“Bitcoin: A Peer-to-Peer Electronic Cash System”
‘The Complaint alleges that Defendant and David Kleiman ("David Kleiman" or "Mr. Kleiman") were former business partners that created Bitcoin under the pseudonym Satoshi Nakamoto. Between 2008 and before David Kleiman's death in April 2013, the two allegedly worked together on Bitcoin, mining bitcoins and developing blockchain related intellectual property. Starting in 2008 through February 2011, they allegedly worked together as a partnership, and from February 2011 until Mr. Kleiman's death in 2013, they conducted their work through Plaintiff W&K Info Defense Research LLC ("W&K"). During this period, significant amounts of bitcoins allegedly were mined and acquired by Defendant and Mr. Kleiman and valuable intellectual property was developed. This lawsuit concerns a dispute over the ownership of bitcoins and Bitcoin-related intellectual property. The Complaint alleges that following David Kleiman's death, Defendant perpetrated a fraudulent scheme to seize Plaintiffs' bitcoins and their rights to certain blockchain related intellectual property. This scheme included, among other things, producing fraudulent documents and forging David Kleiman's signatures on documents to purportedly show that David Kleiman transferred to Defendant bitcoins and intellectual property rights belonging to David Kleiman and W&K before David Kleiman's death. Since then, Defendant has taken sole ownership and control over the bitcoins and related intellectual property and refuses to return any bitcoins or intellectual property to either the estate or W&K. Plaintiffs seek relief against Defendant through various causes of action: …’
‘If that is correct, then the 95 documents are at least very strong evidence that Dr Wright is Satoshi Nakamoto, as is clear from their nature and contents.’
‘34. The White Paper LaTeX Files are therefore of the highest possible importance for the trial of the Identity Issue, and that issue cannot fairly be determined unless Dr Wright is entitled to rely on these documents and have his case on the significance of these documents addressed in expert evidence.’
“There is only one rule of law, namely that the occurrence of the fact in issue must be proved to have been more probable than not. Common sense, not law, requires that in deciding this question, regard should be had, to whatever extent appropriate, to inherent probabilities. If a child alleges sexual abuse by a parent, it is common sense to start with the assumption that most parents do not abuse their children. But this assumption may be swiftly dispelled by other compelling evidence of the relationship between parent and child or parent and other children. It would be absurd to suggest that the tribunal must in all cases assume that serious conduct is unlikely to have occurred. In many cases, the other evidence will show that it was all too likely.”
“Neither the seriousness of the allegation nor the seriousness of the consequences should make any difference to the standard of proof to be applied in determining the facts. The inherent probabilities are simply something to be taken into account, where relevant, in deciding where the truth lies.”
‘…the forgery allegations are of the utmost seriousness and would, if established, do great damage to Dr Wright’s reputation and future endeavours. Although it was confirmed by the Supreme Court in Re B (Children)[2008] UKHL 35 that there is only one civil standard of proof (the balance of probabilities), the courts have maintained that, in general, it is legitimate and conventional, and a fair starting point, that fraud and dishonesty are inherently improbable, such that cogent evidence is required for their proof; see Males LJ at [117] of Bank St Petersburg PJSC v Arkhangelsky[2020] 4 WLR 55 and Teare J in JSC BTA Bank v Ablyazov[2013] EWHC 510 (Comm) , at [76]).’
‘22. In the light of these considerations, the best approach for a judge to adopt in the trial of a commercial case is, in my view, to place little if any reliance at all on witnesses’ recollections of what was said in meetings and conversations, and to base factual findings on inferences drawn from the documentary evidence and known or probable facts. This does not mean that oral testimony serves no useful purpose – though its utility is often disproportionate to its length. But its value lies largely, as I see it, in the opportunity which cross-examination affords to subject the documentary record to critical scrutiny and to gauge the personality, motivations and working practices of a witness, rather than in testimony of what the witness recalls of particular conversations and events. Above all, it is important to avoid the fallacy of supposing that, because a witness has confidence in his or her recollection and is honest, evidence based on that recollection provides any reliable guide to the truth.’
‘23. … Memory plays tricks on people. It is perfectly possible for an honest witness to have a firm memory of events which they believe to be true, but which in fact is not correct. … 30. Although Leggatt J’s words have been sometimes taken as an encouragement to place no reliance on witness recollection, particularly when there is an abundance of reliable contemporaneous documentation, the Court of Appeal has confirmed that the assessment of the credibility of a witness’ evidence should be a part of a single compendious exercise of finding the facts based on all of the available evidence; see Kogan v Martin[2019] EWCA Civ 1645 and Natwest Markets Plc, Mercuria Energy Europe Trading v Bilta (UK) Ltd (In Liquidation)[2021] EWCA Civ 680 at paragraphs 50 and 51. 31. Each witness’s evidence has to be weighed in the context of the reliably established facts (including those which can safely be distilled from contemporaneous documentation bearing in mind that the documentation itself may be unreliable or incomplete), the motives and biases in play, the possible unreliability or corruption of human memory and the inherent probabilities. Where there is reliable contemporaneous documentation, it will be natural to place weight on that. Where documents add little to the analysis, other secure footholds in the evidence need, if possible, to be found to decide whether it is more likely than not that the witness’ memory is reliable or mistaken.’
“The principles that govern expert evidence must be carefully adhered to, both by the experts themselves, and the legal advisers who instruct them.”
“So far as possible, tribunals should feel free to draw, or to decline to draw, inferences from the facts of the case before them using their common sense without the need to consult law books when doing so. Whether any positive significance should be attached to the fact that a person has not given evidence depends entirely on the context and particular circumstances. Relevant considerations will naturally include such matters as whether the witness was available to give evidence, what relevant evidence it is reasonable to expect that the witness would have been able to give, what other relevant evidence there was bearing on the point(s) on which the witness could potentially have given relevant evidence, and the significance of those points in the context of the case as a whole.”
“(a) whether it would have been reasonable and practicable for the party by whom the evidence was adduced to have produced the maker of the original statement as a witness; (b) whether the original statement was made contemporaneously with the occurrence or existence of the matters stated; (c) whether the evidence involves multiple hearsay; (d) whether any person involved had any motive to conceal or misrepresent matters; (e) whether the original statement was an edited account, or was made in collaboration with another or for a particular purpose; (f) whether the circumstances in which the evidence is adduced as hearsay are such as to suggest an attempt to prevent proper evaluation of its weight.”
‘Pursuant toCPR PD1A , the Court shall adopt for the evidence of Dr Wright at trial the adjustments agreed upon by the parties experts in ASD, namely (a) there being clear timetabling of Dr Wright’s evidence; (b) him being given access to a pen and paper; (c) him being given access to a real time transcription screen; (d) there being a lower threshold for breaks in evidence, particularly if he becomes emotionally dysregulated; and (e) follow-up questions being relatively shorter in the event of Dr Wright becoming emotionally dysregulated.’
‘Q. {L11/54/1}, please. This is an email dated25 November 2015 , ostensibly from you, “cwright@tyche.co.uk", to Mr MacGregor and others. Do you say that this is another non-genuine email, something you didn't write? A. I didn't write it, no. Tyche is a British company belonging to Rob that I never worked for. Q. So all this content saying -- referring to the original White Paper being a good start and engaging with Mr MacGregor's ideas, that's all fake content, is it? A. I've no idea what it is. Q. Are you aware who supposedly created these non-genuine documents, Dr Wright? A. Probably someone at Tyche. Q. Who are you fingering for this? A. I've no idea.’
“Fuck. WTF is wrong with him. Well, at least we have NCH [nChain] to focus on, that’s not fake.”
‘Q. But you were introducing two people in the context of a project about cryptocurrencies and you're saying it doesn't occur to you to mention that one of them is the inventor of the whole Bitcoin cryptocurrency blockchain system? A. I didn't want to go to that level of detail, I wanted to introduce two people and let them find out if they had a way of working together. Q. It's not a level of detail; it's one sentence on something which you've told us had not been a matter of secrecy. A. I did not disclose that at the time to MacGregor. Obviously MacGregor found out later.’
‘During the time I was at CBA, which was from October 2022 [sc.2002] until January 2008, Craig and I talked about a whole range of things over that five or six year period: we had a common interest around some stuff that in hindsight related to Blockchain and Bitcoin (I first heard the word Blockchain in late 2008, after I left CBA; I don't remember precisely when I first heard the word Bitcoin, but it was later than that).’
‘Did he show you anything?’
‘96:19 Did he show you anything? 20 A. I do. I do remember seeing a couple of things, besides 21 what Craig drew on the napkin. At a -- at a subsequent 22 meeting, I was shown a paper. It didn't make mention of 23 Bitcoin but it did make mention of -- of something 24 called Timecoin, and that was something that -- as 25 a White Paper that he -- he showed me at that time. 97: 1 Q. You said a bit later. When was that? 2 A. It would have been in that time window I was saying. It 3 was before I joined Westpac and -- and after those 4 series of lunches where he drew on the -- on the napkin. 5 So, around, again, 2009/2010.’
‘Q. I'm going to show you a document and I want to ask you 17 if you recognise the document. Could you be shown -- or 18 could we look at {CSW/31/1}. That's a Timecoin paper, 19 "A peer-to-peer electronic cash system", with 20 Craig Wright's name at the top of it. Do you recognise 21 that document? 22 A. As far as I can recollect that far back, because this 23 isn't something that was discussed in the -- in 24 the Granath court case, but, yes, it does look certainly 25 similar to the document I saw, yes.’
“these were notes I took during the course of this interaction rather than anything I wrote down before the interaction”
‘It may be possible to come to a more concluded view if I was provided access to the computing systems used to author and store this document and the emails associated with it.’
‘120. Other than the visual observations I make above, I do not comment on or consider the content of the document of as this is outside of my expertise, though I have seen the comments made in the Twentieth Witness Statement of Philip Nathan Sherrell. 121. While I have found no anachronistic metadata characteristics within this document itself in the time available to me, I have made several observations that bring it into contrast with the Bitcoin White Paper control copy {ID_000865}. This is to say that the document has been assembled in a different manner to {ID_000865} and does not appear to have been produced from the OpenOffice document used to create {ID_000865} (and it also does not appear to come from {ID_000254}, a document which I understand is said to be related). 122. The same OpenOffice document could not have been used without undergoing significant changes to the formatting and style of the document as well as its content, and the diagrams have been replaced with relatively low-quality static pictures instead of flowchart-style graphic drawings. 123. I also note that the OpenOffice software version 3.0 that was used to author {ID_006565} is still available for download today from Internet resources, and it would have been possible to create a document identical to ID_006565 by downloading and running that software on a computer (or virtual computer) with a backdated clock. The manner in which the email message to which the document was attached has been disclosed is less than ideal and does not allow me a full picture for forensic analysis. 124. The copy of the ZIP file that was created on the Samsung drive has been attributed with timestamps of31 October 2017 , a date I have attributed with significant backdating behaviour on the Samsung drive {G/6/13}.’
“Memory is a bit foggy of my playing to link as part of the network in the way that you advised”
‘Project Chrono is not a time library as std::chrono is. It is a physics simulation library. One would not modify a physics simulation library to come up with a time library. The similarities between Project Chrono and the C++ standard header <chrono> end with the name “chrono”.’
‘…Project Chrono does not even use class types to model time units like the standard library does. It typically uses the built-in type double instead. So, Dr Wright claims to have invented the namespace std::chrono and the class type milliseconds, identical in syntax to what would be proposed for the C++ standard in the future. That strikes me as another remarkable coincidence.’ 261.3. Third: ‘In conjunction with “std::chrono::milliseconds”, Dr Wright’s code uses the syntax “std::this_thread::sleep_for”. This too would not be proposed for the C++ Standard until after the last file modification dates for the code files referred to in my first statement. That strikes me as a third remarkable coincidence.’
‘He did not transfer any bitcoin to me at any time. As I have explained above, he could not have done because I didn’t use Bitcoin until years later than it was launched.’
‘I remember reading this blog post when it first came out, and reading articles responding to it which argued that it was not a genuine signature, and instead reused an existing, public signature by Satoshi from the bitcoin blockchain. I remember that I looked at the blog post and myself verified that it took an existing signature by Satoshi and converted it into OpenSSL format rather than the Bitcoin format so it didn’t look the same as the original. The most obvious tell is that the signature could not be identical to one that was already used. In short, the signature in the blog post proves nothing; I formed the view that it was a deliberate attempt at making an old signature look like it was a recent one.’ ‘… I remember that when I reviewed the blog, it convinced me Craig Wright was not Satoshi…’
“Being the world’s most highly certificated cybersecurity expert, Wright knew how to secure the system. Having a Master of Laws, Wright understood how the system he created would interact with real society, including the legal and political systems. It all bears the marks of a deliberate Divine preparation for this creation, for where in the world can you find another person with all these necessary qualifications?”
‘To implement a distributed timestamp server on a peer-to-peer basis, we will need to use a proof-of-work system similar to Adam Back's Hashcash [6], rather than newspaper or Usenet posts. The proof-of-work involves scanning for a value that when hashed, such as with SHA-256, the hash begins with a number of zero bits. The average work required is exponential in the number of zero bits required and can be verified by executing a single hash. For our timestamp network, we implement the proof-of-work by incrementing a nonce in the block until a value is found that gives the block's hash the required zero bits. Once the CPU effort has been expended to make it satisfy the proof-of-work, the block cannot be changed without redoing the work. …’
‘Ideally, this evidence should have formed the factual background to Mr Madden’s analysis from the outset. Instead, this case has involved the reversal of the orthodox sequencing of factual and expert evidence, where the former comes first and forms the factual basis for the latter. As a result, the very lengthy detail of Dr Wright’s complex computer environment has received only cursory treatment by Mr Madden, across just over 2 pages of his fourth report.’
‘13 October 2023 {K/11/1}. Although the custody details provided by Dr Wright in this document were provided after service of Madden 1, COPA is not understood to have challenged them and they are consistent with Dr Wright’s original11 May 2023 Chain of Custody schedule at {M/1/778}, which also explained that the documents had been stored on third party devices.’
“a. At no stage during the course of its retainer with Dr Wright (across all litigation matters) did Dr Wright inform Ontier that (i) he had an Overleaf account; (ii) this account may contain documents or be capable of generating documents which may be relevant to the issues in dispute; and/or (iii) the Overleaf account hosted LaTeX code or files which would produce a copy of the Bitcoin White Paper; b. Ontier has never seen and/or received copies of any documents or material from Overleaf (whether LaTeX code or otherwise)”
“153: 5 Q. You were responsible for those edits, weren't you, 6 Dr Wright? 7 A. I was. 8 Q. So the file was being edited right up to the day before 9 the LaTeX files were received by Stroz Friedberg? 10 A. Yes. I demonstrated to Shoosmiths, making a small 11 change, adding a full stop, adding a percentage. And 12 where you say there are extensive edits, that's actually 13 not true. Adding a full stop, removing that full stop, 14 is actually two edits. So, when I add a space, that's 15 an edit. If I go percent, comma, slash, etc, that's 16 three edits. So, at one stage, I typed in Matt's, one 17 of my solicitor's, name. That was probably 10 edits. 18 I then undid it and put the original name back. So 19 I was demonstrating how using that, you could change 20 the date and produce a new version, etc. 21 Q. Dr Wright, first of all, this was a document which you 22 were going to present as being a perfect digital 23 watermark of the Bitcoin White Paper. Didn't it occur 24 to you, as an IT security expert, that you shouldn't be 25 mucking with it extensively over the period of time 154: 1 before you produced it? 2 A. I downloaded a copy of the file and gave it to 3 Shoosmiths before I did any of this. So, the first 4 thing is, I downloaded the ZIP from Overleaf, sent it to 5 the solicitors. We did that right at the beginning of 6 this process. And as such, once I've given them a copy, 7 I'm saying that I can't change the copy they have, 8 therefore my making changes and undoing those changes is 9 not a material change. 10 Q. Do you say that all of those edits were done in 11 the presence of Shoosmiths? 12 A. They were on videos, on calls, I sent them some emails 13 while they weren't on there, I sent, like -- 14 Q. You say that all these edits were done in their 15 presence? 16 A. Not in their presence. I emailed them. They weren't 17 there. And do you consider on a video call presence?”
“Dr Wright tells us that he cannot remember what those previous project folders were called or whether he copied them directly within Overleaf or copied them from local copies he had previously downloaded from Overleaf. In any event, Dr Wright says that he deleted the previous projects folders after copying their contents into Maths (OLD). As a result, Dr Wright says he no longer has the project folder used for the Overleaf demonstration to this firm earlier on17 November 2023 .”
“151:17 Q. So earlier, on 17 November, you had the so-called White 18 Paper LaTeX files in a different folder to Maths (OLD) 19 or the Bitcoin folder, right? 20 A. I copied it into my R drive and then uploaded into 21 multiple places for the demonstrations. 22 Q. And you have failed to produce the folder that held 23 those earlier files, haven't you? 24 A. Because I copied back and forwards between the others. 25 Q. You deleted it? 152: 1 A. No, I did not. I moved it. 2 Q. Can we go to {M1/2/210}. 3 This a letter from Shoosmiths, dated 420 February 2024 , so very recently, and we can see in 5 paragraph 2.1: 6 "As you note in Your Letter, the Maths (OLD) project 7 was created on17 November 2023 at 16:26 [pm] ..." 8 As I just put to you: 9 "Dr Wright instructs us that this project was 10 created by merging and/or copying files into Maths (OLD) 11 from previous Overleaf project folders. Dr Wright tells 12 us that he cannot remember what those previous project 13 folders were called or whether he copied them directly 14 within Overleaf or copied them from local copies he had 15 previously downloaded from Overleaf. In any event, 16 Dr Wright says that he deleted the previous projects 17 folders after copying their contents ..." 18 Why have you lied to me about that basic point, 19 Dr Wright? 20 A. I didn't. If you're talking about the previous things, 21 then, yes, I've deleted them multiple times. Overleaf 22 goes back quite a while, including multiple accounts. 23 And have I kept them? No. I've copied between 24 different Overleaf folders. 25 Q. I said specifically to you that you had deleted those 153: 1 previous folders, and you said, "No, I did not, I moved 2 it", is what you said. 3 A. When you're moving, it actually changes the folder 4 structure. So, we're talking about different things. 5 I'm talking about the earlier stuff that I had in 6 Overleaf here; you're talking about what I did on 7 the 17th. So, they're different things. 8 Q. Dr Wright, you deleted relevant and disclosable material 9 just a couple of weeks before your application for an 10 adjournment, didn't you? 11 A. No. I didn't want an adjournment, for a start. But 12 what I did was copy and paste these into different areas 13 for demonstrations. The files in total were kept. 14 Q. You must have known, Dr Wright, that that was improper? 15 A. No, at that stage, everyone was telling me that there 16 was no purpose of these and we wouldn't get them in. 17 That's why I did the demonstrations. I did 18 the demonstrations to show how little teeny weeny 19 changes and how important it was, so I structured 20 a whole lot of demonstrations to show just how critical 21 these little tiny tweaks were and that you couldn't 22 guess them.”
“149:15 Q. Can we go to page 8, please, at 19.2.5, which I know you 16 glanced at earlier {E/24/8}. We can see that, in 17 the second sentence: 18 "Dr Wright instructs me that the only relevant or 19 potentially relevant material hosted on his Overleaf 20 account is the material in a folder entitled 'Bitcoin' 21 did ... and that the other material hosted on 22 Dr Wright's Overleaf account relates to academic and 23 personal interests post-dating 2020 that are not 24 relevant to these proceedings." 25 Right? That's what you told her? 150: 1 A. Yes. 2 Q. And that wasn't true, was it? 3 A. No, I believe it's true. We've disclosed other 4 material, including stuff to do with CookBook, etc, but 5 my university stuff, the work on Teranode, etc, I don't 6 believe is relevant. 7 Q. The Maths (OLD) folder contained -- didn't only contain 8 material relating to your academic and personal 9 interests, did it? 10 A. Only because I copied into the wrong folder. 11 Q. It contained material that was directly relevant to your 12 creation of the White Paper LaTeX files, right? 13 A. No, it didn't. It had where I loaded, on the 17th, 14 files from a different directory so that I could 15 demonstrate the changes. That is directly loaded on 16 the 17th. As you already know, I had meetings with my 17 solicitors demonstrating Overleaf and those files, so 18 they had to exist before the 17th. They were there at 19 my house.”
“190: 5 Q. Now, we know that it was inserted inadvertently by you 6 because we see that at {M1/2/153}. This is a letter 7 from Shoosmiths of1 February 2024 . 2(c): 8 "We understand from our client that the content of 9 the 'Maths (OLD)' project was inadvertently put into 10 this folder by our client." 11 Do you see that? 12 A. That's not what it's saying. It was a copy of the -- 13 the thing. If you're saying a redaction, that's 14 a different thing. So I'm -- 15 Q. The only Maths (OLD) project-related file that we 16 received, when you produced materials to us on 17 22 January, was that json file that I've just taken you 18 to? 19 A. I've no idea. I didn't actually open the file. KLD 20 came out, I clicked the link, we downloaded it, I gave 21 it to them. That's all I know. 22 Q. "We understand from our client that the content of 23 the 'Maths (OLD)' project was inadvertently put into 24 this folder by our client." 25 Right? It was you? 191: 1 A. No, that's not the downloaded file. The Maths (OLD) 2 file, what we're talking about, is Overleaf. 3 I inadvertently copied the Bitcoin stuff into 4 the Maths (OLD). That's what that there is describing. 5 Q. It's talking about the opposite. It's about content of 6 the Maths (OLD) project inadvertently being put into 7 something, right? 8 A. No, not at all. The download was done by either Stroz 9 or KLD at my house when we clicked on the file, and they 10 captured it. 11 Q. Now, if we -- 12 A. I had no interaction with that process. 13 Q. If we hadn't immediately spotted the existence of 14 the project json file in relation to the Maths (OLD) 15 project in your Bitcoin folder, we would never have 16 known of all of the changes that you had made to 17 the White Paper LaTeX files, would we? 18 A. As I said, they were all part of the demonstration 19 process, so all that happened was I clicked the download 20 and all that comes across. 21 Q. So when saying that you had inserted it inadvertently, 22 what that actually means is that you had intended to 23 suppress that file from disclosure to us, right? 24 A. Not at all.”
“125: 9 Q. We're going to come to the changes in a minute and we're 10 going to come to the demonstrations in a minute, but the 11 changes that you made to the BitcoinSN.tex file of 12 the Maths (OLD) project and then to the main tex file of 13 the Bitcoin project included changes which were designed 14 to make the text of your LaTeX file more closely 15 resemble the formatting of the Bitcoin White Paper; 16 correct? 17 A. No, not at all. The demonstrations were to show how 18 the differences were. I'd actually already told my 19 solicitors about it going back to October. 20 Q. We can see, and we're going to go through some of this 21 but hopefully fairly briskly, that you were adjusting 22 the size of the spaceskip commands; do you agree? 23 A. Yes. Like I was saying, you demonstrate how the thing 24 works and I put them in and out. 25 Q. And then you were adding and moving "/:"s, right? 126: 1 A. Yes. 2 Q. And that was to try to enable you to try to replicate 3 the line breaks and the spaces between words in 4 the Bitcoin White Paper, wasn't it? 5 A. Not at all. It was actually putting things back to 6 demonstrate what it is without it and how these things 7 work.” “127: 5 Now, what that animation shows is that you were 6 moving and adjusting text, right? 7 A. Yes, that was part of capturing and what I was 8 demonstrating. The original was demonstrated to my 9 solicitors at my home before any of this happened. 10 Q. And we can see that, generally, the changes started on 11 page 1 and continued down the document, right? 12 A. Oh, as I made each of the change, it's not the whole 13 document changes. To demonstrate what the different 14 commands do, I had to actually put them in.” “132:11 Q. Were you very familiar with LaTeX before you were doing 12 this? 13 A. I know LaTeX. I don't -- I'm not an academic, I don't 14 teach it, so I don't know all the terminology. 15 Q. Because there seemed to be a lot of faffing around with 16 LaTeX in your adjustments, which looked like somebody 17 learning how to do it on the go? 18 A. No, it's demonstrating the differences. Like I said, if 19 you make one small change in any of those values, it 20 significantly changes everything in the line and 21 the only way to demonstrate that is to show it.”
“167:18 Q. What is the point of putting in a witness statement 19 a description of a PDF creation date command if it 20 wasn't a PDF creation date command that Satoshi made? 21 What's the point of mentioning it? 22 A. One, I am Satoshi. Two, the command that I put in there 23 is going to change over time as I'm working on 24 the files. 25 Q. So if you're Satoshi, was that the PDF creation date 168: 1 that you put into the Bitcoin White Paper or not? 2 A. The original White Paper has changed many times and 3 there are multiples. 4 Q. Right. 5 A. So your problem is that you keep saying, "The paper". 6 One, there are multiple versions of the paper, and there 7 are multiple versions of what I've done. 8 Q. No, the problem isn't mine, it's yours. 9 A. No, it's not mine. 10 Q. And the reason the problem is yours is because 11 the relevant version of the Bitcoin White Paper that 12 you're talking about here had a minus six hours time 13 zone. 14 A. No, it had a minus six because of changes in location. 15 Q. We can see it at {H/20/11}. 16 A. Minus seven goes to minus six when you add summer time. 17 Q. Dr Wright, we can see here that the creation date was 18 20090324113315 minus 6, right? 19 A. Minus 7, in the statement, when you add summer time 20 becomes minus 6, plus one hour, so minus 7 plus one is 21 minus 6. 22 Q. Dr Wright, I perfectly well understand that if you were 23 trying to state the relevant time at a minus seven-hour 24 time zone that you would have put 103315, but actually, 25 Satoshi didn't use a minus 7-hour time zone for this 169: 1 version of the White Paper, did he? 2 A. No, you're incorrect once again. Time zones. If you 3 compile it and you change, like, that not to be that 4 part of the year, it will be different. 5 Q. Dr Wright, the whole point of this section of your 6 witness statement is for you to describe the -- is to 7 describe what you were saying was the way in which you 8 could configure the metadata properties, right? 9 A. Yes. 10 Q. But you put in duff metadata properties in your 11th 11 witness statement, didn't you? 12 A. Again, time zones. I know you seem not to understand it 13 on purpose, but when you have a plus one on a time zone, 14 it changes. So time zone plus one means negative 7 plus 15 one, which comes out on the final document as 16 negative 6. 17 Q. If you're manually configuring the Bitcoin White Paper 18 to identify -- and you're doing it in LaTeX, which 19 Satoshi did not do, if that's what he had done, he would 20 have had to put minus 6 to get the output that we're 21 seeing here as the creation -- 22 A. No, if you did it on minus 6, because of plus 1, you'll 23 actually get negative 5. So again, it's like London 24 time. We keep adding an hour, subtracting an hour, 25 making people change clocks -- 170: 1 MR JUSTICE MELLOR: Hang on, Dr Wright. As I understand 2 your evidence, in LaTeX, it's nothing to do with any 3 clock, you put in these numbers. 4 A. Ah, but the system will still use the timestamp 5 information. So you put in those numbers -- 6 MR JUSTICE MELLOR: How? Which bit of this creation date 7 field does the system change then? 8 A. You still have to put in the time zone information if 9 you want it not to change naturally on the system clock, 10 my Lord. So the system clock, when it compiles, will 11 recognise if it's a plus one and add that and modify it. 12 So, when you do this, unless you do something like 13 specify GMT, or Eastern Standard Time specifically, then 14 it's going to take the natural sort of changes and 15 drifts. 16 MR JUSTICE MELLOR: Mm. I think I've previously asked you 17 about whether there was a default or whether you had to 18 put all this in manually. 19 A. If -- 20 MR JUSTICE MELLOR: And I recall you answered it's manual. 21 A. Yes, but what I'm saying here is the difference between 22 the negative 7 and the time zone information, my Lord. 23 They're actually two different settings. 24 MR JUSTICE MELLOR: Yes, I mean, I'm afraid, Dr Wright, 25 I simply don't understand that answer. So if you want 171: 1 me to understand it, you're going to have to explain 2 precisely how this works. 3 A. Yes, my Lord. 4 All right, so what happens is you set a default, and 5 if you put negative 7 and the -- 6 MR JUSTICE MELLOR: Where do you set the default in LaTeX? 7 A. In a command. 8 MR JUSTICE MELLOR: In this command? 9 A. Yes. 10 MR JUSTICE MELLOR: But I thought you said earlier it's just 11 what you type in? 12 A. The negative 7, though, is different to the time. 13 The time is what you type in. Now, you also either set 14 explicitly whether you have time zones changing for 15 summer time, etc, or not. If you don't, then it goes to 16 your clock time, as you're doing it. 17 MR JUSTICE MELLOR: Okay, but I don't understand why you 18 would be worrying about summer time, plus 1, minus 1, 19 etc. 20 A. That's why it comes out, if you put 7 in -- 21 MR JUSTICE MELLOR: No, no, no, why wouldn't -- okay, we'll 22 assume Satoshi is putting in the creation date. 23 A. Yes. 24 MR JUSTICE MELLOR: Why would he worry about whether it was 25 summer time or not? 172: 1 A. No, it's a time zone negative 7. At the time, I was 2 doing a lot of work with American and Caribbean 3 companies, so my default when I printed things was 4 negative 7. The reason for that is, in Antigua, various 5 other islands, a lot of gaming happens. So when I was 6 doing, you know, documents, etc, I used standards for 7 either South American or Caribbean time. Now, that 8 comes with certain plus 1 minus or plus 10 type 9 adjustments. Now -- 10 MR JUSTICE MELLOR: Adjustments from when? 11 A. I'm not exactly sure when summer time does or doesn't 12 start. 13 MR JUSTICE MELLOR: No, no, no, but if you're talking about 14 Antigua and Caribbean saying plus 1/minus 1, that's 15 adjusting relative to which time zone? 16 A. To the negative 7. So it will take negative 7 and add 17 one. So when it compiles, it becomes negative 6. So, 18 the document here says that date, but then it becomes 19 negative 6 in the PDF, because the PDF will display plus 20 summer time, etc. 21 MR GUNNING: Dr Wright, the last time I looked, the time 22 zone difference in the Caribbean was minus 5 hours, 23 but ... 24 A. As I said, also Belize, other places. I did 25 South American and the others. 173: 1 Q. You had a sort of travelling time zone then, did you? 2 A. I did. I had dealings with a variety of 3 Central American and Caribbean areas. I still do.”
“173:19 Q. ….. 20 And we know how you came to put this command into 21 the White Paper LaTeX files; it was something that you 22 did not do until1 December 2023 . 23 A. No, that's incorrect. I'd already demonstrated files 24 set in the future, set in the past, and I've done that 25 multiple times. 174: 1 Q. It's a matter of record. There is no PDF creation date 2 command in the Maths (OLD) project, right? 3 A. I've no idea. 4 Q. It's the PDF creation date that's entered in the Bitcoin 5 project up to 24 November is not the -- doesn't include 6 the time and time zone that you've provided there. 7 A. The one that I demonstrated when they were over at my 8 house in October had all this, and when I demonstrated, 9 I demonstrated how that worked. 10 Q. And we can see where it comes in by looking at 11 the chunks file and this command goes in on 1 December, 12 right? 13 A. No, you can see the demonstrations I did after they'd 14 already come out to my house. 15 Q. Dr Wright, we can take that up in closing, but you're 16 lying. 17 A. No, I'm not.”
“136:18 If we look at the spaceskip command here, we can see 19 you start off having it at 0.3em, right? 20 A. Like I said, I did a demonstration where I was going 21 through each of these settings to show how much it 22 changes. 23 Q. And you then increased it to 0.6em, right? 24 A. I did. 25 Q. And you then reduced it to 0.2em in a bit below that? 137: 1 A. Yes, the best way of demonstrating how it works is to 2 make a large change. 3 Q. Yes, but none of this is being done on one of your 4 demonstrations to Shoosmiths? 5 A. This was actually part of what I was documenting at the 6 time. 7 Q. How were you documenting it? 8 A. I had files. 9 Q. What files? 10 A. I had screenshots, etc, for some of the -- 11 Q. Sorry, you were taking screenshots every time you made 12 a change to your Overleaf files? 13 A. Some of these, yes. Not every single time, but when 14 I was making differences. I also had other 15 conversations even before this. Shoosmiths were at my 16 house -- 17 Q. I'm not interested in your discussions with Shoosmiths. 18 What I'm going to explore is how spaceskip changes and 19 we've seen how the first parameter changed, right? 20 A. Mm-hm. 21 Q. The second parameter was the max stretch that LaTeX 22 would permit to that base spacing, right? 23 A. Yes. 24 Q. And it started at 3.4? 25 A. Mm-hm. 138: 1 Q. And we can see you then reduced that in a number of 2 stages, right? 3 A. Yes, to demonstrate -- 4 Q. A minor tweak upwards we can see at around 370 or 371? 5 A. It's a bit more than that. You'll notice that there are 6 three values. So it was demonstrating, like a three 7 body problem, just how difficult it is to actually find 8 something that matches. But you can't just, like you're 9 suggesting, go, "Oh, I'm going to guess a value" and 10 it's going to match -- 11 Q. The third -- 12 A. -- because if you do that it's going to be way, way out. 13 Q. The third parameter was the shrinkage parameter, right? 14 A. Mm-hm. 15 Q. And that's depicted in blue and it starts at 0.1, yes? 16 A. I'm not sure where it starts, but ... 17 Q. Well, it's -- take it from me, it's at 0.1. 18 A. Yeah. 19 Q. You then increased it to 0.3? 20 A. Mm-hm. Yeah. 21 Q. Before reducing it? 22 A. Yes. 23 Q. And then increasing it, before finalising it at 0.16? 24 A. Mm-hm. 25 Q. Now, so you had in fact at one point set the shrinkage 139: 1 to a level that was lower than the base spacing? 2 A. Yes. 3 Q. Which doesn't make any sense, does it? 4 A. That's the whole point. By doing this, I'm 5 demonstrating just how sort of many changes can occur 6 from a simple little tweak. 7 Q. You're not showing it to anybody, Dr Wright. We know 8 the times when you're showing it to Shoosmiths. This 9 can only be something that you're doing for yourself? 10 A. No, actually, it's not, because I also created documents 11 and I also documented the changes I was doing in what 12 they wanted. 13 Q. We're going to come to the documents that were produced, 14 but standing back from this, we don't see that you were 15 making adjustments to reintroduce known parameters from 16 the Bitcoin White Paper, do we? That's not what you're 17 doing? 18 A. No, I'm actually adjusting it to show how different it 19 can be. 20 Q. What you're doing is tweaking parameters to try to get 21 them to fit the layout of the Bitcoin White Paper, 22 aren't you? 23 A. No, actually, you wouldn't do that. And what 24 you're actually -- you're saying -- 25 Q. It's not a question of what I would do -- 140: 1 A. Well -- 2 Q. -- that's what you did. 3 A. No, I demonstrated how these changes worked. Now, what 4 you're saying in the thing you said, it would be 5 ridiculous, and yes, I noted so how ridiculous some of 6 these things could end up and how different. You notice 7 some of them, the whole structure changes just by 8 a small change.”
“204:22 Q. Now, the text output from Aspose would not create a very 23 good forgery of the Bitcoin White Paper, would it? 24 A. A horrible one. 25 Q. Because no sane person would individually place letters 205: 1 in a word in this way when composing a LaTeX file from 2 scratch, right? 3 A. More than that. It also -- the way that it draws lines, 4 and all sorts of things, are crazy. 5 Q. And indeed, if we look here, we can see that the letters 6 are placed at what seem to be nanometric levels of 7 accuracy, right? 8 A. Yes. 9 Q. Which -- four decimal places of accuracy, some of them? 10 A. Yes. 11 Q. Five decimal places. So that is -- 12 A. That's correct. 13 Q. That is probably 0.0035 nanometres, and that is an 14 insane level of accuracy, so insane that it's obviously 15 ridiculous, right? 16 A. Completely ridiculous, yes. 17 Q. So it would scream out forgery? 18 A. Sorry? 19 Q. It would scream out as a forgery? 20 A. It would scream that someone's used some sort of wacky 21 tool to do something.”
‘My fascination with coding and computing began when I dabbled with C and C++ around the age of eight or nine. By age 11, I had already started writing code for games. I used C and C++ because they were the languages that games were written in. As I discuss below, while I have worked extensively with various coding languages, C++ has remained a cornerstone of my expertise.’
“he hasn’t included all of the emails, and he also hasn’t included the extensive communications that himself and I had on Twitter and direct messages”
‘I cannot recall whether I saw this exact paper or not, but what is written in the abstract is similar to the things that Craig sent through back then. What I do know is that in the late 2000s the papers Craig sent through covered, for example, the concept around hashing, and the secured keys pulling things through to authenticate transactions over a network. I can remember the concepts and what we were talking about, but whether it was that document or another document, I do not know as there was numerous documents with essentially the same information.’
‘Yes/Yes As for 2, yes some. I have a large amount of experiance [sic] decompiling C, C++, Java, script of various types, fortran, .Net, perl, Ruby and others. I have programmed in Java, though I prefer C (pure C, not even object). I used to be a C coder - way back - but I never was good at the graphics. I am not an artist and I never really liked high level languages for coding. I use R and C and occasionally C++ a fair bit for algorithmic coding and statistics work.’
“123: 6 Q. And then, fourthly, we can see that it checked 7 transactions? 8 A. Yes. 9 Q. What was that? 10 A. That it checks transactions? 11 Q. Yes, what was the check of the transactions? 12 A. Basically making sure that they are valid, that 13 the transactions that have been received follow 14 the rules, etc. 15 Q. So what sort of thing? 16 A. What sort of thing. So, basically, Bitcoin uses script. 17 The way that you'd have to then check would be does 18 the key work, does other policies work, are the output 19 and script valid. It's a predicate. So, what we're 20 functionally doing in here is ensuring that all of 21 the input and output is structured correctly, that if 22 there's a message with an ECDSA key that the correct 23 previous block had been signed. 24 Q. So I remember you talking the other day -- I can't 25 remember which day it was -- about how, when you were 124: 1 first running the Bitcoin Software, it hadn't been -- 2 the mining that had been absorbing all of your 3 electricity, as it were, it was doing ECDSA checks in 4 relation to the underlying transactions; is that right? 5 A. And much more. 6 Q. Okay, but when you're talking about ECDSA checking, is 7 that what you're talking about in relation to -- 8 A. That particular part, yes.”
“125:10 Q. It did not involve checking ECDSA signatures, did it? 11 A. Again, that then calls these other functions. 12 Q. Dr Wright, you're wrong about that? 13 A. I am not wrong about that. If you note this, 14 the diagram that you had is hierarchical. So, that 15 particular function calls the next function, and when 16 you're talking about checking CheckSig in that 17 particular one, then that's ECDSA, but it's not in that 18 core. 19 Q. You see, Dr Wright, this is a pretty central core point 20 in relation to the operation of the Bitcoin Software and 21 you don't know about it, do you? 22 A. Actually, I do, and you're not letting me explain it 23 properly. 24 Q. I'm going to explain it to you. Can we go, please, to 25 {L4/97.1/23}. Sorry, 98.1, I think, it is, page 23 126: 1 {L4/98.1/23}. No, 97.1, page 23 {L4/97.1/23}. 2 So, do you see here that we can see a function which 3 is described as "ProcessBlock"? 4 A. I do. 5 Q. And do you see underneath that, the preliminary check 6 that it does is called "CheckBlock"? 7 A. I do. 8 Q. And do you see that a secondary check, after CheckBlock 9 has been completed, is called "AcceptBlock"? 10 A. I do. 11 Q. Now, it is within AcceptBlock that the signatures are 12 checked, isn't it? 13 A. Basically what we have is a series of functions that 14 each of these call other functions. So, where you're 15 trying to say that each of these don't do all of that, 16 the diagram that these guys don't like is a functional 17 call mapping each of these areas down. 18 Q. I'm not asking you about any diagrams, I'm asking you 19 about what is in the CheckBlock function, and you told 20 me that within the CheckBlock function were checks of 21 ECDSA signatures. 22 A. If it's a header and everything else is underneath it, 23 then that is part of the entire function and you are 24 checking everything. So when you have one function 25 follow another to be correct, then all of those 127: 1 sub functions are part of the same function. 2 Q. I'm afraid you're wrong, Dr Wright. If we want to 3 explore how you get to signatures from the AcceptBlock 4 function, I can take you there. Do you want me to do 5 that? 6 A. Like I said, the block includes both the full check and 7 each of these. So when you have a transaction that you 8 have checked, it then goes into the block and it's put 9 into a binary tree structure. All of that is checked as 10 part of the entire function. What you're doing is 11 pulling out each individual call and saying that it's 12 separate. It isn't. 13 Q. We have looked at what the CheckBlock function contains 14 and you have said it contains an ECDSA signature check. 15 It doesn't, does it? 16 A. That's not what I said. 17 Q. Well, we can see what you said. 18 A. What I said was, the function includes all of 19 the processes in that. CheckBlock doesn't work unless 20 each of the called functions are there.”
‘91. In August 2008 1 reached out to a small number of individuals, including Wei Dai and Adam Back, by sharing the link to the White Paper via email as Satoshi Nakamoto, most likely using my satoshi@anonymousspeech.com address. I sent them a link to upload.ae where I had uploaded a single draft of the White Paper. … 92. Wei Dai was a distinguished academic who had previously proposed a digital currency concept called B-Money, which profoundly impacted my thinking. His work was highly influential and laid the groundwork for some ideas incorporated into the Bitcoin project. Notably, Wei Dai's contributions were the first that I acknowledged in the White Paper. After I provided him with a copy of the White Paper, he played a significant role in the development process, guiding me to various signature algorithm libraries, including his secure hash algorithm {SHA-256), which I successfully incorporated into the Bitcoin code base. 93. Adam Back was known for his work on Hashcash (a proof-of-work algorithm different to that in bitcoin which he had proposed to combat email spam). He showed little interest in Bitcoin. His attitude was quite dismissive; he stated that digital cash had been attempted before and was bound to fail. At the time, I did not understand he was pointing at issues associated with creating a cryptocurrency and not digital cash. 94. Contrary to popular belief, Bitcoin's proof-of-work system does not utilise Adam Back's Hashcash system. Instead, it more closely aligns with the methodologies described in Aura's paper. Due to Aura's lack of response, I felt it necessary to reference Adam Back in the Bitcoin White Paper due to the thematic parallels in our work and Back's notable presence in the field.’
“I'm getting ready to release a paper that references your Hashcash paper and I wanted to make sure I have the citation right. Here's what I have: [5] A. Back, "Hashcash - a denial of service counter-measure," http://www.hashcash.org/papers/hashcash.pdf, 2002. I think you would find it interesting, since it finds a new use for hash-based proof-of-work as a way to make e-cash work. You can download a pre-release draft at http://www.upload.ae/file/6157/ecash-pdf.html Feel free to forward it to anyone else you think would be interested. I'm also nearly finished with a C++ implementation to release as open source.”
“Thanks, I wasn't aware of the b-money page, but my ideas start from exactly that point. I'll e-mail him to confirm the year of publication so I can credit him. The main thing my system adds is to also use proof-of-work to support a distributed timestamp server. While users are generating proof-of-work to make new coins for themselves, the same proof-of-work is also supporting the network timestamping. This is instead of Usenet.”
“I was very interested to read your b-money page. I'm getting ready to release a paper that expands on your ideas into a complete working system. Adam Back (hashcash.org) noticed the similarities and pointed me to your site. I need to find out the year of publication of your b-money page for the citation in my paper. It'll look like: [1] W. Dai, "b-money," http://www.weidai.com/bmoney.txt, (2006?).” [1] W. Dai, "b-money," http://www.weidai.com/bmoney.txt, (2006?).”
“Hi Satoshi. b-money was announced on the cypherpunks mailing list in 1998. Here's the archived post: https://cypherpunks.venona.com/date/1998/11/msg00941.html There are some discussions of it at https://cypherpunks.venona.com/date/1998/12/msg00194.html. Thanks for letting me know about your paper. I'll take a look at it and let you know if I have any comments or questions.”
‘1. I’m not a “distinguished academic” and has actually never worked in academia. 2. My understanding (from Satoshi’s first email to me) is that Satoshi only became aware of b-money when he learned about it from Adam Back, which is after he had completed the draft of the whitepaper that he sent to Adam, so it seems wrong that I profoundly impacted Satoshi’s thinking. 3. I did not play a significant role in the development process of Bitcoin. Specifically I did not guide Satoshi to “various signature algorithm libraries, including his secure hash algorithm (SHA-256)”. 4. You can see the entirety of my communications with Satoshi at https://gwern.net/doc/bitcoin/2008-nakamoto.’ aware of b-money when he learned about it from Adam Back, which is after he had completed the draft of the whitepaper that he sent to Adam, so it seems I did not guide Satoshi to “various signature algorithm libraries, including his https://gwern.net/doc/bitcoin/2008-nakamoto.’
‘Prof Wrightson knew of Wei Dai, and pointed me towards a paper titled Knowledge-Based Communication Processes in Building Design” that he knew of because of his work in machine learning. Both Adam Back and Prof Wrightson directed me to Wei Dai. 戴 维 turned out to be another cypherpunk, and he was an incredibly helpful one. I used some of his code in the original release of Bitcoin — with his permission.’
“Adam Back was not the source of the hashing algorithm within bitcoin. He was noted and referenced within the paper following my communications with him in mid-2008. The actual source of hash algorithm that is used for the proof or work is from the following authors: • Tuomas Aura, Pekka Nikander, and Jussipekka Leiwo: • http://www.tcs.hut.fi/old/papers/aura/aura-nikander-leiwo-protocols00.pdf It is my belief that you will recognise the algorithm on reading this paper. There are similarities in hashcash in that it searches for collisions, but the nature of the Bitcoin algorithm is derived from Aura et al. and not from Back. It also needs to be further noted that the code supplied by Wei Dai predates any communications with Adam by two months.”
“I did not directly supply any code to Satoshi. (Again you can see the entirety of my communications with Satoshi at the link I gave earlier.) My understanding is that Satoshi did incorporate some of my code (specifically my implementation of SHA-256) into his Bitcoin code, but that code is in my open source Crypto++ library, and he probably just downloaded and used it without telling me.”
“I did not put down that I was Satoshi when I talked to them. I was just another postgraduate researcher and student. … … In a conversation that I had when I started my degree with Prof Graham Wrightson, I saw that the separate networks and communication infrastructure would end up merging. … Prof Wrightson knew of Wei Dai, and pointed me towards a paper titled “Knowledge-Based Communication Processes in Building Design” that he knew of because of his work in machine learning. Both Adam Back and Prof Wrightson directed me to Wei Dai. 戴维 turned out to be another cypherpunk, and he was an incredibly helpful one. I used some of his code in the original release of Bitcoin — with his permission. Andreas Furche knew of Hal Finney and Adam Back. So I emailed people. I was researching in 2005, and came to the conclusion that I could build something. By 2007, I was ready to start.”
“81:14 A. I'm sorry if it's perfectly clear for you, but it's not. 15 One, I'm not good with remembering people. The funny 16 thing is, when it comes to code, when it comes to other 17 things, I have a near eidetic memory; when it comes to 18 people, I don't; I don't even remember faces very well. 19 But when it comes to recalling people, I'm horrible 20 with it. 21 I did have communications with him, I know that they 22 were valuable to me, more than that I can't say.” “84:12 Q. So your confident assertion in that paper, and 13 the anecdotes about Professor Wrightson pointing you to 14 Wei Dai and discussing Wei Dai with you, that could be 15 wrong? 16 A. Oh, definitely; I get people wrong all the time. I've 17 gone up to people I should know very well and called 18 them the wrong name many times; I do it at work all 19 the time. I have partial aphasia, which means I don't 20 actually recognise faces properly, so --”
“84:21 Q. Page 1, please {L19/209/1}, an email from 22 Professor Furche. He, too, says that he has no 23 recollection of you, and that he left 24 Newcastle University in 1999. That latter bit is from 25 his witness statement. Do you dispute that he left 85: 1 Newcastle University in 1999? 2 A. No. 3 Q. So, he, too, could not have been there to have these 4 rewarding changes with you in 2005 to 2009, could he? 5 A. Possibly. I was there at that stage. But I was also at 6 the Australian Stock Exchange, where he developed 7 the signal process and some of the software for, and 8 also promoted. 9 Q. I'll come to that in a moment. 10 He also says -- we can take this document down. 11 He also says in his witness statement that he's 12 never heard of Hal Finney, with whom -- about whom you 13 supposedly had discussions with him. Is he wrong about 14 that? 15 A. I don't know. As I said, I'm not good with people, and 16 I could have had it wrong, but I don't think I am. 17 Q. He also agrees with Professor Wrightson that the group 18 didn't have a lot of resources, that it never lodged 19 a patent application and that he doesn't recognise 20 the patent paper hyperlinked to your article. Do you 21 accept he's right on those points? 22 A. Yes. I could have got the wrong person and linked 23 the wrong area. I'm not denying that. 24 Q. An awful lot of mistakes in your blogpost now, aren't 25 there? 86: 1 A. I told you, when it comes to people, I'm terrible. This 2 is the whole thing. When it comes to numbers, code, 3 writing things, a predicate system, I'm great; when it 4 comes to interacting with people ... This is why I work 5 from home, this is why I hide away from the world, this 6 is why I don't interact, why you're asking me about all 7 these people I'm supposed to remember. 8 Q. But you do dispute Professor Furche's claim not to 9 recall you, don't you? 10 A. I would find that difficult. I was at 11 the Australian Stock Exchange for a number of years, and 12 the only way I could put it was, I was a gadfly and 13 I was incredibly annoying to a lot of people, including 14 those in seats and other such systems. And some of 15 the other exchanges that he did stuff with as well, 16 I was involved. 17 Q. {CSW/1/82}, please. 18 A. Including Chi-X. 19 Q. Paragraph 433. This is your 11th witness statement, 20 isn't it, Dr Wright? Yes? 21 A. Yes. 22 Q. You claim that Dr Furche and you worked together on 23 the surveillance systems for the Australian Stock 24 Exchange from '97 to 2003, don't you? 25 A. I worked on those systems at that stage, yes, and 87: 1 I believe he was there, and he implemented those -- 2 Q. Professor Furche -- 3 A. -- systems at that time. 4 Q. Professor Furche's work on the ASX's surveillance 5 systems didn't start until after 2003, did it? 6 A. Well, I still remember him, and I definitely remember 7 him from the Perth Mint. 8 Q. So you worked together at Perth Mint in 2005 to 2008, 9 yes? 10 A. No, I was an auditor. 11 Q. "... then had a joint involvement at the Perth Mint, 12 where I was an auditor for BDO (2005-2008)." 13 Yes? 14 A. Yes. 15 Q. In fact, Professor Furche's work in relation to 16 the Perth Mint didn't begin until 2016, did it? 17 A. I don't know, but I'm pretty sure it was him there, and 18 I believe he was also involved with Chi-X. 19 Q. Just setting aside the thing you don't talk about in 20 your 11th witness statement, you couldn't have had 21 a joint involvement with him at the Perth Mint while you 22 -- in 2005 to 2008, because he didn't have a connection 23 with it at that time, did he? 24 A. I don't know, but I do remember him. As I said, I'm 25 terrible with people, but I remember him from something.”
‘I did so because I mentioned it in the White Paper, not because I used the algorithm’, an explanation which I consider to be bizarre, given what Satoshi actually wrote. Dr Wright went on to refer to the algorithm used in Hashcash as being different from that implemented in Bitcoin, on the basis that ‘the algorithm does not use a series of leading zeros as Bitcoin implements.’
‘I will note that the initial Hashcash scheme and the Bitcoin Proof of Work (PoW) mechanism differ in their core concept and the specifics of their implementation, particularly in how the target for hash collision is defined.’ particularly in how the target for hash collision is defined.’
‘e. Target with Leading Zeros: In Bitcoin's PoW, the goal is to find a hash that is below a particular target value, often visualized as a hash with a certain number of leading zeros. This target adjusts over time to maintain a consistent block time despite changes in computational power. f. Mechanism: Bitcoin miners compete to find a hash of the block header that meets the required difficulty level (i.e., has a sufficient number of leading zeros). The difficulty of this task adjusts dynamically with the network's collective hashing power to ensure that the average time to find a block remains consistent.’
“77: 20 Q. Okay. Does it deal with leading zeros, or ...? 21 A. No. 22 Q. Right. 23 A. So, I mean, I believe this end bit is a, sort of, 24 compact representation of -- it involves a compact 25 representation of the difficulty which, then, in turn, 78: 1 creates a target, and so it's checking if the hash is 2 as -- represented as a very large integer, is less than 3 the target, which is -- which is what I said. So that, 4 you know, superficially, if you look at the zeros, there 5 is a certain number of zeros, but, you know, even if you 6 look at it in binary, there are some more bits after it 7 where, you know, the next bit could be a zero or a one 8 and it could still be an invalid proof-of-work, because 9 it's really a floating point number, or a fraction or 10 something.”
“146:20 Q. Now, I'm putting this to you on the basis of the expert 21 evidence of Professor Meiklejohn. It wouldn't have been 22 necessary to run a set up of this magnitude to mine 23 Bitcoin in 2009 or early 2010, would it? 24 A. Of course it would. Ms -- Professor Meiklejohn is 25 misrepresenting Bitcoin mining and nodes. Section 5 of 147: 1 the White Paper doesn't say that you solve hashing. 2 Now, hashing is only one small component. The majority, 3 at a low level like that, is actually validating ECDSA. 4 ECDSA is a far more computationally intense process than 5 hashing. So what we need to do is actually go through 6 validation of blocks, checking, later running testnet as 7 well, and ensuring that all of that process happens 8 before you distribute the block. On top of that, I had 9 to run multiple systems. 10 Bitcoin was configured so that on a single C class, 11 and I had a C class in each area, the 256 IP addresses 12 in V4, or more in IP v6 would only act as a single node 13 on the network. So even if you had 30 machines on 14 a single location, they only broadcast as one node on 15 the network. Now, that allowed me to have multiple 16 systems, including the logging systems and the rest of 17 the Timecoin server. All of that together was really 18 the cost that I experienced.”
“that test network was a really good idea of yours”
“Each node verifies a block before it propagates it to the connected peer nodes. In this way only valid blocks are propagated, and any invalid blocks are quickly isolated. The BitCoin Core client lists all of the validation requirements in the following functions: • CheckBlock • CheckBlockHeader”
“135: 9 Q. Do you want to carry on and we'll see that it then 10 refers to two functions, the first is CheckBlock and 11 the second is CheckBlockHeader, isn't it? 12 A. Again, CheckBlock and CheckBlockHeader were meant to be 13 implemented. CheckBlockHeader was a simple function for 14 SPV. So in the client patches discussed with Gavin in 15 2010, CheckBlockHeader was an implementation of 16 a version of Bitcoin that does not have all of 17 the checking. So that's different to the version Sipa 18 put in, but that doesn't mean that there weren't 19 functions. Again, CheckBlockHeader was about having an 20 SPV, as defined in the White Paper, version of checking 21 just the block headers. 22 Q. There's no reference in the White Paper to 23 CheckBlockHeader, is there? 24 A. It has reference to SPV, which only checks Block Header. 25 There is no reference to any of the coding terms in 136: 1 the Bitcoin White Paper. 2 Q. When you say SPV checks -- "only checks Block Header", 3 what do you mean by "SPV" there? 4 A. Simplified Payment Verification. 5 Q. Right. 6 A. What that basically means is, like -- 7 Q. To assist in the payment of individual transactions? 8 A. No, it's a -- basically what we're talking about is 9 a light node. So a node where an individual doesn't 10 need to download the entire blockchain. For instance, 11 I can just have the block headers and then I can have 12 a localised(?) path of where I'm checking an individual 13 transaction. I can keep each of those. 14 Q. Dr Wright, nobody referred to CheckBlockHeader until 15 the change that I took you to, did they? 16 A. No, that's wrong. That was actually part of building 17 SPV systems, that was basically the function I was 18 looking at at that time. 19 Q. There isn't a single document in which anybody refers to 20 CheckBlockHeader as a single function until Dr W[uille] 21 introduced it through GitHub, right? 22 A. I've no idea when he put it in that, but when I was 23 discussing the introduction of SPV, these concepts were 24 back there as well. 25 Q. Mr Andresen did not introduce CheckBlockHeader, did he? 137: 1 A. No, Mr Andresen got a patch from me initially. So 2 the patches for SPV were actually from Satoshi, me. 3 Q. Dr Wright, we've got the patches that Satoshi Nakamoto 4 sent to Mr Andresen; they do not include 5 CheckBlockHeader. 6 A. No, because I went off to develop things myself. So 7 where I was talking about work that I did in my other 8 companies, I didn't do everything publicly. The work on 9 Teranode now that was iDaemon that I've put in here, all 10 of those documents were based on our work, not his. 11 Q. Dr Wright, I know you want to talk about all of your 12 latest things. I'm actually trying to ask you about 13 things that Satoshi Nakamoto would know about, and that 14 is the original -- 15 A. No, you're -- 16 Q. -- Bitcoin code, right, and there was no reference in 17 the original Bitcoin code to CheckBlockHeader, 18 was there? 19 A. Again, difference between core, as in main nodes, and 20 those that are doing less, SPV, and there is a reference 21 to SPV. SPV nodes are those that only have to check 22 the headers across the network. If you read 23 the section, you will see that. 24 Q. Dr Wright, I am very confident that I can read any 25 section of anything and I will not see a single 138: 1 reference to CheckBlockHeader. 2 A. Because the code's not referenced in the White Paper at 3 all. 4 Q. And you're saying that -- when did you say then you 5 invented this? Was it in 2010, you said, when you were 6 talking to Mr Andresen? 7 A. No, I started working on SPV before I even released 8 Bitcoin. So, what I was doing is a combination of 9 Timecoin, which was a separate product, and Bitcoin. 10 Bitcoin was the main free product; Timecoin extended 11 everything.”
“To reduce confusion between Bitcoin-the-network and Bitcoin-the-software we have renamed the reference client to Bitcoin Core.”
“139: 6 Q. And if we go to the top of page 15 {L3/237/15}, we can 7 see that this document refers to "the UTXO pool". 8 A. Mm-hm. 9 Q. That only came into existence after the Ultraprune 10 request was updated, right? 11 A. No, that's incorrect. Once again, the models that I'd 12 been building include this. So, what you're assuming is 13 that code and ideas that I'd already got in iDaemon, and 14 other such things, are the only place they exist. And 15 what a UTXO pool is, in my system, is very different to 16 yours. 17 Q. Now, if you were Satoshi Nakamoto, Dr Wright, and if you 18 read this document before you purported -- or you chose 19 to rely on it, before -- sorry, if you were 20 Satoshi Nakamoto and you wanted to present the documents 21 you wanted to rely on, you would have spotted those 22 three anachronisms, wouldn't you? 23 A. No, because they're not. That also goes into things 24 like the orphan block pool, which doesn't, I don't 25 believe, exist in BTC Core, but is something in my 140: 1 software. So when we're talking about that, what we 2 have are competing chains and we've made a pool for 3 that. So using a standard term, that one, you would 4 say, is an anachronism because it's not in core, but 5 it's in my paper.”
“157:18 Q. And in reality, Satoshi never transferred any Bitcoin to 19 Zooko Wilcox-O'Hearn, did he? 20 A. Actually, I did. Zooko was very interested because he 21 had been working on a similar thing, MojoNation, 22 beforehand. 23 Q. So he's wrong in his witness statement when he says he 24 didn't receive Bitcoin from Satoshi, is he? 25 A. He is.”
“80: 4 Q. Right. You see, what I suggest is that you're in fact 5 mistaken about that, and given what you've accepted is 6 your very keen interest in Bitcoin, your perception that 7 it was a revelation, that you were entranced and sucked 8 in pretty early, that the reality is that you did in 9 fact get more involved than you now remember: you 10 downloaded, you ran the software and you were sent some 11 Bitcoin by Satoshi. 12 A. No, by the time of -- like I mentioned earlier, Bitcoin 13 had gone from a curiosity to a breakthrough in my mind 14 at some point, and Satoshi was totally my hero. Still 15 is. I love what Satoshi means to me and to people. So 16 if I had ever gotten bitcoins from Satoshi, I would 17 definitely remember that. But again, my earliest use of 18 Bitcoin was OTC trading. You know, "OTC" means "over 19 the counter". I forget what it was called, but there 20 was this thing where people could post, if they wanted 21 to buy or sell bitcoins, and then they could get each 22 other's contact from it. That's my earliest memory of 23 using Bitcoin for anything myself. 24 Q. So, again, I suggest that the fact that you regarded 25 Satoshi as your hero, it beggars belief that you didn't 81: 1 get more involved at the very earliest stage. 2 A. You underestimate my laziness and procrastination.”
“The first version was after I left” {O4/14/36} and then continuing {O4/14/37}: “RYAN CHARLES: So in fact when I look at what the URL is, it says if people can see on my screen, 2009, but then when you click it, the 2009 one is not there and it is a 2011 version instead. DR. CRAIG WRIGHT: Yes. RYAN CHARLES: So it does seem like the lack of version there could indicate that there was a different version at this time that has been excluded. DR. CRAIG WRIGHT: Yes. A different version has been ---- RYAN CHARLES: Just to be clear then, are you saying you did that or did they do that? DR. CRAIG WRIGHT: I did not do that. I was not in control of the web page at this point.”
“This was generated by Vistomail when I set-up the Sakura account in 2008. I subsequently shared this with a number of individuals, including Marti [sic] Malmi, so that they could send code updates to me. It was only published in 2011 by an unknown party (I suspect Marti [sic] Malmi), after I stopped the active use of the Satoshi Nakamoto pseudonym.”
“Basically, bring it on. Let's encourage Wikileaks to use Bitcoins and I'm willing to face any risk or fallout from that act”
“No, don't "bring it on". The project needs to grow gradually so the software can be strengthened along the way. I make this appeal to WikiLeaks not to try to use Bitcoin. Bitcoin is a small beta community in its infancy. You would not stand to get more than pocket change, and the heat you would bring would likely destroy us at this stage.”
“Bit Coin (Bit Coin) is a digital currency. Bit Coin offers a full peer-to-peer currency solution. P2P transfer of funds is available using methods that can even be untraceable. They’re a ways using this technology to transfer funds that cannot be intercepted or stopped. … That said, there are alternatives available in the marketplace such as Bit Coin that offer solutions to the problems that WikiLeaks faces.….”
“189:11 Q. Dr Wright, more pertinently, you did not know that 12 Satoshi was keen to discourage WikiLeaks from using 13 Bitcoin, right? 14 A. Again, I wanted people not to use the other. I'd seen 15 all the sites, I'd gone through everything with people 16 multiple times, so, no, I knew what I said. What you're 17 trying to say is because, on a site, it comes up that 18 way, which, "Bitcoin" and then "Bit Coin". It was meant 19 to be cut and paste as a hyperlink and somehow that 20 ended up funky.”
‘Accordingly, Wright has publicly asserted that one of the ways he can prove he is Satoshi is by referencing his ability to make transactions associated with the Genesis Block and other early Blocks. To date, Wright has failed to do so.’ is Satoshi is by referencing his ability to make transactions associated with the Genesis Block and other early Blocks. To date, Wright has failed to do so.’
“In my view, the evidence provided in the signing sessions cannot be considered as reliable in establishing possession of the private key(s) corresponding to the public key(s) used”
“Ok Satoshi. Your writing is REALLY impressive.”
“This data is thus replayed from those transactions, which… means it provides no cryptographic evidence of the possession of the associated private key.”
“I will present what I believe to be ‘extraordinary proof’ and ask only that it be independently validated.”
‘i) The touchstone is utility; ii) The deployment of negative declarations should be scrutinised and their use rejected where it would serve no useful purpose; iii) The prime purpose is to do justice in the particular case; iv) The Court must consider whether the grant of declaratory relief is the most effective way of resolving the issues raised. In answering that question, the Court should consider what other options are available to resolve the issue; v) This emphasis on doing justice in the particular case is reflected in the limitations which are generally applied. Thus: a) The court will not entertain purely hypothetical questions. It will not pronounce upon legal situations which may arise, but generally upon those which have arisen. b) There must in general, be a real and present dispute between the parties before the court as to the existence or extent of a legal right between them. c) If the issue in dispute is not based on concrete facts the issue can still be treated as hypothetical. This can be characterised as “the missing element which makes a case hypothetical.” vi) Factors such as absence of positive evidence of utility and absence of concrete facts to ground the declarations may not be determinative; Zamir and Woolf note that the latter “can take different forms and can be lacking to differing degrees”. However, where there is such a lack in whole or in part the court will wish to be particularly alert to the dangers of producing something which is not only not utile, but may create confusion.’
‘Declaratory relief will be granted only where there is a real dispute between the parties: Gouriet v Union of Post Office Workers[1978] AC 435 per Lord Diplock at p.501: “…The only kinds of rights with which courts of justice are concerned are legal rights; and a court of civil jurisdiction is concerned with legal rights only when the aid of the court is invoked by one party claiming a right against another party, to protect or enforce the right or to provide a remedy against that other party for infringement of it, or is invoked by either party to settle a dispute between them as to the existence or nature of the right claimed. So for the court to have jurisdiction to declare any legal right it must be one which is claimed by one of the parties as enforceable against an adverse party to the litigation, either as a subsisting right or as one which may come into existence in the future conditionally on the happening of an event … … the jurisdiction of the court is not to declare the law generally or to give advisory opinions; it is confined to declaring contested legal rights, subsisting or future, of the parties represented in the litigation before it and not those of anyone else.”’