Tornado Cash Crypto: Why Privacy Is Not Anonymity

Tornado Cash Crypto: Why Privacy Is Not Anonymity

Prepared by the editorial team. Updated August 31, 2026.

Research Notice: This guide is part of our fintech research series examining blockchain privacy tools and their regulatory context. It is informational and educational only, is not legal, financial or compliance advice, and does not endorse or instruct the use of any mixing service. Laws differ by jurisdiction and change over time; verify current rules for your location.

Tornado Cash crypto debates repeatedly collapse two different properties into one word. Privacy tooling on a public chain weakens the statistical connection between events, which is unlinkability; anonymity would mean no identity is recoverable at all, which is a far stronger claim that almost nothing on a transparent ledger can support. This article sets out the difference and why it changes the conclusions that users, analysts and regulators reach.

What is the difference between unlinkability and anonymity?

Unlinkability means an observer cannot confidently connect two events, such as a deposit and a later withdrawal. Anonymity means no identity can be recovered by any observer at all. The first is a probabilistic property that varies with circumstances, while the second is an absolute claim, and public ledgers rarely support absolute claims.

The distinction is easiest to see in what the contract actually knows. A pooled design records a commitment when funds go in, derived from a secret the depositor keeps, and requires a proof plus a nullifier when funds come out. The contract never learns an identity because it was never given one, so identity is not something the system conceals; it is something the system never held.

That is a narrower achievement than it sounds. What the design conceals is the correspondence between one deposit and one withdrawal, and only within a set of deposits that look the same, so the strength of the property is a number rather than a yes or no. Ordinary language pushes readers the other way, and a tool that makes a link hard to draw ends up described as anonymous by both the users who rely on it and the critics who condemn it.

Why does blockchain analytics survive most privacy tooling?

Because analysis rarely attacks the cryptography. It works on everything the cryptography leaves untouched: amounts, timing, the sequence of transactions, the addresses that funded and received them, and records held off the chain by exchanges and other intermediaries. A sound proof system says nothing about any of that.

Public ledgers are unusually favourable ground for this work. The full history is available to everyone, permanently, at no cost, so an analyst can revisit old data with new methods years later. A conclusion unavailable in 2020 may be drawable in 2026 against the same records, because the records never expire and the techniques improve.

Off-chain correlation is usually decisive. Regulated exchanges hold identity documents matched to withdrawal addresses, and those addresses appear on the ledger like any other. Once one end of a chain of activity is attached to a person, the ledger supplies the rest of the structure, and no on-chain construction can retract information held elsewhere.

This is why enforcement bodies have been able to make specific attributions about pooled funds. Treasury relied on that kind of analysis in the August 2022 designation action, asserting attribution of particular flows to particular actors. The figures in such assertions are contested by researchers, but the underlying point stands: pooled funds are not beyond analysis.

What weakens an anonymity set in practice?

Anything that makes one participant distinguishable from the others. A small pool with few deposits leaves little to hide among, distinctive timing narrows candidates to those active in a window, address reuse links a supposedly fresh identifier to an existing history, and information from outside the chain can eliminate most of the set at once.

The scale of the set is the whole ballgame. If a pool holds thousands of indistinguishable deposits, an observer faces a genuinely hard problem. If it holds a handful, the same observer faces a short list. The design guarantees only that the correspondence is hidden within the set; it does not guarantee that the set is large, and set size depends on the behaviour of everyone else rather than on the mathematics.

Time is the second axis and it works against the user. A deposit followed almost immediately by a withdrawal of the same denomination narrows the field sharply, while delay increases the population of candidates. A user with a reason to move funds quickly cannot buy that protection, so the property is weakest exactly when it is most wanted.

How can you assess what a privacy claim actually promises?

You name the observer the claim is made against, identify exactly which data is hidden, find the assumption the property rests on, account for the data that exists outside the system, and then restate the claim in a form that could be falsified. The procedure below is an evaluation method for reading claims critically.

Step 1: Name the observer the claim is made against

Write down which observer the claim is supposed to defeat, whether that is a casual onlooker, a counterparty, a commercial analytics firm or a government with subpoena power, because a property that holds against one may fail against another. Most claims quietly assume the weakest of those adversaries.

Step 2: Identify exactly which data is hidden

State precisely which field is concealed, such as the link between two transactions, the amount, the participants or the timing, because privacy claims are almost never about all of these at once. Writing the answer down usually reveals how much the claim left unsaid.

Step 3: Find the assumption the property rests on

Look for the condition the guarantee depends on, which for pooled designs is usually the number of indistinguishable participants, because a mathematical property that holds only under an assumption is only as strong as that assumption. An assumption nobody states is still an assumption.

Step 4: Account for data outside the system

List the information that exists outside the protocol entirely, including exchange records, network addresses, public posts and the ordinary correlations of daily behaviour, because no on-chain construction can make external data disappear. This step is where most confident privacy claims lose their force.

Step 5: Rewrite the claim so it can be tested

Restate the claim as a single sentence naming the observer, the hidden field and the assumption, because a claim in that form can be checked or falsified while a word such as anonymous cannot. If the rewritten sentence looks much weaker than the original, the original was doing rhetorical work.

Why does the distinction matter to users and regulators?

Because both sides make expensive errors when they treat unlinkability as anonymity. A user who believes their activity is unrecoverable may behave in ways that create exactly the correlations that expose them. A regulator who accepts the same framing treats a probabilistic weakening as a total blackout, and calibrates policy against a capability that does not exist.

For users, the practical consequence is a false sense of finality. Privacy on a public chain is not a state you enter and remain in, because the ledger is permanent and analysis improves. Relying on such a property is a bet about the future capabilities of observers, and it is a bet with no expiry date.

For policymakers, the framing shapes how proportionate a response looks. If a tool truly conferred anonymity, treating it as a black hole in the financial system would follow naturally. If it weakens a statistical link within a set of participants, while exchange records, timing and behaviour continue to yield attributions, then the case for any given restriction has to be argued on evidence rather than asserted from the word alone.

The legal record reflects the sharper version. The Fifth Circuit’s 2024 Van Loon decision turned on whether immutable contracts were property under a statute, and Treasury removed the designation in March 2025, yet criminal proceedings about individual conduct continued regardless. Those cases were never about whether the mathematics worked.

Privacy words and what they actually claim

Much of the confusion is vocabulary rather than technology, because the same words are used loosely across marketing, journalism and technical writing. The table gives the narrow technical reading of each, as a guide to interpretation rather than an assessment of any product.

Word as commonly used What it can support technically
Anonymous No identity recoverable by any observer, a claim almost nothing on a public chain can support
Unlinkable The connection between two events is weakened within a set, not eliminated
Private Some data is hidden from some observers; the sentence is incomplete until both are named
Untraceable A claim about an adversary’s current capability, which changes as methods improve
Zero-knowledge A proof reveals nothing beyond the statement proved, which says nothing about metadata

Every row narrows a broad word into a testable one, and the narrowing is where the argument usually is. Disputes that look technical often turn out to be two parties using the first column against the second.

Frequently asked questions

Is a zero-knowledge proof itself ever broken by analytics?

Ordinarily not. Analysts work around the proof rather than against it, using the deposit and withdrawal records the contract publishes plus data from outside the chain. The cryptography can be sound while the surrounding pattern of use still supports a confident inference.

Does using a privacy tool by itself imply wrongdoing?

No, and treating it that way confuses a signal with a conclusion. Compliance systems use mixer association as a risk factor that prompts further review, not as a finding, though in practice a flag can still lead to account restrictions that the user must then contest.

Do privacy-focused blockchains solve the problem differently?

They apply concealment at the protocol layer so that shielding is the default rather than an application anyone opts into. That changes the size and shape of the anonymity set, but the same analytical pressure from metadata, exchange records and behaviour outside the chain still applies.

Why do reports about mixer volumes vary so widely?

Different analysts use different heuristics and different definitions of what counts as illicit, so estimates diverge even when they describe the same period. Treasury’s assertion of more than seven billion dollars laundered has been disputed by researchers, which is why such figures should be attributed rather than repeated as settled fact.

Leave a Comment

Your email address will not be published. Required fields are marked *