Hermes

Bitcoin from First Principles

Bitcoin, built from nothing. No crypto libraries, no magic. The secp256k1 curve, the hashes, the signatures, the proof of work, the network, all rebuilt by hand and turned into things you can touch. Nineteen interactive windows onto how a chain of numbers becomes money nobody can forge.

Layer 1 · The Primitives
01
Elliptic curve

The Curve

secp256k1's group law, made geometric. Your private key is a number; your public key is a point on a curve.

Open →
02
Hashing pipeline

Key → Address

Watch a 256-bit secret become an address through SHA-256, RIPEMD-160 and Base58Check. Flip a bit, see the avalanche.

Open →
03
ECDSA

Sign & Forge

Sign a message, verify it, then reuse one nonce across two signatures and watch the private key fall out.

Open →
04
Proof of work

Mine & Chain

Grind a nonce until the hash clears the target, link blocks together, then tamper with one and break the chain.

Open →
Layer 2 · The Systems
05
Consensus

Network & the 51% Attack

Nodes gossip, forks appear and an attacker rewrites a "confirmed" payment.

Open →
06
On-chain

Real Testnet

Build, sign and broadcast a genuine transaction to the Bitcoin testnet.

Open →
07
Stack machine

Script VM

Step through Bitcoin's tiny programming language: P2PKH, multisig, hash locks, timelocks.

Open →
08
BIP-32 / 39

HD Wallet

One seed phrase unfolds into a whole tree of addresses.

Open →
09
P2WSH custody

Multisig Vault

Three keys, one address, a 2-of-3 rule. Lose a key and your coins are safe; lose a thief's, and so are they.

Open →
10
Merkle / SPV

Merkle Proofs

A block fingerprints every transaction in 32 bytes. Prove one is included with a handful of hashes, no full block needed.

Open →
11
BIP-340 / 341

Taproot & Schnorr

Bitcoin's cleaner signature: keys that add, one joint signature for many owners and the tweak behind every bc1p… address.

Open →
12
BIP-327

MuSig2

Three cosigners, one key, one 64-byte signature. The two-round ceremony that makes a multisig vault invisible, with a witness 4× smaller.

Open →
13
BOLT-3 · Layer 2

Lightning Channels

Pay off-chain thousands of times, trustlessly. Publish a revoked state and the revocation key lets your counterparty take everything.

Open →
14
HTLC · Layer 2

HTLC Routing

One payment hops Alice→Bob→Carol with no direct channel. A single preimage settles the whole path; decreasing timelocks keep the middle honest.

Open →
15
RFC 9591

FROST Threshold

Any t of n key-holders sign: 2 of 3, and any one alone can't. One Schnorr signature, the group secret never assembled.

Open →
16
Adaptor sigs · Layer 2

PTLC Routing

Route a payment with point-locks, not hash-locks. A Schnorr adaptor signature per hop; completing it reveals the secret and settles the path, privately.

Open →
17
BIP-340 · Taproot

FROST Taproot Vault

Re-skin FROST to BIP-340: any 2 of 3 officers key-path spend a bc1p vault with one signature, indistinguishable on-chain from a lone wallet.

Open →
18
BOLT-3 · Layer 2

HTLC Second-Stage

Force-close with a payment in flight: the HTLC-timeout / HTLC-success transactions (byte-for-byte BOLT-3), whose output is itself delayed and revocable: the penalty, one level down.

Open →
19
PedPoP · DKG

FROST DKG

Delete the trusted dealer. Each participant contributes a secret only they know; the group key is the sum, never assembled, yet any 2 of 3 still sign. Distributed key generation, from scratch.

Open →