feat: Cashu ecash integration for offline ATM operation and fiat-stable vouchers #26

Open
opened 2026-06-13 22:02:51 +00:00 by padreug · 0 comments
Owner

Migrated from aiolabs/lamassu-next#26 — opened by @padreug on 2026-02-22.\n\n## Summary

Integrate Cashu ecash tokens to enable offline ATM cash dispensing and fiat-stable vouchers. Users complete a transaction on their phone (online), receive a USD-denominated Cashu token, then redeem it at the ATM via NFC tap or QR scan — even if the ATM has no internet connectivity.

Motivation

Currently the ATM requires live Lightning connectivity for every transaction. Cashu ecash solves two problems:

  1. Offline operation — The ATM can accept and verify tokens without contacting any server, enabling deployment in locations with poor or intermittent connectivity.
  2. Fiat-stable value — Cashu mints can denominate tokens in USD (cents), so a $100 voucher is always worth $100 regardless of Bitcoin price fluctuations. The mint operator bears the BTC/USD risk, not the customer.

How it works

Protocol support (confirmed)

The Cashu protocol has first-class support for all required features:

Feature NUT Spec Status
Multi-unit (USD, EUR, sat) NUT-00, NUT-02 Production-ready
USD minting/melting via Lightning NUT-04, NUT-05 Live (Strike backend)
Offline signature verification NUT-12 (DLEQ proofs) Implemented
Double-spend prevention (offline) NUT-11 (P2PK) Implemented
Binary token format for NFC NUT-00 V4 (CBOR) Production-ready

Proposed ATM flow

User (phone, online)          ATM (offline-capable)
─────────────────────         ────────────────────
1. Pay Lightning invoice
2. Receive USD Cashu token
   (e.g. $100 = 10000 cents)
3. Walk to ATM
4. Tap NFC / scan QR ──────> 5. Receive token
                              6. Verify DLEQ proof (offline)
                              7. Verify P2PK lock (offline)
                              8. Dispense $100 cash
                              9. Queue token for redemption
                                 (when back online)

Fiat stability mechanism

  • Mint operates with unit: "usd" keyset (amounts in cents, power-of-2 denominations)
  • Backend (e.g. Strike) converts BTC↔USD instantly at market rate
  • Outstanding tokens are backed by USD, not BTC — no price exposure for token holders
  • Mint operator bears exchange rate risk (mitigated by instant conversion or derivatives hedging)

Implementation areas

1. Self-hosted Cashu mint

  • Add a Cashu mint to the Docker stack (e.g. Nutshell or CDK/mintd)
  • Configure with unit: "usd" and Strike or LND backend
  • Expose mint URL for wallet connections

2. ATM token acceptance

  • Integrate cashu-ts (TypeScript Cashu library)
  • Accept tokens via NFC (V4 CBOR binary format) and QR scan
  • Verify DLEQ proofs and P2PK signatures offline
  • Queue accepted tokens for batch redemption when online

3. Mobile voucher flow

  • New "Buy Voucher" flow in the web UI
  • User pays Lightning → receives Cashu token
  • Token stored in phone wallet (Cashu.me, Minibits, etc.) or as QR/NFC

4. Deployment models

  • Managed: Operator runs the mint, location just operates the ATM hardware
  • Self-sovereign: Location runs their own mint with their own Strike/LND backend

Ecosystem references

> _Migrated from [aiolabs/lamassu-next#26](https://git.atitlan.io/aiolabs/lamassu-next/issues/26) — opened by @padreug on 2026-02-22._\n\n## Summary Integrate Cashu ecash tokens to enable offline ATM cash dispensing and fiat-stable vouchers. Users complete a transaction on their phone (online), receive a USD-denominated Cashu token, then redeem it at the ATM via NFC tap or QR scan — even if the ATM has no internet connectivity. ## Motivation Currently the ATM requires live Lightning connectivity for every transaction. Cashu ecash solves two problems: 1. **Offline operation** — The ATM can accept and verify tokens without contacting any server, enabling deployment in locations with poor or intermittent connectivity. 2. **Fiat-stable value** — Cashu mints can denominate tokens in USD (cents), so a $100 voucher is always worth $100 regardless of Bitcoin price fluctuations. The mint operator bears the BTC/USD risk, not the customer. ## How it works ### Protocol support (confirmed) The Cashu protocol has first-class support for all required features: | Feature | NUT Spec | Status | |---------|----------|--------| | Multi-unit (USD, EUR, sat) | [NUT-00](https://cashubtc.github.io/nuts/00/), [NUT-02](https://cashubtc.github.io/nuts/02/) | Production-ready | | USD minting/melting via Lightning | [NUT-04](https://cashubtc.github.io/nuts/04/), [NUT-05](https://cashubtc.github.io/nuts/05/) | Live (Strike backend) | | Offline signature verification | [NUT-12 (DLEQ proofs)](https://cashubtc.github.io/nuts/12/) | Implemented | | Double-spend prevention (offline) | [NUT-11 (P2PK)](https://cashubtc.github.io/nuts/11/) | Implemented | | Binary token format for NFC | NUT-00 V4 (CBOR) | Production-ready | ### Proposed ATM flow ``` User (phone, online) ATM (offline-capable) ───────────────────── ──────────────────── 1. Pay Lightning invoice 2. Receive USD Cashu token (e.g. $100 = 10000 cents) 3. Walk to ATM 4. Tap NFC / scan QR ──────> 5. Receive token 6. Verify DLEQ proof (offline) 7. Verify P2PK lock (offline) 8. Dispense $100 cash 9. Queue token for redemption (when back online) ``` ### Fiat stability mechanism - Mint operates with `unit: "usd"` keyset (amounts in cents, power-of-2 denominations) - Backend (e.g. Strike) converts BTC↔USD instantly at market rate - Outstanding tokens are backed by USD, not BTC — no price exposure for token holders - Mint operator bears exchange rate risk (mitigated by instant conversion or derivatives hedging) ## Implementation areas ### 1. Self-hosted Cashu mint - Add a Cashu mint to the Docker stack (e.g. [Nutshell](https://github.com/cashubtc/nutshell) or [CDK/mintd](https://github.com/cashubtc/cdk)) - Configure with `unit: "usd"` and Strike or LND backend - Expose mint URL for wallet connections ### 2. ATM token acceptance - Integrate [cashu-ts](https://github.com/cashubtc/cashu-ts) (TypeScript Cashu library) - Accept tokens via NFC (V4 CBOR binary format) and QR scan - Verify DLEQ proofs and P2PK signatures offline - Queue accepted tokens for batch redemption when online ### 3. Mobile voucher flow - New "Buy Voucher" flow in the web UI - User pays Lightning → receives Cashu token - Token stored in phone wallet (Cashu.me, Minibits, etc.) or as QR/NFC ### 4. Deployment models - **Managed**: Operator runs the mint, location just operates the ATM hardware - **Self-sovereign**: Location runs their own mint with their own Strike/LND backend ## Ecosystem references - [Cashu protocol](https://cashu.space/) — open-source Chaumian ecash for Bitcoin - [cashu-ts](https://github.com/cashubtc/cashu-ts) — TypeScript library for wallets - [Cashu.me](https://cashu.me) — browser wallet with NFC tap-to-pay - [Minibits](https://github.com/minibits-cash/minibits_wallet) — Android wallet with NFC HCE - [cashu-pos](https://github.com/niccolosalvato/cashu-pos) — NFC point-of-sale app - [Boardwalk Cash](https://github.com/MakePrisms/boardwalkcash) — USD-focused ecash wallet - [CDK v0.3.0](https://github.com/cashubtc/cdk/releases/tag/v0.3.0) — Strike API backend support - [Cashu highlights Q2/25](https://blog.cashu.space/cashu-highlights-q2-25/) — latest ecosystem progress
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aiolabs/bitspire#26
No description provided.