L-02 · Layering

Crypto and virtual-assets layering

Covers VASP obligations, mixers and chain-hopping, cross-chain bridges and stablecoin rails, the travel rule's uneven global rollout, MiCA, CARF/DAC8, and the evidential strengths and limits of on-chain tracing.

Module lecturer: Dr. Collen Lediga, Ruhr-Universität Bochum

Module progress
0 / 3 lessons96 min remaining

Visual overview

Interactive figure

Offshore chain · from originator to correspondent bank

Every hop is a design choice

Click any node · hover for tooltip

OriginatorPEPTrustDiscretionaryShell Co.BVI / DelawareNomineeDirectorCorresp. bankUSD clearing

Lessons

LESSON 0134 min read

VASPs, mixers and chain-hopping

Figure 3.1 · Geography

One kickback, five jurisdictions

Each hop is a deliberate secrecy choice — a doctrine, a treaty, a professional silence. The final step is always a legitimate-looking asset.

HOP 1HOP 2HOP 3HOP 4LusakaSOURCENicosiaLAYER 1 · TRUSTLuxembourgLAYER 2 · HOLDCOJerseyLAYER 3 · SPVLondonINTEGRATION

Source · Schematic based on ICIJ Panama/Pandora Papers narratives

Virtual asset service providers — VASPs, in the FATF's now-standard terminology, are the crypto ecosystem's functional equivalent of banks, remitters and exchange bureaux, and since the FATF's 2019 revision of its Recommendations they are subject to the same core AML obligations: customer due diligence, suspicious transaction reporting, and; the subject of this module's centrepiece rule, the travel rule requiring originator and beneficiary information to accompany transfers above a threshold. Centralised exchanges (Binance, Coinbase, and their many regional and jurisdiction-specific counterparts), custodial wallet providers, and increasingly certain decentralised-finance front-ends that FATF guidance treats as VASPs by function rather than form, all fall within scope in principle. The gap between principle and practice is where this module lives.

Chain-hoppingChain-hoppingConverting value across multiple blockchains, often via privacy coins or bridges, to break traceability. is the crypto-native analogue of nested correspondent layering. A launderer converts value from one blockchain to another — Bitcoin to Ethereum, Ethereum to a privacy-focused chain such as Monero, then back to a widely-traded asset — using either centralised exchanges or, increasingly, cross-chain bridgeCross-chain bridgeA protocol locking an asset on one blockchain and minting a wrapped equivalent on another, creating a formal ledger discontinuity. protocols that lock an asset on the originating chain and mint a wrapped equivalent on the destination chain. Each hop is designed to break the continuity that on-chain tracing tools rely on. A chain-hop through Monero is particularly effective because Monero's default protocol obscures sender, receiver and amount using ring signatures and stealth addresses, meaning that even sophisticated blockchain-analytics firms can rarely trace value once it has passed through Monero, in contrast to Bitcoin and Ethereum, whose ledgers are fully public and, with the right tooling, traceable with high confidence.

Mixing services and CoinJoinCoinJoinA non-custodial technique combining multiple users' transactions into one, obscuring which input funded which output. protocols pursue the same objective on transparent-ledger chains. A traditional custodial mixer pools deposits from many users and pays out an equivalent value from its own commingled reserve after a delay, deliberately breaking the direct input-output link that a blockchain explorer would otherwise show. CoinJoinCoinJoinA non-custodial technique combining multiple users' transactions into one, obscuring which input funded which output., by contrast, is a non-custodial, cryptographically coordinated technique in which multiple users jointly construct a single transaction with multiple inputs and multiple outputs, such that an external observer cannot reliably determine which input funded which output, the technique underlying wallets such as Wasabi and Samourai, both of which have faced US and European law-enforcement action (Samourai's founders were indicted by the US DOJ in 2024 on money-laundering and unlicensed money-transmission charges, and the service was shut down that year), reflecting a regulatory position that non-custodial mixing tools designed and marketed specifically to defeat AML tracing can themselves attract criminal liability for their operators even absent custody of client funds.

Sanctioned mixing infrastructure has also become a direct target of financial-sector sanctions rather than only criminal prosecution: OFAC's 2022 designation of the Tornado Cash smart-contract addresses (an Ethereum-based non-custodial mixer) marked the first time a piece of autonomous software code, rather than a person or entity, was placed on the Specially Designated Nationals list, a move that generated significant litigation over the limits of sanctioning code as opposed to persons, and which a US appellate court in 2024 substantially narrowed by holding that the immutable smart contracts themselves could not be treated as sanctionable "property" in the way the individuals operating associated infrastructure could; a nuance every investigator citing this case should get right, because the appellate outcome complicates rather than confirms the original designation's legal theory.

StablecoinStablecoinA crypto-asset pegged to a reference currency (typically USD), issued by a centralised entity capable of freezing specific addresses. rails deserve separate attention because they have become the dominant on-ramp and off-ramp currency pair in illicit crypto flows, according to successive Chainalysis annual crime reports. A stablecoinStablecoinA crypto-asset pegged to a reference currency (typically USD), issued by a centralised entity capable of freezing specific addresses. such as USDT (Tether) or USDC, pegged to the US dollar and issued by a centralised entity, offers a launderer price stability that volatile assets like Bitcoin do not, while still moving on a public, pseudonymous blockchain ledger. The centralisation of issuance is simultaneously the vulnerability that traditional criminal assets lack: issuers such as Tether and Circle have, under law-enforcement request, frozen specific addresses' balances at the smart-contract level, an intervention with no clean equivalent in cash-based laundering and one that has become a standard element of asset-freezing strategy in crypto investigations, provided the requesting agency can identify the relevant address before funds are moved onward.

Cross-chain bridges compound the tracing difficulty because the "wrapped" asset minted on the destination chain is, technically, a different token from the original, linked only by the bridge protocol's own internal accounting, accounting that is not always transparent, and that in several major bridge-hack incidents (Ronin in 2022, Wormhole in 2022, among others) has itself been the target of theft rather than merely a laundering conduit. For an investigator, a bridge transaction should be treated analytically the same way a currency-exchange bureau transaction is treated in cash laundering: the value crossing the bridge is continuous in economic substance, but the blockchain record on each side is formally discontinuous, and linking the two sides requires either the bridge operator's own internal ledger (frequently obtainable only by subpoena, and only where the operator is identifiable and cooperative) or inferential analysis of transaction timing and amount correlation across the two chains.

The practical posture I recommend to officials new to this space is to resist two opposite temptations: the temptation to treat blockchain analysis as omniscient (it is not — privacy coins, well-executed CoinJoinCoinJoinA non-custodial technique combining multiple users' transactions into one, obscuring which input funded which output., and cooperative cross-chain laundering can defeat it), and the temptation to dismiss it as useless because some techniques defeat it (most real-world laundering, done by people without specialist technical support, still leaves a traceable trail on transparent-ledger chains, and the majority of illicit crypto value identified in recent Chainalysis reporting still moves through centralised exchanges that are, at least in principle, licensed VASPs subject to KYC obligations). The realistic operating assumption is that on-chain tracing is a powerful but incomplete tool whose effectiveness depends heavily on which specific chains, protocols and off-ramps a given scheme used — precisely the granular technical judgment the next two lessons are designed to build.

ComparisonVERITAS · Dr. Lediga
Custodial mixer01
Pools deposits into a common reserve
02
Pays out from commingled funds after delay
03
Operator holds and controls client funds
04
Clear custody = clear regulatory target
CoinJoin (non-custodial)01
Users jointly construct one multi-input/output transaction
02
No custody transfer to operator
03
Obscures input-output linkage cryptographically
04
Operators still face liability for facilitation (Samourai, 2024)

Custodial mixing vs CoinJoin

Key terms

VASP (Virtual Asset Service Provider)
The FATF's functional category covering exchanges, custodial wallet providers and certain DeFi front-ends performing exchange, transfer or custody services.
Chain-hopping
Converting value across multiple blockchains, often via privacy coins or bridges, to break traceability.
CoinJoin
A non-custodial technique combining multiple users' transactions into one, obscuring which input funded which output.
Stablecoin
A crypto-asset pegged to a reference currency (typically USD), issued by a centralised entity capable of freezing specific addresses.
Cross-chain bridge
A protocol locking an asset on one blockchain and minting a wrapped equivalent on another, creating a formal ledger discontinuity.

Exercise

Using a public blockchain explorer, trace a sample transaction through at least one exchange deposit address and identify at what point (if any) the trail becomes uneconomical to follow manually. Note which chain and which service caused the break.

Mark complete (sign-in) →

Sources

Last reviewed 2026-08-01

  1. 01FATF Recommendation 15 and Interpretive Note (rev. 2019)FATF, 2019.Establishes VASP functional definition and core AML obligations.
  2. 02United States v. Samourai Wallet foundersUS DOJ, 2024.Indictment on money laundering and unlicensed money transmission for non-custodial CoinJoin service.
  3. 03Tornado Cash SDN designation and subsequent appellate rulingOFAC / US Court of Appeals for the Fifth Circuit, 2024.Narrowed sanctionability of immutable smart contracts as 'property'.
  4. 04Crypto Crime ReportChainalysis, 2024.Annual data on stablecoin dominance in illicit on/off-ramp flows.
Full bibliography →
LESSON 0232 min read

The travel rule, MiCA and the tax transparency instruments

Figure 2.1 · Cycle

Fourteen days from cash to legitimacy

A stylised laundering cycle. Elapsed time between deposit and re-entry rarely exceeds three weeks in mature networks.

DAY 0DAY 7DAY 1401 · DAY 0Cash deposit (structured)02 · DAY 3Wire to shell #1 · BVI03 · DAY 5On-lend to trust · Jersey04 · DAY 9Mortgage-backed asset · London05 · DAY 14Dividend loop back to UBO

Source · Composite of published FIU narratives

FATF Recommendation 15's travel ruleTravel ruleFATF R.15 obligation requiring VASPs to collect, hold and transmit originator/beneficiary data for virtual-asset transfers above a threshold., first extended explicitly to virtual assets in the 2019 revision, requires VASPs to obtain, hold and transmit originator and beneficiary information for virtual-asset transfers above a threshold (typically USD/EUR 1,000, though jurisdictions vary), mirroring the wire-transfer transparency obligation you studied in the previous module. The rule sounds simple. Implementation has been anything but, and understanding why is essential to calibrating what evidence a travel-rule record can actually deliver in a live investigation.

The core implementation problem is that the travel ruleTravel ruleFATF R.15 obligation requiring VASPs to collect, hold and transmit originator/beneficiary data for virtual-asset transfers above a threshold. presupposes a closed system of identifiable, cooperating VASPs analogous to the correspondent banking network, but the crypto ecosystem includes an enormous population of self-hosted (non-custodial) wallets that are not VASPs at all and therefore fall outside any institution's obligation to collect counterparty data. A transfer from a licensed exchange to a self-hosted wallet triggers, at most, an obligation on the sending VASP to collect what information it can about the wallet's controller, but there is no institutional counterparty on the receiving end to transmit data to, and no mechanism compelling the wallet holder to identify themselves. FATF's guidance addresses this "sunrise issueSunrise issueThe uneven timing and quality of travel-rule implementation across jurisdictions, complicating counterparty data exchange." (so named because travel-rule obligations came into force in different jurisdictions on different dates, creating an uneven "sunrise" of compliant counterparties) by requiring enhanced due diligence on transfers to unhosted wallets rather than requiring a data field that, by construction, cannot be populated. In practice, implementation quality varies enormously by jurisdiction: FATF's own periodic assessments have repeatedly found that a majority of surveyed jurisdictions have only partially implemented the travel ruleTravel ruleFATF R.15 obligation requiring VASPs to collect, hold and transmit originator/beneficiary data for virtual-asset transfers above a threshold., or have implemented it only for the largest licensed VASPs while leaving smaller or newly-licensed providers effectively unsupervised on this specific obligation.

The technical messaging problem compounds the legal one. Unlike SWIFT, which provides a single, near-universal messaging rail for wire transfers, no equivalent universal rail exists for travel-rule data among VASPs; instead, a competing set of proprietary and semi-open protocols (including consortia such as TRUST and Travel RuleTravel ruleFATF R.15 obligation requiring VASPs to collect, hold and transmit originator/beneficiary data for virtual-asset transfers above a threshold. Protocol implementations by various vendors) have emerged, and interoperability between VASPs using different protocols remains incomplete, meaning that even fully compliant, well-resourced exchanges sometimes cannot transmit required data to a counterparty using an incompatible system, and fall back to manual, email-based compliance workarounds that are slow and audit-trail-poor by comparison with the underlying blockchain record itself.

The European Union has taken the most comprehensive regional regulatory approach with Regulation (EU) 2023/1114, the Markets in Crypto-Assets Regulation (MiCA), which entered into force progressively through 2024, with the bulk of its provisions, including licensing requirements for crypto-asset service providers (CASPs), applicable from December 2024. MiCA establishes an EU-wide authorisation regime for CASPs, prudential and governance requirements, and disclosure obligations for asset-referenced and e-money tokens (the EU's regulatory categories capturing most stablecoins), operating alongside; not instead of, the AML obligations imposed by the recast Transfer of Funds Regulation covered in the previous module. Read together, MiCA and the TFR give the EU one of the most complete crypto-specific regulatory architectures globally, though implementation and supervisory capacity across the twenty-seven member states' national competent authorities remains uneven in the early years of application, a pattern regulators in developing jurisdictions should watch closely as an indicator of realistic implementation timelines for their own future crypto frameworks.

Tax transparency instruments run on a parallel but distinct track from AML travel-rule obligations, and officials frequently conflate the two. The OECD's Crypto-Asset Reporting Framework (CARF), finalised in 2022 and formally endorsed for implementation with first exchanges scheduled from 2027, requires reporting crypto-asset service providers to collect and report information on their customers' crypto-asset transactions to tax authorities, who will then exchange that information automatically with the customer's jurisdiction of tax residence, closely mirroring the pre-existing Common Reporting Standard's architecture for traditional financial accounts. The EU's own implementing instrument, DAC8 (the eighth amendment to the Directive on Administrative Cooperation), transposes CARF-equivalent obligations into EU law and extends the EU's automatic-exchange architecture to crypto-asset transactions, again with implementation building toward operative exchange from 2026-2027 depending on the specific obligation. It is critical for officials to understand that CARF/DAC8 serve tax administration's information needs — identifying unreported crypto gains and income — and are not themselves AML instruments; a crypto transaction can be fully CARF-reportable and tax-compliant while still being a step in a money-laundering scheme, and conversely a transaction can trigger AML suspicion without any CARF reporting obligation attaching if the counterparty is a non-reporting entity.

For a developing-country tax administration or FIU, the sequencing reality is sobering: the AML travel ruleTravel ruleFATF R.15 obligation requiring VASPs to collect, hold and transmit originator/beneficiary data for virtual-asset transfers above a threshold. is nominally already in force in most FATF-member and FATF-style regional body member jurisdictions (though unevenly implemented, as noted above), while CARF/DAC8 tax information exchange will not begin generating usable cross-border data until 2026-2027 at the earliest, and only among jurisdictions that have committed to and operationalised the framework, a list that, as of 2026, remains concentrated among OECD and EU members plus a smaller number of committed non-member jurisdictions. African tax administrations without an existing CARF commitment will therefore need to rely, in the medium term, on a combination of unilateral information requests, MLA channels, and their own domestic VASP licensing and reporting regimes (where these exist at all) rather than on automatic exchange, and building at least a basic domestic VASP licensing and travel-rule supervisory capacity now is the single highest-leverage step such an administration can take ahead of eventual CARF participation.

Analytical matrixVERITAS · Dr. Lediga
AML PURPOSE · TAX-TRANSPARENCY PURPOSEIN FORCE NOW · BUILDING TOWARD 2026-27QUADRANT ATravel rule (FATF R.15)
Nominally in force, unevenly implemented across jurisdictions.
QUADRANT BMiCA / TFR
CASP licensing and AML data requirements applicable from Dec 2024.
QUADRANT CCARF
Finalised 2022, first exchanges scheduled from 2027.
QUADRANT DDAC8
EU implementing directive, phasing in operative exchange 2026-2027.

AML vs tax-transparency crypto instruments

Key terms

Travel rule
FATF R.15 obligation requiring VASPs to collect, hold and transmit originator/beneficiary data for virtual-asset transfers above a threshold.
Sunrise issue
The uneven timing and quality of travel-rule implementation across jurisdictions, complicating counterparty data exchange.
MiCA (Regulation (EU) 2023/1114)
The EU's comprehensive crypto-asset market regulation, with CASP licensing provisions applicable from December 2024.
CARF / DAC8
The OECD Crypto-Asset Reporting Framework and its EU implementing directive, extending automatic tax-information exchange to crypto-asset transactions from 2026-2027.

Exercise

Draft a short briefing distinguishing, for a non-specialist minister, why a fully CARF-reportable crypto transaction can still be part of a money-laundering scheme, using a concrete illustrative transaction chain.

Mark complete (sign-in) →

Sources

Last reviewed 2026-08-01

  1. 01FATF Recommendation 15 and Interpretive NoteFATF, 2019.
  2. 02Targeted Update on Implementation of the FATF Standards on Virtual AssetsFATF, 2024.Documents uneven global travel-rule implementation.
  3. 03Regulation (EU) 2023/1114 (MiCA)European Union, 2023.
  4. 04Crypto-Asset Reporting Framework (CARF)OECD, 2022.First automatic exchanges scheduled from 2027.
  5. 05Council Directive (EU) 2023/2226 (DAC8)European Union, 2023.EU implementing directive extending automatic exchange to crypto-assets.
Full bibliography →
LESSON 0330 min read

On-chain tracing: clustering, peel chains and evidential limits

Figure 3.1 · Geography

One kickback, five jurisdictions

Each hop is a deliberate secrecy choice — a doctrine, a treaty, a professional silence. The final step is always a legitimate-looking asset.

HOP 1HOP 2HOP 3HOP 4LusakaSOURCENicosiaLAYER 1 · TRUSTLuxembourgLAYER 2 · HOLDCOJerseyLAYER 3 · SPVLondonINTEGRATION

Source · Schematic based on ICIJ Panama/Pandora Papers narratives

The final lesson turns to the analytical methods that transform a raw, pseudonymous blockchain ledger into usable investigative intelligence, and to the honest limits of that transformation; limits that matter enormously when this evidence must survive cross-examination in a criminal trial or withstand challenge in an asset-forfeiture proceeding.

Address clustering is the foundational technique. A single individual or entity typically controls many blockchain addresses, not one, and clustering heuristics group addresses believed to share common control based on transaction patterns rather than any explicit on-chain declaration of ownership. The best-known heuristic, common-input-ownership, rests on the observation that when a Bitcoin transaction spends from multiple input addresses simultaneously, those addresses were, at the time of signing, all controlled by whoever authorised the spend (because signing requires the private key for each input), and this heuristic, first published in academic literature over a decade ago, remains the single most reliable non-custodial clustering signal available today. A second heuristic, change-address identification, attempts to distinguish the "payment" output of a transaction from the "change" output returned to the sender, using statistical regularities in output structure, address-reuse patterns, and rounding behaviour; this heuristic is considerably less reliable than common-input-ownership and produces a meaningful false-positive rate, a point every analyst presenting clustering evidence should disclose rather than gloss over.

Peel-chain analysis addresses a specific laundering pattern in which a large initial sum is repeatedly "peeled" — a small amount is spent to a destination address while the bulk of the remaining value is returned to a new change address controlled by the same actor, producing a long, visually distinctive chain of transactions that, followed correctly, reveals both the incremental off-ramping destinations and the actor's evolving address cluster. Peel chains are common in ransomware payment laundering and in structured layering schemes deliberately designed to mimic the appearance of ordinary wallet housekeeping; distinguishing a genuine peel chainPeel chainA repeated pattern of spending a small amount while returning the bulk of value to a new self-controlled change address, common in laundering and ransomware payment flows. from an innocent pattern of routine spending requires corroborating context, not blockchain data alone.

Commercial blockchain-analytics platforms (Chainalysis, TRM Labs, Elliptic, among others) build proprietary attribution databases linking clusters to real-world entities — named exchanges, sanctioned addresses, darknet markets, ransomware wallets, derived from a combination of the heuristics above, known deposit/withdrawal address harvesting from cooperating exchanges, undercover transactions, and open-source intelligence. This attribution layer is where the most significant evidential caution applies: the underlying heuristic-based clustering is a probabilistic inference, not a cryptographic proof, and the attribution linking a cluster to a named real-world entity depends entirely on the proprietary database's own accuracy and currency, which is neither independently auditable by a court in most cases nor infallible; several documented instances exist of attribution databases mislabelling addresses, particularly following exchange-side wallet restructuring events that break previously valid clustering assumptions. I tell officials preparing to rely on commercial attribution evidence in a prosecution to always seek, alongside the vendor's conclusion, the underlying heuristic chain and, wherever possible, independent corroboration, an exchange's own KYC records for the attributed account, a cooperating witness, or a parallel financial-record trail — rather than presenting the attribution as a stand-alone, self-proving fact.

The evidential limits become sharpest at three points already flagged in Lesson 1: privacy coins such as Monero, whose default protocol defeats common-input-ownership clustering entirely by design; well-executed CoinJoin transactions, which deliberately corrupt the clustering heuristic's core assumption by combining multiple independent actors' inputs into a single transaction, and cross-chain bridges, where the wrapped-asset discontinuity breaks clustering continuity across the bridge boundary unless the bridge operator's own internal ledger is separately obtained. A competent defence expert in any jurisdiction with developed digital-evidence practice will probe precisely these three limits, and an investigator or prosecutor who cannot answer confidently on all three should not present clustering-based attribution as conclusive proof of identity.

Despite these genuine limits, on-chain tracing remains, on the whole, dramatically more powerful than traditional financial-forensics tools for the simple reason that the underlying ledger — for Bitcoin, Ethereum and the great majority of actively-traded tokens, is permanently public, immutable, and available in full without any subpoena at all; the investigative bottleneck has shifted from obtaining the data (as it remains in cash and traditional banking investigations) to correctly interpreting an enormous, permanently available dataset. For African FIUs and tax administrations building capacity in this area, the highest-value initial investment is therefore not in expensive proprietary attribution licences alone but in training analysts to run the underlying open-source heuristics themselves, understand their assumptions and failure modes, and use commercial attribution tools as one corroborating input among several rather than as a black-box oracle. That combination of technical literacy and evidential discipline; knowing exactly what a blockchain trace can and cannot prove, is what will determine whether crypto-layering evidence survives appellate scrutiny in the jurisdictions now beginning to prosecute these cases in earnest.

Four-part typologyVERITAS · Dr. Lediga
1CATEGORY 01Common-input-ownership
High reliability; cryptographically grounded inference.
2CATEGORY 02Change-address heuristic
Moderate reliability; meaningful false-positive rate.
3CATEGORY 03Peel-chain pattern recognition
Suggestive; needs corroborating context.
4CATEGORY 04Vendor attribution database
Probabilistic and proprietary; corroborate before reliance.

Reliability of core on-chain tracing techniques

Key terms

Common-input-ownership heuristic
The inference that all addresses spending inputs within a single transaction share common control, since each requires the same signer's private key.
Change-address heuristic
A less reliable technique distinguishing a transaction's payment output from its change output returned to the sender.
Peel chain
A repeated pattern of spending a small amount while returning the bulk of value to a new self-controlled change address, common in laundering and ransomware payment flows.
Attribution database
A commercial analytics vendor's proprietary mapping of address clusters to named real-world entities, probabilistic and not independently auditable in most cases.

Exercise

Prepare a two-page evidentiary memorandum for a hypothetical prosecution relying on commercial blockchain-analytics attribution, listing the specific corroborating evidence you would seek before presenting the attribution as proof of the defendant's control of the traced funds.

Mark complete (sign-in) →

Sources

Last reviewed 2026-08-01

  1. 01An Analysis of Anonymity in the Bitcoin SystemMeiklejohn et al. (academic), 2013.Foundational publication establishing common-input-ownership clustering heuristic.
  2. 02Crypto Crime ReportChainalysis, 2024.Illustrative peel-chain and ransomware laundering typologies.
  3. 03Targeted Update on Implementation of the FATF Standards on Virtual AssetsFATF, 2024.
Full bibliography →

Case study

Chain-hopping a ransomware payment through a bridge and a privacy coin

Jurisdiction: Cross-border (originating African victim, downstream exchange in a non-cooperating jurisdiction)

A ransomware payment made in Bitcoin by a Kenyan logistics firm was traced through a peel chain, across a cross-chain bridge, into Monero, before resurfacing at a centralised exchange as a stablecoin cash-out, testing the practical limits of on-chain tracing across every technique covered in this module.

Facts

  • The victim paid a ransom in Bitcoin to an address provided by the attacker following a ransomware incident.
  • Blockchain analysts identified a peel-chain pattern moving the bulk of funds through eleven intermediate addresses over six days.
  • At the final hop before disappearing from Bitcoin's ledger, the funds passed through a cross-chain bridge and were converted to a wrapped-asset equivalent, then swapped into Monero via a decentralised exchange aggregator.
  • The trail went cold for approximately three weeks while the funds were presumed to be held or moved within Monero's obscured ledger.
  • A comparable value of USDT stablecoin later appeared, deposited to a centralised exchange account in a jurisdiction with limited FATF-standard implementation, opened using apparently fabricated KYC documents.
  • The exchange, once alerted via a law-enforcement request, froze the remaining balance before full withdrawal, but roughly 40% of the traced value had already been withdrawn to a bank account.

Investigative questions

  1. At what specific point did the on-chain trail become unprovable using open-source heuristics alone?
  2. What corroborating evidence, beyond blockchain analysis, would be needed to connect the Monero-side reappearance to the original Bitcoin ransom with evidentiary confidence?
  3. What travel-rule obligations, if properly implemented by the receiving exchange, might have prevented onboarding using fabricated KYC documents?
  4. What asset-freezing mechanisms were available once the funds reached a stablecoin-issuing and centralised-exchange environment that were unavailable while the funds were in Bitcoin or Monero?
  5. How should a prosecutor frame the evidentiary gap during the Monero period in court, without overstating the certainty of the trace?

Learning points

  • A sophisticated layering scheme can combine every technique in this module — peel chains, bridges, privacy coins and stablecoin off-ramping — in a single operation.
  • Evidentiary gaps during a privacy-coin period should be disclosed and addressed with corroborating non-blockchain evidence, not minimised.
  • Issuer-level and exchange-level freezing remain the most effective practical recovery tools, but only once funds re-enter a centralised, identifiable chokepoint.
  • Weak travel-rule and KYC implementation at a single downstream exchange can undermine an otherwise well-executed multi-agency tracing effort.

Where the field disagrees

Is blockchain analytics evidence or inference?

Clustering heuristics are proprietary, rarely peer-reviewed, and have been challenged in court in the United States and Germany. Vendors present attribution with a confidence that the underlying method does not always support. Investigators love the output because it is legible to a judge. Treat every attribution as a hypothesis with a stated error mode, and read the module knowing that this is where defence counsel will attack first.

Lecturer's note · not examinable, but argue it in your essay

Assessment

Module quiz

8 multiple-choice questions. Pass at 70%. Scores are saved to your dashboard.

Begin quiz →

Written work

Essay prompts

  • Q1Evaluate whether the travel rule can ever achieve correspondent-banking-equivalent transparency given the structural presence of self-hosted wallets, and propose realistic policy alternatives.
  • Q2Assess the evidentiary risks of relying on commercial blockchain-analytics attribution in a criminal prosecution, drawing on the Tornado Cash appellate narrowing as an example of legal uncertainty in this space.
  • Q3Argue for a capacity-building sequence a mid-sized African FIU should follow to build credible on-chain tracing capability ahead of eventual CARF participation, given constrained budgets.
Submit essay →

Assignment

"Produce a technical briefing note, suitable for a Director-General, explaining (1) what a travel-rule record can and cannot prove, (2) what an on-chain clustering trace can and cannot prove, and (3) what combination of the two, plus traditional MLA channels, would be required to build a prosecutable case against a hypothetical chain-hopping scheme moving value from a licensed domestic exchange through a bridge and a privacy coin to an offshore off-ramp."