cryptonist
A printed circuit board photographed flat, its traces and mounted components in rows

Explainers

Can governments track crypto? What the chain shows and what KYC adds

A public blockchain records every transfer and attaches no name to any of them. Four mechanisms join the ledger to names: heuristics that group the addresses belonging to one owner, exchanges that attach an identity to some of those addresses, the Travel Rule, which makes exchanges pass that identity along with a transfer, and tax reporting, which sends a yearly summary to the tax authority. Each has a boundary, and beyond it a name has to come from somewhere else.

The legal material is mostly the FATF standard, EU law (cited as first published in the Official Journal) and the OECD framework, with US Treasury and Justice Department notices as examples; other jurisdictions have their own rules.

What a public ledger exposes

On Bitcoin every transaction is announced publicly. Bitcoin’s design paper (section 10) describes the privacy that remains: the public sees that someone sent an amount to someone else, with nothing linking the transaction to a person, as a stock exchange’s tape shows trades without naming the parties.

The design paper names the weak point itself. Multi-input transactions necessarily reveal that their inputs had one owner, and if the owner of one key is revealed, linking could reveal other transactions belonging to the same owner. A name attached to one address is therefore not a fact about one payment but an entry point into the transactions linked to it, and because the history is complete, those include earlier ones.

Clustering: how addresses are grouped

In a 2013 measurement study of Bitcoin by Meiklejohn and colleagues, names were attached by transacting: the authors made 344 transactions with services (section 3.1), including depositing into and withdrawing from exchanges, and observed which addresses were used. Two heuristics (section 4.3) then extended each label to the addresses linked with it, and the authors assess how far each can be trusted, on blockchain data parsed on 13 April 2013.

Common input ownership. Addresses used as inputs to the same transaction are treated as one user’s. The authors call this quite safe, because the sender must know the private key for every input, so combining different owners’ inputs would need them to share keys. The effect is transitive: if A and B are inputs together, and later B and C, all three are one user.

Change-address detection. Bitcoin outputs are spent whole, so a payment smaller than the input returns the remainder to the sender at a change address. In outline, an output to an address never seen before, where no other output is new and none returns to an input address, is treated as change and so as the sender’s.

The authors rate this heuristic significantly less safe (section 4.5). By their test, which counted a labelled change address later used again as a mistake, the first version was wrong for 13% of the addresses it labelled. Refinements brought that to 0.17%, yet clustering still merged Mt. Gox, Instawallet, BitPay and Silk Road, among others, into one super-cluster of 1.6 million keys until two further patterns were excluded. A link made this way is an inference with a measurable error rate, and one wrong link can join strangers.

Fund tracing is also sold as a product. As read on 3 October 2026, Chainalysis describes its Reactor product as used by law enforcement, intelligence, regulatory and tax agencies, exchanges, financial institutions and corporate investigation teams, and as following funds from first deposit to cash-out; that is a vendor’s description, not an independent measurement.

The public record shows the ledger half working. A US Department of Justice release of 7 June 2021 said that, as alleged in the supporting affidavit, reviewing the public ledger let law enforcement track multiple transfers and identify that 63.7 bitcoin, described as proceeds of the ransom Colonial Pipeline paid (about 75 bitcoin), had moved to an address whose private key the FBI held. The release does not say how the FBI came to hold the key.

Exchanges are the identity layer

The chain records the movement. The exchange records the person. In FATF’s glossary (pp. 140-141) a virtual asset service provider is a business that, for others, exchanges virtual assets for fiat currency or for other virtual assets, transfers them, or holds and administers them, among other activities. Paragraph 7 of the Interpretive Note to Recommendation 15 (p. 79) applies Recommendations 10 to 21 to such providers, and Recommendation 10 (p. 14) has countries require them to identify each customer and verify that identity from reliable, independent sources when business relations begin, and to prohibit anonymous accounts and accounts in obviously fictitious names.

In the EU, Regulation 2023/1113 added crypto-asset service providers to the list of financial institutions in Directive (EU) 2015/849 (Article 38(2)(a), applying from 30 December 2024 under Article 38(8)). Its Article 14(6) and (7) have the sender’s provider verify the originator information from a reliable and independent source before a transfer, a check treated as done where the originator’s identity was verified, and the records retained, under Articles 13 and 40 of that directive.

The 2013 study’s authors argued that exchanges had become chokepoints: to buy into or cash out of Bitcoin at scale, they wrote, an exchange was unavoidable, and an agency with subpoena power would have the opportunity to learn whose account received a deposit (sections 1 and 5.2). That was a statement about the market then; the standards above make the identity step an obligation. In most countries a regulated exchange is one registered for anti-money-laundering supervision, which is where the checks come from, as what a regulated exchange is regulated for sets out.

The Travel Rule: identity moves with the transfer

The EU’s banking regulator calls the requirement that sender and receiver information accompany a transfer the so-called travel rule (EBA press release, 4 July 2024). In FATF’s standard, Recommendation 16 (payment transparency, p. 17) requires originator and beneficiary information to remain with a payment or value transfer through the payment chain. Paragraph 7(b) of the Interpretive Note to Recommendation 15 (p. 79) applies this to virtual assets: the sending and receiving providers each hold the information, and the sending provider passes it to the beneficiary provider or financial institution, if any, though it need not be attached to the transfer (footnote 47). Countries may set a de minimis threshold of up to USD/EUR 1,000 for virtual asset transfers, below which the requirement falls to names and a wallet address or transaction reference, which need not be verified unless there is suspicion (Interpretive Note to Recommendation 16, paragraphs 8-9, pp. 81-82; FATF’s Updated Guidance, October 2021, paragraphs 191-192).

In the EU the rule is Regulation (EU) 2023/1113. It applies from 30 December 2024 (Article 40) to crypto-asset transfers where the provider of the originator or of the beneficiary, or an intermediary provider, has its registered office in the Union (Article 2(1)). Article 14(1) and (2) require the sender’s provider to ensure each transfer is accompanied by the originator’s name, ledger address and identifying details such as the customer’s address or date and place of birth, and by the beneficiary’s name and ledger address. That is the legal join between the two halves: the ledger address the chain shows is accompanied by a name the exchange has verified, sent in advance of or alongside the transfer and not required to be attached to or included in it (Article 14(4)). The receiving provider must detect missing information and decide whether to execute, reject, return or suspend the transfer (Articles 16(1) and 17(1)).

The EU took the no-threshold option. Unlike the rules for funds, which distinguish transfers up to EUR 1,000 (Articles 5(2) and 6(2)), Article 14 sets no amount threshold on the information that must accompany a transfer, and recital 30 says transfers of crypto-assets should meet the same requirements regardless of amount and of whether they are domestic or cross-border.

Tax reporting: DAC8 and CARF

Tax reporting is a separate channel from the Travel Rule: it runs yearly and ends at the tax authority. The OECD’s Crypto-Asset Reporting Framework (CARF; rules and commentary approved by its Committee on Fiscal Affairs on 26 August 2022, p. 2) provides for tax reporting on crypto-asset transactions, with a view to automatic annual exchange with the jurisdictions where taxpayers reside (foreword, p. 3). It is a model with a placeholder for each adopting jurisdiction (Rules, Section I). The reporting party is any individual or entity that, as a business, provides a service effectuating exchange transactions for or on behalf of customers (Section IV.B.1, p. 19). It reports each reportable user’s identity and tax details and, for each type of crypto-asset, aggregate amounts, units and transaction counts for purchases and sales against fiat currency, exchanges between crypto-assets, and transfers in and out (Section II.A, pp. 15-16; introduction, paragraph 21, p. 12).

In the EU, Council Directive (EU) 2023/2226, commonly called DAC8, amends Directive 2011/16/EU on administrative cooperation in taxation. Its Article 1(6) inserts Article 8ad, which has Member States require crypto-asset service providers, and operators that are not authorised as providers, to meet the reporting and due diligence rules of Annex VI, with tax authorities exchanging the information automatically. Recital 9 says Union rules should take the OECD framework into account, and Annex VI follows the same structure (Sections II.B and IV.B.3).

Article 2(1) requires Member States to adopt and publish implementing laws by 31 December 2025 and to apply them from 1 January 2026. Annex VI, Section II.D has information reported in the calendar year after the one it relates to, the first for periods from that date, and Article 8ad(6) has authorities exchange it within nine months of the year’s end, so information for 2026 is reported in 2027 and exchanged by 30 September 2027 (computed from the nine-month limit). A directive reaches providers through national law, so a firm’s duty comes from its Member State’s implementing law; those national texts have not been checked state by state.

Both texts build on the identity step: for an individual user the provider obtains a self-certification of tax residence when the relationship begins and checks its reasonableness against what it holds, including documentation collected under customer due diligence (DAC8 Annex VI, Section III.A.1; CARF Section III.A.1, p. 16). Staking and lending count as crypto-asset services (Annex VI, Section IV.B.4), and the framework’s introduction has providers categorise transfers by type where they know it, with staking income, airdrops and loans as examples (paragraph 21, p. 12), so the income in where crypto yield comes from is a category the framework names.

Where tracking stops

On a transparent chain such as Bitcoin, the clustering heuristics still apply where no provider is involved, and the ledger still records every transfer; what is missing is a verified name, and each mechanism needs a ledger link or a provider to supply one.

Self-custody with no provider. A self-hosted address is, in the EU regulation’s definition, a ledger address not linked to a crypto-asset service provider or to a non-EU entity providing similar services (Article 3(20)), and Article 2(4), third subparagraph, takes person-to-person transfers carried out without a provider (Article 3(13)) outside the regulation.

The edge is policed from the provider’s side. For a transfer to or from a self-hosted address the provider must still obtain and hold the originator and beneficiary information, and above EUR 1,000 take adequate measures to assess whether the address is owned or controlled by its own customer (Articles 14(5) and 16(2)). In tax reporting, transfers a provider sends to addresses it does not know to be associated with a provider or financial institution appear as aggregates of value and units (DAC8 Annex VI, Section II.B.3(i); CARF Section II.A(3)(i)), and the framework’s introduction adds that, where this raises compliance concerns, tax administrations could request more detail on the addresses through existing exchange-of-information channels (paragraph 23, p. 12).

Privacy coins. These change the ledger rather than the edge. Monero’s own documentation describes ring signatures, under which an outside observer cannot tell which of a group of possible signers produced a signature; stealth addresses, one-time addresses that stop incoming payments being linked to the recipient’s published address; and RingCT, which hides amounts. A study of Monero, posted in 2017 and revised in 2018, found that about 62% of transaction inputs with one or more mixins (decoy coins) were vulnerable to an analysis that deduces the real input by elimination, and estimated that a heuristic based on input age could guess the real input with 80% accuracy across such transactions. It proposed countermeasures and measured the design it examined, not later changes.

Regulation narrows the edge from the other side. Regulation (EU) 2024/1624, Article 79(1), prohibits crypto-asset service providers from keeping accounts that allow the anonymisation of the account holder or the anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins, defined in Article 3(25) as crypto-assets with built-in features designed to make transfer information anonymous, systematically or optionally. It applies from 10 July 2027 (Article 90), and recital 160 says the prohibition does not reach providers of hardware and software, or of self-hosted wallets, with no access to or control over those wallets.

Mixers. Treasury describes a mixer as receiving a variety of transactions and mixing them together before sending them on, obscuring their origin, destination and counterparties, with a purported purpose of increasing privacy (Blender.io, Tornado Cash). OFAC designated Blender.io, a Bitcoin mixer, on 6 May 2022, which Treasury called the first sanctions on a mixer, and Tornado Cash, an Ethereum mixer, on 8 August 2022, when Treasury said it had been used to launder more than $7 billion since 2019. OFAC removed Tornado Cash from its list on 21 March 2025, and Treasury’s announcement cited a review of the legal and policy issues raised by using financial sanctions against activity in evolving technology and legal environments.

The protection a mixer advertises can be measured. A study of zero-knowledge mixers on Ethereum and Binance Smart Chain found advertised anonymity-set sizes mostly inaccurate and reported shrinking the effective set by 27.34% and 46.02% on average for the most popular mixers on the two chains. That narrows a pool of candidates; it is not an identification.

What “untraceable” usually means. In the 2013 study’s tracing of thefts, thieves who layered and mixed left the authors little opportunity to follow the money with confidence, yet for the Bitfloor theft, where the thief split off large amounts, re-pooled them and repeated the process, the authors followed it by hand and again saw amounts sent to multiple known exchanges (section 5.2). The Monero and mixer studies above point the same way. The reading that follows is that “untraceable” describes cost, not possibility: a tool can make tracing slower, dearer or less certain, but on a public ledger it cannot remove the record, so the claim has to hold against methods and data that do not exist yet. Thefts as DefiLlama records them are tallied by year, class of failure and chain on the hacks data pages.

What it means for a holder’s own exposure

A holder’s exposure comes down to one question: did the value ever pass through a venue that identified its customer? If so, the history is attributable, in a specific sense. That venue holds a name against the addresses it dealt with, so an investigator who can reach its records, or who has tagged its addresses by transacting with it as the 2013 study did, has a starting point, and clustering extends the link outward with the kind of error that study measured. Where the venue is a provider within DAC8 or CARF, a yearly report of the activity there also reaches the tax authority. Value that never touched such a venue has no identity record behind it at any venue, but it sits on the same complete public record. Withdrawing to self-custody ends the venue’s own records of the coins afterwards, though the address it holds still ties them to the public ledger. It does not end what the venue already holds: its customer and transaction records (Directive (EU) 2015/849, Article 40) and the address the coins were sent to, which it must obtain and hold for a transfer to a self-hosted address (Regulation (EU) 2023/1113, Article 14(5)). The wider trade is set out in exchange or self-custody; a key stays control without identity while the ledger that records what it signs stays a record. This describes what each mechanism can see, not a way to avoid a reporting duty.