CHIPs · CHIP-2022-02 · activated

CashTokens: Token Primitives for Bitcoin Cash

Adds fungible tokens and non-fungible tokens (NFTs) directly to Bitcoin Cash outputs, validated by consensus and readable by contracts.

Verified

Summary

CashTokens adds two token primitives to Bitcoin Cash: fungible tokens and non-fungible tokens (NFTs). Tokens live inside ordinary outputs, next to BCH, and every node enforces their rules. See CashTokens for a user guide and tokenstork.com for live token data.

Motivation

The CHIP starts from a limit of the contract system. Before CashTokens, the only commitments a contract could check were transaction signatures and data signatures. Both need a trusted private key, and a contract cannot hold one. So contracts could not issue their own verifiable messages, and decentralized oracles and many cross-contract designs were out of reach.

Token primitives give contracts that ability “without increasing transaction or block validation costs,” while keeping BCH’s stateless UTXO model. Contracts can interact with each other without shared global state.

What it specifies

  • Token categories. Each category ID is a 32-byte transaction ID. It must come from an input that spends output 0 of its parent transaction (a “genesis input”), so category IDs cannot be forged.
  • Fungible tokens. All units of a category are created in its genesis transaction, up to 9,223,372,036,854,775,807 in total.
  • NFTs. Each carries a commitment of 0–40 bytes (raised to 128 bytes in 2026 by P2S). Capabilities: minting (create any number of new NFTs of the category), mutable (create one replacement NFT with a new commitment), or none (immutable).
  • Encoding. A token prefix, marked by byte 0xef, sits at the start of the output’s locking bytecode field.
  • Six inspection opcodes: OP_UTXOTOKENCATEGORY, OP_UTXOTOKENCOMMITMENT, OP_UTXOTOKENAMOUNT, OP_OUTPUTTOKENCATEGORY, OP_OUTPUTTOKENCOMMITMENT, OP_OUTPUTTOKENAMOUNT.
  • SIGHASH_UTXOS, a signing mode that covers all spent outputs.
  • Token-aware CashAddresses. Token-aware wallets must refuse to send tokens to ordinary addresses, which cuts accidental token loss.

Current status

Final (version 2.2.2). Activated on 15 May 2023; chipnet ran it from 15 November 2022.

The stakeholder table records 82 approvals, 1 disapproval (Memo Technology, Inc.) and 253 neutral. The CHIP’s outreach counted non-responses as neutral, so the neutral figure mostly reflects silence, not objection. All node implementations approved except BCHD (neutral).

Stakeholder positions

Only public statements we could link to. Silence is not listed as a position.

Sources

  1. CHIP-2022-02 CashTokens specification
  2. CashTokens stakeholder responses
  3. 2023-05-15 Network Upgrade Specification