwork.me), quoting replies, signing messages and sending attachments. The chain is used not as a ledger but as a transport that cannot drop a message or delete a mailbox.

The format is a colon-delimited envelope after the "pwm1:" marker, with four record types. "m" carries a message. "r" is a reply, and opens with the 64-character SHA-256 hash of the message it answers — that hash is the threading, the equivalent of an In-Reply-To header. "s" carries a base64 signature. "a" is an attachment: a base64url header giving MIME type, filename and byte count, followed by the file itself in base64.

Two files have been sent this way — PROOFOFWORK_IDS.md, 9,324 bytes of Markdown, and a 6,284-byte JPEG named "pepe mic drop.jpeg". Sending a file as base64 inside a data output is expensive and slow, which is rather the point: the sender is paying for delivery that no intermediary can refuse.

The exchange runs from block 948283 to 962976 and reads like any technical correspondence — greetings, wallet debugging, a complaint that transfers appear in the mempool but not in the transfer log, discussion of an order book. Mid-thread the two run a "DRAIN credit" experiment: an address whose private key is deliberately published, so that anyone may sweep it and the sweeping itself becomes the accounting. It worked. Roughly 1.136 BTC has passed through that address across 291 transactions.

It is the youngest protocol here and the smallest by volume, and unlike the others it has no whitepaper, no token and no company. Whether anyone else ever adopts it, the exchange itself is now as permanent as the whitepaper stored a decade earlier.

See also: The full exchange
OP_RETURN

Runes

Assets

Marker OP_13 · first seen 2024-04-20 (block 840,000) · 2bb85f4b004b…

Runes is a fungible-token protocol that switched on at block 840000 — the fourth halving — and immediately became the largest metaprotocol Bitcoin has carried. In its first 10,000 blocks it produced 26,158,164 OP_RETURN transactions: more than every other protocol on this page combined, across all fifteen years of them.

It is also the only protocol here whose identity is an opcode rather than a marker. A runestone is OP_RETURN OP_13 followed by a single data push, and everything meaningful is in that OP_13; the payload itself opens with an ordinary varint that any binary data could start with. That makes runestones easy to miss: anything reading only the pushed bytes sees a payload starting with an ordinary varint and has no way to tell a runestone from any other binary data. The opcode is the whole signature.

The body is a sequence of LEB128 varint tag/value pairs. The overwhelming majority are mints — tag 20 twice, carrying the block and transaction index of the rune being minted — which is why so many runestones are only seven bytes long.

The first one is not a mint but an etching, and it is the rune everyone remembers: Z•Z•Z•Z•Z•FEHU•Z•Z•Z•Z•Z, symbol ᚠ (U+16A0, the runic letter fehu, "wealth"), divisibility 2, premine 11,000,000,000, and terms offering 1,111,111 mints of 100 each. It sits in the halving block itself.

Ordinals inscriptions, the other half of the 2023–24 wave, work differently: an inscription hides in the witness — the signature data segregated from the transaction body — while a runestone is an ordinary output anyone parsing transactions will see. That difference in where the bytes live is why the two are usually catalogued apart.

Encoding evolution: the earliest metaprotocols smuggled data through bare multisig (P2FMS) and fake addresses, which bloat the UTXO set forever. OP_RETURN, standardized in Bitcoin Core 0.9 (March 2014), gave a provably-unspendable data output; Mastercoin (Class C) and Counterparty both migrated to it, and the protocols below were born on it. The same move — from data hidden in payment fields to data in an explicit output — later led to witness-data and Ordinals inscriptions.