Anyone with your wallet address can see every dollar it has ever held — every transaction, forever, free, no password. Blockchain isn't anonymous. It's pseudonymous: the ledger is public, and only the link between an address and your name is missing.
The problem is how many things provide that link. Below are the four that do most of the work, and five documented cases — with court records — where they did.
- The ledger is public forever — deanonymization is retroactive, and the Bitfinex case reached six years back
- Exchange KYC is the strongest link: the 2020 Twitter hackers were charged within 16 days because scam coins hit their verified Coinbase accounts
- Address clustering has been standard technique since a 2013 academic paper — it connects your whole history
- Chainalysis maps 65,000+ real-world entities to over a billion addresses and sells the mapping to governments
- Privacy hygiene helps; true anonymity on transparent chains is practically out of reach
The ledger never forgets
A bank statement is private by default and disclosed by court order. A blockchain is the opposite: disclosed by default, private never. Every transfer you've ever made sits in a public database that anyone — a journalist, an ex, a tax authority — can query without asking.
What's missing is the name tag. And attaching name tags turned out to be so tractable that it became an industry. The academic groundwork was laid in 2013, when Sarah Meiklejohn and colleagues published "A Fistful of Bitcoins" — they made a few hundred ordinary purchases, applied two clustering heuristics, and mapped large parts of the Bitcoin economy with a laptop. Today Chainalysis sells government agencies a mapping of more than 65,000 real-world entities to over a billion addresses, and its 2026 Crypto Crime Report counted at least $154B received by illicit addresses in 2025 — a figure blown up by sanctioned-entity flows (one ruble-backed token alone moved $93.3B), and still under 1% of attributed on-chain volume. The other 99% is people like you, fully visible.
The part that surprises everyone: deanonymization is retroactive. The moment one address is tied to you, everything that address ever did — and much of what its cluster did — gets your name on it, back to the first transaction.
Exchange KYC — the front door
Every regulated exchange verifies your identity, and the moment you withdraw to your own wallet, that address is linked to your passport. Compliance teams buy exactly this mapping; subpoenas carry it to tax authorities and courts.
How fast does this work in practice? In July 2020, three young men hijacked the Twitter accounts of Obama, Musk and Apple to run a bitcoin giveaway scam. Investigators traced the scam coins to Coinbase accounts that had been registered — and KYC-verified — with the hackers' own driver's licenses. Charges came 16 days after the hack. The "anonymous" money ran straight into the front door they'd already signed.
Address reuse and clustering
Use one address twice and you've built a public profile. Spend from several addresses in one transaction and clustering heuristics merge them into a single wallet fingerprint — that's the common-input-ownership rule from the 2013 paper, and it has been bread-and-butter chain analysis ever since.
Clustering is what makes tracing scale. In 2019, investigators took down Welcome to Video, then the largest darknet child-exploitation site, by following payments on the public blockchain from the site's addresses back to exchanges — and through exchange KYC to customers. 337 users were arrested worldwide, with leads sent to 38 countries. Nobody hacked anything; agents read a public ledger.
Off-chain leaks
The chain is only as private as the sloppiest place you ever pasted your address. A donation page with your address next to your name. An ENS name that matches your X handle. A forum signature from 2014.
The canonical example needed no blockchain analysis at all. Ross Ulbricht ran Silk Road behind Tor and pseudonyms, but in 2011 a user called "altoid" promoted the site on forums — and later posted a job ad directing replies to [email protected]. An IRS investigator found it by googling. The market that moved hundreds of millions in bitcoin fell to a forum post. (The coins themselves surfaced later: in 2020 the DOJ seized 69,370 BTC hacked from Silk Road years earlier — that time it was chain analysis. Ulbricht was pardoned in January 2025; the ledger's memory outlived his sentence.)
Network metadata
Your wallet broadcasts transactions from an IP address. Light wallets query servers that can log which addresses you ask about; block explorers see every lookup. None of this is on-chain — all of it is linkable, and it's the layer people forget entirely because no "crypto" is involved.
Six years later: the Bitfinex case
If the Twitter hack shows how fast the links work, the Bitfinex case shows how long they wait. In 2016, someone moved 119,754 BTC out of the Bitfinex exchange. The coins sat, hopped through the AlphaBay darknet market, split across dozens of exchange accounts under fake names. For six years the trail looked cold.
It wasn't. When AlphaBay was taken down in 2017, investigators picked up the thread and followed it to accounts tied to a New York couple — Ilya Lichtenstein and Heather "Razzlekhan" Morgan. A warrant on Lichtenstein's cloud storage decrypted a file listing ~2,000 addresses with their private keys, almost all traceable to the hack. In February 2022 the DOJ seized ~94,000 BTC — $3.6B, then the largest financial seizure in its history. Both pleaded guilty in 2023; in November 2024 Lichtenstein got 5 years and Morgan 18 months. Every hop they made in 2017 was still sitting in public view in 2022.
Five cases, one pattern
| Case | Caught | What tied them | Outcome |
|---|---|---|---|
| Silk Road — Ross Ulbricht | 2013 | Forum post + Gmail address (off-chain) | Life sentence; pardoned Jan 2025 |
| Welcome to Video | 2019 | Payment tracing → exchange KYC | 337 users arrested worldwide |
| Twitter hack | 2020 | Scam BTC → KYC'd Coinbase accounts | Charged in 16 days |
| Colonial Pipeline ransom | 2021 | Ledger tracing; FBI held a key | 63.7 of 75 BTC recovered |
| Bitfinex hack — Lichtenstein & Morgan | 2022 | Six-year trace via AlphaBay + cloud-file warrant | ~94,000 BTC ($3.6B) seized; 5 yrs / 18 mos |
Four different crimes, four different mistakes — one public ledger. Note the Colonial Pipeline row: the FBI recovered most of a ransomware payment a month after it was paid, by watching transfers on the open blockchain until they reached an address whose private key it could obtain.
Mixers and privacy coins
"Fine — I'll just mix." That path has its own map, and it's a minefield.
Tornado Cash, the largest Ethereum mixer, was sanctioned by OFAC in August 2022 after laundering $7B including $455M for North Korea's Lazarus Group. A federal appeals court ruled in late 2024 that immutable smart contracts can't be sanctioned as "property," and OFAC delisted it in March 2025. None of that saved its developer: Roman Storm was convicted in August 2025 of running an unlicensed money-transmitting business, with a retrial on the remaining counts slated for October 2026. Whatever mixing does for your privacy, it does the opposite for your risk profile — mixed coins get flagged by the same analytics firms, and some exchanges freeze them on arrival.
Privacy coins solve the problem at the protocol level — Monero hides sender, receiver and amount by default; Zcash offers shielded transactions. The squeeze there is access, not analysis: Binance delisted Monero in February 2024, and under the EU's anti-money-laundering regulation, exchanges serving EU customers may not handle anonymity coins at all from July 2027. Holding them stays legal; the doors on and off keep closing.
| Bitcoin / Ethereum | Zcash (shielded) | Monero | |
|---|---|---|---|
| Sender | Visible | Hidden | Hidden |
| Receiver | Visible | Hidden | Hidden |
| Amount | Visible | Hidden | Hidden |
| Full history queryable | Yes, by anyone | Only with view key | No |
| Exchange access (2026) | Universal | Shrinking | Delisted by major venues; EU ban from 2027 |
What actually helps
On a transparent chain, privacy is damage control. What moves the needle:
- A fresh address per counterparty. Doesn't beat clustering, but stops the casual lookup — the ex, the employer, the stranger you paid once.
- Two wallets, never touching. One KYC'd wallet for exchange traffic, one for savings, no direct transfers between them. Every case in the table above ran through the moment identity-linked and hidden funds met.
- Treat your address like a bank statement. Don't paste it next to your name — no donation footers, no matching ENS names, no forum signatures. Ulbricht's empire fell to exactly this.
- Assume the exchange knows. Because it does, and so does everyone it answers to.
What doesn't help: believing the word "anonymous" in marketing, and mixing casually — you inherit legal risk without gaining much privacy against a subpoena.
The honest summary: blockchain gives you a pseudonym with a perfect memory. Guard the link between the pseudonym and you, because once it breaks, it breaks for the whole history.