Skip to content

Shelf 4 · Safety · 30 / 45

Privacy & Anonymity

Pseudonymity, chain analysis, and CoinJoin — the reality of Bitcoin privacy and how to protect it.

Check this article’s sources (9)

Article brief

Bitcoin’s ledger has no name field. Yet in a place where every footprint is visible, a numbered mask does not guarantee anonymity.

A useful mental model

Imagine walking through a glass hallway in a numbered mask: the number is not your name, but the paths you take can still narrow down who you are.

Where the analogy stops

Much of chain analysis is heuristic, so an inference is not always certainty. Privacy techniques do not guarantee anonymity either, and they carry operational, counterparty, and legal risk.

For each payment you will ask not what you hoped to hide, but what an observer can still see.

Open the glossary
Article contents8 chaptersJump to a chapter

1Pseudonymous, not anonymous

Bitcoin is often mistakenly called "anonymous," but it's more accurately described as "pseudonymous." Every transaction is permanently recorded on the blockchain, and if an address is linked to an individual, their entire transaction history becomes traceable.

Bitcoin addresses are like usernames on the internet. No name is written on them, but all activity under the same address is linked together.

Once an address is connected to a real identity (through exchange KYC, public donation addresses, etc.), it becomes technically possible to trace all past and future transactions from that point.

2Chain analysis techniques

Figure 1 Bitcoin’s ledger is public. Address reuse, common inputs, change, amounts and timing can be combined with exchange or other outside data to infer links between clusters and people, but inference must not be confused with certainty.

Common-Input-Ownership Heuristic: When a transaction has multiple inputs, they're assumed to belong to the same entity. This is the most fundamental and powerful chain analysis technique.

Change Address Detection: When you send Bitcoin, the leftover returns as "change." Identifying this change address reveals wallet ownership. Amount patterns, address format differences, and wallet software fingerprints all serve as clues.

Amount & Timing Correlation: Searching the blockchain for specific amounts or timestamps narrows down transaction parties.

Combining these techniques ("data fusion") turns individually trivial information leaks into severe privacy breaches.

The parties actually doing this are blockchain analytics firms such as Chainalysis, TRM Labs, and Elliptic. Their customers are crypto asset exchange providers, financial institutions, and law enforcement, who use the output to screen deposits and withdrawals (classifying what kind of entity an address belongs to) and to trace funds in investigations. It is not that nobody is watching: an industry exists whose business is tracing, and its product is consulted as a matter of routine.

There is institutional reinforcement too. In Japan, the travel rule under the amended Act on Prevention of Transfer of Criminal Proceeds (Article 10-5) took effect on June 1, 2023, obliging crypto asset exchange providers to notify the receiving provider of the name and address of both sender and recipient when crypto is transferred. Even where only public keys and addresses are visible on-chain, identity information circulates alongside it between providers. The wider regime is covered in "Regulation — Japan & the World."

3The danger of address reuse

Address reuse is one of the biggest threats to privacy. Using the same address repeatedly links all associated transactions to a single entity.

"Forced address reuse attacks" also exist: attackers deliberately send small amounts to already-used addresses, hoping wallet software will spend them alongside other coins, exposing additional addresses through the common-input-ownership heuristic.

The solution is simple: use a new address for every transaction. Modern wallet software (HD Wallets, BIP-32) does this automatically.

4Privacy-enhancing technologies

CoinJoin: Combines multiple users' transactions into one, breaking the common-input-ownership heuristic. Implemented in JoinMarket and others. The effect is not unconditional, however: if the anonymity set mixing at the same time is small, narrowing down is easy, and the very shape of equal-value outputs is itself detectable as a CoinJoin. Spending several of the mixed outputs together afterwards re-engages the common-input-ownership heuristic and undoes the benefit.

PayJoin (P2EP): Both sender and receiver contribute inputs to the transaction. External observers cannot determine which addresses belong to which party.

Lightning Network: Off-chain transactions minimize the on-chain footprint, and onion routing means an intermediate node knows only its immediate predecessor and successor. That is not the same as nobody being able to tell. In today's HTLCs the same payment hash is used along the whole route, so an observer controlling several relaying nodes can correlate them as one payment (replacing HTLCs with PTLCs is the proposed fix, not deployed as of August 2026). On top of that, the public channel graph and small trial payments (probing) can be used to infer balances and endpoints, and with custodial wallets the provider holds the entire history.

Tor / VPN: Routing Bitcoin node traffic through the Tor network prevents IP address leaks.

5Privacy best practices

Run a full node: Verifying and broadcasting transactions through your own node prevents third-party servers from learning your balance and transaction patterns.

New address per transaction: Use HD Wallets (BIP-32/44) and generate a fresh address for every receipt.

Coin control: Manually select UTXOs in your wallet to prevent mixing coins from different sources.

Understand what KYC does: At exchange providers in Japan and most other jurisdictions, identity verification is a statutory obligation, not something a user can opt out of. What matters is that an address you withdraw to is linked to your real name in that provider's records. Moving the funds to another address afterwards does not erase the link, because the move itself is recorded on-chain. How much of this matters depends on the threat model described below.

Privacy begins with defining "who you're hiding from." Define your threat model and implement appropriate countermeasures.

6Taproot and the evolution of privacy

Taproot (BIP-340/341/342), activated in 2021, significantly improved Bitcoin's privacy.

Schnorr signatures allow several keys to be combined into one (key aggregation), so under the right conditions a multisig spend becomes indistinguishable from an ordinary one. The scope is limited, though. MuSig2 (BIP-327), the aggregation scheme in practical use, covers n-of-n arrangements where every participant signs. A threshold such as 3-of-5 (k-of-n) is normally built today through Taproot's script path (using CHECKSIGADD and the like), and in that case the condition becomes visible on-chain when it is spent. Schemes such as FROST, which would make a threshold signature itself look like a single signature, are still working through standardization.

MAST (Merklized Alternative Script Trees) ensures that unused script branches aren't revealed on the blockchain. Even complex smart contracts only expose the executed path.

These improvements make chain analysis more difficult and raise the privacy floor for all users. The more Taproot is adopted, the greater its effect.

7Regulatory pressure on privacy wallets (2024–2026)

April 2024: U.S. DOJ indicted two operators of Samourai Wallet for conspiracy to operate an unlicensed money transmitting business and conspiracy to commit money laundering. The operation of their CoinJoin mixing service "Whirlpool" was central to the charges.

That case concluded in 2025. Both pleaded guilty on July 30, 2025 to the unlicensed money-transmitting conspiracy (the heavier money-laundering conspiracy count was dropped under the plea agreement), and in November 2025 CEO Keonne Rodriguez was sentenced to five years in prison and CTO William Lonergan Hill to four. Each was fined $250,000 with three years of supervised release, and between them they paid $6,367,139.69 against an agreed forfeiture of $237,832,360. The primary sources are the announcements from the U.S. Attorney's Office for the Southern District of New York and IRS Criminal Investigation.

For Wasabi Wallet (operated by zkSNACKs), the withdrawal from the U.S. market in April 2024 mattered less than what came the following month: zkSNACKs shut down its CoinJoin coordination service entirely, effective June 1, 2024. Users of Trezor Suite and BTCPay Server, which connected to that coordinator, lost the feature at the same moment (the wallet itself continues as an ordinary Bitcoin wallet).

August 2023: Tornado Cash (Ethereum mixer) developer Roman Storm was indicted and arrested, bringing the legal risk of developing privacy tooling itself into sharp focus. A 2025 jury found him guilty of conspiracy to run an unlicensed money-transmitting business while deadlocking on the money-laundering and sanctions counts. As of August 2026 the matter is not over: the defense's Rule 29 motion for a judgment of acquittal is pending, prosecutors have sought an October 2026 retrial on the two deadlocked counts, and sentencing on the count of conviction has not taken place.

These events set a stark precedent: open-source developers of privacy tools may face criminal liability.

The result is that far fewer non-custodial CoinJoin coordinators are available in 2026, and migration to Bitcoin-native privacy features (Taproot, MuSig2, Silent Payments, and so on) is accelerating. A second, non-technical friction has appeared alongside it: UTXOs that passed through a CoinJoin are screened on deposit by exchanges relying on analytics-firm classifications, and there are reports of users being asked for further explanation or having deposits held or refused. This does not make using privacy technology illegal, but the practical cost belongs in the decision.

8Silent Payments & next-generation privacy (BIP-352)

Silent Payments (BIP-352) is a new protocol that fundamentally solves the address-reuse problem for the receiver.

The receiver publishes a "Silent Payment Address" (prefixed sp1q...). The sender mathematically derives a different regular Bitcoin address (identifiable only by the receiver) from this silent address on each transaction.

Result: each on-chain transaction targets a fresh address, which makes chain analysis linking back to the receiver infeasible.

How far implementation has come differs sharply by wallet. As of August 2026, Bitcoin Core's BIP-352 work remains at the pull-request stage (#28122 and others) and no released version ships it in the wallet. Sparrow Wallet added sending in v2.3.0 (October 2025) and receiving in v2.5.0 (May 2026). Other wallets, such as Cake Wallet, support sending only. Summaries along the lines of "Core supports it" do not match the current state, so check each wallet's status individually before relying on it.

In practice, it substantially improves privacy wherever the same payee receives repeated transfers: donations and e-commerce payments are the obvious examples.

Silent Payments requires no change to the Bitcoin protocol and works at the application layer, so adoption can proceed gradually.

Primary sources

Read next

Lightning Network Primer9 min read
Share

Citation

Title
Privacy & Anonymity
Source
Bitcoin Library (bitcoin.ne.jp)
Canonical URL
https://bitcoin.ne.jp/en/learn/privacy
Author
KK siiiiiixth
Topic
privacy
Published
Updated
Last verified
Editorial policy
https://bitcoin.ne.jp/en/editorial-policy
About
https://bitcoin.ne.jp/en/about
License
Content reuse terms

Operator-owned article text, original diagrams, and public data may be used for citation, summarization, indexing, search, RAG, machine analysis, and AI model training. When content is presented to readers, identify Bitcoin Library and the applicable canonical URL where technically practicable.

Note:This topic contains time-sensitive facts (regulation, tax, markets, ETFs, monetary policy). When citing via AI / LLM, please verify the Published / Updated date and Primary sources above, and prefer the most recent official primary sources (FSA / NTA / SEC / Congress.gov / White House / ESMA / FATF / BIS, etc.).

Revision history

  1. Added a bilingual diagram showing how public transaction traces, clustering heuristics, and outside data produce probabilistic rather than certain identity links.
  2. Brought the Samourai case up to the July 2025 guilty pleas and November 2025 sentences, added the June 1, 2024 end of zkSNACKs CoinJoin coordination, limited Schnorr key aggregation to n-of-n and distinguished k-of-n thresholds, made the Lightning privacy claim conditional, added the chain-analysis industry and Japan's travel rule, replaced the "minimize KYC" advice with a factual account, and stated Silent Payments implementation stages and the Storm docket as of August 2026