Guide — privacy and visibility
Tracking and tracing wallet addresses
Every balance and every transaction on a public blockchain is visible to anyone, permanently. Understanding exactly what that exposes — and what it does not — is the difference between informed privacy decisions and false comfort.
- Public Every balance and transaction, permanently
- Pseudonymous Addresses carry no names by themselves
- 1 Apr 2026 CARF reporting live in New Zealand
- Watch-only Monitor cold storage with no keys present
On this page
Block explorers: what anyone can see
A blockchain is a public ledger. That phrase gets used so often it stops registering, so here is what it means concretely: paste any address into a block explorer and you can read its entire financial history. Current balance. Every amount ever received and from which address. Every amount ever sent and to which address. Timestamps for all of it. No account, no permission, no fee.
This is not a flaw or a privacy failure — it is the mechanism by which the system works without a trusted central authority. Every participant can verify every transaction precisely because every transaction is public. But it means the mental model most people arrive with, which is something like a bank account, is wrong in an important way. Your bank statement is private. Your address history is a website.
It is also permanent. There is no deletion, no expiry and no right to be forgotten on a blockchain. An address you used in 2018 still shows what it did in 2018, and will in 2038.
The practical consequence New Zealanders should think about: if you give one address to an employer, a client, a friend or a marketplace, you may have shown them considerably more than the payment. Everything that address has ever done, and — through the clustering described next — possibly a good deal more.
Clustering: how addresses get grouped
Individual addresses are only the beginning. Analysis techniques group addresses that are probably controlled by the same person, and this is where a single disclosure becomes a much larger one.
The most powerful technique is the common-input heuristic. When a Bitcoin transaction spends coins from two different addresses at once, it must have been signed by whoever controls both — so both are almost certainly the same owner. Do that a few times and a cluster forms. Clustering software has been recording this for years.
Change addresses leak too. When you spend part of a balance, the remainder goes to a new address your wallet controls, and patterns in how wallets construct these make change outputs identifiable with reasonable confidence. Amount patterns, timing patterns and round-number payments all add signal.
Account-based chains like Ethereum and Solana are simpler and worse. There is no clustering to do because there is usually only one persistent address per account — every transaction you ever make is publicly attached to the same identifier, forever. That is considerably less private than a well-used Bitcoin wallet.
Why fresh addresses matter
Bitcoin wallets generate a new receiving address for every incoming payment specifically to defeat the simplest form of this analysis. If you reuse one address for your salary, your marketplace sales and a payment from a friend, all three parties can see the others. Using the address your wallet offers, rather than the one you saved last time, costs nothing and helps. See our addresses guide.
Where the identity link actually happens
This is the part that determines whether "pseudonymous" means anything in practice, and the answer is that it depends entirely on the edges rather than the chain.
The blockchain contains no names. There is no field for one, no registry, and no lookup service that turns an address into a person. In that narrow sense addresses are pseudonymous and always will be.
But almost every address eventually touches a business that verified who you are. Exchanges and brokers serving New Zealanders are captured by the AML/CFT Act 2009 and must identify their customers — and from 1 July 2026 the Department of Internal Affairs becomes the single AML/CFT supervisor for them. When you withdraw from a verified account to your wallet, that business now holds a record linking your legal identity to that address. Sell back through the same or another verified platform and the link is confirmed at both ends.
Other linkage vectors: an address posted publicly on a forum or social media, an address given to a merchant who keeps records, IP metadata captured when a wallet queries a third-party server for your balance, and reuse of the same address across services that each know something about you. Combine those with clustering and a determined analyst can often build a substantial picture.
Practical summary: your on-chain activity is pseudonymous in isolation and effectively identified in aggregate for anyone who buys or sells through a regulated platform, which is nearly everyone. Assume that, and you will make better decisions than assuming otherwise.
CARF and what IRD now receives
New Zealand adopted the OECD's Crypto-Asset Reporting Framework with effect from 1 April 2026, and it changes the visibility picture materially.
Under CARF, New Zealand-based Reporting Crypto-Asset Service Providers — broadly, any individual or entity carrying out the exchange or conversion of cryptoassets on behalf of users as a business, including counterparties, intermediaries and trading platforms — must collect identification and tax residency information from users along with transaction details including the types of trades and their values. That is reported annually to Inland Revenue in a specified electronic format, with the first reports due by 30 June 2027, and shared both domestically and internationally. IRD has run a public campaign urging crypto investors to get tax compliant ahead of it.
What that means for a self-custody user is specific. Your wallet is not a reporting provider — there is nobody behind it to report. But the platform where you bought reports, and the platform where you eventually sell reports. IRD sees both ends of your activity and not the middle. If your own records cannot account for the gap, you are the one who explains it.
This is not an argument against self-custody. It is an argument for records. Our tax and CARF guide covers exactly what to keep. General information, not tax advice.
Watching your own wallet safely
A genuinely useful application of all this: monitoring your own cold storage without touching the keys.
Import the extended public key from your hardware wallet into a watch-only wallet, and you can see balances and full transaction history on your phone or laptop. That key can derive all your receiving addresses and mathematically cannot spend anything, because spending needs the private key which stays on the device. BlueWallet implements this particularly cleanly for Bitcoin, and it solves the main practical annoyance of cold storage — that checking it normally means handling the device.
There is one privacy caveat. Handing an extended public key to a wallet means whatever server that wallet queries can see all your addresses as a single cluster, which is a larger disclosure than showing one address. If that matters, point the wallet at your own Electrum server or node — New Zealand's fibre network makes running one straightforward, and our desktop wallets page covers the software.
For general portfolio monitoring, most block explorers offer watchlists, and dedicated portfolio trackers will follow addresses you add. Be selective: a tracker that wants your extended public key is asking for your whole wallet's visibility, and a tracker that wants a signature is asking for something it does not need.
Whale watching, and why it is overrated
Because balances are public, anyone can rank addresses by size and watch large transfers. A cottage industry of alert services has grown around this, and the appeal is obvious: if you could see what large holders were about to do, you could act first.
Two problems make it much less useful than it appears. First, the largest addresses are overwhelmingly not individuals — they are exchange reserves holding thousands of customers' funds, bridge contracts, staking pools and foundation treasuries. A large outflow from an exchange address might be one customer withdrawing, an internal reshuffle, or a cold storage rotation. Interpreting it as a market signal is usually wrong.
Second, entities that genuinely want to move size without signalling it can split transactions, use multiple addresses, or trade off-chain entirely. What you observe is the part they were content for you to observe.
We mention it because "how to find whale wallets" is a common search, and the honest answer is that you can find them easily and the information is worth much less than the services selling it suggest. Nothing on this site is a recommendation to buy or sell anything, and following anonymous addresses is a particularly poor basis for a decision.
Reducing what you expose
Realistic measures, in rough order of effectiveness.
Use a fresh receiving address per counterparty. Free, and it prevents the simplest cross-linking. Just use whatever address your wallet offers rather than reusing a saved one.
Do not consolidate coins from different sources unnecessarily. Spending two addresses in one transaction proves they belong to the same owner. Coin control — available in Sparrow and Electrum on the desktop, and almost no phone wallet — lets you choose which coins to spend and keep sources separate.
Run your own node, or connect your wallet to one. By default a wallet asks somebody else's server for your balance, disclosing every address you own to that server. Running your own removes that disclosure entirely.
Do not post addresses publicly. An address in a forum post or a social media reply is permanently linked to that account.
Keep your street address out of vendor databases. Not on-chain privacy, but the same category of exposure — and after Ledger's 2020 breach of roughly 270,000 customer records including home addresses, and a further exposure through its payment processor disclosed in January 2026, a demonstrated one. Buy hardware from a New Zealand reseller, or ship to a parcel locker. See our buying guide.
Our view
The most common mistake here is not carelessness, it is the wrong mental model. People treat a wallet like a bank account and are surprised to learn that anyone can read it. Once you flip that assumption — everything on-chain is public and permanent, and the identity link happens at the exchanges — the sensible behaviours become obvious and none of them require special tools.
Frequently asked
Questions on this topic
How do I track a crypto wallet address?
Paste the address into a public block explorer for the right chain and you can see its complete balance and transaction history — every amount in and out, every counterparty address, with timestamps. That information is public by design and requires no permission or account. For ongoing monitoring, most explorers offer watchlists, and a watch-only wallet import lets you follow your own cold storage from a phone with no private keys involved.
Can crypto wallets be traced to a person?
Addresses are pseudonymous, not anonymous. The chain itself contains no names — but the moment an address interacts with a business that verified your identity, that business can link the two. From 1 April 2026 New Zealand applies the OECD Crypto-Asset Reporting Framework, so reporting crypto-asset service providers collect identity and tax residency information and report transaction data to Inland Revenue, with first reports due by 30 June 2027 and information shared internationally. The chain is the public part; the identity link sits at the edges.
Can someone steal my crypto if they know my wallet address?
No. A public address lets someone send you funds and read your history. Spending requires the private key, which never leaves your wallet. What an address exposes is information — your balance, your patterns, your counterparties, and through clustering analysis possibly other addresses you control. That is a privacy consideration, not a theft risk, and it is why Bitcoin wallets generate a fresh address per payment.
How do people find whale wallets?
By sorting on-chain data. Because every balance is public, anyone can rank addresses by holdings, watch large transfers, and label known entities — exchange reserves, foundation treasuries, bridge contracts. Several services turn that into feeds and alerts. Two cautions worth keeping in mind: a large address is very often an exchange holding many customers' funds rather than one person, and following whale movements is a poor basis for trading decisions.
Is it possible to find out who owns a crypto wallet?
Not from the blockchain alone, and often yes in practice through other means. Law enforcement and analytics firms combine on-chain clustering with off-chain data — exchange records obtained under legal process, IP logs, publicly posted addresses, and reused addresses across services. For an ordinary person there is no lookup service that returns a name, and anyone offering one is either selling nothing or breaking the law. Do not attempt to identify individuals; if you have been defrauded, report it to police and Netsafe and let them use the proper channels.
Next in this cluster