
How Blockchain Analytics Works — Entity Clustering
All transactions on public blockchains are visible to anyone with access to the blockchain data. Blockchain analytics firms build knowledge graphs by applying clustering heuristics — algorithmic techniques that identify groups of addresses likely controlled by the same entity. The most powerful heuristic for Bitcoin is co-spend analysis: when multiple inputs appear in the same transaction, they were likely all controlled by the same wallet (because signing all inputs requires access to each input's private key). Addresses that co-spend together are clustered into the same entity.
Over time, these clusters grow through additional heuristics: change address identification (the output that goes back to the sender), transaction graph tracing (following fund flows across chains of transactions), and — critically — ground truth labelling from exchange cooperation, court documents, law enforcement disclosures, and open-source intelligence. When a cluster of addresses is definitively identified as belonging to a specific exchange, darknet market, or ransomware operator, all addresses in that cluster are labelled accordingly, and any future transaction from those addresses carries the label.
Major Blockchain Analytics Providers and Their Specialisations
|
Provider |
Headquarters |
Primary Strength |
Typical Gateway Use |
|
Chainalysis |
New York / Global |
Largest attribution database; deepest law enforcement relationships |
Wallet screening API; KYT (Know Your Transaction) |
|
Elliptic |
London / Global |
Strong EU focus; privacy-preserving analytics options |
Wallet screening; transaction monitoring |
|
TRM Labs |
San Francisco |
Emerging markets coverage; strong DeFi analytics |
Real-time screening; VASP-to-VASP risk assessment |
|
Crystal (Bitfury) |
EU / Global |
European regulatory alignment; exchange analytics |
KYC screening; exchange compliance |
|
Merkle Science |
Singapore / Global |
Asia-Pacific specialisation; regulatory intelligence |
APAC-focused gateway integrations |
What Blockchain Analytics Can and Cannot Determine
Blockchain analytics is a powerful but probabilistic tool, and understanding its limitations prevents over-reliance on its outputs as definitive compliance determinations. Analytics can establish with high confidence: whether an address has directly received funds from a confirmed sanctioned wallet or exchange hack; what proportion of funds in a wallet's history can be traced to high-risk sources; and whether an address has interacted with known mixing services or privacy tools. These are evidence-based findings.
Analytics cannot establish with certainty: the identity of the person controlling a wallet; the intent behind transactions involving high-risk exposure (whether funds were received knowingly or through unwitting exposure); or whether intermediate addresses in a transaction chain are co-owned or genuinely separate parties. A business that received USDT payment from a customer whose wallet had 5% exposure to a mixing service that also received funds from a darknet market may have no relationship to the darknet market — the exposure may reflect several degrees of separation with multiple innocent intermediaries.
Privacy Coins and the Limits of Analytics
Monero (XMR), Zcash (ZEC with shielded transactions), and similar privacy-enhanced cryptocurrencies use cryptographic techniques — ring signatures, stealth addresses, zero-knowledge proofs — that conceal the sender, receiver, and amount of transactions on their blockchains. Standard blockchain analytics heuristics are largely ineffective against these networks: co-spend analysis fails when ring signatures obscure input relationships; address clustering is impossible when stealth addresses generate unique one-time addresses for each transaction.
As a result, most regulated crypto payment gateways do not support privacy coins for merchant payment acceptance, and blockchain analytics firms provide minimal risk coverage for these networks. Some jurisdictions — notably South Korea and Japan — have required exchanges to delist privacy coins, and FATF guidance implicitly discourages VASP acceptance of privacy coins by noting the AML compliance challenges they create. Gateways that accept privacy coins must apply compensating controls such as source-of-funds verification for all payments and enhanced transaction monitoring that cannot rely on blockchain analytics.
Compliance Note: This glossary entry is provided for general educational purposes only and does not constitute financial, investment, legal, or tax advice. Industry terminology may vary across jurisdictions and providers; definitions herein may not directly reflect the specific features, terms, or specifications of Finassets' services. For details on Finassets' offerings, please refer to official product documentation or contact our team directly.