PyCoin (PYC)Hi everyone,
I wrote a small proof-of-work cryptocurrency from scratch in Python. It is not a Bitcoin fork, the code is about a dozen small files, and every node keeps and verifies its own copy of the chain (no central server). It is a hobby/educational project: it works, and I'd like people to run nodes, break things and tell me what is wrong with the networking and consensus code.
Source code:
https://github.com/litenonce/pycoinInfo and downloads:
https://renderon.netSpecs- Algorithm: double SHA-256, same idea as Bitcoin
- Signatures: ECDSA on secp256k1, with per-address nonces against replay
- Addresses: SHA-256 + RIPEMD-160, base58 with checksum
- Block reward: 10 PYC per block (plus fees), no halving
- Difficulty: starts at 1 bit, +1 bit every 50 blocks (based on height, not on time)
- Supply: no cap, it grows by 10 PYC per block
- Premine: none. ICO: none. Dev fee: none. The genesis block is empty and every coin comes from mining
- Network: home-made JSON-over-TCP protocol, default port 9333
- Language: Python 3, the only dependency is cryptography
How the network works- Nodes handshake, exchange peer lists, and gossip new blocks and transactions
- A node that sees a peer with more cumulative work finds the last common block (binary search), downloads the missing blocks, re-validates everything from scratch and switches if the branch is valid and heavier
- Transactions from orphaned blocks go back to the mempool
- Everything received from the network is treated as untrusted: signatures, balances, nonces, PoW, difficulty, coinbase amount, timestamps and malformed fields are all checked
- A peer that sends an invalid chain is banned for the session
Wallet / minerTkinter wallet with a built-in miner, a block explorer tab and a Transaction History tab where each transaction is shown as
Pending (in the mempool) or
Done (in a block). Optional 6-word recovery phrase (PBKDF2, locks after 3 wrong attempts).
Running a nodegit clone https://github.com/litenonce/pycoin
cd pycoin/server
pip install -r requirements.txt
python node_server.py --peer IP:PORT
Open TCP 9333 if you want other people to be able to connect to you. A node behind NAT still works (it connects outward, syncs and mines). Seed node:
PUT YOUR NODE IP:PORT HEREDownloads (Windows x64)Pre-built executables, for people who don't want to install Python. The wallet + miner (client.exe) and the node (node.exe) are on the download page:
https://renderon.netSHA-256 client.exe: ec4a7866ef39c93e8f2193cd2534d5ad3972cae710bd888b2f8d83f9064883f8
SHA-256 node.exe: 2cdbe409d832dd88dbb82a03ccaaca5f842614ec644e0c4460196b61c9b08563
Check the hash after downloading (
certutil -hashfile client.exe SHA256 on Windows). The executables are built with PyInstaller from the source in the repo, and they are not code-signed, so Windows SmartScreen will probably warn you. If you don't trust an exe from a stranger (you shouldn't, blindly), run it from source instead: it's a few short files.
Known limitations (please read)- The recovery phrase travels in clear inside its transaction until it is mined, and on a P2P network it is gossiped to every node. Someone relaying it could swap in their own key. Fixing it properly needs a commit-reveal scheme, which I have not done
- wallet.dat (the private key) is not encrypted
- No encryption between nodes, no Sybil protection, only basic size limits against DoS
- It has only been tested with a few nodes on my own machine (gossip, pending to done, fork reorganization, restart from disk). I don't know how it behaves on a real network
- Difficulty depends on height only, so with a lot of hash power the chain will run faster than any target time
What this is notPYC has no market value and I am not promising any. It is not an investment, it is not listed anywhere, and I'm not asking for money. If you want to mine it, run a node or read the code, great.
What I'd like feedback on- The fork choice / reorganization logic
- The sync protocol (is there an obvious way to make a node waste bandwidth or stall another one?)
- A sane replacement for the height-based difficulty
- A safer recovery scheme
Questions and criticism welcome.