On how zero-knowledge proof blockchain mixers improve, and worsen user privacy

Zhipeng Wang, Stefanos Chaliasos, Kaihua Qin, Liyi Zhou, Lifeng Gao, Pascal Berrang, Ben Livshits, Arthur Gervais

Research output: Chapter in Book/Report/Conference proceedingConference contribution

3 Downloads (Pure)

Abstract

One of the most prominent and widely-used blockchain privacy solutions are zero-knowledge proof (ZKP) mixers operating on top of smart contract-enabled blockchains. ZKP mixers typically advertise their level of privacy through a so-called anonymity set size, similar to k-anonymity, where a user hides among a set of k other users.

In reality, however, these anonymity set claims are mostly inaccurate, as we find through empirical measurements of the currently most active ZKP mixers. We propose five heuristics that, in combination, can increase the probability that an adversary links a withdrawer to the correct depositor on average by 51.94% (108.63%) on the most popular Ethereum (ETH) and Binance Smart Chain (BSC) mixer, respectively. Our empirical evidence is hence also the first to suggest a differing privacy-predilection of users on ETH and BSC. We further identify 105 Decentralized Finance (DeFi) attackers leveraging ZKP mixers as the initial funds and to deposit attack revenue (e.g., from phishing scams, hacking centralized exchanges, and blockchain project attacks).

State-of-the-art mixers are moreover tightly intertwined with the growing DeFi ecosystem by offering "anonymity mining'' (AM) incentives, i.e., mixer users receive monetary rewards for mixing coins. However, contrary to the claims of related work, we find that AM does not always contribute to improving the quality of an anonymity set size of a mixer, because AM tends to attract privacy-ignorant users naively reusing addresses.
Original languageEnglish
Title of host publicationWWW '23
Subtitle of host publicationProceedings of the ACM Web Conference 2023
PublisherAssociation for Computing Machinery (ACM)
Pages2022-2032
Number of pages11
DOIs
Publication statusPublished - 30 Apr 2023
EventThe Web Conference 2023 - AT&T Hotel and Conference Center at The University of Texas at Austin, Austin, United States
Duration: 30 Apr 20234 May 2023

Conference

ConferenceThe Web Conference 2023
Abbreviated titleWWW'23
Country/TerritoryUnited States
CityAustin
Period30/04/234/05/23

Keywords

  • cs.CR

Fingerprint

Dive into the research topics of 'On how zero-knowledge proof blockchain mixers improve, and worsen user privacy'. Together they form a unique fingerprint.

Cite this