What is Nostr?
Ademan /
npub19je…pt7r
2023-11-19 14:15:17

Ademan on Nostr: #asknostr Hey waxwing I figure you're the guy to ask here. If I'm building a coinjoin ...

#asknostr

Hey waxwing (nprofile…47xm) I figure you're the guy to ask here. If I'm building a coinjoin but want to *consolidate* two outputs from separate participants which are going to the same recipient, how can all participants validate that their coins are accounted for in the outputs *without* sharing their destinations and amounts with all other participants? I assume this is possible, but I'm struggling to construct it.

ex

A sending 1BTC to D
B sending 1BTC to E
C sending 2BTC to D

Ideally, the outputs would be

3BTC to D
1BTC to E

But how can participants differentiate that from

2BTC to D
1BTC to E
1BTC to F

(without knowing the destinations of each participant's coins, ruining all unlinkability)

I've had a few ideas, but I've run into a brick wall every time. Blinded addition seems not to be useful, since you need to first prove you have contributed enough in inputs which seems to necessitate linking your blinded value to the inputs, ahead of time, negating the value of blinded addition?

I hope I'm missing something obvious (or even a paper doing exactly this?)
Author Public Key
npub19jescdjr3wk552j3q77f3awwhe4qy2ds24xce773exd28nr7emqsm2pt7r