Important NOTE: Beware of the fake website finanzforensik.com — officially only under finanz-forensik.de. Registered at Hanau District Court, HRB 100521.

White paper NO. 13 · Crypto Forensics

The anatomy of professional crypto scammers

How criminal infrastructures really work — and how to trace cryptocurrencies, uncover wallet clusters and secure assets.

14–17 billion USD
Crypto fraud worldwide in 2025 (Chainalysis)
+253 %
Average damage per payment 2024→2025 (782→2,764 USD)
≈ +1.400 %
Impersonation Scam 2025 (AI Deepfakes)
84 %
the illegal inflows into stablecoins (2025)
Cover image of the white paper "The Anatomy of Professional Crypto Scammers" by Finanz Forensik GmbH

Whitepaper

Note on methodology

Conclusions drawn from several hundred cryptoforensic investigations conducted by Finanz Forensik GmbH, supplemented by publicly available sources—no independent statistical analysis. Case studies are anonymized or constructed for illustrative purposes ("illustrative placeholder") and do not allow for conclusions to be drawn about actual cases.

David Lüdtke, Managing Director and Crypto Forensic Expert of Finanz Forensik GmbH

Four victims, one shared wallet. Independent payment flows converge at the cash-out point — this is precisely what makes perpetrator infrastructures forensically vulnerable.

1 Introduction

1.1 The development of crypto fraud

Cryptocurrency fraud has evolved from occasional isolated incidents into a highly organized business model with a division of labor. While previously it was carried out by individual perpetrators with limited technical knowledge, today it involves specialized, sometimes industrial-scale structures: individuals who acquire victims (fake investment platforms, romance or "pig butchering" contacts, social media advertising), individuals who operate the technical infrastructure (wallets, collection points, cross-chain transfers), and individuals who specialize exclusively in cashing out in fiat currency.

This division of labor complicates traditional investigative approaches that target a single responsible person. At the same time, it opens up new forensic avenues: Where there is a division of labor, there are also interfaces—and interfaces leave traces that can be made visible through blockchain analysis and wallet clustering.

1.2 Damage amounts and the dark figure

According to Chainalysis' 2026 Crypto Crime Report, at least $14 billion in on-chain cryptocurrency fraud was proven worldwide in 2025; after full retrospective analysis, this figure is expected to exceed $17 billion—up from approximately $9.9 billion the previous year. The average loss per fraud payment increased from $782 (2024) to $2,764 (2025)—an increase of 253 TW (1 TP3T). Impersonation fraud grew by approximately 1,400 TW (1 TP3T), driven by AI deepfakes.

202527642024782
Average amount of damage per fraud payment (USD). Increase of 253 % within one year (Chainalysis, 2026 Crypto Crime Report — Scams).

General cybercrime in Germany is also at an all-time high: The Federal Criminal Police Office (BKA) registered around 334,000 cases of cybercrime in the narrower sense for 2025, with total damages estimated by Bitkom at €202.4 billion; a good 62 million of these crimes were committed from abroad or from unknown locations. The BKA does not maintain separate, comprehensive statistics on crypto-related damages—which further exacerbates the problem of unreported cases. Many cases go unreported due to shame or the mistaken assumption that blockchain technology is anonymous.

1.3 The professionalization of perpetrators

  • Multilingual, partly industrially organized contact centers for victim outreach
  • Standardized technical infrastructure (wallet generators, layering scripts, pre-configured collective wallets)
  • Established partnerships with OTC brokers and established cash-out channels
  • Use of multiple blockchains and cross-chain bridges for systematic obfuscation
  • Division of labor roles: acquisition, technical processing, cash-out, money laundering

The industrial scale of these structures is exemplified by the Cambodian Huione Group, which, according to Chainalysis data, processed more than $98 billion in crypto assets and laundered at least $4 billion from illegal sources over a period of approximately four and a half years before US authorities cut off the network's access to the financial system. The chairman of the "Prince Group" was indicted for operating forced-labor scam compounds. Professionalization in this context does not mean greater anonymity—on the contrary: the more standardized an infrastructure is, the more recurring its patterns become.

1.4 Why traditional investigative approaches often fail

Traditional approaches focus on the identity of a person: Who opened the account, who operated the website, who was behind the number. This approach is ineffective for internationally operating, specialized groups because the contact person, the technical infrastructure, and the cash-out point are attributable to different actors, often located in different jurisdictions.

1.5 Why the blockchain still leaves traces

A public blockchain is not an anonymous space, but a pseudonymous and completely transparent one. Every transaction is permanent, immutable, and auditable. What's missing is not the history, but the mapping of an address to a real identity. This is precisely where professional analysis comes in—by combining on-chain patterns (clustering, time correlation, balance sheet analysis) with off-chain information (KYC data, OSINT, information requests)—ideally leading to a concrete cash-out account.

1
Forensic finding no. 1

In almost all cases investigated by Finanz Forensik GmbH, the perpetrator's infrastructure left behind more usable traces than the initial contact with the victim. While fake websites, phone numbers, and chat accounts are quickly deleted, the wallet structures used remain permanently and immutably traceable on the blockchain.

Key messages
  • Crypto fraud is now organized through a division of labor: acquisition, technical processing and cash-out are often in different hands.
  • In 2025 alone, at least 14–17 billion USD were stolen worldwide through crypto fraud — and the trend is rising sharply.
  • Traditional investigative approaches often fail because they target a person instead of the infrastructure.
  • A blockchain is pseudonymous, not anonymous — every transaction remains permanently and publicly traceable.
  • The perpetrator's infrastructure usually leaves more traces than the initial contact with the victim.

2 The life cycle of a crypto fraud

To understand the infrastructure of professional criminals, it is helpful to examine the typical path of funds from the victim to their conversion into fiat currency as a process. This lifecycle repeats itself—with variations in detail—in the majority of the cases studied and forms the basis of any subsequent wallet analysis.

1Bank transferVictim pays Fiatto aCrypto exchange2ExchangeExchange inCryptocurrency —last KYC point3Receiving walletfirstOn-chain stationthe perpetrator4Layeringmulti-stageRedirect toConcealment5Collection walletConsolidationseveralVictims6Cash-OutConversion toFiat viaExchange or OTC
The life cycle of a crypto fraud in six phases. Four independent sacrifice paths typically converge into the same pooled wallet via different layering processes — and merge at the cash-out point.

Phase 1 — Bank transfer. The fraud begins outside the blockchain, with a bank transfer or card payment to a cryptocurrency exchange. Forensically, this is the easiest phase to document (bank statement + KYC data from the exchange). The date, amount, recipient's IBAN, and purpose of payment form the link to on-chain analysis.

Phase 2 — Exchange. The fiat deposit is exchanged for cryptocurrency and forwarded to a perpetrator's wallet. This is the last point with a direct, KYC-enforced link between a real person (victim) and a blockchain address before the funds enter the perpetrator's infrastructure.

Phase 3 — Receiving wallet and layering. The receiving wallet is usually only the first stage in a multi-stage forwarding process (layering) designed to make tracing more difficult and to tire out tracing tools. In practice, however, layering patterns are characteristic and recognizable.

Phase 4 — Pooled wallets and clusters. Funds from multiple layering chains—often from several victim cases—converge in a limited number of pooled wallets. This consolidation makes economic sense from the perpetrator's perspective and is the most important starting point for wallet clustering from a forensic point of view.

Phase 5 — Cash-Out. The final step is conversion into fiat currency or a marketable form (real estate, luxury goods, OTC resale). The cash-out is the most vulnerable point because it regularly involves a regulated entity subject to KYC (Chapter 7).

Key messages
  • The life cycle follows typical phases: bank transfer, exchange, receiving wallet, layering, pooled wallet, cash-out.
  • Bank transfers are the easiest forensic evidence to document — they link a real identity to the case.
  • The exchange is where the last direct, KYC-supported connection between the victim and the blockchain address is established.
  • Layering obscures the flow of money, but leaves behind characteristic, recognizable patterns.
  • Pooled wallets and the final cash-out are the most vulnerable points in the entire perpetrator chain.

3 The infrastructure of modern perpetrators

Professional crypto scammers rarely work with a single wallet. They operate complete, reusable systems of receiving, intermediary, and collection wallets, supplemented by exchange accounts, stablecoin routes, and OTC contacts—the actual subject of any serious wallet analysis.

Building blockFunction within the perpetrator infrastructure
Receiving walletsFirst on-chain station after the Exchange; often regenerated for each victim/campaign. Marks the unique starting point of a case; can be linked to others via time correlation.
Intermediate wallets / LayeringPure obfuscation; multiple redirects at short intervals, some with equally sized partial amounts ("peeling"/"splitting"). Automated scripting leaves regular patterns in seconds/minutes.
Collection walletsOrganizational center; this is where funds from many cases converge. If funds from several independent victims flow into this center, it is strong evidence of joint perpetration.
Exchange accountsWithout a cash-out channel, crypto assets are worthless. This is structurally necessary — and the point at which KYC/AML/information requests are most effective.
Cross-Chain BridgesTransfers between blockchains complicate analysis. Modern platforms (e.g., Crystal Intelligence) now fully map cross-chain transactions.
Stablecoins (USDT/USDC)Preferred for pooled wallets/cash-out (no price fluctuations). Approximately 84 TP3T of illegal inflows in 2025 — issuer cooperation (freeze/disclosure) increases traceability.
OTC brokerOver-the-counter exchange of large sums, sometimes without KYC. Preferred cash-out route — an area with regulatory catching-up.
2
Forensic finding no. 2

Offender infrastructures are generally reused multiple times because setting them up—especially acquiring functioning exchange and OTC access—is extremely costly for the perpetrators themselves. This reuse is the key lever in forensic investigations: A single identified component often leads to further, previously unknown victims.

Key messages
  • Professional perpetrators operate complete, reusable infrastructure systems rather than individual wallets.
  • Receiving and intermediate wallets serve to conceal the identity of the recipient; centralized wallets are the organizational hub.
  • Exchange accounts are the most valuable building block because without them, acquired crypto assets remain worthless.
  • Cross-chain transfers and stablecoins complicate analysis but do not prevent it — around 84 % of the illegal inflows in 2025 were attributable to stablecoins.
  • The reuse of these building blocks across multiple victim cases is the central lever of forensic investigations.

4 The Economics of Professional Crypto Scammers

The building blocks explain what a criminal infrastructure consists of—not why it looks the way it does. The answer lies in economics: Professional fraudsters operate like entrepreneurs. They minimize effort, optimize costs, and automate where it's worthwhile. This business logic gives rise to the recurring patterns that forensic analysis makes visible in the first place.

4.1 Perpetrators think in terms of marginal costs, not in terms of maximizing concealment.

A common misconception is that perpetrators exploit every technically possible means of concealment. In practice, infrastructures are only as complex as the case economically requires—no more so. Additional layering, cross-chain jumps, or intermediate wallets cost time, gas fees, and increase the probability of errors. Perpetrators stop where the marginal effort outweighs the marginal benefit.

4.2 Why infrastructure is reused

Building a functioning infrastructure is costly: generating wallets, configuring layering scripts, testing cross-chain routes, and, most importantly, acquiring exchange/OTC access—often with forged identity documents, credible account histories, and OTC contacts. This effort only pays off over multiple uses. The rational consequence: repeated use of the same shared wallets, exchange accounts, and OTC contacts across numerous victims.

Exchange account (KYC passed)90OTC contact70Pooled wallet structure35New wallet address4
Relative procurement costs of individual infrastructure components (illustrative). The more expensive a building block is to procure, the more frequently it is reused—and the more robust the subsequent cluster analysis. Illustrative values to clarify the basic logic.

4.3 Why wallets are recycled

Creating a new wallet address is technically practically free—yet existing intermediate and pooled wallets are reused. The reason lies in the operational complexity: each address must be monitored, supplied with funds, and integrated into the internal accounting system. The larger and more specialized a group, the more its structure resembles a traditional payment system with fixed accounts—and the more valuable the continuity of individual addresses becomes.

4.4–4.6 OTC, Exchange Accounts and Rational Ways

OTC brokers offer lower or no KYC requirements and the ability to exchange large sums without market movement—both of which reduce detection risk and costs, at the cost of dependence on a few „reliable“ contacts. A wallet is easily reproducible; an inconspicuous exchange account with trading limits and passed KYC is not—it is a scarce commodity. This scarcity explains why cash-out accounts remain identical across many unrelated cases, while upstream wallets vary. Offensive infrastructure is never random but the result of rational cost-benefit analysis—the real reason why patterns repeat and cash-out points converge.

3
Forensic finding no. 3

The economic logic of the perpetrators is the real key to understanding their technical infrastructure. Forensic investigators searching for patterns are essentially looking for the points where reuse is profitable for perpetrators—and it is precisely there that the most compelling evidence of clusters emerges.

Key messages
  • Perpetrators act economically — not driven by concealment, but by marginal costs.
  • Exchange accounts are more valuable than wallets because they are scarce and expensive to obtain.
  • Infrastructure is therefore reused — across many victims.
  • This is precisely how wallet clusters and converging cash-out points emerge.
  • Therefore, balance sheet analysis is more worthwhile than isolated risk scores.

5 Wallet Clustering

Wallet clustering assigns multiple blockchain addresses to the same economic actor with a high degree of probability — deliberately from a practical-investigative, not a mathematical-algorithmic perspective: How does an analyst recognize that multiple wallets belong together?

5.1 How can you recognize the same perpetrators?

  • Recurring pooled wallets into which multiple independent victimizations flow.
  • Identical or very similar layering patterns (intermediate steps, time intervals, amount structure)
  • Shared cash-out addresses on the same exchange
  • Reusing the same intermediate wallets across multiple campaigns
  • Sharing the same bridge route to the same destination chain

5.2 How can you recognize the same infrastructure?

Infrastructure clusters persist even when the individuals involved change (e.g., staff turnover in operations). They are characterized by consistent technical patterns—the same wallet generation logic, the same bridge protocol, the same OTC contact—over extended periods, even if individual upstream wallets change.

5.3 & 5.4 Multiple victims, practical starting points

The most reliable indicator is the demonstrable convergence of independent payment flows into the same pooled wallet or exchange account within a plausible timeframe. OSINT (identical communication patterns, website templates, payment requests) provides supporting, but not sufficient, evidence.

Starting pointMeaning
Balance sheet analysisAnalysis of the inflows and outflows of individual wallets over time — the single strongest methodological component (Chapter 6).
Time correlationTransactions occurring in close temporal proximity (e.g., multiple receiving wallets forwarding to the same collection wallet within minutes) indicate centralized, coordinated control.
ConsolidationsTargeted consolidation of balances from multiple addresses into a single target address — one of the strongest cluster signals, as it rarely occurs without common control.
Cash-outsA common endpoint for multiple chains at the same Exchange/OTC address closes the loop — often the decisive approach for information requests.
Key messages
  • Wallet clustering assigns multiple addresses to the same actor — practically, not purely mathematically.
  • Recurring pooled wallets and identical layering patterns are the strongest indicators of joint perpetratorship.
  • Infrastructure clusters persist even when the people involved change.
  • Time correlation and consolidations provide particularly robust cluster signals.
  • The common cash-out endpoint closes the circle and often provides the crucial approach.

6. Balance sheet analysis

Balance analysis of individual wallets is among the most effective, yet in practice least systematically used, tools—from the perspective of Finanz Forensik GmbH, the strongest single component of wallet analysis, stronger than any automated risk score. Instead of individual transactions, the entire account balance of an address is tracked over time, comparable to account movement analysis in banking.

6.1 Why inflows and outflows are more meaningful than risk scores

Risk scores assess an address's proximity to known illegal sources (mixers, darknet, sanctioned addresses). A high score is a useful initial indicator, but it doesn't replace a thorough analysis. More informative is the actual balance sheet movement: When and in what amounts do assets flow in, when and where do assets flow out—and does this create an economically plausible pattern that aligns with the alleged use, or not?

6.2 The central questions of balance sheet analysis

  • How much money flowed through the address in total (cumulative inflow and outflow)?
  • What was the maximum stock level, and when was it reached?
  • When did the consolidation take place — the targeted merging of data from multiple sources?
  • When did the cash-out begin, and over what period of time?
  • Which other victims can be attributed to the same infrastructure based on the inflow times?
  • Which exchange or OTC contact received the largest share of outflows?

These questions are not an end in themselves: This level of detail is precisely what authorities, public prosecutors and lawyers need in order to formulate a request for information, apply for an asset freeze or to provide a coherent basis for a civil lawsuit (Chapters 12/13).

The typical pattern of a collective wallet

The forensic value doesn't arise from an isolated transaction, but from observation: An address with no significant history grows to many times its initial inflow within a short time, before the entire amount is transferred to an identifiable exchange address. Rapid growth, sudden outflow—unusual for legitimate use, but the norm for professional pooled wallets. [Illustrative placeholder—constructed calculation example]

4
Forensic finding no. 4

In practice, a thorough balance sheet analysis regularly provides more reliable evidence for legally admissible documentation than an isolated risk score, because it makes the economic context of an address comprehensible and answers the specific questions that investigators, lawyers and courts actually ask.

Key messages
  • Balance analysis tracks the inflows and outflows of a wallet over time — similar to account transaction analysis.
  • It is more meaningful than an isolated risk score because it shows the economic context.
  • It answers what investigators need: peak value, consolidation point, start of cash-out.
  • Rapid accumulation followed by a sudden, complete outflow is the typical pattern for a pooled wallet.
  • These very questions form the basis of every forensic report that is admissible in court.

7 The Importance of Cash-Outs

Not every exchange involved in the flow of funds is a worthwhile target for investigation—some are merely transit points. The crucial factor is the actual cash-out point: the point at which crypto assets are finally converted into fiat currency, other assets, or a marketable form.

7.1 Why cash-outs are the most important investigative approach

Cash-out points are the point at which the anonymity benefits of blockchain end and regulatory instruments come into play. Unlike an intermediary wallet, an exchange is subject to KYC/AML obligations and is required to provide information. Since perpetrators are limited to a few payout points for economic reasons (Chapter 4), the cash-out exchange is often the key to identifying the real person.

7.2 KYC and AML as leverage

KYC and AML require exchanges to verify identities and report suspicious patterns. In the EU, this is based on a uniform framework: The MiCA Regulation (EU) 2023/1114 has established an EU-wide licensing and supervisory obligation for cryptocurrency asset service providers (CASPs) since the end of 2024. Additionally, the Transfer of Funds Regulation (Regulation (EU) 2023/1113, TFR) has required the transmission of complete originator and beneficiary data since December 30, 2024—the EU implementation of the FATF „Travel Rule“ (Recommendation 16), specified in the EBA Travel Rule Guidelines (EBA/GL/2024/11). If a cash-out address is associated with a MiCA-licensed exchange, an information request can ideally determine the account holder—and increasingly, the chain of previous transfers as well.

7.3–7.5 Freeze, data request, asset seizure

Many larger exchanges can temporarily freeze funds in connection with reported fraud cases. A timely, well-documented freeze request can prevent funds from being moved further before the conclusion of proceedings. Formal data requests (in criminal proceedings via mutual legal assistance requests, in civil proceedings via requests for information) are directed to the exchange of the cash-out address; the likelihood of success depends on the quality of the forensic documentation (Chapter 12). Assets seized can give rise to a criminal attachment order (Sections 111e et seq. of the German Code of Criminal Procedure) to secure subsequent confiscation (Sections 73 et seq. of the German Criminal Code) or a civil attachment order.

Key messages
  • Not every exchange in the cash flow is a target for investigation — the actual cash-out point is crucial.
  • MiCA and the Travel Rule (TFR) oblige crypto service providers across the EU to comply with KYC and disclosure requirements.
  • Cash-out points are the point where the anonymity benefits of blockchain end.
  • Timely freeze requests can prevent funds from being further diverted before the conclusion of the proceedings.
  • Identified cash-out addresses open the way to asset seizure and confiscation under Sections 73 et seq. of the German Criminal Code.

8 Recovery Scams: The Second Scam

A topic almost entirely absent from the literature, but regularly encountered in practice: the recovery scam. In short, the second scam often begins immediately after the first and specifically targets people who have already been harmed and are emotionally vulnerable due to the original crypto fraud.

1Initial fraudVictim loses cryptocurrency assets2Publicly visibleAdvertisement, Forum,Fraud warning3„"Recovery" contactFake forensic expert / authority /Lawyer, advance payment4Second damagefurther payments, oftenfateful
The recovery scam cycle. From the initial fraud to the public disclosure and the second, often more serious, financial loss.

As soon as a victim becomes publicly visible (report, forum post, review on a fraud warning site, contact with a law firm), they often end up on informal "lists" of resold victim data. Anti-fraud investigators describe it unequivocally: Once a victim is known, a second contact attempt often follows—by alleged data recovery specialists (Chainalysis/Operation Shamrock, cited in cryptonews.com, Nov. 2025).

AppearanceProceed
Classic recovery scam„"Recovery experts" proactively contact you, claiming to have located the data, and demand an upfront fee. After payment, contact ceases or further fees are charged.
Fake forensic expertsPerpetrators pose as blockchain forensic experts, present fake, technically sound reports and suggest a swift return of the victims — against advance payment.
Fake authoritiesAlleged employees of the police, public prosecutor's office, BaFin or international authorities demand "release fees" or "taxes" for the payout of seized assets.
Fake lawyersAllegedly specialized lawyers have already obtained a judgment and are demanding court/enforcement costs in advance.
Wallet Verification / Pay to WithdrawRequests to send an amount for "verification" or an "unlock fee" before each payout — both only serve to facilitate further payments.

Recovery scams exploit the emotional state after the damage: hope for restitution, shame about the initial deception, and the desire for quick correction significantly reduce the critical distance.

Identifying characteristics of reputable crypto forensics

Reputable service providers do not demand upfront payment for a "guaranteed" result—an analysis can document traceability, but never guarantee recovery. They operate under a verifiable company identity (legal notice, contact information, professional experience), generally do not contact victims unsolicited, and document their findings methodically and transparently rather than relying on mere assertions.

5
Forensic Finding No. 5

The second type of fraud is not a fringe phenomenon, but a regular consequence of every publicly disclosed cryptocurrency fraud case. Raising awareness about recovery scams should be an integral part of every initial contact with victims—not a secondary, incidental detail.

Key messages
  • The second scam often begins immediately after the first — as soon as a victim becomes publicly visible.
  • Fake forensic experts, fake authorities, and fake lawyers demand upfront fees for an allegedly secure repatriation.
  • Wallet verification and pay-to-withdraw are common methods to force further payments.
  • Reputable forensic service providers never guarantee a result and do not require advance payment.
  • Providing information about recovery scams belongs in every initial consultation — not at the end.

9 ways to identify perpetrator infrastructures: Anonymized case studies

Notice

The case studies are illustrative and anonymized. They summarize recurring patterns from many real-world studies without presenting a specific, identifiable case. [Illustrative placeholders — constructed case studies]

Case A — Four victims, one shared wallet. Four independent victims separately reported losses on the same fraudulent trading platform. Initially, the payment methods differed significantly (exchanges, receiving wallets, layering depths). However, analysis revealed that all four flows converged in the same centralized wallet after three to five intermediate steps—thus linking the initially unrelated cases to a single perpetrator infrastructure and allowing them to file a joint claim with the cash-out exchange.

Case B — Twelve wallets, one exchange address. Twelve seemingly independent wallets showed no direct connections. Only the examination of the final cash-out transaction revealed that all twelve paid into the same deposit address of a user account at a well-known exchange. This is typical of structures that deliberately obscure their origin at the wallet level but rely on a small number of accounts at the cash-out level (Chapter 4).

Case C — Multiple blockchains, one exchange. The targeted use of multiple chains via cross-chain bridges fragmented the analysis. Nevertheless, the same exchange and user account ultimately served as the cash-out source—an indication that cross-chain activity primarily obscures the analysis process and does not necessarily reflect a diversified cash-out structure.

6
Forensic Finding No. 6

In all three patterns, the crucial forensic starting point was not at the beginning, but at the end of the perpetrator chain—at the cash-out address. Wallet-based obfuscation at the upstream stages failed to prevent convergence at the payout point in any of the cases.

Key messages
  • Four independent victims can converge in the same shared wallet via different routes.
  • Twelve seemingly unconnected wallets can ultimately withdraw funds to the same exchange account.
  • Cross-chain activity across multiple blockchains often still results in a single exchange.
  • In all patterns, the crucial investigative approach lay at the end of the chain — not at the beginning.
  • Wallet-based obfuscation hardly prevents convergence at the cash-out point in practice.

10 The biggest misconceptions

In discussions with victims, law enforcement agencies, and lawyers, Finanz Forensik GmbH regularly encounters the same misconceptions about the traceability of crypto transactions. Myth versus forensic reality:

✕ Myth

A high risk score automatically means that the owner of the address is a perpetrator.

✓ Reality

A risk score assesses an address's proximity to known illegal activities. It is an indicator, not proof. Only balance sheet analysis and wallet clustering reveal whether and how an address is actually involved.

✕ Myth

Investigations are terminated once funds have been processed through a mixer.

✓ Reality

Mixers complicate analysis, but don't necessarily end it. Many implementations exhibit their own known patterns; modern tools continue to map inputs and outputs, and the flow to the mixer remains traceable.

✕ Myth

If crypto assets were forwarded, the coins "disappeared".

✓ Reality

Cryptocurrency assets don't disappear. Every transaction remains permanently and publicly documented. What's initially missing is simply the link to a real-world identity, not the transaction history.

✕ Myth

A deleted wallet app means that the wallet no longer exists.

✓ Reality

A wallet is not an app, but an address plus a private key. Deleting the app only removes the local interface; the address and history remain visible.

✕ Myth

Blockchain transactions are completely anonymous.

✓ Reality

Public blockchains are pseudonymous, not anonymous. Every address and transaction is viewable; only the direct identity link, which can often be established via KYC, OSINT, or behavioral patterns, is missing.

✕ Myth

An account balance of 0 means that no relevant activity took place there.

✓ Reality

Zero only shows the current state. What is crucial is the historical balance movement—how much value flowed in and out, and when (Chapter 6).

✕ Myth

Stablecoins like USDT cannot be traced.

✓ Reality

Stablecoins are just as traceable as other tokens. Additionally, centralized issuers (Tether, Circle) can freeze individual addresses upon justified request—sometimes making them easier to trace than other tokens.

Key messages
  • A high risk score is an indication, not proof of guilt.
  • Mixers complicate investigations, but do not end them — the flow to the mixer remains visible.
  • Forwarded crypto assets do not disappear; their history remains permanently documented.
  • Blockchains are pseudonymous, not anonymous — the attribution to an identity can often be established.
  • Stablecoins like USDT are just as traceable as other tokens — sometimes better through issuer freezes.

11 Technical custody ≠ ownership

An underestimated, yet legally crucial issue: the difference between technical control over a blockchain address and the legal allocation of assets — a recent higher court decision has given it increased practical relevance.

11.1 Private Key as a technical, not legal, standard

Whoever controls the private key has unrestricted technical access. This is distinct from the question of who legally owns the assets. A perpetrator who controls the key to a shared wallet, in which funds from multiple victims demonstrably flow, is not automatically the legal owner.

11.2 The decision of the Higher Regional Court of Braunschweig (1 Ws 185/24)

In a decision dated September 18, 2024 (1 Ws 185/24), the Higher Regional Court of Braunschweig (OLG Braunschweig) made a groundbreaking, yet ambivalent, ruling. A defendant had gained access to the seed phrase of another person's wallet within the context of a token project and transferred approximately 25 million units to his own addresses. The OLG upheld the Göttingen Regional Court's (LG Göttingen) lifting of an asset freeze (approximately €2.5 million) ordered to secure the confiscation of the proceeds. The court rejected charges of data espionage (§ 202a StGB – access data was known and used as intended), computer fraud (§ 263a StGB – a blockchain transaction does not contain a declaration equivalent to deception), and data alteration (§ 303a StGB – the data alteration is carried out by the decentralized network itself). As a result, the de facto appropriation through the mere use of a known key remained unpunished under criminal law.

11.3–11.5 Consequences and civil law implications

Technical access alone does not constitute a criminally relevant "theft" or "deception," especially if it is based on known access data and only violates a contractual ancillary obligation (e.g., arising from a trust agreement). Anyone relying solely on criminal law instruments incurs a considerable risk—the civil law basis for claims gains weight. Regardless of the criminal classification, claims for restitution (§ 985 German Civil Code) and unjust enrichment (§ 812 German Civil Code) regularly remain available; while § 985 traditionally requires a "thing" (§ 90 German Civil Code)—a point of contention in legal doctrine—courts have already recognized quasi-proprietary claims for restitution and enforcement. For confiscation under criminal procedure (§§ 73 et seq. German Criminal Code), a suitable connecting offense must exist; if it is lacking, asset protection is not possible, and victims are relegated to civil proceedings.

11.6 Practical implications for reports

Forensic reports should consistently separate technical findings („Address X controlled the power of disposal over Z units at time Y“) from legal assessment (reserved for the commissioning lawyers) — and be designed from the outset to support both criminal procedural and, in parallel and independently, civil legal claims under §§ 985, 812 of the German Civil Code (BGB).

7
Forensic Finding No. 7

The decision of the Higher Regional Court of Braunschweig (1 Ws 185/24) demonstrates that technical access to a wallet can remain without criminal consequences if there is no compelling underlying offense. In practice, this means that precise documentation of fund flows, understandable to non-technical users, is crucial for the enforceability of claims, not only in criminal proceedings but also under civil law—via Sections 985 and 812 of the German Civil Code (BGB).

Key messages
  • Technical access to a private key does not establish legal ownership of the assets.
  • The Higher Regional Court of Braunschweig (1 Ws 185/24) denied theft, computer fraud and data alteration in the case of mere key use.
  • Criminal law is not a safety net for every form of digital breach of contract.
  • Sections 985 and 812 of the German Civil Code (BGB) independently open up civil law claims for restitution and unjust enrichment.
  • Precise documentation of the flow of funds is at least as crucial in civil law as it is in criminal procedure.

12 requirements for a report admissible in court

A technically sound analysis is only effective if it is documented in such a way that it will stand up in court, before public prosecutors, or an exchange compliance department. Minimum requirements:

RequirementContents
documentationEach step of the analysis is documented in such a way that a knowledgeable third party can understand it without asking questions — complete addresses, transaction hashes, timestamps, tools used (e.g. Crystal Intelligence, Maltego).
SourcesEach finding must be traceable back to its source (on-chain observation, exchange information, OSINT). Established findings must be clearly distinguished from assumptions.
calculationsTotals, exchange rate conversions at the time of the transaction, balance sheet trends are documented in a traceable and reproducible manner (e.g., attached raw data exports).
TraceabilityAn independent expert must be able to independently reproduce the same analysis with the same initial data and arrive at the same results.
Screenshots & HashesScreenshots of explorers/platforms save the data state (labels change); transaction hashes are always in full text.
Chain of CustodyComplete documentation of who accessed which data and when, and what steps were taken — version control, tool versions, integrity checks.
Key messages
  • A report that can be used in court documents each step in such a way that a knowledgeable third party can understand it without asking questions.
  • Every finding must be traceable to its source — on-chain, exchange information, or OSINT.
  • Calculations and balance sheet trends must be stored in a reproducible manner, for example through raw data exports.
  • Screenshots and complete transaction hashes ensure the data remains as it was at the time of the investigation.
  • An unbroken chain of custody is a prerequisite for the admissibility of evidence in court.

13 What investigative authorities need

13.1 How should a report be structured?

  • Brief summary of the key findings on the first page (Executive Summary)
  • Clear chronological presentation of the cash flow, ideally supported visually.
  • Separate presentation of established facts and forensic assessments
  • Concrete, actionable recommendations (e.g., specific exchange including contact method for an information request)
  • Complete attachments including raw data, address lists and supporting documents

13.2 & 13.3 What really helps — and what doesn't

The following will significantly accelerate the investigation: the specific, named cash-out exchange including the deposit address, a reliable temporal correlation between inflows and outflows, and indications of further, previously unreported victims of the same infrastructure. Conversely, unstructured raw data exports without context, blanket risk assessments without justification, and speculation about perpetrator identities without solid evidence are of little help. Authorities benefit from precise, prioritized information—not from sheer volume of data.

Key messages
  • A good report begins with a concise executive summary of the key findings.
  • Established facts and forensic assessments should be presented clearly and separately.
  • The most helpful information is the specific cash-out exchange, deposit address, and time correlation.
  • Further, previously unknown victims of the same infrastructure are accelerating the investigation.
  • Unstructured data sets without context or unfounded speculation are of little help to authorities.

14 The Future of Crypto Forensics

Artificial intelligence will not only support cryptoforensics, but fundamentally change it — and the development is two-faced: it significantly accelerates investigations and at the same time the professionalization of the perpetrators.

  • Automated cluster detection across millions of addresses, on a scale no longer feasible manually.
  • Automated balance sheet analysis (Chapter 6) that highlights anomalies in inflow/outflow patterns in real time.
  • Identification of identical perpetrator structures across superficially unrelated cases
  • Detection of identical cash-out patterns, even with previously unconnected addresses.
  • Automated prioritization of investigative approaches based on probability of success and extent of damage.

The reality of this shift is illustrated by the perpetrators' perspective: According to Chainalysis data, AI-powered fraud operations generated an average of 4.5 times the revenue of traditional fraud cases in 2025—through deepfake videos of supposed executives, government officials, and influencers, as well as phishing-as-a-service. When perpetrators use AI for scaling, AI is no longer an optional add-on for investigators, but a necessary prerequisite.

AI-assisted operations4,5Traditional operations1,0
Revenue volume of AI-supported vs. traditional fraud operations (2025). AI-assisted operations achieved on average 4.5 times the expected returns (Chainalysis, 2026 Crypto Crime Report — Scams).

Since criminal infrastructures operate across borders, success increasingly depends on international cooperation (Europol, Interpol, mutual legal assistance). The greatest impact arises where financial investigations, sanctions law, and prosecution intersect (Huione dismantling, Prince Group sanctions). Since the end of 2024, MiCA and the Travel Rule (TFR) have created a uniform, disclosure-based EU framework and should significantly facilitate the traceability of cash-outs between regulated providers; the treatment of self-hosted wallets remains under review. An increasing integration of OSINT and on-chain analysis is to be expected, as well as a growing role for private forensic service providers as intermediaries between victims, exchanges, and authorities.

8
Forensic Finding No. 8

Artificial intelligence is no longer a vision of the future, but is already an integral part of both the perpetrators' and the investigators' work. Any service provider, law firm, or government agency that fails to invest in AI-supported analysis tools will be at a structural disadvantage in the medium term when faced with increasingly AI-driven criminal structures.

Key messages
  • Artificial intelligence is fundamentally changing crypto forensics, not just providing support.
  • AI-powered fraud operations generated 4.5 times the revenue volume compared to traditional methods in 2025.
  • Automated cluster and balance sheet analysis shifts analyst time from discovery to verification.
  • Since the end of 2024, MiCA and the Travel Rule (TFR) have created a uniform, information-sharing EU framework.
  • Those who do not invest in AI-supported analysis fall behind AI-supported perpetrator structures.

glossary

AMLAnti-Money Laundering — regulatory requirements for combating money laundering.
addressA publicly visible identifier on a blockchain to which values are assigned.
Asset RecoveryLegal and forensic efforts to recover misappropriated assets.
Information requestFormal request to an exchange or authority for the release of account information.
claim for unjust enrichmentClaim under § 812 BGB for the reversal of an unjustified transfer of assets.
Balance sheet analysisAnalysis of the inflows and outflows of a wallet over time (Chapter 6).
Blockchain analysisSystematic analysis of transaction data to clarify money flows.
bridgeTechnical mechanism for transferring value between blockchains.
CASPCrypto-Asset Service Provider — a MiCA-licensed crypto asset service provider.
Cash-OutConversion of crypto assets into fiat or other usable assets.
CEXCentralized Exchange — a centralized, regulated trading platform.
Chain of CustodyComplete documentation of the handling of evidence.
ClusteringAssignment of multiple addresses to a single economic actor.
Computer fraudSection 263a of the German Criminal Code (StGB); according to the Higher Regional Court of Braunschweig, this is generally not applicable in the case of a mere blockchain transaction.
Cross-chain transferTransfer of value between different blockchain networks.
DEXDecentralized Exchange — a decentralized trading platform without a central custodian.
EBAEuropean Banking Authority — among other things responsible for the Travel Rule Guidelines.
confiscationAsset confiscation under criminal procedure pursuant to Sections 73 et seq. of the German Criminal Code.
Receiving walletFirst on-chain address to receive funds from an exchange.
FATFFinancial Action Task Force — originator of the „Travel Rule" (Recommendation 16).
FreezeTemporary freezing of an account/balance by Exchange or authority.
Gas FeeTransaction fee for processing a blockchain transaction.
HashUnique cryptographic fingerprint, used, among other things, to identify a transaction.
claim for surrenderClaim under § 985 BGB for the return of an item or a property-like value.
Impersonation fraudFraud in which perpetrators impersonate authorities, companies, or well-known individuals.
KYCKnow Your Customer — Identity verification of customers by regulated providers.
LayeringMulti-stage transfer of funds to conceal their origin.
mixerService for mixing crypto assets from multiple users for the purpose of concealment.
MiCAMarkets in Crypto-Assets — Regulation (EU) 2023/1114 on the regulation of crypto assets/services.
OSINTOpen Source Intelligence — research based on publicly accessible sources.
OTC brokerProviders for the over-the-counter trading of large amounts of crypto assets.
Pay-to-WithdrawRecovery scam variant with repeated fees before alleged payout.
peelingLayering technique: repeatedly splitting small amounts from a larger sum.
Pig ButcheringFraud in which victims are emotionally and financially manipulated over a longer period of time.
Private KeySecret cryptographic key available via a wallet.
PseudonymityAddresses are public, but not directly linked to an identity.
Recovery scamSecond fraud against already victims under the pretext of recovery (Chapter 8).
Risk ScoreAutomated risk assessment of an address based on its history.
Romance scamFraud involving a fake romantic relationship.
Collection walletAddress where funds from multiple sources are consolidated.
Self-Hosted AddressPrivate wallet address, not held with a regulated service provider.
SplittingDividing an amount into several equal sub-amounts for the purpose of concealment.
StablecoinCryptocurrency with a value pegged to a reference currency (usually USD).
perpetrator economyCost-benefit logic behind the construction and reuse of perpetrator infrastructure (Chapter 4).
Transaction hashUnique identifier of a single blockchain transaction.
Travel RuleObligation (FATF Recommendation 16, EU: Regulation 2023/1113) to transmit client/recipient data.
TFRTransfer of Funds Regulation — Regulation (EU) 2023/1113, EU implementation of the Travel Rule.
UTXOUnspent Transaction Output — a credit-based model used, among other things, in Bitcoin.
Asset seizureProvisional securing of assets pursuant to Sections 111e et seq. of the Code of Criminal Procedure.
Wallet ClusteringAssignment of multiple addresses to a single actor (Chapter 5).
Time correlationAn analytical method that correlates transactions that occur close together in time.
intermediate walletAddress that only temporarily holds funds in a layering scheme.

Sources

Analysis & DataChainalysis, 2026 Crypto Crime Report — Scams (2026) · Crystal Intelligence (Blockchain analysis) · Maltego (OSINT/Link analysis) · Europol (Organizational Crime Reports) · BKA, Federal Situation Report on Cybercrime 2025 · BSI.
regulationRegulation (EU) 2023/1114 (MiCA) · Regulation (EU) 2023/1113 (TFR) · EBA/GL/2024/11 (Travel Rule Guidelines) · FATF Recommendation 16.
RightOLG Braunschweig, Decision of 18.09.2024 — 1 Ws 185/24 · §§ 202a, 263a, 303a, 73 ff. StGB · §§ 111e ff. StPO · §§ 90, 812, 985 BGB.

Our services

Finanz Forensik GmbH specializes in crypto forensics, blockchain analysis, OSINT investigations and asset recovery — for victims, law firms, auditors and investigative authorities.

PerformanceWhat you will receive
Blockchain Analysis & TracingTracing money flows via layering, cross-chain and pooled wallets to the actual cash-out point.
Wallet ClusteringAttributing multiple addresses and victim cases to a common perpetrator infrastructure via balance sheet analysis, time correlation, and consolidation.
Balance sheet analysisTransparent inflow/outflow and peak level analysis of individual wallets as a basis for information requests and asset seizure.
OSINT investigationLinking on-chain structures with publicly accessible off-chain traces of the perpetrators.
Report admissible in courtDocumentation with complete hashes, source information, reproducible calculations and a complete chain of custody.
Asset Recovery & Cooperation with AuthoritiesPreparation for freeze requests, information requests, asset seizure (§§ 111e ff. StPO) and civil claims (§§ 985, 812 BGB).
David Lüdtke
David Lüdtke
Managing Director · OSINT Analyst & Crypto Forensic Expert · Financial Forensics GmbH

Court-admissible crypto transaction analysis, OSINT-based asset investigation, and expert reports for defense attorneys, insolvency administrators, and companies. Certified Crystal Expert (CECF, CEEI, CEUI).

Have you been a victim of crypto fraud? Act quickly.

We trace money flows via layering and cross-chain to the actual cash-out point, uncover wallet clusters, and deliver court-admissible reports for freeze requests, information requests, and asset seizures.

Official notice from Finanz Forensik GmbH

We expressly point out that the website finanzforensik.com [This company] has no business or legal connection to our company. You can officially reach us exclusively at [phone number/email address]. finanz-forensik.de.

We have already filed a criminal complaint and submitted the case to the relevant authorities. You can independently verify who we are at any time: Finanz Forensik GmbH is registered with the Hanau District Court under [number of names missing in original text]. HRB 100521 registered.

We provide you with the complete commercial register extract and our detailed documentation of the process here.