Back

Investigation scope and hypotheses

P10-L01 · P10 · P10-M01

Define a falsifiable question and bounded chain-time scope

ILLUSTRATIVE · needs_review

Prerequisites: P08-L08 · P09-L08

Learning objectives

  • Define a falsifiable question and bounded chain-time scope
  • Write a disconfirming test before inspecting a graph.

Why this matters

A vague question such as “Who is behind this token?” quietly bundles funding, technical control, identity and motive. A bounded question lets a second analyst disagree using the same records rather than a competing story.

Explanation

Begin with a claim that can fail. Name the network, exact asset identifier, block interval and event predicate. Separate the observation you need from the hypothesis it may support. “Did output X fund input Y?” is a ledger question; “Does the same person control both?” needs a different evidential bridge.

Pre-register both supporting and disconfirming conditions. If a path is absent from an indexer, check coverage before treating absence as disconfirmation. A graph limited to one chain cannot exclude an exchange withdrawal, bridge or off-chain arrangement. Define a stop rule: when the necessary receipt or ownership evidence is unavailable, narrow the conclusion or mark INSUFFICIENT EVIDENCE. Do not widen the scope merely because a label seems interesting.

Maintain four fields for each claim: OBSERVED record, INFERRED interpretation with alternatives, UNKNOWN fact, and whether available evidence is sufficient for the proposed conclusion. UNKNOWN describes a missing fact; INSUFFICIENT EVIDENCE describes a decision about a claim. A report can observe a transfer while declining an ownership conclusion.

Key terms

Scope: network, asset, interval and predicate.

Falsifier: a record that would contradict the stated test.

Attribution bridge: evidence connecting a technical relation to the proposed controller.

Historical example

ILLUSTRATIVE: analyst R receives a screenshot claiming that fictional asset T on network N was funded by actor H. Stipulated rows show A → B at block 100 and C → B at block 102; no identity evidence exists. The proposed scope is N, blocks 99–103, exact asset T. These labels are not real addresses. The ledger predicate asks whether A funded B within that interval; a separate human-controller claim remains untested.

Visual specifications

Two-column evidence panel: ledger predicate and identity predicate. Show A → B and C → B as stipulated edges; draw no common-owner circle. Add a coverage gate and stop box.

Caption: Fictional scoped inquiry; funding edges do not identify a human.

SPECIFICATION_ONLY — the rendered visual has not been produced or independently reviewed.

What the evidence proves

Within the stipulated fixture, two funding relationships are specified and the scoped question is answerable. The plan makes collection and rejection criteria reviewable.

What the evidence does not prove

It establishes no actual chain event, identity, ownership, intent or global funding history. A small scoped result cannot become an accusation.

Common mistakes

Starting with the suspected person; treating shared destination B as shared control; silently expanding the time interval; interpreting missing provider rows as proof of no transaction.

Practical exercise

Draft a one-sentence falsifiable ledger question and a separate ownership question. Specify the interval, a falsifier, a coverage prerequisite and a stop condition. Classify the two incoming edges and actor H claim.

Show worked correction

Ledger question: “Within N blocks 99–103, does B receive a transfer from A for asset T?” Falsifier: complete decoded records for that interval show a different asset or destination. Coverage prerequisite: all blocks and relevant event types are available. A → B and C → B are OBSERVED only within this fictional fixture. Same-human control is UNKNOWN, and evidence is INSUFFICIENT for actor H attribution. Stop when the needed interval or attribution bridge cannot be obtained.

Checklist

  • Name the exact network and asset.
  • State the interval and predicate before collection.
  • List a falsifier and provider coverage prerequisite.
  • Separate ledger, control and identity claims.

Summary

A reproducible investigation begins with a claim that can fail and a scope that can be checked.

Summary

  • Bound the question before graph interpretation.
  • A funding relationship and ownership attribution require different evidence.
  • Missing coverage can prevent a conclusion.

Next lesson

P10-L02

Tools

Use the named ZECOIN tool only as an evidence-reading context. This lesson creates no tool output, account session or entitlement. Offline exercise; do not sign, deploy, approve or fund anything.

Sources & claim boundaries

  • BTC: Bitcoin developer guide — transactions — Input references identify previous transaction outputs; scripts do not identify a human. Boundary: Mechanism documentation only; original illustrative values are stipulated, not observations. Historical records have separately frozen provenance and explicit collection gaps.
  • API: Esplora public API specification — GET routes, integer satoshis and indexed confirmation/outspend fields. Boundary: Mechanism documentation only; original illustrative values are stipulated, not observations. Historical records have separately frozen provenance and explicit collection gaps.

Evidence classifications

ILLUSTRATIVE — entirely fictional offline inputs; no current observation.

Observation date

null — no real observation

Content version

1

Review date

null

Review status

needs_review

Visual specifications

P10-L01-V01

SPECIFICATION_ONLY · ILLUSTRATIVE

Define a falsifiable question and bounded chain-time scope

Fictional scoped inquiry; funding edges do not identify a human.

Two-column evidence panel: ledger predicate and identity predicate. Show A → B and C → B as stipulated edges; draw no common-owner circle. Add a coverage gate and stop box.

Two-column evidence panel: ledger predicate and identity predicate. Show A → B and C → B as stipulated edges; draw no common-owner circle. Add a coverage gate and stop box.

Stack observations, assumptions, gaps and conclusion at 390 px; retain full IDs and a complete text equivalent. Any wide table scrolls locally.

Prose may follow RTL; IDs, quantities and time axes remain LTR. Preserve dependency direction.

P10-L01-ILLUSTRATIVE-v1

Sources & claim boundaries

BTC · PRIMARY_DOCUMENTATION

Bitcoin developer guide — transactions

Supported claim
Input references identify previous transaction outputs; scripts do not identify a human.
Verification boundary
Mechanism documentation only; original illustrative values are stipulated, not observations. Historical records have separately frozen provenance and explicit collection gaps.
Checked at
2026-10-02
Open primary source
https://developer.bitcoin.org/devguide/transactions.html

API · PRIMARY_DOCUMENTATION

Esplora public API specification

Supported claim
GET routes, integer satoshis and indexed confirmation/outspend fields.
Verification boundary
Mechanism documentation only; original illustrative values are stipulated, not observations. Historical records have separately frozen provenance and explicit collection gaps.
Checked at
2026-10-02
Open primary source
https://github.com/Blockstream/esplora/blob/master/API.md

Dataset provenance

id: P10-L01-ILLUSTRATIVE-v1

dataStatus: ILLUSTRATIVE

observedAt: null

source: Original offline scenario in realOrHistoricalExample

scope: Fictional stipulated labels and values. No wallet, deployment, transaction, token launch or production observation.

Test your reasoning

P10-L01-Q1 · A and C both send to B. Which next conclusion is defensible?
P10-L01-Q2 · The API omits block 101. What should the report do?
P10-L01-Q3 · Which test can actually falsify the scoped funding claim?
P10-L01-Q4 · Why split identity from funding in the report?
P10-L01-Q5 · A required receipt cannot be obtained. Which stopping result is sound?