Bitcoin Institute

David Chaum (1955–)

Invented blind signatures and founded DigiCash

Figures

Dark-navy technical illustration: a blinded, unreadable document passes a signing stamp and becomes a verified token, which leads to a padlocked coin labeled "DigiCash eCash" and then to a crumbling bank, with a horizontal timeline marking 1981, 1990, and 1998.

Bitcoin’s whitepaper never cites David Chaum. It didn’t need to — by the time Satoshi Nakamoto released it, Chaum’s attempt at anonymous digital cash had already been built, sold to banks, and gone bankrupt, more than a decade earlier. Twenty-seven years before the genesis block, in 1982, he had already solved the privacy half of the problem. He had not solved the trust half, and that gap was one of the reasons DigiCash became a historical footnote while Bitcoin did not.

From mix networks to blind signatures (1955–1982)

Chaum was born in 1955 in Los Angeles, California. He earned a PhD in computer science from the University of California, Berkeley in 1982, advised by Bernard Marcel Mont-Reynaud. His dissertation, “Computer Systems Established, Maintained, and Trusted by Mutually Suspicious Groups,” proposed a chain of cryptographic checksums linking blocks of data into an immutable, timestamped record — secured not by proof-of-work, which would not be theorized for another decade, but by tamper-evident physical hardware.

By then Chaum had already published his first major result. In the February 1981 issue of Communications of the ACM, he introduced the mix network in “Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms” — a scheme for routing encrypted messages through relays that reorder and re-encrypt them, so no observer of the network can link a message’s sender to its recipient.

1955Born in Los Angeles,California1981Publishes mix-networkpaper inCommunications of theACM (Feb)1982PhD from UC Berkeley;presents blindsignatures at CRYPTO'82 (Aug 23-25)1983IACR formed, withChaum on its foundingorganizing committee1988Extends blindsignatures to offlineelectronic cash, withAmos Fiat and MoniNaor1990Founds DigiCash inAmsterdam1995Mark Twain Bankbecomes first to issueeCash1998DigiCash files forbankruptcy2016Begins designing xxnetwork, aprivacy-focusedblockchain

Chaum organized and presented at the CRYPTO ‘82 conference in Santa Barbara (August 23-25, 1982), where he unveiled “Blind Signatures for Untraceable Payments.” The technique lets a signer certify a message without ever seeing its contents — a bank can authorize a token as genuine without learning which token it authorized, or who will spend it. It is the cryptographic primitive that would let a payment be as untraceable as physical cash while still being verifiable. Chaum patented it the following year. At that same conference he proposed forming a standing research association; it was formed the next year as the International Association for Cryptologic Research (IACR), with Chaum as one of the seven members of its founding organizing committee.

DigiCash and eCash (1990–1998)

In 1988, working with Amos Fiat and Moni Naor, Chaum extended blind signatures into a design for offline electronic cash that did not require a real-time connection to a bank to prevent double-spending. In April 1990 he founded DigiCash in Amsterdam to commercialize the idea, and by 1994 the company had sent its first electronic payment. In 1995, Mark Twain Bank in St. Louis became the first bank to issue eCash, DigiCash’s blind-signature-based digital currency, followed by Deutsche Bank the next year.

Bigger deals kept falling through. Visa reportedly offered around $40 million for a stake in the company; ING and ABN Amro discussed partnerships worth tens of millions more; Citibank negotiated seriously and pulled out. The closest DigiCash came to mass distribution was Microsoft: Bill Gates wanted to bundle eCash into Windows 95, reportedly offering on the order of $100 million, but the licensing terms Chaum proposed — a per-copy fee — broke off the talks. By 1998, after eight years in business, DigiCash had signed only a few hundred merchants and a few thousand users. That year the company filed for bankruptcy; its patents and remaining assets were sold off, eventually landing with eCash Technologies before InfoSpace acquired what was left in 2002.

The gap DigiCash could not close

DigiCash’s eCash was anonymous the way physical cash is anonymous — the blind signature hid a token’s history from the bank that issued it. But every eCash token still had to be issued and redeemed by a bank. The system removed banks from watching individual transactions; it never removed them from the currency itself. Satoshi’s design took the opposite emphasis, with no documented link back to Chaum’s work: rather than hiding a payment from any single institution, it eliminated the institution’s role in confirming one, using Adam Back’s proof-of-work rather than a bank’s signature to make double-spending costly. Hashcash’s own 1997 announcement placed itself explicitly alongside DigiCash and eCash — then the most developed digital-cash system — as a complement rather than a competitor, which is the closest documented point of contact between Chaum’s work and the lineage that produced Bitcoin.

Significance

Chaum’s later career shows the persistence: after DigiCash’s collapse he kept working on privacy-preserving cryptography from an academic base at CWI in Amsterdam, and starting in 2016 began designing xx network, a blockchain aimed at combining private messaging with post-quantum security, which launched its mainnet in 2021. His graduate students carried his approach forward too — Len Sassaman, later linked to a Satoshi-identity hypothesis in his own right, was Chaum’s PhD advisee at KU Leuven’s COSIC group at the time of his death in 2011. Blind signatures also outlived DigiCash on their own terms: the cryptographic primitive Chaum patented in 1983 is the same one behind modern Chaumian-mint e-cash protocols built on top of Bitcoin’s own Lightning Network. I don’t think DigiCash’s failure was fundamentally a cryptography problem — the blind signature worked exactly as designed. What it couldn’t survive was needing a bank to vouch for a currency it didn’t fully control, on top of the adoption and competitive pressures that sink most payment systems; that dependency on a bank is exactly the kind of single point of failure Bitcoin was built, a decade later, to remove.

Related Entries

1 entries