Video summary

Основы исследования криптовалют 17 06

Main summary

Key takeaways

Educational

Main ideas & lessons from the lecture

Cryptocurrency basics

  • Cryptocurrency is described as a new type of digital financial asset whose circulation happens via a special transaction registry.
  • This registry is a blockchain: a public ledger where transactions are recorded and can be verified.

Scale and major coins (as of the lecture’s reference point)

  • There are 4,800+ cryptocurrencies on blockchain networks (as of April 2021).
  • 2,500+ are actively traded/exchanged and have the largest capitalization.
  • Bitcoin is presented as the most widespread, holding up to ~56% of the market.
  • Other mentioned cryptocurrencies: Ethereum, XRP, Bitcoin Cash.

Why cryptocurrency matters for crime and law enforcement

Crypto is often linked to illegal activity online and in darknet ecosystems, including:

  • Selling/buying prohibited goods and services (e.g., drugs)
  • Hacking and dissemination of malicious information
  • Terrorism financing
  • Cyber fraud
  • Malware and ransomware (e.g., encrypting company systems and demanding payment to a wallet)
  • Money laundering and concealment of income

Key operational goal: agencies want control/taxation, and investigators want the ability to attribute wallet ownership and trace criminal flows.

How cryptocurrency differs from traditional banking (key points)

  • The system does not require a central issuer/regulator to function (unlike fiat money/banks).
  • Transactions are private by default, and owners are anonymous/hidden by default.
  • Despite anonymity claims, the blockchain is public in the sense that transaction data is visible/recorded.
  • Users can generate unlimited addresses for a single wallet (unlike banks, which typically restrict account identifiers), but the underlying wallet can still be linked through analysis.

Methodology / workflow for investigating cryptocurrency-related offenses

1) Trace transactions on the blockchain (core investigation chain)

  1. Start with a known wallet (e.g., one that received stolen funds).
  2. Track outgoing/incoming flows by identifying:
    • sender address
    • recipient address
    • amount
    • timestamp
  3. Verify using metadata such as transaction hashes and block inclusion.
  4. Identify intermediate wallets and continue the trail until it reaches:
    • an exchange/exchanger or another entity later linkable to people/entities.

2) Identify exchanges/entities connected to wallets

  • After tracing wallet-to-wallet chains, investigators try to determine which exchange or exchanger is involved.
  • The lecture emphasizes linking wallets to exchange services to later obtain customer data via legal channels.

3) Obtain ownership/identity via legal mechanisms (“KYC” / official requests)

  • Once the exchange is determined, investigators send official requests as part of procedure (the lecture references KYC and anti–money laundering processes).
  • Exchanges are described as holding customer identity records and can provide them when legally compelled.

4) Enrich attribution using review/leak/public resources

Investigators supplement blockchain tracing with:

  • Public wallet reputation/review sites (to find prior illegal usage)
  • Information leaks (similar to banking-world leaks, though less frequent)
  • Contact artifacts tied to wallets, such as:
    • email addresses
    • usernames
    • social media profiles
    • domain names

5) Apply scoring and risk assessment frameworks (FATF-based)

  • The lecture describes scoring systems to assess wallet reliability/risk.
  • It references FATF (Financial Action Task Force) recommendations as the basis for performing “crypto audits” or risk evaluations.
  • Example model inputs mentioned:
    • wallet age/activity history
    • absence of prior transactions
    • recent registration/verification
    • connections to known illicit clusters/platforms (e.g., transactions linked to illegal markets)
    • other parameters derived from tax-related/monitoring systems and analyses

Tools and products mentioned (for visualization and automation)

Blockchain explorers & tracing browsers

  • Tools/resources are noted that allow viewing blockchain transactions (examples mentioned include block explorers and named services, though some subtitles were garbled).

Visualization and graph-based analysis tools

The lecture claims manual analysis is inefficient and proposes visualization/automation tools such as:

  • Graph/graph-like transaction visualization tools
  • Open-source tools on GitHub, including examples mentioned:
    • “Orbit” (independent development)
    • “Sense” (described as Finnish; open-source)
    • a Russian project from St. Petersburg usable in investigations
  • Maltego, named as widely used by international law enforcement (e.g., Europol/Interpol) for analyzing/visualizing connections

Automated monitoring / alerts

  • Services that monitor wallet movement and alert investigators, including via Telegram or email when a wallet begins activity.

Wallet-to-exchange affiliation lookup resources

Two public resources emphasized for mapping wallets to exchanges:

  • “XP Bit Info Charts”
  • “Valit Explorer” (name appears garbled in subtitles, but refers to a wallet/exchange association explorer)

Mathematical / analytical techniques for attribution (described as advanced steps)

A) Heuristic analysis

Two heuristic categories were described:

  1. Repeated entries (same recipient / patterning)

    • If a user sends funds to the same address regularly (e.g., monthly), investigators may infer a relationship (e.g., contractor/connected party).
    • If a crypto mixer inserts a new wallet into the flow, that wallet may be added into a heuristic “wallet pool.”
  2. Address change analysis (one user controls multiple addresses)

    • A wallet’s first/original address can still receive funds even though many addresses are generated.
    • By analyzing transactions around address generation (“change”), investigators can cluster addresses likely controlled by the same owner.
    • The lecture also mentions coarse geolocation inference (e.g., by continent) by analyzing transaction nodes.

B) Cluster analysis

  • Defined as a multivariate statistical procedure that groups objects (wallets) into homogeneous clusters/communities.
  • Claimed benefits:
    • combines heuristics from address change and repeated patterns
    • can identify very large numbers of user clusters (example cited: 5–5.5 million clusters in a referenced study)
  • Claimed application: identifying exchange addresses using limited “infected” transactions.

C) Knowledge-graph style ranking (graph-of-entities analogy)

  • Uses knowledge graphs as an analogy to search engines ranking based on social graphs and behavioral data.
  • Applied idea: connect wallet groups to known marketplaces/gambling/hacker communities by correlating transaction patterns.

Tracking “digital traces” beyond blockchain payments

The lecture also covers non-blockchain identification paths:

  • When a user pays with cryptocurrency on a site:
    • investigators can use timing, IP address, device info, and cookie data
    • then link to email/social accounts where possible
  • If traffic capture exists, investigators can attempt traffic correlation/eavesdropping (noted as complicated and limited in effectiveness).
  • The lecture claims digital trace collection may become increasingly relevant for identification.

Cryptocurrency anonymization techniques (and why they’re challenged)

1) Exchange-based anonymization (exchange swapping/moves)

  • Users can exchange one crypto to another and withdraw later to make tracking harder.
  • Counterpoint: exchanges still perform KYC and provide data under legal requests, reducing effectiveness.

2) Mixers (mixing/tumbling services)

  • Users send funds to a mixer, then receive “clean” crypto.
  • Counterpoint:
    • modern analytics (cluster analysis/graph tools) can group mixer-related wallets and reconstruct flows
    • by comparing mixer inputs/outputs and rewards, investigators may identify laundering patterns
  • Conclusion: mixers become less useful over time; described as a recurring arms race.

3) Anonymous cryptocurrencies (privacy coins)

  • Mentioned to hide some/all of:
    • sender/recipient addresses
    • transaction amounts
  • Examples referenced: Dash / Monero-type references (subtitles garbled).
  • Claims mentioned:
    • often have low liquidity and limited acceptance
    • only some are truly anonymous (e.g., Monero described as truly anonymous); others are partially traceable (a claim of ~70% traceable for some was mentioned)
  • Also mentioned: U.S. efforts and funding to develop better tracking methods.

4) Protocol changes and scaling privacy features

  • Taproot (Bitcoin update) is mentioned as expected to improve confidentiality/efficiency.
  • Lightning Network is described as enabling cheaper/faster transactions; the lecture suggests it could make tracking tools obsolete at scale (while also noting modern tools can still work partially).
  • Overall claim: even strong tracking tools may fail to identify everything—possibly around ~70% of wallets in best-case scenarios (as claimed).

Conclusion themes

The lecture argues that effective investigation requires combining:

  1. Open blockchain data
  2. Visualization and automated tools
  3. Exchange affiliation resolution
  4. Legal KYC/KYB requests
  5. Enrichment from leaks/reviews/digital traces
  6. Advanced analytics (heuristics, clustering, knowledge graphs)

It emphasizes that big data collection and automation are essential because manual analysis of millions of transactions is not feasible.


Speakers / sources featured (as mentioned)

Speakers / presenters

  • Sergeevich Bekirov (name appears as a speaker; subtitles included garbled wording)
  • An unnamed presenter (referred to as “I” throughout)
  • “Leaders of the gaming company Internet search” (affiliation mentioned; exact name unclear due to garbled subtitles)

Organizations / source types referenced

  • Blockchain networks (general)
  • Exchanges/exchangers (general)
  • Rosfinmonitoring
  • FATF
  • Europol and Interpol
  • Russian tax authorities
  • GitHub
  • NIST-like / assorted unnamed resources (not clearly identifiable from subtitles)

Specific tools/resources named (as sources)

  • Maltego
  • Bitcoin-related analysis/visualization platforms (several names garbled)
  • Bit clusters / Bit Cluster(s) (open-source tool name appears)
  • Graph/sense/info (names partially garbled)
  • Block Sherlock (American company mentioned)
  • Wallet tracing/visualization sites:
    • “Bit Info Charts”
    • “Valit Explorer” (as rendered; likely a wallet/exchange explorer)

Cryptocurrencies mentioned

  • Bitcoin
  • Ethereum
  • XRP
  • Bitcoin Cash
  • Dash
  • Monero
  • Lightning Network (protocol layer)
  • Taproot (Bitcoin update)

Original video