Case studies
How forensic tracing actually works
Interactive walkthroughs showing how a transaction is followed hop by hop, from the first transfer to the exchange or bank where the trail ends.
These are illustrative, constructed examples used to explain our method. They are not real client cases, real addresses or reported outcomes, and no result is implied or promised.
Illustrative example A — stablecoin transfer to an exchange
A payment sent to a fake investment platform, followed across four wallets until it reaches a centralised exchange deposit address.
What the tracing shows
Client wallet — outgoing transfer
The starting point: the transaction hash provided by the client fixes the exact amount, date and destination address on-chain.
Where the file ends up
An evidence file with the full hop list, timestamps and the exchange deposit address, addressed to the exchange compliance team and the reporting authority chosen with the client.
Illustrative example B — trail through a mixing service
A transfer that passes through a mixing service. Tracing continues by matching amounts and timing on the way out.
What the tracing shows
Client wallet
Transaction hash, amount and counterparty address are recorded as the anchor of the file.
Where the file ends up
A documented report stating clearly what could and could not be established, including the limits imposed by the mixing step.
Illustrative example C — bank wire to a shell company
Not every case is on-chain. Traditional transfers are traced through statements, correspondent banks and company registries.
What the tracing shows
Sending bank
Statement and wire confirmation fix the amount, value date and the SWIFT reference used to trace the payment.
Where the file ends up
A dispute file for the sending bank plus a report identifying the receiving entity and its registered jurisdiction.
How your evidence is protected
256-bit encryption in transit
Every form, login and upload travels over TLS with 256-bit AES encryption.
Private document storage
Files are stored in private buckets and served through signed, expiring links.
Evidence-grade case record
Every action, document and status change is timestamped in an audit log you can request.
We never ask for keys
No passwords, private keys, seed phrases, PINs or one-time codes are ever requested.
Want this applied to your case?
Start with the formal case evaluation. We tell you which protocol fits and what is realistically possible.