Hi and welcome to the Stephan Livera podcast focused on Bitcoin and Austrian economics. Today we've got an interview with ErgoBTC, a pseudonymous Bitcoin white hat privacy analyst. But first, the sponsors of the show. So firstly, Kraken, one of the world's leading Bitcoin exchanges. They offer a high quality platform, they offer one of the most liquid Bitcoin exchanges. Exchanges, they have high trading volume and low fees. They've got best in class accounting, reconciliation, and reporting services. They've recently announced and launched Kraken Pro mobile app. Kraken Pro delivers all the security and features you love about the Kraken exchange into beautiful mobile-first design for advanced Bitcoin trading on the go. Kraken also have an OTC desk for those seeking more private, personalized service for large block trades of a hundred thousand USD or more. Kraken offer margin, long and short up to five times and futures. Up to fifty times leverage. Kraken also have the CryptoWatch platform and they offer five fiat currencies. Go and sign up at kraken dot com. This episode is also presented to you by Unchained Capital. Unchained Capital is a Bitcoin financial services company empowering customers with unprecedented financial freedom and control. All their products and services are built on the foundation of multisig. Their approach to collaborative custody gives users control over their private keys. You can use Trezor or Ledger, and you also get the benefit of having a financial partner and financial advisor. Services. So Unchained's two of three vaults are a great option for those thinking through how best to secure their Bitcoin for the long term, and if you have a need to access liquidity but you don't wanna sell your Bitcoin, Unchained's collateralized loans offer a unique option. All Bitcoin is stored on chain in dedicated multisig addresses, and the BTC is never rehypothecated. You can also share in the security of your Bitcoin by holding one of three keys. I'm really impressed with Unchained. I'll be having Parker on the show soon, and they offer excellent- services, they've released valuable content and open source tools such as Caravan and Hermit, so I think you'll enjoy partnering with them. Go and sign up at unchained-dashcapital dot com. Next up is GiveBitcoin dot io, the easiest and safest way to get your friends and family into Bitcoin. Have you ever had that problem where you gave Bitcoin to people but then they lost it? They just didn't understand what they were receiving. That's why GiveBitcoin is important because you can time lock that Bitcoin gift for one to five years, and GiveBitcoin will deliver a lesson from a world class Well-known Bitcoiners such as Saftein, Matt Adel, Jan Pritzker, and others. I'm also an advisor, I have a small equity stake, and I'm assisting with the curriculum also. Don't forget, you can get Bitcoin as a present, birthdays, Christmas, bar mitzvahs, graduation, weddings, you can put it on your wish list, so go sign up at givebitcoin dot io. I really think it can have a positive impact on Bitcoin adoption and understanding, so I'm excited to have them as a sponsor. Last but not least, Bitcoin Outlet, which
TRANSMISSION SLP130
ErgoBTC - Tracking PlusToken Scammers
with White Hat Bitcoin Chain Analysis
ErgoBTC, a pseudonymous bitcoin ‘white hat’ privacy analyst joins me in this episode to talk about his journey tracking PlusToken scammers in their attempts to mix and dump 200k BTC. This is a must listen episode for bitcoiners to understand how your privacy can be impinged, and we also talk about tools and techniques for assessing and defending your own bitcoin privacy. We talk: • How he got into bitcoin privacy analysis • PlusToken scammers - what is the scale of it, and what did they do wrong • In depth discussion on bitcoin mixers and bitcoin privacy • Key takeaways for listeners, mixing products, exchanges on privacy • Future of chain analysis
21x.io delivers rare and extraordinary merchandise to warriors of Bitcoin. Outstanding design isn't blindly slapping your logo on any object available. At 21x, every product they carry is a work of art with a thoughtful design, in keeping with the ethos of Bitcoin. All products created are limited edition. Once that product sells out, that's it. When you purchase something from 21x.io, you'll be one of the only people in the world who have it. It's a sister company to Canada's Bull Bitcoin. Both companies are Bitcoin maximalists through and through. Twenty One X only supports Bitcoin. This core belief has led them to align with other unapologetically maximalist companies. So if you want to rock some merch from a designer with an actual moral compass and unwavering maximalist views, go to twentyone x dot io, grab yourself some of that merch. So today I've got a fantastic interview with Ergo BTC. It's his first interview. He is a pseudonymous Bitcoin white hat privacy analyst or chain analyst, and so- So he's been lighting it up recently with some of his articles and tweets about the PlusToken scam and the ongoing chain analysis that he's been able to do using tools such as kycp dot org and oxt dot me and some spreadsheets. And it's just a really fascinating episode. I highly recommend for those people who aren't as familiar with Bitcoin privacy, check out some of my earlier episodes, episode fifty-eight with Chris Belcher, seventy-eight with Samurai Wallet. And 117 with PureVita. otherwise, I do try to break it down where I can, but I think this will be a fascinating in-interview with some insight into how Ergo was able to track some of the PlusToken scammers, and we talk through a lot of different privacy techniques and their use in practice. So I think you'll really enjoy this interview. Here it is. Ergo, welcome to the show. Thanks, Stefan. Happy to be here. Big fan of the podcast. Thank you. Yeah, so look, man, I know you've been doing a lot of really interesting work. I know you are obviously operating under a pseudonym, so we'll be careful not to dox too many components about yourself. but just obviously without doxing or giving off too much of your own anonymity set, can you just tell us a little bit about how you got into Bitcoin and particularly this, what we might call- White hat Bitcoin chain analysis.
Yeah, sure. I guess I'm kind of like most Bitcoiners, you know, in that I started out as, you know, looking at libertarian politics and Austrian economics, you know, those are good great, great drugs that lead into Bitcoin. in the last year or so, I've probably gotten a little bit more discouraged with, the current political and economic landscape, you know, around the same time earlier this year, I started hanging in a, a few Telegram groups, and I found some Bitcoiners with, an ideology that I kinda- I aligned with, from there stumbled into crypto-anarchy. for those that kinda don't know, crypto-anarchy is basically this concept of creating, you know, a parallel voluntary system that people can opt into, you know, as they wish. It's sort of this gray market stuff, you know, and Bitcoin fits pretty much perfectly into that framework, you know, so I started listening to a couple of, crypto anarchists, do talks, and they're, they're pretty objective, they seem legit, kind of old-school cypherpunks, and many of them raised You know, but with the rise of some of these new non-custodial mixing services, I decided to start doing my own research, and figure out if these services were enough to keep Bitcoin from becoming, I guess, its own panathenicon as these guys, you know, seem a little bit worried about. and in the process of doing my own research, I sort of stumbled into something a little bit bigger. Yeah. You know, so from there, I basically have been, you know, hanging around looking at these, blockchain explorers, mostly OXT and KYCP You know, shared coin, I've looked at Join Market, I've looked at, Wasabi, and I've looked at, you know, Whirlpool. and during looking at, into Wasabi, I noticed somebody was merging large, really large volumes of Bitcoin into a, a, a post mix cluster.
Gotcha. Sorry, can we just, back up just for a second there? I wanna just make sure this is accessible as well. So maybe we could just talk through a little bit on the basics of blockchain surveillance and what are some of the key methods Slide. So, maybe you-- we could just start with some of that, and if you could just outline a little bit around what is the common input ownership heuristic?
Yeah, that's, that's an important one. it's probably one of the most powerful, you know, chain analysis heuristics. the merged input heuristic is, the assumption that all of the inputs in a transaction belong to the same party. and what this does, or what chain analysis can do with this information, is they can, they can cluster the inputs from a transaction, and if this process is, is repeated with a, you know, a handful of other transactions or more, you'll wind up with a, a bit of a bigger cluster. and what this kind of shows them is that, you know, a, a larger entity might be the owner of, you know, many addresses. And, that's sort of, you know, kind of what, sparked this off for me.
Excellent. And, for listeners who are interested in some further background, I recommend checking out episode fifty-eight with Chris Belzer and also reading the Bitcoin Privacy Wiki, which he updated. Now, while we're on this topic of merging and common input ownership heuristic and so on, there are, I guess, multiple ways in which our privacy can be doxed when we're dealing with Bitcoin. One of those ways is, again, as you mentioned, the most obvious one is the merge heuristic, because every Bitcoin transaction has inputs and outputs. Outputs and then where those inputs are being merged, then it can, that can indicate, well, it's probably the same owner, right? And that's like the general heuristic. Obviously, there are other countermeasures to be deployed against that, but that's the basic high-level way to think about it. But another key angle is this, what Chris Belcher calls data fusion, and that's where somebody might post an address just publicly, right? They might have a donation address, and, then the combination of that with on-chain analysis can be one What de-anonymizes that individual or that exchange or that large party? Can you just comment a little bit on your thoughts around that?
Yeah, I mean, there certainly are a, a combination of, of, additional information that chain analysis can use to get, to paint a bigger picture. You know, Bitcoin's pretty powerful, it's got some pseudonymous traits that make it harder to, you know, pair to the real world. but a lot of what chain analysis does, at least from some of my reading, is, is use these, these multiple, you know, heuristic types To try to paint a better picture, and every, you know, additional piece of information, you know, can help you sort of refine your analysis a little bit more. You know, some of the other important ones include address reuse, there's the, the change in, output heuristic and the timing and out-- timing analysis as well. Those, those are all, you know, can help contribute to paint, you know, a, a, a more detailed analysis. Would
you mind helping break the some of those down? So can you tell us why, address reuse? So what
At the, the, you know, the protocol layer, pseudonymous. Each address can be considered to be, you know, basically anyone, you know, but once you reuse an address, that pseudonymity is destroyed. You know, we know that the pre-, you know, the, the previous owner of a transaction or previous owner of an address. Is, is the owner of the address when it's reused, and you don't need to, to do any clustering, you don't need to do any merged input heuristics. It's, it's just a, a fact, you know? So, so that one is, is pretty powerful. It's not even a heuristic, it's just the way it is.
Right. And I guess just to unpack that a little bit further for the listeners who aren't familiar, address reuse can impact not only the party taking payment, but also the parties who are making a payment, because Correct? That's correct.
Yeah, I mean, a-address reuse is, is a pretty big problem. I mean, I-- and during my research, I didn't even realize this, until a little bit later, but, OXT, which I'll, I'll probably talk about more later, does a couple of, privacy metrics, and one of them is address reuse. You can go and you can check out, and, you know, any recent block, and you'll see address reuse anywhere from thirty to fifty percent. So it's, it's
pervasive. That is for the listeners.
Yeah, the change output heuristic is, sometimes it works and sometimes it doesn't. You know, that's the problem with these heuristics is that they're, they're mental shortcuts to try to, you know, shortcut an analysis to make it easier to do. And the change, the change output heuristic is, is something along the lines of, you know, I make a payment to Stefan, I send him, you know, I have a one point one BTC UTXO, I send him one BTC and the, the point one is likely the change output or something along sometimes they'll also pair that with, you know, round number payments can help refine that a little bit further.
Right. And I think another component to add there would also be the index number of the outputs. So as I understand, I can't remember the exact bit, but I believe there was a bit that tried to standardize which-- So if you've got a certain number of inputs and outputs to every transaction, and those outputs are ordered, and depending on how a certain wallet constructs or crafts the transaction, it may be that the change output was always the second one, for Yeah, that's correct. Right. and you also mentioned timing analysis, can you just outline a little bit on how that could de-anonymize a person using Bitcoin?
yeah, you know, I, we'll talk about it a little bit later, but I've been integrating this a little bit into my analysis, and it's that if you have at least enough of an idea of maybe what one entity is doing, you can, you can sort of, better refine your analysis by evaluating when their transactions hit the blockchain or when, you know, the, the transaction first hits the mempool. And, you know, sometimes, transactions from a single party might be all broadcast in the same block, and you can So that can help you sort of paint an even better picture.
Right. And, another one that I can just think of now is also just around the way the script is constructed, because I understand certain wallets can be, subject to fingerprinting analysis. So, an outside observer trying to spy can try to understand, based on the way the Bitcoin scripting is crafted, what sort of wallet was used to create that transaction.
Yeah, that's also the case, and, and I think a lot of, users are also aware of some of the issues with, with- Multi-sig in their current form that once, you know, they're spent, you reveal, you know, how many parties are involved. This is similar to the scripting that you kind of just described.
Right. Yeah. That's great. So I think they're some of the basics, and, pot- potentially we should also talk a little bit about network level privacy. So could you just offer some overall thoughts on that, if you have any, anything to share on that?
Yeah, I'm not a network level expert, but, you know, there are, of course node, you know, to be using that to broadcast your transactions rather than a third party server. also, you know, querying your own Bitcoin node, to keep from revealing your, address balances or sharing your xPubs. These are some common things that, that are problems, especially with some of these, hardware wallets. Great. And,
so look, yeah, I think that's, probably enough, a little bit, enough on the basics. Let's now go a little bit into the story of how you came across, this PlusToken how did this first come across your radar?
Yeah, so I, at least kind of how I started off a little while ago was, you know, I was sort of doing my own research on this, these, non-custodial mixing services, and I was looking at, the Wasabi Mixer in particular, and, I noticed that, A single entity was basically merging a significant amount of Bitcoin. the, the initial tip off to me that this was, you know, a single entity was that, this entity was experiencing a significantly high, you know, amount of address reuse in the mixer. you know, I don't know, I'd have to look up what some of the stats were. I think I found one transaction that was nearly one hundred percent address reuse from, from mixed outputs, which is something that, you know, really shouldn't happen, but I guess can happen in, in some scenarios. There, I just sort of followed the, you know, the merged input heuristic and watched these, these merged outputs as they were joined together, into a, a relatively large cluster, basically sent to, you know, these, these merged transactions were sent to Huobi, a, an Asian exchange, in pretty large volumes, anywhere from, you know, fifty to a hundred Bitcoin, or I think in some cases even up to two hundred, so it was pretty obvious that there was a A, a very large entity using the mixer. I think my initial cluster estimates were around twenty-six hundred Bitcoin, which is not chump change. and from there I started thinking, well, I mean, if I found twenty-six hundred on the way out, it's very likely that I could probably find this on the way in, which would be, you know, sort of a timing attack. and so that's what I, what I got, what I started doing. I looked back and found, you know, some of these larger inputs were, you know, all coming from a, a re- a reused address for the most part. I shared that address publicly, and, Laurent, the, developer of OXT, I think he just hit, took a quick Google and found that, some of those addresses were related to, PlusToken.
Wow, there you go. And so that's, that's an example there of data fusion, Because those addresses had been publicly listed, and then, anyone, any outside observer with enough knowledge and skill and toolsets, so kycp dot org and oxt dot me and so on, could, you know, like yourself, could go and use those tools to try and understand or try and pierce through that veil, if you will, and understand what was going on. So can you tell us a little bit about the timeline here? So when did you first come across this, and what was the timeline of this PlusToken scam? I guess maybe it's
It's worth, you know, going back and talking a little bit about PlusToken, at least sort of what we know, the available information about PlusToken is pretty limited, it sounds like it was pretty popular, in Asia, particularly Korea, Japan, China, and a lot of the information is, you know, is, is, is hard to come by, but I guess the, the, the, you know, the main point of this was that it was a, a Ponzi scheme, you know, users were promised some ridiculously high monthly returns, I don't know, something like ten or fifteen percent a month, which, you know, is, is outrageous. and just like most other Ponzi schemes, they pay out right up until they don't. I think that the-- that they started early in two thousand and eighteen, and sort of, I guess, really got some momentum early in two thousand and nineteen. you know, I think that they may have had a few additional, you know, kind of hiccups with their centralized server, which was, you know, used to, do their payouts, you know, that was, I guess up until late June, when a handful of the associates of PlusToken were arrested, I think they were Chinese nationals, but, you know, the, the data is, is, is pretty hard to come by. from what I understand, the, the, the The, the ringleader, was not arrested. and so I'm gonna guess that the ringleader is the one that controls the private keys to these coins. so, you know, June 27th or the late June arrests happen, PlusToken is basically shut down, we sort of have a couple of coincident events, including, you know, the blow off top and, you know, the, the exchange rate, and from there, I think things sort of remained quiet for a little while. there were a couple reports from others, you know, some tweet threads and, I, I think, some, some research reports about PlusToken that sort of surfaced in, in August or so that indicated that some of the funds were on the move. That's early August was when I originally noticed, the first large whale deposit into Wasabi.
Well, and so, for a bit of context, from what I've anecdotally heard is that in other cases of big hacks, so like Bitfinex hack and some of these others, what actually happens is often those attackers just leave the coins waiting. They're not actually trying to sell them yet. It could be that they're waiting for a later, more opportune time, maybe they're waiting for better mixing technology before they actually try and- sell those bitcoins. but in this case, it looks like they have attempted to, as we'll point out, I think they used some, poor methods of trying to self-shuffle or running massive volumes through one mixer and so on or in an incorrect way. So let's, let's talk a little bit about what do you think they were doing and doing wrong, as you pointed out?
You know, it's, it's hard to guess what exactly they were doing, but I, I think they were, you know, trying to hide the movement of their funds. I, I know that there are some, big links between- Huobi and PlusToken, and that, Huobi was one of the main sources of, of most of the PlusToken deposits. I don't remember what some of the percentages were, I think it was something on the order of fifty or seventy percent. It was, it was a large amount. so, you know, in theory, Huobi has a, a decent idea of how much has gone to PlusToken And from there, you know, PlusToken needs to, if they're gonna try to sell their coins, they need to do something. They can't just go straight from Huobi to PlusToken and back to Huobi. They're gonna have problems. So I think what they were trying to do was to basically hide, hide their transactions on the blockchain. and that sort of was through, you know, I, I picked up two main methods. One was the Wasabi mixer, and I, I think around twenty thousand Bitcoin were, were forced through the Wasabi mixer. And there's
I, it's hard to come up with a good term for this, but it's, it's, it's easier to see than it is to explain, but it sort of is a, a repeated process of splitting the UTXOs and merging them back together. And this isn't mixing, we would consider it mixing if they had identical outputs, but That is very rare. I think even in the cases where they tried to do it, Bolzmann, the OXT algorithm, was able to chew through that and, and, and still create some deterministic links. So the, the self-shuffling process is, like I said, it's, it's repeated splitting and merging of transactions. sometimes, I don't know, a hundred transactions in a, in a self-shuffled, you know, cluster before, you know, merging them on the other way out. And I had originally thought this might have been some type of, you know, tumbler, or subpar tumbler, but, now the more I've been looking into this, I'm starting to think it's just a manual process, th- and, and that sort of comes back to this timing analysis, where the self-shuffle transactions might sit for a few days and then resume, which to me is a little bit more of an indication that it might be a manual process.
Right, yeah. And so just for the listeners, would you mind Outlining a little bit, around what is a deterministic link and why is that a bad thing?
Yeah, so it's probably helpful to describe what a standard Bitcoin transaction looks like, or at least the majority of a Bitcoin transactions. you know, like let's say I want to pay-- I have point four and I want to pay you point one, you know, we'll have an input of point four, an output of point one, and a change back of point three to me. And, you know, this is what most Bitcoin transactions look like. And in this case- We say that they're deterministically linked, the inputs and the outputs are deterministically linked because we can run the CoinJoin Sudoku al-algorithm on this transaction and, and, and, and verify that the input must have paid, you know, the outputs. And this, CoinJoin Sudoku, which is used to deter- you know, find deterministic links, it works not just in this case, you know, with one input, it works with multiple inputs as well. and so deterministic links are, are bad because, you know, with all we have to do is, is look at a transaction, and we can say with one hundred percent certainty that we know that an input paid an output.
Right. And on top of that, I've, I've noticed as well with kycp dot org, there are tools that help. You can type in a TX ID, a transaction ID, and it'll, it'll, it'll assess that transaction from a, Boltsman point of view and from a deterministic link point of view, and, So there's deterministic links and also probable deterministic, deterministic links. so can you just outline a little bit of how that assisted in your analysis? I presume you used that kycp dot org as well.
Yeah, I, I started out using kycp and sort of moved towards, using oxt later, which is something we should also go over, but kycp is a, a, a transaction privacy visualizer. it's, it's used to show the relationships between inputs and outputs. so specific- Specifically, it will look for address reuse, it will look for deterministic links between the inputs and the outputs. if there are no deterministic links, it will show the probabilistic links. and it'll also show, which inputs were merged into the transaction and which outputs were also merged into a, a subsequent transaction. So all of these things are, are sort of used to help elaborate on some of the, the privacy issues with the transaction.
Yeah. And sorry, just one other thing while we're on that topic, Interpretations. So the other thing that you'll see on kycp dot org is interpretations, and for, for instance, in a whirlpool transaction, it will show that, fourteen ninety-six possible interpretations. Can you outline a little bit about what that is?
Yeah, this, this gets to the concept of entropy, and hopefully I, I don't butcher this too much, but entropy is, is, at least in From my understanding of Laurent's vis-uh, mental model of a Bitcoin transaction, he looks at it as, you know, a flow between inputs and outputs. this is sort of a statistical mechanics or a thermodynamics kind of model. I guess the point is that you can see how inputs are paid to outputs. and from there, if, if a transaction has any type of coinjoin characteristics, and the most easily way to identify coin- Point-join characteristics is if there are identical outputs, then the transaction has what's called multiple interpretations. And sort of what this means is that if you have, for example, in a whirlpool transaction, you have three inputs of, you know, well, basically, it's basically five inputs of point o one and five outputs of point o one. You have no way of knowing that one of the point o one inputs didn't pay all five of the point o one outputs. There's just no way to distinguish that, you know, in, in the code. I guess it's sort of a, satoshis don't have serial numbers kind of, perspective. So, I, I guess, you know, it's, it's a little bit of a dis-difficult concept, but if anybody that's had thermodynamics will sort of understand this intuitive concept of entropy. But what the, That is, there's no way of not knowing that one of the inputs didn't pay all of the outputs, or one input didn't pay two of the outputs, or one input didn't pay one of-- only one of the outputs. And this sort of, gets to this idea of multiple interpretations.
Yeah, that's, that's fascinating. And, I think for listeners who really wanna go deep on this I, I would suggest looking at, some of the discussion between, Laurent and, Adam Gibson, also known as Waxwing, there was some discussion around when, Laurent first posted some of the Boltzmann scoring. but again, that's probably a little bit, beyond the technical level that we can handle on this podcast today. but bringing it back then to the- You know, self-shuffling and then running massive volume through Wasabi. So let's bring it back to the behavior that you saw. So basically, they had this big pot of stolen money, and they want a way to try and get fiat out, presumably. And so that's where, as you mentioned, they were doing this quote-unquote self-shuffling process where they're not really mixing, they're just trying to obscure the traces on the blockchain by doing this kind of weirdly structured transactions that then later- All merge back together. And I think you demonstrated this very nicely in some of your charts and some of the, graphs that you were showing from oxt dot me. Can you outline a little bit around your process there?
Yeah, so, I think if we pick up sort of where I left off in the timeline, I'd found the, the, the twenty-six hundred Bitcoin cluster, on the way out of Wasabi, you know, and went back and found the, the major reused address. And, from there, I found that multiple branches off of that reused address Or making deposits into Wasabi or into this self-shuffling process. You know, a-and after sort of seeing enough of this, I was able to kind of come to the conclusion that, you know, this is, is likely one entity that's trying to hide their funds. So, you know, I, I think I had shared that, PlusToken, or no, I'd shared the original address, and, and Laurent brought it back to PlusToken. and from there, he, he created a, a little bit of a diagram using OXT to, illustrate The flow of funds between different clusters. and from there, I was able to sort of get at least a, a preliminary estimate of, of, you know, some of the size of the, the scam. And at the time, you know, I wrote the Medium article, I think it was, you know, fifty thousand or so Bitcoin self-shuffled and, and, and nineteen thousand or so that went through Wasabi.
You also point out in the article, that it's a p-approximately two hundred thousand BTC that was total in-the amount that got scammed, so there might be more to come.
Yeah, that's, that's correct. you know, at the time I wrote the Medium article, I hadn't really done enough digging into the, the size and extent of the, the PlusToken premix cluster. You know, after, I thought that for the most part they had finished, at least around the time that I was writing the Medium article, I thought that they were Transactions that were sort of stalled and, and, and weren't going anywhere. Some addresses that, were full of funds that, that hadn't moved since, since the middle of August. And recently, you know, they had started moving again. and that's when, you know, I, I followed them through the self-shuffling process and I found a, a reused address, that was used to sort of collect transactions before sending them, you know, typically to Huobi, again, you know, more address reuse. from there, I evaluated the That transaction and was able to, you know, sort of verify at least how much through that address, had been sold. I think around, by now, I think it's around seventy-seven thousand that I was able to cluster through that address.
Wow.
Yeah, I mean, it's, it's starting to get, you know, astronomical numbers, you, you sort of start to, you know, lose track, but, you know, after having looked at that, you know, the most recent, address reuse, you know, with, Hu And decided that, okay, I, I need to really get a handle on, on what premix funds are left. and that's when I sort of came up with the recent, you know, tweet thread, that estimated, around one hundred and eighty-five thousand Bitcoin, at least in their, their premix cluster.
Wow, so there's a lot more to come. and I think that also raises the question then that it was basically address reuse that enabled, address reuse on the part of these scammers that enabled you to actually try and Right? Because if they hadn't done that address reuse, it would have been harder for you to do that, right? That's, that's
absolutely correct. Is that, you know, address reuse was a big problem, and it's been pervasive throughout this whole kind of process. it's been, you know, present in the premix, it's been present in some of the mixing, well, actually, in both of the mixers, and it's been present in, you know, the post-mix, behavior.
And, I mean, that, that Reuse addresses, and that'll make this task even harder for next time, right?
Well, I mean, you know, I guess part of the problem too is just the volume of Bitcoin that they've been moving. you know, regardless of whether or not you're, you're reusing addresses or you're using a mixer or not, it, it's, it's real-- I don't wanna say it's easy to track, you know, a hundred and ninety thousand or a hundred and eighty thousand Bitcoin, depending on what they do with it, but, you know, that On, on the back end of a wasabi mix, that's just, you know, crazy. So, you know, that, that gets to the, you know, it's, it's, gets back to sort of a timing analysis problem that if you're gonna do something, with that volume of coins, it's gotta take more than, I don't know, a couple weeks or whatever they were trying to do it in, it's probably a year process or longer.
Gotcha. let's talk a little bit around their use of wasabi then. So, you
You mentioned the timing attack, you also mentioned, Sibill attacking. Can we talk through the process then from a Wasabi perspec- or from the PlusToken scam, people trying to move through Wasabi?
Yeah, I, I mean, it's sort of like I said before, is that, timing analysis is a problem for such a large amount of Bitcoin. And, you know, the Wasabi Mixer is, is relatively big. If you look at some of their transactions, there might be anywhere from, you know, twenty to a hundred Bitcoin that gets processed in, in, you know, I don't wanna call it an average transaction, but in the, the majority of the transactions. And, you know, it's not enough vol-- volume for them to process twenty thousand Bitcoin Bitcoin, in the case of PlusToken, but, you know, I, like I had said before, I, I noticed this, this massive volume on the way out, so I started looking for, kind of a source on the way in. And a-after I had found the, the reused address that was used to, to do most of the, deposits into Wasabi, I was able to use OXT's transaction graph to expand Wasabi transactions and follow them back to, this reused address. And from there, I was able to get a little bit
Where the PlusToken scammers in. You know, you can only, mix, you know, so much with one mixing client, and so in order to speed up the process, it looks like what they did was, deploy multiple mixing clients. this is sometimes referred to as, you know, a Sybil attack. and, and a Sybil attack, the intent is often taken into account, but a Sy-Sybil attacks are problems for all types of, of mixing services. Where there is no reputation and you're trying to keep people anonymous, and usually, there are different ways to mitigate this, but, like I said, the, the scammers were basically in a big hurry. They opened up multiple mixing clients and they, they forced a large volume through Wasabi in a relatively short amount of time.
Yeah, and so it's probably fair to say that this is just generally just a hard problem for any kind of mixing service, and particularly those mixing services that are trying to remain non-custodial, right? So I guess just quick high level, there are some mixing services and so on that are custodial and they've been shut down, I think, Bestmixer is an example, and then there are others such as JoinMarket and Wasabi and Samurai, Whirlpool, which You don't give up control of your bitcoins and but then now the risk is Sibill attacks, correct?
That's correct. it's, it's a problem that all mixing services have, not just Bitcoin. it's something that, you know, privacy researchers have been, researchers have been struggling with for, you know, a long time. and it's not something that we're gonna really solve, you know, on this podcast, but,
you know, it, it is, it is an issue, it, it, it's still, Mixers, at least in Bitcoin, do is they, they charge a fee, a, a, a mixing fee, and there are different ways to do this, you know, Join Market has their maker taker model, Wasabi has a volume based and participant based model, and Whirlpool, for example, has a deposit based model, you know, and it's very hard to, to, to a-address this problem, you know, the, the, the fee, at least in, in Bitcoin mixers too, is Isn't just a security measure, it's also an economic measure, and there are some incentives around there that, that can make it, you know, a very difficult problem to solve.
Right. And for example, I think I saw Chris Belcher on the mailing list talk about this idea of fidelity bonds as a way of deterring scammers, right? That they would have to post up some money so that it would make it harder for Sybil attackers, right? And that's just, that's just one example. but I guess just generally, what are some of the lessons that can be drawn Services and how they could mitigate this kind of problem or at least reduce it where possible.
Yeah, I mean, it, it's probably useful to, you know, talk about How much this, this attack might have cost? I did a, a quick estimate, a, a little while ago, and I, I built a very simple model, based off of just, you know, my observations of, of the mix deposits from the PlusToken scammers. And, you know, the model still needs validation, but I think it's, it's, it's legit for most of the mixing, you know, through Wasabi. And I, I came up with a number estimate of around twelve and a half Bitcoin, It's not entirely accurate, but I just wanted to get a ballpark number, just so I could, for my own sake, you know, think about this, this problem a little bit better. So we've got twenty thousand bitcoins sent through the mixer, and, you know, twelve and a half, you know, on the order of twelve and a half bitcoin paid in fees. It's like, you know, a half a percent or something. It's, it's some negligible amount. You're not going to deter twenty thousand bitcoin getting, getting forced through, you know, a mixer It'd have cost three times as much as the Wasabi mixer, but it's, even if it's fifty Bitcoin, fifty Bitcoin is a drop in the bucket in this, this, you know, twenty thousand Bitcoin problem, you know? But there, there maybe are, are a little bit of lessons here, you know, and that's, it's, it's a, again, it's a difficult problem to solve, but, you know, it's, it's, how do I want to say this?
I, I only really have sort of the three mental models that we talked about before. We had JoinMarket, which has this maker-taker fee process. We've got Wasabi, which has this, you know, volume and participant-based fee process, and Whirlpool, which has this deposit-based, you know, model. And, you know, I, I sort of lean towards favoring Whirlpool's model because, you know, there's no way to not know that each mix deposit isn't a new user. So you, you sort of, you know, a-adjust towards, charging each deposit, you know, each deposit basically is, is what it kind of comes down to.
Gotcha. Yeah. And, there's also the importance of having good post mix practices. So let's, just again for the listeners who aren't familiar with mixing, can you just outline the typical structure then with pre mix and then post mix?
Yeah. it, it's, this is, you know, kind of a, a pretty cool concept. even Join Market, from what I understand, had a, a pre mix Tumbler, where they would separate, you know, large, you know, mix deposits and pre prepare them for mixing. That way nobody was trying to do what happened here with, you know, PlusToken and trying to run twenty thousand Bitcoin through a mixer. Now, most people don't have twenty thousand Bitcoin, but even if it's a hundred Bitcoin, trying to get run through, you know, maybe a join market type volume or liquidity situation, it's gonna be still a problem. so what they would do is, is they would pre-split their UTXOs,
and so I Mix, you know, at least with, I don't think that Wasabi doesn't have any premix preparation, but Whirlpool does. It has their TX0, and the TX0 will take the fee, it will pre-split the transactions into the, you know, premix, you know, deposit amounts, so that they're prepared for mixing. And this is, it's a pretty neat concept, at least with, with, Whirlpool, because what it does is it, is it gets, the, the very similar to the mix outputs, and this gets, gets the, the mixer pretty close to an ideal coinjoin, which technically isn't possible, but Ripple is, is getting close. so that's, that's, I guess, the premix, right? Do you wanna talk
about postmix? Sorry, one other point, I guess, just to outline, the way that might work. So, for example, if you're using Samurai, you might put in, I don't know, for example's sake, you might put in fifteen million sats, which is, zero point one five BTC. And if you wanted to put that into the point o one pool, what it does is it kind of cuts it up into fourteen different pieces, and, Into your, I guess, main wallet or whatever you wanna call it, and then all those other pieces are basically like point oh one with just a little bit more for the mining fee to account for that transaction. I think it might be important to also talk about the unmix change at this point as well. Would you mind just outlining some of your thoughts around that?
Yeah, it's unmix change is always going to be a problem no matter what type of mixer. I mean, there's, there's change with, with almost any type of transaction except for one that's a Of multiple inputs to one output. So there's, there's just about always some type of change in a Bitcoin transaction, and the same thing holds true for, you know, mixing services. JoinMarket, I think they, they have unmix change technically in their mixes, but they have a little bit of a, a neat privacy twist on their, how they handle the change. this is due to their maker taker model. It, it, it, it makes it hard to predict what the, the unmix change outputs, will be because there Bakers to the takers in that process. as far as Wasabi goes, I think that unmix change is typically just, you know, included in the mix, it, it's paid back out to the mix participants in the mixer. And for Whirlpool, Whirlpool takes the unmix change and leaves it outside of the mixer and is taken as part of the TX zero, which is sort of what we said before.
Gotcha. Yeah, great. And, I guess we should just, while we're on this topic, just talk about how toxic Because that can link multiple mixes together, and if, if the user isn't careful, could you just outline a little bit around that point?
Yeah. Ab- absolutely. and it's, it's probably worth, you know, noting back to, Join Market, who also did, some of this, laid some of the groundwork for some of this thought process. they had this concept called mixing depth, where they would basically separate your mixed outputs and your unmixed outputs, into, you know, different, you know, different parts of your wallet Different xPubs, or different private keys, so that you wouldn't, merge your unmix change with your mixed outputs. and this is, you know, a problem that is, is, you know, somewhat hard to deal with, and they, they sort of did it, you know, a couple of years ago. as far as the Wasabi mixer goes, you know, it's the, the unmix change is, I guess, is technically included in the mix outputs. and, you know, users are-- the, the onus That change, I think that they have, they have a, a little red symbol, to show how toxic the, the unmix change is. and in Whirlpool, like we said before, the unmix change is, is, is kept secur-separate, sort of similar to this join market style. And so the problem with this unmix change is that if you, if you merge your unmix change with your mix outputs, then, you know, you basically will re-link, you know, your premix history with your postmix history and com-,
Explanation there. so I guess let's move on then. So that's pre-mix part, then let's talk through the mix and then the post-mix part.
Yeah. so You know, I'm not as, quite as familiar with the coin market as I, you know, as I probably should be, but, you know, from what I understand, they, they will, the, the maker will broadcast that he is willing to do a transaction, a coinjoin transaction for a certain amount. they have a taker process where the taker pays the fee to the maker, they, you know, come together in this market style, you know, mixer, and they decide to do, you know, a transaction for whatever amount that Maker demands, but, you know, the maker's is broadcasting, you know, and like I had said before, you know, you wind up with, depending on the size of the, the Joy Market transaction, a handful of, identical sized mixed outputs and, you know, a little bit of unmixed change with some adjustment for the, the fee taken. You know, the Wasabi Mixer has a lot of moving parts to their mixing process. there's, there are multiple mix outputs, you know, is, is for one. and it sort of depends on, the way that the mix outputs get done depends on sort of who shows up to mix. if somebody shows up, a couple users show up with some larger mix amounts, then you'll have some larger mix outputs. but it's, it's not really, kind of set in stone. It, it depends on kind of who comes to the party
The idea is to try to, from my understanding, to try to get as close to this ideal coinjoin transaction as possible. And so this sort of gets back to the, the, the TX zero concept where the premixed coins are split and prepared for, you know, mixing, and they are, they're basically the exact mix output plus a little bit for the, the miner fee, and on the way out They all wind up with, you know, basically identical mix outputs. This is sort of gets to the concept of perfect or one hundred percent entropy, which I know some of the samurai guys are, are a fan of.
Great. And so then once you've done, gone through that mix, now you have to think about post mix strategy. So what are some things that we should think about with post mix strategy? And also, if you could just elaborate on that risk that I think this is an underappreciated point, which is if you have just gone through a mix with other people, if If those other people don't now take their privacy seriously in a post mix sense, that can screw up your own privacy too, right? So there's like a externality, if you will. Can you just outline a little bit of the thoughts around that?
Yeah, you know, some people think that post mix is just as important or, you know, more important potentially as the, you know, the actual mixing process. As far as I know, I, I think Join Market, implemented some type of pay-to-endpoint or pay-join, type transaction. Wasabi Wallet relies on users to perform coin, coin control, and then the Samurai Mixer, Warpool, has a couple of different post-mix tools that, will, will keep users from hopefully merging, you know, a lot of their mix outputs into a single transaction. and this is, this is a, another sort of difficult problem to solve, you can't take full control away from the user, while still, you know, needing to, try to enforce best mix, you know, best post-mix practices. So, you know, at least with Samurai, they have a couple of post-mix tools that will, keep users from basically, you know, shooting themselves in the foot. you know, and then the, the problem is, is, you know, I, I know that some people say something along the lines of, you know, users need to do their own research and figure out how to do this kind of stuff, but, you know, it's sort of like you said before, there's a little bit of a problem here when your mix-- fellow mix participants, decide
Hundreds of mix outputs on the way out, you know, affects everybody, you know, negatively. so again, this is a difficult problem to solve, you know, without, you know, taking full control away from the users. but there are some things that, that people can do.
Right. And so let's, keep it to now, keep it on PlusToken for now, and then we can come back to some of those other concepts around payjoins and stone wall and so on. but, with, PlusToken and,
how They've cornered the market, right? They've got a large, well, let's say they've got two hundred percent or two hundred thousand, bitcoins, that's, you know, close to one percent of Bitcoin's supply. And you were commenting on how there were some impacts on, over, you know, Bitcoin's market price and potentially even the, run-up, you know, there might have been that artificial price run early this year. Can you outline some of your thoughts there?
Yeah, I'm, I'm not a markets expert, but, you know, it Number doesn't go up, you know, pretty consistently. but, you know, it's, it's, it's pretty obvious to look back in hindsight and say that the run up, maybe from, you know, March until June, was a little bit overdone, and that might have been basically caused by, you know, these PlusToken scammers, just like you said, cornering effectively one percent of, of Bitcoin supply, in, you know, an artificially, you know, fast, and an artificially large, you know, amount. I think that what's happening now is basically just working off a little bit of a hangover from, from that party. and, you know, I, I had, I had tried to do some estimates where, you know, I tried to total how many coins were mixed and then estimate over, you know, the period of time, you know, since, since mixing started, to come up with a little bit of an average of the, the daily distribution from the PlusToken scammers. And, you know, I think I had numbers somewhere between
eleven hundred Issuance is, you know, something on the order of sixty percent or so of the, of the miner's daily issuance. So, you know, if miners are consistent sellers, you know, or at least presumed to be consistent sellers, then, you know, this, this is pretty significant daily supply. So, like I had said, it's, this is probably mostly just, you know, working off a little bit of that, you know, kind of PlusToken hangover. You know, it's also worth noting that, of course, I, you know, I, I do a tweet At least as far as I can tell. I don't know if it was in response to, I'm sure they're not on Bitcoin Twitter, but I don't know if it was that or if they were, just shocked by, you know, the recent price drop, they didn't want the market to drop out from underneath them. So, you know, I don't, I don't think it's much of a big deal in the long term of things, but people, you know, like, like to speculate on, on, the
exchange rate. Right, For another one point five to two months, but as you're saying, they may have noticed this or maybe there's now a bit of attention drawn to it, so they've tried to slow down the selling pace, potentially. Again, we're speculating here.
Right, right. I mean, and I, you know, all I have is a, I don't know, what is about a week and a half of data since I, I did the last tweet thread, so I, you know, I've, I don't wanna call it a new trend in that, you
know
Yeah, maybe, there's only so much they can spend in, on all the, whatever they're spending on. Yeah. Alright, so let's talk then about lessons for listeners coming out of all this. Are there any lessons in terms of impact on mixes?
Yeah. You know, there's a, a couple things, I guess. you know, we sort of talked about the, the sibl behavior before. You know, and it's something that is just always gonna be a problem, but just something that users kinda need to be aware of. Th-there are definitely, you know, lessons, like we had said, you know, the address reuse is a problem, right? For, you know, for all, all Bitcoin. and users just sort of need to be aware that this is kind of going on. You know, I, like I said, I, I sort of recommend people go and spend a little bit of time on OXT and take a look around. You know, I'd mentioned earlier that address reuse is, is pretty, you know, pretty crazy. You know, anywhere from, like I said,
thirty On Bitcoin is exchange, exchange trading. So, you know, exchanges are a bit of a, of a problem here. you know, there are some other things that users can sort of take away, you know, it's, it's to try to, I guess, avoid merging your inputs, you know, basically whenever possible. you know, there might be some times where you can kind of get away with it if you have a fancy algorithm, but, you know, it's, it really is a good idea to learn coin control and, and try to
those are basically some of the two biggest things that, that users could do today.
And, in terms of fee calculation, and here we're talking like for the coinjoin providers, right? So, Join Market and Wasabi and Samurai, are there any impacts there in terms of how we think about fees, how we think about anonym sets as well coming out of mixes going forward?
Yeah, it's-- This is, this is probably gonna make some people upset, but, you know, Wasabi has decided to, to a, a- A, a volume based and a, a participant based fee structure. that's the way, that's the way that they've chosen to do it. You know, it's, and it makes economic sense. It sort of is this, you know, you pay for what you get, and you're, you're basically paying more for mixing more, which, you know, makes, makes perfect sense. you know, this sort of gets into maybe a little bit of a problem with this kind of sibbled behavior where, you know, you don't know for a
Which is why I sort of, you know, appreciate the, the whirlpool model, a little bit. so that might be a little bit of a takeaway, at least, at least when it comes to, when it comes to that sort of simple fee structure. you know, maybe there are a couple others as well. You know, it's that preparing your coins for mixing is, is also important, sort of this, you know, TX zero concept or this join market tumbler concept where coins are, are somewhat prepared so that it's not an obvious
The same user. And then you have the, the post mix lessons as well, which, you know, is, is again, you know, a difficult problem to, to solve, but, you know, enforcing, you know, hopefully best practices is, you know, is encouraged going forward.
Right. Yeah. So I guess, yeah, there's potentially some things that, the mixing services and products will have to consider coming out of this, and, you know, in terms of what, what our customers getting for what they're paying for. So, for example And it's kind of, it becomes difficult if you're charging based on how many users, right? so I guess that's just a, it's just a difficult problem, there's not necessarily an easy answer here. and from a exch- from an exchange perspective, are there any lessons there? I mean, off the top of my head, they should stop reusing addresses and not have static deposit addresses if they are using that practice, correct?
Absolutely. you know, it's, it's, it's absolutely terrible.
you know, Bitcoin, you know, Through this, you know, crypto anarchist lens, which is, you know, privacy is pretty important. I know that, you know, a lot of people are, are, you know, interested in the economics of Bitcoin, and I am as well, but, you know, these exchanges are just, are just terrible for privacy. Between the on-chain privacy, the KYC-ing yourself, it's, it's absolutely terrible. I'm sort of been really getting into this concept lately of, of, you know, gray markets and, you know, peer-to-peer, Bitcoin. i-is probably, is probably better, than KYC-ing yourself. But, you know, I don't think that people are gonna stop gambling on Bitcoin anytime soon. you know, it's just kind of is a shame that, you know, it sort of has gone the way that it's gone. you know, but that all being said, is, is maybe the, the market will, will hopefully come up with a way to, I don't know, maybe punish exchanges for their poor privacy, privacy practices.
Right. And even in a KYC world, at least if ex-exchanges stopped reusing addresses, that would at least help, right?
Yeah, absolutely. I mean, I'm, I'm thinking of people in, in the future, you know, a-and I know that this happens already, you know, front-monet, front-running, deposits to, To, you know, static, ex-exchange addresses. You know, if, if, you know, exchanges are getting front run and not making as much money as they should be, you know, they should be incentivized to, to fix that. but anyway.
Right. Yeah. Well, I guess it depends on if the exchange is the one losing the money because the exchange is taking a fee for the transaction as opposed to the, individuals who are trying to buy or, you know, the person who got front run in that Yeah. But so anyway, I mean, that's a broader question, and I think things like Liquid may help there as well. but let's turn now to privacy more generally, right? So we were talking about it before, so, I mean, we've kind of covered the PlusToken stuff and what they were doing with Huobi and so on. Let's talk about your thoughts around acquiring bitcoins then in a more crypto anarchist compatible manner. What, what are your thoughts there?
Yeah, I, I mean, it sort of gets back to, you know, some of the things that What are the three sort of main aspects of Bitcoin's privacy? We have on-chain, we have network, and we sort of have how you acquire them. And, you know, the how you acquire, acquire part is, is my opinion, very important. You know, this, KYC is, is, is pretty bad. you know, the, the pseudonymity of Bitcoin is, is, is pretty powerful. you know, without any additional information, you know, the, the network level and the on-chain level, you know, don't, don't matter quite as much if, if, you know, you've acquired your coins through a KYC method. so, you know, hopefully I'd like to see, you know, more of a peer-to-peer style, you know, Bitcoin, Economy kinda going forward.
I guess your main tip then is basically to not use KYC services. Do you have any thoughts around individuals, so for example, they might be thinking, okay, I might buy from a KYC exchange and then do CoinJoin afterwards. What's the big deal with that?
Yeah, that's, this is, this is fun. you know, you can't unKYC yourself. you know, KYC is forever. so there will always be that, you know, real world link between how- How you bought your coins, and all of the, you know, tag-along information, driver's license, bank account number, how much you bought, when you bought, the exchange isn't going to forget that. they'll know that you withdrew your coins to an address, and then from there maybe sent to a mixer. so okay, you know, you, you might break the links between, you know, your withdrawal address and, you know, the exchange might not know what you've done with them going forward, but they're just not gonna forget that So it's, you know, and the same thing sort of holds true for, for network level privacy. It's like, you know, even if you are using your own full node and you aren't sharing your xpubs and you're doing, checking all the boxes, it's not gonna matter, it's not going to unKYC you. So I, I think it's just sort of important that, that get, you know, reiterated. and
so in terms of privacy today I guess you've done a lot of white hat chain analysis. Do you have any views on how easy the average user would be to be de-anonymized? Like how ba-basically what I'm asking is, how bad is it today?
How bad is it today? you know, I, I, it sort of gets back to it, I don't wanna keep beating a dead horse with this KYC thing, but, you know, it's, that's, that's very important. you know, as far as, you know, network level privacy, you know, We've got our own full nodes, we've got Tor, we've got all these, you know, add-ons that are coming to Bitcoin Core in the future that should, you know, be pretty good privacy enhancements. and then when it sort of comes to, you know, on-chain, you know, s-- you sort of have to think of, you know, what are you trying to, you know, defend against? you know, we, we think of these chain analysis firms, you know, they're sort of universally hated for, you know, basically trying And so they rightfully should be hated. I, I think that there's a little bit of, you know, embellishment on their part in sort of what they're doing and what they're actually capable of. There's probably a lot of disinformation into what they're actually doing. I think for the most part, they're, they're They're locked in with exchanges, and they're just, you know, monitoring, users transferring from exchange to exchange. and on top of that, maybe they're doing clustering, and they're doing all the other, you know, heuristics that we talked about earlier. For now, I don't think that they're quite as advanced as, you know, we maybe like to, as they maybe like to advertise that they are, but that doesn't mean that they won't be in the future. and so, you know, hopefully Bitcoin is, is gonna be able to stay
Firms. you know, hopefully with the, the advent of these, these non-custodial mixers that are a lot easier for users to, to get their hands on, is that the chain analysis dataset basically becomes useless junk. hopefully that's, that's the way things will go, but, you know, if, if, you know, Bitcoin sort of really does take off, you can bet that chain analysis isn't gonna, remain where they're at. you know, I know we talked a little bit about before this, Inputs and outputs into transaction, you know, and that if you, if your inputs, and you do coin join, you wind up with probabilistic links instead of deterministic links. Well, it's very likely that, you know, in the future, chain analysis, you know, will develop this probabilistic model and do sort of, a lot of the things that we talked about, you know, to, to Paint a better picture, including timing, address reuse, and all the other problems. so it's, you know, is it, is it awful? you know, I, I think that we probably have more of a KYC problem than we do of an on-chain problem, but, you know, hopefully, with, with a lot of these new services, Bitcoin on-chain privacy just gets better.
That brings the question then around what approach we're using, and some of this comes into, as, as we were talking about earlier, things like Payjoin, Coin selection. So let's talk a little bit about the use of some of these techniques and where they may help. So perhaps let's start with pay to endpoint, or also known as payjoin. Can you talk about what that is and how that helps break the heuristics?
Yeah. so there's, there's sort of our two problems with Bitcoin's on-chain privacy. There's the transparent addresses, which allow you to basically create the, a transaction graph, and then there are transparent payment amounts. None of these things are, you know, hidden with confidential transactions or some type of shielded address, it's, it's out on the open. so, you know, what can you do to sort of address these things? you know, we have the, if, if you wanna address the, the transaction graph problem, you'll do a, a, a typical coin join. that could be, you know, any of the, you know, mixers that we talked about, as well as, you know, Samurai has some, some That's, you know, such a stone wall, and stone wall is, is, it's a little bit of a stealth, technique, but what it, what it basically does is it's a simulated one wallet coin join. Rather than being multiple users, it, it will take a couple of your, your UTXOs and perform a mini coin join, and that will break chain analysis, merged input heuristic. You know, the merged input heuristic, you know, basically operates under the assumption that, will, will basically result in a cluster, and You do a, a coin join, you either have to cluster everything or you have to say, "We can't include this in the cluster." so that's, that's one way to, one way to attack it is, is, is via coin join in, in any kind of, traditional coin join at least. and then you, you mentioned, pay join or pay to endpoint before. pay to endpoints, really pretty cool. It's, it, it's basically a regular Bitcoin transaction, and it looks exactly like a, a regular Bitcoin transaction, but because you're involving the recipient of the, the, the payment in the transaction, it basically hides the, the payment amount. So the transparent, you know, payment amount never shows up on the Bitcoin, you know, never, never shows up on the blockchain. so that's, that's pretty cool. Hopefully, some of these, these, mini coin joins get adopted or, or some more widespread
Yeah, that's a great point, and I think one thing we have to be wary with that though is in order to do that sort of pay join, so, my understanding is Samurai Wallet has a feature called Stowaway, which is, I think, either it is that or it's similar to that idea. So for example, let's say I wanted to pay you with a Samurai Wallet cahoots transaction, and in the process of doing that, I think there's like a QR code back and forward process that we and you and I would share, and now- Now, you, you wouldn't get control of my UTXOs, but now you would have increased visibility into my UTXOs, correct? And so that is potentially a, a vector as well, because if everybody starts doing a lot of these pay-to-endpoint or payjoins or join market payjoins, then people do start getting at least some visibility into their transaction partners' UTXO set, correct?
Yeah, that's correct. I mean, there's always this sort of, coordinator problem of, of how do you- Construct the, the coinjoin transaction, whether it's, you know, Samurai Wallet Cooz or, or, you know, Join Market or, or Wasabi, there are some, you know, trade-offs to, to basically each of those systems for trying to construct the transaction. you know, as far as I understand, there's the maker-taker model in Join Market where the, the taker gets all of the privacy because, or, or the taker's the only one that gets all of the privacy. in Wasabi, they To keep things, you know, kind of, from revealing too much information. and Samurai wallet is somewhat similar, but, you know, these, these sort of in-person, things, they re- they require a level of trust between you and a buddy or, or something along those lines. And sort of at that, you know, peer-to-peer kind of level, it's, it's really not, you know, as much of a trust issue as it is trying to trust some, you know, total unknown third party that, you know, your But, you know, it's, it doesn't seem to be, too big of a deal. Great.
And, one other question around the use of StoneWall. So Let me put this in context. So let's say somebody is stacking bitcoins, right? And they wanna stack that, right? And they wanna, and they might have a cold storage, some kind of cold storage setup, whether, whatever that is, they might have multi-signature, whatever they've got. and so they might acquire those bitcoins, however they, however they did that, right? Whether that's KYC exchange or mining or earning it with BTC Pay Server or whatever, and then they might run that through a mix. And then the question is, how would they- Now spend into their cold storage without obviously doxing, okay, this is my cold storage, right? And so one, I guess there are two main approaches that I have seen here. One is the manual control approach where you literally take each coinjoin UTXO and directly spend that into a new address in your- Cold storage, setup. And then the other approach is the kind of more algorithmic stonewall style approach, which creates only probabilistic links but not deterministic links. What, what's your view there? Do, do you agree that that's a good summary? what's your view there on, that kind of thinking?
Yeah, I, I think that's a pretty good summary, right? You can either spend from your, you know, to your cold storage with, you know, the, the manual selection one at a time, or you can, you know And so the algorithmic method, you know, might provide you with some, you know, additional, you know, privacy sort of in the short term. The, the manual selection, as like you said, will have, will be deterministically linked. you've got At, at best, you know, you'll look at the blockchain and, and someone will know that that maybe that was a self spend or, or something along those lines, if, if it just sits for quite a long time. but both of them are, are sort of subject to this time decay, you know, problem that maybe isn't so much of a threat right now with chain analysis, but could be in the future. you know, i-if your coins sit for, for, it's sort of like the reverse of, of, trying to force too many coins through
Maybe gain some additional information if, if I saw five Bitcoin go in and I see five Bitcoin sitting, you might be able to sort of, you know, come up with a little bit more information about those coins. So, you know, users are, are not gonna leave their, all of their coins mixing all of the time, it's just, it's just not the way it's gonna be. You know, nobody wants to keep all of their coins in a hot wallet.
so, you know, if, if you, if you do mix your coins That you should just be prepared to remix your coins in the future. I know a lot of people are big proponents of always be mixing, you know, and that's, that's probably true here. but I just think that users need to be, you know, prepared to be spending directly from mixes to a third party, you know, coming in the future.
Okay, great. So you were talking there around- Cold storage practices when you combined with coin joining, right? And so because most people don't want to leave the keys hot, they're not just gonna be perma-coin joining on their cold stash. Now, maybe in the future some people have talked about ideas around this with PSBT and so on, but for now, let's just say people aren't mixing their main cold stash, right? Or main storage, right? Or hodl stash or whatever you wanna call it. But there is an implication, as you were saying, around timing analysis and Decay and potentially that means people have to be cognizant that they may need to coinjoin on the way out of their cold storage as well. And one e-examples even, and maybe even before we get to that, is just this idea that if you were to, let's say, spend out into your cold storage and then later you needed to spend all of that cold storage into a new set, well, now at that point, what are you doing? You're, you're potentially gonna merge all the- Those outputs together again, and unless the, tools that you're using for your cold storage also have that kind of tooling to do coin joins, which likely they won't. Then you've got to think about that too, and, or the other way is, potentially to do it UTXO by UTXO and just move, even if you've got a hundred different outputs, to move each of those over individually. but then, I guess the lesson then is even on the way out of cold storage You would have to think about that in terms of, okay, maybe I'll run it through a mix and then spend, do a post-mix spend on that.
Yeah, you know, absolutely. I, I, like we said, you know, users aren't gonna leave all of their, you know, coins hot, even with, you know, some potential, you know, possibilities for, for cold, you know, cold mixing, you know, in quotes, you know, so- It's probably the, at least the way I, I think about it is that if, if you're gonna coinjoin and you're gonna send back to cold storage, just be prepared to mix again in the future and, and spend directly, you know, to a third party from a mix, 'cause that's, that really is sort of how these things are, are, are designed to be used, at least in my opinion. I know that, you know, like we said, it's, it's not gonna stop users from mixing to cold storage, but just as long as they're
It, it sort of gets back to this concept of, you know, what, what really are the best, how, what is CoinJoin really best for? I know we talked a little bit about kind of transaction graph privacy, we talked about, you know, hiding the payment amounts and, and all of these, sort of technical things, but at the end of the day, you know, you don't want your, your counterparty to know your, your Bitcoin's history. That's really, where, where CoinJoin, you know, kind of shines. So that's, that Great
point, but let me just slightly push back there. I, well, maybe it's just a question of tooling right now. The tooling right now isn't easy to use to do that. So for example, if you want to spend straight from the mix, well, in the case of Wasabi and Samurai, you can't really do that because it, it dumps it out back into your address right now, and with Samurai, it gets dumped back out into a post-mix section, right? It's not spending directly to the party that you want to. And also because of the equal input and, equal amount that are being coin joined, unless you're gonna pay someone exactly point o one or point o five or point five in the Samurai model or zero point one in the Wasabi model or those other mix amounts, although, as I understand, Join Market does have some, Tumblr- algorithm or script that you can use to say, "I want to pay to this address and then mix it directly there." But what's your view there?
Yeah, I mean, that would be an interesting, you know, addition is, is to mix directly to the third party. but that's, you know, a, a very technical problem that, you know, has a lot of, I guess, technically issues. You know, I keep just going back to spend directly from the mix. You're gonna have maybe these little bits and pieces, or in the Wasabi model, you're gonna have, you know, these deterministic links, but, at least the way I, I sort of see with, with Stonewall and, and Samurai's, you know, model is that, it, Stonewall prioritizes, The change from a previous transaction. This is to sort of, reinforce that model of, "Is this really one wallet or two wallets?" so, you know, that, that sort of helps take care of it, which is kind of neat. I noticed that a little while ago. But, you know, you're still gonna have either these sort of deterministic links or these little bits, little bits that you kind of have to deal with in the future. you know, so it, it sort of is kind of, the, the function of Bitcoin's UTXO model. there's just always gonna be, you know, sort of some kind of change to be a little bit of a problem.
Right, I see you. Yeah, yeah. I think I might have misunderstood, yeah, because you were saying spend directly from the mix, whereas Like, i, i, the result of the mix going directly to the third party, but what you're talking about is more like having a post-mix strategy basically and doing it correctly from a post-mix point of view.
Yeah, it's, it's, you know, are you paying to someone else or are you paying to yourself? that, that I think might be maybe a little bit of a disagreement there.
Gotcha.
Okay.
So The other cool thing is, Stonewall, w-well, with the algorithm, my understanding there is that it will try to include extra inputs into the transaction to basically make it less clear what is actually being spent and who owns what.
Yeah, that's correct. I think we said before, Stonewall is a, a s-- a simulated, you know, coin join. You control all of the UTXOs, but if you look at it on the blockchain, it looks Similar to a, a traditional coin join. I think the way that they, the samurai guys have the, the algorithm tool now is that, you've got basically your, your payment amount, it's got an identical output, and then you've got two identical quote change outputs. So you wind up with sort of four UTXOs typically, while you wind up with three, you know, the, the, the person that you're spending to winds up with one. And so, it's, it's pretty neat, but you sort of, You wind up with, you know, two little, little two little bits of, two anon set, you know, kind of, you know, coin joints.
Right, I see you. Yeah, yeah. And then so then the question then is, what would people do with those other little leftover bits? could, or would they just sort of continually accumulate?
Well, you know, I guess if- The exchange rate does what, you know, we, we think it will do. These little bits become, you know, more and more apt to, to spending. I think that that sort of is number one. And the other thing is, is that, you know, the way that the algorithm works is that you can merge, some of these, a little bits into, you know, a larger transaction that will still, you know, have higher entropy and a higher number of interpretations that we had kind of said before. you know, and then from there, I guess the logical You, you basically have to remix them. I know that Samurai has some plans for that, you know, kind of going forward, which, you know, hopefully will be pretty neat to see. Yeah,
that's awesome. I'm looking forward to seeing that as well. Okay, so, yeah, I think we've done a pretty big, comprehensive talk through a range of, different topics. Are there any helpful resources that you would like to point the listeners to, anything around the Boltzmann algorithm or any other helpful, resources?
Yeah, I mean, For, users to just go out and play around with, you know, the block explorers that we sort of mentioned before. We mentioned KYC-P, we mentioned OXT. OXT is, is really pretty cool. I've even seen some other users recently, you know, looking to track some, you know, scammed or stolen coins, and, and tweeting about it, it's pretty cool. But it has a nice transaction graph feature. Instead of looking at blocks of text, you can play around, and it doesn't even have to be your transaction, it could be somebody
And, you know, I've, I recommend that users read, the gist sections of Laurent's Bolzmann posts. I know you had mentioned before the, the comment section of the first gist between, Waxwing, you know, Adam Gibson and Laurent was, was pretty, was pretty neat. I liked that one particularly because, you know, Adam- Was coming at it from a, you know, okay, what UTXO is the, the payment to the third party, which a lot of people sort of try to impose on Bitcoin. And Laurent's, you know, kind of stance is that, you know, the blockchain doesn't really see, you know, which, you know, user received the output. So that's, that's a pretty neat back and forth that I recommend people go and, go and read. I also like, you know, Gregory Maxwell's, original Bitcoin Talk posts, those are,
is a, is a useful, research paper. And beyond that, I know it's not really, you know, it's usually frowned upon to come on and talk about another podcast, on a podcast, but Bottom Shelf Bitcoin episode twenty-five with Adam Gibson or Waxwing was it, was really very helpful, especially for me in sort of getting a, a good handle on a lot of this stuff. So I think users would be really, you know, if they don't wanna do any of that other stuff, you know, but, and
they're into podcasts, go With Adam Gibson on the bottom shelf Bitcoin, show. And, I guess the next question I've got is just more around your views on the future of chain analysis, right? So to some extent, we can view the use and creation of some of these tools like KYC-P dot org and OXT dot me and so on as ways of You know, doing the white hat analysis on ourselves before somebody else comes and does it on us. where do you see all of this going in terms of the next steps for, let's call it black hat, chain spies versus the, white hat, privacy activist types?
You know, I, I wish that there was, Some more information about what Chainalysis is actually kind of doing now, but of course, they're not gonna, they're not gonna let us know that, you'd have to be in on their sales pitches, to really get a good handle on it. But, you know, I think that hopefully, you know, Bitcoiners are, will stay a couple steps ahead of them. sort of just like you said, you know, we have some of these privacy algorithms that maybe they're aware of, maybe they're not, and that, you know, Bitcoin, Bitcoiners will probably Is even capable of doing. so hopefully, you know, we can just sort of stay, you know, a couple steps ahead of them.
Right. Yeah. And also, did you have any thoughts around the combination of things like coin, coin join techniques with Lightning?
you know, I really haven't spent too much time looking into that yet. You know, it's, it's, there's just only so much time in the day, and I, I chose to start with, with coin join, you know, and specifically on chain. And hopefully,
Interesting potential combination in the future as well that we may see. So, yeah, I guess, was it, were there any other points you wanted to bring up? Or, I think, I think that's pretty much it. So, if you've, got anything else to say, and also, just say that, and also just let the listeners know where they can follow you online. No,
I think we're, we're pretty much all set here. you guys can find me on Twitter at ErgoBTC. just, you
know, hit So how cool was that? Do you think the PlusToken scammers are why the market shot up so fast earlier this year and why this recent dump happened, or do you think it's probably not the most important factor? Either way, I hope you took away some tips on how to protect your own privacy. I've also got an announcement, I've just been announced as a speaker at Bitblock Boom, August 22nd and 23rd of 2020 in Dallas. So use the code Livera and you get 30% off. The website is bitblockboom dot com The show, remember to retweet and share it out with your friends. As always, you can get the show notes and the transcript on my website stephanelivera dot com. Thanks for listening, and I'll see you in the citadels.