The MadBrooks Sage

Transaction Graph Analysis: Following the Flow of Funds

Sep 14, 2026 · 9:12 AM CT · 8:59 · The MadBrooks Sage | Transaction Graph Analysis | Following the Flow of Funds | 9/14/2026

Learn how researchers trace blockchain transactions across addresses, analyze clustering patterns, and what movement patterns reveal about network behavior without identifying individuals.

Apple Podcasts Spotify Pocket Casts RSS

Transcript

If you can't follow the money, you can't understand the system.

Blockchains are transparent by design, which means every transaction that's ever happened is sitting there, visible, waiting to be read. But transparency doesn't equal clarity. Looking at blockchain data without knowing how to analyze it is like staring at a river and trying to understand where all the water came from, where it's going, and what it's carrying along the way. Transaction graph analysis is the discipline that makes sense of that flow. It's how researchers trace funds across addresses, identify patterns in how value moves, and understand network behavior at scale, all without necessarily knowing who any of these people are.

Think of a blockchain as a vast network of tributaries and streams. Each address is a point where water can collect or flow out. Each transaction is a channel connecting one point to another. When someone sends Bitcoin or Ethereum from one address to another, they're creating a visible, permanent link in this network. And once you have enough of these links, you can start to see shapes emerge. Patterns. The way water flows downhill isn't random. Neither is the way value flows through a blockchain.

The basic building block of transaction graph analysis is the transaction itself. You have inputs, addresses sending funds, and outputs, addresses receiving them. When you map these out over time, you create what's called a transaction graph, a web of connections showing who sent what to whom and when. This graph becomes the terrain you're exploring. And like any terrain, it has landmarks, choke points, highways, and backwaters.

One of the first things researchers do is look for clustering. Not all addresses are islands unto themselves. Many addresses are controlled by the same entity, whether that's a person, an exchange, a company, or a bot. If you can figure out which addresses belong together, you start to see the real players in the network instead of just a fog of anonymous labels. This process is called address clustering, and it relies on heuristics, educated guesses based on patterns in how transactions are structured.

The simplest heuristic is called common input ownership. If a transaction has multiple input addresses, meaning several addresses are contributing funds to the same outgoing transaction, it's reasonable to assume those addresses are controlled by the same person or organization. Why? Because creating a transaction requires the private keys for all the input addresses. If I'm spending from three different addresses in one transaction, I must control all three. That's a strong signal. Researchers use this to start grouping addresses into clusters, treating each cluster as a single entity.

Another common heuristic involves change addresses. When you spend cryptocurrency, you often don't send the exact amount sitting in an address. Say you have one Bitcoin and you want to send half a Bitcoin to someone. The protocol requires you to spend the entire Bitcoin. So you send point five to your intended recipient and point five back to yourself, to a new address you control, called a change address. Identifying which output is the payment and which is the change can help researchers link that change address back to the original sender's cluster. There are patterns in how wallets create change addresses, in the ordering of outputs, in the amounts, in the address types used. All of this leaves fingerprints.

Once you've clustered addresses, you can start analyzing flows. This is where things get interesting. You can watch how funds move from one cluster to another, how long they sit still, how they split and merge. Some patterns are obvious. If a large amount of cryptocurrency suddenly moves from a known exchange to a cluster of addresses that then rapidly splits the funds into hundreds of smaller transactions, that might indicate a mixing service or an attempt to obscure the trail. If funds move in a straight line from address to address without much branching, that could be someone consolidating or preparing for a large payment.

Researchers also look at timing. When do transactions happen? Are they regular, like clockwork, or sporadic? Do they correlate with external events, like price movements or network congestion? Timing can reveal automation, can suggest coordination, can hint at whether an entity is reactive or planned in its behavior. Imagine seeing thousands of small payments flowing into a single address every ten minutes, right after new blocks are mined. That's probably a mining pool collecting rewards. The rhythm tells you something the raw data alone doesn't.

Peeling chains are another useful pattern. This is when an address receives funds, sends most of them to a new address, keeps a small amount, then that new address does the same thing, over and over, creating a long chain of transactions that looks like you're peeling layers off an onion. This often happens when someone is making a series of payments from the same source of funds, or when they're deliberately trying to obscure their trail by adding hops. Either way, recognizing the pattern helps you follow the flow even when it's intentionally complex.

Then there's the question of mixing and obfuscation. Some users don't want their transactions to be easily traceable, so they use tools designed to break the link between sender and receiver. Mixing services take funds from many users, jumble them together, and send them back out to new addresses in amounts and at times that make it hard to match inputs to outputs. Analyzing mixed transactions requires more sophisticated techniques, looking at probabilistic links, timing correlations, volume matching. It's harder, but not impossible. The graph still exists. The connections are just fuzzier.

Another dimension researchers examine is the economic behavior encoded in the graph. You can calculate things like the velocity of money, how quickly funds move through the network. You can identify hoarders, addresses that accumulate and rarely spend, versus spenders, addresses with high turnover. You can spot whale movements, large amounts shifting in ways that might signal market actions. You can track the lifespan of funds, how long they sit idle before moving again. All of this tells you about the health, activity, and dynamics of the network.

What's crucial to understand is that transaction graph analysis is not primarily about unmasking individuals. It's about understanding behavior at the level of the network. Yes, law enforcement uses these techniques to trace illicit funds, often combining blockchain analysis with off-chain data like exchange records or IP logs to identify actual people. But for most researchers, the goal is different. It's about seeing how the system works, how participants interact, where bottlenecks form, how resilience is distributed, where centralization creeps in despite decentralized design.

For example, if you analyze Bitcoin's transaction graph over time, you can see the rise of exchanges as central hubs, watch how mining pools consolidate, observe the growth of payment processors and custodial wallets. You can measure how much of the network's activity flows through a handful of major entities versus how much remains peer to peer. This kind of analysis reveals the real topology of a supposedly decentralized system. It shows you the difference between the ideal and the reality.

What movement patterns reveal is intent and structure, even when identity is hidden. They show you who the power users are, where the liquidity is, how quickly information and value propagate, where friction exists. They let you map ecosystems, understand adoption curves, detect anomalies. When a stablecoin suddenly sees massive on-chain transfers during a market crash, the graph shows you the panic in motion. When a new protocol launches and funds start flooding in from a tight cluster of addresses, you can infer coordinated action, maybe insiders, maybe a marketing push. The graph doesn't lie, but it does require interpretation.

The beauty of transaction graph analysis is that it turns raw data into narrative. Every address is a character, every transaction a sentence, every pattern a plot. You're reading the story of a network written in its own ledger, and the more you learn to read it, the more you see.

See you Tuesday.

The flow always reveals more than the source.

← Hot vs Cold Storage: The Security Spectrum of Wallet…Replay Attacks: When Transactions Get Copied Across Chains →

AI generated. Not financial advice.