Blockchain transaction tracing and on-chain analysis
Analysis that shows where the value went.
Crypto transaction analysis for compliance teams, businesses, exchanges, insurers, lawyers, and researchers. We trace cryptocurrency transactions across wallets, bridges, swaps, and chains, and deliver a documented analysis you can act on: flow-of-funds diagrams, transaction schedules, and a written report that states its own limits.
If your crypto was stolen, you are on the wrong page
This page is about the analysis itself, bought by people who need to understand a flow of funds. If you are a victim of theft, fraud, or an investment scam and what you want is your money back, the work is the same tracing but the engagement is different: it is time-critical, it targets the off-ramp, and it is built around freezing a balance and supporting legal process. Start there instead.
Go to crypto asset recoveryWhat a Trace Actually Produces
A public blockchain records every transfer permanently, but the raw record is a list of hashes and amounts with no structure and no names. Tracing is the work of turning that into an ordered account: what left a given address, where it went at each hop, where it was converted or bridged, and where it came to rest. The deliverable is an analysis with reasoning attached, not a data export.
Three techniques carry most of the weight. Flow reconstruction follows value hop by hop and separates the funds in issue from unrelated balances that pass through the same addresses. Address clustering groups addresses that appear to be under common control. Entity attribution links those clusters to real services: exchanges, custodians, bridges, lending protocols, and known illicit infrastructure. The first is observation. The other two are inference, and we label them that way.
Screening Is Not Tracing
The two get sold interchangeably and they answer different questions. Most teams need both, at different moments.
Screening an address
An automated lookup against a risk database. It returns a score or a label based on what is already recorded about that address and its immediate neighbours. It runs in milliseconds, scales to every transaction you process, and is the right control at the point of onboarding or payment. What it cannot tell you is where the funds originated, how they got to the address, or whether a clean score reflects genuine history or merely an absence of coverage.
Tracing the flow
A human analysis of the actual transaction path, across hops, conversions, and chains, aimed at a specific question. It takes days rather than milliseconds and it is not something you run on everything. You commission it when a screening result needs an explanation, when the amount at stake justifies the work, or when you need a documented answer that will be read by a regulator, a board, a court, or a counterparty who will not accept a score.
Who Commissions a Trace
The common thread is a decision that depends on the answer: whether to onboard, to pay, to underwrite, to escalate, to publish, or to sue.
Counterparty and wallet due diligence
Before you take payment from a wallet, onboard a client, or close a deal, an analysis of where that wallet's funds came from and what it has interacted with. Useful when a screening score is clean but the volume, timing, or counterparties do not look ordinary.
Compliance and AML investigations
Alert escalation for exchanges, VASPs, and financial institutions. Where an automated flag needs a human answer, we reconstruct the flow behind it and document the conclusion for the file, whichever way it goes.
Internal fraud and misappropriation
Corporate treasury, custody, or payroll funds moved without authorisation. We separate legitimate movement from the transactions in issue using your internal records alongside the chain data.
Insurance and lending exposure
Underwriting and claims work where the question is the provenance of a holding or the plausibility of a stated loss. On-chain history is verifiable at source, which makes it unusually good evidence for both.
Litigation and enforcement support
Analysis instructed by lawyers to answer a defined question in a live matter: whether assets remain traceable, where they are held, and what the record supports. Presented so it can be exhibited later.
Research and investigative journalism
Structured analysis of protocol exploits, market manipulation, and illicit flows, with the underlying transaction data supplied so your own team or a fact-checker can verify each claim.
Clustering and Attribution, Stated Honestly
This is where on-chain analysis is strongest and where it is most often overstated. The distinction is worth understanding before you rely on anyone's output.
How clustering works
The core heuristic is co-spending: when several addresses are used as inputs to one transaction, one party almost certainly held all those keys. Change address identification extends the cluster further. Behavioural signals add to it, including fee settings, timing patterns, script types, and reuse of the same deposit infrastructure. Each of these is a probabilistic judgement. Co-spend logic is strong on Bitcoin and much weaker on account-based chains, deliberate avoidance defeats it, and a shared custodial wallet can produce a cluster spanning thousands of unrelated users. We record which heuristic supports each cluster and how much weight it bears.
Where attribution comes from
Naming a cluster requires something off-chain. The usual sources are known deposit addresses at exchanges and services, addresses named in sanctions listings and enforcement actions, published disclosures, contract deployments, and claims the owner has made publicly. None of that identifies an individual. It identifies a service, and the service knows its account holder even though we do not. That is the practical route to a real name: reach the venue, then use legal process. Where the data supports only an inference, the report says inference.
Following value across bridges, swaps, and chains
Value rarely stays on one chain. It leaves through a bridge, arrives as a wrapped asset somewhere else, passes through a decentralised exchange, and moves on. Each of those events breaks a naive trace, because the outgoing and incoming legs are separate records on separate ledgers with no shared identifier in the transaction itself. This is where a large share of traces quietly stop and get reported as dead ends.
They usually are not. Bridge contracts emit events, most bridging protocols carry a message identifier, and where neither is available the legs can be reconciled by timing and by amount net of fees and slippage. Swaps are handled the same way: the input asset, the pool, and the output asset are all on-chain. We continue the trace on the receiving chain and report the whole path as one flow rather than as unconnected fragments. It is slower than stopping at the boundary, and it is frequently the difference between an answer and a shrug.
How We Run a Trace
Scope agreed first. A trace without a defined question expands without limit and produces volume instead of findings.
Scope and starting points
We agree the question first, then the addresses, hashes, and date range that answer it. A trace without a defined question expands without limit and produces volume rather than findings.
Flow reconstruction
We follow value hop by hop from the starting points, separating the funds in issue from unrelated balances that pass through the same addresses, and recording every transaction relied on.
Clustering and attribution
We group addresses under apparent common control, identify services, exchanges, and contracts along the path, and record which heuristic or data source supports each identification.
Cross-chain continuation
Where funds bridge or swap, we match the outgoing and incoming legs by contract event, identifier, timing, and amount, then continue the trace on the receiving chain rather than closing the file.
Analysis and deliverables
We produce the written analysis, the flow-of-funds diagrams, and the transaction schedules, with limitations and open alternatives stated on the face of the report rather than left implicit.
What You Receive
Every finding is traceable back to a public transaction you can verify yourself. That is the standard we write to, whether the report ends up in a compliance file or an exhibit bundle.
Flow-of-funds diagrams
The path drawn as a graph, with amounts, dates, and named services on the edges. Built to be read by a compliance committee or a judge without a technical briefing first.
Transaction schedules
Every hop relied on, tabulated with hash, chain, timestamp, asset, and amount. Anyone can verify each row against a public block explorer, which is the point.
Written analysis
The findings in plain language, tied to the specific question asked, with the reasoning shown step by step rather than presented as a conclusion to be taken on trust.
Methodology statement
The tools, data providers, chains, and heuristics used, in enough detail that another competent analyst could repeat the work and reach the same result.
Chain of custody
How each item of evidence was obtained, when, by whom, and how it has been preserved since. Recorded from the start, because it cannot be reconstructed afterwards.
Limitations and assumptions
Where the trail could not be resolved, where an identification rests on inference, and where an alternative explanation remains open. Stated by us before anyone else states it.
Where the analysis is intended for proceedings, it is written to be exhibited and defended. See expert witness and court support for how a trace becomes evidence.
Mixers, privacy protocols, and where a trace legitimately ends
A mixer exists to break the link between a deposit and a withdrawal, and privacy chains conceal amounts and parties at the protocol level. When funds enter either, the trace usually ends. Partial results are sometimes available: unusual amounts, poor timing discipline, and repeated withdrawal patterns can support a probabilistic link, and a deposit into a sanctioned service is itself a finding worth recording. But a suspected link is not a traced path, and we will not present one as the other.
We also stop when continuing stops producing evidence. Saying a trail ended is a finding, and it is more useful than an invoice for another week of analysis that will reach the same place.
What Tracing Can and Cannot Establish
Worth agreeing before you commission anything, because the gap between the two columns is where on-chain analysis gets oversold.
A trace can establish
- That a specific amount moved between specific addresses at a recorded time
- The path value took across wallets, bridges, swaps, and chains
- That a set of addresses behaves as one controlled cluster, to a stated confidence
- That funds reached a named exchange, custodian, protocol, or sanctioned service
- That a stated position or disclosure is inconsistent with the on-chain record
- Where the trail ends, and precisely why it ends there
A trace cannot establish
- Who held the keys when a transaction was signed, without off-chain evidence
- The intention behind a transfer, or whether it was authorised
- A real-world identity from chain data alone — clustering is probabilistic, not proof
- What happened inside an exchange, where balances move off-chain
- A reliable path through a mixer or a privacy-preserving protocol
- Any obligation on anyone to freeze, return, or compensate — that needs legal process
Where a finding rests on inference rather than proof, we say so and explain what would close the gap. Usually that is exchange records obtained through legal process, or documents held by you.
Transaction Tracing FAQ
What is blockchain transaction tracing?
Tracing is the reconstruction of how value moved across a blockchain, starting from an address or a transaction hash and following the flow outward. Public chains record every transfer permanently, but the raw record is a list of hashes and amounts with no structure. Tracing turns that into an ordered account of what left an address, where it went at each hop, where it was converted or bridged, and where it came to rest. The output is an analysis, not a database export.
How is tracing different from screening an address?
Screening checks one address against a risk database and returns a score or a label. It is fast, automated, and shallow: it tells you what is already known about that address, and nothing about the funds themselves. Tracing follows the actual transaction path across hops, chains, and conversions to establish where value came from and where it went. Screening is a filter you run on everything. Tracing is what you do when the filter flags something, or when the answer matters enough to justify the work.
What is address clustering, and how reliable is it?
Clustering groups addresses that appear to be under common control. The main heuristics are co-spending, where several inputs signed into one transaction imply one key holder, and behavioural patterns such as change address selection, consistent fee settings, timing, and reuse of infrastructure. These are inferences, not proofs. Co-spend logic is strong on Bitcoin and much weaker on account-based chains. Heuristics can be defeated deliberately, and shared custodial wallets can produce a cluster that spans thousands of unrelated users. We state which heuristic supports each cluster and how confident we are in it.
Can you tell me who owns an address?
Sometimes, and only with qualification. Attribution comes from linking on-chain behaviour to off-chain information: known deposit addresses at exchanges and services, published or leaked address disclosures, addresses named in enforcement actions, contract deployments, and public claims by the owner. Where the funds reach a regulated venue, the venue knows the account holder even though we do not, which is the usual route to a real identity through legal process. Where attribution rests on inference, we say so and describe what would be needed to confirm it.
Can you follow funds across bridges, swaps, and different chains?
Yes, and it is the part of the work that most often decides whether a trace is useful. Value routinely leaves one chain through a bridge, arrives as a wrapped asset on another, and is swapped through a decentralised exchange before moving on. Each of those events breaks a naive trace, because the outgoing and incoming transactions are separate records on separate ledgers. We match them using bridge contract events, message identifiers, timing, and amount reconciliation net of fees. Many traces are abandoned at exactly this boundary and reported as a dead end when they are not one.
What happens when funds go through a mixer or a privacy coin?
Usually the trace ends there, and we say so rather than presenting a guess as a finding. A mixer is designed to break the link between deposit and withdrawal, and privacy-preserving chains hide amounts and parties at the protocol level. Partial results are sometimes available: unusual amounts, poor timing discipline, or reuse of the same withdrawal pattern can support a probabilistic link, and deposits into a sanctioned service are themselves a finding worth recording. But we distinguish clearly between a traced path and a suspected one, and we will not sell continued analysis past the point where it stops producing evidence.
What do I actually receive at the end of a trace?
A written analysis setting out the scope, the methodology, the data sources, the findings, and the limitations. Flow-of-funds diagrams showing the path visually at a level a non-technical reader can follow. Transaction schedules exhibiting every hop relied on, with hashes, timestamps, amounts, and chains, so that anyone can verify the underlying data independently. Where the analysis may be used in proceedings, a documented chain of custody over how each item of evidence was obtained and preserved.
What information do you need to start a trace?
At minimum one starting point: an address, a transaction hash, or an exchange deposit reference, plus the chain it sits on. Anything else narrows the work and reduces the cost: dates and amounts, the counterparty name if you have one, invoices or contracts, exchange statements, and the question you actually want answered. That last item matters more than people expect. "Is this counterparty exposed to sanctioned entities" and "where did these funds originate" are different analyses on the same data.
Which chains and assets do you cover?
Bitcoin, Ethereum and the major EVM networks, the principal non-EVM chains used to move value at scale, and the stablecoins and tokens issued across them. Coverage matters less than continuity: the practical test is whether an analysis can follow value through a bridge and a swap onto a chain it did not start on, and report it as one flow rather than several unconnected fragments.
More questions answered on our general FAQ.
Related Reading
Have an address and a question?
Send us the starting point and what you need to know. We will tell you what the chain data can answer, what it cannot, and what the analysis would involve.