The limits of keyless forensics
This is the lesson that makes everything before it usable. Analytical technique tells you what you can see. Professional honesty tells you what you are entitled to say about it. Get that second part wrong and your work becomes worthless the first time somebody competent reads it adversarially, because a single unsupportable claim discredits the whole document, including the parts that were right.
Three registers
Every statement in a forensic conclusion belongs to one of three registers, and the discipline is never letting them blur.
| Register | What belongs there | How it is phrased |
|---|---|---|
| Fact | Reproducible on-chain state and events. Contract blacklist status. A transfer with its TxID, amount and timestamp. An address age derived from its first transfer. An official sanctions list match. | "The address is blacklisted at contract level, on-chain event dated 3 July 2026." Anyone can verify it. |
| Reasoned opinion | Interpretation of facts through a stated method. Deposit-address attribution by dominant flow. Behavioral clustering by common funder. Pattern identification. | "The outflow pattern matches a deposit address of [exchange], derived by heuristic." The method travels with the claim. |
| Not available | Identity of a wallet's owner. Intent. Proprietary named clusters. Certainty that funds are clean. Anything beyond the depth we can actually trace. | Say nothing, or say explicitly that it is outside the scope of this analysis. |
The most damaging error is not being wrong. It is presenting register two as register one. "This is Binance" and "this address received funds from a wallet publicly tagged as Binance" may describe the same reality, but only the second survives a lawyer reading it line by line. The first is an unsupported assertion about an entity. The second is a verifiable statement with its evidence attached.
What keyless means and where it stops
We read primary sources directly: token contract state, contract events, transaction data from public explorers, official sanctions lists, public label sets, external scam databases. No resold scoring, no black box. That gives us a specific strength: everything we assert, you can independently reproduce. Reproducibility, not confidence of tone, is what carries an analysis when it is challenged.
It also gives us a specific limit. The large commercial platforms have spent years building proprietary clusters that bind millions of addresses to named entities, assembled from data sources we do not have. We do not have that and we do not imitate it. Where we see a behavioral trait with no public label, we write "consistent with a service or hub by behavior", not a company name. Our tracing depth is honest too: two reliable hops in a report, plus peel-chain following along a dominant flow until it stops. When the trace dissolves into an unlabeled fresh wallet, the finding is that the trace ends there. Inventing the next hop is precisely what makes a report indefensible.
What we do have that they do not
Naming the limit is not the same as conceding the field. Three things sit on our side of the ledger and it is fair to say so.
- A dated freeze corpus of our own. We collect blacklist events straight from the USDT contracts: 2,312 blacklisting events, 1,414 on TRON and 898 on Ethereum, 278 removals, roughly 564 million dollars destroyed. That lets us write "blacklisted since [date]" rather than a bare status, and a dated event is far harder to argue with than a boolean.
- Regional crowdsourced fraud reports. Fresh P2P scam addresses from this region appear in community complaints long before they reach any international threat-intelligence base. This is data the large platforms do not hold.
- An index that grows from real work. Every analysis adds to our own graph and our own derived labels. It is a slow, bottom-up way to build attribution, and it is genuinely ours.
How to phrase conclusions by confidence
Practical wording, in ascending order of what you are claiming. Use the weakest form that still says what you found.
- Verified fact. "Verified directly against the token smart contract as of [date]."
- Structural observation. "The addresses are linked by [specific reproducible behavior]." You are describing the chain, not the people.
- Derived attribution. "Matches [pattern], derived by heuristic." Name the heuristic.
- Public label. "Tagged as [entity] in a public label set." The label's source is part of the claim.
- Absence of finding. "No markers were found in the sources checked, as of [date]." Never "clean".
- Boundary. "This analysis does not establish [X] and no conclusion is drawn on it." A stated boundary strengthens a document.
That fifth line deserves emphasis because it is where most reports quietly cheat. "No markers found" and "clean" are not synonyms. Fresh fraud has not reached the databases yet. Plenty of illicit flow carries no public label at all. And we do not see the proprietary clusters. Writing "clean" claims knowledge of all three, which nobody has.
Answering the request for a guarantee
Sooner or later somebody asks you to confirm that funds are clean, or to guarantee an unfreeze. They are not being unreasonable. They want certainty, and other people in this market sell it to them. Here is how I answer, and it has never cost me a client worth having.
- Say what you can establish. "I can confirm the address is not blacklisted at contract level, has no sanctions match across the sources checked, and appears in no scam database, all as of today's date."
- Name the limit without apologizing. "What no one can confirm is that funds are clean in an absolute sense. Fresh fraud has not reached the databases and part of illicit flow carries no public marker."
- Explain why the honest answer is more useful. "A screening you can verify line by line is something you can hand to compliance. A cleanliness percentage from a black box is something they will discount."
- Name the alternative plainly. "Anyone guaranteeing an unfreeze is describing a decision that belongs to a compliance team they do not work for."
On outcomes specifically, the honest numbers are the ones from the corpus above. Against 2,312 blacklisting events we recorded 278 removals, and independent analysis puts same-year release at roughly 3.6 percent of frozen addresses, around 6 percent historically, with 55.6 percent of frozen volume ultimately destroyed. I give people that figure early, because false hope is its own kind of harm and it also produces bad decisions: it is why people pay unlockers.
Mistakes I see in other people's reports
- A risk percentage with no method. A number without a stated basis is not a finding, it is decoration, and a serious reviewer treats it as such.
- Named entities the author cannot support. One unsupportable name discredits the document.
- Hashes with no narrative. A compliance officer is not an analyst. Unreadable is indistinguishable from unpersuasive.
- Silent limits. A report that never states what it did not do invites the reader to assume the worst about the gaps.
- Results that change between runs. If the same input yields a different conclusion on Tuesday, nothing in it can be relied on. This is why a report should carry an integrity hash over its stable core.
Check yourself
- Task. Take a conclusion you have written, or one from any report you can find, and label every sentence F for fact, O for reasoned opinion, or N for not supportable. Then rewrite each O sentence so its method is stated inside it, and delete or bound every N.
- How to know you did it right. Every F sentence can be verified by a stranger with a public explorer. Every O sentence names its method in the same breath as its claim. Nothing survives in the N category unnamed. If the exercise made your conclusion noticeably weaker in tone, that is the correct outcome: what you removed was never yours to assert, and what remains will survive an adversarial reading. That is the whole difference between a document and a marketing artifact.
Free preliminary case assessment
Describe your situation and we will give you an honest assessment: what is realistically possible, how long it takes and what it costs. No "guaranteed unlocks": they do not exist, because the decision sits with compliance.