7

I'm struggling to understand how ring signatures protect against blockchain analysis.

Each time a transaction is made on the Monero blockchain some outputs already present on the blockchain are used to make a ring signature so that there is no way of knowing which output in the ring is spent.

But as the ring signature is built with old outputs found in the blockchain is it not obvious that the first time an output appears in the blockchain is when this output was really spent?

hyc
  • 4,253
  • 19
  • 21
ant Bldel
  • 1,281
  • 8
  • 15

1 Answers1

4

Remember that other users (those that are not the "owner" of an output) also use this output in their rings as soon as it appears in the blockchain.
So an output might (and most likely will) appear many times in many different rings prior to be actually spent by its owner.

binaryFate
  • 594
  • 2
  • 8