~/degen/deployers $ cat deanon-rassledovaniya-kak-lovyat.md
How scammers get deanonymized: on-chain investigation methods in real cases
The anonymity of a scammer holds together on his discipline - and discipline breaks. Public investigations (the genre that made ZachXBT famous) reveal a recurring toolkit for deanonymization.
Standard vectors
- Graph to an exchange: any money eventually meets KYC - a withdrawal to an exchange links the cluster to an identity (for law enforcement) or at least to a jurisdiction.
- Infrastructure reuse: one ENS, a reused wallet 'for everyday use,' paying for a domain from a dirty address - classic opsec failures.
- Cross-platform traces: a Discord handle equals a forum nickname from a decade ago equals an old Twitter with a face. Scammers are young, but their digital past is not.
- Timing and language: the timezone of activity, language calques, habitual amounts - narrow down the geography to almost nothing.
- Greed as evidence: buying an NFT flex or luxury item from an address linked to a rug pull is the most common ending.
What happens after deanonymization
The spectrum ranges from returning funds 'by agreement' (a regular outcome: it's cheaper for a scammer to return the money than to live under a known name) to criminal cases in jurisdictions with working practices. But honest statistics are modest: high-profile cases get deanonymized, while assembly-line small fry survive for years. The moral for the market: the reputational layer (handwriting registries, screener tags, public threads) punishes faster than courts - and that's what we work with in the section.