{"id":"d3a399c6-ebfa-4272-970d-27364db7d969","arxiv_id":"2605.29131","paper_version":1,"verdict":"CONDITIONAL","confidence":"LOW","novelty_score":3.0,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"A proof-of-concept Tor push protocol implemented in Nimbus on Goerli testnet achieves validator IP unlinkability with 613.82 ms average latency overhead while maintaining network performance.","lead":"The paper implements and tests a Tor-based protocol called Tor push in the Nimbus Ethereum client to unlink validator identities from their IP addresses on the Goerli testnet. A smart generalist might read it to see a practical approach for protecting blockchain networks from IP-targeted attacks like DoS that could disrupt operations.","discovery_kind":"new_application","skeptic_critique":{"model":"grok-4.3","headline":"Goerli PoC latency and privacy results may not generalize to mainnet due to scale, load, and adversary differences","rationale":"The reader's weakest_assumption directly identifies the extrapolation step that the experimental evidence does not cover. No stronger internal inconsistency appears from the abstract and the stated claim; the testnet-to-mainnet gap is the precise location where the argument is least secure.","tokens_in":1781,"tokens_out":339,"duration_ms":12833,"concrete_test":"Re-run the PoC on Holesky (or a mainnet shadow deployment) with at least 50k validators, synthetic mainnet traffic load, and an adversary controlling 5-10% of Tor exits; measure both median attestation latency and success rate of a realistic correlation attack that combines timing and circuit fingerprinting. If either metric degrades beyond the Goerli numbers by >20%, the central claim does not transfer.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The headline claim rests on the measured 613.82 ms average overhead and security properties from the Nimbus PoC on Goerli being representative. Goerli runs at ~10k validators with minimal economic stakes and low adversarial pressure, while mainnet has >500k validators, 12-second slots, and sophisticated attackers who can combine timing, traffic analysis, and partial node control. The paper does not report measurements under mainnet-scale bandwidth contention, validator density, or Tor circuit churn that would occur when many validators adopt the same exit relays. Without those conditions, both the \"tolerable\" latency claim and the unlinkability guarantee remain untested at the operating point that matters.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.3","summary":"The paper reviews network- and consensus-layer techniques for Ethereum validator privacy, introduces a Tor-based 'Tor push' protocol to unlink validator IDs from beacon node IP addresses, describes a deployed PoC implementation in the Nimbus client that routes attestations, aggregations, and proposals over Tor to the Goerli testnet, reports an average latency overhead of 613.82 ms from this deployment, and provides a security analysis, concluding that Tor integration yields tolerable overhead while enhancing location privacy without compromising overall network performance.","tokens_in":1920,"tokens_out":396,"duration_ms":28511,"significance":"If the measured latency and unlinkability properties hold under realistic conditions, the work supplies direct empirical evidence from a working PoC for a practical mechanism to mitigate IP-based attacks (DoS, MEV, finality risks) on Ethereum validators. The deployed Nimbus implementation on Goerli is a concrete strength, offering a falsifiable performance data point rather than purely theoretical analysis.","major_comments":[{"comment":"The central performance claim rests on the reported 613.82 ms average latency overhead (abstract and evaluation), yet the manuscript provides no description of experimental methodology, number of trials, statistical analysis, variance, or comparison baselines. This directly weakens the evidence for the 'tolerable' and 'without compromising overall network performance' assertions.","section":"Evaluation / Experimental Results"},{"comment":"The PoC was run on Goerli (~10k validators, low stakes). The manuscript does not analyze or measure behavior under mainnet-scale conditions (>500k validators, 12-second slots, higher bandwidth contention, Tor circuit churn, or combined timing/traffic-analysis adversaries), which is load-bearing for the claim that results generalize and network performance remains uncompromised.","section":"Discussion / Scalability Analysis"}],"minor_comments":[],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":{"model":"grok-4.3","summary":"We thank the referee for the constructive feedback. Below we respond point by point to the major comments.","responses":[{"response":"We agree that the evaluation section lacks sufficient methodological detail. The reported 613.82 ms figure originates from latency measurements collected during the Nimbus PoC deployment on Goerli, but the manuscript does not describe the number of trials, variance, statistical methods, or non-Tor baselines. We will revise the evaluation section to include these elements, thereby strengthening support for the performance claims.","revision_made":"yes","referee_comment":"[Evaluation / Experimental Results] The central performance claim rests on the reported 613.82 ms average latency overhead (abstract and evaluation), yet the manuscript provides no description of experimental methodology, number of trials, statistical analysis, variance, or comparison baselines. This directly weakens the evidence for the 'tolerable' and 'without compromising overall network performance' assertions."},{"response":"The manuscript presents results from a proof-of-concept on the Goerli testnet and does not claim direct generalization to mainnet. We will add an explicit discussion of scalability limitations, including factors such as validator count, slot timing, bandwidth, circuit churn, and potential adversaries, to better delineate the scope of the current findings. Full mainnet-scale measurements lie outside the scope of this techreport.","revision_made":"partial","referee_comment":"[Discussion / Scalability Analysis] The PoC was run on Goerli (~10k validators, low stakes). The manuscript does not analyze or measure behavior under mainnet-scale conditions (>500k validators, 12-second slots, higher bandwidth contention, Tor circuit churn, or combined timing/traffic-analysis adversaries), which is load-bearing for the claim that results generalize and network performance remains uncompromised."}],"tokens_in":1438,"tokens_out":394,"duration_ms":24391,"standing_objections":[]},"desk_editor":{"model":"grok-4.3","letter":"The paper delivers a working Tor push implementation inside Nimbus that routes attestations, aggregations, and proposals over Tor on the Goerli testnet. They report a measured average overhead of 613.82 ms and claim this keeps the system usable while hiding validator IPs from correlation attacks.\n\nWhat the work actually does is ship code and a live measurement rather than another design sketch. That is the useful part: anyone who needs to decide whether Tor is worth trying for Ethereum validators now has a concrete number and a reference implementation to inspect.\n\nThe limitation is straightforward. Goerli runs at roughly 10k validators with light load. Mainnet has over 500k validators, fixed 12-second slots, and real economic stakes, so both the latency under contention and the unlinkability against a motivated adversary who can observe Tor exits remain unproven. The abstract gives no trial count, variance, or comparison against direct connections, which makes the single headline number harder to rely on.\n\nThe review of prior Ethereum privacy proposals is competent but adds little beyond context. The security discussion is mentioned without enough detail here to judge its depth.\n\nThis is for Ethereum client teams and blockchain privacy engineers who want an existence proof they can test themselves. It is not a foundational result, but the empirical piece is solid enough to justify referee time. I would send it out for review with the expectation that the authors will need to address the testnet-to-mainnet gap and add experimental methodology.","headline":"A deployed Nimbus PoC shows Tor adds ~614 ms latency for validator messages on Goerli, but the mainnet scaling case is untested.","tokens_in":2439,"tokens_out":372,"would_cite":false,"duration_ms":15872,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.3","headline":"Tor push protocol lets Ethereum validators hide IP addresses from their identities with 614 ms average added latency.","keywords":["ethereum","tor","validator privacy","location privacy","ip unlinkability","blockchain security","proof of concept"],"falsifier":"Direct measurement on mainnet showing that Tor push either adds latency far above 614 ms on average or allows successful IP-identity correlation under attack traffic.","tokens_in":2685,"feed_emoji":"🛡️","tokens_out":553,"duration_ms":20664,"temperature":0.7,"pith_summary":"The paper evaluates a Tor-based method to prevent attackers from linking validator identities to IP addresses, which could otherwise enable DoS, MEV, and finality attacks. It reviews prior network and consensus privacy techniques, then presents Tor push as a protocol that routes attestations, aggregations, and proposals through Tor. A working proof-of-concept was built inside the Nimbus client and run on the Goerli testnet. Measurements indicate the approach adds 613.82 ms latency on average while leaving overall network performance intact.","feed_headline":"Tor hides Ethereum validator IPs at 614 ms cost","feed_subtitle":"Goerli testnet PoC shows unlinkability of IDs and addresses is feasible without slowing the network.","key_machinery":"Tor push protocol that forwards validator messages (attestations, aggregations, block proposals) through the Tor network to break IP-to-identity linkage.","core_discovery":"Tor push decouples validator IDs from beacon-node IP addresses by sending messages over Tor, achieving unlinkability that makes end-to-end correlation difficult. The Goerli deployment of the Nimbus implementation shows this is feasible with an average 613.82 ms overhead and no compromise to network operation.","pith_inferences":["The same routing idea could be tested on other proof-of-stake networks that expose validator IPs.","Combining Tor push with existing consensus-layer privacy methods might create defense in depth.","Longer-term monitoring on mainnet would be needed to check whether circuit churn affects attestation timeliness."],"forward_implications":["Validators gain protection against IP-targeted DoS and correlation-based MEV or finality attacks.","Existing Ethereum clients can incorporate the mechanism without breaking consensus or network throughput.","Unlinkability holds as long as Tor circuits remain uncompromised by the attacker."],"fun_headline_variants":["Tor tested to unlink Ethereum validator IPs","614 ms overhead for Tor validator privacy in Nimbus","Goerli test shows Tor feasibility for validator IPs","Tor push PoC for Ethereum validator location privacy"],"cache_read_input_tokens":2112,"weakest_assumption_plain":"The latency and security behavior measured on the Goerli testnet PoC will match what occurs on the production Ethereum mainnet under realistic load and attack conditions.","fun_headline_variants_meta":{"raw":{"variants":["Tor tested to unlink Ethereum validator IPs","614 ms overhead for Tor validator privacy in Nimbus","Goerli test shows Tor feasibility for validator IPs","Tor push PoC for Ethereum validator location privacy"]},"model":"grok-4.3","cost_usd":0.006112,"raw_usage":{"total_tokens":2901,"prompt_tokens":697,"num_sources_used":0,"completion_tokens":55,"cost_in_usd_ticks":61124500,"prompt_tokens_details":{"text_tokens":697,"audio_tokens":0,"image_tokens":0,"cached_tokens":256},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":2149,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":697,"tokens_out":55,"duration_ms":18742,"temperature":1.0,"reasoning_tokens":2149,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-06-29T11:13:57.923112+00:00","model_set":{"reader":"grok-4.3"},"falsifier":"Direct measurement on mainnet showing that Tor push either adds latency far above 614 ms on average or allows successful IP-identity correlation under attack traffic.","supporting_citations":[],"review_version":1}