Skip to content

Glossary · Digital forensics

Blockchain analysis

Also called: Cryptocurrency tracing, Chain analysis, On-chain investigation

Blockchain analysis traces the movement of cryptocurrency across a public ledger and attributes addresses to real-world entities. The ledger itself is permanent and complete, so the hard part is never finding the transactions — it is establishing who controlled the addresses at each end.

Pseudonymous, not anonymous

A public blockchain records every transaction permanently and lets anyone read it. What it does not record is identity — addresses are strings, not names.

That combination is unusual and it favours investigators more than most people expect. In a conventional fraud, obtaining the transaction record requires subpoenas to multiple banks across multiple jurisdictions, each of which takes months. On-chain, the complete record is available immediately, in full, going back to the first transaction. The work is attribution, not discovery.

How attribution actually happens

Addresses become identifiable at the edges, where crypto meets the conventional financial system:

  • Exchanges and other regulated intermediaries hold know-your-customer records. A subpoena or MLAT request to an exchange that received traced funds is frequently the step that produces a name.
  • Clustering. Certain spending patterns reveal that several addresses are controlled by one party. This is inference from observable behaviour, and it is well established, but it is inference — its confidence varies by pattern and an honest analysis says which heuristic was applied.
  • Publicly posted addresses, on forums, ransom notes or social media.
  • Off-chain evidence from devices: wallet software, seed phrases, exchange account records, browser history.

The last category is where digital forensics and blockchain analysis meet, and it is usually the strongest link. A wallet file recovered from a suspect's laptop connects a person to an address far more directly than any on-chain heuristic.

Obfuscation and its limits

Mixers, tumblers, privacy coins, chain-hopping across bridges, and layering through hundreds of intermediate addresses are all used to break the trail.

They work to varying degrees. Volume-based mixing can often be partially unwound by timing and amount correlation. Privacy-focused protocols with cryptographic guarantees are genuinely resistant to on-chain tracing, and an analyst who claims otherwise is overstating. Chain-hopping typically leaves records at the bridge, which is itself an intermediary that may hold identifying data.

An honest opinion states where the trace is solid, where it rests on a heuristic, and where it stops.

Presenting it in court

The ledger data is verifiable by anyone, which is a considerable evidentiary advantage — an opposing expert can independently check every transaction cited. What is contestable is attribution, and that is where a challenge will focus.

A report should therefore separate the two clearly: the transaction path, which is a matter of record, and the identification of the parties, which is a matter of inference and corroborating evidence. Conflating them produces an opinion that looks stronger than it is and collapses under a question about which clustering assumption was used.

Where it matters commercially

Ransomware payment tracing, fraud and Ponzi recovery, asset tracing in divorce and judgment enforcement, sanctions compliance, and insolvency. In each, the practical value is not only knowing where funds went — it is identifying an intermediary within reach of a court, because tracing funds to an address nobody can compel produces knowledge rather than recovery.

From our work

Dealing with blockchain analysis in a live matter?

Our examiners and testifying experts work these questions for a living. Tell us what you're facing.

Reviewed by Law & Forensics. See our editorial standards.