OSINT (open-source intelligence) is how blockchain forensic investigators bridge the on-chain world to real-world identity. On-chain analysis tells you what wallets did. OSINT helps you understand who controls them. The discipline is the integration: every OSINT lead checked against on-chain reality, every on-chain finding corroborated against OSINT context, packaged into a forensic report defensible against cross-examination.
The toolkit in 2026 spans infrastructure analysis (urlscan.io, SecurityTrails, DomainTools, Wayback Machine), breach data (Dehashed, Have I Been Pwned, Intelligence X), account discovery (OSINT Industries, public profile traces), community intelligence (ZachXBT, Chainabuse, Scam Sniffer, SEAL-ISAC), and authoritative sources (OFAC SDN list, court filings, government press releases). Each closes a different gap; using them in combination is what produces attribution that holds up.
This article is the practitioner's walkthrough — the toolkit, the methodology, the wins, the failure modes, the legal boundaries, and what OSINT findings actually look like in court.
In This Article
- What OSINT actually means in blockchain forensics
- Why on-chain analysis alone isn't enough
- The OSINT toolkit, by source category
- Methodology: from wallet to identity
- Where OSINT cracks attribution open
- Where OSINT fails — the limits investigators respect
- The legal and ethical lines
- OSINT in court: Daubert and FRE 702
- OPSEC for investigators
- What this means for victims
- Frequently asked questions
What OSINT Actually Means in Blockchain Forensics
The phrase "open-source intelligence" gets used to mean a lot of different things. In a defense or intelligence-community context, it covers a wide universe of public collection. In blockchain forensics, the working definition is narrower and more specific.
OSINT in this context is the disciplined use of publicly available information to bridge the pseudonymous on-chain world to real-world identity, behavior, or context. The on-chain data tells you what happened; OSINT helps you understand who, why, and from where.
The categories an investigator actually pulls from:
- Social media — Twitter/X, Telegram, Discord, Reddit, Bitcointalk, Medium — where scammers post addresses, dispute scams, recruit accomplices, or accidentally tag themselves
- Infrastructure records — WHOIS, DNS history, SSL certificates, hosting providers — for any phishing site, fake exchange, or scam landing page involved in the case
- Developer footprints — GitHub commits, code reuse patterns, deployment-wallet correlations, even handles in commit signatures — that tie smart contracts back to real authors
- Breach data — leaked credentials, account dumps, breached forum posts — that connect emails, usernames, and IPs across platforms
- Community intelligence — published lists from ZachXBT, Chainabuse, Scam Sniffer, SEAL-ISAC, CryptoScamDB — that flag known-bad addresses and their operators
- Behavioral signals — timezone patterns of activity, denomination preferences, repeated DEX choices — that act as a "digital signature" harder to hide than wallet rotation
- Authoritative sources — OFAC SDN list, court filings, indictments, government press releases, regulatory enforcement actions
- Ephemeral evidence — archived versions of pages, deleted tweets, expired domains — preserved through Wayback Machine, archive.today, and urlscan.io's history
The skill isn't knowing the tools. The skill is knowing which combination produces a defensible attribution for a particular case — and which combination is going to fail validation when the on-chain evidence comes in.
Why On-Chain Analysis Alone Isn't Enough
Blockchain transparency is genuinely powerful. Every transaction, every wallet balance, every contract interaction is public. An investigator can build the entire forward and backward graph of fund flows from any starting address, in real time, without subpoenas or warrants. That access is unique among financial systems.
But the pseudonymity is also genuine. A wallet address has no built-in identity. Two wallets that behave identically might be the same operator or might be unrelated coincidences. A wallet flagged as belonging to a sanctioned group might be a fresh address controlled by the same operator or a stale address abandoned years ago. Without some layer of attribution beyond the on-chain data itself, the investigator's work product reduces to: "Funds went from address A to address B." True, but not useful.
The actions an investigation needs to drive — subpoenas to exchanges, freeze requests to stablecoin issuers, civil suits, criminal referrals, OFAC sanction additions — all require attribution beyond pseudonymity. Even the most aggressive Tether freeze request requires the issuer to believe the addresses are scammer-controlled, which requires evidence beyond "they received funds in a suspicious pattern." The evidence that closes that gap is OSINT.
This is why modern forensic practice integrates the two. We cover the integrated trace methodology in how blockchain forensic investigators trace crypto in 2026; this article goes deep on the OSINT half of that integration.
The OSINT Toolkit, by Source Category
The catalogue below is the toolkit a practicing investigator actually pulls from. Each tool fills a specific role; the goal is fluency in combination, not encyclopedic coverage of any one of them.
Infrastructure analysis
| Tool | What it does | Why investigators use it |
|---|---|---|
| urlscan.io | Captures historical scans of any URL with full request graph, screenshots, and JS bundle analysis | For any phishing site or fake exchange in the case, urlscan often has historical captures even after the site goes down |
| SecurityTrails | Historical DNS records, WHOIS, subdomains, and infrastructure mapping | Connects related domains run by the same operator across time — phishing kits often reuse hosting |
| DomainTools | WHOIS, registrant history, domain ownership tracking | Pulls registrar emails and contact info from the moment of registration, even if later anonymized |
| RiskIQ / PassiveTotal | Passive DNS and SSL certificate correlation | Identifies infrastructure pivots when a scammer rotates domains while keeping certificates or hosting consistent |
| Wayback Machine | Archived snapshots of web pages | Recovers deleted phishing landing pages, fake exchange interfaces, and operator content removed after the fact |
| archive.today | On-demand archive of any URL | The investigator's own evidence preservation — capture suspect pages immediately for chain-of-custody |
Account discovery and breach data
| Tool | What it does | Why investigators use it |
|---|---|---|
| OSINT Industries | Reverse lookup: feed an email, phone number, username, or wallet and surface connected accounts across hundreds of platforms | Fastest way to map an operator's online footprint; commonly identifies overlooked side accounts |
| Dehashed | Searchable database of breached credentials | If an operator's email appears in a breach, this is where you find it — with passwords, hashes, and associated metadata |
| Have I Been Pwned (HIBP) | Free breach exposure check for an email | Quick first-pass check before paying for deeper Dehashed-style queries |
| Intelligence X | Index of leaked, deleted, or hard-to-reach data including paste sites, dark-web content, and document leaks | Surfaces context Google can't reach — particularly for actors who post on Russian or Chinese forums |
| Maltego | Graph visualization for OSINT pivots across data sources | For complex investigations involving many entities; produces visual artifacts useful in reports |
Community intelligence and threat reports
| Source | What it provides | Why investigators use it |
|---|---|---|
| ZachXBT (Twitter/X) | Independent on-chain investigations with public attribution | The single highest-signal community source for major hacks; often first to attribute |
| Chainabuse (TRM Labs) | Community-reported scam addresses with case context | Cross-reference any suspect address against thousands of victim reports |
| Scam Sniffer | Real-time wallet drainer monitoring and alerts | Particularly strong for phishing-drainer operations and approval-scam tracking |
| CryptoScamDB | Community database of scam URLs and addresses | Historical record of confirmed scam infrastructure |
| SEAL-ISAC | Security Alliance threat intelligence sharing | Real-time coordination among security firms during active incidents |
| TRM Labs / Chainalysis / Elliptic blogs | Detailed post-incident analyses | Authoritative published analyses suitable for citation in forensic reports |
On-chain entity context
| Tool | What it provides | Why investigators use it |
|---|---|---|
| Etherscan / Solscan / BscScan | Block explorers with entity tags, public notes, and labeled addresses | First stop for any wallet lookup; tags often confirm exchange or exploiter attribution |
| Arkham Intelligence | Aggregated on-chain entity attribution and clustering | Strong on linking wallets to known exchange addresses, named entities, and historical events |
| MistTrack | Address risk profiling and labeled entity context | Particularly strong for ransomware and DPRK-related entities |
| Breadcrumbs / MetaSleuth | Visual transaction graphing for non-paid analysts | Free or low-cost alternatives to Chainalysis Reactor for graph building |
Authoritative public sources
| Source | What it provides | Why investigators use it |
|---|---|---|
| OFAC SDN list | U.S.-sanctioned individuals, entities, and crypto addresses | The single highest-authority attribution source; sanctioned addresses must be frozen by U.S.-touching exchanges |
| U.S. court filings (PACER) | Indictments, civil complaints, and supporting affidavits | Many DOJ crypto cases include named addresses and detailed attribution rationale |
| DOJ / FBI / Treasury press releases | Official attribution and enforcement actions | Citation-grade source for forensic reports |
| State AG enforcement actions | State-level civil and criminal proceedings | Often surface attribution for crimes that don't reach federal scrutiny |
Methodology: From Wallet to Identity
The standard OSINT workflow when starting from a wallet address. This is the playbook I run on most cases — not every step on every case, but the order of operations is consistent.
Step 1: On-chain context first
Before going to OSINT, lock in the on-chain context. Pull the wallet on Etherscan, Arkham, and MistTrack. Note any entity tags. Identify the funding source (where did this wallet first receive funds?), the most active counterparties, and any cash-out exchange touchpoints. The on-chain pattern tells you what kind of operator you're dealing with before you spend any time on OSINT.
Step 2: Direct address mentions
Search the wallet address as a literal string across:
- Twitter/X (current and historical via the Wayback Machine of specific user pages)
- Reddit (use Pushshift or alternative Reddit search archives if the post was deleted)
- GitHub (commits, issues, comments, repository content)
- Bitcointalk and other crypto forums (where many older addresses were originally posted)
- Telegram (search public channels via @SearchSeeBot or similar)
- Medium and other long-form platforms
- Chainabuse and CryptoScamDB for community reports tagged to the address
- Pastebin and similar — some operators post their addresses publicly without realizing
A surprising number of cases get cracked at this step. Operators are not always operationally careful; they sometimes post their own addresses asking for tips, complaining about freezes, or recruiting victims.
Step 3: Infrastructure attribution (if a phishing site or fake exchange is involved)
For any URL the victim interacted with, pull the full infrastructure history:
urlscan.io/search?q=domain:scamsite.com— pulls every historical scan with screenshots, JS bundles, and request graphsSecurityTrailsfor full WHOIS history, related subdomains, and other domains by the same registrantDomainToolsfor WHOIS history including any pre-anonymization registrant data- SSL certificate transparency logs (crt.sh) for related certificates issued to the same operator
The infrastructure layer is where amateur operators leak the most identity. Reused registrar emails, hosting accounts that connect to other sites, SSL certificates issued to clusters of related domains — all of it shows in the public record.
Step 4: Username and email pivots
If any step above surfaces a username, email address, or persistent handle, pivot through OSINT Industries and Dehashed:
- OSINT Industries: feed the username or email and see every connected account across hundreds of platforms (Instagram, Telegram, Discord, dating apps, gaming platforms, crypto exchanges with public username discovery)
- Dehashed: search for the email or username across breached datasets — surfaces additional emails, password reuse patterns, and other accounts the same actor controls
- Have I Been Pwned: free first-pass check on emails before paying Dehashed for deeper queries
Step 5: Behavioral attribution
Behavioral attribution is the most underrated category in OSINT. The patterns:
- Timezone: map all on-chain activity by the wallet (and any clustered wallets) onto a 24-hour distribution. Operators concentrated in UTC+8-9 (East Asia) show distinctly different patterns from UTC-5 (US East Coast)
- Denomination preferences: exact-amount transfers (e.g., precisely 1.0 ETH) are common from exchanges; oddly precise sub-denominated amounts often reveal scripted operations
- Service preferences: consistent use of the same DEX, the same bridge, the same mixer is a digital signature; Lazarus's preference for Thorchain + eXch + Wasabi is identifiable across multiple incidents
- Linguistic patterns: if operators communicate publicly (in Telegram, Discord, etc.), language analysis — idioms, typos, code-switching — can establish attribution between separate accounts
- Operational habits: always cashing out in fixed batches, always using the same recovery wallet pattern, always rotating new addresses on a fixed schedule — all leave signatures
Behavioral attribution is what makes "the Phemex hacker is the Bybit hacker" possible across separate incidents. The wallet rotates; the habits don't.
Step 6: Cross-validate everything
Every OSINT lead, before it goes into a report, gets validated against the on-chain record. If a Telegram handle claims to control the wallet, look for on-chain behavior consistent with the persona's claims. If a breach connects an email to a username, look for that username on-chain (via Etherscan tags, Arkham labels, or community sources). If a community report flags the address as a scammer, verify the on-chain pattern matches scam behavior rather than coincidence.
This cross-validation step is what separates forensic-quality attribution from speculative attribution. It's also the step that gets skipped most often by inexperienced investigators producing reports that don't survive cross-examination.
Where OSINT Cracks Attribution Open
The cases where OSINT does the heavy lifting, in rough order of frequency:
Phishing operations with reused infrastructure
Wallet drainer operations like Inferno Drainer, Pink Drainer, and Angel Drainer rotate phishing domains constantly — but the underlying infrastructure (hosting providers, registrar accounts, SSL patterns) often persists across rotations. urlscan.io and SecurityTrails reveal these connections in seconds. A single drained-wallet case can be linked to hundreds of others through shared infrastructure attribution.
Romance and pig butchering operations with operator slip-ups
Compound-based pig butchering operations are professionally structured, but individual operators slip. Photos with metadata, time-zone inconsistencies in chat logs, "investment platform" domains with recoverable WHOIS history, recovery-scam follow-ups using the same Telegram handle as the original scam — all of these surface in OSINT and can build a profile of the specific compound or operator.
State-sponsored attribution via behavioral pattern matching
The Lazarus / DPRK attribution chain across the Phemex, Ronin, WazirX, and Bybit hacks is largely behavioral. The same DEXs in the same sequence, the same bridges, the same mixers, the same denomination patterns. ZachXBT's attribution of the Bybit hack to Lazarus within hours rested entirely on this kind of pattern recognition. The publicly-released address list itself is a textbook example of an OSINT artifact — the kind of work product community investigators use to seed every subsequent forensic engagement on the same operator:
I spent the entire day graphing out the laundering movements and flagged theft addresses.
— ZachXBT (@zachxbt) February 22, 2025
I am making 920+ addresses connected to the Bybit hack publicly available here:
The single most public example of OSINT-driven attribution paying off in 2025 was Arkham Intelligence's $1B Bybit hack bounty. Arkham had a standing public bounty for definitive proof of the attacker's identity. ZachXBT submitted his analysis — test transactions, connected wallets, behavioral pattern matches against prior Lazarus operations — and won the bounty within hours of the theft. The whole sequence is a textbook case of how community-led OSINT now operates inside a formal incentive structure rather than just as informal investigation.
BREAKING: BYBIT $1 BILLION HACK BOUNTY SOLVED BY ZACHXBT
— Arkham (@arkham) February 21, 2025
At 19:09 UTC today, @zachxbt submitted definitive proof that this attack on Bybit was performed by the LAZARUS GROUP.
His submission included a detailed analysis of test transactions and connected wallets used ahead of...
Defendant identification via document leaks and court filings
Once a case enters the judicial system, the OSINT layer expands dramatically. Indictments, civil complaints, and supporting affidavits often include named addresses, attribution rationale, and corroborating evidence that becomes citation-grade for related investigations. PACER searches on related entities frequently surface valuable context for parallel investigations.
OFAC sanction integrations
The OFAC SDN list is the highest-authority attribution source available. Once an address is sanctioned, it carries irrefutable attribution that any U.S.-touching exchange must respect. Cross-referencing case wallets against the SDN list (and against historical Treasury press releases for context) is one of the highest-ROI OSINT moves possible — takes minutes, occasionally cracks the case wide open. The Chainalysis breakdown of the Tornado Cash sanction is the canonical reference for understanding how SDN designations flow through to on-chain enforcement.
Where OSINT Fails — The Limits Investigators Respect
OSINT is powerful but not omniscient. The failure modes worth knowing:
Every working investigator runs into these. Skip them at your own risk.
1. False-positive blacklist tags
Community-reported blacklists (Chainabuse, CryptoScamDB, Scam Sniffer) are valuable signals, but they include noise. An address can end up on a blacklist because of a misreport, a coincidental association, or a malicious false flag from a competitor. Always treat blacklist entries as leads, not conclusions. Validate the on-chain pattern matches scam behavior before incorporating the tag into a report.
2. Intentional deception
Sophisticated operators set up deception layers specifically to mislead investigators — sock-puppet accounts that "claim" to control specific wallets, planted social media posts, fake document leaks, and decoy domains designed to misdirect attribution. Lazarus has been observed using these techniques to throw investigators off their actual infrastructure. The mitigation is independent corroboration: never rely on a single source for any attribution that matters.
3. Ephemeral evidence
The web is mortal. Tweets get deleted within hours of being noticed; phishing sites go offline within days; Telegram channels get banned; accounts get suspended. If you find OSINT evidence relevant to a case, archive it immediately — archive.today, Wayback Machine, urlscan.io, screenshots with timestamps, and full HTML downloads. Evidence you didn't preserve is evidence you don't have when the report goes to court.
4. Breached data reliability and ethics
Breached credential databases (Dehashed, Intelligence X) contain valuable data that frequently cracks attribution — but the underlying breaches were illegally obtained, and in some jurisdictions using them is itself questionable. Even where it's legal, the data is often outdated, partial, or contaminated. Use breach data as a lead source; corroborate any finding through legally-obtained sources before relying on it in a report.
5. The irreducible problem: OSINT alone never proves wallet ownership
This is the most important limit and the one most often violated. OSINT can establish strong association — sometimes overwhelming association — between a wallet and a real-world identity. It cannot prove ownership. The only thing that proves ownership is on-chain evidence demonstrating the entity's exclusive control. Every responsible OSINT-driven attribution must be paired with on-chain corroboration that survives an independent technical review. Without that pairing, the attribution is speculative at best and indefensible at worst.
The Legal and Ethical Lines
OSINT operates in a gray zone. Most of what you can do is legal; some of what's tempting isn't. The lines that actually matter:
Public information is generally fair game
Anything posted publicly — tweets, public Telegram messages, GitHub repos, public WHOIS, news articles, court filings — is collectable, archivable, and citable without controversy. The volume of public material in any modern crypto investigation is enormous; you don't need to push into gray areas for most cases.
Sock puppet accounts are legal but Terms-of-Service constrained
Creating a non-attributable account on Twitter, Telegram, or Discord to view a target's public content is legal but typically violates each platform's Terms of Service. The platform can ban the account; the data collected is still usable in most contexts. The professional norm is to use sock puppets sparingly and for legitimate investigative purposes only.
Breached data is jurisdiction-dependent
The legal status of querying breach databases varies by jurisdiction. In the U.S., querying paid services like Dehashed is generally tolerated for investigative purposes; in some EU jurisdictions, the same activity may run into GDPR concerns. For court use, breach-data findings are best treated as leads and corroborated through legally-obtained sources.
Hacking back is illegal
Anything that involves unauthorized access to a target's systems — logging into their accounts, accessing their devices, intercepting their communications — is computer-fraud territory in essentially every jurisdiction. Don't do it. The shortest path from forensic investigator to defendant is hacking back. Every legitimate forensic firm has clear policies prohibiting this.
Privacy considerations for victims and bystanders
OSINT incidentally surfaces private information about victims, bystanders, and uninvolved third parties. Forensic investigators have an ethical obligation to handle that information responsibly: collect only what's relevant, store it securely, share it only with parties who have a legitimate need, and dispose of it when the case closes. Don't be the reason a victim's personal information ends up in a leaked investigator dossier.
OSINT in Court: Daubert and FRE 702
For an OSINT-derived attribution to survive a Daubert challenge under Federal Rule of Evidence 702, the methodology used to gather and validate the OSINT must itself be a recognized practice in the forensic community, applied reliably to the specific case. Pure OSINT-driven attribution without on-chain corroboration is a weak Daubert position. OSINT used to corroborate an on-chain attribution is much stronger.
What strengthens an OSINT-based opinion
- Documented sources — every finding traceable to a specific URL, archived snapshot, or breach record with a timestamp
- Independent corroboration — the same conclusion reached through at least two independent OSINT sources, plus on-chain evidence consistent with the conclusion
- Explicit confidence levels — the expert is clear about which findings are high-confidence and which are probabilistic
- Articulated methodology — the expert can describe not just what the OSINT shows but how it was gathered, what sources were ruled out, and what would change the conclusion
- Chain-of-custody preservation — archived copies of source material, hash-stamped where appropriate, available for opposing counsel's review
What weakens it
- Single-source attribution without independent corroboration
- Reliance on breach data without parallel legally-obtained sources
- Reliance on community blacklists without independent on-chain validation
- Citing deleted social media posts without preserved archives
- Attribution that hinges on a single behavioral pattern rather than a constellation of patterns
The U.S. precedents on blockchain forensic admissibility — U.S. v. Sterlingov (Bitcoin Fog), U.S. v. Storm and U.S. v. Pertsev (Tornado Cash) — have largely focused on the on-chain methodology side. The OSINT side has gotten less direct scrutiny in published opinions, but the same Daubert framework applies, and any expert relying heavily on OSINT for an attribution should be prepared to defend the methodology with the same rigor as the on-chain side. We cover the broader admissibility framework in blockchain forensic evidence in federal civil litigation.
OPSEC for Investigators
OSINT cuts both ways. The same tools and techniques an investigator uses are available to the operators being investigated. The professional baseline:
- Dedicated investigation environment. A separate device, VM, or browser profile that doesn't carry your personal browser history, logged-in accounts, or local files. Investigation activity should never touch personal infrastructure.
- Non-attributable network egress. A commercial VPN at minimum; a residential proxy or bare-metal VPS for higher-stakes work. Never investigate from your home or office IP.
- Sock-puppet accounts. Created on a clean device, with separate email addresses and phone numbers, used only for investigation. Treat them as disposable.
- Search opacity. Some platforms tip off the target when their profile is viewed. Use cached views (Google cache, Wayback Machine) where possible, and direct access only when necessary.
- Breach-data hygiene. Never query breached databases from your personal infrastructure. Breach-data services occasionally get compromised themselves, and you don't want your queries showing up in the next leak.
- Personal communications hardening. Investigators get targeted by the operators they investigate — sometimes through phishing, sometimes through doxing, occasionally through physical threats. Use hardware-backed 2FA on every account, separate work and personal phone numbers, and remove personal information from data brokers.
- Don't tip the target. The most common OPSEC failure is letting the target know you're looking. Don't post about active investigations on social media. Don't query a wallet on a tool that broadcasts queries publicly. Don't visit suspect domains from a browser session that carries identifying cookies.
OPSEC failures end careers. Treat them with the same seriousness as evidence-handling errors.
What This Means for Victims
If you're a victim trying to understand whether OSINT can help recover your funds, the honest framing:
OSINT is a force multiplier, not a magic recovery method
The wallet that drained you, the phishing site that tricked you, the Telegram contact that introduced the "investment" — all of those leave OSINT footprints. A skilled investigator can map them, identify the operator's infrastructure, surface other victims, and build a case package that supports law enforcement referral or civil action. OSINT does not recover funds directly; it builds the case that other mechanisms (law enforcement, exchange subpoenas, OFAC sanction additions) use to act.
OSINT is most powerful when paired with on-chain forensic work
The strongest case packages combine an on-chain trace with OSINT-derived operator attribution. The trace shows where the funds went; the OSINT shows who the operator is or, at minimum, what known group's pattern they match. We integrate both in standard blockchain forensic analysis engagements.
Recovery odds depend on what OSINT reveals
If OSINT identifies the operator as part of a known operation already on the OFAC SDN list, recovery odds are meaningfully higher — sanctioned addresses must be frozen by U.S.-touching exchanges, and any funds that flow through them become recoverable through standard freeze mechanisms. If OSINT identifies the operator as a small unaffiliated actor, recovery is harder but not impossible. If OSINT yields no clear attribution — which happens — the case may be limited to documenting what's known on-chain and waiting for future cooperation breakthroughs. We discuss the realistic recovery picture in can you get crypto back after being scammed.
What you can do as a victim before contacting an investigator
- Preserve everything. Screenshots of every conversation, every URL, every transaction. Save them to a separate device. Don't delete the chat with the scammer — that's evidence.
- Document the platform. If the scam involved a fake exchange or investment platform, archive the URL via archive.today and capture screenshots of the interface, especially your "account" page showing the fake balance.
- Note any handles. Every Telegram handle, Twitter account, email address, phone number, or other identifier the operator used. These are the OSINT pivots an investigator works from.
- Don't engage further. Continued contact gives the operator information to use against you — including OPSEC information about the investigation itself.
Free Forensic Case Assessment
Pig butchering, wallet drainer, exchange hack, or phishing scam — we'll integrate on-chain trace and OSINT to map what happened and tell you honestly what recovery looks like in your specific case. Initial assessments are free and typically returned within 24 hours.
Start a Free Case ReviewFrequently Asked Questions
Final Thoughts
OSINT has matured into a discipline that genuinely belongs alongside on-chain analysis in modern blockchain forensic work. The tools are stronger every year, the public-private cooperation is deeper, and the volume of OSINT material in any given case keeps expanding. None of that changes the fundamental rule: OSINT closes the attribution gap that on-chain data leaves open, but only when paired with disciplined methodology, rigorous validation, and on-chain corroboration.
If you're a victim trying to understand what's possible in your case, the integrated approach is what matters — not "do you do OSINT" or "do you do on-chain" but "do you integrate them rigorously enough to produce attribution that drives action." If you're an aspiring investigator, the fastest path to getting good is reading published investigations carefully and reverse-engineering the methodology behind every conclusion. The work is learnable; the discipline of cross-validation is the part that takes years.
Get in touch if there's a specific case you'd like to discuss.