Beyond decentralization, blockchain technology has long prioritized privacy. The blockchain is pseudonymous: While addresses and transactions are public, they are not tied to a real world identity unless they interface with an intermediary like an exchange.
Privacy-enhancing technologies (PETs) are technologies that improve pseudonymity or even create anonymity by virtue of concealing the parties involved, transaction amounts, or the flow of funds.
This article explores the definition and role of PETs in blockchain, their challenges for compliance and investigations, and how businesses can still identify bad actors despite these privacy protections.
The blockchain is a public ledger. Using a blockchain explorer, anyone can view the historical record of transactions, the parties involved, and other details, such as how much was sent and received. The blockchain is also pseudonymous: Viewers can see that a certain address sent 1 BTC to another address on February 19, but they do not know the exact identities of the people involved.
Privacy-enhancing technologies (PETs) create greater pseudonymity or even anonymity. They can obscure who was involved in a transaction, how much was sent, where funds are going, or even a combination of these measures.
While PETs serve legitimate purposes, the following are some of the most common PETs exploited by bad actors:
Coin mixers, also known as tumblers, are designed to break the traceability of blockchain transactions. One of the most well-known examples is Tornado Cash, which allows users to deposit cryptocurrency into a shared liquidity pool. The funds are then mixed with those from other users before withdrawal, severing the transactional link between sender and recipient. This process makes it difficult to track fund origins, providing privacy but also enabling illicit activities such as money laundering.
Because of their strong association with financial crime, coin mixers have been banned or sanctioned in multiple jurisdictions. In August 2022, the U.S. Office of Foreign Assets Control (OFAC) sanctioned Tornado Cash, citing its use in laundering billions of dollars, including funds linked to cybercriminal groups.
While most cryptocurrencies are pseudonymous—meaning wallet addresses can be viewed on public blockchains without directly revealing owner identities—privacy coins take anonymity further. They obscure transaction details, making it difficult for third parties to analyze fund flows. Privacy coins achieve this through various PETs, including:
While not a blockchain-based PET, the dark web is often used in conjunction with privacy-focused technologies to facilitate illicit activities. Unlike the surface web, which is indexed by search engines, the dark web requires specialized tools like the Tor browser for access. It serves as a hub for underground marketplaces where illicit goods and services—ranging from stolen data to weapons—are bought and sold using cryptocurrency.
Many transactions on the dark web involve privacy coins like Monero due to their enhanced anonymity features. The combination of dark web platforms, privacy coins, and PETs makes it challenging for law enforcement and compliance teams to track illegal financial flows.
To address the challenges PETs present, businesses and investigators can adopt four key strategies:
Although the funds stolen from DMM eventually ended up in a coin mixer, the laundering trail (represented in the image above) reveals a significant amount about the hacker, implicating the Lazarus Group.
By combining these four approaches—risk categorization, behavioral pattern detection, on-chain tracking, and OSINT analysis—businesses and investigators can mitigate the risks posed by PETs while maintaining compliance and security in the blockchain ecosystem.
PETs pose significant challenges for compliance teams and investigators, but they are not insurmountable. Businesses need advanced blockchain analytics solutions to detect, assess, and mitigate risks associated with PETs while ensuring compliance with evolving regulations.
Merkle Science’s Tracker empowers investigators to trace illicit transactions, even when PETs are involved, helping law enforcement and businesses uncover hidden financial flows. Meanwhile, Compass provides a robust compliance framework, identifying high-risk interactions with PETs and ensuring businesses remain ahead of regulatory requirements. Contact us for a free demo of either Tracker or Compass today.