{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "bitcoin-coinjoin",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/bitcoin-coinjoin/",
  "collection": "bitcoin",
  "title": "Bitcoin CoinJoin: collaborative transactions and privacy limits",
  "description": "Understand CoinJoin as collaborative Bitcoin transaction construction, including signing control and the limits of equal-output privacy.",
  "aliases": [
    "bitcoin coinjoin explained",
    "bitcoin coinjoin explained explained"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T19:29:20.637Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "CoinJoin is a way for multiple participants to construct one Bitcoin transaction using inputs they control. Each participant checks the intended result and signs its own inputs. This can make input-to-output ownership harder for an outside observer to infer. It does not hide the transaction from the blockchain, guarantee equal privacy against every observer or require users to give a coordinator their private keys.",
    "claimId": "bitcoin-coinjoin-quick-answer",
    "sourceIds": [
      "x425-btc-coinjoin",
      "x425-btc-dev-transactions"
    ]
  },
  "keyFacts": [
    {
      "label": "Transaction",
      "value": "Multiple participants contribute inputs",
      "sourceIds": [
        "x425-btc-coinjoin"
      ],
      "id": "transaction",
      "claimId": "bitcoin-coinjoin-fact-transaction"
    },
    {
      "label": "Signing",
      "value": "Participants authorize their own inputs",
      "sourceIds": [
        "x425-btc-coinjoin"
      ],
      "id": "signing",
      "claimId": "bitcoin-coinjoin-fact-signing"
    },
    {
      "label": "Privacy",
      "value": "Depends on construction and other available information",
      "sourceIds": [
        "x425-btc-coinjoin",
        "x425-btc-know"
      ],
      "id": "privacy",
      "claimId": "bitcoin-coinjoin-fact-privacy"
    }
  ],
  "prerequisites": [
    "is-bitcoin-anonymous",
    "bitcoin-address-reuse"
  ],
  "sections": [
    {
      "id": "ownership",
      "heading": "Inputs in one transaction need not belong to one person",
      "sourceIds": [
        "x425-btc-coinjoin"
      ],
      "paragraphs": [
        "Gregory Maxwell’s 2013 proposal explains that separate participants can agree on outputs and independently supply signatures. The transaction becomes valid only when all required spending conditions are satisfied. This contradicts treating joint input use as mathematical proof of common ownership.",
        "A coordinator can help arrange a transaction without receiving spending keys. Its knowledge of the input-to-output mapping depends on the protocol; early simple coordination could reveal that mapping to the coordinator."
      ]
    },
    {
      "id": "example",
      "heading": "Equal outputs create ambiguity under limited assumptions",
      "sourceIds": [
        "x425-btc-coinjoin"
      ],
      "paragraphs": [
        "Suppose three participants each contribute 101,000 satoshis and receive one 100,000-satoshi output. The remaining 3,000 satoshis pay the transaction fee. If an observer knows no further links, the equal values alone do not identify which output belongs to which input.",
        "That does not establish a guaranteed one-in-three anonymity probability. A participant knows its own output, and an observer may have network, coordinator or later-spending information that reduces uncertainty."
      ]
    },
    {
      "id": "limits",
      "heading": "The whole wallet history still matters",
      "sourceIds": [
        "x425-btc-coinjoin",
        "x425-btc-know"
      ],
      "paragraphs": [
        "The original proposal discusses participants refusing to sign and implementations that reveal different amounts of information. Coordination can fail without producing a completed transaction. A particular product may add fees or other requirements beyond the general technique.",
        "Address reuse and identifiable later activity can undermine an earlier privacy gain. Evaluate the actual software and observable information rather than assuming every transaction called CoinJoin has the same anonymity properties."
      ]
    }
  ],
  "faq": [
    {
      "question": "Does CoinJoin automatically transfer custody to a mixer?",
      "answer": "No. The collaborative-signing design allows participants to retain their keys and approve the transaction. A separate service that takes custody has different assumptions and should not be treated as equivalent merely because of a label.",
      "sourceIds": [
        "x425-btc-coinjoin"
      ]
    },
    {
      "question": "Are all equal-valued outputs guaranteed to belong to different people?",
      "answer": "No. Values alone do not establish distinct human owners. The illustrative privacy benefit depends on participation and what an observer already knows.",
      "sourceIds": [
        "x425-btc-coinjoin"
      ]
    }
  ],
  "claims": [
    {
      "id": "bitcoin-coinjoin-quick-answer",
      "articleSlug": "bitcoin-coinjoin",
      "statement": "CoinJoin is a way for multiple participants to construct one Bitcoin transaction using inputs they control. Each participant checks the intended result and signs its own inputs. This can make input-to-output ownership harder for an outside observer to infer. It does not hide the transaction from the blockchain, guarantee equal privacy against every observer or require users to give a coordinator their private keys.",
      "sourceIds": [
        "source-24799b57e0005e64",
        "source-b282fdecc069b74d"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-24799b57e0005e64",
          "locator": "Original proposal post: independent input signatures; equal outputs; coordination"
        },
        {
          "sourceId": "source-b282fdecc069b74d",
          "locator": "Introduction; Spending An Output; P2PKH Script Validation; Multisig; Transaction Fees And Change; Avoiding Key Reuse"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read Maxwell’s original2013post and its coordination/DoS/privacy FAQ.303,000sat inputs balance300,000outputs+3000fee. Equal outputs do not guarantee one-in-three anonymity or distinct human owners; coordinator knowledge and later observation are qualified."
        ]
      }
    },
    {
      "id": "bitcoin-coinjoin-fact-transaction",
      "articleSlug": "bitcoin-coinjoin",
      "statement": "Transaction: Multiple participants contribute inputs",
      "sourceIds": [
        "source-24799b57e0005e64"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-24799b57e0005e64",
          "locator": "Original proposal post: independent input signatures; equal outputs; coordination"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read Maxwell’s original2013post and its coordination/DoS/privacy FAQ.303,000sat inputs balance300,000outputs+3000fee. Equal outputs do not guarantee one-in-three anonymity or distinct human owners; coordinator knowledge and later observation are qualified."
        ]
      }
    },
    {
      "id": "bitcoin-coinjoin-fact-signing",
      "articleSlug": "bitcoin-coinjoin",
      "statement": "Signing: Participants authorize their own inputs",
      "sourceIds": [
        "source-24799b57e0005e64"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-24799b57e0005e64",
          "locator": "Original proposal post: independent input signatures; equal outputs; coordination"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read Maxwell’s original2013post and its coordination/DoS/privacy FAQ.303,000sat inputs balance300,000outputs+3000fee. Equal outputs do not guarantee one-in-three anonymity or distinct human owners; coordinator knowledge and later observation are qualified."
        ]
      }
    },
    {
      "id": "bitcoin-coinjoin-fact-privacy",
      "articleSlug": "bitcoin-coinjoin",
      "statement": "Privacy: Depends on construction and other available information",
      "sourceIds": [
        "source-24799b57e0005e64",
        "source-ba4dc8db91e16d53"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-24799b57e0005e64",
          "locator": "Original proposal post: independent input signatures; equal outputs; coordination"
        },
        {
          "sourceId": "source-ba4dc8db91e16d53",
          "locator": "Bitcoin payments are irreversible; Unconfirmed transactions aren't secure; You are your own bank; Bitcoin is not anonymous"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read Maxwell’s original2013post and its coordination/DoS/privacy FAQ.303,000sat inputs balance300,000outputs+3000fee. Equal outputs do not guarantee one-in-three anonymity or distinct human owners; coordinator knowledge and later observation are qualified."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "x425-btc-coinjoin",
      "label": "CoinJoin: Bitcoin privacy for the real world",
      "publisher": "Gregory Maxwell on BitcoinTalk",
      "url": "https://bitcointalk.org/index.php?topic=279249.0",
      "locator": "Original proposal post: independent input signatures; equal outputs; coordination",
      "note": "Collaborative transaction construction and common-input clustering limitations.",
      "version": "Original 2013 proposal; historical mechanism, not a current service endorsement",
      "checkedAt": "2026-10-02T18:53:56.953Z",
      "contentSha256": "0d32a73b96f6afefeee1d32f6392c86164bb5c964f081a37a4b5a42a9ddb32a5",
      "recordId": "source-24799b57e0005e64"
    },
    {
      "id": "x425-btc-dev-transactions",
      "label": "Transactions",
      "publisher": "Bitcoin developer documentation",
      "url": "https://developer.bitcoin.org/devguide/transactions.html",
      "locator": "Introduction; Spending An Output; P2PKH Script Validation; Multisig; Transaction Fees And Change; Avoiding Key Reuse",
      "note": "Inputs, outputs, authorization, change, coinbase exceptions and fee accounting.",
      "version": "Developer guide; historical implementation details require qualification",
      "checkedAt": "2026-10-02T18:53:53.759Z",
      "contentSha256": "2f3fc474d51880e6c7fd4c25f747f8d8d8da49a493ab82af8ff4916fa490d6b8",
      "recordId": "source-b282fdecc069b74d"
    },
    {
      "id": "x425-btc-know",
      "label": "Some things you need to know",
      "publisher": "Bitcoin.org",
      "url": "https://bitcoin.org/en/you-need-to-know",
      "locator": "Bitcoin payments are irreversible; Unconfirmed transactions aren't secure; You are your own bank; Bitcoin is not anonymous",
      "note": "Payment reversibility, confirmation risk and visible transaction records.",
      "checkedAt": "2026-10-02T18:53:53.609Z",
      "contentSha256": "929c698d3e96a7886d6e701b8d55470e6a3586d7eb525325e8993f9c56feb6c0",
      "recordId": "source-ba4dc8db91e16d53",
      "version": null
    }
  ],
  "related": {
    "articles": [
      "is-bitcoin-anonymous",
      "bitcoin-address-reuse",
      "bitcoin-coin-control",
      "bitcoin-payjoin"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and separate automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Bitcoin CoinJoin: collaborative transactions and privacy limits.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-coinjoin/"
}
