# Unmasking the Mixer: How On-Chain Sleuths Demix Tornado Cash Transactions Source: https://x.com/officer_secret/status/2079594342948192597 ## Summary Tornado Cash's privacy promise can be undone in practice through "demixing," in which on-chain analysts use behavioral heuristics on public blockchain data to probabilistically link deposits to withdrawals, without breaking any cryptography. The article describes heuristics such as address reuse, gas price fingerprinting, timing correlation, and voucher count matching, and says academic studies and forensic tools have linked sometimes 20-35% or more of transactions when combined. It highlights two open-source tools: tornado-demix, a Python CLI by prettydeath for deposit-withdrawal correlation, and retrace, a web dashboard by 0xKoda for post-mixer withdrawal analysis. ## Article Tornado Cash, an Ethereum privacy protocol that was once popular, promised to break the on-chain link between depositors and withdrawers through the use of zero-knowledge proofs (zk-SNARKs). Users deposit fixed denomination ETH (0.1, 1, 10 or 100 ETH pools) into shared smart contract pools and later withdraw to a fresh address by proving knowledge of a private note - without revealing which deposit funded the withdrawal. In theory this results in a large anonymity set. In practice, there is often enough information leaked through user behavior, operational metadata and predictable patterns for determined on-chain analysts, sometimes called “sleuths” to probabilistically link deposits to withdrawals. This process is called demixing. No cryptography has been broken. Instead, analysts leverage real-world usage patterns with heuristics applied to public blockchain data (event logs, transaction data, timestamps, gas prices and values). Academic studies and forensic tools have demonstrated these approaches can link large percentages of transactions together, sometimes 20-35% or more when combined, showing billions in value flows. For practitioners, two tools are particularly useful: tornado-demix (for deposit-withdrawal correlation) and retrace (for post-mixer withdrawal intelligence); both are open-source. Core Heuristics Used in Demixing On-chain analysts typically combine several signals: Address reuse: The same address (or closely related cluster) both deposits and withdraws — a common beginner mistake yielding high-confidence links. Gas price fingerprinting: Deposit and withdrawal transactions share an unusual or identical gas price (especially when deviating from the block median), suggesting the same automated wallet or script. Timing correlation: Deposits and withdrawals occur within narrow windows (minutes to days), particularly when the pool’s anonymity set is small. Multi-note “vouchers” and count matching: Users often deposit multiple notes of the same denomination in quick succession (a “voucher”), then later withdraw the exact same count to one or a few addresses. Fee fingerprinting: Genuine withdrawals are slightly less than the denomination due to relayer fees (e.g., ~0.90–0.995× denomination). FIFO / temporal matching and profile matching: Earliest plausible matches or consistent multi-denomination patterns across a user’s activity. Downstream clustering: Tracing one hop from withdrawal addresses to find reconvergence points (shared consolidation addresses). These heuristics are probabilistic, not definitive. They produce “leads” that require further verification (e.g., via transaction graphs or off-chain intelligence). False positives arise from coincidental overlaps, but combining signals and statistical validation strengthens confidence. tornado-demix: Targeted Amount + Timing Correlation tornado-demix (by prettydeath) is a lightweight Python CLI tool specifically built for de-anonymizing Tornado Cash ETH pools via amount and timing heuristics. It does not claim to break zk-proofs; it surfaces probabilistic candidate links using only public Etherscan API data. How it works: It scans for “vouchers”: clusters of same-denomination deposits occurring within a configurable time gap (default ~24 hours). For each voucher of count N, it searches for exactly N withdrawals of the matching denomination within a time window after the deposits. Withdrawals are filtered to realistic fee ranges to exclude noise. Additional modes support cross-wallet profile matching (addresses receiving a full multi-denomination fingerprint) and split-exit clustering (tracing downstream reconvergence from partial withdrawals). Key commands: demix — Analyze a single suspect deposit address. multi — Cross-correlate multiple wallets and find strong profile matches. cluster — Trace split exits to shared downstream addresses. Outputs are clean CSVs (candidates.csv, vouchers.csv, withdrawals_*.csv, etc.) with timestamps, transaction hashes, and candidate flags. It supports resumable runs via caching and is configurable via simple CSV files (wallets list, API keys). Strengths: Focused, efficient, and transparent methodology. Excellent for targeted investigations starting from known deposit addresses. Lightweight (primarily requests + stdlib). Limitations: ETH pools only (no ERC-20 at time of documentation); better with larger N vouchers; purely probabilistic; requires an Etherscan API key. The tool is explicitly positioned for compliance, investigation, and academic research. retrace: Withdrawal-Side Intelligence Dashboard While tornado-demix excels at linking deposits to withdrawals, retrace (by 0xKoda) operates on the other side of the mixer. It is a web-based tool that aggregates and presents consolidated withdrawals from Tornado Cash (and Railgun) in an easy-to-search interface. Key features: Consolidated view of withdrawals — displays them in a digestible format instead of raw Etherscan noise. Fast search by date or ETH address — a major usability improvement over manual explorer queries. Focused, indexed dataset (starting late December 2023, with emphasis on recent/ongoing activity; historical expansion planned). Helps identify consolidation addresses and post-mixer fund flows quickly. retrace enables analysts to quickly explore what happens next after demixing identifies candidate withdrawal addresses – are the funds aggregated, sent on, or spent? It’s particularly good for tracking threat actor behavior, money laundering from hacks, or large-scale patterns. It is part of a larger ecosystem (along with tools like Storm Chasers and Gunwatch) built for efficient transaction tracing in privacy protocols. Strengths: User-friendly frontend; speeds up the “what happened after the mixer?” phase; browser-based (no installation needed for the hosted version). Limitations: Primarily a visualization/search layer rather than a deep heuristic engine; dataset starts from a specific recent date; no detailed public documentation on internal indexing logic. More Tools & Tactics De-mixing TornadoCash (by flipsidecrypto and AMLBotHQ & PureFiProtocol): x.com/amlbothq/status/1740689165652472158 Also (including RAILGUN_Project de-mixers), check out awesome tools by 0xKoda: x.com/0xkoda/status/1740348122596036689 x.com/0xkoda/status/1740158988048867724 t.me/+lP4Tn49176FmMzBk t.me/chainchasers t.me/railgunwatch Other tools: github.com/pareto-xyz/tutela-app www.tokentooling.com/demix github.com/tav-r/tornado_cash_heuristics github.com/lambdaclass/tornado_cash_anonymity_tool github.com/pcaversaccio/tornado-cash-ether-withdrawal-decipherer Bitcoin-focused demixing: HongYoungGee/De-mixing — Practical algorithm for matching inputs/outputs in Bitcoin mixers (e.g., Helix-style services). Newer tools like Cryptracer for Bitcoin transaction tracing, mixer detection, and graph visualization. Commercial platforms (enterprise-grade demixing & attribution): Chainalysis Reactor Elliptic Investigator TRM Labs Forensics Useful Resources Blockchain Forensics: A Practical Guide to Tracing Stolen Funds Blockchain Forensics: Attribution Techniques and the Role of OSINT Blockchain Forensics: Advanced Blockchain Forensics Techniques and Additional Resources Awesome On-Chain Investigations HandBook Beyond the Blockchain: OSINT in Crypto Investigations A Typical Sleuthing Workflow Start with a known deposit address or suspicious activity. Use tornado-demix (demix or multi) to generate candidate withdrawal addresses via voucher/timing/fee matching. Verify and expand leads with gas-price or address-reuse checks. Feed promising withdrawal addresses into retrace (or similar dashboards) to explore consolidation patterns and downstream flows. Combine with broader graph analysis (MetaSleuth, Dune Analytics queries on Tornado withdrawal tables, or commercial tools) and off-chain context. Real-world analyses using similar heuristics have linked substantial volumes, demonstrating that even sophisticated mixers remain vulnerable to behavioral analysis when users do not follow strict operational security (e.g., reusing addresses, withdrawing too quickly, or using distinctive patterns). Limitations, Ethics, and the Ongoing Arms Race All demixing is probabilistic. Overlapping user activity, large anonymity sets, disciplined users (long waits, varied timing, no reuse), and relayer usage reduce effectiveness. Results must be corroborated. These tools are placed in a broader context: Tornado Cash was sanctioned by the U.S. Treasury in 2022 due to documented illicit use, including by state-sponsored actors. Privacy tools have legitimate uses (protecting user data, enabling financial privacy), but they are also misused. On-chain sleuthing aids compliance, law enforcement and ecosystem safety. It's a classic arms race: protocols and users increase hygiene and add features; analysts come up with better heuristics, clustering algorithms and machine learning approaches. Tools like these democratize access to forensic techniques that were previously only available to well-resourced firms. Conclusion On-chain demixing is not a defeat of zero knowledge cryptography it is a use of the gap between cryptographic guarantees and human/operational behavior. Tools like tornado-demix and retrace offer tangible, approachable ways for researchers, compliance teams and investigators to surface leads from public data. For those interested in on-chain analysis, playing around with these repositories (and related resources such as academic papers on Tornado heuristics) can be instructive in understanding both the capabilities and the constraints of mixer privacy. The takeaway for users is clear: Even the best cryptographic mixers require careful operational security to live up to their privacy promises. Keep on being curious. Check things out. Use these powers for good. Support Me Please, consider donating me: 0x1191b7d163bde5f51d4d2c1ac969d514fb4f4c62 or officercia.eth - Ethereum & all EVM chains; 17Ydx9m7vrhnx4XjZPuGPMqrhw3sDviNTU - Bitcoin; TYWJoRenGB9JFD2QsdPSdrJtaT6CDoFQBN - TRX; 4AhpUrDtfVSWZMJcRMJkZoPwDSdVG6puYBE3ajQABQo6T533cVvx5vJRc5fX7sktJe67mXu1CcDmr7orn1CrGrqsT3ptfds - XMR. Please think about making a gift to help me in my efforts. I will be able to devote more time to writing in-depth articles and presenting even more insightful information thanks to your support. Thank you!