State of the transaction privacy work in Bitcoin

These issues are solvable when using the WabiSabi coinjoin protocol.

Papers measuring coinjoin data can be found here, which shows that the anonymity set continuously increases over time from remixes:

Analysis of input-output mappings in coinjoin transactions with arbitrary values by Jiri Gavenda, Petr Svenda, Stanislav Bobon, and Vladimir Sedlacek (Masaryk University, Czechia)

CoinJoin ecosystem insights for Wasabi 1.x, Wasabi 2.x and Whirlpool coordinator-based privacy mixers by Petr Svenda + Jiri Gavenda (Masaryk University, Czechia) and Vasilios Mavroudis + Chris Hicks (The Alan Turing Institute)

Changing Alice’s name to MtGox in the example doesn’t make any difference, an exchange is still a counterparty.

Those heuristics are broken from a third party perspective, but using Payjoin in this scenario doesn’t make any difference for the conventional threat model: Bob can already consolidate these two UTXOs without revealing any new information to Charlie.

It is a Payjoin issue - If Bob accepts a regular payment from Charlie’s mobile wallet instead of a payjoin, less data will be revealed to Charlie (and end up in the hands of surveillance companies).

Silent payments have no privacy advantages compared to a payment sent to a new address that was generated manually. It’s strictly a convenience improvement that allows reuse in two specific scenarios:

  1. Receiving non-public donations
  2. Receiving multiple payments from the same entity.

This is incorrect. Silent payment outputs use Taproot keys, which are exposed onchain.