Researchers dispute over whether Mimblewimble preserves privacy, but they have more to agree than on surface

Quick Take
- Privacy focus blockchain protocol Mimblewimble may not be as private as many users believe, said Dragonfly Capital researcher Ivan Bogatyy
- However, Grin developer Daniel Lehnberg said Bogatyy’s accusation is unfair and attention-grabbing
- The Block talked to both Lehnberg and Bogatyy and discovered that the two have a lot to agree on
We'd love your feedback.
Mimblewimble, a blockchain protocol that is built to “prevent the blockchain from talking about all user’s information,” is in the public hot seat this week.
On Monday, Dragonfly Capital researcher Ivan Bogatyy publicly criticized Grin, a project that implements Mimblewimble, for not being on par with other privacy tokens such as Zcash and Monero. Grin contributor Daniel Lehnberg soon launched a rebuttal, charging Bogatyy’s blog post for “attention-grabbing.” The price of Grin token also took a 13% dip on Monday.
However, as opposing as the two sides appear, they have more to agree under the surface, The Block found after talking with both Bogatyy and Lehnberg.
Bogatyy’s main accusation of Mimblewimble is that the privacy-oriented protocol is not as private as many think. According to Bogatyy, users of privacy tokens usually expect the protocol to hide all transaction details, including the amount of tokens being transferred, where these tokens are from, and where they go. On Mimblewimble and Grin's Github page, it is also stated that a "crucial tenet" of the protocol is "strong privacy and confidentiality guarantees."
However, Grin, while hiding transaction amounts, still reveals the transaction graph of each token, which could further lead to the leak of personal identities, said Bogatyy.
“My claim is that Grin’s privacy is more similar to Bitcoin than people thought before,” Bogatyy told The Block.
This is a point that Lehnberg would in fact concur. “Grin is more like bitcoin than other privacy coins,” said the Grin developer to The Block, admitting that the Mimblewimble protocol indeed reveals transaction graphs.
However, Leghberg also stressed that this has been known among Grin developers since 2018. While Bogatyy claimed he was able to obtain 96% of all the transactions on the network, Lehnberg disputed that running a few full nodes on the Grin network would essentially give anyone similar information, and Grin developers have been aware of this all along.
“It’s a mystery to me what exactly it is that’s supposed to have been broken here,” said Lehnberg.
According to Lehnberg, it is also useless to simply acquire a list of transactions without any KYC information, which Bogatyy conceded to be a ”fair point.” Bogatyy stated in his original blog post that once transaction graphs are known, users may also risk being identified by law enforcement agencies or authorities for conducting these transactions. However, Lehnberg noted that this will only happen when KYC details are also available.
“If an attacker transacts repeatedly with a specific target and this target then transacts with an exchange that the attacker controls, which the target has given their KYC details to, then they might be able to identify the target. It's worth noting that any decoy-based protocol would be vulnerable to this, including Monero,” said Leghberg.
Although Bogatyy’s findings may not be new to Grin developers, they are actively seeking solutions to reduce the exposure of transaction graphs, despite Bogatyy’s belief that this is an intrinsic problem to the protocol. Grin also tries to differentiate itself from other privacy tokens like ZK-SNARKs-based Zcash by increasing scalability.
“ZK-SNARKs are really cool, but they are still very experimental, come with different security assumptions, and scale badly compared to Mimblewimble,” said Lehnberg. "That said, the scientific community is currently making dramatic progress in zero-knowledge research, and this will undoubtedly lead to strong privacy improvements over time.”
Meanwhile, Bogatyy cautions users against completely trusting Grin for privacy protection and suggest developers seeking strong privacy to opt for a combination of Mimblewimble and other protocols.
“I think, generally speaking, users are not digging through the code, not studying the protocol in detail, they don't necessarily know what all that necessarily means.”
© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

