On the Anonymity of Peer-To-Peer Network Anonymity Schemes Used by Cryptocurrencies
Piyush Kumar Sharma, Devashish Gosain, Claudia Díaz
Abstract
Cryptocurrency systems can be subject to deanonimization attacks by exploiting the network-level communication on their peer-to-peer network. Adversaries who control a set of colluding node(s) within the peer-to-peer network can observe transactions being exchanged and infer the parties involved. Thus, various network anonymity schemes have been proposed to mitigate this problem, with some solutions providing theoretical anonymity guarantees. In this work, we model such peer-to-peer network anonymity solutions and evaluate their anonymity guarantees. To do so, we propose a novel framework that uses Bayesian inference to obtain the probability distributions linking transactions to their possible originators. We characterize transaction anonymity with those distributions, using entropy as metric of adversarial uncertainty on the originator's identity. In particular, we model Dandelion, Dandelion++ and Lightning Network. We study different configurations and demonstrate that none of them offers acceptable anonymity to their users. For instance, our analysis reveals that in the widely deployed Lightning Network, with 1% strategically chosen colluding nodes the adversary can uniquely determine the originator for about 50% of the total transactions in the network. In Dandelion, an adversary that controls 15% of the nodes has on average uncertainty among only 8 possible originators. Moreover, we observe that due to the way Dandelion and Dandelion++ are designed, increasing the network size does not correspond to an increase in the anonymity set of potential originators. Alarmingly, our longitudinal analysis of Lightning Network reveals rather an inverse trend -- with the growth of the network the overall anonymity decreases.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bbd44d32-1760-4c56-9cb0-be2b5910b59fCited by top-tier papers2
- Payout Races and Congested Channels: A Formal Analysis of Security in the Lightning NetworkBen Weintraub, Satwik Prabhu Kumble, Cristina Nita-Rotaru, Stefanie RoosCCS 2024 · 5 citations
- Eclipse Attacks on Monero's Peer-to-Peer NetworkRuisheng Shi, Zhiyuan Peng, Lina Lan, Yulian Ge et al.NDSS 2025
Builds on4
- Concurrency and Privacy with Payment-Channel NetworksGiulio Malavolta, Pedro Moreno-Sanchez, Aniket Kate, Matteo Maffei et al.CCS 2017 · 307 citations
- Anonymous Multi-Hop Locks for Blockchain Scalability and InteroperabilityGiulio Malavolta, Pedro Moreno-Sanchez, Clara Schneidewind, Aniket Kate et al.NDSS 2019 · 305 citations
- Bolt: Anonymous Payment Channels for Decentralized CurrenciesMatthew Green, Ian MiersCCS 2017 · 281 citations
- Anonymity Trilemma: Strong Anonymity, Low Bandwidth Overhead, Low Latency - Choose TwoDebajyoti Das, Sebastian Meiser, Esfandiar Mohammadi, Aniket KateS&P 2018 · 99 citations
Related papers
- P2P Mixing and Unlinkable Bitcoin TransactionsTim Ruffing, Pedro Moreno-Sanchez, Aniket KateNDSS 2017 · 134 citations
- Identifying and Characterizing Sybils in the Tor NetworkPhilipp Winter, Roya Ensafi, Karsten Loesing, Nick FeamsterUSENIX Security 2016 · 53 citations
- Breaking and Fixing Virtual Channels: Domino Attack and DonnerLukas Aumayr, Pedro Moreno-Sanchez, Aniket Kate, Matteo MaffeiNDSS 2023
- Deanonymizing Ethereum Validators: The P2P Network Has a Privacy IssueLioba Heimbach, Yann Vonlanthen, Juan Villacis, Lucianna Kiffer et al.USENIX Security 2025
- Blitz: Secure Multi-Hop Payments Without Two-Phase CommitsLukas Aumayr, Pedro Moreno-Sanchez, Aniket Kate, Matteo MaffeiUSENIX Security 2021 · 63 citations
