Blockchain Analytics

 

 

How Blockchain Analytics Works — Entity Clustering

 

All transactions on public blockchains are visible to anyone with access to the blockchain data. Blockchain analytics firms build knowledge graphs by applying clustering heuristics — algorithmic techniques that identify groups of addresses likely controlled by the same entity. The most powerful heuristic for Bitcoin is co-spend analysis: when multiple inputs appear in the same transaction, they were likely all controlled by the same wallet (because signing all inputs requires access to each input's private key). Addresses that co-spend together are clustered into the same entity.

Over time, these clusters grow through additional heuristics: change address identification (the output that goes back to the sender), transaction graph tracing (following fund flows across chains of transactions), and — critically — ground truth labelling from exchange cooperation, court documents, law enforcement disclosures, and open-source intelligence. When a cluster of addresses is definitively identified as belonging to a specific exchange, darknet market, or ransomware operator, all addresses in that cluster are labelled accordingly, and any future transaction from those addresses carries the label.

 

Major Blockchain Analytics Providers and Their Specialisations

 

Provider

Headquarters

Primary Strength

Typical Gateway Use

Chainalysis

New York / Global

Largest attribution database; deepest law enforcement relationships

Wallet screening API; KYT (Know Your Transaction)

Elliptic

London / Global

Strong EU focus; privacy-preserving analytics options

Wallet screening; transaction monitoring

TRM Labs

San Francisco

Emerging markets coverage; strong DeFi analytics

Real-time screening; VASP-to-VASP risk assessment

Crystal (Bitfury)

EU / Global

European regulatory alignment; exchange analytics

KYC screening; exchange compliance

Merkle Science

Singapore / Global

Asia-Pacific specialisation; regulatory intelligence

APAC-focused gateway integrations

 

What Blockchain Analytics Can and Cannot Determine

 

Blockchain analytics is a powerful but probabilistic tool, and understanding its limitations prevents over-reliance on its outputs as definitive compliance determinations. Analytics can establish with high confidence: whether an address has directly received funds from a confirmed sanctioned wallet or exchange hack; what proportion of funds in a wallet's history can be traced to high-risk sources; and whether an address has interacted with known mixing services or privacy tools. These are evidence-based findings.

Analytics cannot establish with certainty: the identity of the person controlling a wallet; the intent behind transactions involving high-risk exposure (whether funds were received knowingly or through unwitting exposure); or whether intermediate addresses in a transaction chain are co-owned or genuinely separate parties. A business that received USDT payment from a customer whose wallet had 5% exposure to a mixing service that also received funds from a darknet market may have no relationship to the darknet market — the exposure may reflect several degrees of separation with multiple innocent intermediaries.

 

Privacy Coins and the Limits of Analytics

Monero (XMR), Zcash (ZEC with shielded transactions), and similar privacy-enhanced cryptocurrencies use cryptographic techniques — ring signatures, stealth addresses, zero-knowledge proofs — that conceal the sender, receiver, and amount of transactions on their blockchains. Standard blockchain analytics heuristics are largely ineffective against these networks: co-spend analysis fails when ring signatures obscure input relationships; address clustering is impossible when stealth addresses generate unique one-time addresses for each transaction.

As a result, most regulated crypto payment gateways do not support privacy coins for merchant payment acceptance, and blockchain analytics firms provide minimal risk coverage for these networks. Some jurisdictions — notably South Korea and Japan — have required exchanges to delist privacy coins, and FATF guidance implicitly discourages VASP acceptance of privacy coins by noting the AML compliance challenges they create. Gateways that accept privacy coins must apply compensating controls such as source-of-funds verification for all payments and enhanced transaction monitoring that cannot rely on blockchain analytics.

 

 

Compliance Note: This glossary entry is provided for general educational purposes only and does not constitute financial, investment, legal, or tax advice. Industry terminology may vary across jurisdictions and providers; definitions herein may not directly reflect the specific features, terms, or specifications of Finassets' services. For details on Finassets' offerings, please refer to official product documentation or contact our team directly.