01
Offline finality
The receiving party decides on the spot, with no network. Not store-and-forward, where the risk is deferred and carried later by someone else — genuine, locally final acceptance.
Background
A statement of the form “no other system is known” is worth exactly what the search behind it is worth. So what follows is the yardstick, the sources, and the findings — named, one by one.
Seven properties, each decidable on its own, against which any system can be measured — an academic construction, an industrial product, a central-bank pilot, a patent. The first six are falsifiable: show one system that meets all six, and the claim falls.
01
The receiving party decides on the spot, with no network. Not store-and-forward, where the risk is deferred and carried later by someone else — genuine, locally final acceptance.
02
The security argument does not rest on a tamper-resistant component inside the user's device. An ordinary smartphone, with no security hardware. Optional use of such a component is acceptable; a claim that collapses without the chip is not.
03
The digital note travels on offline, from hand to hand — at least two hops without returning to the issuer. This is the difference between an electronic-money card and cash: from the card, value moves to the merchant and stops; a banknote carries on.
04
The identity of a double-spender is cryptographically recoverable from the traces of the two payments. No trusted third party unseals anything and no authority exercises judgement — the mathematics yields it, and anyone can check it.
05
The system names exactly the original cheat, and every other honest member of the chain keeps their anonymity — neither the honest holders before the cheat nor those after them are exposed, or even made suspect.
06
A formal theorem that no valid double-spend proof can be produced against an honest user — not by a malicious issuer, and not by colluding chain participants. The literature calls this exculpability, or non-frameability. It is what separates real accountability from mere accusability.
07
A versioned specification, a reference implementation, a working demonstrator, measured sizes and measured runtimes, a named curve choice, a live base layer, and a regulatory and redress framework. A construction that is correct on paper but unusable at a checkout is not a payment system.
The usual objection to a yardstick is that its author cut it to fit. So it is worth pointing out that an entirely independent systematisation measures the fifth property in exactly the same way. One column of the March 2026 SoK: Offline Payment Systems (University of Innsbruck, University of Vienna, SBA Research; arXiv:2603.16320, thirty-six systems) is “privacy revocation”, and it is defined as: DS if revocation occurs only in cases of double-spending, and U if the privacy of honest users may be unintentionally revoked as a side effect of detecting a double-spender. The authors set U in red, as an expressly undesirable property. Of the systems with full offline capability, exactly two receive a U — the same two constructions the yardstick above names as counter-examples. The criterion is not a Pactena invention.
Four decades, item by item, each with what it gave and what it cost. Read in sequence the line has a shape: every step that won a property paid for it somewhere else.
1982
Chaum: the blind signature.
The idea of anonymous digital cash, in a construction elegant enough to remain foundational to this day.
Online. The merchant has to call the bank at every single payment to learn whether the note has already been spent. Unusable offline, and there is no transfer.
1988
Chaum–Fiat–Naor: offline electronic cash.
The birth of the self-revealing double-spend. The spender's identity is encoded into the note so that one payment reveals nothing, while two payments let the bank compute the cheat's name.
One hop. The user pays the merchant, the merchant deposits. No hand-to-hand travel. And one point worth stating precisely: the paper contains no impossibility proof about prevention. What it contains is a design decision — it builds on detection rather than prevention, because offline prevention cannot be given.
1990–1992
Okamoto–Ohta: the first transferable electronic cash.
Money that can move on between any number of users.
Anonymity is weak. Even with no double-spend at all, it is decidable whether two payments were made by the same user. The literature later named this weak anonymity.
1993
Chaum–Pedersen: a negative result.
A proof that a transferred note necessarily grows with every hand-over, and that an observer with unbounded resources always recognises a note it held before.
This theorem hangs over the whole line that follows. Every transferable construction has to pay per hop. The only open question is how much.
2005
Camenisch–Hohenberger–Lysyanskaya: Compact E-Cash.
A breakthrough in withdrawal efficiency — many notes in a single operation, in a small holding. A widely used building block ever since.
Not transferable. User to merchant, and that is the end of the road.
2008
Canard–Gouget: the formal model.
The first formal systematisation of the anonymity notions for transferable cash, and a proof that the strongest conceivable notion is unreachable. They also give a construction that meets every reachable property.
In the literature's own words, “completely impractical” — it rests on generic complexity-theoretic reductions, so it is a proof of concept rather than a buildable system.
2009
Fuchsbauer, Vergnaud and co-authors: constant-size transferable cash.
A neat way around the growth bound: the history of the chain is not carried in the note but stored in receipts held by the users. Size stays constant.
This is the most instructive price in the whole story. On a double-spend, a trusted tracer could reveal the identities of honest holders through whose hands the tainted note later passed — the innocent paid for the guilty, even if only to one privileged party. Two clarifications in fairness: the anonymity is not lost publicly, only towards that trusted party, and the process is interactive, requiring receipts to be requested from users. By the yardstick above the property still fails: honest holders become identified, and become suspect.
2011
Blazy and co-authors: anonymity with a judge.
A repair of the previous work's shortcomings, restoring the honest user's anonymity.
It needs an all-seeing judge. That key does not only identify the cheat: with it, any note and any user can be traced at any time. The price did not fall, it changed shape — a single key that opens the anonymity of the entire system.
2015
Baldimtsi–Chase–Fuchsbauer–Kohlweiss: fully anonymous transferable cash.
The first construction to target all three anonymity notions of the literature without a trusted third party. The authors describe the design goal like this: “it needs to ensure that the right user is accused while the anonymity of honest owners … will be preserved” — essentially the fifth property of the yardstick above, from 2015.
Two prices. The proof of the strongest anonymity notion was later found to contain an error — by the authors of the next chapter. And by the literature's own assessment it is “hardly practical”; the building blocks are “far from being implementable on constrained mobile devices”.
In 2021 Balthazar Bauer, Georg Fuchsbauer and Chen Qian presented Transferable E-Cash: A Cleaner Model and the First Practical Instantiation at PKC. Their construction meets all six falsifiable properties. Offline finality, no hardware trust, unbounded transfer depth, a self-revealing double-spend, attribution that spares the innocent, and a formal no-framing theorem — the last of these against a malicious bank and colluding chain participants at once. All three anonymity notions in the literature are proved, including the strongest one. The independent 2026 systematisation confirms this and places them on the “only in cases of double-spending” side.
The feasibility of the property combination was therefore shown by them. That is not in dispute. The rest of this page is checkable precisely because the source of the concept is named, and because what was added to it is named just as precisely.
What was not done is strictly a category of fact, and it has three elements: there is no published implementation, no measured runtime and no curve choice. Three independent sources confirm this — an ACNS 2026 paper citing the work (“the performance of Bauer et al. is not reported”), the table of the 2026 SoK, where the implementation, transactions-per-second and latency cells are empty, and the first author's own doctoral thesis, in which a search of the full text for runtimes, byte sizes, a prototype or a curve returns nothing substantive.
We view this as practical by current standards.
| Measure | Bauer–Fuchsbauer–Qian 2021 | Pactena v8 |
|---|---|---|
| Payment package handed to the recipient, after withdrawal | 19,248 bytes | ~456 bytes |
| Growth per transfer | +7,392 bytes | +48 bytes |
| Deepest chain | unbounded depth | ~956 bytes (ten hops) |
| Offline verification | not measured | ~12 ms |
| Implementation, benchmark, curve choice | none published | reference implementation and working demonstrator |
The figures in the table come from the efficiency analysis of the paper, which states sizes as abstract group-element counts. Converted to the curve the authors themselves examined — a conversion the citing literature has also carried out, reaching the same result — those counts yield the byte sizes above. Their note is roughly nineteen kilobytes when fresh and grows by roughly seven kilobytes at every hand-over; after a ten-step chain it is on the order of ninety kilobytes. This is not an error on the authors’ part: it is the price of the strongest anonymity notion, which they took on deliberately and justified in the paper. The comparison is made on payment packages rather than proofs because their proof of guilt is 96 bytes and constant with depth — measured on proof size, the two systems would be indistinguishable.
The difference is a deliberate trade-off at two points. The Pactena transfer depth is bounded — ten hops, as a configurable parameter — and theirs is not. Pactena privacy is transactional and separated at the issuer boundary rather than system-wide: the merchant does not learn who paid; the recipient verifies the counterparty in front of them but learns nothing about the earlier holders; and an issuer knows only its own customer, plus the issuer it has to settle with. The intermediate users of the chain are exposed to no one. The strongest anonymity notion in the literature would also require that an issuer cannot follow its own issuance; in a regulated, KYC-based system that is neither necessary nor desirable, because accountability is exactly what is needed at the issuer boundary. The price of the trade-off is measurable: the Pactena payment package grows by 48 bytes per transfer, not by seven kilobytes. Bauer, Fuchsbauer and Qian showed that it can be done; Pactena shows that it can be shipped.
The 1990s genuinely had offline digital cash, in many countries and at scale. This is the part most accounts leave out, and it is the part from which the present situation can be understood.
1990s
DigiCash / eCash — Chaum's company.
Proof that anonymous digital payment works, on an ordinary personal computer, with no security hardware.
In the shipped product the bank verified every note online; the offline mode remained a “future extension”. The company went bankrupt in 1998.
1992–1995
CAFE — the EU ESPRIT project, with Chaum's participation.
The most refined construction of the period — and the only construction of that period with cryptographic identification of the cheat: “Even if the tamper-resistance is broken, users who spend electronic money more than once are identified, and the identity of the user whose guardian was used for this fraud can be proved.” In 1994 the authors already saw that what matters is provability that stands up in court, not detection on its own.
In the project's own words, “it allows just one transfer of the electronic money”. One hop. No chain. The project closed as planned in November 1995 and never became a product.
1990s
Mondex — NatWest, later Mastercard.
Card to card, offline, hand to hand, with no clearing in between — of its era, the only system that could do the chain at unbounded length. An ITSEC E6 certificate, a formal security model, and live operation in more than a dozen countries.
Trust moved into the chip. The card did not prove that no one had cheated; it relied on cheating being infeasible. There is no identification of the cheat: the card stored only the last ten transactions, and no global audit trail existed. Contemporary criticism said exactly this. The last market closed in 2008.
1996–2020s
GeldKarte, Octopus, Proton, Chipknip, Danmønt, Quick, Moneo, Visa Cash.
Working, widespread offline payment, in several countries, in some cases running for decades.
All of them built on a tamper-resistant chip card. Transfer between users is either expressly excluded — the German GeldKarte documentation devotes a section to the principle of “Nichtübertragbarkeit von Guthaben” — or runs through an online application, as with Octopus. None has cryptographic identification of the cheat; abuse is handled by central shadow accounts and blacklists.
2020s
The central banks: the digital euro offline layer, e-CNY, UPI Lite X, the e-krona pilot, the digital pound, BIS Project Polaris.
Offline payment in live, large-volume systems, in a regulated setting, and in some cases with more than one hop.
The security anchor is everywhere a chip inside the user's device, and identification of the cheat is either absent or institutional rather than cryptographic. In the Bank of England's 2025 experiment five vendors out of five used secure elements; the Riksbank tried a design based on phones alone and rejected it in writing.
Two patterns, and they hold across forty years. Where offline payment was taken seriously, hardware was put underneath it. Where the mathematics was chosen instead, either nothing shipped, or the honest paid the cheat's price. No historical system met the multi-hop offline chain and cryptographic identification of the cheat at the same time: Mondex had the chain but not the identification, CAFE had the identification but not the chain.
The strongest historical footnote is this. When David Chaum himself returned to offline, hand-to-hand payment in 2022, he reached back for a physical card, and wrote: “Solutions relying only on software, including previous proposals by the present author, do not provide strong assurance of finality.” That quotation cuts both ways, and both readings belong here. On one, the founder of the field states that no one had succeeded on the software-only path. On the other, a considerable authority states that the path does not lead anywhere. The second reading is a serious challenge — and it is the reason the Pactena construction was measured, not merely designed.
A claim of the form “nothing else was found” is worth what the search behind it is worth. So the sources are named here one by one, with the extent of each.
The second and third rounds of research raised no new finding against the first six properties. The search reached saturation.
Quotations about digital money and offline payment itself.
Each faces open challenges: complete reliance on trusted hardware, the deanonymisation of honest users in the case of double-spending, or growing transactions with each offline payment. To date, no system providing offline functionality has been implemented.
In a fully offline setting without secure hardware, double-spending cannot be prevented. … [The multi-hop mode] hinges entirely on the security of the hardware.
Local storage settlement model — a settlement model referring to secure element (SE) in the digital euro user's devices performing the technical tasks of verification and registration of holdings…
All solutions used secure elements to support double spend and counterfeit prevention or to protect cryptographic key information.
This was not possible as our assessment is that it was not possible to achieve adequate safety. We therefore chose to base the offline solution solely on cards.
Any solution will depend on the tamper resistance of the user device to protect against physical and cyber attacks.
Two further sentences describe the apparent dilemma the whole research was aimed at. The BIS: “if there are no links between devices and user identity, there would be no way to identify potentially malicious users even if malicious devices can be blocked in the system.” The Bank of England: “if double spending were to occur, there would be no way of knowing which device initiated it.”
In 2026 the central-bank field treats anonymity and identification of the cheat as mutually exclusive. The cryptographic literature has known since 2021 that they are not. What was missing was the instantiation that can be delivered.
The cryptographic feasibility of the property combination was established by the academic literature — Baldimtsi–Chase–Fuchsbauer–Kohlweiss in 2015 and Bauer–Fuchsbauer–Qian in 2021. That is not in dispute. What Pactena adds is the innovation and the implementation: measured sizes, measured verification time, a reference implementation and a working demo, on an ordinary phone, with no security hardware. The payment package handed to the recipient is about 456 bytes when freshly issued and about 956 bytes at the deepest chain, verified in about 12 ms.
The transfer depth is deliberately bounded at ten hops, with privacy preserved. External cryptographic review of the payment layer is under way; the outcome will be published. The specification is complete.
As of August 2026 no other publicly documented, working payment system is known that provides this combination of properties together, in implemented and measured form.
The research runs on a continuing basis. If you know of such a system, we would genuinely like to see it.