Chapter 16 of Trappe & Washington: the four requirements of digital cash and why an electronic object loses the one a physical coin gets free; Brands' scheme built on restricted blind signatures, where one spend hides the spender's identity and two spends reveal it automatically; Bitcoin's five stages, proof of work, and mining; and the boundary this chapter draws between what a cryptocurrency guarantees cryptographically — unforgeability, tamper-evidence, committed blocks — and what it assumes economically, namely that honest participants outspend any attacker.
Subject: Cryptography · 60 slides · diagram-first lesson
Open the interactive version of this deck
Title
Cryptography · Chapter 16
Unforgeable, anonymous, and spendable exactly once — and why the third requirement leaves mathematics behind
Objectives
Every previous chapter's requirements could be met by mathematics. This chapter's cannot, and the gap is where cryptocurrencies live.
Figure (svg): The four requirements of a digital cash system, and the tension between anonymity and double-spending detection.
Warm-up
A physical coin is unforgeable, anonymous and spendable once, and nobody designed those properties in.
Discussion prompt
Which of them does an electronic object lose, and why does losing it break the other two?
Hint: Ask what is different about copying.
Answer:
Spendable once is what it loses. A physical coin is hard to counterfeit and, crucially, leaves your hand when you spend it. An electronic object can be copied at essentially no cost, so spending it twice is the default behaviour rather than a difficult attack.
Unforgeability is recoverable — a bank's signature on the coin makes minting impossible for anyone else. Chapter 13 solved this.
But now anonymity is in tension with detection. To stop double spending you need to know which coins have been spent, and the natural way is for the bank to recognise each coin — which destroys anonymity.
So the design problem is precisely those two together: a bank that cannot recognise a coin it issued, and can nonetheless catch anyone who spends one twice. Section 16.2's answer is restricted blind signatures, and it is why that scheme is so much more complicated than a coin.
Figure (svg): The four requirements of a digital cash system, and the tension between anonymity and double-spending detection.
Section
Section 16.1 · pp. 319-320
Concept
The book's framing is that electronic objects reproduce at essentially no cost, in contrast to physical cash, which has usually been rather difficult to counterfeit. Everything about the design follows from that one difference.
Notice the tension. Preventing double spending in real time means the bank sees every transaction, which destroys anonymity and offline use. So the schemes below detect double spending instead — and detection means identifying the cheat, which means anonymity must be conditional.
Figure (svg): The four requirements of a digital cash system, and the tension between anonymity and double-spending detection.
Socratic
The obvious solution: the bank records every coin it issues and every coin it sees spent, rejecting repeats.
Discussion prompt
What does that cost, and why is it not the answer the chapter gives?
Hint: Consider anonymity, availability and scale in turn.
Answer:
It destroys anonymity. To reject a repeat the bank must recognise the coin, and if it can recognise a spent coin it can link it to the withdrawal. The result is a traceable payment system, which is what a bank transfer already is.
It requires the bank to be online for every transaction. A merchant cannot accept a coin without checking, so the system fails when connectivity does — and a physical coin works in a power cut.
And it scales badly: the list grows without bound, and every transaction worldwide is a query against it.
But it does work, and it is what every centralised payment system does. The interesting question is not whether the problem is solvable with a trusted central party — it obviously is — but whether it is solvable without one, or at least without the party seeing everything.
Section 16.2 removes the seeing, using blind signatures so the bank checks a list of coins it cannot link to people. Section 16.3 removes the central party altogether, at the price of an economic assumption.
Section
Section 16.2 · pp. 320-326
Concept
The book presents a system due to Stefan Brands, and is candid that it is much more complicated than the centuries-old system of actual coins — because catching electronic counterfeiters requires something like a signature attached to each coin, and attaching a signature is exactly what threatens anonymity.
The setup is done once by a central authority. Choose a large prime p with q = (p−1)/2 also prime — a safe prime, per Section 10.2 — and let g be the square of a primitive root mod p, so that g has order q.
\[ g^{k_1} \equiv g^{k_2} \!\pmod p \iff k_1 \equiv k_2 \!\pmod q \]
Two secret exponents are chosen, g₁ and g₂ are defined as g raised to them, and the exponents are then discarded — storing them serves no purpose and would compromise the system if discovered. The values g, g₁, g₂ are public, along with two hash functions.
Discarding the exponents is worth pausing on. It is a deliberate destruction of information so that nobody, including the designer, can ever exploit it — the same idea as a nothing-up-my-sleeve constant, and a pattern that recurs in trusted-setup ceremonies today.
Figure (svg): Withdrawing a coin: the spender blinds it, the bank signs without seeing it, and the spender unblinds.
Concept
An ordinary blind signature, from Section 13.1, hides the message completely: the bank signs a value it cannot see and cannot recognise later. That gives anonymity and no accountability at all.
A restricted blind signature constrains what the spender may construct. The blinding is arranged so that the coin necessarily embeds the spender's identity in a hidden form — and the protocol requires the spender to reveal a share of it at spending time.
One share reveals nothing. It is one linear equation in the identity's representation, and the equation is under-determined.
Two shares determine it. If the coin is spent twice, two different merchants issue two different random challenges, so the spender must produce two different shares — and two independent linear equations solve for the identity.
So the system gives anonymity for the honest and identification for the cheat, from one construction. The complexity of the Brands scheme is almost entirely the machinery to make this work.
Figure (svg): Double spending detection: one spend reveals one share of the identity, and two spends reveal enough to recover it.
Worked example
Three phases, and the third only happens to a cheat.
Withdrawal: the spender constructs a coin embedding her identity, blinds it, and sends it to the bank
Why: The bank debits her account and signs the blinded value. It knows it issued a coin to her and cannot recognise that coin later.
The spender unblinds, obtaining a coin bearing the bank's signature
Why: Unforgeable, because only the bank can produce that signature; anonymous, because the bank never saw the coin.
Spending: the merchant sends a random challenge, and the spender responds with a value derived from the challenge and her identity
Why: The merchant checks the bank's signature and the response's consistency. One challenge, one linear equation.
The merchant deposits the coin with the bank, which records it
Why: If the coin appears twice, the bank has two challenge-response pairs.
Verify: two different challenges give two independent equations, which solve for the identity
Why: So the cheat is identified by the mathematics, not by surveillance. The bank learns nothing about honest spenders and everything about a double spender — which is the property the whole scheme exists to deliver. Note that detection is after the fact: the second merchant has already been defrauded, and the system's remedy is legal rather than technical.
Figure (svg): Double spending detection: one spend reveals one share of the identity, and two spends reveal enough to recover it.
Anomaly
The scheme gives full anonymity to honest spenders and full identification of double spenders, with no authority deciding which is which.
Predict first
What makes this possible?
Correct: The identity is secret-shared into the coin, so one spend reveals one share and two spends reveal enough to reconstruct it
This is a genuinely elegant idea and it recurs: a secret released only when a rule is broken, with the rule-breaking itself supplying the second share.
It is also the reason the scheme is complicated. Every step exists to make the sharing sound: the spender must not be able to construct a coin with a false identity, and must not be able to answer two challenges with the same share.
Compare Chapter 17's secret sharing, which is the same mathematics used deliberately rather than as a trap.
Why: The identity is embedded so that each spend, under a merchant's random challenge, releases one linear equation about it. One equation is under-determined and reveals nothing; two are independent and solve. Nobody decides to revoke the anonymity — the act of double spending performs the revocation, automatically and with no discretion involved.
Figure (svg): Double spending detection: one spend reveals one share of the identity, and two spends reveal enough to recover it.
Socratic
The Brands scheme catches a double spender afterwards. It does not stop the second transaction happening.
Discussion prompt
Why is that considered an acceptable design, and when would it not be?
Hint: Compare with what prevention would require.
Answer:
Prevention requires an online check on every transaction, which means the bank is present in every payment — destroying offline use and, without blinding, anonymity. Detection buys back both.
And detection has teeth here because the identity is recovered with certainty, not merely suspected. The remedy is legal, and the deterrent is that cheating is guaranteed to be traced rather than probably caught.
It matches physical cash's model. A forged banknote is detected after acceptance too, and the system relies on the cost of forgery plus prosecution rather than on making forgery impossible.
When it is not acceptable: where the fraud is instantly profitable and the cheat is beyond legal reach — an anonymous party in another jurisdiction, or an amount large enough to justify absconding. Then only prevention will do, and prevention means being online.
Which is exactly why Bitcoin chose the other branch. It prevents double spending outright, by making everyone maintain the ledger — at the cost of every transaction being public forever, which is the opposite trade.
Concept
The mechanism is worth stating on its own, because it is the chapter's cleverest idea and the reason the scheme is so intricate.
The spender's identity is represented so that recovering it requires two independent linear equations. The coin carries the representation in blinded form, and the bank never sees it.
\[ \text{spend once} \;\Rightarrow\; 1 \text{ equation} \;\Rightarrow\; \text{under-determined}, \qquad \text{spend twice} \;\Rightarrow\; 2 \text{ equations} \;\Rightarrow\; \text{solved} \]
The merchant's random challenge is what makes the second equation independent of the first. Two different merchants issue two different challenges, so a spender reusing a coin cannot avoid producing two distinct responses.
Nobody decides to unmask the cheat. There is no authority holding an escrow key and no monitoring. The act of double spending performs the identification, automatically, and the bank learns nothing whatever about anyone who spends honestly.
Figure (svg): Double spending detection: one spend reveals one share of the identity, and two spends reveal enough to recover it.
Counterexample
Suppose a merchant generates its challenge from a counter, or from the time, rather than at random.
Discussion prompt
Show that a double spender can then escape identification.
Hint: She needs the two equations to be dependent rather than independent.
Answer:
She arranges to receive the same challenge twice. With a predictable challenge she can wait for the value to recur, or choose which merchant to visit and when.
Then her two responses are identical, so the two equations are the same equation. The system is still under-determined and her identity is safe.
She has spent one coin twice and cannot be identified, which defeats the entire construction — the bank knows a coin was double spent and has no idea by whom.
So the challenge must be fresh and unpredictable, which is the same requirement as a signature nonce in Chapter 13 and an IV in Chapter 6. It is the third context in which a predictable 'random' value destroys a scheme completely.
And the failure mode is identical each time: the value looks like a formality, its randomness is not obviously load-bearing, and an implementer replaces it with something convenient. Chapter 14's largest failure category, arriving once more.
Figure (svg): Double spending detection: one spend reveals one share of the identity, and two spends reveal enough to recover it.
Section
Section 16.3 · pp. 326-329
Concept
A ledger-based cryptocurrency using a combination of cryptography and decentralized consensus to track every transaction. The book reduces it to five stages, and every user performs all five.
Starting in the middle: transactions happen everywhere and each is broadcast. Every user collects them, verifies they are legitimate, and gathers the valid ones into a block. Then one user — say Zeno — gets lucky, broadcasts the news, and adds his block to the ledger.
About ten minutes later another user, Xenia, gets lucky. If she believes Zeno's block is valid she builds on it; if not, she does not. That choice, made independently by every participant, is the consensus mechanism.
Figure (svg): The five stages of Bitcoin: maintain a ledger, announce transactions, gather them into blocks, solve a puzzle, distribute the solved block.
Concept
The 'getting lucky' is a search. A miner assembles a block, appends a nonce, hashes the result, and checks whether the hash falls below a target. If not, she changes the nonce and tries again.
\[ H\bigl(\text{block} \, \| \, \text{nonce}\bigr) < \text{target} \]
The asymmetry is everything. Finding a nonce takes an enormous number of attempts; checking one takes a single hash. So a block is expensive to produce and free to verify — which is exactly what a distributed system needs, because every participant must verify and only one must produce.
The target adjusts so that, across the whole network's combined effort, a block is found about every ten minutes. Adding miners does not produce blocks faster; it makes each one more expensive.
Mining is the incentive. The successful miner is rewarded with newly created coins and the transaction fees in her block. That reward is what makes it profitable to spend electricity following the rules — the security argument is economic, and the cryptography only supplies the puzzle.
Figure (svg): Proof of work: miners search for a nonce making the block's hash fall below a target, which is hard to find and instant to check.
Worked example
Chapter 12 showed that hash pointers give tamper-evidence relative to a known head, and said agreeing on the head was a separate problem. This is the answer.
Suppose two miners find blocks nearly simultaneously, and the network splits — some users build on Zeno's block, some on Xenia's
Why: A fork. Both chains are internally consistent and neither is wrong.
The rule everyone applies: build on the chain with the most accumulated work
Why: Not the longest by count, but the one representing the most total computation — which is why the rule survives changes in difficulty.
Whichever fork attracts the next block pulls ahead, and miners on the other side switch to it
Why: Their block is orphaned and its transactions return to the pool. The split resolves itself, usually within one or two blocks.
To rewrite history, an attacker must redo the work of every block since the one she wants to change, and outpace the honest network while doing it
Why: Because her chain must become the one with most work.
Verify: this holds only if the honest network controls more computing power than the attacker
Why: That is the assumption, and it is about the world rather than about mathematics. No hash function guarantees it, and it can fail — smaller chains have been reorganised by rented hashpower. The cryptography is sound and the security is an economic argument.
Figure (svg): Two competing chains, with the network following whichever has the most accumulated work.
Anomaly
Bitcoin uses SHA-256, ECDSA signatures and Merkle trees, all sound. Its central claim is that the ledger cannot be rewritten.
Predict first
What is that claim actually based on?
Correct: The assumption that no single party controls more computing power than everyone else combined
The consequence is that security scales with the total work being spent, not with the cryptography. A small chain using the same SHA-256 is cheap to attack, and several have been reorganised by rented hashpower.
It is also why the book places this chapter after Chapter 15. Every earlier security claim was contingent on a mathematical assumption; this one is contingent on an economic one, and the difference in kind is worth noticing.
Why: Hashing makes tampering detectable and signatures make transactions unforgeable, but neither decides which of two consistent chains is real. That is settled by the most-work rule, and the rule only protects history if honest miners collectively outpace any attacker. It is an assumption about the distribution of resources in the world, and it is the load-bearing one.
Figure (svg): Two competing chains, with the network following whichever has the most accumulated work.
Section
Section 16.4 · pp. 329-338
Concept
Separating the two is the most useful thing to take from this chapter.
| Property | Comes from | Kind of guarantee |
|---|---|---|
| A transaction is authorised by the coin's owner | ECDSA signatures | cryptographic |
| The ledger's history is tamper-evident | hash pointers and Merkle trees | cryptographic |
| A block took real effort to produce | proof of work | cryptographic |
| Everyone agrees which chain is real | the most-work rule | economic assumption |
| History will not be rewritten | honest majority of hashpower | economic assumption |
| A coin has value | nothing in the protocol | social |
The top three are theorems. The next two hold while an assumption about the world holds. The last is outside the system entirely, and no amount of cryptography addresses it.
Figure (svg): What each requirement of digital cash costs, and which of them cryptography can supply alone.
Concept
Bitcoin is often described as anonymous. It is pseudonymous, and the distinction is sharp.
Addresses are public keys, not names — so there is no identity in the protocol. But every transaction is public and permanent, so the entire graph of payments is available to anyone, forever.
Chain analysis links addresses by clustering: inputs spent together are usually controlled by one party; change addresses are identifiable by pattern; and any point where a pseudonym touches the identified world — an exchange, a merchant, a delivery address — attaches a name to a cluster and, retroactively, to everything it ever did.
Compare the Brands scheme. There, anonymity is cryptographic: the bank cannot link a coin to a withdrawal, whatever it later learns. Here, anonymity is a matter of not being linked yet — and the ledger is permanent, so the analysis can improve indefinitely against transactions already made.
This is the clearest illustration of the chapter's theme. Two systems both called anonymous digital cash, with guarantees of completely different kinds.
Figure (svg): Pseudonymity against cryptographic anonymity: a permanent public graph that can be de-anonymised later, against a bank that cannot link a coin at all.
Comparison
The Brands scheme and Bitcoin solve the same problem in opposite ways. Fill the blanks.
Comparison matrix
| Brands digital cash | Bitcoin | |
|---|---|---|
| Double spending is | detected afterwards | prevented, by a shared ledger |
| Requires a trusted party? | yes — the bank issues coins | no issuer; a majority assumption instead |
| Anonymity | cryptographic — the bank cannot link a coin | pseudonymous — a permanent public graph |
| Works offline? | yes — the merchant checks a signature | no — confirmation needs the network |
| Security rests on | discrete logarithms | an honest majority of computing power |
Neither dominates. One needs a bank and gives real anonymity; the other needs no bank and gives a permanent public record of everything.
Notation
One inequality, and every property of mining follows from it.
Annotate
On: \( H\bigl(\text{header} \, \| \, \text{nonce}\bigr) < T \)
Expensive to satisfy, instant to check, and self-adjusting. Those three properties are what make it usable as a distributed clock.
Estimation
The network's difficulty adjusts so that a block appears about every ten minutes.
Predict first
Roughly how many hash computations does the whole network perform per block?
Correct: About 10²²
Note what this does and does not buy. It makes rewriting history expensive in proportion to how deep the change is — but only against an attacker who cannot match the network. Against one who can, the same rule that protects the honest chain protects the attacker's.
It is also why the energy debate is not incidental to the design: the cost is the security, so making it cheaper makes the ledger easier to rewrite. That coupling is what proof-of-stake systems try to break.
Why: At a network hashrate on the order of 10²⁰ hashes per second and 600 seconds per block, that is around 10²² attempts for each block found. The number is enormous by design: it is what an attacker must match and exceed to rewrite even one block, and it is why the security is measured in accumulated work rather than in bits.
Figure (svg): Proof of work: miners search for a nonce making the block's hash fall below a target, which is hard to find and instant to check.
Definition probe
Sorting these correctly is the whole point of the chapter.
Sort into buckets
Classify each property of a proof-of-work cryptocurrency.
Explain it to yourself
The puzzle produces no useful output. The hash that solves it is discarded.
Discussion prompt
Explain what the expense is buying, and why a cheap puzzle would not work.
Hint: Ask what an attacker must do to rewrite a block.
Answer:
The expense is the security. Rewriting a block means redoing its proof of work and every proof after it, faster than the honest network extends the chain. The cost of that attack is exactly the cost of the work being redone.
A cheap puzzle would let anyone rewrite history, because catching up would cost nothing. There would still be tamper-evidence — the hashes would not match — but no reason to prefer one chain over another.
It also rate-limits block creation without a clock. In a network with no trusted time source, the difficulty of the puzzle is what makes blocks arrive at a predictable rate, which is what lets participants agree on an ordering.
And it makes participation costly, which is a defence against Sybil attacks: creating a thousand identities is free, but creating a thousand identities' worth of hashpower is not. Votes are weighted by work rather than by identity.
The uncomfortable corollary: since cost is the security, reducing the energy cost reduces the security proportionally. That coupling is intrinsic to proof of work, and it is why alternatives such as proof of stake replace the resource rather than making it cheaper.
Error analysis
From the specification for a store-and-forward digital token system.
Annotate
The signature makes it unforgeable and does nothing else. The three remaining requirements are all unmet, and the fix is the challenge-response that turns a coin into a one-time object.
Real world
Brands' scheme and its relatives were published in the early 1990s, worked, and were not deployed at scale.
Discussion prompt
What defeated them, and what does that suggest about deploying cryptographic protocols generally?
Hint: Chapter 15's Secure Electronic Transaction met the same fate for related reasons.
Answer:
They needed an issuing bank willing to run them, and banks had no incentive to offer a payment instrument they could not trace or reverse. The anonymity that was the scheme's contribution was the reason its operator did not want it.
They needed software on the customer's device, in an era before that was routine — the same obstacle that sank SET.
And credit cards over SSL were good enough. Chargebacks handle fraud, the merchant absorbs the cost, and no user has to install anything. A worse-privacy solution with better operational properties won, which is the ordinary outcome.
What it suggests generally: a protocol competes on operational cost and incentive alignment, not on its security properties. A scheme whose main benefit accrues to users and whose main cost falls on the operator will not be deployed by the operator.
And it explains Bitcoin's shape. It succeeded partly by needing no bank's cooperation at all — the design removes the party whose incentives blocked the earlier schemes, which is a structural answer to a non-technical problem.
Two truths and a lie
Two of these are claims the mathematics does not support.
Eliminate the wrong options
Which statement is correct?
Survives elimination: a
Why: Tamper-evidence is the cryptographic guarantee and it is real. Immutability is an economic one and holds only under a majority assumption. And truthfulness is not a property of the system at all. Keeping the three apart is what lets you evaluate a proposal to 'put X on a blockchain' — the question is always whether the problem was tamper-evidence, and it usually was not.
Ranking
The four requirements from the start of the chapter, ranked by the machinery they need.
Put in order
Why: Unforgeability is one signature — Chapter 13. Anonymity is a blind signature, from the same chapter. Detecting double spending needs the restricted blind signature and its secret-sharing structure, which is where the Brands scheme's complexity lives. And decentralised agreement leaves cryptography entirely: it needs an incentive structure and a majority assumption. The ordering tracks how far each requirement sits from mathematics.
Figure (svg): What each requirement of digital cash costs, and which of them cryptography can supply alone.
Socratic
Each block header contains a single Merkle root committing to all its transactions.
Discussion prompt
Why not just hash the transactions together, and what does the tree structure buy?
Hint: Chapter 12 answered this; the application is what is new.
Answer:
A flat hash would commit to all of them equally well — any change to any transaction changes the digest. So for tamper-evidence alone, a tree is unnecessary.
The tree buys short membership proofs. To prove a transaction is in a block, supply its sibling and one node per level — about log₂ n hashes rather than every transaction in the block.
Which enables lightweight clients. A phone can verify that a payment to it was included in a block by downloading only the headers and a short proof, rather than the whole chain. Without the tree, verification would require the full data.
And it makes headers small and uniform. A block header is a fixed size whatever the block contains, so the chain of headers — the thing that carries the proof of work — stays compact.
The general pattern from Chapter 12: commit to a large set with one value, and prove one element in logarithmic space. Certificate Transparency and content-addressed storage use the identical construction for the identical reason.
Figure (svg): Proof of work: miners search for a nonce making the block's hash fall below a target, which is hard to find and instant to check.
Commit first
A cryptocurrency uses SHA-256, ECDSA on secp256k1, Merkle trees and proof of work, all implemented correctly.
Predict first
Where is the realistic failure?
Correct: Key management — users losing or having private keys stolen, and exchanges being compromised
There is also a cryptographic implementation failure with real history: reused or biased ECDSA nonces, which Chapter 13 showed recover the private key outright. Wallets have shipped with this bug and had funds drained.
And the structural point: removing the trusted party removed the recovery mechanism with it. A bank can reverse a fraudulent transfer; a blockchain cannot, by design. That is the same trade in a different place — the property that makes it censorship-resistant makes it unforgiving.
Why: Every cryptographic component is sound and none has been broken. What actually causes loss is key custody: a private key is a bearer instrument with no recovery path, so theft is final and loss is permanent. Exchange compromises, malware stealing wallet files, and users losing their own keys account for essentially all realised losses.
Constraint
A colleague proposes putting a company's internal audit log 'on a blockchain'.
Discussion prompt
Work out whether it fits, and say what would actually solve the problem.
Hint: Ask which of the guarantees is needed, and whether there is a trusted party.
Answer:
Identify the requirement. An audit log needs tamper-evidence: nobody, including an administrator, should be able to alter history undetectably.
Tamper-evidence needs only hash pointers. Chapter 12's construction gives it with no consensus, no mining and no currency — a hash chain where each entry commits to the previous one, with the head published somewhere the administrator does not control.
Consensus is the expensive part, and it is not needed here. There is a trusted party — the company — and the question is only whether it can cheat. Publishing the head to a third party, or to a public transparency log, answers that.
A blockchain would add proof of work or a validator set, a currency, and a distributed network, to solve an agreement problem that does not exist. It would also make the log public, which an audit log usually must not be.
The rule: a blockchain is the right answer when there is no party everyone trusts and the ledger must be public. Where a trusted party exists, a hash chain plus an external witness is the same guarantee at a fraction of the cost.
This is worth stating clearly because the mismatch is extremely common: most proposals to use a blockchain are proposals to solve tamper-evidence, and tamper-evidence was solved in 1979.
Faded example
Four blanks, and the elegance of the Brands scheme is visible in them.
Fill in the blanks
The coin embeds the spender's identity in a form requiring two equations to recover. At spending time the merchant issues a random challenge, and the spender's response gives one equation. So an honest spender stays anonymous, and a double spender supplies two equations and is identified.
Why: The merchant's challenge must be random and unpredictable, or a cheating spender could arrange to receive the same challenge twice and answer identically — producing one equation rather than two and escaping identification. It is the same requirement as a signature nonce in Chapter 13, and it fails in the same way: predictability defeats the whole construction.
Discrimination
Six mechanisms across the two systems in this chapter.
Sort into buckets
Sort each by the requirement it addresses.
Edge cases
A merchant is told to wait six confirmations before treating a payment as settled.
Discussion prompt
What does each confirmation buy, and is settlement ever final?
Hint: Ask what an attacker must do to reverse a transaction n blocks deep.
Answer:
Each confirmation is one more block of work an attacker must redo. To reverse a transaction six blocks deep, she must build a competing chain of at least seven blocks faster than the honest network builds one — so the cost grows with depth.
Six is a convention, not a threshold. It corresponds to a probability of reversal that is small under the assumption that the attacker controls well under half the hashpower. If she controls more, no number of confirmations suffices.
So settlement is probabilistic, never final. This is a genuine difference from a bank transfer, which is final by legal fiat. A blockchain offers 'increasingly unlikely to be reversed', which is a different kind of assurance.
And the right number depends on the value. A coffee needs zero confirmations because reversing it is not worth the work; a large transfer might sensibly wait for many more.
The general point, and it is the chapter's: where the guarantee is economic, the right parameter is set by comparing the attacker's cost with her gain. That is a business calculation, and no amount of cryptography settles it.
Missing information
The phrase appears in product descriptions constantly.
Discussion prompt
List what remains undetermined, in the order you would ask.
Hint: Start with whether the agreement problem exists at all.
Answer:
Is there a trusted party? If yes, consensus is unnecessary and a hash chain with an external witness gives the same tamper-evidence far more cheaply.
Who validates, and what stops a Sybil attack? Proof of work, a permissioned validator set, or nothing? 'Distributed' without an answer here means 'a database with extra steps'.
What is the cost of rewriting history, in money? For a small chain this can be a few hundred dollars an hour of rented hashpower — a number worth computing before relying on immutability.
Is the data public, and must it be? Permanent publication is a feature for a currency and a liability for anything containing personal information, which cannot then be deleted.
How are keys custodied and recovered? This is where all realised losses occur, and 'not our responsibility' is a common answer.
And what is actually being solved? If the answer is tamper-evidence, that was solved in 1979 and needs none of the rest.
Prediction
Two miners find blocks at nearly the same moment, the network splits, and one branch is abandoned.
Predict first
What happens to the transactions in the abandoned block?
Correct: They return to the pool and are usually included in a later block
This is also why a transaction with one confirmation is not settled: a shallow reorganisation is a normal event, not an attack, and a payment can move from block 500 to block 501 without anything going wrong.
And it is why a double spend attack works the way it does: the attacker's goal is to get a conflicting transaction into the winning chain, so that the original becomes unincludable rather than merely delayed.
Why: The transactions themselves are still validly signed and still unspent, so miners simply put them back into the pool and include them in a subsequent block. Only the block is orphaned, not the transactions. The exception is the block reward, which is created by the block and disappears with it — which is why miners have a strong incentive to build on the chain everyone else is building on.
Figure (svg): Two competing chains, with the network following whichever has the most accumulated work.
Notation
Two systems both described as anonymous, and the difference is in the quantifier.
Annotate
On: \( \text{Bitcoin: } \Pr[\text{linked}] > 0 \text{ and grows} \qquad \text{blind signature: } \Pr[\text{linked}] = \tfrac{1}{N} \)
The lesson generalises past currency: 'anonymous' is a claim about a specific adversary with a specific view, and the anonymity set is usually the binding constraint rather than the mathematics.
Estimation
A blind-signature system's privacy depends on how many indistinguishable coins exist.
Predict first
If a bank issues 1000 coins in a batch, what is an observer's best guess about which one a given spend came from?
Correct: 1 in 1000
Which makes the anonymity set the number to ask about. A system with ten users gives one-in-ten anonymity however good its cryptography, and the mathematics cannot compensate.
This is the same reasoning that makes a mix network or a privacy pool's size the headline figure, and why such systems are less private when they are less popular — an unusual property, where adoption is a security parameter.
Why: Every coin in the batch is equally consistent with the one being presented, so the probability is 1/1000 and no computation improves it. This is an information-theoretic guarantee like the one-time pad's — and, exactly as there, its strength depends on a parameter under the operator's control rather than on any hardness assumption.
Error analysis
From the technical section of a proposal.
Annotate
The first claim is the load-bearing error, and it is the chapter's central point restated: security is hashrate, and hashrate is not inherited.
Missing information
A specification says coins are signed by an issuer and verified by merchants.
Discussion prompt
List what remains undetermined, ordered by how badly each could fail.
Hint: Work through the four requirements in turn.
Answer:
What stops a coin being spent twice? Prevention needs an online check; detection needs an embedded identity and a challenge-response. A signature alone gives neither, and this is the requirement most often left out.
Is the challenge fresh and unpredictable? A predictable challenge lets a double spender produce two identical responses and escape identification entirely.
Is the issuance blinded? Without it the issuer can link every coin to a withdrawal, and the system is a traceable ledger with extra steps.
What happens to the setup secrets? Parameters with a hidden relationship must be destroyed, or whoever holds them can forge.
What is the detection latency and the remedy? Detection after the fact means a merchant has already been defrauded, and the answer must be legal rather than technical.
And what is the anonymity set? A system with few users provides little privacy regardless of the mathematics.
Picture it
The chapter's shape in one picture. The bars get longer as the requirement moves away from mathematics.
Figure (svg): What each requirement of digital cash costs, and which of them cryptography can supply alone.
The first two were solved three chapters ago. The third needed a new construction. The fourth needed an economy.
Explain it
A colleague says mining burns electricity to compute numbers that are thrown away, and that this is obviously absurd.
Discussion prompt
Give the honest explanation — including the part where they are right.
Hint: The waste is the mechanism, not a side effect.
Answer:
Concede the observation: the winning hash is discarded and computes nothing useful. That is accurate.
Then explain what the cost buys. In a network with no trusted party, something must make it expensive to propose a version of history. The electricity is that expense — rewriting the last hour of the ledger means redoing an hour of the entire world's mining, faster than it happens.
And it solves a second problem: identities are free to create, so votes cannot be counted per participant. Weighting by work makes creating a thousand identities useless unless you also have a thousand identities' worth of hardware.
Then the uncomfortable corollary, which is where they are right: because the cost is the security, making it cheaper makes the ledger easier to rewrite. The two cannot be separated within this design, so 'greener proof of work' is close to a contradiction.
Which is why alternatives replace the resource rather than reducing it. Proof of stake makes the expensive thing a deposit that can be confiscated instead of energy that is spent — a different assumption about the world, not an escape from needing one.
The honest summary: the waste is the mechanism, and disliking it is a reasonable position about the mechanism rather than a misunderstanding of it.
Cost model
The security of a proof-of-work ledger is a number in currency, and it can be computed.
Annotate
On: \( \text{cost} \approx \text{(fraction of network hashrate rented)} \times \text{(time)} \times \text{(price per hash)} \)
No cryptographic parameter appears anywhere in this formula, which is the clearest statement of where this chapter's security actually lives.
Real world
The majority assumption is not hypothetical, and it has failed repeatedly.
Discussion prompt
What happens when it does, and what does that tell you about how to evaluate such a system?
Hint: Think about chains sharing an algorithm with a much larger one.
Answer:
Several smaller proof-of-work chains have been reorganised by rented hashpower, with attackers reversing their own deposits at exchanges after withdrawing other assets — a double spend at scale, executed for a few hours' rental cost.
The pattern is chains that share a hash algorithm with a much larger one. Capacity built for the large chain can be pointed at the small one for an afternoon, so the small chain's security is set by the large chain's spare capacity rather than by its own miners.
The cryptography was never involved. SHA-256, the signatures and the Merkle trees all behaved exactly as specified. The assumption about resource distribution was false.
How to evaluate such a system, then: compute the cost of an hour of majority hashrate and compare it with the value of transactions being settled. If the second exceeds the first, the ledger is not protecting them.
And the general lesson for the whole course: a security claim resting on an assumption about the world requires you to check that assumption in your setting. It is not inherited from the protocol, and it does not transfer between deployments.
Explain it to yourself
The Brands scheme's initialisation chooses two secret exponents, defines g₁ and g₂ from them, and then destroys them.
Discussion prompt
Explain why keeping them would be dangerous, and name the modern practice this anticipates.
Hint: Ask what someone knowing the relationship between g, g₁ and g₂ could do.
Answer:
Knowing the exponents means knowing the discrete logarithms relating g, g₁ and g₂. The scheme's security assumes nobody can find them, so anyone who simply kept them has the trapdoor the whole construction was built to be without.
With them, a spender could construct coins whose identity representation is false, or produce two responses that appear independent while encoding nothing — defeating both unforgeability and double-spending detection.
The book's phrasing is exact: storing them serves no useful purpose, and if a hacker discovers them the system is compromised. The safest state for a secret nobody needs is not to exist.
The modern practice this anticipates is the trusted setup ceremony, used by zero-knowledge proof systems whose parameters have exactly this shape. Participants contribute randomness and destroy their contribution, and the setup is secure if any one participant was honest.
And the related idea is nothing-up-my-sleeve numbers — constants derived from digits of π or similar, so that no designer could have chosen them to embed a trapdoor. AES's S-box being algebraic rather than tabulated is Chapter 8's version of the same concern.
Trade off
Both are called privacy and they are different guarantees. Fill the blanks.
Comparison matrix
| Bitcoin | Blind-signature cash | |
|---|---|---|
| What is public | every transaction, permanently | nothing beyond the coin's validity |
| Linkage to identity | possible, by clustering and touchpoints | impossible — the bank never saw the coin |
| Improves or decays over time | decays — analysis improves against a permanent record | fixed — no later analysis helps |
| Accountability for cheating | prevention, so none needed | the identity is revealed automatically |
| Kind of guarantee | not linked yet | cannot be linked |
The third row is the decisive one. A permanent public record means today's privacy is subject to tomorrow's analysis, which is not a risk an unconditional guarantee has.
Sorting
Nothing in this chapter is a new primitive. Everything is assembled from earlier ones.
Sort into buckets
Sort each ingredient by where it came from.
One new construction in the whole chapter. What is new is the combination, and the requirement — agreement without a trusted party — that no combination of primitives can meet.
Commit first
Three settlement options for a transfer worth more than the daily rental cost of a small chain's hashrate.
Predict first
Which do you choose?
Correct: A large proof-of-work chain, waiting a generous number of confirmations
The point of the question is that the answer depends on a number — attack cost against transaction value — rather than on which technology is better. That is what an economic security guarantee means in practice.
And it explains the confirmation convention: waiting is how you buy more attack cost, and the right amount of waiting scales with the amount at stake.
Why: The small chain fails the cost comparison outright — reversing the transfer costs less than the transfer is worth, and hashpower for its algorithm is rentable. The large chain's attack cost exceeds any plausible gain, and confirmations deepen the protection. A bank transfer is also defensible and offers legal reversibility, which is a different guarantee. The digital cash scheme detects double spending after the fact, which is the wrong shape for a single large payment with no ongoing relationship.
Edge cases
A blind signature makes linking a coin to a withdrawal impossible. That is a strong statement with edges.
Discussion prompt
What can still de-anonymise a spender in such a system?
Hint: The cryptography is not the only channel.
Answer:
Timing and amounts. If Alice withdraws a coin of an unusual denomination and one appears minutes later at a merchant, the correlation is obvious without any cryptography being broken. This is traffic analysis, from Chapter 1.
The network layer. The coin travels over a connection with an IP address attached. Blinding protects the coin's contents and not its envelope.
The merchant relationship. A coin spent at a shop that ships to an address links the transaction to a person, whatever the bank can or cannot see.
And withdrawal patterns. If very few people use the system, being a user at all is identifying, and set-size is a limit no protocol can raise.
So the guarantee is precise and narrow: the bank cannot link this coin to this withdrawal. Everything outside that sentence is a separate problem, and most real de-anonymisation happens outside it.
Which is Chapter 1's lesson in its last appearance: a cipher protects the values and not the pattern of the values, and the pattern is often most of the information.
Pattern
This is the first chapter in the book whose requirements cannot all be met by mathematics, and the boundary is worth drawing precisely.
The habit to carry: when a system claims a property, ask whether it is a theorem, an assumption about the world, or a social fact. All three appear in this chapter, and only the first is what the previous fifteen chapters were about.
Figure (svg): What each requirement of digital cash costs, and which of them cryptography can supply alone.
Trap
The trap. Each block contains the hash of the previous one, so altering any block breaks every hash after it. The data is therefore immutable — it cannot be changed, and that is a cryptographic guarantee.
This is the standard description, and the first sentence is exactly right.
Why it fails. Hashing gives tamper-evidence, not immutability: it makes a change detectable to anyone holding the true head. It does nothing to prevent someone building an alternative chain, which is perfectly consistent and equally valid to the hash function.
What actually prevents rewriting is the cost of redoing the work, plus the rule that the chain with the most work wins. Both are outside the cryptography, and the second holds only while honest participants control more hashpower than any attacker.
And that assumption fails in practice. Several smaller proof-of-work chains have been reorganised by attackers renting hashpower for a few hours, at costs in the hundreds or thousands of dollars. Their cryptography was identical to Bitcoin's.
The accurate statement is: rewriting history is detectable, and costs approximately the work done since the point being changed. That is an economic barrier of computable size, and treating it as an absolute is how people end up relying on a chain whose reorganisation costs less than the transaction they are protecting.
The general habit: whenever a system's guarantee involves a majority, a cost, or an incentive, it is an assumption about the world. Assumptions about the world change; theorems do not.
Check
Work it out before you click.
Check your understanding
Hash pointers already make a chain tamper-evident. What does proof of work add?
Answer: B
Why: Hash pointers detect alteration relative to a known head; they cannot say which of two internally consistent chains is real. Proof of work attaches a measurable cost to each block, so 'the chain with the most work' becomes a rule everyone can apply independently and nobody can cheaply subvert. It solves agreement, not integrity.
Check
Recall how the identity is protected and released.
Check your understanding
In the Brands scheme, why does spending a coin once reveal nothing about the spender?
Answer: B
Why: The identity is embedded so that recovering it needs two independent equations. One spend, under one merchant's random challenge, produces one — leaving the system under-determined and the spender anonymous. A second spend under a different challenge produces the second equation, and the identity falls out. Nobody decides to revoke the anonymity; double spending performs the revocation.
Check
The distinction this chapter exists to draw.
Check your understanding
Which of these is an economic assumption rather than a cryptographic guarantee?
Answer: C
Why: Immutability of history depends on honest participants controlling more hashpower than any attacker — a claim about how resources are distributed in the world, not a theorem. It has failed for several smaller chains. The other three follow from signature unforgeability, Merkle tree structure and hash collision resistance respectively, and hold regardless of who owns what.
Connect it up
This chapter's value is knowing where the mathematics ends.
Draw it
List the four requirements of digital cash and, beside each, the mechanism that meets it and whether that mechanism is a theorem, an assumption about the world, or a social fact. Then draw the withdraw-spend-deposit cycle of the Brands scheme, marking where anonymity comes from and where the second equation appears. Beside it, draw Bitcoin's five stages and mark which one involves no cryptography. Finish with the accurate one-sentence statement of what a blockchain guarantees.
That final sentence — tamper-evidence relative to a head, and a cost to rewrite proportional to the work since — is the version worth being able to say precisely, because almost every claim made about blockchains is a loose version of it.
Exit ticket
One question, about the boundary this chapter draws.
Predict first
What does a proof-of-work cryptocurrency assume that is not a mathematical fact?
Correct: That honest participants collectively control more computing power than any attacker
Why: The other three are cryptographic assumptions of the ordinary kind — well studied, and about mathematics. The majority-hashpower assumption is about how resources happen to be distributed in the world, it can change, and it has changed for smaller chains that were reorganised by rented computing power. Tamper-evidence is cryptographic; immutability is economic, and separating the two is what this chapter is for.
Recap
The first requirements in this book that mathematics alone cannot meet.
Chapter 17 next. Secret sharing: splitting a secret among n people so that any k of them can recover it and any k−1 learn nothing at all. It is the same polynomial mathematics that hid the identity in a coin, used deliberately — and it is unconditionally secure, which almost nothing in this book is.
Figure (svg): What each requirement of digital cash costs, and which of them cryptography can supply alone.
Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.