Data written onto a satoshi through the Ordinals protocol. An inscription can contain text, images, audio, video, or other content, and it is stored on the Bitcoin blockchain rather than referenced externally, which gives it strong persistence and makes it difficult to modify later.
How inscription works on Bitcoin
An inscription is data embedded directly onto a satoshi through the Ordinals protocol. Because the content is written on-chain rather than stored as an off-chain reference, the inscription becomes part of Bitcoin’s transaction history and inherits the network’s persistence and immutability properties.
This matters because the content is not just “pointed to” by a hash or URL. It is recorded as blockchain data, so later alteration is not a normal edit operation, and durability depends on Bitcoin node validation and chain retention rather than a separate hosting system.
What can be inscribed
Inscription payloads are flexible. They may include plain text, images, audio, video, or other file types, which is why inscriptions are often discussed as a way to attach arbitrary content to a satoshi. The practical effect is that the satoshi becomes the carrier for a specific piece of encoded data.
That flexibility also creates a conceptual difference between the asset and the content. The bitcoin unit is still a bitcoin unit, but the inscription adds an extra data layer that can be culturally, economically, or technically significant depending on how it is used.
Why inscriptions are persistent
Inscription content is durable because it is anchored to Bitcoin’s distributed ledger rather than an external server. If the underlying transaction remains valid and the chain remains accessible, the content remains discoverable through the protocol’s indexing and interpretation rules.
That persistence can be an advantage for provenance, collectibles, and long-lived records, but it also means the content is difficult to revise, retract, or curate after publication. In practice, this makes the original inscription decision unusually final compared with conventional web publishing.
How inscriptions differ from ordinary metadata
Ordinary metadata usually lives outside the asset and can be updated, deleted, or re-hosted. An inscription is different because the data is committed as part of the blockchain record itself. The distinction is not just technical, it changes the trust model for anyone relying on the content.
For readers, the key question is whether the content should be treated as durable published data or merely as an associated reference. With inscriptions, the answer is durable published data, and that has implications for storage cost, public visibility, permanence, and the difficulty of correction once written.
Risk and Threat Considerations
Inscriptions create persistence benefits, but the same permanence can amplify exposure if the content is sensitive, mistaken, unlawful, or harmful. Once data is written into a blockchain transaction, removal is not operationally simple, and downstream indexing can preserve access long after the original author would prefer to withdraw it.
Failure mechanism: The main failure mode is irreversible publication of content that should not have been committed on-chain, or later discovery that the inscription embedded data with privacy, legal, moderation, or reputational consequences. Because the data is durable and broadly replicated, ordinary deletion controls do not apply.
Impact: The result can be permanent exposure, governance difficulty, and costly remediation effort. In some cases, the issue is not the blockchain itself but the decision to place the wrong data on it in the first place.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.DS-01 — Data-at-rest is protected | Inscription permanence makes data handling and retention central. |
| GV.OC-03 — Cybersecurity is managed as a source of enterprise risk | Public chain publication creates business, legal, and reputational risk decisions. | |
| Recommendation — Classify inscription payloads before publication and restrict durable data to approved content. Require a risk decision for any on-chain publication with lasting visibility. | ||
| ISO/IEC 27001:2022 | A.5.12 — Classification of information | Inscription suitability depends on whether data is appropriate for immutable public storage. |
| A.8.10 — Information deletion | The term highlights the practical limits of deleting data once written on-chain. | |
| Recommendation — Apply information classification before writing content to an inscription. Avoid placing information on-chain when later deletion or correction may be needed. | ||
| GDPR | A.8.24 — Use of cryptography | Where personal data is involved, public blockchain publication can intensify privacy risk. |
| Recommendation — Assess whether any personal data belongs in an inscription before publishing it. | ||
Practitioner Guidance
What to watch for: Treat inscription content as permanently public unless you have a very clear reason and legal basis to publish it. The important judgment is not whether the data can be technically written, but whether it is appropriate to make that data durable and globally replicated.
Practitioner takeaway: If the content matters more than the permanence, inscription is the wrong storage model; if the permanence is the point, the publication decision needs to be deliberate.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org