Cross-chain Asset Tracing
3 min read · Last updated
Assets were moved through four chains and two bridge protocols within a short window, breaking any single-ledger view of the flow.
Executive Summary
Following an unauthorised outflow, assets were moved rapidly across four public chains using two bridge protocols with different settlement models. Conventional single-chain tracing terminated at the first bridge deposit.
The engagement reconstructed the continuation of the flow on each destination chain and documented the basis for every cross-chain link.
Investigation Scope
Scope was defined around continuity of the flow rather than around any single chain.
- ›Identification of every bridge interaction in the outflow path
- ›Reconstruction of the corresponding destination-chain events
- ›Explicit confidence rating for each cross-chain correlation
- ›Termination points recorded at the first attributable service
Technical Challenges
The two bridges used different models: one locked and minted with a deterministic event pair, the other used a liquidity network in which the destination payout came from an unrelated pool. The second model provides no direct link and required statistical correlation.
High transaction volume on one destination chain meant that value-and-time matching alone produced multiple candidates, requiring additional discriminators.
Investigation Methodology
Each link was treated as a hypothesis to be tested, not as a given.
- ›Enumeration of candidate destination events within a defined time window
- ›Elimination using fee structure, rounding behaviour and gas-payer patterns
- ›Behavioural consistency checks across subsequent hops
- ›Documentation of every rejected candidate alongside the accepted one
Blockchain Analysis
Lock-and-mint transfers were confirmed by matching contract events on both sides. Liquidity-network transfers were reconstructed by identifying the single candidate that remained after elimination, then validating it against the continuation pattern observed on subsequent hops.
Correlations were graded: direct event pairing was recorded as high confidence, elimination-based pairing as moderate, and any unresolved segment was reported as unresolved rather than assumed.
Evidence Collection
Both accepted and rejected candidates were preserved so that the elimination logic could be independently audited.
- ›Event logs for every bridge interaction on both sides
- ›Candidate sets with the discriminators applied to each
- ›A confidence register mapping each link to its evidentiary basis
Findings
Three of the four cross-chain segments were reconstructed with a documented basis; one segment remained unresolved and was reported as such. The traced flow terminated at deposit addresses attributable to two centralised services.
Reporting an unresolved segment rather than closing it with an assumption preserved the credibility of the remainder of the analysis.
Outcome
The confidence-graded trace was delivered as an evidentiary package for institutional escalation and legal review.
No outcome is promised in any engagement. The deliverable is a documented, verifiable evidentiary record.
Lessons Learned
Cross-chain tracing is an inference discipline. Its value depends entirely on the honesty of its confidence statements.
- ›Never present an elimination-based match as a direct one
- ›Preserve rejected candidates as part of the record
- ›Report unresolved segments explicitly instead of bridging them with assumptions
Frequently asked questions
- Do bridges make funds untraceable?
- No, but they change the nature of the evidence. Some bridge models produce a direct event pair; others require correlation, which must be reported with an explicit confidence level.
- What does a confidence level mean in a trace?
- It states how the link was established: direct on-chain pairing, elimination among candidates, or behavioural inference. Each has a different evidentiary weight.
- What happens when a segment cannot be resolved?
- It is reported as unresolved. Closing a gap with an assumption undermines the parts of the analysis that are properly supported.

- Cyber Intelligence
- Blockchain Investigations
- Digital Forensics
The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.
Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.
About the research teamRelated case studies
Request Confidential Consultation
SEQRIA provides technical investigation, forensic analysis and evidentiary documentation. Outcomes are never guaranteed. Case intake is confidential and handled by email.
cybersec@securida.info