Deanonymizing Tor hidden service users through Bitcoin transactions analysis
Husam Al Jawaheri, Mashael Al Sabah, Yazan Boshmaf, Aiman Erbad

TL;DR
This paper demonstrates that Bitcoin transactions can be exploited to deanonymize Tor hidden service users by linking their online identities with blockchain data, revealing sensitive associations and compromising privacy.
Contribution
It introduces a practical method for deanonymizing Tor users by analyzing blockchain transactions and social media data, highlighting vulnerabilities in Bitcoin and Tor anonymity models.
Findings
125 users linked to 20 Tor services including sensitive ones
Crawled 1.5K hidden services and collected 88 Bitcoin addresses
Analyzed 5 billion tweets and 1 million forum pages for user identities
Abstract
With the rapid increase of threats on the Internet, people are continuously seeking privacy and anonymity. Services such as Bitcoin and Tor were introduced to provide anonymity for online transactions and Web browsing. Due to its pseudonymity model, Bitcoin lacks retroactive operational security, which means historical pieces of information could be used to identify a certain user. We investigate the feasibility of deanonymizing users of Tor hidden services who rely on Bitcoin as a payment method by exploiting public information leaked from online social networks, the Blockchain, and onion websites. This, for example, allows an adversary to link a user with @alice Twitter address to a Tor hidden service with private.onion address by finding at least one past transaction in the Blockchain that involves their publicly declared Bitcoin addresses. To demonstrate the feasibility of this…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Spam and Phishing Detection · Blockchain Technology Applications and Security
