For investigation of cryptocurrency frauds and financial crimes, we believe every effort must be made to report findings in a manner that is comprehensible to a layperson. It can be challenging to convey technical and cryptographic concepts in the plainest language possible — but a judge or jury cannot fairly evaluate the evidence if they do not understand it.
Effective communication in complex cases begins by establishing clear, standardized definitions for common terms. Below is a glossary developed by the investigative staff of Hudson Intelligence for cryptocurrency casework. We are sharing this internal reference in the hope it will serve as a useful guide for attorneys, investors, regulators and law enforcement.
Cryptocurrency technology, terminology, case law, tax treatment, and regulatory frameworks continue to evolve. This glossary is therefore a work in progress and will be updated as industry practices and investigative methods develop.
John Powers, CFE, CTCE
Last Reviewed: July 2026
Account-Based Model
Address
Address Reuse
Altcoin
Approval
Attribution
Bitcoin (BTC)
Blockchain
Blockchain Analytics
Blockchain Bridge
Blockchain Explorer
Centralized Exchange
Chain Hopping
Change Address
Cluster
CoinJoin
Common Spend
Cross-Chain Swap
Cryptocurrency
Crypto Drainer
Custodial Wallet
Darknet Market
Dark Web
Decentralized Application (dApp)
Decentralized Exchange (DEX)
Decentralized Finance (DeFi)
Deep Web
Digital Currency
Distributed Ledger Technology
Ethereum
Ether (ETH)
Exchange
Exit Scam
Externally Owned Account (EOA)
Fiat
Forfeiture
Freeze or Blacklist
Gas Fee
High-Risk Exchange
Initial Coin Offering (ICO)
Know Your Customer (KYC)
Layering
Mining
Mixer
Monero (XMR)
Node
Non-Fungible Token (NFT)
Peel Chain
Peer-to-Peer (P2P) Exchange
Privacy Coins
Private Key
Protocol
Public Key
Pump and Dump Scheme
Risk Scoring
Rug Pull
Sanctioned Address
Seed Phrase
Self-Custodial Wallet
Seizure
SIM Swap
Smart Contract
Spoofed Token
Stablecoin
Staking
Token
Tokenization
Transaction Hash
Unspent Transaction Output (UTXO)
Virtual Asset Service Provider (VASP)
Virtual Currency
Wallet
Account-Based Model is a method of recording ownership and transactions in which each blockchain address maintains a continuously updated account balance. When a transaction occurs, the balance of the sender's account is reduced and the balance of the recipient's account is increased. Ethereum and many other blockchain networks use an account-based model, in contrast to Bitcoin's Unspent Transaction Output (UTXO) model.
Address is an identifier used to send or receive cryptocurrency or interact with a blockchain application. For example, this is a Bitcoin address: 1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa
Blockchain addresses and their transaction histories are generally visible on a public ledger, while the identity of the person or entity controlling an address may not be publicly disclosed.
Control of assets associated with a self-custodial wallet ordinarily depends on possession of the corresponding private key or other required signing credentials. Addresses maintained by exchanges and other custodians are controlled by the service provider on behalf of its customers.
Address Reuse is the practice of receiving cryptocurrency through the same blockchain address in multiple transactions. While convenient, address reuse can make it easier for investigators and other observers to associate separate transactions with the same user or entity, potentially reducing privacy. For this reason, many modern wallets automatically generate a new receiving address for each transaction. (Learn More.)
Altcoin is a general, somewhat dated, term for any cryptocurrency other than Bitcoin. As the digital asset ecosystem has matured, the term has become less precise and is often replaced by more specific descriptions such as token, stablecoin, governance token, or digital asset.
Approval is an authorization granted by the party who controls a blockchain address permitting a smart contract or other entity to transfer specified digital assets on that party's behalf. Approvals are commonly used by decentralized applications and cryptocurrency exchanges to facilitate transactions. Fraudulent or overly broad approvals may enable unauthorized transfers without requiring any further authorization from the asset owner.
Attribution is the process of associating a blockchain address, wallet, transaction, or other blockchain activity with a known person, business, service, or other identifiable entity. Attribution may be based on publicly available information, blockchain analytics, information obtained through legal process, admissions by a user, or other investigative evidence.
Bitcoin (BTC) is the first decentralized cryptocurrency, introduced in 2009 by the pseudonymous creator Satoshi Nakamoto. It operates on a public blockchain that records transactions without the need for a central authority. Because of its longevity and widespread adoption, Bitcoin remains one of the cryptocurrencies most frequently encountered in blockchain investigations.
Blockchain is a ledger in which transactions or other data are grouped into blocks and recorded according to a network protocol. Public blockchains generally provide a durable and publicly accessible record of transactions. Unlike traditional financial records maintained by a single institution, copies of the blockchain are distributed across a decentralized network of participating computers. Public blockchain records ordinarily identify addresses and transaction details rather than the legal names of the people or entities involved.
Blockchain Analytics is the process of examining blockchain transactions and related information to identify patterns, relationships, or activity relevant to an investigation. Blockchain analytics may include transaction tracing, address clustering, risk scoring, attribution, and the identification of exchanges, illicit services, or other entities associated with blockchain addresses.
Blockchain Bridge is a service or protocol that enables users to move digital assets from one blockchain network to another. Because separate blockchains generally cannot communicate directly, bridges rely on various technical mechanisms to facilitate these transfers, such as locking assets on one blockchain while creating corresponding assets on another.
Blockchain Explorer is an online application that allows users to browse and search transactional details published on a blockchain.
Centralized Exchange (CEX) is a cryptocurrency exchange operated by a company that facilitates the purchase, sale, and custody of digital assets on behalf of its customers. Centralized exchanges commonly perform identity verification, maintain transaction records, and may respond to subpoenas, court orders, or other lawful requests for customer information.
Chain Hopping is the repeated movement of cryptocurrency or other digital assets from one blockchain network to another, often through blockchain bridges, cross-chain swaps, or centralized exchanges. While cross-chain transfers have many legitimate uses, they may also be used to complicate blockchain tracing by dispersing transactions across multiple networks. As a result, chain hopping is commonly encountered in cryptocurrency fraud, money laundering, and other financial crime investigations.
Change Address is a blockchain address generated by a cryptocurrency wallet to receive any remaining value from a transaction after the intended payment and transaction fee have been deducted. In Bitcoin and other UTXO-based blockchains, wallets typically spend one or more entire transaction outputs, returning any excess value to a change address controlled by the sender.
Cluster is a group of blockchain addresses that investigators or blockchain analytics providers assess as likely being under common control. Clustering may be based on blockchain transaction patterns, known attribution data, information obtained through legal process, or other investigative techniques. Because clustering involves analytical judgment, its reliability depends on the underlying evidence and methodology.
CoinJoin is a privacy-enhancing Bitcoin transaction which combines inputs from numerous users and returns multiple outputs of identical values. (Learn More.)
Common Spend is a heuristic, or analytical method, used by blockchain analysts to identify cryptocurrency addresses likely controlled by the same person or entity. The heuristic is based on transactions in which multiple addresses are used together to authorize a single transaction. (Learn More.)
Cross-Chain Swap is the exchange of one digital asset for another across different blockchain networks. Cross-chain swaps may be performed through bridges, decentralized protocols, centralized exchanges, or other intermediary services.
Cryptocurrency is a digital asset that can be transferred electronically and whose ownership and transactions are recorded on a blockchain using cryptographic methods.
Crypto Drainer is malicious software or a malicious smart contract designed to transfer cryptocurrency or other digital assets from a victim's wallet after obtaining the necessary authorization or approvals. Drainers are commonly distributed through fraudulent websites, phishing campaigns, counterfeit decentralized applications, or other deceptive means.
Custodial Wallet is a cryptocurrency wallet in which a third party, such as an exchange or other service provider, controls the private keys on behalf of the user. Because the service provider controls the signing credentials, it generally has the ability to authorize transactions, recover account access, and comply with legal process affecting assets held in custody.
Darknet Market is a website that facilitates the sale and exchange of illicit goods and services on the dark web. (Learn More.)
Dark Web is an anonymized overlay of the internet, accessible through networks such as Tor ("The Onion Router"), I2P and Riffle that utilize layered encryption to obscure the identities and locations of users. (Learn More.)
Decentralized Application (dApp) is a software application that operates on a blockchain or interacts with one or more smart contracts rather than relying solely on centralized servers. dApps may provide financial services, marketplaces, gaming platforms, digital identity services, and many other blockchain-based functions.
Decentralized Exchange (DEX) is a blockchain-based platform that allows users to exchange digital assets directly from self-custodial wallets without transferring custody to a centralized intermediary. Most decentralized exchanges rely on smart contracts to facilitate trading and may allow users to trade directly from self-custodial wallets without creating an account or depositing assets with the platform.
Decentralized Finance (DeFi) is a term describing blockchain-based financial services that operate through smart contracts rather than traditional financial institutions. DeFi applications may facilitate lending, borrowing, trading, asset management, derivatives, and other financial activities without relying on centralized intermediaries.
Deep Web is the portion of the internet that is not indexed by standard search engines, in contrast to the ‘clear net’ most consumers are accustomed to searching through Google or Bing. (Learn More.)
Digital Currency is a broad term referring to value represented and transferred electronically. Depending on the context, the term may include cryptocurrencies, electronic representations of government-issued currency, and other forms of electronically stored value.
Distributed Ledger Technology (DLT) is a system for recording and sharing information across multiple computers so that participants maintain a common record without relying on a single central database. A blockchain is one type of distributed ledger technology.
Ethereum is a decentralized blockchain platform that supports programmable smart contracts and decentralized applications (dApps). Its native cryptocurrency, Ether (ETH), is used to pay transaction fees and interact with applications on the network. Ethereum has become the foundation for many stablecoins, decentralized finance (DeFi) protocols, and other blockchain-based services.
Ether (ETH) is the native cryptocurrency of the Ethereum platform.
Exchange is a platform that facilitates the purchase, sale, or exchange of cryptocurrencies and other digital assets. Some exchanges act as centralized custodians of customer assets, while decentralized exchanges allow users to trade directly from self-custodial wallets without transferring custody to a central intermediary.
Exit Scam is a fraud in which the operators of a business, investment program, exchange, marketplace, or other venture abruptly cease operations and abscond with customer funds or assets. Exit scams have occurred in both centralized cryptocurrency businesses and decentralized blockchain projects.
Externally Owned Account (EOA) is a user-controlled blockchain account on an account-based network such as Ethereum. Unlike a smart contract account, an externally owned account is controlled by a private key and can initiate blockchain transactions by digitally signing them.
Fiat Currency is government-issued money that derives its value from the authority of the issuing government rather than from a commodity such as gold or silver. U.S. dollars, euros, British pounds, and Japanese yen are examples of fiat currencies.
Forfeiture is the legal process through which ownership of seized or restrained property may ultimately be transferred to the government.
Freeze or Blacklist refers to the restriction of cryptocurrency or digital assets so they cannot be transferred or redeemed without authorization. Depending on the blockchain and digital asset involved, a freeze may be implemented by a custodial service, stablecoin issuer, smart contract, or other entity with administrative authority. Assets held in self-custodial wallets generally cannot be frozen unless the underlying protocol provides that capability.
Gas Fee is the transaction fee paid by a user to compensate network participants for processing a transaction or executing a smart contract on certain blockchain networks, particularly Ethereum. The amount of the gas fee generally depends on the computational complexity of the transaction and prevailing network demand.
High Risk Exchange is an informal term used to describe a cryptocurrency exchange that presents elevated compliance or financial crime risks. Factors contributing to this designation may include weak customer identification procedures, limited regulatory oversight, sanctions exposure, unusually high levels of illicit transaction activity, or a history of facilitating anonymous or high-risk transactions. The criteria and methodology used to identify high-risk exchanges vary among blockchain analytics providers. (Learn More.)
Initial Coin Offering (ICO) is a fundraising method in which a blockchain project sells newly created digital tokens to investors, typically in exchange for cryptocurrency or fiat currency. While some ICOs have supported legitimate projects, others have involved fraud, securities law violations, or unsuccessful ventures. The legal treatment of ICOs depends on the structure of the offering and the applicable jurisdiction. (Learn More.)
Know Your Customer (KYC) refers to the identity verification procedures used by financial institutions, cryptocurrency exchanges, and other regulated businesses to confirm the identity of their customers. KYC compliance programs commonly involve collecting identifying information and documentation to help prevent fraud, money laundering, sanctions violations, and other illicit activity.
Layering is a money laundering technique in which funds are moved through multiple transactions, accounts, or jurisdictions to obscure their origin, ownership, or destination. In cryptocurrency investigations, layering may involve transfers among numerous blockchain addresses, exchanges, mixers, cross-chain bridges, or other services intended to complicate tracing efforts. (Learn More.)
Mining is the proof-of-work process through which participants compete to validate transactions, construct blocks, and add them to certain blockchains, including Bitcoin. Miners repeatedly perform computational operations in an effort to produce a block that satisfies the network’s protocol requirements. A successful miner may receive newly issued cryptocurrency and transaction fees.
Mixer (also called a Tumbler) is a service or protocol designed to reduce the traceability of cryptocurrency transactions by combining or obscuring the relationship between deposits and withdrawals. Mixers vary significantly in design and may include centralized custodial services, decentralized protocols, or privacy-enhancing transaction coordination techniques such as CoinJoin. (Learn More.)
Monero (XMR) is a privacy-focused cryptocurrency designed to limit the public visibility of transaction participants and amounts. Unlike Bitcoin, which records transactions on a transparent public ledger, Monero uses cryptographic techniques intended to obscure sender addresses, recipient addresses, and transferred amounts, making blockchain analysis substantially more difficult.
Node is a computer that participates in a blockchain network by storing, validating, transmitting, or otherwise processing blockchain data.
Non-Fungible Token (NFT) is a unique blockchain-based token that represents a distinct digital or physical asset, or rights associated with that asset. Unlike cryptocurrencies such as Bitcoin, NFTs are not generally interchangeable on a one-for-one basis. NFTs are commonly used to represent digital artwork, collectibles, event tickets, gaming assets, and other unique items.
Peel Chain is a technique to launder a large amount of cryptocurrency through a lengthy series of small transactions. (Learn More.)
Peer-to-Peer (P2P) Exchange is a platform or marketplace that enables users to buy and sell cryptocurrency directly with one another rather than through a traditional centralized order book. Depending on the platform, P2P exchanges may provide escrow services, identity verification, dispute resolution, or simply facilitate communication between buyers and sellers. (Learn More.)
Privacy Coin is a cryptocurrency designed to reduce the public visibility of blockchain transactions by incorporating privacy-enhancing cryptographic features. Examples include Monero and Zcash, although the privacy protections offered by different cryptocurrencies vary considerably.
Private Key is secret cryptographic data used to authorize blockchain transactions by creating a digital signature. A person who obtains a private key may be able to transfer the assets controlled through that key. A private key is mathematically associated with a public key.
Private keys should not be confused with wallet passwords, PINs, recovery phrases, or exchange login credentials. Those items may protect access to a wallet or account, but they are not themselves necessarily the private key.
Protocol is the set of rules governing how a blockchain network operates, including how transactions are validated, blocks are created, and participants communicate. Changes to a blockchain protocol may introduce new features, improve security, or modify the network's operation.
Public Key is cryptographic data mathematically associated with a private key. It can be used to verify that a transaction was signed using the corresponding private key without revealing the private key itself. An address may be derived from a public key, depending on the blockchain and address type.
Pump and Dump Scheme is a form of market manipulation in which individuals artificially inflate the price of a cryptocurrency through misleading or coordinated promotional activity before selling their holdings at the inflated price. As demand subsides, the price typically falls, leaving later purchasers with substantial losses. (Learn More.)
Risk Scoring or Address Risk Screening is an automated or analyst-assisted process used to identify a blockchain address’s apparent exposure to services, entities, or categories of activity relevant to compliance or investigative analysis. Blockchain intelligence systems may assign categorical ratings, numerical scores, exposure percentages, or alerts based on attributed counterparties and transaction patterns. The methodology and scale differ by provider.
Rug Pull is a type of cryptocurrency investment fraud in which the creators or promoters of a digital asset or blockchain project abruptly abandon the project and misappropriate investor funds or liquidity. Rug pulls commonly involve newly issued tokens that are aggressively marketed before the organizers withdraw liquidity, sell large holdings, or otherwise render the tokens effectively worthless. In many cases, investors are left holding assets that can no longer be sold or have little or no remaining value.
Sanctioned Address is a blockchain address identified by a governmental authority as being subject to economic sanctions. Transactions involving sanctioned addresses may be prohibited or restricted under applicable law. Cryptocurrency exchanges, financial institutions, and other regulated businesses commonly screen blockchain transactions for sanctions exposure as part of their compliance programs.
Seed Phrase or Recovery Phrase is a sequence of words that can be used to recreate a cryptocurrency wallet and the private keys associated with it. Anyone who obtains a seed phrase may be able to gain control of the corresponding digital assets. Recovery phrases should therefore be protected with the same level of care as private keys themselves.
Seizure is the legal taking or restraint of property by governmental authorities, generally pursuant to a warrant, court order, or other lawful authority. Seizure may preserve cryptocurrency pending a later forfeiture proceeding but does not necessarily determine final ownership. Cryptocurrency may be seized through several mechanisms, including obtaining control of private keys, directing a custodial exchange to restrain or transfer assets, or using an issuer’s administrative controls where applicable. The available method depends on the asset, blockchain, custody arrangement, jurisdiction, and factual circumstances.
Self-Custodial Wallet is a cryptocurrency wallet in which the user, rather than a third party, controls the private keys associated with the digital assets. Because no intermediary has custody of those keys, the user is generally responsible for securing the wallet, safeguarding the recovery phrase or private keys, and authorizing transactions. If access credentials are lost or compromised, there may be no third party capable of restoring access to the assets.
SIM Swap is a fraud in which a criminal causes a victim's mobile telephone number to be transferred to a SIM card under the criminal's control. Once successful, the attacker may intercept telephone calls, text messages, and one-time authentication codes used to access cryptocurrency exchanges, financial accounts, email accounts, or other online services.
Smart Contract is a computer program deployed on a blockchain that automatically executes predefined instructions when specified conditions are met. Smart contracts can facilitate the transfer of digital assets, enforce contractual logic, and support decentralized applications without requiring continuous human intervention.
Spoofed Token is a digital token intentionally created to imitate another cryptocurrency or token by using a similar name, ticker symbol, logo, or other identifying characteristics. Spoofed tokens are commonly used in investment fraud, phishing schemes, and other deceptive practices to mislead users into believing they are interacting with a legitimate digital asset.
Stablecoin is a cryptocurrency designed to maintain a relatively stable value, typically by referencing another asset such as a fiat currency, commodity, or basket of assets. Stablecoins may be backed by reserves, collateralized with other digital assets, or rely on algorithmic mechanisms, and their ability to maintain the intended value may vary.
Staking is the process of committing cryptocurrency to help validate transactions and secure a proof-of-stake blockchain network. In return, participants may receive staking rewards. Staking differs from proof-of-work mining, which relies on computational processing rather than committed digital assets to validate transactions and produce new blocks.
Token is a digital asset created on an existing blockchain rather than operating on its own independent blockchain. Tokens may represent currency, ownership interests, governance rights, access to services, or many other forms of digital value.
Tokenization is the process of representing an asset, right, or other interest as a digital token on a blockchain. Tokenized assets may include securities, real estate interests, commodities, artwork, intellectual property rights, or other tangible or intangible assets.
Transaction Hash also called a transaction ID or TxID, is a unique identifier generated from the data associated with a blockchain transaction. It can ordinarily be entered into a blockchain explorer to locate the transaction and review available details, such as its associated addresses, transferred assets, fees, and status. The displayed time is commonly derived from the timestamp of the block containing the transaction and should not necessarily be treated as the exact time at which a user initiated it.
Unspent Transaction Output (UTXO) is an individual output from an earlier blockchain transaction that has not yet been spent. In Bitcoin and other UTXO-based systems, a wallet’s apparent balance is generally the combined value of the UTXOs it can authorize for spending.
When a UTXO is used, it is consumed in its entirety as an input to a new transaction. The transaction then creates one or more new outputs. If the selected inputs exceed the intended payment and transaction fee, the excess is ordinarily returned as a new output, commonly called change.
Think of it this way: You don't tear apart a dollar bill to buy a pack of gum. You hand over the entire note, and in return, receive a small amount of change. A dime, maybe. You can now use that coin to buy something else.
In this accounting model – used by blockchains of Bitcoin, Litecoin and Dogecoin, among others – existing UTXOs are continually being consumed in transactions that produce new UTXOs in their place.
This differs from the account-based model used by Ethereum, where transactions modify balances associated with accounts.
Virtual Asset Service Provider (VASP) is a person or business that performs specified virtual-asset activities for or on behalf of another person. Under the definition developed by the Financial Action Task Force, those activities include exchanging virtual assets for fiat currency; exchanging one or more forms of virtual assets; transferring virtual assets; safeguarding or administering virtual assets or instruments enabling control over them; and providing certain financial services related to the offer or sale of virtual assets. Depending on their activities and jurisdiction, cryptocurrency exchanges, custodians, brokers, certain ATM operators, and other virtual-asset businesses may qualify as VASPs. The legal terminology and regulatory treatment vary among jurisdictions.
Virtual Currency is a digital representation of value that functions as a medium of exchange, unit of account, or store of value but is not necessarily recognized as legal tender by a government. The precise legal definition varies among statutes, regulations, and jurisdictions.
Wallet is software or hardware used to manage blockchain addresses, cryptographic keys, and transaction signing. A wallet does not literally store cryptocurrency; the blockchain records the assets and transactions associated with relevant addresses.
A self-custodial wallet gives the user control of the signing credentials. A custodial wallet or exchange account relies on a third party to control the relevant private keys and execute transactions for the customer. A hot wallet is connected to an internet-enabled system. A cold wallet keeps the relevant signing credentials offline, reducing exposure to certain online attacksConsult an Investigator
Hudson Intelligence assists law firms, businesses, public agencies and investors with cryptocurrency investigations and due diligence. Every investigation is led by a Cryptocurrency Tracing Certified Examiner (CTCE) and Certified Fraud Examiner (CFE). If you would like to discuss a potential investigation, please complete the form below. We also suggest reviewing our FAQ.