Fedimint Runs Three Independent Codebases in One Live Federation
At Ecash Hackday Berlin on September 30, Fedimint developers ran a single federation across three independent implementations. The next day, Calle unveiled Federated Cashu at bitcoin++. Two teams, one week, one shared problem solved.

The Berlin demos are the first concrete evidence that ecash custody is breaking out of single-implementation fragility.
Key takeaways
- At Ecash Hackday Berlin on September 30, 2026, Fedimint developers ran a single federation across three independent implementations, with Cashu's
thesimplekidbuilding one of them. - On October 1 at bitcoin++ Berlin, Calle unveiled Federated Cashu: a 4-of-5 threshold federation scheme using a new blind BLS signature scheme, extending fault tolerance beyond Cashu's current single-operator model.
- Together, the two advances mark the first publicly demonstrated progress against the software monoculture problem that leaves every Fedimint federation on earth exposed to the same zero-day simultaneously.
Fedimint was built to distribute trust across humans. The flaw: every guardian in every federation was running the exact same codebase. One critical bug in that Rust implementation and the entire protocol surface is vulnerable at once. On September 30 at Ecash Hackday Berlin, that floor got addressed. Three independent teams brought three separate codebases to a single federation, according to Obi Nwosu, Co-Founder of Fedi and Fedimint, writing in a first-person account published October 6.
The following day, Calle took the same fault-tolerance principle and applied it to Cashu's single-operator model, unveiling Federated Cashu at bitcoin++ Berlin on the Main Stage.
What Happened in Berlin
Eric "elsirion" Sirion posted from Ecash Hackday on September 30:
"Had a great time at Ecash Hackday in Berlin, got a Fedimint running with 3 different implementations by @thesimplekid, me and the Fedimint team! Already got 3 Fedimint implementations now, who will build the 4th one?"
The three implementations came from thesimplekid (a Cashu Dev Kit contributor), elsirion independently, and the Fedimint core team. The elsirion/minimint-ng GitHub repository corroborates a separate guardian implementation built from the Fedimint spec, though that work was already underway before the hackday. Three codebases, one federation.
At bitcoin++ the next morning, Calle unveiled Federated Cashu. Per Matthew Vuk (@matthewvuk2), reporting from the Main Stage: Calle described a scheme where any 4-of-5 operators keep a federation running, built on a new blind BLS signature scheme. Calle's framing: "You don't need to trust the operator with your privacy, but you do need to trust the operator with your security." Any combination of 4-of-5 continues the federation.
Nwosu's account puts the monoculture critique plainly: "We built it to remove single people and single institutions as points of failure. But there was just one implementation of the protocol, a software monoculture below federations of humans. Not secure enough." He cites the Coldcard entropy bug and the Liquid federation drain as recent examples of what single-implementation fragility costs users.
Why the Monoculture Problem Matters
Fedimint's human-federation model was always the custody pitch: no single person controls the funds, threshold signing distributes the trust. But the software layer underneath that was a single point of failure. Every guardian globally ran identical code. A single CVE, a single jurisdiction's software ban, a single vendor compromise could sweep everything at once.
The Berlin demo is the first public evidence that this has changed. Independent failure domains at the software layer mean no single bug takes every federation simultaneously. Guardians can run different implementations while the users behind them see nothing change in their wallets. This is infrastructure-layer progress, not a product update.
Federated Cashu adds a second vector. Cashu's existing model requires trusting a single operator with security. The 4-of-5 scheme removes that single point. Two separate protocol families, Fedimint and Cashu, are now converging on overlapping fault-tolerance primitives. The ecash custody layer is getting structurally harder to kill.
The competitive distance from exchange custody widens with every step here. Coinbase, Binance, Kraken: single company, single codebase, single regulator. The ecash trajectory is multi-implementation, multi-jurisdiction, multi-hardware. Those are not the same risk profile, and anyone holding funds on a custodial exchange should understand the difference.
What to Watch
Nwosu laid out five independence layers the ecosystem still needs to close: multiple protocol implementations, multiple wallet implementations, keys generated on hardware from different vendors, multiple independent people behind every federation, and distribution across geographies and jurisdictions. The Berlin week moved two of those five. The remaining three, hardware diversity, operator independence, and jurisdictional distribution, are the next benchmarks worth tracking. Whether the multi-implementation federation holds under production conditions with real bitcoin at stake is the test that matters most.
Sources
Frequently Asked Questions
What is a software monoculture and why does it matter for Bitcoin custody?
A software monoculture means every node or guardian in a network runs the same codebase. If a critical bug exists in that code, it is exploitable across every deployment at once. For Fedimint, that meant every federation globally shared the same vulnerability surface. The Berlin demo introduced independent codebases into a single federation, creating separate failure domains so one bug cannot sweep everything simultaneously.
How is Federated Cashu different from regular Cashu, and does anything change for users?
Standard Cashu requires trusting a single mint operator with the security of funds. Federated Cashu introduces a 4-of-5 threshold scheme: any four of five operators can keep the federation running, and the mint continues even if one operator goes offline or is compromised. Nothing changes wallet-side. This is a guardian and operator infrastructure upgrade.
Does this mean Fedimint and Cashu wallets can now send to each other?
No. The interoperability demonstrated in Berlin is at the guardian and protocol-implementation layer, not the wallet layer. Three different Fedimint codebases can now run the same federation. That is not the same as cross-protocol payments between a Fedimint wallet and a Cashu wallet. Those remain separate.


