The Bisq DAO: On the Privacy Cost of Participation

arXiv:2007.07048 · cs.CR · Submitted 2026-08-15 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.

Tom: Next we'll be talking about the paper "The Bisq Decentralised Exchange: On the Privacy Cost of Participation".

Jane: The paper was written by Liam Hickey and Martin Harrigan from Institute of Technology, Carlow.

Tom: Stay tuned as we take you through the paper and discuss its implications.

Jane: We also have Lu with us today — senior AI researcher at Tsinghua.

Tom: We also have Meng with us today — lead engineer at a mysterious AI startup.

Jane: We also have Lalam with us today — the in-house Large Language Model.

Tom: Alright, let's get started.

Title and First Impressions: Tom: Welcome back to the arXiv channel, everyone. Today we’re looking at a paper that’s going to make a lot of people in the crypto world sit up and pay attention. It’s called “The Bisq DAO: On the Privacy Cost of Participation.”

Jane: And Tom, I have to say, the title alone is doing a lot of work here. “Privacy cost” — that’s the whole story in three words. The paper is basically saying that if you participate in this decentralized exchange’s governance system, you’re paying for it with your privacy, whether you realize it or not.

Tom: Exactly. And for anyone tuning in who hasn’t heard of Bisq, it’s a decentralized cryptocurrency exchange. No middleman, no identity checks. You trade bitcoin for other currencies directly with other people. And the DAO part — that’s the decentralized autonomous organization — is how the project manages itself. Proposals, voting, paying contributors, all of that.

Jane: Right, and the authors, Liam Hickey and Martin Harrigan from the Institute of Technology in Carlow, Ireland, they went looking at how much information leaks out when you take part in that DAO. And the answer is: a lot more than people probably think.

Tom: I love that they didn’t just theorize about it. They actually built a tool to cluster addresses on the Bitcoin blockchain and then matched those clusters to real people. We’re talking about linking pseudonyms, GitHub usernames, even real-world names to a person’s entire trading and voting history.

Jane: And that’s the part that gives me chills, honestly. Because Bisq’s whole pitch is that you don’t need to trust a centralized exchange with your identity. But the paper shows that the blockchain itself, combined with the public data the DAO generates, can be used to piece together who you are and everything you’ve done.

Tom: Yeah, and they found some pretty stark examples. They identified participants who were operating under multiple aliases, and some of those aliases were real-world names. So the anonymity that people think they have — it’s fragile.

Jane: It really is. And the paper’s not just a warning, either. They walk through exactly how they did it, which means anyone with the technical skills could replicate it. That’s the kind of research that should make people in the privacy space think hard about what they’re building.

Tom: Absolutely. And we’re going to get into the nitty-gritty of how they pulled this off in a moment, because the methodology is genuinely clever. But first, Jane, what’s your gut reaction to the title and the authors’ approach here?

Jane: My gut reaction is that this is exactly the kind of paper we need more of. It’s not abstract hand-wringing about privacy. It’s a concrete demonstration with numbers and names. And the authors clearly care about the project — they’re not trying to destroy Bisq, they’re trying to make it better.

Tom: Yeah, and that’s a great segue, because next we’re going to talk about how they actually did the analysis. The clustering heuristic they came up with is the heart of the whole thing, and it’s surprisingly simple once you see it.

The Methodology and Findings: Tom: So we’re back with “The Bisq DAO: On the Privacy Cost of Participation,” and Jane, I want to get into the meat of how they actually cracked this open.

Jane: Yes, and the key insight is something they call the “self-transfer issue.” See, when you interact with the Bisq DAO, you’re creating transactions on the Bitcoin blockchain that involve this token called BSQ. And the vast majority of those transactions — ninety-three percent of them — are what they call self-transfers.

Tom: Self-transfers. So that means the same person controls all the addresses on both sides of the transaction?

Jane: Exactly. You’re sending BSQ to yourself, essentially. It’s like moving money from your left pocket to your right pocket. And the reason it happens is that the Bisq software generates new addresses for every transaction to try to protect your privacy. But because it’s a self-transfer, all those addresses belong to the same person.

Tom: And that’s the clustering heuristic. If you see a transaction where all the inputs and outputs are controlled by the same entity, you can group all those addresses together. And once you group them, you can see the whole picture of what that person has done.

Jane: Right. And they applied this to over thirty thousand BSQ transactions and ended up with about one thousand twenty-seven address clusters. Each cluster is likely one participant. And then they took it a step further — they tagged those clusters with real identities.

Tom: How did they do that part? Because that’s where it gets really personal.

Jane: So the Bisq DAO has a public record of proposals and compensation requests. When someone submits a proposal, they attach their name or their GitHub username. And the genesis transaction — that’s the very first transaction that created all the BSQ — it was built from a spreadsheet that the community maintained before the DAO launched. That spreadsheet had people’s names and their addresses.

Tom: So they matched the spreadsheet to the genesis transaction, and then the clustering heuristic did the rest. One thing leads to another, and suddenly you know that this address cluster is this person, and you can see every trade they’ve ever made, every vote they’ve ever cast.

Jane: Exactly. And they were able to tag ninety-six distinct address clusters that way. And out of those, they found four clusters where the tags didn’t match — meaning one cluster had multiple names attached to it. At first you’d think that’s a false positive, a mistake in the clustering. But the authors argue it’s actually evidence of people operating under multiple aliases.

Tom: That’s wild. So you’ve got one person who’s been participating in the DAO under three different pseudonyms, and the clustering algorithm just lumps them all together because it’s all the same wallet.

Jane: And in some cases, those pseudonyms were real-world names. So the privacy breakdown is complete. The paper even identifies the top ten BSQ transactors, and five of them can be linked to real identities.

Tom: Lu, you’ve been listening to this — what’s your take on the methodology? Is this a novel approach or is it just applying known techniques?

Lu: It’s a really elegant application of a classic technique. Address clustering has been around for years in blockchain analysis, but the specific heuristic they used is tailored to the Bisq DAO’s transaction structure. The fact that ninety-three percent of transactions are self-transfers is a design flaw, honestly. The system was trying to create privacy by generating new addresses, but it defeated itself by making those transactions identifiable.

Tom: So the very mechanism meant to protect privacy is what exposes it.

Lu: Precisely. And the broader implication is that this isn’t just about Bisq. Any system that issues tokens on a public blockchain and has this kind of self-transfer pattern is vulnerable to the same analysis. The paper is a case study in how good intentions can backfire without careful threat modeling.

Jane: And that’s the part that keeps me up at night. Because the people who participated in this DAO were doing it to support a project they believed in. They weren’t being careless. They were following the software’s recommendations. And it still wasn’t enough.

Tom: Right. And the authors don’t just stop at identifying the problem. They actually propose some fixes, and that’s what we’re going to talk about next.

Proposed Improvements and Countermeasures: Tom: So we’re still on “The Bisq DAO: On the Privacy Cost of Participation,” and we’ve established that the clustering heuristic works because self-transfers are so easy to spot. But the authors don’t leave us hanging — they suggest ways to fight back.

Jane: Right, and the first suggestion is to introduce ambiguity. If you can make it hard to tell whether a transaction is a self-transfer or a real transfer, then the clustering heuristic starts producing false positives, which makes the whole analysis unreliable.

Tom: How would you actually do that? Because it seems like the transaction structure is pretty rigid.

Jane: So one idea is to disguise transfer transactions. Normally, a transfer transaction has one output that goes to the recipient and the rest goes back to the sender as change. But what if you created a fake trade fee transaction? A trade fee transaction burns some BSQ, so you could burn a tiny amount and send the rest to the person you’re actually paying. That way, the transaction looks like a trade fee payment, not a transfer.

Tom: That’s sneaky. But the authors point out a flaw, right?

Jane: Yeah, they do. Every trade fee transaction is linked to an actual Bisq trade on the network. So if you see a “trade fee” transaction that isn’t connected to a real trade, you can still figure out it’s a disguised transfer. The heuristic would need to be updated, but it wouldn’t be fooled forever.

Tom: So it’s a cat-and-mouse game. What’s the other suggestion?

Jane: The other one is to create “dummy” transfer transactions. After every self-transfer, you send some BSQ from the change address to a new address you control. To an outside observer, it looks like you’re sending money to someone else. This creates false negatives — the clustering algorithm splits your activity into multiple clusters instead of one.

Lu: And that’s actually the more robust approach, in my opinion. False negatives are less damaging to privacy than false positives. If an analyst thinks two clusters belong to two different people when they’re actually the same person, that’s a dead end for them. The information is fragmented.

Meng: But hold on, doesn’t that cost money? Every transaction on Bitcoin requires a fee, and you’re creating extra transactions that serve no purpose other than to confuse analysts.

Jane: Exactly, and the authors acknowledge that. They say it increases the cost for users, but it’s a trade-off. If you value your privacy, you pay a little more. They even suggest the Bisq software could include a feature to create dummy transactions automatically, so users don’t have to do it manually.

Meng: That’s interesting, but I’m wondering about the practical impact here. If Bisq implemented these changes, would it actually protect users, or would it just make the analysis slightly harder?

Lu: It would make it harder, but not impossible. The fundamental issue is that the BSQ token lives on the Bitcoin blockchain, and Bitcoin is a public ledger. You can’t hide the fact that a transaction happened. You can only obscure who’s behind it. These countermeasures raise the cost of analysis, but they don’t eliminate it.

Tom: So it’s about making privacy the default rather than something you have to opt into?

Jane: That’s the hope. And the authors are careful to say that these are just suggestions — they’re not claiming to have a perfect solution. But the fact that they’re thinking about this at all is a good sign for the project.

Meng: I’d like to see them actually test these countermeasures, though. Run a simulation, see how much they degrade the clustering accuracy. That would be the next step.

Tom: That’s a great point, and I think that’s exactly where the conversation is heading. We’ve got the problem, we’ve got the proposed fixes — now we need to see if they hold up in practice.

Conclusion: Tom: So we’ve reached the end of our discussion on “The Bisq DAO: On the Privacy Cost of Participation.” Jane, give us the final summary.

Jane: Sure. The paper shows that participating in the Bisq DAO comes with a real privacy cost. Because ninety-three percent of BSQ transactions are self-transfers, a simple clustering heuristic can group all of a person’s addresses together. And because the DAO publishes proposals, compensation requests, and other data, those clusters can be linked to real names. The authors demonstrated this by tagging ninety-six clusters and finding multiple instances of people operating under aliases.

Tom: And the implications go beyond just Bisq. This is a warning for any decentralized project that issues tokens on a public blockchain. If you don’t think carefully about how your transactions look to an outside observer, you might be exposing more than you intend.

Jane: Exactly. But the paper isn’t all doom and gloom. They propose concrete countermeasures — disguising transfers, creating dummy transactions — that could make the heuristic less effective. They’re not perfect, but they’re a starting point.

Lu: And I’d add that the broader lesson is about the tension between transparency and privacy. Blockchains are transparent by design, but that transparency can be weaponized. Projects need to think about privacy from day one, not bolt it on later.

Meng: From an engineering standpoint, I’d love to see these countermeasures actually implemented and tested. The paper lays out the theory, but the real world is messy. I hope the Bisq team takes this seriously.

Tom: Well said, Meng. And Lalam, you’ve been quiet — what’s your take on the bigger picture here?

Lalam: I think this paper is a reminder that privacy is not just a technical problem, it’s a cultural one. The people who built Bisq and participated in its DAO did so because they believed in decentralization and autonomy. But they didn’t realize how much of their personal information was leaking out. This research gives them the knowledge to make better choices, and that’s the first step toward building systems that respect user privacy as a core value, not an afterthought.

Tom: Beautifully put. So, to wrap up — “The Bisq DAO: On the Privacy Cost of Participation” is a must-read for anyone in the crypto space, and honestly, for anyone who cares about privacy in digital systems. It’s rigorous, it’s practical, and it’s a wake-up call.

Jane: And with that, we’ll say goodbye to this paper and get ready to dive into the next one. Thanks for listening, everyone.

Tom: See you next time.

Liam Hickey, Martin Harrigan

Institute of Technology, Carlow

cs.CR

Submitted: 2026-08-15

Updated: 2026-08-18

Comments: 13 pages, 1 figure

Code: https://github.com/bisq-network/compensation

License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/

Importance score: 58/100

The gist: The Bisq DAO is a core component of Bisq, a decentralized cryptocurrency exchange.

Key concepts

Bisq Decentralised Exchange
A decentralized cryptocurrency exchange where users trade currencies directly with each other without needing a middleman or identity checks. It operates using a DAO (Decentralized Autonomous Organization) for self-management.
Self-transfer issue
A design flaw in the Bisq DAO where 93% of transactions are self-transfers (sending tokens to oneself). This pattern allows analysts to cluster all addresses controlled by the same person, exposing their activity.
Address Clustering
A technique used in blockchain analysis where multiple addresses belonging to one person are grouped together. By linking these clusters, analysts can piece together a user's entire trading and voting history.
DAO (Decentralized Autonomous Organization)
The mechanism by which the Bisq project manages itself. This involves proposals, voting, and paying contributors, generating public data that contributes to the overall privacy risk.

Terminology

Summary

The Bisq DAO is a core component of Bisq, a decentralized cryptocurrency exchange. The purpose of the Bisq DAO is to decentralize the governance and finance functions of the exchange. However, by interacting with the Bisq DAO, participants necessarily publish data to the Bitcoin blockchain and broadcast additional data to the Bisq peer-to-peer network. We examine the privacy cost to participants in sharing this data. Specifically, we use a novel address clustering heuristic to construct the one-to-many mappings from participants to addresses on the Bitcoin blockchain and augment the address clusters with data stored within the Bisq peer-to-peer network. We show that this technique aggregates activity performed by each participant: trading, voting, transfers, etc. We identify instances where participants are operating under multiple aliases, some of which are real-world names. We identify the dominant transactors and their role in a two-sided market. We conclude with suggestions to better protect the privacy of participants in the future.

The Bisq DAO operates by tracking and interpreting the issuance and actions of a token or colored-coin issued on the Bitcoin blockchain (BSQ). Participants of the Bisq DAO must first hold some BSQ in order to make and vote upon proposals. There is a two-sided market for BSQ. On the supply side, BSQ can be acquired in several ways. BSQ was minted and distributed in a genesis transaction on 15th April 2019. Additionally, new BSQ is minted and distributed in DAO cycles to contributors using the proposal and stake based voting system. BSQ can also be traded between parties in much the same way as non-colored bitcoin using transfer transactions. On the demand side, traders using Bisq can opt to pay trade fees at a reduced rate by acquiring and burning BSQ, thereby increasing the demand for BSQ and rewarding contributors indirectly. In this way, BSQ is used to financially reward contributors as well as manage the operations of the Bisq DAO itself.

Every action on the Bisq DAO, such as a proposal or vote, takes the form of a BSQ transaction. There are twelve transaction types: Trade fee transactions pay Bisq trade fees at a reduced rate using BSQ; Transfer transactions transfer BSQ between addresses in much the same way as non-colored bitcoin; Compensation request transactions request BSQ compensation for contributions to the Bisq project; Reimbursement request transactions are functionally similar to compensation requests; Proposal transactions make proposals that are neither compensation nor reimbursement requests; Blind vote transactions vote on open requests and proposals during the blind vote stage of a DAO cycle; Vote reveal transactions publish unblinded votes during the vote reveal stage of a DAO cycle; Lockup transactions lock BSQ for a specified duration; Unlock transactions unlock previously locked BSQ; Asset listing fee transactions list new tradeable assets on Bisq; Proof of burn transactions destroy BSQ; and the Genesis transaction was the initial transaction that minted and distributed the initial quantity of BSQ.

Due to the Bisq DAO’s reliance on the BSQ token, a significant amount of DAO related activity is published to the Bitcoin blockchain. Bisq attempts to limit the extent to which any activity can be linked to users by generating new address(es) for each transaction. However, Bisq-DAO specific information can aid in this regard. While Bisq generates new address(es) for each BSQ transaction, the majority of these transactions are actually self-transfers, i.e., the same participant owns all of the addresses associated with all of the transaction inputs and outputs. In the list of twelve transaction types above, all but the transfer transactions and the genesis transaction are self-transfers. This points to our Bisq DAO-specific address clustering heuristic: for each self-transfer BSQ transaction, the addresses referenced by all of its transaction inputs and all of its transaction outputs belong to the same participant; for each BSQ transfer transaction, the addresses referenced by all of its transaction inputs and all but the first of its transaction outputs belong to the same participant. Only the address referenced by the first transaction output in a BSQ transfer transaction belongs to the recipient rather than the sender. The self-transfer issue allows the addresses referenced at either side of these transactions to be clustered. The prevalence of self-transfer transactions compounds this issue as only the BSQ genesis transaction and transfer transactions are not necessarily self-transfers.

In this paper we analyse all 30 313 BSQ transactions as of Bitcoin block height 627 911 after the completion of Bisq DAO Cycle 12 on 27th April 2020. Table 1 shows the distribution of the BSQ transaction types, excluding two irregular transactions. We note that 90% of the transactions burn BSQ for trade fees and 93% are self-transfers: participants burn BSQ and/or signal an action to the Bisq DAO (submitting proposals, voting, locking BSQ, etc.), but the remaining BSQ and underlying bitcoin are returned to the same participant.

The transaction inputs and outputs of the 30 313 BSQ transactions reference 109 719 distinct addresses. The address clustering heuristic produces 1027 address clusters. That is, it partitions the 109 719 addresses into 1027 subsets such that all addresses in the same subset are likely controlled by the same participant. Generally, it is difficult to assess the validity of an address clustering due to the unavailability of a ground truth. However, the Bisq DAO offers the following partial solution. We assign a role to each address cluster: 1. If an address cluster contains at least one address referenced by a transaction output of a BSQ proposal transaction, we assign it the proposer role. 2. If an address cluster is not a proposer but it contains at least one address referenced by a transaction output of the BSQ genesis transaction, we assign it the generator role. 3. If an address cluster is neither a proposer nor a generator, we assign it the user role.

There are 775 users, 178 generators and 74 proposers. The roles are significant because we can assign tags, or links to pseudonyms and real-world identities, to all of the proposers using data stored by the Bisq DAO for the BSQ compensation, reimbursement and proposal transactions. Furthermore, we can assign tags to many of the generators using GitHub account usernames associated with transaction outputs of the BSQ genesis transaction. Prior to the launch of the Bisq DAO and the BSQ colored-coin, the Bisq community performed the operations of the Bisq DAO and managed the issuance and circulation of prototypical BSQ colored-coins manually and centrally. During this bootstrapping phase, the Bisq community tracked voting and stakes using a spreadsheet. Additionally, contributors creating compensation requests at this time stated the BSQ address to which compensation should be directed in the request’s associated GitHub issue. Using the addresses found in both the spreadsheet and within the issues found on GitHub, we created a pre-launch BSQ tag database. The Bisq DAO was launched on the 15th April 2019. BSQ holders were given the opportunity to specify the address they wished to use in the BSQ genesis transaction. They could take one of three actions: retain their pre-launch address; publicly announce a new address or change their address privately by notifying the individual(s) who constructed the genesis transaction. For each of these cases, we can create a mapping from pre-launch addresses to post-launch addresses, thus creating a post-launch tag database for addresses referenced by the BSQ genesis transaction. Creating a mapping for the first two cases is trivial as addresses are publicly stated on GitHub. However, we were also able to ascertain post-launch addresses for those who chose to change their addresses privately. We found that the ordering of the transaction outputs of the BSQ genesis transaction matched the ordering of the entries in the spreadsheet. Together, we can assign tags to 96 distinct address clusters. We stress that assigning tags to individual addresses is trivial; the information is publicly available and released by the proposers and generators. However, we are assigning tags to entire address clusters generated using our Bisq DAO-specific heuristic and all of their constituent activity, e.g., trading, voting, transfers, etc.

Returning to the question of validity, we inspected the tags assigned to each address cluster. Out of the 96 tagged address clusters, we identified four with conflicting tags: four address clusters were assigned multiple tags that, ignoring obvious capitalization and spelling errors, were not the same. This could be an indication of false positives generated by our address clustering heuristic. However, on further inspection, we observe that one case contains three different pseudonyms who submitted three different BSQ compensation proposal transactions for overlapping translation contributions. In the other three cases we observe real-world names combined with pseudonyms. We don’t believe these are false positives but evidence of participants operating under multiple aliases. The privacy risk is stark. Additionally, there are nine shared tags: several address clusters were assigned tags that were identical to tags assigned to other address clusters. These are false negatives generated by our address clustering heuristic. They may be due to participants managing multiple Bisq nodes with distinct BSQ wallets or migrating between BSQ wallets using BSQ transfer transactions. We use the shared tags to reduce the number of address clusters to 1015 and the number of tagged clusters to 84. In the context of address clustering, a false negative is less serious than a false positive: assuming that two address clusters may be controlled by two separate participants when in fact they are controlled by one is a lack of information whereas assuming that one address cluster is controlled by one participant when in fact it is controlled by more than one is incorrect information.

Once we have generated the address clusters, we can perform higher-level analyses of activity within the Bisq DAO. We can construct an address cluster graph where each vertex corresponds to an address cluster or Bisq DAO participant and each edge corresponds to a set of BSQ transfer transactions where the source and target vertices represent the sender and recipient of the transactions, respectively. Figure 1 is a visualization of the largest connected component of the address cluster graph where the total value of the transactions associated with each edge exceeds 3000 BSQ. This is an arbitrary value chosen to produce a graph whose size is suitable for this paper; an interactive graph visualization system is required to navigate the entire graph. The color of each vertex represents the role of the corresponding address cluster: red vertices are proposers; blue vertices are generators and white vertices are users. The size of each vertex is proportional to the total amount of BSQ sent to the addresses in the corresponding address cluster. We note that all of the red vertices and three out of the eight blue vertices can be linked with pseudonyms, GitHub account names, and/or real-world names. The address cluster graph represents a financial network where the vertices represent Bisq DAO participants, many of which are identifiable, and the edges represent financial relationships. This is a privacy risk since it implies the applicability of a multitude of financial network analysis techniques.

All BSQ originates with contributors of the Bisq project in either the transaction outputs of the BSQ genesis transaction or the issuance transaction outputs of the accepted BSQ compensation and reimbursement request transactions. Once minted, BSQ can be transferred between any number of participants until it is eventually burnt, primarily by traders for trading fees. We can use the address cluster graph to classify the BSQ transfer transactions based on the roles of the sender (the source address cluster) and the recipient (the target address cluster). The breakdown for the 2095 BSQ transfer transactions (see Table 1) is 971 transfers from proposers and generators to users, 621 transfers from users to users, 350 transfers from proposers and generators to proposers and generators, and 153 transfers from users to proposers and generators. Although there are far fewer proposers and generators than users, the proposers and generators are involved in 70% of all BSQ transfer transactions. A similar situation presents itself in Bitcoin: large centralized services such as exchanges, mining pools, gambling services and darknet markets generate ‘super-clusters’ in the address clustering of the Bitcoin blockchain. Even though they are few in number when compared with the total number of Bitcoin users, they have high degree centrality in their corresponding address cluster graph and are involved in a significant number of Bitcoin transactions. Because of this they are a focus of regulators and blockchain analysis service providers. Within Bisq, the proposers and generators could attract a similar focus: they are involved in a significant number of BSQ transfer transactions, they play a central role in the network and, in many cases, they are easily identifiable.

At the time of our analysis, the Bisq DAO had minted 4 529 424.22 BSQ, the participants had burnt 681 210.40 BSQ, primarily for trade fees, and 3 848 213.82 BSQ remained in circulation. It is an easy task to identify the address clusters that have transacted the most BSQ. Out of the top ten BSQ transactors, five can be linked with GitHub account names and real-world names. The individuals are providing their names when submitting BSQ compensation and reimbursement proposal transactions. Our address clustering heuristic is linking this information with the entirety of their Bisq DAO activity including their transaction volume and balances.

Thus far, we have assessed the Bisq DAO and BSQ token in isolation. However, all BSQ transaction data is published to the Bitcoin blockchain. The set of BSQ transactions is, by definition, a subset of the set of Bitcoin transactions. We can assess the impact of the Bisq DAO on address clusterings of the entire Bitcoin blockchain. The address clusters generated by our heuristic are equally valid when viewed through the lens of the larger Bitcoin blockchain. By extension, the observations stemming from the use of this heuristic are equally applicable. Since the results of the Bisq DAO-specific clustering heuristic can be extended to the Bitcoin blockchain, a comparison between our heuristic and conventional blockchain clustering heuristics can be made. Initially, we intended to merge the results of both clustering heuristics to refine the resultant address clusters. However, we found that when the address clusters generated by both heuristics were merged, they produced large clusters with many false positives. We believe this is due to CoinJoin transactions involving bitcoin that was later colored as BSQ.

We demonstrated the privacy cost in participating in the Bisq DAO. Specifically, we showed that participants may be revealing more information than they intend, especially when submitting BSQ compensation and reimbursement proposal transactions. Even though Bisq generates new address(es) for every BSQ transaction, 93% of these transactions are self-transfers, i.e., all of the transaction inputs and outputs belong to the same participant. This points to a Bisq DAO-specific address clustering heuristic. We implemented this heuristic and applied it to all BSQ transactions to date. The heuristic proves effective in aggregating all activity performed by each participant such as trades, votes, proposals, etc. We can attach pseudonyms, GitHub account names and real-world names to many of the central participants. This has important implications for user privacy. Although not examined in this paper, it has further implications for the Bisq DAO voting system and address clustering in the broader Bitcoin blockchain.

A number of approaches can be taken to defeat this heuristic. The heuristic relies on BSQ self-transfer transactions being easily identifiable. The Bisq software could trigger false positives or false negatives in this heuristic by introducing ambiguity into the distinction between self-transfers and non-self-transfers. Other than the BSQ genesis transaction, transfer transactions are the only BSQ transactions that are not entirely self-transfers. As a result, transfer transactions have the effect of separating clusters generated by our heuristic. Disguising transfer transactions so that they cannot be distinguished from self-transfer transactions would trigger false positives in the heuristic, invalidating generated clusters. For example, a participant could create a BSQ trade fee transaction to transfer BSQ where the “change” was directed to the recipient and a small amount of BSQ was burnt to satisfy the requirement of a BSQ trade fee transaction. While this solution defeats the heuristic as it stands, there are other ways in which BSQ transaction types can be deduced. Every trade fee transaction is linked to the multi-signature transaction of a Bisq trade. Consequently, any trade fee transaction that isn’t linked to a Bisq trade could be identified as a disguised transfer transaction and treated as such. Additionally, transfer transactions can be used to trigger false negatives in our heuristic, thereby diminishing the heuristic’s effectiveness. Triggering a false negative requires the use of ‘dummy’ transfer transactions after each self-transfer transaction. This transfer transaction sends BSQ from the change address used in the last self-transfer to a new address owned by the same user. This gives the appearnce of BSQ being sent between parties, thus reducing the size of the address clusters generated by our heuristic. While dummy transfer transactions reduce the effectiveness of the heuristic, they also create transactions that aren’t otherwise needed, increasing the cost for users. Of course, functionality to create dummy transactions and a best-practices guide could be included in the Bisq software and documentation and only used to improve privacy as required.

The Bisq DAO is an innovative approach to decentralizing the governance and finance functions of a decentralized exchange. However, when viewed through the prism of blockchain analysis and address clustering, it appears vulnerable. Participants of the Bisq DAO, including traders, will expect certain limits on what is known about them and on what others can find out. Blockchain analysis could unsettle this expectation and have a ‘chilling effect’ on adoption.

Improvements for AI systems

Based on the scientific paper, here are the specific improvements I can make to AI systems and what the improved AI system can do:

  • Improvement: Implement the novel Bisq DAO-specific clustering heuristic as a reusable AI module that automatically identifies self-transfer transactions (93% of all BSQ transactions) by analyzing transaction input/output patterns.

  • What it can do: Automatically partition blockchain addresses into participant-controlled clusters with high precision, even when new addresses are generated per transaction. It can distinguish between self-transfers and genuine transfers (e.g., only the first output of a transfer transaction belongs to the recipient).

  • Improvement: Build an AI system that cross-references tagged address clusters to detect when a single participant operates under multiple pseudonyms or real-world names. The paper identified 4 such cases (e.g., one cluster with 3 different translation contributor pseudonyms).

  • What it can do: Flag conflicting tags within a cluster and distinguish between false positives (genuine multi-aliasing) and true clustering errors. This prevents incorrect attribution of activity to separate entities.

  • Improvement: Develop an AI classifier that assigns roles (proposer, generator, user) to address clusters based on transaction type references (e.g., proposal transaction outputs = proposer; genesis transaction outputs = generator).

  • What it can do: Automatically construct an address cluster graph, compute degree centrality, and identify dominant transactors. The paper found that proposers/generators, though few, are involved in 70% of all BSQ transfers—the AI can flag these super-clusters for regulatory or analytical focus.

  • Improvement: Create an AI system that quantifies the privacy cost of participation by merging blockchain data with off-chain data (GitHub usernames, spreadsheet records, compensation issues) to build a comprehensive tag database.

  • What it can do: Given a participant's public data, predict the extent of their exposed activity (trading, voting, transfers, balances) and generate a privacy risk score. This alerts users to unintended information leakage before they engage with DAO features.

  • Improvement: Implement an AI that analyzes transaction patterns to detect attempts to defeat the clustering heuristic (e.g., disguised transfer transactions or dummy transfers that trigger false negatives).

  • What it can do: Identify when a user is intentionally obfuscating their activity (e.g., a trade fee transaction not linked to a real Bisq trade) and suggest privacy-preserving countermeasures (e.g., dummy transfer generation) or warn of reduced anonymity.

  • Improvement: Build an AI system that extends the Bisq DAO clustering results to the broader Bitcoin blockchain, merging with conventional clustering heuristics while avoiding false positives from CoinJoin transactions.

  • What it can do: Map Bisq DAO participant clusters onto the full Bitcoin address graph, enabling analysis of their entire on-chain footprint (not just BSQ activity) and identifying correlations between DAO participation and other Bitcoin transactions.

  • Improvement: Develop an AI that uses the clustering results to assess the stake-based voting system's vulnerability to Sybil attacks or vote manipulation (since clusters reveal actual control over multiple addresses).

  • What it can do: Detect when a single participant controls multiple voting addresses, quantify the risk of vote concentration, and recommend governance changes to preserve decentralization.

The improved AI system can:

  • Automatically de-anonymize blockchain participants with high accuracy using the self-transfer heuristic.

  • Detect multi-aliasing and shared identities across clusters.

  • Generate financial network graphs with identifiable nodes and edges.

  • Assess and quantify privacy risks for individual users or groups.

  • Identify and counteract obfuscation attempts.

  • Extend findings to the entire Bitcoin blockchain.

  • Provide actionable insights for governance and regulatory compliance.

These improvements directly operationalize the paper's findings, turning a privacy vulnerability into a powerful analytical and defensive tool.

Related papers