The flagship casework: exchange freezes, fund recoveries, and exploit attributions, documented in public from the first tip to the final outcome.
$41M tied to the DSJ Exchange and BG Wealth investment fraud schemes frozen after onchain tracing mapped victim deposits to a shared laundering network.
Analysis of a breach exposing an internal payment site used by DPRK-linked operators, offering a rare view into how sanctioned IT-worker earnings move.
Two-part investigation attributing the theft of $46M in U.S. Government-held crypto to John Daghita, known online as “Lick.” An arrest and a large recovery of funds followed.
Investigation into the $28M exploit of the Bittensor network, tracing the attacker’s consolidation and laundering path after the drain.
After attackers breached a service provider connected to the Central Bank of Brazil and moved proceeds into crypto, rapid tracing led to $5M frozen.
Investigation into $6.5M stolen through social engineering attacks attributed to Ronald Spektor, who was later criminally charged in Brooklyn.
Investigation into a violent UK home invasion in which victims were forced to transfer $4.3M in crypto, traced onchain and fully recovered.
Investigation into the $243M social-engineering theft from a Genesis creditor by Malone Lam, Veer Chetal, Danish Zulfiqar, Jeandiel Serrano and associates, followed by criminal indictments and large recoveries of funds.
A project unknowingly hired DPRK IT workers who exploited it for $1.3M; rapid tracing recovered $1M and exposed the hiring network behind it.
Tracing a $15M portion of the Caesars ransomware payment attributed to Scattered Spider led to the recovery of $12M.
Investigation connecting 25+ exploits totaling over $200M to the Lazarus Group through shared laundering infrastructure; $7M recovered.
Investigation into the $11.1M Prisma Finance exploit, tracing the attacker's funds and probing the 'whitehat' framing they attempted after the fact.
The Munchables protocol was exploited for $62M by an embedded DPRK IT worker; within a day, pressure and negotiation produced a full return of funds.
Cold-case investigation into the 2021 Uranium Finance $50M exploit, reviving onchain leads that preceded criminal charges and a $31M recovery.
Investigation into the 2021 AnubisDAO 'rug pull' that drained $60M of raised ETH minutes after launch, tracing the funds nearly two years later.
Investigation identifying the attacker behind the $9M Platypus Finance flash-loan exploit within a day, followed by the arrest of two suspects in France.
Investigation unmasking “HZ,” a phishing drainer operator flaunting stolen proceeds, as Chase Senecal, an early landmark in drainer attribution.
Investigation attributing high-profile Twitter account takeovers and phishing drainer thefts to Cameron Redman (“Cam”/“Cream”), later sentenced in the U.S.
Investigation attributing a string of NFT phishing drainer thefts, including high-value Bored Apes, to two French operators, Mathys and Camille, later indicted in Paris.