Does Bitcoin dream of electronic cash?
The whitepaper's title names a payment system; section 6's gold is an issuance analogy. Satoshi designed one thing — hard issuance, cash use — whose scarcity later tilted it toward digital gold.
Creator of b-money and Crypto++, cited in the Bitcoin white paper
Event Added Updated![A faceless hooded silhouette between a cited document marked "[1]" and a sealed 2008 outreach envelope, with a small open-source code block feeding into a Bitcoin block icon](/images/analysis/2008-08-22-wei-dai-biography-hero.png)
In November 1998, Wei Dai published b-money — a proposal for distributed digital cash — on the cypherpunks mailing list. Ten years later, on August 22, 2008, Satoshi Nakamoto emailed Dai directly:
“I was very interested to read your b-money page. I’m getting ready to release a paper that expands on your ideas into a complete working system. Adam Back (hashcash.org) noticed the similarities and pointed me to your site. I need to find out the year of publication of your b-money page for the citation in my paper.”
Two months later, the Bitcoin whitepaper cited b-money as reference [1]. Bitcoin v0.1 also shipped with Dai’s Crypto++ library for its SHA-256 implementation — making Dai’s code a direct dependency of Bitcoin from the first release.
In March 2014, asked on LessWrong whether Satoshi might be a known figure from the cryptography or cypherpunk communities, Dai answered:
“My guess is that he’s not anyone who was previously active in the academic cryptography or cypherpunks communities, because otherwise he probably would have been identified by now based on his writing and coding styles.”
Wei Dai is a computer scientist and cryptographer who studied at the University of Washington and worked at Microsoft. The combination of b-money as whitepaper reference [1], the Crypto++ codebase dependency, and Satoshi’s pre-launch outreach has made Dai a recurring Satoshi-identity candidate — examined in a dedicated identity-hypothesis entry. The retrospective above is treated as the principal self-denial. The smallest denomination in the Ethereum cryptocurrency, “wei,” is named after him.
In November 1998, Dai published “b-money”, a proposal for an anonymous, distributed electronic cash system, on the cypherpunks mailing list. The b-money proposal described a system where participants could create money by broadcasting the solution to a computational puzzle — much like Bitcoin’s later proof-of-work mining. The paper outlined two protocols: one requiring a synchronous broadcast channel, and another using a set of servers to keep track of balances. B-money was never implemented, but it became one of the key intellectual precursors to Bitcoin.
Dai also wrote and maintained Crypto++, an open-source C++ cryptography library. Bitcoin leaned on it from the start: the earliest archived release, Bitcoin v0.1.3 ALPHA (early 2009), carries src/sha.cpp and src/sha.h with a header note that the routines were “extracted as a standalone file from Crypto++ Version 5.5.2 (9/24/2007)” — the latest Crypto++ release available when Bitcoin was being designed (mid-2007 onward).
The Crypto++ 5.6.0 SSE2-assembly-optimized SHA-256 was integrated into Bitcoin in version 0.3.6 (July 29, 2010 release). Primary-source timeline:
Dai’s code contributions to Bitcoin are twofold: b-money as an intellectual precursor, and Crypto++ as a direct codebase dependency from the earliest released version.
On August 22, 2008, Satoshi Nakamoto emailed Dai directly, writing that he was preparing to publish a paper expanding on Dai’s b-money ideas. Satoshi asked Dai for the year of b-money’s publication to properly cite it. This email, along with a similar one sent to Adam Back two days earlier, represents the earliest known evidence of Satoshi reaching out to existing cryptographers before publishing the Bitcoin white paper. The white paper, published on October 31, 2008, cites b-money as its first reference.
In January 2009, after the launch, the two exchanged more email. Satoshi wrote to Dai about the coming release; Dai replied with notes on Bitcoin’s design — where it matched b-money and where it diverged.
Dai’s 2014 retrospective and Satoshi’s own August 21, 2008 b-money disclaimer to Adam Back are two independent observations converging on the same picture of where Satoshi stood relative to the cypherpunk community during development, examined further in the cypherpunk independent-arrival analysis.
26 entries
The whitepaper's title names a payment system; section 6's gold is an issuance analogy. Satoshi designed one thing — hard issuance, cash use — whose scarcity later tilted it toward digital gold.
Wei Dai announces b-money on the Cypherpunks list as a brief addendum to PipeNet 1.1, pointing readers to his eskimo.com page — the proposal later cited as reference [1] in the Bitcoin whitepaper.
Adam Back reposts the full text of Wei Dai's b-money proposal to the Cypherpunks list, with comments to follow — the message that opened the December 1998 b-money design discussion.
Hayek's 1976 competing-currencies case, the 1995 Extropian 'Hayeks' thought-experiment, and Bitcoin's 2009 non-state issuance — one ideological lineage with bounded direct-influence claims.
Finding Satoshi (Tooley / Miele, April 2026) names Hal Finney and Len Sassaman as Bitcoin co-creators — Finney coded, Sassaman wrote the paper. Lopp and Back disputed the timing.
Bitcoin chose a hard 21M cap; b-money (1998) proposed elastic supply; fiat runs central-bank discretion. The cypherpunk debate, Wei Dai's 2013 regret, and 15 years of cryptocurrency variants.
What Satoshi's design assumed about a fee-only future, and the documented debate over whether transaction fees alone can sustain proof-of-work security after the block subsidy ends around 2140.
On November 20, 2011, Bitcoin v0.5 shipped with the Crypto++ SHA-256 subset removed and replaced by OpenSSL. Wei Dai's library, a direct codebase dependency since v0.1, was gone.
b-money is whitepaper reference [1], his Crypto++ shipped inside Bitcoin v0.1, and he was the second person Satoshi contacted. The evidence for Wei Dai as Satoshi, weighed.
Bitcoin Institute reanalysis of van Dorst's stylometric corpus for the five most-cited candidates. Finding: Szabo top at 4.67th percentile of 12,739 authors; 594 unnamed rank closer; corpus is noisy.
On May 15, 2015, the New York Times published Nathaniel Popper's Decoding the Enigma of Satoshi Nakamoto — a Digital Gold excerpt naming Bit Gold designer Nick Szabo as Satoshi. Szabo denied it.
Adam Back replies to Wei Dai on Cypherpunks, identifying seven monetary-design issues in b-money and proposing Hashcash as the minting mechanism — a substantive analysis ten years before Bitcoin.
Bitcoin v0.1 reuses one cypherpunk primitive (PoW from Hashcash), borrows general CS components (Merkle trees, linked timestamping, ECDSA), and synthesizes the rest (UTXO, mining, 21M cap, P2P).
Recurring Satoshi candidates aligned across four independent layers — profile match, stylometric attribution, direct correspondence, and development environment.
Editorial reading of Satoshi's relationship to cypherpunk, from three primary observations: he didn't know b-money, Wei Dai testified Satoshi was "not previously active," alignment with Hughes 1993.
Benjamin Wallace's Wired feature — an early major mainstream article on Bitcoin. Traces the whitepaper, mining boom, Mt. Gox hack, and growing pains, ending with Garzik's "We really don't care."
Wei Dai announces Disperse/Collect 1.0 on the Cypherpunks list, built from his own Crypto++ library. Confirms he was an active coder, relevant to why he later chose not to implement b-money.
Wei Dai announces b-money on the Cypherpunks list as a secondary item alongside PipeNet 1.1, his primary focus. The proposal later cited in Bitcoin appears in a single sentence at the end of the post.
On LessWrong, Wei Dai clarifies he did not create Bitcoin — "only described a similar idea more than a decade ago" — buys a Radeon 5870 to mine, and warns Bitcoin lacks cryptographer security review.
Wei Dai LessWrong post revealing Satoshi emailed him about Bitcoin v0.1 in early 2009, but Dai ignored it because he was more interested in Less Wrong than Cypherpunks at the time.
Wei Dai replies to Adam Back on Cypherpunks, conceding b-money would be at most a niche mechanism and revealing his shift toward viewing the government monopoly of force as a net benefit.
Wei Dai LessWrong comments: Bitcoin's monetary policy has failed due to volatility, and he never replied to Satoshi's 2008 review email — regretting he could have dissuaded the fixed-supply choice.
Wei Dai's LessWrong Q&A reflections: Satoshi did not read the b-money paper before reinventing the idea, and Dai had grown disillusioned with cryptoanarchy by the time he wrote it up.
Adam Back reflects on his August 2008 email exchange with Satoshi, his regret at not reading the whitepaper carefully, and his COPA v Wright testimony where the complete chain became public.
Nick Szabo's May 2011 blog post on why digital cash took thirteen years between bit gold (1998) and Bitcoin (2009). Names libtech as the private list where bit gold and b-money developed in parallel.
Satoshi emails Wei Dai asking for the correct b-money citation, revealing he learned of it via Adam Back. The email linked the pre-release draft 'Electronic Cash Without a Trusted Third Party'.