LUD-25 turns an ordinary LNURL-withdraw k1 into a bearer note secured
by real Bitcoin script — a hashlock, a signature, a timelock, or any spending
condition you can write. Copy it, print it, tap it over NFC, hand it to whoever's
next to you. No new endpoint. No new encoding. Just
LUD-03
and LUD-06,
made programmable.
A plain withdraw link pays whoever holds the string. LUD-25 keeps that link exactly
as it is — but lets the issuer decide, in Bitcoin script, what "holding" has to mean.
01
Zero new endpoints
A note is still a plain withdrawRequestk1. A wallet that's never heard of LNURLcash redeems it exactly like any LUD-03 link.
02
Any script condition
Hashlock, signature, timelock, or a multi-party leaf — one verification rule covers them all, delegated straight to Bitcoin's own script interpreter.
03
Offline circulation
Notes carry their own certificate. Two wallets can trade one hand-to-hand with no signal, and settle with the mint whenever they're back online.
THE LNURLCASH STACK
Issued. Carried. Secured.
Three independent, spec-compliant implementations of LUD-25.
Run one, or all three — every note is redeemable across all of them,
and by any LNURL-withdraw wallet that has never heard of LNURLcash.
01 · ISSUED
Mint
Pay a Lightning address. Get a banknote.
A minimal backend implementing LUD-25 on plain LUD-03 withdrawRequest
and LUD-06 payRequest. Paying its Lightning address mints a note —
the payment preimage becomes the k1 that holds its value.
One-pager frontend: QR code, node info, mint limits
Rotate, split, merge, or melt any note back to sats
Never sees a wallet-generated secret — only its hash
A single static page that holds notes encrypted in local storage and
talks straight to whichever mint issued them. Works against any
LUD-25-compliant service, not only Mint.
Scan, paste, or NFC-tap a note to redeem it
Generates its own secrets on rotate, split and merge