Several researchers have previously hypothesized possible privacy weaknesses in Mimblewimble’s protocol. Today, Ivan Bogatyy, founding partner of Dragonfly Capital, released research demonstrating a precise way to perform an attack on the protocol’s privacy. The vulnerability allows an attacker to overcome Mimblewimble’s techniques used to combat transaction linkability. In live testing on Grin ($GRIN) using only $60/week of AWS spend, Bogatyy was able to unmask the flow of transactions in real time with a 96% success rate. Bogatyy believes the vulnerability is inherent to Mimblewimble, concluding that Mimblewimble’s privacy is fundamentally flawed.
Why it matters: