Do you knock on your door and demand your private keys? How can they do that if you've broken no laws? How do they even know you have them in the first place?
Do you knock on your door and demand your private keys? How can they do that if you've broken no laws? How do they even know you have them in the first place?
Pretty much. If you're storing your bitcoin with something like Coinbase, they could also knock on Coinbase's door.
> How can they do that if you've broken no laws?
Buying stolen artwork is not a crime if you don't know it's stolen. But the government can still seize the stolen artwork and return it to its original rightful owner. The only recourse you have is to go after the person who sold you the stolen artwork -- which may not be very feasible for you to do in the case of semi-anonymous bitcoin transactions.
> How do they even know you have them in the first place?
If you use a third-party service like Coinbase, they could just ask them. If you're using your own wallet, they'd have to rely on good-old fashioned deduction -- e.g. if the previous holder of the coins has an accounting log showing payment to you in bitcoins, that's probably enough to infer that you have or did have possession. It might be enough to shift the burden of proof so that you have to show that you don't have possession of the bitcoins.
If the stolen property is BTC rather than art, there would be no reason you couldn't follow a perpetual chain of transactions after it.
Curiously, that could be viewed as a very big strength for BTC rather than a weakness. I think a lot of trouble is saved by calling BTC a programmable currency rather than an anonymous one.
How exactly do you prove you don't possess something?
For example, if someone says "I paid tlrobinson 2 bitcoins for mowing my lawn on Sunday," you could produce evidence that you were on a business trip on Sunday and therefore couldn't be the same tlrobinson referenced in the previous statement. Or argue that the person making that statement is a liar. Or point out that 2 bitcoins is an absurd amount to pay for mowing a lawn. Etc.
So how would this influence your remaining Bitcoins? If you send 0.1 Bitcoins to someone else: Would you sell the stolen Bitcoins first? Would you sell the clean Bitcoins first? Are all of your coins tainted by a given percentage?
(Yes, I know that just receiving those coins would create a separate input that you can ignore in order to avoid tainting your coins. But at some point clean and flagged input will be merged together into a single one.)
For some reason I now need to refund the buyer. Do I now first need to transfer all but 0.1 coins to somewhere else, so that I can send the remaining 0.1 coins back?
You make it sound like this is a burden. It seems easy to me, as long as you track taint per-output rather than per address. Just pretend people followed best practices and used a unique address for every output.
So let's take eterm's suggestion that clean coins always come out first. So all we need to do is build a transaction with at least .1 tainted coins, put the non-refund coins as the first output, and put the .1 tainted coins as the second output. First output is an address we control, second output goes back to the person we're refunding.
That's assuming you already mixed up your coins and can't just send back the exact same transaction they sent you in the first place.
Or forfeit it to the feds, at which point they can mark them untainted before they auction them off.
Related: I've met several people who are planning to use bitcoins to avoid paying taxes. I'll leave it as an exercise for the reader why that could be a very bad idea.
Also, it would be inadvisable for the staff of such exchanges to travel to (or transit through) the United States. http://en.wikipedia.org/wiki/David_Carruthers#Arrest_during_...
The reason why those P2P-style exchanges aren't common in the United States is because it's hard to directly transfer money between two people. With SEPA transactions in Europe you can directly transfer money to any recipient, usually for free (or at a very low cost).
[1] Instead, they can sue you locally, even if they crime happened in another country. However, this lawsuit will be according to local laws. So if the crime is only illegal in the other country they can't sue you.
Can you elaborate on which countries do you have in mind for "comply with the local laws, which are often much less strict in terms of AML provisions" ?
For extradition you mention Europe, but the EU AML directive is already comprehensive enough to make illegal most suggested bitcoin-for-laundering use cases; and it can be expected that if there are major loopholes found, then (continuing with their existing AML policy) EU legislation will be quickly adapted to close them.
Also the US is not the world power anymore. They have no authority to 'flag' any currency.