← The Satoshi FilesPrimary-source index ↓
Exhibit 08 · Falsification dossier · evidence cutoff 31 October 2008

THE IAN GOLDBERG FILE

A narrow technical screen: did Goldberg's documented work join anonymous e-cash, computational work, and distributed systems into an authoritative shared history capable of resolving double-spends before Bitcoin?

Scope guard: this is not an allegation and does not claim Goldberg was Satoshi Nakamoto. Capability, proximity, and shared vocabulary are not identity evidence. The file aggressively records both supporting and disconfirming evidence; later Bitcoin references are separated from the pre-cutoff record.
Standing verdict · 11 August 2026

The ingredients are documented. The bridge is not.

Goldberg had unusually relevant pieces: hands-on DigiCash protocol analysis, a confirmed HINDE e-cash collaboration, direct exposure to Adam Back's Hashcash, a distributed pseudonymous-network design, C++ cryptographic implementation work, and Byzantine-robust data recovery. But the recovered pre-cutoff record treats e-cash and client puzzles as separate abuse-control tokens, retains a mint or organizational trust root, and delegates distributed state to other systems. No artifact located here uses proof of work to choose one authoritative transaction history, order conflicting spends, or replace the mint. That missing bridge is presently stronger counter-evidence than the surrounding capability is positive identity evidence.

6relevant capability clusters
0recovered PoW consensus designs
1major archive gap: HINDE internals
31 Oct 2008evidence cutoff
Show evidence

The bridge test

01 · Confirmed

Anonymous e-cash

DigiCash protocol work, mint interactions, payee anonymity, change, and spend-failure analysis.

02 · Confirmed

Computational work

Hashcash/client puzzles proposed as CPU-cost tokens against resource exhaustion.

03 · Confirmed

Distributed privacy

Overlay routing, pseudonyms, replicated information, PIR, Free Haven/Freenet awareness.

04 · Not located

History selection

No recovered rule makes accumulated work select a canonical transaction history.

05 · Not located

Double-spend resolution

Known conflicts still clear at a mint; no permissionless ledger replaces it.

Most probative negative: the 2000 thesis places anonymous e-cash and Hashcash-style puzzles side by side as alternative tokens an anonymity node may demand. When distributed naming/state is needed, it explicitly assumes an external decentralized database such as Gnutella, Freenet, or Free Haven and leaves that problem to those systems. This is close exposure to the ingredients without the Bitcoin synthesis.

Evidence ledger

DateArtifactWhat it establishesWhat it does not establishGrade
21 Nov 1995“ecash protocol: Part 1” and replies, including Hal FinneyGoldberg was publicly dissecting deployed DigiCash mechanics and directly exchanging technical comments with Finney.No decentralized issuance, transaction log, or PoW consensus appears in the recovered thread index.P1 · primary mail archive
31 Dec 1995–5 Jan 1996“Starting an e-cash bank”, Ryan Lackey thread and Goldberg repliesDirect Goldberg–Lackey contact around operating an e-cash bank years before HINDE.An e-cash bank is still a bank/mint model; the thread index alone does not reveal HINDE's later architecture.P1 · primary mail archive
16 Jan 1996“How to make someone else lose ecash”Goldberg found a duplicate-coin-number attack: an adversary could get a copied serial accepted first, causing the original coin to fail. His fix encrypts the coin number and signature to the mint.The mint remains authoritative. This is double-spend expertise, but not a distributed double-spend solution.P1 · primary mail
29 Oct 1996Making Change for Anonymous PayersGoldberg publicly presented payee/mutual anonymity, anonymous change, and using DigiCash without a personal bank account.It extends privacy and usability around DigiCash; it does not remove the mint's authority.P1 · Stanford seminar page
7 Sep 1998Ryan Lackey names HINDELackey explicitly calls HINDE a project with Ian Goldberg to create a workable electronic-cash system, then says it was probably quiescent.No surviving code/design was recovered in this pass. “Workable electronic cash” cannot be upgraded to “decentralized cryptocurrency” without the missing artifacts.P1 · primary mail
Fall 2000Goldberg PhD thesisOne document contains Chaum/Brands e-cash, Back's Hashcash, client puzzles, distributed anonymizing nodes, reputation capital, and external decentralized databases.E-cash and puzzles are alternatives for charging access. There is no chain of work, canonical ordering, mining reward, or mintless spend resolution.P1 · thesis
18 Dec 2000Freedom System 2.0 ArchitectureGoldberg co-designed a distributed overlay with replicated network information, pseudonyms, signed topology and core services.Trust is rooted in Zero-Knowledge master/year/month signing keys and core servers—not permissionless consensus.P1 · company paper
1999–2001Freedom security analysesGoldberg, Adam Back, and Adam Shostack worked on replay, time synchronization, denial-of-service, routing, key distribution and planned distributed lookup.The recovered papers do not turn Hashcash into monetary issuance, incentives, transaction ordering, or a shared ledger.P1/P2 · archived papers
30 May 2001ZKS eCash/PrivateCredential toolkit roleA Zero-Knowledge posting says the hire would work closely with Goldberg, Shostack, and Stefan Brands on eCash and PrivateCredential toolkits.It does not demonstrate that Goldberg and Back jointly designed PoW money or consensus.P1 · contemporary posting
2002–Oct 2008Official publication recordThe pre-cutoff record is rich in OTR, Tor authentication, onion routing, location privacy, user studies and private information retrieval.No listed pre-cutoff publication concerns permissionless consensus, shared transaction ordering, PoW incentives, or blockchain-style timestamps.N1 · bounded corpus negative
2 Mar–17 Jun 2007Percy++ 0.5–0.7.1Goldberg released a C++ PIR implementation. It distributes queries across database servers and can detect/correct incorrect replies. Version 0.7.1 credits patches from Len Sassaman.“Byzantine-robust” here means recovering the correct database block from bad replies—not agreeing on a changing global state.P1/P2 · project + paper
2006–2008Tor, PETS, Free Haven, CodeCon linksGoldberg published on Tor authentication, co-edited PETS 2008 in Leuven, thanked Sassaman for motivating the PIR problem, and served on a CodeCon committee chaired by Sassaman.Conference and research proximity is not evidence of Satoshi contact or shared Bitcoin design work.P1/P2 · papers/programs
Through 31 Oct 2008Timestamp-reference exposure checkA full-text check of the thesis found no Massias, Serret-Avila, Quisquater, or Preneel names; its bibliography instead points to e-cash, anonymity, Hashcash, client puzzles and distributed publishing.Absence from one thesis is not proof of no exposure elsewhere. No positive pre-cutoff Goldberg citation to Bitcoin's timestamp references was located.N1 · bounded corpus negative
2015 · post-cutoffEarliest explicit Bitcoin discussion located in Goldberg's official publication corpusThe Secure Messaging SoK explains Bitcoin's PoW-backed append-only log and its use against double-spending.This is years after Bitcoin launched and is not evidence of pre-2008 knowledge or contact. No earlier Goldberg-authored Bitcoin/Satoshi reaction was located in the searched public corpus.P1 + search limitation

HINDE: confirmed project, missing internals

Confirmed7 Sep 1998

The strongest surviving primary statement

Ryan Lackey wrote that he had paused Eternity DDS and moved to HINDE, “a project with Ian Goldberg” aimed at a workable electronic-cash system. He described the project as a cypherpunk protest against DigiCash and “probably quiescent” after Goldberg moved to Zero-Knowledge Systems. This proves collaboration and purpose; it does not disclose the mint, coin format, source tree, double-spend database, or whether any distributed authority existed.

Open the dated message →
Archive gap

Not recovered

No HINDE source package, README, protocol paper, patent cross-reference, wire format, mint schema, or operational bank record was located in the indexed web, Goldberg's publication/project pages, or searched Cypherpunks archive. Later retellings often call it a “cryptocurrency”; the primary message only says electronic cash.

Best next targets

What would change the verdict

A HINDE file naming a distributed spend database, quorum, timestamp service, conflict-ordering rule, proof-of-work issuance, or mint replacement would be decisive. Highest-value locations: Ryan Lackey's 1997–99 hosts/backups, conference handouts from the Boston electronic-cash event he mentions, old Systemics/Anguilla mirrors, and private tapes or email attachments from either collaborator.

The 2000 thesis under pressure

Ingredient present

E-cash

The thesis surveys Chaum and Brands, treats anonymous payment as necessary for privacy, and proposes electronic cash as one token an anonymity-infrastructure provider could demand before extending a route.

Read the thesis PDF →
Ingredient present

Hashcash and client puzzles

As the second token option, a provider may require a puzzle “in the manner of Hashcash” so an attacker must spend substantial CPU time before consuming network resources.

Open Goldberg's thesis page →
Separation matters

Alternative tolls, not a monetary consensus

The thesis does not mint e-cash with the puzzle and does not use work to decide which spend happened first. Money and work are interchangeable anti-abuse costs imposed by a service node.

Delegated state

The distributed database is assumed

For decentralized name information, the design points to Gnutella, Freenet, or Free Haven and explicitly assumes such a database exists. It does not specify consensus, conflict resolution, or an authoritative history.

Percy++ code and architecture screen

The surviving official project record supports a bounded comparison, not a stylometric match. SourceForge dates the initial release to 2 March 2007; the project changelog identifies major revisions through June 2007, and the paper/project describe the architecture.

DimensionPercy++ 2007Bitcoin pre-release / v0.1Investigative read
PurposePrivate retrieval from one or more database servers without revealing the requested block.Peer-to-peer electronic cash with a replicated transaction history.Different state problem. Percy reads an existing database; Bitcoin orders and changes shared state.
Adversary modelSome servers may collude, fail to reply, or return incorrect answers.Peers/miners may race, relay invalid transactions, or attempt conflicting histories.Both tolerate bad participants, but the correctness goals are not equivalent.
“Byzantine” mechanismError detection/correction reconstructs the right database block from multiple replies.Nodes validate rules; accumulated proof of work selects a chain.Word overlap, architecture mismatch.
Network shapeClient queries a configured set of servers; early releases focused on PIR experiments and command-line tools.Gossiping peers discover, relay, validate and persist transactions/blocks.No shared-history or transaction-relay parallel is established.
Dependencies / platformC++ with Victor Shoup's NTL; SourceForge labels BSD/Linux, command-line/daemon.C++ with Boost, OpenSSL and Berkeley DB; early distribution was Windows-first with a GUI.General C++ competence is relevant; the toolchain and product shape diverge.
Authorship boundaryThe initial project is Goldberg-led; later README credits multiple authors. Version 0.7.1 says its patches were based on Len Sassaman's contributions.Satoshi's early tree is a single integrated application later joined by contributors.Per-file Goldberg authorship and fine-grained style comparison require the preserved 0.5–0.7 source tree; this dossier does not claim a code fingerprint.
Code verdict: Percy++ is strong evidence that Goldberg could ship mathematical C++ and reason about faulty distributed respondents. It is not evidence that he implemented a P2P ledger. The meaningful comparison target is not brace style; it is whether early Percy code contains serialization, persistent transaction state, peer discovery, conflict ordering, work-weighted selection, or incentives. The published architecture indicates none of those load-bearing Bitcoin structures.

People and institutional paths

Direct

Hal Finney

Finney replied in Goldberg's November 1995 e-cash protocol thread. This is confirmed direct technical-list contact, but no recovered exchange joins them on PoW consensus.

Open the thread index →
Direct work

Adam Back

The thesis cites Hashcash, and Back, Goldberg, and Shostack share authorship on the Freedom security analysis. The recovered design uses Hashcash as an anti-abuse idea, not a ledger selector.

Open Freedom security analysis →
Documented exposure

Wei Dai

The thesis discusses and cites Dai's Pipenet; Freedom's security material also notes a Dai attack on the prototype. No recovered Goldberg artifact cites b-money or adopts its monetary design.

Company circle

Stefan Brands

Brands' credential/e-cash work is cited in the thesis, and a 2001 ZKS posting places Brands and Goldberg in the same eCash/PrivateCredential toolkit effort.

Open the 2001 posting →
Direct research path

Len Sassaman

Goldberg's 2007 PIR paper thanks Sassaman for motivating the problem; Percy++ 0.7.1 credits Sassaman-based patches; both appear in the CodeCon/PETS privacy-research circuit.

Open the 2007 PIR paper →
Proximity only

Preneel / Quisquater / COSIC

Goldberg co-edited PETS 2008 in Leuven, establishing institutional proximity to the Leuven cryptography community. The thesis does not cite Preneel, Quisquater, Massias, or Serret-Avila, and no direct pre-cutoff collaboration on timestamping was located.

Open Goldberg's publication list →

What would falsify this verdict?

Priority 1

Recover HINDE internals

A contemporaneous source archive or design note is the largest unknown. Search for mint databases, spent-coin tables, multi-mint settlement, distributed issuance, audit logs, quorum language, timestamps, puzzles, and Lackey/Goldberg comments.

Priority 2

Recover Percy++ 0.5–0.7 source history

Attribute files and commits, then compare architecture and measurable style against Bitcoin's November 2008 code—not only generic C++ idioms. A meaningful hit must survive controls from other Goldberg and NTL-based code.

Priority 3

Search private/company archives

The unpublished Freedom 2.0 protocols/security documents, Zero-Knowledge internal mail, design reviews with Back, and old backup media could reveal whether computational work was ever connected to incentives or shared state.

Priority 4

Locate a dated Bitcoin reaction

The searched public corpus yielded no pre-launch contact and no early reaction. A dated email, talk, commit, or archived post earlier than the 2015 publication-corpus hit would narrow when Goldberg first engaged with Bitcoin.

Primary-source index

  1. Ryan Lackey, “Re: Cypherpunks HyperArchive,” 7 Sep 1998 — the HINDE statement.
  2. Ian Goldberg, “How to make someone else lose ecash,” 16 Jan 1996 — coin-number race and mint-side fix.
  3. Goldberg's 1995–96 Cypherpunks thread index — Hal Finney, Ryan Lackey, e-cash bank and protocol threads.
  4. Stanford seminar: Making Change for Anonymous Payers, 29 Oct 1996.
  5. Goldberg's official thesis page and full 2000 thesis PDF.
  6. Freedom System 2.0 Architecture, 18 Dec 2000.
  7. Freedom Network 1.0 Security Issues and Analysis — dated history begins 1999.
  8. Zero-Knowledge eCash/PrivateCredential toolkit posting, 30 May 2001.
  9. Ian Goldberg's official publication list — bounded pre-cutoff corpus.
  10. Improving the Robustness of Private Information Retrieval, 2007.
  11. Percy++ official project page, changelog, and dated SourceForge releases.
  12. On the Security of the Tor Authentication Protocol, 2006.
  13. Pairing-Based Onion Routing with Improved Forward Secrecy, 2007.
  14. SoK: Secure Messaging, 2015 — post-cutoff Bitcoin discussion, not pre-Bitcoin evidence.
Search limitation: “not located” means absent from the specific public corpora and artifacts searched for this release; it is not proof that a private conversation or lost file never existed. Every negative claim above names its corpus so later finds can update the file cleanly.