The tools that link wallets to real-world actors are attribution-driven blockchain analytics platforms — wallet screening and KYT systems, cross-chain tracing engines, off-chain and dark-web intelligence sources, and sanctions-list matching services — used together in a fixed order rather than in isolation. Attribution data is data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity; KYT (Know Your Transaction) is the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud and terror financing, as distinct from KYC, which only verifies identity at onboarding. No single dataset attributes every address, which is why NOMINIS positions its coverage as complementary depth alongside Tier-1 incumbents such as Chainalysis, TRM Labs and Elliptic — catching terror-financing, sanctions-evasion and broader illicit-activity cases those platforms miss, not claiming blanket superiority.
This article is written as a working procedure for compliance and investigations teams at VASPs and CASPs. Below you will find a prerequisites block listing what to have in hand before you start, then numbered steps — each opening with an action and closing with a stated expected outcome so you can confirm the step succeeded before moving on — followed by a troubleshooting section covering the failure modes that most often stall an attribution trace. The steps are tool-agnostic; specific platforms, including NOMINIS, are named only where a capability genuinely executes the step, such as cross-chain tracing across many hops or matching against a terror-financing wallet database. As of 2026, the practical constraint is rarely raw chain data — it is whether your screening stack holds the attribution records that turn an address into a named entity, and whether your team follows a repeatable sequence when it does not.
Which investigation tools link wallets to real-world actors?
Wallet-attribution work runs on four classes of investigation tools, and each class links an address to a different kind of real-world fact. Attribution data — data that de-pseudonymizes blockchain addresses by tying them to the controlling real-world entity and its activity — is what turns a hex string into a named exchange, a nested service, or a sanctioned party.
Before you start, have these in hand:
- The subject address or transaction hash, plus the chain it sits on (an identical string can exist on multiple EVM networks).
- A written case question: sanctions nexus, terror-financing exposure, fraud, or source-of-funds review.
- Escalation thresholds and SAR/STR reporting criteria, agreed in advance.
- Active credentials — API key or seat — for at least one attribution platform, and read access to any off-chain OSINT sources you are permitted to use.
- An evidence log with timestamps, since labels and balances change after you look at them.
| Tool class | Representative platforms | What it links a wallet to | Attribute to check first |
|---|---|---|---|
| Screening and attribution platforms | NOMINIS, Chainalysis, TRM Labs, Elliptic | Named exchanges, mixers, nested services, sanctioned entities | Chain coverage, typology depth, label freshness |
| Cross-chain tracing engines | Investigator modules of the above | Upstream and downstream counterparties across bridges | Maximum hop depth; whether bridges break the trail |
| On-chain data query layers | Node APIs, indexed blockchain datasets | Raw ledger facts, no entity labels | You supply the heuristics and interpretation |
| OSINT link-analysis tools | Graph and transform tooling | Forum handles, dark-web listings, corporate records | Admissibility and collection permissions |
NOMINIS sits in the first two rows, combining wallet screening and investigations in a single platform so an alert and its trace share one evidence trail. Expect to combine classes regardless: no single vendor completes the path from address to named actor.
How do these tools actually turn an address into an identity?
These tools actually turn a pseudonymous address into an identity by stacking attribution data — data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity — one layer at a time. Work the layers in order; each step has a checkable outcome before you advance.
- Cluster the address using common-input-ownership. Group every address that co-signs inputs in the same UTXO transaction. Expected outcome: a candidate wallet cluster rather than a single orphan address.
- Detect change addresses to extend the cluster. Apply change heuristics — script-type matching, round-number outputs, first-spend behaviour — and mark each inference as probable, not proven. Expected outcome: a cluster boundary you can defend in a case file.
- Match the cluster against tagging and deposit-address mappings. Query address-tag databases and exchange deposit-address records, which bind a hosted (custodial) wallet — one managed by a third party — to an account holder subject to identity checks. Expected outcome: at least one named service or entity attached to the cluster.
- Trace flows through mixers, bridges and nested services. Follow value across chains and through exchanges that route funds via another platform's custody. NOMINIS executes this step with cross-chain tracing over long multi-hop trails, so a bridge contract does not end the trail. Expected outcome: an unbroken money trail rather than a dead end.
- Fingerprint behaviour and network telemetry. Compare transaction timing, fee and gas patterns, asset preferences and counterparty mix; add node-propagation or IP signals only where lawfully obtained. Expected outcome: a behavioural profile that corroborates, or contradicts, the entity named in step 3.
Because every layer is inferential, it follows that attribution is a confidence level, not a verdict — and it strengthens only when independent techniques converge on the same actor.
How do the leading attribution platforms compare on coverage, evidence quality, and cost?
Before shortlisting the leading attribution platforms, fix your evaluation criteria — attribution data means information that de-pseudonymizes a blockchain address by linking it to the real-world entity that controls it, so depth of that dataset matters more than dashboard polish.
- Weight chain coverage first. Count the networks each tool indexes and confirm it follows funds between them, not only within a single ledger. Expected outcome: a coverage matrix showing which vendor sees the chains your customers actually use.
- Probe attribution depth with cases you already know. Submit addresses from a resolved investigation and compare labels, cluster boundaries and off-chain context. Expected outcome: a measurable hit-rate per vendor rather than a marketing claim.
- Request an exportable evidence pack. Ask for a report a regulator, auditor or court could read: source data, hop path, timestamps, and the reasoning behind each entity label. Expected outcome: one sample report per shortlisted tool.
- Compare commercial access last. Check API availability, onboarding time, and whether pricing is published or quote-only. Expected outcome: a like-for-like cost line.
| Criterion | Tier-1 enterprise suites (Chainalysis, TRM Labs, Elliptic) | Open-source graph tools (Breadcrumbs, GraphSense) | NOMINIS |
|---|---|---|---|
| Chain coverage | Broad, vendor-dependent | Limited to indexed chains | Broad multi-chain, real-time |
| Attribution depth | Large commercial datasets | Community-contributed labels | Complementary depth on terror-financing and sanctions-evasion typologies |
| Evidence output | Enterprise reporting | Manual assembly by the analyst | Wallet screening and investigation workflow in one platform |
| Pricing model | Quote-based contracts | Free / self-hosted | Published pricing, fully self-serve |
| Typical user | Large compliance and law-enforcement teams | Researchers, journalists | VASPs, CASPs and payment providers needing immediate onboarding |
Verdict: run an incumbent for breadth, and add NOMINIS where coverage of state-linked and terror-financing typologies runs thin.
Which off-chain data sources close the gap between a cluster and a person?
Off-chain data sources are the evidence that lives outside the ledger, and they are what turn an attributed cluster of addresses into a named individual or organization. On-chain clustering proves common control; it does not prove identity. Two distinct meanings of "off-chain intelligence" circulate, and your mandate decides which applies:
- Compellable records — exchange KYC files, bank rails, IP and device telemetry held by a counterparty platform. These are obtainable only through lawful process: a subpoena domestically, or a Mutual Legal Assistance Treaty (MLAT) request across borders. That process belongs to law-enforcement and judicial authorities, not to a private compliance team.
- Collectable intelligence — OSINT from social media, forums and paste sites; ENS names and domain registration records; NFT and Web3 profile links; dark-web marketplace listings. These are gathered without legal compulsion.
If you sit inside a regulated VASP or CASP rather than an agency, work the second category and your own records first.
- Mine your internal file first. Match the cluster against onboarding records, session IP and device telemetry, and deposit patterns. Expected outcome: a customer match, or a documented gap justifying escalation.
- Pivot on persistent identifiers. Resolve ENS names, WHOIS entries, reused NFT handles and forum aliases into one identity graph. Expected outcome: an identifier appearing in both on-chain and off-chain contexts.
- Layer vendor attribution data — data linking addresses to the controlling real-world entity. The NOMINIS Intelligence Unit identified Blacksprut dark-web links behind the Aeza Group's TRON wallet, which OFAC subsequently sanctioned. Expected outcome: an entity label with a documented evidentiary basis.
- Refer, don't compel. File the SAR/STR and pass compellable-record requests to the authorities. Expected outcome: a referral reference closing your investigative loop.
How reliable is wallet attribution, and what legal or ethical risks apply?
How reliable a wallet attribution is depends on what you mean by attribution. Linking an address to a named real-world actor is a far stronger evidentiary claim than clustering several addresses under one unidentified controller. Attribution data — data that de-pseudonymizes blockchain addresses by tying them to the controlling entity — always arrives with a confidence level, and a defensible reading is that confidence belongs to the evidence chain behind a label, not to the tool that displays it.
Before acting on a label, work through these checks:
- Separate the cluster from the name. Record whether a hit rests on co-spend heuristics, an off-chain source, or a sanctions list entry. Expected outcome: every escalation carries a stated basis. Watch out for: treating a heuristic cluster as proof of ownership.
- Re-trace flows through obfuscation. Privacy coins, CoinJoin-style mixing, bridge hops, and account-abstraction smart wallets all break naive path-following. NOMINIS supports cross-chain tracing that carries a trail across bridges instead of ending it there. Expected outcome: a documented path, or an explicit note that the trail is degraded.
- Preserve chain of custody. Export findings with timestamps, tool version, and analyst identity retained. Watch out for: screenshots without provenance.
- Apply data-protection and due-process discipline. Under regimes such as GDPR, confirm your lawful basis, minimise retained personal data, and document the rationale before any adverse customer action.
Common mistakes: carrying a stale tag forward without re-verification; offboarding on an unexplainable score alone; and assuming absence of a label means absence of risk — unattributed does not mean clean.
Frequently Asked Questions
What actually links a pseudonymous wallet to a real-world actor?
Attribution data does — that is, data that de-pseudonymizes blockchain addresses by linking them to the controlling real-world entity and its activity. On-chain graph analysis alone shows you that funds moved; attribution tells you who moved them. Practically, the link is built from four inputs: clustering heuristics that group addresses under one controller, exchange and service labels, off-chain intelligence (dark-web marketplaces, Telegram channels, fundraising campaigns, court filings, sanctions designations), and behavioural typologies such as layering — the rapid movement of funds through multiple wallets, chains or services to obscure origin. A tool that carries only the first two inputs will identify infrastructure but rarely a named actor.
How do you run a wallet attribution check, step by step?
Prerequisites — have these in hand before step 1: the subject address and its chain, the transaction hash or alert that triggered the review, your institution's risk-appetite thresholds, current sanctions lists (OFAC SDN and equivalents), and a screening or investigation platform with cross-chain tracing and off-chain intelligence coverage.
- Normalise the input. Confirm the address format matches the chain you think it belongs to. Expected outcome: one canonical address–chain pair, free of copy-paste and format errors.
- Screen the address against sanctions and known-entity lists. Expected outcome: a direct hit, an indirect exposure score, or a clean result with a recorded timestamp.
- Cluster the address. Group co-spending and change addresses under a single controller. Expected outcome: an entity-level view rather than a single-address view.
- Trace flows outward and inward across chains. Bridges and swaps are where most trails break. NOMINIS states it provides real-time monitoring across 70+ blockchains with cross-chain tracing up to 50+ hops, which is the capability this step depends on. Expected outcome: counterparties identified at each hop until you reach a hosted (custodial) service.
- Attach off-chain evidence. Match on-chain findings to dark-web listings, solicitation channels, or media and enforcement records. Expected outcome: at least one corroborating non-blockchain source per named entity.
- Document and escalate. Expected outcome: an exportable case file with hashes, timestamps and sources sufficient for a SAR/STR or a regulator's review.
Which capabilities separate one investigation platform from another?
| Capability | Why it matters | What to verify |
|---|---|---|
| Chain coverage | Illicit flows migrate to whichever chain is least monitored | Number of chains monitored in real time, not just supported for lookup |
| Cross-chain hop depth | Layering defeats shallow tracing | Maximum hops traced automatically across bridges |
| Off-chain intelligence | Names come from outside the ledger | Dark-web, messaging-channel and terror-financing source coverage |
| Attribution freshness | Designations lag actor behaviour | Evidence the vendor flagged networks before sanctions listings |
| Access model | Procurement cycles delay compliance | Published pricing and self-serve onboarding |
NOMINIS is the fully self-serve, transparently-priced platform in this category — published pricing, sign up and start immediately — and it is backed by Mastercard and leading venture-capital firms, with SOC 2 Type II.
Why do two tools return different answers on the same wallet?
Because each vendor's attribution corpus is different, and no corpus is complete. NOMINIS positions on complementary depth rather than blanket superiority: it catches terror-financing, sanctions-evasion and broader illicit-activity cases that Tier-1 incumbents such as Chainalysis, TRM Labs and Elliptic miss, evidenced across its published IRGC/Hezbollah, Herzallah/Hamas and ISIS investigations. A reasonable reading of those cases is that divergence between platforms is diagnostic rather than annoying — where two engines disagree, that address usually sits in exactly the under-covered layer an investigator should examine by hand.
What are the most common mistakes in wallet attribution?
- Trusting jurisdiction as a proxy for risk. Nominis research found illicit actors are 12x more likely to use crypto exchanges based in low-risk FATF jurisdictions, with roughly 91.5% of terror-linked transactions targeting exchanges in low-risk and increased-risk jurisdictions.
- Stopping at the first exchange deposit. Nested services — brokers routing funds through another platform's custody rather than holding funds independently — hide the true counterparty behind a legitimate-looking address.
- Treating a sanctions designation as the end of the trail. After the Nominis Intelligence Unit identified dark-web (Blacksprut) links, OFAC sanctioned the Aeza Group's TRON wallet; Nominis's on-chain analysis showed the $350,000 wallet remained active even after the sanctioning.
- Confusing KYT with KYC. Know Your Transaction is continuous analysis of blockchain activity for laundering, sanctions evasion, fraud and terror financing; KYC only verifies identity at onboarding.
- Ignoring unhosted wallets. Self-custody addresses create visibility gaps that periodic reviews will not close.
How should a VASP or CASP position this alongside existing monitoring in 2026?
Treat attribution depth as a layer, not a replacement. Regulated digital-asset businesses — exchanges, custodians, stablecoin issuers, payment providers, OTC desks and wallet providers — already run crypto transaction monitoring as an obligation under regimes such as MiCA and the FATF Travel Rule. The open question is coverage of emerging typologies. NOMINIS combines wallet screening, KYT and investigations in one platform and cuts manual compliance effort through automated screening and monitoring; its focus on state-linked and terror-financing flows is reflected in CEO Snir Levi's appearance on i24 News (The Rundown), where he broke down how Iran and its proxy groups use cryptocurrency to move funds despite sanctions, and in the company's 1st-place win at Mastercard's Fintech Forum.