Ethereum and Token Fraud Investigations
3 min read · Last updated
Ethereum and EVM-compatible networks add contract logic to the ledger, which expands both the attack surface and the available evidence.
Investigations here read internal calls and events, not only external transfers.
- 1External transfer
- 2Token event log
- 3Contract interaction
- 4DEX swap
- 5Bridge exit
Beyond simple transfers
Token movement appears as contract events rather than native transfers. Approvals, delegated transfers and internal calls all form part of the evidentiary record.
Laundering through DeFi
Proceeds are commonly swapped on decentralised exchanges, supplied to liquidity pools or routed through bridges. Each step is recorded, but continuity requires careful event-level matching.
- ›DEX swaps into stablecoins
- ›Liquidity-pool entries and exits
- ›Cross-chain bridge deposits and withdrawals
Approval-based theft
Where a drainer contract is involved, the approval transaction is itself key evidence: it identifies the contract, the moment of compromise and, usually, a large victim population.
Campaign linkage
A single drainer contract typically links many independent incidents into one documented campaign.
Endpoints
As on every network, the objective is a documented endpoint at a service that holds identity data.
Case intake is confidential and handled by email at cybersec@securida.info.
Frequently asked questions
- Do bridges end a trace?
- No, but they interrupt it. Continuation is re-established on the destination chain through value, timing and protocol event matching.
- Are NFTs traceable in the same way?
- Yes. Token identifiers make NFT movement especially explicit, including marketplace sales.

- Cyber Intelligence
- Blockchain Investigations
- Digital Forensics
The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.
Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.
About the research teamRelated briefings
Request Confidential Consultation
SEQRIA provides technical investigation, forensic analysis and recovery assistance. Outcomes are never guaranteed. Case intake is confidential and handled by email.
cybersec@securida.info