Once KYC gets involved.
If I receive coins in my desktop wallet for the cookies I'm selling, how will anyone know who I am? Of course they're not much use until I cash out and then it's a different story.
Or you could use the currency as a currency. Sure, there are a lot more flour suppliers who exclusively accept USD vs ones that take BTC - but compared to the way things were 10 years ago...
Try to buy a Tesla or a house anonymously. All large transactions are subject to KYC.
You usually need some form of distributor's license to not have to pay sales tax on the transaction. That license requires identification.
Of course you could refuse that and just pay the sales tax, but who does that? I would be a little surprised if they even had the means to do it. Warehouses normally sell to distributors, who have distributor's licenses so they don't pay sales tax. Why would they have a system to collect sales tax and send it to the government? That transaction is going to stand out, a lot. Trying to pay for it in Bitcoin is only going to make it worse.
Unless, of course, you're trying to pay the warehouse manager to help you steal the dishwashing detergent. There's no papertrail, but remarkably high counterparty risk. Plus at the end you're stuck with a bunch of hot dishwashing detergent that you're going to have to offload.
Way back in the day I took some profit by purchasing something like $50k in server hardware that needed to be bought one way or the other. Nothing but a "ship to" address and a BTC private key. Was I trying to secretly launder money? Nope, just a boring business transaction that didn't involve VISA. Was it to cheat the tax man? Nope, the IRS had very pointed refused to issue tax guidance up to that point (and continued to do so for years) - so I just paid the long term capital gains when doing the other paperwork one does in a self funded a business venture.
I always wonder about the people who assume cryptocurrency is something that needs a level of law enforcement scrutiny beyond any other method of payment, how much misinformation was required to yield that result, and if they'll be able to adapt to the inevitable.
It sounds to me like you tried to purchase from a seller who expected to be paid in USD, not BTC (which doesn't need a "processor"). Do you really not know why this is a silly complaint - especially given the context?
If I bought cookies from you and paid with crypto you have to know the address I want you to send the cookies to. Or I have to pick them up in person and you'll see me. Either case greatly reduces anonymity.
This vulnerability doesn't exactly exist for all crypto. Privacy coins aren't necessarily unique (or at least for practical purposes). The uniqueness of the coin is what allows it to be tracked. That's why we know where the GOX coins are and this is why that hacker can't use those coins. As soon as they try to turn that into real money we got 'em.
What stops them from converting the coins into something else (e.g. some other cryptocurrency or commodity) in a jurisdiction that doesn't do KYC, and then converting that into dollars? Or just dumping it into a cryptocurrency tumbler?
The whole concept of tracing the source of money is kind of ridiculous. If somebody robs a bank and the bank robber buys a shoe and the shoemaker buys a cake and the baker buys a portrait and the artist buys a screw driver and the hardware store owner deposits the money with that serial number in the bank, the hardware store owner has really nothing to do with the bank robbery, and isn't going to remember which of their thousand customers paid them with that specific bill.
And if you try to say the hardware store owner doesn't get to keep the money all you're doing is causing the money to be stolen twice.
You're not just dependent on your own opsec, you also have to worry about anyone you receive from or send to.
It's definitely a lot more difficult nowadays, though.
It's because KYC requirements and money changing regulation were applied to people selling btc in any real quantity. Someone I knew caught a case a few years ago for doing essentially the localbitcoin (and not telling the undercover to leave when the cop implied he got the money from selling drugs... allegedly).
Anything you tumble, you can (provably) de-tumble. It's just expensive and time-consuming (re-building the blockchain state, yadda yadda). Crypto banking is less anonymous than actual banking, especially if you actually want to pull your money into fiat and need to go through an exchange.
Source? Enough CoinJoins (Wasabi+Joinmarket) and I don’t think so. Note CJ work a bit different than the oldschool custodial tumblers. Combining CJs with LN (reverse) submarine swap for another layer.
With large enough anyonymity sets you should have plausible deniability. This is also a bit time-consuming, more so the larger the amount; there’s no way to do a complete end-to-end transaction of billions of dollars untracably in mere hours without standing out I think. But if you have days/weeks to break the link I think it’s def doable and done.
Obviously make one single mistake and you’re out, but that’s in the nature of these things.
If I’m wrong I’d very much appreciate something substantial.
not really? If you have a transaction that has five equally sized inputs A_{1...5} and five equally sized outputs B_{1...5}, then the max extent you can "provably" de-tumble B_1 is saying "there's a 20% chance that it came from A_1, 20% chance it came from A_2, ..."
You can't do this[1], as the blockchain does its best to be perfectly deterministic. Best you can do is get an oracle to get you a random seed (which you'll see publicly in the oracle token), so you'll know exactly "what went where."
[1] https://blog.chain.link/random-number-generation-solidity/
The transaction chains are generally constructed off-chain.
For Ethereum you can do fancier things with zk constructs, like Aztec and Tornado Cash.
Doesn’t it just need to require that the sum of the inputs is equal to the sum of the outputs?
One-sided JM for BTC include Wasabi and Samourai Whirlpool. Though Samourai are a bit sketch IMO.
Some people will say they aren’t doing anything big enough to warrant attention but that’s forgetting that everyone using a tumbler is paying extra to help anonymous strangers launder money. If anyone involved attracts attention it’ll bring scrutiny to everyone else, and potentially the need to prove that you were “just” committing a small-scale crime and didn’t know that most of the other coins being tumbled belonged to a cartel.
I don't really know, but putting myself in a criminal's shoes, I don't like the idea that my transactions stay in plain view forever. It makes statistical attacks very, very easy. It also makes me vulnerable as-of-yet-undiscovered statistical attacks.
BitCoin is arguably the worst thing for organized crime.
We will soon be living in a world where crime is the norm.
Why do you believe tornado to be secure? The project is self described as experimental software.
“ Tornado.cash was audited. However, it is still an experimental software. Please use at your own risk.”
Exchanges typically ask for an ID in most countries these day before you can purchase any crypto. I'd be curious how you avoid detection unless you started very early in crypto by mining on your own. You'd still need an ID to exchange back to fiat anyway.