Data Points

₿ Cryptocurrency Address

Blockchain wallet address for receiving or sending crypto assets.
Financial

Sources

19
17 no-auth

Disciplines

2
that use it

Mission domains

5
reach

Workbench

native tool

🔌 Sources that yield Cryptocurrency Address (19)

SourceCategoryAuthFormat
Arkham Intelligence
Entity attribution & flow analysis.
Crypto AttributionNONEhtmlhome↗ api↗
Blockchair API
Multi-chain explorer & analytics API.
Blockchain ExplorerNONEjsonhome↗ api↗
Blockstream Esplora
Bitcoin explorer REST API.
Blockchain ExplorerNONEjsonhome↗ api↗
Breadcrumbs
Free visual crypto tracing.
Crypto InvestigationNONEhtmlhome↗ api↗
Chainabuse
Community scam/abuse address reporting (TRM).
Crypto FraudNONEhtmlhome↗ api↗
Chainabuse reports
Community scam/abuse address reporting (TRM Labs).
Crypto FraudNONEhtmlhome↗ api↗
CryptoScamDB
Known scam/phishing crypto addresses & domains.
Crypto FraudNONEjsonhome↗ api↗
CryptoScamDB addresses
Known scam / phishing crypto addresses.
Crypto FraudNONEjsonhome↗ api↗
GraphSense TagPacks
Open attribution tags for blockchain addresses.
Crypto AttributionNONEtexthome↗ api↗
mempool.space API
Bitcoin transaction/address analytics API.
Blockchain ExplorerNONEjsonhome↗ api↗
MetaSleuth (Blocksec)
Fund-flow tracing & labelling.
Crypto InvestigationNONEhtmlhome↗ api↗
MistTrack
AML risk scoring & tracing (SlowMist).
Crypto InvestigationNONEhtmlhome↗ api↗
OFAC Sanctioned Crypto Addresses (0xB10C)
Machine-readable OFAC-designated wallet lists per chain.
Crypto SanctionsNONEtexthome↗ api↗
OXT / WalletExplorer
Bitcoin wallet clustering & attribution.
Crypto AttributionNONEhtmlhome↗ api↗
Ransomwhere export
Crowd-sourced ransomware payment wallets + family attribution.
Ransom PaymentsNONEjsonhome↗ api↗
Ransomwhere payments
Crowdsourced ransomware payment address tracking.
Ransom PaymentsNONEjsonhome↗ api↗
ScamSniffer scam addresses
Community-reported scam wallet addresses.
Crypto FraudNONEjsonhome↗ api↗
BitcoinAbuse / Chainabuse
Reported abusive BTC addresses (extortion, ransom).
Crypto FraudKEYcsvhome↗ api↗
Etherscan API
Ethereum explorer + address labels.
Blockchain ExplorerKEYjsonhome↗ api↗

🔍 Lookup

📜 Playbook — Cryptocurrency Address exploitation

  1. Direction — frame the requirement for Cryptocurrency Address: what decision does this support, by when?
  2. Collection — pull the 19 mapped sources (17 free) and the native workbench (open); capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎫 Cryptocurrency Address

A cryptocurrency address is a public identifier (derived from a public key or script) that receives and sends funds on a blockchain. It is a pseudonymous financial fingerprint used to trace illicit flows, cluster wallets to a single actor, and screen against sanctions and scam databases.

Format: BTC: legacy 1..., P2SH 3..., bech32 bc1... (base58/bech32); ETH/EVM: 0x + 40 hex (EIP-55 checksum); TRON T...; XMR 95-char; each with its own checksum

📡 How it is collected

  • Blockchain explorer scraping
  • Ransom notes and extortion demands
  • Darknet market and scam pages
  • Exchange deposit/withdrawal records
  • Donation/tip jar disclosures
  • Malware config and wallet drainers

🧩 Analysis & hunting techniques

  • Address checksum/format validation
  • Common-input-ownership clustering
  • Change-address heuristics
  • Sanctions and scam-list screening
  • Exchange attribution / entity tagging
  • Peel-chain and mixer detection
  • Cross-chain bridge tracing
  • Dusting-attack detection

🔧 Tools

  • Blockchair
  • Etherscan
  • Breadcrumbs
  • Arkham
  • GraphSense
  • OXT / Samourai tools
  • Chainalysis (commercial)
  • bitcoinlib (Python)

⚡ Workbench actions

  • Validate address format
  • Screen against OFAC/scam lists
  • Cluster co-spending wallets
  • Trace transaction graph
  • Attribute to exchange/VASP
  • Monitor for new activity
  • Export flow graph

📊 Dashboard KPIs

Total received/sent balanceTransaction countSanctions/abuse hit flagCluster size (linked addresses)Days since last activity
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php