pull down to refresh

@daily_btc_lore | Daily Bitcoin History Threads

July 22, 2011 | 15 years ago today

The Paper That Proved Bitcoin Isn't AnonymousThe Paper That Proved Bitcoin Isn't Anonymous


Bitcoin was two and a half years old on the day this paper was submitted, still trading in the neighborhood of $20 to $30, and there was essentially no academic literature about it yet. Most people who used it took for granted that a system built on public keys instead of names was, by design, anonymous. On July 22, 2011, two researchers in Dublin gave that assumption its first serious academic test, and the result became the founding document of an entire field.

Who Reid and Harrigan WereWho Reid and Harrigan Were

Fergal Reid and Martin Harrigan were researchers at University College Dublin, working at a moment when Bitcoin was still closer to a message board curiosity than a financial asset. There was no venture capital pouring into the space, no regulatory apparatus paying attention, and almost nothing published in peer-reviewed venues about how the system actually behaved once real people started using it. Their paper, titled "An Analysis of Anonymity in the Bitcoin System," was submitted to arXiv that day and later presented at IEEE SocialCom 2011 before being published as a book chapter by Springer in 2013. The arXiv submission itself is still there, timestamped and unchanged, at https://arxiv.org/abs/1107.4524.

Two Graphs, One BlockchainTwo Graphs, One Blockchain

The core insight was that Bitcoin's public transaction history could be turned into a network graph, and in fact into two linked ones. The first had individual transactions as its nodes. The second was built at a higher level of abstraction, with "users" as nodes, where a user was a cluster of public keys the researchers inferred belonged to a single real-world entity rather than a single key.

That inference rested on a heuristic that has since become the backbone of the entire chain-analysis industry: if a single transaction spends from multiple inputs at once, those inputs almost certainly share a common owner, because only someone holding every one of those private keys could produce the signatures needed to spend them together. Applied across enough transactions, this simple rule lets a researcher collapse a sprawling list of pseudonymous addresses into a much smaller set of real actors, all without ever seeing a name on the ledger itself.

Context Discovery: Closing the Gap Between Keys and PeopleContext Discovery: Closing the Gap Between Keys and People

A graph of clustered keys still isn't a name. Reid and Harrigan closed that gap with a technique they called context discovery: cross-referencing their clusters against information that was sitting in plain sight elsewhere on the internet. Posts on the Bitcoin Forum where users voluntarily attached their public keys to their handles, activity around the Bitcoin Faucet, and even Twitter posts all provided the missing link between a cluster of keys and an actual identity or persona. None of this required any privileged access. It was all publicly available, scattered across a handful of places the Bitcoin community of 2011 was already congregating.

Tracing WikiLeaks DonorsTracing WikiLeaks Donors

To demonstrate what the method could actually do, Reid and Harrigan pointed it at WikiLeaks' public Bitcoin donation address. Donors who gave to that address reasonably assumed their contributions were untraceable, since nothing about a Bitcoin transaction reveals a name. Yet by combining the clustering heuristic with context discovery, the researchers showed that a meaningful number of those donors could be linked back to identifiable public presences using nothing more than the blockchain itself and information the donors, or people connected to them, had already posted online.

Tracing a Theft: The allinvain CaseTracing a Theft: The allinvain Case

The paper's second demonstration was arguably even more striking. In June 2011, a Bitcoin Forum user known as allinvain reported that roughly 25,000 BTC, worth about $500,000 at the time with Bitcoin trading near $20, had been stolen from his wallet. Reid and Harrigan used their transaction graph to follow the stolen coins as they moved through the network. The exercise doubled as a public proof of concept: the same transparency that was supposed to make Bitcoin trustless and auditable could also function as a forensic trail, turning a theft into something that could be tracked in the open rather than simply disappearing into the ledger's noise.

The Legacy: Pseudonymous, Not AnonymousThe Legacy: Pseudonymous, Not Anonymous

The paper's lasting influence isn't really about WikiLeaks or allinvain specifically. It's the clustering heuristic itself, the common-input-ownership rule that Reid and Harrigan formalized in 2011, which is the direct ancestor of the tools that chain-analysis firms use today to trace stolen funds, sanctions evasion, and ransomware payments. It's also the reason "pseudonymous, not anonymous" became, and remains, the more precise way to describe Bitcoin: an argument the Bitcoin community is still having, fifteen years and countless privacy proposals later.


Part of an ongoing series on Bitcoin history. This event falls on July 22, 2011.

2 sats \ 1 reply \ @Scoresby 3h -100 sats

This is a cool find! I didn't know about this.