HomeDashboardChartsResearchPersonsBubble MapMethodologyGlossaryGlobe

On-chain address tracking — threat actors, state actors, sanctioned entities, and government-seized wallets

Built 2026-06-12 from research/spec-onchain-threat-actor-addresses.json. Attributions verified this pass against FBI PSAs, OFAC SDN designations, Treasury releases, DOJ filings, and chain-forensics (Chainalysis/Elliptic/TRM/Arkham).

Attribution grade. Government attributions (FBI PSA, OFAC SDN, Treasury, DOJ) are high-grade primary. Chain-forensics clustering is strong but probabilistic/labeled. This block does not hand-transcribe long hex addresses (error risk) — it cites the authoritative machine-readable lists (OFAC SDN "Digital Currency Address" fields; FBI PSA IOC lists) and records cluster-level facts. Sanction status is time-varying and dated. Overlay edges excluded from the proofs.

1. Why track on-chain identities

Crypto's transparency cuts both ways: threat actors, governments, and sanctioned entities all hold traceable on-chain addresses. State-grade theft (DPRK), sanctions evasion (Russia/Iran), mixing (Tornado Cash), and state seizure (US government BTC) are all legible on-chain — a first-class data source, not a press summary.

2. North Korea — Lazarus Group (TraderTraitor / APT38)

The most prolific state-grade thief; proceeds fund the DPRK weapons program (UN Panel of Experts; US Treasury).

Address source: per-incident FBI PSA IOC lists + OFAC SDN entries; cluster tracking by Chainalysis/Elliptic/Arkham.

3. Russia — sanctioned exchanges, darknet, ransomware

4. Iran — Nobitex and a state-on-state strike

5. Mixers and the "can you sanction code?" whipsaw

6. The government as an on-chain holder (seizures → reserve)

7. Limits & ingest — and the free-access ceiling (important)

This is an attribution + source-pointer layer, not a raw address dump. Government attributions are high-grade; clustering is labeled. fetch_ofac.py (env-free) ingests the free OFAC Advanced XML (SDN + Consolidated) into data/ofac_crypto_addresses.json757 addresses (522 BTC / 127 TRON / 97 ETH / 10 LTC / 1 XMR), all from the SDN list (the Consolidated list carries none).

The 757 is a FREE-ACCESS FLOOR, not the full universe. It captures only addresses OFAC has formally designated. It deliberately does not include:

So the on-chain identity picture here is a lower bound; full coverage requires the FBI PSA IOC feeds plus a paid forensics subscription. Sanction status is also dated (Tornado Cash 2022 → vacated 2024 → lifted 2025), so a static list overstates what is currently sanctioned.

Verification sources: FBI/Bybit attribution, Tornado Cash sanctions lifted, Silk Road $3.36B, Nobitex hack, US BTC holdings.

← Research index · structured data: spec-onchain-threat-actor-addresses.json · spec-onchain-threat-actor-addresses.md