|
|
|
|
|
by ivancho
895 days ago
|
|
But we don't have to search for those keys in all of the deposits that CM ever made - only in the ones that stopped churning and mixing. Maybe they try to control the dynamics of their lots to be statistically indistinguishable from the withdrawals - but that requires a vastly larger pool of capital and continuous operational effort, and I have a hunch they do not in fact do that. Furthermore, if you are a client, how long are you willing to keep your money in private keys that you know CM also has? Even if you don't mistrust them, you still need to worry about the exact scenario that happened - they get busted and all their private keys get seized. So chances are those amounts leave the CM network of addresses pretty quickly, even if they don't get added up in a single address. So now all that combinatorial explosion drops down to a pretty tractable k-NN classification problem. I would advise against making strong statements like "logically impossible" about things that seem to require a lot of very narrow conditions like perfect actor behavior and strong stationarity in order to be true. |
|
In the restricted scenario provided, it really is logically impossible to know the ownership transfer happened. Your attack requires knowing all inputs into the laundry, which you won't have in the general case, they'll look like any other transfers in the blockchain.
Even if a mixer is busted, I can be pretty sure they abide by their public claim to not keep any history older than a few hours after the mixing is complete, secret keys and all, because it's not in their interest for such evidence of crimes to exist.