Blockchain Analysis
Definition
The forensic examination of a cryptocurrency's public transaction ledger to trace the flow of funds between addresses, cluster addresses controlled by the same entity, and identify cash-out points at regulated exchanges. Used extensively in dark web investigations to link on-chain activity to real-world identities.
- Input
- Public cryptocurrency transaction ledger
- Core techniques
- Address clustering, fund-flow tracing, exchange cash-out identification
- Common use
- Linking dark web/on-chain activity to real-world identities
- Cannot do alone
- Attribute an address to a person without an off-chain identity link
Common questions
How does blockchain analysis identify addresses controlled by the same entity?+
Heuristics such as common-input-ownership clustering (addresses spent together in one transaction likely share a controller) and change-address detection group related addresses into wallets. Combined across many transactions, this builds a picture of an entity's holdings even though the ledger itself never names the owner.
Why is a regulated exchange often the endpoint of a blockchain trace?+
Cryptocurrency itself is pseudonymous, but converting it to fiat currency or withdrawing to a bank typically requires an exchange account subject to KYC identity verification. Once traced funds reach such an exchange's deposit address, investigators can request account records to connect the on-chain trail to a real identity.
Related terms
- Exit Node
- The third relay in a Tor circuit, which forwards decrypted traffic to the public internet destination. The destination server sees the exit...
- I2P (Invisible Internet Project)
- A peer-to-peer anonymity network that routes traffic through a distributed mesh of volunteer nodes using unidirectional tunnels. Unlike Tor, I2P is primarily...
- Onion Routing
- A technique in which a message is encrypted in multiple layers, one per relay node, so that each relay decrypts only its...
- Onion Service (Hidden Service)
- A server reachable through Tor using a .onion address derived from its public key. The server's real IP address is never exposed...
- Traffic Correlation Attack
- A deanonymisation technique that compares timing patterns and traffic volume at the entry point of a Tor circuit and at the destination,...