Good news for the anon crowd: this is nonsense.
The grand way they found to “deanonymize” accounts was…finding publicly disclosed personally identifying information.
In essence, they “doxed” people who explicitly identified themselves.
There are essentially 3 separate studies in this:
1) Hacker News - LinkedIn profile pairs
They found Hacker News accounts that explicitly linked to a LinkedIn profile, stripped the links from one of the accounts, fed it to the model, and told it to go find the other.
Of course, that creates a bit of an issue, because every account in the sample was explicitly not anonymous. The researchers only found them because the owner publicly linked them together. So there is no reason to believe the posting behavior would carry any expectation of anonymity between accounts.
2) Reddit accounts
For the meat of the Reddit section, they didn’t even use multiple accounts; they just took single Reddit accounts, divided them in two (either by subreddit or over time), and concluded the model had “deanonymized” the account when it was able to pick the second half out of a set.
Once again, problematic design for the study because an anonymous account can remain anonymous while still “doxing” itself internally.
If you had half of Satoshi’s posts, it wouldn’t be that hard to identify the others because the “accounts” would naturally talk about the same things in the same way. But would that mean you had “deanonymized” the actual account? Of course not, because neither “half” was behaving with an expectation of anonymity from the other.
They also took a small amount of Reddit users who either had their username as their real name (academics who discussed their institutions and interests) or linked their LinkedIn profile directly for career feedback—neither group operating with an expectation of anonymity—and “deanonymized” them based on the identifying information they provided.
3) Scientist interviews
Finally, they used pseudonymous interviews with scientists who didn’t disclose their names, but did disclose specific details about their research, background, and activities…which they used to match up with online public records. Once again effectively using non-anonymous data as their “anonymous” sample.
So all in all, they proved they could “deanonymize” identities that were never truly anonymous to begin with. Anon universe can breathe a sigh of relief (for now).
Researchers built an AI that doxes any "anonymous" reddit account in under a minutes for $2.
eth zurich and anthropic published a terrifying paper proving that "practical anonymity" on the internet is officially dead.
they built a fully autonomous ai pipeline that takes your pseudonymous posts, extracts your identity signals, searches the web, and figures out exactly who you are. no human investigator needed.
the numbers are actually mindblowing..
- 67% of hacker news users identified correctly
- when the system makes a guess, it is right 90% of the time
- it even unmasked scientists whose interview transcripts were explicitly redacted for privacy
the scariest part? even time doesn't protect you.. they tested users who took a full year break and changed their interests. the ai still matched their old and new profiles with 90% precision. it sees through your persona changes like they aren't even there.
there is no defense against this. the agent splits the work into tiny, benign tasks like "summarizing a profile" or "ranking candidates." no api safety guardrail is going to flag it because no single step looks malicious..
every throwaway account. every "nobody will connect this to me" comment. it’s all just searchable micro-data now.