Very clear presentation from Vorick on why partial anonymity sets are problematic in privacy cryptocurrencies:

https://youtu.be/yq_cOVHr8Pg

An interesting nuance is that the suggested solution actually substantially worsens the big flaw with these systems: the unprunable state gets even larger.

Reply to this note

Please Login to reply.

Discussion

Why are coinjoins immune from this problem?

They absolutely are not ( they *are* 'immune' from the secondary point i made above, which relates to his suggested solution of repeated rounds; but that is about bitcoin having pruneable state, not really about CJ).

The suggested solution where everyone consistently churns isn't a real solution. The fewer people use KYC'd services, the less powerful on chain analytics become.

Compared to Bitcoin's privacy model and the state of Bitcoin's privacy, this "doom" scenario is hyperbole. Amounts are still hidden. Receiver privacy is still fairly strong.

'Compared to bitcoin's privacy it's hyperbole' - but he wasn't doing that. He was comparing it to zcash, or any system with full anon set.