Electronic voting (e-voting) has become an essential topic in the modernization of democratic systems, with promises of accessibility, faster counting, and reduced logistical challenges compared to traditional paper ballots. Yet, widespread adoption has been hindered by persistent trust and security concerns. Vulnerabilities such as malware, server compromise, insider threats, and limited verifiability have generated skepticism regarding the integrity of e-voting platforms. Blockchain technology has emerged as a disruptive innovation capable of reshaping this discourse. Its intrinsic properties—immutability, decentralization, transparency, and consensus-driven validation—directly address many of the fundamental challenges associated with securing digital elections. This manuscript provides a comprehensive exploration of blockchain-based electronic voting, with particular emphasis on the trust and security challenges that shape its practical deployment. Drawing on global case studies, theoretical models, and simulation insights, the research examines how blockchain can ensure tamper resistance, facilitate end-to-end verifiability, and empower voters through transparent audit trails. Key challenges such as scalability bottlenecks, voter anonymity risks, usability barriers, and regulatory gaps are analyzed in depth. The results indicate that hybrid blockchain architectures, which integrate advanced cryptographic techniques such as zero-knowledge proofs, homomorphic encryption, and sharding, hold promise for balancing the competing demands of scalability, privacy, and trust. Furthermore, blockchain must be supported by strong institutional frameworks, inclusive accessibility measures, and continuous technical audits to achieve legitimacy in electoral processes. By systematically mapping both the opportunities and limitations, this research contributes to the ongoing discourse on how technology can strengthen democratic resilience in the digital era. Ultimately, blockchain-enabled voting should be regarded not as a replacement but as an augmentation of existing systems, combining the strengths of distributed technologies with constitutional safeguards to advance secure, transparent, and inclusive electoral participation.
The vulnerabilities in this vigorous digital landscape are taking a more sophisticated shape as the nature and danger of cyber threats and the nature of cyber threats are taking new forms as a zero-day attack, polymorphic malware, insider threat and advanced social engineering methodologies and where traditional reactive security measures are no longer relevant. This issue of organizations detecting the threat, and that they need to mitigate the threat in real time is rather of a challenge in the light of the fact the behaviour of the adversaries is very much similar to that of legitimate user behaviour and as such will create ambiguity issues that will make an organization believe that it has hit a false positive or missed a threat. A proactive approach to cyber threat countering, the Adaptive AI-Driven Autonomous Threat Hunting (ADCH) Framework, is the focus of this paper as it will be able to monitor, analyse, and mitigate the development of the new threats far before it becomes reality. Behavioural profiling and reinforcement learning are employed at ADCH to differentiate between innocent and harmful actors on the fly even in the ambiguous or complex situation, and ethical precautions are taken so that the deepfake interaction modules are tightly regulated and privacy safeguarding. The framework brings together automated threat intelligence extraction where Indicators of compromise (IoCs) are extracted, classified and pooled across different sources and offer rapid and actionable information. Additionally, ADCH is compatible with Siem and SOAR, automates the incident response and mitigation process to minimise latency and dependency on people. Secure logging provides auditability resistant to tampering and transparent recording of events without de-anonymization of sensitive operational data, with blockchain used to enforce the use of permissioned ledger systems, smart contracts, and zero-knowledge proofs. The results of simulation testify that ADCH has been doing consistently well in terms of detection performance and accuracy, precision, recall and F1 scores, the results stand at $80-90$ and far better than the traditional threat hunting systems. Autonomous AI-controlled detection, ethical simulation, automated intelligence extraction, coordinated response, and blockchain-based logging can be combined to help in establishing a strong and intelligent paradigm of defense against the emergent and advanced cyberspace threats and ensure the safety of the digital infrastructures, transparency, accountability and ethical standards.
Mazin Abed Mohammed, Mohd Khanapi Abd Ghani, Israa Badr Al-Mashhadani, Sajida Memon · 7 authors
The exponential growth of healthcare Internet of Things (IoT) data necessitates secure, low-latency analytics that extend beyond centralized architectures. This paper presents BDAFL DNN, a blockchain-integrated data analytics framework that combines Federated Learning (FL) and Deep Neural Networks (DNNs) for real-time, privacy-preserving healthcare analytics across edge and cloud resources. Local devices such as smartwatches and phones collect noninvasive time series sensor streams (heart rate, temperature, and abdomen sensors), perform on device DNN training, and send only model updates to healthcare edge nodes, where a blockchain ledger validates updates for integrity and traceability; validated updates are then aggregated in the cloud via FL to produce a global model without sharing raw data. In a simulation study against representative baselines, BDAFL DNN reduced execution time, energy use, and resource consumption, lowered the deadline miss ratio, and improved blockchain validation correctness. These results show that integrating blockchain with FL-driven edge and cloud DNN analytics can deliver scalable, secure, and timely insights for future healthcare IoT systems. Reason for Expression of Concern:The Editors wish to alert readers to potential concerns regarding the reliability of the findings reported in “Blockchain-Powered Dynamic Segmentation in Personal Health Record”. The journal has initiated an additional editorial assessment of the article’s methodology, data provenance, and reported outcomes to confirm their reliability and reproducibility. This notice is issued to ensure transparency while the review is ongoing. The Expression of Concern does not constitute a final determination regarding the validity of the work. The journal will update readers once the assessment is completed and will take any necessary editorial action in accordance with the journal’s policies and COPE guidance.See expression of concern available at:https://doi.org/10.58496/2026/017 https://mesopotamian.press/journals/index.php/CyberSecurity/article/view/1041
Lingling Xia, Tao Zhu, Zhengjun Jing, Qun Wang · 7 authors
Digital currencies, led by Bitcoin and USDT, are characterized by decentralization and anonymity, which obscure the identities of traders and create a conducive environment for illicit activities such as drug trafficking, money laundering, cyber fraud, and terrorism financing. Focusing on the USDT-TRC20 token on the Tron blockchain, we propose a two-layer transaction network-based approach for virtual currency address identity recognition for digging out hidden relationships and encrypted assets. Specifically, a two-layer transaction network is constructed: Layer A describes the flow of USDT-TRC20 between on-chain addresses over time, while Layer B represents the flow of TRX between on-chain addresses over time. Subsequently, an identity metric is proposed to determine whether a pair of addresses belongs to the same user or group. Furthermore, transaction records are systematically acquired through blockchain explorers, and the efficacy of the proposed recognition method is empirically validated using dataset from the Key Laboratory of Digital Forensics. Finally, the transaction topology is visualized using Neo4j, providing a comprehensive and intuitive representation of the traced transaction pathways.
The integration of Internet of Things (IoT) technologies into public healthcare enables continuous monitoring and sustainable health management. However, conventional frameworks often depend on transmitting and storing raw personal data on centralized servers, posing challenges related to privacy, security, ethical compliance, and long-term sustainability. This study proposes a privacy-preserving framework that avoids the exposure of true health-related data. Sensor nodes encrypt collected measurements and collaborate with a secure computation core to evaluate health indicators under homomorphic encryption, maintaining confidentiality. For example, the system can determine whether a patient’s heart rate within a monitoring window falls inside clinically recommended thresholds, while the framework remains general enough to support a wide range of encrypted computations. A compliance verification client generates zero-knowledge range proofs, allowing external parties to verify whether health indicators meet predefined conditions without accessing actual values. Simulation results confirm the correctness of encrypted computation, controllability of threshold-based compliance judgments, and resistance to inference attacks. The proposed framework provides a practical solution for secure, auditable, and sustainable real-time health assessment in IoT-enabled public healthcare systems.
This study investigates the dynamic relationship between order flow toxicity, measured by the volume-synchronized probability of informed trading (VPIN), and price jumps in the Bitcoin market using high-frequency data and vector autoregressive model (VAR) modelling. By integrating behavioral finance theory to market microstructure framework, we explore how informed trading activity influences jumps in price, and how traders respond to such volatility. Our findings reveal that VPIN significantly predicts future price jumps, with positive serial correlation observed in both VPIN and jump size, suggesting persistent asymmetric information and momentum effects. On the contrary, price jumps occasionally affect VPIN. This study also identifies time-zone and day-of-the-week effects in VPIN, highlighting the role of global trading patterns. The results are robust among the choices of jump tests including Jiang and Oomen (2008) test which is empirically robust against market microstructure noise. These results contribute to a deeper understanding of intraday volatility in cryptocurrency markets and offer practical implications for risk management, trading strategy design, and regulatory oversight.
ABSTRACT Blockchain technology has emerged as a pivotal solution for securing sensitive data across various domains, including artificial intelligence (AI), supply chain management, cloud computing, and healthcare. Its core attributes, confidentiality, decentralization, security, and privacy, offer significant advantages to the healthcare sector. The integration of Internet of Things ( IoT ) devices within healthcare systems enhances interoperability, enabling seamless communication between healthcare software and IT infrastructure. However, traditional healthcare systems face persistent security challenges, including phishing, masquerading, and identity theft. To address these issues, we propose a secure blockchain‐based decentralized application for generating, maintaining, and validating medical certificates. This application facilitates secure interactions among healthcare entities, including hospitals, patients, and IoT devices, while ensuring confidentiality, authentication, and access control through smart contracts. The proposed blockchain architecture enhances data integrity and secure transmission using the zero‐knowledge proof ( ZKP ) mechanism. Additionally, we incorporate the interplanetary file system ( IPFS ) for off‐chain data storage to optimize storage costs and enhance security through Ethereum smart contracts. Performance evaluations demonstrate the effectiveness of our approach in mitigating existing security vulnerabilities, thereby offering a robust and scalable solution for secure healthcare data management.
This study is a comprehensive analysis of the prospects for the development of cryptocurrencies Bitcoin and Ethereum in the context of global economic and political transformations, revealing the fundamental ambivalence of their nature through the dialectic of nominal capitalization and the lack of a stable value paradigm. Using a synthetic methodology combining econometric volatility analysis with an institutional approach, the paper reveals a systemic correlation of the market dynamics of the assets under study with shadow financial flows and speculative practices, demonstrating their permanent dependence on behavioral patterns of mass demand rather than objective macroeconomic factors. Special attention is paid to the process of increasing marginalization of Bitcoin and Ethereum in the system of legitimate economic transactions against the background of the observed convergence of user preferences towards stablecoins, which, combined with extreme price fluctuations (up to +50%), which are stochastic, finally negates their investment viability. The results obtained make it possible to predict with a high degree of reliability the systemic risks of correction by 50% or more due to the fundamental vulnerability of these crypto assets as speculative instruments that do not have price stabilization mechanisms in conditions of geo-economic turbulence.
In today’s digital economy, traditional forms of ownership are undergoing significant changes due to the rise of new technologies, including the spread of Non-Fungible Tokens (NFTs). "Non-fungible" in this context means that each token is unique and cannot be easily exchanged for a similar item, as is the case with conventional digital or physical currencies. A token itself is a digital unit that can represent a digital asset, a piece of art or a unique item, or the granting of a service and so on. This study aims to analyze the role of NFTs as a tool that transforms ownership within the digital space and fosters new economic relationships. The research is grounded in the fundamentals of blockchain technology and integrates economic theories, specifically value theory and contemporary models of capital, in the context of NFTs. The article employs an interdisciplinary approach and examines the mechanisms of uniqueness and decentralized ownership inherent to NFTs, which are reshaping the structure and efficiency of the intangible assets market. Special emphasis is placed on the impact of NFTs on the monetization of digital assets, value formation, and the dynamics of the creative industry. Particular attention is also given to the speculative nature of the market, regulatory challenges, and the prospects for economic sustainability. The findings confirm that NFTs represent not only an economic innovation that transforms ownership mechanisms, but also pose complex challenges related to the legal protection of assets and market stability. The conclusions indicate that NFTs are not merely tools for transforming digital ownership but also play a significant role in shaping new models of the digital economy—models that require further research and regulatory attention. Keywords: NFT, digital economy, ownership transformation, intangible assets, blockchain, economic innovation, monetization, legal regulation.
La tesi esplora il fenomeno della trasformazione digitale, evidenziandone l’evoluzione storica, le tecnologie abilitanti e i benefici strategici per le imprese lungo dimensioni operative, decisionali, innovative e di customer experience. La trasformazione digitale viene presentata come un processo sistemico che coinvolge la digitizzazione, digitalizzazione e infine una profonda ridefinizione dei modelli di business, delle strutture organizzative e delle strategie competitive. Particolare attenzione è dedicata alla tecnologia blockchain, analizzata nei suoi aspetti tecnici fondamentali (nodi, transazioni, blocchi, meccanismi di consenso come Proof of Work e Proof of Stake) e alle sue caratteristiche distintive di sicurezza, immutabilità e decentralizzazione, che la rendono idonea a supportare nuovi paradigmi economici e istituzionali. La tesi approfondisce l’impatto organizzativo della blockchain, con focus sulla digitalizzazione dei processi aziendali, la ridefinizione della divisione del lavoro e i nuovi assetti regolativi e di coordinamento. Si analizzano le Decentralized Autonomous Organizations (DAO) come forme emergenti di organizzazione digitale, fondate su regole programmabili e governance distribuita, che sfidano i modelli tradizionali introducendo automatismi decisionali e nuovi criteri di fiducia. Vengono inoltre discussi i benefici e le sfide connesse all’adozione della blockchain e delle DAO, incluse questioni di scalabilità tecnica, interoperabilità, sicurezza e incertezze normative, ponendo l’accento sulla necessità di integrare competenze tecnologiche, giuridiche e organizzative per sfruttarne appieno il potenziale trasformativo. La tesi presenta la blockchain come infrastruttura digitale generativa capace di abilitare modelli innovativi di collaborazione e governance, con profonde implicazioni per la competitività e la resilienza organizzativa in un contesto economico sempre più digitalizzato e distribuito.
Blockchain technology promises to revolutionize payment systems, yet high transaction costs and network congestion remain significant barriers. This paper introduces WePay, a novel blockchain payment solution that achieves up to $87 \%$ reduction in transaction costs through an innovative gas optimization framework. Our system implements a proprietary transaction batching algorithm, non-custodial cross-chain execution model, and adaptive fee structure that outperforms existing solutions across key metrics. Benchmarking results demonstrate WePay’s superior performance, processing $\mathbf{1, 2 0 0}$ transactions per minute compared to $300-500$ for traditional methods, while maintaining robust security guarantees. User testing with 50 participants revealed a $92 \%$ satisfaction rate and significantly improved adoption potential compared to current blockchain payment systems.
Namrata Mishra, P. K. Chidambaram, Hassan Mohamed Mahdi, Arumalla Spandana · 7 authors
SSI is a quickly appearing paradigm to secure and user-sovereign digital identity management. Nevertheless, existing implementations of SSI still have privacyprotection, interoperability, anti-fraud, and anti-cryptographic resiliency weaknesses. To tackle these issues, this paper presents a proposal of an AI-enhanced, blockchain-based protocol incorporating the use of Zero Knowledge Proofs (ZKP), Multiple Layer Decentralization (MLD) as well as quantumresistant cryptography. The framework uses AI to do dynamic Identity verification and real-time fraud detection, risk-based authentication and provides great advantage to traditional SSI models. The system proposed will utilize ZKPs to provide its users with privacy-preserving authentication so that one can confirm attributes but not reveal sensitive personal data. Multi-layer decentralized identity validation structure is developed to enhance the level of trust, reduce dependence on centralized authorities and enhances/supported interoperability across homogeneous systems. Ancillary, postquantum cryptographic schemes will also be incorporated to protect identities by mitigating the possible quantum computing attacks. Experimental evidence shows that our framework significantly enhances the accuracy of verification, the authentication latency and increases security in comparison to centralised and federated identity management solutions. The scheme is very flexible in financing sector, cross boundaries identity, e-governance portals and Web3 online portals. In the end, this study leads to an increment of a scaleable and privacy-sensitive digital identity system because it bridges existing security, usability and compliance gaps and opens pathways to robust and resilient SSI implementations into the future.
In today’s financial landscape, customer onboarding and lending workflows are increasingly scrutinized for inefficiencies, security vulnerabilities, and compliance risks. Traditional processes rely heavily on centralized databases, manual verifications, and redundant Know Your Customer (KYC) checks, all of which contribute to high operational costs, delays, and susceptibility to fraud. As financial institutions seek more resilient and transparent systems, the integration of blockchain and distributed ledger technologies (DLT) emerges as a promising solution. This paper explores how blockchain—particularly permissioned or consortium-based architectures—can transform onboarding and lending processes by introducing secure, tamper-proof, and auditable transaction records. We present a conceptual framework that leverages smart contracts, decentralized identity (DID), and verifiable credentials (VC) to automate and streamline key steps in customer verification, loan approval, and regulatory reporting. By enabling shared, real-time access to validated information among trusted parties, DLT can reduce duplication, enhance trust, and improve compliance with regulatory mandates such as AML/KYC and data protection laws. The study also evaluates practical considerations, including system interoperability, privacy challenges, governance models, and legal implications. Case examples and pilot initiatives are reviewed to ground the theoretical model in real-world implementations. Ultimately, this paper aims to provide a comprehensive foundation for understanding and applying blockchain-based systems in the financial sector’s most sensitive workflows.
Abstract—The paradigm of digital identity is rapidly shifting from centralized monopolistic control toward decentralized user- centric frameworks to meet the demands of Web3, immer- sive computing and trustless interactions. Traditional identity systems expose users to privacy breaches, vendor lock-in and cross-platform incompatibilities, creating barriers for seamless adoption. To overcome these challenges DIGICRED introduces a decentralized identity and credential system built on Self- Sovereign Identity (SSI) principles leveraging Decentralized Iden- tifiers (DIDs) and blockchain-based cryptographic proofs as the foundation for trust. A verifiable credential layer enables selective disclosure of tamper-proof claims ranging from aca- demic certifications to government-issued IDs preserving privacy while ensuring interoperability. Complementing this a multi- dimensional reputation system fosters trust in anonymous en- vironments, mitigates Sybil attacks and incentivizes meaningful participation across decentralized applications. By integrating privacy-preserving technologies, compliance-aware architectures and scalable trust mechanisms DIGICRED redefines identity management for Web3. This shift marks the emergence of secure portable and user-controlled digital identities laying the groundwork for the future of decentralized applications and cross-platform digital ecosystems. Index Terms—Self-Sovereign Identity (SSI), Decentralized Identifiers (DIDs), Verifiable Credentials (VCs), Blockchain, Web3, Digital Identity, Privacy Preservation, Reputation Systems, Trust Management, Cross-Platform Interoperability. .
Arya Ganendra, Neva Dian Permana, Muhammad Faiz, H. B. J. Clifford
Decentralized Finance (DeFi) proposes a paradigm shift towards a democratized financial ecosystem governed by its users. This vision of decentralization is predicated on the distribution of governance tokens. However, the verity of this claim lacks rigorous empirical validation, raising concerns about a potential "decentralization illusion." This study quantitatively investigates the concentration of governance power within leading DeFi protocols to empirically test this narrative. We employed a multi-faceted quantitative triangulation framework using on-chain data from three archetypal DeFi protocols, selected to represent the core sectors of the ecosystem: a lending market (ProtoLend), a decentralized exchange (ProtoSwap), and a yield aggregator (ProtoYield). Our methodology integrates: (1) Empirical Network Analysis based on on-chain voting power delegation to map the topology of influence; (2) Economic Inequality Metrics, including the Gini Coefficient and Lorenz Curve Analysis, to quantify the distribution of governance tokens; and (3) Systemic Risk Assessment via the Nakamoto Coefficient to determine the minimum number of colluding actors required for a 51% governance attack. The empirical network analysis revealed a distinct core-periphery topology across all protocols, indicative of highly centralized influence structures. This was substantiated by extreme economic inequality, with Gini coefficients of 0.91 for ProtoLend, 0.95 for ProtoSwap, and 0.89 for ProtoYield. Lorenz curves visually confirmed that a minuscule fraction of holders controls the vast majority of voting power. The Nakamoto coefficients were critically low, calculated at 8 for ProtoLend, 5 for ProtoSwap, and 11 for ProtoYield, exposing profound vulnerabilities to collusion and capture. In conclusion, our findings provide robust, triangulated evidence of a pervasive "decentralization illusion" within DeFi. Governance power is not distributed but is instead highly concentrated, replicating the plutocratic power dynamics of traditional finance. This concentration poses significant systemic risks and fundamentally challenges the core value proposition of the DeFi ecosystem.
The rise of centralised social networks has consolidated power among a few major technology companies, raising critical concerns about privacy, censorship, and transparency. In response, decentralised alternatives, including Web3 platforms like Decentralised Social (DeSo) and Fediverse platforms such as Mastodon, have gained increasing attention. While prior research has explored individual aspects of decentralised networks, comparisons between Fediverse and Web3 platforms remain limited, and the unique dynamics of Web3 networks like DeSo are not well understood. This study provides the first in-depth study of DeSo, characterising user behaviour, discourse, and economic activities, and compares these with Mastodon and memo.cash . We collected over 3.1M posts from 13K users on DeSo and Mastodon, along with 11M DeSo on-chain transactions via public APIs. Our analysis reveals that while DeSo and Mastodon share similarities in passive content engagement, they differ in their use of URLs, hashtags, and community focus. DeSo is primarily oriented around Decentralised Finance (DeFi) topics, whereas Mastodon hosts diverse discussions with an emphasis on news and politics. Despite DeSo’s decentralised social graph, its transaction graph remains centralised, underscoring the need for further decentralisation in Web3 platforms. Additionally, while wealth inequality exists on DeSo, low transaction fees promote user participation irrespective of financial status. These findings provide new insights into the evolving landscape of decentralised social networks and highlight critical areas for future research and platform development.
Abstract In the context of the metaverse and Web3, we have a novel set of immersive, decentralised, and interactive environments for its interaction with customers and audiences by marketers. This work represents how AR, VR, blockchain, and AI affect conventional marketing approaches. It speaks of changes such as e-stores and NFTs, the gamification, all to optimize traditional environments and design lively clients’ experiences. They recommend consumer behaviour analysis, ethical concerns, and diversity within the Metaverse as the future research agendas for this research. It analyses Decentraland and The Sandbox as immersive platforms, virtual commerce, and ‘gamification’ of marketing, and more, as immersive models. Customer Experience 3.0 demonstrates that through advanced technologies, organisations can reimagine customer engagements and generate value by turning clients into fans. This paper also seeks to provide orientation to the marketers in a positive way while unveiling opportunities and threats within the metaverse in which it lays down its foundation as a crucial aspect of the future of marketing and consumer research. Keywords: Metaverse marketing, Web3 technologies, immersive customer experience, NFTs, AR/VR, blockchain marketing.
We argue that the principal application for blockchain technology will not be in the financial sector, but rather in maintaining decentralized human governance, from archives to transparent policies encoded in the blockchain in the form of smart contracts.. Such decentralized, blockchain-grounded governance comes not a moment too soon, as nation states are dissolving before our eyes. Will blockchain-based communities replace the nation state? What are the prospects and dangers of this development?
Raffaele Cristodaro, Benjamin Kraner, Claudio J. Tessone
This paper investigates the impact of sanctions on Tornado Cash, a smart contract protocol designed to enhance transaction privacy. Following the U.S. Department of the Treasury's sanctions against Tornado Cash in August 2022, platform activity declined sharply. We document a significant and sustained reduction in transaction volume, user diversity, and overall protocol utilization after the sanctions were imposed. Our analysis draws on transaction data from three major blockchains: Ethereum, BNB Smart Chain, and Polygon. We further examine developments following the partial lifting and eventual removal of sanctions by the U.S. Office of Foreign Assets Control (OFAC) in March 2025. Although activity partially recovered, the rebound remained limited. The Tornado Cash case illustrates how regulatory interventions can affect decentralized protocols, while also highlighting the challenges of fully enforcing such measures in decentralized environments.
Raffaele Cristodaro, Benjamin Kraner, Claudio J. Tessone
Tornado Cash is a decentralised mixer that uses cryptographic techniques to sever the on-chain trail between depositors and withdrawers. In practice, however, its anonymity can be undermined by user behaviour and operational quirks. We conduct the first cross-chain empirical study of Tornado Cash activity on Ethereum, BNB Smart Chain, and Polygon, introducing three clustering heuristics-(i) address-reuse, (ii) transactional-linkage, and (iii) a novel first-in-first-out (FIFO) temporal-matching rule. Together, these heuristics reconnect deposits to withdrawals and deanonymise a substantial share of recipients. Our analysis shows that 5.1 - 12.6% of withdrawals can already be traced to their originating deposits through address reuse and transactional linkage heuristics. Adding our novel First-In-First-Out (FIFO) temporal-matching heuristic lifts the linkage rate by a further 15 - 22 percentage points. Statistical tests confirm that these FIFO matches are highly unlikely to occur by chance. Comparable leakage across Ethereum, BNB Smart Chain, and Polygon indicates chain-agnostic user misbehaviour, rather than chain-specific protocol flaws. These results expose how quickly cryptographic guarantees can unravel in everyday use, underscoring the need for both disciplined user behaviour and privacy-aware protocol design. In total, our heuristics link over $2.3 billion in Tornado Cash withdrawals to identifiable deposits, exposing significant cracks in practical anonymity.