Reuse of Public Keys Across UTXO and Account-Based Cryptocurrencies

arXiv:2601.19500 · cs.CR · Submitted 2026-01-27 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.

Nadia: I'm Nadia, and with me are Elias and Priya, guest researcher.

Elias: Today's paper: "Reuse of Public Keys Across UTXO and Account-Based Cryptocurrencies".

Nadia: Cross-chain key reuse occurs even across fundamentally different system designs (UTXO and account-based), yet our analysis cannot conclusively determine whether this practice is intentional or inadvertent;

Elias: First, who's behind it and why it matters.

Paper summary: Nadia: So, we're talking about "Reuse of Public Keys Across UTXO and Account-Based Cryptocurrencies" today, which is super interesting because it looks at how keys get shared even between fundamentally different system designs. The authors claim they can connect these systems by focusing on the underlying public keys rather than just matching addresses or doing simple format conversions.

Elias: That's right; the core thesis of this paper is that even though Bitcoin and Ethereum use different address formats, they share the same cryptographic primitives, which means their public keys are related. The authors are tackling the gap where previous research was limited to direct address matching or basic format conversion when looking at key reuse across these different networks.

Priya: From a privacy measurement standpoint, this focus on public keys is important because it moves past just looking at what's visible in an address and gets to the actual cryptographic material being reused, which helps us understand the scope of potential exposure. The paper suggests that this practice of reuse weakens both security and privacy across these different designs.

Nadia: Exactly, Priya; the whole point is showing that this cross-chain reuse isn't just a theoretical possibility but an active phenomenon happening at a considerable scale, with researchers identifying one million six hundred four thousand six hundred fourteen keys being reused in at least two of the analyzed systems <ref:2601.19500#pg2>. This gives us a massive dataset to look into.

Elias: And what's particularly striking is the quantification they present; they found that out of those millions of keys reused, at least one million four hundred twenty-nine thousand eight have been actively reused in more than one cryptocurrency, which really shows the active usage happening across these different networks <ref:2601.19500#pg2,at least 1,429,008>.

Priya: I'm curious about what this actually means for privacy; if so many keys are actively being used across Bitcoin and Ethereum together, it suggests that the same underlying secret key material is being leveraged for signing transactions in multiple distinct environments. The paper also points out that internal public key reuse on these networks is still a current thing, with specific script pairs like P2PKH-P2WPKH accounting for about seventy-seven point five percent of total internal reuse events in Bitcoin and Litecoin.

Nadia: That level of active reuse is what makes this paper significant; it’s not just an academic curiosity; it points to real, large-scale activity involving these keys that we need to think about in terms of security risks and privacy leakage. The authors are looking at six cryptocurrencies: Bitcoin, Ethereum, Litecoin, Dogecoin, Zcash, and Tron.

Elias: And their methodology for finding this reuse is what sets them apart; they adapted procedures based on transaction types to extract secp256k1 public keys from UTXO outputs like P2PKH or SegWit types in Bitcoin and then used a "public key recovery method" for account-based systems like Ethereum and Tron.

Paper summary: Priya: It's interesting that they had to use different reconstruction methods depending on whether the system was UTXO or account-based, which highlights the structural differences they are trying to overcome by treating these public keys as first-class citizens in their analysis. The paper does show that address formats like P2PKH and P2WPKH can be derived from the same underlying public key, even if bidirectional conversion without knowing the original key is not always possible.

Nadia: So, to summarize what we've covered so far, this paper shows that cryptographic keys are extensively and continually reused across all of the analyzed blockchain networks, with one million six hundred four thousand six hundred fourteen reused keys in total <ref:2601.19500#pg2,that cryptographic keys are extensively and continually reused across all of the>. We've also seen how the authors quantified that at least one million four hundred twenty-nine thousand eight of those keys are actively reused in more than one cryptocurrency <ref:2601.19500#pg2,at least 1,429,008>.

Elias: Building on that quantification, the paper presents novel clustering methods that don't rely on heuristics but link entities directly by their knowledge of the underlying secret key. They even demonstrate how this key-based approach can be used to improve existing clustering techniques, such as merging clusters based on addresses derived from the same public key.

Priya: The attribution data they found is also quite telling; they successfully associated reused keys with functional categories, identifying one thousand two hundred addresses originating from eight hundred ninety-four unique instances of key reuse that were linked directly to two prominent cryptocurrency exchanges. This suggests that major services are responsible for a significant portion of these key reuse incidents, including those involving DeFi Bridges and mixing services.

Nadia: That finding about the exchanges being responsible is a big piece of the puzzle; it moves the discussion from just theoretical reuse to identifying specific entities that need scrutiny regarding their key management practices. It makes it feel much more concrete what we're dealing with in terms of potential attack vectors.

Elias: The implications for security and privacy are that this cross-chain key reuse occurs even across fundamentally different system designs, which inherently weakens both security and privacy, as the paper states. They suggest the primary objective should be to prevent this by ensuring domain separation in deterministic key derivation.

Priya: I think focusing on preventing reuse through better deterministic standards, like HD wallets, is a practical direction because wallet software often encourages users to seamlessly switch between different cryptocurrencies, which reduces privacy and security risks. However, I do want to mention the limitations they noted; they couldn't detect exclusively passive key reuse because it requires active usage of the underlying key-pair for sending or signing a transaction at least once.

Paper summary: Nadia: That limitation is important to keep in mind; we can see a lot of active reuse, but we have to be careful not to mistake passive involvement for active exploitation unless we can prove that specific usage. The authors also limited their analysis by excluding transactions using newer protocols like Taproot or Mimblewimble Extension Blocks.

Elias: And one more point is that they still haven't given us a reliable verification of HD wallet reuse, which is something they are still working on, meaning the cause of this reuse—whether it’s intentional or inadvertent—remains unclear right now. This paper also notes that while their approach provides ground-truth relationships spanning multiple systems, the causes of the reuse itself are what's still open for investigation.

Priya: So, to wrap up this discussion on "Reuse of Public Keys Across UTXO and Account-Based Cryptocurrencies," we see a lot of evidence showing widespread, active key reuse at a massive scale across different crypto designs. The paper highlights that the main contribution is linking entities by their knowledge of the underlying secret key material, pointing toward major services as being responsible for much of this activity.

Nadia: Looking at this title and the authors—Stutz, Stifter, Dragaschnig, Haslhofer, and Judmayer—it really frames a fundamental problem in modern crypto infrastructure: the assumption that different systems are isolated when their underlying mathematical foundations are shared. It forces us to reconsider how we design key management across these diverse platforms.

Elias: The implications extend beyond just linking addresses; it suggests that the very cryptographic primitives used by these networks create an interconnected web of potential vulnerabilities if key reuse isn't actively managed at the derivation layer. It prompts us to think about the necessary separation in deterministic key derivation processes to keep things secure and private across chains.

Priya: For privacy researchers, this work underscores that simply looking at address formats isn't enough; we have to look deeper into the shared public key space because that's where the real cross-system linkage happens. It gives us a new lens for measuring how much privacy is actually eroded by these interconnected usage patterns.

Nadia: So, what does this mean for the listeners tuning in who want to understand this? The paper demonstrates that we need to be much more aware of the fact that keys aren't truly isolated when they cross network boundaries in this way. This paper is a vital resource for anyone trying to secure or audit crypto systems that bridge different environments.

Elias: Indeed, it provides the necessary ground-truth relationships spanning multiple systems, which is what makes this research valuable for anyone who needs to understand the true scope of key interaction across these designs. It sets a new benchmark for analyzing key reuse in this context.

Conclusion: Nadia: So, we've seen how these researchers mapped out massive key reuse across Bitcoin and Ethereum, and now we need to really get at the core message of this paper titled "Reuse of Public Keys Across UTXO and Account-Based Cryptocurrencies."

Elias: I think the title itself highlights a big problem because it points out that key reuse isn't confined to one type of system, which is a crucial detail for anyone looking at cryptographic assumptions.

Priya: From my side, what I see in the conclusion is that this research provides concrete data showing exactly how many keys are shared between these different crypto architectures, moving beyond just theoretical concerns about interoperability.

Nadia: Exactly, Priya; it's not just a theory anymore because they've quantified the scale of this reuse across six major networks.

Elias: And from a cryptographic standpoint, the authors are showing us that even when systems have different address formats, the underlying mathematical structure—specifically ECDSA over secp256k1—is what allows for this linkage.

Priya: That shared primitive is key; it means the vulnerability isn't in one specific protocol design but in the shared cryptographic tools being used everywhere.

Nadia: It really makes you wonder, Elias, if this widespread reuse means we're looking at a much larger attack surface than we initially thought for these decentralized systems.

Elias: That's where the real concern lies; if someone can leverage that shared key material across multiple chains, the security implications are pretty significant for anyone building on top of these primitives.

Priya: And what this suggests is that privacy concerns aren't isolated to one chain; they’re woven into the fabric of how these underlying cryptographic assets are managed across the entire ecosystem.

Nadia: So, it boils down to understanding that these keys aren't truly isolated when we talk about their usage patterns across different blockchain designs.

Elias: Precisely, and that leads us to thinking about how we can enforce separation in the deterministic key derivation process to mitigate these risks moving forward.

Priya: It sets a lot of groundwork for future work, showing exactly what kind of data is needed to truly understand the causes behind this reuse—whether it’s accidental or intentional.

Nadia: And that's where we are heading next; we need to figure out who is actually driving this reuse and what they're doing with those shared keys.

Complexity Science Hub

cs.CR

Submitted: 2026-01-27

Updated: 2026-10-05

Comments: Accepted at Financial Cryptography and Data Security (FC) 2026. 35 pages, 9 figures

DOI: 10.1007/978-3-032-36697-9_10

Code: https://github.com/bitcoin/bips

Project page: https://citp.github.io/BlockSci/reference/addresses/equiv_address.html

License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/

Importance score: 79/100

The gist: Cross-chain key reuse occurs even across fundamentally different system designs (UTXO and account-based), yet our analysis cannot conclusively determine whether this practice is intentional or

Key concepts

Active Key Reuse
This occurs when the exact same secret key is used to sign transactions in more than one different cryptocurrency network. It is an active usage pattern that directly links two or more systems through the same private key, indicating a potential security vulnerability.
Passive Key Reuse
This refers to a situation where a cryptographic key is only involved on the receiving end of an interaction, such as being used for verification rather than signing. This type of reuse is less direct but still indicates shared cryptographic material across different networks.
ECDSA over secp256k1
This is the specific mathematical foundation used by many cryptocurrencies like Bitcoin and Ethereum for their digital signatures. It dictates how public keys are generated and how transactions are verified, making it the common link that allows keys to be reused across various platforms.
Deterministic Key Derivation
This refers to standardized methods, like those in HD wallets, that allow users to derive different addresses from a single master secret using consistent rules. While convenient for switching networks, this standardization can inadvertently encourage the reuse of underlying key material across systems.

Terminology

Summary

Cross-chain key reuse occurs even across fundamentally different system designs (UTXO and account-based), yet our analysis cannot conclusively determine whether this practice is intentional or inadvertent; this highlights the need to better understand its causes and to raise awareness that such reuse can weaken both security and privacy.

The gist: Cryptographic keys are extensively and actively reused across Bitcoin, Ethereum, Litecoin, Dogecoin, Zcash, and Tron networks at a considerable scale of 1,604,614 keys being reused in at least two systems.

Motivation for the Study

The paper addresses the gap in previous research that focused only on direct address matching or basic format conversion when linking key reuse across different cryptocurrency networks. The authors focus on the underlying public keys to discover reuse within, as well as across, different cryptocurrency networks, leveraging the fact that many cryptocurrencies rely on the same cryptographic primitive: ECDSA over secp256k1. By treating the public keys associated with different cryptocurrency addresses as first-class citizens in the context of key reuse, the work aims to link entities across UTXO and account-based designs where address formats are not directly compatible.

Methodology for Key Identification

The researchers analyze six cryptocurrencies: Bitcoin (BTC), Ethereum (ETH), Litecoin (LTC), Dogecoin (DOGE), Zcash (ZEC), and Tron (TRX). The analysis differentiates between two types of reuse: active key reuse, which indicates the usage of the same secret key for signing a transaction in more than one cryptocurrency, and passive key reuse, where the key is only passively involved on the receiving side. To extract public keys, they adapted procedures based on transaction types; for UTXO cryptocurrencies, they used a modified version of bitcoin-etl to extract secp256k1 public keys from transaction outputs like P2PKH, P2SH, and SegWit types. For account-based systems like Ethereum and Tron, they employed a public key recovery method based on the properties of the secp256k1 elliptic curve to reconstruct the signer’s public key from a signature and message hash.

Quantification of Key Reuse

The analysis revealed that a total number of 1,604,614 keys have been reused in at least two of the considered systems, with at least 1,429,008 keys have been actively reused in more than one cryptocurrency. Specifically, they found that between Bitcoin and Ethereum there are 497,178 reused public keys. The study also shows that key reuse is not a phenomenon of the past; temporal analysis indicates that internal public key reuse on these networks remains a current phenomenon, with specific script pairs like P2PKH-P2WPKH accounting for approximately 77.5% of total internal reuse events in Bitcoin and Litecoin.

Clustering and Entity Attribution

The paper introduces novel clustering methods that do not rely on heuristics but link entities by their knowledge of the underlying secret key. They demonstrate that this key-based approach can be used to improve existing clustering techniques, such as merging clusters based on addresses derived from the same public key. Furthermore, they successfully associated reused keys with functional categories using attribution data, identifying the direct attribution of 1,200 addresses (originating from 894 unique instances of key reuse) to two prominent cryptocurrency exchanges. This suggests that major services are responsible for the majority of key reuse incidents, including those related to DeFi Bridges and mixing services.

Implications and Countermeasures

The findings imply that cross-chain key reuse occurs even across fundamentally different system designs (UTXO and account-based), which can weaken both security and privacy. The paper suggests that the prime objective should be to prevent this by ensuring domain separation in deterministic key derivation and implementing usage patterns that discourage reuse, such as using per-transaction keys in UTXO systems. The use of deterministic standards like HD wallets is noted as a potential cause, where wallet software actively encourages key reuse by allowing users to seamlessly 'switch networks,' i.e. different cryptocurrencies, which reduces privacy and security risks.

Limitations

The study notes several limitations, including the inability to detect exclusively passive (re)use because it requires active usage of a underlying key-pair for sending/signing a transaction at least once. They also restricted analysis to EOAs for account-based systems and excluded transactions utilizing newer protocols like Taproot or Mimblewimble Extension Blocks. The paper concludes that while the approach provides ground-truth relationships that span multiple systems, the causes of reuse—whether intentional or inadvertent—remain unclear, and a reliable verification of HD wallet reuse is still pending.

Conclusion

The research demonstrates that "more than 1.

Improvements for AI systems

Here are specific improvements for AI systems based on the findings of this research, categorized by application:


)1. Enhanced Cross-Chain Entity Attribution and Forensics System:

The paper demonstrates that focusing on underlying public keys allows for ground-truth entity linking across fundamentally different cryptocurrency designs (UTXO vs. Account-Based).

Improvements:

  • Implement a novel clustering algorithm that leverages recovered public keys to map entities across heterogeneous blockchains (e.g., Bitcoin UTXO style and Ethereum account models). This moves beyond heuristic address matching, providing a deterministic link based on shared cryptographic material.

  • Integrate the derived cross-chain key reuse analysis into existing Graph Databases (like those used by Iknaio/GraphSense) to identify systemic reuse patterns involving exchanges, DeFi bridges, and mixers.

  • Develop a module that quantifies Active Key Reuse versus Passive Key Reuse, allowing forensic systems to distinguish between deliberate user activity (active) and unintentional system/wallet design issues (passive).

Improved AI System Capability: This system can perform high-precision financial forensics by tracking the movement of assets across multiple, incompatible blockchains, linking transactions not just by address format similarity but by the underlying private key material used for signing. It can definitively attribute funds to specific entities (e.g., exchanges or mixers) even when those entities employ complex mixing services or cross-chain bridging that obfuscates transaction flow.

  1. Proactive Privacy and Security Auditing for Wallet/Protocol Design:

The research highlights that deterministic key derivation and the reuse of keys across different systems are security vulnerabilities, particularly regarding usability features like switch networks.

Improvements:

  • Create a static analysis tool for blockchain protocols (especially EVM-compatible ones) that flags the use of single, long-lived key derivation branches across multiple disparate cryptocurrency ecosystems (e.g., reusing a seed phrase derivation path between an Ethereum wallet and a Bitcoin wallet).

  • Develop an AI model trained on patterns identified in the paper to predict potential privacy leakage points arising from cross-chain bridge designs (like the Avalanche Bridge example), specifically flagging bridges that appear to facilitate key reuse between UTXO and account models.

Improved AI System Capability: This system can act as a security auditor for blockchain protocols and wallet software. It can proactively warn developers or users about design choices—such as convenient cross-chain switching features—that introduce security risks by allowing the same private key to control assets across multiple, potentially conflicting, security domains.

  1. Advanced Clustering and Heuristic Enhancement:

The paper shows that clustering techniques from one system (e.g., multiple-input heuristics in UTXO) can be transferred and applied to another system (account-based).

Improvements:

  • Develop a transferable clustering engine where the knowledge of an underlying public key acts as a universal linking factor. This engine would allow existing, effective clustering methods from one chain type to be directly applied to addresses in another, even if their native address formats are incompatible.

  • Implement a mechanism that recomputes connected components across different blockchain types using the underlying public key as the primary graph edge definition, effectively merging clusters that share the same cryptographic identity but have different address encodings.

Improved AI System Capability: This system significantly expands the applicability of traditional clustering heuristics (like multiple-input heuristics) into novel, previously inaccessible domains. It allows researchers to systematically map and understand entity relationships across an entire ecosystem of cryptocurrencies by treating the underlying key as a universal identifier, leading to a more comprehensive global entity map.

  1. Anomaly Detection in Transaction Flows:

The analysis of active key reuse (e.g., funds being used for sending transactions across multiple chains) identifies high-risk activity patterns.

Improvements:

  • Train unsupervised anomaly detection models on the distribution and temporal patterns of active cross-chain public key reuse events to flag suspicious user behavior or compromised wallets exhibiting such reuse.

  • Specifically monitor transaction sequences where an address is used as an input in one chain and a reused address is used as an output in another, triggering alerts based on the likelihood derived from the paper's findings (e.g., identifying patterns associated with DeFi bridges).

Improved AI System Capability: This system can serve as a real-time threat detection layer for decentralized finance. It moves beyond simple transaction monitoring to detect complex, multi-chain behavioral anomalies that are indicative of potential money laundering, illicit fund movement, or the exploitation of cross-chain bridge vulnerabilities.

Sources

Related papers