Tools/Explorers

Cashu vs Fedimint: Bitcoin Ecash Protocol Comparison

Compare Cashu and Fedimint ecash protocols for Bitcoin: privacy model, federation requirements, Lightning integration, and use cases.

Spark Team

Cashu vs Fedimint Overview

Cashu and Fedimint are both Chaumian ecash protocols built for Bitcoin, but they make fundamentally different architectural choices. Cashu uses a single-operator mint where one entity holds funds and issues blind signatures. Fedimint distributes custody across a federation of guardians using threshold signatures. Both protocols enable private Bitcoin transactions by converting on-chain or Lightning sats into bearer ecash tokens that can be transferred without revealing sender identity to the mint.

The choice between them depends on your trust model, deployment complexity tolerance, and whether you need single-operator simplicity or federated resilience. The following table summarizes the core differences.

FeatureCashuFedimint
Custody modelSingle mint operatorFederated guardians (t-of-n)
CryptographyBlind Diffie-Hellman Key ExchangeBDHKE + FROST threshold signatures
ConsensusNone (single operator)AlephBFT (asynchronous BFT)
Minimum operators14 (recommended)
Fault toleranceNone1 Byzantine fault per 4 guardians
Lightning integrationMint runs the Lightning nodeSeparate gateway (anyone can run)
Protocol specs31 NUTs (NUT-00 through NUT-30)Module-based SDK
Primary languageRust (CDK), Python (Nutshell)Rust
Active deployments33+ mints online (cashumints.space)11+ federations indexed
Token formatcashuB (CBOR-encoded, V4)Federation-internal notes

For a broader comparison across all ecash implementations on Bitcoin, see our Bitcoin ecash implementation comparison.

Privacy Guarantees

Both protocols derive privacy from David Chaum's ecash concept: the mint signs tokens without seeing their content, so it cannot link issuance to redemption. Cashu specifically uses Blind Diffie-Hellman Key Exchange (BDHKE), an elliptic-curve variant where the wallet creates a blinded message B_ = Y + rG, the mint signs it returning C_ = kB_, and the wallet unblinds to obtain C. Fedimint uses the same blinding scheme but adds FROST threshold signing so no single guardian sees the full signing key.

Sender privacy is strong in both systems: when tokens are redeemed, the mint verifies its own signature but cannot determine who originally received those tokens. Receiver privacy is weaker in both: when a user receives a Lightning payment through the mint or federation, the operator(s) can potentially identify the recipient and could censor incoming payments. Peer-to-peer offline token transfers preserve receiver privacy because the mint is not involved in the handoff.

Both protocols use fixed power-of-2 denominations (1, 2, 4, 8, 16, 32, 64 sats, and so on). A payment of 13 sats consists of tokens worth 8 + 4 + 1. The anonymity set for each denomination is bounded by the mint's or federation's usage volume: higher transaction throughput means more tokens of each denomination in circulation, making individual tokens harder to correlate.

Trust Assumptions

This is the defining difference between the two protocols. Cashu places full custodial trust in a single mint operator. That operator holds all deposited bitcoin and can theoretically abscond with funds, refuse redemptions, or selectively censor users. To partially mitigate this, Cashu's creator proposed a Proof of Liabilities scheme: the mint publishes all blind signatures issued and all spent secrets, with periodic keyset rotations creating auditable epochs. Users retain their blind signatures and can prove omission. However, the scheme is opt-in, requires active user monitoring, and cannot account for Lightning channel balances.

Fedimint distributes trust across a federation of guardians using a t-of-n FROST threshold signature scheme. In a typical 4-guardian setup with a 3-of-4 threshold, no single guardian or minority coalition can unilaterally move funds. The federation uses AlephBFT for asynchronous consensus: no leader election, no synchronized clocks, and the system halts gracefully if too many guardians disconnect (resuming when sufficient guardians return). The formula for Byzantine fault tolerance is 3m + 1: 4 guardians tolerate 1 fault, 7 tolerate 2, 10 tolerate 3.

The tradeoff is operational complexity. A Cashu mint can be deployed by a single developer in minutes. A Fedimint federation requires coordinating 4+ independent operators, running a setup ceremony to generate distributed keys, and ensuring all guardians maintain compatible software versions.

Lightning Gateway Architecture

Both protocols integrate with the Lightning Network for deposits, withdrawals, and interoperability, but the architecture differs significantly.

In Cashu, the mint itself operates the Lightning node. Deposits (minting) follow a two-phase flow: the wallet requests a quote, the mint returns a Lightning invoice, the user pays it, the wallet submits blinded messages, and the mint returns signed tokens. Withdrawals (melting) reverse the process: the wallet submits ecash proofs and a target Lightning invoice, the mint burns the proofs and pays the invoice. NUT-08 handles refunds for overpaid Lightning routing fees, and NUT-15 supports multipath payments. NUT-25 adds BOLT12 as a payment method.

In Fedimint, the Lightning gateway is a separate role decoupled from the guardians. Anyone can operate a gateway: it bridges between federation ecash and the broader Lightning Network using smart contracts for atomic payment completion. Multiple gateways can serve a single federation, providing redundancy and fee competition. As of v0.12.1 (September 2026), gateways include a forwarding-solvency check that tracks peak cumulative margin, warns at 2% drawdown, and refuses to start at 10%.

For more on how Lightning interacts with federated systems, see our Lightning vs Fedimint comparison.

Wallet and Developer Ecosystem

Cashu has a broader diversity of independent implementations. The Cashu Development Kit (CDK) is the primary Rust library, providing core protocol logic, storage backends (SQLite, PostgreSQL, Redb), an Axum-based HTTP server, and Lightning backends for CLN, LND, LNbits, and LDK Node. CDK also ships language bindings for Swift, Kotlin, Go, Flutter, and Python, all wrapping the same Rust core. The reference implementation, Nutshell, is written in Python. A Go mint implementation (Nutmix) also exists.

Cashu wallets include Cashu.me (web), eNuts (mobile), Minibits (mobile with Nostr-based identity), Nutstash (web with multi-mint support), and Macadamia (native iOS). All wallets can connect to any Cashu mint, and users can hold tokens across multiple mints simultaneously.

Fedimint is a unified Rust codebase. The fedimint-client library is available as a native module and via WebAssembly for browser and mobile integration. The module system includes fedimint-wallet (on-chain), fedimint-mint (ecash), and fedimint-ln (Lightning). V2 modules became the default in v0.12.0. The Fedi app is the primary user-facing application for joining and using Fedimint federations.

Setup and Deployment

RequirementCashuFedimint
Minimum operators14 (recommended)
Setup ceremonyNot requiredRequired (distributed key generation)
Lightning nodeOperator runs directlySeparate gateway (decoupled)
Module configurationN/A (monolithic)Must be agreed at setup, immutable after
Upgrade coordinationSingle operator decidesAll guardians must coordinate
Deployment timeMinutesHours (coordination overhead)
Ongoing operationsSingle server maintenanceMulti-party coordination

Real-World Deployments

Cashu has seen broader grassroots adoption due to its low deployment barrier. As of September 2026, cashumints.space indexes 58 total Cashu mints with 33 currently online, plus 604 Nostr-based reviews tracking mint reputation. Individual developers and small communities run Cashu mints for tipping, micropayments, and privacy-preserving transactions.

Fedimint deployments focus on community custody for established groups. Bitcoin Indonesia expanded its federation model to 15 communities in early 2026 for peer-to-peer transactions and circular merchant economies. Bitcoin Ekasi in South Africa has been running a township-based federation for over a year. In Kenya, Tando settles remittance flows over Fedi infrastructure bridging Lightning and M-PESA, and BitSacco reinvents traditional Kenyan SACCOs (savings cooperatives) using Fedimint. A seven-guardian federation running custom modules has been operating on Bitcoin mainnet with real funds since mid-2026.

For research on the broader ecash landscape, see our deep dive on ecash and Chaumian mints on Bitcoin and Fedimint federated ecash.

How Ecash Compares to Statechains

Both Cashu/Fedimint ecash and statechains offer off-chain Bitcoin transfers with privacy benefits, but the underlying models differ. Ecash is custodial: users deposit Bitcoin with a mint or federation and receive bearer tokens representing their balance. The mint holds the actual Bitcoin. Statechains transfer ownership of entire UTXOs off-chain by updating the signing authority from one party to the next, with a statechain entity that cooperatively signs but cannot unilaterally spend.

Spark uses a statechain-inspired model where users retain self-custodial control of their Bitcoin while gaining off-chain transfer capabilities and Lightning interoperability. This offers a middle ground: users do not sacrifice custody (as they do with ecash) but still get fast, private transfers. For users prioritizing self-custody and censorship resistance, a statechain approach avoids the custodial risk inherent in both Cashu and Fedimint.

For a detailed comparison of statechain architectures, see our statechains deep dive.

When to Choose Cashu vs Fedimint

Cashu is the right choice for individual developers, small-scale deployments, and use cases where speed of setup matters more than distributed trust. Running a personal mint for tipping, micropayments, or experimentation takes minutes. The diverse wallet ecosystem and multi-language SDK support make integration straightforward.

Fedimint is the right choice for communities, organizations, and platforms that can coordinate multiple independent guardians. Community banks, savings cooperatives, diaspora networks, and merchant groups benefit from distributed custody that no single party controls. The operational overhead is justified when the community has established trust relationships and real funds at stake.

Neither protocol is appropriate for users who require self-custody. Both are custodial systems where the user trusts the mint or federation to honor redemptions. Users who want off-chain Bitcoin transfers without surrendering custody should explore statechain-based solutions.

Frequently Asked Questions

Is Cashu ecash custodial?

Yes. When you deposit Bitcoin into a Cashu mint, the mint operator holds your funds and issues ecash tokens in return. These tokens are bearer instruments: whoever holds them can redeem them, but the mint must be online and willing to honor the redemption. The Proof of Liabilities scheme provides partial auditability but does not eliminate custodial risk.

How many guardians does a Fedimint federation need?

The recommended minimum is 4 guardians with a 3-of-4 signing threshold. This tolerates 1 Byzantine (malicious or offline) guardian. The formula is 3m + 1 guardians to tolerate m faults: 7 guardians tolerate 2 faults, 10 tolerate 3. Guardians should be independent parties who know and trust each other but do not share infrastructure.

Can Cashu and Fedimint tokens be used interchangeably?

No. Cashu tokens are specific to the mint that issued them, and Fedimint ecash notes are specific to their federation. There is no cross-mint or cross-federation token standard. Users can move value between systems by melting tokens on one side (converting to a Lightning payment) and minting on the other, but this requires a round-trip through the Lightning Network.

Which protocol has better privacy?

Both provide equivalent sender privacy through Chaumian blind signatures. The practical privacy difference comes from anonymity set size, which depends on usage volume rather than protocol design. A high-traffic Cashu mint may offer better privacy than a low-usage Fedimint federation, and vice versa. Receiver privacy is weaker in both systems when Lightning payments are involved.

What happens if a Cashu mint goes offline?

Your ecash tokens become unredeemable. Since the mint operator holds the underlying Bitcoin, tokens cannot be redeemed elsewhere. Cashu supports deterministic secret derivation (NUT-13) and signature restore (NUT-09) so that if the mint comes back online, wallets can recover tokens from a seed phrase. But if the mint permanently shuts down or the operator disappears, funds are lost.

Can I run a Cashu mint and a Fedimint federation simultaneously?

Yes. The protocols are independent and do not conflict. Some communities run a Cashu mint for lightweight, low-value transactions and a Fedimint federation for larger community savings. Wallets like Minibits can connect to multiple Cashu mints, and the Fedi app connects to Fedimint federations.

How does ecash compare to Spark for privacy?

Ecash protocols (Cashu and Fedimint) provide strong sender privacy but require custodial trust. Spark uses a statechain-based model where users maintain self-custody while getting off-chain transfer capabilities. For users who prioritize not trusting a third party with their Bitcoin, Spark offers privacy through its cooperative signing model without surrendering custody. The tradeoff is that ecash provides stronger unlinkability between transactions within the same mint.

This tool is for informational purposes only and does not constitute financial advice. Data is approximate and based on publicly available information as of September 2026. Protocol specifications and deployment counts change frequently. Always verify current data before making decisions.

Build with Spark

Integrate bitcoin, Lightning, and stablecoins into your app with a few lines of code.

Read the docs →