If there is any problem of "linkability" in this scheme, please help me see it. The server does not log any socket events or transaction records of any kind. OK, if someone put a gun to my head and said "put in some code to log everything" then they might be able to discern some pattern like "this coin was issued to this IP address, and then three days later that coin was swapped from this other IP address." OK, that sounds like a potential problem, but I don't see how you can hide this information from the server ITSELF. When you present a coin to the server, it is going to know from which IP address it came, and I don't see a way around that.
Perhaps I am mistaken, but the system you describe seems to be unlinkable-by-policy. Lucrative is unlinkable-by-mathematics. I believe the difference is nontrivial. Patrick McCuller