https://mempool.space/signet/tx/2070fba2551a5702bcfbe9644866...

npub1vadcfln4ugt2h9ruwsuwu5vu5am4xaka7pw6m7axy79aqyhp6u5q9knuu7
hex
822deb9f2f42221af530f817ba7c32626a87465bc9163613b2513b338635681enevent
nevent1qqsgyt0tnuh5ygs675c0s9a60sexy658geduj93kzwe9zwensc6ks8sprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsxwkuyle67y94tj378gw8w2xw2wa6nwmwlqhddlwnz0z7sztsaw2q7gasr0Kind-1 (TextNote)
https://mempool.space/signet/tx/2070fba2551a5702bcfbe964486692d8a5d4519bd58ae2ee2a7d6bf5aed847d4
https://mempool.space/signet/tx/c9e68df6f7384bc43a4379007265ff343e8c381e7ab232e7ea9b94037598803d#vin=0
Nothing about the two transactions shown is strange. The first is 2 in 2 out, the second is 1 in, 2 out; normal payments [1]. If you examine their witness you'll see they're like 90% of other taproot transactions, just keypath, no scripts involved.
But in fact, this is a bet. Two parties flipped a fair coin for the winnings (a small chunk of the input funds). Not literally; they used cryptography to get an exactly 50% chance of winning without having to trust the other. They were both running signet nodes (in fact I had one on my laptop at home and another on a VPS), and used decoy packets in BIP324 (bitcoin p2p encrypted transport) to communicate, so no one could even know the negotiation was happening (side note: this idea feels like it should be useful in many other contexts, and it's surprisingly easy to set up, with a very simple patch to your bitcoind).
So we have a fair bet inside a coinjoin; you could think of it as a randomized payjoin if you like, but, the transfer of funds is not for some goods and services but, just a wager, and it's perfectly fair because of a cryptographic trick that was discussed on delving [2] though it's changed from what was written there.
Payments inside coinjoins break subset sum analysis; this is just another kind of payment. Amongst other virtues of such a system is that it creates economic activity between peers without middlemen which is vital to Bitcoin's general pseudonymity.
The implementation is at https://github.com/AdamISZ/babilonia . The repo is currently 95% AI-written so not very readable (still not unreadable, but, y'know how it is) but I have a paper that I've nearly finished that is human written and human readable for those interested in the mechanics.
[1] In fact those familiar with details of payjoins will see something specific about the 1st transaction that makes it like a payjoin. But it isn't hard to remove that, and anyway, it's only a watermark for 'this is a payjoin', not for what it actually is...
[2] https://delvingbitcoin.org/t/emulating-op-rand/1409/7

Raw JSON
{
"kind": 1,
"id": "822deb9f2f42221af530f817ba7c32626a87465bc9163613b2513b338635681e",
"pubkey": "675b84fe75e216ab947c7438ee519ca7775376ddf05dadfba6278bd012e1d728",
"created_at": 1783778343,
"tags": [
[
"t",
"vin"
],
[
"imeta",
"url https://blossom.primal.net/a48090a76e663837a697a4008abfc0aa9c49f505fdf238ebcd1f851ce2a01ea8.png",
"m image/png",
"ox a48090a76e663837a697a4008abfc0aa9c49f505fdf238ebcd1f851ce2a01ea8",
"dim 1922x295"
],
[
"imeta",
"url https://blossom.primal.net/1dd37511b54623453e8cfdca3dd433d5bb4a50e8a26c7e9b623dce8067f0ebcb.png",
"m image/png",
"ox 1dd37511b54623453e8cfdca3dd433d5bb4a50e8a26c7e9b623dce8067f0ebcb",
"dim 1922x295"
],
[
"client",
"Primal Android"
]
],
"content": "https://mempool.space/signet/tx/2070fba2551a5702bcfbe964486692d8a5d4519bd58ae2ee2a7d6bf5aed847d4\n\nhttps://mempool.space/signet/tx/c9e68df6f7384bc43a4379007265ff343e8c381e7ab232e7ea9b94037598803d#vin=0\n\nNothing about the two transactions shown is strange. The first is 2 in 2 out, the second is 1 in, 2 out; normal payments [1]. If you examine their witness you'll see they're like 90% of other taproot transactions, just keypath, no scripts involved.\n\nBut in fact, this is a bet. Two parties flipped a fair coin for the winnings (a small chunk of the input funds). Not literally; they used cryptography to get an exactly 50% chance of winning without having to trust the other. They were both running signet nodes (in fact I had one on my laptop at home and another on a VPS), and used decoy packets in BIP324 (bitcoin p2p encrypted transport) to communicate, so no one could even know the negotiation was happening (side note: this idea feels like it should be useful in many other contexts, and it's surprisingly easy to set up, with a very simple patch to your bitcoind).\n\nSo we have a fair bet inside a coinjoin; you could think of it as a randomized payjoin if you like, but, the transfer of funds is not for some goods and services but, just a wager, and it's perfectly fair because of a cryptographic trick that was discussed on delving [2] though it's changed from what was written there.\n\nPayments inside coinjoins break subset sum analysis; this is just another kind of payment. Amongst other virtues of such a system is that it creates economic activity between peers without middlemen which is vital to Bitcoin's general pseudonymity.\n\nThe implementation is at https://github.com/AdamISZ/babilonia . The repo is currently 95% AI-written so not very readable (still not *unreadable*, but, y'know how it is) but I have a paper that I've nearly finished that is human written and human readable for those interested in the mechanics. \n\n[1] In fact those familiar with details of payjoins *will* see something specific about the 1st transaction that makes it like a payjoin. But it isn't hard to remove that, and anyway, it's only a watermark for 'this is a payjoin', not for what it *actually* is...\n\n[2] https://delvingbitcoin.org/t/emulating-op-rand/1409/7 \n\n\n\nhttps://blossom.primal.net/a48090a76e663837a697a4008abfc0aa9c49f505fdf238ebcd1f851ce2a01ea8.png\nhttps://blossom.primal.net/1dd37511b54623453e8cfdca3dd433d5bb4a50e8a26c7e9b623dce8067f0ebcb.png",
"sig": "c858ea91ca57dc9e1b2886484d3b05de4f9ef198f96d12392146c59eca7d0a49e0da0b32bc38aeef74f97edee71a30f4f5751bf457730890fdf8d868b06b91e7"
}