Skip to content

Forensics

Preserve and interpret digital artifacts

We examine devices, backups, and application logs with chain-of-custody awareness to support fund-loss investigations.

Forensic focus

Digital forensics clarifies how apps were installed, sessions hijacked, or approvals signed.

Work complements blockchain tracing when victim machines hold the missing context.

When forensics adds value

  • Suspected malware, remote access, or cloned trading apps
  • Disputes over who controlled a device at transfer time
  • Need to validate screenshots versus underlying log files
  • Corporate devices involved in treasury fraud

Artifact classes

01

Mobile images

Parse install history, accessibility abuse, and sideloaded APK/IPA traces.

02

Browser and session data

Recover phishing landing timestamps and cookie/session overlap.

03

Application exports

Validate exchange CSV integrity and API key creation events.

Forensic workflow

  1. 01

    Preservation

    Document acquisition method and hashing where full imaging is feasible.

  2. 02

    Examination

    Targeted parsing aligned to hypotheses—not unfocused data dumps.

  3. 03

    Reporting

    Relate findings to payment events with exhibit references.

Forensic deliverables

Acquisition log

What was taken, when, and from which device profile.

Finding sheets

Per-artifact conclusions with confidence statements.

Crosswalk to chain

Mapping log timestamps to on-chain movements.

Frequently asked questions

Do you need my phone unlocked?

Scope depends on case; we advise on lawful preservation options without bypass coaching.

Can deleted chats be recovered?

Sometimes from backups or server exports; we set expectations early.

Discuss forensic scope

Describe devices and exports available—we will not request seed phrases.