105 / 691

b-money

b-money is Wei Dai’s 1998 proposal for anonymous distributed digital money and contract enforcement among pseudonyms without a state authority.

It described two distinct protocols: one with every participant keeping the account database, and another with a subset of bonded servers. It was not implemented and had neither Bitcoin’s blockchain nor Nakamoto consensus.

On the Cypherpunks mailing list, Wei Dai asked how untraceable digital pseudonyms could exchange value and enforce contracts without government or another outside authority. He treated money and agreement enforcement as infrastructure needed for cooperation. [Wei Dai — b-money original proposal] [Satoshi Nakamoto Institute — b-money archive]

The first protocol assumed an anonymous, synchronous and unjammable broadcast channel. Every participant kept a database of balances; Dai explicitly acknowledged that this communication premise made the protocol impractical. [Wei Dai — b-money original proposal] [Satoshi Nakamoto Institute — b-money archive]

Anyone could create units by broadcasting a solution to a previously unsolved computational problem. Issuance was valued from the estimated cost of the work against a standard basket of commodities, not a fixed supply schedule. [Wei Dai — b-money original proposal] [Satoshi Nakamoto Institute — b-money archive]

A payment was a signed message broadcast to the network. Participants checked the signature and sufficient balance, then debited the sender and credited the recipient in their separate copies of the collective ledger. [Wei Dai — b-money original proposal]

A contract specified maximum reparations, while its parties and an arbitrator posted special deposits. Balances changed after performance, agreement or adjudication, linking the proposed money to economic penalties for breach. [Wei Dai — b-money original proposal] [Satoshi Nakamoto Institute — b-money archive]

The second protocol moved account keeping to a subset of servers. Servers posted deposits and periodically published or committed to their databases, while participants checked consistency through randomly selected servers. [Wei Dai — b-money original proposal] [Cypherpunks Mailing List — b-money discussion thread]

In the second design, participants agreed a planned increase in supply and auctioned the right to create it. Planning, bidding, computation and creation were described, but no algorithmic issuance rule comparable to Bitcoin’s halvings was supplied. [Wei Dai — b-money original proposal] [Cypherpunks Mailing List — b-money discussion thread]

The proposal did not solve reliable anonymous broadcast, server selection and coordination, collusion resistance or final reconciliation of conflicting databases. These were open design assumptions, not a working consensus mechanism. [Wei Dai — b-money original proposal] [Cypherpunks Mailing List — b-money discussion thread] [Cryptoanarchy Wiki — Cypherpunks mailing-list archive repository]

The Bitcoin whitepaper lists b-money as its first reference. Preserved emails show Satoshi asking Wei Dai for citation details and later saying Bitcoin achieved nearly all its goals, but that record does not justify overstating direct technical inheritance. [Gwern archive — Wei Dai and Satoshi Nakamoto emails] [Bitcoin whitepaper] [Metzdowd Cryptography — archived 2008 draft correspondence]

b-money was not a launched currency, a blockchain or software running live consensus. It had no blocks, chainwork, UTXO set, 21-million cap or most-work-chain rule; its importance is as a precise historical proposal. [Wei Dai — b-money original proposal] [Gwern archive — Wei Dai and Satoshi Nakamoto emails] [Bitcoin whitepaper]

For the clearest picture, read this entry together with Wei Dai, Cypherpunks, Reusable Proofs of Work, Proof of Work, Hashcash, Bit Gold. The reverse links also lead from Cypherpunks, Bit Gold, Wei Dai, The Genesis Book.

DOC · 001Wei Dai — b-money original proposalPrimaryDOC · 002Satoshi Nakamoto Institute — b-money archiveDocumentationDOC · 003Cypherpunks Mailing List — b-money discussion threadDocumentationDOC · 004Gwern archive — Wei Dai and Satoshi Nakamoto emailsDocumentationDOC · 005Bitcoin whitepaperPrimaryDOC · 006Metzdowd Cryptography — archived 2008 draft correspondenceDocumentationDOC · 007Cryptoanarchy Wiki — Cypherpunks mailing-list archive repositoryDocumentation
Reviewed 1 August 2026Source-first · No investment advice