Bitcoin Forensics
The views expressed in this
presentation are Mere Apne.
Reference to any specific products,
process ,or service do not
necessarily constitute or imply
endorsement, recommendation, or
views of Min of Def or any Govt
All images used are for illustrative
purposes only & Do not
promote any specific product
Bitcoin Forensics
Bitcoin Forensics
Bitcoin Forensics
Bitcoin Forensics
Bitcoin Forensics
OVERVIEW
WHY,HOW,WHERE
WHO’S WHO?
TECHNOLOGY
CASE STUDY
JAI HINDH
SUMMARY
Bitcoin Forensics
Bitcoin Forensics
Name used by the unknown person
or persons who designed BITCOIN
and created its original reference
implementation
SATOSHI NAKAMOTO
Kahan Gaya Usay Dhoondo
Bitcoin Forensics
AS OF 17TH FEB 2017
1 BITCOIN IS WORTH
1040$
SO 1 BITCOIN IS
70103
THE LAST BITCOIN
(PROBABLY 21 MILLIONTH COIN)
WILL BE MINED IN THE YEAR
2140
Bitcoin Forensics
Bitcoin Forensics
ANONYMITY
VS
PSEUDONYMITY
Mark TwainSamuel Clemens
Bitcoin Forensics
CRYPTOCURRENCY IS AN ATTEMPT
TO BRING BACK A DECENTRALISED
CURRENCY OF PEOPLE, ONE THAT IS NOT
SUBJECT TO INFLATIONARY MOVES BY
A CENTRAL BANK
Bitcoin Forensics
Bitcoin Forensics
Distributed Ledger is a Consensus of
Replicated, Shared & Synchronized
digital data geographically spread across
multiple sites & countries
Type of Distributed Ledger, comprised
of Unchangeable, Digitally
Recorded Data in packages called
BLOCKS
TAMPER EVIDENT LEDGER
Bitcoin Forensics
https://anders.com/blockchain/
BASICALLY CHUNKS OF INFO
THAT CAN BE USED TO
MATHEMATICAL
GUARANTEE ABOUT MESSAGES
Peer-to-
Peer (P2P)
network is
created when
two or
more PCs are
connected &
share
resources
without
going through a
separate
server
computer
Bitcoin Forensics
Bitcoin Forensics
Bitcoin Forensics
“शरीर में 206 हड्डिय ां
है, और सांविध न में
1670 क नून ... हड्िी
से लेकर क नून सब
तोड़त हूूँ….”
SHA तोड़ के
दिख ….
Bitcoin Forensics
Bitcoin Forensics
BITCOIN MINING
Bitcoin Forensics
MERKLE TREE
Bitcoin Forensics
A user for CONDUCTING
TRANSACTIONS utilizing BITCOIN,
he or she must first DOWNLOAD and
setup a BITCOIN WALLET
BITCOIN WALLET can show the
total BALANCE of all BITCOINS it
CONTROLS and let A USER PAY a
specified AMOUNT
WALLET contains a USER’S
PRIVATE KEY, which ALLOWS
FOR THE SPENDING of the
BITCOINS, which are located in
the BLOCK CHAIN
Once wallet is INSTALLED &
CONFIGURED, an ADDRESS
is GENERATED which is
SIMILAR to an E-MAIL or
PHYSICAL ADDRESS
WALLET is basically
the Bitcoin Equivalent
of a Bank account.
Allows to RECEIVE BITCOINS,
STORE them, and then SEND
them to others
Connected to the Internet
or is online is said to be HOT
Cold Wallets & Hot Wallets
Cold is considered
most Secure &
suitable for Storing
Large Amounts of
bitcoins
Hot is suitable for
Frequently
Accessed funds
COLD implies it is Offline or
Disconnected from the
Internet
Designedto be downloaded
& used on Laptops/PCs
DESKTOPWALLETS
Armory, Multibit, Msigna
and Hiveto mention a FEW
Easyto Access.
Available for Different OS
– Windows, Mac OS and Ubuntu.
MOBILEWALLETS
ONLINEWEBWALLETS
PHYSICALWALLETS
Once they are generated, you
print them out on a piece of
paper
Paper Wallets can
Securely hold your BITCOINS
in Cold Storage form for a
long time
Bitaddress.org
or Blockchain.info
BitcoinQt is the First ever built
bitcoin CLIENT WALLET
BITCOINCLIENTS
WALLETS
Original bitcoin
wallet used by the
Pioneers of the
currency
COMPUTERS installed with these wallets
FORM PART OF THE CORE
NETWORK & have access to all
transactions on the blockchain
HARDWAREWALLETS
Bitcoin Forensics
Bitcoin Forensics
BITCOIN ARTIFACTS
They DON’T EXIST
ANYWHERE, even
on a hard drive
When we say SOMEONE HAS
BITCOINS & you look at a
PARTICULAR BITCOIN ADDRESS,
there are NO DIGITAL BITCOINS held
AGAINST that ADDRESS
BALANCE of any BITCOIN
address ISN’T HELD at that
ADDRESS; one MUST
RECONSTRUCT it by looking at
the BLOCKCHAIN
Everyone on the NETWORK knows about a
TRANSACTION and THE HISTORY
OF A TRANSACTION can be TRACED
BACK to the point where the BITCOINS
were produced
Conduct a
SEARCH based
on BLOCK
NUMBER,
ADDRESS,
BLOCK HASH,
TRANSACTION
HASH or
PUBLIC KEY
Bitcoin Forensics
Bitcoin Forensics
BITCOIN-QT FOLDER STRUCTURE
BITCOIN-QT FOLDER STRUCTURE
Blocks – This subdirectory contains blockchain data and
contains a “blk.dat” file and a “blocks/index”
subdirectory.
“blk.dat” stores actual Bitcoin blocks dumped
in raw format.
The “blocks/index subdirectory” is a database
that contains metadata about all known blocks
Chainstate subdirectory- it is a
database with a compact
representation of all currently unspent
transactions and some metadata about
where the transactions originated
BITCOIN-QT FOLDER STRUCTURE
Database subdirectory -
Contains database journaling
files (Data Directory,
BITCOIN-QT FOLDER STRUCTURE
LOCK FILE
DEBUG.LOG
PEERS.DAT
WALLET.DAT
BITCOIN-QT FOLDER STRUCTURE
DB LOCK FILE
EXTENSIVE LOGGING
FILE
PEER INFORMATION
STORAGE FOR
KEYS,TXN,METADATA
etc
Private key of the suspect, they can
search for that particular key on the
Blockchain to Trace the purchases
to other potential Suspects.
investigator has the Bitcoin
Bitcoin Forensics
BITCOIN FORENSIC ARTIFACT EXAMINATION
Windows 7 Professional
Multibit
Bitcoin-Qt
Bitminter
Basic USB ASIC Bitcoin
Gateway laptop ML6720
120 GB WD hard drive
(4) USB ASIC Mining
drives
USB powered cooling fan
32 GB USB thumb drive
Bitcoin Forensics
Bitcoin Forensics
Utilizing the data from
344
transactions,
Meiklejohn able to
identify the owners of
more than a million
Bitcoin addresses
Sarah Meiklejohn, a Bitcoin focused
Computer Researcher
Extensive Research
in
Bitcoin Blockchain
Found that by looking
blockchain an
investigator can
uncover who owns a
Bitcoin addresses
Bitcoin Forensics
Bitcoin Forensics
Bitcoin Forensics
Bitcoin Forensics
Bitcoin transactions occur via a
Network Connection, an investigator
should seize any Physical Object that
can connect to the Internet in addition
to the hard drive
COLLECTION OF BITCOIN ARTIFACTS
Bitcoin Forensics
• System Info
• Info about Logged users
• Registry Info
• Remnants of Chats
• Web browsing Activities
• Recent Communications
• Info from Cloud Services
• Decryption Keys for encrypted
volumes mounted
COLLECTION OF BITCOIN ARTIFACTS
Ulbricht
Ross
Bitcoin Forensics
Bitcoin Forensics
anupamtiwari@protonmail.com
https://about.me/anupam.tiwari

More Related Content

PPTX
State of Bitcoin and Blockchain 2016
PPT
Bitcoin
PPTX
Bitcoin Market Summary - Spark Capital - Produced by Oxana Kunets
PPSX
Is Bitcoin the Future of Money?
PDF
Magister Advisors - Blockchain & Bitcoin in 2016 - A Survey Of Global Leaders
PPTX
Bitcoin and Blockchain Technology Explained: Not just Cryptocurrencies, Econo...
KEY
Bitcoin: The Cyberpunk Cryptocurrency
PPTX
Blockchain: The Information Technology of the Future
State of Bitcoin and Blockchain 2016
Bitcoin
Bitcoin Market Summary - Spark Capital - Produced by Oxana Kunets
Is Bitcoin the Future of Money?
Magister Advisors - Blockchain & Bitcoin in 2016 - A Survey Of Global Leaders
Bitcoin and Blockchain Technology Explained: Not just Cryptocurrencies, Econo...
Bitcoin: The Cyberpunk Cryptocurrency
Blockchain: The Information Technology of the Future

Viewers also liked (17)

KEY
Introduction to bitcoin
PPTX
Bitcoin: Evolution of Virtual Currency
PPTX
Atlas ats powerpoint indiegogo
PPTX
暗号通貨読書会 #7: Bitcoin NG
PDF
Bitcoin Challenges - The Dawn of Trustless Computing
PPTX
State of Bitcoin Q3 2014
PPTX
Bitcoin ,
PPTX
Bitcoin
PDF
Paypal vs Bitcoin: A Filipino Tragedy
PPTX
Some Thoughts On Bitcoin
PPTX
Bitcoin - Understanding and Assessing potential Opportunities
PDF
Sunstone Capital, Avalanche 2014 - Bitcoin: Primer, State of Play, Discussion
PDF
Study on Bitcoin - Technical & Legal Aspects (Presentation at Cyber Cell Gurg...
PDF
Bitcoin and our Decentralized Future
PPTX
State of Bitcoin Q2 2014
PPTX
Expert Briefing - State of Bitcoin
PPTX
State of Bitcoin Q2 2015
Introduction to bitcoin
Bitcoin: Evolution of Virtual Currency
Atlas ats powerpoint indiegogo
暗号通貨読書会 #7: Bitcoin NG
Bitcoin Challenges - The Dawn of Trustless Computing
State of Bitcoin Q3 2014
Bitcoin ,
Bitcoin
Paypal vs Bitcoin: A Filipino Tragedy
Some Thoughts On Bitcoin
Bitcoin - Understanding and Assessing potential Opportunities
Sunstone Capital, Avalanche 2014 - Bitcoin: Primer, State of Play, Discussion
Study on Bitcoin - Technical & Legal Aspects (Presentation at Cyber Cell Gurg...
Bitcoin and our Decentralized Future
State of Bitcoin Q2 2014
Expert Briefing - State of Bitcoin
State of Bitcoin Q2 2015
Ad

Similar to Bitcoin Forensics (20)

PPTX
Blockchain and Bitcoin : A Technical Overview
PPTX
BLOCKCHAIN ,BITCOIN & CRYPTOCURRENCIES WORLD : MECHANICS AND CYBER CRIME
PPTX
Webinar on BITCOIN FORENSICS : BRIGHTTALK
PDF
Symposium on Legal Regulation of Bitcoin, Blockchain & Cryptocurrencies
PDF
Bitcoin Forensics
PPTX
BITCOIN FORENSICS : HAKON-2017 CONFERENCE
PPTX
Bitcoin technology
PPTX
BlockChain BreakDown
PDF
BLOCKCHAIN AND CRYPTOCURRENCY WEEK 3 READING MATERIAL.pdf
PDF
BLOCKCHAIN AND CRYPTOCURRENCY WEEK 3 READING MATERIAL (1).pdf
PDF
BITCOIN FORENSICS : Bsides Delhi Conference
PPTX
RIYAS BitCoion ppt.pptx
DOCX
IMPACT OF BITCOIN ON 21st CENTURY.docx
PDF
Bitcoin for Beginners Start Your Crypto Journey .pdf
PPTX
MONEY ,BITCOIN,BLOCKCHAIN TECHNOLOGY
PDF
Trading-CryptoCurrency-Advanced-Trading-Strategies.pdf
PDF
Trading-CryptoCurrency-Advanced-Trading-Strategies.pdf
PPTX
An introduction to block chain technology
PPTX
An introduction to block chain technology
PDF
Intro to Blockchain and Bitcoin
Blockchain and Bitcoin : A Technical Overview
BLOCKCHAIN ,BITCOIN & CRYPTOCURRENCIES WORLD : MECHANICS AND CYBER CRIME
Webinar on BITCOIN FORENSICS : BRIGHTTALK
Symposium on Legal Regulation of Bitcoin, Blockchain & Cryptocurrencies
Bitcoin Forensics
BITCOIN FORENSICS : HAKON-2017 CONFERENCE
Bitcoin technology
BlockChain BreakDown
BLOCKCHAIN AND CRYPTOCURRENCY WEEK 3 READING MATERIAL.pdf
BLOCKCHAIN AND CRYPTOCURRENCY WEEK 3 READING MATERIAL (1).pdf
BITCOIN FORENSICS : Bsides Delhi Conference
RIYAS BitCoion ppt.pptx
IMPACT OF BITCOIN ON 21st CENTURY.docx
Bitcoin for Beginners Start Your Crypto Journey .pdf
MONEY ,BITCOIN,BLOCKCHAIN TECHNOLOGY
Trading-CryptoCurrency-Advanced-Trading-Strategies.pdf
Trading-CryptoCurrency-Advanced-Trading-Strategies.pdf
An introduction to block chain technology
An introduction to block chain technology
Intro to Blockchain and Bitcoin
Ad

Recently uploaded (20)

PDF
Getting started with AI Agents and Multi-Agent Systems
PDF
sustainability-14-14877-v2.pddhzftheheeeee
PPT
Geologic Time for studying geology for geologist
PDF
Unlock new opportunities with location data.pdf
PPTX
O2C Customer Invoices to Receipt V15A.pptx
PPTX
Benefits of Physical activity for teenagers.pptx
PPT
Module 1.ppt Iot fundamentals and Architecture
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
Developing a website for English-speaking practice to English as a foreign la...
PDF
CloudStack 4.21: First Look Webinar slides
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
A review of recent deep learning applications in wood surface defect identifi...
PPTX
observCloud-Native Containerability and monitoring.pptx
PPTX
Tartificialntelligence_presentation.pptx
PDF
Zenith AI: Advanced Artificial Intelligence
PDF
A comparative study of natural language inference in Swahili using monolingua...
PDF
STKI Israel Market Study 2025 version august
PPT
What is a Computer? Input Devices /output devices
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
Getting started with AI Agents and Multi-Agent Systems
sustainability-14-14877-v2.pddhzftheheeeee
Geologic Time for studying geology for geologist
Unlock new opportunities with location data.pdf
O2C Customer Invoices to Receipt V15A.pptx
Benefits of Physical activity for teenagers.pptx
Module 1.ppt Iot fundamentals and Architecture
Group 1 Presentation -Planning and Decision Making .pptx
Developing a website for English-speaking practice to English as a foreign la...
CloudStack 4.21: First Look Webinar slides
1 - Historical Antecedents, Social Consideration.pdf
A review of recent deep learning applications in wood surface defect identifi...
observCloud-Native Containerability and monitoring.pptx
Tartificialntelligence_presentation.pptx
Zenith AI: Advanced Artificial Intelligence
A comparative study of natural language inference in Swahili using monolingua...
STKI Israel Market Study 2025 version august
What is a Computer? Input Devices /output devices
Assigned Numbers - 2025 - Bluetooth® Document
From MVP to Full-Scale Product A Startup’s Software Journey.pdf

Bitcoin Forensics

  • 2. The views expressed in this presentation are Mere Apne. Reference to any specific products, process ,or service do not necessarily constitute or imply endorsement, recommendation, or views of Min of Def or any Govt All images used are for illustrative purposes only & Do not promote any specific product
  • 11. Name used by the unknown person or persons who designed BITCOIN and created its original reference implementation SATOSHI NAKAMOTO Kahan Gaya Usay Dhoondo
  • 13. AS OF 17TH FEB 2017 1 BITCOIN IS WORTH 1040$ SO 1 BITCOIN IS 70103
  • 14. THE LAST BITCOIN (PROBABLY 21 MILLIONTH COIN) WILL BE MINED IN THE YEAR 2140
  • 19. CRYPTOCURRENCY IS AN ATTEMPT TO BRING BACK A DECENTRALISED CURRENCY OF PEOPLE, ONE THAT IS NOT SUBJECT TO INFLATIONARY MOVES BY A CENTRAL BANK
  • 22. Distributed Ledger is a Consensus of Replicated, Shared & Synchronized digital data geographically spread across multiple sites & countries
  • 23. Type of Distributed Ledger, comprised of Unchangeable, Digitally Recorded Data in packages called BLOCKS TAMPER EVIDENT LEDGER
  • 26. BASICALLY CHUNKS OF INFO THAT CAN BE USED TO MATHEMATICAL GUARANTEE ABOUT MESSAGES
  • 27. Peer-to- Peer (P2P) network is created when two or more PCs are connected & share resources without going through a separate server computer
  • 31. “शरीर में 206 हड्डिय ां है, और सांविध न में 1670 क नून ... हड्िी से लेकर क नून सब तोड़त हूूँ….” SHA तोड़ के दिख ….
  • 38. A user for CONDUCTING TRANSACTIONS utilizing BITCOIN, he or she must first DOWNLOAD and setup a BITCOIN WALLET BITCOIN WALLET can show the total BALANCE of all BITCOINS it CONTROLS and let A USER PAY a specified AMOUNT
  • 39. WALLET contains a USER’S PRIVATE KEY, which ALLOWS FOR THE SPENDING of the BITCOINS, which are located in the BLOCK CHAIN Once wallet is INSTALLED & CONFIGURED, an ADDRESS is GENERATED which is SIMILAR to an E-MAIL or PHYSICAL ADDRESS
  • 40. WALLET is basically the Bitcoin Equivalent of a Bank account. Allows to RECEIVE BITCOINS, STORE them, and then SEND them to others
  • 41. Connected to the Internet or is online is said to be HOT Cold Wallets & Hot Wallets Cold is considered most Secure & suitable for Storing Large Amounts of bitcoins Hot is suitable for Frequently Accessed funds COLD implies it is Offline or Disconnected from the Internet
  • 42. Designedto be downloaded & used on Laptops/PCs DESKTOPWALLETS Armory, Multibit, Msigna and Hiveto mention a FEW Easyto Access. Available for Different OS – Windows, Mac OS and Ubuntu.
  • 45. PHYSICALWALLETS Once they are generated, you print them out on a piece of paper Paper Wallets can Securely hold your BITCOINS in Cold Storage form for a long time Bitaddress.org or Blockchain.info
  • 46. BitcoinQt is the First ever built bitcoin CLIENT WALLET BITCOINCLIENTS WALLETS Original bitcoin wallet used by the Pioneers of the currency COMPUTERS installed with these wallets FORM PART OF THE CORE NETWORK & have access to all transactions on the blockchain
  • 51. They DON’T EXIST ANYWHERE, even on a hard drive
  • 52. When we say SOMEONE HAS BITCOINS & you look at a PARTICULAR BITCOIN ADDRESS, there are NO DIGITAL BITCOINS held AGAINST that ADDRESS BALANCE of any BITCOIN address ISN’T HELD at that ADDRESS; one MUST RECONSTRUCT it by looking at the BLOCKCHAIN
  • 53. Everyone on the NETWORK knows about a TRANSACTION and THE HISTORY OF A TRANSACTION can be TRACED BACK to the point where the BITCOINS were produced
  • 54. Conduct a SEARCH based on BLOCK NUMBER, ADDRESS, BLOCK HASH, TRANSACTION HASH or PUBLIC KEY
  • 58. BITCOIN-QT FOLDER STRUCTURE Blocks – This subdirectory contains blockchain data and contains a “blk.dat” file and a “blocks/index” subdirectory. “blk.dat” stores actual Bitcoin blocks dumped in raw format. The “blocks/index subdirectory” is a database that contains metadata about all known blocks
  • 59. Chainstate subdirectory- it is a database with a compact representation of all currently unspent transactions and some metadata about where the transactions originated BITCOIN-QT FOLDER STRUCTURE
  • 60. Database subdirectory - Contains database journaling files (Data Directory, BITCOIN-QT FOLDER STRUCTURE
  • 61. LOCK FILE DEBUG.LOG PEERS.DAT WALLET.DAT BITCOIN-QT FOLDER STRUCTURE DB LOCK FILE EXTENSIVE LOGGING FILE PEER INFORMATION STORAGE FOR KEYS,TXN,METADATA etc
  • 62. Private key of the suspect, they can search for that particular key on the Blockchain to Trace the purchases to other potential Suspects. investigator has the Bitcoin
  • 64. BITCOIN FORENSIC ARTIFACT EXAMINATION Windows 7 Professional Multibit Bitcoin-Qt Bitminter Basic USB ASIC Bitcoin Gateway laptop ML6720 120 GB WD hard drive (4) USB ASIC Mining drives USB powered cooling fan 32 GB USB thumb drive
  • 67. Utilizing the data from 344 transactions, Meiklejohn able to identify the owners of more than a million Bitcoin addresses Sarah Meiklejohn, a Bitcoin focused Computer Researcher Extensive Research in Bitcoin Blockchain Found that by looking blockchain an investigator can uncover who owns a Bitcoin addresses
  • 72. Bitcoin transactions occur via a Network Connection, an investigator should seize any Physical Object that can connect to the Internet in addition to the hard drive COLLECTION OF BITCOIN ARTIFACTS
  • 74. • System Info • Info about Logged users • Registry Info • Remnants of Chats • Web browsing Activities • Recent Communications • Info from Cloud Services • Decryption Keys for encrypted volumes mounted COLLECTION OF BITCOIN ARTIFACTS