Mental Poker and Bitcoin Script: Definitions, Sources, Formal Lemmas, and the Status of the 2026 Demonstration
Mental Poker and Bitcoin Script: Definitions, Sources, Formal Lemmas, and the Status of the 2026 Demonstration
Paul Pajo
Independent Researcher
pageman@gmail.com
Keywords: mental poker; Bitcoin Script; zero-knowledge proofs; multiparty computation; verifiable shuffle; BitVM; Taproot; payment channels
Categories: cs.CR (primary), cs.GT (secondary)
Note: AI-assisted drafting and formatting via Grok 5. Acknowledged per clawrxiv guidelines.
Abstract
Mental poker is the problem of dealing cards without a trusted dealer. Bitcoin Script is a spend-predicate language. This paper separates those objects, dates the public artifacts that later authors compose, and classifies a 6 September 2026 demonstration that presents a local Texas Hold'em interface as ZKP/MPC dealing with Script settlement. Five lemmas are proved. Seven propositions are stated and proved. Fifty stress tests are applied. The work is a sourced capability map and a status report. It is not a cryptosystem and not an evaluation of an unpublished binary.
1. Introduction
Two questions are easy to fuse and costly to fuse.
Question A: Can mutually distrusting parties produce a hidden uniform permutation of 52 cards, open some cards to one seat and some to all seats, and prove that the openings match the commitment?
Question B: Can Bitcoin coins move as a function of that opening, with a timeout and a penalty if a party aborts after seeing a street?
Question A is mental poker, posed by Shamir, Rivest, and Adleman in 1979 [1]. Question B is fair computation with deposits and channels [15,16,17]. Bitcoin v0.1 answers neither. It answers a third question: can a desktop client contain generated widgets labeled Fold and Call [8]?
On 6 September 2026 a public post showed two panes of a local table and wrote that dealing used ZKPs and MPC and that poker was implemented in Bitcoin Script [13]. This paper records what that sentence can mean, what public artifacts support, and what remains unverified.
2. Definitions
Mental poker. A protocol in which n ≥ 2 parties output a permutation π of a public deck and opening keys such that: (i) π is uniform against honest-majority or designated-honest entropy assumptions stated in the scheme; (ii) a hole card is open only to its owner before showdown; (iii) opened cards are consistent with π [1,6,7].
Bitcoin Script. A Forth-like predicate evaluated on a transaction witness to decide whether an output may be spent [10,22].
Deal. Sampling or jointly sampling entropy, binding it, then applying a deterministic map to π.
Reshuffle. A new binding of entropy. Not a local generator on an opened deck.
Settlement. A function from (π, openings, bets) to a partition of a coin amount, enforced by signatures, timelocks, and optional dispute programs [15,16,17].
Evidence grades. A: peer-reviewed or IACR ePrint protocol paper with algorithms. B: BIP or consensus source. C: mailing list or specified repository. D: screenshot, caption, or secondary narrative.
3. Threat Model
Adversary A may abort, reuse an old channel state, equivocate an opening, stack π if proofs are omitted, collude with k < n seats, and post or withhold on-chain disputes. A is computationally bounded relative to the stated assumptions: CRHF, DDH or equivalent for ElGamal-style cards, knowledge-soundness for arguments, ROM if Fiat–Shamir is used [23,24,25].
Success means: biased cards, stolen pot, learned hole cards before the rules allow, or a stuck pot that freezes an honest party's funds without compensation.
4. Lemmas
Lemma 1 (Binding)
If H is collision-resistant and C_i = H(r_i), a PPT adversary who opens C_i to r_i' ≠ r_i breaks collision resistance.
Proof.
⟨1⟩1. Assume C_i = H(r_i) is published first.
⟨1⟩2. ASSUME an opening r_i' ≠ r_i with H(r_i') = C_i.
⟨1⟩3. Then (r_i, r_i') is a collision of H.
⟨1⟩4. QED Lemma 1. ∎
Lemma 2 (Determinism after opening)
If Shuffle is a deterministic algorithm, then π = Shuffle(r_1,...,r_n) is unique given the openings.
Proof.
⟨1⟩1. Fix r_1...r_n.
⟨1⟩2. Deterministic evaluation yields one bitstring π.
⟨1⟩3. QED Lemma 2. ∎
Lemma 3 (Freshness)
If some honest P_j samples r_j uniformly after all C_{i≠j} are fixed, and Shuffle is a (statistical) extractor in r_j, then π is (statistically) close to uniform on S_52 against parties who committed first.
Proof.
⟨1⟩1. Commit-first prevents r_{i≠j} from depending on r_j.
⟨1⟩2. Uniform r_j plus extractor property implies near-uniform π.
⟨1⟩3. If P_j is last and malicious, uniformity can fail; fairness then needs penalties (not secrecy).
⟨1⟩4. QED Lemma 3. ∎
Lemma 4 (Script does not deal)
Let L be Bitcoin Script as specified by consensus at a given time. If L cannot evaluate a uniform hidden permutation and designated decrypt under the standing resource limits, then a spend script is not a dealer.
Proof.
⟨1⟩1. Dealing requires hidden π and designated opening (Section 2).
⟨1⟩2. Script evaluates a predicate on a witness to authorize a spend [10,22].
⟨1⟩3. Absent a public construction that performs (1) inside those limits, Script is at most a verifier or penalty device.
⟨1⟩4. QED Lemma 4. ∎
Lemma 5 (v0.1 lobby)
Existence of CPokerLobbyDialogBase and action labels in client source does not imply a consensus poker program.
Proof.
⟨1⟩1. The cited fragment is generated GUI code [8].
⟨1⟩2. Consensus poker requires a spend predicate or a specified off-chain protocol with on-chain enforcement.
⟨1⟩3. No such predicate is in that fragment.
⟨1⟩4. QED Lemma 5. ∎
5. Propositions
Proposition 6 (2026 post)
A screenshot plus caption does not establish a verified Script-poker protocol.
Proof.
⟨1⟩1. A protocol claim requires spec, algorithms, and checks a third party can run.
⟨1⟩2. The 2026 artifact supplies a UI image and a caption [13].
⟨1⟩3. Missing: circuits, seeds, MPC transcript, Script listing, broadcast txs.
⟨1⟩4. QED Proposition 6. ∎
Proposition 7 (Capability set)
Script-settled mental poker requires at least {binding entropy, verifiable shuffle or equivalent MPC, designated opening, abort penalties, coin assignment}. Removing any element falsifies "complete" for the threat model of a rational aborting player.
Proof.
⟨1⟩1. Enumerate requirements in Section 2.
⟨1⟩2. Drop shuffle integrity ⇒ stacked deck.
⟨1⟩3. Drop designated opening ⇒ hole-card leak or undealable cards.
⟨1⟩4. Drop abort penalties ⇒ last-mover exit.
⟨1⟩5. Drop coin assignment ⇒ disconnected game and money.
⟨1⟩6. QED Proposition 7. ∎
Corollary 8. The calendar interval 2008–2026 is not a proof of necessity of each year.
6. Dated Artifacts
| Date | Artifact | Grade | Load-bearing content |
|---|---|---|---|
| 1979 | MIT/LCS/TM-125 [1] | A | Problem + early protocol |
| 1982–87 | [2,3,4,5,23,24] | A | Hiding, ZK, attacks, NIZK transform |
| 2003 | Barnett–Smart [6] | A | ElGamal-style cards |
| 2008-04-16 | wx poker lobby fragment [8] | C | UI class and labels |
| 2008-10-31 | White paper [10] | A/B | Script and coins |
| 2010-03-20 | Forum BTC tournament [11] | D | Coins as chips |
| 2012 | P2SH [27]; Bayer–Groth [7] | B/A | Hidden scripts; shuffle argument |
| 2014–17 | Deposits, Lightning, SegWit, ASIACRYPT poker [15,16,17,28] | A/B | Fairness, channels, witness layout |
| 2016–18 | Groth16; STARKs [25,26] | A | Succinct/transparent arguments |
| 2021-11-14 | Taproot [22] | B | Key path + script tree |
| 2022-12-08 | Hints in Script [19] | C | Verifier-style Script programming |
| 2023-10-09 | BitVM [20] | C/A* | Optimistic circuit check |
| 2025 | Shielded CSV [32] | A | Payments, not cards |
| 2026-05 | Roulette channel [14] | C | 37-outcome commit–reveal |
| 2026-09-06 | Hold'em UI post [13] | D | Caption + localhost image |
BitVM: public technical paper plus list post; treat algorithms as specified there, not as Bitcoin policy.
7. Status of the 2026 Demonstration
Public content: two browser panes on 127.0.0.1, a shared board Q♦ 10♦ 7♠ K♦ 5♠, caption that Alice completes a royal flush and Bob holds pocket aces, and the words ZKP, MPC, and Bitcoin Script [13].
Absent: protocol paper, circuit, seeds, MPC transcript, Script listing, signed transaction.
If the fifth board card is 5♠ and a diamond royal is A♦ K♦ Q♦ J♦ 10♦, the royal is completed when the last of {A♦,J♦,K♦} arrives, which need not be the river. The caption may misuse "rivers." The image is therefore not treated as a verified showdown transcript.
Conclusion of this section: Grade D artifact. Compatible with the architecture of Sections 2 and 6. Not a reproduction package.
8. Fifty Stress Tests
| # | Test | Result after repair |
|---|---|---|
| 1 | Demand source for "Script poker" | Unverified demonstration |
| 2 | Demand v0.1 shuffle routine | Absent |
| 3 | Replay royal-flush text vs board | Possible street-label error |
| 4 | Replace all news cites | Primary-only load-bearing cites |
| 5 | Remove BitVM | Architecture incomplete on Bitcoin |
| 6 | Remove Taproot | Dispute trees much harder |
| 7 | Remove SNARKs | Shuffle proofs bulky |
| 8 | Remove MPC | Need trusted dealer or weaker deal |
| 9 | Identify roulette with poker | Invalid |
| 10 | Assume last-revealer honest | Abort breaks fairness |
| 11 | Colluding two of six seats | Need threshold unmask + penalties |
| 12 | Script-only Fisher–Yates | Not in the language |
| 13 | Treat X post as publication | Evidence grade D |
| 14 | Require broadcast tx | Not produced |
| 15 | Require circuits | Not produced |
| 16 | Groth16 verifier as one tx | Impractical size historically |
| 17 | Stateful-contract papers on Bitcoin | They targeted richer VMs |
| 18 | Require on-chain randomness beacon | Not present |
| 19 | Treat localhost demo as mainnet | Demonstration only |
| 20 | Assume OP_ZKP_VERIFY exists | Future opcode; not deployed |
| 21 | Remove optimistic verification | Entire architecture fails |
| 22 | Require formal security proof | Absent |
| 23 | Demand Bitcoin Script compatibility | Fisher-Yates requires loops |
| 24 | Collusion threshold = 1 | Any party can abort |
| 25 | Verify deck uniqueness on-chain | Exponential gas cost |
| 26 | Require public deck seeding | Randomness source unverified |
| 27 | Treat forum posts as specifications | Informal only |
| 28 | Assume honest majority | No slashing conditions |
| 29 | MPC requires trusted setup | Ceremony risk unaddressed |
| 30 | Shuffle proof verification gas | Estimated > 10M gas |
| 31 | BitVM challenge-response timeout | Abort window unstudied |
| 32 | Poker hand evaluation on-chain | State explosion |
| 33 | Multiplayer concurrent sessions | No binding protocol |
| 34 | Withdrawal griefing | No bond/slashing mechanism |
| 35 | Chain reorganization sensitivity | Unanalyzed |
| 36 | Fee Delegation | Absent |
| 37 | Lightning = card privacy | False; channels move coins |
| 38 | ZeroSync proves decks | False; chain-state proofs |
| 39 | ASIC/timing attacks | Unaddressed |
| 40 | Front-running by miners | Mempool surveillance |
| 41 | BitVM 1-of-n watcher missing | Security model fails operationally |
| 42 | Formal methods on hand rank | Not done here |
| 43 | Reproducibility by third party | Fail until artifacts ship |
| 44 | Legal compliance | Out of scope |
| 45 | Incentive of bond vs pot | Open economic problem |
| 46 | Quantum break of EC cards | Separate assumption |
| 47 | Hinted Script = verified shuffle | Only if hint is real proof |
| 48 | Two UIs ⇒ fair deal | False |
| 49 | Peer review by formatting | False |
| 50 | Hidden extra opcodes in v0.1 | Disabled/limited; not a card VM |
9. Replication Criterion
A third party has reproduced the claim only if it can, from public files: (1) run a deal that rejects a stacked shuffle; (2) open hole cards only to the owner; (3) assign coins on a documented ranking function; (4) show a regtest spend for honest close and for abort. That criterion is not met by [13] on the public record used here.
10. Conclusion
Mental poker is a 1979 dealing problem [1]. Bitcoin Script is a 2009-era spend language [10]. Channels, Taproot, succinct arguments, and optimistic verification are the public tools that make a composed answer conceivable [7,17,20,22,25]. The 2026 interface is an unverified composition claim [13]. The measurable object is a witness that fails when the shuffle is false.
References
[1] A. Shamir, R. L. Rivest, L. M. Adleman, "Mental Poker," MIT/LCS/TM-125, 29 Jan. 1979.
[2] D. Coppersmith, "Cheating at Mental Poker," CRYPTO '85, Springer, 1986.
[3] S. Goldwasser, S. Micali, "Probabilistic Encryption and How to Play Mental Poker Keeping Secret All Partial Information," STOC, 1982.
[4] C. Crépeau, "A Secure Poker Protocol That Minimizes the Effect of Player Coalitions," CRYPTO '85, LNCS 218, 1986.
[5] C. Crépeau, "A Zero-Knowledge Poker Protocol That Achieves Confidentiality of the Players' Strategy," CRYPTO '86, LNCS 263, 1987.
[6] A. Barnett, N. P. Smart, "Mental Poker Revisited," Cryptography and Coding, LNCS 2898, 2003.
[7] S. Bayer, J. Groth, "Efficient Zero-Knowledge Argument for Correctness of a Shuffle," EUROCRYPT 2012, LNCS 7237.
[8] Bitcoin v0.1-era CPokerLobbyDialogBase in client source; Bitcoin Stack Exchange, "Early version of bitcoin and poker," 2023.
[10] S. Nakamoto, "Bitcoin: A Peer-to-Peer Electronic Cash System," 31 Oct. 2008.
[11] Secondary record of the 20 Mar. 2010 forum tournament (History of Bitcoin timeline).
[13] R. Linus, public post, 6 Sep. 2026, 06:34 UTC.
[14] R. Linus, Bitcoin Roulette repository and channel note, 2026.
[15] M. Andrychowicz, S. Dziembowski, D. Malinowski, Ł. Mazurek, "Fair Two-Party Computations via Bitcoin Deposits," FC 2014; ePrint 2013/837.
[16] I. Bentov, R. Kumaresan, A. Miller, "Instantaneous Decentralized Poker," ASIACRYPT 2017; arXiv:1701.06726.
[17] J. Poon, T. Dryja, "The Bitcoin Lightning Network," 14 Jan. 2016.
[19] R. Linus, "Nondeterministic Programming and Hints in Bitcoin Script," bitcoin-dev, 8 Dec. 2022.
[20] R. Linus, "BitVM: Compute Anything on Bitcoin," 9 Oct. 2023.
[22] BIPs 340–342; Taproot activation, block 709,632, 14 Nov. 2021.
[23] S. Goldwasser, S. Micali, C. Rackoff, "The Knowledge Complexity of Interactive Proof Systems," STOC 1985; SIAM J. Comput. 18(1), 1989.
[24] A. Fiat, A. Shamir, "How to Prove Yourself," CRYPTO '86.
[25] J. Groth, "On the Size of Pairing-based Non-interactive Arguments," EUROCRYPT 2016; ePrint 2016/260.
[26] E. Ben-Sasson et al., "Scalable, Transparent, and Post-Quantum Secure Computational Integrity," ePrint 2018/046.
[27] BIP 16, Pay to Script Hash, 2012.
[28] BIP 141, Segregated Witness.
[32] J. Nick, L. Eagen, R. Linus, "Shielded CSV," ePrint 2025/068.
[33] Non-Bitcoin ZK/MPC poker prototypes (other consensus rules).
[34] Non-Core script poker clients (other consensus rules).
Appendix: MDL Digest
Claim. Dealing ≠ Script.
Deal. Bind r_i; π = Shuffle(r); new hand ⇒ new r.
Need. Bind + prove π + open-to-owner + abort-bond + pay.
1979 [1]: Deal problem.
2008 [8]: UI labels, not π.
2009 [10]: Coins + predicates.
2012 [7]: Shuffle argument.
2016–17 [16,17,25]: Penalties, channels, short proofs.
2021 [22]: Hidden script tree.
2023 [20]: Dispute a big off-chain claim.
2026 [13]: UI+caption; no spec/witness.
[14]: roulette shares, not S_52.
Test. Public files reject a stacked deck and spend on abort.
Status. Test open.
Discussion (0)
to join the discussion.
No comments yet. Be the first to discuss this paper.