United States: An Untraceable Currency? Bitcoin Privacy Concerns

Bitcoin is often portrayed as an untraceable method of payment that facilitates illicit activities by enabling criminals to make and receive payments without being tracked. This depiction implies that users transacting in bitcoin can do so completely anonymously — that their identities will not be exposed. However, that is not necessarily the case. While bitcoin offers increased privacy compared to traditional payment methods involving a third-party intermediary such as a credit card provider, it is still not as anonymous as a cash transaction. In fact, there are many ways a person's identity could potentially be exposed in bitcoin transactions.

An Overview of the Blockchain

Bitcoin is not anonymous. As we explain below, it is pseudonymous — an important distinction. It is also a decentralized, peer-to-peer digital currency, having no third-party intermediary (for instance, a credit card issuer, merchant processor or bank) that is involved to verify a transaction between a buyer and seller. Since there is no third party, there must be another way to verify a transaction between two users and avoid the "double-spending" problem (i.e., a way of ensuring that a user does not spend bitcoin they have previously transferred).

This is where the blockchain, the truly revolutionary aspect of cryptocurrencies such as bitcoin, comes into play. A blockchain is a public, distributed ledger, in which every transaction is recorded. Unlike traditional payment systems in which the ledger is maintained by a single third party, a blockchain ledger is distributed across a group of computers (thousands of them), each with its own copy of the blockchain transactions. Each block of transactions in a blockchain is confirmed by users in the peer-to-peer network, called "miners," who compete to solve a complex computational problem. The first successful miner to validate the transaction broadcasts it to the network, which then checks the results. Once checked, the new transactions are added as a new block to the blockchain. In the case of bitcoin, the miner who first successfully verified this transaction gets rewarded by the network with newly created bitcoins. As of July 2016, the reward was reduced from 25 to 12.5 bitcoins, and it is expected that the reward will be further reduced to 6.25 bitcoins in 2021.

Anonymity vs. Pseudonymity

Because the bitcoin blockchain is a permanent public record of all transactions accessible by anyone at any time, it is not anonymous. Instead, the transactions in the blockchain are encrypted with public key cryptography that masks the real identities of the individuals behind the transactions. This makes bitcoin pseudonymous. In each bitcoin transaction, each user is assigned two digital keys: (1) a public key or address — the address is actually a hash derived from the public key, but for purposes of this article, we use these terms interchangeably — which everyone can see and is published on the bitcoin blockchain, and (2) a private key, which is only known to the user and is the user's "signature." The private key is used by others to verify that the transaction was in fact signed by that user. The bitcoin blockchain will only show that a transaction has taken place between two public keys (an identifier of 34 random alphanumeric characters), indicating the time and amount of the transaction.

Tracing Bitcoins Back to Individuals

Encryption might create the impression that these transactions are viewable but unmatchable to specific individuals. However, bitcoin is not as untraceable as encryption may imply. Tying an encrypted transaction to an actual individual is possible — it is not a remote risk. There are several ways this could occur.

Users who rely on a bitcoin trading exchange (such as Bitfinex, Binance or Kraken) to exchange currency for bitcoin have to divulge their personal information to that exchange to create an account. The information collected by the exchange varies, but normally includes, at a minimum, a user's first and last name, and, possibly, a phone number. The exchange may also collect a user's IP address. If these exchanges were subject to a data security breach, a user's personal information could be exposed. In addition, some centralized exchanges offer to manage users' bitcoin funds and users' private keys on their behalf.

There are also online wallet service providers that manage users' wallets on their behalf. A wallet is a software program that stores a collection of a user's public and private key pairs. The storage of private keys makes these centralized exchanges, and online wallet service providers, prime targets for criminals because, as discussed above, anyone with access to a user's private key will be able to create a valid bitcoin transaction. A hacker who accesses a user's private key can send all of that user's bitcoins to him or herself, or to any intermediary of their choosing. There have been several high-profile breaches of exchanges in the past, including the February 2014 hack of Mt. Gox, once the world's largest bitcoin exchange. The Mt. Gox attack resulted in a loss of 850,000 bitcoins then valued at $450 million. Thus, hackers who gain control over a user's exchange or online wallet account not only gain access to a user's personal information and transaction history but also to a user's bitcoin funds.

Exchanges are also increasingly subject to regulatory requirements that could lead to government entities accessing a user's personal information. Bitcoin valuation plunged recently when the U.S. Securities and Exchange Commission released a statement warning that online platforms trading digital assets that meet the definition of "securities" would be considered exchanges under the securities laws and need to register with the SEC or show exemption from registration. Although the SEC has not taken any action to date, this means that cryptocurrency exchanges could be subject to the stringent securities regulations applicable to national securities exchanges. Similarly, South Korea announced greater regulation of bitcoin earlier this year. Under the new South Korean regulation, users will only be able to deposit into their exchange wallets if the name used on the exchange matches the name on the user's bank account. Exchanges are also already subject to certain legal requirements, such as responding to subpoenas, which could require them to share personal information with governmental authorities if required by law. For instance, the U.S.-based exchange Coinbase was recently ordered by a court to turn over to the Internal Revenue Service information regarding approximately 14,000 of its customers. A brief review of several exchanges' online privacy policies indicates that exchanges will share a user's information as needed to comply with their legal and regulatory obligations.

Blockchain Analytics

It is also possible to identify users simply by analyzing transactions on the blockchain. Companies like Elliptic and Chainanalysis have built businesses based on blockchain forensics. These companies use analytics on the bitcoin blockchain to link bitcoin addresses to web entities and help their customers assess the risk of illegal activities. Their customers include exchanges but also government entities. In fact, it became public last year that the IRS is using Chainanalysis's software to track potential tax evaders.

Several studies have also shown that it is possible to use network analysis and other methods to observe and potentially tie back blockchain transactions to certain websites and individuals. Specifically, one 2013 study by researchers at the University of California, San Diego and George Mason University showed that it was possible to tag bitcoin addresses belonging to the same user by using clustering analysis of bitcoin addresses. A small number of private transactions with various services were used to identify major institutions (such as exchanges or large websites). From there, the researchers were able to get information on the structure of the bitcoin network, where transaction funds are going and which organizations are party to it. Another study by researchers at ETH Zurich and NEC Laboratories Europe that looked at bitcoin transactions in a small university sample found that using behavior-based clustering techniques could unveil in a typical university environment the profiles of up to 40 percent of the users.

How Bitcoin Users Can Enhance Their Privacy

Despite these privacy issues, bitcoin users need not despair — there are ways to enhance one's privacy on the bitcoin blockchain. First, a bitcoin user can use a new bitcoin address for each transaction and will thus receive a new public key for each transaction, making it more difficult to trace one specific individual's transactions to the same address. This is actually the approach that was envisioned by Satoshi Nakamoto, bitcoin's pseudonymous (and still unknown) founder, who recommended in the paper that first introduced bitcoin using "a new key pair ... for each transaction to keep them from being linked to a common owner." Second, a bitcoin user can take some additional precautions to minimize the risk of traceability on third-party exchanges. The user could use the anonymous Tor browser to access the exchange and create an account without including any real personal information; the user's IP address and personal information would not be exposed. Third, the user could avoid storing bitcoins in online third-party wallets, and only use offline desktop wallets; that reduces the exposure to exchange hacks. Fourth, bitcoin mixing algorithms, such as CoinJoin, link users and allow them to pay together such that the bitcoins are mixed. This makes it harder to identify a particular user because only a group of transactions is published on the blockchain (although studies and research have shown that even CoinJoin presents weaknesses and could allow linking back to a particular individual).

The Monero Alternative

These privacy issues have not gone unnoticed and alternative cryptocurrencies with an increased privacy focus have emerged. Monero is the most prominent of these alternatives. Unlike the bitcoin blockchain, which, as we have noted, is based on a two-key (public and private key) cryptography, the Monero blockchain is based on unique one-time keys and ring signatures. With ring signature technology, the actual signer is pooled together with a group of possible signers, forming a "ring." This creates a distinctive signature that can authorize a transaction. When an individual initiates a Monero transaction, the verifier is able to establish that a transaction came from a group but is not able to determine the identity of the initiator whose private key was used to produce the signature. As a result, the Monero blockchain does not identify a specific sender, and the receivers' addresses and the transaction amounts are hidden. Monero has become the cryptocurrency of choice for privacy-focused users.

Although bitcoin is a decentralized and unregulated payment method, users should understand that this does not mean that their bitcoin transactions are anonymous and hidden from scrutiny. The public nature of the blockchain combined with the increasing threat of government regulation can lead to the identification of users engaged in transacting the currency.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

To print this article, all you need is to be registered on Mondaq.com.

Click to Login as an existing user or Register so you can print this article.

Authors
Events from this Firm
7 Jan 2019, Other, California, United States

Learn how to effectively take an HR department paperless while protecting company information and complying with ‘personnel file’ disclosure laws.

21 Jan 2019, Speaking Engagement, California, United States

Now entering its fifth year, the Pocket Gamer Connects events series has grown to become the biggest and most influential mobile games conference in the west as well as th​e biggest games event overall in the UK and Helsinki.

28 Jan 2019, Other, California, United States

Legalweek New York is the week in which various segments of the legal industry gather to explore the Business and Regulatory Trends, Technology and Talent drivers impacting the industry.

 
In association with
Related Topics
 
Related Articles
 
Related Video
Up-coming Events Search
Tools
Print
Font Size:
Translation
Channels
Mondaq on Twitter
 
Register for Access and our Free Biweekly Alert for
This service is completely free. Access 250,000 archived articles from 100+ countries and get a personalised email twice a week covering developments (and yes, our lawyers like to think you’ve read our Disclaimer).
 
Email Address
Company Name
Password
Confirm Password
Position
Mondaq Topics -- Select your Interests
 Accounting
 Anti-trust
 Commercial
 Compliance
 Consumer
 Criminal
 Employment
 Energy
 Environment
 Family
 Finance
 Government
 Healthcare
 Immigration
 Insolvency
 Insurance
 International
 IP
 Law Performance
 Law Practice
 Litigation
 Media & IT
 Privacy
 Real Estate
 Strategy
 Tax
 Technology
 Transport
 Wealth Mgt
Regions
Africa
Asia
Asia Pacific
Australasia
Canada
Caribbean
Europe
European Union
Latin America
Middle East
U.K.
United States
Worldwide Updates
Registration (you must scroll down to set your data preferences)

Mondaq Ltd requires you to register and provide information that personally identifies you, including your content preferences, for three primary purposes (full details of Mondaq’s use of your personal data can be found in our Privacy and Cookies Notice):

  • To allow you to personalize the Mondaq websites you are visiting to show content ("Content") relevant to your interests.
  • To enable features such as password reminder, news alerts, email a colleague, and linking from Mondaq (and its affiliate sites) to your website.
  • To produce demographic feedback for our content providers ("Contributors") who contribute Content for free for your use.

Mondaq hopes that our registered users will support us in maintaining our free to view business model by consenting to our use of your personal data as described below.

Mondaq has a "free to view" business model. Our services are paid for by Contributors in exchange for Mondaq providing them with access to information about who accesses their content. Once personal data is transferred to our Contributors they become a data controller of this personal data. They use it to measure the response that their articles are receiving, as a form of market research. They may also use it to provide Mondaq users with information about their products and services.

Details of each Contributor to which your personal data will be transferred is clearly stated within the Content that you access. For full details of how this Contributor will use your personal data, you should review the Contributor’s own Privacy Notice.

Please indicate your preference below:

Yes, I am happy to support Mondaq in maintaining its free to view business model by agreeing to allow Mondaq to share my personal data with Contributors whose Content I access
No, I do not want Mondaq to share my personal data with Contributors

Also please let us know whether you are happy to receive communications promoting products and services offered by Mondaq:

Yes, I am happy to received promotional communications from Mondaq
No, please do not send me promotional communications from Mondaq
Terms & Conditions

Mondaq.com (the Website) is owned and managed by Mondaq Ltd (Mondaq). Mondaq grants you a non-exclusive, revocable licence to access the Website and associated services, such as the Mondaq News Alerts (Services), subject to and in consideration of your compliance with the following terms and conditions of use (Terms). Your use of the Website and/or Services constitutes your agreement to the Terms. Mondaq may terminate your use of the Website and Services if you are in breach of these Terms or if Mondaq decides to terminate the licence granted hereunder for any reason whatsoever.

Use of www.mondaq.com

To Use Mondaq.com you must be: eighteen (18) years old or over; legally capable of entering into binding contracts; and not in any way prohibited by the applicable law to enter into these Terms in the jurisdiction which you are currently located.

You may use the Website as an unregistered user, however, you are required to register as a user if you wish to read the full text of the Content or to receive the Services.

You may not modify, publish, transmit, transfer or sell, reproduce, create derivative works from, distribute, perform, link, display, or in any way exploit any of the Content, in whole or in part, except as expressly permitted in these Terms or with the prior written consent of Mondaq. You may not use electronic or other means to extract details or information from the Content. Nor shall you extract information about users or Contributors in order to offer them any services or products.

In your use of the Website and/or Services you shall: comply with all applicable laws, regulations, directives and legislations which apply to your Use of the Website and/or Services in whatever country you are physically located including without limitation any and all consumer law, export control laws and regulations; provide to us true, correct and accurate information and promptly inform us in the event that any information that you have provided to us changes or becomes inaccurate; notify Mondaq immediately of any circumstances where you have reason to believe that any Intellectual Property Rights or any other rights of any third party may have been infringed; co-operate with reasonable security or other checks or requests for information made by Mondaq from time to time; and at all times be fully liable for the breach of any of these Terms by a third party using your login details to access the Website and/or Services

however, you shall not: do anything likely to impair, interfere with or damage or cause harm or distress to any persons, or the network; do anything that will infringe any Intellectual Property Rights or other rights of Mondaq or any third party; or use the Website, Services and/or Content otherwise than in accordance with these Terms; use any trade marks or service marks of Mondaq or the Contributors, or do anything which may be seen to take unfair advantage of the reputation and goodwill of Mondaq or the Contributors, or the Website, Services and/or Content.

Mondaq reserves the right, in its sole discretion, to take any action that it deems necessary and appropriate in the event it considers that there is a breach or threatened breach of the Terms.

Mondaq’s Rights and Obligations

Unless otherwise expressly set out to the contrary, nothing in these Terms shall serve to transfer from Mondaq to you, any Intellectual Property Rights owned by and/or licensed to Mondaq and all rights, title and interest in and to such Intellectual Property Rights will remain exclusively with Mondaq and/or its licensors.

Mondaq shall use its reasonable endeavours to make the Website and Services available to you at all times, but we cannot guarantee an uninterrupted and fault free service.

Mondaq reserves the right to make changes to the services and/or the Website or part thereof, from time to time, and we may add, remove, modify and/or vary any elements of features and functionalities of the Website or the services.

Mondaq also reserves the right from time to time to monitor your Use of the Website and/or services.

Disclaimer

The Content is general information only. It is not intended to constitute legal advice or seek to be the complete and comprehensive statement of the law, nor is it intended to address your specific requirements or provide advice on which reliance should be placed. Mondaq and/or its Contributors and other suppliers make no representations about the suitability of the information contained in the Content for any purpose. All Content provided "as is" without warranty of any kind. Mondaq and/or its Contributors and other suppliers hereby exclude and disclaim all representations, warranties or guarantees with regard to the Content, including all implied warranties and conditions of merchantability, fitness for a particular purpose, title and non-infringement. To the maximum extent permitted by law, Mondaq expressly excludes all representations, warranties, obligations, and liabilities arising out of or in connection with all Content. In no event shall Mondaq and/or its respective suppliers be liable for any special, indirect or consequential damages or any damages whatsoever resulting from loss of use, data or profits, whether in an action of contract, negligence or other tortious action, arising out of or in connection with the use of the Content or performance of Mondaq’s Services.

General

Mondaq may alter or amend these Terms by amending them on the Website. By continuing to Use the Services and/or the Website after such amendment, you will be deemed to have accepted any amendment to these Terms.

These Terms shall be governed by and construed in accordance with the laws of England and Wales and you irrevocably submit to the exclusive jurisdiction of the courts of England and Wales to settle any dispute which may arise out of or in connection with these Terms. If you live outside the United Kingdom, English law shall apply only to the extent that English law shall not deprive you of any legal protection accorded in accordance with the law of the place where you are habitually resident ("Local Law"). In the event English law deprives you of any legal protection which is accorded to you under Local Law, then these terms shall be governed by Local Law and any dispute or claim arising out of or in connection with these Terms shall be subject to the non-exclusive jurisdiction of the courts where you are habitually resident.

You may print and keep a copy of these Terms, which form the entire agreement between you and Mondaq and supersede any other communications or advertising in respect of the Service and/or the Website.

No delay in exercising or non-exercise by you and/or Mondaq of any of its rights under or in connection with these Terms shall operate as a waiver or release of each of your or Mondaq’s right. Rather, any such waiver or release must be specifically granted in writing signed by the party granting it.

If any part of these Terms is held unenforceable, that part shall be enforced to the maximum extent permissible so as to give effect to the intent of the parties, and the Terms shall continue in full force and effect.

Mondaq shall not incur any liability to you on account of any loss or damage resulting from any delay or failure to perform all or any part of these Terms if such delay or failure is caused, in whole or in part, by events, occurrences, or causes beyond the control of Mondaq. Such events, occurrences or causes will include, without limitation, acts of God, strikes, lockouts, server and network failure, riots, acts of war, earthquakes, fire and explosions.

By clicking Register you state you have read and agree to our Terms and Conditions