Tracing Crypto Through Tornado Cash: The 2026 Investigator's Playbook

Tornado Cash has one job, and it does it well. It cuts the on-chain link between the wallet that deposits and the wallet that withdraws. Run a normal trace and it dies at the deposit, picks back up at the withdrawal, and hands you nothing that ties the two together.
You do not need a hypothetical to see the stakes. In February 2025, North Korea's Lazarus Group stole about $1.5 billion from Bybit, the largest crypto heist on record, and pushed the funds through a chain of mixers that included Tornado Cash. Months later, roughly more than a quarter of it was still untraceable. No tool was going to change that. The mixer did its job.
Most investigators know the feeling. You are two hops from a real name, the funds hit Tornado Cash, and the screen goes quiet. That silence is the entire reason the target used it. The question worth asking in 2026 is whether the case really has to stop there, and that comes down to what data you are willing to bring in from beyond the blockchain.
What does Tornado Cash actually do?
Tornado Cash is a zero-knowledge smart contract mixer. A user deposits a fixed denomination of cryptocurrency. After a delay of their choosing, the same denomination is withdrawn to a different wallet. A cryptographic proof inside the contract verifies the withdrawer's entitlement to the funds without revealing which deposit they came from.
Done correctly, every withdrawal is equally likely to correspond to every deposit of the same denomination inside the contract's anonymity set at that moment. The mathematical guarantee is real. It is the assumption every Tornado Cash investigation has to start from.
In practice, the anonymity set has gaps. Most of them come from how users behave, not from how the protocol is built.
Is Tornado Cash legal in 2026?
The legal picture has moved more than once, and getting it current matters, especially for compliance teams assessing mixer exposure. Tornado Cash was sanctioned by the US Treasury in August 2022. In November 2024 the Fifth Circuit ruled in Van Loon that the protocol's immutable smart contracts are not ‘property’ that can be sanctioned under existing statute, and in March 2025 Treasury removed Tornado Cash from the sanctions list. Interacting with the protocol is no longer a US sanctions violation in itself.
That is not the same as safe. The people who built and ran the front end face criminal liability. In August 2025 a New York jury convicted co-founder Roman Storm of conspiracy to operate an unlicensed money transmitting business, while deadlocking on the more serious money laundering and sanctions charges. A retrial on the deadlocked counts is expected in late 2026. In the Netherlands, developer Alexey Pertsev was convicted of money laundering in 2024 and is appealing.
For an investigator, the takeaway is simple. Mixer exposure is still a high-risk signal and still central to the largest laundering cases, even though the protocol itself is no longer sanctioned. Keep the legal posture current, because it has changed before and can change again.
Where do on-chain tracing techniques work against Tornado Cash?
Several behavioural patterns weaken the cryptographic guarantee, and they are where an on-chain investigation starts.
Timing analysis is the most common opening. Deposits and withdrawals that fall within narrow windows, especially when the anonymity set is small, become probabilistically correlatable. A careful user waits. A less careful one does not.
Denomination patterns matter. Tornado Cash operated in fixed pool sizes. A user who deposits 100 ETH and then withdraws ten separate 10 ETH transactions in a short window creates a denomination footprint that narrows the candidate set.
Funding wallet analysis adds another layer. The wallet that pays gas for a withdrawal is often connected to other wallets the user controls, and those may carry attribution-rich history of their own.
Anonymity set composition is the underlying variable. A 100 ETH pool with thirty active users at a given moment is far more linkable than a 0.1 ETH pool with thousands.
Every one of these gets you a probability, not a fact. And a defence lawyer takes a probability apart in an afternoon.
What is the structural limit of on-chain Tornado Cash analysis?

A user who deposits patiently, waits weeks, withdraws into a wallet with no prior on-chain activity, and routes the withdrawal through further privacy tooling has defeated every on-chain technique above. The deposit and withdrawal addresses share no transaction link, no timing correlation strong enough to survive a courtroom challenge, and no funding wallet that ties them together.
This is the protocol working as intended. It is also why a large share of the Bybit funds went dark, and why mixer investigations over the past three years have depended either on operational mistakes by the target or on data that does not come from the blockchain.
Against a disciplined user, the ceiling is structural. No amount of better on-chain analytics lifts it, because the limit is the protocol, not the tooling.
What kind of investigation continues past that plateau?

When the on-chain trail ends, a different kind of attribution takes over, and it is the layer Addressable Investigations built Spectra around. It does not depend on on-chain links between wallets, which is exactly what lets it work here. It connects a wallet to the real-world entity that controls it, and it produces leads and digital evidence: investigative starting points when the chain goes quiet, and time-stamped records that hold up in legal proceedings.
The property that matters for a Tornado Cash case is that it persists even as actors change wallets, and it remains effective even when users attempt to mask their activity through commercial VPN infrastructure.
What we do not do is publish the specific signals behind it, and that is deliberate. The people running these operations read the same material investigators do, and a published method is a method they can work around. What we will describe is what it delivers, not how.
For Tornado Cash specifically, this changes the shape of the case. The investigator is no longer trying to prove an on-chain link between the deposit and the withdrawal wallet. The investigator is establishing whether the same actor is behind both, then resolving that to region-level attribution and the entity behind the operation. Investigators running both layers are closing mixer cases like Tornado Cash that would have stalled on transaction tracing alone.
Freezing funds is an on-chain outcome. Reaching the point where a freeze is even possible, when the deposit and withdrawal wallets share no on-chain link, is not. That is the part the off-chain layer supplies.
How does this fit into an existing investigation workflow?
Off-chain attribution does not replace on-chain forensics. It picks up where the on-chain trail ends, which is exactly where most mixer investigations stall.
The workflow stays sequential. Run transaction analysis first to map the fund flow and identify any connections to known entities. When the trail enters Mixers , the off-chain attribution layer becomes the second pass. If the relevant wallets share an attribution signal, the case continues. If they do not, the investigator at least has a definitive answer rather than an unresolved one. For criminal investigation teams and token recovery firms running cases inside traditional blockchain analytics tools, this is additive. The output is the same kind of investigator-grade intelligence the rest of the case is built on, drawn from data that on-chain tools do not see.
Tornado Cash makes attribution impossible at the protocol layer, and it succeeds at that. But the person moving the funds still exists somewhere off the chain, and that is where the case picks back up.
See how Addressable Investigations layers on top of your forensics stack: investigations.addressable.io.



