The Anonymity Gap: Understanding Real Privacy in Shielded UTXO-based Protocols for DeFi
This paper introduces a unified, non-heuristic analysis framework to quantify real-world privacy in shielded UTXO-based DeFi protocols, revealing through an evaluation of Railgun and Hinkal deployments that public token constraints and historical state transitions significantly reduce anonymity set sizes, often leaving many transactions with minimal or no privacy.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
In the digital world of finance, a paradox has long existed: to use a public ledger that records every transaction, users must find a way to hide their movements. For years, the primary tool for this was the "mixer," a digital service that pooled funds from many people together, shuffled them, and let them withdraw in a way that made it difficult to tell who put in what. However, a new generation of privacy tools has emerged that works differently. Instead of just mixing deposits and withdrawals, these systems allow money to move, split, and merge while staying hidden inside a secure, private state. Think of it not as a single room where everyone gets mixed up, but as a vast, invisible network of tunnels where funds can travel, change hands, and be recombined before finally emerging back into the public view. The question for researchers and users alike is whether this new, more complex system actually offers better privacy, or if the very rules that make it work also leave behind a trail of clues that can be followed.
A team of researchers from institutions including University College London and Nanyang Technological University set out to answer this question by examining the real-world history of these advanced privacy protocols. They focused on two major systems, Railgun and Hinkal, which operate across several different blockchain networks. Unlike previous studies that relied on guessing user behaviors or looking for patterns in how people spend money, this team built a rigorous method that looked only at the public rules and the visible data on the blockchain. They wanted to know: if you take a transaction where money leaves the hidden state and re-enters the public world, how many possible starting points could that money have come from? By tracing the path backward through the system's history without making any assumptions about who the users are, they could measure exactly how much the system's own design shrinks the circle of anonymity.
The researchers constructed a detailed map of how these systems work, breaking the process down into three layers. The first layer involves the notes, or digital tokens, that represent the hidden money. The second layer involves the cryptographic proofs that verify transactions without revealing the details. The third layer is the transaction itself, where the money finally becomes visible again. They developed a method to trace the history of a specific withdrawal backward, applying a series of filters based on the public information available. These filters include checking which digital tree the money belongs to, verifying the time the transaction occurred, ensuring the type of asset matches, and confirming that the amounts add up correctly. By applying these filters one by one, they could eliminate impossible origins and narrow down the list of potential starting addresses.
When they applied this method to the complete on-chain history of four Railgun deployments and five Hinkal pools, the results revealed a significant gap between the theoretical privacy of the system and the reality of what can be deduced. On average, the number of possible starting addresses for a transaction dropped by between 40% and 59% compared to the total number of addresses that were theoretically possible at the time. In some cases, the reduction was even more dramatic. The study analyzed 186,356 unshielding spend transactions where money was withdrawn from the hidden state. Among these, 3,679 transactions ended up with an anonymity set of ten or fewer possible addresses, including 1,228 singletons. This means that for a significant number of users, the public rules of the protocol alone were enough to narrow the possible origins down to a single address, without needing any outside information or behavioral guessing.
The study identified specific reasons why this narrowing happens. One major factor is the type of asset being used. When a transaction involves a specific token, the system's rules often eliminate all other tokens from the list of possibilities, drastically shrinking the pool of candidates. Another factor is the structure of the transaction itself. If a transaction releases money to the public while also creating new hidden notes, the mathematical constraints required to balance the equation can rule out many potential histories. The researchers also found that the history of the pool matters; in systems where the pool is split into different "trees" or sections, a transaction in one section cannot draw from the history of another, effectively cutting the available pool of anonymity in half. Furthermore, the depth of the transaction's history plays a role; the further back the money traveled through the hidden network, the more potential starting points it accumulates, which can sometimes weaken the privacy protection if the path is too complex.
The researchers emphasized that their findings are based strictly on the public constraints of the protocols, not on any attempt to identify specific individuals or link addresses to real-world identities. They did not use heuristics or guesswork about user behavior. Instead, they treated the system as a mathematical puzzle where the only clues are the rules written in the code and the data recorded on the public ledger. This approach provides a baseline for understanding the inherent privacy limits of these systems. The study shows that while these protocols offer a powerful way to keep financial movements private, the very mechanisms that allow for complex, hidden transfers also create a set of public constraints that can significantly reduce the number of possible origins for a transaction.
For users, the implications are clear: the privacy of a transaction depends heavily on the specific asset being used, the timing of the withdrawal, and the structure of the transaction itself. Using a common asset in a large, active pool might offer better protection than using a rare asset in a smaller pool. For the designers of these systems, the results suggest that preserving the continuity of the hidden state across upgrades and avoiding unnecessary splits in the pool's history could help maintain stronger anonymity. The study concludes that while these shielded protocols represent a major evolution in privacy technology, they are not immune to analysis. The public nature of the blockchain means that the rules of the game are always visible, and a careful examination of those rules can reveal the true extent of the anonymity provided.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.