top of page

The Case Was Built on the Wrong Address

Writer: Blockchain Unmasked
Blockchain Unmasked
10 minutes ago
10 min read

What we keep finding when law firms hand us crypto forensics that someone else prepared


More and more of our civil work starts the same way. A law firm has a crypto case. The tracing was done before we were involved, by a vendor, a software tool, or a "recovery company" the victim found online. By the time we see it, the case has already been filed and the defendant has moved to dismiss, sometimes more than once, or, in the fortunate cases, it is heading into arbitration. Then someone asks us to make sense of the data, and we find that it doesn't hold up.


This is not one firm's problem. We've seen it across multiple matters with multiple firms, and the same mistakes keep showing up. I've got to be extremely clear here:


Forensics is not a supporting exhibit in a crypto case.


It is the case.


It decides:

  • which plaintiffs qualify and which get eliminated

  • whether the complaint survives a motion to dismiss

  • how much of the tracing the defense can take apart on cross


I want to lay the patterns out plainly, because every one of them was avoidable, and every one of them cost the client time and money, and possibly the entire case, unless we can rescue it. I'll use concrete examples from the past few years.


Pattern 1: The funds never reached the defendant


In a multi-plaintiff action against a major exchange, the original tracing, done by a "forensics company," showed every plaintiff's funds landing at that exchange.


When we reproduced the traces, many of them did not. Their funds terminated at nested services: separate businesses with their own wallets and their own customers, which keep accounts at the exchange to reach its liquidity.


The victim's money stopped in the nested service's wallets. It never reached the exchange.

The exchange had no customer relationship with the person who received the funds, and no records on them. The nested service did.



A note on this particular "forensics company." Every one of their reports we have reviewed has been wrong. Every single one. For each of those reports the victim paid a non-refundable $6,500 fee and signed a 12.5 percent contingency, with no law enforcement assistance and no expert witness testimony included.


Not that testimony would have helped, since the forensics were wrong.


In this instance, the original "analysts" made two mistakes, and the second is worse than the first.


Mistake one: trusting the label.


The tracing tool had tagged the receiving address with the exchange's name, and the analyst wrote the exchange into the report as the destination.


The label was wrong. I cannot count how many times, and on how many forensics platforms, I have seen a wallet, address, service, or centralized exchange mislabeled.


We cannot take a label as true simply because the screen says it.


In this specific plaintiff's case, the address belonged to the nested service, not the exchange, and the tool had attributed it to the exchange because the nested service moves so much of its money through the exchange's accounts.


A label is a guess about who controls an address. Not truth that should hold up in court.

Nobody checked the guess, and the exchange got named as the defendant on the strength of it.


Mistake two: tracing through the nested service.


The analyst kept tracing on the other side of the nested service, as if the funds had passed through an externally owned account (EOA).


They had not.


A nested service is a custodial pool. Once a victim's funds enter it, they are commingled with every other customer's funds, and whatever leaves on the far side cannot be attributed to that victim without the service's own internal ledger.


You cannot trace through a service like that and then claim the funds ended up in the defendant's wallets.


The plaintiffs whose traces depended on those steps are now candidates to be dropped from a case that is already well underway.


None of this automatically clears the host exchange. An exchange that lets nested services run on its rails without knowing who they are and what they do has a compliance failure of its own, and that failure can support a claim.


But it is a different claim, built on different facts, and it has to be pleaded as one.

The original tracing never gave counsel that choice, because it never identified the nested service in the first place.


Pattern 2: The forensics came from a scam


One plaintiff in a civil matter had a tracing report prepared by a "forensics company" that is, in fact, a recovery scam. This is not our opinion. The FBI seized its website in 2024, and at least one European regulator has issued a public warning against it. Recovery scams target people who have already been defrauded, charge them for a report, and sometimes produce something that looks like a trace.


The FBI has been warning about exactly this since 2023. Its public service announcement on cryptocurrency recovery schemes describes companies that charge an up-front fee and then either disappear or produce an incomplete or inaccurate tracing report and ask for more money, and it notes that these companies may claim ties to law enforcement or legal services to look legitimate. A year later the FBI issued a follow-up on fake law firms doing the same thing.


We flagged this to counsel. Nothing in that report can be relied on, cited, or placed in front of a court or tribunal. The work has to be independently reproduced from the victim's own records.


So the client pays for the same trace twice.


This is not a problem confined to civil practice. In a 2025 federal criminal trial involving a cryptocurrency mixing service, the government's first victim witness testified that her stolen funds had been traced to the mixer by a "recovery company" whose websites the FBI had seized the year before.


Independent analysts reproduced the trace and showed her funds never reached the mixer. The recovery company had followed the wrong output of a swap service and kept going. The defense raised the possibility of a mistrial. If a US Attorney's office can end up with a recovery scam's tracing in front of a jury, a plaintiff's firm can certainly end up with one in its complaint.


We have seen it more than once.


Pattern 3: A picture is not an attribution


Another report in a civil matter came from a tracing vendor and consisted of a flow visualization only.


  • No CSV.

  • No flow of funds in written form.

  • No transaction data.


Just arrows from the victim's wallet, through intermediaries, to a set of destination addresses, several of them labeled as exchanges.


It looked like an exhibit. It was not admissible in any sense.


A diagram looks good and looks official, and it can be useless. Law firms trust "forensics companies" because they have no way of knowing better.


Unfortunately, the visualization was also inaccurate. Several of those destinations reflected commingled funds at intermediary addresses. The victim's money went into an address that also held other people's money, and the chart simply followed everything that flowed out of the wallets.


There was:


  • no stated tracing methodology

  • no rule for how the victim's specific funds were allocated through a mixed address

  • no way for anyone to reproduce the result


When you apply a defensible method, some of those exchange destinations disappear. What remains is a much smaller claim than the one that was filed.


Methodology is not a technicality. Since the December 2023 amendment to Federal Rule of Evidence 702, the party offering an expert has to show the court that it is more likely than not that the opinion rests on sufficient data, on reliable methods, and on a reliable application of those methods to the facts of the case. A chart with no stated method fails all three.


In the federal trial mentioned above, the government's own tracing agent conceded on cross-examination that a different allocation method could have produced a different conclusion.


A defense lawyer who hears that has everything they need.


Pattern 4: The infrastructure was mislabeled


On a separate matter, a well-known data vendor's tracing labeled a bridge contract as a centralized exchange.


Same company brand, very different forensic implication.


A bridge is a smart contract that moves assets between chains. The exchange is a custodial business with customers, KYC files, and records that can be subpoenaed.


The vendor's label collapsed the two.


Everything downstream of that label was subsequently wrong: the theory of custody, the records request, the plaintiff's factual narrative.


Once we corrected it, the plaintiff's facts had to be rewritten.


Why this keeps happening


Address labels in commercial tracing tools are heuristics. They're often right and sometimes badly wrong, and there is no methodology behind them, no evidentiary weight, and nobody accountable when they miss.


  • A dashboard screenshot is not a finding.

  • A report from a company nobody vetted is not a finding.

  • A flow chart with no stated allocation rule is not a finding.


Law firms are not equipped to tell the difference, and they should not have to be.

But when nobody checks, the errors get filed.


What it costs


  • Plaintiffs eliminated after filing, when they could have been screened before.

  • Claims shrunk after the defendant has already seen the original number.

  • A motion to dismiss that succeeds because the complaint cannot plausibly allege the funds reached the defendant.

  • A defense expert who takes the tracing apart on cross-examination while the court watches.

  • Time spent on records requests to the wrong entity.

  • Reports reproduced from scratch on a deadline.

  • A LOT of counsel's time (and money) wasted chasing the wrong conclusion.


Bad forensics doesn't just weaken a case. Often it decides whether there is one at all.

And, possibly worse than the faulty forensics?


The victim paid for the bad forensics. On the faulty reports we have reviewed, we have seen fees starting at $6,500, non-refundable, for the report alone, plus a contingency of 10 percent and often higher on anything recovered.


That price buys a document. It does not buy:

  • law enforcement engagement

  • ongoing support

  • expert witness testimony


Each of those is billed to the victim on top. Someone who has already been defrauded once pays a second time for a report that cannot be used, and a third time to have it done properly.


This is simply wrong.


What good looks like


Every trace we deliver for a civil matter:


  • is independently reproduced from the victim's own transaction records

  • states a tracing methodology for any commingled address

  • verifies every terminus explicitly: custodial account, nested service, bridge, or contract

  • cross-checks every attribution across multiple platforms, beyond our own heuristics

  • arrives as a package an expert can sign and defend under cross-examination


If the funds did not reach the defendant, we say so before anything is filed.


The most valuable thing forensics can tell a law firm is that a case should not be brought.


Correct forensics do not only shrink cases


The same reproduction that eliminates a plaintiff often finds others. A scam wallet that took one client's money usually took many people's, and a proper trace surfaces what the original work never saw:


  • additional victims

  • additional recipients

  • related fraud infrastructure

  • recovery opportunities


Those are investigative leads, not automatic additions to a complaint.


A wallet is not a verified plaintiff, and a shared destination is not proof that every sender suffered the same fraud. Each new plaintiff needs their own authenticated records and counsel's own assessment.


But a firm that starts with correct forensics gets to make that call.


A firm that starts with wrong forensics spends its budget finding out what it does not have.


The alert is the record


There's a second cost to slow forensics that almost nobody prices in. By the time most tracing reaches a law firm, the funds have been sitting at an exchange for months, and nobody ever told the exchange they were stolen. The withdrawal went through quietly, and the exchange can truthfully say it had no idea.


When a matter reaches us within hours of the loss, that changes. We:


  • flag the wallets involved and place them on our risk and monitoring lists

  • alert the receiving exchange, the token issuer where there is one, and any protocol in the path

  • coordinate to stop the funds from moving further, where an intervention opportunity exists


To be clear, flagging is not the same as freezing. The power to restrict an account or a token belongs to the exchange or the issuer. The FBI's own guidance says the same thing: private recovery companies cannot issue seizure orders, and exchanges freeze accounts only through their internal processes or in response to legal process. Our job is to spot the opportunity quickly and put accurate evidence in front of whoever holds that power.


Interdiction doesn't always succeed. But a properly documented alert does something regardless of the outcome: it creates a contemporaneous record of what was reported, to whom, and when. For that record to be worth anything later, it has to contain:


  • the specific transactions and addresses

  • the amounts

  • the basis for concluding the funds are stolen

  • the time it was sent, and proof of delivery or acknowledgment

  • a running log of what the exchange said and what the funds did next


The defense will test every link in that chain, so the details matter.

  • Proof that an email was sent is not proof the compliance team received it.

  • Receipt of an allegation is not actual knowledge that the allegation is true.

  • Silence is not proof that nothing happened internally.


So we treat notification as an evidentiary process, not an email. Done right, it produces a timeline.


Take a hypothetical: the exchange's compliance team acknowledges a substantiated alert at 10:15 a.m., its own records show the funds still under its control at 2:00 p.m., and the withdrawal clears at 2:04. That timeline does not decide liability by itself. It gives counsel concrete questions:


  • What did the exchange know?

  • When did it know it?

  • Who reviewed it?

  • What could they have done?

  • What did they do?


Courts have been willing to work with that kind of record. At least one federal appeals court has held that a bank's failure to stop the theft of funds it knew were being mishandled can be the substantial assistance that supports an aiding-and-abetting fraud claim, and in 2025 the same court reversed the dismissal of a billion-dollar fraud suit against a global bank and eased the pleading standard for knowledge and substantial assistance.


Which claims are available depends on the governing law, and that is counsel's call. But the principle holds: an ignored alert does not automatically create liability. A substantiated warning, its receipt, and what the recipient did afterward can become the evidence that does.


Firms that wait months for forensics never get that record, because the chance to put the exchange on notice is gone once the funds are.


A heads up for law firms


If you have a crypto matter on your desk and the tracing came from somewhere else, there are a few questions worth asking before you rely on it:


  • Who did the work, and can you confirm they are an actual forensics firm with expert witness experience and not a “recovery” service?

  • Did they hand you the transaction data, or only a picture?

  • Did they state how they handled commingled funds, or just draw arrows through them?

  • Did they confirm what each endpoint really is: the exchange itself, a nested service, a bridge, or a contract?

  • Has anyone told the exchange the funds were stolen, and is there a record of it?


If the answer to any of those is no, get the tracing looked at again before it's filed.


We help firms get this right the first time, and we're glad to take a look at whatever you've already been handed.


 
 

Subscribe to our newsletter

Thanks for submitting!

bottom of page