Heuristic – Cryptocurrency Clustering Techniques

The term heuristic is often defined as a practical, fast mental shortcut, rule of thumb, or trial-and-error method used to solve problems or make decisions when finding an optimal solution is too slow or impossible. When used for cryptocurrency tracing, the term heuristic describes cryptocurrency clustering techniques.

One of the best ways to understand how cryptocurrency tracing relies on clustering techniques known as heuristics, is to study United States v. Sterlingov, 719 F. Supp. 3d 65, 68-69 (2024). In Sterlingov, the court explained:

“Given the volume of transactions recorded on the blockchain, investigators frequently make use of proprietary software like Chainalysis Reactor to cluster bitcoin transactions using the co-spend and other heuristics.Much of this work could be done manually given enough time, and as explained below, it is possible to corroborate (or to challenge) the results generated by the software for particular clusters with the public blockchain data, a pad of paper, a pencil, and hours of work….

[Chainalysis’s] Reactor also uses other heuristics based on unique identifiers that Chainalysis has associated with particular services that have in the past or that currently transact on the blockchain.”

First Heuristic Technique – Co-Spend or Common Spend Heuristic

In Sterlingov, the court gave the following explanation of the first of three types of heuristics used by Chainalysis and its Reactor software:

“First, [Chainalysis] uses the co-spend or common spend heuristic, referred to as “Heuristic 1.” This heuristic is based on a unique feature of the blockchain: “A transaction can contain multiple input addresses and multiple output addresses,” and “[w]hen a transaction contains multiple inputs addresses, the input addresses are said to be co-spending.”….

But because each transaction input requires that the sender have access to the private key for each of the corresponding input addresses, it is very likely that a single person or entity controls each of the input addresses….

Imagine, for example, that a virtual wallet holds three bitcoin addresses. The first address contains 1.5 bitcoin, the second address contains 2 bitcoin, and the third address contains 3 bitcoin.

If the owner of the wallet wants to purchase an item that costs 4.5 bitcoin, or transfer that amount to a different address for any other reason, he would need to fund that transaction with two of his three addresses. In order to do so, moreover, he would have to enter the private key for each sending address.

Using the co-spend heuristic, it would then be possible to cluster the two co-spending input addresses together because it is highly unlikely that a user would share his private keys with others. The following diagram reflects this simplified example of co-spending:

Figure 1: Example co-spend depiction…

Example diagram of co-spend or common spend heuristic

The co-spend heuristic dates back to the creation of the Bitcoin system in late 2008 and early 2009.

A white paper prepared by the inventor of the Bitcoin system recognized this weakness in the purported anonymity of the system, observing that “[s]ome linking is . . . unavoidable with multi-input transactions, which necessarily reveal that their inputs were owned by the same owner.

The risk is that if the owner of a key is revealed, linking could reveal other transactions that belonged to the same owner.” See Satoshi Nakamoto, Bitcoin: A Peer-to-Peer Electronic Cash System, at 6 (2008), https://bitcoin.org/bitcoin.pdf.

In a 2013 article, Professor Sarah Meiklejohn and her team of researchers from the University of California at San Diego and George Mason University, described the co-spend heuristic as based on “an inherent property of the Bitcoin protocol” and recognized that it had “already been used many times in previous work.” Meiklejohn at 5.

As her paper explains, the heuristic is “quite safe: the sender in the transaction must know the private signing key belonging to each public key used as an input, so it is unlikely that the collection of public keys [is] controlled by multiple entities (as these entities would need to reveal their private keys to each other).” Id. at 6; see also United States v. 155 Virtual Currency Assets, 2021 U.S. Dist. LEXIS 69035, at *4 (D.D.C. Apr. 9, 2021) (“[B]ecause users often combine multiple bitcoin addresses and use them together in the same transaction (a ‘cluster’), analysis of one transaction might reveal many addresses belonging to a single individual or organization.”).

…The defense responds that “CoinJoin” services enable different individuals to contribute inputs to a single transaction, thereby defeating the assumption that when multiple addresses fund a single transaction, they are controlled by one entity. But Bisbee attests that Chainalysis has “controls in place to detect CoinJoin” and that it “can skip the CoinJoin co-spends” in its clustering. Dkt. 149-1 at 3 (Bisbee Decl.); see also Dkt. 229 at 243 (Aug. 23, 2023 Hrg. Tr.) (Still) (testifying that most blockchain analytics companies are able to identify transactions that occur through Wasabi, one of the most common CoinJoin implementations)….”

Id. at 71-72 (citations omitted).

Second Heuristic Technique – On-Chain Behaviors and Patterns

In Sterlingov, the court gave the following explanation of the second of three types of heuristics used by Chainalysis and its Reactor software:

“The second heuristic (“Heuristic 2”) is based on observing and tracking a particular entity’s on-chain behaviors and patterns. The theory underlying Heuristic 2 is that every large-scale participant in the blockchain leaves a digital “fingerprint,” which can be discerned by looking at the information publicly available on the blockchain ledger and conducting test transactions with addresses known to belong to the target entity…

Once those behaviors have been identified, an algorithm can be used to cluster the potentially thousands of addresses that engage in transactions that match the pattern. Id. at 2-3 n.1 (describing how “rules are customized for each entity” in Heuristic 2 “based on close study of that entity and an understanding of the particular pattern in which the addresses within the cluster interact”).

Given the risk that revealing the precise details regarding Heuristic 2 would permit cybercriminals to circumvent detection in ongoing investigations, Chainalysis provided those details to defense counsel pursuant to a protective order, see Dkt. 210; Dkt. 213, and the Court will, for present purposes, explain the heuristic only at a more general level, using examples.”

Behaviors Related to “Change” Addresses

In Sterlingov, the court gave the following explanation of behaviors related to “change” addresses:

To begin, the heuristic might look to the address type employed and the behavior of the virtual wallet software used by the entity, especially as it relates to “change” addresses. By way of background, blockchain participants typically “store their private keys securely in a digital wallet, which ‘can take the form of software or hardware.'”…

As noted above, the fee charged for mining (i.e., verifying and transmitting a bitcoin transaction) can vary based on the speed (or priority) with which the sending entity seeks to effectuate the transaction.

In addition, when the sending entity holds more bitcoin in the sending address than is necessary to complete the transaction, only some of the bitcoin in the sending address are sent to the receiving address, and the remaining amount is sent to what is referred to as the “change” address. (The Bitcoin system does not permit a user to spend only a portion of the bitcoin held in a given sending address, necessitating the creation of a “change” address to receive the unspent bitcoin.)

Software wallets, moreover, “have distinctive ways of handling [1] fees and [2] change addresses,” permitting Chainalysis to “investigate[] a service’s particular transaction patterns” and to “develop clustering algorithms specific to that service.” Bisbee Expert Report at 6. Through repeated observation, Chainalysis can track unique features, such as the “size of the data contained in the transaction” or the “[l]ock time” (which is “a parameter that schedules a minimal time before the blockchain accepts a transaction”). Id. at 7…

Chainalysis can then use these unique characteristics to identify and to cluster addresses involving the same darknet service.

In one case, for example, a darknet marketplace employed a sliding scale for miner transaction fees such that the fee the marketplace paid varied depending on the size of a transaction—in effect, the service paid more so that the Bitcoin network would record larger transactions more quickly. See Andy Greenberg, Tracers in the Dark: The Global Hunt for the Crime Lords of Cryptocurrency 170 (2022). By using this marker, along with many others, Chainalysis was then able to cluster together the addresses controlled by that marketplace. Id.

Part of the reason that Heuristic 2 works is that “bigger clusters tend to be more predictable in terms of their behavior” because “the operators of these big clusters use automated scripts in order to form their transactions.” George Kappos et al., How to Peel a Million: Validating and Expanding Bitcoin Clusters, arXiV (Cornell University) 1, 11 (2022), https://arxiv.org/abs/2205.13882 (hereinafter “Kappos”)…

Id. at 72-72.

Behaviors Related to Peel Chain

In Sterlingov, the court gave the following explanation of behaviors related to peel chain:

Heuristic 2 also employs another technique, first discussed by Professor Meiklejohn, known as “peel chain behavior.”…

“As noted above, the Bitcoin system does not permit a user to expend only a portion of the bitcoin held in an address; instead, when the user wants to engage in a transaction requiring fewer than all of the bitcoin in the address, the remainder—or “change”—is sent to a change address, which remains under the control the original sender.

“A peel chain is a pattern of Bitcoin transactions that occurs when a wallet receives a relatively large amount of [b]itcoin[,] which it gradually spends in multiple, sequential transactions.” Scholl Expert Report at 5. “Typically, each transaction has one input and two outputs: one output constituting a payment to a separate entity and one output constituting the ‘change’ . . . sent to a new Bitcoin address [that] is controlled by the same wallet as the input address.” Id.

This process can repeat itself through a series of transactions, creating a chain in which “[t]he ‘peel’ refers to the smaller, spending transaction and the ‘chain’ refers to the linked change addresses that continue on.”…

Although, absent other information, the peel chain itself will not necessarily reveal which is the “peel,” or payment, and which is the “change” address, Bisbee explains that when Chainalysis “finds the end of the chain and finds a co-spend with an address that appeared at the beginning of the chain,” it can then “demonstrate[] that the full peel chain is controlled by the same wallet.” Id. In other words, finding an address at the end of a chain that has co-spent with an address at the beginning of the chain makes clear which addresses are in fact change and which are in fact payment….”

Id. at 73-74.

Third Heuristic Technique – Intelligence-Based Heuristic

In Sterlingov, the court gave the following explanation of behaviors related to intelligence-based heuristic:

“The third heuristic used by Chainalysis is the so-called intelligence-based heuristic (“Heuristic 3”), which is not actually a heuristic at all. It refers, instead, to information that Chainalysis has gathered off-chain, from sources such as “data leaks, court documents, Chainalysis data partnerships, exchanges that share their addresses with Chainalysis, and manual merges due to services changing wallets.” Bisbee Expert Report at 9.

Unlike Heuristics 1 and 2, which analyze the blockchain, this heuristic relies on information obtained from sources unrelated to any on-chain activity or analysis.”

Id. at 74.

Read more about cryptocurrency tracing problems in forfeiture cases.


This article was updated on Friday, July 17, 2025.