← Bitcoin Encyclopedia

Address Clustering

🌿 Intermediate

💡 The Plain-English Definition

Address clustering is a technique blockchain analysts use to link multiple Bitcoin addresses to the same owner — building a map of which addresses likely belong to the same wallet, even when no identity information is directly available.

When a transaction spends from two of your addresses at once, analysts can safely assume both belong to the same person — signing requires both private keys. Chain-analysis firms use this to build clusters of addresses that likely share one owner. The risk: once a single address in that cluster is tied to your identity (a KYC exchange deposit, a public post), the whole cluster can become identifiable.Diagram by Bit By Bitcoin.

🤔 But Why Though?

Bitcoin transactions are fully public. Every input, every output, every amount, every address sits on the blockchain — Bitcoin’s permanent public record — forever, visible to anyone. What isn’t public is the identity behind each address. Bitcoin is pseudonymous: addresses don’t have names attached.

Chain-analysis firms worked out that while a single address is anonymous, the patterns you create by using several addresses together can reveal that they belong to the same person. The most powerful of these patterns is the common-input-ownership heuristic: if a transaction has several inputs (the sources of the bitcoin being spent), those inputs were almost certainly controlled by one person — because building a transaction means signing each input with its own private key. So if inputs from Address A and Address B show up together in one transaction, they probably share an owner.

From that one assumption, analysts build clusters — groups of addresses that probably belong to the same wallet. And once even a single address in a cluster is tied to a real identity — through a deposit at a KYC exchange (which verified your identity), a forum post, a public donation address — the whole cluster can potentially be identified.

Major chain-analysis companies — Chainalysis, Elliptic, CipherTrace — have built sophisticated clustering tools that law enforcement, exchanges, and financial institutions use routinely.

🌍 The Real-World Analogy

Imagine every phone call you make is logged publicly — the number you called, when, and for how long. Nobody knows it’s you making the calls, but the pattern is visible. Now an analyst notices that calls from number A and number B always come from the same cell tower, often within minutes of each other, and sometimes call the same numbers. The analyst concludes A and B probably belong to the same person. The moment one number is linked to an identity — say, it called a business that requires ID — the other becomes identifiable too. Bitcoin address clustering works the same way: behavioural patterns, not names.

⚡ So What?

If privacy matters to you, understanding clustering is essential. Ordinary wallet behaviour — reusing an address, combining inputs from different sources, depositing to a KYC exchange — feeds straight into clustering algorithms. What breaks clustering: generating a fresh address for every transaction (which good wallets do automatically), using CoinJoin (a privacy technique that merges several users’ transactions) to break the common-input assumption, and being deliberate about which UTXOs (individual chunks of bitcoin) you combine.

📩 The Daily Bit · free

Get one plain-English Bitcoin email each morning.

The Daily Bit — free, two minutes, unsubscribe anytime.

The Bitcoin EncyclopediaPrefer a book? The Bitcoin Encyclopedia