← Back to Blog

OSINT for Blockchain Forensic Investigators — What It Adds and Where It Fails

A working investigator’s guide to the OSINT toolkit, the methodology for bridging wallets to real-world identity, the attribution wins it makes possible, and the limits every practitioner has to respect.

OSINT constellation diagram showing how social media, breach data, infrastructure records, and behavioral patterns connect a pseudonymous wallet to a real-world identity
The 30-Second Summary

OSINT (open-source intelligence) is how blockchain forensic investigators bridge the on-chain world to real-world identity. On-chain analysis tells you what wallets did. OSINT helps you understand who controls them. The discipline is the integration: every OSINT lead checked against on-chain reality, every on-chain finding corroborated against OSINT context, packaged into a forensic report defensible against cross-examination.

The toolkit in 2026 spans infrastructure analysis (urlscan.io, SecurityTrails, DomainTools, Wayback Machine), breach data (Dehashed, Have I Been Pwned, Intelligence X), account discovery (OSINT Industries, public profile traces), community intelligence (ZachXBT, Chainabuse, Scam Sniffer, SEAL-ISAC), and authoritative sources (OFAC SDN list, court filings, government press releases). Each closes a different gap; using them in combination is what produces attribution that holds up.

This article is the practitioner's walkthrough — the toolkit, the methodology, the wins, the failure modes, the legal boundaries, and what OSINT findings actually look like in court.


What OSINT Actually Means in Blockchain Forensics

The phrase "open-source intelligence" gets used to mean a lot of different things. In a defense or intelligence-community context, it covers a wide universe of public collection. In blockchain forensics, the working definition is narrower and more specific.

OSINT in this context is the disciplined use of publicly available information to bridge the pseudonymous on-chain world to real-world identity, behavior, or context. The on-chain data tells you what happened; OSINT helps you understand who, why, and from where.

The categories an investigator actually pulls from:

  • Social media — Twitter/X, Telegram, Discord, Reddit, Bitcointalk, Medium — where scammers post addresses, dispute scams, recruit accomplices, or accidentally tag themselves
  • Infrastructure records — WHOIS, DNS history, SSL certificates, hosting providers — for any phishing site, fake exchange, or scam landing page involved in the case
  • Developer footprints — GitHub commits, code reuse patterns, deployment-wallet correlations, even handles in commit signatures — that tie smart contracts back to real authors
  • Breach data — leaked credentials, account dumps, breached forum posts — that connect emails, usernames, and IPs across platforms
  • Community intelligence — published lists from ZachXBT, Chainabuse, Scam Sniffer, SEAL-ISAC, CryptoScamDB — that flag known-bad addresses and their operators
  • Behavioral signals — timezone patterns of activity, denomination preferences, repeated DEX choices — that act as a "digital signature" harder to hide than wallet rotation
  • Authoritative sources — OFAC SDN list, court filings, indictments, government press releases, regulatory enforcement actions
  • Ephemeral evidence — archived versions of pages, deleted tweets, expired domains — preserved through Wayback Machine, archive.today, and urlscan.io's history

The skill isn't knowing the tools. The skill is knowing which combination produces a defensible attribution for a particular case — and which combination is going to fail validation when the on-chain evidence comes in.


Why On-Chain Analysis Alone Isn't Enough

Blockchain transparency is genuinely powerful. Every transaction, every wallet balance, every contract interaction is public. An investigator can build the entire forward and backward graph of fund flows from any starting address, in real time, without subpoenas or warrants. That access is unique among financial systems.

But the pseudonymity is also genuine. A wallet address has no built-in identity. Two wallets that behave identically might be the same operator or might be unrelated coincidences. A wallet flagged as belonging to a sanctioned group might be a fresh address controlled by the same operator or a stale address abandoned years ago. Without some layer of attribution beyond the on-chain data itself, the investigator's work product reduces to: "Funds went from address A to address B." True, but not useful.

The actions an investigation needs to drive — subpoenas to exchanges, freeze requests to stablecoin issuers, civil suits, criminal referrals, OFAC sanction additions — all require attribution beyond pseudonymity. Even the most aggressive Tether freeze request requires the issuer to believe the addresses are scammer-controlled, which requires evidence beyond "they received funds in a suspicious pattern." The evidence that closes that gap is OSINT.

This is why modern forensic practice integrates the two. We cover the integrated trace methodology in how blockchain forensic investigators trace crypto in 2026; this article goes deep on the OSINT half of that integration.


The OSINT Toolkit, by Source Category

The catalogue below is the toolkit a practicing investigator actually pulls from. Each tool fills a specific role; the goal is fluency in combination, not encyclopedic coverage of any one of them.

Infrastructure analysis

ToolWhat it doesWhy investigators use it
urlscan.ioCaptures historical scans of any URL with full request graph, screenshots, and JS bundle analysisFor any phishing site or fake exchange in the case, urlscan often has historical captures even after the site goes down
SecurityTrailsHistorical DNS records, WHOIS, subdomains, and infrastructure mappingConnects related domains run by the same operator across time — phishing kits often reuse hosting
DomainToolsWHOIS, registrant history, domain ownership trackingPulls registrar emails and contact info from the moment of registration, even if later anonymized
RiskIQ / PassiveTotalPassive DNS and SSL certificate correlationIdentifies infrastructure pivots when a scammer rotates domains while keeping certificates or hosting consistent
Wayback MachineArchived snapshots of web pagesRecovers deleted phishing landing pages, fake exchange interfaces, and operator content removed after the fact
archive.todayOn-demand archive of any URLThe investigator's own evidence preservation — capture suspect pages immediately for chain-of-custody

Account discovery and breach data

ToolWhat it doesWhy investigators use it
OSINT IndustriesReverse lookup: feed an email, phone number, username, or wallet and surface connected accounts across hundreds of platformsFastest way to map an operator's online footprint; commonly identifies overlooked side accounts
DehashedSearchable database of breached credentialsIf an operator's email appears in a breach, this is where you find it — with passwords, hashes, and associated metadata
Have I Been Pwned (HIBP)Free breach exposure check for an emailQuick first-pass check before paying for deeper Dehashed-style queries
Intelligence XIndex of leaked, deleted, or hard-to-reach data including paste sites, dark-web content, and document leaksSurfaces context Google can't reach — particularly for actors who post on Russian or Chinese forums
MaltegoGraph visualization for OSINT pivots across data sourcesFor complex investigations involving many entities; produces visual artifacts useful in reports

Community intelligence and threat reports

SourceWhat it providesWhy investigators use it
ZachXBT (Twitter/X)Independent on-chain investigations with public attributionThe single highest-signal community source for major hacks; often first to attribute
Chainabuse (TRM Labs)Community-reported scam addresses with case contextCross-reference any suspect address against thousands of victim reports
Scam SnifferReal-time wallet drainer monitoring and alertsParticularly strong for phishing-drainer operations and approval-scam tracking
CryptoScamDBCommunity database of scam URLs and addressesHistorical record of confirmed scam infrastructure
SEAL-ISACSecurity Alliance threat intelligence sharingReal-time coordination among security firms during active incidents
TRM Labs / Chainalysis / Elliptic blogsDetailed post-incident analysesAuthoritative published analyses suitable for citation in forensic reports

On-chain entity context

ToolWhat it providesWhy investigators use it
Etherscan / Solscan / BscScanBlock explorers with entity tags, public notes, and labeled addressesFirst stop for any wallet lookup; tags often confirm exchange or exploiter attribution
Arkham IntelligenceAggregated on-chain entity attribution and clusteringStrong on linking wallets to known exchange addresses, named entities, and historical events
MistTrackAddress risk profiling and labeled entity contextParticularly strong for ransomware and DPRK-related entities
Breadcrumbs / MetaSleuthVisual transaction graphing for non-paid analystsFree or low-cost alternatives to Chainalysis Reactor for graph building

Authoritative public sources

SourceWhat it providesWhy investigators use it
OFAC SDN listU.S.-sanctioned individuals, entities, and crypto addressesThe single highest-authority attribution source; sanctioned addresses must be frozen by U.S.-touching exchanges
U.S. court filings (PACER)Indictments, civil complaints, and supporting affidavitsMany DOJ crypto cases include named addresses and detailed attribution rationale
DOJ / FBI / Treasury press releasesOfficial attribution and enforcement actionsCitation-grade source for forensic reports
State AG enforcement actionsState-level civil and criminal proceedingsOften surface attribution for crimes that don't reach federal scrutiny

Methodology: From Wallet to Identity

The standard OSINT workflow when starting from a wallet address. This is the playbook I run on most cases — not every step on every case, but the order of operations is consistent.

Step 1: On-chain context first

Before going to OSINT, lock in the on-chain context. Pull the wallet on Etherscan, Arkham, and MistTrack. Note any entity tags. Identify the funding source (where did this wallet first receive funds?), the most active counterparties, and any cash-out exchange touchpoints. The on-chain pattern tells you what kind of operator you're dealing with before you spend any time on OSINT.

Step 2: Direct address mentions

Search the wallet address as a literal string across:

  • Twitter/X (current and historical via the Wayback Machine of specific user pages)
  • Reddit (use Pushshift or alternative Reddit search archives if the post was deleted)
  • GitHub (commits, issues, comments, repository content)
  • Bitcointalk and other crypto forums (where many older addresses were originally posted)
  • Telegram (search public channels via @SearchSeeBot or similar)
  • Medium and other long-form platforms
  • Chainabuse and CryptoScamDB for community reports tagged to the address
  • Pastebin and similar — some operators post their addresses publicly without realizing

A surprising number of cases get cracked at this step. Operators are not always operationally careful; they sometimes post their own addresses asking for tips, complaining about freezes, or recruiting victims.

Step 3: Infrastructure attribution (if a phishing site or fake exchange is involved)

For any URL the victim interacted with, pull the full infrastructure history:

  • urlscan.io/search?q=domain:scamsite.com — pulls every historical scan with screenshots, JS bundles, and request graphs
  • SecurityTrails for full WHOIS history, related subdomains, and other domains by the same registrant
  • DomainTools for WHOIS history including any pre-anonymization registrant data
  • SSL certificate transparency logs (crt.sh) for related certificates issued to the same operator

The infrastructure layer is where amateur operators leak the most identity. Reused registrar emails, hosting accounts that connect to other sites, SSL certificates issued to clusters of related domains — all of it shows in the public record.

Step 4: Username and email pivots

If any step above surfaces a username, email address, or persistent handle, pivot through OSINT Industries and Dehashed:

  • OSINT Industries: feed the username or email and see every connected account across hundreds of platforms (Instagram, Telegram, Discord, dating apps, gaming platforms, crypto exchanges with public username discovery)
  • Dehashed: search for the email or username across breached datasets — surfaces additional emails, password reuse patterns, and other accounts the same actor controls
  • Have I Been Pwned: free first-pass check on emails before paying Dehashed for deeper queries

Step 5: Behavioral attribution

Behavioral attribution is the most underrated category in OSINT. The patterns:

  • Timezone: map all on-chain activity by the wallet (and any clustered wallets) onto a 24-hour distribution. Operators concentrated in UTC+8-9 (East Asia) show distinctly different patterns from UTC-5 (US East Coast)
  • Denomination preferences: exact-amount transfers (e.g., precisely 1.0 ETH) are common from exchanges; oddly precise sub-denominated amounts often reveal scripted operations
  • Service preferences: consistent use of the same DEX, the same bridge, the same mixer is a digital signature; Lazarus's preference for Thorchain + eXch + Wasabi is identifiable across multiple incidents
  • Linguistic patterns: if operators communicate publicly (in Telegram, Discord, etc.), language analysis — idioms, typos, code-switching — can establish attribution between separate accounts
  • Operational habits: always cashing out in fixed batches, always using the same recovery wallet pattern, always rotating new addresses on a fixed schedule — all leave signatures

Behavioral attribution is what makes "the Phemex hacker is the Bybit hacker" possible across separate incidents. The wallet rotates; the habits don't.

Step 6: Cross-validate everything

Every OSINT lead, before it goes into a report, gets validated against the on-chain record. If a Telegram handle claims to control the wallet, look for on-chain behavior consistent with the persona's claims. If a breach connects an email to a username, look for that username on-chain (via Etherscan tags, Arkham labels, or community sources). If a community report flags the address as a scammer, verify the on-chain pattern matches scam behavior rather than coincidence.

This cross-validation step is what separates forensic-quality attribution from speculative attribution. It's also the step that gets skipped most often by inexperienced investigators producing reports that don't survive cross-examination.


Where OSINT Cracks Attribution Open

The cases where OSINT does the heavy lifting, in rough order of frequency:

Phishing operations with reused infrastructure

Wallet drainer operations like Inferno Drainer, Pink Drainer, and Angel Drainer rotate phishing domains constantly — but the underlying infrastructure (hosting providers, registrar accounts, SSL patterns) often persists across rotations. urlscan.io and SecurityTrails reveal these connections in seconds. A single drained-wallet case can be linked to hundreds of others through shared infrastructure attribution.

Romance and pig butchering operations with operator slip-ups

Compound-based pig butchering operations are professionally structured, but individual operators slip. Photos with metadata, time-zone inconsistencies in chat logs, "investment platform" domains with recoverable WHOIS history, recovery-scam follow-ups using the same Telegram handle as the original scam — all of these surface in OSINT and can build a profile of the specific compound or operator.

State-sponsored attribution via behavioral pattern matching

The Lazarus / DPRK attribution chain across the Phemex, Ronin, WazirX, and Bybit hacks is largely behavioral. The same DEXs in the same sequence, the same bridges, the same mixers, the same denomination patterns. ZachXBT's attribution of the Bybit hack to Lazarus within hours rested entirely on this kind of pattern recognition. The publicly-released address list itself is a textbook example of an OSINT artifact — the kind of work product community investigators use to seed every subsequent forensic engagement on the same operator:

The single most public example of OSINT-driven attribution paying off in 2025 was Arkham Intelligence's $1B Bybit hack bounty. Arkham had a standing public bounty for definitive proof of the attacker's identity. ZachXBT submitted his analysis — test transactions, connected wallets, behavioral pattern matches against prior Lazarus operations — and won the bounty within hours of the theft. The whole sequence is a textbook case of how community-led OSINT now operates inside a formal incentive structure rather than just as informal investigation.

Defendant identification via document leaks and court filings

Once a case enters the judicial system, the OSINT layer expands dramatically. Indictments, civil complaints, and supporting affidavits often include named addresses, attribution rationale, and corroborating evidence that becomes citation-grade for related investigations. PACER searches on related entities frequently surface valuable context for parallel investigations.

OFAC sanction integrations

The OFAC SDN list is the highest-authority attribution source available. Once an address is sanctioned, it carries irrefutable attribution that any U.S.-touching exchange must respect. Cross-referencing case wallets against the SDN list (and against historical Treasury press releases for context) is one of the highest-ROI OSINT moves possible — takes minutes, occasionally cracks the case wide open. The Chainalysis breakdown of the Tornado Cash sanction is the canonical reference for understanding how SDN designations flow through to on-chain enforcement.


Where OSINT Fails — The Limits Investigators Respect

OSINT is powerful but not omniscient. The failure modes worth knowing:

⚠ The five recurring failure modes

Every working investigator runs into these. Skip them at your own risk.

1. False-positive blacklist tags

Community-reported blacklists (Chainabuse, CryptoScamDB, Scam Sniffer) are valuable signals, but they include noise. An address can end up on a blacklist because of a misreport, a coincidental association, or a malicious false flag from a competitor. Always treat blacklist entries as leads, not conclusions. Validate the on-chain pattern matches scam behavior before incorporating the tag into a report.

2. Intentional deception

Sophisticated operators set up deception layers specifically to mislead investigators — sock-puppet accounts that "claim" to control specific wallets, planted social media posts, fake document leaks, and decoy domains designed to misdirect attribution. Lazarus has been observed using these techniques to throw investigators off their actual infrastructure. The mitigation is independent corroboration: never rely on a single source for any attribution that matters.

3. Ephemeral evidence

The web is mortal. Tweets get deleted within hours of being noticed; phishing sites go offline within days; Telegram channels get banned; accounts get suspended. If you find OSINT evidence relevant to a case, archive it immediately — archive.today, Wayback Machine, urlscan.io, screenshots with timestamps, and full HTML downloads. Evidence you didn't preserve is evidence you don't have when the report goes to court.

4. Breached data reliability and ethics

Breached credential databases (Dehashed, Intelligence X) contain valuable data that frequently cracks attribution — but the underlying breaches were illegally obtained, and in some jurisdictions using them is itself questionable. Even where it's legal, the data is often outdated, partial, or contaminated. Use breach data as a lead source; corroborate any finding through legally-obtained sources before relying on it in a report.

5. The irreducible problem: OSINT alone never proves wallet ownership

This is the most important limit and the one most often violated. OSINT can establish strong association — sometimes overwhelming association — between a wallet and a real-world identity. It cannot prove ownership. The only thing that proves ownership is on-chain evidence demonstrating the entity's exclusive control. Every responsible OSINT-driven attribution must be paired with on-chain corroboration that survives an independent technical review. Without that pairing, the attribution is speculative at best and indefensible at worst.

The Legal and Ethical Lines

OSINT operates in a gray zone. Most of what you can do is legal; some of what's tempting isn't. The lines that actually matter:

Public information is generally fair game

Anything posted publicly — tweets, public Telegram messages, GitHub repos, public WHOIS, news articles, court filings — is collectable, archivable, and citable without controversy. The volume of public material in any modern crypto investigation is enormous; you don't need to push into gray areas for most cases.

Sock puppet accounts are legal but Terms-of-Service constrained

Creating a non-attributable account on Twitter, Telegram, or Discord to view a target's public content is legal but typically violates each platform's Terms of Service. The platform can ban the account; the data collected is still usable in most contexts. The professional norm is to use sock puppets sparingly and for legitimate investigative purposes only.

Breached data is jurisdiction-dependent

The legal status of querying breach databases varies by jurisdiction. In the U.S., querying paid services like Dehashed is generally tolerated for investigative purposes; in some EU jurisdictions, the same activity may run into GDPR concerns. For court use, breach-data findings are best treated as leads and corroborated through legally-obtained sources.

Hacking back is illegal

Anything that involves unauthorized access to a target's systems — logging into their accounts, accessing their devices, intercepting their communications — is computer-fraud territory in essentially every jurisdiction. Don't do it. The shortest path from forensic investigator to defendant is hacking back. Every legitimate forensic firm has clear policies prohibiting this.

Privacy considerations for victims and bystanders

OSINT incidentally surfaces private information about victims, bystanders, and uninvolved third parties. Forensic investigators have an ethical obligation to handle that information responsibly: collect only what's relevant, store it securely, share it only with parties who have a legitimate need, and dispose of it when the case closes. Don't be the reason a victim's personal information ends up in a leaked investigator dossier.


OSINT in Court: Daubert and FRE 702

For an OSINT-derived attribution to survive a Daubert challenge under Federal Rule of Evidence 702, the methodology used to gather and validate the OSINT must itself be a recognized practice in the forensic community, applied reliably to the specific case. Pure OSINT-driven attribution without on-chain corroboration is a weak Daubert position. OSINT used to corroborate an on-chain attribution is much stronger.

What strengthens an OSINT-based opinion

  • Documented sources — every finding traceable to a specific URL, archived snapshot, or breach record with a timestamp
  • Independent corroboration — the same conclusion reached through at least two independent OSINT sources, plus on-chain evidence consistent with the conclusion
  • Explicit confidence levels — the expert is clear about which findings are high-confidence and which are probabilistic
  • Articulated methodology — the expert can describe not just what the OSINT shows but how it was gathered, what sources were ruled out, and what would change the conclusion
  • Chain-of-custody preservation — archived copies of source material, hash-stamped where appropriate, available for opposing counsel's review

What weakens it

  • Single-source attribution without independent corroboration
  • Reliance on breach data without parallel legally-obtained sources
  • Reliance on community blacklists without independent on-chain validation
  • Citing deleted social media posts without preserved archives
  • Attribution that hinges on a single behavioral pattern rather than a constellation of patterns

The U.S. precedents on blockchain forensic admissibility — U.S. v. Sterlingov (Bitcoin Fog), U.S. v. Storm and U.S. v. Pertsev (Tornado Cash) — have largely focused on the on-chain methodology side. The OSINT side has gotten less direct scrutiny in published opinions, but the same Daubert framework applies, and any expert relying heavily on OSINT for an attribution should be prepared to defend the methodology with the same rigor as the on-chain side. We cover the broader admissibility framework in blockchain forensic evidence in federal civil litigation.


OPSEC for Investigators

OSINT cuts both ways. The same tools and techniques an investigator uses are available to the operators being investigated. The professional baseline:

  • Dedicated investigation environment. A separate device, VM, or browser profile that doesn't carry your personal browser history, logged-in accounts, or local files. Investigation activity should never touch personal infrastructure.
  • Non-attributable network egress. A commercial VPN at minimum; a residential proxy or bare-metal VPS for higher-stakes work. Never investigate from your home or office IP.
  • Sock-puppet accounts. Created on a clean device, with separate email addresses and phone numbers, used only for investigation. Treat them as disposable.
  • Search opacity. Some platforms tip off the target when their profile is viewed. Use cached views (Google cache, Wayback Machine) where possible, and direct access only when necessary.
  • Breach-data hygiene. Never query breached databases from your personal infrastructure. Breach-data services occasionally get compromised themselves, and you don't want your queries showing up in the next leak.
  • Personal communications hardening. Investigators get targeted by the operators they investigate — sometimes through phishing, sometimes through doxing, occasionally through physical threats. Use hardware-backed 2FA on every account, separate work and personal phone numbers, and remove personal information from data brokers.
  • Don't tip the target. The most common OPSEC failure is letting the target know you're looking. Don't post about active investigations on social media. Don't query a wallet on a tool that broadcasts queries publicly. Don't visit suspect domains from a browser session that carries identifying cookies.

OPSEC failures end careers. Treat them with the same seriousness as evidence-handling errors.


What This Means for Victims

If you're a victim trying to understand whether OSINT can help recover your funds, the honest framing:

OSINT is a force multiplier, not a magic recovery method

The wallet that drained you, the phishing site that tricked you, the Telegram contact that introduced the "investment" — all of those leave OSINT footprints. A skilled investigator can map them, identify the operator's infrastructure, surface other victims, and build a case package that supports law enforcement referral or civil action. OSINT does not recover funds directly; it builds the case that other mechanisms (law enforcement, exchange subpoenas, OFAC sanction additions) use to act.

OSINT is most powerful when paired with on-chain forensic work

The strongest case packages combine an on-chain trace with OSINT-derived operator attribution. The trace shows where the funds went; the OSINT shows who the operator is or, at minimum, what known group's pattern they match. We integrate both in standard blockchain forensic analysis engagements.

Recovery odds depend on what OSINT reveals

If OSINT identifies the operator as part of a known operation already on the OFAC SDN list, recovery odds are meaningfully higher — sanctioned addresses must be frozen by U.S.-touching exchanges, and any funds that flow through them become recoverable through standard freeze mechanisms. If OSINT identifies the operator as a small unaffiliated actor, recovery is harder but not impossible. If OSINT yields no clear attribution — which happens — the case may be limited to documenting what's known on-chain and waiting for future cooperation breakthroughs. We discuss the realistic recovery picture in can you get crypto back after being scammed.

What you can do as a victim before contacting an investigator

  • Preserve everything. Screenshots of every conversation, every URL, every transaction. Save them to a separate device. Don't delete the chat with the scammer — that's evidence.
  • Document the platform. If the scam involved a fake exchange or investment platform, archive the URL via archive.today and capture screenshots of the interface, especially your "account" page showing the fake balance.
  • Note any handles. Every Telegram handle, Twitter account, email address, phone number, or other identifier the operator used. These are the OSINT pivots an investigator works from.
  • Don't engage further. Continued contact gives the operator information to use against you — including OPSEC information about the investigation itself.

Free Forensic Case Assessment

Pig butchering, wallet drainer, exchange hack, or phishing scam — we'll integrate on-chain trace and OSINT to map what happened and tell you honestly what recovery looks like in your specific case. Initial assessments are free and typically returned within 24 hours.

Start a Free Case Review

Frequently Asked Questions

What is OSINT in the context of blockchain forensics?
OSINT (open-source intelligence) is the disciplined use of publicly available information — social media, domain records, breached data, public reports, archived web content, and behavioral signals — to bridge the pseudonymous on-chain world to real-world identity. On-chain analysis tells you what wallets did; OSINT helps you understand who controls them.
Why isn't on-chain analysis enough by itself?
On-chain data is transparent but pseudonymous. To convert pseudonymity into accountability — for a subpoena, a freeze, a civil suit, or a criminal referral — you need attribution beyond the on-chain data itself. OSINT closes that gap.
What are the most useful OSINT tools for blockchain investigators?
The core toolkit in 2026 includes: urlscan.io and SecurityTrails for domain and DNS history; DomainTools for WHOIS; Wayback Machine and archive.today for ephemeral content; Dehashed, Have I Been Pwned, and Intelligence X for breached data; OSINT Industries for cross-platform account discovery; Chainabuse and Scam Sniffer for community reports; Etherscan, Arkham, and MistTrack for on-chain entity context.
How does an investigator go from a wallet address to a real-world identity?
Start with on-chain context (Etherscan, Arkham, MistTrack tags and counterparties), then search the wallet address as a string across Twitter, GitHub, Telegram, Reddit, and Bitcointalk. If a phishing site is involved, pull WHOIS and DNS history. If a username appears, pivot through OSINT Industries and Dehashed. Validate every lead against on-chain reality before treating it as attribution.
What are the biggest failure modes of OSINT-based attribution?
Five recurring failure modes: false-positive blacklist tags; intentional deception from operators; ephemeral evidence that disappears before you preserve it; breached data that is unreliable or outdated; and the irreducible limit that OSINT alone cannot prove wallet ownership — on-chain corroboration is always required.
Are OSINT findings admissible in U.S. courts?
Depends on the source. Public sources (court filings, news, OFAC, government press releases) are generally admissible. Social media is admissible if properly authenticated and preserved. Breach data is more complicated and varies by court. The safest practice is to preserve OSINT with chain-of-custody, hash-stamp the artifact, and have it independently corroborated by on-chain or other admissible evidence.
How does OSINT interact with the Daubert / FRE 702 standard?
For OSINT-based attribution to survive Daubert, the methodology used to gather and validate must be a recognized practice in the forensic community, applied reliably. Documented sources, timestamps, archive copies, explicit confidence levels, and independent cross-validation against on-chain evidence are the components that make OSINT-driven opinions defensible.
What is the OPSEC posture for an investigator using OSINT?
A dedicated investigation device or VM, a non-attributable VPN or residential proxy, sock-puppet accounts for platforms where direct viewing risks tipping the target, never accessing breach-data sources from personal infrastructure, hardware-backed 2FA on every account, and treating personal communications as targetable by the operators being investigated.
What's the difference between an OSINT-only investigator and a blockchain forensic investigator?
An OSINT-only investigator gathers public information about an actor without necessarily integrating on-chain data. A blockchain forensic investigator integrates OSINT with transaction-graph analysis, wallet clustering, behavioral attribution, exchange-deposit identification, and forensic report production. The integration is what produces attribution that holds up — OSINT-only attribution is rarely sufficient for the actions the work needs to drive.

Final Thoughts

OSINT has matured into a discipline that genuinely belongs alongside on-chain analysis in modern blockchain forensic work. The tools are stronger every year, the public-private cooperation is deeper, and the volume of OSINT material in any given case keeps expanding. None of that changes the fundamental rule: OSINT closes the attribution gap that on-chain data leaves open, but only when paired with disciplined methodology, rigorous validation, and on-chain corroboration.

If you're a victim trying to understand what's possible in your case, the integrated approach is what matters — not "do you do OSINT" or "do you do on-chain" but "do you integrate them rigorously enough to produce attribution that drives action." If you're an aspiring investigator, the fastest path to getting good is reading published investigations carefully and reverse-engineering the methodology behind every conclusion. The work is learnable; the discipline of cross-validation is the part that takes years.

Get in touch if there's a specific case you'd like to discuss.

Zack Coffing — Wallet Witness

Founder of Wallet Witness. Independent blockchain forensic investigator integrating on-chain analysis and OSINT for cryptocurrency fraud cases, exchange-hack laundering analysis, pig butchering investigations, and litigation support. Serving victims, law firms, and law enforcement worldwide. Learn more →