# Bitcoin CoinJoin: collaborative transactions and privacy limits

CoinJoin is a way for multiple participants to construct one Bitcoin transaction using inputs they control. Each participant checks the intended result and signs its own inputs. This can make input-to-output ownership harder for an outside observer to infer. It does not hide the transaction from the blockchain, guarantee equal privacy against every observer or require users to give a coordinator their private keys.

Evidence: [CoinJoin: Bitcoin privacy for the real world](https://bitcointalk.org/index.php?topic=279249.0); [Transactions](https://developer.bitcoin.org/devguide/transactions.html)

Canonical: https://degreesofsatoshi.com/encyclopedia/bitcoin-coinjoin/
Published: 2026-10-02
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T19:29:20.637Z
Data current through: 2026-10-02

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Transaction:** Multiple participants contribute inputs ([CoinJoin: Bitcoin privacy for the real world](https://bitcointalk.org/index.php?topic=279249.0))
- **Signing:** Participants authorize their own inputs ([CoinJoin: Bitcoin privacy for the real world](https://bitcointalk.org/index.php?topic=279249.0))
- **Privacy:** Depends on construction and other available information ([CoinJoin: Bitcoin privacy for the real world](https://bitcointalk.org/index.php?topic=279249.0); [Some things you need to know](https://bitcoin.org/en/you-need-to-know))

## Inputs in one transaction need not belong to one person

Gregory Maxwell’s 2013 proposal explains that separate participants can agree on outputs and independently supply signatures. The transaction becomes valid only when all required spending conditions are satisfied. This contradicts treating joint input use as mathematical proof of common ownership.

A coordinator can help arrange a transaction without receiving spending keys. Its knowledge of the input-to-output mapping depends on the protocol; early simple coordination could reveal that mapping to the coordinator.

Evidence: [CoinJoin: Bitcoin privacy for the real world](https://bitcointalk.org/index.php?topic=279249.0)

## Equal outputs create ambiguity under limited assumptions

Suppose three participants each contribute 101,000 satoshis and receive one 100,000-satoshi output. The remaining 3,000 satoshis pay the transaction fee. If an observer knows no further links, the equal values alone do not identify which output belongs to which input.

That does not establish a guaranteed one-in-three anonymity probability. A participant knows its own output, and an observer may have network, coordinator or later-spending information that reduces uncertainty.

Evidence: [CoinJoin: Bitcoin privacy for the real world](https://bitcointalk.org/index.php?topic=279249.0)

## The whole wallet history still matters

The original proposal discusses participants refusing to sign and implementations that reveal different amounts of information. Coordination can fail without producing a completed transaction. A particular product may add fees or other requirements beyond the general technique.

Address reuse and identifiable later activity can undermine an earlier privacy gain. Evaluate the actual software and observable information rather than assuming every transaction called CoinJoin has the same anonymity properties.

Evidence: [CoinJoin: Bitcoin privacy for the real world](https://bitcointalk.org/index.php?topic=279249.0); [Some things you need to know](https://bitcoin.org/en/you-need-to-know)

## Questions

### Does CoinJoin automatically transfer custody to a mixer?

No. The collaborative-signing design allows participants to retain their keys and approve the transaction. A separate service that takes custody has different assumptions and should not be treated as equivalent merely because of a label.

Evidence: [CoinJoin: Bitcoin privacy for the real world](https://bitcointalk.org/index.php?topic=279249.0)

### Are all equal-valued outputs guaranteed to belong to different people?

No. Values alone do not establish distinct human owners. The illustrative privacy benefit depends on participation and what an observer already knows.

Evidence: [CoinJoin: Bitcoin privacy for the real world](https://bitcointalk.org/index.php?topic=279249.0)

## Claims and scope

### bitcoin-coinjoin-quick-answer

CoinJoin is a way for multiple participants to construct one Bitcoin transaction using inputs they control. Each participant checks the intended result and signs its own inputs. This can make input-to-output ownership harder for an outside observer to infer. It does not hide the transaction from the blockchain, guarantee equal privacy against every observer or require users to give a coordinator their private keys.

Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-coinjoin-fact-transaction

Transaction: Multiple participants contribute inputs

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-coinjoin-fact-signing

Signing: Participants authorize their own inputs

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-coinjoin-fact-privacy

Privacy: Depends on construction and other available information

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

## Sources

- [CoinJoin: Bitcoin privacy for the real world](https://bitcointalk.org/index.php?topic=279249.0) — Gregory Maxwell on BitcoinTalk. Collaborative transaction construction and common-input clustering limitations. Locator: Original proposal post: independent input signatures; equal outputs; coordination. Retrieved: 2026-10-02T18:53:56.953Z.
- [Transactions](https://developer.bitcoin.org/devguide/transactions.html) — Bitcoin developer documentation. Inputs, outputs, authorization, change, coinbase exceptions and fee accounting. Locator: Introduction; Spending An Output; P2PKH Script Validation; Multisig; Transaction Fees And Change; Avoiding Key Reuse. Retrieved: 2026-10-02T18:53:53.759Z.
- [Some things you need to know](https://bitcoin.org/en/you-need-to-know) — Bitcoin.org. Payment reversibility, confirmation risk and visible transaction records. Locator: Bitcoin payments are irreversible; Unconfirmed transactions aren't secure; You are your own bank; Bitcoin is not anonymous. Retrieved: 2026-10-02T18:53:53.609Z.

## Revision history

- 2026-10-02: First publication after primary-source research and separate automated verification.

## Cite this entry

Degrees of Satoshi editorial project. “Bitcoin CoinJoin: collaborative transactions and privacy limits.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-coinjoin/
