Quick Summary
- Cake Wallet COO Seth for Privacy, speaking on the Bitcoin Rails podcast this week, warned that one transaction can compromise years of discreet Bitcoin activity.
- Bitcoin wallets do not hold a balance. They hold UTXOs – separate coins from separate past transactions. When a payment is bigger than any single coin, the wallet quietly combines several of them as inputs to the same transaction.
- If one of those coins came from a KYC exchange (your ID on file) and another came from a no-KYC source, that single transaction links them permanently on a public ledger. Everything you spent now carries your identity.
- Seth: “If you ever spend your no-KYC coins with one of your KYC coins – which if you just let the wallet do its thing, it could do because it doesn’t know the difference – you immediately connect all of the non-KYC Bitcoin that you spend in that with your identity.”
- Context: the developers of privacy mixer Samourai Wallet went to trial and were imprisoned last year. Just this week the US Treasury scrapped two long-stalled crypto surveillance proposals, a rare win for privacy advocates.
- The defense has a name, and almost nobody uses it: coin control.
What Actually Happened
This was not a hack. Nobody broke encryption. Nothing was stolen. It was a warning about the default behaviour of the wallet already sitting on your phone.
Seth for Privacy, chief operating officer of the open-source, self-custody wallet Cake Wallet, appeared on the Bitcoin Rails podcast this week and explained the single most common way Bitcoin users expose themselves without ever noticing. He was not talking about exchanges leaking your data or the state subpoenaing a company. He was talking about you pressing send.
Here is the mechanic, in plain English. A Bitcoin wallet does not store one number that says “you have 0.5 BTC”. It stores a collection of separate unspent transaction outputs – UTXOs – each one a distinct chunk of bitcoin from a specific moment in the past. Some of yours arrived from a regulated exchange after you uploaded a passport photo, a selfie and a utility bill. Some of yours arrived from a peer-to-peer trade, an ATM, a friend, or a Lightning swap where nobody ever learned your name.
Those two kinds of coins live in the same wallet and look identical on screen. Your wallet does not label them. It does not know the difference. So when you want to spend more than any one coin holds – and that happens constantly, because exchange withdrawals come in odd sizes – the wallet grabs whatever coins add up to the amount and stuffs them into the same transaction as inputs.
Bitcoin transactions are public. Every input is visible, permanently, to anyone. So the moment your KYC coin and your no-KYC coin ride in the same transaction, a chain-analysis firm does not need to guess anything. The link is arithmetic. Your verified identity and your private stack are now the same entity, on a ledger that can never be edited.
Seth put it bluntly: “If you ever spend your no-KYC coins with one of your KYC coins – which if you just let the wallet do its thing, it could do because it doesn’t know the difference – you immediately connect all of the non-KYC Bitcoin that you spend in that with your identity.”
He also said something that should sting a little. Unlike people in the global South who have already lived under states that freeze, seize and punish, he argued citizens in the West will probably need to “feel pain” before they take privacy seriously. He added that attitudes are shifting, and that over the last five or six years more people – even in the West – have started treating this as a real problem rather than a hobby for tinfoil hats.
Why This Matters for Bitcoin
The entire pitch of Bitcoin is that you can hold and move value without asking permission. That property does not survive contact with a permanently public ledger attached to your legal name.
Think about what a single linked transaction actually gives away. Not just the coins you spent. The cluster. Chain analysis works by assuming that all inputs to a transaction belong to the same person, then walking that assumption outward across every transaction that person ever touched. One careless spend does not expose one coin. It exposes a map of everything those coins ever touched – your savings, your spending habits, the exchange you use, the address your employer paid you from, the wallet you gave your brother.
And this is not happening in a vacuum. We have already covered how the state can only see 14% of global crypto activity, and is openly building a bigger net for the other 86%. We have also covered what happens when the databases the state does control get leaked: 90 violent crypto crimes in France in seven and a half months, with Chainalysis pointing straight at government and tax-firm data breaches as the cause. The list of who owns what, and where they live, is the reconnaissance report. Coin control is the difference between being a row in that database and not being in it at all.
There is a genuine bit of good news this week, and it deserves to be said out loud. The US Treasury scrapped two long-stalled crypto surveillance proposals that privacy advocates had been fighting for years. That is a real win. But a scrapped proposal is not a deleted database. Your KYC file from the exchange still exists. It still links your identity to an address. And it will still be there the next time someone at a regulator decides to try again – or the next time that file ends up on a forum.
The Love Is Bitcoin Takeaway
Here is the part that should make you angry.
Every exchange that took your passport photo told you Bitcoin was “anonymous money”. Every wallet app that hides coin control behind a settings menu told you it was “optimising your fees”. Every influencer who showed you how to consolidate your UTXOs into one tidy balance before a bull run told you it was “good hygiene”.
Not one of them told you what that single click does to your identity. Not one of them said “by the way, this permanently welds your private coins to the address you bought on a regulated exchange with your real name.”
That is not a technical oversight. That is a product decision. Wallets that expose coin control scare users. Wallets that hide it feel simple, and simple wallets get five-star reviews. The convenience you were sold is the surveillance surface somebody else gets to read later.
You do not have to accept the default. Bitcoin is the only money system in history where you are allowed to be your own bank, and banks do not sweep every deposit into one account with their customer’s name stamped on it for the world to read. Bitcoin wallets do, unless you tell them not to.
Coin control is not a hacker trick and it is not a crime. It is basic accounting hygiene, and it is the one setting that separates people who own Bitcoin from people who are merely holding a publicly labelled IOU. If you want a proper threat model for the device doing the signing, start with how to choose a Bitcoin wallet without getting rekt.
What Beginners Should Do Next
- Open your wallet’s coin control view. In most modern wallets it is a toggle or a settings item, not a default screen. If your wallet genuinely has no way to see individual UTXOs, that tells you what it was built for.
- Label every coin by where it came from. KYC coins (exchange withdrawal with your ID on file) versus no-KYC coins (peer-to-peer, ATM, a friend, a swap). This one habit solves most of the problem, because you can only avoid mixing coins you can identify.
- Never let a KYC coin and a no-KYC coin ride in the same transaction. If you need to move value, spend from one group or the other. If you must consolidate, consolidate within a group, not across it.
- Use a fresh receive address every time. Address reuse hands over free information: it confirms that the same person controls both payments.
- Prefer Lightning for small spending. Cake Wallet integrated Lightning this year for exactly this reason – it is faster, cheaper and more private than broadcasting every small payment on the base chain.
- Stop consolidating for fun. Consolidating UTXOs to save fees is a real trade-off, not free. Do it on purpose, within one privacy group, and understand what it publishes about you.
- Remember that self-custody is not the same as privacy. Holding your own keys protects you from a custodian freezing your balance. It does not protect you from a public ledger – read what happened when an exchange lost access to 4,500 BTC of its own cold storage and think about which half of the problem each fix actually solves.
FAQ
What is a UTXO in Bitcoin?
A UTXO, or unspent transaction output, is a discrete chunk of bitcoin left over from a previous transaction. Your wallet balance is just the total of the UTXOs it controls. They are separate objects, not one number, and that distinction is exactly what makes coin control possible.
What is coin control?
Coin control means choosing which specific UTXOs your wallet spends, instead of letting it pick automatically. It lets you keep coins from different sources separate, so one transaction cannot link them together.
Can one Bitcoin transaction really expose my identity?
It can expose the link between coins. If a UTXO tied to your verified identity at a KYC exchange is spent together with a UTXO that had no identity attached, the public ledger now shows those two are the same person’s money. Chain-analysis firms build their entire business model on that assumption.
Does buying on a KYC exchange ruin my privacy forever?
It attaches your identity to those specific coins and the addresses they sit on. It does not automatically reveal unrelated coins – unless you link them yourself by spending them in the same transaction. That is the whole point of keeping groups separate.
Is using coin control illegal?
No. Choosing which of your own coins to spend is ordinary wallet functionality, offered as a standard feature by many mainstream wallets. Privacy is not a crime, and this article is education, not legal advice.
Why do wallets combine my coins automatically?
Because it is simpler for the user, and it usually reduces the number of UTXOs over time. Simplicity is a legitimate design goal – it just happens to be a privacy cost that the user is rarely told about.
What did Seth for Privacy say about Monero?
He said he would rather Bitcoin’s privacy got good enough that Monero was unnecessary – preferring strong privacy in the tool most people actually use over a niche coin with perfect privacy that few people use.
Is this financial advice?
No. This is education only.
Final Thoughts
Bitcoin was never going to be “anonymous money”. That was marketing, and it was always false. Bitcoin is pseudonymous money, and pseudonymity collapses the moment you weld your real identity to the rest of your stack in a single careless transaction.
Your wallet will do it for you, quietly, because it does not know the difference between the coin you bought with your passport and the coin you earned from a stranger. Nobody is going to warn you at the moment it happens. There is no confirmation dialogue that says “this will follow you for the rest of your life”.
So learn the setting. Label the coins. Keep the groups apart. Then buy your next sats through a route that does not build a permanent profile of your stack for you – grab Bull Bitcoin here and use coupon LOVEISBITCOIN so we know where your stack came from.
Now the question, and I want a real answer in the comments: your wallet has been choosing which coins to spend for you this entire time. Do you actually know how many of them came from an exchange with your name on file – or have you been handing out the map for free?
This article is for education only and is not financial advice.
Primary source: Bitcoin Magazine – Here’s How Not To Screw up Your Bitcoin Privacy