Private · Anonymous · Cash · Transfer

The protocol beneath private digital cash.

Pactena delivers anonymous, offline-capable payments with chain-precise fraud attribution — purpose-built proofs, not a generic zero-knowledge circuit, and fast enough for the point of sale.

Key-management foundation in production, licensed in two EU states·Reviewed cryptography·Post-quantum path designed in

Properties

01

Anonymous payments

The user's identity never reaches the merchant, and two payments cannot be linked — cryptographically, not by policy.

02

Identity-revealing double-spend

Spend the same unit twice and the cheat's own secret key becomes computable — automatic, non-deniable, no surveillance. Counterfeiting cash once took experts to detect; here a double-spend is exposed in milliseconds, with proof.

03

Chain-precise attribution

Offline transfers carry a bounded provenance chain. A double-spend anywhere in it names exactly the original cheat, and every other honest member of the chain keeps their anonymity — neither the honest holders before the cheat nor those after them are exposed, or even made suspect.

04

Offline capability

Payments verify locally against root keys alone. Person-to-person transfer works offline up to ten (or any designed) hops, then refreshes online.

05

One trust chain, one verification

A single signature scheme covers every certificate, note and transfer — Root → Issuer → Merchant/User — checked by one verification function.

06

Card speed, small payment package

The payment package handed to the recipient is about 456 bytes when freshly issued, and about 956 bytes after a maximum-depth transfer chain — verified in about 12 ms.

07

Asset-neutral, institution-operated

A two-layer design carries any form of money. The network is operated in a distributed way by the participating institutions, under the supervision of the domestic authority.

08

Post-quantum ready

A post-quantum variant is designed at the algorithmic level; crypto-agility is built into the architecture.

Architecture

ROOT

Root authority

e.g. a central bank

ISSUERS

Issuers

banks · payment institutions

EDGE

Merchants & Users

point of sale · person-to-person

Account layer (threshold key management) + Payment layer (note-based spending). Settlement runs on the interbank rails that already exist — or, in time, in the digital note itself.

See the architecture →

~456–956 B

Payment package handed to the recipient

~12 ms

Offline verification

35–65 ms

Online payment, end to end

Compliance

Privacy is transactional, not system-wide: anonymous to the merchant, known to the issuer. KYC at onboarding, anti-money-laundering controls where value enters and leaves the system. No new money-laundering channel — the system is more traceable than physical cash.

Where this stands

The gap, and who else is in it.

Thirty-six offline payment systems were surveyed independently in 2026. Every one of them faces the same three open challenges: reliance on trusted hardware, the de-anonymisation of honest users when a double-spend happens, or transactions that grow with every offline payment. The same field was surveyed here as well — the literature, the patents, the central-bank record, the vendors — and the findings are written down, source by source.

Read the survey →

Evidence

Not a promise. A running system.

Several dozen groups across Europe work on the theory in this line, and the best of them could design this protocol. What is rare is not the mathematics. It is one team that also understands interbank settlement, what a supervisor will ask, and the two seconds at a till. That is applied cryptography — where the construction and the business reality are built at the same table.

Read the properties. Then read the open questions.

The specification, the security analysis and the compliance document are shared under NDA.