NODE · LON-01|LONDON --:--:--
DAC | Digital Asset Claims

Knowledge centre · 7 min read

How a digital asset transaction trace is built

From a single starting point to a documented path: the working sequence behind a transaction reconstruction, and where it stops.

A transaction path extending hop by hop across a network graph

Where a trace starts

Every trace begins with a fixed starting point: an address, a transaction hash, or a contract interaction. The starting point is written into the scope before analysis begins, because a trace without a declared origin can be quietly reshaped later to fit whatever it found, and a reader has no way to detect that.

The direction is declared too. Forward tracing follows value away from the starting point; backward tracing establishes what reached it and from where. They answer different questions and produce different files. A matter about where assets went is not the same as a matter about where a holding came from, and running one while describing the other is the most common way a trace becomes misleading.

Reading primary data, not summaries

Analysis reads chain data directly through a controlled collection pipeline rather than relying on the rendering of a third-party interface. Interfaces make display decisions: they collapse internal transactions, round values, hide failed calls and label addresses using their own datasets. Any of those decisions can change what a trace appears to show.

Working from primary data also makes the work repeatable. The pipeline records which sources were queried, at what height, and when. Another analyst can rerun the same collection and reach the same starting material, which is the difference between a documented reconstruction and a persuasive story.

Following hops without losing the thread

Value rarely moves once. It moves through a sequence of transfers, and each transfer is a hop. Following hops naively produces an unreadable explosion of branches, because each address may send to many others. The work of tracing is not collecting hops; it is deciding which branches carry the flow that matters and recording why the others were set aside.

That decision is made on observable grounds: value continuity, timing proximity, fee funding, and patterns such as peel chains where a large balance sheds small amounts at each step. Every branch that is followed and every branch that is dropped goes into the file, so the shape of the trace can be reviewed rather than taken on trust.

Confidence generally falls as hops accumulate. A single transfer between two addresses is a fact. A conclusion drawn eleven hops later, through several services, is an interpretation, and it is presented as one unless independent corroboration was found along the way.

Contracts, bridges and wrapped value

Modern movement is rarely a plain transfer. Value passes through swaps, deposits, approvals, staking positions and bridges. A trace decodes contract calls where the interface can be identified, so a step is recorded as the action it performed rather than as an opaque payload.

Bridges and wrapped assets are treated as one connected event across two ledgers. The originating transaction, the bridge contract interaction and the corresponding release or mint on the destination chain are documented together with their hashes and times. Where the correspondence cannot be established with confidence, the file says the link is unconfirmed rather than assuming continuity because the amounts look similar.

Where a trace stops

Traces end at boundaries, and naming the boundary honestly is part of the work. The most common boundary is a custodial deposit address: once value enters a service, subsequent movement happens in that service's internal books, which are not visible on the chain. The trace records the arrival, identifies the service where it can be identified, and stops.

Pooling services are the other common boundary. Where a mixing or pooling mechanism breaks the link between deposits and withdrawals, the file documents what entered and what left, and does not assert a match unless independent evidence supports one. Amount-and-timing similarity across a pool is a hypothesis, and it is graded as such.

A boundary is not a failure. A file that says clearly where observation stopped is more useful than one that continues past it on inference, because everything downstream of an unmarked assumption is unreliable and the reader cannot tell where the reliability ended.

What the finished trace contains

A completed reconstruction contains the declared starting point and direction, the ordered sequence of steps with hashes and timestamps, the decoded meaning of contract interactions, the branch decisions taken, the confidence grade attached to each linked stage, and an explicit statement of where the trace ended and why.

It does not contain a name attached to an address without an evidential basis, a recovery projection, or a legal characterisation of what occurred. Those are separate questions, and a trace that quietly answers them is doing something other than tracing.

Continue reading

All guides