Back

Related wallets and clusters

P09-L06 · P09 · P09-M02

Build an evidence graph and test alternate ownership hypotheses

ILLUSTRATIVE · needs_review

Prerequisites: P09-L05

Learning objectives

  • Construct a typed evidence graph and reproducible cohort.
  • Compare common-control and shared-service hypotheses fairly.
  • Reconcile internal/external flow without identity attribution.

EN source master · P09-L06 · 45 minutes estimated · needs_review

Why this matters

A cluster can be an observation set, an algorithmic grouping or an ownership hypothesis. Using one word for all three invites unsupported attribution. Common funding, similar timing and shared application use can be genuine relationships without proving a common human owner.

This lesson builds an evidence graph, compares explanations and keeps uncertain edges visible. You will grade hypotheses by their support and missing tests rather than assigning a numeric identity confidence without calibration.

Explanation

Define what cluster means here

Start with an explicit membership rule. “Addresses receiving native funds from HUB in window W” defines a reproducible co-funded set. “Addresses controlled by one person” is a stronger hypothesis requiring independent control evidence.

Name the set according to its rule. A co-funded cohort can be useful for further inspection without being an ownership cluster. If a provider's clustering method is not disclosed, preserve its output as a provider assertion with unknown mechanism.

The graph must separate ledger nodes from entity nodes. Addresses, programs and token accounts are inspectable objects. A human or organization node needs separate substantiation. Do not create it merely to simplify the diagram.

Use typed, sourced edges

Each edge needs network, source, target, type, asset/amount where relevant, event locator, context, result and coverage. “Related” is too vague. A native transfer, shared authority field, program derivation and same application call each answer a different question.

Solana result structures distinguish instructions, signers and balances [S09-STRUCTURES]. They provide mechanism fields for inspecting edges, not a built-in human identity. A signature search only discovers referenced-address activity under its scope [S09-SIGNATURES].

For program-mediated nodes, distinguish derivation from ownership. PDAs use program signing rather than a private key [S09-PDA]. A shared program can process many independent users, so deriving multiple addresses from one program does not by itself merge beneficiaries.

Separate observations from hypotheses

Draw successful supplied movement edges as solid lines. Draw hypothesized control links as dashed lines with an explanation. An unavailable possible edge should be marked unknown, not drawn as if measured.

Observed co-funding supports a relationship. It can be consistent with common control, shared custody withdrawals, a public distribution, payroll or another common service. These alternatives are not all proven; they show that the observation does not uniquely determine ownership.

A transfer between two members can strengthen a question about coordination, but it still does not identify a human controller. A business payment, refund or service routing can also connect independent addresses. Test the mechanism rather than counting arrows as identity votes.

Avoid dependent evidence inflation

“Same minute,” “close together” and “same visible batch” may be three descriptions of one timing feature. Do not count them as independent confirmations. Common funding plus same-source timing can also share one underlying operation.

A provider label and an interface label copied from that provider are dependent. Two displays do not double identity evidence. A report should group such claims by upstream source.

No fixed threshold such as “three clues means same owner” is justified by this fixture. A calibrated model would need a defined target, representative ground truth and error analysis. The lesson instead uses explicit qualitative states and falsifiable evidence requests.

Compare competing explanations fairly

Write what each explanation predicts and what would distinguish it. Common control might predict shared authorization evidence or coordinated management, but shared public activity alone is not exclusive. A service-distribution hypothesis might predict many recipients with differing later behavior, but a partial graph cannot establish that wider population.

Seek evidence that could weaken your preferred interpretation, not just examples that fit it. Missing contrary evidence in an incomplete export is not confirmation. If no supplied record discriminates the hypotheses, report them as unresolved.

A valid finding may be “the fixture supports a co-funded cohort; human ownership is insufficiently evidenced.” This is an analysis result, not a failure to do the task. It tells the reviewer precisely where investigation could advance.

Preserve graph and quantity boundaries

A transfer inside a cohort moves inventory between nodes without adding new external funding. Summing all edges measures gross movement, not external inflow or held balances. Reconcile within a declared boundary.

If HUB sends 10 to each of three members and one member later sends 2 to another, external cohort funding is 30. Gross transfer-edge volume including the internal transfer is 32. Cohort inventory remains30 under the zero-fee closed model. These statistics have different names and cannot be substituted.

Do not merge duplicate views of one event. Keep event locators from P09-L02. A call edge has no quantity unless a distinct value effect is supplied. This exercise's application calls carry no additional native amount.

Report relationships without public identity attribution

Keep provider labels, control hypotheses and observed transfers in different sections. Use neutral identifiers throughout. Commercial status, apparent wealth and popularity cannot raise an evidence state.

No graph authorizes a trading signal or a public accusation. Do not identify a real person from funding paths, and do not infer intent from coordinated-looking activity. The educational aim is an auditable graph with alternatives, coverage and next checks.

Key terms

  • Cohort: set selected by a disclosed observation rule.
  • Ownership hypothesis: proposed shared control needing separate evidence.
  • Typed edge: relationship with explicit mechanism.
  • Dependent clue: evidence describing the same underlying observation.
  • External inflow: movement crossing into the chosen boundary.
  • Discriminating evidence: record that distinguishes competing explanations.

Historical example

ILLUSTRATIVE — FIX-P09-06. SIM-CHAIN-A, synthetic T1–T5. Native balances start0 for W1/W2/W3. Complete listed native effects; fees and other effects are0. Cohort rule: receives 10 from HUB during T1–T3.

RecordSupplied successful operation
G1T1 HUB→W1,10 NATIVE
G2T2 HUB→W2,10 NATIVE
G3T3 HUB→W3,10 NATIVE
G4T4 W1→W2,2 NATIVE
G5T5 W1 calls APP, value0
G6T5 W2 calls APP, value0
L1provider labels HUB “payroll service”; basis absent

T1–T5 establish synthetic order only, not real seconds. No signatures proving shared authority, authenticated payroll provenance or human identity are supplied. H1=common controller; H2=shared service/public distributor with independent recipients.

What the evidence proves

OBSERVED in fixture: W1/W2/W3 share immediate funding source; W1/W2 also interact with APP; an internal2-unit movement occurs.

INFERRED: All three satisfy the co-funded rule. External inflow 30, internal flow2 and final cohort balance 30 under model assumptions.

What the evidence does not prove

UNKNOWN: Human ownership, payroll affiliation, wider HUB recipient set and APP authorization semantics.

INSUFFICIENT EVIDENCE: Neither H1 nor H2 is uniquely established. Equal funding and nearby synthetic order cannot prove common control; L1 cannot authenticate payroll identity.

Common mistakes

Renaming a co-funded set as one owner; counting timing descriptions as independent clues; drawing guessed edges solid; adding internal movement to external funding; and adopting a service label to settle a hypothesis.

Practical exercise

Build the typed graph and calculate final member balances, external inflow and gross native edge volume. Compare H1/H2 using supplied support and one next check for each. State whether a human-ownership cluster can be reported as proven.

Show worked correction

Worked correction and expected reasoning

Solid native edges are G1–G4; separate zero-value call edges G5/G6. L1 remains a provider annotation, not a verified entity node. Any common-control linkage is a dashed hypothesis.

Final balances: W1=10−2=8, W2=10+2=12, W3=10. Total30. External inflow 10+10+10=30; gross native edge volume30+2=32. Internal flow does not add funding.

Both hypotheses are consistent with co-funding. H1 needs independently supported shared-control evidence; H2 needs authenticated service mechanism and relevant broader distribution records. Neither absence of shared-control proof nor absence of verified payroll proves the rival hypothesis.

Report a co-funded cohort, not a proven human owner. Score out of ten: typed graph (three), balances and flow boundaries (three), fair hypothesis comparison (two), bounded finding/evidence requests (two).

Checklist

  • Publish a membership rule.
  • Type and source each edge.
  • Separate measured relationships from control hypotheses.
  • Group dependent clues by mechanism.
  • Reconcile boundary-crossing and internal flows.
  • Test alternatives and preserve unresolved attribution.

Summary

A useful cluster graph can establish relationships while leaving ownership unresolved. Hypothesis testing requires evidence that distinguishes explanations.

Summary

Common funding is not common ownership. Several timing labels can be one clue. Internal movement changes allocation, not external cohort funding.

Visual specifications

Graph HUB→W1/W2/W3 quantities10 and W1→W2 quantity2; APP call edges distinct and value0. Solid observed edges, dashed H1/H2 control/service possibilities. Show final8/12/10, external30 and gross 32 with separate labels; L1 unverified.

Illustrative co-funded cohort; ownership remains unresolved.

Use deterministic SVG/HTML or charts with units, evidence locators and text alternatives. Navy/black with restrained cyan, electric blue and violet; no decorative or fabricated explorer screenshots. At 390px stack annotations; verify 768px, desktop and Arabic RTL when assets are implemented. Keep identifiers LTR and factual time/edge/axis directions unchanged. Use only the official supplied ZECOIN mark. Both visual records remain specifications.

Tools

WALLET_INTELLIGENCE maps to read-only inspection of public address records, relationships and provenance. Verify supported network, exact identifiers, fields and coverage before any runtime integration; no live provider capability is claimed here. Use the embedded offline exercise if data or paid access is unavailable. No wallet connection, credentials, private key, signature or live trade is required. Missing data stays unknown. Academy progress, creator status, payments and referrals never alter Radar evidence.

Sources & claim boundaries

All example records are original ILLUSTRATIVE fixtures, not historical/live chain measurements. Documentation explains mechanisms, not invented amounts or labels. Synthetic chronology is explicitly bounded; observedAt=null is intentional. OBSERVED in an exercise means a supplied fixture record. Re-review documentation and deployed decoding before publication. Provider labels do not establish identity; address control and human attribution require distinct evidence.

Next lesson

P09-L07 after the worked exercise and question review.

Visual specifications

P09-L06-V01

SPECIFICATION_ONLY · ILLUSTRATIVE

Which relationships are observed and which ownership explanation remains hypothetical?

Illustrative co-funded cohort; ownership remains unresolved.

Graph HUB→W1/W2/W3 quantities10 and W1→W2 quantity2; APP call edges distinct and value0. Solid observed edges, dashed H1/H2 control/service possibilities. Show final8/12/10, external30 and gross 32 with separate labels; L1 unverified.

Three addresses receive10 each from HUB; internal2 reallocates to 8/12/10; app calls and service label do not prove shared human control.

390px stacked annotations and accessible text equivalent; 768px/desktop verification pending

Native RTL labels/layout; identifiers LTR; preserve time, number-axis and transfer direction.

FIX-P09-06

P09-L06-V02

SPECIFICATION_ONLY · ILLUSTRATIVE

What is observed, inferred, unknown or insufficiently supported?

Illustrative evidence states and attribution boundaries.

Four labelled rows bound to this lesson's record IDs, claim, limitation and next check; never display a human identity or safety verdict.

Four-state evidence table with record locators and uncertainty.

390px stacked annotations and accessible text equivalent; 768px/desktop verification pending

Native RTL labels/layout; identifiers LTR; preserve time, number-axis and transfer direction.

FIX-P09-06

Sources & claim boundaries

S09-STRUCTURES · official_documentation_or_standard

Solana RPC JSON Structures

Supported claim
Result metadata, fee, instructions and balances as distinct views.
Verification boundary
Primary page inspected; no illustrative ledger values or entity labels independently verified.
Checked at
2026-09-30
Open primary source
https://solana.com/docs/rpc/json-structures

S09-SIGNATURES · official_documentation_or_standard

Solana getSignaturesForAddress

Supported claim
Referenced-address signature history, newest-first order and pagination.
Verification boundary
Primary page inspected; no illustrative ledger values or entity labels independently verified.
Checked at
2026-09-30
Open primary source
https://solana.com/docs/rpc/http/getsignaturesforaddress

S09-PDA · official_documentation_or_standard

Solana Program Derived Addresses

Supported claim
Program-derived addresses and program signing; no PDA private key.
Verification boundary
Primary page inspected; no illustrative ledger values or entity labels independently verified.
Checked at
2026-09-30
Open primary source
https://solana.com/docs/core/pda

Dataset provenance

id: FIX-P09-06

dataStatus: ILLUSTRATIVE

observedAt: null

source: Original frozen educational records embedded in this lesson

scope: Closed fictional co-funded cohort, internal transfer, zero-value app calls and unverified label.

identifiers: Invalid training labels; no usable addresses or signatures

timeBasis: Synthetic S/T or SIM-DAY markers explicitly defined in example; no real ledger/UTC observation

Test your reasoning

P09-L06-Q1 · What is the reproducibly supported group?
P09-L06-Q2 · What are final W1/W2/W3 native balances?
P09-L06-Q3 · What is external cohort funding?
P09-L06-Q4 · How should same-minute/nearby/batch clues be treated if they describe one event?
P09-L06-Q5 · Which hypothesis is uniquely proved here?