Crypto transfers can be hard to understand when they are just a list of numbers and addresses. This demo turns one real, saved USDT case into a picture you can explore. USDT is a cryptocurrency, and an address is where it can be sent or received.
Click an address to see its transfers, open the supporting transaction details, and read the investigation report. The goal is to show what happened, what might explain it, and what we still do not know.
When would I use this?
Use it to learn how an analyst follows crypto transaction evidence.
Use it to review a concrete example of investigative reasoning.
No setup needed: the example is already loaded.
This is one saved case, not a live search tool. Connections and similar transfer amounts do not prove wrongdoing or identify the people involved.
ETHEREUM MAINNET · SAVED NODE EVIDENCE
USDT investigation demo
Brandon Candela · AML investigation work sample. Explore 15 addresses from a saved public Ethereum case. No installation or wallet connection required.
Arrows show recorded sender → recipient. Click a node to filter transfers. This graph is a two-hop relationship view, not a claim that the same funds moved along every edge.
Step through recorded events in order. Playback timing is illustrative, not real elapsed time.
Case scope & findings
An address is not a person. Activity patterns alone do not establish wrongdoing, common control, or USD conversion inside an exchange.
Transfer evidence
UTC / block
Sender
Recipient
USDT
Transaction / log
Select a transaction for full evidence details.
Provenance & limits
This demo uses a fixed saved case, not live monitoring or arbitrary-wallet tracing. Evidence checks run when the demo is built; your browser loads the resulting case. Raw JSON-RPC requests and responses are saved in the GitHub repository under data/raw. SHA-256 checks detect local changes against the manifest; they are not independent proof of blockchain inclusion. Block hashes are checked against the saved node responses. The node remains a trusted data source.