Repository navigation
CacheCoin (CCCN) 0.1.5 for Windows
CacheCoin (CCCN) 0.1.5 for Windows
Frozen. Superseded by windows-0.2.0: statically linked executables, a pinned and verified Tor bundle, PROVENANCE.txt and Verify Download.cmd. This page is kept for the record; do not use it for new installs.
This is the sixth portable Windows package of CacheCoin: cachecoind.exe and
cachecoin-cli.exe from the tagged tree, the PowerShell launcher, the
documentation and a bundled Tor Expert Bundle.
The binaries are unsigned and this build is not reproducible. Read the whole
note before running.
Why 0.1.5 exists
0.1.4 added My Keys and Backup.cmd and Check Status.cmd. Those tools used
bin\cachecoin-cli.exe directly but did not verify the package the way the
launcher does. A tampered package (a swapped cachecoin-cli.exe, for example)
could therefore read wallet keys if the user ran the keys tool without ever
starting the launcher first. 0.1.5 closes that gap before the next audit round.
The node itself is unchanged (same patch fingerprint).
What changed in 0.1.5
- New shared helper
tools\CacheCoin-Package.ps1. Both tools now verify
version.jsonfail-closed before doing anything:- it must exist and be readable;
- it must list the programs, the launcher and the tools themselves;
- every listed program, launcher or tool file must be present and match its
sha256. A mismatch stops the tool with a clear message and tells the user
to download the package again and checkdocs\VERIFY.txt.
docs\VERIFY.txtnow documents the stronger check and its honest limit: a
fully forged package that also replacesversion.jsonis not caught by this
check. The trust anchor remains the ZIP hash and the GPG signature that the
user verifies themselves.version.jsonnow covers 35 files in this build (the helper is hashed too).
Tests on this build: backup files and sha256 output; key display behind the
typed phrase; wrong-phrase refusal; a tampered cachecoin-cli.exe is refused
with no keys shown and no node started; the restored package passes again.
0.1.4 is frozen as published; the hardening ships as 0.1.5.
Files
CacheCoin-Windows-0.1.5.zip
sha256:7c1de68e1ff44a7c0f9941c97650e28f5927f410dee96b4fde7d973ca388d23fSHA256SUMS.windows.txt(sha256 of every file in the package)SHA256SUMS.windows.txt.asc(detached GPG signature of the checksum file)version.json(inside the package: pins, patch fingerprint, per-file sha256)
Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).
Provenance
- Base pins: Bitcoin Core v31.1, commit
9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
7607fb2faed24d5a679e139a9828d194bbc644a4. - Patch fingerprint:
6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
(cat patches/*.patch | sha256sum). Compare it withdoc/verification.md. - The release tag
windows-0.1.5is a signed Git tag; verify it with
git tag -v windows-0.1.5after importingrelease-key.asc. - Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
version.json. The bundle's sha256 was checked against the Tor Project's
publishedsha256sums-signed-build.txt.
Verify before running
Get-FileHash CacheCoin-Windows-0.1.5.zip -Algorithm SHA256Unpack it, then:
gpg --import release-key.asc # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txtThe gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.
What this is
A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Double-click Start Node.cmd to begin. New users should read
docs\BEGINNER_GUIDE.md. There is no GUI and no daemon mode.
Honest limits
- Not reproducible. The sha256 values prove only that the files arrived
unchanged in transit; the GPG signature proves the checksum file came from
the CacheCoin release key. Nobody can yet rebuild the exact bytes. - The executables are unsigned at the OS level (no Authenticode).
- SmartScreen. Windows will show "Windows protected your PC" on first launch;
choose More info, then Run anyway, after checking the sha256. - Outside the suites. The Windows
.exefiles are not covered by the
repository's automated test suites. CI starts the node in regtest, verifies
the genesis and mines one block; on this package the node was also run against
mainnet, synced to the live tip and connected to a peer over Tor. The entry
points and tools were exercised on a clean sandbox, including a tampered
cachecoin-cli.exebeing refused. - Integrity check scope. The tools' fail-closed check covers a swapped file
inside a genuine package. It cannot cover a fully forged package that also
replacesversion.json; only the ZIP hash and the GPG signature catch that. - No daemon mode.
cachecoind -daemondoes not exist on Windows (MinGW has
nofork()); run it in a window or under Task Scheduler. - Mining is a lottery. Expect weeks without a block; it may never pay. The
PER ticket system shares fees only when fees exist. Mining costs electricity
whether or not it pays. - No financial advice. This is open-source software provided as is under the
MIT license; nothing here is financial advice, an offer or a promise of return.