Coinbase Tornado Cash and Mixer Deposit Screening

Coinbase Tornado Cash and Mixer Deposit Screening

Prepared by the editorial team. Updated August 31, 2026.

Research Notice: This guide is part of our fintech research series examining blockchain privacy tools and their regulatory context. It is informational and educational only, is not legal, financial or compliance advice, and does not endorse or instruct the use of any mixing service. Laws differ by jurisdiction and change over time; verify current rules for your location.

Coinbase Tornado Cash searches usually come from one of two questions: what the exchange had to do with the litigation, or what a regulated venue does when funds with mixer history arrive. The first has a short answer, because Coinbase funded the legal challenge that became Van Loon v. Department of the Treasury and had no operational or commercial link to the service. This article addresses the second question at industry level, describing how risk-based screening generally works without attributing any threshold or policy to a named firm.

What generally happens when a deposit has mixer history?

Nothing automatic. Incoming transactions are screened against analytics data, and an association with a mixing service raises a risk indicator rather than triggering a fixed outcome. What follows depends on the venue’s own risk appetite, the amount involved, the customer profile and whether the exposure is direct or several steps removed from the source.

The governing idea is the risk-based approach, which international standards and most national regimes require. Rather than applying identical controls to every transaction, a firm assesses where its risk actually sits and allocates attention accordingly. That is why there is no single industry rule for mixer exposure: the framework deliberately produces different answers at different firms, in different jurisdictions, for different customers.

The range of possible responses is wide. A programme may record the finding and do nothing, may ask for information about the source of funds, may hold a credit pending review, may escalate for a reporting decision, or may decline the relationship. Each of these is a different action with different consequences, and treating them as one outcome called being frozen is the commonest misunderstanding.

Specific thresholds are almost never published. A firm that disclosed the exact exposure percentage that triggers a review would be publishing its detection logic, so confident public claims about a named venue’s internal trigger points should be treated as unsourced unless the firm itself said so.

Why does direct exposure count for more than indirect?

Direct exposure means value arrived at the deposit address straight from the flagged source. Indirect exposure means it passed through one or more intermediate addresses on the way. The distinction carries a great deal of weight, because direct exposure suggests the depositor dealt with the source while indirect exposure may reflect nothing the depositor knew about.

The reasoning is about inference rather than about morality. A single transfer from a mixing contract to a customer deposit address is evidence of a specific interaction. Value that reaches the same address after moving through several unrelated parties supports no such inference, because at each transfer the funds may have been bought, sold, paid or settled by people with no connection to one another.

Indirect exposure also accumulates through ordinary activity. Balances at trading venues are pooled, liquidity moves constantly, and any actively used address will eventually show some indirect association with something undesirable. A programme that treated all exposure as equivalent would generate an unusable volume of alerts and would fail its own risk-based test by spending effort where the risk is negligible.

Why does the number of hops change the assessment?

Because each additional transfer between the source and the deposit weakens the inference that the depositor had anything to do with that source. One hop is close to direct contact. Value that has moved six times through actively used addresses usually says very little, since it merges with unrelated flow at every step along the way.

How that dilution is counted is itself a methodological choice. Some approaches apportion tainted value proportionally across the outputs of each transaction, so exposure decays as funds mix with clean value. Others treat any downstream output as carrying the association regardless of proportion. The two produce very different numbers from identical chain data, which is why a percentage is meaningless without the method that generated it.

This is also why providers disagree. Vendors build their own address clusters, label entities from different intelligence, choose different hop limits and apply different apportionment rules, so a transaction that scores as low risk at one provider can be flagged at another. Firms subscribing to more than one source treat that divergence as an ordinary feature of the data rather than as a defect to be resolved.

How can you interpret a risk score before acting on it?

You identify the provider and what the number measures, establish whether the exposure is direct or indirect, check the attribution method and hop limit behind it, look at the dates involved, and treat the result as one input for a qualified reviewer. The procedure is a way of reading data, not a decision rule.

Step 1: Identify the provider and what the number measures

Establish which provider produced the flag and what its score is actually measuring, because a category label, a percentage of tainted value and a composite risk rating are three different quantities. Comparing them as though they were one figure produces contradictions that exist only in the reading.

Step 2: Establish whether the exposure is direct or indirect

Determine whether the funds arrived straight from the flagged source or passed through intermediate addresses first, since that single distinction usually changes the weight of the finding more than the score itself does. Most alerting systems expose this in the underlying detail even when the summary view hides it.

Step 3: Check the attribution method behind the number

Read the provider’s methodology for how it apportions value across mixed transactions and how many hops it traverses, because different accounting rules produce different percentages from identical chain data. Vendors publish this in general terms, and the general terms are enough to know what the number cannot mean.

Step 4: Check the dates behind the label

Look at when the flagged activity occurred and when the label was applied, because a category can be added or revised long after the transactions it describes took place. A finding about activity from several years ago is a different fact from a finding about last week.

Step 5: Treat the score as one input and escalate it

Record the flag as one input among several and route the case to a qualified compliance reviewer rather than treating the number as a decision in itself, because an automated score carries no legal conclusion. Documenting what the score said and what was done with it is what makes the decision defensible afterwards.

Why does a delisting not switch this screening off?

Because the obligation never came from the sanctions list. Anti-money-laundering duties arise from separate legislation requiring firms to understand their customers, monitor activity and report suspicion, and those duties are driven by assessed risk. Removing a name from a list ends one specific prohibition and leaves the risk assessment exactly where it was.

The two regimes work differently in kind. Sanctions screening is close to binary: a name is listed or it is not, and a match creates a hard prohibition. Anti-money-laundering analysis is probabilistic, asking how likely it is that value has an illicit origin and what a reasonable firm should do about that likelihood. A change in the first has no mechanical effect on the second.

Timing adds a further complication. Tornado Cash was removed from the sanctions list in March 2025, but activity from the designated period still happened while the prohibition was in force, and firms assess historical conduct against the rules that applied at the time. A delisting is forward-looking and does not rewrite the record behind it.

Exposure types and how they are usually weighed

Weighting varies by firm, so the table describes the general logic rather than any particular programme. It is offered as an orientation to why two deposits that both show a mixer association can be treated completely differently.

Type of exposure Typical weight in a risk-based review
Direct transfer from the flagged contract Highest, because it evidences interaction with the source itself
One intermediate address with no other activity High, since a pass-through address adds little separation
Several hops through actively used addresses Lower, and progressively harder to attribute to the depositor
Exposure inherited through a venue’s pooled balances Usually low, because pooled value belongs to many customers
Historical exposure predating a change in status Assessed against the rules in force at the time and still recorded

The common thread is proximity. The closer the depositor sits to the flagged source, the more the association tells a reviewer, and the further away, the more it describes the network rather than the customer.

Frequently asked questions

Can a firm decline funds that are not connected to anything unlawful?

Generally yes, because a private business sets its own risk appetite and its terms of service usually reserve that discretion. A decision to decline is a commercial and compliance judgment rather than a finding that anyone did anything wrong, and the two are frequently confused by people on the receiving end.

Do two analytics providers always produce the same answer?

No. Providers build their own address clusters, apply different attribution rules and traverse different numbers of hops, so the same transaction can carry different scores at different vendors. Firms that subscribe to more than one provider treat disagreement as normal rather than as evidence that one of them is broken.

Does a risk flag stay attached to an address permanently?

Labels can be revised, and providers do update attributions as their datasets improve, but a historical association is rarely removed simply because time has passed. That is why an assessment records the date of the check as well as the result.

Will a venue explain exactly why a deposit was queried?

Often not in detail. Rules in many jurisdictions restrict what a regulated firm may disclose about a suspicion or a report, and firms also avoid publishing the specifics of their detection logic. A customer with a genuine dispute is usually better served by taking it to counsel than by inferring policy from a support reply.

Leave a Comment

Your email address will not be published. Required fields are marked *