Analytics

How Crypto Mixers Work—and Why They Are Still Traced

Pool-of-addresses diagram and risk labels on a monitor, representing how crypto mixers work and why AML traces them
In brief

How crypto mixers work: a service or contract takes an asset from one address and later pays a comparable amount to another, breaking the direct A-to-B arrow on the ledger. That does not make the transfer invisible: deposits, withdrawals, amounts, and timestamps stay public, and AML systems treat mixer exposure as high risk. Depositing those coins to a centralized exchange often produces a pause, not a "clean" balance. Exposure analysis is blockchain analytics. This is not a guide to mixing.

What a mixer does—and what it does not

A crypto mixer (tumbler) is a service or smart contract that accepts cryptocurrency and later sends a comparable amount to another address so the explorer does not show a direct "sender to recipient" arrow. A centralized service holds a pool on its own addresses. A contract mixer takes a deposit into a pool and later allows a withdrawal from another address with a cryptographic proof. Bitcoin CoinJoin-style schemes combine several participants' inputs in one transaction.

What a mixer does not do: erase the ledger, hide amounts and timestamps, or confer legal anonymity. The public chain remains a log. A centralized operator, to pay "your" coins to the right person, must match deposits to withdrawals—"no logs" is marketing, not a law of physics. A contract pool breaks the direct link more strongly, but deposits into a known contract and withdrawals from it remain visible events.

This article is literacy for a victim and for someone who already has an exchange pause. It is not a guide to using a mixer, picking a service, or "cleaning" coins. Trying to "run it through again to drop the flag" usually makes the AML picture worse. What the "dirty crypto" label means in practice is in what is dirty crypto.

Why AML flags hops through a mixer

FATF treats mixers and tumblers as products that reduce transparency of flows and raise money-laundering risk. Exchanges and KYT vendors therefore put known-mixer exposure in high-risk typologies: a direct pool exit onto a deposit address, a short hop chain right after an exit, a link to a sanctioned contract. Policies differ on depth (direct touch versus several hops), but the logic is the same: obfuscation is a red flag even if you "only wanted privacy."

Sanctions are a separate layer. OFAC has listed both centralized mixers and contract-pool addresses. For a platform that screens the SDN list, a deposit from such a contract is not a privacy debate; it is possible sanctions exposure. An indirect path through several addresses is weaker than a direct exit, but it can still trigger manual review. How to read address risk before a deposit is in how to check a crypto wallet for AML risk.

Mixer exposureWhat an exchange often does
Direct deposit from a pool exitWithdrawal pause, source-of-funds / origin request
Two to four hops after an exitDepends on the share of the amount and vendor policy
Another mix "to clean" the coinsAn extra obfuscation signal
Indirect touch via a shared hot walletContext review, not an automatic verdict

Why the trail is often still readable

The direct A-to-B arrow is gone; the graph is not. Analysts look at the mixer's address set, the population of deposits and withdrawals, correlation on time and amount (minus fees), and repeated patterns. For CoinJoin, they limit the common-input heuristic and watch which outputs later spend together. For contract pools, they compare deposits and withdrawals in a close window, especially for unusual amounts. That is probabilistic: not every withdrawal is tied to your deposit with courtroom confidence.

Centralized services also leave a trail off-chain: seized servers and operator records have been public facts in criminal cases more than once. "The service shut down" does not delete your TxIDs from Bitcoin or Ethereum. So an investigator saying "it went into a mixer, end of story" describes added difficulty, not physical impossibility. A narrow DIY of one to three hops into a pool is in how to trace a scammer crypto wallet; a full after-pool analysis is no longer a single explorer page.

An honest limit: the larger the pool and the more carefully withdrawals are spaced, the weaker the correlation. A mixer is not a "get-out-of-jail" card for an attacker and not a "recovery guarantee" for a victim. If stolen funds entered a pool, a realistic goal is to record the entry, assess whether comparable amounts later hit exchanges, and not expect a miracle from one screenshot. The map after the pool is blockchain analytics.

First steps if mixed coins reached an exchange

  1. Record the TxID into the known pool or service and, if visible, the exits—network, amount, UTC time, addresses.
  2. Do not deposit the "tail" from the same cluster to another platform "as a test": you multiply the exposure.
  3. If the pause is already on your account—one ticket, an origin package matching the exchange request, no VPN geo-shift and no second account.
  4. Do not "clean" the remainder through another mixer: for AML that looks like obfuscation.
  5. Do not hand a seed phrase or keys to a "flag removal" service.
  6. If you are a theft victim and the trail entered a pool—save the entry hash; next is a map of exits, not a promise that coins will be "pulled out of the mixer."

For a theft victim, a mixer entry narrows the custodial freeze window but does not cancel trail preservation for a report. For a holder who received mixed coins via P2P, screening the address beforehand is more honest than explaining it to the exchange after the fact. Neither scenario is fixed by mixing instructions—there are none here, and there will not be.

When you need pool attribution, an assessment of whether exits reached an exchange, or a package for manual review, use blockchain analytics. Case support after that assessment is on success-fee. Pause and tracing outcomes depend on the platform, exposure depth, and facts; there is no promise that a flag will drop or funds will return.

Limitations

Risks and limitations

  • Mixer exposure often leads to an AML pause on an exchange; lifting the restriction is not guaranteed.
  • Tracing through a pool is probabilistic: not every exit is provably linked to your deposit.
  • Mixing again "to clean" usually strengthens the risk signal instead of removing it.
  • Prepaid "we will remove the mixer flag" services that ask for a seed phrase are a common scam.
  • This article explains why mixers are flagged and traced; it is not a how-to-mix guide.
Sources

Sources used

Next

Related resources

ServiceBlockchain analyticsBack to the blog
Next step

Need an assessment of your situation?

Briefly describe what happened — without seed phrases or private keys. We will outline possible routes and assess their feasibility.

Request a free assessment
Free initial assessment

Describe what happened

Answer a few questions so we can assess the situation and suggest the next steps.

Do not send seed phrases, private keys, passwords, or 2FA codes. They are not needed for an initial assessment.

Do not send seed phrases, private keys, passwords, or 2FA codes.