David Chaum and Digital Cash
Abstract
David Chaum worked out how to make money and messages anonymous in the 1980s, years before most people had heard of the internet. His blind-signature scheme (1983) made it possible to spend a digital coin that a bank had certified as real without the bank learning who spent it or where. His mix networks (1981) did the same for email, and became the intellectual ancestor of Tor. He turned the money idea into a company, DigiCash, and its eCash product ran on real bank accounts in the mid-1990s. Then it collapsed. Chaum turned down a reported $40 million from Visa and a bundling deal with Microsoft, banks licensed the technology and never shipped it, and ordinary web users declined to care about privacy they did not know they were losing. DigiCash went bankrupt in 1998. A decade later Bitcoin built anonymous digital cash on the one thing Chaum’s design still needed and could not shed: a company in the middle.
Big Brother Obsolete
David Chaum was born in Los Angeles in 1955 and took a computer science PhD at the University of California, Berkeley, in 1982. He came out of it with a conviction unusual for the era: that the computerization of payments and records was building the infrastructure of mass surveillance, and that cryptography was the only thing that could stop it. He laid the argument out plainly in a 1985 paper for Communications of the ACM titled “Security without Identification: Transaction Systems to Make Big Brother Obsolete.” The claim was that you could have all the accountability a bank or a state needed (no double-spending, no forgery, no fraud) while revealing none of the identifying detail that made records dangerous.
To get there he had already invented the two primitives the rest of his career rested on. In 1981 his paper “Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms” described a mix network: a chain of relays, each of which shuffles and re-encrypts the messages passing through it, so that no single relay can link a sender to a recipient. That idea runs underneath Tor and every anonymity system after it. In a 1983 paper, “Blind Signatures for Untraceable Payments,” he solved the harder problem of anonymous money.
The Blind Signature
A blind signature lets an authority sign a document without seeing it. Chaum’s own analogy was a sealed envelope lined with carbon paper: you sign the outside, the signature transfers to the paper inside, and you never read what you signed.
Applied to money, it works in steps. Your software generates a digital coin with a random serial number and multiplies it by a secret blinding factor, hiding the serial number. The bank checks your balance, deducts the amount, and signs the blinded coin, certifying “this is worth one dollar” without seeing the serial number. Your software divides out the blinding factor, leaving a valid, bank-signed coin the bank has never actually seen. When you spend it, the merchant deposits it and the bank recognizes its own signature and honors it, but cannot connect the coin to the withdrawal it came from. The bank stops double-spending by keeping a list of serial numbers already deposited. Privacy for the payer, safety for the bank, both at once.
DigiCash
Chaum founded DigiCash in Amsterdam in 1989 to sell the idea, under the product name eCash. In 1994 the company handed out one million dollars in test tokens called “CyberBucks” to online users, and the first real eCash payments followed. In 1995 the Mark Twain Bank of St. Louis became the first bank to issue eCash tied to actual dollars; Deutsche Bank, Credit Suisse, and banks in Australia and Austria licensed the technology.
The interest from the top of the industry was real. Visa reportedly offered $40 million for a stake. Microsoft wanted eCash built into Windows 95, which would have put a wallet on nearly every new PC in the world. Citibank negotiated seriously. On paper, in 1996, David Chaum held the patents on digital money at the exact moment electronic commerce was about to begin.
Dead End
None of it converted. By 1998 the whole eCash system counted roughly 5,000 users and 300 merchants, and DigiCash filed for bankruptcy. Its assets were sold and passed through eCash Technologies to InfoSpace in 2002.
The failure had several causes, and Chaum owned some of them. Former staff and reporters described him as a difficult negotiator who would not close: the Visa money, the Microsoft deal, and various bank rollouts stalled on terms and control he would not concede, and the banks that did license eCash never launched it to consumers at scale. There was a deeper problem than any single deal. eCash still needed a trusted operator, the bank issuing and clearing the coins, so it inherited exactly the central point of failure that a bank represents. It solved the customer’s privacy without removing the institution.
And the customers did not ask for it. Chaum’s own explanation was that he had arrived too early and aimed too high: “As the web grew, the average level of sophistication of users dropped. It was hard to explain the importance of privacy to them.” Web shoppers in 1996 wanted a checkout that worked, and credit cards, for all their surveillance, worked. The privacy eCash protected was a cost most users did not feel they were paying.
What Came After
The ideas outlived the company. When Bitcoin appeared in 2009 (see The Cryptocurrency Revolution), it was in a direct line from Chaum’s work, and it answered the one weakness he never removed: it replaced the trusted bank in the middle with a distributed ledger, so digital cash could clear with no operator to go bankrupt, be subpoenaed, or refuse a deal. The cypherpunks who built that world read Chaum first; he is fairly called the intellectual grandfather of cryptocurrency, and his mix networks did as much for the privacy movement as his coins did for money.
Chaum himself moved on to cryptographically verifiable voting, deploying the Scantegrity system in a binding public election in Takoma Park, Maryland, in 2009, and returned to the ledger world in 2020 with the privacy-focused xx network. His standing does not rest on a company that worked. It rests on having written down, before the internet was a mass medium, most of the mathematics that a surveillance-resistant digital society would eventually need.
📚 Sources
- David Chaum — Wikipedia — biography, the 1981/1983/1985 papers, DC-nets, voting systems, and the xx network
- DigiCash — Wikipedia — eCash mechanics, the Mark Twain Bank trial, the Visa and Microsoft approaches, the 5,000-user figure, and the 1998 bankruptcy
- David Chaum, “Security without Identification: Transaction Systems to Make Big Brother Obsolete” — Communications of the ACM 28:10 (1985) — Chaum’s own statement of the surveillance-versus-cryptography case
- David Chaum, “Blind Signatures for Untraceable Payments” — Advances in Cryptology (CRYPTO ‘82 Proceedings), 1983 — the blind-signature primitive underlying eCash