The call usually opens the same way. Someone has an address, a transaction hash, and a screenshot from a block explorer, and they want to know when we can serve the defendant. The chain feels like a confession — every transfer, permanently recorded, available to anyone who looks.
It is a remarkable evidentiary record. It is also frequently misunderstood, and the misunderstanding tends to surface at the worst possible moment: after a complaint has been filed, when opposing counsel starts asking how you got from an address to a person.
The distinction worth holding onto is simple. The blockchain is excellent evidence of movement. It is silent on identity.
What the chain actually gives you
On a public chain, the ledger of transfers between addresses is complete, timestamped, and effectively immutable. You can establish that a specific quantity of value left one address and arrived at another at a specific time, and you can follow that value forward across hops without asking anyone's permission or waiting on a subpoena.
That is a genuine advantage over traditional banking records. When I traced funds through correspondent banks, each hop meant a new institution, a new legal process, and weeks of waiting — and a foreign bank could simply decline. On-chain, the next hop is already visible. The trail may be complicated, but it is not gated.
So when someone asks whether the money can be followed, the answer for on-chain activity is usually yes. Following is the easy part.
Where attribution actually comes from
Addresses are pseudonymous. Nothing in the protocol binds one to a human being. Every attribution in a well-built report comes from somewhere off-chain, and the strength of the case depends almost entirely on the quality of those off-chain sources:
- Exchange and virtual asset service provider records. When funds reach a regulated exchange, that exchange generally holds identity documents, bank linkages, login IP addresses, and device information for the depositing account. This is the single most productive source of attribution, and it requires legal process.
- The victim's own records. Communications, wallet software, invoices, and payment instructions frequently identify the destination address and who supplied it.
- Device and communications evidence. Seed phrases, wallet applications, browser history, and messages recovered from devices tie a person to keys directly.
- Open-source material. Addresses posted publicly, reused across forums or marketplaces, or associated with known services and prior incidents.
Notice that none of these are on-chain. The chain gets you to the door of an exchange; a subpoena, a warrant, or a cooperative counterparty gets you through it.
The part that gets challenged: clustering
Tracing tools group addresses into clusters said to be controlled by a common entity. These groupings rest on heuristics — reasonable inferences drawn from transaction structure, such as the assumption that inputs jointly spent in a single transaction share an owner, or that a particular output is change returning to the sender.
These heuristics are useful and often correct. They are also inferences, and inference is exactly where a competent opposing expert will concentrate. A heuristic that holds across most ordinary transactions can fail in specific circumstances, and commercial tools do not always expose the reasoning behind a given grouping. Attribution labels attached to clusters may come from vendor research of varying quality and vintage.
An analysis that presents a cluster label with the same confidence as a transaction record has blurred two very different classes of evidence. That is a soft target.
Where the trail genuinely degrades
Some techniques meaningfully damage traceability. Mixing services, chain-hopping through bridges, conversion into privacy-focused assets, and layering through high-volume services can break continuity. Sometimes analysis can pick the funds up on the far side; sometimes it cannot, and the honest answer is that the trail ends here.
Clients are not well served by an examiner who never reaches that conclusion. A report claiming an unbroken chain through a mixer should invite hard questions about how each link was established.
What to ask your examiner
- Which conclusions are direct observations from the ledger, and which are inferences from clustering or attribution?
- What is the basis for each attribution — exchange records, victim documents, device evidence, open-source, or a vendor label?
- Can another analyst reproduce this from the same raw data?
- Where does the trail weaken, and what would strengthen it?
- What legal process is needed, and what are the relevant record-retention windows?
What holds up
Analyses that survive scrutiny share a few traits. They separate observation from inference explicitly, in the text and in the exhibits. They document the raw data, the tools, and the versions used, so the work is reproducible. They pursue the off-chain record early, because exchange logs are not retained indefinitely and delay closes doors. And they state the limits plainly rather than leaving them to be discovered on cross.
The strongest cases I have seen were not the ones with the most elaborate on-chain diagrams. They were the ones where the on-chain trail and the paper trail — bank records, KYC files, communications, devices — met and corroborated each other. The chain proved the movement. People proved the ownership.
If you are evaluating a matter involving digital assets, the useful early question is not whether the funds can be traced. It is what identity evidence exists at the point where those funds touched a regulated institution, and how quickly you can reach it.