So more likely than not, the people calling for regulations on bitcoin have little to no understanding of its basic properties.
How many on HN would gladly jump at the opportunity to "understand the necessary hashtags", and write the software with skinner box like interfaces for our glorious institutions that we owe our mind and body to in order to protect us from ourselves?
Excluding those of you who already work on these profitable boondoggles of course… ;)
I think it is. From my limited understanding of cryptocurrency wallets and transaction, I believe the distributed ledger is public, so anyone (incl. Govt.) can see which wallet address has how much coins / funds in it. But you can't see which physical human or institution owns that wallet / address.
That's how it's widely known that just about 1,650 wallets hold a majority of the world's bitcoins. These are wallets with > 1000 bitcoins. They are called 'Whales'. But it's almost impossible to tie a Whale account to, say, Richard Branson or Ross Ulbricht.
If you take Paypal payments as example, this is similar to everyone knowing your email address for paypal, but only paypal knowing that the email address is tied to you.
Not only is the wallet address public you can see entire transaction history of each address. Keeping a Bitcoin address separate from your true name is exceedingly difficult.
1. When you trade Bitcoins into fiat money with an exchange you reveal your true name.
2. When you purchase something with Bitcoin you reveal the mapping between your Bitcoin address and your mailing address.
3. Unless you are using TOR when you announce a transaction on the network you reveal the mapping from IP address to Bitcoin address.
4. When someone sends you Bitcoins they can track how those Bitcoins and spent and what Bitcoin addresses they are moved to.
5. Companies have large databases of known identity to Bitcoin address mappings allowing process of elimination or guilt by association privacy attacks.
"Bitcoin offers privacy—as long as you don't cash out or spend it" - PC World
Disclaimer: I do Bitcoin privacy research.
1. There is no logical relationship between address A that spends to address B. 2. A could be part of the same wallet as B, or not. 3. A or B could be undisclosed addresses of merchants, or unrelated parties entirely. You may have to ask, and they may choose to tell you.
Defeating your inferences is trivial. A blockchain analysis may reveal that A sent to B, who sent to C, but there is no logical relationship between A and C based on this transmission alone. Moreover, A can send to B, B' sends to C. You derive no information.
Had a follow up question on some things.
> 1. When you trade Bitcoins into fiat money with an exchange you reveal your true name.
I get that. But how are the hackers who stole / continue to steal from exchanges like in the Mt Gox hack -- and more recently, the CoinCheck[1] -- hack, able to get away with it? See CoinCheck link and quote below. Important takeaway is
> Coincheck has identified and published 11 addresses where all 523 million of the stolen coins ended up. You can see for yourself online. Trouble is, no one knows who owns the accounts
From what I understand, in both cases, hackers hacked into the Exchange, stole the Private Keys to the "Hot Wallets" holding large amounts of the coin (bitcoin, NEM etc) and then transfered the coins into their own "Wallet" which isn't tied to any exchange. So as far as bitcoin or NEM is concerned, this transfer was/is a legitimate ledger transaction as the private key from sender was used to deposit the coins into receiver (hackers' ) wallet.
Not trolling, really would like to know the following
1) How are exchange hackers able to remain anonymous and not get caught.
2) How do they move the coins they stole and cash out on FIAT?
Obviously (or maybe not) these hackers wouldn't be buying stuff and shipping to their home address, so #2 above is moot.
3) Is it possible (wearing my conspiracy theorist hat here) that these exchange CEOs / Founders perpetrate the hack themselves, so they can declare a loss, and then take possession of the coins and use the anonymity to cash out at a later date?
[1] How to Steal $500 Million in Cryptocurrency http://fortune.com/2018/01/31/coincheck-hack-how/
> 2. Where did the stolen coins go?
> That’s one of the stranger aspects of these heists. Because transactions for Bitcoin and the like are all public, it’s easy to see where the NEM coins are — even though they’re stolen. Coincheck has identified and published 11 addresses where all 523 million of the stolen coins ended up. You can see for yourself online. Trouble is, no one knows who owns the accounts.
It is a good question and I don't have an answer as I don't know many of the details of the Mt. Gox hack. Many details on these hacks are not public. There have been arrests in Mt. Gox BTW.
My favorite quote on this subject is:
1. One possible answer is that the attackers just sit on the coins and don't attempt cash them out see "Bitcoin offers privacy — as long as you don't cash out or spend it".
2. Another possibility is the thieves either live or cashed out in jurisdictions which won't cooperate with investigations.
3. Or as your article states the thieves could attempt to move the coins through privacy coins such as zCash or Monero to hide the final destinations of the coins. However that is a fairly risky proposition, if they make a mistake they are cooked and there are so many mistakes they could make. I don't believe either zCash or Monero offer network level privacy other than TOR and TOR is problematic as it was not designed for cryptocurrencies. Monero is planning I2P support [0].
Then again it could be the case that law enforcement organizations investigating some of these cases don't have the expertise to understand the highly technical evidence they have.
https://decentralize.today/a-new-attack-vector-to-deanonymiz...
https://www.coursera.org/learn/cryptocurrency/lecture/qnS76/...
Because of KYC[1] and AML[2], an address belonging to an exchange wallet should probably be considered doxxed. An authority can say “Hey Coinbase, I see you sent coin from address A on this date. Show me what account that came from.”
CoinJoin[3] was intended to solve this problem, but apparently doesn't[6]. I was going to say that a decentralized cross-chain trading scheme[4][5] to launder through an anonymous currency such as Monero or ZCash might provide anonymity, but it looks like there's enough information to correlate the transactions across chains. (Even if there weren't, cross-chain trading might practically have one of the same issues as CoinJoin: that the transaction volume is just too low to provide anonymity.)
There's other cryptocurrencies designed to provide anonymity[8]. The Lighting Network[10] might add this to Bitcoin[11]; I don't know if that's still one of their goals.
EDIT: I somehow missed EthanHeilman's comment, above, when I wrote this. He says pretty much everything I said about why it's hard to keep Bitcoin activity private, more clearly. I included more links, though :-)
[1] "Know Your Customer", https://en.wikipedia.org/wiki/Know_your_customer
[2] "Anti Money-Laundering", https://en.wikipedia.org/wiki/Money_laundering#Anti-money-la...
[3] "CoinJoin", https://en.wikipedia.org/wiki/CoinJoin
[4] "Atomic cross-chain trading", https://en.bitcoin.it/wiki/Atomic_cross-chain_trading
[5] "First Ever Cross Chain Atomic Swap Between Bitcoin and Litecoin a Success", http://bitcoinist.com/first-ever-cross-chain-atomic-swap-bet...
[6] S. Goldfeder et al, "When the cookie meets the blockchain: Privacy risks of web payments via cryptocurrencies" (2017) https://arxiv.org/pdf/1708.04748.pdf.
[7] "Bitcoin Transactions Aren’t as Anonymous as Everyone Hoped ", Technology Review Aug, 2013, https://www.technologyreview.com/s/608716/bitcoin-transactio... summarizes [6].
[8] "Keybase chooses Zcash" https://keybase.io/blog/keybase-and-zcash has a fun example of address linkage.
[9] Sudhir Khatwani, "9 Anonymous Cryptocurrencies You Should Know About", 2/02/18. https://coinsutra.com/anonymous-cryptocurrencies/
[10] Lightning Network, https://lightning.network.
[11] Aaron van Wirdum, "How the Lightning Network Layers Privacy on Top of Bitcoin", Bitcoin Magazine, Dec 19 2016. https://bitcoinmagazine.com/articles/how-the-lightning-netwo...
Local wallets cycle addresses often.