Skip to main content

Source & destination of funds

Trace the movement of funds and surface where continuity breaks.

ChainGuard traces direct and indirect exposure through the bounded graph available for monitored Bitcoin and account-based wallets, attributes activity where evidence supports it, and flags where continuity breaks.

How we follow value

  • Bitcoin input/output relationships
  • Account-graph tracing
  • Bounded multi-hop analysis
  • Upstream and downstream direction

What we resolve

  • Entity attribution per hop
  • Known and unknown terminal sources
  • Sanctioned, mixer and threat exposure

What we report back

  • Confidence assessment
  • Completeness assessment
  • Graph evidence retained with the case

Trace demonstration

A sanitized example of multi-hop tracing.

One path resolves to an attributed exchange. The other reaches a bridge, where continuity breaks and the trail is reported as broken rather than extended by assumption.

TraceIllustrative example · sanitized data, not a live trace
Illustrative multi-hop fund tracing graphA sanitized example showing a subject address tracing through intermediate hops to an attributed exchange on one path, and to a bridge trace break leading to an unattributed cluster on another path.Subject addressIntermediate hopIntermediate hopAttributed exchangeBridge: trace breakUnattributed clusterDestination address
  • Attributed
  • Trace break
  • Unattributed

Direction

Tracing runs both ways, for different questions.

Upstream: where did this come from?

For an incoming deposit, tracing runs backwards through the relationships available in the ingested graph. On Bitcoin that starts from the transaction inputs feeding the monitored output; on an account-based network it means walking the account graph. Each hop is attributed only where persisted evidence supports it.

Downstream: where is this going?

For an outgoing withdrawal, tracing runs forwards towards terminal destinations such as an exchange, a service, a bridge or a cluster that cannot be attributed. The result is reported with the confidence it actually carries.

Limitations

Where tracing stops, and why we say so.

A trace that overstates its reach is worse than one that reports its boundary. These are the three cases where ChainGuard stops and labels the result.

Trace break

Bridges and cross-chain movement

Continuity can break where value leaves one network and reappears on another. ChainGuard reports a trace break rather than asserting a link it cannot evidence.

Trace break

Mixing and pooling services

Where a service deliberately breaks the link between input and output, the platform records the interaction and stops, instead of guessing at the far side.

Trace break

Unattributed clusters

Where a terminal source or destination cannot be established, it is reported as unknown. An unattributed cluster is never silently treated as clean.

ChainGuard does not claim universal protocol decoding. Where the evidence is inferred rather than observed, the result says so.

Private deployment review

See tracing applied to your institution's flow of funds.

Map ChainGuard to your institution’s transaction, policy and evidence workflows.