{
  "episodeId": "SLP297",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "ergo": {
      "name": "Ergo",
      "role": "guest",
      "tag": "ERGO"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:09",
      "start": 8.91,
      "text": "Hi, you're listening to Stephan Livera podcast, a show about Bitcoin. Today, for episode two hundred and ninety-six, my guest is Ergo. Now, Ergo is a team member in OXT Research, which is also, part of the broader Samurai Wallet team. So, Ergo is a white hat chain analyst, and today we're gonna talk about some of the basic- concepts around Bitcoin privacy. So this will be more of a beginner focused episode for those of you who might be new, you're trying to learn about Bitcoin. We're going to talk about some of the privacy heuristics, common pitfalls and gotchas, as well as the way chain analysis or chain surveillance works and what are the techniques that they use, as well as some of the techniques that can be used in defense against this. Also, we'll talk a little bit about what it might look like to go and actually try to chain surveil yourself. This show is brought to you by Swan Bitcoin, the best way to accumulate Bitcoin with automatic recurring buys and smash buys. Swan Bitcoin takes a focus on education, so if you are new to Bitcoin yourself, or if you have friends who are new to Bitcoin, Swan Bitcoin is a great place to send them because there's a specific focus on education and content. And what I've found is that the more somebody knows, the more they're looking and committed to buy Bitcoin. Swan has cheap fees, really fast to set up, and you can automate your stacking. It's available internationally with wires and for high net worth individuals or businesses and other entities, there's Swan Private where you can get one-on-one calls And a dedicated Bitcoin account expert, so get ten dollars added to your account when you sign up at swanbitcoin dot com slash livera. Lend at HodlHodl is a peer-to-peer Bitcoin backed lending platform, so you can lend out stablecoins or borrow against your Bitcoin globally and anonymously, there's no KYC. So the average APR people are getting is around twenty-five percent. Also, you no longer need to sell your Bitcoin to get some liquidity. Lend at HodlHodl allows you to borrow against your Bitcoin, and you will still hold one key in the two-of-three Bitcoin, and you also know there's no rehypothecation. So lend dot hodl hodl allows peer to peer lending and borrowing directly between users. With this platform, you set your own terms and put up offers depending on how long you want to borrow or lend and the interest rate. Go to lend dot hodl hodl dot com. So there's been a lot of changes in the Bitcoin mining world with a lot of miners coming out of China. If you want to get started mining, compass mining dot io can help you. Compass is an online marketplace, so you can go there, you can That's already been vetted by the team. So you don't need to have advanced technical knowledge, you can quickly get started, and in doing so, you can tap into economies of scale and access reasonably priced hardware and cheap industrial power rates. Go to compassmining dot io and start mining Bitcoin today. Onto the show. Ergo, welcome back to the show."
    },
    {
      "speaker": "ergo",
      "time": "02:53",
      "start": 173.29,
      "text": "Hey, it's Stephane, thanks for having me back."
    },
    {
      "speaker": "stephan",
      "time": "02:55",
      "start": 174.87,
      "text": "Yeah, Ergo, so I, I see you've got, some really excellent work coming out soon, and so we're gonna talk today a little bit about, how chain surveillance works and how to chain surveil ourselves. So this is gonna be a beginner level, episode, just to put it out there and help upskill people. Maybe you're new to Bitcoin and you're learning a little bit about this, and you know, you might have heard some"
    },
    {
      "speaker": "stephan",
      "time": "03:22",
      "start": 201.6,
      "text": "things they might say, would they say, \"Oh, Bitcoin is totally private, \"or \"Is it totally public? \""
    },
    {
      "speaker": "ergo",
      "time": "03:27",
      "start": 206.71,
      "text": "I guess that, that kind of concept has changed a lot, over the last, I don't know, few years, right? You know, originally we started out with kind of an anonymous payments meme, you know, around Silk Road, WikiLeaks donations, but, you know, recently, I think, the traceability of Bitcoin has become, or at least the knowledge of the traceability of Bitcoin has become a good bit more mainstream,"
    },
    {
      "speaker": "ergo",
      "time": "03:52",
      "start": 231.58,
      "text": "understand what the technology is and how it works, and that's kind of, you know, the point of, of the guide that I've written."
    },
    {
      "speaker": "stephan",
      "time": "03:57",
      "start": 237.13,
      "text": "Excellent. Yeah, so let's start talking a little bit about some of the ways in which you might decrease or lose privacy in Bitcoin. So could you just give an overview, just for a total beginner, let's say they've, maybe they've just bought some of their first Bitcoin, but they, they don't really know anything about the privacy elements of Bitcoin, what would you say to them?"
    },
    {
      "speaker": "ergo",
      "time": "04:21",
      "start": 260.9,
      "text": "I, I To have a, a, a decent understanding of Bitcoin privacy, you, you sort of need to start with the concept of UTXOs and get at least a basic understanding of what a UTXO is. And, you know, for a beginner, that can be a little bit daunting. You know, maybe your, your wallet, you know, most wallets will, will kind of abstract that concept of UTXOs away. Yeah. You know, so maybe they have, you know, a, a simple hardware wallet and they're using, you know, for example, Trezor's,"
    },
    {
      "speaker": "ergo",
      "time": "04:52",
      "start": 291.58,
      "text": "Wallets will, will sort of, basically have the same kind of, U X, right? You'll see, you know, your total wallet balance, and then you'll see sort of the bookkeeping, the credits and debits of, of your incoming transactions that, you know, increase the balance of your wallet, and the outgoing transactions that will kind of decrease the, the balance of your wallet. You know, underlying kind of a lot of that is, is really the concept of, of UTXOs."
    },
    {
      "speaker": "stephan",
      "time": "05:15",
      "start": 315.24,
      "text": "Gotcha. Yeah. So let's try and break that down a little"
    },
    {
      "speaker": "stephan",
      "time": "05:22",
      "start": 321.62,
      "text": "Be approaching this with the mindset of, \"Oh, it's just like money in my bank account. I just see the amount there. I've got, say, a hundred dollars, or I've got a thousand dollars, and I receive money, it goes up, I, I pay money, it goes down.\" That might be what a Bitcoin wallet looks like when you are totally new to all of this, but actually in reality, what happens in the background, and your wallet manages this for you, is this concept of unspent transaction outputs. So can you explain a little bit around that and how Bitcoin transactions"
    },
    {
      "speaker": "ergo",
      "time": "05:52",
      "start": 351.58,
      "text": "We'll start first with just kind of the concept of an address, right? An address is, is a, you know, a, a public key or a representation of your wallet's public keys. That's what you hand out to someone when you want to receive a payment. there's a difference between an address and a UTXO. now a UTXO, will be what your wallet software really receives and recognizes, and then is later kind of spent. So if you go back to that sort of UX flow where you have your- Your general wallet kind of, overview balance with the credits and debits for your incoming and outgoing transactions. Each of those incoming transactions will very likely represent, you know, a single, unspent transaction output. that's, that's basically, a piece of a Bitcoin, kind of for lack of a, a, a better term. But each of those pieces of Bitcoin, is sort of what gets managed, in the background by your wallet software, as you had mentioned."
    },
    {
      "speaker": "stephan",
      "time": "06:48",
      "start": 407.72,
      "text": "Yeah. And so for listeners, one analogy I like to use when I This, say, I'm at a Bitcoin meetup and I'm teaching somebody, I might use the analogy of gold. So let's say I had ten ounces of gold and I wanted to pay one ounce of gold to Ergo. And so, I'm obviously oversimplifying a little bit, but just to help understand the concept, imagine I melted down that ten ounces of gold into one hunk of nine ounces and one hunk of one ounce, and then I gave that to Ergo. That might be a nice, easy way to think about what's going on in the background when your wallet composes or Transaction. So do you want to just elaborate on that idea?"
    },
    {
      "speaker": "ergo",
      "time": "07:24",
      "start": 444.09,
      "text": "Yeah, yeah. I mean, that's, that's exactly kind of what happens, is that, you know, a, a UTXO is, is completely consumed, you know, destroyed on the input side of a transaction, and it's recast, you know, as, as outputs to a new transaction. And what you just described in that sort of very simple example with your, you know, ten on the input side and a one and a nine on the output side, that's very, analogous to a simple Probably one of the most common transaction types, I think about fifty percent of Bitcoin spends will have one input and two outputs, just as you said. And so then we can go from, you know, kind of that concept of UTXOs into how do we sort of interpret that kind of transaction."
    },
    {
      "speaker": "stephan",
      "time": "08:06",
      "start": 485.65,
      "text": "Gotcha. Yeah, yeah. And so essentially for listeners out there, just think of it like your wallet is managing all of this in the background, right? But what Ergo and I are talking about today is we're just trying to help explain for you that dynamic so you can understand that and then You can use to, maintain your privacy. And so essentially, when those transactions are composed or constructed, as Ergo was just explaining, your wallet will have a range of UTXOs, it will select from them and then compose the transaction. And it just so happens that some of these-- there's certain heuristics that apply. So Ergo, could you just outline some of the heuristics that are appl-- that are possible out there?"
    },
    {
      "speaker": "ergo",
      "time": "08:45",
      "start": 525.16,
      "text": "Yeah, there, there are a handful of ways to interpret, each transaction, you know, and it's not just the- Simple spends, but, you know, in the guide I focus specifically a good bit on simple spends because, that's what a significant portion of, of transactions are like. but to, you know, to kind of simplify things in the guide, I mostly represent the simple spend as the payment and change, you know, kind of, output model So as you said in your example, if you were gonna try to pay me one, you know, ounce of gold or let's just say one Bitcoin, using a ten Bitcoin UTXO, that one Bitcoin will be, a payment to me, and the nine, minus any minor fees, will be the change that gets paid back to you as a new UTXO. And so the interpretations that we sort of, as a chain analyst, as, as you're looking at a transaction like that, is, is what information do I have that I can use to figure Which of those outputs would be a change back to the original wallet? And if you can link, you know, inputs and change outputs over a series of transactions, you can track, what's likely a single user or single wallet's behavior over multiple transactions. So, yeah, there are a, a handful of, of kind of specific, heuristics for interpreting a simple spend like that, and that has to do typically with the address types, the address formats or the script types. There's PKH addresses which start with ones, compatible SegWit or P2SH addresses which start with threes, and then native SegWit and eventually pay-to-taproot, right? each of those has a little bit of a different, you know, format which you can use to, detect which output might be a change. If your wallet has, is spending from a, a, let's say, a, a native SegWit output, it's very likely that it will generate a native SegWit out-output as change, and if one of The other outputs is to a different address type, then we can assume which one is, is the, the payment and which one is the change. so that's, that's one example that would be, I guess, script, the script heuristic. let me think. and there's, there's a few others. There's, round type payment amounts, right? So in our example, which you had just sort of described, with a ten BTC input and a one BTC payment to me, that nine BTC change won't Nine minus the miner fees. Yep. You know, we would interpret that nine BTC as in change, nine in change, as, as the change back to you."
    },
    {
      "speaker": "stephan",
      "time": "11:21",
      "start": 681.04,
      "text": "Yeah, yeah. So let me just again zoom out a little bit there. So listeners, imagine you were trying to externally chase or watch what somebody else is doing, right? So you don't necessarily know everything they're doing, but if you-- because remember, all these transactions are on the blockchain, you can just download the blockchain. It's about maybe a little bit under four hundred gigabytes right now, so you can just download The chain surveillance firms have specialized tools and techniques to do this, and essentially they are trying to figure out where the flows are going. Okay? Now, I guess there are perhaps-- you could, you could argue that some people are doing it in a white hat way, and some people are doing it in perhaps a black hat way to try to taint coins or to say, \"Oh, these coins are, quote unquote, dirty because they came from the so-called, you know, for example, the Silk Road, dark net market, or whatever that, you know, in-- like people will Do that, but the point being, these heuristics can give off a fingerprint to that chain analyst or the person trying to surveil, right? And so essentially that's why these heuristics matter, because they are what will be used to try to, de-anonymize or try to understand what is-- to try and pierce that veil and see what's actually going on on the chain, so to speak, on, in terms of the transaction graph. so maybe, yeah, if you could just outline a little bit about what is, what is the transaction graph?"
    },
    {
      "speaker": "ergo",
      "time": "12:43",
      "start": 763.14,
      "text": "Transaction graph is, is, a mapping of the UTXO relationships, over multiple transactions. as we described before, you know, the UTXOs, in your wallet will be consumed and then spent in a transaction, and create a new set of UTXO outputs. And so what the transaction graph attempts to do is, is, is visualize kind of those flows. OXT has a, a free transaction graph version. it's one of the only ones that- That I think is out there. There are a few others, but I'm really not quite familiar with them. and this is a, a very common tool that chain analysis will kind of use to, to map those flows over, you know, and, and see if they can't track, you know, a single user."
    },
    {
      "speaker": "stephan",
      "time": "13:29",
      "start": 808.57,
      "text": "Yeah. Okay. And just going back to the heuristics then, as you were saying, so we spoke, we spoke about simple spends. What about sweeps? So when we spend the entirety of a single UTXO to a new address, what is this"
    },
    {
      "speaker": "ergo",
      "time": "13:43",
      "start": 823.18,
      "text": "Sweep, we usually refer to as a transaction with one input and one output. the, the term really derives from sweeping a private key, which is from that sort of original UTXO from one wallet to a new wallet. And when, we do a sw- or when a sweep, or when you observe a sweep, an analyst can kind of make some assumptions about what, what that transaction might be. And because there is no, second output that could be interpreted as change, a simple spend is usually Interpreted as, or a sweep is usually interpreted as a, a self spend, where a user is simply spending to themselves, or possibly spending to some other service where they can keep a balance, for example."
    },
    {
      "speaker": "stephan",
      "time": "14:26",
      "start": 866.16,
      "text": "Right, right. And I guess while we, while we're talking about, this aspect, the heuristics, it's probably also important to mention here that you don't necessarily know for sure just based on the on-chain data, you might need to combine that with other information. could you just explain a little bit around that and what, what does it This is probabilistic type analysis."
    },
    {
      "speaker": "ergo",
      "time": "14:46",
      "start": 885.54,
      "text": "Yeah, so it, a lot of that comes back to the pseudonymity of Bitcoin, right? Bitcoin doesn't include, anyone's personal identification information at the protocol level when a transaction is, is broadcast to the network. So because of that, we now have to use some of these, heuristics for interpreting transactions. And because we're using heuristics, heuristics are kind of rules of thumb, they're kind of shortcuts, mental shortcuts based on typical user behavior and typical- wallet software behavior. and because these are heuristics, they might not be correct. There might be another interpretation to kind of that transaction. We can't really know unless we can potentially get some, you know, additional information that might not be, you know, just, included in that individual transaction. It might be maybe some address reuse, kind of on the output side of that transaction, or maybe it's a spend to a wallet cluster at Coinbase or something like that. And from there, you can sort of narrow down some of those additional interpretat- transaction interpretations and get a better idea of, of, what you think you're observing."
    },
    {
      "speaker": "stephan",
      "time": "15:53",
      "start": 952.78,
      "text": "Right. And as an example, let's say somebody had an open dime and they were claiming that open dime, they were sweeping, right, as we mentioned, the sweep heuristic, and so that could just-- it could just be somebody claiming it, right? And, but the other way is it could be that they are making a donation. So that's maybe another way. So they found, It's a protest in some country under an authoritarian regime or whatever it may be, then they might be donating that. So that's another example where it is a bit probabilistic, but as you point out, that it requires the, and for analysis, it requires looking generally one step back and one step forward to sort of see what happened before that and what happened after that, where did it go? From then, you might have a bit better idea on what was the truth of that matter."
    },
    {
      "speaker": "ergo",
      "time": "16:36",
      "start": 996.33,
      "text": "Yeah, that's exactly correct. Yeah. And so, in the, in the guide, I, I And external transaction data. and so internal transaction data is the information that's only included in that single transaction. You have the input and output addresses, the input and output amounts, and a few other kind of technical parameters. And that information is a good bit limiting, right? And so if you have that example of that sweep, you know, we can't quite tell, right? We might not be-- From, you know, outside of that individual transaction, we might be able to get a better idea of what we think we're observing."
    },
    {
      "speaker": "stephan",
      "time": "17:11",
      "start": 1031.43,
      "text": "Yeah, yeah. So sometimes it re- Requires adding in data obtained from some other means, whether that is another form of surveillance or whether that is some kind of information sharing, and we'll get to some of those as well. So another spend type is called the consolidation spend. So what's that and what's a common interpretation there?"
    },
    {
      "speaker": "ergo",
      "time": "17:28",
      "start": 1047.71,
      "text": "Yeah, so a consolidation transaction is if you have a, a very fragmented kind of UTXO set in your wallet, and you're looking to, you know, maybe save on fees in the future and sort of reduce the, the UTXO set size of your wallet, you might spend all of the Those UTXOs to, to yourself, and this is kind of similar to that simple spend, or that, that sweep, where if we only have one output, then we can kind of make that same assumption that, well, this isn't really quite that true payment fingerprint with an out, a payment and a change output, because we only have that single output, we're either, again, you know, spending the entirety of this, this UTXO set to someone else, or we're spending it to, to kind of ourselves. this is kind of So a little more skinny on the UTXO set size, so that's, that's one of the common places that we see that."
    },
    {
      "speaker": "stephan",
      "time": "18:18",
      "start": 1098.26,
      "text": "Yeah, great example there. And, probably the other bad example is, is if people are consolidating, coming out of a coin join and not aware that they need to make sure that they're maintaining the, the privacy afterwards. But anyway, that's probably a bit more of an advanced conversation, we'll get to that later. there's another heuristic called batch spends. So what's a batch spend?"
    },
    {
      "speaker": "ergo",
      "time": "18:38",
      "start": 1118.05,
      "text": "a batch spend is, And this is a sign of relatively large economic activity. this isn't kind of a typical spend. There aren't very aren't-- there actually aren't very many wallets that can even do a batch spend, but this is a sign of, of kind of large economic activity. And it's typically exchanges that are doing this. And what they'll do is they'll, they'll try to use as few inputs as possible and as many outputs as possible in that transaction to try to save on their miner fees, that will reduce the size of the transaction transaction, and they can make as many payments to their users on chain as kind of possible. So a batch spend is most likely, an example of, exchange activity."
    },
    {
      "speaker": "stephan",
      "time": "19:22",
      "start": 1162.12,
      "text": "Yeah, interesting, hey."
    },
    {
      "speaker": "ergo",
      "time": "19:23",
      "start": 1163.14,
      "text": "You can get a better, idea of that when you look at some of the examples in the guide, batch spend, if you open that up in OXT, we have labels of, of exchanges, and that'll be displayed in that kind of batch spend example, and that'll become a little bit more obvious when you can see the example."
    },
    {
      "speaker": "stephan",
      "time": "19:38",
      "start": 1178.31,
      "text": "Yeah, yeah. So Lots of people are using an exchange and they are buying on that exchange, and now they want to withdraw. And so, a common technique exchanges are, implementing, and it's a good thing they're doing this from a fees point of view, is that they are batching up the withdrawals for those customers. So in this example, there might be one huge UTXO, however many, you know, ten bitcoins, and there's ten customers who are all withdrawing one bitcoin each, just to make the numbers easy, right? And so that's one possibility. Or maybe another possibility might be it's an We are paying out the employees, and they're just doing it in a batch way, right? So that's potentially another possible explanation. But as you quite rightly point out, there's not a lot of wallets that actually support this kind of spend type, so it is a little bit of a giveaway there that this is probably an exchange spend."
    },
    {
      "speaker": "ergo",
      "time": "20:30",
      "start": 1229.55,
      "text": "Yeah, exactly."
    },
    {
      "speaker": "stephan",
      "time": "20:30",
      "start": 1230.27,
      "text": "Okay. And then we've got coin joints. So what does a coin joint look like on chain?"
    },
    {
      "speaker": "ergo",
      "time": "20:35",
      "start": 1234.77,
      "text": "and this, this is kind of one of my last basic examples is a coin joint transaction, which has multiple inputs and multiple outputs, Specifically, will have, many identical outputs, and in the guide we discuss kind of how those, that, that construct works and why it's kind of important, but it does have a relatively distinct kind of on-chain fingerprint,"
    },
    {
      "speaker": "stephan",
      "time": "20:59",
      "start": 1259.41,
      "text": "yeah. And so then when it comes to looking at what's going on, as we were saying, we use those change heuristics to try to understand where were the flows going, and you, some, approaches might be to try to Cluster some of the addresses into certain entities and say, \"Oh, look, that's, you know, that's Binance over there, or that's, you know, this other entity over there, and this, you know, these are some of the individuals that got payouts from that exchange and so on and so forth.\" And that, that's essentially one of the ways that a chain analyst might try to look at this, right?"
    },
    {
      "speaker": "ergo",
      "time": "21:32",
      "start": 1292.01,
      "text": "Yeah, that's one of the ways that they'll try to, you know, maybe leverage some additional external data to kind of aid in their, their"
    },
    {
      "speaker": "ergo",
      "time": "21:43",
      "start": 1303.22,
      "text": "Basic, payment heuristics before for detecting a, a change output. We also, you know, kind of went over the transaction graph, and then you sort of mentioned there kind of wallet clusters, right? Wallet clustering among exchanges. and so wallet clustering is the grouping of multiple addresses that otherwise are relatively unrelated when they are later co-spent in the same transaction. You know, an analyst based on the way most Bitcoin wallets work can make the assumption that all All of those otherwise unique addresses are controlled by the same entity. And as Stefan kind of mentioned earlier, you can take that sort of clustering to the next level, where a, a regular cluster that hasn't been attributed to kind of e- any economic entity, if you can interact with that entity or get any other additional information, then you can then take the, those, those addresses, those clustered addresses, and give them a label as some kind of economic entity like Finance or Coinbase or, or something along those lines."
    },
    {
      "speaker": "stephan",
      "time": "22:41",
      "start": 1360.75,
      "text": "Right. Yeah. And I guess the other thing to think about I mean, whether it's a different exchange, if it's, you know, Swan Bitcoin or Cash App or whoever, but then the other aspect is many Bitcoin exchanges are also using a custodian in the background. So you might think it's that, but actually it's like a custodian, although they would have distinguished, I guess, the accounts for them might be still segregated, obviously. Like, you know, the custodian might not necessarily be putting together, pooling together in this sort of omnibus account, but maybe that's another aspect to consider there for the- Chain analyst."
    },
    {
      "speaker": "ergo",
      "time": "23:14",
      "start": 1394.34,
      "text": "Yeah, exactly. is that sort of broader kind of custody, sort of the Zappo type, you know, broader custody model, if they're sort of underneath that custodial umbrella, you might not sort of see that. but you, what you might see is that on chain, you might see those UTXOs get consumed into that maybe broader, that broader cluster, and if you can figure out that, well, a few of these p-uh, exchanges are using this, this same cluster, well, then, you know"
    },
    {
      "speaker": "stephan",
      "time": "23:44",
      "start": 1423.82,
      "text": "Right, I see, yeah. And there are other pieces of data that can be used to fingerprint things. So, can you give some examples there of other pieces of data that are, so-- that are, I guess, different from just necessarily the transaction graph?"
    },
    {
      "speaker": "ergo",
      "time": "23:59",
      "start": 1439.27,
      "text": "Yeah, so this is a little bit more kind of technical, but there are a few additional pieces of, of information that are included in a transaction. version number, a lock time. And replaced by fee, and there maybe are a few other sort of attributes that go along with the transaction that aren't just the inputs and outputs and amounts that can give us a clue as to, you know, what wallet software we think we might be observing. And there are, you know, different wallets that will have kind of different, or, or will fall under the same kind of fingerprint, you know, so for example, I think, Electrum uses version two and a lock time that's greater than zero. there are a few other wallets that have that sort of fingerprint. So if you see, mul- if you're tracking, an entity over multiple transactions, and you then check the fingerprint of those series of transactions, and you see that the, the, The, the fingerprint, the version number or the lock time changes, you can guess that you're now potentially not following maybe the same entity as you thought you were. There's been a new software introduced into this kind of mix, which can make kind of that tracking a bit more, I don't wanna say difficult, but you know that, there's a possibility that you're, you're dealing with either a new user, a new software at that point."
    },
    {
      "speaker": "stephan",
      "time": "25:23",
      "start": 1523.01,
      "text": "Yeah, good way to put that. And so let me just break that down again. So for listeners who are following along, there Different pieces of software in use. So as an example, the exchange might have been, you know, using a custodian, and that custodian might have been using a different kind of Bitcoin software to create and broadcast the transaction. And based on some of these little clues in terms of how that transaction was constructed and broadcast onto the chain, that might give off, hints to the analyst, \"Oh, what am I dealing with here?\" So as an example, you know, as you're saying, Electrum is a popular wallet, maybe, Specter and Sparrow and Phone wallets, they might have their own little fingerprint, if you will, and so that's also another aspect to be considered when, you're trying to either trace back what's going on on the chain or if you're trying to be more private, you have to think about that also. So the, the, the, I guess there's different approaches there. So in some cases, the idea is to try to make things look the same so that way everything just looks the same, but then another approach is actually to sort of randomize. And in different cases or in different types of data or fields I guess there are different approaches in play. So a quick example would be, I believe there was a bit in relation to, random, output selection. I think it's like making-- so as an example, instead of making the change output always the zero with, you know, the first one, it might be randomized. That's one example."
    },
    {
      "speaker": "ergo",
      "time": "26:49",
      "start": 1608.53,
      "text": "Yeah, exactly. and I think Laurent has-- the, Laurent is the developer of OXT, has written a little bit about kind of this concept of, how do we sort of mitigate some of these fingerprint I think his, his take home is, is that it should be randomized, and if you spend a little bit of time, you know, looking at things on chain, you'll sort of see these patterns start to emerge where, you know, if, we think we're following the same user, where we've got the same version number, we've got the same lock time, we see that, that change UTXO or that change output in that simple spend is always paid to, you know, like your example, the, the, the first, UTXO output, you can become a good bit more, confident that you're, you're tracking the same entity over multiple transactions. And so to break that, you know, we would, you would try to randomize as many of those things as possible."
    },
    {
      "speaker": "stephan",
      "time": "27:43",
      "start": 1663.22,
      "text": "Yeah."
    },
    {
      "speaker": "ergo",
      "time": "27:44",
      "start": 1663.6,
      "text": "What's a"
    },
    {
      "speaker": "stephan",
      "time": "27:44",
      "start": 1663.87,
      "text": "peel chain?"
    },
    {
      "speaker": "ergo",
      "time": "27:45",
      "start": 1664.95,
      "text": "appeal chain is, is that simple spend that we've talked about, one input and two output, that's over, a series of transactions. you can think of it as kind of, monotonically decreasing, that change UTXO amount Amount by each payment. So in our, our previous example, we had a ten in, ten BTC input, a one BTC payment, and a nine BTC change. that nine BTC change will then get used in another transaction, let's say again for one BTC. so there's a one BTC payment and an eight BTC change. So then we had ten, nine, eight, right? That's sort of that, that decreasing kind of UTXO, amount, which is what is kind of characterized as a peel chain. and as we've sort of talked about, you know, this is a, a very, very, very common spend type. about fifty percent of, transactions are these simple spends with one input and two output, and over a series of transactions, they will make, kind of this peeling chain, that is evident on the transaction graph. And I think it's pretty important, the surveillance firms try to frame this as a, a money laundering technique I think they call it structuring, you know? and I think it's really important to hammer home that, well, no, that's, very much basic normal wallet behavior, and to interpret it as money laundering is just absolutely ridiculous. But, so anyway, you, you might see us refer to peel chains in, in some of our previous writing and some of our previous work, but that's kind of the general concept. Right,"
    },
    {
      "speaker": "stephan",
      "time": "29:22",
      "start": 1762.07,
      "text": "right. And let me explain something there as well for listeners. And obviously, I, I totally agree with you there, but I think it That historically, the understanding, at least maybe under in some of the regulators or in some of the banking sectors, they might have thought of it like, \"Oh, see, Bitcoin, everyone just uses the same address, and you're not meant to actually use wallets that actually give you a new address for each payment type. And therefore, your effort to try to use an, what's known as an HD, hierarchical deterministic wallet that makes new addresses each time, that's-- you're trying to obfuscate your behavior, and that's bad because you're now stopping us from being able to assess the- The source of your funds, which is often a regulatory requirement in things like AML and sanctions and things like that, so maybe that's-- I'm not, I'm not excusing their behavior, I'm just trying to, offer a potential explanation of why in their mind they think peer chains are obfuscating when obviously you and I know that's not. And so perhaps this is a good point to also explain the concept around a deterministic spend versus a non-deterministic spend. Could you explain what that means?"
    },
    {
      "speaker": "ergo",
      "time": "30:28",
      "start": 1827.87,
      "text": "Yeah, so we've, we've talked a little bit about some of That we use to interpret kind of these simple spends. We did, you know, address, well, I don't even know if we talked about address reuse, but address reuse is one, the round payment amount and the like type or different script output types, can be used to evaluate what we think might be a payment and what might be a change. but so, and, and an analyst has to, has to kind of make those decisions, right, based on those heuristics. So there's a little bit of uncertainty there that's kind of provided by Bitcoin's anonymity. However, and Stefan's qu- to go back to Stefan's question, which is about what is a deterministic spend, this gets back to that sort of UTXO flow model, which maybe we discussed in a previous, podcast, where that, in that simple spend, we know for a fact that there was only one UTXO. And because there's, you know, and so we know that that one UTXO was used to pay both of the outputs. and so that we consider to be deterministic because it's a one hundred percent certain interpretation. it's the only kind of interpretation of the relationship between that input and both of those outputs is, is that it's deterministic. Yeah, right."
    },
    {
      "speaker": "stephan",
      "time": "31:42",
      "start": 1902.33,
      "text": "And so essentially, when you get to that point where you see that this is a deterministic spend, then that's giving off way- Many more clues to the chain analyst in that, instance because now there's so much less doubt over whether that was, you know, which output was paying which one, well, who-- which one was the change output, as we were, talking about earlier. And I think another important point just to spell out here is this is-- it can seem a bit overwhelming, but what we're talking about here is mainly around the transaction graph and some of the associated points there. There is another whole range of, ways in which our Privacy can be, reduced or lost because exchanges and many other parties have data sharing agreements with the likes of the chain surveillance firms or potentially with the taxation or police and law enforcement agencies as well. So could you outline a little bit around that aspect of it, the data sharing and, the aspect of having a starting point?"
    },
    {
      "speaker": "ergo",
      "time": "32:43",
      "start": 1963.12,
      "text": "Yeah, if we walk it back to that sort of simple spending, example again, if we're trying to guess which output we think Might be, the payment and which one might be the change. If we know that one of those outputs goes to, a, a custodial exchange, then that remaining output is very likely, very obviously, kind of the change output. and so that's where we kind of get back to that external, data and how it can affect the transaction graph and, and how it can reduce the pseudonymity of Bitcoin. so, you know, Stephan brings up some additional points about how the surveillance firms will have- Data sharing agreements where they might, be privy to, who may control an address or a cluster that, you know, somebody else might not be totally privy to. And that will sort of, again, you know, act as that, reducer of the, the privacy provided by that kind of basic ambiguous simple spend. and there's, there's a multiple, multitude of ways that these surveillance firms do share information. They share with exchanges, they share with law enforcement, they share, they- Sibyl the, the Bitcoin network by running malicious Electrum nodes. They, they, they do, a lot of, additional in, you know, information gathering that, you know, somebody like me doesn't have access to, and that can, you know, of course, greatly enhance their, the accuracy of their, their analyses."
    },
    {
      "speaker": "stephan",
      "time": "34:10",
      "start": 2049.63,
      "text": "Yeah. And so then in terms of defending against analysis, and if you are attempting to maintain privacy in Bitcoin, this is where things like Coinjoin, an equal output coinjoin, can come in and, essentially, break that link in a forward privacy sense. So could you just explain a little bit about what it means to break the privacy only in forward, like what's forward privacy?"
    },
    {
      "speaker": "ergo",
      "time": "34:36",
      "start": 2075.55,
      "text": "so we had talked about that deterministic spend ex-spend example, right, where there's a transaction with one input and two outputs, we know for a fact that that one input was used to pay both of those outputs. When you get to an equal output coinjoin transaction, an analyst may be following someone along who's doing deterministic spends, and eventually they may come across, that equal output coinjoin, which effectively addresses that deterministic relationship between inputs and outputs. And the way that a coinjoin will do that is by, including multiple inputs and m- and creating a transaction with multiple like amount outputs. And so as an analyst might be following, a UTXO flow, do-performing a transaction graph analysis, when they come to that coinjoin, they won't know, unless there's some additional, flaws or, or issues with the coinjoin, they won't necessarily know which output can be attributed to that original input. And so the way that, a coinjoin, establishes forward privacy is by Basically introducing doubt into the transaction graph."
    },
    {
      "speaker": "stephan",
      "time": "35:49",
      "start": 2149.47,
      "text": "And so then it can be thought of like a, a reset in some sense, that if you've earned some coins and you now want privacy with those coins in terms of how you spend them, I guess we could say it's a prudent idea to then run it through a coin join before then going on to do your actual spends, going on from that, right?"
    },
    {
      "speaker": "ergo",
      "time": "36:10",
      "start": 2169.95,
      "text": "Yeah. I mean, there's always the concept that, you know, privacy is, is bad and, you know, the, the- Coinjoins are easily identified on chain by their, you know, like type amounts, but, we kind of use the analogy that coinjoin is very much similar to the concept of encryption. We know that encryption, an analyst or an observer may know that encryption is happening because they can't read whatever the, the plaintext, they're seeing that cipher text. they may know that encryption is going on, but they can't reliably interpret what the message is. And so that's what, you know- You know, a coin join will do for you. The analysts will know that the coins were spent forward into that coin join, but they can't reliably, follow, the amounts across that, that coin join. Right. and so, so if you're receiving a payment, right, that one of the, the consequences of, of Bitcoin's very, transparent nature is that sending and receiving payments necessarily reveals some of your UTXO set to your counterparty. So if- If you're doing some type of economic activity or maybe you're a journalist in a, you know, a, a, a despotic third world country who has been deplatformed or maybe you're in a so-called Western democracy and you've been deplatformed by, you know, private companies at the behest of the government, and you are, you know, receiving payments in Bitcoin, someone can evaluate your UTxO's future spending. So if you receive coins, you should coinjoin them to establish that Sort of forward privacy and make it difficult for anyone to, potentially surveil you going forward. Back"
    },
    {
      "speaker": "stephan",
      "time": "37:53",
      "start": 2273.02,
      "text": "to the show in a moment. Have you thought about backing up your Bitcoin wallet? CipherGrid is a new product coming from CipherSafe dot io. This is the best value metal seed Backup product in the industry. You get everything you need for fifty nine dollars. It's two stainless steel plates for all twenty four of your seed words, and you get an automatic center punch to punch in the words, and it's normally four per word. It's stainless steel hardware to hold it all together. You can lock it with a padlock and you get a tamper evidence seal. And just like all CipherSafe products, it's made from stainless steel, it's fireproof, rustproof, and waterproof. So don't just rely on that piece of paper. What if your house went up on fire? What if it wasn't accessible to your heirs or whoever your loved ones were that you wanted to pass it on to? Make sure you've got this covered. Go to CipherSafe dot io and order yours. Use the code Livera to get a discount"
    },
    {
      "speaker": "stephan",
      "time": "38:49",
      "start": 2328.78,
      "text": "So many people in the industry talk about the Coldcard, it's quite a highly recommended device. It's a specialized device used to store your Bitcoin private keys and to sign Bitcoin transactions, and you can use that with a micro SD card so that your Coldcard never has to directly touch a computer, you can plug it to the wall with power. And Coldcard offers all sorts of features. They've got seed export, they've got an address explorer on the device, it supports single signature and multi-signature. It's really an excellent hardware wallet device that you should look into. So go to coinkite dot com and use the code livera to order yours. And finally, Unchained Capital are helping customers upgrade their security to multi-signature. So there's this need to upgrade beyond using a custodian and potentially even using a single-signature wallet. With Unchained, you can create a collaborative custody, two of Three wallet, you hold two keys, Unchained holds the other, and if you're unsure about how to do this setup, it's quite easy, you can go to Unchained dot com and set up an account, or there's a concierge service which is quite popular now, you get two hardware wallets shipped to you, you get video calls, personal one to one guidance to get you set up, even if you've never held your own keys before. So go to Unchained Dash Capital dot com slash concierge and get fifty dollars off with the promo code Livera. Back to the show In my DMs or just in person, sometimes people ask me, \"Oh, so if I just coinjoin on private, right?\" Well, okay, it helps you in a forward transaction graph privacy sense, but we have to remember if you purchase those coins on a KYC exchange, that KYC record still exists. So hypothetically, a hacker could attack that exchange, steal that information, or, a government agency could subpoena that agency or just ask that exchange-- sorry, subpoena that exchange or ask that- Exchange, and in many jurisdictions around the world, regulated entities have to cooperate, they're mandated to, or they are essentially-- it's kind of like a, an understanding that you need to play nice with, with them. So you should assume that, the regulators or law enforcement would be able to get that transaction data and say, \"Oh, look, per- person ABC purchased five bitcoins on this exchange at this date.\" So even if they later went through a coin join, there's still that record existing there."
    },
    {
      "speaker": "ergo",
      "time": "41:05",
      "start": 2465.09,
      "text": "Yeah, I think it's a good point to, to- Remind everyone of that, the activity that you do on chain, will not reach into the exchange's database and delete all of your records. You know, so yes, you might, you might be able to, establish that forward privacy on chain, but the, the records that you leave with, with those regulated entities, you kinda need to be, need to remain cognizant of."
    },
    {
      "speaker": "stephan",
      "time": "41:30",
      "start": 2489.73,
      "text": "Yeah. And so I, I understand that, people might be listening and thinking, \"Oh, hang on, Stefan, aren't you like advertising for KYC services as well?\" Well, I-- at least for me personally, my view is you have to make your own assessment on whether you, you are willing to take that risk because you think you would earn-- you will end up with more sats. So if you think that's, you know, for you, that's, the way you could go about it. I mean, I, I personally have used KYC services,"
    },
    {
      "speaker": "stephan",
      "time": "41:59",
      "start": 2519.39,
      "text": "Stand and appreciate the, the never KYC gang who, say just don't do it, only ever earn or mine or, you know, purchase non-KYC, and in doing so, you are more private. I think that's fair to say, because there's no starting point, or at least you're making it harder for there to be a starting point for that analysis, whereas in a KYC context, you have to consider that."
    },
    {
      "speaker": "ergo",
      "time": "42:20",
      "start": 2539.81,
      "text": "Yeah, and you bring up that, that good point where, an analyst kind of needs a starting point. You know, if you just pull up if any sort of user pulls up a block explorer, samples a random transaction without much context, you know, it, it's kind of mostly noise. but with that starting point, you'll gain a bit of context and, you know, if, if the goal of that, that analysis is to target an entity, you know, you absolutely need that starting point. and so that gets back to, you know, kind of the, the concept of, of the addresses that you provide and where you leave them, right? And, and where that record stays."
    },
    {
      "speaker": "stephan",
      "time": "42:58",
      "start": 2577.77,
      "text": "Right. And it's probably also fair to say that many exchanges and financial institutions have things like data retention laws, that they have to maintain the law, maintain the data on their customers, even I think it's up to seven years after termination of the relationship with that customer. So even if you, let's say, you delete, you said to the exchange, \"Uh, I wanna delete my account and, please delete all my data,\" they might still be mandated by the law to keep that data for seven more years. So something to think about as well, and so I, I think that's There to think about. Obviously, everyone has to make their own assessment. What risks are they comfortable with? What price are they willing to pay in terms of acquiring Bitcoin? 'Cause we all want to acquire it, but it's about what price are we willing to pay? What are we willing to do to get some Bitcoin to earn it, mine it, however you wanna do it, and also another topic that comes up is this concept of confidential transactions. Now, confidential transactions, as it stands today, it doesn't seem likely, at least, you know, as we speak today, in August twenty In the future, this could come, but Ergo, I'm curious your thoughts as a chain analyst, what would the impact be? Would it mean people would still need to use CoinJoin or would they not need to use CoinJoin? What's the, impact analysis there if we were to get confidential transactions on Bitcoin?"
    },
    {
      "speaker": "ergo",
      "time": "44:14",
      "start": 2654.28,
      "text": "So there are, I think, a few different types of confidential transactions. maybe the one that, you know, we should just start with is, is the one that hides the, amounts. Of the UTXO is consumed and, and created in a transaction. and as you sort of walk through the guide, if, if you look at some of the examples that, that I talk about, you know, there's the round number payment heuristic, for example, with confidential transactions, that interpretation kind of goes out the window. there's also the, the, the, the problem, I wouldn't call it a problem, there's also, well, there's also the, the concept that how the, the relationship and the flow is across An individual transaction, can be used to interpret that transaction. And in the guide, I discuss the concept of, Boltzmann, which is the, the privacy algorithm that Laurent created to evaluate CoinJoin transactions. And if amounts become hidden, that analysis is gone as well. we can't really do that, that change detection for some of these, non-one hundred percent entropy CoinJoins. And so really, confidential transac- It would be, you know, it would sort, sort of knock out a bunch of those, those heuristics and those analysis points that we have, at least surrounding just the amounts. Now, the problem is that that doesn't necessarily, address the transaction graph and so if you're still doing maybe these deterministic spends with one input and two outputs, you know, sort of like what you would see on Liquid, that can still be deterministically backtracked, right? You might be able to find someone's peg into that. Into that, you know, kind of side chain. so while the confidential transactions would address a lot of those heuristics and some of those analyses, there needs to be sort of that coinjoin property, that multiple input, multiple output transaction that makes the transaction graph non-deterministic, right? Or at least more sort of noisy, more difficult to evaluate."
    },
    {
      "speaker": "stephan",
      "time": "46:20",
      "start": 2779.59,
      "text": "I see. Yeah. And so essentially what I'm reading from you there is that coinjoins aren't dead, and, you will even- Hypothetically, if we got confidential transactions, we might still use coin joins or something like that, or maybe it might be some sort of batch spending mech-mechanism, some kind of blinded batch spending mechanism, used to create doubt when multiple parties have actually contributed their inputs into a transaction, right?"
    },
    {
      "speaker": "ergo",
      "time": "46:45",
      "start": 2805.33,
      "text": "Yeah, exactly. and, you know, so I, I know I don't have the best understanding of Monero, but my understanding of how their sort of ring signature and, and decoy- Inputs works is that, that's designed to basically address this issue specifically, right? So they still do that even though they have that confidential transactions on their chain."
    },
    {
      "speaker": "stephan",
      "time": "47:05",
      "start": 2825.38,
      "text": "Yeah. And, just to fill in some blanks for listeners as well, you might be thinking, \"Well, hang on, what-- Well, okay, it looks, it sounds like it's pretty good, why can't-- Why don't we get it?\" Well, the reality also is that there are various trade-offs with that as well, and so it may be unclear whether the Bitcoin community would sup-- be supportive of that, because Scalability might take a hit or, there are potential concerns that people might say, \"Oh, okay, there might be an inflation risk and so on beyond the twenty-one million, obviously. \" but obviously many of those things depend on which particular style of confidential transactions we were to go with, but essentially that's the short answer today, that's why we don't have it today because essentially for some of these reasons it was seen like the community, and the Bitcoin users just out there in the world might not go for this change, and so that's where we sit Sure, if technology improves, some other advancement comes along, it might be more feasible at that point. So also wanted to talk about Payjoin. So what's a Payjoin, or, or, or a Stowaway in the Samurai model? What is that?"
    },
    {
      "speaker": "ergo",
      "time": "48:10",
      "start": 2890.14,
      "text": "So this is a, a, a different type of Coinjoin. we have discussed the equal output Coinjoints, which are easily identified on chain by their multiple outputs with the same amounts. that's very similar to encryption, right? We can see it But we can't reliably interpret it. then there's the, a different sort of coinjoin model, which is this payjoin, pay-to-endpoint, you might see that, it's also called stowaway, there are a handful of names, and they all sort of attempt to do, the same thing, on chain. And what they do is they, they involve the payment recipient in the transaction. So if I wanted to pay you, you and I would get together, you would contribute an Input to this transaction, and I would pay you, and we would, basically use our two inputs to create, a new transaction where you get your payment amount and I get my change UTXO. And what that does is that looks very much like, not necessarily a simple spend, but another very basic Bitcoin spend, where, if, for example, I have a, a wallet that has, two UTXOs that are both for, you know, zero point two five, let's say, Bitcoin, and I wanna spend zero point four, neither one of those individual UTXOs is enough to cover that payment amount. So my wallet will select both of those, it will combine them, it'll- Make that zero point four amount, and I'll get my zero point one change. And that's a, another very simple Bitcoin spend, and what that would look like on chain is that would look like, the merged input heuristic or the common input ownership heuristic, that we talked about before, where the, both of those addresses will be clustered by, a, a third party observer, a chain analyst. but when we come back to that sort of pay join model, because you and I are both collaborating to make that transaction We are breaking that common input ownership heuristic, right? The common input own-ownership heuristic assumes that all of the inputs to the transaction are owned by the same entity, but because you and I are working together to make this spend, and we, you might not necessarily have any additional data that can, show that on chain, or distinguish that on chain, a payjoin is indistinguishable from a normal spend. And so to kind of take a full circle, that relates back to the concept of, stegan Anonymity, which is another privacy technique which, which hides the fact that the, the privacy technique is being used, which is in contrast to that sort of encryption, style where, we know it's happening, but we can't reliably interpret it."
    },
    {
      "speaker": "stephan",
      "time": "50:53",
      "start": 3052.61,
      "text": "Right. And so the discussion in the Bitcoin community has been that, oh, okay, well, let's try to increase PayJoint adoption, and in doing so, we might help break the common input ownership heuristic. And so that, I guess, is one potential idea, although So there may be potential even downsides on that as well, because for people to use it at the start, some users might end up in scenarios where they, quote-unquote, get in trouble from, say, a chain surveillance firm, or in reality, a law enforcement or some kind of government, or even just someone else who's using that, chain surveillance incorrectly because they actually applied the common input only heuristic when actually it was a pay join and that, you know, that it, that it led them the wrong way. And so potentially the wrong person might get fingered for something. And so Hypothetically, you did pay join and that person went on to do something bad, then you might actually get in trouble with that too. So I guess it's, it's an im-pr- it's one of those things where obviously I, I want to see more pay join adoption, but I can understand there's also that potential, mental block there for people that they might not wanna feel like they're getting in trouble for something someone else did."
    },
    {
      "speaker": "ergo",
      "time": "51:55",
      "start": 3115.18,
      "text": "Yeah, and that's exactly why, pay join by itself isn't necessarily enough, at least in my view, History forward. the only way to really kind of subvert that forward or, or establish that forward privacy is with sort of an equal output coin join, right? There may be some other additional concepts that are, in theory right now, but that equal output coin join, if you do that, a pay join and then later go on to, do that equal output coin join, you might not be able to be followed forward, so that, that forward privacy is, is kind of really important. And, you know, I guess if I could maintaining your sort of pseudonymity, and maintaining your pseudonymous use of Bitcoin, you wouldn't have to worry so much about, you know, the, the case that Stefan just, just brought up. I see."
    },
    {
      "speaker": "stephan",
      "time": "52:48",
      "start": 3167.85,
      "text": "Yeah, exactly. Because if you, for example, you never gave them a starting point, every time you acquired KYC-acquired Bitcoin, you did it without, without KYC, then Then you can just go right ahead and use Payjoin to your heart's content, because at that point, there's no-- you know, there wasn't any data on you in the start, or at least a lot less data. Obviously, it's always a relative thing with that, we're just trying to talk through the basic idea. And so, I guess it's a similar thing with this concept of coin swap, where it, it might be a similar kind of mental block like we were saying earlier that, quote unquote, the wrong person would get fingered for something and pointed at and"
    },
    {
      "speaker": "stephan",
      "time": "53:27",
      "start": 3206.95,
      "text": "Or coin swap. And so that is, I guess, maybe it's pointing towards this idea that we really have to view things, like you've got to run it through a coin join and then use other tools that are post mix tools. So I guess that's, that's probably the, if I had to try and explain what I think of as the samurai approach, that's essentially what I understand of it. do you have anything to add there or you disagree? Agree?"
    },
    {
      "speaker": "ergo",
      "time": "53:50",
      "start": 3229.79,
      "text": "No, I agree"
    },
    {
      "speaker": "stephan",
      "time": "53:50",
      "start": 3230.43,
      "text": "100%. Gotcha. Yeah. So, Lightning adoption increases and maybe people might, as an example, they might coin join and then put those funds into their lightning node or lightning wallet and open channels from then. So maybe that's another aspect of it as well, and maybe there'll be additional work coming on things like, well, as Taproot, which is, locked in and will activate later this year, that might also contribute to some of the heuristics being, or at least some of the fingerprinting being more difficult longer term once everyone is kind of adopted. Over into the Taproot world, so let's talk a little bit about if somebody wanted to, now, now that we've kind of explained some of the, you know, the key concepts, let's talk a little bit about what it would look like to try and chain surveil ourselves. So can you tell us a little bit about some of the starting points and of course, some of the gotchas, or maybe explain, don't do this on your, normal internet, use, use Tor or, use VPN for that."
    },
    {
      "speaker": "ergo",
      "time": "54:50",
      "start": 3289.51,
      "text": "Yeah, you know if you plug your transaction ID into some, you know, third party, you know, website, third party browser, third party block explorer, that might be associated with whatever IP address that you're using, so use a VPN, use Tor. You know, in, in my opinion, I think, you know, one of the, the biggest things that people should try to do is get familiar with some of what their transactions look like on chain. That gives them some valuable context, they have their own sort of starting point. you know, it'll, it Very likely that whatever their starting point will be, will be that, that batch spend that we discussed earlier,"
    },
    {
      "speaker": "stephan",
      "time": "55:33",
      "start": 3332.86,
      "text": "right, from a KYC exchange withdrawal,"
    },
    {
      "speaker": "ergo",
      "time": "55:35",
      "start": 3335.26,
      "text": "from a KYC exchange, a few inputs, many, many outputs, and you might plug in either your address or your transaction ID into the block explorer, and you're gonna see, you know, this transaction, it's not gonna make very much sense, right? You're just gonna see a ton of addresses and, a ton of different amounts. and that's sort of where kind of OXT can come in,"
    },
    {
      "speaker": "ergo",
      "time": "55:57",
      "start": 3356.97,
      "text": "And labeled, a handful of exchanges, right? And I shouldn't say a handful, many exchanges, certainly not all of them, but that starting point, that context can be very valuable for people when they say, \"Oh, this is exactly what my, my transaction looks like. I'm one hop from this exchange's hot wallet, right?\" i's kind of a, a, a, a probably a what most people will see if they try to start looking at what they've, what their transaction history looks like. and there's a few other"
    },
    {
      "speaker": "ergo",
      "time": "56:27",
      "start": 3386.75,
      "text": "aware of. So one of the others would be kind of address reuse. If they're really not, careful, or maybe they, they've signed up for an exchange and that exchange only lets them input one address, or they've just always used that same address, not really kind of knowing what they're doing, that address will show relatively all of their activity or a significant portion of their activity. you know, so, so those are some, some really kind of basic things that people can start with, right? Is, is looking at maybe kind of what those, what Spending, then we can kinda get into the spending and really receiving payments, we can get into kind of the implications of that as well."
    },
    {
      "speaker": "stephan",
      "time": "57:03",
      "start": 3422.58,
      "text": "Right. Yeah. And yeah, so maybe let's talk a little bit about that. So let's say this user has, let's say the hypothetical user, they have bought on a KYC exchange, they've withdrawn to their mobile wallet, and now they wanted to buy something on a website, what would that look like on chain?"
    },
    {
      "speaker": "ergo",
      "time": "57:16",
      "start": 3436.18,
      "text": "Yeah. So it'll, it'll depend on their UTXO set in their wallet. If they have enough to, to make discussed before, it'll have that payment output and it'll have, that change output. And depending on how your wallet is configured, you might be able to run through, some of the heuristics that we list in the guide and say, \"Oh, look, this is relatively clearly, the, the change output that gets paid back to my own wallet.\" you might be able to even take it a step further and apply some external transaction data and look at how that payment UTXO is spent, right? You can basically s-follow the future spending of The entity that you pay, you can see some additional information about their wallets. And I think when people start to do that, I think the gravity of, of what the transparency of Bitcoin's transaction nature is like, kind of becomes real, will really kind of sink in, right? I mean, in, in the normal financial world, you know, if I wanted to use, I don't know, Venmo to send Stefan five dollars, I couldn't then follow Stefan's, you know, future spending of that five dollars. But you can do that with- With Bitcoin, and it's not great, it's very not good for privacy, so I think that that would kind of, definitely benefit users to, to take it to that level and, and kind of see what they can't find about some of the, the spends that they've made, you know, and, and use that information to, you know, maybe benefit themselves and, you know, help the people that they might have, have also paid or interacted with."
    },
    {
      "speaker": "stephan",
      "time": "58:50",
      "start": 3529.87,
      "text": "Right. And also importantly, depending on how you use Bitcoin, you may be disclosing how many So as an example, if you are keeping all your coins in one address and you just keep withdrawing into that address and then you pay out of that address, then it's very, very obvious, if you pay out of that, you pay that UTXO, it becomes very obvious to your counterparty how much you have, and that could be a big deal if in the future that's a lot of money and potentially you are painting a target on your back at that point."
    },
    {
      "speaker": "ergo",
      "time": "59:18",
      "start": 3558.41,
      "text": "Yeah, I mean, that, that's, you know, so the opposite is true, right? So you, we Their activity forward. Well, if we've done sort of those, one of those simple spends, they can do the reverse, right, to us. They know which, which output was the payment that they received, and they can make the guess that, you know, the, the, the remaining output is the change that was, you know, paid back to the person that they received the payment from. And so then they could track that spending as it goes forward. And as Stefan said, the larger the UTXO, the more often it's used, the more sort of, Of additional data that gets kind of wrapped up with that UTXO."
    },
    {
      "speaker": "stephan",
      "time": "01:00:00",
      "start": 3600.67,
      "text": "Right. So are we totally defenseless or do we have any techniques we can use in our defense here, Ergo?"
    },
    {
      "speaker": "ergo",
      "time": "01:00:06",
      "start": 3606.3,
      "text": "Yeah, of course we do. there's, there's a couple, and so I sort of close the guide with, some of the, the basic samurai wallet tools that, you know, users can, can use to, you know, basically maintain their privacy, as much as possible, as much as Bitcoin will sort of allow. we talked about needing A, an analysis, right? And if we are publishing the addresses that we are using on chain, that is a starting point any analyst. So to address that issue, Samurai Wallet has a version of stealth addresses, which you'll see referred to as BIP forty-seven. I think there's a new version that's coming out that will be under, the Open Bitcoin Privacy projects. They're sort of, I wouldn't call it BIP, but they're sort of, new privacy sort of, standard. we'll see the next version of That, but this is a, a, what I'm talking about is, is a stealth address, that you and I can share between each other, or I could send to you, through whatever kind of means, and you can connect to that, that, that stealth address, establish a payment channel between, or, basically a payment channel between you and I that allows us-- or allows you to generate an infinite number of receive addresses for me. So every time you wanted to pay Ergo, you could find my Paynum, you could, you could- Fire up, the connection, establish the connection, and, that wouldn't allow a third party to, to get a starting point on chain. You would still know that you had paid me, but no other third party would know that. And so we call that kind of the stealth address concept, where the address that gets published isn't the address that shows up on chain. So that's kind of one of the main, main aspects that people can use to defend their privacy. and then we, I, I discussed some of the others. You know, Samurai Wallet has it has some additional spending tools like Stonewall, for example, which is, either a simulated one-party coinjoin or an actual two-party coinjoin. and Stonewall is great for sort of breaking all of the, all of the simple, spend heuristics that I discussed earlier in, in the guide. There's also RippleCoinJoin, which is for really for establishing that forward privacy, doesn't have any change outputs, it doesn't have any real, you know, deterministic link to any of your Previous activity, and the last, well, I shouldn't say last, there's also Payjoin, which we discussed, is a, a different sort of model of coin join, and then there's the Ricochet tool, which, simply adds hops, can still be, is still, you know, fairly useful today."
    },
    {
      "speaker": "stephan",
      "time": "01:02:41",
      "start": 3761.28,
      "text": "Right. Yeah. So, these are a range of techniques that can be used, and maybe if you're get-getting a get-a bit confused 'cause there's all these different names and you're not sure what they all mean Phone, if you don't have one, or, you know, just use your existing Android phone if you don't wanna go to that level, and then you can install Samurai Wallet, you can, receive some Bitcoin into it, you can run it through a coin join, so run it through Whirlpool, so basically that's running it through the equal output coin join, as we spoke about, and then basically when you spend, you wanna be, be, basically using one of those techniques, so that means StoneWall or StoneWall x2, and so think of"
    },
    {
      "speaker": "stephan",
      "time": "01:03:25",
      "start": 3805.53,
      "text": "it, Post mix spending, and so you use one of the post mix tools. So generally this will be like a stone wall or a stone wall x2 where you collaborate with someone. So just to keep it simple, and if, if you're getting started, that's one way that you might make every payment that you're doing, make it a stone wall. And so Samurai Wallet will automatically default to that on if it's available. And so that's one way to, I guess, just slowly dip your toe in the water and get started, and then later on, then you will sort of understand more about these"
    },
    {
      "speaker": "stephan",
      "time": "01:03:56",
      "start": 3836.75,
      "text": "So that's a few ideas, I guess, there for listeners out there who are interested in that. Do you have any tips that you would give for a beginner who maybe hasn't had much exposure to the world of Bitcoin privacy? What sort of things should, should they be thinking about?"
    },
    {
      "speaker": "ergo",
      "time": "01:04:09",
      "start": 3849.76,
      "text": "you know, probably one of the things, and, and we didn't mention this as, as a tool, is to get familiar with the concept of coin control. we discussed kind of that concept of UTXOs very early on at the start of the show. those UTXOs Over all wallet balance that you have. And you should get familiar with knowing that, you know, each one of those UTXOs has a slightly unique history, a unique, previous transaction history. maybe they all came from the same exchange, or maybe they came from different exchanges, or maybe you had your friend send you, you know, fifty bucks 'cause you split dinner. You should get familiar with, with practicing coin control if you can, right? There are a handful of wallets that, that do coin control, Samurai Wallets one of them, You know, so the concept of sort of, you know, when-- as a, a, a UTXO comes in, you give it a label, right? And the label should be, you know, probably consist of who it came from and what that payment was for, kind of at the very least. and then, you know, you can get used to, keeping your coins somewhat separate if they're all-- they all happen to be in the same wallet, and if they have separate histories, you, you might want to do that. So that's kind of,"
    },
    {
      "speaker": "stephan",
      "time": "01:05:26",
      "start": 3926.75,
      "text": "Well, as an example, you might have different sources of Bitcoin income, so you might have bought that, or you might have mined it, or you might have had some earnings on your online store that you're running or whatever way you're using to earn those coins, you might notate that. And so then when you run through the CoinJoin, you might wanna segregate which ones you run through the CoinJoin together. So as an example, when you run through Whirlpool, you might say, \"I wanna do, you know, so there's the hundred, thousand sat pool You might want to run through seven hundred thousand sat or a little bit over that, but you would want to make sure all the inputs going in for that are from the same kind of source, otherwise you're sort of doxing, the cross of those different income sources, aren't you?"
    },
    {
      "speaker": "ergo",
      "time": "01:06:11",
      "start": 3971.26,
      "text": "Yeah, you know, we talked about the, the common input, input ownership heuristic, when you combine coins from separate sources, an analyst will assume that, you know, those, those coins are, you know, belong to the same wallet, you know, so them separate, you can keep the, the relationship between those UTXOs separate. and as Stefan said, you can, you know, fire up a coin join and establish that forward privacy as you're sort of looking to spend in the future."
    },
    {
      "speaker": "stephan",
      "time": "01:06:38",
      "start": 3998.34,
      "text": "Yeah."
    },
    {
      "speaker": "ergo",
      "time": "01:06:39",
      "start": 3999.16,
      "text": "And so"
    },
    {
      "speaker": "stephan",
      "time": "01:06:40",
      "start": 4000.62,
      "text": "also, when, when it comes to spending in the future, do you have any thoughts there on coin joining now versus coin joining into the future? So somebody might be thinking, okay, what if I just buy on a KYC exchange, withdraw it to my cold storage now, and only worry about the coin join stuff in the Would your response or thought be there?"
    },
    {
      "speaker": "ergo",
      "time": "01:06:58",
      "start": 4018.73,
      "text": "Well, you know, it's kind of, a personal, choice. I mean, if you're only ever looking to, you know, hop back in and out and, and capture some gains, maybe you don't really care about your privacy, you know, that's, that's fine. you know, but certainly, your transaction history really doesn't, you know, shouldn't, shouldn't be anybody else's business. I know that there's a little bit of a taboo"
    },
    {
      "speaker": "ergo",
      "time": "01:07:26",
      "start": 4046.89,
      "text": "and people who have things to hide. but we live in this, you know, sort of crazy world now, the solar winds world where, literally everything, is, is packed, compromised, shared without your permission. you know, so establishing that, that sort of forward privacy, you know, sooner rather than later, you know, might be, become a little bit more necessary, sooner rather than people, can even kind of think, but, you know, I mean, it really- It has to be sort of, you know, a personal decision, I think. I mean, if it, you know, and that's, that's just, that's just kind of it, I think."
    },
    {
      "speaker": "stephan",
      "time": "01:08:04",
      "start": 4084.36,
      "text": "Yeah, yeah. And so maybe one way to put it for listeners is if you are interested to, let's say, buy a VPN, that might be an example where you want some privacy from corporate surveillance, and VPNs can potentially help you against that, and you might want to be able to pay for that with Bitcoin. And so then it would be ideal if"
    },
    {
      "speaker": "stephan",
      "time": "01:08:26",
      "start": 4106.75,
      "text": "Pay for it. You use a CoinJoin, you use a Stonewall as an example. So you might have earned some coin, run it through CoinJoin, and then used a Stonewall, to buy or to pay for that VPN. That's one example where you might want that privacy. That is just a, maybe just an easy example for people out there."
    },
    {
      "speaker": "ergo",
      "time": "01:08:44",
      "start": 4124.26,
      "text": "Yeah, exactly. there's a few, services that, few VPNs that accept Bitcoin, and a lot of people are using their credit cards to pay for their, pay for their, Even need to be, accepting credit cards except for their sort of subscription model, but there, there are a few, great kind of VPNs that accept Bitcoin. They don't require any personal information, they, they'll give you, basically a throwaway account number, and it's, it's, it's pretty straightforward. So that's, that's probably a good place for a lot of people to get started if they wanna sort of make their first, you know, semi-private kind of Bitcoin spend, would"
    },
    {
      "speaker": "stephan",
      "time": "01:09:22",
      "start": 4162.95,
      "text": "be, would be buying a Conference and you wanna be able to buy merch and have, you know, buy a t-shirt or whatever, and maybe that's another example where you might be doing little spans here and there, and that's where, again, you can use stonewall and these techniques. Also wondering your thoughts, I guess longer term, if we are anticipating that the block space market, the market, the fee that we have to pay for our transactions rises, do you have any thoughts on what that impact would be on CoinJoin and privacy focused users?"
    },
    {
      "speaker": "ergo",
      "time": "01:09:53",
      "start": 4193.99,
      "text": "I think that, you know, at least with To be pretty well prepared for kind of the high fee environment, users will, get their coins in a whirlpool kind of as quickly as they can or as quickly as they want at times of low fees, and then, you know, because of the incentive model of whirlpool, they get kind of free remixing, so a lot of people are, are incentivized to get their coins in at, at sort of cheap, you know, cheap block space, cheap, cheap transaction fee times, so they can get their privacy and start, you know, You know, as early as they can. you know, but kind of going forward, I mean, what, what will the fee market look like? I mean, supposedly now we're in the, the greatest bull market of history, and, I mean, I haven't checked the mempool today, but, I mean, what's it looking like? Is it, is it--"
    },
    {
      "speaker": "stephan",
      "time": "01:10:39",
      "start": 4239.58,
      "text": "Let me have a look."
    },
    {
      "speaker": "ergo",
      "time": "01:10:40",
      "start": 4240.5,
      "text": "Actually, I have to, I have to look too. But it's been relatively quiet, I think, for the last few weeks,"
    },
    {
      "speaker": "stephan",
      "time": "01:10:45",
      "start": 4245.68,
      "text": "right? Yeah."
    },
    {
      "speaker": "ergo",
      "time": "01:10:52",
      "start": 4252.51,
      "text": "Right now, next And blocks. I mean, we'll, we'll, we'll see. I mean, I'm not sure what is to say that, you know, fees necessarily rise and, you know, sat per byte, you know, sustainably over the long term, who knows? I know that's kind of supposedly the, the model, but I mean, a lot of people are still anchored to fiat world, right? Everyone's still paying their, their electric bill in fiat, you know, at least the miners, that is."
    },
    {
      "speaker": "ergo",
      "time": "01:11:21",
      "start": 4281.31,
      "text": "but, you know, there may be a chance You know, you can, you can say, you know, well, if, if people are kind of struggling with sort of the fee market now, I mean, a lot of people, they, they just wait till kind of blocks kind of clear out, and, and space empties up. Yeah. You know, but if, if we can see something that's kind of sustained for a while, you know, I mean, users will adapt. there are potentially some protocol upgrades, you know, cross input signature aggregation being kind of the big one that would, Right? you know, so that is possibly, implemented at some point in the future. I know it was discussed a while back, but I, I really haven't been keeping up much with, the protocol development lately 'cause there doesn't seem to be too much happening. you know, but, you know, that would, that would be potentially something that could, help ease some of those fee pressures."
    },
    {
      "speaker": "stephan",
      "time": "01:12:16",
      "start": 4336.48,
      "text": "Yep. and I guess while we're at it, a lot of the things we've been talking about today have been in terms of the transaction graph and, Bitcoin on chain and things like that, but let's also recognize that there are other ways that your privacy can be impacted too. It could be, for example, internet surveillance. It could be that, somebody sees the transaction or knows the IP that you used to broadcast your transaction Essentially figure out, oh, based on this IP, we know this ISP owns that block. Let's go ask this ISP, hey, who was using this IP at that time? Oh, boom, it's Stephan Livera or it's Ergo or it's whoever, give us their info, where do they live? And then now all of a sudden they've, they've traced it down quite a bit. So that's probably another example of another area, that to think about also, so do you have any thoughts to add there for listeners?"
    },
    {
      "speaker": "ergo",
      "time": "01:13:06",
      "start": 4386.63,
      "text": "yeah, I"
    },
    {
      "speaker": "ergo",
      "time": "01:13:10",
      "start": 4390.91,
      "text": "Sort of Tor, usage, right? And Tor will mask your IP address, your internet service provider will still know that you're using Tor, you know, because of some of the, I think it's the length of the packets and a few other things that have to do with Tor, but they won't, you know, necessarily know that, you know, maybe that you're broadcasting a Bitcoin transaction. I mean, the same thing goes for, hiding behind a VPN, maybe they'll know that you're using a VPN, but they won't know that you"
    },
    {
      "speaker": "ergo",
      "time": "01:13:41",
      "start": 4421.13,
      "text": "I mean, VPN usage has probably grown a lot, I think, in, in the last, few years, I think, some of the people that I wouldn't expect to be, to see, you know, using VPNs or using VPNs, and that's sort of for different reasons, but, you know, it, it's, you know, it's tough, a lot of people don't fully understand how the internet works, I mean, it's very transparent, it's kind of like Bitcoin,"
    },
    {
      "speaker": "ergo",
      "time": "01:14:07",
      "start": 4447.09,
      "text": "it's,"
    },
    {
      "speaker": "ergo",
      "time": "01:14:11",
      "start": 4451.07,
      "text": "Your, hide your IP address, right?"
    },
    {
      "speaker": "stephan",
      "time": "01:14:13",
      "start": 4453.23,
      "text": "Yeah. And, potentially another idea might be in the future, more commonplace use of this idea of having somebody else broadcast your transaction for you. So I know, for example, there are, I think there are some services right now that do do this. So as an example, if you have, the transaction that hasn't been broadcast yet, that file, you can go and put that up and have somebody else broadcast it from their node. So maybe that's also, some, an area that has opportunities to be explored in the Bitcoin privacy World, what do you think?"
    },
    {
      "speaker": "ergo",
      "time": "01:14:41",
      "start": 4481.75,
      "text": "Yeah, I think at one point, that was called Dandelion."
    },
    {
      "speaker": "stephan",
      "time": "01:14:45",
      "start": 4485.33,
      "text": "well, the, so the Dandelion thing was a little bit different, though. I think that was more like at a node level."
    },
    {
      "speaker": "ergo",
      "time": "01:14:49",
      "start": 4489.8,
      "text": "Yeah."
    },
    {
      "speaker": "stephan",
      "time": "01:14:50",
      "start": 4490.26,
      "text": "Yeah, I mean, you're right, but I think Dandelion got knocked down because of, various other, I think DOS, Do-DOS protections and things. there were some other reasons that the idea got nixed, unfortunately. So"
    },
    {
      "speaker": "ergo",
      "time": "01:15:01",
      "start": 4501.45,
      "text": "Yeah, but I mean, it, I think it still Is that you can take, depending on your wallet, I think it's, it's probably only Bitcoin Core, probably Electrum, and Samurai, you can, get what's called the transaction hex, which is sort of the, The, the broadcastable version of, of your transaction and pop it into, I, I think at least, Blockstream dot info will do this for you. They have, a, a transaction push service where you can just, you know, copy and paste and have Blockstream's node, you know, broadcast the transaction for you."
    },
    {
      "speaker": "stephan",
      "time": "01:15:40",
      "start": 4540.36,
      "text": "Yeah. So that's potentially an idea and maybe we'd see that become more commonplace as well. This is another layer to add on to all of the other techniques that, can be used, but I know I'm conscious as Different concepts. So I guess just keeping it simple, so the simple summary would be, you know, try out the basics and slowly learn a little bit, and from there you can improve your level and try out some of the basics in terms of surveilling yourself. Like so imagine you were to, spend and then try to trace back yourself on the chain using, say, oxt dot me or one of these others using a VPN or Tor, and you can trace back and see, oh, what does it look like to an outside observer? Do you have any final tips there for listeners?"
    },
    {
      "speaker": "ergo",
      "time": "01:16:21",
      "start": 4581.03,
      "text": "No, Guide, there's, there's a handful of examples, we, there's some visuals, right? The transaction graphs in there, and, and I think visuals will always help people. So, you know, give the guy to read, and if you've got any questions, I'm around, typically on Telegram, I'm sort of on Twitter, but, you know, find me on Telegram. And, yeah, I think that's it."
    },
    {
      "speaker": "stephan",
      "time": "01:16:40",
      "start": 4600.75,
      "text": "Fantastic. Well, I'll put all the links in the show notes, and, thank you, Ergo, for joining me"
    },
    {
      "speaker": "ergo",
      "time": "01:16:44",
      "start": 4604.52,
      "text": "on"
    },
    {
      "speaker": "stephan",
      "time": "01:16:46",
      "start": 4606.3,
      "text": "So I hope you enjoyed that episode and found it useful in terms of explaining concepts you may not have heard explained before. So take a chance now and go and explore your own privacy and try to chain surveil yourself. Now of course, use a VPN or Tor when you are doing this, but it's a useful exercise just to learn a little bit about what your Bitcoin on-chain activity looks like to an outside observer. As always, if you enjoyed the show, make sure to give it a rating and review and to share it with your friends, especially those who haven't thought of it. About privacy, they might learn something from this one. Get the show notes at stephanlivera dot com slash two nine seven. Thanks, and I'll see you in the citadels."
    }
  ]
}
