<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0' version='2.0'><channel><atom:id>tag:blogger.com,1999:blog-38040511487295963</atom:id><lastBuildDate>Thu, 11 Apr 2013 14:41:11 +0000</lastBuildDate><category>wikileaks</category><category>datasets</category><category>code</category><category>theft</category><category>bitcoin</category><category>anonymity</category><category>analysis</category><title>An Analysis of Anonymity in the Bitcoin System</title><description></description><link>http://anonymity-in-bitcoin.blogspot.com/</link><managingEditor>noreply@blogger.com (Martin Harrigan)</managingEditor><generator>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-38040511487295963.post-3418287759644456524</guid><pubDate>Fri, 30 Sep 2011 14:47:00 +0000</pubDate><atom:updated>2011-11-22T15:36:01.817-08:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>analysis</category><category domain='http://www.blogger.com/atom/ns#'>bitcoin</category><category domain='http://www.blogger.com/atom/ns#'>anonymity</category><category domain='http://www.blogger.com/atom/ns#'>datasets</category><category domain='http://www.blogger.com/atom/ns#'>code</category><title>Code, Datasets and SPSN'11</title><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;If you would like to generate a text-file describing the entire list of Bitcoin transactions from your local data directory, we have &lt;a href="https://github.com/harrigan/bitcointools" target="_blank"&gt;forked Gavin Andresen's bitcointools project&lt;/a&gt;&amp;nbsp;to include an "--all-transactions" option. &amp;nbsp;It produces a tab-delimited text-file where each line corresponds to one input or output of a transaction (in/out) and has one of the following formats:&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;in,&amp;nbsp;hash,&amp;nbsp;coinbase&lt;/li&gt;&lt;li&gt;in,&amp;nbsp;hash,&amp;nbsp;prev_hash,&amp;nbsp;prev_index,&amp;nbsp;pubkey&lt;/li&gt;&lt;li&gt;out,&amp;nbsp;hash,&amp;nbsp;index,&amp;nbsp;pubkey,&amp;nbsp;value&lt;/li&gt;&lt;/ul&gt;For the analysis in our previous &lt;a href="http://anonymity-in-bitcoin.blogspot.com/2011/07/bitcoin-is-not-anonymous.html"&gt;blog post&lt;/a&gt;, we constructed three networks from this text-file: the transaction network, the public-key network and the user network. They are essentially directed graphs with attributes. Their construction is described in &lt;a href="http://arxiv.org/abs/1107.4524"&gt;the preprint on arXiv&lt;/a&gt;. The networks were constructed on 13th July 2011.&lt;br /&gt;To help others verify our work, and allow further academic study of the Bitcoin networks, we are making these networks, generated from the public transaction history, available for download:&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;The Transaction Network (&lt;a href="http://docs.google.com/leaf?id=0Bx-PwSuJ8dC3MWQwNzc3MzAtMTc3NC00NGZhLWI5YTAtZDFlNTVmMjU5ZjRi&amp;amp;hl=en_GB"&gt;transaction_vertices_2011-07-13.txt&lt;/a&gt;, &lt;a href="http://docs.google.com/leaf?id=0Bx-PwSuJ8dC3YTNjNzg0Y2UtNWM1Ni00MDU2LTg2MGMtYThkYWFkNWI3MmIz&amp;amp;hl=en_GB"&gt;transaction_edges_2011-07-13.txt&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;The Public-Key Network (&lt;a href="http://docs.google.com/leaf?id=0Bx-PwSuJ8dC3MTBiYzYxZTctODFhMC00MDFlLWFjMmQtZWMzN2Q2YjM5OTNk&amp;amp;hl=en_GB"&gt;public_key_vertices_2011-07-13.txt&lt;/a&gt;, &lt;a href="http://docs.google.com/leaf?id=0Bx-PwSuJ8dC3NGQ4MWZiZDEtZGU1Ni00OWEyLTk3NGQtZDU0OGIzMzI4MDI1&amp;amp;hl=en_GB"&gt;public_key_edges_2011-07-13.txt&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;The User Network (&lt;a href="http://docs.google.com/leaf?id=0Bx-PwSuJ8dC3NGFlMDk0NTItOWE0ZC00MzIzLWExNTQtYTRkYWY0MDZhOGRm&amp;amp;hl=en_GB"&gt;user_vertices_2011-07-13.txt&lt;/a&gt;, &lt;a href="http://docs.google.com/leaf?id=0Bx-PwSuJ8dC3MGEzZGFjODktMDlmYi00NzMwLWFlOWMtMDgzNzY1ZTQ4YWEx&amp;amp;hl=en_GB"&gt;user_edges_2011-07-13.txt&lt;/a&gt;)&lt;/li&gt;&lt;/ul&gt;In each case, the first two columns in an edge list reference line numbers in the corresponding vertex list. For example, the first entry in&amp;nbsp;&lt;a href="http://docs.google.com/leaf?id=0Bx-PwSuJ8dC3MGEzZGFjODktMDlmYi00NzMwLWFlOWMtMDgzNzY1ZTQ4YWEx&amp;amp;hl=en_GB"&gt;user_edges_2011-07-13.txt&lt;/a&gt;&amp;nbsp;("1 - 5994 - 8.94 - 2011-07-04-09-05-56") indicates that the user represented by line number 1 of&amp;nbsp;&lt;a href="http://docs.google.com/leaf?id=0Bx-PwSuJ8dC3NGFlMDk0NTItOWE0ZC00MzIzLWExNTQtYTRkYWY0MDZhOGRm&amp;amp;hl=en_GB"&gt;user_vertices_2011-07-13.txt&lt;/a&gt;&amp;nbsp;sent the user represented by line number 5944, 8.94BTC on the 4th July 2011.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Finally, we will be presenting a paper describing our work at the&amp;nbsp;&lt;a href="http://spsn11.media.mit.edu/"&gt;First International Workshop on Security and Privacy in Social Networks 2011 (SPSN'11)&lt;/a&gt;&amp;nbsp;next month.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description><link>http://anonymity-in-bitcoin.blogspot.com/2011/09/code-datasets-and-spsn11.html</link><author>noreply@blogger.com (Martin Harrigan)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-38040511487295963.post-3570651810390844552</guid><pubDate>Fri, 30 Sep 2011 08:20:00 +0000</pubDate><atom:updated>2011-10-17T08:06:09.788-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>analysis</category><category domain='http://www.blogger.com/atom/ns#'>bitcoin</category><category domain='http://www.blogger.com/atom/ns#'>anonymity</category><category domain='http://www.blogger.com/atom/ns#'>theft</category><category domain='http://www.blogger.com/atom/ns#'>wikileaks</category><title>Bitcoin is not Anonymous</title><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span id="goog_1401972768"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;TL;DR&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;a href="http://www.bitcoin.org/"&gt;Bitcoin&lt;/a&gt; is not inherently anonymous. It may be possible to conduct transactions is such a way so as to obscure your identity, but, in many cases, users and their transactions can be identified. We have performed an analysis of anonymity in the Bitcoin system and published our results in &lt;a href="http://arxiv.org/abs/1107.4524"&gt;a preprint on arXiv&lt;/a&gt;.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;b&gt;The Full Story&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;Anonymity is not a prominent design goal of Bitcoin. However, Bitcoin is &lt;a href="http://twitter.com/#%21/wikileaks/status/80774521350668288"&gt;often referred to&lt;/a&gt; as being anonymous. &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;We have performed a passive analysis of anonymity in the Bitcoin system using publicly available data and tools from network analysis. The results show that the actions of many users are far from anonymous. We note that several centralized services, e.g. exchanges, mixers and wallet services, have access to even more information should they wish to piece together users' activity. We also point out that an active analysis, using say marked Bitcoins and collaborating users, could reveal even more details. The technical details are contained in &lt;a href="http://arxiv.org/abs/1107.4524"&gt;a preprint on arXiv&lt;/a&gt;. We welcome any feedback or corrections regarding the paper.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;b&gt;Case Study: The Bitcoin Theft&lt;/b&gt;&lt;b style="font-size: medium;"&gt;&lt;span style="font-weight: normal;"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;To illustrate our findings, we have chosen a case study involving a user who has many reasons to stay anonymous. He is the alleged thief of 25,000 Bitcoins. This is a summary of the victim's postings to the &lt;a href="http://forum.bitcoin.org/index.php?topic=16457.0"&gt;Bitcoin forums&lt;/a&gt; and an &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;analysis of the relevant transactions.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;&lt;b&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;The victim woke up on the morning of 13/06/2011 to find a large portion of his Bitcoins sent to &lt;a href="http://blockexplorer.com/address/176LRX4WRWD5LWDMbhr94ptb2MW9varCZP"&gt;1KPTdMb6p7H3YCwsyFqrEmKGmsHqe1Q3jg&lt;/a&gt;. The alleged theft occurred on 13/06/2011 at 16:52:23 UTC shortly after somebody broke into the victim's &lt;a href="http://mining.bitcoin.cz/"&gt;Slush pool&lt;/a&gt; account and changed the payout address to &lt;a href="http://blockexplorer.com/address/15iUDqk6nLmav3B1xUHPQivDpfMruVsu9f"&gt;15iUDqk6nLmav3B1xUHPQivDpfMruVsu9f&lt;/a&gt;. The Bitcoins rightfully belong to &lt;a href="http://blockexplorer.com/address/1J18yk7D353z3gRVcdbS7PV5Q8h5w6oWWG"&gt;1J18yk7D353z3gRVcdbS7PV5Q8h5w6oWWG&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="line-height: 24px;"&gt;&lt;b&gt;An Egocentric Analysis&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="display: block; text-align: left;"&gt;&lt;div style="display: block; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;span class="Apple-style-span"&gt;&lt;a href="http://1.bp.blogspot.com/-naxagbLRdSI/TihbllkcY3I/AAAAAAAATe8/1YuN2Gw46iQ/s1600/thief_public_key_2_steps_with_extras.png"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5631852035325059954" src="http://1.bp.blogspot.com/-naxagbLRdSI/TihbllkcY3I/AAAAAAAATe8/1YuN2Gw46iQ/s320/thief_public_key_2_steps_with_extras.png" style="cursor: pointer; display: block; height: 272px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;b&gt;Fig. 1: The egocentric user network of the &lt;span style="color: #e41a1c;"&gt;thief&lt;/span&gt;.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="display: block; margin-left: auto; margin-right: auto; text-align: left;"&gt;&lt;span class="Apple-style-span"&gt;We consider the user network of the thief. Each vertex represents a user and each directed edge between a source and a target represents a flow of Bitcoins from a public-key belonging to the user corresponding to the source to a public-key belonging to the user corresponding to the target. Each directed edge is colored by its source vertex. The network is &lt;i&gt;imperfect&lt;/i&gt; in the sense that there is, at the moment, a one-to-one mapping between users and public-keys. We restrict ourselves to the egocentric network surrounding the &lt;span style="color: #e41a1c;"&gt;thief&lt;/span&gt;: we include every vertex that is reachable by a path of length at most two ignoring directionality and all edges induced by these vertices. We also remove all loops, multiple edges and edges that are not contained in some biconnected component to avoid clutter. In Fig. 1, the &lt;span style="color: #e41a1c;"&gt;red vertex&lt;/span&gt; represents the &lt;span style="color: #e41a1c;"&gt;thief&lt;/span&gt; and the &lt;span style="color: #4daf4a;"&gt;green vertex&lt;/span&gt; represents the &lt;span style="color: #4daf4a;"&gt;victim&lt;/span&gt;. The theft is the green edge joining the &lt;span style="color: #4daf4a;"&gt;victim&lt;/span&gt; and the &lt;span style="color: #e41a1c;"&gt;thief&lt;/span&gt;. There are in fact two green edges located nearby in Fig. 1 but only one directly connects the &lt;span style="color: #4daf4a;"&gt;victim&lt;/span&gt; to the &lt;span style="color: #e41a1c;"&gt;thief&lt;/span&gt;.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div dir="ltr" style="text-align: left;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div dir="ltr" style="text-align: left;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="display: block; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;span class="Apple-style-span"&gt;&lt;a href="http://3.bp.blogspot.com/-wEJqDIZwY6g/Tihb7dz_7JI/AAAAAAAATfE/Br5pEk9GtHw/s1600/thief_public_key_2_steps_only_extras_annotated.png"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5631852411199941778" src="http://3.bp.blogspot.com/-wEJqDIZwY6g/Tihb7dz_7JI/AAAAAAAATfE/Br5pEk9GtHw/s320/thief_public_key_2_steps_only_extras_annotated.png" style="cursor: pointer; display: block; height: 320px; margin: 0px auto 10px; text-align: center; width: 246px;" /&gt;&lt;/a&gt;&lt;b&gt;Fig. 2: An interesting sub-network induced by the &lt;span style="color: #e41a1c;"&gt;thief&lt;/span&gt;, the &lt;span style="color: #4daf4a;"&gt;victim&lt;/span&gt; and three other vertices.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="display: block; margin-left: auto; margin-right: auto; text-align: left;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="display: block; margin-left: auto; margin-right: auto; text-align: left;"&gt;&lt;span class="Apple-style-span"&gt;Interestingly, the &lt;span style="color: #4daf4a;"&gt;victim&lt;/span&gt; and the &lt;span style="color: #e41a1c;"&gt;thief&lt;/span&gt; are joined by paths (ignoring directionality) other than the green edge representing the theft. For example, consider the sub-network shown in Fig. 2 induced by the &lt;span style="color: #e41a1c;"&gt;red&lt;/span&gt;, &lt;span style="color: #4daf4a;"&gt;green&lt;/span&gt;, &lt;span class="Apple-style-span" style="color: #984ea3;"&gt;purple&lt;/span&gt;, &lt;span class="Apple-style-span" style="color: #dddd33;"&gt;yellow&lt;/span&gt; and &lt;span class="Apple-style-span" style="color: #ff7f00;"&gt;orange &lt;/span&gt; vertices. This sub-network is a cycle. We contract all vertices whose corresponding public-keys belong to the same user. This allows us to attach values in Bitcoins and timestamps to the directed edges. Firstly, we note that the theft of 25,000 BTC was preceded by a smaller theft of 1 BTC. This was later reported by the &lt;span style="color: #4daf4a;"&gt;victim&lt;/span&gt; in the Bitcoin forums. Secondly, using off-network data, we have identified some of the other colored vertices: the &lt;span style="color: #984ea3;"&gt;purple vertex&lt;/span&gt; represents the &lt;span style="color: #984ea3;"&gt;main Slush pool account&lt;/span&gt; and the &lt;span style="color: #ff7f00;"&gt;orange vertex&lt;/span&gt; represents the computer hacker group &lt;span style="color: #ff7f00;"&gt;LulzSec&lt;/span&gt; (see, for example, their &lt;a href="http://twitter.com/LulzSec/status/76388576832651265" style="color: #336699;"&gt;Twitter stream&lt;/a&gt;). We note that there has been at least &lt;a href="http://pastebin.com/88nGp508" style="color: #336699;"&gt;one attempt&lt;/a&gt; to associate the &lt;span style="color: #e41a1c;"&gt;thief&lt;/span&gt; with &lt;span style="color: #ff7f00;"&gt;LulzSec&lt;/span&gt;. This was a fake; it was created after the theft. However, the identification of the &lt;span style="color: #ff7f00;"&gt;orange vertex&lt;/span&gt; with &lt;span style="color: #ff7f00;"&gt;LulzSec&lt;/span&gt; is genuine and was established before the theft. We observe that the &lt;span style="color: #e41a1c;"&gt;thief&lt;/span&gt; sent &lt;a href="http://www.urbandictionary.com/define.php?term=31337" style="color: #336699;"&gt;0.31337 BTC&lt;/a&gt; to &lt;span style="color: #ff7f00;"&gt;LulzSec&lt;/span&gt; shortly after the theft but we cannot otherwise associate him with the group. The &lt;span style="color: #984ea3;"&gt;main Slush pool account&lt;/span&gt; sent a total of 441.83 BTC to the &lt;span style="color: #4daf4a;"&gt;victim&lt;/span&gt; over a 70-day period. It also sent a total of 0.2 BTC to the &lt;span style="color: #dddd33;"&gt;yellow vertex&lt;/span&gt; over a 2-day period. One day before the theft, the &lt;span style="color: #dddd33;"&gt;yellow vertex&lt;/span&gt; also sent 0.120607 BTC to &lt;span style="color: #ff7f00;"&gt;LulzSec&lt;/span&gt;. The &lt;span style="color: #dddd33;"&gt;yellow vertex&lt;/span&gt; represents a user who is the owner of at least five public-keys:&lt;/span&gt;&lt;/div&gt;&lt;div style="display: block; margin-left: auto; margin-right: auto; text-align: left;"&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blockexplorer.com/address/1MUpbAY7rjWxvLtUwLkARViqSdzypMgVW4" style="color: #336699;"&gt;&lt;span class="Apple-style-span"&gt;1MUpbAY7rjWxvLtUwLkARViqSdzypMgVW4&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blockexplorer.com/address/13tst9ukW294Q7f6zRJr3VmLq6zp1C68EK" style="color: #336699;"&gt;&lt;span class="Apple-style-span"&gt;13tst9ukW294Q7f6zRJr3VmLq6zp1C68EK&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blockexplorer.com/address/1DcQvXMD87MaYcFZqHzDZyH3sAv8R5hMZe" style="color: #336699;"&gt;&lt;span class="Apple-style-span"&gt;1DcQvXMD87MaYcFZqHzDZyH3sAv8R5hMZe&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blockexplorer.com/address/1AEW9ToWWwKoLFYSsLkPqDyHeS2feDVsVZ" style="color: #336699;"&gt;&lt;span class="Apple-style-span"&gt;1AEW9ToWWwKoLFYSsLkPqDyHeS2feDVsVZ&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #336699;"&gt;&lt;a href="http://blockexplorer.com/address/1EWASKF9DLUCgEFqfgrNaHzp3q4oEgjTsF" style="color: #336699;"&gt;1EWASKF9DLUCgEFqfgrNaHzp3q4oEgjTsF&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div style="display: block; margin-left: auto; margin-right: auto; text-align: left;"&gt;&lt;span class="Apple-style-span"&gt;Like the &lt;span style="color: #4daf4a;"&gt;victim&lt;/span&gt;, he is a member of the &lt;span style="color: #984ea3;"&gt;Slush pool&lt;/span&gt;, and like the &lt;span style="color: #e41a1c;"&gt;thief&lt;/span&gt;, he is a one-time donator to &lt;span style="color: #ff7f00;"&gt;LulzSec&lt;/span&gt;. This donation, the day before the theft, is his last known activity using these public-keys.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;A Flow and Temporal Analysis&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;In addition to visualizing the egocentric network of the &lt;span class="Apple-style-span" style="color: #e41a1c;"&gt;thief&lt;/span&gt; with a fixed radius, we can follow significant flows of value through the network over time. If a vertex representing a user receives a large volume of Bitcoins relative to their estimated balance, and, shortly after, transfers a significant proportion of those Bitcoins to another user, we deem this interesting. We built a special purpose tool that, starting with a chosen vertex or set of vertices, traces significant flows of Bitcoins over time. In practice we have found this tool to be quite revealing when analyzing the user network.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-9-DKVn-iPGs/TijWaNSrVJI/AAAAAAAAAXc/Wz7D23OBcFQ/s1600/AllegedtheftBlogVizSmaller.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-9-DKVn-iPGs/TijWaNSrVJI/AAAAAAAAAXc/Wz7D23OBcFQ/s320/AllegedtheftBlogVizSmaller.png" width="320" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;Fig. 3: A visualization of Bitcoin flow from the theft. The size of a vertex corresponds to its degree in the entire network. The color denotes the volume of Bitcoins &lt;span class="Apple-style-span" style="font-family: arial,sans-serif; font-size: small; font-weight: normal; line-height: 16px;"&gt;—&lt;/span&gt; warmer colors have larger volumes flowing through them. &lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;We also provide an &lt;a href="https://sites.google.com/site/btcanalysis/AllegedTheftBlogVersion.svg?attredirects=0&amp;amp;d=1"&gt;SVG&lt;/a&gt; which contains hyperlinks to the relevant &lt;a href="http://blockexplorer.com/"&gt;Block Explorer&lt;/a&gt; pages.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-5BMrk807RuA/Tijfxum0BZI/AAAAAAAAAXg/eXnRGYSoxZI/s1600/theftBlogViz.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span"&gt;&lt;img border="0" height="144" src="http://3.bp.blogspot.com/-5BMrk807RuA/Tijfxum0BZI/AAAAAAAAAXg/eXnRGYSoxZI/s320/theftBlogViz.png" width="320" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;Fig. 4: An annotated version of Fig. 3.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;In the left inset, we can see that the Bitcoins are shuffled between a small number of accounts and then transferred back to the initial account. After this shuffling step, we have identified four significant outflows of Bitcoins that began at 19:49, 20:01, 20:13 and 20:55. Of particular interest are the outflows that began at 20:55 (labeled as &lt;b&gt;1&lt;/b&gt; in both insets) and 20:13 (labeled as &lt;b&gt;2&lt;/b&gt; in both insets). These outflows pass through several subsequent accounts over a period of several hours. Flow &lt;b&gt;1&lt;/b&gt; splits at the vertex labeled &lt;b&gt;A&lt;/b&gt; in the right inset at 04:05 the day after the theft. Some of its Bitcoins rejoin Flow &lt;b&gt;2&lt;/b&gt; at the vertex labeled &lt;b&gt;B&lt;/b&gt;. This new combined flow is labeled as &lt;b&gt;3&lt;/b&gt; in the right inset. The remaining Bitcoins from Flow &lt;b&gt;1&lt;/b&gt; pass through several additional vertices in the next two days. This flow is labeled as &lt;b&gt;4&lt;/b&gt; in the right inset.&lt;br /&gt;&lt;br /&gt;A surprising event occurs on 16/06/2011 at approximately 13:37. A small number of Bitcoins are transferred from Flow &lt;b&gt;3&lt;/b&gt; to a heretofore unseen public-key &lt;a href="http://blockexplorer.com/address/1FKFiCYJSFqxT3zkZntHjfU47SvAzauZXN"&gt;1FKFiCYJSFqxT3zkZntHjfU47SvAzauZXN&lt;/a&gt;. Approximately seven minutes later, a small number of Bitcoins are transferred from Flow &lt;b&gt;3&lt;/b&gt; to another heretofore unseen public-key &lt;a href="http://blockexplorer.com/address/1FhYawPhWDvkZCJVBrDfQoo2qC3EuKtb94"&gt;1FhYawPhWDvkZCJVBrDfQoo2qC3EuKtb94&lt;/a&gt;. Finally, there are two simultaneous transfers from Flow &lt;b&gt;4&lt;/b&gt; to two more heretofore unseen public-keys: &lt;a href="http://blockexplorer.com/address/1MJZZmmSrQZ9NzeQt3hYP76oFC5dWAf2nD"&gt;1MJZZmmSrQZ9NzeQt3hYP76oFC5dWAf2nD&lt;/a&gt; and &lt;a href="http://blockexplorer.com/address/12dJo17jcR78Uk1Ak5wfgyXtciU62MzcEc"&gt;12dJo17jcR78Uk1Ak5wfgyXtciU62MzcEc&lt;/a&gt;. We have determined that these four public-keys &lt;span class="Apple-style-span" style="font-family: sans-serif; line-height: 20px;"&gt;—&lt;/span&gt; which receive Bitcoins from two separate flows that split from each other two days previously &lt;span class="Apple-style-span" style="font-family: sans-serif; line-height: 20px;"&gt;—&lt;/span&gt; are all contracted to the same user in our ancillary network. This user is represented as &lt;b&gt;C&lt;/b&gt;.&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;There are several other examples of interesting flow. The flow labeled as &lt;b&gt;Y&lt;/b&gt; involves the movement of Bitcoins through thirty unique public-keys in a very short period of time. At each step, a small number of Bitcoins (typically 30 BTC which had a market value of approximately US$500 at the time of the transactions) are siphoned off. The public-keys that receive the small number of Bitcoins are typically represented by small blue vertices due to their low volume and degree. On 20/06/2011 at 12:35, each of these public-keys makes a transfer to a public-key operated by the &lt;a href="http://mybitcoin.com/"&gt;MyBitcoin&lt;/a&gt; service. Curiously, this public-key was previously involved in &lt;a href="http://forum.bitcoin.org/index.php?topic=20427.0"&gt;another separate Bitcoin theft&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;WikiLeaks&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://wikileaks.org/"&gt;WikiLeaks&lt;/a&gt; recently &lt;a href="http://twitter.com/wikileaks/status/80774521350668288"&gt;advised its Twitter followers&lt;/a&gt; that it now accepts &lt;i&gt;anonymous&lt;/i&gt; donations via Bitcoin. They &lt;a href="http://wikileaks.org/support.html"&gt;also state&lt;/a&gt; that "Bitcoin is a secure and anonymous digital currency. Bitcoins cannot be easily tracked back to you, and are a [sic] safer and faster alternative to other donation methods." They proceed to describe a more secure method of donating Bitcoins that involves the generation of a one-time public-key but the implications for those who donate using the tweeted public-key are unclear. Is it possible to associate a donation with other Bitcoin transactions performed by the same user or perhaps identify them using external information?&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-lno9k3rjDjk/TijliwpNIQI/AAAAAAAAAXk/EioKzYD3QX0/s1600/blogForumWikileaks.PNG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span"&gt;&lt;img border="0" height="318" src="http://4.bp.blogspot.com/-lno9k3rjDjk/TijliwpNIQI/AAAAAAAAAXk/EioKzYD3QX0/s320/blogForumWikileaks.PNG" width="320" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"&gt;Fig. 5: A visualization of the egocentric user network of WikiLeaks. We can identify many of the users in this visualization.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;Our tools resolve several of the users with identifying information gathered from the &lt;a href="http://forum.bitcoin.org/"&gt;Bitcoin Forums&lt;/a&gt;, the &lt;a href="https://freebitcoins.appspot.com/"&gt;Bitcoin Faucet&lt;/a&gt;, Twitter streams, etc. These users can be linked either directly or indirectly to their donations. The presence of a &lt;a href="http://mining.bitcoin.cz/"&gt;Bitcoin mining pool&lt;/a&gt; (a large red vertex) and a number of public-keys between it and WikiLeaks' public-key is interesting. Our point is that, by default, a donation to WikiLeaks' 'public' public-key may not be anonymous.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Conclusion&lt;/b&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;This is a straight-forward passive analysis of public data that allows us to de-anonymize considerable portions of the Bitcoin network. We can use tools from network analysis to visualize egocentric networks and to follow the flow of Bitcoins. This can help us identify several centralized services that may have even more details about interesting users. We can also apply techniques such as community finding, block modeling, network flow algorithms, etc. to better understand the network.&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;b&gt;Feedback&lt;/b&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;We are excited about the Bitcoin project and consider it a remarkable milestone in the evolution of electronic currencies. &lt;/span&gt;Our motivation for this work has not been to de-anonymize any individual users; rather it is to illustrate the limits of anonymity in the Bitcoin system. It is important that users do not have a false expectation of anonymity. We welcome any feedback or comments regarding &lt;a href="http://arxiv.org/abs/1107.4524"&gt;the preprint on arXiv&lt;/a&gt; or the details in this post.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;i&gt;Follow on&lt;/i&gt;:&lt;br /&gt;We have wrote a follow on blog post: &lt;a href="http://anonymity-in-bitcoin.blogspot.com/2011/09/code-datasets-and-spsn11.html"&gt;http://anonymity-in-bitcoin.blogspot.com/2011/09/code-datasets-and-spsn11.html&lt;/a&gt;&amp;nbsp; where we release some of the data we extracted, in other to allow other researchers replicate our work, or perform follow on analysis.&lt;/div&gt;&lt;/div&gt;</description><link>http://anonymity-in-bitcoin.blogspot.com/2011/07/bitcoin-is-not-anonymous.html</link><author>noreply@blogger.com (Martin Harrigan)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-naxagbLRdSI/TihbllkcY3I/AAAAAAAATe8/1YuN2Gw46iQ/s72-c/thief_public_key_2_steps_with_extras.png' height='72' width='72'/><thr:total>44</thr:total></item></channel></rss>