The 2-Bit Bitcoin Transmission That Proves Nothing Useful

CryptoVault
Price Analysis

A developer just sent Bitcoin from a device with no internet connection using Apple's Find My network. The throughput: 2 bits per signal. The security: nonexistent. The practical value: zero. The intellectual value: potentially significant. Here's why the distinction matters.

In late 2024, a Cashu ecosystem developer known as @callebtc posted a proof-of-concept on X that has been circulating in technical circles for the better part of a year. The claim: you can transmit Bitcoin value from a fully air-gapped device by encoding Cashu ecash tokens into BLE beacon signals, then relaying those signals through Apple's Find My mesh network β€” the same crowd-sourced infrastructure that pings your missing AirTag across continents. The experiment works. The experiment is also, by every measurable engineering metric, unviable as a payment mechanism.

The 2-Bit Bitcoin Transmission That Proves Nothing Useful

This is not a story about a breakthrough. It is a story about a data detective finding something interesting in the noise.

Context: What Cashu Actually Is, and Why This Matters

Cashu implements Chaumian ecash on Bitcoin. David Chaum sketched the cryptographic proof in 1982. Cashu builds on that lineage: a trusted mint receives Bitcoin, issues bearer tokens backed 1:1 by that collateral, and lets users transact those tokens without revealing identity to counterparties. The privacy is real. The custody dependency is also real β€” you are trusting the mint not to freeze, overspend, or vanish. Every Cashu token is a digital IOU that moves like cash: possession is ownership, and if someone intercepts it, it is gone.

The Find My experiment layers a transmission layer on top of this. An ESP32 microcontroller β€” the $4 open-source development board found in hobbyist electronics projects worldwide β€” simulates an AirTag BLE beacon. The beacon broadcasts a 2-bit payload on each cycle. A nearby iPhone, running Apple's Find My service, picks up that signal and relays it through Apple's servers. The recipient retrieves the accumulated bits using an Apple account and reconstructs the Cashu token.

The architecture is elegant in the way a Rube Goldberg machine is elegant. The performance is, frankly, catastrophic.

The Core Problem: A Security Model Built on Two Broken Assumptions

Based on my audit experience tracing FTX wallet flows in 2022, I have developed what I consider a non-negotiable standard: if you cannot point to an encrypted, authenticated, and permissioned path for value transfer, you do not have a payment system. You have a public bulletin board with money written on it.

This experiment fails all three conditions. First, the payload is unencrypted. Second, the Cashu token ID is broadcast in plaintext. Third, the bearer token itself requires no authentication to spend. The result is that any third party within BLE range β€” any passing iPhone, any curious developer with a USB BLE sniffer, any automated bot farm β€” can intercept the signal, reassemble the token, and immediately spend it. The token is not just exposed; it is broadcast. There is no distinction between sending and giving up ownership.

The throughput compounds the disaster. At 2 bits per signal, a single Cashu token requires over 1,000 broadcast cycles to transmit completely. This is not a bandwidth optimization problem β€” it is a fundamental mismatch between the carrier medium and the payload. The experiment's author acknowledges that only "gift-level" amounts should be sent through this channel. That is not a limitation. That is a disqualification from every meaningful use case.

The 2-Bit Bitcoin Transmission That Proves Nothing Useful

What I Think Is Actually Being Demonstrated

After reading through the technical writeup and tracing the architecture, I suspect the true thesis of this experiment is not "here is a new payment channel." The true thesis is: Apple's Find My network constitutes an unmonitored, physically distributed data channel that can carry arbitrary payloads, and no one has quantified its abuse surface.

This is the more interesting claim. And it is a claim with regulatory implications that no one in the crypto space has seriously mapped.

The Find My network is a crowd-sourced relay system. Millions of iPhones act as anonymous routers for BLE beacons. This is, functionally, a covert channel β€” information smuggled inside legitimate traffic. The experiment does not break a security boundary; it exploits a design gap in Apple's assumption that BLE beacons will only carry AirTag location data. The gap is not a vulnerability in the traditional sense. It is a purpose deviation β€” the network accepts any beacon-shaped payload without validating its semantic intent.

This matters because it means the abuse surface is not theoretical. It is demonstrated. And it is one developer, one weekend, and a $4 microcontroller away from being reproducible by anyone with curiosity and an ESP32.

The Apple Dependency: The Parasitic Architecture Problem

Every serious infrastructure project has a single point of failure. Lightning Network's SLP depends on Bitcoin consensus. Cashu depends on mint solvency. This experiment depends on two external actors simultaneously not breaking it: Apple must not deprecate the unofficial Find My interface, and the Cashu mint must not close.

Based on my analysis of the 2024 ETF inflow mechanics, I know that institutional capital flows create mechanical market pressures that no one can opt out of. Apple's Find My interface is not a protocol. It is a product feature with terms of service, legal exposure, and a corporate security team that reviews third-party integrations. The experiment uses an unofficial interface. Apple can patch it with a firmware update. They can rate-limit beacon parsing. They can add payload validation that rejects non-AirTag beacon formats.

This is not a risk that engineering can solve. It is a structural dependency on a counterparty's continued goodwill. Every time I see a project architecture that parasitizes a single corporation's infrastructure without that corporation's explicit endorsement, I flag it as a high-severity existential risk. This is no exception.

The Correlation-Causation Blind Spot

The media framing of this story leans heavily on the "Bitcoin payment is becoming more accessible" narrative. That narrative is wrong. Or more precisely, it is conflating demonstrating a path exists with demonstrating a path is usable. These are not the same thing. The difference between a proof of concept and a product is not narrative β€” it is throughput, security, reliability, and regulatory compliance. This experiment has none of those.

What the experiment does prove is that a physically distributed, mesh-relayed data channel exists that is not currently audited, rate-limited, or semantically validated. That is a finding about Apple's infrastructure, not about Bitcoin's payment layer. The Cashu component is almost incidental β€” any data could have been transmitted through this channel. The fact that the payload happened to be a bearer token is what makes the story newsworthy, not technically relevant.

Correlation is a map, but causation is the terrain. The experiment correlates with "new Bitcoin payment path." It does not cause one. The terrain between the map and reality is 1,000 broadcast cycles, zero encryption, and a corporate terms of service.

What I Would Actually Track

If I were building a Dune dashboard to monitor this development, I would not track Cashu mint volume. I would track three things: First, whether Apple modifies its Find My beacon parsing behavior in any iOS or macOS update β€” a subtle change in beacon validation logic would be the first signal of tightening. Second, whether GitHub forks of the original repository introduce encryption or error-correction coding β€” that would signal a transition from novelty to research. Third, whether any regulatory body issues guidance on the classification of ecash transmitted through unauthorized relay networks β€” the AML angle is the one that could actually kill this direction.

I would also monitor whether the same developer publishes a follow-up that addresses the encryption gap. The 2-bit bandwidth is physically incapable of carrying a key exchange protocol β€” that is a hard constraint. But if someone builds a hybrid approach that uses the Find My channel for one-time pad generation with pre-shared secrets, that would be a genuine architectural advancement. I have not seen that yet.

The Takeaway

This is not a payment innovation. It is a covert channel discovery. The Cashu token is a convenient payload, not a meaningful contribution to Bitcoin's payment layer. The real question β€” the one that would be interesting to answer with actual data β€” is whether Apple's Find My network can be reliably and durably abused as a data transport, and what the legal and technical cost curve of defending against that abuse looks like. Until someone publishes a quantitative model of Find My's abuse surface, this experiment remains a curiosity with a $4 hardware budget and a corporate dependency that could disappear overnight.

The next time someone tells you Bitcoin payments are becoming "as easy as sending a text," I want them to show me the throughput, the encryption, and the compliance audit. A 2-bit beacon signal is not a text message. It is a whisper in a crowded room, and everyone is listening.