Reading mixer-output topology: a primer

AndersFX — Cointiverse forensic case file

“The funds went into Tornado Cash” is, for many victims, the moment hope evaporates. The understanding is that mixers anonymize transactions perfectly, and once funds enter, the trail is unrecoverable. The reality is more nuanced. Mixers are an obstacle, not a wall. The cartographer’s desk reads mixer outputs more often than not.

What mixers actually do

A mixer pools deposits from many users and disburses outputs in fixed denominations to fresh addresses, breaking the direct deposit-to-withdrawal link. In an ideal mixing operation, no on-chain analysis can connect a specific deposit to a specific withdrawal. In practice, “ideal mixing” requires user discipline (waiting between deposit and withdrawal, varying amounts, varying timing) that most users do not maintain. Imperfect mixing leaves chartable signatures.

The topology of a real-world mixer-output

Once funds exit a mixer, the next-hop pattern is critical. Funds that go directly from a mixer-output to a centralized exchange’s deposit address are a strong signal — the user did not maintain post-mixer hygiene, and the off-ramp identity is recoverable. Funds that move through several intermediate addresses before reaching a mixer-output recipient signal more sophistication, and the cartographer must rely on cluster analysis at the next-hop layer.

Time-correlation and amount-correlation

Two analytical levers remain even in well-mixed cases. Time correlation: deposits and withdrawals close in time form weak but useful probabilistic links, particularly when the deposit volume is unusual. Amount correlation: a mixer that disburses fixed denominations leaves arithmetic constraints. If a perpetrator deposits 14.7 ETH and the mixer disburses in 10 ETH increments, the residual 4.7 ETH must come out somewhere — and that “somewhere” is often a separate address that, traced, produces a chartable connection.

The cartographer’s working framing: mixers reduce confidence; they rarely eliminate it. A 70%-confidence mixer-output trace is still actionable for compliance freeze requests at a cooperative exchange. The map continues past the mixer.