The Ledger Was Always Public
On Lords of Crypto Crime, and how the internet money everyone swore was anonymous kept getting people arrested.
In 2011, Andy Greenberg wrote a Forbes cover story about Bitcoin. It was one of the first big mainstream features on it, and it helped set the terms everyone used for the next decade: internet money, outside the banks, effectively anonymous.
Eleven years later he published a book about how wrong that was, and he is upfront about his own part in it: "I'm guilty of thinking that bitcoin was a privacy-preserving technology back in 2011."
The book is Lords of Crypto Crime here, and Tracers in the Dark in the US, same text. I went in expecting a heist procedural, and it is one, and the heists are great. It is also, quietly, a book about what happens when nobody reads the documentation.
Worse than a bank
I spent a couple of years at a core banking company, so I am fonder of boring financial ledgers than most people. A bank's ledger is private, you need a subpoena to see it, it stops at a national border, and one day it gets deleted, because retention policies are finite.
Bitcoin's ledger is the opposite on all four counts. Public, no subpoena needed, no jurisdiction, kept forever. None of that was ever a secret, it is just how the thing works. What the book is really good on is how long almost everybody managed not to take it seriously, up to and including people running billion-dollar drug markets on top of it.
The part that actually spooked me is that the tracing works backwards. Nobody had to be watching you in 2012. They can reconstruct 2012 in 2020, from a copy of the ledger you helped publish. And as Greenberg points out, nothing had to be weakened to make that possible. No backdoor, no broken encryption. Everyone opted in.
It was all in a paper from 2013
The technical heart of the book is a paper Sarah Meiklejohn published as a PhD student in 2013, called "A Fistful of Bitcoins." I only know it through the book, but the abstract contains the sentence the whole tracing industry grew out of:
Bitcoin has the unintuitive property that while the ownership of money is implicitly anonymous, its flow is globally visible.
The method has two parts, and the first was already known: if two addresses are used as inputs to the same transaction, the same person controls both. Applied to the whole chain, that collapsed everything into about 5.5 million clusters.
The second part was hers. When you spend Bitcoin you have to spend the whole input, so the remainder comes back to you at a freshly generated "change" address, one your wallet software creates silently and you may never see. If exactly one output of a transaction is a brand new address receiving for the first time, it is almost certainly the change coming home, which means it belongs to the sender. Follow that link at every hop and you can walk a chain of hundreds of transactions and see who actually got paid.
My favourite bit is how unglamorous the rest of it was. A cluster is anonymous until you can attach a name to it, and the way they attached names was to go shopping. They made 344 transactions with real services. They mined on a Radeon graphics card, gambled on Satoshi Dice, bought things from merchants, donated to WikiLeaks, kept a Silk Road wallet. They put money through four laundering services, one of which simply stole it, and another of which twice sent them back their own coins, which the authors note probably means they were its only customer.
Those 344 transactions tagged about 1,070 addresses by hand. Run through the clustering, that turned into over 1.8 million. The weak point was never the cryptography, it was everywhere the system touched the ordinary economy.
One more detail, because it matters later. Her first version of the change heuristic was too eager, and it merged Mt. Gox, Instawallet, BitPay and Silk Road into one enormous blob, which is to say it concluded that the exchange, the payment processor and the drug market were all the same person. She found the behaviours causing it, tightened the rule, and accepted missing a lot of real connections to get the false-positive rate down to about 0.17%.
And all of this was public in 2013. The paper says, more or less in so many words, that an agency with subpoena power could work out who was paying whom. Ross Ulbricht never read it. Neither, apparently, did anyone else in the rest of the book.
The actual crime
I will not spoil the good cases. Two things stood out to me.
The first is the corrupt agents, because they stop the book from being a police recruitment advert. Carl Force of the DEA and Shaun Bridges of the Secret Service were both on the Silk Road task force, and both stole from the investigation they were running. Force took over $700,000 while negotiating a film deal about the case. Bridges took around $820,000, got caught, and then stole roughly 1,600 more bitcoin from a government wallet after his arrest and before reporting to prison. The same ledger caught them too. It does not care which side you are on.
The second is Welcome to Video, where I will just give you the numbers. Eight terabytes. More than 250,000 unique videos, 45% of them previously unknown to investigators. Over a million bitcoin addresses on the server, roughly one per user account. 337 arrests across 38 countries. At least 23 children removed from ongoing abuse. And a lot of those users had paid directly from exchange accounts that were already verified against their real passports.
What happened after the book
The book came out in November 2022, so it misses the case I most wanted its opinion on. In March 2024 a man called Roman Sterlingov was convicted of running Bitcoin Fog, a long-running mixing service, largely on blockchain tracing done with Chainalysis software. His defence argued the software should not be admissible at all, because it is a black box with no published error rate. Under questioning, a Chainalysis witness confirmed there are no peer-reviewed studies of the tool's accuracy, and a competing firm reportedly ran the same data without reaching the same conclusion. The evidence went in anyway, and he got twelve and a half years.
I have no idea whether he did it. What bugs me is the comparison you can now make: the PhD student published her error rate and tuned her method to avoid false positives, and the industry that commercialised her idea made it to a federal witness stand without producing an equivalent number.
The job she turned down
Chainalysis offered Meiklejohn a job. She said no.
Her worry, in the book, is not really whether the technique works. It is what it does at scale to everyone who is not a criminal: banks quietly dropping customers whose coins have the wrong history somewhere upstream, with no charge, no hearing and nobody to appeal to. As she puts it: then it gets much sketchier, right?
And the ledger is permanent, so whatever privacy you have on it today also depends on tracing techniques nobody has invented yet. I have been chewing on that one since I finished it.
Anyway, read it. I went in for the heists and came out with strong opinions about a 2013 academic paper I still have not actually read, which is probably the best review I can give it.