Paper 2026/2174

Blind Spots in Blind Signatures: A System-Level Security Analysis of Deployed Chaumian Ecash

Huaifeng Chen
Yuchang Zhang
Yu Cheng
Abstract

Cashu, the dominant deployed Chaumian ecash system, has grown to 31 specification documents, 58 indexed mints, and seven interoperable wallets, while the cryptographic literature has studied only its blind-signature core. Every incident in the system’s short audited history, including a cross-mint theft disclosed in early 2026, is compositional: it emerges from keyset rotation, wallet recovery, and multi-mint identity. We give the first system-level security analysis of a deployed ecash system, built on a five-layer model, a nine-property family (three properties new), and a stateful one-more-unforgeability theorem whose proof separates forgery from theft; the deployed attacks commit theft without forging anything. We reproduce the disclosed theft end-to-end, exhibit a strictly stronger public-key-claim variant, and measure all 58 indexed mints: every reachable mint declares support for DLEQ proofs, the sole remaining defense, yet declarations are unauthenticated the guardrail sits with the issuer, not the wallet. A theft theorem gives necessary and sufficient conditions for prevention, and replaying three fixes shows the cheapest one costs honest issuers nothing. A defect taxonomy and a three-system comparison suggest a broader lesson: recoverability is not free. All artifacts are pure standard-library Python and pass the 49 o cial test vectors.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Chaumian ecashblind signaturesCashusystem-level security analysismainnet measurement
Contact author(s)
chenhf @ ncse com cn
zhangyuchang26 @ mails ucas ac cn
chengyu_cs @ zjut edu cn
History
2026-09-26: approved
2026-09-23: received
See all versions
Short URL
https://ia.cr/2026/2174
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2174,
      author = {Huaifeng Chen and Yuchang Zhang and Yu Cheng},
      title = {Blind Spots in Blind Signatures: A System-Level Security Analysis of Deployed Chaumian Ecash},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2174},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2174}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.