Cross-Chain Crypto Laundering Tracing and Attribution

From Addresses to Entities: How Cross-Chain Laundering Gets Named

MetaSleuthInvestigationAttribution
September 17, 20266 min read

The Short Answer: Naming Who Is Behind Means Clustering Addresses Into Entities

Cross-chain crypto laundering tracing ends in one question: who is behind this address? The answer is an entity rather than another address, and the technique that produces it is address clustering. Naming who is behind is the step that turns a trail of addresses into a named entity, and address clustering is how that step is performed. The rest of this article explains why cross-chain laundering resists that step, what the naming workflow looks like stage by stage, and how MetaSleuth makes the whole process tractable.

A single actor almost never launders through a single address. The same person controls dozens or hundreds of addresses, and a graph tool groups those addresses into a cluster by finding shared funding, shared timing, or shared addresses on the other side. When a cluster is named, the investigation has moved from tracing to naming.

An entity can be a single person, a laundering group, an exchange, a scheme, or a sanctioned organization. The behaviors that get addresses clustered match the FATF red-flag indicators for virtual assets. Naming does not need a real-world name on day one. It needs a stable grouping that lets an investigator refer to the same actor across thousands of addresses, which is the foundation every later step builds on.

This is the difference between detection and naming. A transaction monitor flags a suspicious transfer. Naming answers the harder question of who is behind the flag. The monitor says something happened. The investigator says who did it.

In the Nomad Bridge incident, address clustering collapsed 322 apparent addresses into no more than 219 distinct entities. Two of those entities controlled nearly half of the loss, a finding that stays invisible when addresses are examined one at a time.

Why Cross-Chain Laundering Resists Naming

Laundering gets harder to name the moment it leaves a single chain. A path that moves value across Ethereum, a bridge, BNB Chain, an instant exchange, and then Bitcoin breaks the single-chain graph into fragments. Each chain has its own explorers, address formats, and gaps, so naming requires stitching the fragments back together.

Cross-chain bridges add another break. When assets move through a bridge, the token is locked on one chain and minted or released on another, so there is no single transaction that an investigator can follow straight through. The path has to be reassembled from two half-records on two different ledgers.

Practitioners describing cross-chain laundering cases return to the same demand: a laundering path spanning Ethereum, BNB Chain, Polygon, Avalanche, and Bitcoin must be traced and named across all of those chains, not one network.

One recurring research direction asks for exactly this: cross-chain fund tracing and node-level API interception, both of which push naming beyond a single network.

Instant exchanges make the problem worse. They let a user swap assets without an account, which severs the deposit-to-withdrawal link that a single-chain exchange would preserve. Re-linking those two sides is a matching problem, and it is where naming usually stalls. Mixers add a second layer of hiding on top, because they break the one-to-one path into a shared pool.

The Naming Workflow

Naming follows a repeatable workflow with four stages: shared-deposit clustering, cluster merging, naming the entity, and cross-chain re-naming.

The order matters because each stage depends on the one before it. You cannot merge clusters you have not found, and you cannot identify an entity you have not merged. The workflow is linear, but each stage can loop back when new addresses surface.

Shared-deposit clustering finds addresses funded by the same source. Starting from two victim-provided TRON addresses, MetaSleuth used shared-deposit address clustering to expand the analysis into a complete fund network. The seed addresses led to hot wallets, then to intermediate addresses, then to exit channels, and finally to exchange deposit addresses.

Cluster merging groups those addresses into larger clusters when they share downstream behavior. Two addresses that started apart can end up in the same cluster because they both paid into the same exit channel. Entity identification then names the cluster as an exchange hot wallet, a Ponzi scheme, or a sanctioned entity. The offense underneath, laundering, is laid out plainly in FinCEN's overview. The entity name is what turns the cluster into something actionable: a name, a jurisdiction, or a wallet that a case can be opened against.

The payoff is a named entity, not a list. In a US DOJ laundering case, MetaSleuth's analysis of one address traced more than 10,000 transfers and more than 700 addresses on the other side. That scale only matters because the transfers resolve into names an investigator can act on.

The last stage is cross-chain re-naming. When funds cross a bridge, the cluster on the destination chain is matched back to the cluster on the source chain, so the entity stays continuous across the jump.

Nomad Bridge clustering: 322 addresses collapsed into 219 entities, two holding nearly half the loss

How MetaSleuth Makes Naming Tractable

MetaSleuth makes naming tractable by combining a large labeled address graph, cross-chain analysis, and instant-exchange tracing.

BlockSec has described MetaSleuth as enabling near real-time tracking during incident response, and the platform is used by regulators and law enforcement agencies around the world. In practice, an investigator follows the flow visually. Each hop renders as an edge between addresses, and labeled entities appear as named nodes. The path reads as a story instead of a spreadsheet of hashes.

MetaSleuth carries more than 600 million address labels, so a clustered address can often be named directly rather than left as an anonymous identifier. This is what MetaSleuth's address graph gives an investigator.

MetaSleuth supports 12 chains listed in its official documentation, and its cross-chain view follows funds through bridges. A single workspace shows the source chain and the destination chain together, so the investigator does not have to rebuild the graph by hand.

The instant-exchange matching method BlockSec presented at ACM SIGMETRICS 2025 links deposits to withdrawals at more than 80% accuracy, reported as an academic result rather than a product benchmark. That matching is the piece that closes the deposit-to-withdrawal gap instant exchanges open.

The method is not theoretical. The VerilyHK investigation and the US DOJ case both end in named entities because the labeled graph, the cross-chain view, and the matching method are combined in one workspace.

MetaSleuth entity network view clustering related addresses into named entities

What to Do Next

Pick one laundering trail that currently stops at a dead end, and run it through the naming workflow. Start from the seed address, cluster it, merge the clusters, and name the entity. The moment you can say who is behind the addresses instead of just listing them, the investigation has moved forward.

Name the actors with MetaSleuth and turn a multi-chain trail into a named entity.

This piece is part of the MetaSleuth investigations and forensics guide, where the tracing method, evidence handling, and tooling tiers are covered end to end.

Frequently Asked Questions

Trace Funds with MetaSleuth

On-chain investigation platform for multi-hop fund tracing and forensics