August 26, 2026
at
11:20 am
EST
MIN READ

While some view Bitcoin as a form of anonymous money, this is not quite true. Bitcoin is pseudonymous, which is different from being anonymous. While your Bitcoin wallet is not attached to your real identity, every transaction that your wallet has performed is stored in a public database for the world to see. As a result, Bitcoin can not be considered truly anonymous.
The gap between anonymous and pseudonymous is where blockchain investigators and sleuths live. On its own, a Bitcoin wallet address is just a meaningless string of characters. The moment that this wallet touches something that is associated with a real identity, such as an exchange account, the string of characters is no longer meaningless. From that point on, every transaction that the wallet has made and will make in the future will be associated with that identity.
This guide will cover what the Bitcoin ledger records, how to track the movement of Bitcoin on-chain, and when funds can no longer be traced.
Bitcoin runs on a shared ledger that all nodes in the blockchain network possess a copy of. When Bitcoin is sent, the transaction is broadcast to the network, packed into a block by a miner, and then recorded forever. There is no centralized blockchain admin who can hide, edit, or delete the transaction.
This functions similarly to a public chain-of-custody log which shows how specific parcels moved between parties. The log contains information on what was moved, who sent it, who received it, when the exchange occurred, and what the recipient did with the parcel. All the handovers are signed, but the signatures reference codes instead of names. Anyone can read this log, but the hard part is figuring out who each of the codes belong to.
Bitcoin has two design choices that make Bitcoin easier to follow than physical cash.
The first is that transactions consume specific coins. Bitcoin uses the UTXO (unspent transaction output) model, where wallets do not hold Bitcoin balances. Instead, each wallet holds a collection of unique chunks of Bitcoin. Each one of these chunks is the leftover from a previous transaction. When Bitcoin is spent, chunks are consumed and new leftover chunks are created. Old chunks are marked as spent and new chunks have a record of where they came from. As a result, each Bitcoin satoshi has a documented history that can be traced back to the block it was mined out of. Physical cash on the other hand, has no such record of the hands it has passed through.
The second is that spending reveals ownership. If a single transaction spends Bitcoin from five different addresses at once, the spender would need the keys to all five of these addresses. Investigators treat transactions like these as evidence that addresses belong to the same entity. By applying that rule across millions of transactions, investigators can group different addresses into a cluster. Clusters are a central pillar of blockchain analysis, and they are the reason why Arkham can show entity pages for organizations that operate up to thousands of different addresses.
The Bitcoin ledger shows several pieces of information:
The OP_RETURN allows users to attach a small amount of data to a transaction. Because that data is permanent and public, sometimes very important information can be found there.
The LuBian Hack is a good example of this. After roughly 127K BTC was drained from the Chinese mining pool, LuBian spent 1.4 BTC across 1,516 transactions asking the hacker to send the stolen Bitcoin back in exchange for a reward. One of these messages can be viewed here. The hacker never responded, but the messages are permanently recorded in the blockchain ledger, available for anyone to see. These messages were a key piece of evidence when Arkham broke the story in August 2025, making it the largest recorded Bitcoin theft of all time. OP_RETURN messages have also been used during the recent Coldcard exploit. Victims of the Coldcard exploit have been seen sending messages on-chain to the hacker’s address, pleading for their funds to be returned.
What the Bitcoin ledger does not record is equally as important. The ledger does not keep track of names, email addresses, IP addresses, phone numbers, and country of residence. These pieces of information live off-chain in exchange databases, court filings, social media, and online forums. An important part of tracing Bitcoin requires matching the on-chain footprint to the off-chain identity using OSINT, and the on-chain portion is the easier of the two for an investigator to compile.
Navigating this data can be overwhelming, which is why Arkham built a unique BTC explorer. It serves as one of the only platforms in the space where users can view Bitcoin transactions - especially those involving labelled entities - in a clean, highly readable format.

Paste an address or Transaction ID into the Arkham search bar. Alternatively, you can search up a labelled entity such as “US Government” from Arkham’s database of labelled addresses.

Arkham’s entity page gives users information on an entity’s holdings, balance history, transaction history, and counterparties. Users can filter by date or sort transactions by USD value to see if anything of interest pops up.

Arkham’s Visualizer turns an address or entity into a network graph, revealing inflows and outflows as lines between nodes. This makes it easy to see whether funds are arriving from an exchange, being split out into new wallets, or returning back to somewhere users already recognize. By adding a second entity to the search, the Visualizer will draw direct connections between the two, allowing users to quickly see the transaction relationship between two entities.

Tracer follows the movement of funds hop by hop across wallets, and users can click on any line between two nodes to open a transaction log that can be further filtered by token or dollar value. Tracer is the tool to use when a wallet has split its balance across a chain of intermediary wallets in a method called peel chaining, where a large amount of funds moves forward while a small portion peels off with each hop.
Bitcoin’s pseudonymity breaks when a wallet transacts with a known on-chain entity, such as an exchange. This is especially true for exchanges, as deposit addresses are typically unique to each customer. While users may not know who the transacting wallet belongs to at this point, the business the wallet interacts with will know.

Tracing is typically a drawn out process that requires hours of investigative effort. Arkham allows users to attach private labels to addresses so that your findings persist between sessions. Arkham also allows users to set alerts that fire when an entity on your watchlist moves funds, filtered by criteria such as size, chain, or token.
Bitcoin is pseudonymous when remaining on-chain. Converting Bitcoin to cash lets you spend that value off-chain, but also typically leads to an identity being attached.
Buying or selling Bitcoin on a regulated exchange commonly requires a government ID and a home address. Depending on the exchange, your country, and your verification tier, exchange requirements often also include a face photo, and in the US a Social Security number. As a result, the exchange holds a permanent record linking your identity to the deposit address they generated for your account and the withdrawal address that you provided to them. Every transaction that this provided address makes afterwards can be directly linked to you. This is the reason why blockchain analysis is often described as more of a funnel rather than a search. The middle of the journey can be difficult to follow on-chain, but the start and end of the journey are where regulated businesses sit with records that a court can subpoena.

Alternatives to exchanges come with their own unique risks. Peer to peer trades can work at a small scale, but leaves a counterparty that could be a scammer, informant, or undercover agent. Bitcoin ATMs are heavily regulated with compliance rules and record videos of their users. Offshore exchanges with weaker KYC processes are much more likely to get sanctioned or breached, and investigators gain access to these exchange’s records when either ends up occurring.
The police do have the ability to trace Bitcoin, and are better at doing so than most people assume. Law enforcement has two significant advantages that private researchers do not. The first advantage is that they can subpoena exchanges, and the second advantage is that they have the ability to seize devices to gain access.
Law enforcement has a strong track record of tracking down and seizing stolen funds. The US Department of Justice’s forfeiture of 127K BTC worth $15 billion from the Chen Zhi and Prince Group case in October 2025 was the largest asset seizure in American history. The 2016 Bitfinex hack was cracked years later when investigators were able to trace stolen coins to accounts tied to a couple. (Ilya Lichtenstein, 35, and Heather Morgan, 33).
Not every case takes years. In July 2025, federal prosecutors and the Secret Service filed civil forfeiture complaints covering over $25 million recovered from international scam networks. The largest complaint accounted for over $12 million taken from over 200 victims in romance scams. Law enforcement was able to follow the money through hundreds of intermediary wallets, and was able to identify wallets holding balances that could be recovered at the end of the trail. Since launching in November 2025, the Scam Center Strike Force have recovered over $800 million from cases such as these.
What cases that are resolved quickly and over years have in common is that the evidence needed to solve these cases never expires. Investigations made public in recent years often trace transactions that occurred from many years ago. Because of Bitcoin’s permanent ledger, there is no statute of limitations on the evidence found on-chain. A trail that was too cold to follow with the tools that were available in 2020 can be picked up again the moment a new piece of information presents a new possible lead.
Mixers take coins from a number of users, pool them together, shuffle them around, and then send different coins back out to the depositors. The idea of a mixer is to break the link between the depositing address and the withdrawing address. There are two main types of mixers.
The older and simpler model of mixer is the custodial mixer. Users send their Bitcoin to a deposit address generated by the mixer, and the service sends back different Bitcoins out of a pool funded by other users’ deposits. More advanced custodial mixers had additional features to help make tracing funds harder. Payouts could be delayed by randomized amounts of time, making timing correlation far less reliable. Payouts could also be split into multiple addresses in uneven amounts instead of one lump sum. One key flaw to custodial mixers is that operators need to know which payout belongs to which deposit, otherwise the service would not work properly. This mapping exists on a server somewhere, and when the server is seized, investigators can use it to de-anonymize every transaction that the mixer ever processed.
Non-custodial mixers, on the other hand, have users co-sign a large transaction with many inputs and outputs so that observers can not say with certainty which output belongs to which input. Because no one is ever holding someone else’s coins, non-custodial mixers do not have the exit scam risk or mapping log risk that custodial mixers have. However, non-custodial mixers do not remove legal risk. The transactions that non-custodial mixers create have a very distinct on-chain structure that is easy for investigators to spot, even if the individual links within the transaction are rather uncertain.
While mixers do make it harder to trace Bitcoin that passes through them, it is extremely difficult to make Bitcoin completely untraceable. Statistical analysis can be used to help determine where a Bitcoin went. If 1 BTC goes into a mixer and 0.98 BTC comes out several minutes later to a brand new address, this correlation is not definitive proof, but is a potential lead worth following. Additionally, mixed funds have a tendency to get flagged by an exchange’s compliance team. Coins that have passed through a known mixer service are much harder to spend than coins that have not, making it harder to get real world value out of these coins.
Bitcoin is traceable by design. The blockchain ledger is public, permanent, and records history for every single Bitcoin in existence. This is not a flaw that needs to be patched, this is the property of a blockchain network that allows it to function without a central authority.
What makes tracing hard is not Bitcoin’s design, but rather the sheer amount of volume that the Bitcoin network processes. Following funds through a chain of thousands of addresses, figuring out which outputs are payments and which ones are leftover change, and identifying transactions where Bitcoin touches a real business is a tedious and time-consuming process when done manually.












.png)
.png)








.jpg)
.jpg)




























.png)
.png)
.png)
.png)










.png)
.png)




.png)
.png)




.png)
.png)


.png)
.png)


.png)
.png)
.png)
.png)






















.png)
.png)


.png)
.png)
.png)
.png)


.png)
.png)








.png)
.png)








.png)
.png)





