03 Mar 2022

Top Data Integrations & OSINT Tools for Cryptocurrency Investigations

Maltego Team

Executive Summary đź”—︎

Cryptocurrency has seen enormous growth in the world economy. However, this has paved the way for criminal activity on the blockchain, which is why it is becoming increasingly important to trace and investigate transactions in different cryptocurrencies. The tools to obfuscate criminal cryptocurrency transactions are constantly evolving and luckily, so are the tools to trace them.

In this whitepaper, Maltego and our experts give you an overview of how criminals obfuscate cryptocurrency and list out 7 most useful tools for cryptocurrency investigations.

Key Takeaways đź”—︎

  • Criminals are obfuscating cryptocurrency movements through blockchain explorers.
  • There are 7 OSINT tools and data providers integrated with Maltego that allow one to investigate and trace cryptocurrency movements.
  • Maltego’s real-time data mining and information visualization capabilities allow investigators to effectively map out cryptocurrency movements.

Table of Content đź”—︎

Since its launch in 2009 by Satoshi Nakamoto, Bitcoin has seen its market capitalization rise from around 1 billion in 2013 to more than 1 trillion in 2021. While this explosive growth was taking place, a flurry of other cryptocurrencies was born. And, while Bitcoin remains the crypto coin with the highest market cap (and by far!), Ethereum and some others found success as well. As a result, today’s cryptocurrency transactions are complex, numerous, and continue to grow in volume.

To be able to investigate cryptocurrency transactions, one must understand how they differ from transactions made using fiat currencies, like dollars or euros. Given that each cryptocurrency can have its own set of evolving protocols defining these transactions, it quickly becomes an important aspect of the investigator’s job to keep up with the technology. For example, the Bitcoin “Taproot” update from last November introduced new mechanisms to Bitcoin, some of which improved the user’s privacy.

Some concepts, like smart contracts or the fact that a transaction can have multiple input and output addresses, are not self-evident and require that the investigator dives into the cryptocurrency they want to investigate before thinking of tracking its transaction.

Criminal Activities on the Cryptocurrency Blockchain đź”—︎

Why would one need to track cryptocurrency transactions? Well, while the popularity of cryptocurrencies grew, so did their usage. While there is a lot of legitimate usage for cryptocurrency, criminals also saw an opportunity in the decentralization and the relative anonymity offered by some cryptocurrencies. For example, according to a 2021 paper by Igor Makarov and Antoinette Schoar (London School of Economics and the National Bureau of Economic Research), “Illegal transactions, scams, and gambling together make up less than 3% of volume” of the Bitcoin transaction worldwide

Even if 3% seems like a small number, it should be noted that according to Binance, “in 2021, the Bitcoin network processed about $489 billion per quarter”, which means there are potentially billions of dollars of ill-gotten cryptocurrency being processed every year.

Tracking these ill-gotten funds can lead to the identification of the criminals moving said funds around and, sometimes, it may even lead to their recovery, as what happened during the Colonial Pipeline hack where the FBI was able to recover $2.3 million worth of Bitcoin. After the Bitcoin was seized, Deputy Attorney General, Lisa O. Monaco, made the subsequent declaration: “Following the money remains one of the most basic, yet powerful tools we have.”

3 Ways How Criminals Obfuscate the Trail of Bitcoin đź”—︎

Being able to track funds through cryptocurrency transactions is an important mean used by authorities to prevent and detect possible instances of money laundering. It is also something done by cryptocurrency exchanges—places used to buy and sell cryptocurrency in exchange for fiat currencies—to avoid unknowingly participating in organized crime and terrorism financing.

Several online free tools such as Blockchair, Etherscan and Ethplorer, exist that allow you to list the transactions linked to any given address in the most popular cryptocurrencies. These blockchain explorers offer an interface to visualize the information saved in the blockchain, namely the input and output addresses, the amount of the transactions, and the time of the transactions. However, this information alone may not be sufficient because investigators must put all the different bits of data together and find their correlations..

Let’s take Bitcoin as an example. Every transaction is available on the blockchain, a distributed public ledger that anyone can consult. Since regulated crypto exchanges have a KYC (Know Your Customer) duty, they by law should know the identity of people withdrawing funds using their services. To avoid having illegal funds traced back to them, criminals will use several methods to obfuscate the trail of Bitcoin. Here are some of these methods.

Peeling Chains đź”—︎

A peeling chain is a pattern commonly used to hide where a fairly big amount of coins is going. It usually starts off with a large number of coins concentrated in one address. This address will then send its money to two addresses. Transferring almost all the coins to the first address and the remainder to the second address. Then the process repeats itself until no money is left to “peel off”. Disseminating small amounts of money in many addresses makes it less likely to raise red flags for exchanges and other actors looking for money laundering. It also makes it more difficult for investigators to follow the money trail since it is split across multiple addresses.

Peeling chains

Tumblers and Coinjoins đź”—︎

Tumblers are services that will attempt to anonymize your Bitcoin by bouncing them around the blockchain and mixing them with other Bitcoins while using different patterns to make it difficult to link a spender to a recipient. Using them is not strictly illegal, but several Bitcoin Tumbler operators have been arrested for money laundering amongst other criminal offenses. A coinjoin is a method used to combine multiple Bitcoin payments into a single transaction. This way, several spenders can associate to merge their Bitcoin and have them redistributed appropriately to the right recipients. This arrangement makes associating a spender with its recipient(s) quite difficult.

Chain Hopping đź”—︎

Chain hopping is the act of exchanging your coins from one type of cryptocurrency to another. For example, one could exchange their Bitcoin for an equivalent amount of Monero to take advantage of the privacy features built into it. Chain hopping can be done using a traditional exchange or a specialized website.

Even though there are legitimate uses for tumblers and coinjoins, exchanges are becoming more and more reluctant to process coins that have been through these services, for fear of participating in money laundering. This can ultimately complicate the cash out process.

7 Useful Data Providers and OSINT Tools for Tracing Cryptocurrency Movements đź”—︎

As we have seen, tracking cryptocurrency funds across different transactions is necessary, and Blockchain explorers are tools freely available online that can help you do so. However, their use of text to display transactions makes it difficult to follow the money when any number of obfuscation methods have been used.

With its graphical approach, Maltego is perfect for visualizing complex cryptocurrency transactions. Here is a selection of the most useful data integrations in Maltego to investigate cryptocurrency payments. The list is in alphabetical order and doesn’t indicate any ranking or preference.

Top 7 Maltego data integrations for cryptocurrency investigations

Download this whitepaper for detailed descriptions and evaluations of the cryptocurrency data provided by each provider listed above.

Download the resource

DE +49
Albania +355
Algeria +213
Andorra +376
Angola +244
Anguilla +1264
Antigua And Barbuda +1268
Argentina +54
Armenia +374
Aruba +297
Australia +61
Austria +43
Azerbaijan +994
Bahamas +1242
Bahrain +973
Bangladesh +880
Barbados +1246
Belarus +375
Belgium +32
Belize +501
Benin +229
Bermuda +1441
Bhutan +975
Bolivia +591
Bosnia and Herzegovina +387
Botswana +267
Brazil +55
Brunei Darussalam +673
Bulgaria +359
Burkina Faso +226
Burundi +257
Cambodia +855
Cameroon +237
Canada +1
Cape Verde +238
Cayman Islands +1345
Central African Republic +236
Chile +56
China +86
Cote d'Ivoire +225
Colombia +57
Comoros +269
Congo +242
Cook Islands +682
Costa Rica +506
Croatia +385
Cuba +53
Cyprus +90392
Czech Republic +42
Denmark +45
Djibouti +253
Dominica +1809
Dominican Republic +1809
Ecuador +593
Egypt +20
El Salvador +503
Equatorial Guinea +240
Eritrea +291
Estonia +372
Ethiopia +251
Falkland Islands (Malvinas) +500
Faroe Islands +298
Fiji +679
Finland +358
France +33
French Guiana +594
French Polynesia +689
Gabon +241
Gambia +220
Georgia +7880
Germany +49
Ghana +233
Gibraltar +350
Greece +30
Greenland +299
Grenada +1473
Guadeloupe +590
Guam +671
Guatemala +502
Guinea +224
Guinea-Bissau +245
Guyana +592
Haiti +509
Honduras +504
Hong Kong +852
Hungary +36
Iceland +354
India +91
Indonesia +62
Iran, Islamic Republic of +98
Iraq +964
Ireland +353
Israel +972
Italy +39
Jamaica +1876
Japan +81
Jordan +962
Kazakhstan +7
Kenya +254
Kiribati +686
Korea, Democratic People's Republic of +850
Korea, Republic of +82
Kuwait +965
Kyrgyzstan +996
Lao People's Democratic Republic +856
Latvia +371
Lebanon +961
Lesotho +266
Liberia +231
Libyan Arab Jamahiriya +218
Liechtenstein +417
Lithuania +370
Luxembourg +352
Macao +853
Macedonia, the former Yugoslav Republic of +389
Madagascar +261
Malawi +265
Malaysia +60
Maldives +960
Mali +223
Malta +356
Marshall Islands +692
Martinique +596
Mauritania +222
Mauritius +230
Mayotte +269
Mexico +52
Micronesia, Federated States of +691
Moldova, Republic of +373
Monaco +377
Mongolia +976
Montserrat +1664
Morocco +212
Mozambique +258
Myanmar +95
Namibia +264
Nauru +674
Nepal +977
Netherlands +31
New Caledonia +687
New Zealand +64
Nicaragua +505
Niger +227
Nigeria +234
Niue +683
Norfolk Island +672
Northern Mariana Islands +670
Norway +47
Oman +968
Pakistan +92
Palau +680
Panama +507
Papua New Guinea +675
Paraguay +595
Peru +51
Philippines +63
Poland +48
Portugal +351
Puerto Rico +1787
Qatar +974
Reunion +262
Romania +40
Russian Federation +7
Rwanda +250
San Marino +378
Sao Tome and Principe +239
Saudi Arabia +966
Senegal +221
Serbia +381
Seychelles +248
Sierra Leone +232
Singapore +65
Slovakia +421
Slovenia +386
Solomon Islands +677
Somalia +252
South Africa +27
Spain +34
Sri Lanka +94
Saint Helena +290
Saint Kitts and Nevis +1869
Saint Lucia +1758
Sudan +249
Suriname +597
Swaziland +268
Sweden +46
Switzerland +41
Syrian Arab Republic +963
Taiwan +886
Tajikistan +7
Thailand +66
Togo +228
Tonga +676
Trinidad and Tobago +1868
Tunisia +216
Turkey +90
Turkmenistan +993
Turks and Caicos Islands +1649
Tuvalu +688
Uganda +256
United Kingdom +44
Ukraine +380
United Arab Emirates +971
Uruguay +598
United States +1
Uzbekistan +7
Vanuatu +678
Holy See (Vatican City State) +379
Venezuela +58
Viet Nam +84
Virgin Islands, British +84
Virgin Islands, U.S. +84
Wallis and Futuna +681
Yemen +967
Zambia +260
Zimbabwe +263

By clicking on "Access", you agree to the processing of the data you entered and you allow us to contact you for the purpose selected in the form. For further information, see our Data Privacy Policy.

Don’t forget to follow us Twitter and LinkedIn and sign up to our email newsletter to stay updated on new use cases, tutorials, and event information!

By clicking on "Subscribe", you agree to the processing of the data you entered and you allow us to contact you for the purpose selected in the form. For further information, see our Data Privacy Policy.