A blockchain shows an investigator what happened, and almost never who did it. A transaction is a permanent, precise record of value moving between addresses, but the address is a pseudonym, and the ledger says nothing about the person, company, or intent behind it. That gap is why a modern crypto investigation is never purely on-chain. The strongest cases fuse two kinds of evidence, on-chain signals from the ledger and off-chain signals from the world around it, into a single, defensible picture.
A crypto investigation is the process of tracing cryptocurrency activity, attributing it to real-world actors, and building evidence that supports enforcement or recovery. It combines on-chain analysis of blockchain transactions with off-chain intelligence such as know-your-customer records, sanctions lists, and open-source information. The goal is not just to follow the money, but to identify who controls it and prove that link to an evidential standard.
For law enforcement, this multi-source approach is now the norm rather than the exception. On-chain data establishes the movement; off-chain data establishes the identity. Neither is sufficient alone.
On-chain signals are the facts recorded directly on the blockchain. They are complete, permanent, and openly verifiable, which makes them powerful evidence, and they are the backbone of any trace. The main on-chain signals investigators work with are:
What on-chain signals cannot do is put a name to an address. They prove a flow with near-certainty, but the identity at the end of that flow lives off-chain.
Off-chain signals are everything relevant that does not live on the blockchain. They are what turn a cluster of addresses into a named entity, and they are where identity, intent, and context come from. Off-chain sources include know-your-customer and exchange records, sanctions and watchlists, seizure data, court filings, corporate registries, and open-source intelligence (OSINT) such as forum posts, leaked databases, social media, and dark-web listings.
Off-chain signals are richer in context but weaker in certainty. A forum post linking a username to a wallet is a lead, not proof, and its reliability has to be weighed. The discipline of a good investigation is knowing which off-chain source carries evidential weight and which is only a pointer to the next step.
Multi-source intelligence is the practice of fusing on-chain and off-chain signals so each compensates for the other's blind spot. On-chain data is certain about movement but silent on identity; off-chain data is rich on identity but uncertain and incomplete. Combined, they let an investigator prove both what happened and who was behind it.
A typical fusion looks like this. On-chain clustering expands a single address into the full wallet an actor controls. An off-chain know-your-customer record from a regulated exchange, obtained at the off-ramp, attaches a name to one address in that cluster. OSINT corroborates the link and adds context on the wider operation. Sanctions and watchlist data flag whether any counterparty is a designated entity. The result is a chain of reasoning that neither the ledger nor the open web could have produced alone.
Consider a ransomware case. The payment address is known from the outset, an on-chain signal. Clustering expands it into the operator's wider wallet, and flow tracing follows the proceeds through a mixer and a cross-chain bridge to a deposit address at a regulated exchange. That exchange holds the off-chain KYC record. OSINT, a reused username on a forum, corroborates the operator's identity, and a sanctions match on an intermediary confirms exposure to a designated entity. Each signal is ordinary on its own; fused, they identify the actor.
The weight of that fused evidence matters more than ever, because the regulatory perimeter is not yet doing the work. In its targeted report on decentralised finance, published July 21, 2026, the Financial Action Task Force (FATF) found that 93% of the 143 responding jurisdictions had not yet implemented its standards for DeFi arrangements. Where supervision is thin, the intelligence investigators can assemble themselves carries the case.
The two signal types answer different questions, and an investigator needs both.
Put simply, on-chain tells you what moved and where; off-chain tells you who and why. A case built on one without the other is either an anonymous flow or an unproven allegation.
Not all off-chain signals are equal, and treating a lead as if it were proof is a common mistake. Investigators weigh each source by how reliable and defensible it is, roughly in three tiers:
The skill is sequencing them, using lead-grade OSINT to find where to look, then anchoring the finding in an evidential source that will hold up.
Fusing signals is only useful if the result stands up to scrutiny. That means every attribution carries a documented confidence level, high, moderate, or low, and a clear record of which source supports it. It means distinguishing the operator who controls the keys from the beneficiary who holds funds through someone else's infrastructure. And it means an audit trail an analyst can defend later, because in court an unexplained or black-box conclusion is a weak foundation. Multi-source intelligence raises confidence precisely because independent signals corroborate each other, but only when the methodology behind the fusion is transparent.
Scorechain gives investigators the on-chain half of this picture and the labelled intelligence that connects it to the off-chain world. Scorechain Investigator takes an analyst from a single address to a complete, documented case, running on Scorechain's Digital Asset Intelligence graph. It traces funds across swaps, bridges, decentralised exchanges, and mixers on multiple blockchains, clusters addresses under a single controller (see our guide to wallet clustering and entity attribution), and matches them against a database of more than 939,000 labelled on-chain entities.
That labelled-entity layer is where on-chain meets off-chain. Attribution to exchanges, mixers, sanctioned entities, and known services turns a raw flow into named counterparties, and a transparent, auditable risk score, on a scale of 0 to 100 where a lower score signals higher risk, shows the reasoning behind every rating rather than hiding it in a black box. Flux Analysis visualises fund flows and indirect exposure across protocols and chains, Wallet Screening checks an address and its cluster against the same database, and the Blockchain Analytics API feeds that intelligence into an agency's own case-management and OSINT systems, so the on-chain signal sits alongside the off-chain evidence in one workflow. This is the intelligence layer behind Scorechain's wider work on blockchain forensics. Coverage spans 25+ blockchains with 2,800+ VASP entries, giving investigators the cross-chain and counterparty reach a multi-source case demands.
A blockchain will always tell you what happened. Turning that into who, and proving it, is a question of intelligence, not just analytics, and that is what multi-source investigation delivers.
If your team is building crypto investigation or AML capability, book a Scorechain demo to see on-chain tracing, entity attribution, and cross-chain intelligence applied to your own cases.
Optional partner line, keep if this is a joint SafeHorizon post: This reflects the on-chain intelligence layer Scorechain contributes to SafeHorizon, the Horizon Europe project detecting and disrupting crime-as-a-service across the web, deep web, and darknet.
Yes, in most cases. Every transaction is permanently recorded on the blockchain and openly verifiable, so investigators can follow value from address to address, even through swaps and bridges. Tracing establishes the movement of funds; identifying the person behind an address then requires off-chain signals such as exchange KYC records.
On-chain signals are facts recorded on the blockchain itself, such as transaction flows, address clusters, and exposure, and they are near-certain about value movement but pseudonymous. Off-chain signals are everything outside the ledger, such as KYC records, sanctions lists, and open-source intelligence, and they carry identity and context but vary in reliability. A crypto investigation needs both.
Blockchain intelligence clusters the addresses an actor controls, attributes them to known entities, and measures exposure to illicit activity, turning raw on-chain data into leads and evidence. Combined with off-chain intelligence, it lets investigators move from an anonymous flow to a named, documented case that holds up to scrutiny.
OSINT, or open-source intelligence, is publicly available off-chain information used to attribute and contextualise on-chain activity. In a crypto investigation it includes forum and social-media posts, leaked databases, corporate registries, and dark-web listings that can link a wallet to a person or service. It provides leads and corroboration, but its reliability must be weighed before it becomes evidence.
Because each answers a question the other cannot. On-chain data proves what moved and where, with near-certainty, but says nothing about identity. Off-chain data supplies identity, intent, and context, but is incomplete and variable in reliability. Fusing them produces a case that establishes both the flow and the actor, which is what enforcement and recovery require.
The most reliable are evidential sources: know-your-customer records from regulated exchanges, seizure data, and court filings, which are documented and admissible. Sanctions lists, corporate registries, and VASP directories are authoritative for flagging and context. Open-source intelligence is valuable for leads and corroboration but variable in reliability, so it is weighed carefully rather than treated as proof.
Open-source intelligence is publicly available, but using it in a crypto investigation is still bound by data-protection rules, jurisdictional constraints, and evidential standards. A forum post or leaked dataset may generate a lead, yet its provenance and reliability must be documented before it supports a formal finding. Sound practice anchors any OSINT lead in an evidential source that will hold up to scrutiny.































