What is blockchain forensics?

Blockchain forensics is the practice of tracing funds across public blockchains, attributing wallet addresses to real-world entities and packaging the result as evidence for enforcement action or compliance decisions.
Law enforcement agencies and government analysts use blockchain forensics to investigate illicit activity on blockchains, which can include state-sponsored theft, sanctions evasion, illicit marketplaces and more. Compliance teams use it to resolve escalations and file suspicious activity reports (SARs).
Blockchain forensics is distinct from cryptoasset screening. Screening is the automated check that runs on addresses and transactions as they arrive, flagging anything carrying known risk. Forensics is analyst-led. It takes a single case and reconstructs what happened, where the funds came from, where they went and what that means for a decision.
How does blockchain forensics work?
Blockchain forensics splits across two parties: A blockchain analytics provider builds and maintains the on-chain dataset, and the investigator or compliance analyst who works on top of that dataset. Knowing which steps belong to which party will help understand what blockchain forensics actually involves.
Step 1: Identify the starting point
Every investigation begins with an on-chain data point. For law enforcement, the starting point might be a payment address supplied by a ransomware victim or negotiator, wallet data recovered from a seized device, an address named in a victim report or a tip-off from a partner agency.
For compliance teams, the trigger is more often internal: an alert raised during routine screening that an analyst has escalated, meaning the case starts from a risk signal rather than a known crime.
What happens next depends on what you’re trying to solve. You can trace funds backwards to establish where they came from, which is what a compliance team needs to assess a deposit. You can trace forwards to establish where funds went, which is what an investigation needs to locate assets for seizure or identify a cash-out point.
Scoping matters here, because the transaction graph is effectively unbounded. An investigator has to decide at the outset what question the investigation wants to answer and how far from the starting point it needs to go for that.
Step 2: Work from attributed data
Blockchain forensics depends on knowing which addresses belong to whom. That knowledge is not inherently on the blockchain. It has to be built, and that’s what blockchain analytics providers like Elliptic do continuously. They group addresses that share an owner, a process called address clustering, and attach labels identifying those owners, a process called attribution.
Some of that clustering and attribution comes from investigators at the analytics provider confirming addresses directly, by transacting with a service or documenting the addresses it publishes. Some comes from scripts recognizing known patterns in how wallets behave.
The result is a version of the blockchain in which addresses and transactions are clustered and attributed. Investigators and analysts then use that to investigate cases, which is why the quality of a provider’s data and intelligence is so important.
Step 3: Trace the flow of funds
With addresses and transactions labeled and clustered, an investigator can follow funds and identify which attributed entities it moved through along the way. This is harder than it seems, because funds rarely move in clean separate parcels. A single transaction can draw money from several sources and pay it out to several destinations at once.
Tracing therefore involves a methodological choice. For example, once stolen funds are pooled with unrelated funds, a rule has to determine which onward payments still carry the traced funds, and there is more than one reasonable rule. That rule is what an investigator is relying on at every hop where funds mix. It is why the same trace has to be reproducible: another analyst following the same path under the same rule should arrive at the same conclusion.
Distance matters as well. Funds one transfer away from a sanctioned exchange mean something quite different from funds eight transfers away, and compliance teams set their own thresholds for how far out they treat exposure as material.
Step 4: Follow the funds across blockchains
Moving money between blockchains has become a common laundering technique. Services exist specifically to make it easy: stolen Bitcoin arrives at a swap service and leaves as a stablecoin on a different network. From there a bridge moves it somewhere else again. Sophisticated operations repeat this many times in quick succession, across half a dozen networks.
They do so to make the trail significantly harder to follow. When funds enter a service on one blockchain and leave on another, there is often no transparent link between the two events. Each blockchain holds a complete record of its own half and knows nothing of the other. An investigator watching the first one sees money arrive at a service, but does not see how it exists.
This is again where blockchain analytics steps in. Elliptic developed Holistic technology to automatically follow funds across blockchains. A trail that crosses several blockchains can be followed as a single continuous path versus a path that has to be reconstructed with every chain-hop.

The multi-stage route taken by a portion of the Central Bank of Iran funds, across several blockchains.
Step 5: Get the information held off-chain
Attribution identifies whoever controls an address. But sometimes that’s a centralized exchange holding funds for millions of customers, not the individual you’re after. Attributions can also be collective rather than individual, naming a ransomware operation or a darknet market when the investigation wants a particular affiliate or the person running it. And some addresses are not attributed at all, as is often the case with unhosted wallets.
To continue from those points, an investigator needs off-chain information. An exchange operating under anti-money laundering rules has to identify its customers, so it holds names, documents and often bank details that appear nowhere on the blockchain.
The investigator looks for the point where funds entered one of those exchanges, because illicit actors may use them to turn cryptoassets into fiat, in which case the exchange could have information about their identity. Even a self-custody wallet may touch a regulated business eventually, and that transaction becomes the link investigators look for.
Access to those records then requires a legal process. This can be a court order or subpoena when it falls under the investigating agency's own jurisdiction, a request through a mutual legal assistance treaty (MLAT) when it does not. Many exchanges also cooperate voluntarily, within what their data protection obligations permit.
But the business may sit somewhere that will not assist or may not collect identity information in the first place (which is why launderers prefer such services). Even in those cases, the investigation still has a documented trail ending at an attributed destination, which may be sufficient to support a seizure, a sanctions designation or a disruption operation with no name attached.
Step 6: Package the evidence
The final step turns a completed trace into something a court, a regulator or an auditor will accept. Reproducibility is the test that governs it. Another analyst given the same data should be able to follow the same path and reach the same conclusion, which means the reasoning has to be recorded as the work: which addresses were followed, why each attribution was relied on and where the trail was judged to end.
For law enforcement, the output is built for a case file: visualizations tracking funds from a starting address to a cash-out point, attributions documented with the evidence behind them and transaction trails complete enough to serve as exhibits. The sophistication of the analysis matters, but so does the ability for a non-specialist to follow it.
For compliance teams, the output is an audit trail and potentially a SAR filing. A SAR has to show why the analyst reached a particular view. The person who signs the filing is usually not the person who ran the trace, so the record also has to make sense to somebody reading it cold.
Preservation matters as well. Services shut down and evidence available during an investigation may be gone by the time a case reaches court years later. Screenshots, links to sources and timestamps captured at the time are what survive. It is also why the note made at the start of the investigation matters: it establishes what was known when a decision was taken, rather than what the dataset shows today.
What makes a blockchain forensic solution effective?
Every step above depends on the dataset an investigator or analyst relies on, which is why choosing a blockchain analytics vendor is both important and hard. You need to understand how they source and validate their threat intelligence, how quickly they add sanctions designations, what the platform automatically produces that’s valuable for an auditor, and more.
This is why we created our guide on 20 questions to ask a blockchain analytics provider, with strong answers and red flags for each question. Whether you are running a first procurement or reviewing a provider you already use, it is the list we would want to be held to.
