Blockchain Analytics
Definition
The use of tools such as Chainalysis, Elliptic, or CipherTrace to trace cryptocurrency fund flows across a public ledger. Because most public blockchains record every transaction permanently, investigators can follow funds from a victim payment through mixing services to an exchange where identity information may be compelled by court order.
- Field
- Cryptocurrency and financial cybercrime investigation
- Example vendors
- Chainalysis, Elliptic, CipherTrace
- Relies on
- Permanent public ledger record
- Common endpoint
- Exchange compelled to disclose identity
Common questions
How do mixing services complicate blockchain analytics?+
A mixer pools funds from many users and redistributes them, breaking the simple one-to-one link between sender and receiver addresses, so analysts rely on clustering heuristics and timing patterns rather than a single direct transaction trail to keep following the funds.
Does blockchain analytics work the same way on every cryptocurrency?+
No, it works best on transparent ledgers like Bitcoin and Ethereum where every transaction is publicly visible; privacy-focused coins that obscure sender, receiver, or amount by design are much harder or effectively impossible to trace with the same tools.
What legal step is usually needed to convert a traced address into a real identity?+
Tracing alone only links addresses and transaction flows; identifying the person behind an address typically requires a court order or subpoena compelling an exchange that performed identity verification on that account to disclose its records.
Related terms
- Advance-Fee Fraud
- A scheme in which the victim is promised a large future payment in exchange for an upfront fee. Variants include the classic...
- Bulletproof Hosting
- Hosting providers, typically in jurisdictions with weak law enforcement cooperation, that explicitly or implicitly ignore takedown requests and abuse complaints. Dark web...
- Business Email Compromise (BEC)
- A fraud in which an attacker impersonates a trusted executive, finance counterpart, or supplier over email to authorise fraudulent wire transfers or...
- Card-Not-Present (CNP) Fraud
- Fraudulent use of payment card data in a transaction where the physical card is absent, typically an online or telephone purchase. The...
- Escrow Wallet
- A cryptocurrency address controlled by the marketplace that holds a buyer's payment until the buyer confirms receipt. Escrow wallets create an auditable...
- Money Mule
- A person who receives fraudulently obtained funds into their bank account and transfers them onward, taking a commission. Mules may be witting...
- Mutual Legal Assistance Treaty (MLAT)
- A bilateral or multilateral treaty under which signatory states agree to assist each other in gathering evidence for criminal investigations. MLATs define...
- Onion Service
- A Tor-based server reachable only through the Tor network via a .onion address derived from the service's public key. The routing protocol...
- Operational Security (OPSEC)
- The set of practices a threat actor uses to prevent adversaries from identifying them or their infrastructure. In dark web investigations, OPSEC...
- Phishing
- A mass deception attack delivered by email, SMS (smishing), or voice call (vishing) in which the attacker impersonates a trusted entity to...
Explained in these topics
- Dark Web Marketplaces and Criminal InfrastructureTechniques applied to public cryptocurrency ledgers to cluster addresses controlled by the same entity, trace fund flows between wallets, and link on-chain act...
- Online Fraud and Financial Cybercrime