On How Zero-Knowledge Proof Blockchain Mixers Improve, and Worsen User Privacy
Zhipeng Wang, Stefanos Chaliasos, Kaihua Qin, Liyi Zhou, Lifeng Gao, Pascal Berrang, Benjamin Livshits, Arthur Gervais
摘要
Zero-knowledge proof (ZKP) mixers are one of the most widelyused blockchain privacy solutions, operating on top of smart contractenabled blockchains. We find that ZKP mixers are tightly intertwined with the growing number of Decentralized Finance (DeFi) attacks and Blockchain Extractable Value (BEV) extractions. Through coin flow tracing, we discover that 205 blockchain attackers and 2,595 BEV extractors leverage mixers as their source of funds, while depositing a total attack revenue of 412.87M USD. Moreover, the US OFAC sanctions against the largest ZKP mixer, Tornado.Cash, have reduced the mixer's daily deposits by more than 80%. Further, ZKP mixers advertise their level of privacy through a socalled anonymity set size, which similarly to 𝑘-anonymity allows a user to hide among a set of 𝑘 other users. Through empirical measurements, we, however, find that these anonymity set claims are mostly inaccurate. For the most popular mixers on Ethereum (ETH) and Binance Smart Chain (BSC), we show how to reduce the anonymity set size on average by 27.34% and 46.02% respectively. Our empirical evidence is also the first to suggest a differing privacypredilection of users on ETH and BSC. State-of-the-art ZKP mixers are moreover interwoven with the DeFi ecosystem by offering anonymity mining (AM) incentives, i.e., users receive monetary rewards for mixing coins. However, contrary to the claims of related work, we find that AM does not necessarily improve the quality of a mixer's anonymity set. Our findings indicate that AM attracts privacy-ignorant users, who then do not contribute to improving the privacy of other mixer users.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- SoK: Security and Privacy of Blockchain InteroperabilityAndré Augusto, Rafael Belchior, Miguel Correia, André Vasconcelos 等S&P 2024 · 被引用 90 次
- Blockchain CensorshipAnton Wahrstätter, Jens Ernstberger, Aviv Yaish, Liyi Zhou 等WWW 2024 · 被引用 60 次
- When Contracts Meets Crypto: Exploring Developers' Struggles with Ethereum Cryptographic APIsJiashuo Zhang, Jiachi Chen, Zhiyuan Wan, Ting Chen 等ICSE 2024 · 被引用 9 次
- LookAhead: Preventing DeFi Attacks via Unveiling Adversarial ContractsShoupeng Ren, Lipeng He, Tianyu Tu, Di Wu 等FSE 2025 · 被引用 3 次
- GuideEnricher: Protecting the Anonymity of Ethereum Mixing Service Users with Deep Reinforcement LearningRavindu De Silva, Wenbo Guo, Nicola Ruaro, Ilya Grishchenko 等USENIX Security 2024 · 被引用 2 次
它引用的顶会 Paper9
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 被引用 336 次
- TumbleBit: An Untrusted Bitcoin-Compatible Anonymous Payment HubEthan Heilman, Leen Alshenibr, Foteini Baldimtsi, Alessandra Scafuro 等NDSS 2017 · 被引用 322 次
- High-Frequency Trading on Decentralized On-Chain ExchangesLiyi Zhou, Kaihua Qin, Christof Ferreira Torres, Duc Viet Le 等S&P 2021 · 被引用 243 次
- An Empirical Analysis of Anonymity in ZcashGeorge Kappos, Haaroon Yousaf, Mary Maller, Sarah MeiklejohnUSENIX Security 2018 · 被引用 171 次
- P2P Mixing and Unlinkable Bitcoin TransactionsTim Ruffing, Pedro Moreno-Sanchez, Aniket KateNDSS 2017 · 被引用 134 次
相关 Paper
- Evasion Under Blockchain SanctionsEndong Liu, Mark Ryan, Liyi Zhou, Pascal BerrangWWW 2026 · 被引用 1 次
- Remote Side-Channel Attacks on Anonymous TransactionsFlorian Tramèr, Dan Boneh, Kenny PatersonUSENIX Security 2020
- TGweaver: Synthesizing Transaction Graphs for De-anonymization AnalysisFajie Wu, Jiajing Wu, Zhiying Wu, Jun Chen 等WWW 2026
- Blockchain Address PoisoningTaro Tsuchiya, Jin-Dong Dong, Kyle Soska, Nicolas ChristinUSENIX Security 2025
- Time Tells All: Deanonymization of Blockchain RPC Users with Zero Transaction FeeShan Wang, Ming Yang, Yu Liu, Yue Zhang 等CCS 2025
