DDCP Manifesto
Decentralized Digital Currency Protocol
The Better Money
Unconditional. Private. Sound.
v20260924-4 · September 2026
There is no such thing as perfect money.
But there is better money — and people deserve access to it.
“The central bank must be trusted not to debase the currency,
but the history of fiat currencies is full of breaches of that trust.”— Satoshi Nakamoto
“Trusted third parties are security holes.”— Nick Szabo
I. The Vision
1.1 There Is No Best Money
As disciples of Mises and Hayek, we begin with a conviction: there is no perfect money, and there is no single best money for all individuals, in all places, at all times. The nature of the economy is fluidity. Money is one good among many, and its value — like all value — is subjective, contextual, and mutable. The best monetary arrangement for any society is not a monopoly on money but a plurality of competing currencies, each with its own properties, each allowing individuals to opt in freely based on what they value.
Most people around the world have access to only one currency: the local legal tender their government has declared mandatory. Some have the luxury of accessing a dollar or a euro — occasionally through parallel or informal markets — as a means of protecting the value of their savings. But even the dollar and the euro, better than most, are not foreign to debasement, seigniorage, and an accelerating drift toward becoming instruments of state surveillance and individual control.
DDCP’s mission is not to be the best money for everyone. It is to make The Better Money available to everyone — one option among competing currencies, with the best set of qualities a currency can offer not only for individuals but for society.
1.2 What Better Money Looks Like
Better money has four qualities, each reinforcing the others. None is optional for the destination. Together they define a standard that no existing monetary instrument — fiat, CBDC, or centralized stablecoin — currently meets in full.
Quality 1 — The Basics: Divisible, Portable, Fungible, Durable, Counterfeit-Proof
These are the foundational properties of money that every monetary economist agrees on. Banked people in developed economies take them for granted: they pay and transfer money by transferring property rights over portions of their deposits, immediately and globally. Most people in the world do not have this access — they depend on cash that satisfies some of these properties but not all, and banking systems that marginally serve them. Better money delivers these basics to everyone, not as a privilege of geography or institutional access, but as a baseline.
Quality 2 — Fast, Cheap, 24/7 Payments With No Restrictions
This is the promise crypto stablecoins made to the world — and partially kept. Reduce the cost of payments and transfers, make them instant, make them available at any hour without waiting for a bank’s business hours or a correspondent network’s settlement window. The “no restrictions” element is the part the existing stablecoin market has not kept: every major centralized stablecoin today operates with restrictions that its issuer can apply at any moment, for any reason, with no prior notice and no appeal.
Quality 3 — Unconditional, Private and Free from Arbitrary Seizure
This is the most consequential quality and the hardest to deliver. The right to exchange value freely for goods and services — to transact without surveillance, to hold assets without arbitrary seizure, and to participate in the economy without submitting to political conditions — are fundamental individual civil rights, preconditions for the exercise of every other freedom. You cannot organize politically, support causes, practice religion, or make personal decisions with full autonomy if every financial transaction is visible to and potentially weaponizable by whoever holds executive power.
Free societies have navigated the balance between individual financial privacy and legitimate law enforcement for centuries, arriving at a settled framework: the state may investigate and seize assets, but only through judicial process, with individual targeting, evidentiary standards, and the right of appeal. That framework did not emerge by accident. It exists because unchecked financial surveillance and seizure are instruments of political control, not just law enforcement. Better money does not take that framework away. What it denies is the capability digitization added on top of it: reaching everyone at once, through a single instruction, without naming anyone.
Quality 4 — Value Preservation
Going back to Mises: there is no such thing as stable value. The economy is in constant flux, and money is no exception. But there is more and less susceptibility to debasement, and more and less vulnerability to seigniorage and politically motivated monetary expansion.
Money began as a commodity anchor — grain receipts in Mesopotamia, silver by weight, gold coins — value rooted in what people actually consumed and needed. The long-term horizon of The Better Money returns to that foundation: purchasing power anchored not in any sovereign’s decisions but in the real goods that sustain and drive the real economy. The energy that powers industries. The agricultural products that feed populations. The industrial inputs that build and wire the physical world. Value rooted in what people consume — not in what they believe others will pay for it.
The distinction that matters is not which goods are in the basket but why they are demanded. Value anchored in goods the world needs to use is anchored in something outside anyone’s expectations about price. A consumption anchor does not promise stability through every kind of crisis. It removes one specific risk, and the one this Manifesto is concerned with: that the unit itself can be diluted by decision. No sovereign can debase a basket of goods the world consumes. That horizon is what this protocol aims to keep open.
II. The Problem: Money as an Instrument of Control
2.1 The Pattern Is Not New — and Not Ideological
The seizure of privately held savings by governments is not a characteristic of authoritarian regimes acting outside their legal framework. It is a recurring feature of democratic governance when a state’s financial needs converge with the structural accessibility of private assets. The pattern does not require bad intent. It requires only opportunity.
In April 1933, the United States government — a democratic republic with a written constitution, an independent judiciary, and a tradition of property rights — issued Executive Order 6102, requiring people in the United States to surrender their privately held gold to the Federal Reserve at a fixed exchange rate, under penalty of criminal prosecution. Gold was reachable through the banking system for bank-held deposits, and through the force of criminal law for privately held coins and bars. Gold was not seized from criminals. It was confiscated from ordinary people who held it, regardless of how it was obtained or what individual circumstances surrounded it.
People who surrendered it had been paid an amount in dollars that was roughly 40% lower than the gold value at the January 1934 revaluation. What was taken was not only the gold. It was the 40% of their savings in gold.
In February 2002, the Argentine government did something very similar: it converted every dollar deposit in the domestic banking system into pesos by decree, at an official rate that left savers with less than half the dollar value of their deposits, held in the one institution they had been told was safe.
These episodes are separated by nearly seventy years and two continents, but they share a common structure: the government needed the asset, and the asset was accessible through the financial infrastructure it commanded. They also share something less noticed and more important: the timing. In each case the exit closed before the measure was announced, because the measure could not work otherwise. The banks were shut before the gold was called in. Withdrawals were capped before the deposits were converted. The decision reaches the citizen after the door is closed. This is not a failure of the process. It is the process.
The lesson is architectural, and it does not depend on the character of any government: accessible savings are politically reachable savings, regardless of the form that access takes. A person who concludes that their savings are exposed cannot act on that conclusion at the moment the risk becomes visible, because visibility is the one thing the design withholds.
2.2 The Banking System: The Original Compliance Chokepoint
Modern banking formalized this accessibility into architecture. When you deposit money at a bank, you acquire a claim on the bank — a legal obligation denominated in currency. You do not own the money; you own a debt instrument from an institution that is licensed by, regulated by, and continuously supervised by the state. The bank’s ledger is the authoritative record of your claim. The bank’s solvency and cooperation are the preconditions for your ability to exercise it.
This architecture has produced genuine benefits: payment efficiency, fraud protection, credit infrastructure, economic coordination at scale. But it has simultaneously made the entirety of a society’s financial claims continuously accessible to whoever can issue instructions to the banking system. To reach an individual’s savings, a government does not need to go to that individual’s home. It needs only to instruct the bank.
The Canadian episode of February 2022 is the clearest modern demonstration of this property exercised in a fully functioning liberal democracy. The Canadian government invoked emergency powers directing financial institutions to freeze the accounts of people taking part in or supporting a political protest — without individual court orders, and for most of those affected without any criminal charge. The directive was issued to financial institutions. The institutions complied instantly, because their regulatory relationship with the government made non-compliance unthinkable and their architecture made compliance trivial.
The episode illustrates a structural property of centralized financial infrastructure: there is no judicial process that must occur before a freeze is executed. A government issues a directive; the bank acts on it; the account is frozen. Courts can review the legality of that action afterward — two Canadian courts have since found the invocation of emergency powers unlawful — but a ruling that a freeze was illegal cannot unfreeze the weeks of frozen funds, missed payments, and real consequences that accrued while the legal process ran its course. Due process arrives after the harm. The freeze arrives first.
2.3 CBDCs: Formalizing the Architecture of Control
More than 140 countries are exploring Central Bank Digital Currencies. The stated rationale is compelling: financial inclusion, payment efficiency, real-time settlement. Governments are right that their citizens want faster, cheaper, more accessible payments. Where CBDC advocates are either mistaken or disingenuous is in what they describe as the instrument delivering those outcomes.
A CBDC is not a digital version of cash. Cash is unconditional: it works for any transaction, in any location, for any person, without third-party approval. A CBDC is a digitally issued currency whose terms of use are set and enforceable by the issuing authority. The capabilities being built into CBDC architectures globally represent not a new invention but the systematic encoding into monetary infrastructure of precisely the access capabilities that have historically been exercised situationally through the banking system. The CBDC proposal formalizes into money itself:
- Expiry dates — money that must be spent within a defined period or is forfeited, eliminating savings and mandating consumption on the state’s schedule. In China's digital currency pilots, local governments have already issued handouts that could be spent only at designated merchants and were withdrawn if not spent by a deadline.
- Spending category restrictions — transactions for non-approved goods or services blocked at the infrastructure level, without the need for a court order or individual review.
- Geographic limits — money whose use is restricted to defined jurisdictions.
- Behavioral conditions — purchasing power made contingent on compliance with state-defined criteria. Western proposals disclaim such features, but they rest on the same issuer-controlled ledger that would permit them, and a decision not to use a capability is a policy, not a limit.
- Administrative freezes without due process — wallets blocked instantly by algorithmic flag or administrative directive, with no court order, no individual notice, and no right of challenge before the freeze takes effect.
As Max Raskin and Richard Epstein have argued, the surveillance capabilities of such an architecture do not require authoritarian intent to produce authoritarian outcomes: administrations of every political character would be able to observe, restrict, and reverse any financial decision their citizens make. The danger is in the architecture, not in the character of any particular administration that inherits it.
The CBDC is not the future of cash. It is the conditional replacement for cash — delivering digital payment efficiency while removing the individual civil rights that make money an instrument of human freedom rather than state control.
2.4 Centralized Stablecoins: Going Backwards
The United States, through the GENIUS Act, chose a different path from CBDC: a regulated private stablecoin framework. This path is healthier in principle — private issuers rather than state-issued currency. But its implementation has produced instruments that are, in the relevant sense, already conditional money. The freeze function is not a theoretical capability. It is in active, daily use.
By July 2026, Tether and Circle together had frozen more than $5.7 billion across nearly ten thousand addresses. These include, in many cases, legitimate enforcement actions. But the mechanism that enables legitimate enforcement is identical to the mechanism that enables illegitimate enforcement: a single administrative decision, executed instantly, with no judicial review required at the moment of execution and no prior notice to the affected party.
On March 23, 2026, Circle froze USDC balances in sixteen unrelated business hot wallets — exchanges, casinos, forex platforms, payment processors — in response to a sealed civil court order in a private commercial dispute. Among the frozen addresses was the ckETH Minter smart contract operated by the DFINITY Foundation — public blockchain infrastructure processing transactions for thousands of users who had no relationship to the litigation whatsoever. Several of the wallets, the bridge contract among them, were released days later — not through any process open to their owners, but after public criticism. One compliance decision, structurally unlimited blast radius.
The problem is not that Circle complied with a court order. The problem is architectural: a single company, exercising a single administrative key, can instantly freeze the operational infrastructure of multiple unrelated parties with relief available only after the fact — by litigating against an order they were never party to, or by public pressure — and a blast radius limited only by what that key can reach.
The capability is also poorly aimed. Because a freeze must be executed by a controlling party, and because that party’s actions are visible on a public ledger before they take effect, the parties being targeted are the ones best equipped to escape.
The trajectory of technology development in this space is moving in the wrong direction. Emerging approaches are being applied to digital currency systems in ways that deepen the problem rather than resolve it. Encryption is being used to let an issuer enforce spending restrictions, freeze functions, and compliance conditions on a balance it never decrypts. Such systems claim to protect privacy in a narrow technical sense while giving issuers and governments more, not less, programmatic control over how money can be used. A currency whose ciphertext an issuer can computationally condition is not private money. It is supervised money with better optics. Any architecture that retains an administrative key — regardless of how that key is implemented, including through encryption — preserves the structural properties that made the 1933 gold confiscation, the 2002 Argentine deposit conversion, and the 2022 Canadian bank freeze possible.
2.5 Your Keys, Your Money?
“Not your keys, not your coins” states a mathematical property of cryptographic systems: whoever holds the private keys to a wallet controls what happens to its contents. In traditional banking, control flows from the regulator to the institution to the depositor — which is why a government can direct a bank to freeze an account without ever engaging the account holder directly. Self-custody inverts this relationship: control flows from cryptographic proof to the keyholder, and no instruction to a third party can redirect it.
The right to hold money without depending on any intermediary’s cooperation is the digital equivalent of the right to hold cash. DDCP cannot prevent governments from passing laws. But the critical structural distinction is this: a law directing a custodian to hand over its records — as EO 6102 directed banks, as Argentina’s decrees directed the banking system — is a single instruction to a concentrated intermediary. A law requiring individual physical access to each holder’s private keys, at the scale of a society, is a different kind of enforcement entirely. It requires reaching every individual holder separately, not issuing one instruction to one institution.
This distinction becomes precise when applied to centralized stablecoins. With USDC or USDT, you can hold the private keys to your own wallet — in the technical sense, you are the keyholder. And yet you do not truly own your money. An issuer that retains an administrative key at the token contract level, independently of any keys you hold, has made a specific design choice: your access to the value is conditional on their restraint.
Your keys grant you access to your wallet address. If the issuer holds a master key to the value inside, your control is conditional on their restraint — and restraint is not an architecture.
III. Our Commitments
This Manifesto is published by DDCP Foundation Inc, which stewards the protocol but does not control the currencies built using it. It sets out the protocol’s properties, the Foundation’s commitments, and the conditions a currency must meet. A currency that meets all of them is called here a conforming currency.
DDCP’s commitments are commitments to the four qualities of better money — not to a particular technical implementation, but to the direction the design is oriented and the lines it will not cross regardless of pressure. They begin with the commitment from which everything else follows.
Your Keys, YOUR Money — Truly Yours
Satoshi Nakamoto’s contribution to the problem of sound money was not the invention of digital currency. It was the demonstration that digital property rights could be asserted through cryptographic proof and decentralized consensus, working toward the elimination of the trusted third party as the authoritative record-keeper.
“Not your keys, not your coins” is the foundational principle of self-custody in digital assets — the recognition that if you do not hold the private cryptographic keys to your digital wallet, you do not truly control your holdings. DDCP’s first and most important commitment is to make the second half of that principle equally true: if you do hold your keys, you do truly control your money. Only you. Not the issuer. Not the government. Not any intermediary.
That second half is not guaranteed by any centralized stablecoin. You can hold your own wallet keys and still have your stablecoins frozen — because the issuer holds an administrative key that operates independently of any keys you hold. The promise “not your keys, not your coins” protects you from custodial loss. It does not protect you from the issuer’s master key. The two sides of the principle are not symmetric: one is a property of cryptography; the other is, so far, only a property of restraint.
A holder who decides to leave can leave. Anyone holding a token that a third party can freeze retains that option only until someone else decides otherwise: the exit exists right up to the moment it is needed, and then it does not. Where no such key exists, the timing of the decision belongs to the holder — which is the whole of what the episodes above took away.
DDCP removes the concentrated intermediary from the equation, so that the gap between political will and financial control is the full distance between government power and individual private keys.
DDCP commits to making both sides real by design. No administrative override key in the protocol. A conforming currency carries no master key held by any issuer, government, or intermediary. If you and only you hold the private keys to your wallet, then you and only you control the conforming currency inside it — as a structural property of the protocol, not as a promise any company can keep or revoke.
On Unconditionality
The commitment to unconditionality flows directly from the commitment to genuine self-custody. A protocol that delivers “your keys, your money” as a structural fact must also never introduce the conditions that would hollow it out. We will never introduce, and will resist any proposal to build, any of the following into DDCP:
- Administrative freeze functions of any kind
- Spending restrictions limiting what value can be exchanged for
- Expiry conditions causing holdings to lapse
- Behavioral conditions making access contingent on compliance with external criteria
- General-purpose programmable logic deployable by third parties at the protocol layer — which would create vectors through which the above could be reintroduced
These are not implementation gaps to be filled later. They are architectural commitments — the negative space that defines what DDCP is.
A currency whose transfers can be stopped at the point of settlement is conditional money, whatever its other properties. The absence of a key is not sufficient if the infrastructure that completes a transaction can be instructed to refuse it. This protocol’s aim is that no single government can determine whether a transfer settles — not by holding a key, and not by holding the machines that confirm it. Bitcoin has shown for more than a decade and a half that settlement can be placed beyond the decision of any single government. Carrying that property to currencies with the additional qualities described here is work that remains to be done.
The history of monetary systems is a history of sound rules bent under sufficient pressure. Monetary institutions subject to human discretion will, in moments of crisis or sufficient political pressure, exercise that discretion in ways that benefit whoever holds the pressure — not as a moral failing, but as a structural inevitability. The design question for sound money is not whether to trust the right people. It is how to build an architecture that remains sound even in the absence of trustworthy people, or in the presence of trustworthy people under sufficient pressure.
No single crisis and no single government should be sufficient to override these properties — that resistance must be built in, not relied upon.
On Financial Privacy
Financial privacy is not a feature. It is a civil right — the right to exchange value, to hold savings, and to participate in economic life without being subjected to permanent, automatic surveillance by the state or by any private entity that can be compelled to act as its proxy.
In the Canadian episode of February 2022 the order did not stop at banks. Police circulated a list of cryptocurrency addresses to exchanges and directed them to halt transactions, and a parallel civil injunction reached more than a hundred addresses and nine platforms. Where a custodian held the keys, the funds were frozen exactly as bank accounts were. Where holders held their own keys, they were not — one self-custodial provider replied that it had nothing to hand over. But every one of those addresses was permanently visible. A transparent ledger meant that participation in a protest, once funded on a public chain, became a permanent record available for retrospective targeting by whoever later decided it mattered. Self-custody defeated the freeze. It did not defeat the surveillance. Better money requires both.
Five dimensions of financial privacy matter: the balance held in an account, the amount of each transaction, the identity of the initiating party, the identity of the receiving party, and the timing and frequency of activity. The stakes are immediate and personal. Not only your salary should be private; what you do with it — which doctors you see, which causes you fund, which businesses you build — is your private matter. Your business’s supplier relationships and payment flows are competitively sensitive. Your personal spending reflects your beliefs, your health, your relationships. A monetary system without financial privacy does not protect any of these.
DDCP commits to building toward meaningful privacy across all five dimensions — privacy that is real for the overwhelming majority of legitimate users, and that preserves lawful access to identity and records at the points where people enter and leave the system, through judicial process rather than administrative override.
On Crime
That commitment invites a harder question, and it deserves a straight answer. Crimes are acts, committed by people. A currency is a thing, and like every store of value before it, it can be one of the means by which the benefit of a crime is carried away, as cash has been, as gold has been. Digital value moves faster, easier, further, and in larger amounts than banknotes, and we do not pretend that makes no difference. But the question a society should ask is not whether an instrument can be abused, because all of them can. It is what everyone is required to surrender in order to prevent that abuse, and whether the prevention works.
In the case of digital currencies what is required to be surrendered to prevent criminal abuse is total: permanent, automatic, retrospective visibility of every economic act of every person, without individualized suspicion, and capability to seize it, by default.
What is obtained in exchange is marginal. A peer-reviewed study of the global anti-money laundering regime, published in Policy Design and Practice in 2020, found that it intercepts roughly three billion dollars of an estimated three trillion dollars in criminal funds generated each year — a success rate of about 0.1 percent — while costing banks and other businesses more than three hundred billion dollars a year in compliance, over a hundred times the amount recovered. Its author, who cautions that the underlying data are poorly validated, calls it the world’s least effective policy experiment. The cost of that machinery falls on the billions of people who have done nothing.
The distinction we hold is procedural. Enforcement directed at an identified person, through judicial process, with evidentiary standards and a right to be heard, is legitimate. Enforcement directed at an account address, by executive will, with no named person and no hearing, is what this protocol does not support. That is the same procedural distinction liberal societies have applied to every other form of coercive state power.
A court can compel a person. It can compel the institutions that hold that person’s money. What it cannot do is reach value held in self-custody without going through the holder — the same position it has always occupied with cash, and with any other property a person keeps themselves, where enforcement means an order served on a named individual rather than an instruction sent to an institution. That limit is not something this protocol introduced. It is what the digitization of money removed, and what this protocol restores.
Lawful investigation remains possible. Identity exists at the boundary, where people enter and leave this system through licensed intermediaries that are subject to legal process like every other financial institution. Between two people who hold their own keys, a transfer should be as private as cash has always been.
Privacy is not an exemption from law. DDCP does not propose to change anyone’s legal obligations, and provides no mechanism for avoiding them. Legal obligations do not depend on being observed: they applied before third-party reporting existed, and they apply today to every cash transaction that no one records. What universal financial surveillance changed is not what people owe, but the decision to watch everyone continuously in order to collect it.
DDCP makes no claim to improve a jurisdiction whose institutions are captured. No monetary design has ever done that. But where capture has occurred, a surveillance-and-freeze architecture has never been a safeguard. It has been an instrument available to whoever did the capturing.
On Value Preservation
The long-term commitment is toward a value anchor rooted in the consumption basket of the real economy — globally traded productive commodities, the energy, agricultural products, and industrial inputs regularly demanded by the global economy. A value preservation instrument anchored in consumption has no sovereign who can debase it and no central bank whose commitment requires trusting. DDCP Foundation commits to stewarding the protocol so that the path toward The Better Money remains open. How that horizon is realized — by whom, with what reserve composition, in what form — is a question the market will answer over time, consistent with the competing currencies framework this protocol enables.
DDCP currencies pegged to a national currency are subject to whatever purchasing power their reference currency retains or loses. This is sufficient for most use cases: payments between any two parties regardless of where they are, remittances arriving without correspondent banking fees, payroll and contractor compensation across borders, access to stable digital value for anyone without a bank account, and trade and business operations on unconditional terms.
A conforming currency is fully backed. Its reserves are held against whatever it promises to be worth: for a currency pegged to a national currency, one unit of that currency for each unit issued; for any other anchor, what that anchor defines. Full backing means the promise is covered. It does not mean the purchasing power of the promise is guaranteed — that depends on what the currency is anchored to, which is the subject of everything above. The reserve management function is separated from the issuance function and entrusted to an independent foundation — a structure that permits more binding rules and mandates than a commercial entity can sustain, operating without profit incentives that could compromise the obligation to maintain full backing. Each conforming currency’s reserves are ring-fenced, so that they stand behind no other currency’s obligations, and independently attested, so that backing can be verified rather than asserted. The same aim that applies to settlement applies to reserves: that no single government can reach a decisive share of what stands behind a currency. Where a currency’s regulatory framework constrains where its reserves may sit, that aim is not available to it, and the constraint belongs in that currency’s own specification.
On Honesty and the Long Game
We will document what the protocol cannot do and will not do. We will document known design boundaries and known risks. Where the protocol depends on infrastructure it does not control, we will document that dependency and its risks. We will be transparent about the gap between the commitments described in this Manifesto and the properties delivered at any given moment. We do not promise outcomes we cannot deliver. We do not claim technical properties that have not been built.
Some currencies built using this protocol will carry capabilities their issuers hold over them — required by a license in some cases, adopted by the issuer’s own choice in others. No issuer capability may be presented as a guarantee of this protocol, and no DDCP guarantee may be claimed for a currency that does not provide it. What any particular currency does and does not do is a question about that currency, not about this protocol. The answer is in its own published specification: which capabilities its issuer holds over it, under what conditions they may be used, and which of its properties were settled at issuance rather than left open to later change. Alignment with this document is a claim like any other, and a currency either provides these properties or it does not.
We cannot stop anyone from claiming alignment with what is written here. What we can do is be explicit about the currencies we ourselves recognize, and we will not describe a currency as meeting these commitments without having examined it. The absence of a statement from us is not an endorsement and not a judgment.
Progress here is not all-or-nothing. A currency that delivers some of what this Manifesto describes, and not the rest, is still better than what it replaces. We encourage and welcome work that moves money in this direction — built using this protocol or built elsewhere. What we ask of it is only that it state accurately what it delivers and what it does not, so that no one mistakes a step for the destination. The commitments in this Manifesto are the destination. They were never meant as the price of admission for trying.
This is a long-horizon project, measured in decades. The individuals who need this most are not the early adopters of the next technology cycle. They are the younger generations facing monetary conditions that today’s citizens cannot fully anticipate, in political circumstances that have not yet revealed themselves. We build for them.
There is no perfect money.
But there is better money — and people deserve access to it.
No expiry. No restrictions. No permission required.
Join us.