Global financial integrity is fundamentally challenged by cryptocurrency mixers such as Tornado Cash, which facilitate billions in illicit fund flows. Low detection rates, reliance on labeled training data that is unavailable for novel attacks, and failure to analyze temporal coordination patterns are all impediments to the effectiveness of existing forensic tools. We introduce CONSENSUS, a self-supervised heterogeneous ensemble framework that addresses the challenge of attribution in mixed transaction streams. Our system requires no pre-existing labels, and it generates supervision signals directly from on-chain behavioral patterns. It synthesizes evidence by orchestrating nine analytical modalities—including deterministic clustering, behavioral analysis, and multiple graph neural network architectures—through a formal consensus mechanism. This multi-modal approach produces transparent, auditable risk scores from a 111-dimensional behavioral fingerprint. We validated the framework on five major decentralized finance (DeFi) exploits, including the Ronin Bridge and Poly Network hacks. Using raw transaction data, it detected all known primary attackers at 100% accuracy without training. Crucially, the framework's self-supervised components successfully identified the novel attack pattern of the Poly Network exploit, thereby demonstrating robustness to out-of-distribution threats that defeat supervised methods. By providing a transparent, zero-label solution, CONSENSUS establishes a new paradigm for flexible, effective risk profiling and forensic investigation.
Rao et al. (2026) studied this question.