An incomplete guide to stealth addresses
vitalik.eth.limo
vitalik.eth.limo
When Peter Todd wrote a paper describing the technique for Bitcoin in Jan 2014 I wrote the first implementation. [1, 2]
At the time I wanted to call them re-usable addresses, because the published address by the person wanting to receive funds is truly and privately re-usable. This is super useful for writing static addresses in places (like GitHub pages or on business cards) which don’t implicitly divulge the full transaction history for that address. So for example taking donations for your open source project without having to show a public record of all those donations.
The trade-off of not having to provide a server for generating one-time addresses is that the receiver has to scan the whole blockchain and perform a bit of work to check if each one might actually be for them.
Anything you do to reduce this scanning burden also reduces the privacy of the scheme, necessarily.
So although the usability of the paying semantics are fantastic, the usability of receiving requires network and computation. Typical PIR trade-off.
However, one thing I really love is that on the receiving side you can have just one private key which will allow you to discover all sent funds. Under the hood on the blockchain no addresses are actually being reused.
So you have to scan for your funds, but they will all be there with just one key to keep secure and one public address that can be “paid-to” without being able to actually lookup any transactions that were actually sent to that address.
I don’t know if they ever standardized an address form to use this scheme in Bitcoin but in my opinion it is a really fantastic way to use a public blockchain.
At the time, I tried and failed to write the receiver-side scanning code into bitcoind because I didn’t know enough C++.
[1] - https://www.mail-archive.com/bitcoin-development@lists.sourc...
So if Alice wants to send Bob an NFT, Bob creates a new address (recoverable with the same seed phrase) and Alice sends it there. Bob can then fund the wallet with tornado cash to use the NFT.
It's a stupidly complex way to achieve privacy and Tornado Cash is illegal. That's why we need private by default chains like Aztec & Aleo
With stealth addresses, once Bob published his public address, multiple senders can transfer to Bob without further interaction by Bob.
There is a long list of issues here but tornado is just a program. The users of that program can use it for good or bad. They sanctioned the creators and Tornado is still chugging along. It’s equivalent to banning cryptography because money launderers encrypt their messages.
Here is a good summary of the argument against Treasury by Coin Center
https://www.coincenter.org/coin-center-is-suing-ofac-over-it...
You'll note that all kinds of entities, including full banks, are on the OFAC list[1]. This doesn't amount to a blanket ban on banking, and "it's just a bank, there are others" is not an argument that anyone finds convincing.
even Treasury’s own regulations and past executive orders limit the applicability of sanction controls to transactions with persons, entities, or their property. The Tornado Cash sanction was made without statutory and also without regulatory authority. It was made contrary to law.
TL;DR: The Treasury Department doesn't care that Tornado Cash is "just" a computer program, because a computer program is an instrument made and operated by human beings. Even an autonomous program does not escape this, for the same reason that you can't escape a murder charge by throwing a bomb into the air and claiming gravity as a defense.
[1]: https://blog.yossarian.net/2022/09/14/Tornado-Cash-and-bulle...
The government is not allowed to put a camera in my house and watch me 24/7. Sure, I might be committing crimes inside my house. But unless the government can convince a judge that they suspect me of committing crimes that justify such a camera, they cannot install said camera.
Similarly, merely using a technique to obfuscate the origin of my own money is not enough to claim I am a criminal. I can do similar with gold coins and paper cash, and in high dollar amounts.
Eventually I’ll want to use my financial assets to purchase something, and at that point the receiver should ask me where I got my money (if legally required to) and with Tornado Cash I can fully explain the origin of my legal funds.
Acting like Tornado itself is enabling crime is absurd.
The link is explained in the post: in both instances, a human is the prime mover. No court in the world draws a distinction between "Joe kills Bob" and "Joe builds a Bob-killing robot that kills Bob." Similarly, no court in the world is likely to draw a distinction between "North Korea launders money" and "North Korea uses an autonomous program to launder money." It simply isn't relevant.
> Similarly, merely using a technique to obfuscate the origin of my own money is not enough to claim I am a criminal. I can do similar with gold coins and paper cash, and in high dollar amounts.
To be clear: if attempt to obfuscate your cash transactions by structuring them beneath the limits that trigger CTR reporting, you're committing a crime. You can have reasonable opinions about whether that ought to be a crime, but it is absolutely not legal in the current regulatory scheme to intentionally avoid your reporting requirements.
> Acting like Tornado itself is enabling crime is absurd.
We have a precise, material example of Tornado enabling a specific crime. That crime is the reason it's on the OFAC list, and it's stated in clear, precise language on the Treasury's site. Again: you can claim that Tornado is an instrument, and anything can be used to commit crime, but it is a matter of fact that Tornado was both used to commit crimes and made committing those crimes easier than they otherwise would have been (by sidestepping financial regulatory frameworks).
I believe the law requires presumption of innocence. We shall see what the judge says. I think your arguments are unconvincing and actually, when analyzed, see them as dangerous and given to statist authoritarian tendencies.
I don’t even know what your comment adds to the discussion, it is very boring and also uninteresting and perhaps you should exit this thread before you degrade it further.
Furthermore once the software is no longer gray, it could be embedded via API in many other entities to enable privacy, just as encryption was once taboo and now is everywhere. It’s only the gray nature of this privacy solution that prevents its normalization.
In this curious land of the free, government can take criminal proceeds and clean and resell it while also claiming the freedom-taxpayers may not express themselves with others in computer code.
I expect Tornado Cash will be found to have the same protections as PGP in the 90s.
"Running a computer program" is too vague, and legality of it depends on the context.
[0] since everything on this Blockchain is public, you can easily see proceeds of cybercrime coming into tornado. It's not really a point of contention.
Even if you 100% knew that all of the money was legal mixing is money transmission according to the government which means you need to register in every state you operate, register with the federal government, and have a compliance program, or you will get up to 5 years in prison. Hawaladars/various ethnic equivalents especially post 9/11 have learned the rules on money transmission the hard way, even when they literally "know their customers" in a much more real way than banks do. Here's an example where I'm from https://apnews.com/article/yemen-us-news-ap-top-news-mi-stat... - fortunately these guys were spared prison though.
There is also the issue of determining how it is a Foreign Asset to begin with. Is it based on the developer they identified? They have to prove that it was not deployed by an American which probably cannot be proven by the nodes (maybe records of an API could do it, but not when running your own nodes)
Tornado Cash autonomous contracts cannot. They need to establish proof of who or what organization deployed it. I believe they skipped this step for incompetence or for needing it clarified in court
The problem is that once Bob actually spends something from this address, everyone knows that Bob controls the address. Because if Alice can calculate an address for Bob, so can anyone else.
If appropriated is to harsh, how about integrated instead?
Zcash uses zksnarks, which have advanced considerably since Zcash launched. Ethereum's zkrollups use more recent types of zksnarks.
Stealth addresses "using elliptic curve cryptography were originally introduced in the context of Bitcoin by Peter Todd in 2014," according to Vitalik's post.