Primary figures from our own case register. Where a figure covers a period, the period is stated — a number without a period is not evidence.
The full set, each figure with the date it was measured, is on the data page; the registry entries behind the company are on credentials.
Businesses that lost assets. Our reference case is corporate: 5,000,000 USDT recovered for the payment processor CoinsPaid after a major theft — covered by Bitcoin.com News, verifiable without a single document from us. Another documented case: $1.8M stolen from a corporate holder, $1.6M of it frozen in July 2025 before it could be laundered onward.
Counsel and compliance teams running their own case. Where a law firm, an insurer or an internal compliance function is already handling the matter, the engagement can be scoped to the forensic work alone (the trace and the report), with the legal steps staying with your lawyers. We do not practise law, and this arrangement is the normal one, not an exception.
Individuals with a case worth investigating. Private wallet drains, exchange-bound thefts, address-manipulation losses — our case file documents both corporate and private engagements. The published threshold is a loss from $200,000; smaller cases are reviewed individually.
People preparing a legal case. A police report and a court filing need on-chain evidence in a form an institution will accept. Our forensic reports are built for exactly that use, and cases typically require a police report in your jurisdiction before a provisional freeze becomes a formal block. The legal steps themselves are executed by partner lawyers admitted in the relevant jurisdiction, under our case management — we do not practise law, and we say so on every page.
The assessment is free and answered within two business hours — including the honest answer that there is nothing to investigate. A meaningful share of enquiries ends exactly there, at no cost.
These are two different products, and firms that blur them are usually selling the second while only delivering the first. An investigation establishes what happened and where the assets are, and ends in a report. Recovery is what third parties do with that report, and the decision belongs to them, not to us.
| Forensic investigation | Asset recovery | |
|---|---|---|
| What it produces | A documented trace and an evidence pack | Funds released back to the owner |
| Who decides the outcome | The chain — the transactions either link or they do not | Exchanges, token issuers, police and courts |
| Typical duration | Days to weeks | 6–9 months from an exchange; 6–36 months for complex cases |
| Can it stand alone | Yes — for insurance, an internal investigation, a regulator, a probate or shareholder dispute | No — recovery without forensics is a request with nothing behind it |
| What we can commit to | The work and the report | Never the result. No firm honestly can |
Every recovery starts with forensics. Not every forensic investigation ends in recovery, and when the trace shows there is no realistic path, we say so and stop, rather than sell the next stage. What a full recovery engagement involves is set out on the recovery process page.
What you provide at intake. Transaction hashes and addresses, the dates and amounts, and the narrative of what happened: how contact was made, which platform or wallet was involved, what was signed or approved, and any correspondence, domains and screenshots you still have. Nothing else is required to open an assessment, and the assessment costs nothing.
What we read on-chain. Native and token transfers; internal calls; smart-contract event logs; token approvals — the mechanism behind wallet-drainer losses; bridge deposits and the matching withdrawal on the receiving chain; swaps through decentralised exchanges; and deposits into services that hold customer funds.
What we add from outside the chain. Attribution and risk data from the platforms we work with — Global Ledger and BitOK, both partnerships confirmed on the partners’ own sites — plus public sanctions listings and the structure of exchange deposit addresses.
The identity behind an address is not on the chain. It exists inside a regulated service that performed KYC, and it is released through legal process — not through a tool, and not for a fee. Anyone offering you a name from an address is selling something else.
Chains covered: Ethereum · Bitcoin · Tron · BSC · Polygon · Solana, including cross-chain cases. Monero is not covered — see «what we do not do» below.
Obfuscation is not exotic any more — it is the default. Four techniques cover most of what we see, and each has a forensic counterpart. None of them is magic: they are documented procedures with stated inputs and thresholds, which is what makes a finding reviewable by someone who was not in the room.
| What the funds are put through | How the trail is picked back up |
|---|---|
| Chain hopping — assets moved across blockchains through bridges to break continuity | The deposit on one chain is correlated with the withdrawal on the other through bridge contract events, amounts and timing |
| Mixers and tumblers — funds pooled with other users and paid out in fragments | Volume and timing correlation and peel-chain tracking across the exits, to narrow the anonymity set rather than guess inside it |
| DEX swaps — the tracked token exchanged for another asset with no custodian involved | Contract event logs are parsed and the value is followed through the calls, instead of following the surface token transfer |
| Address fan-out — proceeds split across hundreds of fresh addresses | Clustering: common-input-ownership on UTXO chains, contract-interaction and gas-funding patterns on account chains — many addresses resolve to one operator |
Reproducibility. Every heuristic result is recorded with its inputs and thresholds, so a second analyst can run the same steps and reach the same conclusion or show where it fails. A finding nobody else can re-derive is an opinion, and opinions do not move compliance departments.
Attribution only where it is real. Wallets are scored by proximity to known illicit clusters, darknet markets and sanctioned entities, and named only where funds touch a regulated service that can be reached through legal process. Everything else is described as what it is: an unattributed cluster.
Two clocks run in every case and they are nothing alike. Stopping an asset is measured in hours and days. Returning it to its owner is measured in months. Quoting the fast number for the slow process is the single most common thing dishonest sites do, so both are printed here.
You send transaction hashes, addresses, amounts and what happened. Nothing is charged and nothing is signed at this stage.
A free call: whether the assets are traceable, whether they have already reached a service that can act, and whether there is a realistic path at all. If there is not, that is the answer you get.
Identity checks through Sumsub, then the agreement — scope, commercial terms and what happens if nothing is recovered, all fixed in writing before any work begins.
The forensic core: the movement of funds is reconstructed hop by hop across chains, bridges, mixers and swaps, and the receiving addresses are clustered and scored.
The stolen transactions are flagged with AML providers, so that the assets are marked before they reach an exchange counter.
Filed with the services holding the funds, with the evidence attached. A stablecoin issuer is approached through its official procedure — we claim no private channel to any issuer, because we have none.
The evidence pack goes to you and your counsel; a report to the police in your jurisdiction is normally what turns a provisional freeze into a formal block.
Partner lawyers in the relevant jurisdiction carry the evidence into proceedings, under our case management.
By court decision or issuer payout. This is the slow clock, and it is the honest one.
What the flagging in step 05 does and does not achieve is set out on AML monitoring; the eleven steps a full recovery engagement runs through are on the recovery process page.
It describes a freeze, never a return. In the CoinsPaid case the freeze landed inside it, and across our own cases the freeze was already in place two days in 42% of the time — a measured share of what has happened, not a window anyone commits to. Any site that quotes 48 hours as the time to get your money back is describing a process that does not exist.
Where the funds moved, hop by hop, across chains and through mixers, until they touch a service with a compliance department — an exchange, a processor, a stablecoin issuer.
The trace, formatted and sourced so that an exchange compliance team, a police unit or a court can act on it — not a PDF of screenshots.
AML flagging within 4 hours; a freeze request to an exchange takes 2–4 days; a stablecoin issuer responds through its official procedure in 24–62 hours.
Partner lawyers admitted in the relevant jurisdiction take the evidence forward until funds are released by court decision or issuer payout.
The report is the deliverable, so it is worth knowing what a serious one contains before you commission one from anybody. Ours is built around a single test: a reader who has never spoken to us should be able to follow every conclusion back to a transaction they can open themselves.
Reporting standards for court-bound work are set out separately on blockchain forensics; the tracing techniques behind the trace itself are on crypto tracing and mixer tracing, and the schemes behind the losses themselves on types of crypto scam.
A forensic report is not self-executing. It is read by people who then decide something: an exchange compliance officer deciding whether to hold a balance, a police unit deciding whether to open a file, a lawyer deciding what to plead, a court deciding whether to order a transfer. The report is built for those four readers, and its structure follows from that.
The usual sequence. The evidence pack supports a freeze request while the assets are still moving; a police report in your jurisdiction then converts a provisional hold into a formal block; the same material goes into the civil or criminal filing that follows.
Who takes the legal steps. We do not. StarCompliance does not practise law: proceedings are run by partner lawyers admitted in the relevant jurisdiction, across the 12 jurisdictions we work in, under our case management. That division is stated in the engagement agreement and on every page of this site, because a forensics firm claiming to litigate is a red flag in itself.
Whether funds come back is decided by courts, exchanges and token issuers. We commit to the investigation and the report, and we publish the real timelines above. Any firm guaranteeing a recovery outcome is telling you something it cannot know.
If you searched for blockchain forensic software, note the difference: a software licence gives your team a tracing tool; an investigations firm gives you the finished evidence and carries the case to institutions. We are not a software vendor. Our investigators work with partner platforms — Global Ledger (partnership announced on their blog, 22 September 2025, with a quote from our CEO) and BitOK (partnership confirmed on BitOK’s own site) — both confirmed on the partners’ own sites, which is the only kind of partnership claim worth reading.
If your organisation needs tooling rather than an investigation, those partners are the right starting point. If you need the funds found, frozen and returned — that is us.
The investigators are in-house. 30+ analysts and investigators employed by the company, not a coordination layer over freelancers. The forensic work — tracing, clustering, evidence preparation — is done by our own team; the legal steps are the part we hand to admitted lawyers, and we name that split rather than blur it.
The company is a licensed entity, and the entry is checkable. STAR COMPLIANCE CYBER RISK MANAGEMENT SERVICES L.L.C, trade licence No. 1135542, register No. 1876962, DCCI 439332, issued in Dubai on 12 January 2023 and valid to 11 January 2027. The company has been operating since 2022 and licensed in Dubai since January 2023 — both dates, because one without the other is how companies quietly age themselves. Every registry entry is listed on credentials.
The public record exists outside this website. Our CEO was interviewed by ForkLog on 23 July 2024, and the CoinsPaid recovery was covered by Bitcoin.com News on 30 April 2025. Coverage we did not publish ourselves is collected on press, and the ten-point check we invite you to run on us (and on anyone else you are considering) is on verify.
This list costs us clients. It stays because a firm without limits is a firm without compliance obligations.
CoinsPaid — recovered for the payment processor after a major theft, documented outside this website — covered by Bitcoin.com News, with the story told by the affected company, not by us. The forensics behind it — the tracing, the evidence pack, the freeze — is the work this page describes.
How a full engagement runs end to end, with stage-by-stage timelines and acceptance limits, is on the recovery process page; the rest of the documented case file is in the case file, and the ten-point check we invite you to run on us is on the verification page.
Send the transaction hashes and what happened. Within two business hours you get a person’s answer on whether this is traceable, what the realistic path looks like, and how long each stage takes — including the answer that there is nothing worth investigating. Nothing is charged and nothing is signed at that stage.
Request a free case assessmentFounder and CEO, StarCompliance · blockchain investigations since 2022 · interviewed by ForkLog, 23 July 2024 · on Bitcoin.com News, 30 April 2025 · LinkedIn. The registry record behind that name is on credentials, and every external mention of it on press.
Reviewed by: compliance reviewer — not named: no reviewer profile has been supplied. We would rather name nobody than name someone we have not asked.
Disclaimer. This page is informational and is not legal advice. Outcomes in asset recovery depend on courts, exchanges and token issuers, and no outcome is promised. Figures are from our own case register as of 9 September 2026, and each is published with the period it covers. StarCompliance does not practise law; legal steps are executed by admitted lawyers in the relevant jurisdiction.
This page describes the investigation service. If you are still working out what happened to you, the guides below explain each type of theft on its own terms — how the scheme runs, what evidence survives it, and what recovery realistically looks like.