A free and open-source Chaumian ecash protocol built for Bitcoin, enabling private, instant, and offline-capable digital payments. The protocol defines an ecash system with two parties — a mint (server that issues and redeems ecash tokens) and a wallet (client that holds bearer tokens). Blind signatures preserve privacy: a mint cannot link token issuance to redemption, providing strong untraceability. Multiple independent wallet and mint implementations exist across Python, TypeScript, Rust, and other languages. Transactions are instant and final. Transfers between mints are routed via the Lightning Network. Protocol specifications are published as NUTs (Notation, Usage, and Terminology). Governed by the OpenCash Association.
Detalle del Estado de DesarrolloReleased (multiple production wallet and mint implementations; iOS/Android apps; PWA; CLI tools; Python nutshell reference; TypeScript cashu-ts; Rust CDK)
PropietarioOpenCash Association (protocol stewardship); cashubtc GitHub org (open-source implementations); community-developed
Órgano de Gobierno OpenCash Association (protocol stewardship via the NUTs specification process)
PaísGlobal / Cypherpunk community
Año de Inicio 2022
StackRust (CDK — Cashu Development Kit); TypeScript (cashu-ts); Python (nutshell reference implementation); protocol-agnostic (any language can implement NUTs)
OrígenesCypherpunk / Privacy payments (based on David Wagner's 1996 variant of Chaumian blinding; motivated by need for private, peer-to-peer digital cash that preserves user privacy from mints and third parties; Bitcoin-native)
Base de DatosMint-local (each mint maintains its own token database; no global ledger; bearer token model means wallet holds tokens locally; no user account database at mint)
Lenguaje de ConsultaN/A (payment protocol; no query language)
Arquitectura P2PMint-and-wallet federation (mints issue and redeem tokens; wallets hold bearer tokens locally; peer-to-peer token transfers between wallets without mint involvement; blind signatures prevent mint from linking issuance to redemption; offline-capable token transfers between wallets)
Red de SuperposiciónApplication-wide (scoped to individual mint deployments; cross-mint via Lightning routing; no global DHT or relay network required)
Direccionamiento por ContenidoNo (token model; no content addressing)
Local-FirstYes (bearer tokens stored locally on wallet device; offline token transfers between wallets possible without internet; Lightning required only for mint interactions)
Cifrado de Extremo a Extremo (E2EE)Yes (blind signatures provide strong untraceability; mint cannot link user identity to transactions; no user accounts at mint; no transaction graph visible to mint)
Biblioteca de CRDTsN/A (payment protocol; no collaborative editing)
Tolerancia a Fallos BizantinosN/A (payment protocol; Byzantine fault tolerance not applicable)
FirmaBlind signatures (RSA or Ed25519 blind signature scheme; mint signs tokens without seeing token identity; wallet holds and presents tokens)
PermisosOpen (any wallet can interact with any compliant mint; no permissioning beyond Lightning Network access)
Compatibilidad con la Web SemánticaNo (payment protocol; no semantic web features)
Contrato InteligenteNo (not a smart contract platform; conditional payment logic not in base protocol)
Posición en la Pila del ProtocoloApplication layer (sits above Bitcoin/Lightning transport; defines token issuance, transfer, and redemption semantics; not a transport protocol)
Incorporación de Activos/ValorNative (ecash tokens are the value-bearing primitive; asset embedding is the protocol's core purpose)
Madurez del Protocolo / EstandarizaciónReleased / Community standard (multiple independent production implementations across 5+ languages; active ecosystem of wallets and mints; NUTs specification published; OpenCash Association stewardship; no formal IETF or ISO standardization; de facto standard for Bitcoin ecash)
¿Ve algo que falta o que podría mejorarse? Cuéntenos →