That’s actually pretty clever! I was wondering how, with such a large number of inputs, you could successfully deter a malicious entity (state actor?) from sybil attacking and screwing up each coinjoin.

Is there a limit to the # of “blame rounds,” or does it keep going, progressively kicking out non-cooperative parties, until the coinjoin finally succeeds?

Reply to this note

Please Login to reply.

Discussion

If there's less than 150 eligible inputs remaining, then there's no advancement to a blame round. There's also an arbitrary limit of 7 blame rounds.

To be an active adversary in coinjoin is expensive for two reasons:

The attacker has to pay the mining fee for each input and output.

The attacker has to pay the interest for bitcoin required for the attack, that's thousands of bitcoin per month.