Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› How should investigators move beyond simple wallet tracing…
Threats, Abuse & Incident Response

How should investigators move beyond simple wallet tracing when a criminal network uses multiple blockchain services and exchange deposit addresses?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Threats, Abuse & Incident Response

Investigators should combine fund tracing with criteria based transaction searches that reflect how the criminal service actually operates. That means identifying payment patterns, comparing matched transaction amounts across chains, and expanding from known addresses to linked wallets and deposit accounts. This approach helps expose infrastructure that ordinary follow the money workflows can miss, especially when actors fragment activity across exchanges, chains, and storage wallets.

Why wallet tracing needs to become service tracing

Once a criminal network uses exchange deposit addresses, bridge hops, and multiple chains, the useful question is no longer only where a coin last moved. Investigators need to ask how the service operates, because the same actor may split value across accounts, reuse deposit infrastructure, and create transaction patterns that only become visible when you search by behaviour, not by a single address.

That shift matters because deposit addresses often represent an operating layer rather than a final destination. A criteria-based search can expose repeated amount ranges, timing rhythms, and chain-to-chain handoffs that link otherwise separate wallets into one operational cluster. In practice, this is how investigators move from a single payment trail to an infrastructure view.

It also changes how evidence is interpreted. A lone transfer can be misleading if the network deliberately fragments funds, but repeated matches across assets and services can show coordinated control. The stronger the pattern consistency across addresses, the more likely the activity reflects a common service workflow rather than unrelated user behaviour.

How criteria-based transaction searches expand the investigative surface

Criteria-based searching starts with the behaviour the criminal service cannot easily hide, such as fixed deposit thresholds, mirrored transfer amounts, or recurring exchange-facing patterns. Investigators then expand from known seed addresses to wallets and deposit accounts that fit those criteria, rather than waiting for every hop to be linked manually.

This works best when the search criteria are derived from the service model itself. If a network routinely routes funds from customer-facing wallets into exchange deposits, the investigator should look for amount matching, burst timing, and repeated cross-chain conversions that appear in the same operational window. The goal is to identify the service’s transaction grammar, not merely its next wallet.

For this kind of analysis, adversary tradecraft mapping helps frame the movement layer more clearly. MITRE ATT&CK Enterprise Matrix is useful here because it reinforces the broader problem: hostile networks often combine credential access, lateral movement, and operational staging rather than relying on one obvious path. That mindset keeps investigators from overfitting to a single address lineage.

What good investigative workflow looks like in multi-service crypto cases

A practical workflow usually begins with a small set of confirmed addresses, then branches into cluster expansion, transaction-amount matching, and service-level hypothesis testing. Investigators should preserve the logic of each expansion step so they can explain why a linked wallet or deposit account belongs in the same case set.

Two additional checks are often decisive. First, compare transfers across chains and services to see whether the same values recur after fees or conversion steps, because matching amounts can survive fragmentation when the actor is operationally consistent. Second, validate whether the deposit address behaves like an endpoint or a relay, since exchange infrastructure can mask the relationship between sender and final holder.

If the case involves repeated use of deposit addresses or third-party services, the analytic focus should stay on operational patterning, not just asset custody. That is where the search becomes more than tracing, and starts becoming attribution support for the broader network.

Risk and Threat Considerations

Criminal networks benefit from fragmented on-chain activity because it weakens simple follow-the-money methods and increases the chance that investigators stop at the first exchange deposit address. The more services and chains they use, the more likely they are to hide the controlling relationship behind ordinary-looking transfer patterns.

Failure mechanism: Investigators rely on address lineage alone, while the actor distributes value through recurring amounts, exchange hops, and cross-chain movement that only become visible through criteria-based searching and service-level clustering.

Impact: Related wallets can remain unlinked, supporting infrastructure can be missed, and the case may understate the size or coordination of the criminal network.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK provides the primary governance reference for this topic.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTactic and Technique Matrix — Enterprise MatrixMaps adversary movement and staging patterns behind multi-service crypto activity.
Recommendation — Map observed transaction-stage behavior to ATT&CK-style adversary patterns and hunt for coordinated staging.

Practitioner Guidance

What to prioritise: Build your first search criteria around behaviour the service must repeat, such as transfer amounts, timing windows, deposit patterns, and cross-chain conversion signatures. Those patterns are more stable than any one wallet.

What to verify: Before treating a wallet as linked, confirm that the same pattern appears across multiple transactions and, where possible, across multiple services. Single-point matches are weak evidence when the actor is deliberately fragmenting activity.

Practitioner takeaway: The key move is to treat blockchain tracing as an operational clustering problem, not a one-address pursuit, because the service logic is often what reveals the network.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org