A wallet blinds a coin message before an issuer signs it, then unblinds the signature into a verifiable token. The issuer still controls issuance and redemption and must stop double spending, but need not learn which withdrawn coin was paid to which merchant.
Chaum’s objective was an electronic payment instrument with the portability and payer privacy of physical cash. A valid token should be transferable by data while remaining authentic and difficult to trace through the issuer. [David Chaum — Blind Signatures for Untraceable Payments] [David Chaum — Security Without Identification]
The wallet chooses a unique coin message and mathematically blinds it. The issuer checks funding or authorization and signs the hidden message, so it certifies value without seeing the final coin identifier. [David Chaum — Blind Signatures for Untraceable Payments]
The wallet removes the blinding factor while preserving the issuer’s valid signature. The resulting token can be publicly checked against the issuer’s key, yet the signature transcript does not reveal which withdrawal created it. [David Chaum — Blind Signatures for Untraceable Payments]
A payer gives the signed token to a merchant, who verifies it and normally sends it to the issuer for deposit. Redemption closes the loop because the token is a claim on that issuer rather than a self-existing commodity. [David Chaum — Blind Signatures for Untraceable Payments] [David Chaum — Security Without Identification]
Since digital tokens copy perfectly, an online issuer records redeemed serial numbers and rejects repeats. This spent set prevents inflation but means availability and final acceptance depend on contact with the mint. [David Chaum — Security Without Identification]
Chaum, Fiat and Naor described offline cash in which a payer could spend without immediate issuer contact. Carefully split identity information stayed hidden for honest use but could be reconstructed if the same coin was spent twice. [Chaum, Fiat and Naor — Untraceable Electronic Cash]
Fixed denominations simplify anonymous verification but make exact payment and change harder. Systems can withdraw several coins, return freshly issued change, or use protocols designed to avoid linking inputs and outputs. [David Chaum — Blind Signatures for Untraceable Payments] [GNU Taler — Design principles]
Blind signatures hide the withdrawal-to-payment link; they do not conceal merchant knowledge, network timing, malware, amount patterns or issuer shutdown. Backups and key handling also matter because bearer tokens can be lost or stolen. [David Chaum — Blind Signatures for Untraceable Payments] [David Chaum — Security Without Identification]
GNU Taler adapts blind-signature payments with income transparency rather than payer surveillance. Cashu and Fedimint use Chaumian tokens around Bitcoin and Lightning, trading global consensus for trust in a mint or federation. [GNU Taler — Design principles] [Cashu protocol specifications] [Fedimint documentation]
Bitcoin provides issuerless settlement and a public double-spend history; Chaumian eCash provides stronger payer unlinkability inside an issuer domain. They solve different trust problems and can be layered together rather than treated as identical money. [Cashu protocol specifications] [Fedimint documentation] [Bitcoin whitepaper]
For the clearest picture, read this entry together with David Chaum, Blind signature, DigiCash, Cashu, Fedimint, Double-spend. The reverse links also lead from DigiCash, Blind signature, Fedimint, Cashu.