REF-2026-0155 · Anonymised case record

    Wallet Intelligence Investigation

    3 min read · Last updated

    A set of addresses appearing across unrelated reports was assessed for common control using clustering and behavioural analysis.

    Executive Summary

    Addresses recurring across several unconnected incident reports raised the question of whether a single operator was responsible. The engagement assessed common control on the evidence available, without overstating what clustering can establish.

    The result was a graded assessment rather than a binary conclusion.

    Investigation Scope

    The mandate was assessment of common control and characterisation of operational behaviour.

    • Clustering analysis across the supplied address set
    • Behavioural profiling of timing, value structuring and service preference
    • Explicit statement of attribution limits
    • A reusable indicator set for future incident matching

    Technical Challenges

    Common-input clustering applies cleanly to UTXO chains but not to account-based chains, where shared control must be inferred from funding patterns and operational behaviour instead.

    Service-controlled addresses can produce false clustering signals, so custodial infrastructure had to be identified and excluded before any conclusion was drawn.

    Investigation Methodology

    Exclusion of custodial and contract addresses preceded all clustering work.

    • Classification of every address as user-controlled, contract or service-controlled
    • Common-input analysis where the chain model supports it
    • Funding-pattern and gas-payer analysis on account-based chains
    • Temporal profiling to identify consistent operational windows

    Blockchain Analysis

    Two distinct clusters emerged. Within each, funding originated from a shared source and activity followed a consistent daily window. Between the clusters, the only connection was a shared preference for the same intermediate services, which is a weak signal and was recorded as such.

    The assessment concluded common control within each cluster at high confidence, and connection between clusters at low confidence.

    Evidence Collection

    Each classification decision was documented with the observation that produced it, so the cluster boundaries could be audited.

    • Address classification register with supporting observations
    • Clustering output with the method applied to each chain
    • An indicator set formatted for reuse in future matching

    Findings

    The reports involved at least two separate operational clusters rather than one actor. Behavioural signatures were sufficiently distinctive to support future matching against new incidents.

    No individual identity was asserted; on-chain data supports control assessment, not identification.

    Outcome

    The graded assessment and indicator set were delivered for use in institutional reporting and for correlation against future incidents.

    No outcome is promised in any engagement. The deliverable is a documented, verifiable evidentiary record.

    Lessons Learned

    Clustering answers a narrow question — whether addresses are commonly controlled — and it answers nothing about who exercises that control.

    • Exclude custodial infrastructure before clustering anything
    • State the chain model, because it determines which methods are valid
    • Grade weak signals as weak rather than aggregating them into false certainty

    Frequently asked questions

    Can wallet analysis identify a person?
    No. It can establish whether addresses appear to be under common control and characterise operational behaviour. Identification requires records held by regulated services and legal process to obtain them.
    Is clustering reliable on account-based chains?
    Standard common-input clustering does not apply. Control must be inferred from funding relationships and behavioural patterns, which carries lower confidence and must be reported accordingly.
    What is an indicator set used for?
    It allows a new incident to be compared against documented behaviour, which can show whether it belongs to a previously observed cluster.
    Author
    SEQRIA Research Team emblem
    SEQRIA Research TeamInvestigative research unit, SEQRIA
    • Cyber Intelligence
    • Blockchain Investigations
    • Digital Forensics

    The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.

    Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.

    About the research team

    Related case studies

    Request Confidential Consultation

    SEQRIA provides technical investigation, forensic analysis and evidentiary documentation. Outcomes are never guaranteed. Case intake is confidential and handled by email.

    cybersec@securida.info
    Intelligence Center