WhirWhir
Home / How Whir works

How Whir works

Whir turns traceable coins into private ones by pooling your deposit with unrelated deposits and paying you back from the shared pool. The result is a payout that no longer has a direct on-chain edge to the coins you sent in. There is no account, no email and no KYC — a mix begins and ends with the addresses you provide, and every record is erased 24 hours after payout.

What CoinJoin actually does

A normal Bitcoin transaction has clear inputs and outputs, so chain-analysis firms can cluster addresses and follow value from one hop to the next. A CoinJoin is a single collaborative transaction that combines many participants' inputs and outputs at once. Because dozens of unrelated payments settle together, an outside observer cannot reliably say which input paid which output — the deterministic link that clustering depends on is gone.

Whir builds on this well-studied, community-standard technique rather than a custodial black box. Your coins are routed through the pool and back out; they are never parked in a house wallet that holds customer balances.

The Whir process, step by step

  1. Set your terms and get a letter of guaranteeChoose the coin, enter one to three receiving addresses, and pick a delay from ASAP up to 48 hours. Whir returns a unique one-time deposit address plus a PGP-signed letter of guarantee that binds this order to that address.
  2. Send your coins to the deposit addressSend exactly the amount shown to the one-time address. Nothing here needs an account — your order lives only as a claim link and letter that you keep.
  3. Confirmation and poolingAfter the first network confirmation your deposit enters the CoinJoin pool, joining unrelated deposits so the inputs and outputs can no longer be matched one-to-one.
  4. Optional time delayIf you set a delay, Whir holds the payout for the window you chose. Spacing the payout away from the deposit defeats simple timing correlation, where an observer links a deposit to the very next withdrawal.
  5. Receive clean, unlinked outputsMixed coins arrive at your address in a single transaction on your schedule, carrying no direct link to the coins you deposited.
  6. Records are deletedTwenty-four hours after payout, the order, addresses and letter are purged. There is no history left to subpoena, sell or leak.

Delays, splits and timing

Two controls put timing analysis in your hands. Splitting lets you send the payout to up to three separate addresses, so a single large amount does not reappear as one obvious output. Delays let you decouple the payout from the deposit in time. Used together, they make it far harder to link the two halves of a mix by amount or by moment.

  • Up to three receiving addresses per mix, entered when you create the order
  • Delay anywhere from immediate up to 48 hours
  • A unique deposit address is generated for every single order
  • Payout is made in a single blockchain transaction on your chosen schedule

The threat model Whir defends against

Whir is designed to frustrate the ways ordinary Bitcoin activity gets deanonymised:

  • Address clustering — grouping addresses that appear as co-inputs to link your wallet history
  • Timing correlation — matching a deposit to the withdrawal that immediately follows it
  • Amount fingerprinting — following an unusual, round or exact amount from hop to hop
  • Data-retention risk — logs or accounts that could later be seized, sold or leaked

What Whir deliberately does not do

There is no sign-up, so there is no profile to correlate. There is no custody, so there is no balance to freeze or lose to an exit. And there is no long-term logging, because order data is time-boxed and deleted after the mix settles. Privacy comes from holding as little about you as technically possible — not from a promise to guard a database forever.

You are on the verified Whir mirror at whir-mirror.vip. Always verify your letter of guarantee against Whir's published PGP key before sending, and ignore any link sent to you unsolicited. A site that asks for an email, a password or KYC is not Whir.