Practical Privacy: Tools, Tradeoffs, and Real Threat Models
Translate the theory of crypto privacy into a working playbook: build a real threat model, weigh today's tools (stealth addresses, Railgun, Aleo, Aztec, Monero, Zcash, Tor, coin control), and understand the practical and legal landscape as of 2026.
28 min · advanced · part of Privacy in Crypto
What you'll learn
- Threat Modeling: Privacy Against Whom?
- Receive Privacy vs. Send Privacy
- A Tour of the Tools, Honestly Assessed
- Common Pitfalls: Address Poisoning, Linking, and Operational Errors
- The Legal Landscape, Briefly
- Use Cases: From Journalists to Small Businesses
- A Practical Recommendation Stack
- For Deeper Reading
Key terms
- Threat model
- A structured statement of what you are protecting and from whom. Different adversaries (peer, competitor, state, insider) require different defenses; the right tool is the one that fits a specific model.
- Receive privacy
- The property that incoming payments to you do not reveal your full balance, your unrelated income streams, or your other counterparties. Solved by stealth addresses (EIP-5564) and shielded pools.
- Send privacy
- The property that outgoing payments do not reveal which of your funds you used, your remaining balance, or links to your other counterparties. Solved by shielded pools (Railgun, Aztec) and chain-native privacy (Monero).
- EIP-5564
- The Ethereum standard for stealth addresses, derived from Vitalik Buterin's January 20, 2023 article. Implemented by Umbra, Fluidkey, and an increasing number of wallets in 2025-2026.
- Kohaku
- An Ethereum Foundation initiative focused on integrating privacy primitives into the Ethereum reference stack, with collaboration on shielded-pool standards including work alongside Railgun.
- Noir
- A Rust-inspired programming language for writing zero-knowledge circuits, used by the Aztec Ignition Chain (mainnet November 2025) for private smart-contract development.
- Leo
- Aleo's zero-knowledge programming language, used to write applications that run on the Aleo mainnet (launched September 18, 2024). Designed for first-class private inputs and selective disclosure.
- JoinMarket
- A peer-to-peer Bitcoin CoinJoin implementation with no central coordinator, distinguishable from Wasabi or Samourai in that there is no operator to indict or shut down.
- Address poisoning
- An attack where a scammer sends a tiny dust transaction from a vanity address that mimics one of your real counterparties, hoping you copy the wrong address from your transaction history. Defended by always verifying full addresses and using a named address book.
- Coin control
- Manual selection of which UTXOs to spend in a Bitcoin transaction. Implemented in wallets like Sparrow. Foundational to preventing accidental cluster merging that lets analysts link unrelated UTXOs to a single owner.
- Temporal mixing
- Waiting non-trivial amounts of time between deposit and withdrawal in a shielded pool to defeat timing-correlation analysis. Quick in-and-out flows defeat the privacy guarantees of the pool.
- Selective disclosure
- The ability to reveal specific facts (a balance, a counterparty, a tax-relevant flow) to a chosen party — auditor, accountant, regulator — without revealing your full transaction history. A core design goal of modern shielded-pool systems.
Read the full lesson in the CryptoBipto app.
Open lessonEducational only — not financial advice.
