ETH Zurich and Anthropic Study Finds LLMs Can Unmask Anonymous Accounts for a Few Dollars Each
Key Takeaways
- •The pipeline correctly identified 226 of 338 Hacker News users, roughly 67%, at 90% precision using only publicly accessible posts.
- •The entire benchmark cost under $2,000, averaging about $1 to $4 per identified profile, highlighting how inexpensive large-scale deanonymization has become.
- •The system runs in four stages—Extract, Search, Reason, and Calibrate—and deliberately abstains when uncertain to reduce false positives.
- •The researchers did not release the code, prompts, or any real identities, and the study passed review by ETH Zurich's ethics board before publication.
- •The authors conclude that the practical obscurity shielding pseudonymous accounts no longer holds, citing risks to journalists, activists, advertisers' targets, and crypto users.

Researchers at ETH Zurich, the AI safety group MATS, and Anthropic have built an automated LLM pipeline capable of connecting pseudonymous online posts to real-world identities. In testing, the system identified hundreds of Hacker News users at 90% precision, at a cost as low as $1 per user.
The study, "Large-scale online deanonymization with LLMs", was first posted to arXiv on February 18 and later appeared in the proceedings of the 35th USENIX Security Symposium, a leading academic venue for security research. It drew renewed attention this week after circulating on X and Reddit.
The paper's authors are Simon Lermen, Daniel Paleka, Joshua Swanson, Michael Aerni, Nicholas Carlini, and Florian Tramèr. Carlini is an employee of Anthropic, the company behind the Claude models, while the others are affiliated with ETH Zurich and MATS.
Four stages narrow a pool of 89,000 candidates
The attack requires no stolen data or hacked servers. The agent works only with information anyone can already view publicly, performing the work of a patient investigator more cheaply and faster.
The researchers divided the process into four stages: Extract, Search, Reason, and Calibrate. First, a language model pulls identity clues from raw posts — hints of a job, a location, or a characteristic way of phrasing. Semantic embeddings then narrow a pool of up to 89,000 candidates down to a shortlist. A reasoning model grades the strongest matches and decides whether two accounts belong to the same person. The Calibrate stage causes the pipeline to abstain when it is not certain, reducing false positives.
The pipeline runs on off-the-shelf tools: web search, embeddings, and models such as GPT-5.2. Earlier deanonymization attacks, such as the 2008 re-identification of the anonymized Netflix ratings, relied on structured data. That episode demonstrated how supposedly anonymous records could be unmasked by cross-referencing outside information — a data-heavy precursor to the automated, low-cost approach described here.
226 of 338 Hacker News users identified at 90% precision
To evaluate the method without risking real people, the team assembled a benchmark of 338 Hacker News users — the technology forum run by startup accelerator Y Combinator — whose bios pointed to a LinkedIn page, giving each a known ground-truth identity. Given only each user's comments and submissions, the agent correctly identified 226 — about 67% — at 90% precision. It made 25 incorrect calls and abstained on 86 accounts. Classical non-LLM baselines scored close to zero in the paper's larger matching tests.
The experiments cost less than $2,000 in total, or roughly $1 to $4 per profile.
Two additional datasets tested the approach further: one matched Reddit users across two different movie communities, and another reconstructed a single Reddit history by splitting it into two time periods. On both, the LLM methods outperformed older techniques by a large margin.
Warnings and safeguards
The authors point to a range of potential abuses: governments targeting journalists or activists, companies building ever-sharper advertising profiles, and scammers compiling dossiers for social-engineering pitches.
"The combination is often a unique fingerprint," Lermen wrote in a February 24 blog post. He added that if a team of smart investigators could identify someone from their posts, LLM agents likely can too — and the cost is only going down.
The researchers did not release the code, the prompts, or any real identities surfaced by the system. The study was reviewed by the ethics board of ETH Zurich before publication.
"The practical obscurity protecting pseudonymous users online no longer holds," the paper concludes. That kind of obscurity is what most pseudonymous accounts — common across developer forums and crypto communities alike — have rested on until now.
The renewed attention to the study came a day after SEC Commissioner Hester Peirce cautioned against bulk KYC — know-your-customer, the identity checks financial firms are required to run on their users — data collection, saying the approach amounts to "building bigger and bigger data haystacks." Recent breaches at Revolut and at vendors tied to hardware-wallet maker Trezor have fueled fears of "wrench attacks," in which someone who learns that a person holds crypto shows up in person.