Digital Asset Investigation
3 min read · Last updated
A corporate treasury discovered unauthorised outbound transfers from a multi-signature arrangement following a change in signer procedure.
Executive Summary
A corporate holder identified outbound transfers from a treasury wallet that did not correspond to any approved internal instruction. The transfers occurred shortly after an operational change to the signing procedure.
The engagement established what occurred on-chain, when it occurred, and which internal and external conditions made it possible, without attributing responsibility to any individual.
Investigation Scope
The mandate was strictly factual reconstruction, with governance findings kept descriptive.
- ›Reconstruction of every outbound transfer within the review window
- ›Correlation of on-chain events with internal approval records
- ›Review of the custody configuration as it existed at each relevant time
- ›Documentation suitable for insurer and board review
Technical Challenges
Approval records were held in systems with inconsistent time sources, so internal timestamps could not be compared directly with block times until a clock-offset baseline was established.
Part of the activity involved contract interactions rather than simple transfers, which required decoding call data to determine what had actually been authorised.
Investigation Methodology
Reconstruction preceded interpretation; no conclusion was drawn before the timeline was complete.
- ›Full extraction of wallet history for the review period
- ›Decoding of contract interactions to recover the authorised action
- ›Normalisation of all internal timestamps to a single reference clock
- ›Gap analysis between authorised instructions and executed transactions
Blockchain Analysis
Transaction-level analysis showed that the unauthorised movements were executed through an approval granted earlier and never revoked, rather than through a compromise of the signing keys themselves.
Downstream flow was traced to the first attributable service. The path showed no obfuscation attempt, which was itself recorded as a behavioural observation.
Evidence Collection
On-chain data, decoded call data and internal records were preserved together so the correlation could be reproduced independently.
- ›Wallet history exports with block heights and decoded input data
- ›Hash-verified copies of internal approval records as supplied
- ›A reproducibility annex allowing a third party to repeat the analysis
Findings
The investigation established that a standing contract approval, granted for an earlier operational purpose, remained active and was the mechanism used. Key material showed no evidence of compromise.
Findings were framed as mechanism and sequence, not as allegation.
Outcome
The documented timeline and mechanism analysis were provided for insurer review and internal governance decisions.
No outcome is promised in any engagement. The deliverable is a documented, verifiable evidentiary record.
Lessons Learned
Standing approvals are a durable exposure that survives personnel and procedural change.
- ›Review and revoke contract approvals on a fixed schedule
- ›Keep custody-system clocks synchronised to a common reference
- ›Retain decoded transaction records, not only value summaries
Frequently asked questions
- Does an unauthorised transfer always mean key compromise?
- No. A significant share of incidents originate from standing permissions or approval mechanisms rather than from key material being obtained.
- Can an investigation apportion internal responsibility?
- A technical investigation documents mechanism, sequence and access conditions. Apportioning responsibility is a governance or legal determination made on that record.
- Is on-chain analysis reproducible by a third party?
- It should be. Every finding is delivered with the underlying identifiers and method notes so an independent analyst can repeat the work and reach the same result.

- Cyber Intelligence
- Blockchain Investigations
- Digital Forensics
The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.
Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.
About the research teamRelated case studies
Request Confidential Consultation
SEQRIA provides technical investigation, forensic analysis and evidentiary documentation. Outcomes are never guaranteed. Case intake is confidential and handled by email.
cybersec@securida.info