How to Trace a Bitcoin Wallet: UTXOs, Clustering and the Limits
Bitcoin tracing works differently from Ethereum, and the difference decides what you can prove. Here is how UTXOs, change addresses and clustering actually work, and where a Bitcoin trace stops being useful.
Bitcoin Is Not an Account. It Is a Pile of Unspent Outputs.
Why the mental model you use for Ethereum produces a wrong trace on Bitcoin.
What this guide says in 5 lines
- Bitcoin has no accounts and no balances. It has unspent transaction outputs, and tracing means following those outputs.
- Change addresses are the central problem: a single payment can split into a payment output and a change output, and the change is usually the larger one.
- Clustering heuristics — common-input ownership, change detection, address reuse — are inferences, not facts. Label them as such.
- A Bitcoin trace is strongest when it reaches a regulated exchange deposit, and weakest after a CoinJoin or a chain swap.
- Write the trace as a numbered list of outputs with amounts and block heights, not as a diagram.
Bitcoin tracing is not Ethereum tracing with a different explorer. The two chains model value differently, and that difference changes what a trace can prove. On Ethereum you follow an account's balance from address to address. On Bitcoin there are no accounts and no balances at all — there are unspent transaction outputs, and a transaction consumes some and creates others. If you trace Bitcoin as though it were an account chain, you will produce a report that looks plausible and is wrong.
This guide explains the model in plain terms, shows how change addresses create the central difficulty, explains what clustering heuristics can and cannot establish, and is honest about the point at which a Bitcoin trace stops being useful evidence.
The model: UTXOs, not balances
A Bitcoin wallet does not hold a balance. It holds a set of unspent outputs — individual chunks of bitcoin, each with an amount and a script that says who can spend it. When you send, the wallet selects some of those chunks, consumes them entirely, and creates new outputs: one for the recipient, and usually one back to yourself.
This is why a Bitcoin transaction can have several inputs and several outputs, and why “how much is in this address” is a less meaningful question than it is on Ethereum. An address can hold many outputs, and a wallet can control many addresses.
| Bitcoin (UTXO) | Ethereum (account) | |
|---|---|---|
| Unit of value | Unspent outputs, each with an amount | A balance attached to an address |
| A transaction | Consumes inputs, creates outputs | Moves an amount from one account to another |
| Sending part of a balance | Splits into a payment output and a change output | Debits the account and credits another |
| Tracing means | Following outputs forward, output by output | Following transfers forward, address by address |
| Main difficulty | Identifying which output is change | Identifying which address is an internal transfer |
If your trace treats a Bitcoin address as an account with a balance, it is wrong. Rewrite it as a list of outputs with amounts and block heights before you attach it to anything.
Change addresses: the central problem
When a wallet spends an output larger than the payment, the remainder comes back to the sender as a new output, usually at a fresh address. That is the change output, and it is the reason Bitcoin tracing is harder than it looks.
The practical consequence is that a single payment of 0.5 BTC from a 3 BTC output produces two outputs: 0.5 BTC to the recipient and roughly 2.5 BTC back to the sender at a new address. If you follow the larger output, you are following the victim, not the thief. This mistake is common in amateur traces and it is fatal to the report's credibility.
- 01Open the transaction and list every output with its amount.
- 02Identify the output that matches the amount you expected to be stolen. That is the payment output.
- 03Treat the remaining output as probable change, and label it as probable rather than certain.
- 04Follow the payment output forward, and note that the change output may be spent later in a way that reconnects the two.
- 05Record the block height and timestamp for each step, because chronology is what makes the trace verifiable.
Label every inference as an inference. “Probable change output” is honest and defensible; “the thief's address” is a conclusion you cannot support and an investigator will discount.
Clustering: what it can and cannot establish
Clustering is the set of heuristics analysts use to group addresses that probably belong to the same wallet. It is genuinely useful, and it is also genuinely uncertain. Understanding the difference is what separates a report from a guess.
| Heuristic | What it infers | Reliability |
|---|---|---|
| Common-input ownership | Inputs spent together in one transaction belong to one wallet | Strong, and the basis of most clustering. Still an inference. |
| Change-address detection | The output that is not the payment is change | Moderate. Reliable in simple transactions, unreliable in complex ones. |
| Address reuse | The same address used twice belongs to one wallet | Strong when it occurs, but good wallets avoid reuse entirely. |
| Deposit-address patterns | An address that receives many small payments is an exchange deposit | Moderate. Useful for identifying where a freeze is possible. |
| Timing correlation | Outputs created in the same block belong to one actor | Weak. Coincidence is common and this should rarely be relied on. |
Clustering produces probabilities, not identities. A cluster is a set of addresses that probably share an owner. It is not a person, and presenting it as one is the fastest way to have a report dismissed.
Running the trace, step by step
You need a block explorer and a text file. The work is methodical rather than technical, and an hour produces something an investigator can verify independently.
- 01Search the receiving address and list every transaction it appears in, with block heights.
- 02For the transaction matching your loss, list all inputs and outputs with amounts.
- 03Identify the payment output and the probable change output, and label them accordingly.
- 04Follow the payment output to the next transaction, and repeat. Note how long funds sat at each step.
- 05Flag any output that looks like a deposit into a centralised exchange — that is where a freeze becomes possible.
- 06Note any CoinJoin, chain swap or consolidation that breaks the trail, and say so explicitly rather than skipping it.
- 07Write the result as a numbered list: step, block height, date, amount, address, and whether the link is certain or inferred.
A trace that says “the trail becomes ambiguous after step 6” is more useful than one that pretends to be certain. Investigators trust the first and discount the second.
Where a Bitcoin trace stops being useful
There are three points at which a Bitcoin trace loses most of its value, and knowing them tells you how much time to invest.
The first is a CoinJoin, where multiple parties combine inputs so that no output can be attributed to any input. The second is a chain swap through a bridge or an atomic swap, which moves value to a different ledger with a different model. The third is a consolidation into a large exchange hot wallet, where your output becomes one of thousands and individual attribution ends.
None of these makes the trace worthless. A trace that documents the path up to the break, and names the break honestly, still establishes that funds left your control and where they went while they were traceable. That is what a report needs.
The most valuable output of a Bitcoin trace is usually the exchange deposit it reaches, not the full path. That deposit is the only point where a lawful freeze is technically possible.
Turning the trace into evidence
A trace becomes evidence when it is written down, dated and attached to a report. Screenshots alone are weak, because they cannot be verified and they do not show the reasoning.
Produce a document with: the transaction hashes, the block heights, the amounts, the addresses, and a clear statement of which links are certain and which are inferred. Attach it to your IC3 complaint, your police statement and any exchange freeze request. That document is what an analyst can check, and checkability is the whole standard.
Include the block height for every step. It is the one field that lets anyone verify your trace without trusting you, and it costs nothing to add.
Common questions
Trace the address in your browser
Paste the receiving address into the tracer: it reads the public ledger, builds the hop record and exports a dated evidence file you can attach to a report.
Primary sources and further reading
- Chainalysis — Crypto Crime Report www.chainalysis.com
- FBI IC3 — Internet Crime Report www.ic3.gov
- FTC — What To Know About Cryptocurrency and Scams consumer.ftc.gov
- CISA — Cryptocurrency Scams www.cisa.gov
External links open in a new tab and are provided so you can verify the underlying material yourself. TrueMoneyTalk is not affiliated with these organisations.
Keep reading
Someone you know may be in this situation right now.
Disclaimer: this guide is general information, not legal, financial or recovery advice, and it is not a substitute for advice from a licensed professional in your jurisdiction. Individual outcomes vary and are never guaranteed.