When a Bitcoin wallet broadcasts a transaction to the Bitcoin network, it connects to peer nodes and propagates the transaction. The first node that receives a transaction can often infer that it came from the broadcaster's IP address with reasonable confidence, especially if the wallet connects to few peers. This IP-to-transaction linkage is separate from on-chain analysis and cannot be resolved by on-chain privacy techniques like CoinJoin alone.
Exchanges, blockchain explorers, and blockchain API services collect IP addresses of users who query transaction data. A user who visits a blockchain explorer to check their transaction status from their home IP creates a durable IP-to-address linkage in the explorer's logs. This linkage can be requested by law enforcement or obtained through data breaches.
Tor prevents both types of linkage. Transactions broadcast through Tor appear to the Bitcoin network as originating from a Tor exit node. Blockchain explorer queries made through Tor appear to the explorer as coming from a Tor exit node. Neither provides useful information for linking to the user's real IP address.