Glossary
What is blockchain analytics?
Blockchain analytics is the examination of public blockchain data — transactions, addresses and their relationships — to trace how funds move, group addresses under common control, and assess the risk associated with on-chain activity.
Every public blockchain is an open dataset: complete, permanent and pseudonymous. Blockchain analytics is the tooling built on that dataset — parsing ledgers into transaction graphs, applying heuristics and machine learning to find structure, and enriching the result with labels for known services and actors.
For compliance teams, the headline output is exposure analysis: whether funds arriving at or leaving a wallet have passed through exchanges, mixers, darknet markets or sanctioned entities, and how many hops away. For investigators, it is tracing: following stolen or illicit value across wallets, services and chains.
What are the core techniques of blockchain analytics?
Three techniques do most of the work:
- Address clustering — grouping addresses likely controlled by one entity, using heuristics such as common transaction inputs and behavioral patterns. Clusters turn millions of addresses into a map of services and actors.
- Fund-flow tracing — following value through the transaction graph across hops, wallets and increasingly across chains via bridges and swap services.
- Risk scoring — quantifying an address's or transaction's proximity to labeled illicit activity: sanctioned entities, stolen funds, ransomware, darknet markets. Scores are probabilistic and depend on the vendor's labels and heuristics.
What is blockchain analytics used for?
Exchanges and financial institutions use analytics to assess deposits and withdrawals for indirect exposure, investigate alerts and meet expectations around tracing. Law enforcement uses it to follow criminal proceeds and support seizures — many headline crypto recoveries rest on analytics-driven tracing. Issuers and regulators use it to understand illicit-finance patterns and to build the cases behind designations.
Its limits matter as much as its power: clustering heuristics can be wrong, labels can be stale, and scores are estimates. Analytics findings are inputs to human judgment, not verdicts — which is one reason compliance programs pair them with deterministic checks.
Blockchain analytics vs direct screening: which do you need?
They answer different questions. Analytics asks: is this address connected to illicit activity through its transaction history? Direct screening asks: does this identifier appear on a published list? The first is probabilistic, powerful for investigation, and requires interpretation. The second is deterministic, fast enough to sit inline in a product flow, and easy to defend in an audit because every match cites an official record.
Many teams need both, and the split is usually architectural: direct screening as the enforced inline control, analytics for investigation, alert triage and indirect-risk policy. CompliAPI provides the direct-screening side only — deliberately.
Where screening fits in a product
The deterministic inline check
Screen wallet addresses for direct appearance on sanctions and crime lists before funds move — a fixed-latency GET request with an auditable answer.
Wallet screening API for crypto compliance →Identifier checks beyond wallets
Screen the emails, websites and government IDs connected to an account alongside its addresses.
OFAC API — screen against the official SDN list →Session risk signals
Add geolocation and VPN detection as further deterministic inputs to your risk rules.
VPN Detection API for OFAC & Sanctions Screening →Scope
This article describes blockchain analytics as a category. CompliAPI is not an analytics platform: it does not trace funds, cluster addresses or produce risk scores. It performs direct lookups against official sanctions lists and labeled risk datasets — the deterministic layer many teams run alongside an analytics platform.
Frequently asked questions
What is address clustering in blockchain analytics?
Heuristics that group addresses likely controlled by the same entity — for example, addresses repeatedly spent together — turning raw ledgers into a map of services and actors. Clustering is powerful but probabilistic: heuristics can over- or under-group.
What does a crypto risk score measure?
An estimate of an address's or transaction's proximity to labeled illicit activity in the vendor's dataset — sanctioned entities, stolen funds, darknet markets — usually weighted by hops and value. Different vendors' scores can disagree because labels and heuristics differ.
Do I need blockchain analytics if I already screen addresses directly?
It depends on your risk obligations. Direct screening covers counterparties the public record already names; analytics covers indirect exposure through transaction history. Many businesses run direct screening inline and reserve analytics for investigations — others need both inline.
Why keep direct screening separate from analytics?
Because the properties differ: a list lookup is deterministic, fast and auditable against an official record, which suits enforcement in a payment path. Analytics is probabilistic and interpretive, which suits investigation. Separating the layers lets each do what it is good at.
Related solutions and data sources
Sanctions screening
Wallet screening API for crypto compliance
Automated crypto wallet and address screening against OFAC and global sanctions lists in one GET request.
Sanctions screening
OFAC API — screen against the official SDN list
Screen crypto wallets, emails, IDs and countries against the official US Treasury OFAC SDN list, refreshed every 15 minutes.
Data sources behind this term: Tornado Cash, Ransomwhere
Related terms: Blockchain intelligence, Money laundering, Sanctions screening
From the blog: Crypto Wallet Screening: What It Is and How It Works →
Add the deterministic screening layer
Get a free API key and screen your first address in minutes.
14-day free trial. No credit card required.