BTC $- · ETH $- · SOL $- · BNB $- · XRP $- · DOGE $- · TON $- · ADA $- · AVAX $- · LINK $- · SUI $- · TRX $- · gas - gwei degen 74/100

~/degen/deployers $ cat deanon-rassledovaniya-kak-lovyat.md

degen Batch Deployers ·June 30, 2026

How scammers get deanonymized: on-chain investigation methods in real cases

the crptch team · analytics desk · 2 reading time

The anonymity of a scammer holds together on his discipline - and discipline breaks. Public investigations (the genre that made ZachXBT famous) reveal a recurring toolkit for deanonymization.

Standard vectors

  • Graph to an exchange: any money eventually meets KYC - a withdrawal to an exchange links the cluster to an identity (for law enforcement) or at least to a jurisdiction.
  • Infrastructure reuse: one ENS, a reused wallet 'for everyday use,' paying for a domain from a dirty address - classic opsec failures.
  • Cross-platform traces: a Discord handle equals a forum nickname from a decade ago equals an old Twitter with a face. Scammers are young, but their digital past is not.
  • Timing and language: the timezone of activity, language calques, habitual amounts - narrow down the geography to almost nothing.
  • Greed as evidence: buying an NFT flex or luxury item from an address linked to a rug pull is the most common ending.

What happens after deanonymization

The spectrum ranges from returning funds 'by agreement' (a regular outcome: it's cheaper for a scammer to return the money than to live under a known name) to criminal cases in jurisdictions with working practices. But honest statistics are modest: high-profile cases get deanonymized, while assembly-line small fry survive for years. The moral for the market: the reputational layer (handwriting registries, screener tags, public threads) punishes faster than courts - and that's what we work with in the section.

[tg @crptchs] ✓ track record