Search content
Sort by

Showing 20 of 31 results by blindmixer
Post
Topic
Board Service Announcements
Re: [BETA] blindmixer.com - Next-gen mixer | Chaumian Bank | Lightning | Blinded-Sig
by
blindmixer
on 03/12/2023, 21:30:01 UTC
It's good to see that it is possible to withdraw funds from your platform even though you stop doing business, but why is there no warning or any information anywhere on the site that the service stops working?
I just registered an account and I didn't come across a single notification why is it even possible to create a new account on a service that stops working?
I made a similar suggestion last month. Maybe they missed it out, but I think it would be a good idea they implement it. So many people out there only check this threads once they realize their money is stuck, not before using the service.

This is unfortunate, but I guess everything has a beginning and an ending. At least you are signing out honorably rather than some service that just decide to exit scam. My three suggestions.
  • Disable the creation of new wallets that may lead to some unsuspecting members using your service not knowing that it's shutting down
  • Maybe add a warning banner or notification on your home page or user dashboard stating that the service is shutting down
  • Extend the deadline for withdrawal of money from the current custodian if need be. 2 weeks seems like a narrow window.

I am glad they extended the deadline.



I did not know that the service would no longer work because I did not see any warning anywhere. In the last month, I had 5-6 transactions and everything worked properly. Yesterday I sent 0.012 btc to blindmixer and then I saw that something was wrong. The transaction status says: pending conf. An error also appears: "Failed to fetch" and "Custodian is not aware of the hookin!". In the meantime, I sent an email to support as well as a private message to the OP, but no one answers. Is there any possibility for me to save those bitcoins?
We've sent you a pm.
Post
Topic
Board Service Announcements
Merits 4 from 1 user
Re: [BETA] blindmixer.com - Next-gen mixer | Chaumian Bank | Lightning | Blinded-Sig
by
blindmixer
on 29/10/2023, 15:13:51 UTC
⭐ Merited by LoyceV (4)
Dear all, the current maintainers of blindmixer have decided to no longer continue.

Please withdraw your money from the current custodian before October 1 2023.

If you have issues, do not email, post them here.

Kind regards,
We've extend the deadline already but there are still some deposits left. Please withdraw ASAP.
Post
Topic
Board Service Announcements
Merits 1 from 1 user
Re: [BETA] blindmixer.com - Next-gen mixer | Chaumian Bank | Lightning | Blinded-Sig
by
blindmixer
on 17/09/2023, 11:18:48 UTC
⭐ Merited by LoyceV (1)
Dear all, the current maintainers of blindmixer have decided to no longer continue.

Please withdraw your money from the current custodian before October 1 2023.

If you have issues, do not email, post them here.

Kind regards,
Post
Topic
Board Service Announcements
Re: [ANN] Whirlwind.money | ⚡No Fee⚡ | Ultimate Privacy | Anonymity Mining 12% APR🔥
by
blindmixer
on 02/06/2023, 13:34:50 UTC
I created a beginner-focused explainer on Blind Certificates as it relates to Whirlwind last month (https://bitcointalk.org/index.php?topic=5444933.msg62070355#msg62070355). Whirlwind was first proposed as a service that would eventually operate on Blind Certificates (again, to get caught up to speed on that, check out my graphic in the prior link). Theymos had this idea back in 2018, but no one have ever run with it.

Integrating Blind Certificates would be a historic leap, like something on par with the creation of the first DEX or the first DAO. It's what makes me excited about Whirlwind as something more than just another mixer. My current understanding is that this Blind Certificate model is still one of the eventual goals, but the realities of running a business and doing this development is that you obviously first need to gain traction, revenue, etc. first. Then there's the difficulties of explaining a concept that seems confusing (Blind Certificates) to the public in a way that makes them understand it. I'm working on a few volunteer contributions with the design skills I have, and if anyone else has any other skills to contribute so we can add value here and there so the main team can focus on improving and scaling Whirlwind, let's get to work. If you can see the eventual vision, it's easy to get really excited about this as something that will be historic.

Have you taken a look at our service? I think we have implemented exactly this!
Post
Topic
Board Service Announcements
Merits 1 from 1 user
Re: [BETA] blindmixer.com - Next-gen mixer | Chaumian Bank | Lightning | Blinded-Sig
by
blindmixer
on 29/04/2023, 15:15:07 UTC
⭐ Merited by xandry (1)

Why don't you answer my E-Mails since weeks?

I am waiting now for weeks for my money. The service said the transaction was sent but in fact it was not and my money just got detucted.

Please check your email, we should have responded now. Apologies.

For those curious, the transaction was never propagated due to a flaw in our fee selection, as it was somehow below the min relay fee. We hope to have fixed issue this now.


I also reversed other requests in background: All incoming and outgoing transactions are transferred without any extra encryption directly through cloudflare... So if cloudflare would record all the traffic it would be very easy to trace back all transactions.
See how it works on my outgoing, non-existing transaction:



Well yes, but not quite: see, apart from browser headers and your ip, there is in theory nothing that connects your deposit to your withdrawals, as we use blind signatures in order to break that connection.
However, if you restore (resync) your wallet you will indeed make it very easy for us to infer what deposits and withdrawals belong to you, as you are querying them in quick succession.

This is a real problem we are not entirely sure how to tackle yet. Perhaps we could only allow you to restore your wallet at a certain time of day, so as to make it impossible for us (and cloudflare) to guess if there is just 1 individual restoring, or multiple.



Thats the same way how incoming transactions are checked... Just using another subdomain... "very secure"
Maybe when using TOR those two subdomains are connected to using different ips but was far as I have seen for now its not like the service is used by hundreds of people at the same time, so because of this and using other header parameters by the browser i am sure it would be possible for a child to figure out which request and wallet belongs to who. In my opinion this is not acceptable.

Indeed, it is quite trivial to guess which input belongs to which output, and really boils down to simple probability, especially with a small set of active coins (unused blind signatures).
We acknowledge this. The only way to really overcome this is by growing our userbase. Yes, we could also impose additional restrictions such as not allowing you to withdraw random amounts, or forcing you to wait some time before withdrawing, but that would probably be detrimental to the UX.

Because of it the mixer is not that blind as you describe. You could also easy track it back by headers and time. To make the whole thing make a sense you should encrypt the data in the browser somehow using keys only your server and the client nows.

We have thought about encrypting the data before sending it to our server and we might revisit this soon because indeed, there are not really any cons apart from the fact that it does not really improve your privacy, but rather gives you the illusion that it does since we can still see your ip and headers associated with an action and connect the dots.
There is really no way around it, to attain privacy you as the client will need to be proactive as well. Use the tor browser and rotate your IP between deposit and withdrawal. Wait a little bit before withdrawing, and don't withdraw the same, close, or division of the original amount.
 
And the whole "blind" thing can't work ever in my opion. Because your server always will know incoming and outgoing transactions to validate. So why don't focus on better mixing? I see people here and also I experienced receiving my coins back. Who needs a mixer where this happens?
You still might be misunderstanding what blindmixer offers: we don't know the inputs associated with your unblinded coins (though we can of course infer), not just as a promise, but as a fact.
As a result it can happen that you receive your own inputs back, because we do not associate them with "you"; that is, your original deposit. It would be impossible for us to do so due to our usage of blind signatures.

Everyone should want a mixer where this happens as a result of using blind signatures, because it is a symptom of providing true privacy, and not one that is merely based on promises.

I really like the idea of the service, but for the rest it is not usable for production.
There is a lot work to do in improving privacy and you should make the raw transaction code viewable for the sender, so when your node fails to broadcast they can do it manually.
We could indeed push the raw transaction hex to users, but it would not have helped in your case as the transaction was simply invalid.

Apologies again and agreed, there are still a lot of bugs we need to iron out and plenty of ways to improve the current product.
Post
Topic
Board Service Discussion
Re: Ultimate Bitcoin Privacy - Discussion
by
blindmixer
on 22/04/2023, 12:57:07 UTC
blindmixer might be a nice example of this: we already utilize blind schnorr signatures, and have full non-repudiation:

every action taken by the client requires a signature that only the client can generate, as such we cannot dupe any single user with it being proveable.

A consequence of this is that it is a little more complex than a single webpage: the client needs to actively generate signatures and store them. JS will be required. Still, we believe that we packaged it as simple as possible for the average user.

A huge drawback currently is that our scheme is centralized, meaning that we can exit-scam at any point. We have looked into using a MuSig scheme with multiple signers, and it should definitely be possible. Don't think it will play very nicely with lightning as of right now, but that will undoubtedly change in the future.

Post
Topic
Board Service Announcements
Re: [BETA] blindmixer.com - Next-gen mixer | Chaumian Bank | Lightning | Blinded-Sig
by
blindmixer
on 22/04/2023, 12:37:34 UTC
Bump! We have temporarily increased our deposit fees to 1%. We intend to use 100% of these funds to kickstart a signature campaign. Lightning deposits are still free.

It has taken 3 Days, maybe they don't monitor it much or maybe the system required a time lapse or more coins to be deposited for the mixing to occur. Or maybe it's to get me to post on bitcointalk and contact them by email Wink
Did you use the batch functionality by any chance?



Let us know if you have any questions.
Post
Topic
Board Service Announcements
Merits 2 from 1 user
Re: [BETA] blindmixer.com - Next-gen mixer | Chaumian Bank | Lightning | Blinded-Sig
by
blindmixer
on 23/09/2022, 11:38:44 UTC
⭐ Merited by LoyceV (2)
We are having issues with our provider of hosting. We are trying to solve this before migrating.

There is about 0.02BTC hooked in that we currently know of which includes the BTC from above poster.

Sorry for the inconvenience.
Post
Topic
Board Service Announcements
Re: [BETA] blindmixer.com - Next-gen mixer | Chaumian Bank | Lightning | Blinded-Sig
by
blindmixer
on 06/08/2022, 15:17:48 UTC
hello guys, got into a sad situation associated with the use of this service.
I topped up my wallet, requested a withdrawal (~650k sat.) and that's it. The transaction has not been transferred to my details, its status is "Hookout is in queue!" already a week, also emailed "blindmixer@protonmail.com" but haven't received a response in 5+ days.
I ask the owners of the service to contact me.
Resolved, sorry. Your transaction was stuck due to lack of initiating transactions.
Post
Topic
Board Wallet software
Re: CoinJoin Alternatives to Wasabi
by
blindmixer
on 18/05/2022, 20:41:22 UTC
We also think we offer something that might be of interest to users looking for alternatives to coinjoin:

 - blinded submarine swaps
 - reverse submarine swaps - though both of these are with counterparty risk
 - internal transfers,
 - regular blinded on-chain deposit/withdraws, against (currently) 0% fees - this might change at some point in the future
 - Economies of Scale

The privacy implications of our product are enormous and pretty revolutionary if used correctly: your withdrawn funds will be consisting of any deposit made by other users, including your own.

Given a large enough userbase and correct usage of our product (for example: timing & non-unique withdrawal amounts) we believe that a very high degree of on-chain privacy can be achieved.

Though of course there is (as of right now) a significant catch: we are a centralized entity. While all of our communications are provably-honest and privacy against us is retained using blinded schnorr signatures, we can at any point in time break that promise.

We think our product stacks up very well against currently existing mixers
 
 + free internal transfers - allows you to transfer btc to a friend off-chain / with privacy
 + complete lightning integration - make blinded lightning transfers
 + provably-honest communications
 + blinded-sig scheme - provable privacy against the mixer
 + cheaper - only pay network fees as of now
 + can be used as a day-to-day wallet - added privacy + no additional transactions required in comparison to traditional mixers
 + insert withdrawal as a batch transaction - only pay for the output space ~31 vb
 + open-source software
 - incorrect use or lack of use by other users can make it easy for blockchain heuristics.

compared to CoinJoins:

 + more flexible - withdraw any amount at any point
 +- may or may not offer better on-chain privacy. This is something that largely depends on how many users we have and how you use us*.
 - centralized - requires custody over your funds
 + cheaper ?
 + can be used as a day-to-day wallet - added privacy + no additional transactions required in comparison to traditional coinjoins


Looking forward to hearing you guys' opinions about us. Would you want to use us?
Post
Topic
Board Project Development
Re: Feedback Wanted | blindmixer.com | blind-sig | lightning | chaumian bank
by
blindmixer
on 07/05/2022, 11:00:55 UTC
Bump! Looking for people to test and review our software!
Did some tests with the testnet and I believe there's a bug in the "send" tab:

  • Toggling the sat/btc buttons and clicking the max button leads to a wrong amount for the btc part [decimal point is in the wrong location]!

Thank you! We've added this to the list of bugs to fix.
Post
Topic
Board Project Development
Re: Feedback Wanted | blindmixer.com | blind-sig | lightning | chaumian bank
by
blindmixer
on 01/05/2022, 12:40:53 UTC
Bump! Looking for people to test and review our software!
Post
Topic
Board Project Development
Re: Feedback Wanted | blindmixer.com | blind-sig | lightning | chaumian bank
by
blindmixer
on 29/04/2022, 20:10:55 UTC
Bump! Looking for people to test and review our software!

Post
Topic
Board Service Announcements
Re: [BETA] blindmixer.com - Next-gen mixer | Chaumian Bank | Lightning | Blinded-Sig
by
blindmixer
on 29/04/2022, 20:01:42 UTC
Please note: the wallet has been updated!

New wallet file:
Code:
https://mixer.blindmixer.com/main.3b3a02afbe328e2366eb.js#7fWgpIBtNrbSUMNkB1aVSA9bWnRyEqw0NogHk7V4FaY=

Updated Signature:
Code:
-----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQQc46fSQnUrlHD2WF+RIzyGWiysCQUCYmrw5QAKCRCRIzyGWiys CZnQAQCPuuLObmXHMy4KdmbjuuD2k2iZ3BJVMUoiadY3+5AhZwD8CojLdCnRaB3N AdZklGxOpLN1+cmMnVz8qyfrJGnoNQY= =bafc -----END PGP SIGNATURE-----

Get the signature:

Code:
curl https://updates.blindmixer.com | grep -Po '"'"signature"'"\s*:\s*"\K([^"]*)' | awk '{gsub("\\\\n","\n")};1' > main.3b3a02afbe328e2366eb.js.asc
^ Probably an easier way to do this Smiley

Wallet file:
Code:
curl https://mixer.blindmixer.com/main.3b3a02afbe328e2366eb.js > main.3b3a02afbe328e2366eb.js

Should check out!

Code:
gpg --verify main.3b3a02afbe328e2366eb.js.asc main.3b3a02afbe328e2366eb.js

Let us know what you think!
Post
Topic
Board Project Development
Re: Feedback Wanted | blindmixer.com | blind-sig | lightning | chaumian bank
by
blindmixer
on 28/04/2022, 20:52:48 UTC
I like the "Generate Lightning Invoice" option for the Lightning Network feature....
Right! You can seamlessly switch between making an on-chain transaction and lightning. Make a deposit on-chain, withdraw using lightning!

I just want to ask a question... Seeing that a major "Mixer" owner gave up the data of it's users when things got heated a while ago, would it be possible to create a Mixer service that are OpenSource and decentralized and not owned and operated by a centralized individual or group?
Yes, this would be very possible even while largely retaining the current code of blindmixer. This is something we're interested in doing in the long-term, as it is currently the single biggest caveat of blindmixer! ...Though we're not quite sure yet how complicated this will become. 

Sorry for the lack of detail in my answer; I am intentionally keeping this a bit vague for now as it's a bit of an empty promise as of currently.

It will give proof that logs are not stored and it will not be controlled by a owner that can give up any personal information or transaction history? (The code can then be scrutinized and Peer reviewed by experts to confirm that)
Please note: blindmixer already has this. We cannot link your in- and outputs like traditional mixers can, though we can obviously still log your ip and so forth.

Making the mixer decentralized would as I currently see it really only change the backend and besides decentralization not add much in terms of actual privacy related features... + We might actually have to scrap certain features like lightning completely.

It can still push the "fees" to an address that are predefined in the code and the receiver of those funds can then use other mixer services to hide it's destination.  Huh

I think in a multisig scheme such a thing would not necessarily be required - signers can agree to a predefined split and correspondingly dynamically sign transactions or blinded coins.


Post
Topic
Board Project Development
Re: Feedback Wanted | blindmixer.com | blind-sig | lightning | chaumian bank
by
blindmixer
on 06/04/2022, 10:06:09 UTC
Bump!
Post
Topic
Board Project Development
Re: Feedback Wanted | blindmixer.com | blind-sig | lightning | chaumian bank
by
blindmixer
on 31/03/2022, 15:39:10 UTC
I just did some more testing with the wallet, and here are a couple of issues I found:
Thank you for doing so, first of all.

- When you refresh the site while you're on the Send/receive or LN receive pages, you'll get an error saying that the file does not exist.
- The site asks you to re-enter your password when you simply refresh the transactions page.
Both of these issues are actually intended behaviour, though it can probably be repackaged to look a bit more professional.

- When you refresh the site while you're on the Send/receive or LN receive pages, you'll get an error saying that the file does not exist.
I see. This is because you're asking the host (github) for a certain URL that only existed client-side (SPA). We should just automatically redirect you back to the "login page" to avoid any confusion.

- The site asks you to re-enter your password when you simply refresh the transactions page.

This is also intended behaviour; the wallet is not really supposed to be "refreshed". If you have just made a transaction it should automatically redirect you to the transaction status. Refreshing the transaction page will not actually fetch any new data. Perhaps it does display previously unseen states that were already stored locally but not visible yet, however switching between the send/receive/transaction tab should make these new entries visible -- there would be no need to refresh. I guess this should perhaps be made more clear?

I'm also not sure what the "Check" and "sync" buttons are supposed to do since nothing is happening when I click them.
The "check" button sends a request to a blockchain explorer to discover if there have been any new transactions made to said address - if so - the wallet will ask the custodian to accredit the deposit.
I agree with you that there are two potential issues / improvements. We could remove the button on the /receive/ tab and automatically check the latest address to see if it received any new deposits, (but keep it on /addresses/ as that would become resource-intensive)

And secondly we should probably redirect users to the deposit once it is found. Currently after clicking "Check" you should switch back to the transactions tab to see the new transaction item and the corresponding information, which is admittedly a bit confusing. (No page refresh is needed though)

The sync button checks for any missing deposits, withdrawals, or unfinished states (unclaimed) by querying the custodian with your deposit addresses + unspent coins. You can try and see for yourself by taking your current seed, restore, and click sync. The transactions tab should automatically be populated with all of your previous transactions, and attempt to finalize them.

Post
Topic
Board Project Development
Merits 2 from 1 user
Re: Feedback Wanted | blindmixer.com | blind-sig | lightning | chaumian bank
by
blindmixer
on 29/03/2022, 19:58:59 UTC
⭐ Merited by OmegaStarScream (2)
Taproot is already supported on your wallet if I understand correctly or not?
We support sending to Taproot addresses starting with witness version (1). I'm not sure what current developments are (if there have been more witness versions introduced) We don't support generating taproot deposit addresses, not until bitcoin core supports it anyway.

Is there any instructions I can read before I use it, and what should be written instead of mainnet custodian url address?
double click the input field and the url for the testnet custodian should show up (https://testnet.blindmixer.com/#pubmp1qf98kxatpw43mqjft6j72dps5wn66yzp47k3zm0yn4skhedv32x5sphklj2)

After that, simply deposit using a lightning testnet wallet or a testnet faucet.

Does that mean that the wallet cannot be restored anywhere else even with the mnemonic phrase?
Correct. Since the wallet is fully custodial it can only be restored with your current custodian.

Also, I would've understood if the URL had some kind of unique identifier in it, but it's just displaying the home page link?
This was done to reemphasize the importance of remembering the right custodian in case there would have been multiple operators running the blindmixer software, which has not been the case thus far. Still, you might get confused between testnet and mainnet wallets.
Post
Topic
Board Service Announcements
Re: [BETA] blindmixer.com - Next-gen mixer | Chaumian Bank | Lightning | Blinded-Sig
by
blindmixer
on 29/03/2022, 14:22:43 UTC
Hi everyone! We're looking for your feedback!

If you wish to review our service and let us know what we could improve on feel free to comment.


An update on this:
B. You speak of tor so much, yet blindmixer does not work in the tor browser?
We're not sure what changed but our wallet now works by default if you use the standard tor browser settings.

If you use the tor browser in combination with something like Tails (4.28) you still need to go to

Code:
about:config ->> dom.indexedDB.privateBrowsing.enabled
Post
Topic
Board Project Development
Topic OP
Feedback Wanted | blindmixer.com | blind-sig | lightning | chaumian bank
by
blindmixer
on 29/03/2022, 13:39:49 UTC
As the title suggests we are looking for feedback and things to improve.

If you wish to review our service, please do so by all means.
We will respond to all of your comments and categorize the given feedback if we can confirm the issue, and keep you updated as to whether or not it is fixed.

Current feedback:

Example:
 - Add XYZ (suggested by XYZ) Status: XYZ

Bugs:
 
 -

Features:

 -

Improvements:

 -