Bitcoin Institute

Wei Dai

Creator of b-money and Crypto++, cited in the Bitcoin white paper

Figures
🔍 Identity hypothesis →

A faceless hooded silhouette between a cited document marked "[1]" and a sealed 2008 outreach envelope, with a small open-source code block feeding into a Bitcoin block icon

In November 1998, Wei Dai published b-money — a proposal for distributed digital cash — on the cypherpunks mailing list. Ten years later, on August 22, 2008, one day after learning of b-money for the first time through Adam Back’s referral, Satoshi Nakamoto emailed Dai directly:

“I was very interested to read your b-money page. I’m getting ready to release a paper that expands on your ideas into a complete working system. Adam Back (hashcash.org) noticed the similarities and pointed me to your site. I need to find out the year of publication of your b-money page for the citation in my paper.”

Two months later, the Bitcoin whitepaper cited b-money as reference [1].

Bitcoin v0.1 also shipped with Dai’s Crypto++ library for its SHA-256 implementation, making Dai’s code a direct dependency of Bitcoin from the first release.

In March 2014, asked on LessWrong whether Satoshi might be a known figure from the cryptography or cypherpunk communities, Dai answered:

“My guess is that he’s not anyone who was previously active in the academic cryptography or cypherpunks communities, because otherwise he probably would have been identified by now based on his writing and coding styles.”

Wei Dai is a computer scientist and cryptographer who studied at the University of Washington and worked at Microsoft.

The combination of b-money as whitepaper reference [1], the Crypto++ codebase dependency, and Satoshi’s pre-launch outreach has made Dai a recurring Satoshi-identity candidate — examined in a dedicated identity-hypothesis entry. The retrospective above is treated as the principal self-denial. Wired’s own November 2011 feature on Bitcoin’s rise and fall quoted Dai calling it “very significant” — praise that, in the archive’s reading of that piece, ties directly to the identity-hypothesis candidacy raised here.

The smallest denomination in the Ethereum cryptocurrency, “wei,” is named after him.

1998b-money proposalpublished on thecypherpunks mailing list(Nov)Adam Back publishescritique of b-money'smonetary design (Dec)2008Satoshi emails AdamBack to verify aHashcash citation (Aug20)Back's reply pointsSatoshi to b-money forthe first time; Satoshisays he wasn't aware ofit (Aug 21)Email from Satoshi toDai - asks aboutb-money citation yearfor the whitepaper (Aug22)Bitcoin whitepaper citesb-money as its firstreference (Oct)2009Bitcoin v0.1 ships withCrypto++ 5.5.2SHA-256; Satoshiemails Dai about therelease (Jan 10)2010Bitcoin v0.3.6 integratesCrypto++ 5.6.0SSE2-optimizedSHA-256 (Jul)2014LessWrongretrospective - Satoshiwas 'not previouslyactive' in cypherpunkcommunities (Mar)

b-money (1998)

In November 1998, Dai published “b-money”, a proposal for an anonymous, distributed electronic cash system, on the cypherpunks mailing list. The b-money proposal described a system where participants could create money by broadcasting the solution to a computational puzzle — much like Bitcoin’s later proof-of-work mining. The paper outlined two protocols: one requiring a synchronous broadcast channel, and another using a set of servers to keep track of balances. B-money was never implemented. Bitcoin’s whitepaper cites it as reference [1], added after Satoshi had completed his own design independently of it.

Crypto++

Dai also wrote and maintained Crypto++, an open-source C++ cryptography library — a project he was actively coding on the cypherpunks list as early as 1996, when he announced Disperse/Collect built from it. Bitcoin leaned on it from the start: the earliest archived release, Bitcoin v0.1.3 ALPHA (early 2009), carries src/sha.cpp and src/sha.h with a header note that the routines were “extracted as a standalone file from Crypto++ Version 5.5.2 (9/24/2007)” — the latest Crypto++ release available when Bitcoin was being designed (mid-2007 onward).

The Crypto++ 5.6.0 SSE2-assembly-optimized SHA-256 was integrated into Bitcoin in version 0.3.6 (July 29, 2010 release). Primary-source timeline:

  • 2010-07-25: BitcoinTalk member “BlackEye” demonstrated integrating Crypto++ 5.6.0 SHA-256 with SSE2 assembly — “the fastest SHA256 yet using the SSE2 assembly code.”
  • 2010-07-26: Satoshi responded — “Is that still starting from Crypto++? Lets get this into the main sourcecode.”
  • 2010-07-27 (SVN rev 114): Satoshi confirmed adding the library subset — “I added a subset of the Crypto++ 5.6.0 library to the SVN. I stripped it down to just SHA and 11 general dependency files… The combined speedup is about 2.5x faster than version 0.3.3. This is SVN rev 114.”
  • 2010-07-29: v0.3.6 release alert — Satoshi credited BlackEye for the Crypto++ ASM SHA-256 and tcatm for the midstate cache optimization: “Total generating speedup 2.4x faster.”
  • 2010-08-09: Satoshi stated explicitly — “When we switched to Crypto++ 5.6.0 SHA-256 in version 0.3.6, generation got broken on the Linux 64-bit build.”

Dai’s connection to Bitcoin is twofold: b-money, cited in the whitepaper after the fact, and Crypto++, a direct codebase dependency from the earliest released version.

Satoshi’s First Contact

One day after emailing Adam Back to verify a Hashcash citation, Satoshi learned of b-money for the first time: Back’s reply on August 21, 2008 pointed him to Dai’s proposal, and Satoshi’s own response — “Thanks, I wasn’t aware of the b-money page, but my ideas start from exactly that point” — is the primary-source record that the design had been built independently of it. The next day, Satoshi emailed Dai directly, describing the paper he was about to release as one that “expands on your ideas” — the courtesy of a new citation rather than an acknowledged design debt — and asking for the year of b-money’s publication to cite it properly. The white paper, published on October 31, 2008, cites b-money as its first reference.

Later Correspondence

That August 22 email had also carried the pre-release draft paper. Dai’s reply confirmed b-money’s 1998 posting date and archive links and said only that he would “take a look at it and let you know if I have any comments or questions” — comments that, by Dai’s own later account, never came. In an April 2013 LessWrong comment, Dai called this his biggest regret: “when Satoshi wrote to me asking for comments on his draft paper, I never got back to him. Otherwise perhaps I could have dissuaded him… from the ‘fixed supply of money’ idea.” In a 2014 post, Dai added that he had separately ignored Satoshi’s early-2009 email announcing the Bitcoin v0.1 release itself, the full implementation of “the paper I sent you a few months ago,” distracted at the time by LessWrong rather than Cypherpunks — not beginning to mine until 2011, an entry point he later clarified in a LessWrong thread by stating plainly that he did not create Bitcoin.

Significance

Dai’s 2014 retrospective and Satoshi’s own August 21, 2008 b-money disclaimer to Adam Back are two independent observations converging on the same picture of where Satoshi stood relative to the cypherpunk community during development, examined further in the cypherpunk independent-arrival analysis.

Related Entries

30 entries

Article

Decoding the Enigma of Satoshi Nakamoto and the Birth of Bitcoin — Nathaniel Popper / New York Times investigation naming Nick Szabo (May 15, 2015)

Nathaniel Popper ↔ Nick Szabo, Satoshi Nakamoto, Adam Back, Hal Finney, Wei Dai

On May 15, 2015, the New York Times published Nathaniel Popper's Decoding the Enigma of Satoshi Nakamoto — a Digital Gold excerpt naming Bit Gold designer Nick Szabo as Satoshi. Szabo denied it.

Analysis

Who Is Satoshi Nakamoto: 12 Geniuses and the Mystery of the Century

Bitcoin Institute ↔ Satoshi Nakamoto, Adam Back, Wei Dai, Hal Finney, James A. Donald, Peter Todd, Nick Szabo, Len Sassaman, Dorian Nakamoto, Craig Wright, Paul Le Roux, Elon Musk, Isamu Kaneko

Recurring Satoshi candidates aligned across four independent layers — profile match, stylometric attribution, direct correspondence, and development environment.

Article

"The Rise and Fall of Bitcoin" — Wired's landmark feature on Bitcoin's first boom and bust

Benjamin Wallace ↔ Satoshi Nakamoto, Gavin Andresen, Laszlo Hanyecz, Jeff Garzik, Hal Finney, Wei Dai, Nick Szabo, Stefan Thomas, Dan Kaminsky, Amir Taaki

Benjamin Wallace's Wired feature — an early major mainstream article on Bitcoin. Traces the whitepaper, mining boom, Mt. Gox hack, and growing pains, ending with Garzik's "We really don't care."