Chain analysis explained: how blockchain analytics clusters and labels addresses, the main vendors, how exchanges screen deposits, and where it goes wrong.

Chain analysis, usually called blockchain analytics, is the practice of reading a public blockchain to work out who is likely behind which addresses and where funds came from and went to. Analysts group addresses into clusters that probably share an owner, attach real-world labels to those clusters, such as an exchange, a mixer or a sanctioned group, and turn the result into a risk score that compliance teams act on.
One point of confusion is worth clearing up first: Chainalysis is a company; chain analysis is the practice. Chainalysis is one of several vendors that sell blockchain analytics software, alongside firms such as TRM Labs, Elliptic and Crystal Intelligence. This guide explains how the techniques work, how exchanges use them, where they go wrong, and what it means if your deposit has been put on hold.
Most public blockchains are open ledgers. Anyone can see every transaction, the addresses involved and the amounts. What the ledger does not show is who controls an address. Chain analysis tries to close that gap by combining what is on-chain with what is known off-chain.
Satoshi Nakamoto's Bitcoin white paper anticipated this. Its privacy section suggests using a new key pair for each transaction, but notes that some linking is unavoidable when a transaction has several inputs, because those inputs reveal a common owner. Academic researchers turned that observation into a method. In "A Fistful of Bitcoins" (IMC 2013), Meiklejohn and colleagues at UC San Diego and George Mason University clustered Bitcoin addresses with heuristics and then labelled clusters by transacting with known services themselves. Commercial blockchain analytics grew from the same ideas.
Today the term mainly covers two jobs:
Vendors do not publish their full methods, but the building blocks are well documented.
Clustering groups addresses that are probably controlled by the same entity. On Bitcoin-style chains, the classic rule is the multi-input (or common-input-ownership) heuristic: if several addresses are spent together as inputs to one transaction, they are treated as one owner. The second classic rule is change detection: when a transaction pays someone and sends the remainder back to its sender, analysts try to identify which output is the "change" address, so it can join the sender's cluster.
Account-based chains such as Ethereum work differently. There are no multi-input transactions to exploit, so analysts lean on other patterns, such as exchange deposit addresses that forward funds to a known hot wallet, and on smart contract interactions, which are often easy to label because the contract code and deployer are public.
A cluster is only useful once it has a name. Vendors build attribution databases from test transactions with services, public disclosures, sanctions lists, court documents, investigators and victims' reports. The US Treasury's sanctions office adds some cryptocurrency addresses to its Specially Designated Nationals list, but its own FAQ says those listings are not likely to be exhaustive. Crystal Intelligence, for example, says on its website that it covers more than 330 blockchains and over 118,000 attributed entities (checked 8 October 2026).
With clusters and labels in place, the software follows value forward and backward through the transaction graph. Investigators use it to answer "where did these funds go?" Compliance tools ask the reverse question: "how much of this deposit can be traced back to a risky source, and how many hops away is it?" Modern tools also follow funds across bridges and swaps between chains.
Finally, exposure is converted into a score or alert. Direct exposure (the deposit came straight from a sanctioned address) is weighted more heavily than indirect exposure several hops back. Each exchange sets its own thresholds for categories such as sanctions, darknet markets, scams, stolen funds and mixers.
The market is concentrated in a handful of specialist firms. The list below is neutral and based on each company's own published descriptions, checked on 8 October 2026; it is not a ranking.
Chainalysis also publishes widely cited crime estimates. Its 2026 Crypto Crime Report, published 8 January 2026, says illicit addresses received at least $154 billion in 2025, driven mainly by a 694% rise in value received by sanctioned entities. Chainalysis describes the figure as a lower bound that tends to rise as more illicit addresses are identified. Treat any single vendor's figures as one estimate built on that vendor's own attribution data. If you are comparing tools for a platform, our guide to the best crypto transaction monitoring software in 2026 goes into more depth.
For a regulated exchange or other crypto-asset service provider, blockchain analytics is one control among several. It typically shows up in four places.
Deposit screening (KYT). Each incoming deposit is scored against the source of the funds. A clean score credits automatically. A high score holds the funds for review, and a direct sanctions hit can mean the funds are frozen and reported.
Withdrawal and wallet screening. Before sending funds out, the exchange checks the destination address. Sending to a sanctioned address or a known scam wallet is blocked. Our explainers on sanctions screening software and free crypto sanctions screening cover this step.
Travel Rule and self-hosted wallets. In the EU, the Transfer of Funds Regulation (EU) 2023/1113, which has applied since 30 December 2024, requires identifying information to travel with crypto transfers. For a transfer of more than EUR 1,000 to a self-hosted address, the sending provider must take adequate measures to assess whether the customer owns or controls that address (Article 14(5)). Recital 17 of the same regulation names "distributed ledger technology (DLT) analytic tools" as one of the measures that can help detect the origin or destination of crypto-assets in higher-risk situations. See the crypto Travel Rule explained.
Investigations and reporting. When an alert escalates, analysts use investigation tools to build the case behind a suspicious activity report. On-chain data sits alongside off-chain controls: identity checks, customer profiles and rule-based transaction monitoring. Compliance platforms such as iDenfy run that off-chain side, with monitoring rules and sanctions and PEP screening linked to the verified customer. Our guide to AML transaction monitoring in crypto explains how the pieces fit, and AML red flags in crypto lists the patterns analysts look for.
If an exchange has held your deposit or asked where the funds came from, blockchain analytics is often the reason. A few practical points:
DeFi works differently: when you use a non-custodial protocol from your own wallet, there is usually no account opening and no KYC. JewelSwap's apps on MultiversX, Sui and Radix are non-custodial and do not run KYC themselves; our explainer on KYC in DeFi covers the details. Your on-chain history is still public, though, and a regulated exchange will screen it when you move funds there.
Blockchain analytics is powerful but probabilistic. Its main weaknesses are well known.
None of this makes the evidence worthless. Courts have accepted blockchain tracing as part of prosecutions: the operator of the Bitcoin Fog mixer was convicted by a jury in March 2024 and sentenced in November 2024 to 12 years and six months, according to the US Department of Justice. But it does mean analytics output should be treated as a lead to investigate, not a verdict.
No. Chainalysis is a company, co-founded in 2014, that sells blockchain analytics software. Chain analysis, or blockchain analytics, is the general practice of clustering, labelling and tracing addresses on a public blockchain. Other vendors include TRM Labs, Elliptic and Crystal Intelligence.
It groups addresses that probably share an owner using heuristics, such as addresses spent together in one Bitcoin transaction, and then attaches labels from off-chain sources such as test transactions with services, sanctions lists, public disclosures and investigations. The result is an informed estimate, not proof.
Usually because its screening tool linked the funds, directly or a few hops back, to a risky source such as a mixer, scam, hack or sanctioned address. The exchange will typically ask where the funds came from. Clear records such as transaction hashes and exchange statements help resolve the review.
Yes. Clustering heuristics can link addresses that do not share an owner, labels can be mistaken, and vendors' databases differ. That is why exchanges combine analytics scores with human review and customer information before taking action.
Some front ends screen connecting wallets against sanctions lists, but most non-custodial protocols do not run KYC or KYT on users. Regulated exchanges, however, will screen funds that arrive from DeFi.
This article is educational and is not legal or financial advice. Vendor descriptions and figures are as of 8 October 2026 and come from each company's own website, Chainalysis's 2026 Crypto Crime Report, EUR-Lex, the US Treasury and the US Department of Justice, linked inline. Vendors are listed for illustration, not as recommendations.