Method and heuristics
Exactly what the scanner reads, how it decides that a stealth address was withdrawn, and how each heuristic is defined.
The method follows Kovács and Seres, Anonymity Analysis of the Umbra Stealth Address Scheme on Ethereum (2023). Where we had to make a choice they did not describe, it is written down here.
Scopes
| Scope | What it covers | Use |
|---|---|---|
| Paper-comparable | Umbra payments, Umbra registrations and withdrawals before 2023-07-01 | Checks the pipeline against the paper's 48.51% |
| Since cutoff | Umbra and ERC-5564, first paid on or after 2023-07-01 | The leak rate since the study |
| All | Everything, full history | Totals |
| By year | By year of first payment | The trend |
Data
| Step | Source |
|---|---|
| Payments | Umbra Announcement and ERC-5564 Announcement events |
| Registrations | Umbra StealthKeyChanged and ERC-6538 StealthMetaAddressSet events |
| Relayed Umbra token withdrawals | Umbra TokenWithdrawal events |
| Payment sender | The from of each payment transaction |
| Withdrawals | Outgoing ETH, internal, ERC-20, ERC-721 and ERC-1155 transfers of every stealth address |
| Signer, type, fee | from, type and maxPriorityFeePerGas of each withdrawal |
| Gas funding | Incoming ETH of token-only stealth addresses |
| Freshness | The nonce of each stealth address just before its first payment |
The scan ends at a finalized block, so a lagging index cannot change a fixed range later. For ERC-5564, the metadata gives the asset: selector 0xeeeeeeee is ETH, known token transfer selectors are tokens.
Definitions
- Unit of analysis: the stealth address. Several payments to one stealth address count once.
- Fresh: a real stealth address has sent nothing before its first payment. Announced addresses that had are left out (3 in this run).
- Owned withdrawal: a transfer out of the stealth address at or after its first payment, outside the payment transaction, made by the owner. That means signed by the stealth address, an Umbra
TokenWithdrawal, any transfer of a smart-account or EIP-7702 delegated stealth address, or a relayed move of the token that was paid in. - Withdrawn: the paid asset left: ETH for an ETH payment, the token for a token payment.
- Single withdrawal: the paid asset left in exactly one transaction. A later sweep of leftover gas does not break it.
Heuristics
- H1, registrant reuse. A recipient of the withdrawal is an address that registered stealth keys.
- H2, same sender and receiver. A recipient is the sender of a payment to that stealth address. We apply the single-withdrawal rule to H2 as well as H1.
- Paper metric. H1 or H2 on the single withdrawal, over all withdrawn addresses.
- H3, collector pattern. Single withdrawals with one recipient, grouped by recipient; groups of two or more are clusters. Contract recipients such as routers are excluded to avoid false clusters.
- H4, unique priority fee. Fee-market withdrawals signed by the stealth address. A priority fee used by at most five such transactions is unique, and stealth addresses that share one are grouped. Self-signed token withdrawals are included; the paper excluded token payments.
- H5, gas funding (ours). A token-only stealth address that signed its own transaction needed ETH first. If that ETH came from a registrant, or from an address the funds later went to, it is linked. ETH from the payer or from contracts does not count.
H1, H2 and H5 name an identity. H3 and H4 shrink the crowd a payment hides in, but name no one.
Reproducibility
The first run stores the end block, the cutoff block, a code version and a hash of the settings. A fresh download of the same range must produce the same fingerprint. This run: blocks 12,343,914 to 26,127,110, fingerprint cc961f9b2c0bbd11.
Limits
- Implementations that never announce on-chain are invisible here.
- Exchange deposit addresses count as ordinary recipients.
- At most 10,000 transfers are read per address; this run hit that limit 0 times.
- These are lower bounds: real analysts also use timing, amounts and off-chain data.