Forensic investigations into theft, fraud, and money laundering across public blockchains. Threat intelligence, transparency advocacy, and five years of casework published in public.
Features & acknowledgements
The funds and individuals whose donations keep this casework public and free for victims.
Capabilities proven across five years of public casework: free to the victims who need them, and available for engagement by individuals, exchanges, protocols, and law firms.
Comprehensive investigations combining onchain analysis with OSINT to connect the wallets, infrastructure, and identities behind thefts, scams, and laundering operations.
Following stolen funds across chains, bridges, mixers, and exchanges, building the transaction record that holds up under scrutiny.
Working directly with exchanges and stablecoin issuers to freeze stolen assets before they can be cashed out.
Packaging evidence for civil and criminal legal cases and returning frozen funds to victims where possible.
$41M tied to the DSJ Exchange and BG Wealth investment fraud schemes frozen after onchain tracing mapped victim deposits to a shared laundering network.
$41MfrozenTwo-part investigation attributing the theft of $46M in U.S. Government-held crypto to John Daghita, known online as “Lick.” An arrest and a large recovery of funds followed.
$46MinvolvedInvestigation into the $243M social-engineering theft from a Genesis creditor by Malone Lam, Veer Chetal, Danish Zulfiqar, Jeandiel Serrano and associates, followed by criminal indictments and large recoveries of funds.
$243MinvolvedAnalysis of a breach exposing an internal payment site used by DPRK-linked operators, offering a rare view into how sanctioned IT-worker earnings move.
Investigation into the $28M exploit of the Bittensor network, tracing the attacker’s consolidation and laundering path after the drain.
$28MinvolvedAfter attackers breached a service provider connected to the Central Bank of Brazil and moved proceeds into crypto, rapid tracing led to $5M frozen.
$5MfrozenInvestigation into $6.5M stolen through social engineering attacks attributed to Ronald Spektor, who was later criminally charged in Brooklyn.
$6.5MinvolvedInvestigation into a violent UK home invasion in which victims were forced to transfer $4.3M in crypto, traced onchain and fully recovered.
$4.3Mfully recoveredMany cases start with an anonymous tip from the community and end in the public record. What happens in between follows a steady arc: the trail gets traced, funds get frozen where possible, and the evidence is built to hold up in court.
Most cases start with a victim report or community tip: an address, a name, a pattern that keeps repeating.
Onchain flows are mapped hop by hop and matched with offchain evidence until the picture is complete.
Exchanges freeze what can be frozen and attribution puts names on the operation.
Investigations are published openly with the receipts. Some before action is taken, some after, depending on the case.
The form collects no identifying metadata: no IP address, no tracking, no required contact details. Just what you know. Every submission is read, and tips that hold up have become published investigations.