A ruled notebook and pencil on a dark research desk under a single bench lamp

Practical on-chain research

Guides to start on-chain research properly

First pass Describe, don't conclude
Written down Three notes per address
Cluster test Agree or disagree, with reasons
Last step Write the conclusion

A reading order for the first weeks of on-chain analytics work, from one wallet lookup to a routine you can repeat.

Start here Begin with the first wallet lookup

These guides exist for the first few weeks, when the tools are available but the routine is not

Each one is short, ordered, and meant to be followed on a real address rather than read passively. By the end you should have a repeatable way to look at a wallet or a token and know what to write down.

Work them in order if you are new, or jump to the one that matches the question in front of you. Nothing here needs an account or a paid tier to start; the exercises run on public chain data.

What you leave with

  • A written description of one address you care about
  • A decision on one cluster, with your reasons attached
  • A five-step flow-tracing routine you can run again
Open the Wallet Tracker

Guide one

Your first wallet lookup

Open the Wallet Tracker and paste one address you already care about. Read the recent activity in order, oldest first, and write down three things: where the funds came from, what the wallet holds now, and which counterparties appear more than once. That last list is usually where the interesting part starts.

Do not draw conclusions yet. The goal of the first pass is a description, and descriptions are what later analysis stands on. Keep the three answers in one place so every later step can point back at them.

Start with the first wallet lookup
An analyst at the edge of frame working at three softly glowing monitors in a dark research room
First pass, one sitting: read recent activity oldest-first and keep the three answers in a single place.

Guide two

Reading labels without trusting them

Check every label attached to the addresses you found. Note where the label came from and how old it is. An exchange label from last year may still be correct, and it may not, if custody changed.

  1. Source and age Write down who attached the label and when. A label with no date cannot be weighed against a custody change later.
  2. What the label explains "This is an exchange wallet" tells you funds reached a venue. It does not tell you what happened next, and it never tells you why.
  3. Where it can mislead A shared custody provider can hold many clients under one label. Treat it as a waypoint on the path, not as the actor at the end of it.
  4. The habit Date every label you accept, and note the ones you set aside. When someone asks how you got there, that record is the answer.

Guide three

Clustering your first set of addresses

Take two or three addresses that interacted and run them through Wallet Clusters. Look at which signals the tool found and decide whether you agree. Write down whether you consider them one actor, and why. Disagreeing with the tool, with a reason, is the skill this exercise builds.

Strongest signal

Common funding source

Two addresses that first received value from the same place are the easiest pair to defend. Note the funding transaction and the date, because the same sender looked at months apart is a weaker case than the same sender in the same week.

Middle signal

Contract interaction

Repeated use of the same contracts in the same order is worth recording, especially when the addresses also share a funding source. On its own it is suggestive rather than conclusive.

Weaker signal

Timing

Same hour, same day is a lead to check, not a finding. Busy hours on a busy chain produce plenty of coincidence.

A stack of plain aluminium plates catching amber light on one edge against a graphite surface

Guide four

Following a token across chains

Pick a token you follow and trace one flow that crosses a bridge. Note the deposit and withdrawal windows, and record how confident the link is. If the trail goes cold, mark it as cold rather than guessing.

This guide pairs with Token Flows, which explains what the different flow shapes tend to suggest.

Read the flow-tracing guide

Record for a bridge hop

Deposit window
Before
Withdrawal window
After
Confidence
Stated, not implied
If the trail goes cold
Mark it cold

Guide five

Building a flow-tracing routine

A routine is a fixed sequence you run every time, so you notice deviations instead of chasing them. Keep the sequence identical across sessions. The value is in the comparison, and comparison needs consistency.

Step one

Identify the wallets involved and note each address exactly as it appears.

Step two

Check the labels, with their source and date, before you lean on any of them.

Step three

Test the clusters and record where you agree or disagree, with reasons.

Step four

Trace the bridge hops and match the deposit window to the withdrawal window.

Step five

Note any destination you can name, and stop there if you cannot name one.

Run the same five steps in the same order every session. When something looks different, the difference is the finding.

Guide six

Where outside data fits in your routine

Some questions need context beyond wallet activity. Pull from these sources as the question demands, and record which source supported which conclusion.

GMGN and other third-party analytical data sources can be referenced inside FlowLens workflows. They are independent data references, not partners of this site, and each one carries its own method and its own limits.

DeFiLlama First stop for protocol-level comparisons, when the wallet question is really a question about where activity sat across venues.
Nansen Useful when you want labeled counterparties quickly, and you are comfortable treating another team's labels as a starting point rather than a verdict.
CryptoQuant and CoinGlass Cover exchange flows and derivatives positioning, which is where you check whether a movement in wallets lines up with a broader venue pattern.
Flipside Handles questions that need a custom query, when the standard views cut the data in a shape that does not match what you are asking.
Elliptic A different category altogether, focused on investigations and risk workflows. Bring it in when the question is about exposure rather than activity.

Guide seven

Mistakes beginners make

The most common error is treating a cluster as a confirmed identity. The second is reading exchange inflows as automatic sell pressure. A close third is assuming a bridge hop means a trail is broken when it usually just needs matching windows.

Milder but persistent: skipping the write-up. If you cannot describe the conclusion in a few sentences with the evidence attached, you do not have one yet.

  • A cluster is a hypothesis about an actor, not the actor's name.
  • Funds reaching an exchange is arrival, not intent, and not a signal on its own.
  • A bridge hop rarely ends a trail; it usually asks you to align two windows.
  • No write-up means no conclusion, however long you looked at the screen.
Out of tolerance A conclusion without its evidence attached is not a conclusion

Guide eight

A short list of habits to keep

None of that is glamorous, and all of it is what makes the output defensible when someone asks how you got there.

  • Label with a date Every label you accept carries the day you accepted it.
  • State confidence Note it explicitly, so a hunch is never filed next to a fact.
  • Recheck after a week Custody moves; your working conclusions should move with it.
  • Record disagreements When two sources differ, write both down instead of averaging them into a third number.
  • Keep the routine Same sequence every session, so comparisons mean something.

Questions before you start

Common things newcomers ask on the first pass. If your question is about a specific tool view, the Tools page has the instrument detail.

How long should the first wallet lookup take?

Most addresses resolve in one sitting. Read the recent activity oldest-first and stop once you have the three notes: funding source, current holdings, and any counterparty appearing more than once. A longer first pass usually means you started drawing conclusions instead of describing.

Do I need paid tools to run these exercises?

No. The Wallet Tracker and Wallet Clusters run on public chain data. The outside sources listed here are optional context, and which of them you need depends on the question, not on the guide number.

What if the clustering tool and I disagree?

Write down both positions with the signal each one used. The tool may be reading a funding pattern your eye skipped; you may be reading a label the tool accepted without a date. A recorded disagreement is more useful than a forced agreement.

How does FlowLens use outside data sources?

The architecture is built to add analytical modules and data sources over time, including GMGN and other third-party analytical data sources, which are referenced as independent inputs rather than partners. Record which source supported which conclusion so a later reader can follow the same path.

Put the routine in front of a real address

Open the Wallet Tracker, paste one address, and work through the first guide as written. If you would rather see how the instrument is put together first, the Tools page walks through Wallet Clusters and the AI Activity Summary.

Open the Wallet Tracker Read the on-chain research notes

Questions about a workflow, or want the address details? Reach the FlowLens desk.