Anonymous e-cash
DigiCash protocol work, mint interactions, payee anonymity, change, and spend-failure analysis.
A narrow technical screen: did Goldberg's documented work join anonymous e-cash, computational work, and distributed systems into an authoritative shared history capable of resolving double-spends before Bitcoin?
Goldberg had unusually relevant pieces: hands-on DigiCash protocol analysis, a confirmed HINDE e-cash collaboration, direct exposure to Adam Back's Hashcash, a distributed pseudonymous-network design, C++ cryptographic implementation work, and Byzantine-robust data recovery. But the recovered pre-cutoff record treats e-cash and client puzzles as separate abuse-control tokens, retains a mint or organizational trust root, and delegates distributed state to other systems. No artifact located here uses proof of work to choose one authoritative transaction history, order conflicting spends, or replace the mint. That missing bridge is presently stronger counter-evidence than the surrounding capability is positive identity evidence.
DigiCash protocol work, mint interactions, payee anonymity, change, and spend-failure analysis.
Hashcash/client puzzles proposed as CPU-cost tokens against resource exhaustion.
Overlay routing, pseudonyms, replicated information, PIR, Free Haven/Freenet awareness.
No recovered rule makes accumulated work select a canonical transaction history.
Known conflicts still clear at a mint; no permissionless ledger replaces it.
| Date | Artifact | What it establishes | What it does not establish | Grade |
|---|---|---|---|---|
| 21 Nov 1995 | “ecash protocol: Part 1” and replies, including Hal Finney | Goldberg was publicly dissecting deployed DigiCash mechanics and directly exchanging technical comments with Finney. | No decentralized issuance, transaction log, or PoW consensus appears in the recovered thread index. | P1 · primary mail archive |
| 31 Dec 1995–5 Jan 1996 | “Starting an e-cash bank”, Ryan Lackey thread and Goldberg replies | Direct Goldberg–Lackey contact around operating an e-cash bank years before HINDE. | An e-cash bank is still a bank/mint model; the thread index alone does not reveal HINDE's later architecture. | P1 · primary mail archive |
| 16 Jan 1996 | “How to make someone else lose ecash” | Goldberg found a duplicate-coin-number attack: an adversary could get a copied serial accepted first, causing the original coin to fail. His fix encrypts the coin number and signature to the mint. | The mint remains authoritative. This is double-spend expertise, but not a distributed double-spend solution. | P1 · primary mail |
| 29 Oct 1996 | Making Change for Anonymous Payers | Goldberg publicly presented payee/mutual anonymity, anonymous change, and using DigiCash without a personal bank account. | It extends privacy and usability around DigiCash; it does not remove the mint's authority. | P1 · Stanford seminar page |
| 7 Sep 1998 | Ryan Lackey names HINDE | Lackey explicitly calls HINDE a project with Ian Goldberg to create a workable electronic-cash system, then says it was probably quiescent. | No surviving code/design was recovered in this pass. “Workable electronic cash” cannot be upgraded to “decentralized cryptocurrency” without the missing artifacts. | P1 · primary mail |
| Fall 2000 | Goldberg PhD thesis | One document contains Chaum/Brands e-cash, Back's Hashcash, client puzzles, distributed anonymizing nodes, reputation capital, and external decentralized databases. | E-cash and puzzles are alternatives for charging access. There is no chain of work, canonical ordering, mining reward, or mintless spend resolution. | P1 · thesis |
| 18 Dec 2000 | Freedom System 2.0 Architecture | Goldberg co-designed a distributed overlay with replicated network information, pseudonyms, signed topology and core services. | Trust is rooted in Zero-Knowledge master/year/month signing keys and core servers—not permissionless consensus. | P1 · company paper |
| 1999–2001 | Freedom security analyses | Goldberg, Adam Back, and Adam Shostack worked on replay, time synchronization, denial-of-service, routing, key distribution and planned distributed lookup. | The recovered papers do not turn Hashcash into monetary issuance, incentives, transaction ordering, or a shared ledger. | P1/P2 · archived papers |
| 30 May 2001 | ZKS eCash/PrivateCredential toolkit role | A Zero-Knowledge posting says the hire would work closely with Goldberg, Shostack, and Stefan Brands on eCash and PrivateCredential toolkits. | It does not demonstrate that Goldberg and Back jointly designed PoW money or consensus. | P1 · contemporary posting |
| 2002–Oct 2008 | Official publication record | The pre-cutoff record is rich in OTR, Tor authentication, onion routing, location privacy, user studies and private information retrieval. | No listed pre-cutoff publication concerns permissionless consensus, shared transaction ordering, PoW incentives, or blockchain-style timestamps. | N1 · bounded corpus negative |
| 2 Mar–17 Jun 2007 | Percy++ 0.5–0.7.1 | Goldberg released a C++ PIR implementation. It distributes queries across database servers and can detect/correct incorrect replies. Version 0.7.1 credits patches from Len Sassaman. | “Byzantine-robust” here means recovering the correct database block from bad replies—not agreeing on a changing global state. | P1/P2 · project + paper |
| 2006–2008 | Tor, PETS, Free Haven, CodeCon links | Goldberg published on Tor authentication, co-edited PETS 2008 in Leuven, thanked Sassaman for motivating the PIR problem, and served on a CodeCon committee chaired by Sassaman. | Conference and research proximity is not evidence of Satoshi contact or shared Bitcoin design work. | P1/P2 · papers/programs |
| Through 31 Oct 2008 | Timestamp-reference exposure check | A full-text check of the thesis found no Massias, Serret-Avila, Quisquater, or Preneel names; its bibliography instead points to e-cash, anonymity, Hashcash, client puzzles and distributed publishing. | Absence from one thesis is not proof of no exposure elsewhere. No positive pre-cutoff Goldberg citation to Bitcoin's timestamp references was located. | N1 · bounded corpus negative |
| 2015 · post-cutoff | Earliest explicit Bitcoin discussion located in Goldberg's official publication corpus | The Secure Messaging SoK explains Bitcoin's PoW-backed append-only log and its use against double-spending. | This is years after Bitcoin launched and is not evidence of pre-2008 knowledge or contact. No earlier Goldberg-authored Bitcoin/Satoshi reaction was located in the searched public corpus. | P1 + search limitation |
Ryan Lackey wrote that he had paused Eternity DDS and moved to HINDE, “a project with Ian Goldberg” aimed at a workable electronic-cash system. He described the project as a cypherpunk protest against DigiCash and “probably quiescent” after Goldberg moved to Zero-Knowledge Systems. This proves collaboration and purpose; it does not disclose the mint, coin format, source tree, double-spend database, or whether any distributed authority existed.
Open the dated message →No HINDE source package, README, protocol paper, patent cross-reference, wire format, mint schema, or operational bank record was located in the indexed web, Goldberg's publication/project pages, or searched Cypherpunks archive. Later retellings often call it a “cryptocurrency”; the primary message only says electronic cash.
A HINDE file naming a distributed spend database, quorum, timestamp service, conflict-ordering rule, proof-of-work issuance, or mint replacement would be decisive. Highest-value locations: Ryan Lackey's 1997–99 hosts/backups, conference handouts from the Boston electronic-cash event he mentions, old Systemics/Anguilla mirrors, and private tapes or email attachments from either collaborator.
The thesis surveys Chaum and Brands, treats anonymous payment as necessary for privacy, and proposes electronic cash as one token an anonymity-infrastructure provider could demand before extending a route.
Read the thesis PDF →As the second token option, a provider may require a puzzle “in the manner of Hashcash” so an attacker must spend substantial CPU time before consuming network resources.
Open Goldberg's thesis page →The thesis does not mint e-cash with the puzzle and does not use work to decide which spend happened first. Money and work are interchangeable anti-abuse costs imposed by a service node.
For decentralized name information, the design points to Gnutella, Freenet, or Free Haven and explicitly assumes such a database exists. It does not specify consensus, conflict resolution, or an authoritative history.
The surviving official project record supports a bounded comparison, not a stylometric match. SourceForge dates the initial release to 2 March 2007; the project changelog identifies major revisions through June 2007, and the paper/project describe the architecture.
| Dimension | Percy++ 2007 | Bitcoin pre-release / v0.1 | Investigative read |
|---|---|---|---|
| Purpose | Private retrieval from one or more database servers without revealing the requested block. | Peer-to-peer electronic cash with a replicated transaction history. | Different state problem. Percy reads an existing database; Bitcoin orders and changes shared state. |
| Adversary model | Some servers may collude, fail to reply, or return incorrect answers. | Peers/miners may race, relay invalid transactions, or attempt conflicting histories. | Both tolerate bad participants, but the correctness goals are not equivalent. |
| “Byzantine” mechanism | Error detection/correction reconstructs the right database block from multiple replies. | Nodes validate rules; accumulated proof of work selects a chain. | Word overlap, architecture mismatch. |
| Network shape | Client queries a configured set of servers; early releases focused on PIR experiments and command-line tools. | Gossiping peers discover, relay, validate and persist transactions/blocks. | No shared-history or transaction-relay parallel is established. |
| Dependencies / platform | C++ with Victor Shoup's NTL; SourceForge labels BSD/Linux, command-line/daemon. | C++ with Boost, OpenSSL and Berkeley DB; early distribution was Windows-first with a GUI. | General C++ competence is relevant; the toolchain and product shape diverge. |
| Authorship boundary | The initial project is Goldberg-led; later README credits multiple authors. Version 0.7.1 says its patches were based on Len Sassaman's contributions. | Satoshi's early tree is a single integrated application later joined by contributors. | Per-file Goldberg authorship and fine-grained style comparison require the preserved 0.5–0.7 source tree; this dossier does not claim a code fingerprint. |
Finney replied in Goldberg's November 1995 e-cash protocol thread. This is confirmed direct technical-list contact, but no recovered exchange joins them on PoW consensus.
Open the thread index →The thesis cites Hashcash, and Back, Goldberg, and Shostack share authorship on the Freedom security analysis. The recovered design uses Hashcash as an anti-abuse idea, not a ledger selector.
Open Freedom security analysis →The thesis discusses and cites Dai's Pipenet; Freedom's security material also notes a Dai attack on the prototype. No recovered Goldberg artifact cites b-money or adopts its monetary design.
Brands' credential/e-cash work is cited in the thesis, and a 2001 ZKS posting places Brands and Goldberg in the same eCash/PrivateCredential toolkit effort.
Open the 2001 posting →Goldberg's 2007 PIR paper thanks Sassaman for motivating the problem; Percy++ 0.7.1 credits Sassaman-based patches; both appear in the CodeCon/PETS privacy-research circuit.
Open the 2007 PIR paper →Goldberg co-edited PETS 2008 in Leuven, establishing institutional proximity to the Leuven cryptography community. The thesis does not cite Preneel, Quisquater, Massias, or Serret-Avila, and no direct pre-cutoff collaboration on timestamping was located.
Open Goldberg's publication list →A contemporaneous source archive or design note is the largest unknown. Search for mint databases, spent-coin tables, multi-mint settlement, distributed issuance, audit logs, quorum language, timestamps, puzzles, and Lackey/Goldberg comments.
Attribute files and commits, then compare architecture and measurable style against Bitcoin's November 2008 code—not only generic C++ idioms. A meaningful hit must survive controls from other Goldberg and NTL-based code.
The unpublished Freedom 2.0 protocols/security documents, Zero-Knowledge internal mail, design reviews with Back, and old backup media could reveal whether computational work was ever connected to incentives or shared state.
The searched public corpus yielded no pre-launch contact and no early reaction. A dated email, talk, commit, or archived post earlier than the 2015 publication-corpus hit would narrow when Goldberg first engaged with Bitcoin.