Blockchain Forensic Analysis Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Blockchain Forensic Analysis flashcards as text
What is the primary purpose of a 'peeling chain' pattern in blockchain forensics?
Answer: To obfuscate the origin of funds by repeatedly splitting and forwarding small amounts
A peeling chain moves funds through a series of transactions where one output is sent onward and the remainder is kept, creating a chain that obscures the original source.
Which heuristic assumes that all inputs in a Bitcoin transaction belong to the same wallet owner?
Answer: Common input ownership heuristic (CIOH)
The Common Input Ownership Heuristic (CIOH) is a foundational blockchain clustering technique that groups addresses whose UTXOs are co-spent in the same transaction.
In Ethereum forensics, what does analyzing the 'internal transactions' (traces) reveal that standard transaction logs do not?
Answer: Value transfers triggered by smart contract execution
Internal transactions (message calls) capture ETH movements that occur within smart contract logic and are not recorded as top-level transactions.
A suspect uses a centralized mixer that pools funds from many users and redistributes equivalent amounts. Which forensic indicator most reliably links the deposit to the withdrawal?
Answer: Timing correlation and matched denomination amounts
Timing analysis combined with denomination matching is the strongest available signal when a mixer disrupts direct UTXO linkage between deposit and withdrawal.
What distinguishes a 'hot wallet' from a 'cold wallet' in the context of exchange forensics?
Answer: Hot wallets are internet-connected and used for daily operations; cold wallets are offline and hold reserves
Hot wallets remain online for operational liquidity, making them higher-risk targets, while cold wallets are air-gapped to protect bulk reserves.
Which blockchain data element would a forensic analyst primarily use to identify a 'dusting attack' victim?
Answer: Addresses that received tiny, unsolicited micro-transactions below the dust limit
Dusting attacks send sub-dust amounts to target addresses so that if the victim later co-spends the dust, the attacker can cluster and deanonymize their wallet.
When reconstructing a DeFi exploit on Ethereum, which tool provides the most granular trace of every internal call and state change during a specific transaction?
Answer: A transaction debugger/tracer such as Tenderly or Foundry's cast run
Debuggers like Tenderly replay transactions step-by-step, exposing every CALL, DELEGATECALL, and storage slot change that a receipt or basic explorer view omits.