De-Mixing Wasabi Coinjoin Transactions: A Deep Dive Into Chainalysis’ Deanonymizing Claims
De-Mixing Wasabi Coinjoin Transactions: A Deep Dive Into Chainalysis" Deanonymizing Claims
On Tuesday, journalist Laura Shin published a story that claims to identify the 2016 Genesis DAO hacker who siphoned 3.6 million ethereum from the decentralized autonomous organization. While the story surprised the crypto community, one of the biggest eye-openers was the blockchain analysis methods leveraged, and the claim that Chainalysis allegedly “de-mixed” Wasabi transactions. Community Shocked by Chainalysis ‘De-Mixing’ Wasabi Transactions, Samourai Wallet Criticizes Wasabi’s Coinjoin Scheme
An article published by the journalist Laura Shin has revealed a so-called shocker about the use of Coinjoin transactions. Specifically, Shin’s report highlighted how she used a “powerful and previously secret forensics tool from crypto tracing firm Chainalysis.” According to the report, Chainalysis discovered the attacker sent 50 bitcoin to a Wasabi wallet, and the blockchain intelligence firm was reportedly able to “de-mix” the transactions. This piece of information was unexpected to a great number of crypto supporters. After the article was published, bitcoin advocate Nic Carter wrote: Lots of crazy stuff in the DAO hacker piece this am, but the part that stood out to me was Chainalysis being able to demix Wasabi [transactions].
Furthermore, the team behind the Samourai wallet criticized Wasabi’s mixing scheme on Tuesday as well. Wasabi has been under fire in the past over privacy concerns and the team has been debating Samourai developers over the issue for years. If you are using wasabi, you need to read this thread: https://t.co/FL7f30nWeC
"With Wasabi if you are mixing 10 BTC, I can trivially track that 10 BTC as it is peeled down into smaller utxos. The left over change is part of the mix tx, and thus creates a determinstic link" pic.twitter.com/yTqJCp0YLp
— ODELL (@ODELL) July 18, 2019
On July 16, 2019, Wasabi tweeted that it donated funds to the Tor project and left the transaction ID in the tweet. Crypto developer Keonne Rodriguez replied to Wasabi’s tweet and claimed to deanonymize the transfer.
“Input:1 comes from [the previous transaction] to Wirex in the amount of 4BTC in which 38 inputs from Wasabi mixes were merged,” Rodriguez said at the time. “Since Wirex uses 1 static address and doesn’t refresh them we know that the total amount sent to this Wirex account is 6 BTC (nice job).” The software engineer continued: Input:0 comes from a prev mix with 31% of [transactions] seen together (this is actually a fairly low number for Wasabi, nice job), and a few obvious deterministic links. About 30 of the outputs have been clustered by OXT, and I suppose I can go and cluster more with a more powerful PC. Samourai Sends Wasabi an ‘Immediate Private Disclosure’ in 2019, Wasabi Wallet Founder Stressed Samourai’s Claims Were ‘Inflated’
On August 19, 2020, the Samourai wallet team published a blog post that claimed to find two potential privacy vulnerabilities with Wasabi’s mixing scheme. Samourai detailed it discovered this information while researching the infamous Twitter hack that took place that summer. According to the wallet developers, they made an “immediate private disclosure” to the Wasabi team concerning the issues.
“The intention of this statement is to provide enough time for Wasabi Wallet users to seriously consider pausing usage of the Coinjoin aspect of the Wasabi software, if users wish to continue making use of this feature they should consider their reported anonset is *at best* equal to the anon-set of the last mix that generated the UTXO,” Samourai wrote at the time. However, Adam Ficsor, the founder of Wasabi wallet, claimed at the time that Samourai’s claims were “inflated.”
“They claimed Wasabi is broken because of the lack of randomness in coin selection for Coinjoins,” Ficsor said in an interview published the day after Samourai’s vulnerability report. “More specifically, they tried to show that if an adversary knows all the UTXOs in a wallet, then it can tell which coin will be mixed next time. This is pointless as the only entity who knows the UTXOs in a wallet is the user itself. Then they moved on to building more and more on this false premise, repeating their conclusion over and over again, and that’s the rest of the technical part of the letter.” Ficsor added: The community knows their claims are inflated and in their latest attempt they seek more credibility by trying to get us to play along with their nonsense by writing us a blackmail letter that has all the social engineering tricks in it, like setting deadlines to create a sense of urgency, repeating their false conclusions over and over again, and presenting the possible options that we have and explaining the consequences of us not playing along to create a sense of fear. Amir Taaki Calls Coinjoin Schemes ‘Absolute Garbage,’ Gavin Andresen Wouldn’t Be Surprised if ‘85% of Tornado Cash Usage Was Not Private’
In addition to Wasabi, the Coinjoin mixing scheme itself has been criticized for leaking specifics about the mixing participants. Essentially, Coinjoin is an anonymization scheme first proposed by the developer Gregory Maxwell and it allows participants to combine multiple payments into a single transaction in order to obfuscate the transaction process. It’s true that Coinjoin offers a deeper anonymity set, but if a user mixes a bunch of coins and eventually consolidates them into one address, it can still leave behind some traces to the original owner.
This issue has been known for quite some time and many developers have explained the downfalls of the deanonymization procedure. In July 2020, the crypto developer and activist Amir Taaki told the public that UTXO mixing concepts like Coinjoin were “absolute garbage.” Taaki is well known for developing the privacy wallet Dark Wallet, an unfinished Coinjoin wallet protocol he developed with Defense Distributed’s Cody Wilson. Taaki also claimed that the privacy-centric coin monero (XMR) and concepts like Mimblewimble were not that great.
Furthermore, the former Bitcoin Core developer Gavin Andresen has called out issues with Coinjoin schemes in the past as well. In a blog post published in January 2020, Andresen discussed the ethereum (ETH) mixing tool called Tornado Cash. Interestingly, Andresen wrote that he wouldn’t be surprised if a paper came out in 2023 that shows “85% of tornado usage was not private.” Andresen’s blog post adds: Not because the cryptography is broken, but because it is really hard for mere mortals to use something like Tornado (or Coinjoin or other similar technologies) in a way that doesn’t leak information about their wallet.
Meanwhile, speaking with theblockcrypto.com’s Yogita Khatri and Tim Copeland, Chainalysis told the reporters that “Laura’s report about our role in her investigation is accurate.” The reporters also spoke with the Chainalysis competitor Elliptic and co-founder Tom Robinson stated that “Elliptic can also demix Wasabi transactions in some circumstances.” Tags in this story 2019, Adam Ficsor, Amir Taaki, Chainalysis, Chainalysis Wasabi, CoinJoin, Coinjoin Schemes, DAO hacker, DAO hacker piece, Dark Wallet, Deanonymizing Claims, deeper anonymity set, Elliptic, equal inputs, Gavin Andresen, Gregory Maxwell, Keonne Rodriguez, Laura Shin, Laura Shin article, Mimblewimble, Mixing, mixing tools, original address, Privacy, privacy concerns, samourai wallet, Tim Copeland, Tom Robinson, Tor project donation, Tornado cash, wasabi, Wasabi Wallet, Yogita Khatri
What do you think about the claims showing Chainalysis de-mixed Wasabi transactions and the claims against Wasabi’s mixing scheme in the past? Let us know what you think about this subject in the comments section below. Jamie Redman
Jamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 5,000 articles for Bitcoin.com News about the disruptive protocols emerging today. SCRT Labs Launches $400 Million Fund to Bolster Privacy Network"s Ecosystem and Application Layer PRIVACY | Jan 19, 2022 Crypto Mixing Tools Tornado.cash and Cashfusion Obscure More Than $8 Billion in Transactions PRIVACY | Dec 25, 2021
Image Credits: Shutterstock, Pixabay, Wiki Commons Previous articleFinder’s Experts Predict Dogecoin Will Reach $0.16 This Year, Panelist Says ‘Luster Will Wear Off as Meme Coins Lack True Utility’ Next articleEU Members Want to Task New AML Watchdog With Crypto Oversight, Report Unveils Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments More Popular NewsIn Case You Missed ItFintech Specialists Predict Ethereum Price Hitting $6,500 This Year Before Rising to $26,338 by 2030
A panel of fintech specialists has predicted that the price of ethereum will reach $6,500 by year-end. It will then rise to $10,810 by 2025 before more than doubling to $26,338 by 2030. Fintech Specialists Share Ether Forecasts Price comparison ... read more.JPMorgan Predicts Long-Term Bitcoin Price of $150K — Outlines Challenges Ahead Fitch Ratings Downgrades El Salvador Deeper Into Junk Status Citing Bitcoin Risks City of Miami Gets $5.25M Disbursement From Miamicoin as MIA Flounders 88% Lower Than Price High RBI: Cryptocurrency Is a Big Threat to Macroeconomic and Financial Stability in India