Ethereum threat attribution

A framework for finding the crypto wallets of threat actors, criminal groups and terror-financing networks.

Pusula learns a group's laundering pattern from its known wallets and trains a detector for it in minutes, starting with Lazarus Group.

Featured attribution 0x57210832aa7e…5717c3b08e Risk score
99.99/100
Attributed to
Lazarus Group
Wallets traced
489
Analysed
6 days ago
Open the full report

How Pusula works

Every analysis follows the same five steps, and a new group only needs its own trained detector.

One analysis from start to finish

  1. 01

    Enter an address

    An investigator enters a suspicious Ethereum address.

  2. 02

    Trace the network

    Pusula traces the wallet's transactions hop by hop.

  3. 03

    Measure behaviour

    It measures 116 behavioural features of the network.

  4. 04

    Score with the detector

    The group's detector, a VAE, scores the wallet.

  5. 05

    Attribute the wallet

    The wallet is attributed to the group with a risk score.

Research

Have an address to check?

Accounts are issued on application to investigators, compliance teams and researchers.