A token sale publishes a story: a supply, a window, a price curve, a roadmap. The blockchain publishes a different thing entirely — a set of addresses and the times at which coins moved between them. When the two disagree, the chain is the one that is not marketing.
This guide sets out six checks you can run yourself, in a block explorer, with no paid tools and no special access. Each is scored against a live example: the LEAF sale, protocol string ico-20, which opened on Bitcoin’s base layer on Saturday 12 September 2026, advertised a 9,666-block mint window, and moved every satoshi out of its treasury address on Sunday 13 September. The full record is in this desk’s reporting. Here we are interested in the method, not the project.
The checks work on any sale that raises to an on-chain address, which is most of them. Nothing here requires you to have participated, and nothing here will tell you whether a token will be worth anything. What it will tell you is whether the money is where the sale said it would be.
Before you start: find the two addresses
Almost every on-chain sale has two addresses that matter, and they are usually different.
The treasury is where your money goes. The protocol address, if there is one, is where a marker output goes — a dust payment that identifies the transaction as belonging to the sale. Some sales have only a treasury. Some route through a contract. On Bitcoin, sales that use OP_RETURN payloads typically have both.
Find them from a transaction, not from the website. Take any confirmed participation transaction — yours, or one you find by searching the protocol string — and open it in an explorer. The outputs will show you the treasury (the large value), the protocol marker (a tiny fixed value, often 330 or 546 satoshis) and your change. Write both addresses down. Do not take them from a Telegram message, a pinned tweet or a QR code; those are among the most commonly substituted artefacts in this field. The address-level techniques are in Field Guide #47.
For the worked example: the treasury is bc1pq43ahs…sypleaf and the protocol marker address is the Bitcoin address holding 598.5 BTC retained from the Liquid sidechain exploit — an unusual pairing that is itself the subject of separate reporting.
Check 1 — Establish the window, in blocks, from the deploy
Sales advertise durations in days. Chains measure in blocks. The conversion is where the first misreading happens, because a chain does not produce blocks on a schedule — it produces them at an average rate that varies by up to a third either side for weeks at a time.
Find the deploy or launch transaction and record its block height, not its date. Add the advertised window in blocks. That gives you an end height. Then compare the end height to the current tip. The difference, divided by the chain’s current average block interval, gives you a real estimate of the remaining time — and it will usually differ from the marketing figure.
Scored: the deploy landed in block 966,606 at 03:05:37 UTC on 12 September. The advertised window was 9,666 blocks, “about 67 days”. So the sale ends at block 976,272. The treasury was emptied at block 966,807 — 201 blocks in, 2.08% of the way through, with 9,465 blocks left. Framing it in days would have made this look like “day two of sixty-seven”, which is true but soft. Framing it in blocks makes it exact.
What a clean sale looks like: the treasury is still accumulating when the window is 2% elapsed. That is the entire point of a window.
Check 2 — Pull the treasury’s full transaction list and find every spend
This is the check that does the work, and it is the one people skip because the summary page looks sufficient. It is not.
An explorer’s address page shows you a balance and a transaction count. What you need is the list of transactions in which the address appears as an input — that is, transactions where it spent, rather than received. On a busy address, spends can be four transactions out of twelve hundred, and they will not be on the first page.
Most explorers let you page through the full chain history. Work through it and flag every transaction where the treasury address appears on the input side. For each one, record: block height, timestamp, number of inputs consolidated, every output value and destination, and the fee.
Scored: the LEAF treasury has 1,125 transactions. Exactly eight are spends. One is the deploy. The other seven are the sweep, and they arrive in two tight clusters — four in block 966,807 at 10:42:24 UTC, three in block 966,817 at 12:03:36 UTC, eighty-one minutes apart. Together they consolidated 843 inputs and moved 133,500,000 satoshis for 147,373 satoshis of fees.
Read the clustering. Seven transactions in two blocks is not a treasury paying bills over time. It is a single decision, executed once, by someone who was at a keyboard for those eighty-one minutes.
Check 3 — Age the destination addresses
Where the money went tells you less than how old the place it went to is.
For each destination, open its address page and look at the transaction count and the oldest transaction. There are three cases, and they mean different things:
- An exchange deposit address. Usually identifiable by heavy, mixed traffic and rapid onward consolidation. Means the operator is converting to fiat or another asset, and that a regulated intermediary now has a record.
- An established address with history. Means the operator is moving into an existing pot — a cold wallet, a company treasury, a market-making float. Comparatively benign, and checkable against the project’s own disclosures if it has made any.
- A fresh address whose first-ever transaction is the one you are looking at. Means a new container was created specifically to receive this money. This is what cold storage looks like. It is also what cashing out looks like. On its own it distinguishes neither — but combined with Check 4, it often does.
Scored: all three LEAF destinations were fresh. Address A (bc1qeyylxht…ujajqt, native SegWit) had a lifetime transaction count of zero before 10:42:24 UTC on 13 September. So did address B (bc1pa8vrkzs…qrffjrs, Taproot) and address C (bc1ppszyukd…qtvezl8, Taproot). Their first appearance in Bitcoin’s history is the sweep.
Check 4 — Look at the split, then follow the next hop
The shape of a distribution is evidence. Round numbers that repeat are a decision; ragged numbers are usually an algorithm or a cost.
Compute each destination’s share of the total. Then — and this is the step that separates a useful check from a screenshot — go to each destination and see whether it has spent again, how quickly, and into what.
Speed is informative. Coins that sit for weeks behave like savings. Coins that move within hours, in a round amount, with a small remainder returning as change, behave like a withdrawal.
Scored: A and B received exactly 60,500,000 satoshis each — 60,000,000 in the first cluster, 500,000 in the second — and C received 12,500,000. Shares: 45.32% / 45.32% / 9.36%. Two identical halves and a smaller third.
Then the hops. B spent its 60,000,000 at 14:27:31 UTC, two hours and twenty-four minutes after the second cluster, in a transaction that also carried an OP_RETURN reading {"p":"ico-20","op":"transfer","tick":"LEAF","amt":"100000"} — the sale’s own protocol string, instructing a transfer of 100,000 tokens. A spent its 60,000,000 twelve minutes later at 14:39:46 UTC, sending 2,100,000 satoshis onward and 57,899,577 back to itself. C has not moved at all.
What you can and cannot conclude. An equal two-way split is consistent with two partners. It is equally consistent with one person using two wallets. The chain does not distinguish them until the two addresses co-sign — that is, until a single transaction spends outputs belonging to both. Common-input ownership is the test; identical amounts are not. Say which one you have.
Check 5 — Compute the fee-to-delivery ratio and the blockspace cost
This check measures whether a sale is economically sane for the people paying into it, and it is almost never published by anyone.
Sum the miner fees paid by every participation transaction. Then sum what those transactions actually delivered to the protocol marker address. Divide. If participants are paying several satoshis in fees for every satoshi that arrives anywhere, the mechanism is burning the majority of its own throughput on overhead.
Then compute the blockspace: total virtual bytes across all participation transactions, divided by the number of distinct blocks they occupied, as a share of the one-million-vB block limit. This tells you what the sale cost everyone else.
Scored: LEAF’s 1,114 mints paid 1,344,703 satoshis in fees and delivered 367,620 satoshis to the marker address — mints only, excluding the deploy. That is 3.66 satoshis of fee per satoshi delivered. They occupied 765,745 virtual bytes across 82 blocks — an average of about 0.93% of a block, every block, for a day and a half.
The interpretation is narrow and worth stating carefully. A high ratio does not mean fraud. It means the marker payment is not where the value is — the value is in the separate commitment to the treasury, and the marker is a tag. But it does tell you that participants are paying a real, quantifiable toll to be counted, and that toll is a floor under what the token must eventually be worth for them to break even.
Check 6 — Measure concentration among the funders
The last check asks who was actually in the room.
For every participation transaction, record the address that funded it. Count distinct funders. Count how many participations the largest funders made, and what share of the money they put in. Then compare the two: share of transactions and share of value can be wildly different, and the gap is the finding.
This distinguishes a genuine crowd from a manufactured one. A sale where five addresses made 60% of the participations was mostly talking to itself. A sale with hundreds of distinct funders and a small median ticket reached real people — which raises, rather than lowers, the stakes on everything else you have found.
Scored: LEAF had 875 distinct funding addresses across 1,114 mints. The busiest single funder made 8 mints — 0.7%. The top five together made 33 mints, 3.0% of the total, but contributed 17.1% of the satoshis. The median commitment was 30,000 satoshis, about twenty-three dollars. Eighteen mints committed the bare 330-satoshi dust and nothing more; 252 committed 1,000 satoshis or less; 32 committed 0.01 BTC or more; the largest single commitment was 6,400,000 satoshis.
So: a wide, shallow, genuinely distributed crowd, with a value concentration nearly six times its transaction concentration — 17.1% of the money from 2.96% of the mints. That is what a real retail rush looks like.
Putting the six together
Run in sequence, the checks produce a timeline rather than a verdict, and the timeline is what you report:
- Window (Check 1): 201 of 9,666 blocks elapsed — 2.08%.
- Spends (Check 2): 7 transactions, 2 blocks, 81 minutes, 843 inputs, 133,500,000 satoshis.
- Destinations (Check 3): 3 addresses, all with zero prior history.
- Split and hops (Check 4): 45.32% / 45.32% / 9.36%; two of three moved on within two hours and forty minutes of the second cluster; one carried a token-transfer instruction.
- Economics (Check 5): 3.66 satoshis of fee per satoshi delivered; 0.93% of every block for 36 hours.
- Crowd (Check 6): 875 funders, median ticket about $23, top five 3.0% of mints and 17.1% of value.
Add the one piece of context that no single check produces — the rate. LEAF’s mints peaked at 381 in the hour to 01:00 UTC on 13 September, then ran 233, 131, 39, 2, 1, 1. The sweep began at 10:42, roughly seven hours after the last hour with more than ten mints. The money left after the money stopped arriving, not before.
What these checks do not tell you
Discipline here is the difference between analysis and an accusation, so be explicit about the limits.
- They do not establish ownership. Fresh addresses receiving equal shares are not proof of two people, or of one. Only a common-input spend settles that.
- They do not establish intent. Operators move funds to cold storage, pay contractors, seed marketplace liquidity and hedge, all legitimately, and all of it looks like this on-chain.
- They do not establish loss. Nobody has lost anything until a token that was promised fails to be delivered or fails to be worth what was paid. A treasury movement is not that event.
- They do not tell you a price. Be especially careful with ticker collisions: there is a token called LEAF quoted publicly at $0.1755 that is a different asset entirely from the ico-20 LEAF described here. Matching three letters is not matching an asset.
- They do not read the specification. This desk verified 1,114 transactions; it did not verify a published spec that requires them to look that way.
What the checks do give you is a set of statements that are true regardless of anyone’s intentions, each traceable to a block height and a timestamp, each reproducible by a reader in about twenty minutes. That is the whole ambition of this guide.
The one-line version
Find the treasury from a transaction, not a website. Convert the window to blocks. List every spend, not every transaction. Age the destinations. Follow the next hop and watch the clock. Divide fees by delivery. Count the funders two ways. Then say only what those numbers say.
Earlier guides in this series cover the neighbouring problems: reading a flooded address, reading a chain rollback, reading a whitehat’s bounty demand, reading a sidechain peg incident, reading a hardware-wallet breach notice and checking whether a treasury company bought well. The full set is in the Reading Room.
New marker AK1: address C — the 12,500,000-satoshi share, unspent since 12:03:36 UTC on 13 September — spends at least one output by Monday 21 September. Reading at publication: unspent. This is the cleanest single test of whether the third share behaves like a fee or like a wallet.
Method: prices, funding, open interest, basis, mining and on-chain figures in this article are pulled directly by Bitcoin Mastery at the timestamp stated — Bitstamp BTC/USD daily candles for closes, Binance BTCUSDT spot and USDT-margined perpetual for intraday, open interest, funding and account ratios, Binance COIN-M quarterly contracts for basis, mempool.space for difficulty, hashrate, address balances and individual Bitcoin transactions, blockstream.info’s Liquid API for sidechain block heights, hashes, timestamps and transaction counts, alternative.me for the Fear & Greed series and Farside Investors’ table for ETF flows. Transaction counts, fee totals, byte totals and OP_RETURN payloads are recomputed from the full confirmed transaction list of the address concerned, not read off a summary. Where a third-party figure is cited we name the source and its date; where two sources disagree we print both. Every streak or extreme figure is published with the first date of its series in the same sentence.
Disclaimer: This article is for informational purposes only and does not constitute investment advice. Cryptocurrencies are volatile and you can lose money. Nothing here is a recommendation to buy or sell any security, digital asset, token or exchange-traded fund, including MSTR, L-BTC, ORDI or the LEAF token where discussed above. Token sales of the kind described in this article are unaudited, frequently anonymous and have no obligation to deliver anything in return for a payment; treat any coin sent to one as capable of going to zero. Do your own research and consult a licensed financial advisor before making investment decisions.