Blockchain Intelligence Methodology
Our investigative methodology for digital asset intelligence and blockchain forensic analysis.
9 min read · Last updated
This document describes the investigative methodology SEQRIA applies to digital asset intelligence and blockchain forensic analysis. It is maintained as an internal working reference and published for clients, counsel and institutional counterparties who require visibility into procedure before instructing work.
The methodology defines sequence, evidentiary standards and reporting constraints. It does not describe outcomes. Blockchain analysis establishes what can be observed on a ledger and what can be reasonably inferred from it; it does not determine whether any party will act on those findings.
1. Investigation Lifecycle
Every engagement follows the same ten phases. Phases are sequential; a phase is not entered until the preceding one has produced a recorded output.
- 1Initial Assessment
- 2Evidence Review
- 3Blockchain Analysis
- 4Wallet Attribution
- 5Transaction Mapping
- 6Risk Assessment
- 7Exchange Intelligence
- 8Documentation
- 9Reporting
- 10Case Closure
Each phase produces a recorded output that becomes an input to the next.
- 01
- Initial AssessmentIntake of the reported incident, identification of the asset classes and networks involved, and a feasibility review establishing whether on-chain data is sufficient to support analysis. Cases with no verifiable transaction identifiers are declined at this stage.
- 02
- Evidence ReviewStructured review of material supplied by the instructing party: transaction hashes, wallet addresses, platform correspondence, screenshots and account records. Each item is logged, hashed and assessed for integrity before it enters the working file.
- 03
- Blockchain AnalysisReconstruction of the transaction path from the point of loss forward. Inputs and outputs are followed across the relevant ledgers, with each hop recorded against block height and timestamp.
- 04
- Wallet AttributionClustering of addresses into probable controlling entities using co-spend heuristics, behavioural patterns and known service fingerprints. Attribution confidence is recorded explicitly and never presented as identification of a natural person.
- 05
- Transaction MappingConstruction of a directed graph of value movement, including consolidation points, splitting patterns, bridge crossings and terminal deposits. The graph forms the evidentiary spine of the final report.
- 06
- Risk AssessmentScoring of counterparties and endpoints against sanctions data, known illicit-service typologies, mixer exposure and jurisdictional risk. Scores are stated with their basis and the date of the underlying data.
- 07
- Exchange IntelligenceIdentification of centralised venues that received traced value, determination of the applicable compliance contact, and preparation of the material such a venue requires to review the deposit internally.
- 08
- DocumentationAssembly of the evidence package: exhibit index, hash manifest, chain-of-custody record, wallet diagrams and transaction tables in a format suited to institutional and legal review.
- 09
- ReportingProduction of the technical report, including an executive summary, findings, stated confidence levels, limitations and recommended next steps for counsel or law enforcement.
- 10
- Case ClosureFormal closure with a retention decision on case data, delivery of the final package to the instructing party, and a record of any matters left open for future re-examination if new on-chain activity occurs.
2. Evidence Preservation
Evidence handling precedes analysis. Material that cannot be shown to be unaltered has limited value in regulatory or judicial review, regardless of what the analysis concludes.
- Hash verification
- Every file received or generated is hashed (SHA-256) at the point of receipt. Hashes are recorded in a manifest that accompanies the final package.
- File integrity
- Working copies are used for analysis; originals are retained unmodified in read-only storage and re-hashed before delivery to confirm they are unchanged.
- Screenshots
- Captured with visible URL, system clock and full page context. Partial or cropped captures are treated as indicative only and marked as such in the exhibit index.
- Wallet exports
- Address lists, balances and transaction histories are exported in machine-readable form with the source, block height and query timestamp recorded.
- Transaction records
- Each transaction is stored with its hash, block, timestamp, inputs, outputs and fee, retrieved from at least one independent node or explorer for verification.
- Metadata preservation
- Original file metadata is preserved intact. Extraction is performed on copies so that timestamps, device identifiers and editing history remain intact on the source.
- Chain of custody
- A dated log records who received each item, from whom, in what condition, and every subsequent access. The log is included in the delivered package.
3. Wallet Attribution
Attribution assigns control of addresses to entities, not to individuals. The distinction is maintained throughout the report: an address may be attributed to a service, a cluster or an operational pattern; naming a person requires evidence obtained through lawful process by an authorised body.
- Wallet clustering
- Grouping of addresses under probable common control using co-spend analysis, change-output heuristics and consistent scripting or nonce behaviour.
- Behaviour analysis
- Examination of transaction cadence, value structuring, fee policy and automation signatures that distinguish operator-controlled wallets from service infrastructure.
- Entity attribution
- Matching clusters against documented deposit-address patterns of exchanges, bridges, payment processors and known illicit services, with a stated confidence level for each match.
- Transaction timing
- Temporal analysis of activity windows, which can indicate operating hours, automation or coordination between otherwise unlinked clusters.
- Known services
- Cross-reference against maintained datasets of custodial services, mixers, gambling platforms and sanctioned addresses, with the dataset version recorded.
- Exchange interaction
- Identification of deposits into and withdrawals from custodial venues, which are the points at which off-chain records may exist.
- Risk indicators
- Documented signals such as mixer proximity, peel-chain structuring, rapid cross-chain movement and exposure to sanctioned entities.
4. Blockchain Analytics
Analysis is conducted per network, because ledger models differ. Findings from one chain are not assumed to transfer to another; cross-chain continuity must be evidenced at the bridge or venue that connects them.
- Bitcoin
- UTXO-model tracing with co-spend clustering, change identification, peel-chain reconstruction and consolidation analysis.
- Ethereum
- Account-model tracing including internal transactions, contract interactions, token transfers and approval events that may explain unauthorised outflows.
- USDT
- Issuer-token analysis across its deployed networks, including the issuer's freeze history as a matter of public record, without any assumption that freezing will occur in a given case.
- Solana
- Programme-level tracing across associated token accounts, with attention to high transaction throughput and rapid dispersal patterns.
- Cross-chain movement
- Correlation of an outbound transaction on one chain to an inbound transaction on another by value, timing and bridge contract behaviour, with the correlation confidence stated.
- Bridge analysis
- Examination of bridge contracts, relayers and liquidity pools to establish whether continuity is demonstrable or only probable.
- Mixer detection
- Identification of deposits to mixing and privacy services. Where value enters such a service, the report states that the trail terminates rather than presenting speculative continuation.
- Liquidity tracking
- Analysis of movement through decentralised exchanges and liquidity pools, including swap paths used to change asset type mid-trail.
5. Exchange Intelligence
Centralised venues are the primary point at which on-chain analysis meets identifiable off-chain records. SEQRIA prepares material to the standard those venues and their regulators expect; it does not act on behalf of any authority and cannot compel disclosure.
- Centralized exchanges
- Identification of the receiving venue from deposit-address patterns, and determination of its operating entity and supervisory jurisdiction.
- Compliance requests
- Preparation of structured notifications to compliance and financial-crime teams, containing transaction identifiers, timestamps and the analytical basis for the concern.
- KYC evidence
- Documentation framed so that a venue or authority can match a deposit to an account record under its own legal basis. SEQRIA neither requests nor receives customer identity data directly.
- Deposit tracing
- Reconstruction of the path into the venue, isolating the specific deposit transaction rather than the wider cluster.
- Withdrawal tracing
- Where subsequent outbound activity is observable, continuation of the trail beyond the venue, with the break in evidentiary continuity clearly noted.
- Risk analysis
- Assessment of the venue's jurisdiction, licensing status and responsiveness history, which informs the realistic value of escalation in that direction.
6. Digital Evidence
On-chain data is only part of a case file. Off-chain material establishes context, intent and the mechanism of loss, and is handled under the same preservation standard as blockchain records.
- Transaction hashes
- Primary identifiers verified against the ledger before use. Any hash that cannot be resolved on-chain is excluded from findings.
- Wallet addresses
- Recorded in canonical form with checksum verification and network designation to avoid cross-network confusion.
- Screenshots
- Platform interfaces, balances, correspondence and account states, captured with full context and indexed as exhibits.
- Email headers
- Full headers retained for originating-infrastructure analysis, authentication results and delivery path reconstruction.
- Device evidence
- Where supplied, device-level artefacts are reviewed in copy form only, with the original preserved for any subsequent forensic examination by an authorised examiner.
- Metadata
- Document, image and file metadata extracted and reported with its provenance, including where fields are absent or inconsistent.
- Communication logs
- Messaging records, call logs and platform correspondence organised chronologically to support the case timeline.
7. Case Documentation
Documentation is prepared so that a reader who was not present during the investigation can follow each conclusion back to its underlying evidence.
- Timeline
- A chronological record of events combining off-chain incidents with on-chain transactions, each entry referenced to an exhibit.
- Executive summary
- A non-technical statement of what was examined, what was established, what remains unresolved and what the stated limitations are.
- Evidence references
- Every factual claim carries an exhibit reference. Claims without a reference are removed before delivery.
- Wallet diagrams
- Cluster diagrams showing attributed entities, confidence levels and the boundaries of each cluster.
- Transaction graphs
- Directed value-flow graphs annotated with amounts, timestamps and endpoint classifications.
- Technical findings
- Detailed analytical section written for a technical reader, including method, data sources and query dates.
- Risk score
- A structured score for identified endpoints and counterparties, with the scoring basis published alongside the result.
- Recommendations
- Procedural next steps for counsel, law enforcement or compliance teams. Recommendations are procedural only and do not forecast outcomes.
8. Legal Coordination
SEQRIA operates as a technical investigator and produces material for parties with the standing to act. It does not provide legal advice, does not represent clients before authorities and does not conduct enforcement.
- Law firms
- Delivery of technical findings in a form instructing counsel can rely on for civil proceedings, freezing applications or regulatory submissions.
- Law enforcement
- Preparation of referral packages structured to the intake requirements of the relevant national unit or cybercrime authority.
- Compliance teams
- Notification material for financial institutions and virtual-asset service providers, framed for internal review under their own obligations.
- Regulators
- Structured submissions to supervisory bodies where the conduct falls within a regulated activity or licensing regime.
- Evidence packages
- A complete package: exhibit index, hash manifest, chain-of-custody log, diagrams and the technical report.
- Court-ready documentation
- Documentation prepared to a standard suited to judicial review, with methodology, data sources and limitations disclosed so findings can be independently examined.
9. Reporting Standards
Reporting standards constrain what may be written. They exist to keep the report defensible when it is examined by an opposing technical expert.
- Technical accuracy
- Every on-chain assertion is verified against ledger data at a recorded query time. Inference is labelled as inference.
- Transparency
- Methods, tools, datasets and their versions are disclosed, so that a third party can reproduce the analysis from the same inputs.
- Evidence references
- Findings are traceable to specific exhibits and transaction identifiers rather than to summary description.
- Investigation limitations
- Gaps, terminated trails, unresolved attribution and data-availability constraints are stated explicitly in the report body, not only in the appendix.
- Independent verification
- Reports are structured so that another qualified analyst can verify or challenge each conclusion using public ledger data.
- Professional ethics
- No outcome is promised, no probability of asset return is stated, and no engagement is accepted where the objective conflicts with applicable law.
10. FAQ
- What does this methodology cover?
- It covers the procedure applied to digital asset intelligence work: intake assessment, evidence preservation, ledger analysis, attribution, exchange intelligence, documentation and reporting. It does not cover legal representation or enforcement, which are outside SEQRIA's function.
- Does blockchain analysis result in the return of assets?
- No. Analysis establishes where value moved and which entities can be identified along that path. Any return of assets depends on decisions taken by exchanges, regulators, law enforcement or courts. SEQRIA provides recovery assistance in the form of technical evidence and does not state or imply that assets will be returned.
- How is attribution confidence expressed?
- Each attribution carries a stated confidence level with its basis: heuristic clustering, service fingerprint matching, behavioural correlation or documented public disclosure. Attribution is to an entity or cluster, never to a named individual.
- What happens when value enters a mixer or privacy service?
- The report records the deposit, the service, the amount and the timestamp, and states that evidentiary continuity ends at that point. Speculative reconstruction beyond a mixing service is not presented as a finding.
- Can findings be used in court?
- Documentation is prepared to be usable in judicial and regulatory proceedings, with a chain-of-custody record, hash manifest and disclosed methodology. Admissibility is determined by the forum and by instructing counsel, not by SEQRIA.
- Does SEQRIA contact exchanges on a client's behalf?
- SEQRIA prepares structured notifications for compliance teams and can transmit technical material where appropriate. It does not act as an agent of the client, cannot compel disclosure and does not receive customer identity data from venues.
- How long does an investigation take?
- Duration depends on the number of hops, the networks involved, cross-chain activity and the completeness of the material supplied at intake. Estimates are given per case after the initial assessment and are revised when scope changes.
- What material is required at intake?
- At minimum, verifiable transaction hashes or wallet addresses, the approximate time of loss, and any platform correspondence. Cases without verifiable on-chain identifiers cannot be analysed and are declined.
- How is client data retained?
- Case data is held under a documented retention decision recorded at closure, processed in accordance with GDPR, and deleted or archived according to that decision. Retention terms are agreed before work begins.
- Can another analyst verify the results?
- Yes. Reports disclose methods, data sources, tool versions and query dates so that an independent analyst working from public ledger data can reproduce or challenge each conclusion.
Related services
Related briefings
Case intake
SEQRIA is a digital intelligence and forensic investigations company. Work is limited to technical investigation, evidence documentation and recovery assistance in the form of material prepared for counsel, compliance teams and authorities. No outcome is promised.
cybersec@securida.info
- Cyber Intelligence
- Blockchain Investigations
- Digital Forensics
The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.
Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.
About the research team