Process · Buyer literacy
How crypto forensics investigations work: step by step
If you've never worked with a crypto forensics firm before, the process can feel opaque — you hand over some wallet addresses and hope something comes back. In practice, it follows a fairly consistent lifecycle across the institutional-tier providers, whether you're working with a software platform or an investigative firm. Understanding the stages helps you ask better questions when you're comparing vendors, and sets realistic expectations for how long the work actually takes.
This matters most in the first hours after you notice something is wrong: knowing what evidence to preserve and what a firm will actually ask for can be the difference between a traceable case and one where the trail has already gone cold by the time you make contact.
Seven stages
The investigation lifecycle
-
Evidence submission
You provide what you have: transaction hashes (TXIDs), wallet addresses, exchange account details if relevant, and a written timeline of what happened. The more specific this is, the more a firm can actually do with it — a vague “my crypto was stolen last week” gives an investigator almost nothing to start from, while specific TXIDs let them begin tracing immediately.
-
Case-acceptance review
Before committing resources, most firms assess whether there's enough on-chain evidence to realistically proceed, and whether the case fits their acceptance criteria — some apply a minimum reported-loss threshold. This stage typically takes anywhere from a day to two weeks.
-
Cluster analysis
Investigators group wallet addresses that show behavioral or structural links — repeated co-spending patterns, shared funding sources, timing correlations — to map which addresses likely belong to the same actor, even across many separate-looking wallets designed to look unrelated.
-
Cross-chain tracing
If funds moved from one blockchain to another (via a bridge or a swap service), investigators follow that trail across chains rather than losing it at the point of conversion. This is one of the more technically demanding parts of the process, since different blockchains use different transaction structures.
-
Transaction de-mixing
When funds pass through a mixer or tumbler — a service designed to obscure the trail by pooling and redistributing funds from many users — specialized techniques attempt to probabilistically reconnect inputs to outputs. This step is where recovery odds drop the most, and where results are least certain.
-
Wallet attribution
Investigators attempt to connect a wallet cluster to a real-world identity or entity, using a combination of on-chain patterns, exchange KYC data (where legally accessible through appropriate legal process), and open-source intelligence.
-
Report or expert testimony
The findings are documented in a forensic report, which may support a law-enforcement referral, an asset-freeze request, or, if the case goes to court, expert-witness testimony explaining the methodology and conclusions under oath.
Techniques
Core techniques, explained
The vocabulary vendors use in sales calls, translated into what actually happens to your case.
-
Cluster analysis
Grouping wallet addresses likely controlled by the same entity, based on shared transaction patterns such as common inputs on a single transaction or repeated interaction with the same set of counterparties.
-
OSINT
Using publicly available information (forum posts, social media, leaked data, domain registrations, past scam reports) to connect a wallet or transaction to a real identity or a known threat actor.
-
Mixer / tumbler analysis
Probabilistic techniques for tracing funds through services designed to break the on-chain link between sender and receiver by pooling many users' funds together before redistributing them.
-
Smart-contract analysis
Reviewing a DeFi protocol's contract code line by line to understand how an exploit happened: which function was called, what assumption it violated, and where the drained funds went afterward. Relevant when the incident is a hack rather than a simple wallet theft.
-
Coin-swap tracing
Following funds through decentralized exchanges or cross-chain swap services where assets change form mid-transaction — for example, ETH swapped for a stablecoin before being bridged to another chain.
-
Sanctions screening
Checking traced wallets and counterparties against sanctions lists (OFAC and equivalent regimes), relevant both for compliance purposes and because some attacker infrastructure is already known and listed.
Firms differ in how many of these they run in-house versus license from an institutional platform — an investigative firm's own team typically handles attribution and reporting, while the underlying transaction-tracing data may come from a licensed analytics tool like Chainalysis, TRM Labs, or Elliptic. When you're comparing providers, it's reasonable to ask which of these techniques they perform themselves versus which they source from a third-party platform, since that affects both cost and how much the firm can explain about its own methodology if questioned later.
None of these techniques guarantee an outcome. Their effectiveness depends heavily on how the funds moved after the incident — which is exactly why guaranteed-recovery claims (see our scam-avoidance guide) don't hold up to how this actually works.
Deliverables
What you actually get
An engagement is only as useful as the artefacts it leaves behind. Ask which of these five a provider includes as standard, which are priced separately, and which it does not produce at all — the answer usually tells you more about a firm than its technology stack does.
-
Forensic report
The documented findings: what was traced, how, and with what confidence level. A good report explains its reasoning, not just its conclusion, so it can withstand scrutiny from an opposing party or a skeptical regulator.
-
Chain-of-custody documentation
A record proving the evidence wasn't altered between collection and presentation, required if the case may go to court. This is a formal requirement in most jurisdictions, not an optional nicety.
-
Expert witness testimony
A qualified investigator explaining the methodology and findings under oath, if the case is litigated. Firms with actual courtroom experience tend to write reports differently from day one, anticipating the questions a report will face under cross-examination.
-
Asset-freezing coordination
Where funds have been traced to an identifiable exchange or custodian, some firms coordinate directly with that platform or with law enforcement to request a freeze. This step depends heavily on jurisdiction and how cooperative the receiving platform is.
-
Ongoing monitoring, where relevant
For compliance-driven engagements rather than one-off incidents, some providers offer continuous wallet or transaction monitoring rather than a single point-in-time report, which is closer to how the institutional analytics platforms are typically used day to day.
The distinction that decides your shortlist
Institutional software vs. investigative service
Institutional tool
Platforms like Chainalysis, TRM Labs, Elliptic, and Merkle Science build the analytics software — banks, exchanges, and regulators license it and run their own tracing using in-house staff or a licensed investigator.
Investigative service
Firms like Kroll, BDO, FTI Consulting, KPMG, Crystal Intelligence, and Paranoid Security are hired directly. They run the investigation — often using those same institutional tools internally — and hand you a completed report.
If you're comparing providers, know which category you're actually looking at — “does this company investigate my case, or do I need to license a tool and do the tracing myself” is the first question to ask, and it's a fair question to put directly to any vendor's sales team before you get further into a conversation.
See the full comparison: best crypto forensics companies in the UAE — 2026 ranking →
FAQ
Process questions
How long does an investigation take?
Straightforward single-chain tracing can take days to a few weeks. Cases involving mixers, cross-chain bridging, or multiple jurisdictions can run months, especially when law-enforcement coordination is involved.
What evidence do I need to provide?
At minimum: transaction hashes (TXIDs) and the wallet addresses involved. A clear written timeline of what happened, and any exchange account information you have, speeds up the case-acceptance review significantly.
Will the findings hold up in court?
Courts weigh forensic evidence on its methodology and chain-of-custody documentation, not on the firm's name alone. Firms with actual court-testimony experience tend to structure their reports specifically for that scrutiny from the start.
Can an institutional tool like Chainalysis investigate my case directly?
Generally no — these are software platforms licensed to banks, exchanges, and regulators, not case-intake services for individual businesses. If you want a case investigated end to end, you'd typically go to an investigative firm, which may use one of these platforms internally as part of its own process.
Does every investigation involve a mixer or cross-chain tracing?
No — many cases involve funds that stayed on a single chain and moved directly to an identifiable exchange account, which is comparatively straightforward to trace. Mixer use and cross-chain movement are what push a case toward the harder end of the spectrum, not the default.