pull down to refresh

I used Samourai/Whirlpool for a few years. Fresh wallet, dojo instance, tor. Let's say I had one main utxo that went into Samourai, got split into equal pieces via their tx0 idea, and then went through 20-30 mixes.

If I recombine any of these smaller utxos, does it make it easier to identify the original utxo from which they came?

1208 sats \ 6 replies \ @Kruw 25 Jul

Whirlpool has worse privacy, fees, speed, and custody model than a regular Bitcoin payment:

-The privacy is worse than sending normal on chain payments because tx0 always reveals common input ownership and creates change
-The fee is worse than on chain payments because the victim wastes fees in tx0, wastes fees remixing sybil attackers, and wastes fees paying the coordinator (feeding the attacker)
-The speed is worse than a regular payment because you have to confirm tx0, then Whirlpool, then spend. Best case scenario 30 minutes.
-The trust model is worse than a regular payment because the coordinator can just steal your fees in tx0 and never whirlpool your coins.

Samourai's absence from the community unironically prevented Bitcoin from being destroyed. It is a downgrade for users in every possible category, see an example here: https://bitcointalk.org/index.php?topic=5482818.msg63551707#msg63551707

I had a fantasy about building a tool that shows your exposed Whirlpool data for a long time, but it would have been pointless since it would not include the xpub data from Samourai and the Electrum data from Sparrow. But now it is relevant since Ashigaru at least requires Tor, so a tool that tracks the on chain peeling that is built in to tx0 would be mostly accurate from a third party blockchain viewer perspective.

reply

I'm willing to accept all of this.

my question is about the ease with which someone can identify the common ancestor from before the tx0 if 2 or more of the 5 outputs from the tx0 are later recombined.

for instance if I had a single kyc'd utxo which tx0 split into 5 equal utxos and then those go through many rounds of whirlpool mixing, does combining any number of them trivially link them back to the original kyc'd input (since it is the obvious origin of all five)?

reply
462 sats \ 0 replies \ @Kruw 25 Jul
my question is about the ease with which someone can identify the common ancestor from before the tx0 if 2 or more of the 5 outputs from the tx0 are later recombined.

Easily, and in some cases, with certainty. The structure of Whirlpool makes this worse, but it's an underlying problem for any private currency system: Some people have realllllly short time preferences that undermine their anonymity.

reply
169 sats \ 1 reply \ @OT 25 Jul
wastes fees remixing sybil attackers,

Whirlpool didn't charge for remixes.

reply
1047 sats \ 0 replies \ @Kruw 25 Jul

I mean the t2new entrants to Whirlpool who go through a tx0 subsidize the mining fees to push UTXOs forward for 3 remixing participants. If the remixers are all coins belonging to the attacker, that means the victim pays for their own attack.

reply
41 sats \ 1 reply \ @ek 25 Jul
Samourai's absence from the community unironically prevented Bitcoin from being destroyed.

Can you explain how Samourai's presence in the community would have destroyed bitcoin?

see an example here: https://bitcointalk.org/index.php?topic=5482818.msg63551707#msg63551707

A reply for more context:

Look man, I don't know what you're trying to do here. Don't you have enough with 15 neutral color tags but basically saying you're a piece of shit? Now you want to open a rational debate by quoting someone who is going to die? If it's because Wasabi pays you to represent them on the forum, the best thing you can do is stop doing it. Otherwise you're just going to inspire more hate.
reply
1147 sats \ 0 replies \ @Kruw 25 Jul

Those angry replies are from the "mixer site" cartel that took over Bitcointalk's merit and trust system. ChipMixer then scammed all of them. That's basically the reason the site died: Everyone cycles merit and farms spam to get payouts from corrupt advertising campaign managers.

It's a good thing we have Nostr and Stacker News. Otherwise, we would be stuck with that bullshit, X, and fucking reddit.

reply

After 20-30 mixes recombining them from all sorts of utxos shouldn't be that easily identifiable. Not even the amount will match anymore after so many fees.

reply
41 sats \ 0 replies \ @adlai 26 Jul

the Bitcoin blockchain is not Big Data, and graph theory is older than modern cryptography.

reply
55 sats \ 2 replies \ @Kruw 25 Jul

This doesn't scale, since new entrants to Whirlpool pay the mining fees to remix the existing liquidity. This means in order for one user to get to 10 mixes, that would require 5 different users to stop at one mix (with a 5 input / 5 output structure).

reply
230 sats \ 1 reply \ @tomlaies 25 Jul

well that wasn't OPs question tho, was it

reply
222 sats \ 0 replies \ @Kruw 25 Jul

Haha. Thanks for correcting me, I didn't see there was a parent comment.

reply

Your Product has great potential and offers some useful features, but I encountered a few issues that could be improved. Please contact me so I can share detailed feedback and suggest the changes I'd like to see.

WhatsApp: +923189350750
Email: mailto:contact@rforrank.com

Yes — recombining them can absolutely weaken the privacy you gained.

Even after many mixes, if multiple equal-value UTXOs ultimately came from the same tx0 and you merge them again, you’re giving chain analysts a much stronger clue that those branches share a common ancestor. The mixes help, but recombination can still undo part of that separation.

In practice, avoiding merges is usually the safer move if privacy is the goal.