A free and open-source Chaumian ecash protocol built for Bitcoin, enabling private, instant, and offline-capable digital payments. The protocol defines an ecash system with two parties — a mint (server that issues and redeems ecash tokens) and a wallet (client that holds bearer tokens). Blind signatures preserve privacy: a mint cannot link token issuance to redemption, providing strong untraceability. Multiple independent wallet and mint implementations exist across Python, TypeScript, Rust, and other languages. Transactions are instant and final. Transfers between mints are routed via the Lightning Network. Protocol specifications are published as NUTs (Notation, Usage, and Terminology). Governed by the OpenCash Association.
Dev Status DetailReleased (multiple production wallet and mint implementations; iOS/Android apps; PWA; CLI tools; Python nutshell reference; TypeScript cashu-ts; Rust CDK)
OwnerOpenCash Association (protocol stewardship); cashubtc GitHub org (open-source implementations); community-developed
CountryGlobal / Cypherpunk community
Start Year 2022
StackRust (CDK — Cashu Development Kit); TypeScript (cashu-ts); Python (nutshell reference implementation); protocol-agnostic (any language can implement NUTs)
OriginsCypherpunk / Privacy payments (based on David Wagner's 1996 variant of Chaumian blinding; motivated by need for private, peer-to-peer digital cash that preserves user privacy from mints and third parties; Bitcoin-native)
DatabaseMint-local (each mint maintains its own token database; no global ledger; bearer token model means wallet holds tokens locally; no user account database at mint)
Query LanguageN/A (payment protocol; no query language)
TermsFree / Open source (protocol is free; mints may charge fees; OpenCash Association accepts donations)
FundsUndisclosed
Based OnBitcoin (Layer 1 — token backing and settlement); Lightning Network (inter-mint transfers and Bitcoin on/off-ramp); Chaumian blind signatures (David Wagner 1996 variant); RSA/Ed25519 blind signature schemes
P2P ArchitectureMint-and-wallet federation (mints issue and redeem tokens; wallets hold bearer tokens locally; peer-to-peer token transfers between wallets without mint involvement; blind signatures prevent mint from linking issuance to redemption; offline-capable token transfers between wallets)
Overlay NetworkApplication-wide (scoped to individual mint deployments; cross-mint via Lightning routing; no global DHT or relay network required)
Content AddressingNo (token model; no content addressing)
Local-FirstYes (bearer tokens stored locally on wallet device; offline token transfers between wallets possible without internet; Lightning required only for mint interactions)
E2EEYes (blind signatures provide strong untraceability; mint cannot link user identity to transactions; no user accounts at mint; no transaction graph visible to mint)
CRDTs LibN/A (payment protocol; no collaborative editing)
Byzantine Fault ToleranceN/A (payment protocol; Byzantine fault tolerance not applicable)
SignatureBlind signatures (RSA or Ed25519 blind signature scheme; mint signs tokens without seeing token identity; wallet holds and presents tokens)
PermissionsOpen (any wallet can interact with any compliant mint; no permissioning beyond Lightning Network access)
Semantic Web CompatibilityNo (payment protocol; no semantic web features)
Smart ContractNo (not a smart contract platform; conditional payment logic not in base protocol)
Protocol Stack PositionApplication layer (sits above Bitcoin/Lightning transport; defines token issuance, transfer, and redemption semantics; not a transport protocol)
Asset / Value EmbeddingNative (ecash tokens are the value-bearing primitive; asset embedding is the protocol's core purpose)
Protocol Maturity / StandardizationReleased / Community standard (multiple independent production implementations across 5+ languages; active ecosystem of wallets and mints; NUTs specification published; OpenCash Association stewardship; no formal IETF or ISO standardization; de facto standard for Bitcoin ecash)
See something missing or that could be improved? Let us know →