What is address clustering?¶
Address clustering is the analytical grouping of blockchain addresses that may be controlled by the same wallet, service or entity.
Avoid the dangerous assumption¶
The dangerous assumption is that a cluster proves all included addresses belong to one named person.
Clustering may use transaction patterns, shared inputs, change-address behaviour, service labels, timing or other technical indicators.
Some methods are stronger on particular blockchains than others.
A cluster can help investigators understand likely common control, follow value and identify links that are not obvious from one address alone.
But clustering is usually an inference rather than a direct provider record.
Wallet software, exchanges, payment processors and collaborative transactions can create patterns that resemble common ownership.
Addresses controlled by a large service may also be grouped together even though the underlying customers are unrelated.
Preserve the addresses, transactions, tool or method used, date of analysis and confidence level.
Document the reason each address was added to the cluster.
Do not present analytical labels as established identity.
Where possible, corroborate the cluster through exchange records, seized-wallet data, device artefacts, communications or known transaction behaviour.
A cluster may change as new blockchain activity or attribution data becomes available. Later evidence may strengthen, narrow or overturn the original grouping.
When reporting, distinguish confirmed common control from probable or possible association.
Explain the limitations of the method and avoid naming a person unless separate evidence supports that attribution.
Operational takeaway¶
Use address clustering as a structured analytical lead and corroborate common control through provider, wallet, device or contextual evidence before attributing the cluster to a person.