Blockchain forensics, run by agents.
Paste an address. Six forensic agents trace where the funds went, name who is holding them, and hand your counsel the parties to subpoena — with a sealed, court-ready exhibit behind every finding.
Six forensic agents · Recovery leads for counsel · Sealed & publicly verifiable
What we are
A forensic team, run by agents.
Not a $100k tool you have to drive.
The incumbents sell an analyst a tool to trace with, by the six-figure license. We run the investigation for you: six forensic agents trace the money, name who is holding it, and hand your counsel the parties to subpoena — with a sealed, court-ready exhibit behind every finding.
Chain of custody
Every finding SHA-256 hash-linked into an append-only audit log. Tamper-evident across the matter lifecycle.
Examiner declaration
An examiner of record reviews, applies honest limitations, and signs the certification block.
FRE 902(13)/(14)
Packaged for self-authentication of electronically generated records — court-ready, never over-claimed.
Public verifier
Opposing counsel opens the seal in a browser, no account, and confirms it themselves.
Verify a sealed report yourself. No account.
Opposing counsel, a court clerk, or a jury member can independently verify a ForensicBlock seal from a browser — Merkle root, hash chain, methodology version, anchor state. Paste a hash and check it now — no account, nothing to take on faith.
Paste a sealed report's Merkle root or evidence SHA-256, or use a sample. Open the verifier · Read the methodology
We never slap a “verified” badge on a record you haven’t checked. Each anchor renders its own honest state per report — SHA-256 sealed, RFC 3161 timestamped, and Bitcoin-anchored via OpenTimestamps — confirmable on the public verifier.
Crime moved on-chain.
The tools to follow it didn't move with it.
Blockchain crime is a daily reality — sanctioned counterparties, drained wallets, mixers, cross-chain hops. The investigation tooling that handles it was built for governments and the world's biggest banks, sold for six-figure contracts, and gatekept from everyone else. A fintech onboarding a sanctioned address, a family chasing a stolen wallet, a compliance team of one — locked out.
Lost to crypto fraud in 2024 — reported to the FBI's IC3, up 66% in a single year.
What incumbent forensic platforms routinely run annually for enterprise deployments — out of reach for most teams.
Manual analyst time to reconstruct a multi-hop cross-chain trail by hand — bridges, mixers, and all.
We thought that was backwards. The mission below is our answer.
Not a black-box label.
Evidence you can defend.
Chainalysis sells the label. We seal the exhibit. Every finding is cryptographically anchored, methodology-versioned, and chained into an append-only audit log — independently checkable, FRE 902(13)/(14) ready. Opposing counsel verifies the packet in a browser without an account. That's the difference between an answer and evidence.
Numbers we publish, you verify. Every value above is independently checkable —read the raw feed ↗
Numbers you can verify, not numbers we made up.
Every value is fetched from a public endpoint when this page renders.
Proof, not claims
The incumbents gate their incident analysis.
We publish ours — check it yourself.
See the full registry Bybit Exploiter (DPRK / Lazarus Group)
Bybit cold-wallet theft — the largest crypto theft on record
KyberSwap Exploiter (alleged: A. Medjedovic)
KyberSwap liquidity-pool exploit
Euler Finance Exploiter
Euler Finance flash-loan exploit
Wormhole Bridge Exploiter
Wormhole token-bridge exploit
Poly Network Exploiter 1
Poly Network cross-chain exploit
Every entry cites the primary sources — FBI/IC3, court filings, Etherscan, Chainalysis, TRM — and states verbatim what the public record does and does not establish. Paste any of these addresses into the free checker and confirm it against the chain yourself.
Six forensic agents.
The chain of evidence, end-to-end.
Each agent contributes a step in the forensic record — not an investigation step, a custody step. Tracer reconstructs the fund flow. Sentinel authenticates sanctions hits. The Examiner attributes entities. Hunter maps the subpoena target. The Custodian watches it 24/7. The Sealer Bates-stamps the exhibit. You walk out with a sealed, FRE 902-packaged packet a court can verify.
Reconstructs the on-chain trail through mixers, bridges, and exchanges — a hop-by-hop record of custody.
OFAC + Tron/TRC-20 hits, each carrying its named source — attribution that holds on cross.
Clusters entities and detects layering / structuring — every cluster sources its heuristic. No black-box labels.
Maps subpoena targets and the deposit address you can name on a freezing-order application.
24/7 immutable monitoring — webhook the instant a watched address moves, sealed to the audit chain.
Bates-stamps the exhibit. SHA-256 sealed, FRE 902(13)/(14) packaged, opposing-counsel-verifiable.
Trace 7 chains deep.
Screen 18.
Full forensic tracing — hop-by-hop fund flow, entity attribution, and a sealed exhibit — runs on 7 live networks: Ethereum, Bitcoin, Tron, Polygon, Arbitrum, Base, and Optimism. Sanctions and risk screening reaches further still, across 18 networks including Litecoin, Monero, Zcash, XRP, and BNB Smart Chain. Stablecoins — USDT, USDC, DAI — are screened on every live EVM network.
OFAC + multi-authority sanctions, on every supported chain.
Seal your first court-ready record.
Free. Verifiable. Defensible.
Bring one address from a live matter. The forensic agent fleet produces the record — chain of custody, examiner declaration, FRE 902(13)/(14) packaging — and you walk out with a sealed packet opposing counsel can verify from a browser without an account.