"Crypto digital forensics" is used to sell two different things, and a person who has just lost funds needs both. The first is the forensics of the theft itself: how the money left — which device, which key, which signature, which message. The second is the forensics of the chain: where the money went, who holds it now, and whether that party will answer a request. This article sets out what each half establishes, what a forensic investigation actually produces, and where it sits in an asset recovery case.
Two questions, two kinds of evidence
How did the funds leave? A theft has a mechanism, and the mechanism is evidence. A seed phrase typed into a fake wallet page. A token approval signed on a site that looked like a mint. A SIM swap that let someone reset an exchange login. Malware on the laptop that swapped the address in the clipboard. Each of these leaves traces outside the blockchain — in the browser, the device, the exchange's login history, the messages that led up to it — and each changes what happens next: whether the wallet is still compromised, whether more can be lost, and which of the standard scam types the case belongs to. We describe those types, and what can realistically follow each one, on the scam types page.
Where did the funds go? The transaction that took the money is public, and so is every transaction after it. On-chain forensics reconstructs that path: through splits, swaps, bridges and mixers, to the addresses where the funds stopped — and, critically, establishes which of those addresses belong to a service with a compliance desk. This is the half that decides whether there is a case at all, because an exchange can freeze a balance and a self-custody wallet cannot be asked to do anything.
The two halves feed each other. The device side tells you the theft was a drainer contract, which tells the chain side which approval transaction to start from. The chain side shows the funds reached an exchange, which tells the device side what the police report needs to say for that exchange to act on it.
What is preserved first, and how
Forensics begins before analysis: with preservation, because the value of evidence drops with every action taken on the compromised device or wallet. What we ask for on day one, and what a victim can secure alone in the first hour:
- The transaction hashes of the theft and the addresses that received the funds — copied from your own wallet or exchange history, not from a screenshot of the scam site.
- Every message, page and contact that led to the loss: the chat, the link, the app, the phone number, the "support agent". Originals, uncropped, with timestamps.
- The state of the device and the accounts: which wallet software, which browser extension, whether the seed phrase was ever typed anywhere, which exchange logins exist and from where.
- The token approvals still active on the affected addresses, so that a drainer cannot take the next deposit.
Once material reaches us, it is fixed: in our practice evidence is fixed with SHA-256 hashes and a chain of custody is kept when it is handled, so that a file can later be shown to be the same file that was collected. That is a procedural discipline, not a legal claim — whether a given court accepts a given piece of evidence is that court's decision, and a chain of custody is what makes the question answerable rather than an argument.
What an on-chain forensic investigation establishes
The work has a shape, and the deliverable is the same whether the reader is an exchange, a police unit or a lawyer.
- The path. The movement of the specific sum from the theft transaction to the present, across chains and assets, with a hash behind every step — including the steps an explorer does not show cleanly: contract calls, bridge deposits matched to withdrawals on another chain, swaps that change the asset. The mechanics are on the crypto tracing page.
- The operator. A thief uses many addresses; clustering shows which of them are controlled by one party. Fifty addresses become one operator, and "the funds are scattered" becomes "the funds are in three places".
- The endpoints. Which of those places is a centralised exchange, a payment processor, an OTC desk — a party that can be asked — and which is a self-custody wallet or a mixer, which cannot. Attribution is stated with its confidence; an address is either attributed to a named service or it is not, and the report says which.
- The breaks. Where the trail runs through a mixer or a chain-hop, the analysis is statistical — volume and timing correlation — and is reported as a hypothesis with a confidence level, not as a fact. What that looks like is on the mixer tracing page.
- The answer. Are the funds, or part of them, at a venue that can freeze them, and are they still there? Everything the legal side does is built on that sentence, and the preliminary sweep that produces it happens before any contract is signed.
What the report is for, and who reads it
A forensic report has four readers, and it is written for all of them at once. The exchange's compliance team reads it to decide whether to place a provisional hold — in our cases a freeze request with a proper evidence pack takes 2–4 days at an exchange, and a request to a stablecoin issuer through its published procedure is answered in 24–62 hours. The police unit reads it so that the case has addresses and hashes in it rather than a description of a website; a police report or other formal law-enforcement documentation may support a longer-term or more formal freeze, depending on the venue and jurisdiction. The lawyer reads it to know whom to write to and in which jurisdiction. And a court, months later, reads it to decide whether the frozen funds go back to the victim.
What makes a report usable by all four is the same property: every claim in it points to something the reader can check — a transaction, a source, a labelled inference. What a report of ours contains is set out on the blockchain forensics page. What it never contains is a promise about what any of the four readers will decide.
Where forensics sits in a recovery case
It is the front of the process, not the whole of it. In the eleven steps we publish on the recovery process page, the forensic work is the preliminary sweep before any contract (step 02) and the full investigation report after it (step 04). Around it, on a clock of their own, run the actions the report makes possible: the stolen transactions are flagged with the AML screening providers exchanges rely on within four hours of intake — what that does and does not do is on the AML monitoring page — and, depending on the case and jurisdiction, freeze requests may be submitted to the venues the trace identified through law-enforcement or other accepted legal or compliance channels, supported by investigation materials such as the report. After a freeze, the case leaves forensics and becomes legal work, on two separate routes: a return from an exchange typically comes on a court decision, in our cases 6–9 months later; a first payout through a stablecoin issuer, in our cases, 12–20 months in; complex or multi-jurisdiction cases run 6–36 months. The legal steps are carried out by partner law firms admitted in the relevant jurisdiction — we do not practise law. All of the clocks, with the dates they were measured, are on our figures page.
What forensics cannot do
- Name the thief. On-chain evidence reaches a service; the service holds the identity and releases it to an authority or a court, not to a private firm.
- Reverse a transaction. Nothing on any public blockchain can be undone; what can happen is a freeze at a party who holds the funds, and a return ordered later.
- Work Monero cases. Its design means we cannot produce the evidence an exchange or a court would need, so we decline those cases rather than bill the attempt.
- Produce a case out of a loss that is too small to pursue. Our published threshold is a loss from $200,000; smaller cases are reviewed individually, and the honest answer at that size is often that the free steps — reporting, notifying the exchange — are the whole of what makes sense.
- Guarantee anything. Exchanges, issuers, police and courts decide; forensics gives them something to decide on.
When to commission it, and what it costs to ask
The assessment is free, and we aim to respond within two business hours of receiving the hashes — including when the answer is that there is nothing to pursue. If a case is opened, identity checks and the contract are completed through Sumsub before any work starts; an upfront retainer is payable before work begins and is not refundable, and the fees that follow are commissions on the funds actually frozen and on the funds actually returned. No amounts or percentages are published — the terms are fixed in the engagement agreement. Where funds come back through a stablecoin issuer's reissue, the issuer charges its own fee — about 20–25% of the amount — which is not ours. We do not take cases where the source of the funds cannot be confirmed, and we stop work if a client misstates the facts. How to check those statements — and any other firm's — without contacting anyone is on the verification page.
If the funds are traceable and the loss is significant, send us the transaction hashes: the assessment is free, and we aim to respond within two business hours, including when the answer is that there is nothing to pursue. Write through the contact page or message @StarCompliance on Telegram.
Questions people ask about crypto forensics
Do I need forensics if I already know the address the funds went to?
The receiving address is the start of the trail, not the end of it. Funds rarely stay at the first address; what matters is where they stopped and whether that place will answer a request. Establishing that is the forensic work.
Can I do the tracing myself with a block explorer?
For one or two hops, often yes. The trail usually breaks at a bridge, a swap or an exchange deposit address, where an explorer shows a transfer but not what it means. The other limit is the deliverable: an exchange or a police unit acts on a report it can check, not on a list of addresses in an email.
What is the difference between crypto tracing and crypto forensics?
Tracing is the reconstruction of where the funds went. Forensics is the wider discipline — preserving evidence, establishing how the theft happened, attributing endpoints, and writing it all up so a third party can verify it. Tracing is the largest part of forensics in a theft case, but not the whole of it.
Will the forensic report be accepted in court?
That is decided by the court, and we do not claim it in advance. What we can say is what the report contains — a hash behind every step, a source behind every attribution, inferences labelled as such, artefacts hashed and logged — and that reports of this kind are what freeze requests and police filings are built on in our own cases.
How fast does the forensic part happen?
The preliminary sweep is part of the free assessment; we aim to respond within two business hours. If the case is opened, flagging of the stolen transactions happens within four hours of intake, and the full investigation report (step 04 of the published process) is what the freeze requests are built on.
Is the forensic assessment free?
Yes. The assessment is free, and we aim to respond within two business hours of receiving the hashes, including when the answer is that there is nothing to pursue. If a case is opened, the terms are fixed in the engagement agreement.
This article is informational material, not legal advice, and no outcome is promised: decisions on freezing and releasing funds are made by exchanges, issuers and courts. Figures are from StarCompliance casework and are published, with the period each covers, on our figures page.






