Skip to article
Degrees of SatoshiFollow the connections.
Degrees of Satoshi/ Encyclopedia

Encyclopedia Origins and culture · Entry 406

The cypherpunks: the mailing list and the ideas that came before Bitcoin

Theme
Origins and culture
Sources
8 cited records
Reading time
About 11 minutes
Automated verification
Substantive update
In this article

At a glance

Key facts

Key facts for The cypherpunks: the mailing list and the ideas that came before Bitcoin
FactDetailSource
Founding meetingSeptember 1992, where Tim May’s Crypto Anarchist Manifesto was read aloud[2]
The manifesto“A Cypherpunk’s Manifesto,” Eric Hughes, 9 March 1993[1]
Untraceable paymentsDavid Chaum’s blind-signature paper, 1982; first electronic cash payment 27 May 1994[3][4]
HashcashProposed by Adam Back in May 1997 to throttle email abuse; paper dated 1 August 2002[5]
b-moneyWei Dai, November 1998: money created by solving computational problems[6]
Bit goldNick Szabo’s blog post, filed under December 2005 and dated December 2008 on the page[7]
Bitcoin announced31 October 2008, on the cryptography mailing list at metzdowd.com[8]
01

A mailing list, a manifesto and the line “Cypherpunks write code”

The cypherpunks were programmers, cryptographers and privacy activists who organized around an email list in the early 1990s. The group’s founding meeting was held in September 1992; we know that because the archived copy of Tim May’s manifesto notes it was read aloud there. What held them together was a conviction: privacy in a networked world would have to be built out of mathematics, by volunteers.

Eric Hughes put that conviction into words on 9 March 1993 in “A Cypherpunk’s Manifesto.” It opens with a distinction: “Privacy is necessary for an open society in the electronic age. Privacy is not secrecy.” Privacy, he argued, is the power to choose what you reveal about yourself, and that power needs tools. He named three: anonymous mail forwarding, digital signatures, and electronic money.

Money is where the manifesto gets specific. “Privacy in an open society requires anonymous transaction systems,” Hughes wrote, and “until now, cash has been the primary such system.” Then comes the line the movement is remembered for: “Cypherpunks write code.” Someone has to write the software that defends privacy, and since nobody gets privacy unless everyone can, they would write it.

02

Tim May imagined markets nobody could police, and money was the missing piece

Timothy C. May’s “Crypto Anarchist Manifesto” is older than the group. According to the notes on its archived copy, he wrote it in mid-1988, handed it out at conferences that year, read it at the cypherpunks’ founding meeting in September 1992, and posted it online on 22 November 1992. It opens with a deliberate echo of Marx: “A specter is haunting the modern world, the specter of crypto anarchy.”

May’s claim was that cryptography would let people deal with each other without revealing who they were. “Two persons may exchange messages, conduct business, and negotiate electronic contracts without ever knowing the True Name, or legal identity, of the other.” He did not pretend it was all upside: the same document says an anonymous computerized market could make possible “abhorrent markets for assassinations and extortion.”

Notice what the vision needs. If you are going to do business with someone whose legal name you will never learn, you need a way to pay them that does not run through a bank that knows you both. The proposals discussed below explore different parts of that problem; this comparison is a technical lineage, not proof that every author shared one motive.

03

David Chaum showed how to make digital cash untraceable, and then built it

An influential answer came before the cypherpunks group existed. David Chaum published “Blind Signatures for Untraceable Payments” in 1982. If a third party sees the payee, amount and time of every payment you make, he wrote, it can learn “a great deal about the individual’s whereabouts, associations and lifestyle.” But cash, the anonymous alternative, “suffers from lack of controls and security.” He wanted a system where nobody could see whom you paid, yet you could still prove that you had paid.

His trick was the blind signature, and he explained it with carbon paper. Put a slip inside an envelope lined with carbon paper, have an official sign the outside, and the signature transfers to the slip without the official ever seeing what is written on it. A bank could sign a digital coin the same way: it certifies that the coin is real without being able to recognize it later when it is spent. The result is a bank-issued token that the bank itself cannot trace.

Chaum did not leave it on paper. His company, DigiCash, recorded what his own timeline calls the “world’s first electronic cash payment over computer networks” on 27 May 1994, partnered with Mark Twain Bank of St. Louis in 1995, and later worked with Deutsche Bank and Credit Suisse. The catch was structural. A blind signature still needs a signer, so Chaum’s cash was private but issued by an institution. Bitcoin’s announcement, fourteen years later, would list “no mint or other trusted parties” as a design goal.

04

Adam Back made computers pay for email; Wei Dai imagined money made of work

In May 1997, Adam Back proposed Hashcash as a way to throttle abuse of “un-metered internet resources such as email, and anonymous remailers.” A sender’s computer must solve a small puzzle before a message is accepted, one that takes real effort to solve but a fraction of a second to check. Back’s 2002 paper calls the puzzle a “cost-function” that must be “efficiently verifiable, but parameterisably expensive to compute,” and describes its output as “a token which can be used as a proof-of-work.” Satoshi’s 2008 announcement would say new coins are made with Hashcash-style proof of work.

Wei Dai’s “b-money,” circulated in November 1998, brought the pieces together on paper. It opens by declaring, “I am fascinated by Tim May’s crypto-anarchy,” and describes a community whose members “cannot be linked to their true names or physical locations.” Such a community needs money, so Dai proposed a currency in which “anyone can create money by broadcasting the solution to a previously unsolved computational problem.” Every participant would keep a record of how much belonged to each pseudonym, and payments would be broadcast to everyone.

Dai was candid about the problems. His first protocol, he wrote, “is impractical, because it makes heavy use of a synchronous and unjammable anonymous broadcast channel,” and his second handed the record-keeping to a set of servers. He closed by hoping the idea was “a step toward making crypto-anarchy a practical as well as theoretical possibility.” Money created by computation, held by pseudonyms, tracked by a shared record: that is most of Bitcoin’s vocabulary, ten years early. What was missing was a way to make thousands of strangers agree on one copy of the record.

05

Nick Szabo’s bit gold got close, but its pieces were not interchangeable

Nick Szabo’s proposal, “Bit gold,” sits on his blog under a December 2005 address, though the page itself now displays a date of 27 December 2008. It starts from a complaint that “our money currently depends on trust in a third party for its value,” and points to the twentieth century’s inflations as proof that this is “not an ideal state of affairs.” Gold is scarce without anyone’s say-so. Could bits be?

His answer was a chain. Take a public “challenge string,” compute a proof of work from it, have the result timestamped by several independent services, and register it in a distributed registry of titles, a public record of who owns what. The most recent piece of bit gold provides the challenge for the next one, so the pieces link together in order, and anyone can verify a piece and trace its owner through the chain of title.

Szabo saw the flaw himself. Because computers get faster, a piece of bit gold made this year costs less to make than one made last year, so “unlike fungible atoms of gold,” the pieces would trade at different values and dealers would have to bundle them into standard units. Bitcoin’s consensus amounts do not assign different face values according to mining year, although maturity, spending conditions and market treatment can still differ; how the design gets there, and how it picks between competing versions of the ledger, is the technical story told in our origins dossier.

06

On 31 October 2008, Bitcoin arrived by email, on a list where these people were still talking

At 2:10 in the afternoon, US Eastern time, on 31 October 2008, a message with the subject line “Bitcoin P2P e-cash paper,” from a sender named Satoshi Nakamoto, reached the cryptography mailing list hosted at metzdowd.com. “I’ve been working on a new electronic cash system that’s fully peer-to-peer, with no trusted third party,” it began, followed by a link to a nine-page paper and a short list of properties: double spending prevented by a peer-to-peer network, no mint or other trusted parties, participants who can be anonymous, and new coins made with Hashcash-style proof of work.

Read against the previous fifteen years, that list is a checklist of the cypherpunk problem. Chaum’s privacy goal, without Chaum’s bank. Back’s cost function, put to a new use. Dai’s money-from-work and pseudonymous balances, with a mechanism for agreement. Szabo’s chain of proofs, with interchangeable units. The email did not claim to have invented the pieces; it claimed to have made them work together. Our walk through the white paper follows that argument and the debate it started.

One thing the record does not tell you is who Satoshi Nakamoto was, or whether that person had ever posted to the cypherpunks list. The announcement went to a list of cryptographers and used the vocabulary these people had built. That is a lineage, not an identification, and this site does not treat it as one; see what is actually known about Satoshi. Hughes had written that cypherpunks write code. Fifteen years on, somebody did.

07

Separate a precursor, an implementation and an identity claim

Compare the proposals by the problem each addresses. Blind signatures concern what an issuer can learn when signing a payment token. Hashcash attaches computational cost to an action. B-money and bit gold consider ways to organize digital value and records. Those are related questions, but the proposals are not interchangeable descriptions of Bitcoin.

A shared idea does not identify a pseudonymous author. Read an original proposal for its mechanism, a release or working system for evidence of implementation, and correspondence for what its author actually said. The fact that Bitcoin draws on this intellectual history does not establish which earlier writer, if any, used the name Satoshi.

Direct answers

Questions people ask

What does the word “cypherpunk” mean?

It is the name a group of privacy-minded programmers and cryptographers gave themselves when they began meeting in 1992. Eric Hughes’s 1993 manifesto defines the outlook: privacy is not secrecy but the power to choose what you reveal, and cypherpunks defend it by writing code rather than by asking permission.

Did the cypherpunks invent Bitcoin?

Not as a group, and no earlier proposal was Bitcoin under another name. Chaum’s blind signatures, Back’s Hashcash, Dai’s b-money and Szabo’s bit gold each solved part of the problem. Satoshi Nakamoto’s 2008 announcement described a system with no trusted third party that used Hashcash-style proof of work, and the paper it linked to made the pieces work together. The people and ideas were the soil; the working network was new.

Was Satoshi Nakamoto a cypherpunk?

Nobody knows who Satoshi Nakamoto was, so nobody can say. The announcement went to a cryptography mailing list in October 2008, used the movement’s vocabulary and drew on its proposals, which makes Bitcoin a cypherpunk project in spirit. Whether its author ever posted to the original cypherpunks list is not something the record establishes.

What is the difference between b-money, bit gold and Bitcoin?

b-money (1998) described money created by solving computational problems and tracked by every participant, but its author called the first version impractical. Bit gold (Szabo’s blog, mid-2000s) chained proofs of work together with timestamps and a title registry, but its pieces were worth different amounts depending on when they were made. The 2008 Bitcoin announcement linked to a design paper describing proof-of-work agreement without a trusted third party. Public software followed in January 2009; temporary forks and competing tips remain possible.

Inspect the evidence

The answer and key facts have stable claim links. These records retain the scope and qualification when reused.

Cypherpunk writers argued that people should be able to protect privacy through cryptography and working software. Eric Hughes’s 1993 manifesto explicitly connects privacy with anonymous transaction systems. Before Bitcoin, proposals such as blind-signature cash, Hashcash, b-money and bit gold explored different parts of digital cash. Bitcoin’s paper and announcement combine related ideas; this intellectual history does not identify Satoshi.

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
Founding meeting: September 1992, where Tim May’s Crypto Anarchist Manifesto was read aloud

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
The manifesto: “A Cypherpunk’s Manifesto,” Eric Hughes, 9 March 1993

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
Untraceable payments: David Chaum’s blind-signature paper, 1982; first electronic cash payment 27 May 1994

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
Hashcash: Proposed by Adam Back in May 1997 to throttle email abuse; paper dated 1 August 2002

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
b-money: Wei Dai, November 1998: money created by solving computational problems

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
Bit gold: Nick Szabo’s blog post, filed under December 2005 and dated December 2008 on the page

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
Bitcoin announced: 31 October 2008, on the cryptography mailing list at metzdowd.com

Scope: Bitcoin. Verification: verified · 2026-10-02T18:22:07.965Z.

Link to this claim
Revision history
  1. — Initial Bitcoin encyclopedia entry at this permanent URL.
  2. — Revised direct answer to preserve source scope and qualifications. Corrected scope or wording: Every cypherpunk money project of the next fifteen years, and Bitcoin after them, is Corrected scope or wording: The first serious answer came before the cypherpunks existed. Corrected scope or wording: Bitcoin’s coins are interchangeable whenever they were mined Corrected scope or wording: Bitcoin (2008) was announced as a working system with no trusted third party, and its Distinguished Bitcoin’s October 2008 paper announcement from its January 2009 software release and qualified the comparison with bit gold’s nonfungible work units.
  3. — Added reusable claims, explicit source locators, and matching Markdown and JSON. This publishing change does not itself establish factual verification.
  4. — Added “Separate a precursor, an implementation and an identity claim”, clarified the search description. Independent verification is recorded separately.

Source register

Sources and references

Retrieval dates and locators are recorded individually.
  1. A Cypherpunk’s ManifestoEric Hughes · 1993-03-09activism.net archive

    The 9 March 1993 text: privacy is not secrecy, privacy requires anonymous transaction systems, cash has been the primary one, and cypherpunks write code.

    Locator: The 9 March 1993 text: privacy is not secrecy, privacy requires anonymous transaction systems, cash has been the primary one, and cypherpunks write code. · Retrieved: 2026-10-02T14:49:18.777351+00:00Open source
  2. The Crypto Anarchist ManifestoTimothy C. May · 1992-11-22activism.net archive

    The manifesto text plus its distribution notes: written mid-1988, handed out at Crypto ’88, read at the September 1992 founding meeting, posted 22 November 1992.

    Locator: The manifesto text plus its distribution notes: written mid-1988, handed out at Crypto ’88, read at the September 1992 founding meeting, posted 22 November 1992. · Retrieved: 2026-10-02T14:49:18.778199+00:00Open source
  3. Blind Signatures for Untraceable PaymentsDavid Chaum · 1982chaum.com (author’s archive of the Springer reprint)

    The paper’s introduction on what third parties learn from payment records, the carbon-paper envelope analogy, and the blind-signature protocol.

    Locator: The paper’s introduction on what third parties learn from payment records, the carbon-paper envelope analogy, and the blind-signature protocol. · Retrieved: 2026-10-02T15:04:18.422539+00:00Open source
  4. eCash timelineDavid Chaumchaum.com

    Dates the blind-signature paper to 1982, records the first electronic cash payment on 27 May 1994, and lists DigiCash bank partnerships including Mark Twain Bank (1995), Deutsche Bank (1996) and Credit Suisse (1998).

    Locator: Dates the blind-signature paper to 1982, records the first electronic cash payment on 27 May 1994, and lists DigiCash bank partnerships including Mark Twain Bank (1995), Deutsche Bank (1996) and Credit Suisse (1998). · Retrieved: 2026-10-02T14:49:21.580350+00:00Open source
  5. Hashcash: A Denial of Service Counter-MeasureAdam Back · 2002-08-01Satoshi Nakamoto Institute mirror of hashcash.org

    States that Hashcash was proposed in May 1997 to throttle abuse of email and anonymous remailers, defines the cost-function, and calls its token a proof-of-work.

    Locator: States that Hashcash was proposed in May 1997 to throttle abuse of email and anonymous remailers, defines the cost-function, and calls its token a proof-of-work. · Retrieved: 2026-10-02T15:04:11.761958+00:00Open source
  6. b-moneyWei Dai · 1998-11Satoshi Nakamoto Institute library

    The November 1998 proposal: the crypto-anarchy opening, money created by broadcasting solutions to computational problems, two protocols, and the admission that the first is impractical.

    Locator: The November 1998 proposal: the crypto-anarchy opening, money created by broadcasting solutions to computational problems, two protocols, and the admission that the first is impractical. · Retrieved: 2026-10-02T14:49:20.585079+00:00Open source
  7. Bit goldNick SzaboUnenumerated (Nick Szabo’s blog)

    The proposal’s trust-in-a-third-party opening, its seven steps (challenge string, proof of work, timestamps, title registry), and the non-fungibility caveat; the URL is filed under December 2005 while the page shows 27 December 2008.

    Locator: The proposal’s trust-in-a-third-party opening, its seven steps (challenge string, proof of work, timestamps, title registry), and the non-fungibility caveat; the URL is filed under December 2005 while the page shows 27 December 2008. · Retrieved: 2026-10-02T14:49:22.442075+00:00Open source
  8. Bitcoin P2P e-cash paperSatoshi Nakamoto · 2008-10-31Cryptography mailing list archive, metzdowd.com

    The 31 October 2008 email (14:10 EDT) announcing the paper, with its list of properties including no trusted third party, no mint, and Hashcash-style proof of work.

    Locator: The 31 October 2008 email (14:10 EDT) announcing the paper, with its list of properties including no trusted third party, no mint, and Hashcash-style proof of work. · Retrieved: 2026-10-02T14:48:59.965467+00:00Open source
How this article was made

Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.

Editorial method and corrections

Degrees of Satoshi editorial project. “The cypherpunks: the mailing list and the ideas that came before Bitcoin.” Published 2026-09-23; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/cypherpunks-before-bitcoin/