01
Exploit tracing
Follow attacker wallets post-incident.
DeFi exploit
Users lose funds when protocols are drained, or when they interact with forked malicious contracts.
Includes governance hacks, reentrancy bugs, oracle manipulation, and malicious forks posing as official apps.
Victims may be liquidity providers or traders on compromised interfaces.
Attacker exploits contract logic at scale.
DNS or CDN compromise redirects to malicious router.
Locked assets minted unredeemed on destination chain.
Exploit proceeds move through mixers and OTC quickly.
01
Follow attacker wallets post-incident.
02
Map user losses to pool events.
Never provide a seed phrase, private key, or authentication code to anyone claiming they can recover funds—including parties who contact you unsolicited. Legitimate investigators do not need wallet secrets to begin a case review.
Depends on treasury, governance, and insurance—not guaranteed.