
Intake and preservation
An investigator on a call within the hour, evidence frozen before it decays, and the loss scope agreed in writing on day one.
End-to-end risk management for digital assets, from prevention through to incident response. We trace what moved, name who holds it, and harden the gap it left through.
First-party coverage across 14 chains
“We had the transaction hashes on day one and no idea what they meant. Rolled had a named endpoint and a filed freeze request before the week was out.”
Explorers, screening vendors, sanctions lists, a spreadsheet nobody trusts and a half-written affidavit. The evidence is in there somewhere. Getting it out is the job we took off your desk.
One practice. From the first suspicious hop to a report your counsel can file.
Screening, tracing, custody assurance and reporting run as one practice, so the finding that starts as a flag ends as something your counsel can file.
Counterparty exposure
Treasury wallet · 1,204 counterparties
18 flagged of 1,204 screened
Sanctioned mixer, indirect
OFAC2 hops · 340 ETH
Listed service, funds arrived via one intermediary
Unlicensed OTC desk
Flagged1 hop · 88 ETH
No registration in operating jurisdiction
High-risk exchange deposit
Flagged3 hops · 1,410 ETH
Weak KYC tier, account opened 9 days prior
Darknet-adjacent cluster
Watch4 hops · 12 ETH
Attribution medium, monitoring left open
Licensed custodian
CleanDirect · 6,200 ETH
Regulated entity, screening clear
We show the heuristics behind every merge, so opposing counsel can test the reasoning instead of just doubting it.
Timing, value and gas analysis across mixer outputs, reported with a confidence figure and never as a certainty.
Bridges, wrapped assets and swap routers reconciled so value keeps its identity when the chain changes.
CCSS, ISO 27001 and internal control frameworks taken from gap analysis through to evidenced remediation.
Expert statements, deposition prep and exhibits built to survive challenge on method, not just conclusion.
Dormant hoards and reactivated clusters alert the moment they move, months after the matter goes quiet.
Stack sanctions exposure, cluster attribution and bridge activity onto the same graph until the picture stops being a hunch and starts being a finding.
Entity resolution
Co-spend and behavioural heuristics
Every endpoint carries the jurisdiction that governs it, so you know which lever is realistically available before you spend on it.
Each cluster merge and every demix inference is logged with its basis. Anyone competent can re-run the work and land where we did.
Dormant hoards stay watched after the report ships. When a cluster reactivates months later, you hear about it in under a minute.
One team carries the matter end to end. Nothing gets handed to a stranger halfway through, and nothing gets lost in the handover.
Most firms pick one. Doing all three is what lets the assessment learn from the investigation, and the investigation learn from the last assessment.

Asset tracing, exploit reconstruction and attribution work that stands up in front of an exchange, an insurer or a court.
Explore
CCSS-aligned custody reviews, contract and protocol assessments, and the engineering work to close what we find.
Explore
Licensing, travel-rule and monitoring programmes designed by people who have run the investigations behind them.
ExploreEvery engagement ends in one document: what happened, how we know, what it is worth pursuing and what to fix so it does not happen twice.
Unauthorised outflow, treasury multisig
Value at loss
18,420 ETH
Attributed
62%
Hops traced
5
Endpoints named
6
F-01Signer key compromised via a malicious approval
SevereTwo signers approved an unlimited allowance to an attacker-controlled contract already seen in six prior matters.
F-02Two deprovisioned signers retained quorum weight
SevereOffboarding never propagated to the multisig, leaving the effective threshold below the documented policy.
F-03No screening on outbound destinations
FlaggedOutflows were not checked against sanctions or risk lists, so the first mixer deposit raised nothing internally.

A client came to us three weeks after a theft. They had done the obvious work. Hashes collected, exchange notified, a report filed with the local force. Everything the playbook said to do.
What nobody had done was follow the smallest branch. A single hop carrying under two percent of the value, split off early and written off as noise.
That branch paid a hosting invoice. The invoice carried a name. The name held the rest.
Three weeks of everyone chasing the big number, and the answer sat in the rounding error. So we follow every branch, including the ones that look like nothing, because the one you skip is the one that ends the matter.
Every investigator on the bench carries the certifications the industry actually recognises, and the practice re-certifies rather than coasting on the year it qualified.
Within hours. The first 24 hours decide how much is recoverable, so intake runs on a duty rota. You get an investigator on a call, a preserved evidence set and the first hop map before the funds finish their initial peel chain.
Constantly. We package findings in the formats agencies and compliance desks actually action: attribution memos, subpoena-ready cluster exhibits and freeze requests with the transaction evidence attached rather than summarised.
No firm can promise recovery, and any that does should worry you. What we do is establish where value went, who controls the endpoint and which lever is realistically open, whether that is an exchange freeze, a civil claim or a criminal referral. Recovery follows from that.
Assessments and advisory run on fixed scopes quoted after a short discovery call. Live incidents start on a retainer against an hourly rate, with the estimate revised the moment tracing tells us how deep the matter goes.
Never. Engagements run under mutual NDA by default, evidence sits in a per-matter enclave, and we will not publish, benchmark or reference your incident without written sign-off.
Yes. Compliance analysts, SOC teams and legal staff take the same curriculum our investigators do, on your own case data where you want it, ending in a graded practical rather than a slide deck.

Tell us what happened. You get an investigator on a call, not a sales sequence, and the first hop map before the day is out.