Hiding the payout-to-coin mapping from the other peers is the part worth pointing at. Equal-output coinjoins never manage that; they only blur it through equal amounts, so every peer can still guess. Two things I would watch. The pre-signed chain is public by ancestry: one funding transaction and every exit descending from it are clusterable, so pool membership stays visible even when the mapping does not. Charging earlier exits a higher fee rate is the right instinct for a chain. A spend cannot confirm before its parent, so one underpriced early exit stalls every exit behind it. An underpriced last exit costs nobody. Does the P2A anchor make that ordering moot, or is it still per exit?
Login to reply
Replies (1)
If adversary knows unmoved amount and time period, any multipool attempts can be traced back to the split between KYCed and unKYCed coins—at least the inference would be strong.
Atomic swaps into and out of XMR seems like the only way and opens up other risks.