A private family office, North America
$2.3M traced through a mixer-bridge cluster, evidence packet delivered in eleven days.
- Traced and attributed
- $2.3M
- Brief to evidence packet
- 11 days
- Preservation target identified
- 1 exchange
A long-time client lost the better part of an OTC settlement to a phishing-grade signature on a stale wallet. By the time the engagement opened, the funds had moved through a privacy mixer, a cross-chain bridge, and a deposit address at a major centralized exchange. The brief was simple and unforgiving: where are the funds now, who controls them, and what do we hand the client's counsel to act on it.
- 01Cluster the source
Reconstructed the spending pattern of the originating wallet; isolated the exfil transaction within sixteen minutes of the signed approval.
- 02Trace through the mixer
Used timing-amount-fingerprint analysis on the mixer's deposit/withdrawal pool to recover candidate withdrawal sets within a tight confidence band.
- 03Bridge attribution
Followed the candidate withdrawals across a cross-chain bridge; intersected the destination-side flow with our own bridge-event index to lock the path.
- 04Deposit-address resolution
Resolved the terminal address to a deposit at a major US-domiciled exchange; documented the path so the client's counsel could prepare the preservation request.
- 05Evidence packet
Delivered a written report, reproducible methodology, annotated on-chain graphs, and a block-height-keyed audit trail. The packet went directly to the client's counsel; courtroom presentation was not part of our scope.
We do not promise recovery. We delivered the evidence the client's counsel needed to ask for it.
Source notes redacted · Client identification withheld by agreement