⏸Cherry Graffiti
|
AgentsAppsAutomationBitPensionBlogBoardroomBondsBuildButtonsCareersCashboardClientsComponentsContactContentContractsCoursesCreativeDevelopersDividendsDocsExchangeFoundersGigsKintsugiLibraryMarketMetanetMintMoneyButtonMusicPackagesPipelinePortfolioPricingProjectsRewardsRoadmapSchematicsServicesSkillsSmart ContractsStudioTaaSTokensToolsTreasuryVideoWebsitesWorkAgentsAppsAutomationBitPensionBlogBoardroomBondsBuildButtonsCareersCashboardClientsComponentsContactContentContractsCoursesCreativeDevelopersDividendsDocsExchangeFoundersGigsKintsugiLibraryMarketMetanetMintMoneyButtonMusicPackagesPipelinePortfolioPricingProjectsRewardsRoadmapSchematicsServicesSkillsSmart ContractsStudioTaaSTokensToolsTreasuryVideoWebsitesWork
Back to Blog
Featured

The Someone Problem

The Someone Problem
Richard Boase
|
5 min read
|6 March 2026|
TOKEN: the-someone-problem
.MD Source
$401bit-signidentityelectronic-signaturesattributionnon-repudiationBSVAerotekWright

There is a peculiar species of engineering failure that consists not in building the wrong thing but in building the right thing for the wrong question. For thirty years, electronic signature systems have answered "what does the mark look like?" with increasing sophistication — typed names, email headers, clicks, biometric scans, cryptographic hashes. The question on which enforceability actually depends — whose mark is this? — has been treated as someone else's problem.

Craig Wright's recent essay, The Mark That Belongs to No One, identifies this omission with a precision the technical community should find uncomfortable. The thesis is one sentence: in American private-law signature doctrine, a signature does not satisfy the signature requirement for enforcement unless it is attributable to an identifiable legal person. That is not a proposal. It is a description of what the law already requires and has required since the Statute of Frauds was enacted in 1677.

Wright is a contested figure. That caveat has applied in every essay in this series that references his work, and it applies here. But the argument stands independent of the person making it, and in this case the argument is structural: five sources of American signature doctrine — the Statute of Frauds, the UCC, the Restatement, E-SIGN, and the UETA — each using different vocabulary, each drafted by a different body, each containing the same requirement. There must be a person. And the person must be identifiable.

I. The Three-Step Framework

Wright derives a decision procedure for analysing any disputed signature. The procedure is descriptive — it describes what courts are already doing.

Step 1: Formal Validity. Is the act a "signature" under applicable law? The law's answer has always been maximally permissive. An "X" suffices. A typed name suffices. A rubber stamp, a fax header, an email "from" field, a click on a button. Step 1 is rarely where a disputed signature fails.

Step 2: Attribution. Is the signature attributable to a legal person identifiable through evidence available to a court? This is the critical step — where the analysis shifts from the properties of the mark to the identity of the person. Attribution is not a property of the signing act. It is a property of the evidentiary record available at enforcement. A signing act perfectly identified at execution may fail Step 2 if witnesses die and records are lost. A pseudonymous blockchain transaction may satisfy Step 2 if chain analysis or compulsory process can recover the signer.

Step 3: Consequences. If Steps 1 and 2 are satisfied, any remaining claim of "anonymity" reduces to pseudonymity or privacy — neither defeats enforceability. If Step 2 fails, enforcement collapses. There is no "party to be charged."

The framework is elegant because it separates what technologists have conflated. Cryptographic sophistication is a Step 1 property — it ensures the mark is durable and tamper-resistant. Attribution is a Step 2 property — it links the mark to a person. A 4096-bit RSA key pair with a self-signed certificate is, from the standpoint of enforcement, legally identical to an illiterate farmer's "X" with no witnesses. Both are marks that cannot, without additional evidence, be linked to any identified person.

II. The Non-Repudiation Myth

This should be uncomfortable for anyone building on blockchain. The entire digital signature ecosystem — PGP, Ethereum wallet signatures, Bitcoin's ECDSA — has been engineered around integrity and non-repudiation of the key. The textbooks say: if you hold the private key, you cannot deny having signed. Therefore the signature is attributable.

This is wrong, and it is wrong for reasons that predate computers by centuries. A person can be forced to sign under duress. A key can be compromised without the holder's knowledge. A custodial service can sign on behalf of a user without their specific intent for a specific document. An employer can require an employee to use a shared credential. A phishing attack can harvest keys. In every one of these cases, the cryptographic proof is perfect — the correct key signed the correct message — and the attribution is broken.

Non-repudiation is a property of mathematics, not of law. Courts do not care that the private key was used. Courts care whether the person intended to sign this document for this purpose. The gap between "the key signed" and "the person signed" is exactly the gap Wright identifies, and it is the gap that thirty years of cryptographic engineering have declined to close.

The link between key and person has been treated as an externality. Wright's essay demonstrates that this externality is, in fact, the only thing that matters for enforcement.

III. The Aerotek Standard

If the three-step framework is the skeleton, the Texas Supreme Court's 2021 decision in Aerotek, Inc. v. Boyd is the musculature. Four employees completed an online hiring application requiring unique login credentials, personal identifying information, and electronic signature of an arbitration agreement. All four later denied signing. Aerotek produced timestamped audit logs, witness testimony about the system's design, and an in-court demonstration that the application could not be submitted without signing.

The Court held that once the proponent demonstrates the efficacy of the system's security procedures, the burden shifts to the alleged signer to produce evidence — not mere denial — of how the signature could have appeared without their act.

Wright distils this into a four-element test. One: the system restricted access through a unique credential not known to the proponent. Two: the system recorded the act as performed through that credential. Three: a rebuttable inference that the signature was the credential holder's act. Four: the alleged signer may defeat the inference by producing evidence of compromise or unauthorised access — but must produce evidence, not speculation.

This is a litigation standard. Something courts can quote. Something engineers can build for.

IV. What the Attribution Layer Requires

Reading Wright's framework as an engineering specification produces five concrete requirements for any system claiming to produce enforceable electronic signatures.

Requirement 1: A root identity anchor. The signing credential must be linked to an identity record that exists independently of any single transaction — the digital equivalent of the attesting witness who watched the farmer press his mark.

Requirement 2: Graduated attestation. Not all identity evidence is equal. An OAuth login is weaker than a government-issued ID verified by a third party. The architecture should make the strength of the attribution chain explicit and auditable.

Requirement 3: Attestation portability. If a person verifies their identity through a KYC process for one purpose, that verification should be usable across every system reading the same protocol. Identity is a property of the person, not of the platform. A KYC attestation recorded on-chain as a portable credential is what portability looks like. The verification happens once. The attestation travels.

Requirement 4: On-chain persistence. The evidentiary record must survive the platform that created it. The attribution evidence — not just the signature hash, but the identity links — must be inscribed on an immutable ledger.

Requirement 5: The agency chain. Attribution to the wrong person is attribution failure. The system must record delegation — this person authorised that person to sign on their behalf — as an auditable, on-chain relationship.

V. The $401 Protocol and bit-sign.online: An Honest Assessment

The $401 identity protocol described in the first essay in this series was designed around a version of these requirements — not derived from Wright's framework, which had not yet been published, but convergent with it. bit-sign.online is the first operational implementation. It is early-stage, and measuring it against Wright's five requirements produces a mixed but instructive scorecard.

Requirement 1 — Root anchor: satisfied. The protocol defines a root identity token inscribed on the BSV blockchain: { p: "401", op: "root" }. One root per handle, immutable, referenced by every subsequent strand.

Requirement 2 — Graduated attestation: satisfied. Identity strength is calculated across four levels — Basic (OAuth only), Verified (self-attestation or ID documents), Strong (paid signing or peer attestation), and Sovereign (third-party KYC). Crucially, the levels are type-gated, not score-gated: fifty OAuth connections still produce Level 1. A single paid signing strand elevates to Level 3. This reflects the evidentiary gradation courts will apply.

Requirement 3 — Attestation portability: satisfied by design. Every strand follows a canonical JSON format inscribed via OP_RETURN, verifiable by any system querying the BSV blockchain through WhatsOnChain or equivalent. A dual-write pattern syncs strands across the bit-sign and path401 databases, but the on-chain inscription is the authoritative record. Any system implementing the $401 spec can read any strand without trusting bit-sign.online. When third-party KYC is wired in — and it is not yet — the resulting attestation will be a $401 strand like any other: portable, on-chain, readable by any system implementing the protocol.

Requirement 4 — On-chain persistence: satisfied. Root tokens, strands, and document signing records are inscribed as BSV OP_RETURN transactions. If bit-sign.online shuts down tomorrow, every inscription remains on the ledger, parseable by anyone who reads the $401 format.

Requirement 5 — Agency chain: not satisfied. This is the gap. The current architecture has no delegation model — no mechanism to record "this identity authorised that identity to sign on its behalf." Co-signing and peer attestation exist, but these are attestation flows, not delegation flows. The $403 authorisation protocol is the intended home for agency chains, but it remains planned rather than built.

The document signing flow produces something close to the Aerotek evidence package: unique credential (HandCash wallet key), identity-linked audit trail ($401 root plus strands), timestamped record of the signing act (on-chain inscription), and document integrity proof (SHA-256 hash). Whether this evidence is sufficient for a court applying the Aerotek framework is an untested question. The system produces the record. Courts will determine its weight.

VI. What This Series Has Been Building Toward

The Bit Trust proposed an open protocol for distributed IP. The problem exchange proposed tokenising infrastructure challenges. The substrate of consent proposed proof-of-indexing as the recording layer for copyright enforcement.

Each essay identified the same structural dependency. The Bit Trust records contributions — but contributions must be attributable to contributors. The problem exchange prices solutions — but solutions must be attributable to solvers. The consent layer records indexing events — but consent must be attributable to rights holders.

Attribution is the invariant. It runs through every layer of the stack, from the Statute of Frauds to the BSV blockchain, from the attesting witnesses of 1677 to the identity strands of 2026. The technology changes. The requirement does not.

A mark must belong to someone. That is not a new rule. It is the oldest rule. And it is the one that nobody bothered to build for.


This is the fourth essay in a series. Previous: Path402 & The Bit Trust | $AGI & $SPV: What's Your Problem? | The Substrate of Consent

More Articles
Get in Touch