Is Bitcoin traceable? How tracing works
發布於: 2026年9月16日
本文尚未翻譯成您的語言,您正在閱讀 English 原文。
Is Bitcoin traceable? Yes. Every Bitcoin transaction is written to a public ledger that anyone can read, and a whole analytics industry reads it for a living. What the ledger does not contain is names, so most of this guide is about how a name gets attached anyway: the patterns that tie addresses to one owner and the places where identity enters from outside the chain. We run notrace.exchange, a crypto mixer, and one section near the end describes what ours does.
Is Bitcoin anonymous?
Not in the way the word is usually meant. Bitcoin is pseudonymous: coins move between addresses, and an address is a string of characters, not an identity. The whitepaper put the idea in one line in its section on privacy: "The public can see that someone is sending an amount to someone else, but without information linking the transaction to anyone."
The catch is in how much the public can see. The privacy page on bitcoin.org says that all Bitcoin transactions are public, traceable, and permanently stored, and that anyone can see the balance and every transaction of any address. A pseudonym holds only until one address behind it is tied to a person. The whitepaper names that risk too: if the owner of a key is revealed, linking could reveal other transactions that belonged to the same owner.
Is Bitcoin 100% untraceable?
No. The ledger is public and permanent, so a transaction nobody can connect to you today stays on record for whoever finds the missing link later. bitcoin.org warns that something not traceable now may become trivial to trace in the future. How hard a particular trail is to read depends on how the coins were handled, which is what the patterns below describe.
How Bitcoin is traced
Tracing starts by grouping addresses that probably belong to one owner, and only then asks who that owner is. A handful of patterns do most of the grouping.
Coins spent together. A payment often needs more than one input, and each input is signed by whoever controls it. The whitepaper admits the consequence: multi-input transactions "necessarily reveal that their inputs were owned by the same owner." Analysts call this the common-input or co-spend heuristic. In a February 2024 memorandum opinion, US District Judge Randolph Moss wrote that the most widely accepted means of clustering relies on co-spend.
Change. Bitcoin spends whole outputs, so a payment usually sends part of the value to the recipient and returns the rest to a new address of the sender. Pick out which output is the change, and that new address joins the sender's group. In 2013 Sarah Meiklejohn and colleagues combined these two heuristics in A Fistful of Bitcoins. Starting from 1,070 addresses they had tagged by making 344 transactions with known services, they put names on 2,197 clusters covering more than 1.8 million addresses. That was more than a decade ago, and the tools have improved since.
Reused addresses. An address that receives many payments gathers them into one visible history, which is why bitcoin.org advises using a new address each time you receive a payment.
The network, the amounts and the clock. A node that relays a transaction can log the IP address it arrived from. A 2014 paper by Biryukov, Khovratovich and Pustogarov estimated that an attacker holding no more than 50 connections to each Bitcoin server could reveal the sender's IP address for 11% of all transactions, and for up to 60% if the attacker accepted a slight denial of service on the network, a figure they confirmed on the test network. Both figures describe the Bitcoin network of 2014. On the chain, every amount and the time of each block are public, and TRM Labs, a blockchain analytics firm, lists behavioural and timing analysis among its methods.
None of this names anyone yet. The same firm says in its glossary that clustering alone does not identify who controls a wallet.
Can Bitcoin be traced to a person?
Yes, when the trail touches a place that records who someone is:
- an exchange or broker that checked your identity before you bought or sold;
- a shop that holds your delivery address, or an invoice with your name on it;
- a service that logged your IP address or your email;
- someone you paid who knows who you are;
- files on your own devices or in your online accounts.
Once one address in a cluster has a name, the rest of the cluster inherits it, along with the transactions before and after. The authors of the 2013 study concluded that an agency with subpoena power would be well placed to identify who is paying money to whom.
Can police and the FBI trace Bitcoin?
They can, and Justice Department announcements show them doing it with the ledger and with ordinary investigative work. In February 2022 the FBI formed its Virtual Assets Unit, a team that gives the rest of the bureau blockchain analysis, equipment and training in seizing virtual assets. Four cases from those announcements:
- Colonial Pipeline, 2021. On 7 June 2021 the DOJ announced the seizure of about 63.7 bitcoins from a ransom paid a month earlier. As alleged in the supporting affidavit, agents reviewed the Bitcoin public ledger, tracked multiple transfers and found the address the coins ended up at. The announcement does not say how the FBI came to hold that address's private key.
- The Twitter hack, 2020. When three people were charged on 31 July 2020, IRS Criminal Investigation said its Cyber Crimes Unit had analyzed the blockchain and de-anonymized bitcoin transactions, which identified two of the hackers.
- Bitfinex, 2022. On 8 February 2022 two people were arrested in Manhattan over bitcoin stolen from Bitfinex in 2016. More than 94,000 bitcoins were seized after search warrants on their online accounts turned up files holding the private keys to the wallet that had received the stolen coins. Both later pleaded guilty.
- Silk Road coins, 2021. On 9 November 2021 agents searching a house in Gainesville, Georgia seized about 50,676 bitcoins, some of them on a small computer hidden in a popcorn tin. The coins had been stolen from Silk Road in 2012. The US Attorney in Manhattan credited state-of-the-art cryptocurrency tracing and good old-fashioned police work.
The ledger rarely closes a case on its own: it points to an address, and the name arrives through a warrant, an account, a device or a customer record. A trail does not expire either: the Silk Road coins were seized nine years after they were taken.
Can the IRS track your crypto?
For taxes, the IRS also collects paperwork from the places where crypto meets dollars.
- Your own return. Form 1040 and the other main federal tax returns carry a yes-or-no digital asset question: whether during the year you received a digital asset as a reward or payment, or sold, exchanged or otherwise disposed of one.
- Broker reports. Under final regulations, custodial brokers report gross proceeds on Form 1099-DA for transactions on or after 1 January 2025, and cost basis for certain transactions on or after 1 January 2026.
- Summonses for customer records. On 28 November 2017 a federal court in Northern California ordered Coinbase to produce names, taxpayer IDs, dates of birth, addresses and account activity for customers with at least $20,000 in any one transaction type in any year from 2013 to 2015. By Coinbase's own estimate, that covered 14,355 account holders and 8.9 million transactions. Courts later authorised similar John Doe summonses for Circle and Kraken in 2021 and for SFOX in 2022.
The IRS also writes to holders directly. In July 2019 it announced it was sending letters to more than 10,000 taxpayers with virtual currency transactions who may have reported them incorrectly, saying the names came from various ongoing compliance efforts.
Is crypto traceable beyond Bitcoin?
Mostly yes, and some chains are easier to read than Bitcoin.
Ethereum and its tokens. Ethereum works with accounts rather than separate coins: an account keeps its balance at one address, along with a counter of every transaction it has sent. There is no change output to spread activity across, so an address used for months carries its whole history in one place. ethereum.org describes Ethereum as a public and transparent ledger by design.
Stablecoins. USDT and USDC add an issuer that can act on an address. Tether's terms allow it to freeze Tether tokens when the law requires or when Tether decides it is prudent. On 11 September 2026 Tether said it had worked with more than 340 law enforcement agencies in 67 countries, contributing to the freezing of more than $5 billion in assets. Circle's USDC terms let it block transfers to and from an address on its blocklist.
Switching coins. Converting into another asset does not end a trail by itself. A 2018 study combined 13 months of data from the conversion service ShapeShift with eight blockchains and tracked money as it moved between ledgers.
Which crypto is not traceable?
No coin comes with a guarantee. Some are designed to hide far more than Bitcoin, and researchers have found gaps in how they were used.
Monero says it hides the sender, receiver and amount of every transaction using stealth addresses, ring signatures and RingCT. A paper first published in 2017 found that about 62% of inputs in Monero's early history that used decoys could be traced by elimination, and that the real input could be guessed with 80% accuracy because it was usually the newest one. Monero has changed its protocol since, so those figures describe its past.
Zcash leaves the choice to the user: shielded addresses keep the details private, transparent ones make them public, as on most blockchains. A paper presented at USENIX Security 2018 concluded that Zcash can be used privately, but that simple heuristics based on identifiable patterns of usage can shrink its anonymity set considerably.
Places to buy and sell Monero are getting fewer. Binance stopped trading Monero on 20 February 2024, and Kraken halted Monero trading and deposits for clients in the European Economic Area on 31 October 2024, citing regulatory changes.
Can someone steal your Bitcoin if they have your wallet address?
Not with the address alone. An address is what you give people so they can pay you; spending needs the private key, which must never be revealed. An address does give other things away. Anyone who has it can see its balance and every transaction, and two tricks use it against you:
- Dusting. Someone sends a tiny amount to your address. Trezor describes dust as coins intended to track your transactions and potentially link your wallet to your identity; such attacks rely on what you do next, such as spending the dust together with other coins.
- Address poisoning. An attacker creates an address that looks like one you have dealt with before and makes it show up in your transaction history, for example with a tiny or zero-value transfer, so it sits there waiting to be copied by mistake. A USENIX Security 2025 paper counted 270 million such attempts against 17 million victims on Ethereum and BNB Smart Chain over two years, with at least $83.8 million lost.
Before every payment, check the whole address, not only its first and last characters.
What makes Bitcoin harder to trace
Privacy on Bitcoin mostly comes down to not handing an observer the patterns above, whether that observer is someone you trade with, an employer who pays you or a stranger who has learned one of your addresses.
What helps:
- A new address for every payment you receive. Someone who paid you once cannot look up that address and find your other payments there.
- Not spending coins from different sources together. Wallets with coin control let you choose which coins pay. Spend coins from your salary and coins a friend sent you in one transaction, and anyone reading the chain sees one owner behind both histories.
- CoinJoin. Several people sign one transaction with equal outputs, so the chain no longer shows which input paid which output. How rounds work and where they still run is in What is CoinJoin.
- A mixing service. Coins go to the mixer's address, and the payout leaves in separate transactions from a different sender, so no transaction on the chain connects the two. Amounts and times stay public on both sides, so a payout of the same size that leaves minutes after the deposit is easy to match; splitting the payout and delaying it is what makes that match harder. The checks worth running on any mixer are in a separate guide.
What does not help on its own:
- Tor. It hides your IP address from the nodes you connect to. bitcoin.org suggests it for exactly that, and Bitcoin Core's documentation describes running a node behind Tor to anonymize outgoing connections. Bitcoin Core 31.0, released in April 2026, added a private broadcast option that sends transactions submitted through its sendrawtransaction command only over Tor or I2P. None of it changes what a transaction says: inputs, outputs and amounts stay public. The Bitcoin Wiki gives the example of a wallet set up to run over Tor that still let a third-party server link two purchases and pick out the change address.
- Moving coins between your own wallets. Each move is one more public transaction, and the heuristics above link it straight back.
Where a mixer fits: notrace.exchange
This is what an order on notrace.exchange looks like on 16 September 2026:
- The link stays off the public chain. Every order is settled on a private settlement layer, so the link between your deposit and your payout is not written to the public blockchain.
- The payout is split in two. It always leaves as two transfers to two different addresses you name, each after its own delay. You choose each delay from 0 to 6 hours in one-hour steps; it counts from the moment your deposit settles, and a small random spread is added so nothing leaves at a round time.
- Coins. BTC, ETH, SOL and TRX, plus USDT and USDC on several networks. The payout can be in the coin you sent or in another one.
- A promise you can check. Before you pay, the order page offers a letter signed with our PGP key, stating what you send, the least you receive, both addresses and both delays.
- No account. There is no registration and no document check: you create an order and come back to it by its link, so keep that link.
While a delay runs, the funds for that transfer are held by us; section 8 of the terms says so.
Where to start
Four coins have a dedicated page that opens the form in that coin with its live minimum: the bitcoin mixer, Ethereum, Solana and USDT on Ethereum; every other coin and network in the list above is on the main form. The step-by-step guide walks through a single order, from the amount to both transfers arriving. Our fee on 16 September 2026 was 0.5%, and the current one is always in the FAQ.