Chain Fraud Watch
GUIDES

What to do, in the order that matters

Written for the first day after a theft or a scam. Free, no signup, and useful whether or not you ever hire us.

SECTION 1
1).

The first 24 hours

Evidence disappears fast and trails cool fast. What you do in the first hours decides how much can be established later.

  1. 1/
    Move what is left, then stop touching itMove remaining funds to a new wallet with a new seed generated on a clean device. Do not reuse the compromised wallet for anything, including receiving a refund.
  2. 2/
    Record the theft transaction immediatelyCopy the transaction hash, the address the funds left, and the address they went to. Screenshot everything with the clock visible. This is the entire starting point for any trace.
  3. 3/
    Report to the exchange and the police the same dayIf funds reached a named exchange, contact its security team and file a police report in your jurisdiction. Both create records that anyone acting on the case later will need.
  4. 4/
    Ignore anyone who messages you offering recoveryAccounts that appear in your replies within hours of a theft are almost always a second scam. Nobody legitimate asks for an upfront fee plus your seed phrase, and no tool can reverse a confirmed transaction.
SECTION 2
2).

Evidence checklist

What an investigator, an exchange or a court actually needs from you. Gather it once, properly.

  1. 1/
    Transaction hashes for every movementThe theft transaction first, then anything you sent afterwards. Hashes, not screenshots of balances, are what let someone else verify the path.
  2. 2/
    Your addresses and the thief'sEvery address you controlled that was affected, and every destination address you can see. Label which is which so nothing gets mixed up later.
  3. 3/
    Captures of the contact itselfPhone numbers, emails, chat logs, caller ID, the fake site URL, the signature request you approved. Attribution usually comes from this, not from the chain.
  4. 4/
    A written timeline with timestampsWhat happened, in order, with times and time zone. Written the same day, while you still remember the sequence.
SECTION 3
3).

Where to report

Reporting in parallel is normal and expected. One channel rarely does everything.

  1. 1/
    Local police, for the case numberEven where the force has no crypto capability, the report creates a record that exchanges and insurers will ask for.
  2. 2/
    The receiving exchangeIf funds landed at a business with a compliance desk, that business holds the account records behind the receiving address. Only they, or legal process served on them, can produce those.
  3. 3/
    National fraud and cybercrime channelsMost countries have a central reporting body separate from local police. File there too; that is often where cases get aggregated across victims.
  4. 4/
    Counsel, if the amount justifies itCivil process can compel disclosure in ways a police report cannot. Worth pricing early rather than after the trail cools.
SECTION 4
4).

Responsible disclosure

How we handle findings about people, and why we are careful about publishing.

  1. 1/
    Findings go to parties who can actClients, exchange security teams, and law enforcement. A public thread feels satisfying and warns the person you are tracing.
  2. 2/
    We name people only when charges are publicBefore that, an identification is an allegation about someone who has not been charged, however good the evidence looks.
  3. 3/
    Naming carries risk you inheritPublishing an accusation exposes you to defamation claims and can prejudice a live investigation. We will tell you when we think publishing is a bad idea.
  4. 4/
    Tell us privately if you have informationIf you hold information about a case we are working, send it to us rather than posting it. Attribution holds up better when the subject does not see it coming.

If it happened in the last few hours, stop reading

Send us the theft address and what happened. Reading can wait; a cooling trail doesn't.

Report a case