Case studies

How forensic tracing actually works

Interactive walkthroughs showing how a transaction is followed hop by hop, from the first transfer to the exchange or bank where the trail ends.

These are illustrative, constructed examples used to explain our method. They are not real client cases, real addresses or reported outcomes, and no result is implied or promised.

Illustrative example A — stablecoin transfer to an exchange

A payment sent to a fake investment platform, followed across four wallets until it reaches a centralised exchange deposit address.

USDT-TRC20 · ≈ $48,000

What the tracing shows

Client wallet — outgoing transfer

The starting point: the transaction hash provided by the client fixes the exact amount, date and destination address on-chain.

Where the file ends up

An evidence file with the full hop list, timestamps and the exchange deposit address, addressed to the exchange compliance team and the reporting authority chosen with the client.

Illustrative example B — trail through a mixing service

A transfer that passes through a mixing service. Tracing continues by matching amounts and timing on the way out.

Bitcoin · ≈ 0.9 BTC

What the tracing shows

Client wallet

Transaction hash, amount and counterparty address are recorded as the anchor of the file.

Where the file ends up

A documented report stating clearly what could and could not be established, including the limits imposed by the mixing step.

Illustrative example C — bank wire to a shell company

Not every case is on-chain. Traditional transfers are traced through statements, correspondent banks and company registries.

SWIFT · ≈ $120,000

What the tracing shows

Sending bank

Statement and wire confirmation fix the amount, value date and the SWIFT reference used to trace the payment.

Where the file ends up

A dispute file for the sending bank plus a report identifying the receiving entity and its registered jurisdiction.

How your evidence is protected

  • 256-bit encryption in transit

    Every form, login and upload travels over TLS with 256-bit AES encryption.

  • Private document storage

    Files are stored in private buckets and served through signed, expiring links.

  • Evidence-grade case record

    Every action, document and status change is timestamped in an audit log you can request.

  • We never ask for keys

    No passwords, private keys, seed phrases, PINs or one-time codes are ever requested.

Want this applied to your case?

Start with the formal case evaluation. We tell you which protocol fits and what is realistically possible.