Time Tells All: Deanonymization of Blockchain RPC Users with Zero Transaction Fee
Shan Wang, Ming Yang, Yu Liu, Yue Zhang, Shuaiqing Zhang, Zhen Ling, Jiannong Cao, Xinwen Fu
Abstract
Remote Procedure Call (RPC) services have become a primary gateway for users to access public blockchains. While they offer significant convenience, RPC services also introduce critical privacy challenges that remain insufficiently examined. Existing deanonymization attacks either do not apply to blockchain RPC users or incur costs like transaction fees assuming an active network eavesdropper. In this paper, we propose a novel deanonymization attack that can link an IP address of a RPC user to this user's blockchain pseudonym. Our analysis reveals a temporal correlation between the timestamps of transaction confirmations recorded on the public ledger and those of TCP packets sent by the victim when querying transaction status. We assume a strong passive adversary with access to network infrastructure, capable of monitoring traffic at network border routers or Internet exchange points. By monitoring network traffic and analyzing public ledgers, the attacker can link the IP address of the TCP packet to the pseudonym of the transaction initiator by exploiting the temporal correlation. This deanonymization attack incurs zero transaction fee. We mathematically model and analyze the attack method, perform large-scale measurements of blockchain ledgers, and conduct real-world attacks to validate the attack. Our attack achieves a high success rate of over 95% against normal RPC users on various blockchain networks, including Ethereum, Bitcoin and Solana.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3678ba1b-3a19-4fdc-a262-eb6f34abd037Builds on12
- A Stealthier Partitioning Attack against Bitcoin Peer-to-Peer NetworkMuoi Tran, Inho Choi, Gi Jun Moon, Anh V. Vu et al.S&P 2020 · 126 citations
- VRust: Automated Vulnerability Detection for Solana Smart ContractsSiwei Cui, Gang Zhao, Yifei Gao, Tien Tavu et al.CCS 2022 · 31 citations
- AppSniffer: Towards Robust Mobile App Fingerprinting Against VPNSanghak Oh, Minwook Lee, Hyunwoo Lee, Elisa Bertino et al.WWW 2023 · 26 citations
- DETER: Denial of Ethereum Txpool sERvicesKai Li, Yibo Wang, Yuzhe TangCCS 2021 · 26 citations
- Fuzz on the Beach: Fuzzing Solana Smart ContractsSven Smolka, Jens-Rene Giesen, Pascal Winkler, Oussama Draissi et al.CCS 2023 · 22 citations
Related papers
- Deanonymizing Ethereum Users behind Third-Party RPC ServicesShan Wang, Ming Yang, Wenxuan Dai, Yu Liu et al.INFOCOM 2024 · 4 citations
- As Strong As Its Weakest Link: How to Break Blockchain DApps at RPC ServiceKai Li, Jiaqi Chen, Xianghong Liu, Yuzhe Richard Tang et al.NDSS 2021
- Deanonymizing Ethereum Validators: The P2P Network Has a Privacy IssueLioba Heimbach, Yann Vonlanthen, Juan Villacis, Lucianna Kiffer et al.USENIX Security 2025
- Is My RPC Response Reliable? Detecting RPC Bugs in Blockchain Client under ContextZhijie Zhong, Yuhong Nan, Mingxi Ye, Qing Xue et al.ICSE 2026
- On How Zero-Knowledge Proof Blockchain Mixers Improve, and Worsen User PrivacyZhipeng Wang, Stefanos Chaliasos, Kaihua Qin, Liyi Zhou et al.WWW 2023 · 69 citations
