What an address actually is
An address is derived from a key pair. It is created offline, without registration, identity check or central register, and one person can hold an unlimited number of them. Nothing in the address itself encodes a name, a country or an account.
This is why a public ledger can be completely transparent about money and completely silent about people. Every transfer is visible; the identities at either end are not part of the record.
What can be established from the ledger
- Which addresses are likely under common control, from spending patterns, funding sources and timing.
- Whether an address behaves like an automated forwarder, a consolidation wallet or a service deposit address.
- Whether funds reached a centralised service that collects customer identity information.
- Whether an address is publicly labelled — some belong to known services, and some have been published in scam reports by others.
How attribution really happens
Attribution to a person almost always comes from outside the ledger. The usual route is that funds reach a service which holds identity records, and those records are released to law enforcement or under a court order. That is a legal process, not a technical one.
Less often, an operator links their own address to a public identity: posting it on a profile, reusing it across sites, or paying it from an account already tied to them. Where that exists we document it and state the evidence; where it does not, we say the address is unattributed.
Why claims to the contrary are a warning sign
Offers to "identify the wallet owner", supply an IP address behind a transaction or provide a name from an address alone describe something the technology does not support. In practice these offers appear after a loss and are followed by a fee request.
A genuine report distinguishes between what is evidenced, what is inferred with a stated confidence level, and what is unknown. If those three things are not separated, the report is not evidence.
What to do with an address you have
- Record it exactly, along with the transaction hashes of every transfer you made to it.
- Check it on a public explorer, or with our free address lookup, to see the activity for yourself.
- Include it in your Action Fraud report and in any report to the exchange you used.
- Do not contact the address owner or send further funds to "test" a response.
If you are looking at your own case rather than reading generally, our cryptocurrency investigation service explains how a case is scoped and worked, the asset tracing hub covers the network-specific work, and our overview of cryptocurrency scam recovery in the UK sets out what is realistic. Asset pages: USDT tracing, Bitcoin tracing and Ethereum tracing. You can also contact the investigations team directly.
Common questions
- Can an IP address be obtained from a transaction?
- Not from the ledger. Transactions record addresses, amounts and timing, not network origin, and any IP observed by a node is unreliable and not part of the permanent record.
- Do investigators have a database of wallet owners?
- There are databases of labelled service addresses — exchanges, bridges, known scam clusters. There is no database mapping ordinary addresses to individuals.
- So what is the point of tracing?
- It establishes where funds went and whether they reached somewhere with customer records, which is what makes a report to an exchange, bank or police force actionable rather than anecdotal.
Have a case you want reviewed?
We scope at intake and tell you honestly whether the onchain data supports a traceable case.
Key terms in this guide
Plain-English definitions from the Wallsec glossary.