Investigation Package
Tracing, analytics, and documented findings
What's Included
- Deep Multi-Hop Cross-Chain Tracing
- Mixer (Tornado Cash) De-anonymization
- Centralized Exchange (VASP) Identification & Liaison Setup
- Official Forensic Expert Report
Investigation Package is our core blockchain forensics service for tracing stolen or misappropriated cryptocurrency through complex, obfuscated transaction paths. Unlike a basic wallet lookup, this engagement is built for cases where funds have already moved through multiple wallets, chains, or privacy tools — and where you need a documented, defensible trail rather than a rough guess at where the money went.
What This Investigation Covers
Most stolen crypto doesn’t sit in one wallet — it moves through dozens of intermediate addresses, cross-chain bridges, and privacy tools within minutes of a theft. A surface-level lookup on a block explorer won’t reconstruct that path. Our analysts manually trace each hop, cluster related addresses using on-chain heuristics, and identify where funds ultimately settle — most often a centralized exchange (VASP) where an identity check occurred at sign-up.
This isn’t automated software output run once and handed to you. Every case is worked by an analyst who reviews the chain manually, flags anomalies a script would miss (like deliberate decoy transactions or dust attacks meant to confuse tracing tools), and adjusts the investigation strategy as the trail develops. Automated clustering tools are part of our process, but they inform the analyst’s judgment — they don’t replace it.
How Multi-Hop Cross-Chain Tracing Works
When funds move across a single chain, tracing is relatively direct: each transaction has a visible sender and receiver, and clustering heuristics (common-input-ownership, change address detection, peel chain analysis) can link addresses controlled by the same actor. The complexity increases sharply once funds cross into a different blockchain — through a bridge, a cross-chain DEX aggregator, or a wrapped-asset swap.
Cross-chain hops break the simple linear trail because the destination chain has its own address space and transaction history. We reconstruct these transitions by correlating bridge contract events, timing windows between the source-chain deposit and destination-chain withdrawal, and matching transaction amounts net of bridge or swap fees. Where a case involves three, four, or more chain hops, this correlation work is repeated at each transition point until the trail either terminates at an identifiable exchange or goes cold.
We document every hop with transaction hashes, timestamps, and the reasoning behind each link — so the trail isn’t just a conclusion, it’s a reproducible chain of evidence.
Why Mixer Analysis Matters
Tornado Cash and comparable mixers are designed to break the on-chain link between deposit and withdrawal by pooling funds from many users and letting them withdraw to a new address with no direct on-chain connection to their deposit. We don’t rely on the mixer’s anonymity set alone — we cross-reference timing correlation, deposit/withdrawal amount matching, and gas-fee fingerprinting patterns built from prior cases to narrow down probable output addresses.
This kind of de-anonymization work is probabilistic, not absolute — and we’re upfront about that with clients. Depending on pool size, deposit amount uniqueness, and how quickly funds were withdrawn after mixing, we can sometimes narrow output candidates to a small set of addresses, and in favorable cases to a single one. Where certainty is limited, our report states the confidence level explicitly rather than presenting a guess as fact. This is analytical work, not guesswork, and it’s documented step by step in the final report.
Identifying the Receiving Exchange (VASP)
Once a trail lands on an address that shows exchange-style deposit patterns — high transaction frequency, consolidation from many unrelated addresses, or a known hot-wallet signature — we work to identify which Virtual Asset Service Provider (VASP) controls it. This draws on wallet-attribution databases, historical hot-wallet address sets, and behavioral fingerprints specific to major exchanges.
Identifying the exchange matters because it’s the point where the funds re-enter a KYC’d environment. An exchange that performed identity verification at account opening is also the point where a freeze request or subpoena has real leverage — which is why exchange identification is treated as a distinct deliverable in this package, not a footnote.
What You Receive
At the end of the engagement, you get a forensic report documenting the full trace: wallet clusters, transaction paths, timestamps, and the exchanges where funds were identified. The report is structured in sections — an executive summary for non-technical readers, a detailed transaction-by-transaction trace for technical or legal review, and an annex of supporting evidence (transaction hashes, screenshots of relevant blockchain explorer data, and clustering methodology notes).
This report is built to hold up under scrutiny from compliance teams, legal counsel, or law enforcement — not a casual summary. Where funds land on an identified exchange, we also set up direct liaison with that exchange’s compliance desk to support a freeze request, providing the documentation package that compliance teams typically require to act quickly.
Our Methodology & Evidentiary Standards
We work under institutional evidentiary standards, meaning every claim in the report is backed by a citable on-chain data point — a transaction hash, a timestamp, a block number — rather than an unsupported assertion. This matters if the case later moves into a legal, insurance, or law-enforcement context, where the report may need to withstand cross-examination or third-party review.
Our toolkit combines commercial blockchain analytics platforms with manual review and in-house clustering scripts built from patterns observed across hundreds of prior cases. No single tool is treated as authoritative — cross-verification between independent methods is standard practice before any conclusion goes into the final report.
Who This Package Is For
This package fits victims of wallet compromises, exchange hacks, romance-scam crypto losses, and business treasury incidents where funds have already moved beyond the original wallet. It’s also a fit for compliance teams at exchanges or fintechs who need an independent trace to support an internal investigation, and for legal counsel building a civil case who need a defensible forensic record rather than an in-house guess.
If you’re still deciding whether your case needs full tracing or just a preliminary review, our Initial Consultation is the lighter starting point — it gives you a quick assessment of whether the funds are traceable at all before you commit to a full investigation. If your case has already progressed to the point of needing subpoenas, freeze orders, or court filings, our Legal Support Package builds directly on the findings from this investigation.
What Happens After the Investigation
Once the report is delivered, next steps typically fall into one of three paths: submitting the findings to the identified exchange’s compliance team to request a freeze, handing the report to law enforcement as supporting evidence for a criminal complaint, or using it as documentation for insurance, tax-loss, or civil litigation purposes. We stay available after delivery to clarify any part of the trace for the party reviewing it — an investigator, a compliance officer, or opposing counsel.
It’s worth being direct about what this package does not do: we are not a law enforcement agency, and we cannot compel an exchange to freeze funds or force a recovery. What we deliver is the analytical foundation — a documented, defensible trail — that gives whoever acts next (an exchange, a court, an investigator) the evidence needed to act on your behalf.
Confidentiality & Case Handling
Case details, wallet addresses, and personal information are handled under strict confidentiality throughout the engagement. Intake happens through an encrypted channel, and findings are shared only with you and, where you authorize it, the specific third parties involved in recovery efforts (an exchange, your legal counsel, or law enforcement). We don’t publish case details or use client data for any purpose outside the engagement.
How It Works
-
Case Intake & Wallet Mapping We ingest your transaction hashes, wallet addresses, and incident timeline, then build an initial on-chain map of fund movement across all connected clusters.
-
Multi-Hop Cross-Chain Tracing Our analysts follow the funds through multiple hops and bridges — including cross-chain swaps — reconstructing the full path even where obfuscation layers were used.
-
Mixer De-anonymization & Clustering Where funds pass through Tornado Cash or similar mixers, we apply heuristic clustering and timing analysis to identify probable output addresses and re-link the trail.
-
Forensic Report & Exchange Liaison You receive a documented forensic report suitable for compliance, legal, or law-enforcement use, plus direct liaison setup with identified centralized exchanges (VASPs).
Frequently Asked Questions
How long does an Investigation Package take to complete?
Most cases are completed within 5–7 business days, depending on the number of hops, chains involved, and mixer complexity. Complex cross-chain cases may take longer.
Can you guarantee my funds will be recovered?
No. We are a forensic analytics firm, not a law enforcement agency or financial institution. We trace funds, identify exchanges, and document findings — recovery itself depends on exchange cooperation and legal action outside our control.
What information do I need to provide to start?
At minimum, the relevant wallet addresses and transaction hashes (TXIDs) involved in the incident, plus a brief summary of what happened and when.
Is the forensic report admissible for legal or compliance purposes?
The report is structured to institutional evidentiary standards and is commonly used to support compliance filings, legal proceedings, and law enforcement referrals, though admissibility ultimately depends on your jurisdiction.
What happens after funds are traced to an exchange?
We set up direct liaison with the identified exchange's compliance or security team to support a freeze request, alongside the documentation needed for that request.
Related Services
Ready to start your case?
Get a confidential assessment from our forensic team within 24 hours.
Get Started