Blockchain Evidence Collection
3 min read · Last updated
An existing trace had to be re-documented to an evidentiary standard after its methodology was challenged in proceedings.
Executive Summary
A previously produced trace was challenged on the grounds that its methodology was undocumented and its outputs could not be independently reproduced. The underlying analysis was largely sound; its documentation was not.
The engagement re-established the same analysis to an evidentiary standard, with full preservation, method documentation and reproducibility.
Investigation Scope
The scope was documentation and verification rather than new investigation.
- ›Independent re-derivation of every asserted transaction path
- ›Preservation of source data with hashes and acquisition records
- ›Written methodology annex describing each analytical step
- ›Chain-of-custody record from acquisition to delivery
Technical Challenges
Blockchain data is public but not static in presentation: explorers reformat, re-index and occasionally revise displayed data. Preservation therefore had to capture raw node-level responses rather than explorer screenshots.
Reorganisations near the tip of the chain meant confirmation depth had to be recorded for every captured transaction.
Investigation Methodology
Every step was designed so that an independent analyst could repeat it and obtain identical output.
- ›Acquisition of raw transaction and block data with recorded confirmation depth
- ›Cryptographic hashing of every artefact at the point of acquisition
- ›Written statement of each heuristic applied and its limitations
- ›Independent re-derivation by a second analyst before delivery
Blockchain Analysis
The re-derivation confirmed the original path in full, and corrected one hop where the earlier work had merged two distinct addresses. The correction was documented rather than silently applied.
Each hop was delivered with its raw data, its method note and its confidence basis.
Evidence Collection
Preservation was treated as the primary deliverable rather than as a by-product of the analysis.
- ›Raw node-level responses stored alongside human-readable exports
- ›SHA-256 hashes recorded at acquisition and verified at delivery
- ›Continuous chain-of-custody log with handler, time and action
- ›A verification guide enabling a third party to reproduce the result
Findings
The re-documented trace withstood methodological review. The single correction identified during re-derivation strengthened rather than weakened the record, because it demonstrated that the process detects its own errors.
Outcome
A fully preserved, reproducible evidentiary package was delivered with a methodology annex suitable for expert review.
No outcome is promised in any engagement. The deliverable is a documented, verifiable evidentiary record.
Lessons Learned
An analysis that cannot be reproduced is not evidence, however accurate it happens to be.
- ›Preserve raw responses, not explorer screenshots
- ›Record confirmation depth at the moment of capture
- ›Document heuristics and their limits before conclusions are drawn
Frequently asked questions
- Why is public data still preserved?
- Because the presentation of that data changes over time and because an evidentiary record must show what was observed, when, and by what method.
- What makes a blockchain trace defensible?
- Reproducibility, documented heuristics, hash-verified preservation and an unbroken chain of custody. Conclusions alone are not defensible.
- Does correcting an error damage the analysis?
- No. A documented correction demonstrates that the methodology has internal verification. Undisclosed corrections are what damage credibility.

- Cyber Intelligence
- Blockchain Investigations
- Digital Forensics
The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.
Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.
About the research teamRelated case studies
Request Confidential Consultation
SEQRIA provides technical investigation, forensic analysis and evidentiary documentation. Outcomes are never guaranteed. Case intake is confidential and handled by email.
cybersec@securida.info