Skip to main content
Forensic Masterclass

How to Trace
Stolen Bitcoin

A deep-dive technical breakdown of how professional blockchain investigators track Bitcoin from the moment of theft to the centralized exchange cash-out point.

The Transparency of Bitcoin

Bitcoin was created to be a trustless, decentralized electronic cash system. To achieve trust without a central bank, the system requires radical transparency. Every single Bitcoin transaction since the Genesis Block in 2009 is recorded in a public ledger, distributed across thousands of computers worldwide.

When a scammer steals your Bitcoin, they have not hidden the money. They have broadcasted the theft to the entire planet. The challenge is not *seeing* the transaction; the challenge is *understanding* the identity behind the cryptographic addresses.

Understanding the UTXO Model

To trace Bitcoin, you must first understand how Bitcoin actually works. Unlike your bank account (which uses an account-balance model), Bitcoin uses the UTXO (Unspent Transaction Output) model.

Think of UTXOs like physical cash. If you have a $50 bill and want to buy a $10 coffee, you don't subtract $10 from your $50. You hand the cashier the $50 bill, the cashier destroys it, and hands you two new bills: a $10 bill (their payment) and a $40 bill (your change).

This is exactly how Bitcoin operates. When a scammer moves your stolen Bitcoin, the transaction consumes the existing UTXO and creates multiple new UTXOs. One output goes to the scammer's destination, and the other output (the change) goes back to a newly generated address controlled by the scammer.

Tracing Bitcoin requires an investigator to meticulously map these inputs, outputs, and change addresses to ensure they are following the stolen funds, not the change given back to the scammer.

A diagram illustrating the Bitcoin UTXO inputs and outputs
Understanding the UTXO model is the foundation of all Bitcoin tracing.

Heuristics: Connecting Addresses

A single scammer may use 500 different Bitcoin addresses. If investigators treated each address as a different person, tracing would be impossible. Therefore, we use "Heuristics"—rules of thumb applied by software to cluster addresses together and prove they are controlled by the same entity.

1. The Common-Input Heuristic

This is the most powerful rule in blockchain forensics. If a transaction has two inputs (e.g., Input A and Input B), the Bitcoin protocol requires the sender to mathematically sign *both* inputs to authorize the transaction. Therefore, whoever signed that transaction must possess the private keys for both Address A and Address B. The software automatically clusters Address A and Address B together as belonging to the same person.

2. The Change-Address Heuristic

As discussed in the UTXO model, Bitcoin wallets automatically generate a brand new "change address" for every transaction. Forensic software analyzes the outputs of a transaction. If one output has been seen before on the blockchain, and the other is a brand new, never-before-seen address, the software assumes the new address is the change address, and clusters it with the sender's identity.

By applying these heuristics to millions of transactions, enterprise software (like TRM Labs or Chainalysis) collapses millions of separate addresses into unified "Entities" (e.g., "Entity: Scammer Syndicate X" or "Entity: Binance Hot Wallet").

Defeating CoinJoin and Mixers

Advanced scammers know about heuristics. To break the trace, they use privacy techniques like CoinJoin or custodial mixers.

A mixer works by taking deposits from hundreds of different people, pooling the Bitcoin together, scrambling it, and sending the Bitcoin back out to new addresses at random intervals minus a fee. To the naked eye on a block explorer, the trace is dead.

However, forensic investigators can often defeat poorly executed mixers through Volume and Temporal Analysis. If a victim's wallet deposits exactly 14.321 BTC into a mixer, and 12 hours later, a new, unrelated wallet withdraws 14.310 BTC (the deposit minus the exact mixer fee), an investigator can deduce a high-probability link between the deposit and the withdrawal. While this isn't mathematically certain, it is often enough to form probable cause for a subpoena.

Video: De-mixing Bitcoin Transactions

The Fiat Off-Ramp

The ultimate goal of tracing is not to find where the Bitcoin is "sitting." A scammer can hold stolen Bitcoin in a cold wallet in the jungle for ten years, and law enforcement can do nothing about it.

The goal is to trace the Bitcoin until it hits a VASP (Virtual Asset Service Provider). This is typically a centralized exchange like Coinbase, Kraken, Binance, or OKX. Scammers must use these exchanges to convert their Bitcoin into fiat cash (USD, EUR) to buy houses, cars, or fund further operations.

When a scammer deposits stolen Bitcoin into an exchange, the exchange requires KYC (Know Your Customer) information. The exchange holds the scammer's real name, passport, selfie, and bank account details.

A visualization showing digital wallets connecting to a central exchange identity verification database
Centralized exchanges are the critical chokepoint where digital aliases meet real-world identities.

Once a forensic investigator identifies the specific exchange and deposit address, they produce an actionable intelligence report. This report is handed over to the victim and their local or federal law enforcement agency.

Armed with the report, law enforcement can issue a Preservation Request to the exchange, legally forcing the exchange to freeze the scammer's account so the funds cannot be withdrawn. Following the freeze, law enforcement issues a Subpoena to obtain the scammer's KYC documents.

Once the scammer is identified, the recovery moves from the digital realm into the traditional legal system via civil litigation or criminal asset forfeiture.

Why DIY Tracing Fails

Many victims attempt to trace their own Bitcoin using free block explorers like Blockchain.com. They will follow a transaction chain, find an address holding $500 million in Bitcoin, and assume they have found the "master scammer wallet."

In reality, they have simply traced their funds to the cold storage wallet of a massive exchange like Binance. They don't have the enterprise clustering software required to identify the *specific user deposit address* associated with the scammer. They only see the massive pool of funds belonging to millions of users.

Professional tracing software costs tens of thousands of dollars per license for a reason. If you have suffered a significant loss, it is highly recommended to seek a professional evaluation.

Request Bitcoin Tracing

If your Bitcoin was stolen, submit the exact transaction hashes of the theft below. Our analysts will conduct a preliminary heuristic review to evaluate tracing viability.

Initialize Trace Protocol

Submit blockchain artifacts (hashes/addresses) for preliminary forensic viability analysis.

Please provide the exact transaction hashes where the funds left your control.

Our analysis infrastructure is secured and compliant with strict evidentiary standards.