All articles
Blockchain Tracing & Forensics

UTXO vs Account Model Tracing: What Investigators Need to Know

Bitcoin and Ethereum use fundamentally different transaction models, and this changes how investigators trace funds. Learn the key differences and the techniques for each model.

NexusCore Investigations Team2026-08-0410 min read
UTXO vs Account Model Tracing: What Investigators Need to Know

Bitcoin and Ethereum — the two most investigated blockchains — use fundamentally different transaction models. Bitcoin uses the UTXO (Unspent Transaction Output) model; Ethereum uses the account-based model. These models are not just technical differences — they fundamentally change how investigators trace funds, cluster addresses, and build transaction graphs. This article explains the key differences and the techniques for each.

The UTXO Model (Bitcoin)

In the UTXO model, the blockchain does not track balances. Instead, it tracks unspent transaction outputs — chunks of bitcoin that were created as outputs of previous transactions and have not yet been spent. A "wallet" is a collection of private keys that control specific UTXOs. The wallet's balance is the sum of the UTXOs it controls.

When a transaction is created:

  1. It selects one or more UTXOs as inputs (these UTXOs will be consumed/destroyed)
  2. It creates one or more new UTXOs as outputs (these are the new chunks of bitcoin)
  3. The total of the inputs must equal the total of the outputs plus the fee
  4. Typically, one output is the payment (to the recipient) and one is the change (back to the sender)

Each UTXO is associated with an address (or a script that defines how it can be spent). An address can have multiple UTXOs. A transaction can spend UTXOs from multiple addresses (if the sender controls all of them).

Forensic Implications of the UTXO Model

  • Common-input-ownership heuristic: When multiple addresses are inputs to the same transaction, they are likely controlled by the same wallet. This is the foundation of Bitcoin address clustering.
  • Change address identification: Each transaction typically has a change output, and identifying it is essential for following the right trail.
  • No account-level state: There is no "account" on Bitcoin — only UTXOs. An investigator works with addresses and UTXOs, not balances.
  • Transaction graph is bipartite: Each transaction connects inputs to outputs. The graph is a series of bipartite connections.

The Account Model (Ethereum)

In the account model, the blockchain tracks balances associated with addresses. An address is an account with a balance. When a transaction is created:

  1. It specifies a from address (the sender) and a to address (the recipient)
  2. It specifies a value (the amount to transfer)
  3. The sender's balance is decremented and the recipient's balance is incremented
  4. There is no "change" — the remaining balance stays in the sender's account

Smart contracts are also accounts (contract accounts) that hold balances and execute code when they receive transactions.

Forensic Implications of the Account Model

  • No common-input-ownership heuristic: Each transaction has a single sender. There is no multi-input clustering. Instead, investigators use behavioral clustering (same contract interactions, same deployer, coordinated movement).
  • No change addresses: The remaining balance stays in the sender's account. There is no change output to identify. This simplifies tracing in one sense (no change ambiguity) but removes a clustering signal.
  • Internal transactions: Smart contracts can call other smart contracts within a single transaction, creating "internal transactions" (also called traces or message calls). These are not separate transactions on the blockchain but are recorded in the transaction's execution trace. An investigator must examine internal transactions to follow funds that pass through contracts.
  • Token transfers: ERC-20 token transfers are not native transactions — they are events emitted by the token contract. An investigator must look at the Transfer event logs, not just the transaction list.
  • Contract interactions: A single transaction can interact with multiple contracts (e.g., a swap through a DEX router that calls a pool, which calls a token contract). The investigator must follow the entire call chain.

Key Differences for Investigators

Clustering

Bitcoin (UTXO): Clustering is based primarily on the common-input-ownership heuristic. When two addresses are inputs to the same transaction, they are clustered. This is a strong, well-understood heuristic.

Ethereum (Account): Clustering is based on behavioral patterns — addresses that interact with the same contracts, are deployed by the same deployer, or move funds in coordinated patterns. This is more subjective and requires more analysis.

Following Funds

Bitcoin (UTXO): Following funds requires identifying the change output at each step. The investigator must apply change address heuristics to determine which output to follow. This adds complexity but also provides clustering signals.

Ethereum (Account): Following funds is simpler at the address level — the transaction specifies the from and to. But when funds pass through smart contracts (DEXs, bridges, mixers), the investigator must follow the internal transactions and event logs to track the funds through the contract call chain.

Token Transfers

Bitcoin (UTXO): Bitcoin has a single native asset (BTC). There are no "token transfers" to track separately. (Omni Layer and other protocols create token-like assets on Bitcoin, but they are rare in investigations.)

Ethereum (Account): Ethereum has thousands of ERC-20 tokens and NFTs. Token transfers are recorded as events, not as native transactions. An investigator must examine the Transfer event logs to track token movements. A single address may hold many different tokens, each with its own transfer history.

Graph Structure

Bitcoin (UTXO): The transaction graph is a bipartite graph (inputs to outputs) with change address ambiguity at each step. The graph tends to be wide (many outputs) and deep (many hops).

Ethereum (Account): The transaction graph is a simple directed graph (from to to) at the address level, but with complex internal structure when contracts are involved (internal transactions, event logs). The graph is simpler at the address level but more complex at the contract interaction level.

Other Chains

Tron: Uses an account model similar to Ethereum. Tracing techniques are similar, with a focus on TRC-20 token transfers (especially USDT).

Solana: Uses an account model but with a different architecture (Sealevel parallel execution). Transactions can contain multiple instructions (like internal transactions). Tracing requires understanding Solana's instruction-level structure.

Cardano: Uses an extended UTXO model (eUTXO), which combines UTXO with smart contract capabilities. Tracing is similar to Bitcoin but with additional complexity from smart contract interactions.

Practical Implications for Multi-Chain Investigations

In a multi-chain investigation (which is most investigations today), the investigator must switch between UTXO and account model techniques as funds move across chains. For example:

  1. Stolen ETH (account model) is traced through DEX swaps and contract interactions
  2. It is bridged to Bitcoin (UTXO model) and traced through peel chains and change address analysis
  3. It is bridged to Tron (account model) and traced through TRC-20 token transfers

Each chain requires the appropriate model-specific techniques.

Conclusion

The UTXO and account models are fundamentally different, and each requires different forensic techniques. UTXO-based chains (Bitcoin) rely on common-input-ownership clustering and change address identification. Account-based chains (Ethereum, Tron, Solana) rely on behavioral clustering and internal transaction analysis. A competent investigator must understand both models and be able to switch techniques as funds move across chains. Understanding the model is the first step to understanding the trace.

Share this article