Case triage
Crypto theft & fraud: when you need a forensics investigation
Not every crypto loss is the same kind of problem, and the situation you're in changes both your realistic recovery odds and which type of firm you actually need. A wallet drainer attack and a slow-moving investment fraud call for different evidence, different urgency, and sometimes different specialists entirely. Here's a breakdown of the common case types, what affects your odds, and what to do in the first 24 hours.
Typology
Common case types
Seven patterns cover most of what reaches a forensics firm's intake queue.
-
Wallet drainer attacks
A malicious smart contract or phishing site tricks you into signing a transaction that transfers assets out of your wallet, often via a fake token approval that looks routine at the moment you sign it. These move fast — funds are typically routed through several intermediate wallets or a mixer within minutes of the initial theft, which makes reporting speed unusually important for this case type specifically.
-
Rug pulls
A DeFi project's creators withdraw liquidity or mint and dump tokens, collapsing the project's value for everyone who bought in. Tracing here focuses on the developer wallets and where the withdrawn liquidity went, and recovery is often complicated by the fact that no theft occurred in a technical sense — the funds moved through mechanisms the project's own smart contract permitted.
-
Romance scams / “pig-butchering”
A long-con fraud where a scammer builds a personal relationship, often over weeks, before persuading the victim to invest in a fake trading platform that shows fabricated returns to encourage further deposits. These often involve larger cumulative sums moved over weeks or months across multiple deposits, and victims frequently don't realize what happened until they try to withdraw funds and can't.
-
Business email compromise
An attacker impersonates a vendor or executive to redirect a legitimate crypto payment to a wallet they control — a corporate-fraud pattern that happens to use crypto as the payment rail rather than a bank wire. These cases often have a clearer paper trail than consumer-facing scams, since there's usually a genuine underlying business transaction the fraud was inserted into.
-
Ransomware
Extortion payments made in crypto to regain access to encrypted systems. Tracing these funds is often coordinated with law enforcement rather than pursued independently by the victim organization, partly because ransomware groups are frequently already known entities with previously identified wallet infrastructure.
-
DeFi exploits
A vulnerability in a protocol's smart contract is exploited to drain funds from a liquidity pool or lending platform — investigation typically requires smart-contract analysis to understand exactly how the exploit worked, alongside standard wallet tracing to follow where the drained funds went afterward.
-
Sanctions-evasion exposure
Not always theft — sometimes the issue is discovering, after the fact, that counterparties or transaction flows touch sanctioned entities, which is a compliance and AML concern rather than a straightforward “recovery” case. This case type typically calls for a compliance-oriented review rather than an incident-response investigation.
Expectations
Recovery likelihood by case type
Realistic expectations matter more than optimism here. A few factors consistently affect outcomes.
-
Speed of reporting
The faster a case is reported, the more likely funds are still sitting in an identifiable wallet or on an exchange that can be asked to freeze them. Every hour that passes gives an attacker more time to move funds further from the point of theft.
-
Mixer or tumbler usage
If the attacker routes funds through a mixing service quickly, traceability drops substantially — not to zero, but meaningfully, since de-mixing is probabilistic rather than a guaranteed reconstruction.
-
Case-acceptance thresholds
Some investigative firms apply a minimum reported-loss threshold before taking a case, simply because small cases often don't have enough on-chain evidence or investigative upside to justify the work relative to its cost.
-
Cross-border complexity
Funds that cross multiple jurisdictions and exchanges slow down both tracing and any legal freeze/recovery action, since each additional jurisdiction can mean a different legal process to compel a platform to act.
-
How the receiving platform responds
A centralized exchange that cooperates quickly with a freeze request meaningfully changes outcomes compared with funds that land on a platform with no compliance function to contact at all.
None of this means small or complex cases are hopeless — it means the honest answer to “can I get it back” is “it depends on these specific factors,” not a guaranteed percentage. Any provider that skips straight past this nuance to a confident number before reviewing your case is worth treating with the same skepticism covered in our scam-avoidance guide.
Immediate response
What to do in the first 24 hours
-
Preserve everything
Save transaction hashes (TXIDs), wallet addresses, screenshots of the incident, and any communication with the attacker or the platform involved. Write down a timeline while it's fresh — the order events happened in often matters as much as the events themselves.
-
Do not contact the attacker directly
Attempting to negotiate can complicate any later law-enforcement or legal action, and offers no real leverage since the attacker has no incentive to return funds voluntarily.
-
Report to the relevant authority
In the UAE, this typically means the local police cybercrime unit; depending on the platforms involved, you may also need to notify the exchange or VASP where funds were last seen, since some platforms can only act on a formal report or law-enforcement request.
-
Check whether the receiving platform is identifiable
If your traced funds landed on a known centralized exchange rather than an anonymous wallet, that platform may be able to freeze the account pending investigation — this window closes quickly once funds move again.
-
Avoid engaging a “guaranteed recovery” service under time pressure
This is exactly the moment scam operators target — see our scam-avoidance guide before contacting anyone promising a specific outcome. A firm that takes a day or two to properly review your case is not moving too slowly; it's doing the case-acceptance step correctly.
Next step
Once you've preserved your evidence and reported the incident, the next decision is which type of provider to approach — a licensed analytics platform your bank or exchange already uses, or an investigative firm you hire directly to run the case end to end. Our main comparison covers both categories with verifiable UAE and regional presence, scored against the same criteria for every entrant.
FAQ
Recovery expectations
Can stolen crypto actually be recovered?
Sometimes — it depends heavily on how quickly you report, whether funds passed through a mixer, and whether the receiving platform can be legally compelled to act. There's no universal percentage that applies to every case.
Does my case need to be a large amount to be investigated?
Not necessarily, but some investigative firms apply a minimum reported-loss threshold before accepting a case, since smaller cases sometimes lack enough on-chain evidence to justify a full investigation. A firm can tell you this during case-acceptance review — it's not a red flag.
Is a DeFi exploit different from a simple wallet theft?
Yes — a DeFi exploit usually requires smart-contract analysis to understand how the vulnerability was exploited, in addition to standard wallet tracing. Not every forensics provider does both equally well.
Should I report a case even if I think the funds are unrecoverable?
Yes — reporting still contributes to law-enforcement intelligence on the attacker or platform involved, and can matter for insurance, tax, or regulatory purposes even without a recovery.
Is a business email compromise (BEC) case treated differently from a consumer scam?
Often yes — because BEC typically involves a real underlying business transaction that fraud was inserted into, there's usually a clearer paper trail (invoices, internal approvals, vendor communications) than in a purely consumer-facing scam, which can make attribution more straightforward even though the sums involved are often larger.