Bitcoin Forum
September 11, 2026, 05:29:05 AM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Privacy on Bitcoin after 2024: how tracing works  (Read 53 times)
windpath (OP)
Legendary
*
Offline

Activity: 1286
Merit: 1040


View Profile WWW
September 10, 2026, 01:24:57 PM
Merited by PrivacyG (2)
 #1

New chapter on LearnBitcoin: Privacy on Bitcoin: What Works and What Doesn't
https://www.learnbitcoin.com/rabbit-hole/bitcoin-privacy

For this crowd the interesting parts are probably:
  • The tracing section, which goes back to Meiklejohn's 2013 "Fistful of Bitcoins" paper and the two heuristics that still do most of the work, plus the point that the whitepaper itself named the common-input leak.
  • The Bitcoin Fog / Sterlingov material, where Chainalysis's own witness testified she was unaware of studies establishing Reactor's error rate. Relevant to anyone who has had a deposit frozen on a risk score.
  • The 2024 timeline: Samourai arrests (April 24), the Wasabi coordinator's voluntary exit (June 1), the 2025 pleas and sentences, and the fact that no court ever ruled on whether a non-custodial coordinator is a money transmitter, because the case ended in a plea.
  • JoinMarket's status: survived 2024 on architecture, then the reference codebase was archived in April 2026 for lack of maintainers, with joinmarket-ng carrying the network.
  • PayJoin (BIP-78 / BIP-77) and Silent Payments (BIP-352) as the direction of travel.
Some of you were around for the early coinjoin threads on this forum. If any of the history is off, say so and it gets fixed and credited.


https://www.LearnBitcoin.com – Free Bitcoin Education
Antidote47k
Member
**
Online Online

Activity: 98
Merit: 68


View Profile
September 10, 2026, 06:59:16 PM
 #2

The PayJoin part make me wonder how much this really becomes an arms race between transaction construction and chain analysis.
Breaking the common input heuristic was a big step, but then it gets tricky with the newer wallet fingerprint work. Oftentimes analyst can be able to recover the sender/receiver partition by looking at signature behaviour, nSequence, coin selection, and how inputs/outputs behave before and after the PayJoin.

This really shows the subtle shift of the problem from “which inputs belong together?” to “which wallet engine produced this?” and then down to the surrounding graph context.

This is also the reason why it was a very interesting situation when PayJoin v2/BIP-77 and Silent payments/BIP-352 was introduced. PayJoin deals with the assumption on the input side and Silent payment with the reusable address heuristic on the output side.
Makes me wonder how feasible is it for PayJoin to remain ahead when privacy properties is not only based on the structure of the transactions, but also on how two entirely different wallet implementations can mimic each others behaviour.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!