Back to Blog
PrivacyUpdated September 16, 2026·4 min read

How AI chain analysis de-anonymises transparent blockchains — and what still defeats it

Blockchain analytics used to be a few heuristics run by hand; it is now machine learning applied to every transaction on every transparent chain, tied to exchange KYC data. What the models actually infer (ownership clusters, change outputs, exchange identities, timing links), how confident they are, where they fail, and the two things that still work: privacy coins and discipline at the boundary.

The asymmetry

A transparent blockchain is the ideal dataset for machine learning: complete, permanent, structured, and public. Every heuristic that analysts once applied by hand — "these inputs were probably spent by one owner", "this output is probably change" — is now a feature in a model trained on millions of labelled transactions, where the labels come from exchange KYC data, seized wallets, and the analysts' own test transactions. The output is not a guess about one address; it is a graph of clusters with names attached, updated continuously.

Understanding what those models can and cannot infer is the difference between privacy habits that work and ones that only feel like they do.

What the models infer, and how well

InferenceBasisReliability
Common ownership of inputsInputs spent together in one transaction are usually one walletVery high on Bitcoin outside CoinJoin
Change output identificationAmount patterns, script types, round numbers, output orderingHigh; modern wallets reduce but do not remove it
Address reuse linkageSame address used twiceCertain
Exchange identityDeposit addresses belong to known exchange clusters; KYC ties them to a personCertain for the exchange; the person, via the exchange's records
Timing and amount correlationA withdrawal of X followed by a deposit of X elsewhere within minutesHigh when amounts are unusual; low for round amounts with delay
Behavioural fingerprintingFee choices, transaction times, wallet software quirks, output countsMedium and improving — this is where ML adds the most
Cross-chain tracingMatching a swap's deposit on one chain to a payout on another by amount, time and rateMedium for transparent-to-transparent; fails when one side is a privacy coin

The last row is the key one for anyone using an account-free exchange. A BTC → ETH swap can, in principle, be matched across chains by an analyst who sees both sides and knows the rate. A BTC → XMR swap cannot: the Monero side has no amount, no receiver and no traceable output to match against.

Where the models fail

  • Privacy coins. Monero gives the model nothing: no sender (ring signatures), no receiver (stealth addresses), no amount (RingCT). Shielded Zcash likewise, inside the pool. Analytics firms sell "probabilistic" Monero tracing; the public evidence for its accuracy is thin, and the protocol keeps hardening (ring size increases, and a planned move to full-chain membership proofs that removes ring-based analysis altogether).
  • Round amounts with delay. Timing/amount correlation depends on distinctiveness. 0.05 BTC an hour later is not a link; 0.04731 BTC eleven minutes later is.
  • Fresh addresses in a wallet with no identified history. A cluster with no exchange touchpoint has no name. It becomes identified only when it touches something identified.
  • CoinJoin done well. Equal-output CoinJoins break the common-input heuristic; the analysis becomes probabilistic rather than certain. It does not hide amounts or the fact of participation.

The boundary is where identity leaks

In practice, the models attach names at exactly one kind of place: where coins touch an identified party — an exchange withdrawal, a KYC merchant, a labelled donation address. Everything else is inference from those anchors. So the defence is not "be invisible"; it is "control the boundary":

  1. Withdraw from the exchange to your own wallet, not to a swap or a merchant.
  2. Break the graph at the boundary with a privacy coin: BTC → XMR from your wallet; what happens after is off the map.
  3. When returning to a transparent chain, receive to a fresh address — XMR → BTC — and do not reunite it with identified coins.
  4. Vary amounts and timing so the two sides of a break do not correlate.

An account-free exchange contributes one specific thing here: it is a boundary crossing that does not add a new identified anchor, because it never learns who you are.

Transparency where it belongs

Transparency is not the enemy; misplaced transparency is. Public auditability of a protocol's supply, of an exchange's reserves, of a charity's spending — those are the right uses. A permanent public record of every individual's purchases, searchable by anyone with the analytics subscription, is the wrong one, and it exists only because transparent chains were designed before the consequences were understood. Privacy coins are the correction; the habits above are how to use it.

Frequently asked questions

Can AI trace Monero? No public method reliably does. Claims of "Monero tracing" rely on user mistakes (reusing a payment ID, sending exact amounts, using a compromised remote node) rather than on breaking the protocol.

Is Bitcoin "anonymous"? No. It is pseudonymous, and pseudonyms are broken by the inferences above. Treat every Bitcoin transaction as attributable unless you have taken specific steps.

Does using an account-free exchange hide the Bitcoin side? No — the deposit is a normal public Bitcoin transaction. It hides the exchange's knowledge of you and, when the payout is a privacy coin, everything after.

What about Lightning? Payments are not on a public ledger, but channel funding and closing are, and routing nodes see part of each path. It reduces the dataset; it does not remove you from it.

Where should I start? Habit 1 above costs nothing; the privacy best practices ranks the rest by impact.

Ready to swap privately?

No account required. Start in seconds.

Start swapping →