How Blockchain Forensics Actually Works (Not the Movie Version)
Last reviewed Sep 8, 2026 · Reviewed by our CEH-certified investigation team

The two wrong assumptions people start with
Most people land on one of two opposite, equally wrong ideas about crypto tracing. The first: "It's on a public blockchain, so anyone can just look up who has my money." The second: "Crypto is anonymous, so it's basically gone." Neither is right. Blockchain transactions are permanently recorded and public — but a wallet address by itself doesn't tell you who controls it. Tracing is the work of connecting addresses to real-world identities and destinations, and that work is genuinely investigative, not a lookup.
What tracing actually is
Cryptocurrency tracing follows the movement of funds across one or more blockchains to understand where they went, who else might be involved, and where they currently sit (TRM Labs). It combines two kinds of information:
- On-chain data — the actual transaction history: which addresses sent and received funds, how much, and when.
- Off-chain intelligence — everything the blockchain itself doesn't tell you: which addresses belong to known exchanges, which have been flagged for prior fraud or sanctions, and (when a case reaches the right point) who an exchange's KYC records identify as the account holder.
Attribution to an actual person only happens through that second layer. The blockchain alone gives you a map of where money moved — it takes lawful off-chain data, usually obtained from a compliant exchange, to connect a wallet to an identity.
The core techniques
A few foundational heuristics do most of the real work in tracing Bitcoin-style transactions:
- Co-spending / multi-input clustering — when a transaction combines multiple input addresses, they're very likely controlled by the same entity, since spending from several addresses at once normally requires holding the private keys to all of them.
- Change address (shadow address) detection — many transactions send "change" back to a new address controlled by the sender; identifying which output is change versus payment lets investigators keep following the sender's own holdings forward.
- Wallet fingerprinting and temporal analysis — different wallet software has recognizable patterns (fee choices, output structuring, timing behavior) that help group addresses even without a direct on-chain link.
Applying these consistently builds a cluster — a set of addresses very likely controlled by one entity — rather than tracking a single address in isolation (AMLBot).
What makes a case easier or harder
- Fewer hops, faster reporting — funds that haven't moved through many wallets yet, reported quickly, are the most traceable.
- Which chain and asset — the ten blockchains we cover (Bitcoin, Ethereum, Tether, Tron, BNB Smart Chain, Solana, Polygon, Litecoin, Ripple, Avalanche) each have different transaction structures, but all leave a workable trail. Assets specifically engineered for untraceability behave very differently — we're upfront when a case involves one.
- Mixers and chain-hopping — services designed to obscure the trail by pooling funds from many sources, or moving value across chains through bridges, make tracing harder but not impossible; this is where clustering across mixer inputs/outputs and cross-chain bridge analysis becomes the actual investigative work, which is why our team specializes in multi-hop tracing rather than single-transaction lookups.
- Whether the trail reaches a compliant exchange — this is the real turning point in most cases. A wallet sitting outside any regulated platform can be identified and watched, but funds only become recoverable once they touch a point — usually an exchange — that can act on a legal request.
Where tracing ends and legal action begins
Tracing tells you where funds are and, ideally, who's likely holding them. It doesn't, by itself, get money back — that happens when an exchange freezes an account, a regulator acts on a complaint, or a court orders funds returned, and all three of those require a well-documented case, not just a diagram of wallet addresses. See our guide on getting an exchange to freeze scammer funds and on what makes forensic evidence court-admissible for what happens after the trace itself.
Frequently asked questions
If the blockchain is public, why do I need an investigator at all?+
Because a public ledger of addresses isn't the same as an identified person. Turning "this wallet received the funds" into "this is who controls it, and here's the jurisdiction it's reachable in" requires clustering analysis, off-chain intelligence, and — eventually — a legal request an exchange has to honor. That's specialized work most victims can't do themselves.
Can a trace fail completely?+
Yes, honestly — funds moved through certain privacy-focused assets, or held indefinitely in a non-custodial wallet with no exchange interaction, may never reach a recoverable point. We tell clients plainly when a specific trail looks like that, rather than promising an outcome we can't deliver.
How long does a trace like this take?+
Once your case file is prepared, the dual-track investigation stage — tracing the transaction while identifying the receiving merchant — typically runs 1 day to 1 week; see our full process timeline for every stage.
Do you use the same tools professional forensic firms use?+
Our certified investigators use blockchain analysis techniques and multi-hop tracing methodology consistent with industry practice, applied by a Certified Ethical Hacking (CEH) technical team — see our team page for how that work is structured.
Start with a free, no-obligation case review
A specialist will tell you honestly whether your case looks traceable before you spend anything — no recovery, no fee for that work.
Get a free case review