Crypto Security & Privacy How Private Broadcast Tools Mask Transaction IPs Owen Gaines Owen Gaines is a professional poker player and author who has played an estimated ten million hands and written four poker strategy books. September 29, 2026 Every cryptocurrency transaction has to enter the network somewhere. The first node or server that receives it sees the IP address it came from. Blockchain analysis links addresses to each other; network-level observation can link those addresses to a physical connection. Private broadcast tools exist to break that second link. For crypto poker players, the relevant question is narrow: who learns your IP address when you send a deposit or move a withdrawal, and can they tie it to your wallet? The answer depends on how your wallet connects to the network. Some setups leak your IP and addresses to a single third party on every sync. Others spread the broadcast so no observer can reliably identify its origin. This guide explains what a broadcast reveals, how Tor, Dandelion++, and self-hosted nodes mask the origin, and where network-layer privacy stops protecting you. What a Transaction Broadcast Reveals On Bitcoin, a new transaction spreads through the peer-to-peer network node by node. An observer connected to many nodes can record when each node first announces it. The node that announced earliest is statistically likely to be close to the source. Academic research has shown this “first-spy” approach can link a meaningful share of transactions to IP addresses when the sender connects directly from a home network. Most players don’t connect to the peer-to-peer network at all. Light wallets query a server operated by the wallet provider or a third party. That server sees your IP address, every address you ask about, and every transaction you broadcast. It doesn’t need timing analysis; the association is handed to it directly. Account-based chains follow the same pattern. Ethereum wallets usually connect through an RPC provider that sees your IP, your address, and your transactions before they reach any public mempool. How Broadcast Privacy Tools Work Tor and I2P Routing Tor routes traffic through three relays with layered encryption, so the destination sees a Tor exit or onion address rather than your IP. Bitcoin Core can run entirely over Tor or I2P, and many wallets can route server connections through Tor. The receiving node or server still sees your transaction and addresses, but it can no longer attribute them to your connection. Dandelion++ Stem-and-Fluff Propagation Dandelion++ changes how a transaction spreads. In the “stem” phase, it passes privately along a random chain of single peers. Only after a random number of hops does it enter the “fluff” phase and broadcast normally. An observer who sees the first public announcement sees a node several hops from the true source. Monero uses Dandelion++ by default; Bitcoin Core does not. Running Your Own Node A self-hosted node removes the third-party server entirely. Your wallet queries your own node, so no outside operator learns which addresses you watch. Broadcasts from your node are still visible on the peer-to-peer network, which is why node operators often combine self-hosting with Tor. What This Means for Crypto Poker Players Each wallet setup distributes knowledge differently: Setup Who Sees Your IP With Your Addresses Main Limitation Light wallet, default server Server operator One party sees your full address history and IP Light wallet over Tor No one directly Server still sees which addresses belong together Own node, clearnet Well-connected network observers, probabilistically Timing analysis can estimate the origin Own node over Tor or I2P No one directly Slower sync; requires setup and maintenance VPN VPN provider Trust moves to the provider rather than disappearing None of these setups changes what the poker site knows. The site issued the deposit address to your account and logs your login connection. Broadcast privacy protects you from outside observers, not from the counterparty you’re paying. It also has no effect on withdrawal processing or confirmation times. Common Mistakes Players Make Routing broadcasts through Tor while the same wallet syncs with a default server over a normal connection, leaking the IP through the other channel Assuming a VPN makes transactions anonymous, when the VPN provider can log the same association Pasting a signed transaction into a web broadcast page without Tor, handing that site the IP-to-transaction link Treating network privacy as a way around site terms; location and account rules still apply regardless of how a transaction is broadcast Limits of Network-Layer Privacy On-Chain Data Stays Public Masking the origin IP doesn’t hide the transaction. Amounts, addresses, and the links between inputs and outputs remain permanently visible on transparent chains. Address clustering can still group your wallets together. Network privacy and on-chain privacy are separate layers, and improving one does nothing for the other. Account-Level Identity Exchanges and poker sites that know your identity can link any address they send to or receive from with your account. Tax and reporting obligations exist in many jurisdictions regardless of how a transaction is broadcast. Broadcast tools reduce passive surveillance; they don’t change your legal or contractual position. Timing Correlation If you request a withdrawal and broadcast a sweep from the receiving address seconds later, anyone watching both can correlate the events. Timing patterns can undo network-layer protection without any IP data at all. Sweeping a Withdrawal to Cold Storage Over Tor A player receives a Bitcoin withdrawal from a poker site to a hot wallet and wants to move it to cold storage without exposing their home IP to network observers or a wallet server. Receiving wallet: desktop wallet connected to the player’s own node Node configuration: connections restricted to Tor Destination: a hardware wallet address never used with any exchange or site Fee: set from current mempool conditions, typically a few dollars in normal traffic The Technical Process The wallet builds the transaction, the hardware wallet signs it, and the node relays it to peers over Tor. Peers see an onion connection, not the player’s IP. Because the wallet queries only the player’s node, no third-party server learns the addresses involved. The player waits several hours after the withdrawal confirms before sweeping, which weakens simple timing correlation. The Outcome The transaction confirms normally, typically within 10-30 minutes depending on fee rate. Outside observers can see the on-chain movement but can’t tie it to a home connection. The poker site still knows it paid that withdrawal address, and the chain still shows where those coins went. The protection is real but limited to the network layer. How Professionals Handle Broadcast Privacy Experienced players decide which parties they’re willing to share data with and configure their setup accordingly, instead of relying on a single tool. Technical Risk Management They route every wallet connection through the same privacy path, so sync traffic doesn’t leak what broadcasts conceal. They keep wallet software updated and verify downloads, because a compromised wallet makes network security irrelevant. Play stays in the ACR Poker software under normal account rules, separate from wallet infrastructure. System Optimization They run a node on a low-power device, connect their wallets to it, and avoid reusing addresses, so each layer of privacy supports the others. Technical Evolution in Transaction Privacy Bitcoin developers have explored sending each transaction through short-lived, single-purpose Tor or I2P connections, which would give node users private broadcast without extra configuration. Encrypted peer-to-peer transport (BIP324) is already deployed in Bitcoin Core, making passive traffic inspection harder. Light-wallet privacy is improving as well, with compact block filters letting wallets sync without revealing addresses to a server. For players, the direction is toward private-by-default broadcasting. On-chain transparency and account identity remain unchanged. Frequently Asked Questions Can someone see my IP address when I send Bitcoin? Potentially. A light wallet’s server sees your IP and addresses directly. If you run your own node on a normal connection, observers connected to many nodes can estimate a transaction’s origin through timing analysis. Routing your wallet or node through Tor or I2P prevents either party from attributing the transaction to your IP. What is Dandelion++? Dandelion++ is a propagation method that first passes a transaction privately through a random chain of single peers, then broadcasts it normally. The first public announcement appears several hops from the real source, which defeats simple first-spy analysis. Monero uses it by default. Bitcoin Core does not implement it. Does masking my IP make my transactions anonymous? No. It hides the network origin only. Amounts, addresses, and transaction links stay public on transparent blockchains, and address clustering can still connect your wallets. Exchanges and poker sites that know your identity can still link addresses they interact with to your account. Broadcast privacy is one layer, not anonymity. Is a VPN enough for transaction privacy? A VPN hides your IP from the wallet server or network peers but gives the same association to the VPN provider. Whether that is acceptable depends on the provider’s logging and jurisdiction. Tor spreads trust across several independent relays. Also note that VPN use can conflict with site location rules, which still apply. Why does my light wallet server matter for privacy? To show your balance, a light wallet asks its server about each of your addresses. The server learns which addresses belong to one user and, without Tor, which IP they belong to. Connecting the wallet to your own node, or routing it through Tor, removes or reduces what that server can learn. Does private broadcasting slow down my deposit? Only slightly. Tor adds seconds of latency to relaying, and Dandelion++ adds a short stem phase before normal propagation. Confirmation time is still driven by block intervals and your fee rate. The larger cost is setup: running a node over Tor takes more configuration and maintenance than a default light wallet.