Skip to content

LibraryCredit and stable value1998Design paperCorpus record

b-money

b-money. Wei Dai.

Participants broadcast contract offers. Money is created by solving a computational problem, and a collective bookkeeping system tracks balances. A second variant uses a subset of servers.

A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.

Read it as the problem statement: joint bookkeeping without an issuer. Do not read it as a system you can implement line by line.

The five-minute read

The defect

A digital cash system that uses a central issuer can be switched off. Dai asked whether a group of untraceable pseudonyms could keep the books themselves.

The proposal

Participants broadcast contract offers. Money is created by solving a computational problem, and a collective bookkeeping system tracks balances. A second variant uses a subset of servers.

Creation of money is tied to computational cost.

The ledger is collective, not a bank's database.

The bound

This is a sketch, not a protocol with a proof.

One action, walked through

  1. Broadcast a signed update.
  2. The collective book-keepers apply it if the contract rules say so.
  3. Disputes are referred to the servers in the second variant, who must be replaced if they misbehave.
  4. What happens when two book-keepers disagree?

The argument, unpacked

What the paper is for

Read it as the problem statement: joint bookkeeping without an issuer. Do not read it as a system you can implement line by line.

What happened after

Bitcoin, and then every stake design, is a later answer to the agreement problem this note leaves open.

What has to be true

  • This is a sketch, not a protocol with a proof.
  • It is not Bitcoin, though Bitcoin cites the problem.
  • It does not describe mining pools, difficulty adjustment, or script.

What happened after the paper

Bitcoin, and then every stake design, is a later answer to the agreement problem this note leaves open.

What to check before you use the idea

  • Who updates the books?
  • What happens when two book-keepers disagree?
  • How is new money created?

Terms

Collective bookkeeping
A ledger held by the participants rather than an issuer.
Contract
A broadcast offer the note treats as the transaction.

The problem the paper names

A digital cash system that uses a central issuer can be switched off. Dai asked whether a group of untraceable pseudonyms could keep the books themselves.

What the design proposes

  • Creation of money is tied to computational cost.
  • The ledger is collective, not a bank's database.
  • The sketch leaves the agreement protocol unspecified. That gap is the whole of the later consensus literature.

How the mechanism is specified

  • Broadcast a signed update.
  • The collective book-keepers apply it if the contract rules say so.
  • Disputes are referred to the servers in the second variant, who must be replaced if they misbehave.

What this page does not treat as proven

  • This is a sketch, not a protocol with a proof.
  • It is not Bitcoin, though Bitcoin cites the problem.
  • It does not describe mining pools, difficulty adjustment, or script.

Why a venture studio still reads it

Read it as the problem statement: joint bookkeeping without an issuer. Do not read it as a system you can implement line by line.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.