Most writing on this subject stops at the reassurance that the blockchain is public, so cryptocurrency can be traced. True, and not much use when you are advising on a matter. What matters is what the process needs to get started, what it produces, and how far the findings can be pushed. This article covers all three, including the last one.
TLDR | Key Takeaways
• Tracing does not begin on the blockchain. It begins with something in conventional disclosure that points to the blockchain.
• One confirmed address usually leads to more than one address, though the techniques that achieve this produce probable groupings rather than proof.
• Assets rarely stay on one chain, and a trace that follows a single ledger will lose the trail at the first swap.
• An address can be shown to hold assets. Showing who controls it is a separate question with a separate standard of confidence.
What a Self-Custodied Wallet Leaves Behind
A hardware wallet in a drawer generates no statement. No institution holds the assets, so no institution can be asked to produce a record of them. That is the practical difficulty, and it is why document analysis reaches exchange holdings and stops there.
What self-custody does leave is a point of entry. Crypto almost never arrives in a wallet from nowhere. At some point it was bought with pounds, and buying it with pounds means a payment left a bank account and went somewhere. That transaction sits in the disclosure you already hold.
Everything after that point is recorded on the blockchain, permanently and publicly. The ledger was never the difficulty. Finding the door into it is.
Where Does a Trace Actually Start?
Four places, in rough order of how often they produce something usable.
Bank statements. Payments to an exchange are the most common entry point by a wide margin. A card payment or transfer to Coinbase, Kraken or Binance establishes that an account existed, indicates which assets were likely bought, and dates it. It also gives a figure to reconcile against whatever has been disclosed.
Exchange records. Where an account is identified, the withdrawal history is the bridge to self-custody. Assets that left the exchange went to an address, and that address is on the ledger. This is the step most often missed, because a disclosed exchange balance looks like a complete answer to the question that was asked.
Device and account artefacts. Wallet software on a laptop, a browser extension, a password manager entry, a photograph of a seed phrase, an app on a phone, exchange signup confirmations sitting in an email account. None of these are the assets. All of them indicate a wallet exists and narrow down what type.
Tax records. Where disposals have been declared, the filings indicate holdings and rough scale.
None of this is exotic. It is conventional disclosure, read by someone who knows which entries point at a ledger.
What Can a Single Address Reveal?
More than it appears, because addresses are rarely used in isolation.
On Bitcoin, the main technique rests on a simple observation. To spend from several addresses in one transaction, you need the key to every one of them. So when addresses are spent together, the same person is likely behind all of them. Do that across a whole transaction history and one address you knew about leads to several you did not.
Two other patterns help. Bitcoin cannot spend part of a holding, so a transaction sends the remainder back to the sender at a fresh address, and spotting that links the new address to the old one. Wallet software also leaves recognisable habits in how it puts transactions together.
Ethereum records transactions in a fundamentally different way, so none of that carries across. Linking addresses there depends on other patterns: which deposit addresses get reused, how someone claims free token distributions, the order in which they grant permissions to applications, which contracts they interact with. An expert experienced only in Bitcoin is not automatically equipped for an Ethereum-heavy case, and the reverse holds too.
Both of the limits that go with this matter more in proceedings than they do in an investigation.
The first is that none of these methods deliver certainty. They identify links that are likely rather than proven, they can group together addresses belonging to different people, and no agreed error rate exists for any of them. That constrains how findings ought to be expressed in a report written for a court.
The second concerns those software habits. On their own they establish nothing about ownership, because two wallets can look identical simply because both run the same application. Without a transaction actually connecting the addresses, a shared habit is a lead worth following rather than a finding.
Following Value Across Chains
This is where a trace most often fails when run by someone treating one ledger as the whole picture.
Bitcoin gets swapped for Ethereum. Ethereum goes into a stablecoin. The stablecoin crosses a bridge onto another network and something comes out the other side. Every one of those steps is recorded, but each is recorded on a ledger that makes no reference to the others. Reading them as one continuous movement of
value is a specific skill, and it is the difference between a trail that ends at the first swap and one that does not.
What Tracing Can Establish, and What It Cannot
Being straight about the limits matters more here than anywhere else, because a report that overreaches is worse than no report.
What holds up. That an address exists and what it holds. What moved in and out, in what amounts, on what dates. Whether funds reached an exchange, which brings verified identity records into scope. Whether assets moved to a third party, and when, relative to the proceedings.
Where it stops. Without a starting point, nowhere. If disclosure contains no payment to an exchange, no device artefact, no declared disposal and no admission, there is no door into the ledger, and no amount of tooling substitutes for one. Some assets resist analysis by design: privacy coins are built to defeat it, and mixing services are built to break the link between funds going in and funds coming out. Both usually leave evidence that something occurred, which is sometimes the useful finding on its own, but neither reliably yields a trail through to the far side.
"I can tell you to the penny what an address holds. Who controls it is a different sentence with a different level of confidence, and the report has to be clear about which of the two it is giving you."
Liam Ben Ari
Director of Digital Assets, Wealth Recovery Solicitors
Attribution. Establishing that an address holds assets is straightforward. Establishing that a particular person controls it depends on evidence from outside the blockchain: the exchange account that funded it, the device it was accessed from, the pattern of activity around it. An address is not a name, and a report that treats it as one will not survive being tested.
What Ends Up in the Report
For a report to be usable in financial remedy proceedings it has to be followable by someone who has never seen a wallet address. In practice that means setting out the addresses examined and how each was identified, the transaction history relied on, the valuation applied and the method behind it, and the reasoning connecting an address to a party, expressed at whatever level of confidence the evidence supports.
Two points are worth insisting on. Findings and inferences should be separated, because a report that mixes them holds up considerably less well than one that labels which is which. And the analysis should be documented to the point where another expert could repeat it: the platform used and its version, the attribution data relied on, the audit trail behind each step. Analysis that cannot be reproduced is difficult to defend, whatever it concluded.
Suspect Undisclosed Crypto in a Matter You Are Handling?
The earlier a trace begins, the more the disclosure you already hold is worth. Our forensic team works from conventional disclosure through to court-ready reporting, and we will tell you at the outset whether the material you have gives us a viable starting point. Speak to our team to discuss a case.
Read more in our series of guides on cryptocurrency and divorce:
• Instructing a Single Joint Expert for cryptocurrency
• Can cryptocurrency be hidden in a divorce
• Cryptocurrency in divorce settlements
• Practical challenges of cryptocurrency in divorce proceedings
• Three misconceptions about cryptocurrency in divorce
Frequently Asked Questions
Can cryptocurrency be traced if no wallet address has been disclosed?
Often, but it depends on the rest of the disclosure. Payments to an exchange in bank statements, an identified exchange account with a withdrawal history, device artefacts or declared disposals can each provide a starting point. Where none of those exist there is no entry point to the ledger, and a trace is not viable.
How does one wallet address lead to others?
On Bitcoin, addresses used together as inputs to a single transaction are likely to share a controller, because the transaction required the private key for each. Repeated across a full transaction history, one known address commonly leads to several that were not disclosed. These methods identify likely links rather than proof, and a report should say so.
Is cryptocurrency untraceable once it has moved between blockchains?
No, though it takes more work. Each chain records its own transactions without reference to the others, so following value through a swap or a bridge means reading several ledgers as a single sequence. A trace confined to one chain will appear to end at the first swap.
Can a report prove that a specific person controls a wallet?
That is a different question from what the wallet holds. Attribution relies on evidence from outside the blockchain, such as the exchange account that funded the address or the device used to access it. A report should state the strength of that connection rather than assert control as established fact.
What are the real limits of blockchain tracing?
No starting point means no trace. Privacy coins are designed to defeat this analysis, and mixing services break the link between funds going in and funds coming out. In those cases it is often possible to establish that something occurred without following the assets to a destination.
Wealth Recovery Solicitors provides FPR Part 25 compliant forensic reports for Family Courts across England and Wales. If cryptocurrency features in a matter you are handling, get in touch for a confidential discussion.
This article is for general information only and does not constitute legal advice. Forensic outcomes depend on the material available in each case, and nothing here should be read as a guarantee of what a trace will establish.

