Exchange Intelligence Investigation
3 min read · Last updated
Traced funds reached deposit addresses at several centralised services with different jurisdictions and compliance postures.
Executive Summary
A completed trace terminated at deposit addresses controlled by several centralised services operating under different regulatory regimes. The remaining question was procedural: which service, in which jurisdiction, could act on what evidence.
The engagement produced service-specific submissions matched to each provider's compliance requirements and jurisdictional obligations.
Investigation Scope
Scope covered attribution of deposit points and the construction of submissions for each.
- ›Confirmation of service attribution for each terminal deposit address
- ›Determination of the operating entity and jurisdiction behind each service
- ›Assessment of the applicable reporting and escalation route
- ›Preparation of tailored submissions per service
Technical Challenges
Deposit-address attribution is inferential: an address is identified as belonging to a service through observed consolidation behaviour, not through a published register. Each attribution therefore required corroboration.
Several services operated through multiple entities, so the correct legal counterparty had to be determined before any submission had value.
Investigation Methodology
Attribution was corroborated before any service was contacted.
- ›Consolidation-pattern analysis to confirm service-controlled addresses
- ›Cross-checking against independently observed deposit behaviour
- ›Corporate and licensing research to identify the operating entity
- ›Mapping of each entity to its supervisory authority and reporting route
Blockchain Analysis
Terminal deposit addresses were confirmed as service-controlled through their sweep behaviour into known hot-wallet infrastructure. Timing and amount data were preserved so the service could locate the corresponding internal account record.
Where attribution rested on a single observation, it was reported as provisional.
Evidence Collection
Each submission contained only what the receiving service required, packaged to its stated format.
- ›Per-service transaction sets with timestamps and confirmation data
- ›Attribution basis notes for every deposit address asserted
- ›Jurisdiction and entity mapping supporting the choice of recipient
Findings
Funds reached four distinct services across three regulatory regimes. Two operated under EU supervision with defined escalation routes; the others required a different procedural approach through their respective authorities.
The report set out what each service could be asked to do, and what lay outside its powers.
Outcome
Tailored submissions were delivered for each service alongside a jurisdictional escalation map for the client's legal representatives.
No outcome is promised in any engagement. The deliverable is a documented, verifiable evidentiary record.
Lessons Learned
A trace only becomes actionable when it is routed to the entity with both the records and the obligation to respond.
- ›Identify the operating entity, not just the brand
- ›Match the submission to the service's stated compliance process
- ›State attribution confidence; overstated claims delay compliance review
Frequently asked questions
- Will an exchange disclose account information on request?
- Generally not to a private party. Disclosure ordinarily requires legal process. A well-constructed submission supports internal review and preservation while that process is pursued.
- Why does the operating entity matter?
- Because obligations attach to the legal entity and its supervisor, not to the brand. Submissions directed at the wrong entity are typically not acted upon.
- How is a deposit address attributed to a service?
- Through observed consolidation into known service infrastructure, corroborated by independent observations. The basis is always stated in the report.

- Cyber Intelligence
- Blockchain Investigations
- Digital Forensics
The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.
Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.
About the research teamRelated case studies
Request Confidential Consultation
SEQRIA provides technical investigation, forensic analysis and evidentiary documentation. Outcomes are never guaranteed. Case intake is confidential and handled by email.
cybersec@securida.info