Track me if you can: Ephemeral coin tracing
Privacy-preserving payment systems are well understood, yet concerns about their misuse for financial crime have led to only limited adoption in regulated settings such as central bank digital currencies (CBDCs) and institutional stablecoins. Tracing is one tool for addressing these concerns: acting on external evidence implicating a user, law enforcement follows the suspect's funds through the ledger to uncover laundering routes and accomplices. Existing coin-tracing schemes, however, provide no cryptographic bound on tracing reach: once initiated, a trace may propagate indefinitely through the transaction graph or persist across all future transactions of a targeted user. Keeping surveillance targeted and temporary therefore depends on the restraint of the authority or a committee. We introduce ephemeral coin tracing (ECT), a primitive that bounds tracing reach by construction. Each account carries an encrypted tag that records which traced identifiers its funds carry while hiding its tracing status from users. When funds move, the sender's tag degrades and merges with the recipient's tag. Each tracing contribution expires independently after a policy-defined number of hops and then becomes unrecoverable even to the tracing authority, without affecting other live contributions in the same tag. Public parameters also bound how many identifiers a tag can distinguish simultaneously. We formalize ECT and give constructions based on exponential ElGamal, Damgård-Jurik encryption, and Ring-LWE, the last providing post-quantum security.