How we reach a conclusion.
A report is only worth something if the reader can see how it was made. This page sets out what we measure, how we judge, the data we rely on and where on-chain analysis stops being able to help.
Approach
Every report separates two kinds of statement. Measurements are facts read from the blockchain: balances, dates, transfers, who funded whom. They are exact and anyone can check them. Judgments are conclusions drawn from those facts, such as whether a group of wallets is controlled by one party. They are probabilistic, and we present them that way.
Measurements are produced by fixed, versioned code, so the same input gives the same output. Software assists with collecting evidence and drafting. A named analyst reviews every finding, looks for innocent explanations, and is responsible for the conclusion.
What we measure
How clusters are identified
A cluster is a set of addresses we assess as likely to be controlled by one party. No single signal is treated as proof. We look for combinations of:
- Common funding. The first funds in each wallet came from the same non-exchange address, directly or through a short chain.
- Batch funding. Many wallets funded in one transaction or in a tight sequence with near-identical amounts.
- Synchronised behaviour. The same actions, in the same order, within the same narrow time windows.
- Shared exits. Proceeds consolidated to the same wallet or the same exchange deposit address.
- History. The same pattern repeated across earlier distributions.
A high-confidence cluster requires at least two independent signals. Funding on its own is never enough.
Wallet quality tiers
Where a report covers many wallets, each is placed in one of four tiers so the population can be described simply.
The thresholds used are stated in each report.
Confidence
Judgments are graded high, medium or low, and population-level estimates are given as a range with a central figure rather than a single number. A statement such as "38-45% of holders are independent" is a more honest description of the evidence than "41.3%".
Attribution of a wallet to a named person or company is only ever stated as the client's belief or as an inference, with the evidence for it. Ownership cannot be proven from chain data.
False positives
The most common way this kind of analysis goes wrong is by treating ordinary behaviour as coordination. We control for it specifically:
- Wallets funded directly from an exchange are never clustered on funding alone, because thousands of unrelated people share the same exchange hot wallet.
- Payroll, grant, faucet and onboarding addresses that fund many unrelated wallets are identified and excluded as funders.
- Smart accounts and multisignature wallets are assessed on their owners' behaviour.
- Where a report recommends excluding addresses, we advise an appeal window and provide the reasons for every address so appeals can be decided quickly.
Data sources
- Public blockchain data for the networks in scope, obtained through enterprise-grade indexing providers: transactions, transfers, balances, contract events and prices at the time of each event.
- Address labels for exchanges, liquidity pools, bridges, lockers and other known contracts, from provider datasets and public label sets, supplemented by our own research.
- Published sanctions lists for the sanctions exposure check.
- Documents supplied by the client, such as exchange statements or a seller's KPI definitions. These are relied on as supplied and identified as such.
We use public data only. No tracking scripts, no device fingerprinting and no personal data beyond what a client chooses to give us.
What we cannot see
- Activity inside a centralised exchange. Customers holding an asset on an exchange appear as one address.
- Order-book venues and other off-chain trading.
- A determined operator who funds every wallet from a separate exchange account and deliberately varies behaviour.
- Privacy networks, and chains outside the scope agreed for the report.
- Anything about the identity of a wallet's owner beyond what their on-chain behaviour implies.
Each report restates the limits that matter for its conclusion. Our sanctions exposure check is a hygiene check. It is not an anti-money-laundering risk rating and does not replace a regulated firm's screening provider.
Review and corrections
Every report includes a method appendix and, for multi-wallet reports, a data file listing each address with its tier, cluster and reasons, so your own team can check the work. If a finding is shown to be wrong we correct the report, state what changed and reissue it.
Independence
We are paid by the party that carries the risk if the numbers are wrong: the investor, the acquirer, the foundation, the issuer protecting its own distribution, or the individual evidencing their own funds. We do not sell ratings or "verified" badges to the projects we assess, take no referral fees, and hold no position in assets we are engaged to report on. Who commissioned a report, and what it covered, is confidential.
Questions about how we work?
Tell us what you want audited and the decision it feeds into. You get a fixed quote and a delivery date before any work starts.