Aller au contenu
Accueil Seqlense DOC Seqlense Web3 Monitoring Seqlense Notes Seqlense IMMO Investigation crypto Investigation OSINT Formation & conseil Tarifs Blockchains supportées Academy Blog Partenaires Contact
EN FR DE
Mon Seqlense Commencer
Back to blog

OSINT for compliance: enriching an investigation beyond the chain

Where public sources add the context a blockchain alone cannot.

A blockchain tells you what moved, when, and between which addresses. It rarely tells you who was behind the keyboard, why the transaction happened, or whether the counterparty is the sanctioned entity your alert flagged. That gap is where open source intelligence (OSINT) earns its place in a compliance investigation. Used well, public sources turn a cluster of hexadecimal addresses into a defensible narrative that a regulator, a bank partner, or a court can follow.


What the chain shows and what it hides

On-chain data is precise but shallow. You can trace a flow of funds across wallets, spot peel chains, and measure exposure to a mixer or a high-risk exchange. What the ledger will not give you is attribution: the real-world identity, the business context, the intent.

A typical investigation stalls at questions like these:

  • Whose wallet is this, and does it belong to a person, a shell company, or a service?
  • Is the counterparty a registered VASP, an unlicensed operator, or a scam front?
  • Does the transaction pattern match a legitimate business model or launder proceeds?
  • Are there earlier red flags (litigation, adverse media, a prior enforcement action) that reframe the risk?

None of these live on the chain. They live in public records, corporate registries, court filings, forums, social media, archived websites, and the regulators' own publications. OSINT is the discipline of collecting and verifying that publicly available information in a structured, repeatable way.


Where OSINT adds the missing context

Think of enrichment in layers, each answering a question the chain cannot.

Identity and entity resolution. Company registries, beneficial ownership data, and business filings connect a trading name or a domain to real people and jurisdictions. A wallet labelled only as "exchange deposit" becomes a named platform with a known licensing status once you pin down the operating entity.

Counterparty and licensing status. Before you treat a counterparty as a regulated VASP, confirm it. National registers, warning lists, and regulator publications tell you whether a platform is authorised, blacklisted, or simply unknown. Under the FATF standard often called the travel rule, transfers between virtual asset service providers are supposed to carry originator and beneficiary information, so knowing who is actually on the other side is not optional.

Reputation and adverse media. News archives, sanctions and enforcement notices, and specialist reporting surface prior fraud, insolvency, or criminal association. A single credible adverse-media hit can move a case from routine monitoring to enhanced due diligence.

Technical footprint. Domains, wallet addresses posted publicly, scam-report databases, breach data, and social profiles help link a suspect address to a campaign, a phishing kit, or a known threat actor. Attribution rarely comes from one source; it comes from several weak signals that agree.

Behavioural and contextual signals. Public forums, Telegram and X posts, job ads, and archived pages (via web archives) reveal how an operation presented itself over time, which is often the difference between a genuine business and a facade.


Turning fragments into a defensible finding

OSINT is only as good as its method. Three habits separate a usable investigation from a pile of screenshots.

  1. Corroborate before you conclude. Treat any single source as a lead, not a fact. Two or three independent sources that agree carry weight; one anonymous claim does not.
  2. Preserve provenance. Record the URL, the capture date, and ideally an archived copy of every source. If a page disappears or is edited, your finding must still stand on its own.
  3. Weigh the source. A national regulator's warning list is not the same as an unattributed forum post. Grade reliability explicitly so a reviewer can see how you reached your conclusion.

A short reliability note in the case file goes a long way:

Source type Typical reliability Use
Regulator register or warning list High Confirm licensing, sanctions, enforcement
Corporate registry or court filing High Identity, ownership, jurisdiction
Established specialist press Medium to high Adverse media, context
Social media, forums, chat groups Low to medium Leads, behavioural context

For EU teams, OSINT is not a licence to collect everything. You are still processing personal data, so GDPR principles apply: a lawful basis, data minimisation, purpose limitation, and retention limits. Scraping behind logins, using deceptive access, or hoarding personal data "just in case" creates its own compliance risk. The safe posture is narrow, documented collection tied to a specific investigative purpose, with sources you could show a supervisor without embarrassment.


Bringing it together with your on-chain workflow

The strongest investigations run the two tracks in parallel: on-chain analytics to establish the flow of funds, and OSINT to attribute and contextualise it. One without the other is either a graph with no names or a story with no evidence.

This is where a suite that keeps both sides in one place helps. Seqlense pairs blockchain address monitoring and risk scoring in Monitoring with an Investigation service and OSINT support, while its Doc module lets you check a counterparty against publications from roughly 85 European regulators using simple filters such as doctype:sanction or doctype:communique. The point is not more tooling for its own sake; it is closing the distance between what the chain shows and what your file needs to prove.


Sources

Related articles

Writing effective regulatory-watch queries: a SEQQL primer

Getting precise results from source, doctype and language filters.

Building a vendor register your DPO can defend

Purposes, categories and the discipline that makes a register hold up.