The breakthrough

What digital cash could not solve for forty years.

This is the longest open question in the history of digital money. It stayed open not because no one worked on it — but because every solution had a price that no one wanted to pay.

The problem

01

You cannot hand the same banknote over twice.

Once you have paid with it, it is no longer yours. That is not a rule, it is physics: the paper is one object.

02

Digital money is data. Data can be copied.

Sending a file twice is exactly as easy as sending it once.

03

Online this is solvable. Offline it is not.

With a network you can ask a central record whether the money has already been spent. Without one, there is no one to ask.

Not everything can be solved — and that is worth saying out loud.

If the recipient is not on a network, a double-spend cannot be detected at the moment of payment. What cannot be detected cannot be prevented.

Qashmore does not promise prevention. It promises something else, and in practice it is almost as good: certain, provable exposure.

What was tried

Ten stops along four decades. At every one of them the same three questions: what it was, what it gave, and what it cost.

  1. 1982–1988

    What it was

    The idea. Chaum, then Chaum–Fiat–Naor: let the payment stay anonymous, but let anyone who spends twice reveal themselves mathematically.

    What it gave

    The right answer — self-exposure instead of prevention.

    The price

    It stayed on paper. It never ran in a live system, at real scale.

  2. The 1990s

    What it was

    DigiCash. Chaum's own company turned the principle into a product, with banks and real customers. It used no security hardware.

    What it gave

    It proved that anonymous digital payment works.

    The price

    In the shipped product the bank verified every banknote online; the offline mode remained a “future extension”. The company went bankrupt in 1998.

  3. 1992–1995

    What it was

    CAFE, the EU research project, with Chaum.

    What it gave

    The only system of its era with cryptographic identification of the cheat: “Even if the tamper-resistance is broken, users who spend electronic money more than once are identified.”

    The price

    In the project's own words, “it allows just one transfer of the electronic money” — there is no chain.

  4. The 1990s

    What it was

    Mondex. Card to card, with no network, hand to hand. ITSEC E6.

    What it gave

    The only system that could carry an offline chain of unlimited length.

    The price

    Trust moved into the chip. The card did not show that no one had cheated — it trusted that no one could. There is no identification of the cheat. The last market closed in 2008.

  5. 1996–2000s

    What it was

    GeldKarte (DE), Octopus (HK), Proton, Chipknip, Danmønt, Quick, Moneo, Visa Cash.

    What it gave

    Working, widely adopted offline payment — in several countries, for decades.

    The price

    All of them tamper-resistant chip cards. Transfer between users is either missing or built on the same hardware. None of them identifies the cheat.

  6. 2009

    What it was

    Transferable e-cash at constant size (Fuchsbauer and colleagues).

    What it gave

    At last the money could pass through several hands before it returned to the bank.

    The price

    Honest people paid the cheat's price. On a double-spend, a trusted tracer could also reveal the identities of the honest holders through whose hands the tainted money later passed.

  7. 2011

    What it was

    Anonymity with a judge (Blazy and colleagues).

    What it gave

    It gave the honest user's anonymity back.

    The price

    It needed an all-seeing “judge” — losing exactly the promise the whole line had been built for.

  8. 2015

    What it was

    The first fully anonymous transferable e-cash (Baldimtsi–Chase–Fuchsbauer–Kohlweiss).

    What it gave

    No trusted third party. A theoretical breakthrough.

    The price

    Its building blocks make it impossible to run beside a till.

  9. 2021

    What it was

    Bauer–Fuchsbauer–Qian. The first complete construction with security proofs — all three anonymity notions, unlimited chain depth.

    What it gave

    It showed that the task can be solved. That is not in dispute; the concept is theirs.

    The price

    There is no published implementation, measured running time or curve choice. From the published element counts, their payment package is about 19 kilobytes after withdrawal and grows by about 7 kilobytes per hop.

  10. The 2020s

    What it was

    The central banks. The offline layer of the digital euro, the offline mode of China's e-CNY, India's UPI Lite.

    What it gave

    Offline payment in live, large-scale systems.

    The price

    All of them build on security hardware. In the Bank of England's 2025 experiment five vendors out of five used secure elements; the Riksbank tried it with phones alone and rejected that in writing.

Two patterns. Wherever offline was taken seriously, hardware was put underneath it. Wherever the mathematics was chosen, either no shipped system came of it, or honest people paid the cheat's price. The chain and the precise naming of the cheat have never gone together.

What no one shipped in forty years.

One. Spend twice and you reveal yourself.

The two traces of a double-spend together yield the cheat's own key, mathematically. It is automatic, it cannot be denied, and it requires the surveillance of no one.

Two. It also works in an offline chain of transfers.

If the money has passed through several hands, all of them offline, and somewhere in the chain someone cheated — the system names exactly that one person.

Three. Everyone else is untouched.

Every other, honest member of the chain keeps their anonymity — neither the honest holders before the cheat nor those after them are exposed, and none of them becomes a suspect. Not even if someone deliberately tried to steer suspicion onto them.

That is exactly where the 2009 solution failed.

The chain

Four people, four roles. The money stays offline the whole way.

  1. A

    the payer

    Receives the digital banknote from their bank. Hands it on offline.

  2. B

    the intermediate holder

    Accepts it, then hands it on. Offline throughout.

  3. C

    the cheat

    Spends the same banknote twice.

  4. D

    the honest recipient

    Accepts it. Has no idea that anything is wrong.

The next time any point of the chain reaches a network, the system names C — personally. A, B and D stay anonymous, and none of them can be drawn into suspicion. D is made whole by the issuer guarantee: the cheat's bank pays, then recovers the amount from the cheat.

Two separate things, and they are worth keeping apart. That suspicion cannot be steered onto the honest holders follows from a theorem of the construction. That their money is safe as well follows from the issuer guarantee — that is the business arrangement, with a limit.

The depth of offline transfer is set by the deployment — ten steps today — after which the money has to be refreshed online once. The payment package handed to the recipient is about 456 bytes when freshly issued and about 956 bytes at the deepest chain; verification takes about 12 milliseconds.

What this means in practice

No special phone is needed.

No security chip, no manufacturer acting as gatekeeper.

The honest recipient is not left worse off.

The risk does not stay with them.

Supervision does not have to see everything.

The checks happen where value enters and where it leaves.

If you want to argue with it

The self-exposing detection of the Chaum line stayed on paper; it never ran in a live system, at real scale. Published central-bank offline experiments build on security hardware — on five vendors, the Bank of England's 2025 report says word for word: “All solutions used secure elements.”

The first construction showing that this combination of properties is achievable was given by Bauer, Fuchsbauer and Qian in 2021, with a complete, refereed security model and proofs, and by their own standard they call it practical. That is not in dispute. The difference, however, is measurable: from the published element counts the payment package is about 19 kilobytes and grows by about 7 kilobytes per hop, with no implementation, no measured running time and no curve choice. The Pactena solution stays at about 956 bytes even after ten hops, verified in about 12 milliseconds. The trade-off is deliberate: the Pactena chain depth is bounded on purpose (and is a configurable parameter).

External cryptographic review of the payment layer is under way; the outcome will be published.

As of August 2026 no publicly documented, working system is known that delivers all of this together. IACR ePrint, DBLP, the full text of Google Patents, the document archives of the BIS, the ECB, the Fed and the EDPB, twelve CBDC vendors, and the entire Real World Crypto corpus from 2015 to 2026 were combed through. If you know of another such solution, we would genuinely like to read about it.

The full survey ↗

Fraud reveals itself. Honesty does not.

Why Qashmore →