Research explains how onchain investigators use behavioral heuristics (timing, gas fees, address patterns) to demix Tornado Cash transactions and link deposits to withdrawals.
Regulation & Gov ยท
Onchain investigators can probabilistically connect deposits and withdrawals through Tornado Cash, the Ethereum privacy mixer, by analyzing behavioral signals rather than direct transaction links. Vladimir S. outlined techniques that exploit patterns in timing between deposits and withdrawals, transaction costs, and wallet activity signatures โ heuristics that work because users often follow predictable sequences even when using the protocol's zero-knowledge proofs to obscure fund origins.
Tornado Cash's technical design severs on-chain traceability by accepting fixed-denomination deposits and allowing withdrawals to fresh addresses via zkSNARK proofs, making the source of funds cryptographically unlinkable. Yet this privacy guarantee applies only to the contract layer; behavioral analytics operate above it, correlating timing and cost patterns across multiple transactions to infer probable matches between entry and exit points in the mixer's pools.
The demixing capability underscores a practical gap between theoretical privacy and real-world anonymity. Investigators cannot definitively prove a link but can assign probabilities based on measurable on-chain behavior, a method that has become increasingly relevant as the protocol has been used to launder proceeds from exchange hacks, protocol exploits, and sanctioned entity transfers. Whether such probabilistic deanonymization holds up in enforcement remains an open question.