This glossary covers the key terms used in cryptocurrency security, fraud investigation, blockchain forensics, and money laundering analysis. Each entry includes a plain-language definition, how it works in practice, and how investigators or victims can detect it. Updated for 2026.
Jump to Section
Scam & Fraud Types
A long-con investment fraud where scammers build a romantic or friendship relationship with a victim over weeks or months before introducing a fake crypto investment platform. The victim is gradually encouraged to deposit increasing amounts — the "fattening" — before the platform disappears and all funds are stolen. The name comes from the Chinese term for "slaughtering the pig."
A fraud where the scammer builds a romantic relationship with the victim entirely for financial exploitation. Unlike pig butchering (which uses romance as a vehicle to an investment scam), romance scams may involve direct requests for money, gift cards, or crypto for fabricated emergencies — medical crises, travel problems, business failures.
A DeFi scam where project developers drain investor funds by removing liquidity, abandoning the project, or exploiting a backdoor in the smart contract after enough investor capital has been deposited. Common in token launches and NFT projects.
A second-wave fraud targeting people who have already been scammed. Recovery scammers pose as investigators, law enforcement, or recovery specialists and promise to retrieve stolen funds for an upfront fee. They specifically target people who have recently filed fraud reports or posted about being scammed.
A market manipulation scheme where organizers accumulate a low-cap token, then artificially inflate its price through coordinated buying, social media hype, and fake volume — then sell ("dump") their holdings at the peak, crashing the price and leaving other investors with losses.
A fraudulent website or app designed to look like a legitimate cryptocurrency exchange or investment platform. Victims deposit funds and see fake balances showing profits. When they attempt to withdraw, they're told they owe taxes, fees, or other charges — which are just additional theft mechanisms.
A social engineering attack where victims are tricked into revealing seed phrases, private keys, or login credentials through fake websites, emails, or messages impersonating legitimate services — exchanges, wallets, or support teams.
A smart contract attack where a victim is tricked into signing a transaction that grants unlimited approval for a malicious contract to spend their tokens. Common in fake NFT mints, fake airdrop claims, and malicious DeFi sites.
An attack where a criminal convinces a mobile carrier to transfer a victim's phone number to a SIM card the attacker controls. This allows them to intercept SMS-based two-factor authentication codes and gain access to exchange accounts and wallets.
Blockchain Forensics Terms
A forensic technique that maps the complete flow of funds across the blockchain — tracking every transaction from origin through intermediate wallets to final destination. The resulting graph shows exactly how money moved, how it was split or consolidated, and where it ultimately ended up.
The process of grouping multiple wallet addresses that are likely controlled by the same entity, based on behavioral patterns, transaction inputs, timing analysis, and address reuse. Clustering reduces a sprawling network of hundreds of wallets to a manageable set of actors.
The process of linking a wallet cluster to a known real-world entity — an exchange, a darknet market, a sanctioned address, or a previously identified criminal organization. Attribution converts an anonymous address into a named actor.
The documented record of how digital evidence was collected, preserved, analyzed, and reported — establishing that evidence has not been tampered with and is admissible in legal proceedings. In blockchain forensics, chain of custody includes documentation of every transaction hash, wallet address, timestamp, and methodology step.
The collection and analysis of publicly available information to support an investigation. In blockchain forensics, OSINT bridges the gap between on-chain wallet addresses and real-world identities — using social media, domain records, forum posts, and other public sources.
The systematic analysis of on-chain transaction data to identify illicit activity, map criminal networks, and produce actionable intelligence. Broader than forensics — includes proactive monitoring, threat actor profiling, and pattern recognition across multiple cases.
Money Laundering & Obfuscation
A service that pools cryptocurrency from multiple users and redistributes equivalent amounts to different addresses, breaking the direct transaction link between sender and receiver. Used by criminals to obscure the origin of illicit funds.
Moving funds across multiple blockchains via bridges or cross-chain swaps to complicate forensic tracing. A common laundering pattern in large crypto fraud operations — funds may move from Bitcoin to Ethereum to Tron across multiple hops.
A laundering technique where stolen funds are immediately split across many wallets after receipt to reduce traceability and complicate investigation. A single theft may fan out to 50 or 100 wallets within minutes.
The second stage of money laundering — moving funds through multiple transactions, conversions, and accounts to obscure their origin. In crypto, layering involves combinations of mixing, chain hopping, DEX swaps, and wallet fan-out.
A cryptocurrency designed to provide transaction privacy by obscuring sender, receiver, and amount information. Monero (XMR) is the most widely used privacy coin and the most significant obstacle to blockchain tracing.
DeFi & Smart Contract Exploits
An attack exploiting uncollateralized loans that must be borrowed and repaid within a single blockchain transaction. Attackers borrow massive amounts of capital, manipulate prices across protocols, and repay the loan — all in one transaction — leaving the targeted protocol with losses.
A smart contract vulnerability where a malicious contract repeatedly calls back into a target contract before the first execution completes — draining funds in a loop. The DAO hack (2016), which led to the Ethereum hard fork, was a reentrancy attack.
An attack targeting cross-chain bridge protocols — the infrastructure that allows assets to move between blockchains. Bridge exploits have been among the largest individual crypto thefts, with single incidents exceeding $600 million.
Technical Attack Methods
The theft of a wallet's 12 or 24-word recovery phrase, which grants complete and permanent control over all assets in that wallet. Anyone with the seed phrase owns the wallet — there is no recovery mechanism once a seed phrase is stolen.
Malware that monitors the clipboard for cryptocurrency addresses and silently replaces them with an attacker-controlled address. Victims copy what they believe is the correct destination address, paste it, and send funds directly to the attacker.
An attack where tiny amounts of cryptocurrency ("dust") are sent to many wallet addresses. If the recipient later spends that dust in a transaction combined with other funds, it can allow the attacker to de-anonymize the wallet by linking addresses together.
Legal & Regulatory Terms
Identity verification requirements that regulated financial institutions — including cryptocurrency exchanges — must apply to their customers. KYC data typically includes name, address, government ID, and sometimes source of funds documentation.
A bilateral or multilateral agreement between countries that allows law enforcement agencies to share evidence and cooperate in criminal investigations across borders. Relevant when stolen crypto is traced to an exchange operating in a foreign jurisdiction.
An emergency court order that freezes assets pending further legal proceedings. In crypto fraud cases, TROs can be used to freeze exchange accounts before stolen funds are withdrawn — requiring swift action and strong forensic evidence.
Encountered One of These in Your Case?
A blockchain forensic investigator can trace what happened to your funds, identify who was behind it, and produce documentation your attorney or law enforcement can act on. Free consultation — no commitment.