Furthermore, if you are a client, how long are you willing to keep your money in private keys that you know CM also has? Even if you don't mistrust them, you still need to worry about the exact scenario that happened - they get busted and all their private keys get seized. So chances are those amounts leave the CM network of addresses pretty quickly, even if they don't get added up in a single address. So now all that combinatorial explosion drops down to a pretty tractable k-NN classification problem.
I would advise against making strong statements like "logically impossible" about things that seem to require a lot of very narrow conditions like perfect actor behavior and strong stationarity in order to be true.