Mixer Tornado Cash: How Anonymity Degrades in Practice
Prepared by the editorial team. Updated August 31, 2026.
Research Notice: This guide is part of our fintech research series examining blockchain privacy tools and their regulatory context. It is informational and educational only, is not legal, financial or compliance advice, and does not endorse or instruct the use of any mixing service. Laws differ by jurisdiction and change over time; verify current rules for your location.
Mixer Tornado Cash is usually described as though its cryptography delivered anonymity outright, when what the design delivers is a probability that depends on how many other people are doing the same thing at the same time. The zero-knowledge proof is sound; the privacy outcome is statistical, and it decays under ordinary conditions. This article explains why the practical result falls short of the guarantee readers assume.
Why is the privacy guarantee weaker than the cryptography suggests?
Because the cryptographic claim and the privacy claim are different claims. A zero-knowledge proof establishes that a withdrawal corresponds to some earlier deposit without revealing which one. Anonymity is the separate question of how many deposits that could plausibly be, and that count is set by user behaviour and pool activity rather than by mathematics.
The mechanism is worth stating plainly, because the confusion usually begins there. A deposit records a commitment, a hash of a secret held by the depositor, and a later withdrawal publishes a nullifier derived from that same secret, which lets the contract release the deposit exactly once without publishing any link between the two events. On its own terms the proof does that job.
What the proof cannot do is create a crowd. It shows only that a withdrawal belongs to the set of deposits already sitting in the pool. If that set is large and genuinely uniform, the statement is close to useless to an observer. If the set is small, or if most of its members can be accounted for by other means, the identical proof narrows to something very close to an identification.
What does an anonymity set actually measure?
An anonymity set measures how many deposits a given withdrawal could plausibly have come from, judged from the position of someone watching the chain. A pool of a thousand indistinguishable deposits supports a one in a thousand guess. A pool of four supports a one in four guess. It is a headcount of candidate origins.
Fixed denominations exist to keep that headcount meaningful. If deposits carried arbitrary amounts, the amount itself would identify them, and matching a withdrawal to a deposit would collapse into arithmetic. Standardising the size makes deposits interchangeable as far as the ledger records. The cost is partition: each denomination forms its own crowd, so a protocol that looks busy in aggregate can consist of several thin pools.
The number quoted in commentary is almost always the nominal one, the total deposits ever made in a denomination. The set that matters for a particular withdrawal is smaller. Deposits made after it cannot have been its origin, and deposits already spent or already tied to identifiable parties fall out of the candidate list too. What remains is the effective set, rarely the figure that gets published.
How does timing narrow the crowd a withdrawal hides in?
Every deposit and withdrawal is a timestamped transaction written permanently to a public ledger. The candidate set for any withdrawal is bounded by that timeline, since only deposits made earlier can be its source. When activity in a denomination is sparse, the bounded window contains very few deposits, and the crowd shrinks to whatever happens to be inside it.
Timing carries information in a second way. Human and automated behaviour is regular: activity clusters in particular hours, repeats at similar intervals, and follows the rhythm of whatever process produces it. An observer comparing deposit patterns against withdrawal patterns is not decrypting anything; they are correlating two public sequences.
Short round trips are the most visible version of this. A deposit followed closely by a withdrawal of the same denomination, during a stretch when little else occurred, leaves a pairing that requires no cryptographic insight to notice. The record also persists indefinitely, available for re-examination years later with better tooling than existed at the time, which means a privacy outcome is never finally settled.
Why does off-chain information matter more than the on-chain design?
Because the ledger is only one of several record sets an observer can consult. Exchange account files, service provider logs, addresses published openly, and statements made on social platforms sit entirely outside the protocol and are untouched by anything it does. A single external record connecting two addresses can settle what the chain leaves ambiguous.
Funds generally enter and leave the wider crypto economy through identity-verified venues, so the address funding a deposit and the address receiving a withdrawal each tend to have a documented owner somewhere. The privacy question becomes whether those two endpoints can be joined, and the join may come from data with no connection to any blockchain.
Address reuse is the ordinary way this happens without anyone intending it. A withdrawal address that later receives funds from a known counterparty, pays a service which keeps records, or appears in a published list acquires an identity retrospectively. The chain then supplies the link between that identity and the earlier withdrawal.
Institutional records also outlast legal changes. Although Treasury removed Tornado Cash from the sanctions list in March 2025, the transaction records and risk flags intermediaries created between 2022 and that date still exist. Privacy that depended on nobody writing something down has already failed by the time the note is written.
How can you read an anonymity-set claim critically?
You read it by asking what the number counts, checking which denomination and asset it applies to, separating the nominal total from the effective candidate set, establishing the time window it covers, and identifying the off-chain assumptions underneath it. The procedure below is for evaluating a published privacy claim, not for interacting with any service.
Step 1: Ask what the number counts
Establish whether the figure counts total deposits ever made, deposits still unspent, or candidate origins for one specific withdrawal, because those three numbers can differ by orders of magnitude. A claim that never states which of the three it means is not yet a claim you can evaluate.
Step 2: Check the denomination and the asset
Confirm which denomination and which asset the figure describes, since sets do not pool across sizes or tokens and a headline total can quietly aggregate several unrelated crowds. The relevant crowd is always the one a particular transaction sits inside, never the sum of all of them.
Step 3: Separate nominal size from effective size
Set aside the members an observer could already account for, including deposits attributable to known parties and deposits made after the event in question, because only the remainder provides genuine cover. The gap between the published figure and that remainder is usually where an overstatement lives.
Step 4: Establish the time window
Identify the period the figure covers and whether it reflects activity at the moment being described or a cumulative total gathered over years, since a lifetime count says little about how busy a pool was on a given day. Quiet stretches inside a long-running pool are common and are invisible in a lifetime total.
Step 5: Identify the off-chain assumptions
Ask what the claim assumes about information outside the blockchain, because almost every published privacy estimate treats the ledger as the only evidence available to an observer. Once external records are admitted into the analysis, an estimate built on chain data alone becomes an upper bound rather than a result.
Where the design guarantee and the practical outcome diverge
The distance between the two claims is easiest to see side by side. The table sets the property the design genuinely provides against the outcome commonly observed once ordinary conditions apply, describing general tendencies rather than any particular transaction.
| What the design guarantees | What tends to happen in practice |
|---|---|
| A withdrawal cannot be linked to one deposit by the proof | It can often be narrowed to a few candidates using timing and volume alone |
| All deposits of one denomination are interchangeable | Many are already attributable through the venues that funded them |
| The anonymity set grows as the pool grows | The set that matters is bounded by time and by which deposits remain unspent |
| The protocol itself reveals no identity | Identity arrives from account records, address reuse and public statements |
| Privacy holds as long as the cryptography holds | Privacy can erode later as new data and better analysis become available |
Every row describes the same gap. The cryptographic property is stated about a transaction in isolation, while the outcome is decided by everything surrounding it, which no contract can govern.
Frequently asked questions
Is the zero-knowledge proof itself ever the weak point?
Rarely, in the sense that the erosion described here requires no cryptographic failure at all. A soundness flaw in a proving scheme would be a serious event in its own right, but the loss of privacy discussed in this article happens while the mathematics continues to work exactly as specified.
Does a deposit gain privacy as more people join the pool later?
Partially, and less than intuition suggests. Later deposits can widen the candidate set for a withdrawal that has not yet happened, so continuing activity does add cover in that direction. It cannot add candidates to a withdrawal that already occurred, because deposits made after an event were never possible sources of it.
Why do published anonymity-set figures differ so much between sources?
Because the sources are counting different things and frequently do not say which. One may report lifetime deposits, another unspent deposits, another an estimate of candidates for a single transaction after filtering. All three can be accurate and mutually inconsistent, which is why the definition matters more than the number.
Does weakened anonymity mean a transaction can be attributed with certainty?
No, and treating a narrowed candidate set as an identification is a common error. Reducing a thousand possibilities to five is a large analytical step, but five is not one, and a probabilistic inference is not proof. The distinction matters most in legal settings, where the standard of evidence is higher than the standard of suspicion.
