Icons & Legends5 min read

David Chaum’s DigiCash: Private Payments Still Needed a Bank

In 1995, Mark Twain Bank offered dollar-denominated eCash using DigiCash technology. David Chaum’s could separate a digital coin’s withdrawal from its later payment, yet the business still needed issuing banks, merchants and customers. Its story joins an ingenious privacy mechanism to a much harder adoption problem.

David Chaum’s DigiCash: Private Payments Still Needed a Bank

3-Minute Fast Briefing

  • The ParadoxChaum’s work for CRYPTO ’82 introduced . They let a signer validate a hidden message, creating a foundation for electronic payments that could not be linked to a particular withdrawal.
  • The Turning PointOn October 23, 1995, Mark Twain Bank began accepting applications for dollar eCash accounts. DigiCash supplied the technology; the bank remained the issuer and checked redeemed coins against repeat spending.
  • The LegacyDigiCash sought protection in November 1998. Contemporary reporting and Chaum’s later account describe a business struggling to attract both merchants and customers, not a demonstrated break of blind-signature cryptography.

Chronological Timeline

1982A signature without seeing the message

Chaum’s work for CRYPTO ’82 proposes for untraceable payments.

1992Privacy explained to a wider audience

In Scientific American, Chaum explains how linked electronic records expose personal activity and how cryptography can limit that linkage.

1994The CyberBucks experiment

DigiCash tests electronic cash with an experimental currency rather than bank-issued dollars.

October 23, 1995A dollar-denominated bank service

Mark Twain Bank begins accepting applications for accounts using DigiCash’s eCash technology.

November 1998Chapter 11 protection

Wired reports DigiCash’s bankruptcy filing after staff cuts and the end of its U.S. banking trial.

March 2002Assets continue under another owner

American Banker reports InfoSpace’s acquisition of eCash Technologies, a business created from DigiCash patents and assets.

A Password in the Post

On October 23, 1995, Mark Twain Bank of St. Louis began accepting applications for eCash accounts. The launch announcement described a striking combination: download the application form from the Internet, send it by mail or fax, and receive a password in the post. Digital cash would live on a computer’s disk, but entry still passed through a bank and a physical envelope.[2]

DigiCash supplied the technology under a non-exclusive licence. Earlier CyberBucks experiments had used a test currency; the bank service was denominated in U.S. dollars. Steven Levy’s 1994 Wired account had described the experimental system and its prospective online shops. The move to bank money changed what the tokens represented: this was no longer merely a demonstration currency circulating among early participants.[2][4][5]

The Other Envelope

David Chaum’s paper for CRYPTO ’82 offered a way to obtain a valid signature without exposing the message being signed. Its paper analogy used an opaque, carbon-lined envelope: a signature applied outside could leave a mark on the hidden sheet. A gives the signer authority to validate something without automatically giving it the ability to recognize that item later.[1]

In his 1992 Scientific American article, Chaum explained the larger concern. Seemingly ordinary records of calls, purchases and other activities could be joined into a detailed account of someone’s life. His aim was not simply to make payments faster. It was to change which connections a system could make about the people using it.[3]

In the documented eCash design, the customer’s software chose a coin’s identifying number, hid it mathematically, obtained the bank’s signature and removed the hiding layer. The result was a coin whose signature could be verified, without the bank being able to match that redeemed coin to a particular withdrawal through this signing process. The hidden envelope was now mathematics, not stationery.[2][3]

Private Does Not Mean Bankless

A merchant still submitted received coins to the bank. The bank checked them against coins already spent, so copying a digital file did not make a second valid payment. Chaum’s Scientific American explanation explicitly described an online check against a central list. The design separated knowledge of the withdrawal from knowledge of the spent coin; it did not eliminate the institution that issued and redeemed money.[3]

This distinction limits the privacy claim as well. A bank knew an account holder was withdrawing value, and a seller could learn information during a purchase. Blind signatures protected the link between the signed coin and its withdrawal; they were not a promise to erase every identity, delivery address or network trace. Issuer trust and payment privacy answered different questions.[2][3]

The Two Sides That Had to Arrive Together

The privacy mechanism did not supply a ready-made market. Forbes reported in 1999 that the three-year Mercantile banking trial had attracted about 5,000 customers with combined account balances of only $100,000. Those figures describe that trial, not DigiCash’s total funding or every user worldwide. Chaum told the magazine that attracting enough merchants to interest customers—and enough customers to interest merchants—had been difficult.[7]

In November 1998, Wired reported that DigiCash had filed for protection, following job cuts and the end of its U.S. banking trial. The company was about $4 million in debt, according to the report. These are records of commercial distress. They do not demonstrate that someone defeated the cryptography, nor establish a single personality flaw as the cause of the company’s failure.[6]

The Company Ends; the Design Question Remains

In March 2002, American Banker reported that InfoSpace had bought eCash Technologies, a business formed from DigiCash’s patents and assets. The article described a broader transaction-processing operation. An asset’s survival under another company is different from the original private-cash service achieving mass adoption.[8]

The Bitcoin whitepaper later attacked a different dependency: a trusted institution deciding whether money had already been spent. It proposed a peer-to-peer, proof-of-work transaction history with publicly announced transactions. Comparing the documents reveals a design distinction, not proof that DigiCash turned into Bitcoin. Chaum showed how an issuer could validate money while learning less about its use; Bitcoin proposed agreement without that issuing bank at the centre. Privacy and decentralization were never interchangeable promises.[1][3][9]

Connected Lore & Universe

Connected Stories in this Universe

Explore the chain reaction of historical breakthroughs, blunders, and legends.

Sources & References

  1. [1]Source 1: Blind Signatures for Untraceable Payments, CRYPTO ’82David Chaum / CRYPTO ’82 proceedingsAccessed 2026-09-12
  2. [2]Source 2: October 23, 1995: Mark Twain Bank eCash launchDigiCashAccessed 2026-09-12
  3. [3]Source 3: Achieving Electronic Privacy, Scientific American, 1992David Chaum / Scientific AmericanAccessed 2026-09-12
  4. [4]Source 4: DigiCash’s preserved eCash milestonesDavid Chaum’s eCash archiveAccessed 2026-09-12
  5. [5]Source 5: E-Money: contemporary reporting from 1994Wired / Steven LevyAccessed 2026-09-12
  6. [6]Source 6: DigiCash Outta Cash, November 1998WiredAccessed 2026-09-12
  7. [7]Source 7: Requiem for a Bright Idea: adoption figures and Chaum’s accountForbes / Julie PittaAccessed 2026-09-12
  8. [8]Source 8: InfoSpace buys eCash Technologies, March 2002American BankerAccessed 2026-09-12
  9. [9]Source 9: Bitcoin: A Peer-to-Peer Electronic Cash SystemSatoshi NakamotoAccessed 2026-09-12