Blockchain & digital asset investigations
Build a technical account of relevant digital asset transactions and their connection to a reported incident. We combine supported blockchain analysis with authorised off-chain evidence, explaining what can be traced and what remains uncertain.
Discuss your requirements
Define the transaction question
The starting material may include transaction identifiers, wallet addresses, exchange statements and communications supplied by the client. We verify the relevant network and asset, clarify the reported event and establish an evidence register. The scope identifies the questions to answer: where a transfer went, how events relate in time, or which records could support a further enquiry through an authorised process.
Trace observable activity and explain the method
We analyse available transaction paths, relevant addresses, token movements and interactions with services or contracts. Each significant finding is linked to a reproducible reference where possible. Attribution labels from analytical tools are treated as claims with a stated source and confidence. Clustering assumptions, incomplete coverage and changes between networks are documented so the visual transaction map does not imply more certainty than the underlying data supports.
Connect on-chain records to the incident
A blockchain address is not, by itself, a verified person. We correlate the observed activity with client-provided records, account information, messages and lawful public-source research. Exchange or service-provider records may be needed to resolve ownership or control and are obtained through the appropriate authorised channel. We distinguish evidence of a transfer from evidence about intent, beneficiary identity or responsibility.
Assess limits before setting expectations
Some paths become difficult to follow through custodial platforms, cross-chain activity, privacy mechanisms or incomplete data. The report identifies the stopping point and explains what additional information would be needed. Technical tracing does not create the authority to freeze, seize or return assets. Recovery depends on the facts, relevant service providers and applicable legal processes; a tracing engagement does not guarantee a financial outcome.
Prepare a usable investigation package
The deliverable includes the evidence references, transaction chronology, flow diagrams and an explanation of analytical assumptions. We can prepare a technical briefing for the client’s legal team, insurer or investigators and identify specific preservation questions for relevant providers. Secure handling and restricted distribution are agreed because the package may contain sensitive financial and personal information.
Start with transaction identifiers and the reported event
A useful initial scope identifies the network, relevant transaction references, dates and the event the client needs to understand. We compare observable transfers with the supplied incident account and explain the units and time references used. The analysis should not require private keys or wallet recovery phrases; those secrets do not establish the research question and should remain protected.
Explain address labels and attribution confidence
A transaction graph shows relationships between addresses, not necessarily between identified people. Labels from tools or third parties need to be assessed for their source and reliability. We distinguish direct observations from attribution assumptions and identify where exchange records or other off-chain information would be needed. This helps legal and investigative recipients understand what the graph supports.
Deliver a package another specialist can follow
The report can include relevant transaction references, a scoped flow diagram, research dates and a narrative of the observed movement. Complex services or gaps are marked where they limit tracing. The recipient should be able to distinguish the visible flow from any unverified conclusion about ownership, intent or recovery prospects. Further requests to providers or authorities are coordinated by the appropriately authorised parties.
What you receive
- Validated starting records and investigation scope
- Referenced transaction chronology and flow map
- Attribution assessment with confidence and assumptions
- Technical evidence package and unresolved questions
- Provider-record and preservation requirements for advisers
- Scoped transaction-flow diagram with traceable references
- Attribution assumptions and off-chain evidence requirements
Common questions
Can you guarantee recovery of cryptocurrency?
No. We provide technical investigation. Tracing, freezing and recovery are different activities, and recovery depends on external parties and the applicable legal process.
Does an address identify its owner?
Not necessarily. Ownership or control requires corroborating evidence; a tool label or transaction connection is not automatically a verified identity.
Should we send private keys or recovery phrases?
No. An initial enquiry should contain a brief description only. Relevant records and any sensitive evidence are exchanged through an agreed secure process.
Can you analyse more than one blockchain in the same matter?
We first assess the relevant networks, services and available data. Cross-network movement can introduce gaps or ambiguity, which are reflected in the proposed scope and final findings.
Can a tracing report be given to a lawyer or law-enforcement contact?
A report can be prepared for agreed authorised recipients with source references and methodological limits. Decisions about formal submission or legal action remain with the commissioning party and its advisers.
Connected expertise
All services
Corporate & insider investigations
Confidential technical investigations into suspected insider activity, IP loss, digital fraud and misuse of corporate information.
Explore service
Threat intelligence & brand protection
Open-source research, threat intelligence, social media monitoring, and assessment of impersonation and digital exposure.
Explore service
Computer & mobile forensics
Forensic examination of computers, phones, storage media and backups, with documented acquisition, timelines and evidence limitations.
Explore service