At the Initiative for Cryptocurrencies and Contracts, we have explored the ways cryptocurrency systems protect users' anonymity. Anonymity in cryptocurrencies is fueling crime by enabling criminals to evade identification by law enforcement. We believe that this problem will get worse as cryptocurrencies evolve stronger privacy protections and become more flexibly programmable. We also believe there's no simple solution.
The first major cryptocurrency, bitcoin, allows users to conceal their names. But users' transaction amounts and bitcoin account numbers (known as "addresses") are visible to anyone - even people who don't use bitcoin but know how to read the transaction ledger.
This approach offers more privacy than credit cards and bank accounts, even against powerful entities like governments who might try to trace money obtained by criminals. Bitcoin's privacy both attracts users - law-abiding and otherwise - and raises law enforcement agencies' suspicions.
It is true that bitcoin and other cryptocurrencies create opportunities for tax evasion, ransomware and illicit marketplaces selling everything from narcotics to illegal arms. Some concerns, though, like the potential uses for terrorists, are probably overblown.
When crimes happen that involve bitcoin, law enforcement and security experts can exploit the system's privacy defects. They study illicit activity and can sometimes trace criminals to systems where their identities can be discovered.
If this isn't possible, they can often still obtain clues about criminals' behaviour. To identify a payer, bitcoin requires that the payer send payment to a unique address. This address acts like a kind of transaction serial number.
Systems with stronger privacy have arisen to shield users - and criminals - from such scrutiny. CoinShuffle and TumbleBit bundle transactions together allowing bitcoin users to launder money and achieve stronger anonymity.
Their success has been limited so far. Technical problems are one reason, but mainly their technical complexity and limited software support makes them hard for people to use.
When autonomous smart contracts are combined with anonymous cryptocurrency, they provide opportunities to handle money in complicated ways that hackers can exploit. In the future, "criminal smart contracts" may emerge.
These might be programmed to make automatic payments when specific secrets are stolen, websites hacked and defaced, or even for physical crimes ranging from vandalism to terrorism. The anonymity of the underlying cryptocurrency would hide the criminal's identity.
Today, smart contracts cannot easily obtain trustworthy data from the internet about crimes like vandalism. But advances in crime will eventually emerge, aided by continuing improvements in anonymity technologies.
Scientists have for decades sought to design systems that balance law enforcement needs with individual privacy in digital currency. Most of these systems provide what is called "conditional anonymity," allowing authorities to learn user identities selectively through a technical process that can involve courts or other overseers. Appealing as it sounds, this approach is unworkable. If one authority, say the U.S. federal court system, has the ability to strip users of anonymity, then all authorities will want it. Privacy will then be meaningless.
Crime-fighting requires empowerment of authorities. Cryptocurrencies are innately anti-authority technologies. How this is resolved will determine the future of the world's monetary systems. There is no simple answer.
All cryptocurrency systems work in roughly the same way. Groups of computers receive transaction information directly from users who want to send each other money. The computers order and permanently record these transactions in a public ledger so that anyone can read them. The public ledger also makes it possible to keep track of how much currency individual users own.
Developers tweak the code in different cryptocurrency systems to add additional features, like fast transaction processing or improved anonymity.
Cryptocurrencies are not limited to simple money transfers. Newer systems like Ethereum also include in the public ledger not just a record of which account sent money to whom, but small computer programs called "smart contracts."
Once entered into the ledger, these programs remain forever executable. They can store and send money in arbitrarily complex ways. Any user - or another smart contract - can trigger execution of a smart contract simply by sending it a transaction.
Today, law enforcement authorities can exploit privacy weaknesses in systems like bitcoin to identify certain cryptocurrency as belonging to criminals and thus as "tainted." This strategy will no longer work when stronger privacy technologies conceal tainted cryptocurrency.
