05 / Chokepoints
Where funds can actually be frozen
Start with the uncomfortable fact: nothing on the Bitcoin network itself can freeze a coin. There is no issuer, no administrator, no blacklist. As long as stolen funds sit in a wallet, no court order touches the UTXO — only the moves it. Interception is possible anyway, because thieves don't want UTXOs. They want money they can spend — and every road from coin to cash runs through doors that can be locked.
Every road to cash passes a door
Chokepoint #1: the exchange deposit
The single most important moment in any trace is a tainted output landing on a known . At that instant, three things become true at once: the funds are inside a system that can freeze them; the account that received them is tied to identity records; and the exchange's obligations give its compliance team both the authority and, in many jurisdictions, the duty to act on credible theft evidence.
This is the payoff of everything in chapters 1–3: the deposit transaction's txid, the audit trail behind it, and the computed taint share are exactly the package a compliance team needs to place an administrative hold while law enforcement engages. Related doors, same logic: , payment processors, and fiat off-ramps of every kind.
Chokepoint #2: legal process
A freeze buys time; process recovers money. The sequence usually runs: police report establishing the theft → law-enforcement or court demand to the custodian (production orders for account records, freezing injunctions over the assets) → adjudication → restitution. Courts in many jurisdictions now grant freezing and disclosure orders over crypto held at exchanges, including against unknown ("persons unknown") defendants; cross-border cases add mutual-legal-assistance time but follow the same shape. Slow is the honest description — months, not days. It is also the only path that ends with funds returned rather than merely stuck.
Chokepoint #3: the keys themselves
When funds never touch a custodian, one route remains: seizing the — through arrest, device seizure, or a compelled . This is how most headline recoveries actually happen; agencies have clawed back nine-figure sums years after a theft because keys eventually surfaced. It is entirely a law-enforcement action. No private party can do it, and anyone selling you "wallet hacking" as a recovery service is describing either a crime or a scam — usually the latter.
What decides outcomes: timing and evidence
Two variables dominate every real case. Speed: deposits can be traded and withdrawn within hours, so the window between a tainted UTXO moving and the funds leaving custody is short — watching unspent tainted outputs (and even the ) converts hindsight into advance warning. Evidence quality: compliance teams and courts act on specific, reproducible claims — this deposit txid, this audit trail, this taint percentage under a stated convention — and ignore vague accusations. A victim who arrives with a police report number and a deterministic trail is a different case than one who arrives with a screenshot.
What is not a chokepoint
Honesty requires naming the dead ends too. Miners cannot freeze funds and cannot durably censor a paying transaction — any miner anywhere can include it. Bitcoin itself has no blacklist and, barring a protocol change nobody serious expects, never will. (The contrast is instructive: centrally-issued stablecoins can and do freeze tokens at the issuer level — a power BTC deliberately lacks.) And non-custodial wallets answer to no one: if stolen funds simply sit in one, the realistic options are watching, waiting for a cash-out attempt, and law-enforcement key seizure. A trace doesn't change that — it makes sure you're ready the moment the coins move.