The wallet provider could, in principle, be subpoenaed / coerced /hacked / owned by the NSA. I imagine there will eventually be a Tor-like "onion" anonymization method, where bitcoins are routed through multiple such services, so that no single service need be trusted (except to not steal your money). The main challenge with these techniques is avoiding forms of traffic analysis, where I notice B$98.23 heading from A to B, and shortly thereafter, B$98.22 heading from C to D, and infer that these represent a single transaction chain despite being disconnected in the block chain record. Such attacks can be minimized by, e.g., settling on a fixed transaction amount for all transactions with a given service, and adding random delays commensurate with the transaction rate and degree of anonymity required.