In This Article
The "I lost my crypto" excuse has become a standard concealment tactic in divorce. The reasoning is simple: cryptocurrency is irreversible, self-custody wallets have no customer service to verify with, and the assets are difficult to compel through normal discovery. A spouse who claims their wallet is lost gets to argue that the crypto cannot be valued, divided, or recovered — which is the same outcome as not having to disclose it at all.
What that strategy depends on is the disclosing spouse and their attorney not knowing what the on-chain record actually shows. Every wallet, every transaction, every staking deposit, every DeFi interaction is permanently recorded on the blockchain and publicly verifiable by anyone with the address. The question is never "did the loss really happen." The question is "what does the wallet's on-chain history say about whether it is actually lost." A forensic investigator answers that question.
Real Loss vs. Convenient Loss
Real cryptocurrency loss does happen. It happens often. Forgotten passphrases, destroyed hardware wallets, lost recovery cards, and inherited wallets without instructions are all common. Industry estimates put the share of permanently lost Bitcoin at roughly 20% of total supply — so when a spouse says they lost something, the claim is at least plausible on its face.
But real loss has a specific on-chain signature, and convenient loss has a different one. The forensic question is whether the wallet's actual behavior matches the loss story.
A genuinely lost wallet:
- Received funds at some past date.
- Has not transacted in a long time — typically years, not months.
- Shows no staking activity, no DeFi interactions, no token approvals, no airdrop claims.
- Has no nearby wallets in the cluster that show consistent counterparty activity with the disclosing spouse's known accounts.
- Was reported lost to anyone (insurance, IRS, exchange) at the time the loss occurred, not retroactively when the divorce was filed.
A conveniently lost wallet:
- Transacted recently — often suspiciously close to the date of separation, the filing date, or the request for production.
- Continues to transact after the date of supposed loss.
- Shows active staking, DeFi positions, or NFT collection management.
- Has counterparty activity with addresses linked to the spouse's other accounts.
- Has no contemporaneous documentation of the loss — no exchange ticket, no police report, no insurance claim, no tax filing.
The on-chain record is the same in both cases. It either supports the loss story or refutes it.
"I Lost the Seed Phrase"
The most common version of the excuse: the spouse claims they wrote down their 12 or 24 word recovery phrase, lost the paper, and can no longer access the wallet. The claim is plausible because seed-phrase loss is a real failure mode that affects experienced and inexperienced users alike.
Forensic verification asks four questions of the on-chain record:
1. Does the wallet's most recent transaction predate the supposed loss?
If the spouse claims they lost the seed phrase in 2023 but the wallet has transacted in 2024 or 2025, the claim is provably false. Someone with control of the seed continued to use the wallet after the date the spouse says access was lost.
2. Is the wallet currently passive, or is it under active management?
A wallet whose seed has been lost cannot do anything. It cannot claim airdrops, sign transactions, vote in DAOs, claim staking rewards, or interact with DeFi protocols. If the wallet shows any of those activities after the supposed loss date, someone has the seed.
3. Are there receiving transactions after the loss date?
Anyone can send crypto to a wallet, even one whose owner has lost access. So inbound transactions alone do not refute a loss claim. But inbound transactions from addresses that appear elsewhere in the spouse's known activity are suspicious — why is the spouse continuing to send funds to a wallet they claim is inaccessible?
4. Does the cluster around the wallet remain active?
Wallets rarely operate in isolation. A "lost" wallet that is part of a cluster of wallets continuing to transact with one another suggests the loss claim covers only one wallet in a broader network the spouse still controls.
If the spouse claims they lost the seed but the wallet still receives airdrops, executes governance votes, or rebalances DeFi positions, ask the simple question: who is doing those things on the wallet's behalf? A genuinely lost wallet is mute. A wallet whose loss is fictional is not.
Spouse Claiming Lost Crypto You Can't Verify?
A forensic investigator can audit any wallet address against the actual on-chain record and produce a report your attorney can use in court. Free initial scoping.
Start a Free Case Review"My Wallet Was Hacked"
The hack story is the second most common excuse. The spouse claims their wallet was drained by a phishing attack, a malicious smart contract approval, or a compromised seed phrase, and that the funds are now gone to an attacker they cannot recover from.
Real hacks have specific signatures. A drained wallet shows:
- Rapid drainage in a short time window — often a single transaction or a sequence of transactions within minutes.
- Funds transferred to a single attacker address or a small set of attacker-controlled addresses.
- The attacker address often has other victims — multiple wallets feed in, all drained.
- Movement of funds through known mixing services (Tornado Cash, Wasabi) or cross-chain bridges shortly after the drain.
- Contemporaneous reporting — to the exchange, to the wallet provider, to law enforcement, on social media. People who get hacked talk about it.
A manufactured hack lacks most of these signatures. The drainage is too clean, the destination address has no other victims, the funds sit at the destination instead of being laundered, and the spouse never reported the incident to anyone at the time.
The destination address is the central forensic question. If the supposed attacker address can be analyzed and linked back to the spouse — through clustering analysis, through transaction patterns, through subsequent withdrawals to the spouse's known accounts — the hack story collapses. The spouse hacked themselves, which is to say, transferred their own funds to a wallet they still control.
For a deeper look at how real hacks unfold on-chain, see our analysis of the Bybit $1.4B hack and the Ronin bridge attribution — both show what genuine attacker behavior looks like, in contrast to the patterns of manufactured hack stories.
"I Sent It to the Wrong Address"
Cryptocurrency transactions are irreversible, so the "wrong address" claim has surface-level plausibility. Send 5 ETH to one character off the intended address, and the funds are gone forever — to whoever controls the typo wallet.
The forensic question is: what is at the address the spouse claims they accidentally sent to?
Three categories of receiving address tell you whether the claim is true:
Dormant address (the claim might be true)
The receiving address has no other inbound or outbound transactions. The funds sit there untouched. This is consistent with a true accidental send to an unowned address. The funds are still recoverable as a documentable destination — but they are unlikely to be retrievable in practice.
Burn address (the claim is implausible)
The address is a known burn address (0x0...0, 0xdead, etc.) or a vanity address that requires intentional generation. Accidentally sending to a burn address is essentially impossible — the wallet software warns the user, and the address itself is recognizable.
Active address (the claim is false)
The receiving address has subsequent activity — outbound transactions, deposits to other wallets, exchange interactions. The address was actively under someone's control. If clustering analysis links that address to the spouse's other known activity, the "wrong address" was actually the spouse's own wallet, intentionally funded.
| Receiving Address Behavior | What It Means |
|---|---|
| Dormant since the supposed accident | Claim is plausible; funds are documentably gone but the address remains a real on-chain destination. |
| Active before and after the supposed accident | Claim is false; the address was an existing wallet someone was using. |
| Receives further deposits from spouse's known accounts | Claim is false; the spouse continues to fund the wallet they claim was an accident. |
| Withdraws to exchange accounts in the spouse's name | Claim is false; the funds returned to the spouse's control. |
| Linked by clustering to the spouse's other wallets | Claim is false; the receiving address is part of the spouse's wallet cluster. |
"The Exchange Went Down"
A variation of the loss excuse leans on the spouse's claim that funds were held on an exchange that subsequently failed — FTX, Celsius, BlockFi, Voyager, Mt. Gox, others. The spouse argues the funds were locked in bankruptcy and effectively zero.
This claim is testable in three ways:
Bankruptcy claims registry
If the spouse really had funds at a failed exchange, they almost certainly filed a claim in the bankruptcy proceeding. Most exchange failures have publicly searchable creditor lists. If the spouse never filed a claim, the holdings may not have existed at the exchange in the first place — or the spouse withdrew them before the failure.
Pre-failure withdrawal pattern
Many spouses who claim "FTX took my crypto" actually withdrew their funds in the weeks before the collapse, when the warning signs were public. On-chain analysis of withdrawal addresses associated with the exchange can confirm or refute this.
Recovery distributions
Most failed exchanges have made or are making partial recovery distributions to creditors. If the spouse had a real claim, they may have received and not disclosed those distributions. The recipient address of recovery distributions is on-chain and traceable.
The Staking and DeFi Tells
The single strongest evidence that a "lost" wallet is not actually lost is concurrent active management. A wallet cannot be simultaneously inaccessible and earning staking rewards, voting in DAOs, or rebalancing DeFi positions. Each of those activities requires someone to sign transactions, and signing transactions requires the seed phrase.
Common active-management signals to look for:
- ETH staking — solo staking or liquid staking via Lido, Rocket Pool, or Coinbase. The wallet appears as a depositor, claims rewards, and may have re-staked.
- DeFi liquidity provision — Uniswap V3 LP positions, Aave deposits, Compound balances, Curve LP tokens. Each requires periodic interaction or accrues yield that is itself an on-chain event.
- Airdrop claims — a wallet that claimed an airdrop after the supposed loss date proves the seed is still in use. Airdrops require an active signature.
- NFT trading — buying, selling, or transferring NFTs requires signing transactions. A "lost" wallet cannot list an NFT on OpenSea.
- DAO governance votes — voting in a DAO requires the wallet to sign a vote message. Vote records are public per DAO and tied to wallet address.
- Token approvals — every approval transaction is on-chain. A new approval after the loss date is signed by someone with the seed.
Any of these activities, post the supposed loss date, refutes the loss claim. There is no benign explanation for a "lost" wallet that continues to govern DAOs, claim airdrops, and rebalance LP positions.
What Your Attorney Needs from the Report
For the forensic report to be useful in court, it needs to address each excuse the spouse has offered with specific on-chain evidence. The structure your attorney will want to attach to filings includes:
- Wallet identification — the specific addresses the spouse has acknowledged or that have been identified through subpoena and tracing.
- Loss timeline — the date the spouse claims access was lost, drawn from sworn statements or interrogatory responses.
- Post-loss activity log — a chronological record of every transaction, signature, governance vote, claim, and DeFi interaction that occurred after the supposed loss date.
- Counterparty analysis — addresses that have transacted with the "lost" wallet, with attribution where possible to the spouse's known accounts.
- Conclusion — a direct statement that the on-chain record does or does not support the loss claim, with a list of specific transactions that contradict the claim.
The report becomes the evidence your attorney uses to compel disclosure, support a motion to compel, or attach to a contempt filing if the spouse refuses to acknowledge the wallet remains under active control. For broader context on how forensic findings translate to courtroom use, see our overview of blockchain forensic evidence in federal civil litigation.
Need a Forensic Report on a "Lost" Wallet?
Wallet Witness audits "lost," "hacked," and "wrong address" claims against the on-chain record and produces evidence-grade reports for divorce litigation. Free initial scoping call.
Start a Free Case ReviewFrequently Asked Questions
Disproving a "lost crypto" claim is one half of the offensive forensic playbook. The other half is finding the assets your spouse never disclosed in the first place — see hidden crypto assets in divorce for the full discovery and tracing methodology. If you are on the receiving end of a false hidden-asset accusation, see how to prove you have no crypto in a divorce for the defensive playbook.
Need this work done?
If you or your attorney need a forensic trace, evidence package, or expert-witness report for a divorce case involving hidden or disputed crypto, see Divorce & Family Law Crypto Forensics for what the engagement covers (both sides represented).