Yep. If they have the xpubs, then the history of those wallets is unmixed, and every mix round those wallets participated in has its anonymity set reduced, because the known xpub adresses are effectively doxxed. There could be mix rounds with only one dojo input; elimination process, that round is now moot. Enough such rounds, and the whole pool is effectively deanonymized, with maybe small pockets of anonymity left over
Discussion
Thanks. May have to read a few times lol.
been reading about this. samo uses hardened xpubs, which can be used to derive sibling accounts. only if the postmix xpub is shared does the problem exist as we think
If the app shows you the balance, it sent the xpub. Each of the 4 whirlpool accounts were sent. Only question is whether the agencies got that data, or eg. it was/will be wiped 🤷♂️
I'd err on the side of the xpub data being compromised
the app has separate views for each balanc eof the 4 accounts. if u havent opened the tab for mix in quite a while, the 3 relevant xpub may have been deleted from the cache
deposit xpub might as well be kyc anyway, if the funds deposited to it came from an exchange