§ 00 · The argument
Privacy is not secrecy.
It is the power to choose.
Every claim on this page has a source and a date. Several of the numbers were counted directly from the primary data on 24 August 2026, rather than repeated from an article. Where the honest answer is “nobody has published that”, this page says so instead of filling the gap.
§ 01 · 1993
Somebody wrote this down before the internet had shops on it
Privacy is necessary for an open society in the electronic age. Privacy is not secrecy. A private matter is something one doesn’t want the whole world to know, but a secret matter is something one doesn’t want anybody to know. Privacy is the power to selectively reveal oneself to the world.
When I purchase a magazine at a store and hand cash to the clerk, there is no need to know who I am… When my identity is revealed by the underlying mechanism of the transaction, I have no privacy. I cannot here selectively reveal myself; I must always reveal myself.
That last sentence is a precise description of a published bitcoin address. Not a bad analogy for one. A description of one. The mechanism reveals you, so the choice is taken away, so there is nothing left to selectively reveal.
David Chaum, 1987
“New and more serious dangers derive from computerized pattern recognition techniques: even a small group using these and tapping into data gathered in everyday consumer transactions could secretly conduct mass surveillance, inferring individuals’ lifestyles, activities, and associations.”
A revised version of his 1985 paper, “Security without Identification: Transaction Systems to Make Big Brother Obsolete”. He described chain analysis eight years before the web had a shopping cart.
Hal Finney, 1993
“Cash, ordinary folding paper money, is one of the last bastions of privacy in our financial lives… If you go into a store today and make a purchase with cash, no records are left tying you personally to the transaction.”
Protecting Privacy with Electronic Cash, Extropy #10. The man who received the first bitcoin transaction is also the first entry in the physical attack database further down this page.
Satoshi Nakamoto, 2008
“As an additional firewall, a new key pair should be used for each transaction to keep them from being linked to a common owner… if the owner of a key is revealed, linking could reveal other transactions that belonged to the same owner.”
Section 10 of the whitepaper, titled Privacy. The problem was documented on day zero. Doing something about it took until 2024.
§ 02 · What you actually publish
Not our claim. Bitcoin’s own documentation
Anyone can see the balance and all transactions of any address… once addresses are used, they become tainted by the history of all transactions they are involved with… For these reasons, Bitcoin addresses should only be used once and users must be careful not to disclose their addresses.
The same table for alice@silentpayments.net is empty. Not private, not redacted, not behind a login. There is no page to load, because there is no address to look up and nothing that says any of those payments belong together.
The address above is the example one from the bech32 specification and the figures beside it are illustrative. Every row is a field a real explorer prints for a real address, which is the only claim being made.
The same page has a section headed “Be careful with public spaces”, and its advice is to not put an address on a website or a social profile at all unless full transparency is what you want. That is the official position, and it is why the donate button on almost every project you like is a payment processor rather than an address.
Bitcoin has the unintuitive property that while the ownership of money is implicitly anonymous, its flow is globally visible.
And it works in reverse, years later
James Zhong committed wire fraud against Silk Road in September 2012. In November 2021 the IRS criminal investigation division searched his house and seized 50,676 bitcoin, then worth $3.36 billion. He pled guilty in November 2022. Nine years passed between the act and the chain analysis that found him, and the chain did not forget any of it.
bitcoin.org states the general form of this plainly: “something not traceable currently may become trivial to trace in the future.” An address you publish today is published against every analysis technique that will exist for the rest of your life.
§ 03 · Who is reading
There is a paid profession on the other side of your address
In United States federal prime contract awards to Chainalysis, across 152 awards.
Counted from the USAspending.gov API, 24 Aug 2026. Prime contracts only, so this is a floor.
Of that, from the Treasury alone, over 17 awards. Justice adds $49.7M, Homeland Security $19.2M.
Same query, same day. Largest single award: $26.8M.
Countries whose agencies, exchanges and banks Chainalysis says it supplies.
Their own company page, retrieved 24 Aug 2026.
Individual bitcoin addresses currently on the United States sanctions list.
Counted from Treasury’s own SDN Advanced XML, 24 Aug 2026. 1,007 crypto addresses across all chains.
Where that money came from
Every cryptocurrency address on the United States sanctions list
That last number is the cleanest available proof that a bitcoin is not simply a bitcoin. A specific string of characters can be placed on a sanctions list, and from that moment every regulated business on earth must treat coins that touched it differently. The official documentation uses the word for this without flinching: taint. And it spreads. If you move funds from a published address to another address you own, the second one inherits the history of the first.
The scam that exists because people copy addresses out of history
Address poisoning: an attacker generates an address that looks like one you recently paid, sends you a dust payment so it appears in your history, and waits for you to copy the wrong one. On 3 May 2024 a single victim sent $68 million in wrapped bitcoin to a lookalike address. The attacker returned it, and still netted $1.49 million from the rest of a campaign that used more than 82,000 addresses, of which only 22 ever received more than $100 from anyone but the scammer.
Note the mechanism, because it is the argument for a name. The attack works because the thing you paste is a long opaque string, taken from a visible transaction history. Remove the visible history and remove the copy-paste, and the attack has nowhere to stand.
§ 04 · The physical bill
The part of this argument that is not abstract
Jameson Lopp maintains a public list of physical attacks on people for their bitcoin. He publishes no total, so we counted the rows ourselves on 24 August 2026, and a second, independent count agreed exactly.
The same numbers as a table
| Year | Incidents | Year | Incidents |
|---|---|---|---|
| 2014 | 1 | 2021 | 36 |
| 2015 | 5 | 2022 | 36 |
| 2016 | 4 | 2023 | 26 |
| 2017 | 12 | 2024 | 42 |
| 2018 | 26 | 2025 | 85 |
| 2019 | 10 | 2026 to 11 Aug | 55 |
| 2020 | 15 |
What was taken
$58 million in 2025, the highest annual total on record, and more than $30 million in the first half of 2026. Attempted extractions were roughly $316 million in 2024 and $180 million in 2025.
Chainalysis, 6 Aug 2026. Their own caveat: these figures likely undercount, because many incidents go unreported.
They are your neighbours
“In Sweden, 100% of victims with known residency status were locals. In France, 93% were local residents. In Brazil, 82%. In the United States, 77%.” This is local reconnaissance, not opportunism.
Chainalysis, 6 Aug 2026.
The first row on the list
29 December 2014. Hal Finney, Santa Barbara. Swatted after months of harassment and extortion. The man who wrote that this work was “dedicated to making Big Brother obsolete” opens the ledger of what happens when you are visible.
More attempts, fewer of them working
The share of violent thefts that actually ended in a payment, three years running. People are getting better at not being able to hand anything over, which is what good custody looks like from the outside.
67%
32 of 48 attempts ended in a payment
49%
47 of 95 attempts ended in a payment
26%
12 of 46 attempts ended in a payment
Chainalysis, 6 August 2026. Read the two charts together rather than separately: attempts are rising and the success rate is falling, so the total taken still hit a record $58 million in 2025.
The careful version of this argument, because the sloppy version is a lie
Nobody has published a case where a victim was located by looking up a published bitcoin address on a block explorer. We looked, including at the peer reviewed study that interviewed offenders, and that vector does not appear in it. If you see somebody claim otherwise, they invented it, and we are not going to join them.
What is documented, and is enough:
- Chainalysis names the inputs directly: targeting happens “whether through monitoring social media, analyzing blockchain data, leveraging leaked information, or receiving tips from insiders”, and warns that disclosing holdings “through social media, conference appearances, or on-chain activity linked to known identities” can make you a target.
- In 2024 a French tax official is alleged to have stolen and sold dossiers on wealthy crypto holders, containing names, addresses, holdings and phone numbers. A wave of attacks followed. A published address is the self-service version of that dossier, except you compiled it yourself and you cannot take it back.
- Perceived wealth is sufficient. In May 2024 a Belgian barber was lured to a flat and attacked over a fortune he had boasted about. He held £6.71.
A silent payment address does not make you safe. It removes one specific thing from the public record: the running total of what you have been paid, sitting next to your name.
§ 05 · The law
What the rules actually say, as of today
This section exists because the crypto press gets it wrong in both directions, and because a page that scares you with things that are not true has forfeited the right to be believed about the things that are.
In force Your address is legally personal data in the EU
The European Data Protection Board, in guidelines adopted on 7 July 2026: “If the user is a natural person and those public keys can be used to identify the individuals by means reasonably likely to be used… then those identifiers qualify as personal data.”
Europe’s own data protection regulator agrees with the premise of this whole site. A wallet address is information about a person, and publishing it is publishing that.
In force Every regulated crypto transfer is reported
The Transfer of Funds Regulation has applied since 30 December 2024, with no minimum threshold for crypto, unlike ordinary bank transfers. Name, ledger address, account number and identifying document travel with every transfer between service providers.
Above 1,000 euro to or from a self-hosted address, the provider must take steps to assess whether you actually control it.
2027 The anonymity ban, correctly described
The EU Anti-Money Laundering Regulation applies from 10 July 2027, not 1 July, whatever you have read. Article 79 forbids credit institutions, financial institutions and crypto-asset service providers from keeping anonymous accounts or handling anonymity-enhancing coins.
It binds that closed list of businesses. It does not bind you.
Not true “The EU is banning self-custody”
Recital 160 of the same regulation says the opposite in as many words: the prohibition “does not apply to providers of hardware and software or providers of self-hosted wallets insofar as they do not possess access to or control over those crypto-asset wallets.” And the transfer rules expressly exclude person to person transfers made without a service provider.
In the United States, the FinCEN rule that would have applied identity checks to self-hosted wallets was withdrawn on 12 April 2024. The mixing rule has been proposed since October 2023 and has never been finalised.
The accurate summary: surveillance is being applied at the regulated exit and entry points, thoroughly and with no lower limit, and not to the individual holding their own coins. Which means the thing that determines what the record says about you is what you publish. That is the part still under your control, and it is the only part this site can help with.
§ 06 · Scope
What this fixes, and what it plainly does not
Fixed
- A published identifier that does not reveal a balance
- Payments to you that cannot be linked to each other on the chain
- Two payers who cannot discover they paid the same person
- No need to hand out a fresh address, ever, to anyone
- No transaction announcing that you are about to be paid privately
- An identifier a human can read out over a phone
Not fixed
- Your exchange still knows what it sent and to whom
- Spending is a separate problem, with its own analysis
- Amounts are still public, as they always were
- Timing still leaks, and always did
- Telling people how much bitcoin you own is still the single worst thing you can do
- The domain operator, us included, can still redirect a name. Hence the log
We must defend our own privacy if we expect to have any. We must come together and create systems which allow anonymous transactions to take place… Cypherpunks write code. We know that someone has to write software to defend privacy, and since we can’t get privacy unless we all do, we’re going to write it.
Sources
- A Cypherpunk’s Manifesto, 1993
- The Crypto Anarchist Manifesto, 1988
- Chaum, Card Computers to Make Big Brother Obsolete
- Finney, Protecting Privacy with Electronic Cash
- The bitcoin whitepaper, section 10
- bitcoin.org, Protect your privacy
- Bitcoin wiki, Address reuse
- A Fistful of Bitcoins, 2013
- USAspending.gov, federal contract data
- The OFAC sanctions list
- Lopp, Known Physical Bitcoin Attacks
- Chainalysis on wrench attacks, Aug 2026
- Chainalysis on address poisoning
- EDPB blockchain guidelines, v2.0
- EU Transfer of Funds Regulation
- EU Anti-Money Laundering Regulation
- xkcd 538, where the five dollar wrench comes from
- Bitsaga: the surveillance state’s honeypot
- Bitsaga: bitcoin privacy, the practical guide
- Bitsaga: 42 things a cypherpunk setup still trusts