Encyclopedia How the network works · Entry 225
Bitcoin CoinJoin: collaborative transactions and privacy limits
In this article
At a glance
Key facts
Inputs in one transaction need not belong to one person
Gregory Maxwell’s 2013 proposal explains that separate participants can agree on outputs and independently supply signatures. The transaction becomes valid only when all required spending conditions are satisfied. This contradicts treating joint input use as mathematical proof of common ownership.
A coordinator can help arrange a transaction without receiving spending keys. Its knowledge of the input-to-output mapping depends on the protocol; early simple coordination could reveal that mapping to the coordinator.
Equal outputs create ambiguity under limited assumptions
Suppose three participants each contribute 101,000 satoshis and receive one 100,000-satoshi output. The remaining 3,000 satoshis pay the transaction fee. If an observer knows no further links, the equal values alone do not identify which output belongs to which input.
That does not establish a guaranteed one-in-three anonymity probability. A participant knows its own output, and an observer may have network, coordinator or later-spending information that reduces uncertainty.
The whole wallet history still matters
The original proposal discusses participants refusing to sign and implementations that reveal different amounts of information. Coordination can fail without producing a completed transaction. A particular product may add fees or other requirements beyond the general technique.
Address reuse and identifiable later activity can undermine an earlier privacy gain. Evaluate the actual software and observable information rather than assuming every transaction called CoinJoin has the same anonymity properties.
Direct answers
Questions people ask
Does CoinJoin automatically transfer custody to a mixer?
No. The collaborative-signing design allows participants to retain their keys and approve the transaction. A separate service that takes custody has different assumptions and should not be treated as equivalent merely because of a label.
Are all equal-valued outputs guaranteed to belong to different people?
No. Values alone do not establish distinct human owners. The illustrative privacy benefit depends on participation and what an observer already knows.
Inspect the evidence
The answer and key facts have stable claim links. These records retain the scope and qualification when reused.
CoinJoin is a way for multiple participants to construct one Bitcoin transaction using inputs they control. Each participant checks the intended result and signs its own inputs. This can make input-to-output ownership harder for an outside observer to infer. It does not hide the transaction from the blockchain, guarantee equal privacy against every observer or require users to give a coordinator their private keys.
Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.
Link to this claimTransaction: Multiple participants contribute inputs
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.
Link to this claimSigning: Participants authorize their own inputs
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.
Link to this claimPrivacy: Depends on construction and other available information
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.
Link to this claimRevision history
- — First publication after primary-source research and separate automated verification.
Source register
Sources and references
Retrieval dates and locators are recorded individually.- CoinJoin: Bitcoin privacy for the real worldGregory Maxwell on BitcoinTalk
Collaborative transaction construction and common-input clustering limitations.
Locator: Original proposal post: independent input signatures; equal outputs; coordination · Version / scope: Original 2013 proposal; historical mechanism, not a current service endorsement · Retrieved: 2026-10-02T18:53:56.953ZOpen source - TransactionsBitcoin developer documentation
Inputs, outputs, authorization, change, coinbase exceptions and fee accounting.
Locator: Introduction; Spending An Output; P2PKH Script Validation; Multisig; Transaction Fees And Change; Avoiding Key Reuse · Version / scope: Developer guide; historical implementation details require qualification · Retrieved: 2026-10-02T18:53:53.759ZOpen source - Some things you need to knowBitcoin.org
Payment reversibility, confirmation risk and visible transaction records.
Locator: Bitcoin payments are irreversible; Unconfirmed transactions aren't secure; You are your own bank; Bitcoin is not anonymous · Retrieved: 2026-10-02T18:53:53.609ZOpen source
Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.
Editorial method and correctionsDegrees of Satoshi editorial project. “Bitcoin CoinJoin: collaborative transactions and privacy limits.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-coinjoin/