Trace cryptocurrency addresses and transactions on public blockchains using block explorers including Etherscan, Blockchair, mempool.space and Blockscout. Covers common-input clustering, ENS resolution, exchange deposit addresses, mixers, CoinJoin, Tornado-style pools, cross-chain bridges, and OFAC sanctions screening. Use when following a Bitcoin or Ethereum wallet, investigating where a ransom or scam payment went, or checking an address against sanctions listings. Applies to ransomware incide
Follow the Crypto is an OSINT investigation skill for tracing cryptocurrency addresses and transactions across public blockchains using block explorers such as Etherscan, Blockchair, mempool.space, and Blockscout. Its premise is that public chains are pseudonymous rather than anonymous: every transfer is permanently visible, and the investigative task is attribution, which usually resolves at an off-ramp where value converts to fiat through an identity-collecting service. It emphasizes tracing confidently but attributing carefully, warning against treating clustering-heuristic output or proprietary vendor labels as fact.
The skill provides a triage table for what to do given an address, transaction hash, ENS name, screenshot, or a ransom/scam payment demand, and a method for establishing the chain and address type, reading an explorer properly (first/last-seen, received versus balance, counterparties, contract bytecode), choosing the correct mental model for UTXO versus account-model chains, and applying clustering heuristics like common-input ownership and change-address identification with an honest account of their reliability. Reference files catalogue explorers and tooling by chain and job (block explorers, multi-chain explorers, clustering and flow analysis, query/analytics platforms, attribution/labelling, abuse and sanctions reporting, node access) and detail address formats. It covers ENS resolution, exchange deposit addresses, mixers, CoinJoin, Tornado-style pools, cross-chain bridges, and OFAC sanctions screening.
It targets fraud investigators, incident responders, AML and sanctions compliance analysts, and asset-recovery and financial-crime professionals. The work is read-only analysis of public blockchain data and public reporting sources, with a strong emphasis on evidentiary rigor, citing which tool produced which label and on what date, and checking current sanctions lists rather than memory.
Bitcoin and other UTXO chains, Ethereum and EVM chains, plus Solana, Tron, XRP Ledger, Cosmos, Substrate/Polkadot, and others, using explorers such as mempool.space, Blockstream, Blockchair, Etherscan, Blockscout, and Otterscan.
No. It reads public blockchain data and public reporting/sanctions sources through block explorers and analytics platforms; it is investigative and read-only.
The skill treats common-input ownership as a strong heuristic but stresses that clustering output is probabilistic and that commercial attribution labels are unauditable proprietary guesses that should always be cited to their source and date.
Yes. It covers OFAC Sanctions List Search and other regimes (UK, EU, UN), advising you check the current list rather than relying on memory since designations change.
Ransomware incident response, AML and sanctions compliance, fraud recovery and asset tracing, and financial-crime investigation.
Quick Setup:
.claude/skills/Repository
useosint/osint-skills