publishing the warranty on the network. Doing so would
destroy M’s reputation and affect its business.
2. Randomized mixing fee: Mixcoin applied a randomized
mixing fee to improve the anonymity by using the beacon function, which is a publicly verifiable random
function used to produce a random number in the range
[0, 1].
3. Mix indistinguishability: Mixcoin guarantees that it will
hide the interaction between Alice and M from passive
attacks.
4. Sequential mixing: Mixcoin’s design supports multiple
repetitions of the mixing process through independent
mixers, which maintains anonymity against active
attacks, but costs time and mixing fees.
However, Mixcoin represents a single point of failure
where an attacker could gain access to the mixing server and
reveal mixing process records to a malicious third party. The
attacker could also steal Alice’s funds by sending her coins
to its own secret address instead of Alice’s k out address.
Moreover, although Mixcoin allows Alice to detect the
theft when it occurs and expose M, the protocol does not
prove the validity of the complaint. There are two possible
cases of theft complaint. In the first case, the theft complaint
is valid because M acts dishonestly by stealing Alice’s
funds. In the second case, the theft complaint is invalid
because M acts honestly, and Alice generates a fake complaint to damage M’s reputation. Invalid complaints are not
detected by Mixcoin because the mixing process uses fresh
addresses that have no transaction history, and no mechanism proves ownership of the addresses published in the
theft complaint.
3 Related Work
In this section, we discuss the related work that has proposed
improving Bitcoin users’ anonymity and other works that
use threshold cryptography within Bitcoin.
3.1 Bitcoin Privacy Solutions
Mixing Protocols. This category proposes a solution that
improves anonymity without requiring modifications to the
Bitcoin protocol. Table 1 shows a comparison of the related
mixing protocols.
Centralized Mixing Protocols. Besides Mixcoin, Blindcoin (Valenta and Rowan 2015) improves upon Mixcoin by
using a blind signature with a public log to hide the mapping
Table 1 Comparison of Bitcoin
mixing protocols
Attribute Name
Mixcoin
(Bonneau et al.
2014)
Blindcoin (Valenta
and Rowan 2015)
CoinJoin
(Maxwell
2013)
CoinShuffle (Ruffing
et al. 2014)
Category
Centralized
Centralized
Decentralized
Decentralized
Mixing process
performed by
Single mixer
Single mixer
Set of
participant
users
Set of participant
users
Cryptograph
layer
Signed warranty
Signed warranty,
blind signature,
public log
Group
transaction
Group transaction
and public key
encryption
DoS attack
against mixing
process
Prevented
Prevented
Not
prevented
Not prevented
Internal
unlinkability
Not guaranteed
Guaranteed
Not
guaranteed
Guaranteed
External
unlinkability
Guaranteed
Not guaranteed
Guaranteed
Guaranteed
Theft issue
Detectable
Detectable
Prevented
Prevented
Anonymity set
dependency
Set of clients use
mixer at same
time
Set of clients use
mixer at same time
Set of
participant
users
Set of participant
users
Scalability
Scalable
Scalable
Limited
Limited
Cost
Mixing fee and
two transaction
fees
Mixing fee and four
transaction fees
One
transaction
fee
One transaction fee
T-Mix: A Threshold Cryptography Mixing Service for Bitcoin
293
destroy M’s reputation and affect its business.
2. Randomized mixing fee: Mixcoin applied a randomized
mixing fee to improve the anonymity by using the beacon function, which is a publicly verifiable random
function used to produce a random number in the range
[0, 1].
3. Mix indistinguishability: Mixcoin guarantees that it will
hide the interaction between Alice and M from passive
attacks.
4. Sequential mixing: Mixcoin’s design supports multiple
repetitions of the mixing process through independent
mixers, which maintains anonymity against active
attacks, but costs time and mixing fees.
However, Mixcoin represents a single point of failure
where an attacker could gain access to the mixing server and
reveal mixing process records to a malicious third party. The
attacker could also steal Alice’s funds by sending her coins
to its own secret address instead of Alice’s k out address.
Moreover, although Mixcoin allows Alice to detect the
theft when it occurs and expose M, the protocol does not
prove the validity of the complaint. There are two possible
cases of theft complaint. In the first case, the theft complaint
is valid because M acts dishonestly by stealing Alice’s
funds. In the second case, the theft complaint is invalid
because M acts honestly, and Alice generates a fake complaint to damage M’s reputation. Invalid complaints are not
detected by Mixcoin because the mixing process uses fresh
addresses that have no transaction history, and no mechanism proves ownership of the addresses published in the
theft complaint.
3 Related Work
In this section, we discuss the related work that has proposed
improving Bitcoin users’ anonymity and other works that
use threshold cryptography within Bitcoin.
3.1 Bitcoin Privacy Solutions
Mixing Protocols. This category proposes a solution that
improves anonymity without requiring modifications to the
Bitcoin protocol. Table 1 shows a comparison of the related
mixing protocols.
Centralized Mixing Protocols. Besides Mixcoin, Blindcoin (Valenta and Rowan 2015) improves upon Mixcoin by
using a blind signature with a public log to hide the mapping
Table 1 Comparison of Bitcoin
mixing protocols
Attribute Name
Mixcoin
(Bonneau et al.
2014)
Blindcoin (Valenta
and Rowan 2015)
CoinJoin
(Maxwell
2013)
CoinShuffle (Ruffing
et al. 2014)
Category
Centralized
Centralized
Decentralized
Decentralized
Mixing process
performed by
Single mixer
Single mixer
Set of
participant
users
Set of participant
users
Cryptograph
layer
Signed warranty
Signed warranty,
blind signature,
public log
Group
transaction
Group transaction
and public key
encryption
DoS attack
against mixing
process
Prevented
Prevented
Not
prevented
Not prevented
Internal
unlinkability
Not guaranteed
Guaranteed
Not
guaranteed
Guaranteed
External
unlinkability
Guaranteed
Not guaranteed
Guaranteed
Guaranteed
Theft issue
Detectable
Detectable
Prevented
Prevented
Anonymity set
dependency
Set of clients use
mixer at same
time
Set of clients use
mixer at same time
Set of
participant
users
Set of participant
users
Scalability
Scalable
Scalable
Limited
Limited
Cost
Mixing fee and
two transaction
fees
Mixing fee and four
transaction fees
One
transaction
fee
One transaction fee
T-Mix: A Threshold Cryptography Mixing Service for Bitcoin
293
