Daily Aggregator (Partial Transactions)

Si wouldn’t know the real anonymity set since Sn is the one verifying the inputs and dropping spam

Check the “b)” section in Tromp’s post. They can see the size of the subset. Though, s1 and sn can still be malicious and cooperate.

Perhaps it might be worth thinking in the direction of having anyone receive a pack of coinswap data (encryptions included) so that we randomize who gets the real output and input and form a circle S1 → S2 … Sn → S1 where they make two linear passes across the circle to collect all the valid coinswaps. But I have not thought about this yet