Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
How blockchain analysts link multiple crypto addresses to one entity — and what that means for your on-chain privacy.
Wallet clustering is the process of grouping multiple blockchain addresses that likely belong to the same person, exchange, or service — turning dozens of pseudonymous addresses into a single traceable entity.
Most people assume each crypto address is a separate, private identity. It rarely works that way. A single trader might control fifty addresses across multiple wallets. An exchange might control millions. Clustering is how analysts collapse that sprawl back into a single picture. It powers compliance tools at regulated exchanges, law-enforcement investigations, and the “smart money” tracking features you see on platforms like Arkham and Nansen. Whether you are a compliance analyst, a DeFi trader tracking whale positions, or an ordinary user wondering how exposed your activity really is — the mechanism is the same.
Every blockchain is a public ledger. Anyone can see every transaction, every address, and every balance. What no one can see directly is who controls which address.
That gap between “visible on-chain” and “identified in real life” is pseudonymity. It is narrower than most people expect. Address clustering — also called transaction clustering or blockchain address clustering — is the analytical process that narrows it further. The algorithm looks for addresses that behave as if they share the same private key holder.
The output of wallet clustering is an entity: a labeled cluster of addresses treated as a single economic actor. The same whale who sent 500 ETH to a DeFi pool, funded a hardware wallet three weeks earlier, and collected airdrop tokens through four separate addresses may all belong to one entity cluster. Analysts do not need to know that person’s legal name to connect those addresses. The cluster is the unit of analysis. The label comes later.
The distinction between “cluster” and “identified person” runs through everything that follows. Clustering alone produces entities. Deanonymization happens when an entity cluster is connected to a real-world identity, usually through an identity anchor.
The practical consequence: a cluster can be built, scored, flagged, and shared across analytics platforms long before any legal name is attached to it. By the time you deposit to a KYC’d exchange, that cluster already has a history. Compliance software at the exchange reads that history automatically.
The mechanics differ by blockchain. On Bitcoin, two heuristics do the heavy lifting.
The first and most powerful is the Common Input Ownership Heuristic (CIOH). Bitcoin transactions can consume multiple “input” addresses in a single spend. To do that, all those inputs must be signed — and to sign them, you need each address’s private key. If Address A, Address B, and Address C all appear as inputs in the same transaction, an analyst can conclude they are all controlled by the same entity. That conclusion becomes the basis for linking the three addresses into one cluster.
Here is a simple example. Imagine you hold Bitcoin across three addresses — maybe from different purchase dates or different wallets you used to use. You decide to consolidate them in a single send:
Because A, B, and C appeared together as inputs, CIOH links them to the same owner. Then the change address heuristic kicks in: Address D received the change from your spend, so it is also likely yours. The cluster just expanded to include a fourth address — one you have never seen flagged before.
Combining CIOH with change-address detection at scale has allowed blockchain analytics firms to collapse roughly 184 million Bitcoin addresses into around 40 million entity clusters. That is a compression ratio of more than four to one, built from publicly available transaction data alone.
One important break in the logic: CoinJoin. This privacy protocol deliberately mixes inputs from multiple unrelated users into a single transaction. Because the inputs did not all belong to the same person, CIOH applied to a CoinJoin transaction produces a false cluster. That is a feature from the privacy user’s perspective and a known limitation from the analyst’s. Bitcoin’s Taproot upgrade further complicates things by making CoinJoin transactions look like ordinary single-signature transactions, reducing the surface area analysts have to work with.
Whether your Ethereum activity is “just as trackable” as Bitcoin is one of the most common questions around address clustering. The answer is yes — but through different methods.
Bitcoin uses a UTXO (Unspent Transaction Output) model. Every transaction consumes specific previous outputs and creates new ones. That explicit input-output structure is what makes CIOH possible in the first place. Ethereum uses an account model instead: each address has a running balance, like a bank account, and transactions debit and credit that balance directly. There are no inputs to co-sign, so CIOH does not apply.
The table below shows how the two models compare on the dimensions that matter for bitcoin address clustering and beyond.
| Dimension | Bitcoin (UTXO) | Ethereum (Account) |
|---|---|---|
| Primary clustering method | Common Input Ownership Heuristic | Behavioral fingerprinting |
| Key heuristic | Shared transaction inputs | Shared deployer, funding wallet, contract interaction patterns |
| Privacy exposure level | High — CIOH is efficient and well-established | High — MEV signatures, timing analysis, and contract patterns are effective substitutes |
Ethereum clustering relies on behavioral fingerprints: shared deployer addresses (a developer who launches multiple contracts from one address), funding wallet heuristics (the address that funded your wallet also funded five others in the same block), timing analysis, and MEV bot signatures. CIOH does not apply, but the result is the same — a probabilistic cluster built from public on-chain signals.
Modern analytics firms like Chainalysis and TRM Labs have also extended clustering across chains by following bridging activity. When funds move from Bitcoin to Ethereum via a bridge, the two clusters on each chain can be linked. Cardano and Solana both use UTXO variants, which means CIOH-style analysis partially applies there too. Regardless of which chain you use, the baseline assumption should be that on-chain behavior is rarely as private as users expect.
More people than most users think. Wallet clustering is not a niche government tool. It is built into exchange compliance infrastructure, retail analytics products, and security research workflows.
The largest user group is the compliance and law enforcement sector. Regulated exchanges in the EU, UK, and US are required under FATF’s Travel Rule and MiCA to screen counterparty addresses. To do that at scale, they license software from Chainalysis, Elliptic, and TRM Labs, all of which use clustering as the foundation for their AML risk scoring. Law enforcement agencies use the same platforms to trace illicit funds: following a cluster from a ransomware payment, through a mixing service, to a withdrawal address at an exchange is a standard investigative workflow. That compliance work connects directly to the broader world of AML obligations in crypto, where regulators expect exchanges to flag and investigate suspicious address activity.
The second group is on-chain traders and researchers. This is the audience who first encountered wallet clustering inside Arkham Intelligence, Nansen, or a Crypto Twitter thread about whale moves. Arkham uses entity deanonymization — its own term for clustering with entity labeling — to group wallet addresses under named entities: known funds, exchanges, protocols, and high-profile traders. Nansen calls the same underlying approach transaction clustering and surfaces it as “smart money” signals. Bubblemaps takes a different visual approach, showing holder concentration and wallet relationships as a graph to help users spot insider clusters in meme coin launches. If you have ever opened a bubble map on a new token and seen a cluster of wallets clearly controlled by the same party, you were looking at applied wallet clustering.
The third group is security researchers, OSINT investigators, and journalists. Academics study exchange fund flows to document systemic risk. Investigative journalists use clustering to document fraud, track sanctioned entities, and map out exchange insolvency scenarios. Practitioners combine clustering with traditional OSINT — linking on-chain cluster data with IP addresses, social media, and legal entity records — to build attribution cases.
The key concept here is the identity anchor. A wallet cluster on its own is pseudonymous — it is a label like “Unknown Entity 3847.” That cluster can hold millions of dollars, execute thousands of transactions, and interact with dozens of protocols, all without a legal name attached to it.
The moment one address in that cluster interacts with a KYC’d exchange, the picture changes. Your exchange account links your real identity to the deposit address. Clustering extends that identity across every other address in the same cluster. A single deposit or withdrawal from a verified account can retroactively connect your identity to months of prior on-chain activity.
Several on-chain behaviors increase your exposure to deanonymization — and some are more obvious than others:
The KYC verification process is what converts a pseudonymous cluster into a named one — which is why how an exchange handles identity data is as consequential as what you do on-chain.
The cost of deanonymization has also fallen sharply. USENIX Security 2025 research found that passive network observers could link IP addresses to blockchain addresses with high accuracy across Bitcoin, Ethereum, and Solana, with deanonymization attempts costing under $4 at scale using modern infrastructure. These are not nation-state-level resources.
One privacy option is to choose chains or protocols that make clustering structurally harder. Privacy coins like Monero and Zcash use cryptographic techniques that obscure sender, receiver, and amount. They work, which is exactly why Monero, Zcash, and Dash were delisted from EU-regulated exchanges in 2024 as regulatory pressure escalated under MiCA. Choosing a privacy coin means accepting reduced exchange access in regulated markets.
Not all clustering tools are built for the same purpose. The compliance analyst at a regulated exchange and the DeFi trader trying to track a whale are using fundamentally different products, even if the underlying on-chain address analysis draws on similar heuristics.
Here is how the major platforms divide up.
| Tool | Primary use case and audience |
|---|---|
| Chainalysis Reactor | Compliance and law enforcement — investigation workflows, sanctions screening, case-building for prosecutors |
| Elliptic | Enterprise AML compliance — risk scoring for regulated exchanges and financial institutions |
| TRM Labs | Compliance plus government contracts — used by agencies including the IRS, FBI, and OFAC |
| Arkham Intelligence | On-chain intelligence and entity deanonymization — trading signals, entity labeling, public bounty system for wallet attribution |
| Nansen | Smart money and DeFi portfolio tracking — wallet labels, token flow analysis, fund positioning |
| Bubblemaps | Visual token distribution and holder relationships — pattern recognition for meme coins and token launches |
These tools are not interchangeable. Compliance platforms need legal defensibility: their cluster determinations are used in court cases and regulatory filings, so accuracy standards are high and human review is standard. Trading intelligence platforms optimize for speed and entity breadth — Arkham added AI-powered entity deanonymization and KOL wallet tagging in 2025, expanding its label database aggressively. Visual tools like Bubblemaps optimize for pattern recognition at a glance, making it fast to spot whether a new token’s top holders are actually the same insider cluster wearing different addresses.
Wallet clustering is probabilistic, not certain. And when it is wrong, the consequences land on real users.
False positives happen when a clustering algorithm incorrectly groups addresses from different entities. The most common trigger: both addresses interacted with the same shared infrastructure — a popular coinjoin service, a dust distribution, or a commonly used bridge contract. The algorithm sees the shared connection and merges two unrelated clusters into one.
The Ghost Clusters study (USENIX Security 2025) measured clustering accuracy across major providers and found a wide range: roughly 95% accuracy for darknet marketplace clusters, but as low as 25% for clusters adjacent to mixing services. That 25% figure means three out of four addresses in a mixer-adjacent cluster could belong to completely unrelated entities.
In practice, a false positive can look like this: a user receives a tiny amount of Bitcoin from an address they do not recognize — a dust transaction designed to probe or link addresses — and their address ends up merged into a cluster that is later flagged as connected to a sanctioned entity. When that user tries to withdraw funds from a regulated exchange, the system flags the transaction automatically. The account may be suspended pending a compliance review.
If this happens to you, these steps give you the best path forward:
Over-reliance on automated clustering without human review has drawn criticism from legal defenders and blockchain forensics experts. For most users transacting normally, false positives are rare. But they are not impossible, and knowing what to do when flagged beats assuming it will never happen.
Cryptographic tools offer a longer-term defense. Zero-knowledge proofs allow transactions to be verified without revealing sender, receiver, or amount — making CIOH and behavioral fingerprinting structurally impossible to apply. ZK-based privacy protocols are still maturing, but they represent the most technically rigorous answer to clustering at the protocol level.
Wallet clustering is the process of grouping multiple blockchain addresses that likely belong to the same person or service into a single entity. Analysts use spending pattern heuristics — primarily the Common Input Ownership Heuristic on Bitcoin — to link addresses without needing to know the owner’s real identity.
The Common Input Ownership Heuristic (CIOH) works by observing which addresses appear together as inputs in a single Bitcoin transaction. Spending from multiple addresses in one transaction requires signing with each address’s private key. If you can sign all three inputs, you control all three addresses — so the heuristic groups them into one cluster. It is the most widely used method in wallet clustering on Bitcoin’s UTXO-based ledger.
Wallet clustering on its own produces a pseudonymous entity — a labeled cluster with no legal name. Personal identification happens when that cluster is connected to an identity anchor, most commonly a KYC’d exchange account. Once one address in your cluster is linked to your verified identity, the entire cluster’s activity is potentially attributable to you.
Multiple wallets help only if they are never funded from the same source and never used in the same transaction. Funding five wallets from a single address creates a shared-funder cluster almost immediately. Consolidating funds across wallets in one transaction triggers CIOH. The protection comes from how the wallets are funded and used, not from the number of wallets alone.
CoinJoin breaks the CIOH assumption by mixing inputs from multiple unrelated users, making it impossible to conclude shared ownership. It does not make you fully anonymous — transaction graph analysis and other heuristics still apply. Privacy coins like Monero and Zcash use cryptographic obfuscation at the protocol level, which is far more resistant to clustering. Both approaches involve tradeoffs: CoinJoin requires compatible software and careful usage, and privacy coins face increasing delistings from regulated exchanges under MiCA and similar frameworks.
Wallet clustering is already running on your addresses. Here are five practical steps you can take this week.
Start by checking your own exposure. Tools like Arkham Intelligence and Nansen let you search any public address and see which entity cluster it may belong to, which labeled wallets it has interacted with, and what flagged addresses are nearby. Knowing your starting position takes five minutes.
Next, audit your address reuse. If you have been using the same deposit address across multiple platforms or transactions, that address is a growing cluster. HD wallets generate a new address for every receive transaction by default — switch to one if you have not already.
Think carefully about which exchange you use to convert funds. The exchange is your identity anchor. Funds deposited to a KYC’d exchange link your legal identity to that address, and clustering extends that identity backward. Know what you are agreeing to when you verify your account — that is the decision, not whether to use exchanges at all.
If you received unexpected micro-transactions recently, do not spend them by consolidating with your main balance. Dust is sometimes deliberately sent to link otherwise disconnected addresses via the CIOH. Spending it merges the clusters.
Finally, if your account has ever been flagged or a withdrawal delayed without explanation, ask the exchange for the specific address or cluster that triggered the flag in writing. Most compliance teams will respond to a formal written request, and a clean transaction history is usually enough to resolve a false positive.