Machine learning is a useful tool for blockchain analysis, if used responsibly. Automated tools are able to quickly scan enormous arrays of data directly from the blockchain and find patterns that an analyst might miss — if they even managed to review such a volume of information manually at all. When applied sensibly, machine learning plays an important supporting role in working with blockchain data.
However, every provider of such analytical solutions faces one fundamental question: where is the boundary of the acceptable use of machine learning? If ML results are automatically taken as established truth, this can reduce the value of all blockchain analytics. For example, a predictive model may wrongly assume that several cryptocurrency addresses belong to one organization, and thus feed erroneous data into the system.
Nevertheless, machine learning has serious potential to help with the collection and analysis of information. If the results obtained with ML are clearly labeled as probabilistic estimates that require additional verification, they can be used to guide the analysis without distorting its results.
Where machine learning is applied in analytical work
Machine learning is not used to determine cryptocurrency wallet segments. However, it can be selectively applied in other important and significant areas of analytical work.
As explained in a study on the ontology of blockchain analytics, the concept usually called a «cluster» actually includes three different analytical statements. The first is structural: which addresses are controlled by the same key. The second is attributional: which specific organization or person a particular address belongs to. The third is operator-related: what relationships exist between that organization or person and a specific address.
Wallet segments belong to the structural category. These are first-level analytical statements that must be deterministic, reproducible and verifiable, and must also have an understood-in-advance model of possible errors. This is what can be called the standard of structural reliability.
Predictive models should not be used to determine wallet segments, because machine learning is not able to meet this standard of structural reliability. And the point here is not the accuracy of such models. Even a perfectly accurate predictive model still would not meet this standard. Its decision-making logic is formed on the basis of data, not derived from specific rules that can be verified and reproduced. If the training data changes, the rules by which the model works may change too, which means its conclusions may change as well.
Instead, machine learning can be used as one of many tools for forming second-level analytical conclusions. These include the search for potentially significant objects for further investigation, evidence-based classification of categories, anomaly detection and pattern recognition. Such signals can be useful for guiding an investigation and determining which data requires additional verification.
Artificial intelligence and machine learning can also be used to strengthen tools for detecting and disrupting fraudulent schemes. Such systems are able to continuously learn from data from the internet, chat correspondence and blockchain activity in order to identify new and evolving fraud schemes.
Why this matters in court: the Daubert standard
In one US criminal case, the defense challenged a blockchain-analytics methodology, arguing that it was insufficient and contained significant flaws. The court, however, concluded that the approach used to form groups of linked addresses was well-founded. An important role in this conclusion was played by the court's ability to examine the methodology for building such groups and to verify that the logic of the analysis was transparent enough for independent verification.
Thus, the court decision confirmed a specific methodology based on deterministic and reproducible rules with documented error-protection mechanisms. It did not mean that blockchain analytics as an entire category of methods is automatically considered reliable.
An approach based largely on machine learning may face serious difficulties when tested against the Daubert standard. If the provider of an analytical system is unable to explain how a group of addresses was formed, what evidence supports the label assigned to it, or why the model reached a specific conclusion, such a methodology may not withstand scrutiny in a hearing under Rule 702 of the US Federal Rules of Evidence. The consequences of this can be serious for investigations, prosecutions and corporate compliance programs.
Practical consequences
Incorrectly formed wallet segments can affect decisions on which real people and real investigations depend.
For law enforcement, an erroneous segment can send an investigation down a false trail. For example, investigators may spend months on a suspect based on a link between wallets that does not actually exist, or send legal requests to the wrong cryptocurrency exchanges. In some cases, erroneous searches may even be carried out on the basis of insufficient evidence. In complex investigations spanning several jurisdictions, a single incorrect initial signal may be enough to seriously slow an investigation down or lead it into a dead end.
For compliance specialists, the consequences can be no less serious. A false match linking a client's wallet to a sanctioned organization or person can lead to the closure of an account, the freezing of funds and the filing of a suspicious activity report to regulators. As a result, a client may lose access to financial services because of a link that in reality never existed.
For prosecutors, a wallet segment that does not withstand careful scrutiny can destroy an entire case. Defense attorneys will scrutinize the methodology on the basis of which each claimed link between cryptocurrency addresses was established.
Cases built on unexplained machine-learning results may be dismissed or create a legal precedent that later casts doubt on other criminal cases based on blockchain evidence.
