Log in
For business
KYT office
Compliance solution to monitor risks, detect sanctions and ensure AML rules.
KYT office
Compliance solution to monitor risks, detect sanctions and ensure AML rules.
AML certification
How industry players can get up-to-date knowledge and professional certification.
AML certification
How industry players can get up-to-date knowledge and professional certification.
Comprehensive transaction analytics that helps to build graphs and trace funds.
Graph
Travel rule
(soon)
For personal use
Telegram bot
Bot for checking crypto for risks, providing AML reports.
Telegram bot
Bot for checking crypto for risks, providing AML reports.
Crypto recovery
Services are focused on tracking
and recovering crypto assets.
Сrypto recovery
Services are focused on tracking
and recovery crypto assets.
Docs and reports
All types of documents related
to cryptocurrency.
Docs and reports
All types of documents related
to cryptocurrency.
Portfolio tracker
Information about all assets and risk assessment in one place.
Portfolio tracker
Information about all assets and risk assessment in one place.
AML checks
Сhecking wallets and transactions
for illicit funds.
AML checks
Сhecking wallets and transactions
for illicit funds.
ES
FR
中文
Вход
AML-сертификация
Актуальные знания в области AML/KYT от ведущих экспертов отрасли.
AML-сертификация
Актуальные знания в области AML/KYT от ведущих экспертов отрасли.
Graph
Визуализация перемещения активов
и связей между кошельками.
Graph
Визуализация перемещения активов
и связей между кошельками.
KYT Office
Мониторинг транзакций и кошельков для вашего отдела комплаенса.
KYT Office
Мониторинг транзакций и кошельков для вашего отдела комплаенса.
Для себя
Для Бизнеса
Travel rule
(Cкоро)
Телеграм-бот
Бот для проверки кошельков и транзакций с выдачей отчётов.
Телеграм-бот
Бот для проверки кошельков и транзакций с выдачей отчётов.
Возврат средств
Услуги по отслеживанию и возврату украденных криптоактивов.
Возврат средств
Услуги по отслеживанию и возврату украденных криптоактивов.
AML-проверки
Проверка кошельков и транзакций на наличие "грязной" криптовалюты.
AML-проверки
Проверка кошельков и транзакций на наличие "грязной" криптовалюты.
Портфолио трекер
Информация о всех активах и оценка рисков в одном месте.
Портфолио трекер
Информация о всех активах и оценка рисков в одном месте.
Отчёты
Все типы документов связанные
с криптовалютой.
Отчёты
Все типы документов связанные
с криптовалютой.
PRIVATE
Government
Financial institutions
Exchanges
PSP's
Wallets
Gambling platforms
Investment platforms
Stablecoin issuers
Investigators
Regulators
Law enforcement
Для бизнеса
Госсектор
Финансовые организации
Биржи
Платежные провайдеры
Кошельки
Игровые платформы
Инвестиционные платформы
Эмитенты стейблкоинов
Расследователи
Регуляторы
Правоохранительные органы
ES
FR
中文
08.10.2026

How to Track a Bitcoin Transaction: From TxID to Transfer Graph

To check a Bitcoin transfer, all you need is its hash, known as the TxID. With it, you can find the transaction in a blockchain explorer, check its confirmations, and see which addresses received the BTC. From there, you can start following the funds as they move on.

Using a real 10,000 BTC transfer as an example, we’ll show you how to find a transaction by its hash and read its data, and then build a clear map of the funds’ route in BitOK Graph.


Содержание:

  • How to Find a Bitcoin Transfer by TxID
  • Network, Confirmations, Fee, and Status
  • How to Track a Bitcoin Transaction with BitOK Graph
  • How to Save Verifiable Results
  • Frequently Asked Questions (FAQ)

How to Find a Bitcoin Transfer by TxID

A TxID (transaction ID, or transaction hash) is a unique identifier for a transfer. It works like a parcel tracking number: you use it to find a specific shipment and check its status. The same goes for a BTC transfer: you paste the hash into a blockchain explorer and see whether the transaction has been included in a block and how many confirmations it has.

Important! A TxID says nothing about who the sender or recipient is. It only points to a record on the blockchain.

Steps:
1.Open a Bitcoin block explorer, such as blockstream.info.

2.Paste the TxID into the explorer’s search bar. You can also open a transaction directly by URL: take https://blockstream.info/tx/ and add your TxID to the end, with no spaces. For our transaction, the link looks like this:

https://blockstream.info/tx/a1075db55d416d3ca199f55b6084e2115b9345e16c5cf302fc80e9d5fbf5d48d

3.If nothing comes up, check that the Bitcoin network is selected and that the TxID was copied in full, with no spaces or extra characters.
The explorer shows the block, time, inputs, outputs, and fee.
Transaction details on blockstream.info.

Network, Confirmations, Fee, and Status

A Bitcoin transaction hash is a string of 64 characters: the digits 0−9 and the letters a-f, with no 0x prefix. Litecoin, Bitcoin Cash, and other networks use the same format, so you can’t tell which network a transaction belongs to from the hash alone.

Before you search, check in your wallet or on the exchange that the transfer was sent over the Bitcoin (BTC) network, and open an explorer for that network. For testnet transfers, you need a testnet explorer.

Bitcoin transaction status shows whether the transaction has been included in a block or is still waiting for confirmation. When you search by TxID, you’ll see one of three results:

Search result

What it means

What to do

Unconfirmed

The explorer can see the transaction, but it hasn’t been included in a block yet

Wait for confirmation; check the fee rate and network congestion

Confirmed

The transaction has been included in a block

Check the number of confirmations

Not found

The explorer can’t find a transaction with that hash. Possible reasons: a typo in the TxID, the wrong network, the transaction was never broadcast, it was replaced by another transaction, or it was dropped from the mempool

Check the TxID and the network in the wallet or exchange the transfer was sent from

Confirmations. One confirmation means the transaction has been included in a block. Each new block added on top adds another. For large amounts, 6 confirmations is a common threshold, but that’s an established practice rather than a protocol rule. In our example, block 57,043 was mined on May 22, 2010, at 18:16:31 UTC, and the transaction now has more than 900,000 confirmations.

Fee. Bitcoin has no separate "fee" field. The fee is simply the difference between the total of the inputs and the total of the outputs, and the explorer calculates it for you. In practice, what matters is the fee rate in sat/vB (satoshis per virtual byte; one satoshi is 0.1 BTC), because it determines how quickly a transaction gets included in a block.

In our example, the inputs total 10,000.99 BTC, the single output is 10,000 BTC, and the fee is 0.99 BTC. By today’s standards, a fee like that is enormous. But it makes sense in context: the transaction took place many years ago, when bitcoin was worth only a tiny fraction of its current price.

How to Read Inputs, Outputs, and Change

Imagine you have a $ 100 bill and your purchase costs $ 60. You hand over the whole bill and get $ 40 back in change.

Bitcoin works in a similar way. An amount you’ve received and haven’t spent yet is called a UTXO, or unspent transaction output. Think of it as a banknote. When you send a payment, your wallet spends the whole UTXO and creates new amounts: one for the recipient and, if anything is left over, one back to you.

Unlike banknotes, UTXOs don’t come in fixed denominations. And the fee comes out of the amount being spent, just like any other cost.

In this analogy:
  • A transaction input is the instruction that says which “banknote” you’re spending. A transaction can have several inputs.

  • Transaction outputs are the new amounts the transfer creates: $60 for the seller and $40 for you.

  • Change is the output that returns the leftover amount to the sender after the payment and the fee.
To learn more about transaction types, read BitOK’s article on transaction types.
How to read the result in an explorer:
  • Inputs are the funds a transaction spends. Each input points to an output of an earlier transaction, essentially saying, “I received this amount before, and now I’m spending it.” In an explorer, an input shows the address the funds came from, the amount, and a pointer to that earlier transaction.

  • Outputs show where the funds go: the new amounts and the addresses they’re sent to. Outputs are numbered in order, but the count starts at zero: the first output is #0, the second is #1, and the third is #2. In technical data, this number is called vout. It lets you pinpoint exactly which part of a transfer you’re tracking, since a single transaction can have several outputs.

  • Change is the output that sends the leftover amount back. Going back to the banknote example: if you pay with a $100 bill for a $60 purchase, you get $40 back. In Bitcoin, the leftover amount also arrives as a separate output, usually at an address belonging to the sender.
Why explorers don’t always label change. The blockchain records the amount and spending conditions of each output, but it has no tag saying “payment to the recipient” or “change to the sender.” The wallet that created the transfer usually recognizes its own change address, but a third-party explorer doesn’t have that information. If an explorer labels an output as change, that’s an educated guess based on indirect clues. And a missing “change” label doesn’t mean there’s no change.

Now let’s apply these rules to the transaction we opened in the explorer above. We’ll call it the first transaction (its TxID starts with a1075db5…):

Item

Value

Inputs

131, all from a single address, 1XPTgDRhN8RFnzniWCddobD9iKZatrvH4

Total inputs

10,000.99 BTC

Outputs

1: 17SkEw2md5avVNyYgj6RiXuQKNwkXaxFyQ, 10,000 BTC

Fee

0.99 BTC

There is only one output, so the first transaction has no change. Everything except the fee went to 17SkEw…. You can’t call this address the “payment recipient” based on the transaction structure alone: it’s simply the address the output was sent to.

How to Track a Bitcoin Transaction with BitOK Graph

The question “where did the money go?” can be answered with a repeatable series of steps: take an output, check whether it has been spent, and open the transaction that spent it. Then do the same for that transaction’s outputs. The result is a chain of transactions, or in other words, a graph.

In an explorer, every step in the chain means opening a new page and cross-checking the data by hand. BitOK Graph helps you visualize the path of the funds. Let’s walk through the tool using the first transaction, which you already know: a transfer of 10,000 BTC from May 22, 2010.

Step 1. Create a Project and Find the Transaction by TxID

Open BitOK Graph in your browser, create a new project, and select the Bitcoin (BTC) blockchain.
In the top left corner of the workspace, click the search icon and paste the TxID of the first transaction:

a1075db55d416d3ca199f55b6084e2115b9345e16c5cf302fc80e9d5fbf5d48d

Select the search result to add the transfer to the graph.
Two nodes appear on the graph:
  • Cluster 1XPTgDRh... is a cluster of addresses linked to the sending side. A cluster is a group of addresses that the tool has combined based on analytical signals. The +359 label shows how many more addresses belong to the group. In the explorer, all 131 inputs came from a single address, while the cluster is a broader grouping.

  • 17SkEw2m...XaxFyQ is the address that received 10,000 BTC.
The arrow between them shows the direction and amount of the transfer. Clustering is the result of analytical grouping, and on its own it doesn’t prove that all the addresses belong to a single owner.

Step 2. Look at the Recipient’s Transactions

Click the node 17SkEw2m...XaxFyQ. An address card opens on the right: 23 transfers (21 incoming and two outgoing), with the first one recorded on May 22, 2010.
To follow the funds further, you only need the outgoing transfers. Click the filter icon next to the “Transfers” heading, select “Outgoing” in the “Any direction” field, and apply the filter with the “Done” button.
Инструмент показывает два исходящих направления от 22 мая 2010 года, 22:26:

Recipient address or cluster

Amount

Cluster 19teQR8M... (13TETb...2tE2)

4,223 BTC

1MLh2UVH...EPU6RY

5,777 BTC

Total

10,000 BTC

Both rows belong to a single transaction, which we’ll call the second transaction (its TxID starts with cca7507897abc896..., and the full hash is given below in the verification section).

It’s important to distinguish between a transaction and its outputs: one transaction can create several outputs, so two rows in Graph don’t mean two separate transactions. Which of the two outputs is the payment and which is change can’t be determined from blockchain data (more on this in the section on hypotheses).

Step 3. Build the Graph of Further BTC Movement

To add the transfers you found to the diagram, click the “+” icon next to each outgoing transfer in the transfers list. BitOK Graph adds two new nodes and connects them with arrows to the address 17SkEw2m...XaxFyQ.
Now the entire section you’ve explored is visible on a single screen.

Step 4. Continue the Route and Set Stopping Conditions

To go further, click either of the two new nodes, look at its outgoing transfers, and add them to the graph the same way you did in Step 3. In our example, the funds from these two outputs were spent later: the 5,777 BTC output in block 57,053, and the 4,223 BTC output in block 64,683.

How to Verify the Graph in an Explorer

You can check what the graph shows against the blockchain. Here’s how to verify the section we just built, using blockstream.info as an example.

1. Open the second transaction in the explorer. Paste its TxID into the search bar, or append it to the link https://blockstream.info/tx/:

cca7507897abc89628f450e8b1e0c6fca4ec3f7b34cccf55f3f531c659ff4d79
На странице видно:
  • Block: 57,044, status “confirmed.” It comes right after block 57,043, which contains the first transaction (a1075db5…). About 9 minutes passed between the two blocks.

  • Confirmations: 913,465 (the number grows with every new block).

  • Confirmation time: 22:26:08 GMT+4. In UTC, that’s 18:26:08, or about ten minutes after the first transaction’s block (18:16:31 UTC).

  • Input: one. It shows exactly which funds the transaction is spending. Instead of the sender’s address, the explorer shows a pointer to the earlier transaction: a1075db5…5d48d:0. You read it in two parts: a1075db5…5d48d is the TxID of the earlier transaction (the first one, where we started), and 0 is the output number within it. Counting starts at zero, so 0 means the first (and only) output. Put together, it says: “this transaction spends output 0 of the first transaction.” That output held the 10,000 BTC that arrived at the address 17SkEw…. To see the details, find the first transaction in the explorer by its TxID.

  • Outputs: two.
2. Compare the amounts with the table in Step 2 of the Graph section. The amounts, 5,777 and 4,223 BTC, match, and together they add up to 10,000 BTC. The 22:26 timestamp in Graph matches 22:26:08 in the explorer, so it’s the same transfer. The 4,223 BTC output appears in the explorer as P2PK with no address, while Graph shows the transfer for the same amount as a cluster, 19teQR8M….

3. If an output has no address, follow it by transaction hash and output number. The explorer will show a public key rather than an address in the usual form, so you can’t look up such an output by an address string.

4. Check that the next transaction really spends the right funds. For each output, look for its status: “spent” or “unspent.” It may appear next to the output or inside the “Details” block. If an output has been spent, go to the spending transaction and look in its inputs for an entry in the same “TxID:output number” format. For example, output 1 of the second transaction should appear as cca75078…:1. In our example:
  • output 0 was spent in 3b8328fe7e53a8162cf023738a53c85a3cbf21efe517ab878e8cfecc3a2e22db, block 57,053;

  • output 1 was spent in 9e744590d196b63d02a1dd7ef596fd6082286f84295d66da411a9ffebfdd1957, block 64,683.
5. Compare the data with a second explorer. If you checked in one explorer, open the same TxIDs in another (for example, blockstream.info and mempool.space). Compare the block, amounts, output numbers, and links to the spending transactions.

Keep in mind: “spent” only means that the output is referenced in the inputs of another transaction. Nothing on the blockchain tells you who is behind it.

How to Save Verifiable Results

A tracing result is only valuable if someone else can reproduce it. Here’s what to save:
  1. The full TxID of every step, with no abbreviations.
  2. Block numbers, times (UTC), and the date you ran the check.
  3. Output numbers, so it’s clear exactly which output was spent.
  4. Amounts in BTC or satoshis, plus the fee.
  5. The data source: which explorer or API you used and what query you ran.
  6. The status of each conclusion: observation or hypothesis, with the heuristic noted.
  7. Screenshots of the graph and explorer pages (or JSON exports) that back up each step.
A minimal table for your report:

Step

TxID

Block

Output #

Address

BTC

Status

Comment

1

a1075db5…

57,043

0

17SkEw…

10,000

observation

no change

2

cca75078…

57,044

0

1MLh2U…

5,777

observation

purpose not determined

2

cca75078…

57,044

1

P2PK

4,223

observation

purpose not determined

Frequently Asked Questions (FAQ)

Where can I check the status of a Bitcoin transaction by TxID?

In any Bitcoin explorer: paste the TxID into the search bar on its site. You’ll see the status, block, number of confirmations, inputs, outputs, and fee.

Why can’t the explorer find my TxID?

The possible reasons are listed in the status table in the section on the network and confirmations: a typo in the string, the wrong network, a testnet transaction, or a transaction that never reached the network.

How many confirmations are enough for a Bitcoin transaction?

There’s no fixed number: 6 confirmations is used as a conservative threshold for large amounts, but the requirements depend on the recipient and the amount.

How can I tell which output is the change?

You can’t say for sure from blockchain data alone. The second transaction shows why: both outputs look equally plausible as payments, so any conclusion remains a hypothesis.

Can I find the owner from an address?

Not from the blockchain itself. Linking an address to a person or organization requires outside sources and independent verification (see the section on hypotheses).

What should I do if an output has no address?

It’s most likely the old P2PK format. Follow the output using the transaction hash and output number.

Discover what Graph can do for address analysis
Support
Get it

To inquire about our plans, click here

Try BitOK for free