Shared Infrastructure Is Not Evidence of Common Control
Two wallets do not share an operator merely because both interact with a sponsor, bridge, router, or exchange. Widely used infrastructure is context, not identity or control evidence.
Two wallets touching the same resource can look like a connection. Often, it is not one.
They may both interact with an exchange, a bridge, a router, a sponsor, or another service used by many unrelated people. The shared touchpoint is a fact. It is not, by itself, evidence that the wallets share an operator, intention, or organisation.
This mistake is common because a graph makes shared infrastructure look like a relationship. Lines converge on one node. The picture becomes visually persuasive. But a picture of shared use is not a finding of common control.
Infrastructure is a map feature, not an identity claim
Public chain infrastructure exists to be used. A bridge connects many unrelated wallets. An exchange hot wallet can process activity for many customers. A router exists to route. Their presence can help explain a path through a system, but it does not identify the people on that path.
The correct question is not “do these wallets share a counterparty?” That question is too easy. The better question is “what, if anything, does that shared counterparty allow us to conclude?”
Often the answer is limited: it establishes that both wallets interacted with the same public resource. The report should stop there unless independent evidence justifies more.
Why false connection is expensive
An unsupported clustering claim can distort everything that follows. It can make unrelated activity look coordinated, inflate a trace, direct attention toward the wrong person, or encourage a client to treat a hypothesis as a fact.
The cost is not only reputational. In a legal or compliance setting, a weak connection can undermine stronger parts of a report because the reader no longer knows which labels were carefully established and which were visually inferred.
This is why Evidence Tiers separates infrastructure from identity. The report can describe the system accurately without turning a shared service into an accusation.
Suspicion should point inward first
The investigator’s own clustering claim deserves more scrutiny than a convenient external explanation. It is easy to be suspicious of an address because it appears beside another address in a graph. It is harder, and more useful, to ask what evidence would show that the connection is merely common use of a public system.
That is the same habit described in Falsify First. Before a relationship is treated as meaningful, the ordinary explanation must be allowed into the analysis.
What a careful report can say
It can say that wallets used the same resource. It can state whether the resource is publicly labelled. It can explain that the observation is insufficient for identity attribution. It can identify the off-chain records that would be needed to answer the next question.
What it should not do is turn a common technical touchpoint into a named cluster or a claim of common control without evidence that can bear that weight.
That restraint is not less analytical. It is more honest about what public records can and cannot show.