A cluster is a group of blockchain addresses judged to be under the same control and treated as one party for screening purposes. Services generate addresses constantly — a fresh deposit address per customer, a fresh change address per transaction — so one address is rarely the whole picture. Clustering is what lets a name attach to more than one address at a time.
A counterparty who sends you funds from a brand-new address has, on paper, no history at all. Checked in isolation, that address returns nothing, and nothing is easy to mistake for clean.
Clustering is what closes that gap. If the new address belongs to a group already associated with a party, the check speaks about the party rather than about the string you were given. That is also how a payout to a "different wallet" gets recognised as the same customer, and how thousands of deposit addresses resolve to one venue.
The behaviour is normal, not evasive. Bitcoin wallets create a change address on almost every spend, exchanges issue a private deposit address to each customer, and merchants rotate settlement addresses as a matter of routine. Reading a single address as a whole identity would misjudge nearly every party you deal with.
The result speaks about the party behind the address where a grouping is known: the entity name, its category, and what the party's funds are connected to. Where the grouping is an inference from on-chain behaviour rather than a documented attribution, that difference matters — a documented, published attribution is a stronger claim than a behavioural grouping, and a result should let you tell them apart before you act on one.
In the Telegram bot the answer arrives in seconds, free, three checks a day. In the workspace the party is a case with a history and a watchlist entry, so the next address from the same counterparty is recognised rather than re-investigated.
At industry level, from publicly visible behaviour: addresses spent together in one transaction are normally controlled by the same signer, and services follow recognisable patterns of sweeping and change. Different tools reach different groupings, so the strength of a cluster claim matters as much as its existence.
Yes. A grouping is an inference about control, and inferences are wrong sometimes. That is why a documented attribution and a behavioural grouping should be recorded as different kinds of evidence.
No. A wallet is software holding keys; a cluster is a conclusion about which addresses one party controls. They often coincide, and when they do not, the cluster is the one that matters for screening.
Also available in: · · ·
Because it has been grouped with addresses you or your wallet used before. The history is not the new address's own; it belongs to the party the address is attributed to.
Send any wallet to the Telegram bot and get a verdict in seconds. Three checks a day, free, no signup. Desks that screen every deposit run it on plans from $199/mo.