Bitcoin privacy has an awkward flaw: sometimes the trail starts before anyone sends a coin.
A company paying a supplier in BTC may think it is revealing only the invoice amount. In reality, a reused wallet address can expose who was paid, how much moved, when it happened, and potentially what else that wallet has done.
For a competitor, the information is sitting in plain sight. A block explorer can turn a payment into a map of counterparties, treasury movements, and deal activity without needing access to the company’s books.
The obvious assumption is that the exposure begins when a transaction hits the blockchain. But research published in July 2026 by KU Leuven’s DistriNet group suggests the wallet itself can give users away earlier.
Researchers tested 85 popular browser-extension wallets and found that the wallets could leak enough information to let websites fingerprint and track users. Across the full sample, 36 wallets were vulnerable to fingerprinting, representing roughly 82% of the installs studied.
The problem is almost mundane. To display a balance, a wallet can contact an outside server and send the associated address. No dramatic exploit is required. The software is simply revealing information as part of its normal operation.
That distinction matters because Bitcoin privacy is not only about hiding a transaction. It is also about limiting the number of places where an address can become attached to a person, a company, or a digital identity.
Bitcoin Privacy Has a Wallet Problem Before the Chain Gets Involved
The KU Leuven study found that 17 wallets, representing about 23 million installs, could expose links between multiple addresses belonging to the same user.
In 22 of the 36 affected wallets, websites could still obtain an address after a user had revoked access and restarted the browser.
There was another wrinkle. Websites could often determine which wallet extensions a person had installed without that user connecting a wallet at all. Researchers found that 23 of the 36 affected wallets could leak an address through content loaded from another website, without the user clicking anything.
The response from wallet providers was uneven. Coinbase Wallet, Coin98, and Hana made changes after being contacted by the researchers. MetaMask, Rabby, and OKX did not make changes, according to the study summarized in the reference article.
The researchers also tested 30 decentralized applications. Only 11 properly revoked wallet access when users disconnected or logged out.
Once an address becomes visible, the blockchain does what it always does: it keeps the record.
The Public Ledger Can Turn One Address Into a Profile
Blockchain analytics companies can examine transaction patterns and estimate which addresses are controlled by the same person or organization.
Repeated transfers between wallets, similar interactions, and other behavioral patterns can allow software to group addresses together. One known wallet can therefore open the door to a much larger cluster of activity.
By mid-2026, Chainalysis said it had grouped more than 1 billion blockchain addresses into over 134,000 identified entities.
Changing networks does not automatically solve the problem. Analysts can trace assets through bridges, while transactions involving decentralized exchanges remain publicly recorded because the swaps still happen on-chain.
The result is a strange contradiction at the heart of Bitcoin privacy. An address may look anonymous because it is just a string of characters. But enough connected activity can turn that string into a detailed financial history.
There are concrete examples of this process working. After the Colonial Pipeline ransomware attack in 2021, US investigators traced Bitcoin through several wallets and recovered about $2.3 million of the $4.4 million ransom.
Helix offers an even cleaner demonstration.
The darknet tumbler, operated by Larry Dean Harmon from 2014 to 2017, was built around the promise of making Bitcoin harder to trace. Customers sent coins through the service, which mixed funds before returning what it described as “clean” bitcoin.
About 354,468 BTC, worth roughly $311 million at the time, passed through Helix.
The mixing changed the appearance of the transaction history. It did not remove the history itself. Every movement remained permanently recorded on the blockchain, including the 2.5% commission Harmon charged.
A service designed to obscure the trail still left one.
Bitcoin Privacy Gets Messier When a Wallet Meets a Real Identity
Tracing coins is only one part of the equation. Investigators and analysts also need a way to connect an address to an actual person or business.
Regulated exchanges can provide that bridge. They know which deposit addresses belong to customers and maintain identity information through KYC checks. If investigators trace funds to one of those addresses, they can seek account details through legal process.
The impact can extend beyond a single transaction. Once one address in a larger cluster is connected to a name, the other addresses associated with that cluster may become easier to identify too.
Sometimes the connection is even more straightforward. People and businesses publish wallet addresses themselves on websites, donation pages, Telegram chats, or public profiles. Once an address is linked publicly to a name, its transaction history is public as well.
For a business, that can mean a supplier payment reveals more than the payment itself. Years of transaction history can make counterparties, treasury movements, and other relationships easier to reconstruct.
But blockchain tracing is not infallible.
The systems used to connect wallets depend heavily on patterns and probability, which means they can generate both false positives and false negatives.
A person can also inherit unwanted scrutiny from the history of coins they receive. One documented P2P buyer had an account frozen after receiving Bitcoin that had previously passed through a mixer.
For exchanges and regulated companies, a mistaken alert can create real compliance and customer-support problems. A legitimate customer may find funds frozen because an automated system made the wrong connection.
There are also places where tracing becomes harder. Privacy-focused cryptocurrencies such as Monero are more difficult to follow, while investigations can stall when funds reach exchanges in jurisdictions that do not cooperate.
Even major analytics firms have had to revise their own figures. In early 2025, Chainalysis cut its estimate of crypto stolen by North Korea in the previous year from $1 billion to $660.5 million after reassessing several hacks.
Courts have also seen challenges to the weight given to proprietary blockchain-analysis tools. Defense teams in cases including Bitcoin Fog and Tornado Cash questioned how much confidence should be placed in software whose underlying methods cannot be fully inspected from the outside.
That question carries particular weight because Chainalysis is also a major US government contractor. Independent reporting based on federal records found that the company had received more than $93.2 million in government awards.
The stakes are not abstract. A mistaken attribution can freeze funds, while in countries with weaker protections, tracing technology may expose donors, journalists, or people financing political opposition.
Most of the privacy exposure in this story is difficult for an ordinary user to control. Wallet software can leak addresses. Analysis tools can connect activity. Exchanges can attach identity records to blockchain addresses.
The clearest part a user can still influence is the direct connection between sender and recipient.
When one wallet pays another, that relationship is written permanently onto the blockchain. ChangeNOW’s Private Transfers feature is designed to remove that direct path by routing a payment through a separate, one-time address rather than sending funds directly to the recipient.
The feature does not make the broader transaction anonymous. Wallet metadata can still leak, blockchain analysis can still connect surrounding activity, and AML checks remain relevant at deposit, transfer, and payout stages.
For API partners, Private Transfers is presented as an optional feature inside the existing transfer infrastructure. It uses the same API key and fee model and does not require a separate integration.
That makes its purpose narrower than the word “privacy” might suggest: it removes one visible sender-to-recipient connection that a user can choose not to create.
Andy Greenberg’s decade covering crypto crime led him to a blunt conclusion about the technology he had once regarded as difficult to trace: “it took me a decade to realize how opposite of untraceable Bitcoin really was.”
That is the uncomfortable reality behind Bitcoin privacy. The wallet can leak. The blockchain can preserve. A cluster can point to a name.
The useful question is therefore not whether Bitcoin is completely anonymous. It is where the trail begins, which parts can be linked, and which connections can still be avoided.
