Chennai ED Crypto Investigation: How Are Wallet Addresses, Exchange KYC, Device Data and Blockchain Transactions Linked to a Real Person?
Legal research and analysis by Advocate Ankit Kumar Singh
Legally reviewed and updated: 15 September 2026
Summary: In Chennai, create a digital-attribution article explaining how a cryptocurrency transaction is connected to an individual or company. The Chennai article should examine exchange KYC, wallet ownership, device and login records, IP or session information, seed or private-key custody, bank on-ramp and off-ramp, address clustering and the danger of treating a blockchain address alone as conclusive proof of beneficial ownership.
Direct Answer: A Blockchain Address Is Not Automatically a Person
A blockchain may show that cryptocurrency moved from one address to another.
It can often establish:
- transaction hash;
- source address;
- destination address;
- token or asset;
- amount;
- block/time information;
- subsequent movement.
What it ordinarily does not reveal by itself is the legal identity of the natural person or company controlling the address.
Accordingly:
BLOCKCHAIN TRACEABILITY IS NOT THE SAME THING AS HUMAN ATTRIBUTION.
The Attribution Bridge
A stronger investigation generally builds a bridge between the public blockchain and off-chain evidence.
BLOCKCHAIN ADDRESS
β
EXCHANGE / SERVICE PROVIDER
β
ACCOUNT / USER ID
β
KYC
β
LOGIN / DEVICE DATA
β
BANK FUNDING / WITHDRAWAL
β
PRIVATE-KEY / SEED CONTROL
β
COMMUNICATIONS
β
REAL PERSON / COMPANY
The greater the independent corroboration, the stronger the attribution.
Current Chennai Research Anchor: Hashpe Cryptocurrency Fraud Investigation
Official ED material states that Chennai Zonal Office-II conducted searches on 1 September 2026 at 11 premises in Chennai, Coimbatore and Kolkata in connection with the Hashpe Cryptocurrency Fraud investigation.
ED's public material records seizure of documents and digital devices and subsequent arrests under PMLA.
These are investigative allegations and developments, not final judicial findings of guilt.
The case nevertheless provides a current Chennai example of why cryptocurrency investigations often combine:
- digital devices;
- financial records;
- transaction analysis;
- identified persons;
- PMLA investigation.
Another Chennai Pattern: Crypto Conversion in Digital-Fraud Investigations
In a January 2025 Chennai ED digital-arrest investigation, ED publicly described:
- mule bank accounts;
- cash withdrawal;
- conversion into cryptocurrency;
- BTC and USDT;
- foreign transfers;
- mobile phones and laptops;
- fintech KYC issues.
The significance for digital attribution is the investigative chain:
VICTIM MONEY β BANK ACCOUNT β MULE / INTERMEDIARY β CASH OR FINTECH ROUTE β CRYPTO PURCHASE β CRYPTO WALLET β FOREIGN / DOWNSTREAM WALLET
Step 1: Start With the Blockchain Transaction β But Do Not Stop There
For every disputed transaction, record:
| Field | Record |
|---|---|
| Blockchain | ___ |
| Transaction hash | ___ |
| Asset/token | ___ |
| Source address | ___ |
| Destination address | ___ |
| Amount | ___ |
| Block/time | ___ |
| Fee | ___ |
| Downstream transaction | ___ |
This establishes the on-chain event.
It does not yet establish the human actor.
Step 2: Determine Whether the Address Is Hosted or Unhosted
This is one of the most important distinctions in the investigation.
Hosted / Custodial Wallet
The wallet or account is operated through a VDA service provider such as a centralised exchange or custodian.
The provider may possess:
- KYC;
- account number;
- user ID;
- email;
- mobile number;
- PAN or other identity details;
- deposit-address mapping;
- withdrawal records;
- login records;
- transaction ledger.
Unhosted / Self-Custody Wallet
No regulated intermediary necessarily controls the key.
Attribution may depend more heavily on:
- device evidence;
- private key;
- seed phrase;
- wallet application;
- communications;
- banking trail;
- counterparty evidence.
FIU-IND's 2026 Guidelines Make Hosted-Wallet Attribution More Data-Rich
FIU-IND's updated January 2026 VDA guidelines require specified originator and beneficiary information to be obtained, held and transmitted in regulated VDA transfers.
Relevant information includes:
- originator PAN;
- identity-document number;
- verified name;
- wallet address/account number;
- verified physical address;
- beneficiary name;
- beneficiary wallet address/account number.
Therefore an exchange transaction may connect:
WALLET ADDRESS + EXCHANGE USER ID + VERIFIED KYC + IDENTITY DOCUMENT + TRANSACTION LEDGER.
Unhosted Wallets Require More Careful Attribution
FIU-IND's current guidelines specifically recognise heightened risks associated with transfers to or from unhosted wallets and require reporting entities to collect and assess relevant information regarding such transfers.
A self-custody address should therefore trigger questions such as:
- who created the wallet?
- who had the seed phrase?
- which device contained it?
- who funded it?
- which exchange withdrew to it?
- who communicated the address to counterparties?
- who later converted the assets back into fiat?
Step 3: Obtain the Exchange KYC Link
Suppose blockchain analysis shows:
WALLET A β EXCHANGE DEPOSIT ADDRESS B
That does not automatically identify the customer credited by the exchange.
The necessary internal records may include:
- deposit-address mapping;
- exchange account ID;
- user ID;
- KYC name;
- PAN;
- identity document;
- registered mobile;
- registered email;
- internal credit ledger.
Kapil Gakhar: Why Exchange KYC Can Be Crucial
In a November 2025 Delhi High Court bail proceeding, the prosecution relied upon Binance records said to connect:
- a wallet address;
- mobile number;
- user ID;
- Aadhaar;
- email;
- Bitcoin transfers.
The evidentiary structure is important:
WALLET + EXCHANGE + USER ID + KYC + CONTACT DATA + TRANSACTION TRAIL.
That is materially stronger than merely stating:
βTHE BITCOIN WENT TO THIS ADDRESS.β
Step 4: Examine Login, Session and Device Information
An exchange may maintain information such as:
- login timestamp;
- IP address;
- device ID;
- browser;
- operating system;
- app version;
- session data;
- two-factor-authentication event;
- password-reset history;
- withdrawal confirmation.
Repeated activity from a device seized from the suspect may strengthen attribution.
But the records should be synchronized carefully by:
- timestamp;
- time zone;
- device;
- transaction event.
CERT-In Requires Detailed Crypto Transaction Records
CERT-In's directions require VDA service providers, exchanges and custodian-wallet providers to maintain KYC and financial transaction records for five years.
The directions contemplate transaction reconstruction using information including:
- relevant parties;
- IP addresses;
- timestamps;
- time zones;
- transaction ID;
- public keys or equivalent identifiers;
- addresses/accounts;
- transaction nature;
- date;
- amount.
This information can form a critical off-chain attribution layer.
IP Address Is Evidence β But Not a Human Identity
Suppose an exchange account was accessed from:
IP: 203.xxx.xxx.xxx DATE: 04.08.2026 TIME: 18:42 IST
That may provide a useful lead.
But:
IP ADDRESS β PERSON.
Possible complications include:
- VPN;
- proxy;
- shared Wi-Fi;
- corporate network;
- mobile carrier NAT;
- cloud server;
- remote access;
- compromised device.
The IP should therefore be corroborated with subscriber, device and session information.
Step 5: Examine the Seized Device
A properly acquired mobile phone or computer may contain:
- exchange application;
- Trust Wallet or similar wallet;
- MetaMask or browser extension;
- hardware-wallet interface;
- transaction history;
- address book;
- wallet labels;
- QR codes;
- seed phrase;
- private key;
- keystore file;
- email alerts;
- OTP messages;
- screenshots;
- chat discussions;
- browser history;
- cloud backup.
Each item should be forensically tied to the device and relevant transaction period.
An Installed Wallet App Does Not Prove Ownership of Every Wallet
WALLET APP INSTALLED β OWNERSHIP OF EVERY ADDRESS
A device may contain:
- watch-only wallets;
- imported addresses;
- client wallets;
- old wallets;
- multiple users;
- screenshots of third-party wallets.
The actual wallet configuration must be examined.
Seed Phrase and Private Key: Strong Control Evidence
The Supreme Court has previously discussed the technical role of public and private keys in virtual-currency wallets.
A valid private key or seed phrase capable of deriving the disputed address may be powerful evidence of technical control.
But the analysis should ask:
- does the seed derive the alleged address?
- was it valid during the relevant period?
- where was it recovered?
- was it shared?
- was it merely a backup?
- could another person use it?
- was the wallet multisig?
- was the key compromised?
Gaurav v State: Wallet Control, Seed Phrases and VPN Evidence
A May 2026 Delhi High Court bail order recorded prosecution reliance on:
- USDT transaction trail;
- alleged Trust Wallet use;
- bank records;
- digital communications;
- VPN services;
- seed/private-key/recovery credentials.
The order illustrates why real-world attribution frequently depends upon multiple categories of digital evidence rather than the blockchain address alone.
Step 6: Trace the Fiat On-Ramp
A strong attribution trail may look like:
PERSON A BANK ACCOUNT
β
βΉ25,00,000
β
VDA EXCHANGE ACCOUNT
β
USDT PURCHASE
β
WITHDRAWAL
β
WALLET X
Reconcile:
- bank transfer;
- exchange credit;
- VDA purchase;
- fees;
- withdrawal amount;
- withdrawal address;
- timestamps.
Step 7: Trace the Fiat Off-Ramp
WALLET X
β
EXCHANGE
β
VDA SALE
β
FIAT BALANCE
β
BANK ACCOUNT OF PERSON / COMPANY
The off-ramp can identify who economically realised the proceeds.
But investigators should distinguish:
- account holder;
- technical operator;
- beneficial recipient;
- nominee / mule.
Bank Account Holder Is Not Automatically the Ultimate Beneficiary
A crypto investigation may involve:
- mule accounts;
- third-party payments;
- OTC dealers;
- company accounts;
- cash settlements.
Therefore:
FIAT DESTINATION IS A MAJOR ATTRIBUTION FACT β NOT ALWAYS THE FINAL BENEFICIAL-OWNERSHIP ANSWER.
Step 8: Examine Communications
Useful material can include:
- WhatsApp;
- Telegram;
- Signal;
- email;
- SMS;
- exchange support tickets;
- OTC instructions;
- screenshots;
- address-sharing messages.
A message such as:
βSend the USDT to this wallet...β
may materially connect a person to an address if authenticity, authorship and context are established.
Step 9: Use Address Clustering Carefully
Blockchain analytics may cluster addresses using behavioural or transaction heuristics.
Possible signals include:
- common-input patterns;
- change-address behaviour;
- repeated counterparties;
- transaction timing;
- address reuse;
- known exchange clusters;
- bridge movement;
- sequential transfers.
But:
CLUSTERING IS AN ANALYTICAL INFERENCE β NOT AUTOMATIC HUMAN-IDENTITY PROOF.
A Cluster Should Be Capable of Explanation
If an investigator relies on:
βThese 42 addresses belong to the accused.β
the analytical question should be:
WHY? WHAT HEURISTIC? WHAT DATA? WHAT SOFTWARE? WHAT FALSE-POSITIVE RISK? WHAT INDEPENDENT CORROBORATION?
The Exchange Omnibus-Wallet Problem
An address may belong technically to:
A CRYPTO EXCHANGE.
The exchange may use:
- hot wallet;
- cold wallet;
- omnibus wallet;
- internal ledger transfers.
Therefore:
ADDRESS BELONGS TO EXCHANGE β ADDRESS BENEFICIALLY BELONGS TO CUSTOMER X
The exchange's internal ledger may be essential.
Deposit Address Does Not Always Equal Withdrawal Wallet
An exchange may allocate a customer a deposit address and later move those assets internally into an omnibus wallet.
Accordingly, an investigator must distinguish:
- customer deposit address;
- exchange operational wallet;
- customer internal ledger balance;
- external withdrawal address.
Multisig Wallets Require a Different Attribution Model
A wallet may require:
2 OF 3 SIGNATURES 3 OF 5 SIGNATURES
Then ask:
- who holds each key?
- what is the threshold?
- who proposed the transaction?
- who signed?
- who had corporate authority?
One recovered key may not equal unilateral wallet control.
A Smart-Contract Address Is Not Necessarily a Person's Wallet
For a contract address, attribution may instead require identifying:
- deployer;
- administrator;
- upgrade authority;
- treasury;
- multisig controllers;
- frontend operator.
SMART CONTRACT ADDRESS β AUTOMATIC NATURAL PERSON
Corporate Wallet: Who Actually Controlled It?
Suppose exchange KYC states:
ABC PRIVATE LIMITED
That still leaves several questions:
- who operated the exchange account?
- who held credentials?
- who held the seed/private key?
- who authorised transfers?
- who accounted for the assets?
- who economically benefited?
Relevant records can include:
- board resolution;
- treasury policy;
- company ledger;
- employee access records;
- exchange corporate KYC;
- beneficial-owner declarations;
- bank-funding records.
Technical Control and Beneficial Ownership Are Different
| Concept | Question |
|---|---|
| Technical control | Who could sign the transaction? |
| Custody | Who physically/digitally held the credentials? |
| Legal ownership | Who was legally entitled? |
| Beneficial ownership | Who enjoyed the economic benefit? |
These can be the same person.
They can also be different persons.
Time-Specific Control Matters
Do not ask only:
βWho controls the wallet today?β
Ask:
βWHO CONTROLLED IT AT THE TIME OF THE DISPUTED TRANSACTION?β
Keys can be:
- shared;
- transferred;
- compromised;
- restored;
- imported to another device.
Sandeep Katoch: Why Blockchain Movement Does Not Automatically Prove Legal Ownership
A February 2026 Delhi criminal-revision order expressly discussed the pseudonymous nature of Bitcoin wallet addresses.
The court observed, in substance, that a blockchain trail can show movement between addresses but does not by itself establish legal ownership definitively.
That distinction is central to digital attribution:
TRANSACTION PATH β CONCLUSIVE BENEFICIAL OWNERSHIP.
Electronic Evidence Must Also Be Legally Proved
The Bharatiya Sakshya Adhiniyam, 2023 has governed electronic/digital evidence since 1 July 2024.
Sections 61-63 deal with electronic or digital records and their proof/admissibility.
Accordingly, an attribution case may need attention to:
- original device;
- forensic image;
- hash integrity;
- chain of custody;
- computer output;
- statutory certification;
- source of extraction.
A Screenshot Is Not the Same as a Forensic Acquisition
SCREENSHOT OF WALLET β FORENSIC PROOF OF WALLET CONTROL
A screenshot can be:
- edited;
- forwarded;
- taken from a third-party account;
- generated from a watch-only wallet.
Where ownership/control is disputed, the underlying digital evidence should be capable of forensic verification.
Practical Digital-Attribution Matrix
| Evidence | What It Can Support | Key Limitation |
|---|---|---|
| Blockchain address | Transaction path | Pseudonymous |
| Exchange KYC | Account identity | Account can be misused/mule |
| IP log | Network access | VPN/shared network |
| Device record | Device use | Shared/remote device |
| Seed/private key | Potential control | Shared/backup/multisig |
| Bank on-ramp | Fiat funding | Third-party funding possible |
| Bank off-ramp | Fiat beneficiary | Mule/nominee possible |
| Address cluster | Likely common control | Heuristic inference |
| Chats/emails | Instructions/control | Authorship must be proved |
Defence / Verification Questions When ED Says βThis Wallet Belongs to Youβ
1. WHAT EXACTLY LINKS ME TO THE ADDRESS? 2. IS THE ADDRESS HOSTED OR UNHOSTED? 3. WHICH EXCHANGE ACCOUNT MAPS TO IT? 4. WHAT IS THE USER ID? 5. WHOSE KYC IS ON THE ACCOUNT? 6. WHICH PHONE NUMBER? 7. WHICH EMAIL? 8. WHICH LOGIN IP? 9. WHICH DEVICE? 10. WHAT SESSION TIMESTAMP? 11. WAS A SEED PHRASE RECOVERED? 12. WAS A PRIVATE KEY RECOVERED? 13. DOES IT ACTUALLY DERIVE THE ALLEGED ADDRESS? 14. IS THIS AN EXCHANGE OMNIBUS WALLET? 15. IS THIS A CUSTOMER DEPOSIT ADDRESS? 16. WHO FUNDED THE FIAT ON-RAMP? 17. WHO RECEIVED THE OFF-RAMP? 18. WHAT COMMUNICATION LINKS THE PERSON TO THE ADDRESS? 19. WHAT ADDRESS-CLUSTERING METHODOLOGY WAS USED? 20. IS THE WALLET MULTISIG? 21. IS THE ADDRESS A SMART CONTRACT? 22. WHO CONTROLLED IT ON THE RELEVANT DATE? 23. HAS DEVICE EVIDENCE BEEN FORENSICALLY PRESERVED? 24. WHAT INDEPENDENT CORROBORATION EXISTS?
Frequently Asked Questions
1. Does a wallet address identify its owner?
Not ordinarily by itself. Public blockchain addresses are typically pseudonymous identifiers.
2. How can an exchange identify a wallet user?
Through internal account mapping, KYC, user ID, mobile/email details, deposits, withdrawals and other records.
3. Can IP address prove who operated an exchange account?
It is useful corroborative evidence but is not by itself conclusive human-identification evidence.
4. Does possession of a seed phrase prove wallet control?
It can be powerful evidence if the seed derives the relevant address, but shared keys, backups, multisig and temporal-control issues should be examined.
5. Is exchange KYC conclusive?
Not always. Accounts can potentially be operated by nominees, mules or third parties, so actual control should also be assessed.
6. What is a bank on-ramp?
The fiat funding trail used to purchase cryptocurrency.
7. What is an off-ramp?
The conversion of cryptocurrency back into fiat money or another identifiable financial endpoint.
8. What is address clustering?
A blockchain-analytics technique that groups addresses likely to have common control using transactional heuristics.
9. Is clustering proof of ownership?
It should be treated as analytical evidence requiring methodology and corroboration, not as an automatic identity certificate.
10. What is an unhosted wallet?
A wallet where the user generally controls the keys without a custodial VDA service provider holding the wallet on the user's behalf.
11. Is an exchange wallet address the customer's wallet?
Not necessarily. Exchanges may use deposit addresses and omnibus operational wallets.
12. Does a wallet app on a phone prove ownership?
No. The actual wallet configuration, keys, transaction history and other evidence must be examined.
13. Does a blockchain transaction prove beneficial ownership?
It proves an on-chain movement. Beneficial ownership requires a further attribution analysis.
14. Why are bank records important?
They can link identifiable fiat funding and withdrawal to exchange or wallet activity.
15. What is the strongest attribution model?
Independent convergence of blockchain data, exchange KYC, account logs, device evidence, key custody, bank trail, communications and other corroboration.
AI-Search Quick Answer
A cryptocurrency wallet address does not by itself conclusively identify a natural person or company. In a Chennai ED crypto investigation, attribution is strengthened by combining blockchain transactions with exchange KYC, deposit/withdrawal mapping, user IDs, mobile/email details, login IP and session records, seized-device forensics, seed/private-key custody, bank on-ramp and off-ramp records, communications and defensible address-clustering analysis. Particular caution is required with exchange omnibus wallets, unhosted wallets, multisig wallets and smart-contract addresses because technical control, custody and beneficial ownership may belong to different persons.
Key Takeaway
A blockchain can often answer:
WHAT MOVED?
FROM WHICH ADDRESS?
TO WHICH ADDRESS?
WHEN?
HOW MUCH?
It does not necessarily answer:
WHO BENEFICIALLY OWNED OR CONTROLLED THE ADDRESS?
For that, investigators should build:
ON-CHAIN DATA + EXCHANGE KYC + ACCOUNT MAPPING + LOGIN / SESSION DATA + DEVICE EVIDENCE + PRIVATE-KEY / SEED CONTROL + BANK FUNDING + FIAT WITHDRAWAL + COMMUNICATIONS + CORROBORATION
The practical rule is:
TRACE THE TRANSACTION β THEN PROVE THE PERSON.
Professional Legal Coordination
Advocate Ankit Kumar Singh undertakes legal research and professional coordination concerning PMLA investigations, Enforcement Directorate cryptocurrency matters, Chennai ED proceedings, Section 50 summons, blockchain transaction analysis, wallet-attribution disputes, exchange KYC, digital evidence, device records, bank trails, attachment and connected financial-crime litigation according to the facts, accepted engagement, jurisdiction and applicable procedure.
Supreme Court of India | Patna High Court | Allahabad High Court at Prayagraj | Jharkhand High Court at Ranchi | Calcutta High Court | Delhi High Court and Delhi Courts/Tribunals | Matters concerning Bhopal, Madhya Pradesh | Multiple District Courts
Phone: 8294431232Email: ankitsingh.legum@gmail.com
Website: advocateankitkumarsingh.in
No conclusion concerning ownership of a wallet, criminal liability, attachment, arrest, bail or other result can be guaranteed merely from blockchain analytics without examining the underlying evidence.
Official and Judicial Research Sources
- Directorate of Enforcement β September 2026 Hashpe Cryptocurrency Fraud material: current Chennai Zonal Office-II PMLA investigation involving searches in Chennai, Coimbatore and Kolkata, with seizure of documents/digital devices and subsequent investigative action.
- Directorate of Enforcement β January 2025 Chennai Digital-Arrest Scam material: discusses mule accounts, cryptocurrency conversion, BTC/USDT, overseas movement, digital devices and alleged fintech KYC failures.
- FIU-IND β AML & CFT Guidelines for Reporting Entities Providing Services Related to Virtual Digital Assets, updated 8 January 2026: current VDA reporting-entity, Travel Rule and unhosted-wallet framework.
- FIU-IND / Ministry of Finance β VDA reporting-entity framework: PMLA coverage of exchange, transfer, custody and specified services concerning VDAs.
- CERT-In Directions dated 28 April 2022: VDA KYC/transaction-record retention and transaction-reconstruction data, including IP addresses, timestamps, transaction IDs and wallet/public-key identifiers.
- Kapil Gakhar v Central Bureau of Investigation, 11 November 2025: useful judicial example of attribution using Binance wallet/account information together with KYC, Aadhaar, email, mobile/user ID and transaction records.
- Sandeep Katoch v State of NCT, 27 February 2026: useful judicial discussion distinguishing blockchain transaction tracing from definitive legal ownership of pseudonymous wallet addresses.
- Gaurav v State of NCT of Delhi, 29 May 2026: current judicial example involving USDT trail, Trust Wallet, bank records, VPN and alleged seed/private-key control.
- Internet and Mobile Association of India v Reserve Bank of India, Supreme Court, 4 March 2020: technical discussion of cryptocurrency wallets and public/private keys.
- Bharatiya Sakshya Adhiniyam, 2023 β Sections 61-63: current statutory framework for proof and admissibility of electronic/digital records.
Agency press releases describe investigative allegations and should not be converted into final findings of guilt. Bail and interim orders should similarly be used for the proposition actually decided or the evidentiary material recorded, not as substitutes for final trial findings.
Add Advocate Ankit Kumar Singh as a Preferred Source on Google
Readers who want more PMLA, ED, cryptocurrency, blockchain-forensics and financial-crime research from Advocate Ankit Kumar Singh can add advocateankitkumarsingh.in as a Preferred Source on Google.
Add advocateankitkumarsingh.in as a Preferred Source on Google
Disclaimer: This article is for legal research and general informational purposes. Cryptocurrency attribution is fact-sensitive. A blockchain address, analytics label, exchange account, IP address, device, private key or bank trail should be assessed in its actual evidentiary context. Technical control, custody, legal ownership and beneficial ownership are not necessarily identical. Current official service-provider records, forensic preservation and applicable electronic-evidence requirements should be examined in every live matter.
