← Back to After Theft

The Stages of a Crypto Forensic Investigation

A professional forensic investigation is not a single act — it is a sequence of stages, each with its own deliverable. Understanding the sequence helps you evaluate a firm's progress, know what to expect, and recognize when something is off.

When someone asks "can you recover my crypto," the honest answer begins with walking them through what the work actually looks like. Recovery is a downstream outcome. The upstream work is the investigation — the part that produces the evidence, the attribution, and the court-admissible paper trail that makes any subsequent recovery possible. This article describes how that work is staged inside a competent forensic firm, so you can see what you are buying and how to judge progress.

Stage 1: Intake and Scoping

The first 1–3 days after engagement are spent documenting the case. This is unglamorous but critical. Skipping it — or doing it sloppily — means every subsequent stage is built on an unstable foundation.

During intake, an investigator collects:

  • The victim's wallet addresses and the transaction hashes of the outbound transfers.
  • All communication with the scammer (screenshots, message exports, platform URLs).
  • Dates, times, and the sequence of events leading to the loss.
  • Any on-platform identifiers: usernames, email addresses, phone numbers, payment references.
  • The victim's own KYC status on the exchanges involved, which determines what records can later be subpoenaed.

Deliverable: A signed engagement letter with a defined scope, a documented case file, and a clear list of what the investigator will and will not do.

Red Flag at This Stage

If an investigator starts "tracing" before completing intake — especially before you have a signed engagement letter — they are skipping due diligence. A legitimate firm will not begin paid work without documented scope.

Stage 2: On-Chain Tracing

This is the technical core of the investigation. Using tools like Chainalysis Reactor, TRM Labs, Arkham, Breadcrumbs, or proprietary tooling, the investigator follows the stolen funds hop by hop through the blockchain.

What happens here:

  • Forward tracing from the victim's sending address through each subsequent hop.
  • Cluster analysis to identify wallets controlled by the same entity (multiple addresses owned by the same attacker).
  • Cross-chain tracing if the scammer used a bridge to move funds between Ethereum, BSC, Tron, or Bitcoin.
  • Mixer / tumbler analysis if the funds were passed through Tornado Cash, Wasabi, Sinbad, or similar services. See mixers and privacy coins recovery for what this means for your case.
  • Pattern matching against known scam infrastructure and clusters previously documented in other cases.

Tracing can take from a few hours (direct hop to a major exchange) to several weeks (complex cross-chain laundering through mixers). See realistic recovery timelines for what to expect at each stage.

Deliverable: A transaction graph — usually presented both as a visual diagram and a tabular breakdown — showing where the funds are today and every hop along the way.

Stage 3: Attribution

Tracing tells you where the funds are. Attribution tells you who controls them. This is the stage that determines whether recovery is even possible.

Attribution outputs generally fall into three tiers:

Tier A — Terminated at a regulated exchange. The funds sit in a deposit address belonging to a known exchange (Binance, Coinbase, Kraken, Bitfinex, OKX, etc.). The exchange has KYC records for the account holder. Recovery is procedurally possible via law enforcement subpoena or civil court order.

Tier B — Terminated at an unregulated or adversarial exchange. The funds sit at an exchange that does not respond to US law enforcement (certain offshore platforms, known laundering hubs). Recovery is much harder but may still be possible with coordinated international action.

Tier C — Still in private wallets. The funds are not at any exchange. Recovery requires either identifying the individual through OSINT (on-chain plus off-chain clues) or waiting for the attacker to move the funds to an exchange that can be subpoenaed.

Deliverable: A written attribution assessment ranking the outcome by tier and identifying, where possible, the specific counterparty holding the funds.

Stage 4: Off-Chain OSINT

For cases where on-chain attribution is incomplete, investigators expand to off-chain sources:

  • Telegram and Discord channel scraping for scam group infrastructure.
  • Reverse image search of scammer profile photos.
  • Domain and WHOIS records for fake platform URLs.
  • Breach data correlating email addresses, phone numbers, or IP addresses to real-world identities.
  • Social media footprints of the impersonated "investor" or "support agent."

This stage is particularly important in pig-butchering cases, where the scam infrastructure is often shared across hundreds of victims — meaning other victims may have uncovered evidence that ties the attacker to an identifiable group or jurisdiction.

Deliverable: Supplementary evidence file combining on-chain findings with off-chain corroboration.

Stage 5: Reporting

The output of the investigation is a formal report. At minimum it contains:

  • Executive summary for non-technical readers (bank fraud officers, judges, detectives).
  • Methodology section documenting the tools and techniques used.
  • Full transaction table with hashes, amounts, timestamps, and hop-by-hop flow.
  • Attribution section with tier classification and named counterparties.
  • Recommendations for next steps: law enforcement referral, civil freeze order, exchange compliance contact, or case closure.

The report is written to be admissible in civil litigation and usable by law enforcement. That means careful sourcing, reproducible methodology, and qualified statements where evidence is inferential rather than definitive.

Deliverable: The forensic report — typically 15 to 60 pages depending on complexity.

Stage 6: Hand-Off and Follow-Through

Most investigations do not end with the report. Typical hand-offs include:

  • Law enforcement referral: Submitting the report with the case file to IC3, FBI, Secret Service, or a state-level cyber unit, along with an introduction to a specific agent or task force.
  • Exchange compliance contact: Submitting tracing evidence directly to the exchange's law enforcement / compliance team where the funds are currently held, requesting account freeze and preservation of records.
  • Civil litigation support: Providing expert declarations and testimony in support of TRO / injunction motions, subpoenas, and John Doe complaints.
  • Insurance claim support: Providing documentation for crime or cyber insurance claims where applicable.

Deliverable: Ongoing updates as law enforcement or counsel proceed. This phase can extend for many months.

What Realistic Outcomes Look Like

Across the cases I see, outcomes cluster into three groups:

  • Full or partial recovery (roughly 10–20% of cases): Usually cases where funds terminated at a regulated exchange and law enforcement or civil action reached the account before the balance was moved.
  • Evidence produced, recovery pending (roughly 30–40%): Funds are located, attributed, and frozen or flagged, but recovery depends on long-running legal process.
  • Closed without recovery (roughly 40–60%): Funds moved through mixers, foreign unregulated exchanges, or OTC desks that do not respond. Case documentation is still valuable for tax deduction and insurance.

The split varies dramatically by case profile, especially by how quickly the investigation was engaged. Cases started within 48 hours of loss recover at roughly 3x the rate of cases started 30+ days out. Speed matters more than any other single factor.