Cryptology ePrint Archive: Report 2020/723

On the Confidentiality of Amounts in Grin

Suyash Bagad and Saravanan Vijayakumaran

Abstract: Pedersen commitments have been adopted by several cryptocurrencies for hiding transaction amounts. While Pedersen commitments are perfectly hiding in isolation, the cryptocurrency transaction rules can reveal relationships between the amounts hidden in the commitments involved in the transaction. Such relationships can be combined with the public coin creation schedule to provide upper bounds on the number of coins in a commitment. In this paper, we consider the Grin cryptocurrency and derive upper bounds on the number of coins which can be present in regular transaction outputs. In a March 2020 snapshot of the Grin blockchain, we find that out of the 110,149 unspent regular transaction outputs 983 of them have less than 1800 grin (number of coins typically minted in half an hour) stored in them. On the other hand, 95% of the unspent regular transaction outputs in the snapshot have an upper bound which is at least 90% of the total Grin supply at their respective block heights. We conclude that while our method does not violate the confidentiality of the amounts in most of the outputs on the Grin blockchain, the amounts in some outputs can be estimated to be in a narrow range.

Category / Keywords: applications / Cryptocurrency, Mimblewimble, Pedersen commitments

Original Publication (with minor differences): Crypto Valley Conference on Blockchain Technology 2020

Date: received 16 Jun 2020, last revised 17 Jun 2020

Contact author: sarva at ee iitb ac in, suyashnbagad1997@gmail com

Available format(s): PDF | BibTeX Citation

Note: Changes to Introduction section to state that Beam allows download of historical blocks

Version: 20200618:014321 (All versions of this report)

Short URL:

[ Cryptology ePrint archive ]