REF-2026-0138 · Anonymised case record

    Digital Asset Investigation

    3 min read · Last updated

    A corporate treasury discovered unauthorised outbound transfers from a multi-signature arrangement following a change in signer procedure.

    Executive Summary

    A corporate holder identified outbound transfers from a treasury wallet that did not correspond to any approved internal instruction. The transfers occurred shortly after an operational change to the signing procedure.

    The engagement established what occurred on-chain, when it occurred, and which internal and external conditions made it possible, without attributing responsibility to any individual.

    Investigation Scope

    The mandate was strictly factual reconstruction, with governance findings kept descriptive.

    • Reconstruction of every outbound transfer within the review window
    • Correlation of on-chain events with internal approval records
    • Review of the custody configuration as it existed at each relevant time
    • Documentation suitable for insurer and board review

    Technical Challenges

    Approval records were held in systems with inconsistent time sources, so internal timestamps could not be compared directly with block times until a clock-offset baseline was established.

    Part of the activity involved contract interactions rather than simple transfers, which required decoding call data to determine what had actually been authorised.

    Investigation Methodology

    Reconstruction preceded interpretation; no conclusion was drawn before the timeline was complete.

    • Full extraction of wallet history for the review period
    • Decoding of contract interactions to recover the authorised action
    • Normalisation of all internal timestamps to a single reference clock
    • Gap analysis between authorised instructions and executed transactions

    Blockchain Analysis

    Transaction-level analysis showed that the unauthorised movements were executed through an approval granted earlier and never revoked, rather than through a compromise of the signing keys themselves.

    Downstream flow was traced to the first attributable service. The path showed no obfuscation attempt, which was itself recorded as a behavioural observation.

    Evidence Collection

    On-chain data, decoded call data and internal records were preserved together so the correlation could be reproduced independently.

    • Wallet history exports with block heights and decoded input data
    • Hash-verified copies of internal approval records as supplied
    • A reproducibility annex allowing a third party to repeat the analysis

    Findings

    The investigation established that a standing contract approval, granted for an earlier operational purpose, remained active and was the mechanism used. Key material showed no evidence of compromise.

    Findings were framed as mechanism and sequence, not as allegation.

    Outcome

    The documented timeline and mechanism analysis were provided for insurer review and internal governance decisions.

    No outcome is promised in any engagement. The deliverable is a documented, verifiable evidentiary record.

    Lessons Learned

    Standing approvals are a durable exposure that survives personnel and procedural change.

    • Review and revoke contract approvals on a fixed schedule
    • Keep custody-system clocks synchronised to a common reference
    • Retain decoded transaction records, not only value summaries

    Frequently asked questions

    Does an unauthorised transfer always mean key compromise?
    No. A significant share of incidents originate from standing permissions or approval mechanisms rather than from key material being obtained.
    Can an investigation apportion internal responsibility?
    A technical investigation documents mechanism, sequence and access conditions. Apportioning responsibility is a governance or legal determination made on that record.
    Is on-chain analysis reproducible by a third party?
    It should be. Every finding is delivered with the underlying identifiers and method notes so an independent analyst can repeat the work and reach the same result.
    Author
    SEQRIA Research Team emblem
    SEQRIA Research TeamInvestigative research unit, SEQRIA
    • Cyber Intelligence
    • Blockchain Investigations
    • Digital Forensics

    The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.

    Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.

    About the research team

    Related case studies

    Request Confidential Consultation

    SEQRIA provides technical investigation, forensic analysis and evidentiary documentation. Outcomes are never guaranteed. Case intake is confidential and handled by email.

    cybersec@securida.info
    Intelligence Center