Reproducible. Cited. Defensible.
A method built to survive the toughest reader in the room: opposing counsel. Every claim in this page describes how we work — not a promise about what any investigation will recover.
Four commitments on every case.
Chain-of-custody first
Every artifact — screenshots, exports, wallet dumps — is timestamped and hashed on receipt, and stored in a version-controlled workspace preserved for the life of the case.
Confidence tiers, always disclosed
Every counterparty attribution carries an explicit confidence tier — Confirmed / Probable / Possible — with the underlying signal disclosed.
Facts before inferences
Observed on-chain facts are separated from analytical inferences in every report. A reader can accept our facts and reach their own conclusions.
Second-analyst review
No report leaves the firm without independent re-derivation by a second analyst who did not conduct the primary tracing.

Data acquisition — and why we re-derive it.
A tracing conclusion is only as strong as its underlying data. We pull from multiple independent sources and re-derive the on-chain facts ourselves rather than accepting a single vendor's labels — because a report that cannot be re-run by an opposing expert is not a report we will sign.
Direct RPC queries against full nodes for Bitcoin, Ethereum, Tron, Solana, and major EVM L2s, cross-checked against independent indexers so no single data provider is a single point of failure.
Public explorers used for spot-verification of hashes, confirmations, and mempool timing — never as the sole source for a material finding.
Enterprise blockchain-analytics licenses provide entity labels and cluster hints, which we treat as leads to verify, not conclusions to cite unverified.
Sanctions lists, exchange disclosures, court filings, breach databases, and public counterparty statements, logged with retrieval date and source URL.
Exchange statements, wallet exports, messages, and emails — authenticated where possible against their own metadata before being relied upon.
Where feasible, we independently reconstruct the transaction graph from raw chain data rather than trusting a vendor's pre-built graph, so every hop is verifiable by a third party.
Heuristics we use — and their limits.
Heuristics are probabilistic, not proof. Each one has a documented failure mode, and every report states which heuristics contributed to a given conclusion and how that lowers its confidence tier.
Addresses spent together in a single UTXO transaction are typically controlled by one entity. Breaks down with CoinJoin and some wallet-batching software.
Identifies the likely 'change' output in a transaction using script-type, address-reuse, and rounding heuristics. Unreliable against privacy-aware wallets.
Tracks a sequence of transactions that repeatedly 'peel off' a small amount while the remainder moves on — common in layered laundering. Can be mimicked by legitimate batching.
Links deposits and withdrawals across services by matching value and timing windows. Weakens as pooling and delay increase; always stated as circumstantial, not conclusive.
Groups addresses believed to share a controller, then maps clusters to known entities. Confidence depends entirely on the quality of the underlying attribution signal.
Follows value across chain bridges and into wrapped tokens by matching burn/mint events and liquidity movements. Limited where bridges pool user funds without a 1:1 on-chain link.
Where statistically viable, analyzes deposit and withdrawal patterns at mixing services. We report this as probabilistic association only, and disclose the mixer's design when it defeats reliable linkage.

Not every asset behaves the same on-chain.
USDT and USDC are issued under centralized smart contracts whose issuers (Tether, Circle) can, in some circumstances and typically following law-enforcement or legal process, freeze specific addresses. We document freeze feasibility as a factual matter, not a guaranteed outcome.
The same stablecoin behaves differently by chain: Tron's TRC-20 transfers are cheaper and faster, which affects layering speed and the number of hops typically observed before an off-ramp attempt, versus Ethereum's ERC-20 rails.
Wallet-drainer incidents often exploit token approvals rather than moving funds directly. We reconstruct the approval history, identify the drainer contract, and trace proceeds through subsequent swaps and marketplace sales.
Three tiers, each with a defined evidentiary bar.
Every attribution and every hop in a transaction graph is labelled with one of three tiers. The tier is disclosed next to the finding, not buried in a footnote.
Supported by a direct, verifiable link: an exchange KYC confirmation, an issuer statement, a signed on-chain message, or a match against a primary-source, publicly attributed address.
Supported by convergent heuristic and OSINT signals — e.g., clustering plus timing correlation plus a partial public attribution — but without a single direct confirmation.
A plausible but unconfirmed link, typically a single weak signal (e.g., amount correlation alone). Reported for completeness, with the limitation stated explicitly and no attribution acted upon at this tier alone.

Chain of custody, from first byte.
Every artifact — a wallet export, a screenshot, an on-chain snapshot — is hashed on receipt, timestamped, and stored in an encrypted, write-once, version-controlled workspace unique to your matter. Access is logged. Retention aligns to your counsel's litigation hold.
Findings are challenged before a client ever sees them.
A second analyst, without access to the first analyst's working notes, independently reconstructs the transaction graph from raw data and compares results.
Findings are presented internally and stress-tested for alternative explanations before they are accepted into the draft report.
Every assumption made where data is incomplete is logged in a register attached to the case file, so it can be revisited if new evidence emerges.
What an Aegis report contains, section by section.
Plain-English narrative of what occurred on-chain — written for non-technical decision-makers.
What we were asked to investigate, by whom, and any limits on scope agreed in writing.
Every tool, dataset, node, and heuristic used, at what version, so findings can be reproduced.
Annotated flow of funds with every hash, timestamp, and counterparty label cited.
Identified services, exchanges, or clusters — with confidence tier and supporting signal.
Documented assumptions made where source data was incomplete or ambiguous.
Realistic legal and compliance channels the evidence can support. Not guarantees.
Data gaps, unresolved hops, and where the analysis necessarily stopped.
Signed by primary and reviewing analyst, with qualifications, disclosures, and numbered exhibits.
Written to be filed, not just read.
An Aegis report is drafted with a specific reader in mind: the judge, arbitrator, regulator, or insurance adjuster who will decide the matter. Every section is structured to support direct citation in pleadings and affidavits.
- Numbered paragraphs and numbered exhibits for cross-referencing
- Verbatim transaction hashes in the appendix
- Independent verification path for every finding
- Signed by both primary and reviewing analyst

Built against the standards US courts actually apply.
A forensic report is only useful if it can be admitted, disclosed, and defended. We draft with an awareness of the frameworks federal and state courts generally use to evaluate expert and documentary evidence — including the reliability factors associated with Federal Rule of Evidence 702 (and the Daubert line of cases) for expert testimony, and the authentication requirements of Rule 901 for exhibits. Whether any report or testimony is ultimately admitted is a decision for the court, not for Aegis or its clients — we structure our work to meet the criteria a court is likely to examine, and we disclose our limitations rather than leaving them to be found in cross-examination.
The analyst's qualifications, training, and case experience are disclosed in the report and in any declaration.
Techniques are published, repeatable, and applied consistently across matters — not invented per case.
Conclusions rest on cited on-chain records and preserved artifacts, not on unverifiable third-party assertions.
Where a heuristic is used, the report names it, states its error modes, and lowers the confidence tier accordingly.
Artifacts are hash-verified at capture with a documented acquisition log supporting authentication before the court.
Findings adverse to the instructing party are reported in the same terms as favourable ones.
Reports can be issued alongside a signed declaration and consecutively numbered exhibits, formatted for direct attachment to a filing.
We do not opine on legal conclusions, criminal liability, or the likelihood of recovery.
Reports are versioned; any amendment is issued as a dated addendum, never a silent edit.
What we will not claim.
Evidence-grade tracing supports recovery efforts through counsel, exchanges, insurers, and law enforcement — it does not, by itself, recover funds. Outcomes depend heavily on where funds landed and on the cooperation of third parties outside our control.
- ✕We do not guarantee recovery of any funds, at any stage of an engagement
- ✕We do not provide legal advice — findings are handed to your counsel to act on
- ✕We do not claim certainty where a heuristic is probabilistic, and we say so
- ✕We do not trace beyond the point our evidence and tools reliably support
- ✕We do not represent that a court will admit any report or testimony
See our disclaimer for the full scope of what our services are, and are not.

The stack behind every report — and why we version it.
We combine commercial analytics platforms with in-house tooling and full-node access. Every finding declares which tool produced it, at which version — a practice that lets an opposing expert reproduce, and if warranted, challenge our work on its merits.
Direct RPC access to Bitcoin, Ethereum, Tron, Solana, and major EVM L2s — no reliance on third-party indexers alone.
Enterprise licenses with leading blockchain analytics providers, cross-validated on every attribution.
Proprietary clustering, deposit-address grouping, and drainer-signature libraries, maintained and version-tagged internally.
Structured OSINT feeds for sanctions lists, exchange disclosures, and public counterparty attributions.
Malicious contract analysis performed in isolated environments — never on client infrastructure.
Every tool and dataset used is pinned by version and cited in the report's tooling manifest, dated to the day of use.
Bring us your hardest case.
We take on matters where on-chain evidence can materially advance a legal, regulatory, or insurance outcome — and we say so honestly when it can't.