DEV Community

xui axaeu
xui axaeu

Posted on AI-assisted

BitMessage: What If Communication Could Become a Source of Decentralized Participation?

BitMessage is an experimental protocol proposal built around Proof-of-Presence-and-Meaning (PoPM), a participation mechanism designed to connect everyday communication with cryptographically verifiable protocol events, distributed infrastructure, and a native economic system.

This manifesto describes the architecture, threat model, tokenomics, privacy model, and research requirements behind the idea.

This is not a claim that the protocol is already secure or production-ready. It is a proposal intended to be examined, attacked, tested, and improved.

The Full Technical and Economic Manifesto of the BitMessage Ecosystem
A decentralized communication network built around participation, privacy, and real network utility
Chapter 1. The Centralization Trajectory of Modern Consensus

Decentralization is not merely the absence of a central server.

A network is meaningfully decentralized when independent participants can use it, contribute to it, and maintain it without depending entirely on a single institution or on resources available only to industrial-scale operators.

The history of distributed ledgers demonstrates that every consensus mechanism organizes participation around some scarce resource.

Proof-of-Work organizes competitive block production around computation, energy, hardware efficiency, and access to infrastructure.

Proof-of-Stake organizes validation influence primarily around capital committed to the protocol.

Neither mechanism is inherently illegitimate.

Both have demonstrated that decentralized consensus can function at scale.

Their structural differences, however, reveal a larger question:

What resource should determine access to economic participation in a decentralized communication network?

BitMessage proposes that communication itself should become part of the answer.

A communication network already possesses a vast population of active participants. Every day they exchange messages, interact with software, consume bandwidth, provide storage, and keep devices connected to the network.

Traditional blockchains generally treat these activities as external to consensus.

BitMessage attempts to integrate them into the protocol economy.

The resulting framework is called Proof-of-Presence-and-Meaning, or PoPM.

PoPM is not presented as a universal replacement for Proof-of-Work or Proof-of-Stake.

It is a participation and reward mechanism designed to connect useful communication activity with cryptographically verifiable protocol events.

The architecture deliberately separates this mechanism from the finality mechanism of the ledger.

This distinction is fundamental.

The network does not need to prove that one cryptographic identity corresponds to one biological human.

It needs to establish that participation events are fresh, bounded, economically constrained, and verifiable.

The central BitMessage principle is therefore:

A person using the network for its intended purpose should be able to participate in the network's economy without first becoming an industrial miner or a large capital holder.

Chapter 2. Proof-of-Presence-and-Meaning

PoPM begins with a rejection of a dangerous assumption.

Human behavior is not unrepeatable magic.

Software can simulate mouse movement.

Software can simulate keyboard timing.

Software can generate natural-language text.

Software can reproduce entire user interfaces.

Therefore BitMessage does not define behavioral entropy as proof of humanity.

Instead, behavioral interaction is one input into a larger cryptographic participation mechanism.

PoPM combines several independent properties:

fresh epoch challenges;
local behavioral entropy;
cryptographic commitments;
controlled participation frequency;
optional verifiable delay;
resource-bound infrastructure roles;
explicit economic accounting.

Each component exists for a different reason.

No single component is expected to eliminate every adversarial strategy.

Behavioral Entropy

The BitMessage client may locally observe bounded interaction signals such as pointer movement, interaction timing, keyboard-event timing, navigation activity, and other permitted interface events.

The purpose is not surveillance.

The purpose is to provide a local input that changes across participation events.

The raw interaction stream is not required to become public blockchain data.

Instead, the client derives a commitment from the local state.

A simplified representation is:

E_e = H("BitMessage-Entropy" || C_e || public_key || session_id || local_entropy)

The resulting value commits the participant to the local entropy without publishing the underlying interaction record.

The protocol does not claim that this commitment proves a human was present.

It proves only that the participant supplied an input to the specified cryptographic procedure.

This distinction is central to the security model.

Chapter 3. Fresh Epochs and Network Challenges

Behavioral data becomes much more useful when it cannot simply be prepared years in advance and replayed indefinitely.

BitMessage therefore divides protocol activity into discrete epochs.

Each epoch receives a fresh network challenge derived from already finalized network state and a protocol randomness source:

C_e = H("BitMessage-PoPM" || network_id || epoch_e || R_e || B_(e-1))

Where:

network_id identifies the BitMessage network;
epoch_e identifies the current epoch;
R_e is the finalized randomness value for the epoch;
B_(e-1) represents the finalized state from the previous protocol round.

The challenge is not controlled by an individual participant.

It is not an arbitrary input selected by the client.

It is not a mining nonce.

A participant therefore cannot choose an advantageous challenge and distribute computation around it in advance.

The objective is not to prevent an attacker from reacting quickly after the challenge becomes public.

That is impossible in a public network.

The objective is narrower:

Previously prepared participation data must become unsuitable for a new epoch unless the attacker performs the new protocol computation required by that epoch.

Freshness is therefore a protocol property rather than a timestamp claim.

Chapter 4. The PoPM Participation Ticket

The message payload is independently committed:

M_e = H("BitMessage-Message" || message || metadata)

The behavioral commitment is:

E_e = H("BitMessage-Entropy" || C_e || public_key || session_id || local_entropy)

The participant's protocol input becomes:

X_e = H("BitMessage-Ticket" || C_e || public_key || session_id || M_e || E_e)

The key property of this construction is the absence of a freely searchable mining nonce.

The client does not produce:

nonce_1
nonce_2
nonce_3
...

until one of them happens to generate a favorable result.

Instead, a specific participation event deterministically produces one protocol input.

The protocol may then derive:

T_e = H("BitMessage-Result" || X_e || Y_e)

where Y_e is either the direct protocol result or the result of the optional sequential-delay layer described below.

Eligibility is evaluated against a protocol-defined target:

T_e < Target_e

The target controls the expected frequency of successful events.

Because the participant cannot freely search an arbitrary nonce space, the computation does not automatically become conventional Proof-of-Work.

This is one of the defining properties of PoPM.

Chapter 5. Verifiable Delay as a Timing Layer

Fresh challenges prevent old tickets from being reused indefinitely.

They do not, by themselves, impose a meaningful delay between challenge creation and participation.

For situations where the protocol requires a measurable sequential delay, BitMessage may use a Verifiable Delay Function (VDF).

A VDF is intended to require a sequence of operations that is difficult to parallelize within a single evaluation while allowing substantially faster verification of the resulting proof.

A participant derives:

X'_e = H("BitMessage-VDF" || X_e)

and evaluates:

(Y_e, π_e) = VDF_Eval(X'_e, τ_e)

The network verifies:

VDF_Verify(X'_e, Y_e, π_e) = TRUE

The VDF therefore serves as a sequential timing layer.

It does not serve as a universal anti-botnet mechanism.

A botnet containing one million independent machines can perform one million independent VDF evaluations in parallel.

Likewise, a sufficiently motivated attacker may invest in hardware optimized for the selected VDF construction.

BitMessage therefore makes no claim that a VDF eliminates parallel attackers.

Its purpose is more precise:

prevent unrestricted local search from becoming the dominant source of advantage;
reduce the usefulness of rapid precomputation;
impose a predictable sequential cost on each participation lane;
provide a publicly verifiable delay.

The protocol should select and parameterize its VDF only after benchmarking consumer CPUs, GPUs, cloud infrastructure, and likely specialized hardware.

The security parameter is not chosen because it "looks slow."

It is chosen from an explicit adversarial cost model.

Chapter 6. Sybil Resistance and the Fundamental Permissionless Constraint

Any permissionless cryptographic system faces the same fundamental fact:

Creating a new keypair is cheap.

One person can create one identity.

The same person can create one hundred thousand identities.

Therefore BitMessage does not define:

one public key = one human

because that proposition cannot be established from cryptographic key generation alone.

PoPM is consequently not advertised as proof-of-personhood.

Instead, BitMessage uses several distinct identity classes.

Communication Identity

A user can create one or more public communication identifiers.

These identifiers provide privacy and flexibility.

Participation Identity

Participation events are rate-limited and bound to explicit protocol state.

Creating additional keys does not allow a single key to exceed its participation budget.

Infrastructure Identity

Roles that can materially influence network availability or final consensus require additional resource commitments.

Such commitments may include:

storage capacity;
bandwidth;
uptime;
refundable collateral;
other measurable resources specified by the protocol.

These requirements are not intended to recreate simple capital-weighted governance.

Their purpose is to make infrastructure Sybil attacks materially more expensive.

A network cannot simultaneously promise unrestricted free identities, unlimited influence per identity, and perfect Sybil resistance.

BitMessage does not make that promise.

Instead, it makes Sybil cost an explicit engineering parameter.

Chapter 7. Consensus Finality Is Separate from PoPM

PoPM is not the sole source of blockchain finality.

This is an intentional architectural boundary.

PoPM produces participation proofs and can determine eligibility for defined protocol actions and rewards.

A separate deterministic consensus layer establishes canonical ledger state.

The consensus layer validates:

transaction signatures;
transaction commitments;
PoPM proofs;
VDF proofs where applicable;
fee rules;
resource claims;
double-spend protection;
block structure;
rules governing chain finality.

The exact finality mechanism must be specified independently and must include explicit assumptions about the percentage of adversarial participants the network can tolerate.

This separation provides an important benefit.

A change to the semantic anti-spam system does not need to redefine blockchain validity.

A new language model does not become a consensus dependency.

A new machine-learning classifier cannot fork the network merely because two versions disagree about whether a sentence appears human.

Consensus verifies cryptographic facts.

The application layer evaluates social and semantic signals.

This separation is mandatory for architectural stability.

Chapter 8. Meaning, Uniqueness, and Anti-Spam

BitMessage does not require every full node to maintain an eternal global database of every plaintext sentence ever transmitted.

Such an architecture would impose unnecessary storage and privacy costs.

Instead, the system distinguishes several levels of duplicate detection.

Cryptographic Duplication

A transaction contains a cryptographic identifier and commitment.

If the same transaction or participation event is submitted twice under a context where replay is forbidden, validators can reject the second submission without needing to inspect every historical plaintext message.

Bounded Reuse Windows

Anti-spam mechanisms may maintain rolling sets of recently observed commitments.

These sets have a bounded lifetime.

A node does not need to remember every communication event in the history of humanity.

It needs to retain only the state required by the active anti-abuse rules.

Semantic Similarity

Semantic analysis can be useful for application-level spam suppression.

However, semantic similarity is not treated as canonical blockchain validity.

The network does not require every validator to run the same neural network merely to determine whether two sentences express the same idea.

A future implementation may use:

embeddings;
statistical classifiers;
language models;
local heuristics;
user-configurable filters.

These mechanisms operate above the cryptographic consensus layer.

Their output may determine local ranking, relay preference, visibility, or spam handling.

Their output must not silently rewrite the canonical ledger.

The objective is not to make automated text generation impossible.

The objective is to ensure that generating millions of messages produces limited economic value unless those messages consume real network resources or satisfy actual network demand.

Chapter 9. The Botnet Model

A serious protocol must assume that attackers may have access to compromised machines.

Therefore BitMessage does not rely on the claim that attackers must rent expensive servers.

A botnet can distribute computation across thousands or millions of devices.

The protocol addresses this through multiple independent restrictions.

Per-Lane Limits

Each participation identity has a bounded participation rate.

A device cannot create unlimited protocol events per second merely by executing the client continuously.

Epoch Freshness

Old tickets cannot be replayed indefinitely.

Sequential Delay

Where required, VDF evaluation imposes a minimum sequential cost per participation lane.

Reward Saturation

The protocol does not have to grant constant rewards for unlimited message volume.

Marginal rewards can decrease as participation exceeds the useful operating range.

Resource Pricing

Large-scale storage, bandwidth, and persistent routing consume real resources and incur corresponding costs.

Infrastructure Requirements

Consensus-critical infrastructure roles can require measurable resource commitments.

The objective is not to prove that a botnet cannot operate.

The objective is to make economic extraction from automated activity substantially harder than simply creating identities.

That distinction matters.

A successful botnet is possible.

A profitable botnet is the actual economic question.

Chapter 10. Pre-Computation and Freshness

An attacker may begin computation as soon as public information becomes available.

BitMessage therefore does not define security around the idea that the attacker can never know the current challenge.

The real objective is to prevent the attacker from preparing a valid participation event before its relevant protocol context exists.

A participation ticket is tied to:

the current epoch;
finalized network randomness;
finalized chain state;
public key;
session state;
message commitment;
entropy commitment;
VDF output where enabled.

A historical ticket does not remain valid merely because its underlying behavioral input was once valid.

A previously captured entropy record is not itself a valid participation ticket.

A timestamp alone is not considered a security primitive.

Freshness comes from cryptographic context.

The protocol therefore distinguishes between:

Old data

and

Old authorization.

Old data may exist forever.

Old authorization must expire.

Chapter 11. Dual Tokenomics

BM is the native settlement asset of the BitMessage ecosystem.

Its primary purpose is network utility.

The system does not depend on the proposition that the token will appreciate.

The token has value within the protocol because decentralized communication consumes resources.

Storage consumes physical disk capacity.

Routing consumes bandwidth.

Persistent nodes consume electricity and connectivity.

Large media transfers consume significantly more infrastructure than small text messages.

BM is therefore used to settle access to these resources.

Storage Market

Users requiring persistent decentralized storage pay BM.

Storage providers contribute measurable capacity and receive compensation according to the resources they actually provide.

Encrypted fragments can be distributed among independent nodes with redundancy so that the loss of some providers does not automatically destroy stored objects.

Bandwidth and Routing

Large transfers require more network capacity.

Bandwidth-intensive operations therefore carry corresponding protocol costs.

Relay and infrastructure providers receive resource compensation according to deterministic accounting rules.

Premium Digital Property

The ecosystem can also use BM for:

short usernames;
custom handles;
enterprise communication features;
API access;
creator channels;
subscription systems;
other application-level services.

These features create token utility independent of speculative trading.

Chapter 12. The Message-Fee Burn

Unlimited free messaging creates an obvious spam vector.

BitMessage therefore introduces a small base protocol fee for ordinary messages.

The base messaging fee is permanently burned.

It is not paid to a developer wallet.

It is not controlled by a central foundation.

It is removed from the effective token supply according to deterministic protocol rules.

If network activity increases, cumulative burn increases.

However, BitMessage explicitly rejects the simplistic claim that burning tokens guarantees higher prices.

Token supply is only one variable.

Market demand, liquidity, velocity, issuance, competition, and external economic conditions remain relevant.

The burn therefore serves a specific purpose:

Network activity creates a predictable token sink while the resource economy creates functional demand.

Infrastructure fees remain separate.

Storage, bandwidth, relay, and other measurable resource payments are distributed to resource providers rather than burned.

The two mechanisms must never be conflated.

Chapter 13. Controlled Issuance

PoPM rewards follow a transparent issuance schedule.

The network may issue larger rewards during its bootstrapping phase to encourage participation and infrastructure deployment.

As the ecosystem grows, marginal rewards decline according to predefined protocol rules.

The objective is to prevent a permanent incentive for useless message generation.

Reward allocation should therefore reflect more than raw message count.

The protocol can account for:

successful participation events;
defined communication activity;
infrastructure contributions;
network demand;
resource consumption.

The economic target is not:

more messages = infinite money

but:

useful participation + useful infrastructure = sustainable economic utility
Chapter 14. Decentralized Communication Infrastructure

BitMessage does not require a single centralized messaging server.

The network consists of independent participants operating different logical roles.

Clients

Clients provide the user-facing communication interface.

Relay Nodes

Relay nodes forward encrypted traffic.

Storage Nodes

Storage nodes maintain encrypted fragments of persistent data.

Full Nodes

Full nodes validate blockchain state and participate in the consensus protocol.

A single physical device may perform multiple roles.

Peer Discovery

Peer discovery is distributed rather than dependent on a single mandatory directory.

Multiple bootstrap mechanisms may exist.

The disappearance of one bootstrap provider should not imply the disappearance of the network.

Multi-Hop Routing

Packets may be routed through multiple relays.

Each intermediate relay receives only the information required to forward its current packet.

This reduces metadata concentration.

It does not create perfect anonymity against a global adversary.

Traffic analysis, endpoint compromise, malicious relays, timing correlation, and other attacks remain possible.

The protocol therefore promises reduced metadata concentration, not universal invisibility.

Chapter 15. Distributed Storage

Large files are fundamentally different from text messages.

They consume storage capacity and bandwidth.

BitMessage therefore treats persistent data availability as a resource market.

A file can be encrypted locally and divided into fragments.

Fragments can then be distributed across independent storage providers.

Redundancy or erasure coding can allow the system to reconstruct data even if some providers disappear.

The storage provider does not need access to plaintext content.

The provider stores encrypted material and receives compensation for measurable resource contribution.

The user purchases persistence rather than trusting a single company to keep a copy.

The economic relationship is explicit:

storage demand -> resource contribution -> provider compensation

This is the foundation of the BitMessage decentralized storage economy.

Chapter 16. Privacy by Architecture

A privacy-oriented communication network should minimize the amount of information it requires from its users.

BitMessage account creation therefore begins locally.

A cryptographic keypair is generated by the client.

The public key becomes the account identifier.

The private key remains under user control.

Phone-number verification is not structurally required.

Email registration is not structurally required.

A central database mapping every account to a government identity is not structurally required.

This does not mean that every form of network metadata disappears.

No protocol operating on ordinary internet infrastructure can honestly promise that.

The architectural objective is instead:

Do not collect information merely because centralized software traditionally collects it.

Behavioral Privacy

Behavioral entropy is especially sensitive.

Raw cursor paths and keyboard timings should therefore remain local.

The network receives cryptographic commitments and, where formally implemented, zero-knowledge proofs concerning specified computations over private inputs.

A zero-knowledge proof can establish mathematical correctness of a defined statement without revealing the witness used to produce it.

It cannot prove biological humanity by itself.

BitMessage does not claim otherwise.

Chapter 17. End-to-End Encryption

Communication content must remain inaccessible to intermediaries by default.

BitMessage therefore uses end-to-end cryptography for private messages.

A Double Ratchet-based construction can continuously derive fresh message keys and provide important protections under specified compromise conditions.

Encryption protects message content.

Key management protects account authority.

Routing mechanisms reduce metadata concentration.

These are separate layers.

A compromised endpoint can still reveal information to an attacker.

A compromised relay can still observe the metadata available to that relay.

A globally positioned adversary may still perform traffic analysis.

Privacy is therefore described through explicit threat models rather than absolute language.

Chapter 18. Identity, Devices, and Recovery

Decentralized identity should remain under user control.

The protocol therefore separates:

account identity;
device keys;
session state;
recovery material.

A user can authorize an additional device through cryptographic procedures.

A recovery mechanism can allow restoration of account control from user-held recovery material.

The service operator should not possess a secret capable of universally impersonating users.

Convenience must not silently reintroduce the centralized authority the protocol was designed to remove.

The underlying principle is:

The network may help recover access, but the network must not become the owner of the identity.

Chapter 19. User Experience

The majority of users do not want to operate cryptographic infrastructure.

They want to communicate.

BitMessage should therefore present itself as a communication application before it presents itself as a blockchain.

The interface can provide:

private conversations;
group chats;
public channels;
file sharing;
voice messages;
usernames;
device synchronization;
familiar messaging controls.

The economic and cryptographic systems remain in the background.

The user does not manually search for a mining nonce.

They do not operate a mining pool.

They do not configure blockchain internals merely to send a message.

They communicate.

The local client handles the participation protocol in the background.

A qualifying participation event may generate BM.

The intended interaction model is therefore:

communicate -> participate -> contribute -> earn

The complexity belongs to the protocol.

The simplicity belongs to the user.

Chapter 20. What BitMessage Does Not Claim

BitMessage does not claim that:

human behavior cannot be simulated;
VDFs eliminate botnets;
VDFs eliminate specialized hardware;
one public key represents one human;
Sybil attacks become mathematically impossible;
semantic AI can safely determine blockchain validity;
zero-knowledge proofs prove biological humanity;
onion routing guarantees perfect anonymity;
decentralized storage makes data indestructible;
token burning guarantees price appreciation;
decentralized infrastructure can never be censored.

Such claims would weaken the credibility of the protocol.

BitMessage instead makes narrower and measurable claims.

It aims to demonstrate that:

ordinary communication can generate legitimate participation events;
participation events can be cryptographically fresh;
unrestricted nonce mining can be excluded from the participation mechanism;
sequential delay can be used where measurable timing resistance is required;
infrastructure roles can carry explicit resource commitments;
semantic filtering can remain outside deterministic consensus;
storage and bandwidth can become native economic resources;
users can participate without mandatory real-world identity registration;
communication infrastructure can be distributed across independent operators.

These are engineering objectives.

They can be tested.

Chapter 21. Security and Adversarial Testing

The protocol should be considered an experimental distributed system until demonstrated otherwise.

Before production deployment, the project must publish a complete threat model covering:

Sybil attacks;
replay attacks;
pre-computation;
botnets;
VDF acceleration;
malicious clients;
malicious relays;
eclipse attacks;
network partition;
traffic analysis;
storage corruption;
resource exhaustion;
consensus equivocation;
economic manipulation.

The project must also publish the parameters that determine economic security.

For example:

maximum participation frequency;
epoch duration;
VDF delay;
reward schedule;
resource pricing;
storage collateral;
infrastructure requirements;
anti-spam limits.

These values should not be justified by intuition alone.

They should be derived from measurements and adversarial modeling.

A serious test is therefore not:

“Can an honest user earn a token?”

A serious test is:

“How much does it cost an attacker to obtain one percent, ten percent, or thirty percent of economically useful network participation?”

That is the metric that matters.

Chapter 22. The Research Program

The manifesto is not a substitute for a protocol specification.

Before the network carries meaningful economic value, BitMessage should release:

a formal state-transition specification;
a complete PoPM specification;
the exact VDF construction and parameters;
a replay-resistance proof;
a precise definition of participation budgets;
a Sybil and botnet cost model;
a consensus safety and liveness analysis;
storage failure simulations;
eclipse-attack simulations;
network partition testing;
cryptographic proof specifications;
open-source reference implementations;
reproducible builds;
independent security audits.

The protocol should be implemented before its strongest assumptions are marketed.

The economic model should be simulated before its token supply is considered secure.

The networking model should be attacked before its privacy claims are considered credible.

The PoPM mechanism should be measured against real automation frameworks before claims about automation resistance are made.

The most valuable result of an early security audit is not a perfect report.

It is the discovery of an attack that can still be fixed.

Chapter 23. The BitMessage Principle

Bitcoin asked whether money could exist without a central financial authority.

Privacy-oriented communication systems asked whether people could communicate without surrendering every conversation to a centralized platform.

BitMessage asks another question:

What happens when communication itself becomes a source of decentralized participation?

The answer is not that human behavior becomes mathematically magical.

It does not.

The answer is that a communication network already produces useful activity that can become part of its economic architecture.

Users create demand.

Nodes provide resources.

Resources receive compensation.

Protocol participation receives measurable constraints.

Cryptographic challenges provide freshness.

Sequential delay can restrict rapid computation within individual participation lanes.

Consensus remains deterministic.

Semantic systems remain outside consensus where their decisions cannot be perfectly reproduced by every validator.

Privacy remains an architectural objective rather than a marketing promise of absolute invisibility.

And the token exists because the network consumes real resources.

BitMessage therefore attempts to reverse a familiar relationship.

Traditional crypto applications ask users to acquire an asset before the network becomes useful.

BitMessage begins with the useful application.

The communication network creates activity.

The activity creates resource demand.

The resources create an economy.

The economy supports the infrastructure.

And users become participants in the system they are already using.

That is the idea behind Proof-of-Presence-and-Meaning.

Not proof that a machine is a human.

Not proof that attacks are impossible.

Not proof that decentralization creates invulnerability.

Instead:

fresh participation.

measurable resource contribution.

deterministic cryptography.

distributed infrastructure.

privacy by architecture.

and an economy derived from actual network utility.

A decentralized network should not exist solely for those who can afford industrial mining equipment or enormous financial positions.

It should create a meaningful path for ordinary users to participate in the infrastructure they depend upon.

A messenger first.
A decentralized network second.
An economy derived from utility.
Participation as a native property of communication.

That is the BitMessage ecosystem.

Status and Invitation

BitMessage is an experimental protocol proposal, not a finished cryptocurrency or production-ready messaging network.

The purpose of publishing this manifesto is to expose the architecture to technical criticism.

I am particularly interested in feedback on:

cryptographic assumptions;
PoPM design;
VDF parameterization;
Sybil resistance;
botnet economics;
consensus architecture;
P2P routing;
distributed storage;
privacy;
and token economics.

The strongest version of BitMessage will not be the version that receives the most praise.

It will be the version that survives the strongest attacks.

Top comments (0)