Background

The field, measured.

A statement of the form “no other system is known” is worth exactly what the search behind it is worth. So what follows is the yardstick, the sources, and the findings — named, one by one.

The yardstick

Seven properties, each decidable on its own, against which any system can be measured — an academic construction, an industrial product, a central-bank pilot, a patent. The first six are falsifiable: show one system that meets all six, and the claim falls.

01

Offline finality

The receiving party decides on the spot, with no network. Not store-and-forward, where the risk is deferred and carried later by someone else — genuine, locally final acceptance.

02

No hardware trust

The security argument does not rest on a tamper-resistant component inside the user's device. An ordinary smartphone, with no security hardware. Optional use of such a component is acceptable; a claim that collapses without the chip is not.

03

Multi-hop transfer

The digital note travels on offline, from hand to hand — at least two hops without returning to the issuer. This is the difference between an electronic-money card and cash: from the card, value moves to the merchant and stops; a banknote carries on.

04

Self-revealing fraud

The identity of a double-spender is cryptographically recoverable from the traces of the two payments. No trusted third party unseals anything and no authority exercises judgement — the mathematics yields it, and anyone can check it.

05

Attribution that spares the innocent

The system names exactly the original cheat, and every other honest member of the chain keeps their anonymity — neither the honest holders before the cheat nor those after them are exposed, or even made suspect.

06

No framing

A formal theorem that no valid double-spend proof can be produced against an honest user — not by a malicious issuer, and not by colluding chain participants. The literature calls this exculpability, or non-frameability. It is what separates real accountability from mere accusability.

07

Deliverability

A versioned specification, a reference implementation, a working demonstrator, measured sizes and measured runtimes, a named curve choice, a live base layer, and a regulatory and redress framework. A construction that is correct on paper but unusable at a checkout is not a payment system.

The usual objection to a yardstick is that its author cut it to fit. So it is worth pointing out that an entirely independent systematisation measures the fifth property in exactly the same way. One column of the March 2026 SoK: Offline Payment Systems (University of Innsbruck, University of Vienna, SBA Research; arXiv:2603.16320, thirty-six systems) is “privacy revocation”, and it is defined as: DS if revocation occurs only in cases of double-spending, and U if the privacy of honest users may be unintentionally revoked as a side effect of detecting a double-spender. The authors set U in red, as an expressly undesirable property. Of the systems with full offline capability, exactly two receive a U — the same two constructions the yardstick above names as counter-examples. The criterion is not a Pactena invention.

The academic line

Four decades, item by item, each with what it gave and what it cost. Read in sequence the line has a shape: every step that won a property paid for it somewhere else.

  1. Year

    1982

    What it was

    Chaum: the blind signature.

    What it gave

    The idea of anonymous digital cash, in a construction elegant enough to remain foundational to this day.

    The price

    Online. The merchant has to call the bank at every single payment to learn whether the note has already been spent. Unusable offline, and there is no transfer.

  2. Year

    1988

    What it was

    Chaum–Fiat–Naor: offline electronic cash.

    What it gave

    The birth of the self-revealing double-spend. The spender's identity is encoded into the note so that one payment reveals nothing, while two payments let the bank compute the cheat's name.

    The price

    One hop. The user pays the merchant, the merchant deposits. No hand-to-hand travel. And one point worth stating precisely: the paper contains no impossibility proof about prevention. What it contains is a design decision — it builds on detection rather than prevention, because offline prevention cannot be given.

  3. Year

    1990–1992

    What it was

    Okamoto–Ohta: the first transferable electronic cash.

    What it gave

    Money that can move on between any number of users.

    The price

    Anonymity is weak. Even with no double-spend at all, it is decidable whether two payments were made by the same user. The literature later named this weak anonymity.

  4. Year

    1993

    What it was

    Chaum–Pedersen: a negative result.

    What it gave

    A proof that a transferred note necessarily grows with every hand-over, and that an observer with unbounded resources always recognises a note it held before.

    The price

    This theorem hangs over the whole line that follows. Every transferable construction has to pay per hop. The only open question is how much.

  5. Year

    2005

    What it was

    Camenisch–Hohenberger–Lysyanskaya: Compact E-Cash.

    What it gave

    A breakthrough in withdrawal efficiency — many notes in a single operation, in a small holding. A widely used building block ever since.

    The price

    Not transferable. User to merchant, and that is the end of the road.

  6. Year

    2008

    What it was

    Canard–Gouget: the formal model.

    What it gave

    The first formal systematisation of the anonymity notions for transferable cash, and a proof that the strongest conceivable notion is unreachable. They also give a construction that meets every reachable property.

    The price

    In the literature's own words, “completely impractical” — it rests on generic complexity-theoretic reductions, so it is a proof of concept rather than a buildable system.

  7. Year

    2009

    What it was

    Fuchsbauer, Vergnaud and co-authors: constant-size transferable cash.

    What it gave

    A neat way around the growth bound: the history of the chain is not carried in the note but stored in receipts held by the users. Size stays constant.

    The price

    This is the most instructive price in the whole story. On a double-spend, a trusted tracer could reveal the identities of honest holders through whose hands the tainted note later passed — the innocent paid for the guilty, even if only to one privileged party. Two clarifications in fairness: the anonymity is not lost publicly, only towards that trusted party, and the process is interactive, requiring receipts to be requested from users. By the yardstick above the property still fails: honest holders become identified, and become suspect.

  8. Year

    2011

    What it was

    Blazy and co-authors: anonymity with a judge.

    What it gave

    A repair of the previous work's shortcomings, restoring the honest user's anonymity.

    The price

    It needs an all-seeing judge. That key does not only identify the cheat: with it, any note and any user can be traced at any time. The price did not fall, it changed shape — a single key that opens the anonymity of the entire system.

  9. Year

    2015

    What it was

    Baldimtsi–Chase–Fuchsbauer–Kohlweiss: fully anonymous transferable cash.

    What it gave

    The first construction to target all three anonymity notions of the literature without a trusted third party. The authors describe the design goal like this: “it needs to ensure that the right user is accused while the anonymity of honest owners … will be preserved” — essentially the fifth property of the yardstick above, from 2015.

    The price

    Two prices. The proof of the strongest anonymity notion was later found to contain an error — by the authors of the next chapter. And by the literature's own assessment it is “hardly practical”; the building blocks are “far from being implementable on constrained mobile devices”.

Bauer–Fuchsbauer–Qian, 2021 — the one real challenger

In 2021 Balthazar Bauer, Georg Fuchsbauer and Chen Qian presented Transferable E-Cash: A Cleaner Model and the First Practical Instantiation at PKC. Their construction meets all six falsifiable properties. Offline finality, no hardware trust, unbounded transfer depth, a self-revealing double-spend, attribution that spares the innocent, and a formal no-framing theorem — the last of these against a malicious bank and colluding chain participants at once. All three anonymity notions in the literature are proved, including the strongest one. The independent 2026 systematisation confirms this and places them on the “only in cases of double-spending” side.

The feasibility of the property combination was therefore shown by them. That is not in dispute. The rest of this page is checkable precisely because the source of the concept is named, and because what was added to it is named just as precisely.

What was not done is strictly a category of fact, and it has three elements: there is no published implementation, no measured runtime and no curve choice. Three independent sources confirm this — an ACNS 2026 paper citing the work (“the performance of Bauer et al. is not reported”), the table of the 2026 SoK, where the implementation, transactions-per-second and latency cells are empty, and the first author's own doctoral thesis, in which a search of the full text for runtimes, byte sizes, a prototype or a curve returns nothing substantive.

We view this as practical by current standards.
Bauer, Fuchsbauer, Qian: Transferable E-Cash: A Cleaner Model and the First Practical Instantiation, IACR ePrint 2020/1400, introduction. The authors do consider their own construction practical, and measured against the earlier, genuinely unrealisable constructions that assessment is fair.
MeasureBauer–Fuchsbauer–Qian 2021Pactena v8
Payment package handed to the recipient, after withdrawal 19,248 bytes ~456 bytes
Growth per transfer +7,392 bytes +48 bytes
Deepest chain unbounded depth ~956 bytes (ten hops)
Offline verification not measured ~12 ms
Implementation, benchmark, curve choice none published reference implementation and working demonstrator

The figures in the table come from the efficiency analysis of the paper, which states sizes as abstract group-element counts. Converted to the curve the authors themselves examined — a conversion the citing literature has also carried out, reaching the same result — those counts yield the byte sizes above. Their note is roughly nineteen kilobytes when fresh and grows by roughly seven kilobytes at every hand-over; after a ten-step chain it is on the order of ninety kilobytes. This is not an error on the authors’ part: it is the price of the strongest anonymity notion, which they took on deliberately and justified in the paper. The comparison is made on payment packages rather than proofs because their proof of guilt is 96 bytes and constant with depth — measured on proof size, the two systems would be indistinguishable.

The difference is a deliberate trade-off at two points. The Pactena transfer depth is bounded — ten hops, as a configurable parameter — and theirs is not. Pactena privacy is transactional and separated at the issuer boundary rather than system-wide: the merchant does not learn who paid; the recipient verifies the counterparty in front of them but learns nothing about the earlier holders; and an issuer knows only its own customer, plus the issuer it has to settle with. The intermediate users of the chain are exposed to no one. The strongest anonymity notion in the literature would also require that an issuer cannot follow its own issuance; in a regulated, KYC-based system that is neither necessary nor desirable, because accountability is exactly what is needed at the issuer boundary. The price of the trade-off is measurable: the Pactena payment package grows by 48 bytes per transfer, not by seven kilobytes. Bauer, Fuchsbauer and Qian showed that it can be done; Pactena shows that it can be shipped.

The industrial and central-bank line

The 1990s genuinely had offline digital cash, in many countries and at scale. This is the part most accounts leave out, and it is the part from which the present situation can be understood.

  1. Year

    1990s

    What it was

    DigiCash / eCash — Chaum's company.

    What it gave

    Proof that anonymous digital payment works, on an ordinary personal computer, with no security hardware.

    The price

    In the shipped product the bank verified every note online; the offline mode remained a “future extension”. The company went bankrupt in 1998.

  2. Year

    1992–1995

    What it was

    CAFE — the EU ESPRIT project, with Chaum's participation.

    What it gave

    The most refined construction of the period — and the only construction of that period with cryptographic identification of the cheat: “Even if the tamper-resistance is broken, users who spend electronic money more than once are identified, and the identity of the user whose guardian was used for this fraud can be proved.” In 1994 the authors already saw that what matters is provability that stands up in court, not detection on its own.

    The price

    In the project's own words, “it allows just one transfer of the electronic money”. One hop. No chain. The project closed as planned in November 1995 and never became a product.

  3. Year

    1990s

    What it was

    Mondex — NatWest, later Mastercard.

    What it gave

    Card to card, offline, hand to hand, with no clearing in between — of its era, the only system that could do the chain at unbounded length. An ITSEC E6 certificate, a formal security model, and live operation in more than a dozen countries.

    The price

    Trust moved into the chip. The card did not prove that no one had cheated; it relied on cheating being infeasible. There is no identification of the cheat: the card stored only the last ten transactions, and no global audit trail existed. Contemporary criticism said exactly this. The last market closed in 2008.

  4. Year

    1996–2020s

    What it was

    GeldKarte, Octopus, Proton, Chipknip, Danmønt, Quick, Moneo, Visa Cash.

    What it gave

    Working, widespread offline payment, in several countries, in some cases running for decades.

    The price

    All of them built on a tamper-resistant chip card. Transfer between users is either expressly excluded — the German GeldKarte documentation devotes a section to the principle of “Nichtübertragbarkeit von Guthaben” — or runs through an online application, as with Octopus. None has cryptographic identification of the cheat; abuse is handled by central shadow accounts and blacklists.

  5. Year

    2020s

    What it was

    The central banks: the digital euro offline layer, e-CNY, UPI Lite X, the e-krona pilot, the digital pound, BIS Project Polaris.

    What it gave

    Offline payment in live, large-volume systems, in a regulated setting, and in some cases with more than one hop.

    The price

    The security anchor is everywhere a chip inside the user's device, and identification of the cheat is either absent or institutional rather than cryptographic. In the Bank of England's 2025 experiment five vendors out of five used secure elements; the Riksbank tried a design based on phones alone and rejected it in writing.

Two patterns, and they hold across forty years. Where offline payment was taken seriously, hardware was put underneath it. Where the mathematics was chosen instead, either nothing shipped, or the honest paid the cheat's price. No historical system met the multi-hop offline chain and cryptographic identification of the cheat at the same time: Mondex had the chain but not the identification, CAFE had the identification but not the chain.

The strongest historical footnote is this. When David Chaum himself returned to offline, hand-to-hand payment in 2022, he reached back for a physical card, and wrote: “Solutions relying only on software, including previous proposals by the present author, do not provide strong assurance of finality.” That quotation cuts both ways, and both readings belong here. On one, the founder of the field states that no one had succeeded on the software-only path. On the other, a considerable authority states that the path does not lead anywhere. The second reading is a serious challenge — and it is the reason the Pactena construction was measured, not merely designed.

Sources examined

A claim of the form “nothing else was found” is worth what the search behind it is worth. So the sources are named here one by one, with the extent of each.

IACR ePrint Archive
The complete transferable e-cash corpus — five items, the most recent being the 2020 preprint of Bauer–Fuchsbauer–Qian. No new transferable construction has appeared since.
DBLP
The full post-2021 publication list of every author in the line, and all thirty-eight papers citing Bauer–Fuchsbauer–Qian, read one by one.
SoK: Offline Payment Systems, 2026
All thirty-six systems of the survey, cell by cell, read out of the paper’s LaTeX source.
Conference programmes
Real World Crypto in full from 2015 to 2026, the IACR video archive of 2,290 recordings, the Financial Cryptography main programme and the CoDecFin workshop from 2019 to 2026.
Doctoral and master’s theses
The HAL, CORE, TU Delft, Normandie and CUHK archives — including a thesis defended in March 2026 that, after four years of targeted research, still rests on security hardware.
Google Patents
Full-text and classification search, some forty queries, with twenty-seven patents read at claim level.
Central-bank and international documents
Twenty-four projects, thirteen of them in the full text of the official document — BIS, the ECB, the Bank of England, the Riksbank, the Fed and the EDPB — and each of the twelve vendors of BIS Project Polaris, individually.
Standards bodies
ISO/TS 12812, EMVCo, ISO 20022, W3C, ETSI, X9 and GSMA. Where the full text sits behind a paywall, only what the published scope supports is asserted.
Historical stored-value systems
Twenty-five systems traced back to primary sources — Mondex, DigiCash, CAFE, GeldKarte, Octopus and the rest of the field.
Industrial and non-academic corpus
The complete media.ccc.de archive and DEF CON 27 to 33.
Research funding registries
Through the OpenAIRE aggregator: CORDIS, ANR, DFG, UKRI, NWO, NSF and FWF. The query offline AND payment returns zero projects.
Non-English literature
Chinese, Japanese, Korean, Russian, German and French sources. Every accessible item rests, without exception, on a hardware trust anchor.

The second and third rounds of research raised no new finding against the first six properties. The search reached saturation.

Outside voices

Quotations about digital money and offline payment itself.

Each faces open challenges: complete reliance on trusted hardware, the deanonymisation of honest users in the case of double-spending, or growing transactions with each offline payment. To date, no system providing offline functionality has been implemented.
Senn, Judmayer, Stifter, Böhme: SoK: Offline Payment Systems, arXiv:2603.16320v1, March 2026, Appendix G
In a fully offline setting without secure hardware, double-spending cannot be prevented. … [The multi-hop mode] hinges entirely on the security of the hardware.
Prof. Dr.-Ing. Tibor Jager, expert opinion on the digital euro's offline modality, EDPB Support Pool of Experts Programme, October 2025. The document states expressly that it is an expert opinion and not an official EDPB position.
Local storage settlement model — a settlement model referring to secure element (SE) in the digital euro user's devices performing the technical tasks of verification and registration of holdings…
European Central Bank, Draft digital euro scheme rulebook v0.9, 31 July 2025, glossary. The secure element here is not an option but part of the definition.
All solutions used secure elements to support double spend and counterfeit prevention or to protect cryptographic key information.
Bank of England, Digital pound experiment report: Offline payments, 2025 — five vendors out of five
This was not possible as our assessment is that it was not possible to achieve adequate safety. We therefore chose to base the offline solution solely on cards.
Sveriges Riksbank, E-krona pilot Phase 4, March 2024 — on the attempt to build the offline solution on phones alone
Any solution will depend on the tamper resistance of the user device to protect against physical and cyber attacks.
BIS Innovation Hub, Project Polaris Part 1: A handbook for offline payments with CBDC, May 2023

Two further sentences describe the apparent dilemma the whole research was aimed at. The BIS: “if there are no links between devices and user identity, there would be no way to identify potentially malicious users even if malicious devices can be blocked in the system.” The Bank of England: “if double spending were to occur, there would be no way of knowing which device initiated it.”

In 2026 the central-bank field treats anonymity and identification of the cheat as mutually exclusive. The cryptographic literature has known since 2021 that they are not. What was missing was the instantiation that can be delivered.

Where Pactena stands

The cryptographic feasibility of the property combination was established by the academic literature — Baldimtsi–Chase–Fuchsbauer–Kohlweiss in 2015 and Bauer–Fuchsbauer–Qian in 2021. That is not in dispute. What Pactena adds is the innovation and the implementation: measured sizes, measured verification time, a reference implementation and a working demo, on an ordinary phone, with no security hardware. The payment package handed to the recipient is about 456 bytes when freshly issued and about 956 bytes at the deepest chain, verified in about 12 ms.

The transfer depth is deliberately bounded at ten hops, with privacy preserved. External cryptographic review of the payment layer is under way; the outcome will be published. The specification is complete.

As of August 2026 no other publicly documented, working payment system is known that provides this combination of properties together, in implemented and measured form.

The research runs on a continuing basis. If you know of such a system, we would genuinely like to see it.