PING and REJECT: The Impact of Side-Channels on Zcash Privacy (
)
"We present two types of active side-channel attacks against private (a.k.a. shielded) transactions in Zcash. The attacks, called PING and REJECT, exploit differences in behavior between the payee of a particular shielded transaction and the remaining Zcash clients. By monitoring peer-to-peer traffic and injecting its own messages, an active attacker can remotely observe these differences due to fault and timing side-channels."