Crypto & Digital Asset Investigation

Diliguard provides crypto investigation tools to trace digital asset movements. We bridge fiat and blockchain data to expose money laundering networks.

What Is Crypto Investigation Software?

Diliguard’s Crypto Investigation software checks a wallet address against sanctioned and criminal wallet databases, pulls its live balance and transaction count from public blockchain explorers, and, when an IP address is provided, checks the network origin of the associated activity. It returns a named threat attribution, not a generic risk score.

How Crypto Investigation Software Works

  • Illicit Wallet Tracing: Cross-references the wallet against databases of addresses linked to intrusion groups, ransomware operations, fraud, and darknet markets.
  • Sanctions Screening: Checks the wallet specifically against government sanctions lists covering BTC and ETH addresses, separate from the broader illicit-activity check.
  • Balance and Transaction Lookup: Pulls real-time balance and unspent transaction outputs (UTXOs) directly from public blockchain explorers.
  • IP Network Correlation: When paired with an IP address, checks whether the activity originated through a residential proxy, VPN, or datacenter, using the same infrastructure as IP & Network Intelligence.

What Diliguard Returns

A wallet with no findings returns a green “Pass: Clear Wallet” banner with a Wallet Card showing the address, current balance, and transaction count. A flagged wallet returns a red “Critical Alert: High Risk Wallet” banner, with the same Wallet Card plus one Associated Threats card per finding, naming the specific threat (for example “Lazarus Group” or “Sanctioned Wallet”) and the link depth, meaning whether the connection is direct or indirect.

Data Sources and Coverage

Illicit wallet and sanctions screening draw on curated databases of wallets tied to known intrusion groups, ransomware operations, darknet markets, and government sanctions designations for BTC and ETH addresses. Balance and transaction data comes directly from public blockchain explorers in real time, not a cached snapshot. IP correlation, where used, draws on the same network intelligence data as the standalone IP module.

Frequently Asked Questions

Which cryptocurrencies does Diliguard’s sanctions screening cover?

Crypto Sanctions screening covers BTC and ETH addresses. Illicit Wallet Trace and Balance Check work on wallet addresses generally, but sanctions-list matching is specific to BTC and ETH.

What does “indirect connection” mean in a threat finding?

It means the flagged wallet has not transacted directly with a known illicit address, but funds have passed through an intermediate wallet that has. Diliguard reports the link depth so the reviewer can judge how far removed the exposure actually is.

Does a clear wallet result guarantee the funds are legitimate?

No. A clear result means no match was found against the databases checked at the time of the query. Wallet ownership and fund origin outside those specific databases are not confirmed by this check alone.

Can Diliguard check a wallet before accepting a payment, not just after?

Yes. The check is designed to run pre-transaction, before a withdrawal or deposit is processed, so a flagged wallet can be intercepted rather than discovered after funds have moved.

Where This Fits

Crypto Investigation is the core screening layer for Crypto-Asset Service Providers, covering wallet risk scoring during onboarding and before large withdrawals are processed.

Architecture and Integration

This blockchain forensic tool operates alongside AML Compliance & PEP Screening so fiat and crypto risk are managed in one workflow. Exchanges and financial institutions integrate the combined intelligence via the Developer API at api.diliguard.com, authenticated with an API key from the portal’s Settings page, or through the @sluxia/diliguard-mcp MCP server for agent-driven workflows.