BLOCKCHAIN FRAUDForensic Intelligence
Methodology

How we analyze a case, and what we don't claim.

Every finding we publish should be checkable by you. This page names the sources we use, what each one actually contributes, how we state confidence, and the limits we hold ourselves to. We don't claim partnerships we don't have; we cite the public data we work from.

The data we work from

These are the sources behind our analysis. None of them is a partner or an endorser; they are public datasets and explorers that any investigator can consult, and that you can consult yourself to verify our work.

SourceWhat it isWhat it contributes
TronScan / EtherscanPublic block explorers for TRON and EVM chainsThe transaction trail itself: every transfer, wallet, timestamp, and contract method. This is the primary evidence in any trace.
OFAC SDN listThe U.S. Treasury's sanctions list, which includes designated cryptocurrency addressesSanctions screening. A hit means an address is tied to a designated entity, a hard fact, not a heuristic.
ChainAbuseA public, community-reported database of scam addresses and domainsWhether an address or site has been reported before, and by how many people. We also contribute reports from our own cases.
MetaMask eth-phishing-detectThe open-source phishing blocklist MetaMask ships withKnown phishing domains targeting EVM wallets.
Phantom blocklistThe open-source blocklist Phantom ships withKnown phishing domains targeting Solana wallets.
DeFiLlama hacks feedA public dataset of DeFi exploits and lossesContext on whether a protocol or token has a known exploit history.
Document metadataThe producer, creator, and timestamp fields inside PDFs and imagesForgery tells. A "bank statement" generated by a free PDF library is a checkable fact, not an opinion.

How the free check works

The free analyzer runs entirely in your browser. It reads what you paste against a library of 43 known fraud patterns plus a red-flag layer that catches the universal tells: guaranteed returns, urgency, wallet-connect lures, advance-fee demands, seed-phrase requests, and recovery pitches. It also detects wallet addresses, transaction hashes, and URLs and isolates them as evidence. It does not call any external service, and nothing you paste leaves the page.

It produces a rating, the specific patterns that fired and why, and recommended next steps. It is deterministic: the same input always produces the same result, and every reason it gives points to something in your text.

How we state confidence

Every finding carries one of three labels, and we never blur them.

Automated signal

A pattern matched, or a heuristic fired. Useful and fast, but it is a signal, not proof. Everything the free check reports is this.

Confirmed evidence

A fact verified against a primary source: a transaction on a public explorer, a sanctions listing, a document's own metadata. Paid cases are built on this.

Inconclusive

We looked and could not determine. We say so. "No signal found" is reported as inconclusive, never as "safe" or "clean."

What a paid investigation adds

The limits we hold ourselves to

What we never claimWe never guarantee the recovery of funds. Recovery, when it happens, runs through courts, exchange compliance, and law enforcement, and depends on facts no investigator controls. Any firm that guarantees recovery, or that charges a percentage of "recovered" funds, is running the scam we investigate.

Report integrity

Every report, free or paid, carries a SHA-256 fingerprint of its contents and a timestamp. If a single character of the report changes, the fingerprint changes. It is a tamper-evidence measure, not a court certification, and we describe it as exactly that.