





































Stablecoins now settle roughly 82% of institutional over-the-counter trade volume, according to Finery Markets' Q1 2026 review of more than 5.2 million institutional spot trades, which means the majority of OTC flow clears across public blockchains that anyone can read in real time.
Hinkal is the privacy protocol that lets desks keep counterparties, amounts, and settlement flow confidential while every transaction stays verifiable, auditable, and compliant on the same chains they already use.
An OTC desk's edge lives in information no one else is supposed to have: who it trades with, in what size, and how its inventory shifts after each fill. When that activity settles on a transparent ledger, a patient observer can rebuild most of it without ever touching the desk's internal systems.
This guide breaks down the full reverse-engineering workflow step by step: who reads the tape, which tools they use, how scattered addresses collapse into a desk's identity, how counterparties and inventory get reconstructed, why standard defenses leak anyway, and how the exposure can be closed without changing wallets, chains, or stablecoins.
[[KEY_TAKEAWAYS]]

An OTC desk sells discretion. Clients route size through a desk precisely to avoid the market impact and signaling that come with executing on a public order book. That value proposition assumes the trade stays private, and for the negotiation itself it does. The leak happens at the settlement.
When a bilateral trade clears on a public chain, the desk is no longer publishing a redacted print to a regulated tape that hides counterparty identity. It is broadcasting the raw settlement record to every indexer, analytics firm, competitor, and searcher bot watching the chain, permanently and in full detail.
Exchange internal flow is comparatively protected, because trades that net inside a centralized venue never touch the chain individually. OTC settlement is the opposite: each leg is an on-chain event with a sender, a recipient, an amount, and a timestamp. The desk's most sensitive activity is also its most exposed.
The asymmetry runs entirely against the desk. In a voice or RFQ market, only the two parties know the trade. On public settlement, the two parties know the trade and so does everyone else with a block explorer.
In traditional markets, reading the tape means studying time and sales data, the running record of executed prices and sizes, to infer who is active, how urgent they are, and where the pressure sits. Skilled traders inferred institutional intent from the shape of the flow long before anyone published a position.
On a public blockchain, the tape is the ledger itself, and it is richer than any exchange print. Every settled transfer carries an amount, a token, a timestamp, a sending address, a receiving address, and the identity of whoever paid the gas. The mempool adds a second layer, exposing intent before a transaction even confirms.
Reading the tape on-chain therefore means more than watching flow. It means attributing that flow to a specific desk, linking the desk to its counterparties, and turning a stream of transfers into a live model of the desk's book.

Reconstruction is not a single adversary. It is a set of actors with different motives, each of whom benefits from a different slice of the desk's exposed activity.
Competing desks want the client roster.
Each of these actors reads a different part of the same public record, and none of them needs the desk's cooperation.
The reconstruction described in this guide does not require bespoke infrastructure. A capable analyst assembles it from tools that are mostly free or commercially available.
Block explorers such as Etherscan, Solscan, and Tronscan expose raw transaction data, address histories, token transfers, and contract interactions. Attribution and analytics platforms in the Arkham, Nansen, Chainalysis, and Elliptic category layer entity labels on top of that data, so a labeled address propagates its identity to everything it touches.
Data environments like Dune let analysts write queries across the full history of a chain, turning ad hoc inspection into repeatable dashboards. Mempool monitors surface pending transactions before confirmation, and public labeled datasets and prior investigations give analysts a head start on tagging exchanges, funds, and known desks. The barrier to entry is low, and it keeps falling.
Reverse-engineering a desk's book is a repeatable process. An analyst rarely improvises. They run a sequence, and each stage feeds the next.
Everything starts from one known address. A seed can come from a client who publicly acknowledged a trade, a press release naming a settlement partner, a large round-number transfer that stands out, a labeled address on an analytics platform, or a withdrawal to a known exchange deposit address.
The desk does not need to reveal anything itself. One confirmed link to a single wallet is enough to begin, because the graph grows outward from that first node.
Clustering collapses scattered addresses into a single entity, and the heuristics differ by chain architecture.
Deposit-address reuse is especially powerful, because centralized venues assign persistent deposit addresses per client, so any interaction with those addresses labels the relationship. Behavioral correlation ties wallets that transact in lockstep or in the same size bands, and address poisoning is an active technique where an analyst seeds lookalike addresses to bait mistaken sends that confirm control.
Change and residual balances leak how much capacity a wallet still holds.
Once a handful of addresses are labeled as a desk, every future transaction those addresses touch inherits the label automatically. The desk does not get to reset the graph. It grows against them with every settlement.
Clustering identifies the desk. Mapping identifies who it serves, which is often the more valuable secret. Repeated settlement between the desk's cluster and an external cluster is a relationship, and repetition makes it legible.
A counterparty settled with every Tuesday in similar size has a visible cadence. When that counterparty's other addresses touch a labeled fund, a market maker, or a corporate treasury, the desk's client roster fills in by inference. Withdrawal patterns to identifiable exchange deposit addresses reveal where a client ultimately routes funds, which hints at their broader strategy.
With the entity and its relationships mapped, net flow reconstructs the position. Summing inflows and outflows across the desk's cluster over a window approximates its inventory in each asset. Watching how that inventory moves after large fills exposes directional bias.
Hedging behavior is the sharpest signal: when a desk absorbs a large client sell and routes offsetting size to a centralized venue, the on-chain leg of that hedge is visible even when the exchange side is not. The timing gap between the client fill and the hedge reveals how quickly the desk lays off exposure and how much risk it is willing to warehouse.
Even when addresses rotate, behavior persists, and behavior is a fingerprint. Desks settle on predictable cadences, cluster around business hours in a specific timezone, favor round settlement sizes, reuse the same relayers or infrastructure, and exhibit consistent gas-bidding habits.
An analyst who has profiled a desk's timing distribution, size bands, and operational rhythm can re-identify it on a brand new set of wallets within days by matching the pattern. The wallets changed. The desk did not.

It helps to name the categories of information that escape, because each maps to a different competitive harm.
Identity signals attach on-chain activity to a real entity through clustering and labeling.
The individual data points are mundane. Their combination reconstructs the book.
Moving activity across chains feels like an escape and rarely is. Bridges create their own linkage, because a deposit on the source chain and a withdrawal on the destination chain usually match on amount and timing within a narrow window. Analysts trace this correlation directly, and many bridges emit events that make the pairing explicit.
Cross-chain messaging and canonical bridge contracts are among the most heavily labeled infrastructure on every analytics platform.
A desk that fragments its flow across Ethereum, an L2, Solana, and TRON does not erase the graph. It hands the analyst a slightly larger one, and the same clustering heuristics apply on each chain.
Because most OTC settlement now clears in stablecoins, the properties of those tokens shape the leak. Major stablecoin transfers are fully visible on-chain, and issuer-level events add detail: mint and burn activity, and freeze or blacklist actions, are public and timestamped. On chains that support memo or reference fields, settlement metadata can leak counterparty context directly.
Round-number stablecoin amounts, common in OTC settlement, stand out against the noise of retail activity and make large legs easy to isolate. The settlement layer that made OTC efficient also made it exceptionally readable.
Consider a desk that settles a large client sell of a major asset for stablecoins. An analyst starts from a single seed, a settlement address surfaced when the client's treasury was labeled on an analytics platform.
Common-funding analysis ties that address to three others the desk funded from the same treasury, forming the initial cluster. Over the following weeks, the cluster settles repeatedly with two external clusters in consistent size bands, so the analyst maps two recurring counterparties.
Netting the cluster's flows shows the desk accumulating one stablecoin and shedding the asset, which points to a directional position. Twenty minutes after each large client fill, the cluster sends offsetting size to a labeled exchange deposit address, exposing both the hedge and its speed.
None of this required inside access. The desk published every piece, one settlement at a time, and the analyst assembled the book from the public record.

Most operational security measures raise the cost of analysis without removing the signal, and a counterparty buying edge will pay that cost. Fresh wallets look clean until common-funding analysis ties them to the same treasury.
Order splitting fragments a large trade, but the fragments still net to the original position, and correlated timing reunites them. Internal transfers between a desk's own wallets are trivially linkable and often draw the cluster graph for the analyst.
Moving to a new chain resets nothing, because the same heuristics apply everywhere and bridges create fresh linkage. Waiting between legs adds noise but not opacity.
The structural problem is that all of these tactics sit on top of a transparent settlement layer. They obscure the surface while the underlying record stays public. Institutions already sense this. Finery Markets found that around 40% of surveyed institutions now name OTC as their first-choice execution venue and route more than half of their trades off-screen, specifically to avoid signaling intent.
The irony is that off-screen execution followed by on-chain settlement re-exposes on the ledger exactly what the desk went off-screen to hide.
Settlement leakage converts directly into worse execution and lost commercial ground. Front-running is the sharpest edge: because pending transactions sit in a public mempool, searcher bots read intent before confirmation and reorder blocks to extract value, a dynamic that has drained hundreds of millions of dollars from on-chain traders and continues at scale in 2026.
A desk whose settlement telegraphs a large move pays for that visibility in slippage. Quote fading follows, as counterparties who can see a desk's inventory adjust pricing against it.
Adverse selection compounds over time, as the best-informed counterparties preferentially trade against a book they can read. Relationship risk sits underneath all of it, because a visible client list is a poachable client list. Each of these erodes the exact advantage an OTC desk is built to sell.
The exposure comes from settling in the clear, so the fix is to settle confidentially without leaving the chains, wallets, and stablecoins the desk already runs on. This is what Hinkal provides, and it is the only full-privacy multichain solution where the sender, the recipient, and the amount all stay private across EVM networks, Solana, and TRON.
Hinkal is a smart contract on public chains that gives a desk a private balance controlled by its existing wallet keys. Funds move into that balance, transact privately, and can move back out to any public address when needed. Every transaction is proven valid using zero-knowledge proofs, so it stays verifiable on-chain while participants and amounts remain hidden.
Because a relayer broadcasts the transaction, the desk's own wallet never appears as the origin. In a private-to-private settlement, the ledger shows no sender wallet and no recipient wallet, only the Hinkal smart contract and the relayer address, so no observer can determine who traded, with whom, or in what size.
In a public-to-public settlement, the deposit into Hinkal and the withdrawal out of it are cryptographically unlinkable, which severs the sender-recipient connection that clustering depends on.
This dismantles the workflow at its source. There is no seed to identify, no counterparty address to map, no net flow to sum into an inventory estimate, no timing correlation between a fill and its hedge, and no stable fingerprint to re-identify.
For desk operations, Hinkal Pay delivers confidential settlements and payouts across Solana, TRON, Ethereum, and major EVM networks. Hinkal Prime adds the enterprise control layer, with permissioned multi-user access, queued and reviewable payouts, batch payouts, and compliance controls on high-value transactions. Hinkal Integrations exposes the same protocol through an API and SDK, so privacy can be embedded beneath an existing desk stack, per transaction.
None of this requires migration, and Hinkal never holds the funds. The protocol has run in production for more than three and a half years, has processed over 500 million dollars in cumulative volume, and has completed six independent security audits.
Privacy that regulated desks can use has to mean opacity to the public ledger, not to auditors. Chainalysis KYT screens wallet addresses before execution, preventing high-risk funds from entering the smart contract, so compliance is enforced at the entry point.
Viewing keys give the desk selective disclosure: a key can be shared in full or in part, scoped to specific transactions or time ranges, with a regulator, an auditor, or a counterparty, without revealing anything on the public chain.
Downloadable transaction history is available out of the box. The desk controls exactly who sees its activity, disclosing to the parties entitled to it while staying invisible to the competitors and searchers who are not.

Hinkal lets an OTC desk settle at institutional scale while keeping its counterparties, sizes, and inventory confidential on the public chains it already operates on.
An OTC book is built from information the market is not supposed to have, yet public settlement hands that information to anyone reading the chain through a repeatable workflow: seed an address, cluster it into the desk, map the client graph, net the flows into an inventory, and fingerprint the behavior.
Confidential settlement removes the raw material that workflow depends on, while zero-knowledge verification, Chainalysis KYT screening, and viewing keys keep every transaction provable and auditable to the parties who should see it.
If your desk's edge depends on discretion, book a demo to see how Hinkal closes the leak without changing a single part of your existing flow.
Read Next
Counterparties reverse-engineer an OTC desk's book from on-chain settlement by running a repeatable workflow: they identify a seed address, cluster the desk's related wallets into a single entity, map the counterparties it repeatedly settles with, net its flows to estimate inventory and direction, and fingerprint its timing and behavior. Because settlement is public and permanent, each step feeds the next without any inside access.
The information that leaks when an OTC desk settles on a public blockchain falls into five categories: identity signals that attach activity to the desk, size signals that expose trade magnitude and inventory, timing signals that reveal urgency and hedging speed, relationship signals that expose the client roster, and strategy signals that emerge when the other four combine to reveal how the desk prices and manages risk.
Fresh wallets, order splitting, and bridges cannot reliably hide an OTC desk's flow, because they operate on top of a transparent settlement layer. Fresh wallets get tied together through common-funding analysis, split orders still net to the original position, and bridge deposits match their withdrawals on amount and timing. These tactics raise the cost of analysis without removing the underlying signal.
OTC settlement is more exposed than exchange trading because each bilateral leg is an individual on-chain event with a visible sender, recipient, amount, and timestamp, whereas trades that net inside a centralized exchange never touch the chain individually. The desk's most sensitive activity, its client settlements and hedges, becomes its most publicly readable activity.
Hinkal keeps OTC settlement private and compliant by giving the desk a private balance controlled by its existing wallet keys, hiding the sender, recipient, and amount while zero-knowledge proofs keep every transaction verifiable on public chains. Chainalysis KYT screens addresses before execution, and viewing keys provide scoped, revocable disclosure to regulators or auditors, so the desk stays private to the market and transparent to the parties entitled to see it.






















