Bitcoin was not the first attempt at digital cash.
It was the first one that worked. Between 1981 and 2008, at least a half-dozen serious technical projects tried to build a private, native, internet-based form of money. Each of them solved a piece of the problem. None of them solved the whole problem. Bitcoin is best understood as the moment when those isolated solutions were finally assembled into a single coherent system.
Reading the Bitcoin whitepaper without knowing this prehistory is like reading the last chapter of a novel and assuming the author invented the characters in chapter one. The references in Satoshi’s paper are not throwaway citations. They are an explicit acknowledgment that Bitcoin stands on a stack of prior work. To understand why Bitcoin’s design choices are what they are, you have to understand what each of those prior projects tried, what each of them got right, and where each of them broke.
DigiCash and eCash: The First Try
The story begins with David Chaum. In 1981, while most people had never seen a personal computer, Chaum published “Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms,” a paper that effectively founded the field of cryptographic privacy. Two years later, he published the cryptographic primitive that would define his career: the blind signature.
A blind signature works like this. A bank can sign a digital “banknote” (a unique number) without ever seeing the number itself. The user scrambles the number with a random nonce, sends it to the bank, gets it signed, and unscrambles it. The bank’s signature is now attached to a banknote the bank cannot recognize. When the recipient later deposits that banknote, the bank can verify its own signature is valid, but cannot link the deposit to the original withdrawal. Privacy is preserved. Double-spending is prevented because the bank checks each banknote’s serial number against a database of already-redeemed notes.
In 1990, Chaum founded DigiCash in Amsterdam to commercialize the system. The product was called eCash. Through the mid-1990s, DigiCash signed licensing agreements with Mark Twain Bank in St. Louis, Deutsche Bank, Credit Suisse, and several others. Microsoft offered roughly $100 million to integrate eCash into Windows 95. Visa was prepared to invest $40 million. Netscape considered bundling it into the dominant web browser of the era.
Every one of those deals fell through. By 1998, DigiCash had filed for bankruptcy. The technology worked. The market did not. eCash required the public to value privacy enough to seek out a separate payment system, and at the dawn of the consumer internet, the public did not.
The deeper architectural lesson was that eCash was centralized. The bank was a single point of failure. If the bank shut down, the money died with it. Bitcoin would later treat that single point of failure as the problem to be eliminated, not the cost of doing business.
Hashcash: Buying the Right to Speak
Adam Back proposed Hashcash in 1997 to solve a different problem: email spam. The idea was elegant. Require every email sender to attach a small “proof of work,” a token that took measurable CPU time to compute but was instant to verify. For a normal user sending a few dozen emails a day, the cost was unnoticeable. For a spammer trying to send a million, it was prohibitive.
The mechanism Back used has since become the most-cited cryptographic primitive in finance. It worked by requiring the sender to find a partial hash collision: a string of bits that, when hashed with a cryptographic function (Back’s 2002 paper specifies SHA-1 or MD5), produced an output starting with a specified number of zero bits. The only way to find such a string was to try one candidate after another until one worked. The cost of producing a token was proportional to the number of leading zeros required. The verification, by contrast, was a single hash computation.
Hashcash was deployed in spam filters, and proof-of-work systems of the same family were adopted by Microsoft’s Penny Black research project. Both demonstrated that proof-of-work could meaningfully throttle abuse without trusted third parties. Hashcash did not solve the digital cash problem. It solved a piece of it: how to make a digital action expensive in a verifiable, decentralized way.
The Bitcoin whitepaper cites Hashcash as reference [6]. Bitcoin’s mining algorithm is, structurally, a generalization of Hashcash. Where Hashcash imposed a fixed cost per email, Bitcoin imposes a dynamically adjusting cost per block. The unit of work changed. The underlying primitive did not.
B-money: The Distributed Ledger Idea
In November 1998, the cypherpunk Wei Dai published “b-money” on the cypherpunk mailing list. The proposal was short, fewer than 1,500 words, and it contained an idea that was structurally close to what Bitcoin would later become.
Dai began with an explicit political premise. He was, he wrote, “fascinated by Tim May’s crypto-anarchy.” The community he wanted to enable would be one in which “violence is impossible, and violence is impossible because its participants cannot be linked to their true names or physical locations.” That community required a money it could call its own.
The b-money protocol described two ideas. In the first version, every participant maintained a separate database of how much money belonged to each pseudonym. New money was created by broadcasting solutions to computational problems whose cost equaled the work performed. Transfers were broadcast and recorded by every participant. In the second, more practical version, only a subset of “servers” maintained the ledger, with collateral mechanisms to keep them honest.
What Dai got right was profound: a money supply governed by computational work, an open ledger maintained collectively, and digital pseudonyms as identity. What he could not solve was consensus. If different participants saw conflicting transactions, b-money offered no rigorous mechanism to converge on a single shared truth. The idea of a distributed ledger was there. The idea of how to keep that ledger consistent across an adversarial network was not.
The Bitcoin whitepaper opens its references list with Wei Dai’s b-money as reference [1]. Adam Back later pointed Satoshi to Wei Dai’s page, and Satoshi added the citation to his draft.
Bit Gold: Chain-of-Title for Pure Information
Nick Szabo’s Bit Gold proposal, drafted in the late 1990s and published in 2005, was the closest theoretical predecessor to Bitcoin. Szabo had been thinking carefully about the properties that made physical commodities serve as money. He framed it as “unforgeable scarcity” produced by “unforgeably costly” computation, and worked through how to reproduce those properties in pure information.
Bit Gold’s mechanism worked roughly as follows. A public “challenge string” is created. A participant computes a proof-of-work over that challenge. The proof is timestamped through a distributed timestamp service. The result is added to a public title registry. The output of one round becomes the challenge for the next, chaining the proofs together. Ownership is established not by possessing the bits (they are public) but by holding the lead position in a chain of cryptographic title transfers.
The structural similarity to Bitcoin is unmistakable. A chain of proof-of-work outputs. Public timestamping. Title registered through cryptographic signatures. The element Szabo could not solve was the same one b-money could not solve: how to ensure that all participants in the network agreed on the canonical chain, in real time, without a trusted third party. Bit Gold’s distributed timestamp service required honest operation by enough participants, but had no mechanism to enforce it.
Bitcoin: The Synthesis
When Satoshi Nakamoto’s paper appeared in October 2008, its references list was short. Eight citations total. Wei Dai’s b-money was reference [1]. Adam Back’s Hashcash was reference [6]. The remaining six citations were timestamping papers by Massias, Avila, Quisquater, and Haber-Stornetta, along with Merkle on hash trees and Feller on probability. Bit Gold was not cited directly, though its design choices map cleanly onto Szabo’s framework.
The paper’s contribution was not any single new primitive. It was the way the existing primitives were combined.
Bitcoin took blind-signature-style anonymity from Chaum and replaced the trusted bank with a public ledger. It took proof-of-work from Hashcash and made the difficulty adjust over time so that block production remained constant as more miners joined. It took the distributed-ledger and proof-of-work-as-money concepts from b-money and gave them a concrete consensus mechanism. It took the chained-proof-of-work and unforgeable-scarcity concepts from Bit Gold and added the longest-chain rule, which solved consensus by making honest behavior the most economically rational choice for any participant.
That last piece, Nakamoto Consensus, is the original contribution. Everything else was already in the literature.
The Lesson
Bitcoin is sometimes presented as a flash of singular genius. It is more accurately a thirty-year relay race in which each runner handed off a partial solution to the next. Chaum solved digital privacy. Back solved decentralized cost imposition. Dai solved the ledger structure. Szabo solved the chain-of-title structure. Satoshi solved the consensus problem and assembled the rest.
Knowing this prehistory matters, because it sets the standard for what counts as a genuine improvement on Bitcoin. Every project that has claimed to be a “better Bitcoin” has, on inspection, broken at least one of the constraints these earlier failures already taught. Reintroducing trusted parties. Sacrificing decentralization for throughput. Loosening the supply schedule. Bitcoin is what is left after thirty years of removing what does not work.
Sources: Bitcoin Whitepaper (Nakamoto, 2008) | Hashcash White Paper (Back, 2002) | b-money (Dai, 1998) | Bit Gold (Szabo, 2005) | The Genesis Files (van Wirdum) | PRDV 151, Unit 3 “The Cypherpunk Movement, Cryptography, and the Origins of Digital Sovereignty” | Satoshi-Dai correspondence (Cryptography Mailing List archives)
What Is A.W. Block?
A.W. Block is a digital asset estate investigation and Bitcoin advisory firm. On the estate side, we support attorneys, probate administrators, and fiduciaries with asset identification, blockchain investigation, and court-ready documentation. On the advisory side, we work with individuals and institutions on Bitcoin custody, accumulation strategy, and education.
awblock.io
Found value? Share, subscribe, and/or send sats here: bc1qrlgzu0m94wdrsnxjg8qym7jtnudelgfypmjmaa
Around the Block is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.


