SoK: Cryptocurrency Mixing and Anonymity - Architectures, Threat Models, Operational Aspects and Security

arXiv:2504.20296 · cs.CR, cs.DC · Submitted 2025-04-28 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.

Nadia: I'm Nadia, and with me are Elias and Priya, guest researcher.

Elias: Today's paper: "SoK: Cryptocurrency Mixing and Anonymity - Architectures, Threat Models, Operational Aspects and Security".

Nadia: This survey provides a comprehensive review of mixing proposals and existing implementations, beginning by summarizing a set of review criteria for mixing services, focusing on control structures, obfuscation primitives,

Elias: First, who's behind it and why it matters.

Title and authors: Nadia: We’re starting with the title and authors of "SoK: Cryptocurrency Mixing and Anonymity - Architectures, Threat Models, Operational Aspects and Security." It signals that this paper isn't just a catalog; it intends to map out the whole landscape of mixing techniques, including their operational realities and security considerations. Elias I see how the focus on "Threat Models" suggests they aren't just describing what services *do*, but analyzing exactly how those services can be attacked or bypassed.

Priya: I’m interested in what that means for the actual privacy we get; does it suggest that some architectures are inherently weaker against tracking than others, regardless of their advertised obfuscation methods?

Nadia: That’s a fair question, Priya; we need to know if there are inherent weaknesses based on the structure of centralization versus decentralization. Elias And the authors seem set on looking at both the high-level classifications and then drilling down into the inner processes that create those mixing effects.

Priya: So, it’s not just about whether a service is centralized or decentralized, but also how specific techniques like swapping or shuffling actually interact with those structures?

Nadia: Precisely; they are trying to map out the entire ecosystem of obfuscation primitives and then assess the attributes—both positive and negative—of each approach. Elias That systematic review seems important because it helps us see where the gaps are in current understanding of mixing mechanisms.

The paper's summary: Nadia: Now, let’s look at the actual summary of "SoK: Cryptocurrency Mixing and Anonymity - Architectures, Threat Models, Operational Aspects and Security." It frames the purpose as creating a comprehensive survey of mixing techniques and implementations across the entire ecosystem surrounding anonymization tools. Elias I see how they set out to review existing surveys but then pivot to focus specifically on implementation differences that genuinely impact security and anonymity.

Priya: So, instead of just summarizing what others have said, they are looking for the subtle details in how those techniques are actually put into practice across different environments.

Nadia: That’s right; they categorize services based on things like centralized control elements or whether they operate within a single chain or cross-chain. Elias And they also clearly identify privacy-preserving cryptocurrencies as a category, even though they aren't strictly mixers in the traditional sense, because hiding details is part of the goal.

Priya: That distinction between traditional mixers and those built into cryptocurrencies seems like a critical point for understanding where the anonymity actually resides.

Nadia: It is; they emphasize that modern mixers rely heavily on an anonymity set, which is essentially how many transactions are in the mixing pool to ensure flow obfuscation works effectively. Elias And they link this directly to taint analysis as a major threat, showing how tracking "dirty" coins has become a huge concern.

The paper's improvements: Nadia: Moving onto the improvements suggested in "SoK: Cryptocurrency Mixing and Anonymity - Architectures, Threat Models, Operational Aspects and Security," the authors seem to be pushing for a deeper analysis of those inner processes like obfuscation primitives. Elias I noticed they focus heavily on grouping techniques into specific methods like swapping, shuffling, aggregation, and randomized delays.

Priya: What this means for us is that we need to scrutinize these individual techniques more closely than just looking at the service type; we need to understand how these primitives combine.

Nadia: Exactly; they are exploring how different obfuscation techniques can be combined in ways that might create novel security vulnerabilities or, conversely, enhance privacy in unexpected ways. Elias They also look at things like address freshness and off-chain transactions as methods that could affect the overall mixing outcome.

Priya: And this leads to the idea that maybe a service using one specific primitive is inherently more robust against a certain type of tracking than another, which is really valuable data for us.

Nadia: Right; they are trying to characterize these services based on those combinations and then assess the resulting attributes in terms of security and anonymity. Elias It’s a very granular approach, moving from broad categories down to the specific operational details that define a mixer's actual performance.

Conclusion: Nadia: So, wrapping up the discussion on "SoK: Cryptocurrency Mixing and Anonymity - Architectures, Threat Models, Operational Aspects and Security," it seems the paper provides a really solid framework for understanding this complex ecosystem by systematically classifying services and analyzing their operational security attributes. Elias I think the main implication is that we have a much clearer map of what's out there, especially when comparing centralized versus decentralized mixing approaches.

Priya: I feel like the biggest impact is forcing researchers to look beyond simple labels and demand proof about how those techniques actually perform under various attack scenarios, which gives us better metrics for privacy.

Nadia: I agree; the paper’s focus on identifying implementational differences that affect security and anonymity is what makes it useful for real-world analysis. Elias And they clearly laid out areas where future work should concentrate, specifically in exploring advanced cryptographic techniques like multiparty computation alongside decentralized governance models.

Priya: That points toward the next stage of research needing to integrate those advanced cryptographic tools to truly secure the transfers we’re discussing.

Nadia: Well, that concludes our discussion on this paper; it gives us a lot to chew on as we think about future defensive measures in DeFi. Elias It certainly sets a high bar for what a thorough survey of mixing techniques should look like. Priya I just want to say that the level of detail they provide on the operational aspects is really helpful for anyone trying to build better tools or defenses.

Brno University of Technology (BUT University) · Slovak Technical University (Faculty of Informatics and Information Technologies)

cs.CR, cs.DC

Submitted: 2025-04-28

Updated: 2026-09-28

Comments: 32 pages overall, submitted to, and presented at EAI BlockTEA 2026 conference (accepted)

License: http://creativecommons.org/licenses/by/4.0/

Importance score: 83/100

The gist: This survey provides a comprehensive review of mixing proposals and existing implementations, beginning by summarizing a set of review criteria for mixing services, focusing on control structures,

Key concepts

Mixing Services
These are tools used to obscure transaction details to enhance anonymity. The paper reviews these services by focusing on control structures, obfuscation primitives, and how they operate within different environments like single or cross-chain systems.
Anonymity Set
This refers to the number of transactions included in a mixing pool. The authors link this directly to taint analysis as a major threat, showing how tracking 'dirty' coins is a significant concern for anonymity.
Obfuscation Primitives
These are the specific techniques used within mixers, such as swapping, shuffling, aggregation, and randomized delays. The paper examines how these individual techniques combine to create novel security vulnerabilities or enhance privacy.

Terminology

Summary

This survey provides a comprehensive review of mixing proposals and existing implementations, beginning by summarizing a set of review criteria for mixing services, focusing on control structures, obfuscation primitives, and robustness. Subsequently, it systematically analyzed the proposed systems and explored exemplary attack vectors. Furthermore, it provided a detailed comparison of the services and highlighted the threats and limitations inherent to their architectures.

The review reveals that the mixing ecosystem is diverse and filled with innovative approaches. However, few of the existing solutions have successfully achieved a completely undetectable transfer of capital. This challenge remains highly debated and is further compounded by increasing regulatory scrutiny and governmental backlash. Addressing these limitations will require new paradigms that balance user privacy, system efficiency, and regulatory compliance. Future work should explore advanced cryptographic techniques, such as multiparty computation and zero-knowledge proofs, alongside decentralized governance models.

The paper reviews mixing schemes based on classifications such as:

(de-)centralization:

"Centralized mixing service is an unintuitive approach to fund transfer obfuscation in an otherwise decentralized network. The advantage of having a centralized mixing body is reduced network communication overhead and, therefore, increased efficiency and coordination [4, 3]. They provide an easily expandable and straightforward interface at the cost of a centralized nature. A centralized institution is in its entirety trust-based, meaning that users rely on the reputation and goodwill of service providers not to be rid of their capital [3]. Another thing to mention is the opaqueness of a centralized mixer, where such a service may keep track of user information."

"Decentralized mixers meet the vision of a decentralized service – a key concept for blockchains. A direct consequence can be reduced operation speed and difficulties with scalability. Although not suffering from a centralized trust-based architecture prone to scamming, decentralized mixing services can also suffer from certain attacks. An example of such an attack is a DoS-type attack in which an attacker enters the mixing pool along with other users. The attacker then refuses to sign the transaction, resulting in the inability to execute mixing (famous examples are CoinJoin-based systems [17]). Another possible attack (Sybil attack [38]) can happen when the adversary controls a majority or a large number of transactions in the mixing pool. This allows them to better track and deanonymize other users, rendering the mixing process ineffective."

"Centralized cross-chain exchanges Wu et al. identified another supplementary class of mixing – cross-chain services [2, 39]. These services further impede taint analysis by transferring funds between cryptocurrencies. They require extensive synchronization and robustness in order to facilitate safe and lossless exchange."

(Inner Processes/Obfuscation Primitives):

"An important grouping feature in mixers is the principle of obfuscation. The ecosystem of existing techniques is vast; therefore, we focused on the approaches and methods used by the services described in the included papers and practical services (see Sec. 4). The considered obfuscation techniques involve: swapping (e.g., [17, 18]), shuffling (e.g., [19, 20]), aggregation (e.g., [9, 10, 21]), peeling chains (e.g., [9, 10]), randomized fees (e.g., [10, 22, 23, 24, 25, 21, 26, 27]), randomized delays (e.g., [10, 22, 17, 19, 20, [etc.]), address freshness (e.g., [etc.]), off-chain transactions (e.g., [9, 10, 23]), zero-knowledge proofs (e.g., [24, 25, 27]), other techniques, such as cross-chain transactions (e.g., [28, 29, 30, 31]), ring signatures (e.g., [26, 23]), TEEs (e.g., [22, 32, 33, 34, 35], etc.)"

(Proposals vs. Implementations):

"Finally, we can divide approaches by their academic nature vs. the real-world implementation: This results into the following categories: 1. peer-reviewed publications from academia without any implementation or with a proof-of-concept implementation; 2. peer-reviewed publications from academia with full implementation; 3. fully operational implementation, potentially with a white-paper."

(Specific Approaches and Mechanisms):

"Helix. Based on the approaches outlined above, we can characterize Helix as a service using several privacy measures. Based on the analyses of Balthasar [11] and Möser [8], it is clear that Helix utilized a form of centralized swapping.

Improvements for AI systems

Here are specific improvements to AI systems based on the insights from this survey, categorized by application:


)1. Enhanced Anonymity and Privacy in Decentralized Finance (DeFi) Applications:

The paper highlights a diverse landscape of mixing services (CoinJoin, CoinShuffle, CoinParty) and privacy-preserving cryptocurrencies (Monero, Zcash). The key takeaway is that anonymity is contingent on the size of the anonymity set and the effectiveness of the underlying cryptographic primitives.

Improvements for AI Systems:

  • Develop an AI agent capable of dynamically selecting or constructing optimal mixing protocols based on real-time network conditions (e.g., transaction volume, block confirmation times) to maximize anonymity while minimizing latency (addressing User-added delay).

  • Create a machine learning model trained to predict the vulnerability of specific decentralized mixers (e.g., CoinJoin variants) against Sybil attacks or DoS attacks based on observed network topology and participant behavior.

  • Design AI agents that utilize Zero-Knowledge Proofs (ZKPs) like those in MixEth or Tornado Cash, allowing them to verify capital ownership and execute complex financial transactions without revealing the underlying sensitive data (sender, receiver, amount).

Improved AI System Capability:

This system can act as a secure DeFi intermediary or transaction orchestrator. It could facilitate high-value transfers between users on a public blockchain while ensuring that the transaction flow is obfuscated using dynamically chosen mixing techniques (e.g., switching from CoinJoin to CoinShuffle if certain network conditions are detected) and cryptographically proven ownership, thereby maximizing user privacy against taint analysis and deanonymization attempts.

)2. Advanced Threat Detection and Forensics in Blockchain Environments:

The survey details various deanonymization techniques, including taint analysis, temporal analysis, and machine learning models used by chainalysis. It also discusses the vulnerabilities of TEEs (Intel SGX) to side-channel attacks and rollback attacks.

Improvements for AI Systems:

  • Build a sophisticated AI forensic tool that integrates temporal correlation analysis with transaction pattern recognition to proactively identify suspicious tainted flows, even when standard taint analysis fails due to low volume or fixed fees.

  • Develop an AI model specifically designed to detect subtle timing anomalies indicative of Ring Signature exploitation in privacy coins like Monero by analyzing block time variance and transaction frequency patterns across a network.

  • Create a vulnerability scanning AI that simulates side-channel attacks against TEE implementations (like SGX) by analyzing instruction patterns or memory access sequences to predict potential data leaks.

Improved AI System Capability:

This system serves as an autonomous blockchain security auditor and investigative tool. It can move beyond simple signature checks to detect sophisticated, low-level deanonymization attempts—such as timing attacks on Monero transactions or hardware-level exploits against TEEs—by learning the subtle statistical patterns that human investigators or simpler algorithms miss.

)3. Secure Cross-Chain and Interoperable Systems:

The paper reviews centralized cross-chain exchanges and privacy-preserving cryptocurrencies (Oasis, Secret) that use TEEs for confidential smart contracts. It also notes the need for robust synchronization in cross-chain services to impede taint analysis.

Improvements for AI Systems:

  • Design an AI agent focused on optimizing cross-chain transaction paths between different Layer 1 and Layer 2 networks by predicting which chain/protocol offers the best combination of anonymity set size and low latency, minimizing synchronization overhead.

  • Develop a system that uses ZKPs (as in MixEth) to verify the integrity of data transferred across disparate blockchain environments without needing to trust the intermediary exchange infrastructure itself.

Improved AI System Capability:

This AI can function as an intelligent interoperability layer for decentralized applications (dApps). It would autonomously route complex, multi-step transactions across various blockchains, selecting the most privacy-preserving and efficient path available at that moment, ensuring transaction integrity is maintained through ZKPs rather than relying solely on centralized exchange trust.

Abstract

Public blockchains record transaction histories that enable address clustering, taint analysis, and cross-service attribution, thereby motivating the development of mixers and privacy layers. Our work presents a structured scoping review of 22 representative systems, defining a common unlinkability objective and five adversary archetypes. We evaluate these systems against a taxonomy of attack surfaces, including chain analysis, timing inference, custodial compromise, coordination abuse, network metadata, and trusted execution compromise. While nominal anonymity-set size and cryptographic strength characterize privacy in theory, effective anonymity in practice depends on transaction denominations, cover traffic, relayer behavior, and compliance-interface design. Distinguishing nominal from effective anonymity, we derive four core lessons: (1) Privacy is strongest when integrated into everyday transactions, since standalone mixing creates an easily profiled user subset; (2) Trust points, including operators, peer quorums, and hardware enclaves, must be explicit so users know who can break privacy; (3) Network metadata, including gas funding and timing, must be treated formally as protocol data in privacy evaluations; and (4) Compliance should use auditable cryptographic predicates for selective disclosure rather than broad operator discretion. Ultimately, our systematization clarifies the strengths, failures, and future requirements of blockchain privacy architectures.

Sources

Related papers