[论文解读] On How Zero-Knowledge Proof Blockchain Mixers Improve, and Worsen User Privacy
本文研究了零知识证明(ZKP)区块链混币器的隐私权衡,揭示了尽管它们被广泛用于隐藏交易关联,但同时也被205个恶意实体和2,595个BEV提取者利用,用于洗钱4.1287亿美元的攻击收益。研究显示,广告宣传的匿名集合大小具有误导性,且匿名挖矿吸引了忽视隐私的用户,导致尽管有激励措施,整体隐私水平反而下降。
Zero-knowledge proof (ZKP) mixers are one of the most widely-used blockchain privacy solutions, operating on top of smart contract-enabled blockchains. We find that ZKP mixers are tightly intertwined with the growing number of Decentralized Finance (DeFi) attacks and Blockchain Extractable Value (BEV) extractions. Through coin flow tracing, we discover that 205 blockchain attackers and 2,595 BEV extractors leverage mixers as their source of funds, while depositing a total attack revenue of 412.87M USD. Moreover, the US OFAC sanctions against the largest ZKP mixer, Tornado.Cash, have reduced the mixer's daily deposits by more than 80%. Further, ZKP mixers advertise their level of privacy through a so-called anonymity set size, which similarly to k-anonymity allows a user to hide among a set of k other users. Through empirical measurements, we, however, find that these anonymity set claims are mostly inaccurate. For the most popular mixers on Ethereum (ETH) and Binance Smart Chain (BSC), we show how to reduce the anonymity set size on average by 27.34% and 46.02% respectively. Our empirical evidence is also the first to suggest a differing privacy-predilection of users on ETH and BSC. State-of-the-art ZKP mixers are moreover interwoven with the DeFi ecosystem by offering anonymity mining (AM) incentives, i.e., users receive monetary rewards for mixing coins. However, contrary to the claims of related work, we find that AM does not necessarily improve the quality of a mixer's anonymity set. Our findings indicate that AM attracts privacy-ignorant users, who then do not contribute to improving the privacy of other mixer users.
研究动机与目标
- 调查ZKP混币器在多大程度上被区块链攻击者和BEV提取者用作非法资金来源。
- 分析OFAC对Tornado.Cash实施制裁后,对混币器使用情况及用户行为的影响。
- 使用链上启发式方法,评估ZKP混币器广告宣传的匿名集合大小的准确性。
- 评估匿名挖矿(AM)是否提升了混币器匿名集合的质量,还是导致其下降。
- 识别以太坊与币安智能链用户在隐私行为上的差异。
提出的方法
- 通过链上交易分析,在以太坊和币安智能链上追踪资金流动,识别与已知恶意或BEV提取地址相关的存款人和取款人。
- 提出五种基于时间、金额和地址聚类的链上启发式方法,以比简单存款计数更准确地估算匿名集合大小。
- 应用启发式交叉技术以减少有效匿名集合大小,并通过公开的侧信道数据验证结果。
- 通过比较匿名挖矿启动前后对手的关联优势,衡量匿名挖矿的影响,同时过滤掉忽视隐私的用户。
- 对制裁后Tornado.Cash的活动进行实证分析,追踪资金流向中间地址和中心化交易所。
- 使用统计分析比较以太坊与BSC用户之间的隐私行为,识别用户在隐私偏好上的差异。
实验结果
研究问题
- RQ1ZKP混币器在多大程度上被区块链攻击者和BEV提取者用作资金来源?
- RQ2OFAC对Tornado.Cash的制裁如何影响混币器的使用情况和资金流动模式?
- RQ3ZKP混币器广告宣传的匿名集合大小是否真实反映了用户的实际隐私水平?
- RQ4匿名挖矿是否提升了混币器匿名集合的质量,还是吸引了忽视隐私的用户?
- RQ5以太坊与币安智能链用户在隐私行为上是否存在可测量的差异?
主要发现
- 共有4.1287亿美元的攻击收益存入Tornado.Cash和Typhoon.Network,其中205个恶意地址和2,595个BEV提取者使用混币器作为资金来源。
- OFAC制裁使Tornado.Cash的日均存款量下降超过83%,但仍有487个地址在制裁后存入6,259万美元,其中超过85%的取款资金通过中间地址路由,以规避审查。
- Tornado.Cash 1 ETH池的广告匿名集合大小(51,286)存在严重误导;基于启发式的分析显示,以太坊上有效匿名集合大小平均减少27.34%。
- 在币安智能链上,使用相同启发式方法后,有效匿名集合大小减少46.02%,表明其隐私保护水平远低于宣传宣称。
- 匿名挖矿并未提升隐私质量;匿名挖矿启动后,对手的关联优势从平均7.00%上升至13.50%,主要因吸引了大量忽视隐私的用户。
- 实证证据显示,以太坊与BSC用户在隐私偏好上存在差异,BSC用户表现出更少的隐私保护意识,表现为交易聚类和时间模式的差异。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。