Repository navigation
CacheCoin (CCCN) 0.2.0 for Windows
CacheCoin (CCCN) 0.2.0 for Windows
Frozen. Superseded by windows-0.2.1: a minor packaging fix. Kept for the record; do not use it for new installs.
Published 2026-10-09. This is the seventh portable Windows package of CacheCoin:
cachecoind.exe and cachecoin-cli.exe from the tagged tree, the PowerShell
launcher, the window (CacheCoin.exe), the documentation and the pinned Tor
Expert Bundle.
The binaries are unsigned and this build is not reproducible. Read the whole
note before running.
Why 0.2.0 exists
0.1.x shipped dynamically linked executables and a copy step that collected the
MinGW/library DLLs (libsqlite3-0.dll among them) next to them; it recorded no
Tor pin inside the repository; and it gave the user no single command to check a
package's provenance. Three fixes, one release:
- the node links SQLite, Boost, libevent and the MinGW runtime statically, so
the package ships no third-party DLL at all, and CI fails if any dependency
becomes dynamic again; - the Tor Expert Bundle is pinned (archive sha256 and signing key in the repo)
andwindows/verify_tor_bundle.shchecks every bundled file against it; - every packaged file is identified in
PROVENANCE.txt, and
Verify Download.cmdchecks a package in one step.
The consensus source is unchanged (same patch fingerprint as 0.1.5).
0.1.5 is frozen as published; the static link, the Tor pin and the provenance
ship as 0.2.0.
What changed in 0.2.0
- Static runtime.
objdump -pon the built executables lists only Windows
system DLLs. CI asserts this before packaging: an import that exists in
/mingw64/binfails the job. The package contains no*.dll. - Sanitized executables. Built with
-ffile-prefix-map/-fmacro-prefix-map
(no absolute build paths in strings),-Wl,-s(no DWARF) and
-Wl,--no-insert-timestamp(PE header time 1970-01-01). - Clean-environment test. CI runs the packaged folder with the MSYS2
PATH
removed, creates a wallet and mines a regtest block: the only check that
proves the folder works on a machine that never had MSYS2. - Tor pin. Expert Bundle 15.0.24 (tor 0.4.9.13), archive
tor-expert-bundle-windows-x86_64-15.0.24.tar.gz, sha256
e9dc6ccc93cd6afa507193f4de284d6424233ff5102155cd2c94b259e8a22b65, signed by
Tor Browser Developers (keyEF6E286DDA85EA2A4BA7DE684E2C6E8793298290).
windows/verify_tor_bundle.shchecks the archive sha256 and compares every
file with it in both directions (missing, mismatched and extra files fail).
tor/**matches the archive byte for byte. - Provenance.
PROVENANCE.txtsays where every file came from, its license
where documented, and the remaining gaps;version.jsonlists the version,
the pins, the patch fingerprint and the sha256 of all 53 packaged files. - Verify Download.cmd (
tools/CacheCoin-Verify.ps1): checksversion.json,
every file hash and the checksum list, and the GPG signature when Gpg4win is
installed andSHA256SUMS.windows.txt.ascis next to the ZIP or one folder
above. When it cannot check the signature it says so instead of claiming
authenticity. - Wallet tools.
My Keys and Backup.cmdis replaced by
Create New Wallet.cmd(offline key/address maker; the old key editor is
removed). TheCacheCoin.cmdshim is removed and the entry points call
launcher\CacheCoin.ps1directly, propagating its exit code. - Window. Built with
--gui-dir:CacheCoin.exeandCacheCoin App.cmd
are insideversion.jsonand the checksums. The window build is
deterministic (twobuild_det.ps1runs produced the same bytes). - Docs.
README-Windows.txt(plain-language file guide),WHY_TOR.md,
twelve license texts, updateddoc/build-windows.mdand
doc/verification.md; SECURITY.md gains "The Windows package" with the
accepted limits of the launcher's enforcement.
Files
CacheCoin-Windows-0.2.0.zip
sha256:ce2002f343410e21b33d411853d37e843b6950325bee84dbb60b723dc91d6543SHA256SUMS.windows.txt(sha256 of every file in the package)SHA256SUMS.windows.txt.asc(detached GPG signature of the checksum file)- raw executables for direct hashing:
cachecoind.exe
ed5d5a8c6a54128e761b0ba92df157f7ca3b2f4670843dc9ed3f719a99dc0418,
cachecoin-cli.exe
1621a9623fa3e866505a6fd4afb0a9a27146c1dfeffa4b3f48544a7773787fb6,
CacheCoin.exe
68e1f30d742bd55e4bbf0c52fb648c771cba1d54ffb371d5e92ace1cd0d30267 PROVENANCE.txt,TOR-PIN.txt(also inside the package)
Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).
Provenance
- Base pins: Bitcoin Core v31.1, commit
9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
7607fb2faed24d5a679e139a9828d194bbc644a4. - Patch fingerprint:
6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
(cat patches/*.patch | sha256sum). Compare it withdoc/verification.md. - The release tag
windows-0.2.0is a signed Git tag; verify it with
git tag -v windows-0.2.0after importingrelease-key.asc. Commit
a29c212(full hash on the tag page). - Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
version.json;TOR-PIN.txtcarries the archive, its sha256 and the key.
Verify before running
Get-FileHash CacheCoin-Windows-0.2.0.zip -Algorithm SHA256Unpack it, then:
gpg --import release-key.asc # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txtThe gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.
Verify Download.cmd performs the same three checks in one step.
What this is
A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Start Node.cmd runs the node; Start Mining.cmd runs node + CPU miner + peer;
CacheCoin App.cmd opens the window; Check Status.cmd reports height, peers
and disk (needs a running node); Create New Wallet.cmd makes a wallet offline.
New users should read README-Windows.txt and docs\START_HERE.txt. Mining
also accepts incoming Tor connections (default cap: 32 connections, about 5 GB
uploaded per day). There is no daemon mode.
Honest limits
- Not reproducible. The sha256 values prove only that the files arrived
unchanged in transit; the GPG signature proves the checksum file came from the
CacheCoin release key. Nobody can yet rebuild the exact bytes; compare the
patch fingerprint, not the binary hash, when you rebuild. - The executables are unsigned at the OS level (no Authenticode).
- SmartScreen. Windows will show "Windows protected your PC" on first
launch; choose More info, then Run anyway, after checking the sha256. - Outside the suites. The Windows
.exefiles are not covered by the
repository's automated test suites. CI starts the node in regtest, verifies
the genesis and mines one block; the packaged tree was also deep-tested
(encrypt, unlock, backup, restore with rescan, then mining on the restored
wallet). - Integrity check scope. The fail-closed check covers a swapped file inside
a genuine package. It cannot cover a fully forged package that also replaces
version.json; only the ZIP hash and the GPG signature catch that. The
remaining accepted limits are listed in SECURITY.md, section "The Windows
package"; the file-hash check cannot see a TOCTOU swap or an alternate data
stream. - No daemon mode.
cachecoind -daemondoes not exist on Windows (MinGW has
nofork()); run it in a window or under Task Scheduler.cachecoin-cli -rpcwaitstill works. - Mining is a lottery. Expect weeks without a block; it may never pay. The
PER ticket system shares fees only when fees exist. Mining costs electricity
whether or not it pays, and mining publishes this computer's.onionaddress. - No financial advice. This is open-source software provided as is under the
MIT license; nothing here is financial advice, an offer or a promise of return.