Cryptocurrency Tracing: How Investigators Follow the Money On-Chain
Cryptocurrency tracing is the practice of following funds across a public blockchain, from one address to the next, until the money reaches a point where a real identity attaches to it. The ledger is permanent and readable by anyone, so the movement is never the hard part. The hard part is attribution: turning a pseudonymous wallet into a named person or company.
Key Takeaways
- Pseudonymous is not anonymous. Every transaction sits on a public ledger forever. Chainalysis estimated that illicit addresses received at least $154 billion in 2025, yet the illicit share of all crypto activity stayed below 1%, which is why the honest money and the dirty money share the same visible rails.
- Clustering does the heavy lifting. The common-input-ownership heuristic collapses thousands of addresses into a handful of actors you can reason about.
- The trail breaks at mixers, bridges and privacy coins. Each obscures a different thing, and each leaves a different residue an investigator can work with.
- Identity attaches at the ramp. Cashing out through a regulated exchange is the moment know-your-customer records enter the picture, and it is usually where a case is won.
- Stablecoins now carry most illicit value. Chainalysis reported they accounted for 84% of illicit transaction volume in 2025, so a modern trace is mostly a stablecoin trace across chains.
What Is Cryptocurrency Tracing?
Cryptocurrency tracing is following the movement of funds across a blockchain to reconstruct where value came from and where it went. It separates cleanly into two problems that beginners tend to blur. Tracing is the on-chain work of walking the transaction graph from address to address. Attribution is the off-chain work of connecting an address to a person, a company or a service. You can trace millions of dollars perfectly and still have no idea whose money it is.
That distinction organizes everything that follows. The blockchain gives you the trace for free, because it is a public record by design. Attribution is where investigative craft, legal process and identity correlation actually decide the case. If you are new to open source work generally, our primer on what OSINT is sets the frame, and the OSINT recon guide shows where a crypto trace sits inside a full engagement.
Why the Public Ledger Is Both a Gift and a Trap
A public blockchain records every transaction permanently, and anyone can read it without permission. For an investigator that is the gift: unlike a bank, no one has to hand over the records, and nothing can be quietly deleted after the fact. The trap is that the same permanence works against sloppy analysis, because a wrong attribution is also on the record and can be challenged years later.
The scale is worth stating plainly. In its 2026 Crypto Crime Report, Chainalysis estimated that illicit cryptocurrency addresses received at least $154 billion in 2025, a sharp rise on the firm's revised 2024 figure of $57.2 billion, with a 694% increase in value received by sanctioned entities driving much of the growth. Two numbers from that report change how you should trace. Stablecoins accounted for 84% of illicit transaction volume, so most traces now follow tokens like USDT and USDC rather than Bitcoin. And the illicit share of all attributed crypto activity remained below 1%, meaning the flows you care about are a thin thread running through enormous legitimate traffic.
Two Ledger Models: UTXO Versus Account
Before you trace anything, know which of two accounting models the chain uses, because it changes what a "transaction" even looks like. Bitcoin and its relatives use the UTXO model, where coins are discrete unspent outputs consumed and recreated with each spend. Ethereum and most smart-contract chains use the account model, closer to a bank balance that goes up and down.
| Aspect | UTXO model (Bitcoin) | Account model (Ethereum) |
|---|---|---|
| Unit of value | Discrete unspent outputs | A running balance per address |
| What a spend looks like | Many inputs combine into new outputs, plus change | A balance decrement and increment |
| Strongest clustering signal | Common-input-ownership across combined inputs | Behavioral patterns, contract interactions, deposit addresses |
| Change address confusion | Common; the change output looks like a payment | Rare; no change output concept |
| Typical assets | BTC, LTC, BCH | ETH, ERC-20 stablecoins, most tokens |
The practical consequence is that a Bitcoin trace leans hard on input clustering and on not mistaking a change address for a recipient, while an Ethereum or stablecoin trace leans on token transfer logs and on recognizing the deposit addresses that exchanges generate per user. Get the model wrong and you will read the same transaction two different, both incorrect, ways.
The Core Tracing Techniques
On-chain tracing is a small set of techniques applied with discipline. None of them is magic, and each has a failure mode that a careful analyst states out loud rather than hiding. The table below is the working core.
| Technique | What it does | Where it fails |
|---|---|---|
| Common-input-ownership clustering | Groups addresses spent together as one wallet | CoinJoin and collaborative transactions deliberately break the assumption |
| Change-address detection | Separates the payment from the change returning to the sender | Wallets that avoid address reuse make change harder to spot |
| Transaction graph analysis | Maps the flow of value across hops to find sources and sinks | Peeling chains and high fan-out inflate the graph into noise |
| Amount and timing correlation | Matches a known input to a likely output by value and time | Uniform denominations and delays defeat naive matching |
| Known-entity tagging | Labels addresses belonging to exchanges, mixers or services | Labels age; a service can move addresses or change behavior |
The oldest and still most powerful of these is clustering. The academic foundation is the 2013 study A Fistful of Bitcoins by Meiklejohn and colleagues, which showed that clustering plus a handful of real-world tags could de-anonymize large swathes of Bitcoin activity. Everything in commercial blockchain analytics builds on that idea: reduce the address soup to entities, tag the entities you can identify, and let the graph between them tell the story.
Where the Trail Goes Dark: Mixers, Bridges, Privacy Coins
Three tools exist specifically to break tracing, and confusing them wastes effort. A mixer pools funds to sever the link between deposit and withdrawal. A cross-chain bridge moves value to another blockchain, so the trail continues on a ledger you were not watching. A privacy coin hides amounts and parties at the protocol level. Each obscures a different layer.
| Obfuscation | What it hides | Residue an investigator can use |
|---|---|---|
| Mixer or tumbler | The link between the deposit and the withdrawal | Timing, round amounts, poor anonymity-set size, reused withdrawal patterns |
| CoinJoin | Which input paid which output in a shared transaction | Fixed denominations, subsequent consolidation of "clean" coins |
| Cross-chain bridge | Continuity, by hopping to another chain | Bridge deposit and mint events pair up; the amount survives the hop |
| Privacy coin (Monero, Zcash) | Amounts and parties by protocol design | Entry and exit through transparent chains, exchange records, timing |
The lesson practitioners repeat is that people rarely stay disciplined all the way through. A mixer only helps if the withdrawal is not immediately reconsolidated with tagged funds. A bridge only helps if you were not also watching the destination chain, and modern analytics watch many chains at once. Privacy coins are the genuine hard stop, but even there the money usually has to enter from and exit to a transparent chain, and those two moments are visible. For the messier human sources that sit around these tools, our guide to dark web OSINT covers the forums and markets where the withdrawal addresses often surface first.
The Attribution Moment: On-Ramps and Off-Ramps
The single most important idea in crypto investigation is that value almost always has to touch the regulated world to become useful. To buy crypto with a card or turn it back into spendable cash, funds pass through an on-ramp or off-ramp, typically a centralized exchange that runs know-your-customer checks and retains records reachable by legal process. That deposit or withdrawal is the attribution moment.
This is why experienced investigators trace toward the ramps rather than obsessing over every intermediate hop. You do not need to name every wallet in a peeling chain. You need to reach the exchange deposit address, then obtain the account records through the proper channel. The Travel Rule, drawn from FATF Recommendation 16 and implemented by regulators worldwide, requires virtual asset service providers to collect and pass on originator and beneficiary information above set thresholds, which is precisely the data that closes the gap.
Attribution also arrives from outside the chain entirely, and often earlier. An exchange account was opened with an email. That email was reused on a forum, a breached service, or a social profile. A username repeats across platforms. A phone number ties three accounts together. This identifier layer is ordinary OSINT, and it frequently names the suspect before the on-chain graph does. Our walkthrough of an OSINT investigation from a phone number shows the same correlation logic applied to a different starting identifier.
trader_payouts@example.com
- Linked accountsexchange, two forums, one social profile
- Reused usernamesame stem found on 3 platforms
- Breach exposureappears in known leaks
- Infostealer logscredentials seen in stealer logs
- Phone correlationnumber links to a second account
- Next steprequest records for the named account
Making the Trace Hold Up: Evidence and Chain of Custody
A trace that cannot survive challenge is a story, not evidence. Because the blockchain is immutable, the raw data is unusually strong, but the way you capture and present it decides whether it holds. Record the exact block height and timestamp for each transaction you rely on, hash the exported data, and document the version and settings of any analytics tool that produced a cluster or a label, because a label is an inference and opposing counsel will treat it as one.
The recurring mistake is presenting a vendor's automated cluster as fact. A cluster is a probabilistic claim built on heuristics that can fail against CoinJoin or a custom wallet. State the heuristic, state its confidence, and keep the underlying transactions so anyone can reproduce the path. Our guide to digital evidence preservation covers timestamping, hashing and reproducibility in detail, and the discipline transfers directly to on-chain work.
Is Crypto Tracing Legal?
Reading the public blockchain is legal, because it is open data published for anyone to inspect. The legal questions attach to the steps around it. Obtaining subscriber and transaction records from an exchange requires proper legal process, and skipping that taints the result. Processing what you gather is regulated too: if the subject is a person, the data is personal data, governed in the EU by GDPR and in Brazil by the LGPD, Law 13.709/2018, with purpose limitation applying even to public information.
There is also the question of how you obtain identity data off-chain. Reading a public forum post that reveals a withdrawal address is one thing; deceiving someone into disclosing account details is another. The line between passive collection and active pretexting matters as much here as anywhere, and our overviews of whether OSINT is legal and, for the United States specifically, OSINT law in the US, work through the boundaries you are operating inside.
Attribution First, With espectrosint
Since crypto cases are won at attribution, the fastest progress usually comes from the identity layer rather than the graph. espectrosint is built for that layer: it takes an identifier and correlates it across 200+ public sources plus a proprietary breach and infostealer-log dataset, in a single search. It does not run blockchain analytics, and it is honest about that scope; what it does is name the person behind the account.
In a crypto workflow that looks like this:
- Recover an email, username or phone number attached to the on-ramp or off-ramp account.
- Run it to find linked accounts and social presence across platforms without touching the subject.
- Check breach and infostealer exposure, which often reveals the same person's other credentials and services.
- Pivot to name, domain or IP when the trail turns corporate rather than personal.
- Read the connection graph and timeline to see which identities cluster together.
- Export to PDF, CSV or JSON with dates so the attribution stays traceable in the case file.
The platform also accepts a blockchain address as a search input, so a known wallet can be a starting identifier alongside the more productive email and username pivots. For fraud teams building a broader stack, our roundup of the best OSINT tools for fraud investigation places identity correlation next to the on-chain analytics it complements, and our note on OSINT for KYC and compliance covers the same data in a regulated setting.
Name the person behind the wallet
espectrosint correlates email, phone, username, name, domain, IP and blockchain address across public sources and a breach and infostealer dataset, in one search with a connection graph and case-ready export.
Run a search See pricingFrequently Asked Questions
Can Bitcoin transactions really be traced?
Yes. Bitcoin is pseudonymous, not anonymous. Every transaction is recorded on a public ledger that anyone can read, so the movement of funds between addresses is permanent and visible. What is hidden is the link between an address and a person. Tracing follows the money across addresses; attribution is the separate step that ties an address to a real identity, and it usually happens at a regulated exchange.
What is address clustering in crypto tracing?
Address clustering groups many blockchain addresses that are probably controlled by the same entity. The best known method is the common-input-ownership heuristic: when several addresses are spent together as inputs to one transaction, they are almost always held by one wallet. Clustering turns thousands of scattered addresses into a smaller number of actors an investigator can actually reason about.
Do mixers and privacy coins make tracing impossible?
They make it harder, not always impossible. Mixers and cross-chain bridges break the direct link between input and output, and privacy coins like Monero hide amounts and parties by design. Investigators counter with timing analysis, amount correlation, off-chain data and the errors people make around the edges of these tools. But a clean privacy-coin path with disciplined operational security can end a trail.
How does an anonymous wallet become a named person?
At the on-ramp or off-ramp. To turn crypto into cash or buy it with a card, funds usually pass through a regulated exchange that performs know-your-customer checks and keeps records reachable by legal process. That deposit or withdrawal is the attribution moment. The identity often surfaces even earlier through reused emails, usernames and phone numbers linked to the exchange account.
Is cryptocurrency tracing legal?
Reading the public blockchain is legal; it is open data by design. The legal questions attach to what you do next: obtaining subscriber records from an exchange requires proper legal process, and processing the resulting personal data falls under privacy law such as GDPR in the EU or the LGPD in Brazil. Tracing for evidence also has to preserve chain of custody to survive challenge.
Conclusion
Crypto tracing rewards a clear separation of two jobs. The blockchain hands you the trace, permanent and public, and it is generous with the movement of money. It tells you almost nothing about identity, and that silence is where the real work lives. Follow the funds toward the ramps, treat every cluster as a hypothesis with a stated confidence, and reach for the identity layer early, because the person is usually named at an exchange or through a reused identifier long before the last hop is mapped.
So run the case in that order. Map the flow to the nearest regulated ramp, then pivot on the email, username or phone number attached to it. For the capture discipline that makes the result stand up, continue with digital evidence preservation, and for where this fits in a full investigation, continue with the OSINT recon guide.