Skip to content
Impersonation notice: Aegis never guarantees fund recovery and never solicits victims by DM. Verify all communication through this website.
Aegis
Financial Forensics
Methodology

Reproducible. Cited. Defensible.

A method built to survive the toughest reader in the room: opposing counsel. Every claim in this page describes how we work — not a promise about what any investigation will recover.

Principles

Four commitments on every case.

Chain-of-custody first

Every artifact — screenshots, exports, wallet dumps — is timestamped and hashed on receipt, and stored in a version-controlled workspace preserved for the life of the case.

Confidence tiers, always disclosed

Every counterparty attribution carries an explicit confidence tier — Confirmed / Probable / Possible — with the underlying signal disclosed.

Facts before inferences

Observed on-chain facts are separated from analytical inferences in every report. A reader can accept our facts and reach their own conclusions.

Second-analyst review

No report leaves the firm without independent re-derivation by a second analyst who did not conduct the primary tracing.

Brass scales of justice beside a legal notebook, representing evidentiary standards in blockchain forensics
Step one

Data acquisition — and why we re-derive it.

A tracing conclusion is only as strong as its underlying data. We pull from multiple independent sources and re-derive the on-chain facts ourselves rather than accepting a single vendor's labels — because a report that cannot be re-run by an opposing expert is not a report we will sign.

Full nodes & indexers

Direct RPC queries against full nodes for Bitcoin, Ethereum, Tron, Solana, and major EVM L2s, cross-checked against independent indexers so no single data provider is a single point of failure.

Block explorers

Public explorers used for spot-verification of hashes, confirmations, and mempool timing — never as the sole source for a material finding.

Commercial attribution datasets

Enterprise blockchain-analytics licenses provide entity labels and cluster hints, which we treat as leads to verify, not conclusions to cite unverified.

OSINT

Sanctions lists, exchange disclosures, court filings, breach databases, and public counterparty statements, logged with retrieval date and source URL.

Client-supplied records

Exchange statements, wallet exports, messages, and emails — authenticated where possible against their own metadata before being relied upon.

Re-derivation

Where feasible, we independently reconstruct the transaction graph from raw chain data rather than trusting a vendor's pre-built graph, so every hop is verifiable by a third party.

Analytical techniques

Heuristics we use — and their limits.

Heuristics are probabilistic, not proof. Each one has a documented failure mode, and every report states which heuristics contributed to a given conclusion and how that lowers its confidence tier.

Common-input-ownership

Addresses spent together in a single UTXO transaction are typically controlled by one entity. Breaks down with CoinJoin and some wallet-batching software.

Change-address detection

Identifies the likely 'change' output in a transaction using script-type, address-reuse, and rounding heuristics. Unreliable against privacy-aware wallets.

Peel-chain analysis

Tracks a sequence of transactions that repeatedly 'peel off' a small amount while the remainder moves on — common in layered laundering. Can be mimicked by legitimate batching.

Timing & amount correlation

Links deposits and withdrawals across services by matching value and timing windows. Weakens as pooling and delay increase; always stated as circumstantial, not conclusive.

Cluster attribution

Groups addresses believed to share a controller, then maps clusters to known entities. Confidence depends entirely on the quality of the underlying attribution signal.

Bridge & wrapped-asset following

Follows value across chain bridges and into wrapped tokens by matching burn/mint events and liquidity movements. Limited where bridges pool user funds without a 1:1 on-chain link.

Mixer entry/exit analysis

Where statistically viable, analyzes deposit and withdrawal patterns at mixing services. We report this as probabilistic association only, and disclose the mixer's design when it defeats reliable linkage.

Hardware wallet screen showing transaction data examined during a wallet compromise investigation
Token-specific considerations

Not every asset behaves the same on-chain.

Stablecoin issuer freeze mechanics

USDT and USDC are issued under centralized smart contracts whose issuers (Tether, Circle) can, in some circumstances and typically following law-enforcement or legal process, freeze specific addresses. We document freeze feasibility as a factual matter, not a guaranteed outcome.

TRC-20 vs ERC-20

The same stablecoin behaves differently by chain: Tron's TRC-20 transfers are cheaper and faster, which affects layering speed and the number of hops typically observed before an off-ramp attempt, versus Ethereum's ERC-20 rails.

NFT & approval-drainer traces

Wallet-drainer incidents often exploit token approvals rather than moving funds directly. We reconstruct the approval history, identify the drainer contract, and trace proceeds through subsequent swaps and marketplace sales.

Confidence tiering

Three tiers, each with a defined evidentiary bar.

Every attribution and every hop in a transaction graph is labelled with one of three tiers. The tier is disclosed next to the finding, not buried in a footnote.

Confirmed

Supported by a direct, verifiable link: an exchange KYC confirmation, an issuer statement, a signed on-chain message, or a match against a primary-source, publicly attributed address.

Probable

Supported by convergent heuristic and OSINT signals — e.g., clustering plus timing correlation plus a partial public attribution — but without a single direct confirmation.

Possible

A plausible but unconfirmed link, typically a single weak signal (e.g., amount correlation alone). Reported for completeness, with the limitation stated explicitly and no attribution acted upon at this tier alone.

Gloved forensic examiner sealing a hard drive in an evidence bag to preserve chain of custody in a blockchain investigation
Evidence handling

Chain of custody, from first byte.

Every artifact — a wallet export, a screenshot, an on-chain snapshot — is hashed on receipt, timestamped, and stored in an encrypted, write-once, version-controlled workspace unique to your matter. Access is logged. Retention aligns to your counsel's litigation hold.

SHA-256
Hash on ingest for every artifact
AES-256
Encryption at rest, TLS 1.3 in transit
Write-once archive
Timestamped exports cannot be silently altered
Immutable log
Access & modification trail, reviewed on delivery
Air-gapped
Cold-storage backup per engagement
Timestamped exports
Every re-run of raw chain data is dated and versioned
Quality control

Findings are challenged before a client ever sees them.

Independent re-derivation

A second analyst, without access to the first analyst's working notes, independently reconstructs the transaction graph from raw data and compares results.

Peer challenge

Findings are presented internally and stress-tested for alternative explanations before they are accepted into the draft report.

Assumption register

Every assumption made where data is incomplete is logged in a register attached to the case file, so it can be revisited if new evidence emerges.

Report anatomy

What an Aegis report contains, section by section.

Executive summary

Plain-English narrative of what occurred on-chain — written for non-technical decision-makers.

Scope & instructions

What we were asked to investigate, by whom, and any limits on scope agreed in writing.

Data sources & tooling manifest

Every tool, dataset, node, and heuristic used, at what version, so findings can be reproduced.

Transaction graph

Annotated flow of funds with every hash, timestamp, and counterparty label cited.

Counterparty attribution

Identified services, exchanges, or clusters — with confidence tier and supporting signal.

Assumption register

Documented assumptions made where source data was incomplete or ambiguous.

Recovery pathways

Realistic legal and compliance channels the evidence can support. Not guarantees.

Limitations

Data gaps, unresolved hops, and where the analysis necessarily stopped.

Analyst declaration & exhibits

Signed by primary and reviewing analyst, with qualifications, disclosures, and numbered exhibits.

Inside the report

Written to be filed, not just read.

An Aegis report is drafted with a specific reader in mind: the judge, arbitrator, regulator, or insurance adjuster who will decide the matter. Every section is structured to support direct citation in pleadings and affidavits.

  • Numbered paragraphs and numbered exhibits for cross-referencing
  • Verbatim transaction hashes in the appendix
  • Independent verification path for every finding
  • Signed by both primary and reviewing analyst
Written blockchain forensics methodology document setting out cryptocurrency tracing and reporting protocols
Evidentiary alignment

A forensic report is only useful if it can be admitted, disclosed, and defended. We draft with an awareness of the frameworks federal and state courts generally use to evaluate expert and documentary evidence — including the reliability factors associated with Federal Rule of Evidence 702 (and the Daubert line of cases) for expert testimony, and the authentication requirements of Rule 901 for exhibits. Whether any report or testimony is ultimately admitted is a decision for the court, not for Aegis or its clients — we structure our work to meet the criteria a court is likely to examine, and we disclose our limitations rather than leaving them to be found in cross-examination.

Qualified opinion

The analyst's qualifications, training, and case experience are disclosed in the report and in any declaration.

Reliable method

Techniques are published, repeatable, and applied consistently across matters — not invented per case.

Sufficient data

Conclusions rest on cited on-chain records and preserved artifacts, not on unverifiable third-party assertions.

Applied faithfully

Where a heuristic is used, the report names it, states its error modes, and lowers the confidence tier accordingly.

Authenticity (Rule 901 framing)

Artifacts are hash-verified at capture with a documented acquisition log supporting authentication before the court.

Duty of candour

Findings adverse to the instructing party are reported in the same terms as favourable ones.

Declarations & exhibits

Reports can be issued alongside a signed declaration and consecutively numbered exhibits, formatted for direct attachment to a filing.

No overreach

We do not opine on legal conclusions, criminal liability, or the likelihood of recovery.

Version control

Reports are versioned; any amendment is issued as a dated addendum, never a silent edit.

Honesty about limits

What we will not claim.

Evidence-grade tracing supports recovery efforts through counsel, exchanges, insurers, and law enforcement — it does not, by itself, recover funds. Outcomes depend heavily on where funds landed and on the cooperation of third parties outside our control.

  • We do not guarantee recovery of any funds, at any stage of an engagement
  • We do not provide legal advice — findings are handed to your counsel to act on
  • We do not claim certainty where a heuristic is probabilistic, and we say so
  • We do not trace beyond the point our evidence and tools reliably support
  • We do not represent that a court will admit any report or testimony

See our disclaimer for the full scope of what our services are, and are not.

Earth at night from orbit illustrating the cross-border jurisdictional reach and limits of cryptocurrency exchange cooperation
Tooling & version manifest

The stack behind every report — and why we version it.

We combine commercial analytics platforms with in-house tooling and full-node access. Every finding declares which tool produced it, at which version — a practice that lets an opposing expert reproduce, and if warranted, challenge our work on its merits.

Full-node access

Direct RPC access to Bitcoin, Ethereum, Tron, Solana, and major EVM L2s — no reliance on third-party indexers alone.

Commercial analytics

Enterprise licenses with leading blockchain analytics providers, cross-validated on every attribution.

In-house heuristics

Proprietary clustering, deposit-address grouping, and drainer-signature libraries, maintained and version-tagged internally.

Open-source intelligence

Structured OSINT feeds for sanctions lists, exchange disclosures, and public counterparty attributions.

Sandboxed execution

Malicious contract analysis performed in isolated environments — never on client infrastructure.

Version pinning

Every tool and dataset used is pinned by version and cited in the report's tooling manifest, dated to the day of use.

Ready to test our method?

Bring us your hardest case.

We take on matters where on-chain evidence can materially advance a legal, regulatory, or insurance outcome — and we say so honestly when it can't.