Cryptocurrency investigations combine classic digital forensics, blockchain analysis, OSINT techniques, and the correlation of multiple intelligence sources. This guide summarizes a complete, field-tested workflow suitable for:

Every tool listed here is open-source, freemium, or widely used in professional environments.


1. Initial Scoping

Before touching the chain, define:

Key questions:


2. Collect the Base Evidence

For every blockchain investigation, you must obtain:

Essential inputs

Triaging tools

This phase anchors the entire investigation.


3. Multi-Chain Blockchain Exploration

Once you have an address or TXID, begin wide recon.

Universal Block Explorers

Blockchair

https://blockchair.com/ Multi-chain explorer with entity hints, charts, and metadata.

OKLink

https://www.oklink.com/ Excellent for:

Blockscan

https://blockscan.com/ All EVM chains in one interface.


4. Chain-Specific Explorers

Bitcoin

Ethereum & EVM

Solana

Tron


5. Visual Tracing & Graph Analysis

This is where you visualize the flows:

Breadcrumbs (highly recommended)

https://www.breadcrumbs.app/

GraphSense (open-source)

https://graphsense.info/

OXT.me (BTC only)

https://oxt.me/


6. Attribution & Entity Identification

Goal: determine who controls the receiving address.

You are looking for:

Helpful tools:

Elliptic Investigator (enterprise)

https://www.elliptic.co/

AMLBot (risk score)

https://amlbot.com/

Crystal Blockchain

https://crimeflare.org/ (mirror) Professional-level attribution.

WalletExplorer (BTC)

https://www.walletexplorer.com/


7. Mixer, Bridge & Tumbler Detection

Look for:

Mixer detection tools:

Bridge detection:


8. Exchange Tracing

Your objective is to identify if the funds ended at:

Indicators of exchange involvement:

Once an exchange appears as a destination, a formal request (LEA pathway) is possible.


9. OSINT Correlation

You now merge blockchain traces with other intelligence sources.

Infrastructure

Social / Human OSINT

Metadata

Historical content

Your goal is to identify:


10. Reporting – Defensible & Clear

Your final output should contain:

1) Executive Summary

2) Timeline

Chronological reconstruction of:

3) Blockchain diagrams

Export from Breadcrumbs or GraphSense.

4) Entity attribution

5) Technical appendix


11. Full Crypto Investigation Workflow (Condensed)

  1. Collect evidence
  2. TXIDs, wallets, logs, timestamps

  1. Clone the device (if compromise suspected)
  1. Run multi-chain recon
  2. Blockchair → OKLink → Blockscan

  1. Visualize the flow
  2. Breadcrumbs / GraphSense

  1. Identify services
  2. mixer → bridge → exchange

  1. OSINT correlation
  2. usernames, domains, metadata, infrastructure

  1. Determine destination
  2. CEX / service / cluster

  1. Prepare formal report
  2. chain-of-evidence + timelines + diagrams


12. Additional Tools You Should Consider

Monitoring

Forensics (local)

Automation


Final Notes

This workflow is designed to be:

It matches the needs of real-world cybercrime investigations and integrates directly into the SystemLog OSINT and Forensics sections.