Breaking Mimblewimble’s Privacy Model

Several researchers have previously hypothesized possible privacy weaknesses in Mimblewimble’s protocol. Today, Ivan Bogatyy, founding partner of Dragonfly Capital, released research demonstrating a precise way to perform an attack on the protocol’s privacy. The vulnerability allows an attacker to overcome Mimblewimble’s techniques used to combat transaction linkability. In live testing on Grin ($GRIN) using only $60/week of AWS spend, Bogatyy was able to unmask the flow of transactions in real time with a 96% success rate. Bogatyy believes the vulnerability is inherent to Mimblewimble, concluding that Mimblewimble’s privacy is fundamentally flawed.

Why it matters:

  • This is a known vulnerability of the Mimblewimble protocol. Developers designed Dandelion and full-block cut-through aggregation to prevent linkability, but both rely on a large participant base (more users makes linking transactions or becoming a supernode more impractical), which is lacking in the early days of Mimblewimble projects.
  • While transaction linkability may be compromised by this vulnerability, transaction amounts are still hidden. Privacy is just one feature Mimblewimble promises, with the other being scalability.
Let us know what you loved about the report, what may be missing, or share any other feedback by filling out this short form. All responses are subject to our Privacy Policy and Terms of Service.
Mentioned Assets

Suggested Research Based on your Watchlists

Create a new watchlist
Mentioned Assets