TL;DR - Crypto wallets are pseudonymous, not anonymous, so law enforcement can often link an address to a person through exchange records, address clustering, and off-chain data tied to public transactions.
A wallet address looks like a wall of random characters with no name attached, which is why people assume it is private. The address itself carries no identity. The transactions it makes, however, are permanent, public, and easy to follow - and that trail is what investigators actually work with. Linking an address to a person is rarely about cracking cryptography. It is about connecting on-chain activity to the moments where it touched the real world.
Are crypto wallets actually anonymous?
No. The correct word is pseudonymous. Your address is a pseudonym, like a pen name, that stands in for you on a public ledger. Anyone can read every transaction that pseudonym has ever made, in full, forever. There is no setting to make a Bitcoin or Ethereum address private after the fact.
True anonymity would mean the activity could never be tied back to you. Pseudonymity means it can, the moment one transaction connects to your name. Most people make that connection themselves the first time they buy crypto on an exchange, withdraw to a personal wallet, or send funds to a service that knows who they are. From that point, the public history of the address is a thread an investigator can pull.
How does law enforcement link a wallet to a person?
Investigators rarely break encryption. They connect the open ledger to identity data they can subpoena. A few vectors do most of the work.
The strongest is the regulated exchange. Almost everyone eventually moves funds to or from a platform that collected their name, ID, and bank details at sign-up. When an address transacts with that exchange, law enforcement can request the account records behind it with a warrant or subpoena. That single link can unmask an entire chain of prior transactions.
The second is address clustering. Analytics firms such as Chainalysis, TRM Labs, and Elliptic group addresses that behave as if one entity controls them - shared inputs, change patterns, repeated timing. One identified address in a cluster can tag the whole group. The third is off-chain leakage: a wallet address posted on a forum or social profile, an IP address logged by a node or service, or metadata from a KYC submission. None of these read the blockchain at all; they sit beside it and wait to be matched.
The address carries no name on its own; investigators resolve it through the points where it touched the regulated world.
Can a no-KYC self-custody wallet still be traced?
Often, yes. Holding funds in a self-custody wallet with no identity verification removes the direct name tag, but it does not erase the transaction graph. The wallet still has to receive funds from somewhere and eventually send them somewhere, and those endpoints are where identity tends to leak.
If the wallet was funded by a withdrawal from a KYC exchange, the link is already there. If it later sends to one, the link forms then. Even peer-to-peer transfers leave a counterparty who may themselves be identified later. A wallet can stay unlinked for a long time, but it usually only takes one transaction with a regulated, identified party to anchor the whole history. This is the same reason a deposit can be flagged long after the funds first moved - the trail does not expire.
What actually breaks the link between a wallet and its owner?
Fewer things than people hope, and most of them raise their own red flags. Centralised mixers can sever the on-chain link by pooling and reshuffling funds, but any contact with one is itself a loud risk signal that screening tools weight heavily. Privacy chains with shielded transactions are the genuine blind spot for tracing, though converting to or from them is often treated as high-risk by default. Custodial swap services that take one asset in and pay a different one out can break the direct trail, but they keep internal records and answer law-enforcement requests.
The moves that genuinely obscure a link are the same ones that make a wallet look suspicious to a screening tool.
The ordinary moves people assume help - making a fresh address, bridging to another chain, swapping tokens - do not. A new address inherits the risk of whatever funded it, and cross-chain hops leave matching records on both sides. There is more on that in our guide to tracing crypto across blockchains. The deeper point is that breaking a trace and looking clean are different things: the methods that actually obscure a link are themselves the behaviours that make a wallet look suspicious.
How can you see your wallet the way an investigator would?
You can retrace much of this yourself. Pull the address up on a block explorer such as Etherscan, walk back through its funding transactions, and note any that touch a known exchange, mixer, or flagged contract. Doing it by hand is slow, easy to misread, and only covers one chain at a time. Screen the address with Plastron to see sanctions, mixer, and stolen-funds exposure across Ethereum and six other chains at once, with no wallet connection needed.
The reason to check is the same reason this matters at all: the public history that lets an investigator trace a wallet is the same history a compliance desk reads before it accepts your deposit. If you understand your own wallet screening picture first, you find out what others would see - the exposure two or three hops back, the contact with a flagged address you never transacted with directly - before it turns into a frozen account or a source-of-funds request. The full mechanics of that deposit check are covered in our note on how exchanges trace a deposit's origin.
Often, yes. They follow the public transaction trail to a point where the address touched a regulated exchange or other identified service, then request the account records behind it with a subpoena or warrant. The blockchain itself does not name you, but the points where it meets the regulated world usually do.
Is a wallet with no KYC anonymous?
No, it is pseudonymous. Skipping identity verification removes the direct name tag, but the wallet's full transaction history stays public. One transfer to or from an identified party can anchor that history to a person.
Does using a new wallet address hide my old activity?
Not reliably. A new address inherits the risk of whatever funds it, and clustering tools group addresses that behave as one entity. The old activity stays linked through the funding path.
How can I check what my wallet reveals?
Look the address up on a block explorer to read its history, or run it through a multi-chain screening tool that traces exposure across networks at once. That shows the same risk picture an exchange or investigator would assemble.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.