Skip to content

Releases: triplecN/CacheCoin

CacheCoin (CCCN) 0.2.1 for Windows

Choose a tag to compare

@triplecN triplecN released this 09 Oct 04:38

CacheCoin (CCCN) 0.2.1 for Windows

Published 2026-10-09. This is the eighth portable Windows package of CacheCoin:
cachecoind.exe and cachecoin-cli.exe from the tagged tree, the PowerShell
launcher, the window (CacheCoin.exe), the documentation and the pinned Tor
Expert Bundle.

The binaries are unsigned and this build is not reproducible. Read the whole
note before running.

Why 0.2.1 exists

A minor packaging fix. The two node executables in this ZIP are the ones CI
built; they carry the project's product name and icon in their Windows version
resources, and the CI job now fails if that metadata is missing. The 0.2.0 ZIP
was assembled from a locally built set where that step had not run, and its
PROVENANCE.txt described the package as if it had. Source, patch fingerprint and
consensus behavior are unchanged.

0.2.0 is frozen as published.

Files

  • CacheCoin-Windows-0.2.1.zip
    sha256: 4cd664b9bcb6ca0319e8bdf895e93815f74508d6bd69d6260afdf0cd5e7ee1f7
  • SHA256SUMS.windows.txt (sha256 of every file in the package)
  • SHA256SUMS.windows.txt.asc (detached GPG signature of the checksum file)
  • raw executables for direct hashing: cachecoind.exe
    7f933882ee632c09347dd5bede51c9251c1976e3868a9df754329db4f9265200,
    cachecoin-cli.exe
    8cb5098b9f65736025357a7dc408e0a058dba027321c763f4ef4448084da725b,
    CacheCoin.exe
    68e1f30d742bd55e4bbf0c52fb648c771cba1d54ffb371d5e92ace1cd0d30267
  • PROVENANCE.txt, TOR-PIN.txt (also inside the package)

Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).

Provenance

  • Base pins: Bitcoin Core v31.1, commit
    9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
    7607fb2faed24d5a679e139a9828d194bbc644a4.
  • Patch fingerprint: 6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
    (cat patches/*.patch | sha256sum). Compare it with doc/verification.md.
  • The release tag windows-0.2.1 is a signed Git tag; verify it with
    git tag -v windows-0.2.1 after importing release-key.asc. Commit
    ca67356 (full hash on the tag page).
  • Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
    version.json; TOR-PIN.txt carries the archive, its sha256 and the key.

Verify before running

Get-FileHash CacheCoin-Windows-0.2.1.zip -Algorithm SHA256

Unpack it, then:

gpg --import release-key.asc          # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txt

The gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.
Verify Download.cmd performs the same three checks in one step.

What this is

A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Start Node.cmd runs the node; Start Mining.cmd runs node + CPU miner + peer;
CacheCoin App.cmd opens the window; Check Status.cmd reports height, peers
and disk (needs a running node); Create New Wallet.cmd makes a wallet offline.
New users should read README-Windows.txt and docs\START_HERE.txt. Mining
also accepts incoming Tor connections (default cap: 32 connections, about 5 GB
uploaded per day). There is no daemon mode.

Version strings: the package is 0.2.1; the node executables report the upstream
31.1.0; the window reports 0.2.0 because it did not change in this release.

Honest limits

  • Not reproducible. The sha256 values prove only that the files arrived
    unchanged in transit; the GPG signature proves the checksum file came from the
    CacheCoin release key. Nobody can yet rebuild the exact bytes; compare the
    patch fingerprint, not the binary hash, when you rebuild.
  • The executables are unsigned at the OS level (no Authenticode).
  • SmartScreen. Windows will show "Windows protected your PC" on first
    launch; choose More info, then Run anyway, after checking the sha256.
  • Outside the suites. The Windows .exe files are not covered by the
    repository's automated test suites. CI starts the node in regtest, verifies
    the genesis, mines one block and runs the wallet flow with a clean PATH.
  • Integrity check scope. The fail-closed check covers a swapped file inside
    a genuine package. It cannot cover a fully forged package that also replaces
    version.json; only the ZIP hash and the GPG signature catch that. The
    remaining accepted limits are listed in SECURITY.md, section "The Windows
    package"; the file-hash check cannot see a TOCTOU swap or an alternate data
    stream.
  • No daemon mode. cachecoind -daemon does not exist on Windows (MinGW has
    no fork()); run it in a window or under Task Scheduler. cachecoin-cli -rpcwait still works.
  • Mining is a lottery. Expect weeks without a block; it may never pay. The
    PER ticket system shares fees only when fees exist. Mining costs electricity
    whether or not it pays, and mining publishes this computer's .onion address.
  • No financial advice. This is open-source software provided as is under the
    MIT license; nothing here is financial advice, an offer or a promise of return.

CacheCoin (CCCN) 0.2.0 for Windows

Choose a tag to compare

@triplecN triplecN released this 09 Oct 02:50

CacheCoin (CCCN) 0.2.0 for Windows

Frozen. Superseded by windows-0.2.1: a minor packaging fix. Kept for the record; do not use it for new installs.

Published 2026-10-09. This is the seventh portable Windows package of CacheCoin:
cachecoind.exe and cachecoin-cli.exe from the tagged tree, the PowerShell
launcher, the window (CacheCoin.exe), the documentation and the pinned Tor
Expert Bundle.

The binaries are unsigned and this build is not reproducible. Read the whole
note before running.

Why 0.2.0 exists

0.1.x shipped dynamically linked executables and a copy step that collected the
MinGW/library DLLs (libsqlite3-0.dll among them) next to them; it recorded no
Tor pin inside the repository; and it gave the user no single command to check a
package's provenance. Three fixes, one release:

  • the node links SQLite, Boost, libevent and the MinGW runtime statically, so
    the package ships no third-party DLL at all, and CI fails if any dependency
    becomes dynamic again;
  • the Tor Expert Bundle is pinned (archive sha256 and signing key in the repo)
    and windows/verify_tor_bundle.sh checks every bundled file against it;
  • every packaged file is identified in PROVENANCE.txt, and
    Verify Download.cmd checks a package in one step.

The consensus source is unchanged (same patch fingerprint as 0.1.5).

0.1.5 is frozen as published; the static link, the Tor pin and the provenance
ship as 0.2.0.

What changed in 0.2.0

  • Static runtime. objdump -p on the built executables lists only Windows
    system DLLs. CI asserts this before packaging: an import that exists in
    /mingw64/bin fails the job. The package contains no *.dll.
  • Sanitized executables. Built with -ffile-prefix-map/-fmacro-prefix-map
    (no absolute build paths in strings), -Wl,-s (no DWARF) and
    -Wl,--no-insert-timestamp (PE header time 1970-01-01).
  • Clean-environment test. CI runs the packaged folder with the MSYS2 PATH
    removed, creates a wallet and mines a regtest block: the only check that
    proves the folder works on a machine that never had MSYS2.
  • Tor pin. Expert Bundle 15.0.24 (tor 0.4.9.13), archive
    tor-expert-bundle-windows-x86_64-15.0.24.tar.gz, sha256
    e9dc6ccc93cd6afa507193f4de284d6424233ff5102155cd2c94b259e8a22b65, signed by
    Tor Browser Developers (key EF6E286DDA85EA2A4BA7DE684E2C6E8793298290).
    windows/verify_tor_bundle.sh checks the archive sha256 and compares every
    file with it in both directions (missing, mismatched and extra files fail).
    tor/** matches the archive byte for byte.
  • Provenance. PROVENANCE.txt says where every file came from, its license
    where documented, and the remaining gaps; version.json lists the version,
    the pins, the patch fingerprint and the sha256 of all 53 packaged files.
  • Verify Download.cmd (tools/CacheCoin-Verify.ps1): checks version.json,
    every file hash and the checksum list, and the GPG signature when Gpg4win is
    installed and SHA256SUMS.windows.txt.asc is next to the ZIP or one folder
    above. When it cannot check the signature it says so instead of claiming
    authenticity.
  • Wallet tools. My Keys and Backup.cmd is replaced by
    Create New Wallet.cmd (offline key/address maker; the old key editor is
    removed). The CacheCoin.cmd shim is removed and the entry points call
    launcher\CacheCoin.ps1 directly, propagating its exit code.
  • Window. Built with --gui-dir: CacheCoin.exe and CacheCoin App.cmd
    are inside version.json and the checksums. The window build is
    deterministic (two build_det.ps1 runs produced the same bytes).
  • Docs. README-Windows.txt (plain-language file guide), WHY_TOR.md,
    twelve license texts, updated doc/build-windows.md and
    doc/verification.md; SECURITY.md gains "The Windows package" with the
    accepted limits of the launcher's enforcement.

Files

  • CacheCoin-Windows-0.2.0.zip
    sha256: ce2002f343410e21b33d411853d37e843b6950325bee84dbb60b723dc91d6543
  • SHA256SUMS.windows.txt (sha256 of every file in the package)
  • SHA256SUMS.windows.txt.asc (detached GPG signature of the checksum file)
  • raw executables for direct hashing: cachecoind.exe
    ed5d5a8c6a54128e761b0ba92df157f7ca3b2f4670843dc9ed3f719a99dc0418,
    cachecoin-cli.exe
    1621a9623fa3e866505a6fd4afb0a9a27146c1dfeffa4b3f48544a7773787fb6,
    CacheCoin.exe
    68e1f30d742bd55e4bbf0c52fb648c771cba1d54ffb371d5e92ace1cd0d30267
  • PROVENANCE.txt, TOR-PIN.txt (also inside the package)

Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).

Provenance

  • Base pins: Bitcoin Core v31.1, commit
    9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
    7607fb2faed24d5a679e139a9828d194bbc644a4.
  • Patch fingerprint: 6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
    (cat patches/*.patch | sha256sum). Compare it with doc/verification.md.
  • The release tag windows-0.2.0 is a signed Git tag; verify it with
    git tag -v windows-0.2.0 after importing release-key.asc. Commit
    a29c212 (full hash on the tag page).
  • Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
    version.json; TOR-PIN.txt carries the archive, its sha256 and the key.

Verify before running

Get-FileHash CacheCoin-Windows-0.2.0.zip -Algorithm SHA256

Unpack it, then:

gpg --import release-key.asc          # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txt

The gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.
Verify Download.cmd performs the same three checks in one step.

What this is

A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Start Node.cmd runs the node; Start Mining.cmd runs node + CPU miner + peer;
CacheCoin App.cmd opens the window; Check Status.cmd reports height, peers
and disk (needs a running node); Create New Wallet.cmd makes a wallet offline.
New users should read README-Windows.txt and docs\START_HERE.txt. Mining
also accepts incoming Tor connections (default cap: 32 connections, about 5 GB
uploaded per day). There is no daemon mode.

Honest limits

  • Not reproducible. The sha256 values prove only that the files arrived
    unchanged in transit; the GPG signature proves the checksum file came from the
    CacheCoin release key. Nobody can yet rebuild the exact bytes; compare the
    patch fingerprint, not the binary hash, when you rebuild.
  • The executables are unsigned at the OS level (no Authenticode).
  • SmartScreen. Windows will show "Windows protected your PC" on first
    launch; choose More info, then Run anyway, after checking the sha256.
  • Outside the suites. The Windows .exe files are not covered by the
    repository's automated test suites. CI starts the node in regtest, verifies
    the genesis and mines one block; the packaged tree was also deep-tested
    (encrypt, unlock, backup, restore with rescan, then mining on the restored
    wallet).
  • Integrity check scope. The fail-closed check covers a swapped file inside
    a genuine package. It cannot cover a fully forged package that also replaces
    version.json; only the ZIP hash and the GPG signature catch that. The
    remaining accepted limits are listed in SECURITY.md, section "The Windows
    package"; the file-hash check cannot see a TOCTOU swap or an alternate data
    stream.
  • No daemon mode. cachecoind -daemon does not exist on Windows (MinGW has
    no fork()); run it in a window or under Task Scheduler. cachecoin-cli -rpcwait still works.
  • Mining is a lottery. Expect weeks without a block; it may never pay. The
    PER ticket system shares fees only when fees exist. Mining costs electricity
    whether or not it pays, and mining publishes this computer's .onion address.
  • No financial advice. This is open-source software provided as is under the
    MIT license; nothing here is financial advice, an offer or a promise of return.

CacheCoin (CCCN) 0.1.5 for Windows

Choose a tag to compare

@triplecN triplecN released this 04 Oct 14:19

CacheCoin (CCCN) 0.1.5 for Windows

Frozen. Superseded by windows-0.2.0: statically linked executables, a pinned and verified Tor bundle, PROVENANCE.txt and Verify Download.cmd. This page is kept for the record; do not use it for new installs.

This is the sixth portable Windows package of CacheCoin: cachecoind.exe and
cachecoin-cli.exe from the tagged tree, the PowerShell launcher, the
documentation and a bundled Tor Expert Bundle.

The binaries are unsigned and this build is not reproducible. Read the whole
note before running.

Why 0.1.5 exists

0.1.4 added My Keys and Backup.cmd and Check Status.cmd. Those tools used
bin\cachecoin-cli.exe directly but did not verify the package the way the
launcher does. A tampered package (a swapped cachecoin-cli.exe, for example)
could therefore read wallet keys if the user ran the keys tool without ever
starting the launcher first. 0.1.5 closes that gap before the next audit round.

The node itself is unchanged (same patch fingerprint).

What changed in 0.1.5

  • New shared helper tools\CacheCoin-Package.ps1. Both tools now verify
    version.json fail-closed before doing anything:
    • it must exist and be readable;
    • it must list the programs, the launcher and the tools themselves;
    • every listed program, launcher or tool file must be present and match its
      sha256. A mismatch stops the tool with a clear message and tells the user
      to download the package again and check docs\VERIFY.txt.
  • docs\VERIFY.txt now documents the stronger check and its honest limit: a
    fully forged package that also replaces version.json is not caught by this
    check. The trust anchor remains the ZIP hash and the GPG signature that the
    user verifies themselves.
  • version.json now covers 35 files in this build (the helper is hashed too).

Tests on this build: backup files and sha256 output; key display behind the
typed phrase; wrong-phrase refusal; a tampered cachecoin-cli.exe is refused
with no keys shown and no node started; the restored package passes again.

0.1.4 is frozen as published; the hardening ships as 0.1.5.

Files

  • CacheCoin-Windows-0.1.5.zip
    sha256: 7c1de68e1ff44a7c0f9941c97650e28f5927f410dee96b4fde7d973ca388d23f
  • SHA256SUMS.windows.txt (sha256 of every file in the package)
  • SHA256SUMS.windows.txt.asc (detached GPG signature of the checksum file)
  • version.json (inside the package: pins, patch fingerprint, per-file sha256)

Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).

Provenance

  • Base pins: Bitcoin Core v31.1, commit
    9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
    7607fb2faed24d5a679e139a9828d194bbc644a4.
  • Patch fingerprint: 6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
    (cat patches/*.patch | sha256sum). Compare it with doc/verification.md.
  • The release tag windows-0.1.5 is a signed Git tag; verify it with
    git tag -v windows-0.1.5 after importing release-key.asc.
  • Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
    version.json. The bundle's sha256 was checked against the Tor Project's
    published sha256sums-signed-build.txt.

Verify before running

Get-FileHash CacheCoin-Windows-0.1.5.zip -Algorithm SHA256

Unpack it, then:

gpg --import release-key.asc          # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txt

The gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.

What this is

A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Double-click Start Node.cmd to begin. New users should read
docs\BEGINNER_GUIDE.md. There is no GUI and no daemon mode.

Honest limits

  • Not reproducible. The sha256 values prove only that the files arrived
    unchanged in transit; the GPG signature proves the checksum file came from
    the CacheCoin release key. Nobody can yet rebuild the exact bytes.
  • The executables are unsigned at the OS level (no Authenticode).
  • SmartScreen. Windows will show "Windows protected your PC" on first launch;
    choose More info, then Run anyway, after checking the sha256.
  • Outside the suites. The Windows .exe files are not covered by the
    repository's automated test suites. CI starts the node in regtest, verifies
    the genesis and mines one block; on this package the node was also run against
    mainnet, synced to the live tip and connected to a peer over Tor. The entry
    points and tools were exercised on a clean sandbox, including a tampered
    cachecoin-cli.exe being refused.
  • Integrity check scope. The tools' fail-closed check covers a swapped file
    inside a genuine package. It cannot cover a fully forged package that also
    replaces version.json; only the ZIP hash and the GPG signature catch that.
  • No daemon mode. cachecoind -daemon does not exist on Windows (MinGW has
    no fork()); run it in a window or under Task Scheduler.
  • Mining is a lottery. Expect weeks without a block; it may never pay. The
    PER ticket system shares fees only when fees exist. Mining costs electricity
    whether or not it pays.
  • No financial advice. This is open-source software provided as is under the
    MIT license; nothing here is financial advice, an offer or a promise of return.

CacheCoin (CCCN) 0.1.4 for Windows

Choose a tag to compare

@triplecN triplecN released this 04 Oct 13:42

CacheCoin (CCCN) 0.1.4 for Windows

This is the fifth portable Windows package of CacheCoin: cachecoind.exe and
cachecoin-cli.exe from the tagged tree, the PowerShell launcher, the
documentation and a bundled Tor Expert Bundle.

The binaries are unsigned and this build is not reproducible. Read the whole
note before running.

Why 0.1.4 exists

0.1.3 was correct but not simple enough for people who do not program. A new
user had to know which mode to choose and how to run PowerShell commands for a
backup or for their private keys. 0.1.4 adds plain double-click entry points and
a guided keys tool. The node itself is unchanged (same patch fingerprint).

What is new in 0.1.4

Four double-click files now sit next to CacheCoin.cmd (which still works):

  • Start Node.cmd - run the node only. Safe default; no mining, low CPU.
  • Start Mining.cmd - run the node and mine. The wallet is created
    automatically with a modern SegWit address (cccn1q...); nothing has to be
    typed. Mining still waits for a saved and confirmed backup first.
  • My Keys and Backup.cmd - the guided tool:
    • Option 1 (recommended): saves cachecoin-main-wallet-<date>.bak and
      cachecoin-main-descriptors-<date>.json to a folder or USB stick and
      prints their sha256 values. Warns if the folder syncs to a cloud.
    • Option 2 (advanced): shows your private keys only after you type a
      confirmation phrase, after asking you to turn the internet off. The keys
      are never written to a log file, and the screen is cleared when you are
      done.
    • It never generates a separate key: it exports the keys of your existing
      wallet. A standalone key that is not part of the wallet would be easy to
      lose and would not hold the coins that the wallet holds.
  • Check Status.cmd - shows block, peers and balance without remembering
    commands.

Under the hood: the package builder now ships tools\ and all entry-point
.cmd files, version.json covers them (34 files in this build), and
docs\BEGINNER_GUIDE.md and docs\START_HERE.txt describe the new files.

What deliberately did not change: mining never pays to an address the user
types (a typo would burn the reward), and there is no separate "create a key"
step (the wallet already has keys; the backup files are the key material).

0.1.3 is frozen as published; the UX work ships as 0.1.4.

Files

  • CacheCoin-Windows-0.1.4.zip
    sha256: aa4693f74955254a3dcc55cd03260ae56b69c320793d74838c577c4e7e71252c
  • SHA256SUMS.windows.txt (sha256 of every file in the package)
  • SHA256SUMS.windows.txt.asc (detached GPG signature of the checksum file)
  • version.json (inside the package: pins, patch fingerprint, per-file sha256)

Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).

Provenance

  • Base pins: Bitcoin Core v31.1, commit
    9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
    7607fb2faed24d5a679e139a9828d194bbc644a4.
  • Patch fingerprint: 6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
    (cat patches/*.patch | sha256sum). Compare it with doc/verification.md.
  • The release tag windows-0.1.4 is a signed Git tag; verify it with
    git tag -v windows-0.1.4 after importing release-key.asc.
  • Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
    version.json. The bundle's sha256 was checked against the Tor Project's
    published sha256sums-signed-build.txt.

Verify before running

Get-FileHash CacheCoin-Windows-0.1.4.zip -Algorithm SHA256

Unpack it, then:

gpg --import release-key.asc          # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txt

The gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.

What this is

A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Double-click Start Node.cmd to begin. New users should read
docs\BEGINNER_GUIDE.md. There is no GUI and no daemon mode.

Honest limits

  • Not reproducible. The sha256 values prove only that the files arrived
    unchanged in transit; the GPG signature proves the checksum file came from
    the CacheCoin release key. Nobody can yet rebuild the exact bytes.
  • The executables are unsigned at the OS level (no Authenticode).
  • SmartScreen. Windows will show "Windows protected your PC" on first launch;
    choose More info, then Run anyway, after checking the sha256.
  • Outside the suites. The Windows .exe files are not covered by the
    repository's automated test suites. CI starts the node in regtest, verifies
    the genesis and mines one block; on this package the node was also run against
    mainnet, synced to the live tip and connected to a peer over Tor. The new
    .cmd entry points and the keys tool were exercised on a clean sandbox:
    backup files, key display behind the typed phrase, wrong-phrase refusal, and
    the status output.
  • No daemon mode. cachecoind -daemon does not exist on Windows (MinGW has
    no fork()); run it in a window or under Task Scheduler.
  • Mining is a lottery. Expect weeks without a block; it may never pay. The
    PER ticket system shares fees only when fees exist. Mining costs electricity
    whether or not it pays.
  • No financial advice. This is open-source software provided as is under the
    MIT license; nothing here is financial advice, an offer or a promise of return.

CacheCoin (CCCN) 0.1.3 for Windows

Choose a tag to compare

@triplecN triplecN released this 04 Oct 13:11

CacheCoin (CCCN) 0.1.3 for Windows

This is the fourth portable Windows package of CacheCoin: cachecoind.exe and
cachecoin-cli.exe from the tagged tree, the PowerShell launcher, the
documentation and a bundled Tor Expert Bundle.

The binaries are unsigned and this build is not reproducible. Read the whole
note before running.

Why 0.1.3 exists

A third audit round on 0.1.2 found no High issue, but it confirmed one Medium
availability problem and two documentation mistakes:

  • A single peer's clock could pause mining for every Windows miner. The
    launcher paused mining when peers reported that the local clock was ahead by
    more than 5 minutes, and the chain tip was older than 5 minutes. On this
    chain the tip is often older than that, so one peer with a slow clock (for
    example a seed without NTP, or a malicious peer) could stop all launcher
    miners - exactly when the chain most needs them. Verified in regtest with the
    real binaries: one peer at -1 hour produced timeoffset=-3605,
    MiningGated=True.
  • BACKUP.txt step 2 used ren "%APPDATA%\...", which does not work in
    PowerShell, and step 6 promised that mining resumes after a restore, while the
    saved mode stays node and mining does not start.
  • 0.1.2 is frozen as published; these fixes ship as 0.1.3.

The consensus patch series did not change: its fingerprint is the same in every
build (6a89aa14..., see Provenance). Nothing in this release changes the node.

What changed in 0.1.3

  • Clock differences are now warnings only. Mining no longer pauses because
    of a clock disagreement, in either direction. Why this is safe:
    Bitcoin Core adjusts time by the median peer offset, and a block found with a
    genuinely wrong clock is simply rejected by the network - only the reward is
    lost, never funds. The real gates remain: node not answering, still syncing,
    or zero peers. The launcher logs one clear warning per run and tells the user
    to fix Windows time if it is wrong.
  • BACKUP.txt is now PowerShell-only and tested as written:
    • step 2: Rename-Item "$env:APPDATA\CacheCoin\wallets" wallets.old
    • step 6: CacheCoin.cmd -Mode mining (the saved mode is restored to mining
      by that one start; after that a normal double-click mines again)
  • New docs/BEGINNER_GUIDE.md, a step-by-step English guide for people who do
    not code. It covers: node-only vs mining mode; how the wallet creates its own
    modern SegWit address (cccn1q...) so nothing has to be typed; the mandatory
    backup before mining with hard warnings to keep the files offline or on a USB
    stick; how to print private keys (listdescriptors true) with the same
    warnings; how to stop the node; and how to check status, including the
    optional local block explorer at http://127.0.0.1:8080 (the repository's
    explorer/app.py, which needs Python 3 and is not bundled in the ZIP).
  • docs/START_HERE.txt now points to the beginner guide first.

Deliberately not changed (Low findings from the same audit, deferred to avoid
launcher churn): a repeated "custom bind" warning for the launcher's own lines;
listen=1 # comment parsing; the saved backup-confirmation state after a
transient listdescriptors failure; CI diagnostic collection for nine suites;
two cosmetic phrases in BACKUP.txt. None of these touch funds or consensus.

Files

  • CacheCoin-Windows-0.1.3.zip
    sha256: 634fe000f393aa7c8bbd1cd4d96c84702e25db942612cb525c75fb10e80443e2
  • SHA256SUMS.windows.txt (sha256 of every file in the package)
  • SHA256SUMS.windows.txt.asc (detached GPG signature of the checksum file)
  • version.json (inside the package: pins, patch fingerprint, per-file sha256)

Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).

Provenance

  • Base pins: Bitcoin Core v31.1, commit
    9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
    7607fb2faed24d5a679e139a9828d194bbc644a4.
  • Patch fingerprint: 6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
    (cat patches/*.patch | sha256sum). Compare it with doc/verification.md.
  • The release tag windows-0.1.3 is a signed Git tag; verify it with
    git tag -v windows-0.1.3 after importing release-key.asc.
  • Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
    version.json. The bundle's sha256 was checked against the Tor Project's
    published sha256sums-signed-build.txt.

Verify before running

Get-FileHash CacheCoin-Windows-0.1.3.zip -Algorithm SHA256

Unpack it, then:

gpg --import release-key.asc          # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txt

The gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.

What this is

A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Double-click CacheCoin.cmd to start. New users should read
docs\BEGINNER_GUIDE.md. There is no GUI and no daemon mode.

Honest limits

  • Not reproducible. The sha256 values prove only that the files arrived
    unchanged in transit; the GPG signature proves the checksum file came from
    the CacheCoin release key. Nobody can yet rebuild the exact bytes.
  • The executables are unsigned at the OS level (no Authenticode).
  • SmartScreen. Windows will show "Windows protected your PC" on first launch;
    choose More info, then Run anyway, after checking the sha256.
  • Outside the suites. The Windows .exe files are not covered by the
    repository's automated test suites. CI starts the node in regtest, verifies
    the genesis and mines one block; on this package the node was also run against
    mainnet, synced to the live tip and connected to a peer over Tor.
  • No daemon mode. cachecoind -daemon does not exist on Windows (MinGW has
    no fork()); run it in a window or under Task Scheduler.
  • Mining is a lottery. Expect weeks without a block; it may never pay. The
    PER ticket system shares fees only when fees exist. Mining costs electricity
    whether or not it pays.
  • No financial advice. This is open-source software provided as is under the
    MIT license; nothing here is financial advice, an offer or a promise of return.

CacheCoin (CCCN) 0.1.2 for Windows

Choose a tag to compare

@triplecN triplecN released this 04 Oct 12:15

CacheCoin (CCCN) 0.1.2 for Windows

This is the third portable Windows package of CacheCoin: cachecoind.exe and
cachecoin-cli.exe from the tagged tree, the PowerShell launcher, the
documentation and a bundled Tor Expert Bundle.

The binaries are unsigned and this build is not reproducible. Read the whole
note before running.

Why 0.1.2 exists

0.1.1 was audited again after publication and one High bug was found and
reproduced in the launcher:

  • -Stop could restart the node instead of stopping it. In Windows
    PowerShell 5.1, a process started with redirected output can report a null
    ExitCode. The supervisor read "null exit code" as a crash and restarted the
    node, so a stop request turned into a restart loop. This only affects how the
    launcher stops; it cannot affect consensus, balances or mining.

The launcher fix has two parts: the process handle is now cached so a clean exit
reads as exit code 0, and -Stop writes a stop marker that the running launcher
consumes and exits on, with the marker removed on every path. The fix was tested
end-to-end on the packaged binaries: node-only start, -Stop, node and launcher
exit, no restart, launcher exit code 0.

0.1.1 is frozen as published; the fix ships as 0.1.2 instead of rewriting it.

The consensus patch series did not change: its fingerprint is the same in every
build (6a89aa14..., see Provenance). Nothing in this release changes the node.

What changed in 0.1.2

  • -Stop no longer restarts the node (the High bug above); the launcher also
    exits correctly when the node stops by itself with a clean exit code.
  • An existing cachecoin.conf that enables listening (listen=1 or
    listenonion=1, e.g. written by an older launcher) is now enforced with
    loopback-only bind= lines and a torcontrol= setting on every start, not
    only on first install. A custom bind= line is kept and warned about.
  • The mining clock gate is corroborated with the chain: mining pauses only when
    peers report the local clock ahead and the tip is older than 5 minutes.
    A single peer can no longer pause mining. A peers-report-behind case is a
    warning, not a pause.
  • The wallet descriptor list is retried once; if it still does not answer while
    mining, the backup confirmation is dropped and mining stays paused instead of
    proceeding on an unverified wallet.
  • node-out.log no longer grows: the node runs with -printtoconsole=0.
    Errors still land in node-err.log and are shown in the launcher log.
  • The autostart task check no longer uses wildcard matching, so package paths
    containing [ or ] do not cause a re-register loop.
  • The cloud-folder warning also covers My Drive (Google Drive for desktop).
  • BACKUP.txt has a corrected, tested restore procedure (node-only mode first,
    createwallet before importdescriptors, UTF-8 output encoding).
  • CI only: the test suites reserve the fixed ports they use (29333/29334 and
    39xxx) against ephemeral-port collisions, print node diagnostics on a failed
    start, and wait for the Tor peer handshake before the Shunko rotation check.
    These are test/build changes and are not part of the shipped binaries.

Files

  • CacheCoin-Windows-0.1.2.zip
    sha256: 90ecf2df8fdb131e0f189de19303b12fc5b30c58d176c276ad8be0d9a715ae9d
  • SHA256SUMS.windows.txt (sha256 of every file in the package)
  • SHA256SUMS.windows.txt.asc (detached GPG signature of the checksum file)
  • version.json (inside the package: pins, patch fingerprint, per-file sha256)

Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).

Provenance

  • Base pins: Bitcoin Core v31.1, commit
    9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
    7607fb2faed24d5a679e139a9828d194bbc644a4.
  • Patch fingerprint: 6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
    (cat patches/*.patch | sha256sum). Compare it with doc/verification.md.
  • The release tag windows-0.1.2 is a signed Git tag; verify it with
    git tag -v windows-0.1.2 after importing release-key.asc.
  • Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
    version.json. The bundle's sha256 was checked against the Tor Project's
    published sha256sums-signed-build.txt.

Verify before running

Get-FileHash CacheCoin-Windows-0.1.2.zip -Algorithm SHA256

Unpack it, then:

gpg --import release-key.asc          # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txt

The gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.

What this is

A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Double-click CacheCoin.cmd to start. There is no GUI and no daemon mode.

Honest limits

  • Not reproducible. The sha256 values prove only that the files arrived
    unchanged in transit; the GPG signature proves the checksum file came from
    the CacheCoin release key. Nobody can yet rebuild the exact bytes.
  • The executables are unsigned at the OS level (no Authenticode).
  • SmartScreen. Windows will show "Windows protected your PC" on first launch;
    choose More info, then Run anyway, after checking the sha256.
  • Outside the suites. The Windows .exe files are not covered by the
    repository's automated test suites. CI starts the node in regtest, verifies
    the genesis and mines one block; on this package the node was also run against
    mainnet, synced to the live tip and connected to a peer over Tor.
  • No daemon mode. cachecoind -daemon does not exist on Windows (MinGW has
    no fork()); run it in a window or under Task Scheduler.
  • Mining is a lottery. Expect weeks without a block; it may never pay. The
    PER ticket system shares fees only when fees exist. Mining costs electricity
    whether or not it pays.
  • No financial advice. This is open-source software provided as is under the
    MIT license; nothing here is financial advice, an offer or a promise of return.

CacheCoin (CCCN) 0.1.1 for Windows

Choose a tag to compare

@triplecN triplecN released this 04 Oct 10:13

CacheCoin (CCCN) 0.1.1 for Windows

This is the second portable Windows package of CacheCoin: cachecoind.exe and
cachecoin-cli.exe from the tagged tree, the PowerShell launcher, the
documentation and a bundled Tor Expert Bundle.

The binaries are unsigned and this build is not reproducible. Read the whole
note before running.

Version history (why 0.1.1 exists)

0.1.0 was the first Windows package. While it was being hardened on its first
day it was rebuilt and re-uploaded several times: the first build had a launcher
bug that broke the normal double-click start, and later rounds fixed the wallet
backup check, the mining gate, process cleanup and the configuration rewrite.
Each time, the signed tag was moved to the corrected commit so that the tag, the
source and the ZIP stayed consistent. That is why an early 0.1.0 download can
have a different ZIP hash than the final one.

Rewriting the files of a published version is bad practice: two people who both
downloaded "0.1.0" can hold different bytes and have no way to tell. So that
stops here. 0.1.0 is frozen as published; 0.1.1 is the same code as the final
0.1.0 build (commit 025c328), published under a new number instead of
rewriting 0.1.0 again. If your 0.1.0 ZIP matches the hash on the 0.1.0 release
page, you already have this build and 0.1.1 changes nothing functional for you.

The consensus patch series did not change at any point: its fingerprint is the
same in every build (6a89aa14..., see Provenance). What changed during 0.1.0
was the Windows launcher and the package around it, not the node.

What changed from the first 0.1.0 build

  • The launcher starts correctly on a normal double-click.
  • The wallet identity check hashes stable descriptor strings, so the backup
    confirmation survives address generation and mining; a replaced wallet still
    invalidates the old confirmation.
  • The mining gate no longer mistakes an old-but-synced tip for a sync in
    progress, and it pauses when the clock is off.
  • The opt-in "help other nodes connect" setting binds only to loopback.
  • The logon task re-registers when the package folder moves, and -EnableAutostart
    / -DisableAutostart manage it directly.
  • Config rewriting understands [sections], UTF-16 and BOM files, and never
    duplicates keys.
  • BACKUP.txt now includes a restore procedure that was tested
    (restorewallet, and importdescriptors with the .descriptors array).
  • version.json must list the program files before the launcher trusts it.

An adversarial audit of the consensus patch series found no inflation, split or
balance-theft path; the accepted findings are recorded in
doc/consensus-audit-notes.md.

Files

  • CacheCoin-Windows-0.1.1.zip
    sha256: 080ea0491a87df0bc855573afcf950320b215ac7be2371e54ff6d5ec6694819c
  • SHA256SUMS.windows.txt (sha256 of every file in the package)
  • SHA256SUMS.windows.txt.asc (detached GPG signature of the checksum file)
  • version.json (inside the package: pins, patch fingerprint, per-file sha256)

Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).

Provenance

  • Base pins: Bitcoin Core v31.1, commit
    9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
    7607fb2faed24d5a679e139a9828d194bbc644a4.
  • Patch fingerprint: 6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
    (cat patches/*.patch | sha256sum). Compare it with doc/verification.md.
  • The release tag windows-0.1.1 is a signed Git tag; verify it with
    git tag -v windows-0.1.1 after importing release-key.asc.
  • Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
    version.json. The bundle's sha256 was checked against the Tor Project's
    published sha256sums-signed-build.txt.

Verify before running

Get-FileHash CacheCoin-Windows-0.1.1.zip -Algorithm SHA256

Unpack it, then:

gpg --import release-key.asc          # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txt

The gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.

What this is

A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Double-click CacheCoin.cmd to start. There is no GUI and no daemon mode.

Honest limits

  • Not reproducible. The sha256 values prove only that the files arrived
    unchanged in transit; the GPG signature proves the checksum file came from
    the CacheCoin release key. Nobody can yet rebuild the exact bytes.
  • The executables are unsigned at the OS level (no Authenticode).
  • SmartScreen. Windows will show "Windows protected your PC" on first launch;
    choose More info, then Run anyway, after checking the sha256.
  • Outside the suites. The Windows .exe files are not covered by the
    repository's automated test suites. CI starts the node in regtest, verifies
    the genesis and mines one block; on this package the node was also run against
    mainnet, synced to the live tip and connected to a peer over Tor.
  • No daemon mode. cachecoind -daemon does not exist on Windows (MinGW has
    no fork()); run it in a window or under Task Scheduler.
  • Mining is a lottery. Expect weeks without a block; it may never pay. The
    PER ticket system shares fees only when fees exist. Mining costs electricity
    whether or not it pays.
  • No financial advice. This is open-source software provided as is under the
    MIT license; nothing here is financial advice, an offer or a promise of return.

CacheCoin (CCCN) 0.1.0 for Windows

Choose a tag to compare

@triplecN triplecN released this 03 Oct 16:31

CacheCoin (CCCN) 0.1.0 for Windows

This is the first portable Windows package of CacheCoin: cachecoind.exe and
cachecoin-cli.exe from the tagged tree, the PowerShell launcher, the
documentation and a bundled Tor Expert Bundle.

The binaries are unsigned and this build is not reproducible. Read the whole
note before running.

This package replaces the earlier 0.1.0 builds. It fixes a launcher regression
that broke the normal double-click start, and it tightens the launcher: the
wallet identity check now hashes stable descriptor strings (so the backup
confirmation survives address generation and mining), the mining gate no longer
mistakes an old-but-synced tip for a sync in progress, the opt-in "help other
nodes connect" setting binds only to loopback, the logon task re-registers when
the folder moves, config rewriting understands sections, UTF-16 and BOM files,
the backup documentation now includes a working restore procedure, and
version.json must list the program files before the launcher trusts it. An
adversarial audit of the consensus patch series found no inflation, split or
balance-theft path; the accepted findings are recorded in
doc/consensus-audit-notes.md.

Files

  • CacheCoin-Windows-0.1.0.zip
    sha256: e768e93761dab989d68f14dca716b6b8949f3252c0bb61837cad2f66a659a7e3
  • SHA256SUMS.windows.txt (sha256 of every file in the package)
  • SHA256SUMS.windows.txt.asc (detached GPG signature of the checksum file)
  • version.json (inside the package: pins, patch fingerprint, per-file sha256)

Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).

Provenance

  • Base pins: Bitcoin Core v31.1, commit
    9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
    7607fb2faed24d5a679e139a9828d194bbc644a4.
  • Patch fingerprint: 6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
    (cat patches/*.patch | sha256sum). Compare it with doc/verification.md.
  • The release tag windows-0.1.0 is a signed Git tag; verify it with
    git tag -v windows-0.1.0 after importing release-key.asc.
  • Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
    version.json. The bundle's sha256 was checked against the Tor Project's
    published sha256sums-signed-build.txt.

Verify before running

Get-FileHash CacheCoin-Windows-0.1.0.zip -Algorithm SHA256

Unpack it, then:

gpg --import release-key.asc          # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txt

The gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.

What this is

A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Double-click CacheCoin.cmd to start. There is no GUI and no daemon mode.

Honest limits

  • Not reproducible. The sha256 values prove only that the files arrived
    unchanged in transit; the GPG signature proves the checksum file came from
    the CacheCoin release key. Nobody can yet rebuild the exact bytes.
  • The executables are unsigned at the OS level (no Authenticode).
  • SmartScreen. Windows will show "Windows protected your PC" on first launch;
    choose More info, then Run anyway, after checking the sha256.
  • Outside the suites. The Windows .exe files are not covered by the
    repository's automated test suites. CI starts the node in regtest, verifies
    the genesis and mines one block; on this package the node was also run against
    mainnet, synced to the live tip and connected to a peer over Tor.
  • No daemon mode. cachecoind -daemon does not exist on Windows (MinGW has
    no fork()); run it in a window or under Task Scheduler.
  • Mining is a lottery. Expect weeks without a block; it may never pay. The
    PER ticket system shares fees only when fees exist. Mining costs electricity
    whether or not it pays.
  • No financial advice. This is open-source software provided as is under the
    MIT license; nothing here is financial advice, an offer or a promise of return.

Note added after publication

This package was rebuilt several times during its first day while the launcher
was hardened, and the signed tag was moved to the corrected commit each time.
It is now frozen: the assets on this page are the final 0.1.0 build. Later
changes were published as 0.1.1 instead of rewriting this version; see the
0.1.1 release notes for the full history.