Skip to content
Seqlense DOC Seqlense Web3 Monitoring Seqlense Notes Audit & Advisory Investigation Crypto OSINT Investigation Training & Advisory Seqlense Immo Pricing Academy Blog Partners Supported Chains Contact My Seqlense Get Started
Back to blog

Mixers, bridges and privacy coins: scoring counterparty risk

A pragmatic view of the hardest-to-trace flows and how to risk-rate them.

Not all crypto flows carry the same risk. A payment that moves straight from one regulated exchange to another leaves a clean, attributable trail. Funds that pass through a mixer, hop across a cross-chain bridge, or convert into a privacy coin do the opposite: they break the link between sender and receiver by design. For compliance and investigation teams, these are the flows that turn a routine screening into a genuine judgement call. This piece sets out a pragmatic way to think about the three hardest-to-trace categories and how to risk-rate exposure to them.


Why these three are different

Most blockchain analytics rests on one assumption: transactions are public, so you can follow the money. Mixers, bridges and privacy coins each attack that assumption in a distinct way.

  • Mixers (tumblers) pool funds from many users and pay out from the pool, so the on-chain link between the deposit and the withdrawal is deliberately severed. Some are custodial services; others are non-custodial smart contracts.
  • Bridges move value between chains. A user locks an asset on chain A and receives a wrapped equivalent on chain B. Tracing has to jump networks, and attackers exploit that seam to launder proceeds, often at speed after a hack.
  • Privacy coins such as Monero bake confidentiality into the protocol itself. Amounts, addresses or both are obscured for every transaction, so there is often no public trail to follow at all.

The practical consequence is the same in each case: you lose deterministic tracing and have to reason about probability and context instead.


Exposure is not the same as guilt

The single most important framing for a counterparty risk model is that touching one of these tools is a risk signal, not a verdict. Mixers have legitimate uses: donors protecting activists, individuals shielding salary or net worth from public view, businesses hiding commercial flows from competitors. Bridges are core infrastructure for ordinary multi-chain activity. Treating every interaction as illicit generates noise, buries real cases, and is hard to defend to a regulator who expects a risk-based approach.

The legal ground here has also shifted, which matters for how you write policy. In 2025 the US Treasury removed Tornado Cash from the sanctions list after the Fifth Circuit held that immutable smart contracts are not "property" that OFAC can designate (U.S. Treasury). That does not make mixer exposure clean, and other mixers and many designated wallet addresses remain sanctioned, but it is a reminder that a static blocklist is not a risk model. Sanctions status can change, and your controls need to be updated when it does.


A scoring model that holds up

Rather than a single blocklist flag, score the counterparty on several axes and combine them. A workable set:

Factor Lower risk Higher risk
Directness Several hops and time between the tool and your customer Direct deposit or withdrawal to your customer
Volume share Tainted flow is a tiny fraction of activity Majority of funds routed through obfuscation
Tool type Regulated bridge, transparent service Sanctioned mixer, privacy coin, known laundering route
Context Plausible privacy rationale, consistent profile Funds trace to a hack, scam or darknet market
Timing Historic, one-off Repeated, or immediately after a known incident

The point of a matrix like this is to separate the customer who once received bridged funds from a customer whose wallet is a pass-through for freshly stolen assets. Both "touched a bridge", but only one deserves escalation.

A few operating principles make it usable:

  1. Weight direct exposure over indirect. One hop from a sanctioned mixer is not the same as five hops and a year of unrelated activity.
  2. Set thresholds, not absolutes. Decide in advance what share of tainted inflow triggers enhanced due diligence versus a filing.
  3. Document the rationale. A risk score you cannot explain is a score you cannot defend in an audit.
  4. Keep sanctions and typologies current. The Tornado Cash example shows why lists move; so do bridge exploit patterns.

Where the regulation is heading

The trend in the EU is toward less anonymity, not more. Under the recast Transfer of Funds Regulation (Regulation (EU) 2023/1113), the crypto "travel rule" applies from 30 December 2024, requiring crypto-asset service providers to collect and transmit originator and beneficiary information with transfers, with no de minimis threshold for crypto (European Banking Authority). Transfers to and from self-hosted wallets and interactions with obfuscation tools attract extra scrutiny. Firms that already score counterparty exposure will find the travel rule easier to live with than firms still relying on a simple allow/deny list.


Bringing it into workflow

Scoring is only useful if it fires before funds settle and lands in front of the right analyst. That means continuous address monitoring rather than point-in-time checks, alerts tied to your own thresholds, and a clear path from a raised score to a documented decision. Seqlense Monitoring is built for exactly this: on-chain surveillance of watched addresses, risk scoring and alerts, with blockchain Investigation and OSINT services when a flagged flow needs to be traced to source. The regulatory side stays close too, since the same team tracking mixer and bridge typologies can watch EBA and ESMA guidance as it lands.

Mixers, bridges and privacy coins will keep evolving faster than any blocklist. A defensible programme does not try to ban the categories outright. It rates them, in context, and can show its work.


Sources

Related articles

Building a vendor register your DPO can defend

Purposes, categories and the discipline that makes a register hold up.

Corporate structures and UBOs: following ownership across borders

Untangling who really controls an entity through layered ownership.