Skip to content
Impersonation notice: Aegis never guarantees fund recovery and never solicits victims by DM. Verify all communication through this website.
Aegis
Financial Forensics
Methodology

Reproducible. Cited. Defensible.

A method built to survive the toughest reader in the room: opposing counsel.

Principles

Four commitments on every case.

Chain-of-custody first

Every artifact — screenshots, exports, wallet dumps — is timestamped and hashed on receipt, and stored in a version-controlled workspace preserved for the life of the case.

Confidence tiers, always disclosed

Every counterparty attribution carries an explicit confidence tier (High / Medium / Low) with the underlying signal disclosed — clustering, public attribution, exchange confirmation, or heuristic inference.

Facts before inferences

Observed on-chain facts are separated from analytical inferences in every report. A reader can accept our facts and reach their own conclusions.

Second-analyst review

No report leaves the firm without independent review by a second analyst who did not conduct the primary tracing.

Leather-bound expert forensic report with gold seal representing defensible blockchain investigation methodology
Report anatomy

What a Aegis report contains.

Executive summary

Plain-English narrative of what occurred on-chain — written for non-technical decision-makers.

Transaction graph

Annotated flow of funds with every hash, timestamp, and counterparty label cited.

Counterparty attribution

Identified services, exchanges, or clusters — with confidence tier and supporting signal.

Recovery pathways

Realistic legal and compliance channels the evidence can support. Not guarantees.

Tooling manifest

Every tool, dataset, and heuristic used, at what version, so findings can be reproduced.

Analyst declaration

Signed by primary and reviewing analyst, with qualifications and disclosures.

Secure encrypted evidence storage racks used by Aegis Financial Forensics for blockchain investigation chain of custody
Evidence handling

Chain of custody, from first byte.

Every artifact — a wallet export, a screenshot, an on-chain snapshot — is hashed on receipt, timestamped, and stored in an encrypted, version-controlled workspace unique to your matter. Access is logged. Retention aligns to your counsel's litigation hold.

SHA-256
Hash on ingest for every artifact
AES-256
Encryption at rest, TLS 1.3 in transit
Immutable log
Timestamped access & modification trail
Air-gapped
Cold-storage backup per engagement
Tooling & data

The stack behind every report.

We combine commercial analytics platforms with in-house tooling and full-node access. Every finding declares which tool produced it, at which version — so nothing in a Aegis report is a black box.

Full-node access

Direct RPC access to Bitcoin, Ethereum, Tron, Solana, and major EVM L2s — no reliance on third-party indexers alone.

Commercial analytics

Enterprise licenses with two leading blockchain analytics providers, cross-validated on every attribution.

In-house heuristics

Proprietary clustering, deposit-address grouping, and drainer-signature libraries maintained internally.

Open-source intelligence

Structured OSINT feeds for sanctions lists, exchange disclosures, and public counterparty attributions.

Sandboxed execution

Malicious contract analysis performed in isolated environments — never on client infrastructure.

Version pinning

Every tool and dataset used is pinned by version and cited in the report's tooling manifest.

Inside the report

Written to be filed, not just read.

A Aegis report is drafted with a specific reader in mind: the judge, arbitrator, regulator, or insurance adjuster who will decide the matter. Every section is structured to support direct citation in pleadings and affidavits.

  • Numbered paragraphs for cross-referencing
  • Verbatim transaction hashes in the appendix
  • Independent verification path for every finding
  • Signed by both primary and reviewing analyst
Detailed blockchain forensic report pages with cited transaction graphs prepared by Aegis Financial Forensics
Evidentiary alignment

A forensic report is only useful if it can be admitted, disclosed, and defended. We draft to the criteria that decide that question — and state our limitations rather than leaving them to be found in cross-examination.

Qualified opinion

The analyst's qualifications, training, and case experience are disclosed in the report and in any declaration.

Reliable method

Techniques are published, repeatable, and applied consistently across matters — not invented per case.

Sufficient data

Conclusions rest on cited on-chain records and preserved artifacts, not on unverifiable third-party assertions.

Applied faithfully

Where a heuristic is used, the report names it, states its error modes, and lowers the confidence tier accordingly.

Authenticity

Artifacts are hash-verified at capture with a documented acquisition log supporting authentication.

Duty of candour

Findings adverse to the instructing party are reported in the same terms as favourable ones.

Stated limitations

Every report carries a limitations section: data gaps, unresolved hops, and where analysis stopped.

No overreach

We do not opine on legal conclusions, criminal liability, or the likelihood of recovery.

Version control

Reports are versioned; any amendment is issued as a dated addendum, never a silent edit.

Ready to test our method?

Bring us your hardest case.

We take on matters where on-chain evidence can materially advance a legal, regulatory, or insurance outcome — and we say so honestly when it can't.