David Chaum: DigiCash, eCash, and the Invention of Digital Privacy
David Chaum invented blind signatures in 1982 and founded DigiCash to build eCash, the first electronic money with cryptographic privacy. Why the company failed in 1998 and what Bitcoin took from his work.
David Chaum is the American cryptographer who invented the building blocks of digital privacy: mix networks in 1981 and blind signatures in 1982. He founded DigiCash in Amsterdam in 1990 to commercialize eCash, the first electronic money that let a payer spend a digital coin without the issuing bank learning who spent it. DigiCash filed for bankruptcy in 1998.
1. Who Is David Chaum? The Cryptographer Who Started the Field
- Background & Experience: Chaum, born in 1955, completed his PhD in computer science at the University of California, Berkeley in 1982. His dissertation, "Computer Systems Established, Maintained, and Trusted by Mutually Suspicious Groups", described a system in which records are protected by hash-linked structures maintained by parties who do not trust one another, a description that reads today as an early sketch of the problem blockchains address. He founded the International Association for Cryptologic Research and established the cryptography group at CWI, the national research institute for mathematics and computer science in Amsterdam, which trained a generation of European cryptographers. He also taught at the NYU Graduate School of Business and at the University of California. Most of the privacy technology that exists on the internet today traces to problems he formulated between 1979 and 1985.
2. Major Contributions: Mix Networks, Blind Signatures, and eCash
- Major Contributions:
- Mix networks (1981): In "Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms", published in Communications of the ACM, Chaum described servers that collect a batch of encrypted messages, reorder them, and forward them, so no observer can link a sender to a recipient. This is the conceptual ancestor of remailers, onion routing, and Tor.
- Blind signatures (1982): Presented at CRYPTO '82 in "Blind Signatures for Untraceable Payments". The technique lets a bank sign a token without seeing its contents, in the same way one might sign through carbon paper inside a sealed envelope. The result is a digital coin that the bank can verify as genuine and unspent, but cannot trace back to the person who withdrew it. This single primitive made anonymous digital cash mathematically possible.
- DigiCash and eCash (1990-1998): Chaum founded DigiCash in Amsterdam to turn blind signatures into a product. The first electronic payment was sent in 1994. Mark Twain Bank in St. Louis issued eCash to US customers from 1995, and Deutsche Bank, Credit Suisse, and several others licensed the technology. Adoption stayed small, in the low thousands of users and a few hundred merchants.
- The dining cryptographers protocol (1988): A method by which a group can broadcast a message such that every participant can verify a message was sent but no one can determine who sent it, achieving unconditional sender anonymity without any trusted server. It remains the theoretical baseline against which later anonymity systems are measured, and it is the direct ancestor of the anonymous broadcast layers used in modern privacy networks.
- Untraceable credentials and voting: Chaum extended the same approach to identity, proposing in 1985 that people could prove entitlements without revealing who they are, and later designed verifiable election systems including Punchscan and Scantegrity, the latter used in municipal elections in Takoma Park, Maryland.
- Later work: Chaum has continued in the field, leading the xx network, a mix-network-based messaging and payment platform, and his eCash design was revisited in central bank digital currency research, including the Bank for International Settlements Innovation Hub's Project Tourbillon, which concluded in 2023.
3. Chaum's Place in Blockchain History
- Impact Assessment: Chaum defined the problem that Bitcoin later solved, and solved a different part of it first. His question was whether electronic money could preserve the privacy of physical cash; his answer required a bank to issue and redeem the tokens, which meant the system had a single operator who could be shut down, subpoenaed, or simply go out of business. Bitcoin inverted the trade-off: it removed the issuer and accepted a public ledger, giving up Chaum's privacy properties to gain censorship resistance. The cypherpunk movement grew directly out of the intellectual space he opened, and every privacy coin, mixer, and zero-knowledge payment system since is working on the synthesis he started.
- Key Perspectives: Chaum's 1985 paper title states his thesis in full: "Security without Identification: Transaction Systems to Make Big Brother Obsolete". He argued that identification was being built into electronic payment by default and habit rather than by necessity, and that the cost of that default would be a permanent, searchable record of everyone's economic life.
4. Common Misconceptions About David Chaum
- Controversies & Criticisms:
- "DigiCash failed because the technology did not work": The cryptography worked. The company failed commercially. Banks were slow, consumers had no reason to prefer it over credit cards, and merchants had no reason to accept a currency consumers did not hold. Reporting on the company's collapse, including accounts from former employees, describes negotiations with Netscape, Microsoft, and Visa that broke down over terms; Chaum has disputed some characterizations of his role. DigiCash filed for bankruptcy in 1998 and its assets were sold in 1999.
- "eCash was a cryptocurrency": It was not. eCash was denominated in ordinary national currencies and required a bank to issue tokens and prevent double-spending. It had no independent monetary unit, no mining, and no decentralized ledger.
- "Chaum invented blockchain": His 1982 dissertation contains hash-linked, mutually-distrusted record keeping, and it is fair to call it a precursor. It does not contain proof-of-work, an incentive mechanism, or open participation, all of which are load-bearing parts of what the word means today.
- "He is anti-cryptocurrency": He has criticized specific designs, particularly the privacy properties of public ledgers, while continuing to build digital cash systems himself.
- "Bitcoin made his work obsolete": Bitcoin solved the issuance problem and abandoned the privacy one, and the industry has spent fifteen years trying to recover what eCash had by construction. Zero-knowledge proofs, confidential transactions, stealth addresses, and mixers are all attempts to restore, on a public ledger, the property a blind signature provided in a single step in 1982.
5. Timeline and Current Status
-
1981: Publishes the mix network paper in Communications of the ACM.
-
1982: Presents blind signatures at CRYPTO '82; completes his Berkeley PhD; founds the IACR.
-
1985: Publishes "Security without Identification".
-
1990: Founds DigiCash in Amsterdam.
-
1994: First eCash payment sent.
-
1995: Mark Twain Bank begins issuing eCash in the United States.
-
1998: DigiCash files for bankruptcy.
-
1999: Chaum sells DigiCash and leaves the company.
-
2016-present: Works on privacy networks, including cMix and the xx network.
-
Current Status & Future: Chaum remains active in cryptography and digital currency design, leading the xx network and advising on privacy-preserving payment architectures. Interest in his original approach has returned through central bank digital currency projects, which face exactly the problem he posed in 1982: how to issue electronic money that a state can audit in aggregate but cannot use to watch individuals.
Frequently Asked Questions
Who is David Chaum?
What was DigiCash and why did it fail?
What is a blind signature?
Was eCash a cryptocurrency?
Did David Chaum invent blockchain?
References
Nick Szabo: Bit Gold, Smart Contracts, and the Blueprint Before Bitcoin
Nick Szabo coined the term smart contract in 1994 and designed Bit Gold in 1998, the decentralized digital currency proposal closest to Bitcoin. The full record of his work, his ideas, and his denial of being Satoshi.
Adam Back: Hashcash, Proof of Work, and the First Email Satoshi Sent
Adam Back announced Hashcash on the cypherpunks list in March 1997, invented the proof-of-work function Bitcoin later adopted, and received Satoshi Nakamoto's first known email on August 20, 2008.