The treasury: a fund no one person can spend
Bitflash has no company and no premine, so an exchange listing is paid for the only way left: by the people who mine and hold it, into a 2-of-3 multisig on the chain itself. What is in it, where it came from and where it goes are read from the blocks, not from a spreadsheet.
Not open yet. The mainnet treasury exists the moment its three keys are in the node's source and this page names their holders. Until then nothing here takes coins, and the figures below stay empty. The whole mechanism is live on the test network.
Read every 30 seconds from treasury.json, regenerated by a node from its own block files whenever a block arrives. A grey dot means this page could not reach it.
01What it is for
One thing: the first exchange listing — the listing fee, and what a listing demands around it (an integration test node, a market-making float if the exchange requires one, nothing else). When that is paid, the next goal is written here before a satoshi moves toward it.
It is not an investment, and it does not owe anyone anything. A contribution is a donation to a piece of free software, with the one difference that here you can watch it, block by block, and see that it was not taken.
02Why a promise is not asked of you
The usual way to fund a listing is “send it to the founder”. The founder could leave. So the treasury is built so that leaving takes nothing:
Two keys of three
The address is a bare 2 <key1> <key2> <key3> 3 OP_CHECKMULTISIG script — valid on this chain since genesis, no new rule. Any spend needs signatures from two holders. The founder holds one key and lives in one place; the other two are held by other people in other places. One person, one key, zero coins.
The keys are in the source
The three public keys are compiled into the node (src/treasury.cpp), printed by gettreasuryinfo, shown below, and named in the signed charter. Four copies from four places; if any two disagree, something is wrong and you can see it.
The chain is the ledger
Every coin in and out is an output on the chain. This page is a reading of it that any node can repeat: scripts/build-treasury.py --verify takes the file this page shows and checks it against your own block files.
What this cannot do: stop two holders from colluding. That is why they are named, not the same person twice, and why every spend is announced before it is signed — so a spend that was not announced is a spend everyone sees for what it is.
03Rules of spending
- Only the stated goal. Nothing leaves for anything this page does not name as the current goal.
- Announced first, seven days ahead. Exchange, amount, destination address and invoice are posted on the Discord and in the ledger below before anyone signs.
- Two named holders sign, and the transaction says which two.
- Never to a holder. No key holder's own address is ever a destination, including as change.
- Everything shows up here, in the block it lands in, with its reason next to it.
- Not refundable. A donation is a donation. If the goal is never reached the coins stay where they are, visible, until it is.
- A key holder who goes quiet for 90 days is replaced: the other two sign a move to a new 2-of-3, announced like any spend.
04How to contribute
Three ways, all opt-in, none in consensus. A node that never heard of the treasury relays its outputs like any other.
Donate from a wallet
# in the window: Send Coins, then the button
# "Donate to the Bitflash treasury"
# over RPC, either of
donate 10
sendtoaddress treasury 10
# or as an output of a raw transaction
createrawtransaction [...] {"treasury": 10}Solo miner: a share of each block
# 10% of every block you find, paid in the
# coinbase itself; the block is worth the same
bitflash -treasuryshare=10
# or Options -> Solo -> the slider (0 to 50)Pool operator: the fee
# the pool fee goes to the treasury
# instead of the operator's wallet
bitflash -poolfeeto=treasury
# miners on that pool contribute by mining,
# in proportion, without doing anything05Every movement
Newest first. coinbase is a miner's share, transfer a donation or a pool fee, spend a payment out with where it went. The transaction id opens in the explorer.
| block | when (UTC) | kind | BTF | transaction | note |
|---|---|---|---|---|---|
| waiting for the ledger… | |||||
06Verify it yourself
The script and the keys
# from any node 1.2.29 or later
gettreasuryinfo
# the same three keys, from the source
grep -A3 MAINNET_KEYS src/treasury.cpp
# decode what is shown below
decodescript <script hex>The ledger against your chain
curl -O https://status.bitflash.network/treasury.json
python3 scripts/build-treasury.py --datadir ~/.bitflash \
--script <script hex> --verify treasury.json
# ok: treasury.json agrees with this node's chain
# up to height N: balance X BTF, M movementsThe output script, exactly as it is on the chain:
—
- required
- —
- network
- —
- ledger tip
- —
07Who holds the keys
| key | holder | public key |
|---|---|---|
| key 1 | the founder, Brazil | — |
| key 2 | to be named: a community member, not the founder | — |
| key 3 | to be named: a community member, not the founder, another country | — |
A holder is a person with a name people can reach, who keeps the key on a machine of their own and signs with signrawtransaction. The charter they signed, and the release key that signed it, are at docs.bitflash.network/treasury.