Why
The stated purpose of the operation is the finding. It was not run to detect anything — the crypto intelligence already existed, and the operation's job was to convert it into leads investigators could act on. That sentence locates the bottleneck precisely, and it is not where most people assume. On-chain analysis was never the scarce part. The transaction graph is public, permanent and complete; anyone can trace flows between addresses and cluster them. What the graph never contains, at any depth of analysis, is a name.
So the operation was a join, and the join key lives off-chain. An address becomes a person only where the chain touches an intermediary that performed identity verification — an exchange, a payment platform. That is why the participant list matters more than the tooling: 9+ agencies for legal authority and 13+ private firms because the identity half is theirs, held in systems that compete with each other. Getting Binance, Coinbase and Block to contribute against the same address set, in one place, over several days, is an organisational achievement, not a technical one. Chainalysis says it intends to reuse that model for other crime types, which is the honest description of what was actually built.
The distribution of the numbers says the same thing again. 125 countries and 100+ platforms across clear and dark web on one side; 16 confirmed registered offenders on the other. The wide numbers describe the graph, which is easy to see. The narrow number describes identification, which requires the join. The ratio between them is the price of the missing key.
And this catalogue has already asked the constructive version of the question. what-encryption-does-not-hide studies computing over data that cannot leave its owner, and what-encryption-does-not-hide asks which parties see which fields. Put those next to a fusion operation and a real question appears: how much of this join could be done without anyone pooling raw identity data — private set intersection over address lists, clean-room queries answering does this address match a verified account at your institution without disclosing the account. Not a criticism of the operation, which used what exists. A statement of what the technique would have to become to run without a room.
How it works
The funnel, and where it stops
| Step | Published | What the step requires |
|---|---|---|
| Addresses and identifiers examined | 29,120 | On-chain analysis — public data, no permission needed |
| Investigative leads produced | 14,300 | Enrichment and correlation across months of prior work |
| Suspect accounts identified | 7,700+ | The join — only exchanges and payment platforms can supply it |
| Registered offenders confirmed | 16 | Cross-reference against an external registry |
| Arrests, prosecutions, sanctions | not yet published | Courts and jurisdictions — 125 of them are in scope |
Every published figure sits upstream of the one that decides whether the operation worked. That is not concealment: the outcomes genuinely have not happened yet, and Chainalysis says it will share them as they arrive. It does mean the honest reading of the announcement today is a pipeline was built and filled, not a result was achieved — and the follow-up worth diarising is whether the bottom row ever gets a number.
Why the participant list is the artifact
| Contribution | Who supplied it | Why it cannot come from elsewhere |
|---|---|---|
| Transaction graph, clustering | Chainalysis | Public data — the one part anyone could reproduce |
| Identity behind an account | Binance, Coinbase, Block | Held under KYC obligations, in competing systems |
| Legal authority to act | Europol, AFP, RCMP, NCA | Jurisdictional, and there are 125 jurisdictions here |
| Content classification | IWF and specialist non-profits | Neither exchanges nor analysts are positioned to do it |
| The room itself | NCFTA | Somewhere all of the above can sit together lawfully |
The question this catalogue can actually work on
How much of the join survives without pooling? The operation's shape — bring every holder of a fragment into one room — is the version available today. The version worth studying is whether the same answer can be reached by parties who never exchange raw records: private set intersection over address lists, or a clean-room query returning matched / not matched against a verified-account set without revealing the account. what-encryption-does-not-hide is where the technique lives; this is a concrete problem to point it at, with a public funnel to measure any proposal against.
Reading it soberly
The subject is the most serious one this catalogue touches, and the discipline is unchanged: report only the published numbers, mark the step that has none, and do not treat leads as outcomes. The Korean note in the announcement — that these cases keep arising domestically and that blockchain intelligence will be offered to support investigations — is a statement of intent, and belongs in the same column as everything else that has not happened yet.
Where it lands in Jayverse
- Verex: treat Stripe onboarding as the actual identity join. Log which addresses were bound to a verified identity, when, and by which check, since the chain itself never carries a name and Verex's onboarding is the one place it does.
- Wallet + Verex: don't pool the join across services by default. When Wallet addresses need to be checked against Verex's verified accounts, prefer a match/no-match query over sharing raw KYC records between the two repos.
- Auditor: record the join, not just the transaction. The methodology doc should name which identity provider verified which account for a given resolution or dispute, mirroring the operation's own finding that the participant list is the real artifact.
Key expressions
| Expression | 뜻 · 쓰이는 자리 |
|---|---|
| join | (서로 다른 데이터를) 연결·결합하는 것 · 온체인 주소와 오프체인 신원을 잇는 작업. "the join between an on-chain address and an off-chain identity" |
| convert into | ~로 전환하다, 바꿔놓다 · 기존 정보를 실행 가능한 단서로 만드는 과정. "convert it into leads investigators could act on" |
| clean-room query | 원본을 노출하지 않고 격리된 방식으로 하는 조회 · 신원 정보를 직접 공유하지 않고 대조만 하는 기법. "a clean-room query returning matched / not matched" |
| private set intersection | 두 집합의 교집합만 확인하고 나머지는 공개하지 않는 기법 · 신원 데이터를 직접 넘기지 않고 대조할 때. "private set intersection over address lists" |
| cross-reference against | ~와 대조·교차 확인하다 · 확보한 명단을 외부 등록부와 비교할 때. "Cross-reference against an external registry" |
| sit upstream of | (프로세스상) ~보다 앞단에 위치하다 · 발표된 숫자들이 아직 결과가 아닌 중간 단계임을 말할 때. "sits upstream of the one that decides" |
| in scope | (적용) 범위 안에 포함된 · 관할권이나 국가 수를 셀 때. "125 of them are in scope" |
| belong in the same column as | ~와 같은 취급을 받아야 하다 · 아직 실현되지 않은 항목들을 한데 묶을 때. "belongs in the same column as everything else" |
| diarise | (나중에 확인하려고) 메모·일정에 적어두다 · 앞으로 지켜볼 후속 사항을 표시할 때. "the follow-up worth diarising" |
| held under [obligations] | ~라는 의무 하에 보관·관리되다 · 신원 정보가 규제 의무 아래 잠겨있는 상황. "Held under KYC obligations" |
| NCFTA | 국가 사이버포렌식 훈련 연합(National Cyber-Forensics and Training Alliance) · 여러 기관이 모여 작전을 수행한 물리적 거점. "held at the NCFTA in New York" |
| AFP | 호주연방경찰(Australian Federal Police) · 작전에 참여한 법 집행기관 중 하나. "the Australian Federal Police" |
| RCMP | 캐나다 왕립기마경찰(Royal Canadian Mounted Police) · 작전에 참여한 캐나다 측 법 집행기관. "the RCMP, the UK National Crime Agency" |
| NCA | 영국 국가범죄청(UK National Crime Agency) · 작전에 참여한 영국 측 법 집행기관. "the UK National Crime Agency" |
| IWF | 인터넷 감시재단(Internet Watch Foundation) · 콘텐츠 분류를 담당한 비영리 참여기관. "the Internet Watch Foundation" |
| Chainalysis | 온체인 분석 전문 기업(blockchain analytics firm) · 이번 다기관 작전을 주도한 주체. "Chainalysis ran a multi-agency operation" |