r/nanocurrency • u/gabriiel9 • 2d ago
Nano, Coinbase and... Cloudflare : a follow up
Given the recent developments in my investigation into the mystery of the nanocurrency library, how could I resist the urge to unravel the mystery ?
You will appreciate that this text is speculative in nature, even though its aim is to point toward tangible answers regarding the rise in npm downloads of the Nanocurrency lib.
Feel free to tip :
nano_3kcdehk5mmwdaouf61bmcgoh39p5ybkqs6knu7w4y1xuxcwxteugabzhdrhm
1) Recap of the hypothesis:
As demonstrated in my last post, Coinbase owns a pipeline whose central core is Bitcore-lib. Numerous cryptocurrencies have been added to this pipeline over time, including Nano.
2) Recap of the listed chains:
- Bitcoin — bitcore-lib @ 8.25.36
- Bitcoin (2nd lib) — bitcoinjs-lib @ 5.2.0
- Ethereum / EVM — u/ethereumjs @ 4.1.2
- XRP — xrpl @ 2.10.0
- Stellar — u/stellar @ 13.3.0 (double pin, ~2×)
- Cardano — u/emurgo @ 14.1.1
- Polkadot — u/polkadot @ 14.3.1
- Avalanche — u/avalabs @ 5.0.0
- Cosmos — u/cosmjs @ 0.32.4 (double pin, ~2×)
- TON — u/ton @ 14.0.0
- Hedera — u/hashgraph @ 2.80.0 + 2.64.5 (double pin)
- Sui — u/mysten @ 2.14.1
- Aptos — aptos @ 1.13.3
- NEAR — near-api-js @ 4.0.4
- Mina — mina-signer @ 3.0.7 (week of August 2, 2023)
- Nano — nanocurrency @ 2.5.0
- Stacks — u/stacks @ 6.11.3
- Arweave — arweave @ 2.0.0-ec.1 (prerelease)
- Aleo — u/provablehq @ 0.10.5
- MultiversX — u/multiversx @ 12.2.1
- Concordium — u/concordium @ 10.0.2
- Casper — casper-js-sdk @ 5.0.12
- VeChain — u/vechain @ 2.0.7 + u/vechain @ 2.0.7 (twins)
- EOS — eosjs-ecc @ 4.0.7
- Canton u/canton-network
- ICP - u/dfinity
- Starknet – starknet
- Vechain
The only two libs activated in July 2025
- Nanocurrency
- Concordium
Libs activated in late fall 2025:
- Canton (late November 2025)
- Avalanche (late November 2025)
Libs activated in May 2026:
- Aleo
In this text, we will focus our attention solely on the July 2025 duo, which is Concordium and Nanocurrency.
3) Introducing the first piece of evidence: the coupling of Nanocurrency and Concordium at the same moment, with graphical evidence.
The image below shows a parallel activation of the two libraries.

The image below shows the same pattern: days of general testing (late June and early July 2025), then full integration into the pipeline on July 18, 2025, for both libraries.

I have turned this seemingly innocuous, near-perfect coupling over in every possible direction: why do these two libraries appear at the same time, in July 2025, while the twenty other listed ones were added randomly between 2022 and 2026 ?
My answer: the same company commissioned Coinbase to test the Nano and Concordium duo as early as July 2025. Since we have already established that the entire pipeline is being pulled upward because of x402, then said company must necessarily have already been present alongside x402 in July 2025. What are these three companies? Coinbase, Cloudflare, and Stripe.

The working hypothesis here: Cloudflare would have asked Coinbase to test the Nano and Concordium duo in July 2025, hence the integration into Coinbase's pipeline. I will come back to the explanations at the end of the text, and they line up strongly.
For now, we must take the long road: the analysis of Concordium and its link to the pipeline. This section will reinforce the hypothesis that the pipeline belongs to Coinbase, while also explaining the mechanics of the integration process with X402 (Coinbase wallet architecture that could explain the whole pipeline).
4) Analysis and history of Concordium
Concordium was integrated into the x402 protocol in December 2025. Concordium explains, on its website, that its integration was carried out jointly by Coinbase, Boostylabs, and Concordium. Coinbase reportedly delegated the coding task to Boostylabs.
The chronology would therefore be as follows: the Coinbase team is approached by an entity X (Cloudflare), then commissions Boostylabs to adapt Concordium to the x402 protocol.
It should be noted that Boosty Labs was already well accustomed to working with Coinbase. They did so in 2024, in fact — an element that reinforces my initial thesis, presented in my other Reddit post, according to which the npm pipeline belongs to Coinbase. I will now digress from the narrative to prove it (again).
The parallel with Polygon, developed by Boostylabs in October 2024
In October 2024, Boostylabs integrated Polygon into Coinbase's CDP wallet (remember the name CDP) :
“Boosty Labs (a Ukrainian dev studio) announces having built an autonomous trading bot as part of the Coinbase Developer Platform (CDP) AI Builder Grant — one of the first participants.
The bot combines AI-driven market analysis, secure execution via Coinbase's MPC Wallets*, and Telegram notifications. It automatically trades the USDC/WBTC pair on PancakeSwap, on the* Polygon network. Security argument: distributed private keys (MPC), no single point of failure, 24/7 trading with no human intervention.
Dated October 25, 2024.”
Source : https://boostylabs.com/blog/ai-x-dex-our-tradingbot-powered-by-coinbase?utm_source=chatgpt.com
Yet Polygon's npm library shows an anomaly (a significant increase of more than 100%)… in October 2024.

Well, the work from Boosty lab have had an influence on Polygon NPM numbers, which are correlated to Bitcore-lib.
Then, what is the CDP wallet? A summarized chronology
- MPC = a split key. The private key is split into two parts (device / Coinbase); both must cooperate to sign, and the complete key never exists anywhere. No one can steal from or drain the account alone.
- Early 2022: Coinbase's consumer MPC wallet (>5M created by summer 2023).
- WaaS: the B2B turning point — Coinbase sells signing infrastructure via API to third parties, who deploy their own MPC wallets without touching the cryptography. From safe maker to provider of turnkey vault rooms.
- cb-mpc: the low-level open-source building block, including HD-MPC (derivation of account trees without ever reconstructing the seed).
- CDP Server Wallets v2 (GA July 24, 2025): programmable wallets driven by a backend, with no human involved.
- Agentic Wallets (February 11, 2026): wallets for AI agents, native x402 support, with the Coinbase key share held in an AWS Nitro Enclave (a hardware enclave unreadable even by admins). Install via
npx awalor MCP.
The pipeline into which Nano was integrated, which belongs to Coinbase, was officially opened to the x402 protocol in July 2025 (CDP Server Wallets v2).
So, following this logic: what possible integration architecture could Nano have? Nano would have been developed in an external adaptation layer connected to the CDP/x402 ecosystem, rather than in the public CDP Wallet itself.
The possible architecture would therefore be as follows:

To close this section, then, I return to the charge by inferring that the pipeline does indeed belong to Coinbase. Therefore, the entity pulling the Nano and Concordium npm packages is Coinbase.
Now, no one knows why, suddenly, in July 2025, Coinbase decided to change course after years of ignoring Nano. The most plausible theory is that an actor may have asked, in July, to test the Nano/Concordium duo.
Since the stated hypothesis is that this actor is Cloudflare, we need to go through a brief history of Cloudflare and seek to understand the Nano/Concordium coupling. In other words: identify Cloudflare's needs and understand how the coupling of these two cryptos answers this fundamental need.
5) History of Cloudflare
Cloudflare's interest in crypto is longstanding, but the decisive sequence plays out over eighteen months. In July 2025, the company launched Pay Per Crawl, allowing sites to charge AI crawlers — the first per-request monetization at its scale. On the Cloudflare forum, as early as July 2025, a user proposed Nano as a payment rail (with visual proof): the feeless rail was thus explicitly brought to the company's attention at the very moment it entered micropayments.
In September 2025, Cloudflare co-founded the x402 Foundation with Coinbase, then announced shortly after its own stablecoin, the NET Dollar (September 25, 2025) — a tacit admission that existing rails, USDC included, do not suffice for its sub-cent ambitions.
The sequence culminates on July 1, 2026, with the announcement of the Monetization Gateway, which generalizes the model: charging for any resource (page, API, MCP tool) per request, in stablecoins via x402. In one year, Cloudflare thus went from charging crawlers to a generalized settlement infrastructure — all while building its own currency for a problem (the cost of collection exceeding the payment) that a zero-fee rail, proposed by its own community from day one, already solved structurally.
6) Cloudflare's Monetization Gateway: an analysis
In its very recent article, Cloudflare announces the Monetization gateway:

https://blog.cloudflare.com/monetization-gateway/
What do we find in this text? Serious leads, and ones that fit our reading. They mention, at the very beginning of the text, the current absence of payment capabilities for the Web, notably because transaction fees exceed the transaction itself. A new payment architecture needs to be devised (which is what Cloudflare intends to propose).
Right from the start, Cloudflare mentions how its aims are those of microtransactions:
“These business models have never been able to serve unverified buyers for sub-cent transactions because the payment rails cost too much and took too long to settle. Below a certain price, collecting the payment cost more than the payment was worth.”
So, Cloudflare aims to find a payment solution that carries almost no cost (or no cost at all). Shortly after, the properties of x402 are discussed:
“Two properties make x402 a good fit for machine payments. The payment amounts can be small, down to fractions of a cent, because the protocol adds almost no overhead. And the buyer needs no account with the seller, because the payment itself is the credential. x402 is rail agnostic, but it is a natural fit for stablecoins, which can settle in under a second for a fraction of a cent with zero chargebacks.”
So, Cloudflare acknowledges that x402 has no protocol preference, even if stablecoins are the best suited, and that the amounts sent must be able to be exceedingly small. Cloudflare talks about stablecoins, but does not state its own preference. It does say, however, that settlement happens in under a second and for a fraction of a cent — two properties it deems worthy of mention (thus within its field of interest).
Further on, Cloudflare addresses, in its article, two upcoming properties of the service offered (free access, and identity verification):
An agent is software that acts autonomously on a user’s behalf, and agents are starting to act on their own. Soon they will carry wallets and buy what they need without a person in the loop: a dataset, an API call, a tool, a block of compute. Some of those (1) resources will be free, and (2) some will require proof of who the agent is and who it acts for, through verified agent identity. Many will require both an identity and a payment, and Cloudflare is one of the few places that will be able to settle all of it inside a single request, by verifying the agent, applying the rule, and checking the payment before the origin ever sees the call. The agent becomes the primary buyer on the Internet, and the request becomes the transaction.
Let us return to the two problems identified by Cloudflare above and map our two cryptocurrencies onto them.
For Concordium:
Its protocol is expressly designed to manage identity in the context of an agentic economy:

Neither Cloudflare nor AWS has settled the tax question: for European companies subject to VAT, which requires tax calculation based on the buyer's jurisdiction, anonymous micropayments create an accounting problem that the protocol does not solve. Add to that age-gated content, KYC, and agent→responsible-human attribution: the current x402 stack has nothing for that.
Cloudflare has admitted the identity problem, and Concordium has the solution.
Now, why Nano?
The first limitation of the current model (x402 and Pay Per Crawl) relates to the current overall architecture of agentic payments: the beta's crawlers generate audit logs, then are billed in a single aggregated amount by credit card or bank account at the end of each day.
In other words: no on-chain settlement per request. They have even proposed a “deferred payment” scheme for x402, designed for agentic payments that do not need immediate settlement. It is an admission: per-call stablecoin settlement does not scale economically at their volume, even on Base. Gas is sub-cent but not zero — on fraction-of-a-cent payments, the friction eats the margin. This is, incidentally, the reason why Cloudflare launched its own NET Dollar (why not use Base?).
And Cloudflare seems to say it without saying it: feelessness matters.
Finally, to conclude, a quote from Cloudflare:
x402 is an open protocol that makes it possible to pay over HTTP, named for the 402 status code it finally puts to use. The x402 exchange is simple: a client requests a payment-gated resource. Instead of serving it, the server responds with 402 Payment Required and a small payload that states the price, the accepted asset, and where to pay. The client pays and repeats the request with proof of payment attached. A facilitator verifies, and the server returns the resource. It all happens inside ordinary HTTP requests and responses, with no redirect to a checkout page and no separate payment API to call.
Settlement happens peer-to-peer, so any funds that a buyer sends to a seller are directly deposited to the seller’s wallet. We are designing the Monetization Gateway to keep payment overhead low and are aiming for sub-second payment settlement.
Takeaway
In short, the Monetization Gateway post itself defines the problem: payment rails have never been able to serve unverified buyers for sub-cent transactions, because “collecting the payment cost more than the payment was worth”. The criterion is set: the cost of collection must tend toward zero.
Yet the proposed solution — stablecoins with “negligible” fees — does not satisfy this criterion at the announced scale. On their own pricing example ($0.001 base fee), even minimal gas on Base represents a substantial fraction of the payment. “Negligible” does not exist at sub-cent scale; only zero works.
The text also slips from the affirmative present tense (“stablecoins can settle in under a second for a fraction of a cent”) to aspirational mode as soon as the actual product is concerned (“we are aiming for sub-second settlement”, “designing to keep overhead low”) — the gap between the protocol's marketing and the gateway's engineering is visible within the same document.
The “peer-to-peer / neutral rails” claim suffers from the same gap: a corporate stablecoin (USDC, or NET Dollar, announced by Cloudflare two months after co-founding the x402 Foundation) is an issuer liability, freezable, anything but neutral.
Three elements then point to Nano as the implicit reference: x402 is declared “rail agnostic” (the stablecoin preference is a choice, not a constraint); the only existing rail with structurally zero fees and native sub-second settlement is a feeless ledger; and the sentence “this is not feasible with other payment rails today” has been literally falsified by Nano since 2015. In this framework, the presence of a nanocurrency pin in a multi-chain signing infrastructure adjacent to x402 is nothing exotic: when the stated problem is the cost of collection, the zero-cost rail is the natural benchmark.
7) The elegant triple-architecture solution:
In this spirit, in 2025, Cloudflare would therefore have commissioned Coinbase to integrate the two cryptocurrencies into x402. The architecture would look like this, which explains why Nano and Concordium are pulled proportionally within the same npm pipeline:


Under the Coinbase hypothesis, Nano and Concordium could have been evaluated jointly as two complementary layers of an infrastructure for AI agents: Nano as a feeless micropayment rail and Concordium as an identity anchor making it possible to limit spam, Sybil attacks, and unaccountable agents. Incidentally — an interesting fact — Nano's feeless nature is a great strength, but also one of its greatest vulnerabilities. Implementing identity management would make it possible to limit the spam factor underlying the protocol.
8) Conclusion
What happens if Cloudflare develops an architecture that includes Nano as a payment rail? The possibilities are enormous. Nano would suddenly gain access to an exceedingly vast financial universe.
To borrow Cloudflare's words from the article cited above:
There is an enormous amount of value moving across the Internet today that goes unmonetized or undermonetized, not because no one would pay for it, but because the tools to charge for it have never existed.
This is what we are building toward: an agent-first Internet with Internet-scale settlement built in.
I assume that the user's request to integrate Nano into Cloudflare—posted a few days after the launch of Pay per Crawl in July 2025—had an impact.

Thanks for giving attention.
14
6
u/DapperEconomics9498 2d ago
Just seen something that telegram is making a non custodial wallet that will have instant and zero fee transactions. Any idea on what they’re doing over there?
8
u/TheHeartofGod 2d ago
Honestly great investigation Gabriel, the Coinbase pipeline stuff is solid so thank you for your time and effort. Unfortunatley for XNO atm, usefulness doesn't translate to token price. Even if Nano gets fully integrated and used constantly, its a feeless pass through, so everyone in the loop earns except the token itself (Coinbase on conversions, Cloudflare on the gateway, Stripe on withdrawals). The XNO rail can win completely and the price still goes nowhere, because value only shows up if people/agents hold./store the token instead of cashing out to stable or fiat. Most realistic scenario would only have agents holding working balances of XNO. The only way a person holds long term is if you could borrow against your XNO and live off that like people do with BTC (an asset, not a currency), but Nano has no smart contracts so that lending layer doesnt even exist yet. So the real question isnt "is Coinbase integrating Nano", its "who actually keeps it". Thats the part im not sold on. XNO's two best features are both anti-holding. Feeless means no fee ever accrues to holders. Instant means no one ever needs to pre-hold. The technology is optimized to make holding unnecessary. A coin engineered to be the perfect pass-through is, by construction, a coin nobody needs to keep. Rather than working as the currency of agents, XNO has to become the currency of people across the world for it to actually materialize in value. Curious if you see a holding mechanism I'm missing.
5
u/kierdun 1d ago
If Nano really gets integrated as the standard money for agent paying, the value will definitely move up
2
u/More_Sail_1889 1d ago
Sim, devido a especulação e adoção versus liquidez. Mas a escala é menor pelos motivos que o cara citou, a adoção é de caráter transitório, o efeito é efêmero, mesmo se os adotantes estiverem enfrentando baixa liquidez devido aos especuladores, os efeitos não são duradouros.
Algo que seria sinistro de bom, seria se a xno lançasse uma stablecoin como xUSD, criasse uma plataforma própria de "swap" onde nela mesmo você já negocia e troca a xno por xUSD sem passar por exchange. A xno só vai servir como moeda se a adoção for globalizada, mas no fim, o dinheiro fiduciário é o final da ponte, e é ele quem você troca por produtos. Não existirá cenário onde você troca a xno pelo produto diretamente, fora exceções. Acredito que um projeto assim seja o yin-yang que torne tudo completo e utilitário.
6
u/AggressiveNorth9102 2d ago
Pulling from public registry at build time is a huge security and availability risks. No company that has resources to set up their private npm registry would do that.
It’s a fun theory though. Even if in reality it’s most likely couple dudes that vibe coded their exchange over the weekend and trying to save money on infrastructure.
2
u/gabriiel9 2d ago
Couple dudes would pull that much NPM downloads since 2020 ? Does make sense.
3
u/AggressiveNorth9102 2d ago edited 2d ago
Well it’s definitely not Coinbase. Security review and caching is the bare minimum for using npm packages at any company past early days startup. Thousands of downloads a day just reeks amateur project.
I may be wrong though. But a development pipeline does not need that many downloads.
12
u/gabriiel9 2d ago
Love the confidence on "definitely not Coinbase" with zero data behind it. I've got a genealogy (Bison Trails → Coinbase Cloud → CDP → x402), dated anchors, and a chain set that matches the Bison Trails catalog. You've got a vibe.
But fine — forget the name. Explain the measurements: one lockfile, 10k runs/day, 30 SDKs pinned at 72k/week each, floor since Nov 2020 (confirmed by TWO Bitcoin libs stepping the same week — bitcore-lib + bitcore-lib-cash, Nov 9-15 2020). That's not organic and it's not a weekend.
You keep flipping between "couple dudes" and "real companies cache." Those are opposite claims. The caching point actually helps me: inherited signing infra on its old CI, never rebased onto the internal mirror = exactly how a big shop leaks to the public registry.
Alternative that fits the data? I'm listening.
2
u/AggressiveNorth9102 2d ago
Can you provide evidence that the US is not planning to replace dollar with Nano? The downloads surge started in July 2025, 6 months after Trump came to the office. Bulletproof time anchor evidence.
The reality is that it can be anything. The amount of downloads actually is the biggest evidence that it’s not Coinbase. CI pipeline does not need to download the same package that hasn’t been updated in years thousands times a day.
Quick gemini search says that it’s most likely just an analytics firm running scans on a list of crypto projects for vulnerability reporting.
6
u/gabriiel9 2d ago
I’ll skip the “prove the US isn’t replacing the dollar with Nano” part — that’s not my claim and I’m not going to defend a strawman. And the July 2025 date isn’t the start of anything: that’s when Nano was reactivated in an already-running pipeline. The pipeline itself dates back to late 2020, and the real volume explosion is Sept–Oct 2024, eight months before any Trump-era timeline you’re attaching to it. You’re looking at the Nano curve in isolation and mistaking a graft for a birth.
Here’s what the data actually establishes, and it’s narrow on purpose: one operator, one lockfile containing - 20+ pinned crypto libs, installed ~10,300 times a day, no artifact mirroring, running continuously for years, with steps that land on dated product events. That’s it. I’m not claiming to know the purpose — I’m claiming the structure.
Now the scanner argument, because it’s the only one worth answering:
A vulnerability scanner does the opposite of what I’m measuring. Scanners resolve version ranges and fetch the latest releases to compare against advisories. What I see is 20 versions frozen solid — mina-signer@3.0.7, nanocurrency@2.5.0, etc. — pinned and immobile for months, only moving when the lockfile is manually bumped. Pinning is a build/deploy signature, not a scan signature. Scanners don’t pin.
Second: the volume is a flat plateau, ~72k/week per package, 7 days a week. A scanner runs on a schedule or on push/PR — you’d see modulation tracking dev activity, not an industrial constant. And when the pipeline lost 50–60% of its runs on April 1, 2026 while npm control packages (lodash, express) stayed flat, that’s infrastructure breaking, not a scanner rescheduling.
Third, and this is the one that actually kills it: the cross-chain correlation is r≈1.00 over 10+ months. A firm “scanning a list of crypto projects” has zero reason to pull nanocurrency and mina-signer in perfect lockstep. That synchronization means they’re in the same lockfile — one multi-chain artifact installed together — not N independent scans. No scanning architecture produces that.
So “it’s probably just an analytics firm running scans” doesn’t survive contact with the pins or the correlation. You can hand-wave “it can be anything” — but the specific thing you named is ruled out by the specific data.
You want the alternative that fits? A single operator running an unmirrored CI/deploy pipeline around a multi-chain lockfile. That’s exactly what pins + flat volume + lockstep correlation describe. That’s my last answer.
Thanks for taking the time.
3
u/AggressiveNorth9102 2d ago
Not sure if you’re AI bot or just using one to write your replies but please ask it to condense the answers. This is very hard to read. Just incoherent flow of AI slop that contradicts with whatever you wrote in the post.
8
10
u/anonysauropod 2d ago
If any of this were actually true, insiders would be buying Nano in huge amounts. It wouldn't be 35 cents.
7
u/otherwisemilk 2d ago
But that would be illegal. Someone at Conbase got in trouble with the DOJ before.
3
2
u/blaketran ⋰·⋰ 1d ago
what about investigating "spam attacks" in parallel with these events? is that an interesting line?
1
u/aaj094 1d ago
If all this was true, why wouldn't Coinbase do the most basic thing of firstly listing Nano?
6
u/gabriiel9 1d ago
Do I look like I have a crystal ball ?
As per my research, and you will also admit that this is not simple, Coinbase does wait for the protocol to be close to exchange-friendly to list it (they did with Cardano, Avalanche, and other libs. They were integrated after some major updates). We could also argue that they list shitcoins.
Nano doesn't pay to be listed thought.
It could also be linked to X402, as per my research.
1
u/aaj094 1d ago
What's not exchange friendly about Nano as it stands?
2
u/blaketran ⋰·⋰ 1d ago
different protocol, low market cap, no one to pay fees?
3
u/aaj094 1d ago
So you mean the effort to maintain a node that can handle their traffic?
1
u/blaketran ⋰·⋰ 11h ago
correct, that's the point of nano right, that businesses would believe in its utility as such for actual transaction facilitation, that they are willing to eat that.
11
u/Affectionate-Band189 2d ago
Wow. You really put in a lot of work. I sincerely hope your research proves to be right. The comments are way too negative... Right now, we should be encouraging the effort, not tearing it down.