KU Leuven Study: 36 Bitcoin (BTC) Wallets Leak User Data Before Any Transaction
A KU Leuven study found 36 Bitcoin (BTC) browser wallets leak user addresses before any transaction, while on-chain clustering and KYC complete the profile.
AI SummaryAI
- KU Leuven researchers tested 85 browser-extension wallets totaling about 35 million Chrome installs
- 36 wallets covering roughly 82% of installs could be fingerprinted before any transaction
- 17 wallets spanning about 23 million installs exposed links between a single user's addresses
- Chainalysis had grouped over 1 billion addresses into more than 134,000 identified entities by mid-2026
KU Leuven Study Flags 36 Wallets
A Bitcoin (BTC) payment can reveal far more than the figure on an invoice, and the exposure begins before a transaction is ever signed. A business that settles a supplier from a reused wallet address leaves the counterparty, the amount and the timing visible to anyone with a block explorer, and new research shows the leak starts even earlier. In July 2026, researchers from KU Leuven's DistriNet group examined 85 of the most widely used browser-extension wallets — collectively around 35 million Chrome Web Store installs — and concluded that the wallets themselves broadcast enough data to fingerprint and follow their users. No exploit is involved: when an extension pings an outside server to display a balance, that request carries the wallet address in the clear, behaving exactly as the software was designed. Across the full sample, the fingerprinting weakness alone reaches 36 wallets, which together account for roughly 82% of the installs studied. Within that subgroup, 17 wallets covering about 23 million installs could also expose links between separate addresses belonging to the same user, 22 of the 36 kept leaking an address even after the user revoked access and restarted the browser, and 23 could pass an address to a website through third-party content without a single click. Most vendors did not treat the findings as a serious bug: Coinbase Wallet, Coin98 and Hana made changes, while MetaMask, Rabby and OKX did not, and of 30 decentralized apps tested, only 11 properly revoked wallet access on logout. For treasuries weighing a Strategic Bitcoin Reserve or routine supplier payments, that pre-transaction metadata is a standing disclosure risk. Background on the asset is in our What is Bitcoin (BTC) guide, and our Bitcoin tag hub tracks related coverage.
Clustering, KYC and the Helix Ledger
Once an address surfaces, the public chain supplies the rest of the profile. Blockchain-analysis firms look for patterns — wallets that repeatedly transact with one another or behave alike — and cluster them under a single owner, so one confirmed address can implicate many others. The scale is industrial: by mid-2026, Chainalysis said it had grouped more than 1 billion blockchain addresses into over 134,000 identified entities. Moving funds across bridges or swapping on a decentralized exchange does not sever the trail, because every swap is still written publicly on-chain. Investigators have demonstrated the endgame repeatedly: after the 2021 Colonial Pipeline ransomware attack, US authorities followed Bitcoin through several wallets and recovered about $2.3 million of the $4.4 million ransom. Mixing fared no better. Larry Dean Harmon ran Helix, a tumbler popular on darknet markets, from 2014 to 2017, and roughly 354,468 BTC — about $311 million at the time — passed through it. He charged a 2.5% commission per swap, and that fee went on-chain like every other coin, permanently recording the operator of a service built to erase trails. The final step is identity: when traced funds touch a regulated exchange, KYC records tie the wallet to a name, and earlier clustering extends that name to the whole address group. Businesses also publish addresses on donation pages and profiles, exposing years of timestamped history. The analysis is not infallible either — patterns produce false positives, one documented P2P buyer had an account frozen over coins that had passed through a mixer before he owned them, and in early 2025 Chainalysis cut its estimate of crypto stolen by North Korea from $1 billion to $660.5 million. Defense teams in the Bitcoin Fog and Tornado Cash cases have challenged conclusions from proprietary tools outsiders cannot inspect, and Chainalysis, a major US government contractor, has received more than $93.2 million in federal awards. The same clustering logic that flags illicit flows also maps every large holder, from a crypto whale to an ordinary business paying in BTC, on the immutable proof-of-work ledger.
Privacy Is Now a Treasury Risk
COINOTAG's reading is that both findings form one arc: Bitcoin's transparency is a feature at the protocol level and a liability at the business level. The KU Leuven study — the primary document behind the wallet findings — states plainly that 36 of 85 tested extensions leak identifying data before any signature, after which on-chain clustering and KYC complete the profile. Forensic disputes such as the Celsius estate's BitMEX lawsuit show how far wallet tracing now reaches into commercial conflicts. Firms handling BTC should treat address hygiene as operational security, not an optional extra.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


