Tüm makaleler

CoinJoin, Mixers and Privacy Coins

Yayınlandı: 13 Ağustos 2026Anonimlik

Bu makale henüz dilinize çevrilmedi — English dilindeki orijinali okuyorsunuz.

Şu dillerde de mevcut:EspañolРусский中文

CoinJoin, mixers and privacy coins all try to break the link between sender and receiver, and they are routinely lumped together. They should not be. Two of them rearrange a record that stays in a public blockchain forever; the third never writes that record. The difference rarely matters on the day you transact. It matters years later, when an old transaction is examined with tools that did not exist when you made it.

An Anonymous mask in a hood against a green circuit board and binary code

What CoinJoin is, and how it differs from a mixer

A mixer — also called a tumbler — is a service. You send coins to its address, it sends different coins back from a shared pool, minus a fee. In between, your money belongs to someone else.

CoinJoin is not a service at all. It is a way of building a transaction: several participants combine their inputs into one transaction with several outputs, so an outside observer cannot tell which input paid which output. Your coins never leave your wallet, and the signature stays yours.

That makes CoinJoin the honest one of the two. It removes the single largest risk in mixing — handing your money to a stranger. In practice it still needs a coordinator to find you counterparties, and coordinators turn out to be the fragile part, but the custody problem is genuinely solved.

What CoinJoin does not solve is the one both approaches share: the result is still a public transaction on an open ledger. It will sit there for as long as the network exists, available to anyone who wants another look.

Is CoinJoin traceable?

Not directly, and that is the wrong question to ask about it.

Nobody breaks a CoinJoin by inspecting the transaction itself; the ambiguity is real. What analysts do instead is work around it. They look at what went in and what came out — amounts, timing, how the outputs were later spent, whether change was merged with a known address, whether the same wallet reused a coordinator in a recognisable pattern. Each of those is a probability, and probabilities accumulate.

The important part is that this analysis is retrospective and open-ended. The transaction does not expire. A CoinJoin from 2019 can be revisited in 2029 by better software, with more reference data, and with exchange records that did not exist at the time. Privacy that decays is a delay, not a defence.

Five reasons mixing does not protect you

You hand your coins to a stranger. For the duration of a mix, the operator owns your money. If they vanish, make a mistake, or have their servers seized, there is nobody to ask for it back. This one applies to mixers, not to CoinJoin.

The mix is analysed after the fact. See above. This is the argument that actually matters, and it applies to both.

Mixed coins get flagged. Exchange compliance systems tag addresses associated with known mixers, and the deposit gets frozen on arrival — before anyone asks who you are. Privacy that ends with your funds stuck at a venue has not solved your problem.

Services have operators, and operators are prosecuted. A mixer is a business with a legal entity, servers and a person in charge. All of it gets seized, and so does whatever data was kept. "We keep no logs" is verified exactly once, and not by you.

The anonymity set is small. You can only hide in a crowd. A mixer's crowd is whoever happened to be mixing alongside you — hundreds of people per round at best. The smaller the service, the clearer the result.

What happened to mixers and coordinators since 2023

These are not hypothetical risks. Dates and figures below come from Europol, the US Department of Justice and the IRS.

Bitcoin Fog. A jury convicted Roman Sterlingov in March 2024; he was sentenced to 12.5 years with $395 million forfeited. The case was built on reconstructing transfers made years before the investigation began. The reliability of that analysis was contested by the defence and the argument is not settled — but the lesson for a user does not depend on how it ends. Old transactions were taken apart long after the fact.

ChipMixer. On 15 March 2023, German and US authorities with Europol support seized four servers, 7 TB of data and 1,909 bitcoin — roughly €44 million. The service had run since 2017.

Samourai Wallet. The founders were arrested in April 2024. In July 2025 they pleaded guilty to conspiring to run an unlicensed money transmitting business, and in November 2025 received five and four years. More than $237 million in criminal proceeds had passed through the service.

Wasabi Wallet. On 1 June 2024 the developer shut down its own CoinJoin coordinator, citing legal uncertainty. The wallet still works; coinjoins through that coordinator do not. Trezor Suite and BTCPayServer users lost the feature along with it.

eXch. German police seized the service's infrastructure on 30 April 2025 — €34 million and 8 TB of data — one day before it was due to close voluntarily.

Cryptomixer. Between 24 and 28 November 2025, Swiss and German authorities with Europol took three servers, the domain, €25 million and 12 TB of operational data. About €1.3 billion had moved through it since 2016.

Tornado Cash sits apart, because it is immutable smart contracts rather than a company. The US Treasury sanctioned it in August 2022; in November 2024 an appeals court held that immutable code cannot be "property", and the sanctions were lifted in March 2025. Its developer is being prosecuted separately: in August 2025 a jury convicted him on one count of three and deadlocked on the other two, with a retrial sought for autumn 2026. That case is not over.

Six services in three years. The eight terabytes of data taken from one of them is a useful measure of what "we keep no logs" is worth.

Which cryptocurrencies are actually private

The list is shorter than most rankings suggest, and the coins on it do not work the same way.

Monero (XMR) — privacy is mandatory and on by default for everyone. There are no transparent transactions: the sender is hidden by a ring signature, the receiver by a one-time stealth address, the amount by RingCT confidential transactions. There is no setting to forget.

Zcash (ZEC) — stronger cryptography, but optional privacy. It has two address types: transparent ones behave like bitcoin and are fully visible; shielded ones hide everything. Users choose, and most historically chose transparent. There is a full walkthrough in our piece on how to check a Zcash transaction.

Dash — appears on "anonymous coin" lists out of habit. Its PrivateSend is a form of mixing layered on top of an ordinary open ledger, which puts it structurally closer to a mixer than to Monero. Its own developers dropped the privacy-coin positioning years ago.

The distinction between the first two and the third is not cipher strength. It is which layer the privacy lives on — inside the protocol, applied as the transaction is made, or bolted on top of records that are already public. Everything said above about mixing applies to the bolted-on kind.

What a privacy coin does differently

Monero uses three mechanisms at once. A ring signature mixes your real input with decoys so an observer cannot tell which one was spent. A stealth address is generated fresh for every payment, so a recipient's address never appears twice on the chain. RingCT hides the amount while still proving that inputs and outputs balance.

Three practical consequences follow:

  • there is no intermediary — the coins never leave your wallet, so there is nothing to seize or lose;
  • there is no public record to come back to in five years with a better tool;
  • the anonymity set is every transaction on the network, not the handful that mixed alongside yours.

How well that holds up is best measured by other people's efforts. In 2020 the US tax authority offered a bounty of up to $625,000 for a Monero tracing tool and awarded $1.25 million in contracts to blockchain analytics firms. No cryptographic break has been publicly demonstrated since. The same firms support Zcash and Dash; Monero remains a blind spot for them.

One honest caveat: this does not mean Monero users are never identified. They are — and never through the chain itself. Every publicly documented case has relied on metadata, an IP address, or KYC records held by an exchange. Which brings us to the part you control.

Using privacy properly: where it actually leaks

The cryptography does its job. The rest is habits, and the mistakes are the same for everyone.

Returning funds to the same account. You withdraw from a verified exchange, route through a private coin, and deposit back to the same account. The file on you is not broken, it is extended: same identity, same account, a tidy pause in the middle.

Matching amounts. 0.847 BTC leaves; an hour later 0.845 BTC appears somewhere. That pair links itself with arithmetic, no cryptography required. Round the figures and split them up.

Matching timing. Swapping immediately after receiving funds is the most visible correlation of all. It works even when nothing else does.

The network layer. A coin hides the contents of a transaction, not your IP address. A wallet that connects directly from your home line tells the node on the other end where the transaction came from. Run your own node, and reach the network over Tor.

Transparent Zcash addresses. Holding ZEC on a t-address and assuming the coin protects you is the classic error with that coin. It is waiting to be asked.

A published address. An address that has ever appeared next to your name — in a listing, a profile, a message — makes its entire history public, backwards and forwards.

The pattern is worth stating plainly: leaks happen at the boundaries. Where a private coin meets an open blockchain, an exchange, your IP address, or your name.

Is CoinJoin illegal? And what changes in 2027

Collaborative transactions are not illegal as such, and no court has held otherwise. What has been prosecuted is running a service: the charge in the Samourai and Tornado Cash cases was operating an unlicensed money transmitting business, not writing or using privacy software. That distinction is why coordinators keep shutting down while the underlying technique does not.

Privacy coins are being handled differently — not banned, but pushed off regulated venues. OKX delisted Monero in January 2024 and Binance in February, with withdrawals closing that May. In the EU, Article 79 of the anti-money-laundering regulation takes effect on 10 July 2027: obliged entities, crypto services included, will be barred from keeping anonymous accounts or handling anonymity-enhancing coins.

Read that carefully, because headlines get it wrong. It restricts platforms, not individuals. Owning privacy coins, holding them in a self-custody wallet and transacting peer-to-peer are not criminalised. What changes is where you can buy and sell them, not whether you may use them.

Swapping without a mixer

The practical conclusion: the job people go to a mixer for is done by swapping into a private coin, without handing custody to anyone.

An exchange that requires no registration spares you a second file: no account means no record tying your identity to your addresses. Where verification is required by law and where it is not is unpacked separately: crypto exchange without KYC.

If XMR is what you need, the steps and the real costs are covered separately in how to buy Monero anonymously, and the most common route — bitcoin to Monero — has its own page with the live rate and limits. Other pairs and rates are on the rates page; swapping needs no account, and the mechanics of an order are answered in the FAQ.

In short

Mixing and privacy coins solve the same problem at different layers. A mixer or a CoinJoin rearranges a public record that stays on the chain forever and reads better every year; a mixer additionally requires trusting a stranger and leaves a mark that gets your deposit frozen. A privacy coin never creates that record: Monero hides sender, receiver and amount, and hides them for everyone at once. Six major services have been taken down in three years, and no one has publicly broken Monero despite being paid to try. But the coin only protects the contents of a transaction — send the same amount back to the same verified account and your privacy ends there, not on the blockchain.

Paylaş: