The wallets I pay the most attention to on any whale board are the ones with no past. A fresh address, funded through a Tornado Cash relayer or a chain of CoinJoin outputs, that immediately starts trading like it has been doing this for years. The natural question is who is behind it, and the honest answer is usually that nobody knows for sure. But that answer does more work than it should, because mixers conceal much less than you might assume, and the specific ways they leak are worth understanding whether you track whales for a living or just want a realistic picture of what on-chain privacy can actually deliver.
What a mixer actually does to the graph
Chain analysis works because a blockchain is a graph. Coins flow from output to input, addresses cluster together when they get spent in the same transaction, and if you follow the edges patiently you can usually walk from almost any wallet back to an exchange withdrawal with a name attached. Everything a mixer does is an attack on that graph.
CoinJoin, the Bitcoin flavor, works through ambiguity. A coordinator collects inputs from many participants and builds one large transaction with equal-valued outputs. If a hundred people each end up with an identical 0.1 BTC output, an outside observer cannot say which output belongs to which input. Your history is still on-chain, it just fans out into a crowd. Implementations like Whirlpool used fixed pool denominations for exactly this reason, since equal outputs are what create the ambiguity in the first place.
Tornado-style mixers, the Ethereum flavor, go further. You deposit a fixed denomination into a smart contract pool and receive a secret note. Later, from any address, you present a zero-knowledge proof that you made one of the deposits, without revealing which one, and the contract pays out. A relayer can submit the withdrawal and take a fee, so the receiving address never even needs gas from somewhere traceable. Cryptographically, the link between deposit and withdrawal does not exist on-chain at all. Graph traversal just stops at the pool.
On paper that sounds like the end of the story. In practice it is where the interesting part starts.
The heuristics that still work
What a mixer really gives you is a set of candidates, everyone who deposited and could plausibly be behind your withdrawal. Every heuristic that shrinks that set is an attack, and most of them are embarrassingly simple.
Timing is the big one. If you deposit 100 ETH and withdraw 100 ETH forty minutes later, your real anonymity set is whoever else deposited in that window, which during a quiet stretch might be three people. Analysts sort deposits and withdrawals by time and score the plausible pairings. Patience is the entire defense, and most users do not have any, because they mixed the coins for a reason and the reason is usually urgent.
Amounts are next. Fixed denominations exist to prevent amount matching, but the amounts people actually want to move are whatever they happen to have. Someone moving an awkward total ends up making a distinctive pattern of deposits across the 100, 10, and 1 ETH pools, then withdraws the same pattern on the other side. The individual notes are unlinkable, but the shape of the batch is a fingerprint. On the CoinJoin side the equivalent failure is change. The equal outputs are mixed, but the leftover change output is not, and if you later spend mixed coins and that unmixed change in one transaction, you have re-linked everything yourself.
Then there is behavior, which is where most of the deanonymization actually happens. In the research on Tornado Cash usage, a surprising share of deposits could be linked to withdrawals using nothing more exotic than the habits of the users. The common failure modes are worth listing because people repeat them constantly.
- Withdrawing to an address that had already interacted with your old wallet, even once, even for dust.
- Skipping the relayer and paying withdrawal gas from a wallet in your existing cluster.
- Carrying the same distinctive gas settings, wallet software quirks, or time-of-day pattern across both sides of the pool.
- Consolidating mixed funds with unmixed funds later, which quietly undoes the whole exercise.
- Returning to the same exchange account, the same DeFi contracts, or the same counterparties you used before mixing.
None of these break the cryptography, they just route around it. The mixer did its job, and the human on either end handed the link back.
Your privacy depends on everyone else
The part people underestimate is that the anonymity set is shared infrastructure. Every user who gets deanonymized, by their own carelessness or by an exchange subpoena, gets subtracted from the candidate set for everyone else. If a pool had fifty deposits in your window and analysts can rule out forty of them, your effective privacy shrank without you doing anything wrong. It also decays forward in time, since intersection attacks compound as more of the surrounding activity gets labeled. This is why privacy researchers keep repeating the same finding, that the honest anonymity set is much smaller than the raw deposit count suggests, and it only gets smaller.
It is also why the compliance world treats mixer exposure the way it does. Exchanges flag deposits with mixer history, analytics firms score the taint, and Tornado Cash itself spent time under US sanctions, which pushed a lot of that flow elsewhere. I am not making a legal point here, just noting that coins with mixer history are already handled as a distinct category by everyone whose job is to look at them.
Reading mixer outflows in whale tracking
Which brings me to why I care. When a mixer-funded wallet shows up trading size, the usual playbook is useless. There is no history to read, no exchange cluster, no old positions. But the mixer origin is itself information. Someone paid fees, accepted delay, and took smart-contract risk specifically to sever their history, and retail almost never bothers. So the wallet earns its own category, and the analysis flips from history to forward behavior. What does it trade, at what size, on which venues, with what timing. If a known whale went quiet a few weeks before this wallet appeared, and the position sizing rhymes, that is a hypothesis you can actually test against the heuristics above. This is roughly how we handle it at Blockcircle, where mixer outflows get tagged as their own wallet class rather than scored like ordinary fresh wallets, because pretending they are ordinary produces garbage signals.
The rule of thumb I would leave you with runs in both directions. If you are the analyst, remember that the pool boundary is where graph tools stop and pattern work begins, and the pattern work is more productive than the cryptography suggests it should be. If you are the one seeking privacy, assume the mixer only buys you ambiguity among the other users in your window, and that every habit you carry across the pool spends some of it. Most people spend all of it within a week and never find out.