Skip to content

CacheCoin (CCCN) 0.2.0 for Windows

Choose a tag to compare

@triplecN triplecN released this 09 Oct 02:50
· 4 commits to main since this release

CacheCoin (CCCN) 0.2.0 for Windows

Frozen. Superseded by windows-0.2.1: a minor packaging fix. Kept for the record; do not use it for new installs.

Published 2026-10-09. This is the seventh portable Windows package of CacheCoin:
cachecoind.exe and cachecoin-cli.exe from the tagged tree, the PowerShell
launcher, the window (CacheCoin.exe), the documentation and the pinned Tor
Expert Bundle.

The binaries are unsigned and this build is not reproducible. Read the whole
note before running.

Why 0.2.0 exists

0.1.x shipped dynamically linked executables and a copy step that collected the
MinGW/library DLLs (libsqlite3-0.dll among them) next to them; it recorded no
Tor pin inside the repository; and it gave the user no single command to check a
package's provenance. Three fixes, one release:

  • the node links SQLite, Boost, libevent and the MinGW runtime statically, so
    the package ships no third-party DLL at all, and CI fails if any dependency
    becomes dynamic again;
  • the Tor Expert Bundle is pinned (archive sha256 and signing key in the repo)
    and windows/verify_tor_bundle.sh checks every bundled file against it;
  • every packaged file is identified in PROVENANCE.txt, and
    Verify Download.cmd checks a package in one step.

The consensus source is unchanged (same patch fingerprint as 0.1.5).

0.1.5 is frozen as published; the static link, the Tor pin and the provenance
ship as 0.2.0.

What changed in 0.2.0

  • Static runtime. objdump -p on the built executables lists only Windows
    system DLLs. CI asserts this before packaging: an import that exists in
    /mingw64/bin fails the job. The package contains no *.dll.
  • Sanitized executables. Built with -ffile-prefix-map/-fmacro-prefix-map
    (no absolute build paths in strings), -Wl,-s (no DWARF) and
    -Wl,--no-insert-timestamp (PE header time 1970-01-01).
  • Clean-environment test. CI runs the packaged folder with the MSYS2 PATH
    removed, creates a wallet and mines a regtest block: the only check that
    proves the folder works on a machine that never had MSYS2.
  • Tor pin. Expert Bundle 15.0.24 (tor 0.4.9.13), archive
    tor-expert-bundle-windows-x86_64-15.0.24.tar.gz, sha256
    e9dc6ccc93cd6afa507193f4de284d6424233ff5102155cd2c94b259e8a22b65, signed by
    Tor Browser Developers (key EF6E286DDA85EA2A4BA7DE684E2C6E8793298290).
    windows/verify_tor_bundle.sh checks the archive sha256 and compares every
    file with it in both directions (missing, mismatched and extra files fail).
    tor/** matches the archive byte for byte.
  • Provenance. PROVENANCE.txt says where every file came from, its license
    where documented, and the remaining gaps; version.json lists the version,
    the pins, the patch fingerprint and the sha256 of all 53 packaged files.
  • Verify Download.cmd (tools/CacheCoin-Verify.ps1): checks version.json,
    every file hash and the checksum list, and the GPG signature when Gpg4win is
    installed and SHA256SUMS.windows.txt.asc is next to the ZIP or one folder
    above. When it cannot check the signature it says so instead of claiming
    authenticity.
  • Wallet tools. My Keys and Backup.cmd is replaced by
    Create New Wallet.cmd (offline key/address maker; the old key editor is
    removed). The CacheCoin.cmd shim is removed and the entry points call
    launcher\CacheCoin.ps1 directly, propagating its exit code.
  • Window. Built with --gui-dir: CacheCoin.exe and CacheCoin App.cmd
    are inside version.json and the checksums. The window build is
    deterministic (two build_det.ps1 runs produced the same bytes).
  • Docs. README-Windows.txt (plain-language file guide), WHY_TOR.md,
    twelve license texts, updated doc/build-windows.md and
    doc/verification.md; SECURITY.md gains "The Windows package" with the
    accepted limits of the launcher's enforcement.

Files

  • CacheCoin-Windows-0.2.0.zip
    sha256: ce2002f343410e21b33d411853d37e843b6950325bee84dbb60b723dc91d6543
  • SHA256SUMS.windows.txt (sha256 of every file in the package)
  • SHA256SUMS.windows.txt.asc (detached GPG signature of the checksum file)
  • raw executables for direct hashing: cachecoind.exe
    ed5d5a8c6a54128e761b0ba92df157f7ca3b2f4670843dc9ed3f719a99dc0418,
    cachecoin-cli.exe
    1621a9623fa3e866505a6fd4afb0a9a27146c1dfeffa4b3f48544a7773787fb6,
    CacheCoin.exe
    68e1f30d742bd55e4bbf0c52fb648c771cba1d54ffb371d5e92ace1cd0d30267
  • PROVENANCE.txt, TOR-PIN.txt (also inside the package)

Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).

Provenance

  • Base pins: Bitcoin Core v31.1, commit
    9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
    7607fb2faed24d5a679e139a9828d194bbc644a4.
  • Patch fingerprint: 6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
    (cat patches/*.patch | sha256sum). Compare it with doc/verification.md.
  • The release tag windows-0.2.0 is a signed Git tag; verify it with
    git tag -v windows-0.2.0 after importing release-key.asc. Commit
    a29c212 (full hash on the tag page).
  • Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
    version.json; TOR-PIN.txt carries the archive, its sha256 and the key.

Verify before running

Get-FileHash CacheCoin-Windows-0.2.0.zip -Algorithm SHA256

Unpack it, then:

gpg --import release-key.asc          # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txt

The gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.
Verify Download.cmd performs the same three checks in one step.

What this is

A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Start Node.cmd runs the node; Start Mining.cmd runs node + CPU miner + peer;
CacheCoin App.cmd opens the window; Check Status.cmd reports height, peers
and disk (needs a running node); Create New Wallet.cmd makes a wallet offline.
New users should read README-Windows.txt and docs\START_HERE.txt. Mining
also accepts incoming Tor connections (default cap: 32 connections, about 5 GB
uploaded per day). There is no daemon mode.

Honest limits

  • Not reproducible. The sha256 values prove only that the files arrived
    unchanged in transit; the GPG signature proves the checksum file came from the
    CacheCoin release key. Nobody can yet rebuild the exact bytes; compare the
    patch fingerprint, not the binary hash, when you rebuild.
  • The executables are unsigned at the OS level (no Authenticode).
  • SmartScreen. Windows will show "Windows protected your PC" on first
    launch; choose More info, then Run anyway, after checking the sha256.
  • Outside the suites. The Windows .exe files are not covered by the
    repository's automated test suites. CI starts the node in regtest, verifies
    the genesis and mines one block; the packaged tree was also deep-tested
    (encrypt, unlock, backup, restore with rescan, then mining on the restored
    wallet).
  • Integrity check scope. The fail-closed check covers a swapped file inside
    a genuine package. It cannot cover a fully forged package that also replaces
    version.json; only the ZIP hash and the GPG signature catch that. The
    remaining accepted limits are listed in SECURITY.md, section "The Windows
    package"; the file-hash check cannot see a TOCTOU swap or an alternate data
    stream.
  • No daemon mode. cachecoind -daemon does not exist on Windows (MinGW has
    no fork()); run it in a window or under Task Scheduler. cachecoin-cli -rpcwait still works.
  • Mining is a lottery. Expect weeks without a block; it may never pay. The
    PER ticket system shares fees only when fees exist. Mining costs electricity
    whether or not it pays, and mining publishes this computer's .onion address.
  • No financial advice. This is open-source software provided as is under the
    MIT license; nothing here is financial advice, an offer or a promise of return.