Analyst seated at a night research desk, monitors glowing behind with unreadable traces

Wallet intelligence

Wallet intelligence starts with labels and clusters

Two wallets can look identical in a block explorer and mean completely different things. This page explains how labels, clusters, and attribution claims are built — and where each one stops being reliable.

What this page covers

Address labeling sources direct and traced
Clustering evidence behavioral signals
Attribution bar highest evidence
Behavior reading pattern over identity
The claim that breaks first a cluster is not an owner

The three layers: label, cluster, attribution

Research notes

A label is a statement about an address, usually that it belongs to a named service or entity. A cluster is a set of addresses that likely share an owner. Attribution is the strongest claim, naming the entity behind the cluster. Each layer rests on different evidence, and mixing them up is the most common source of bad on-chain conclusions.

FlowLens keeps the layers separate in every write-up. A note that says "exchange wallet" is making a labeling claim. A note that says "these addresses are one actor" is making a clustering claim, with all the uncertainty that implies. Keeping the two apart is what lets you go back later and change your mind about one without throwing out the other.

Layer What it claims Evidence it needs
Label This address belongs to a named service or entity of some kind. Published disclosures, contract function, or repeated deposit and withdrawal patterns.
Cluster These addresses likely share one owner or operator. Shared funding source, coordinated timing, gas patterns, or reused withdrawal addresses.
Attribution A specific named entity is behind this cluster. A direct source wherever possible. A matching pattern alone stays provisional.

Read the middle column down: each row asks for more than the one above it. The flagged row is the one that gets repeated most often and retested least.

Analyst seen over the shoulder at a desk, monitors glowing with unreadable traces

Label maintenance

A labeled-address set is a catalog that someone keeps current. The upkeep is the useful part — the list itself is downstream of it.

How an address gets labeled

Labels come from several directions. Protocol contracts are labeled by function — a bridge contract is a bridge contract, and that label rarely moves. Exchange and custody wallets are identified through known deposit and withdrawal patterns and, in many cases, published disclosures. Fund and market-maker addresses are identified over time as their behavior repeats against the same venues and counterparties.

Some labels are direct and stable. Others are traced and revisable, which is why a label's age matters as much as its content. A wallet labeled two years ago may have changed hands; a wallet labeled last month carries fresher evidence behind it. When you pull a labeled address from a third-party source, you are also inheriting that source's maintenance schedule and its revision history, whether or not you check them.

FlowLens treats every label as dated. The written note records where the label came from and when it was last confirmed, so a reader can weigh an old label differently from a fresh one. Data pulled from a platform known for wallet labeling, such as Nansen and its large labeled-address set, is useful precisely because someone maintains that catalog. The maintenance is the product — and the reason a label from one source should not be silently merged with a label from another.

Before you trust a label

  • Who published it, and does that source name its evidence?
  • When was it last confirmed, and has the address been reused since?
  • Is it a labeling claim only, or does the note quietly assert ownership?

Clustering: behavioral signals, not proof

Clustering looks for addresses that behave like they share a hand. A common funding source is the clearest signal: if ten addresses received their first gas from one wallet, they probably belong to one operator. Coordinated timing is weaker but still useful, especially when the addresses interact with the same contracts in the same order.

Gas patterns and transaction ordering can add weight. So can reuse of the same withdrawal address across venues. None of it is proof. Two unrelated operators can share a funding source through a common exchange, a shared custodian, or a service that batches withdrawals. A careful cluster states the signals present, the signals expected but missing, and what confidence level the analyst assigned — because a reader who cannot see the reasoning cannot judge the group.

Wallet Clusters in the FlowLens Wallet Tracker applies these heuristics and shows the grouping for review rather than hiding the reasoning behind a single score. You get the addresses, the shared signals that tied them together, and the edge cases the heuristic flagged as uncertain. Where two addresses plausibly belong to different operators but share one funding hop, the cluster notes it instead of resolving it silently.

Signals a cluster may cite

Shared first funding source strong
Coordinated transaction timing moderate
Identical gas settings across addresses moderate
Reused withdrawal address across venues moderate
Shared exchange withdrawal hop only weak

The bottom row is the one that fools people most often. One shared hop does not make one owner.

Address attribution and its limits

Attribution names an entity. It deserves the highest evidentiary bar because it is the claim most likely to be repeated and least likely to be retested. A direct disclosure from an exchange is strong. A cluster that matches a known entity's patterns is suggestive, and it can be wrong.

We treat attribution claims as provisional unless a direct source supports them. Where a cluster only resembles a known actor, the note says so. That caution is not hedging. It reflects how often behavior overlaps between unrelated operators using the same infrastructure — the same bridge, the same aggregator, the same custody arrangement.

The practical consequence for a reader is simple. When you see a named entity attached to a cluster, look for the source. If a direct disclosure sits behind it, the claim carries. If the note says the behavior "resembles" a known actor, you are looking at a suggestion, and the right move is to treat it as one.

Attribution confidence

Direct disclosure > matching pattern > resemblance only.

A public statement of ownership or a named source above the line; a pattern match or a vague resemblance below it, is a lead, not a conclusion.

What wallet behavior patterns actually reveal

Behavior tells you what an address does, which is often more useful than who it is. Consistent accumulation without exchange deposits suggests holding. Repeated routing through a mixer or a bridge before an exchange deposit suggests intent to obscure the trail. Market-maker behavior looks different again: high transaction counts, tight timing, inventory moving between venues.

Reading patterns means comparing an address against its own history first. A wallet that has always used one bridge is unremarkable for using it again. A wallet that suddenly changes its route, its timing, or its counterparties is worth a closer look — not because change proves intent, but because it breaks the baseline the earlier behavior established.

Reading a route change

Steady baseline Same bridge, same venue pattern, same cadence for months. Unremarkable when it continues.
Route change A new bridge or a new intermediary before deposits. Worth documenting, not by itself a finding.
Timing shift Activity moving from slow, patient movement to a compressed window. Compare against market structure before drawing meaning.
Signal overlap Two or more of the above in the same window — the case worth writing up, with the baseline attached.

Smart money, described without mythology

Smart money gets talked about as if it were a fixed list. It is not. It usually means wallets with a track record that analysts have chosen to follow, and the list changes with market conditions. The useful practice is to define your own criteria and recheck them, rather than inheriting a roster from a screenshot.

Labeled tracking tools make the watchlist easier to maintain. What they cannot do is guarantee that a historically strong wallet continues to be right, and any note claiming otherwise has stopped being research. A wallet that produced good outcomes in one market regime can persist in a habit that no longer works — and the only way to catch that is to keep the criteria written down next to the results.

A workable watchlist note states four things: the reason the wallet is on the list, the window you are judging it over, the review date, and the criteria that would take it off. Anything less drifts into mythology within a month or two.

Top-down view of aluminium plates on a graphite desk, low amber side light

Combining wallet data with portfolio and market views

Wallet intelligence answers questions about specific actors. It does not show you the full picture of positions or market structure. That is where adjacent tools fit. Zapper and CoinStats track holdings across wallets and exchanges, DeFiLlama covers TVL and protocol-level comparisons, and CryptoQuant handles exchange-flow and market-cycle context. Each covers a slice.

The workflow that works is sequential. Use a portfolio view to find what moved, use wallet intelligence to understand who moved it, and use market-structure data to check whether the move is unusual for the wider market. Pulling one number out of step two and acting on it alone is how a reasonable dataset produces an unreasonable conclusion.

Tool What it covers
Zapper Portfolio holdings pulled across wallets and chains into one position view.
CoinStats Holdings tracking across wallets and exchange accounts for a wider position read.
DeFiLlama Protocol-level TVL and comparison data for judging the setting behind a movement.
CryptoQuant Exchange-flow and market-cycle context for testing whether a move is unusual.
FlowLens Wallet Tracker The step that identifies who moved a value, using Wallet Clusters and an AI Activity Summary to describe the behavior in reviewable language.

FlowLens is built as a hub rather than a single dataset. New data sources and analytical modules connect through the same ruled row and the same confidence language, so a new source lands next to the existing ones without changing how you read the page.

Clustering across chains

Cross-chain behavior complicates clustering because addresses are chain-specific, and the same operator may use different addresses on each. Bridges and shared funding sources are the usual connections between the two, so to speak, and a cluster that spans chains is generally less certain than one on a single chain.

FlowLens documents cross-chain clusters separately and labels the confidence lower by default. Two addresses on two chains meeting the same bridge at the same time is a starting point, not a conclusion — the bridge itself handles many unrelated users, and its timing is often governed by its own batching rather than by any one operator.

Token flow tracing covers the mechanics of following funds once they cross a bridge: how the receiving address is identified, how return paths are checked, and how a flow that leaves one chain is matched to its arrival on another.

Long-exposure view of a dark research room with monitors glowing and rain on the window

Keeping an intelligence habit honest

Three habits keep wallet research from turning into storytelling, and none of them require special tooling. They require the discipline to separate observation from inference in writing, which is what this entire section is about.

Write it down Record the label source and the date you last confirmed it, even for a label you inherited from a catalog you trust.
Name the signals State the clustering signals you actually found, including the ones you expected and did not see.
Revisit later Recheck conclusions after a meaningful time has passed, because addresses get reused and labels get revised.

Questions readers raise most

How certain is a wallet cluster, really?

It varies by the signals behind it. A shared first funding source with coordinated timing reads differently from two addresses that only touched the same exchange withdrawal hop. Read the signals the cluster names before you read the group itself.

Does a label ever expire?

Not on a clock, but a label's confidence drops with its age. An address can change hands, and a service can fold or be acquired. Confirm the label before you repeat it as if it were current.

Where does the AI Activity Summary fit in?

It is a written read of an address's recent activity — the same reasoning you would write down yourself, kept in reviewable language alongside the raw rows. It summarizes what happened; the evidence for the summary sits next to it in the tracker.

Does FlowLens rely on GMGN or other third-party sources?

GMGN is supported as an independent third-party analytical data source, referenced for the activity it already publishes; this is a data reference only, not a partnership or endorsement in either direction. The same holds for any source added later.

Can I add my own data source?

The architecture is built to extend — new data sources and analytical modules attach through the same ruled presentation and the same confidence language you see on this page. Send a data correction or tell us which source you work with, and it goes into the same review queue as everything else.

Put the label, cluster, and confidence next to each other

That is the whole method. When the three sit side by side, a weak claim looks weak and a strong one looks strong — and neither gets to borrow authority from the other. If a label or cluster on this page reads wrong, tell us; corrections are part of the record.

Email[email protected]

Phone+1-650-552-9923

Office2455 Bennett Avenue, Suite 400, Mountain View, CA 94043

Monday–Friday, 9:00 AM – 6:00 PM Pacific Time