Bitcoin ETFs Tipped to Triple Gold Holdings: BTC Price Impact
Bloomberg's Eric Balchunas predicts Bitcoin ETFs could hold three times gold's ETF assets, implying a potential BTC price range of $490k-$730k.
Bitcoin payments leave a permanent trail, and wallet extensions can leak data even before a transaction is signed.
From a business standpoint, Bitcoin transactions carry a largely overlooked risk. When a company pays a supplier using the same wallet address, the recipient can see more than just that single payment.
At this very moment, a competitor could use a block explorer to view every Bitcoin payment you've made — amounts, timestamps, and counterparties. This isn't just a concern for those trying to hide activity. It represents a continuous business risk: anyone with time can trace treasury moves, partnerships, and deal flow.
Many assume the exposure begins on-chain when a transaction is signed. That is incorrect. In July 2026, KU Leuven's DistriNet group examined 85 widely used browser-extension wallets and discovered that these wallets can leak data to fingerprint and track users even before any transaction occurs.
When a wallet pings an external server to show a balance, the request sends the wallet address in plain text. This is not a bug; the extensions function as designed. Among the 85 tested, 36 wallets — representing about 82% of the installs examined — had this fingerprinting vulnerability, and all subsequent statistics refer to that group.
This applies to legitimate users as well. Andy Greenberg, a longtime reporter on crypto crime, spent a decade watching criminals believe the blockchain hid their activities, only to see investigators uncover them. He eventually realized how untraceable Bitcoin was not. The ledger meant to provide protection became the evidence that led to convictions.
False confidence typically affects those who think they are private but aren't really hiding anything: a donor whose donations become public, a journalist whose sources can be deduced from their payments, or the business counterparty mentioned earlier.
Much of this exposure is passive, not active. This article examines the full scope of the exposure and identifies the single link users can control.
Crypto wallets can disclose data before any transaction occurs. To display a balance, browser wallets commonly ping external servers, submitting the wallet address. The KU Leuven study covered 85 extensions with about 35 million Chrome Web Store installations. Of those, 36 wallets — approximately 82% of the installs — could be identified and tracked via this method.
Seventeen wallets, with around 23 million installations, could also reveal connections between multiple addresses used by the same person. For 22 of the 36 vulnerable wallets, websites could still access an address even after the user had revoked permission and restarted the browser.
An additional issue: websites can frequently identify which wallet extensions are installed without any user interaction with the wallet. The researchers also found that 23 of the 36 affected wallets could leak an address via content loaded from a third-party site, even without a click.
Most wallet providers contacted by the researchers did not consider this a critical flaw. Coinbase Wallet, Coin98, and Hana implemented changes, whereas MetaMask, Rabby, OKX, and others did not. The researchers also examined 30 decentralized apps; only 11 correctly revoked wallet access when users clicked "disconnect" or logged out.
Once an address is exposed, the public blockchain supplies the remaining details.
Blockchain analytics firms search for transaction patterns indicating that multiple addresses are controlled by the same individual or entity.
For instance, if multiple wallets frequently transfer funds to each other or behave similarly, clustering software can link them. Consequently, a single identified address can uncover many others.
This process occurs on a massive scale. By mid-2026, Chainalysis reported that it had grouped over 1 billion blockchain addresses into more than 134,000 known entities.
Shifting funds across blockchains does not necessarily destroy the trail. Analysts can track assets via cross-chain bridges. Decentralized exchange swaps also remain publicly recorded on the blockchain, so they don't automatically conceal the transaction.
The outcome is straightforward: a wallet address appears as a random character string, but when sufficient activity is linked to it, it can form a comprehensive financial profile.
Real-world examples demonstrate this. Following the 2021 Colonial Pipeline ransomware attack, US authorities traced Bitcoin across multiple wallets and recouped approximately $2.3 million of the $4.4 million ransom.
During Bitcoin's early days, Helix gained popularity on darknet markets. Its single purpose was to make Bitcoin untraceable. From 2014 to 2017, Larry Dean Harmon operated it as a tumbler, mixing customers' coins to hide their origins and promoting the result as "clean" bitcoin. The entire operation revolved around concealment, designed solely to sever the link between a coin's source and its destination.
Approximately 354,468 BTC, worth around $311 million at the time, flowed through Helix. The mixing altered the appearance of the trail but did not eliminate it. Each coin still left an indelible record on the blockchain, unchangeable and permanent.
Harmon charged a 2.5% fee on each swap, and that fee joined the other coins on the blockchain forever. The commission he collected for operating a concealment service created the evidence that pointed back to him. The very service intended to eliminate the trail ended up inscribing its owner onto the unerasable trail.
Helix demonstrates that moving Bitcoin does not guarantee erasure of the trail. However, tracing the funds is only part of the process. Analysts must still link wallet addresses to actual individuals or companies.
This typically occurs when funds reach a regulated exchange. Exchanges maintain records of which deposit addresses belong to their customers and conduct KYC identity verification. If investigators follow Bitcoin to such an address, they can obtain account information via legal channels.
A single link can expose much more than a single transaction. If blockchain analysis has already clustered multiple addresses under a likely common owner, identifying one gives a name to the entire cluster. The exchange may be aware only of the address that interacted with its platform, but prior clustering ties it to others.
Sometimes no legal process is necessary. Individuals and companies often publicize their own wallet addresses on websites, donation pages, Telegram groups, or public profiles. Once an address is openly associated with a name, all its prior transactions become viewable.
For businesses, this poses a fundamental privacy issue. Paying a supplier can reveal earlier payments, treasury activities, and other partners. Since blockchain transactions are immutable and time-stamped, a single identified wallet can simplify reconstructing years of activity.
This does not imply that blockchain analysis is flawless.
The systems for linking wallets depend largely on patterns and probability. They can yield both false positives and false negatives — legitimate actions may be flagged, and illicit activity may go undetected.
One issue is transaction history. Bitcoin can change hands many times. If coins once passed through a mixer or a flagged wallet, a subsequent owner may inherit the risk profile even if unrelated to the prior use.
There is a documented case of a peer-to-peer buyer whose account was frozen because the Bitcoin received had previously been through a mixer.
For exchanges and similar regulated entities, such errors carry real costs. A false positive can freeze a genuine customer's funds and generate compliance and customer service issues.
Tracking companies also face limitations. Privacy-oriented cryptocurrencies like Monero are far more difficult to trace. Investigations can also halt when funds reach exchanges in non-cooperative jurisdictions.
Even the largest blockchain analytics firms have issued significant revisions. In early 2025, Chainalysis lowered its estimate of cryptocurrency stolen by North Korea in the prior year from $1 billion to $660.5 million — a reduction of over $300 million after reevaluating several hacks.
The dependability of these systems has also been contested in court. Defense lawyers in cases such as Bitcoin Fog and Tornado Cash have challenged the credibility of analysis from proprietary software that external parties cannot thoroughly review.
This scrutiny is significant because Chainalysis also serves as a major US government contractor. Independent reporting from federal records revealed it had received over $93.2 million in government contracts.
The greatest risk from incorrect results is borne by innocent users. An erroneous link can freeze an account. In jurisdictions with weaker safeguards, the same tracing instruments can expose donors, journalists, or those financing political opposition. While blockchain tracing can uncover much, its findings should not be considered automatically accurate.
The majority of the exposure outlined above occurs without user control. Wallets may leak addresses before any transaction. Blockchain analysis can cluster addresses, and regulated exchanges can link wallets to real identities via KYC data.
What users can still manage is the direct sender-recipient link. When one wallet pays another, that connection is recorded permanently on-chain and can later expose counterparties, treasury activity, and business ties.
ChangeNOW launched a feature called Private Transfers to eliminate that direct link. The service routes a payment through a unique one-time address, so the recipient does not get funds straight from the sender. This severs the visible sender-recipient path without asserting full anonymity.
Other forms of exposure persist. Wallet metadata can still be leaked, blockchain analysis can still track surrounding activity, and AML checks remain in place during deposit, transfer, and payout steps.
For API partners, Private Transfers is an optional addition to the existing transfer system. It uses the same API key and fee structure and does not need a separate product or integration. Its goal is limited: remove the one visible link that users can decide not to create.
Let's return to the starting point. Andy Greenberg once believed the blockchain concealed its users, but after years of observation he reached the opposite conclusion: "it took me a decade to realize how opposite of untraceable Bitcoin really was." This is the foundation of the entire article. Complete untraceability does not exist. Wallet leaks, chain records, and clustering all converge on a name.
That is the relevant perspective: not anonymity, which a decade of traced coins shows to be a story rather than a property, but a clear account of which layer closes and which stays open. Private Transfers removes the one link users can choose not to create.
Share to
Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.
Bloomberg's Eric Balchunas predicts Bitcoin ETFs could hold three times gold's ETF assets, implying a potential BTC price range of $490k-$730k.
Bloomberg analyst Eric Balchunas predicts Bitcoin ETFs will triple gold ETFs in assets as younger investors mature and volatility decreases.
XRP's two-week RSI fell to a record low near 33.5, sparking debate over whether the token has found its cycle bottom.
Ric Edelman likens current bitcoin purchases to Amazon in 1999 and expects the cryptocurrency to reach $500,000 by 2030.