Recently, front-line investigation and appraisal bodies — the Criminal Investigation Corps of the Zhejiang Provincial Public Security Department, the Wenzhou Municipal Public Security Bureau, Shanghai University of Political Science and Law, and the Wenzhou Judicial Appraisal Centre — jointly published "Virtual Currency Forensic Analysis Techniques and Field Application" (in Criminal Technology, DOI: 10.16467/j.1008-3650.2026.0025, online first 2026). Rarely, it explains the forensic and tracing chain of crypto criminal cases thoroughly, from a front-line casework and appraisal perspective.

Many assume that when authorities handle a crypto case, they just stare at a block explorer looking at a few transfers. Reality is far more complex — the real difficulty is a much harder question: how to turn an anonymous on-chain address into evidence that holds up in a criminal case file. And that is exactly what Delta & Capital's technical team does day in, day out.

Below, drawing on this research and Delta & Capital's field experience, we take apart the full chain from a single on-chain address to a criminal case file, step by step.

1. The first step is always: who controls this wallet?

An on-chain address is just a string of characters; it carries no name. So the first task in a case usually falls on proving the control relationship: who actually commands this address. Chasing the coins comes later.

Where does the evidence come from? From the suspect's phone, computer, hard drive, hardware wallet; from wallet apps, seed phrases, private keys, keystore files, Bitcoin's early wallet.dat file, and various login records. Holding the seed phrase or private key equals full control of the address — the paper says it bluntly: only by seizing the private key have you truly seized the virtual currency in the address; seizing merely a phone captures only the medium storing the key.

Here is a pitfall both ordinary people and investigators easily hit: seeing a balance in an address does not mean having transfer authority. One must distinguish watch-only wallets (view but cannot sign), cold wallets (offline authorization), and multisig wallets. Many seize only the online watch-only wallet but miss the cold or multisig medium that can actually sign transfers — so the assets remain unmovable.

2. Why seize the phone, computer, and hard drive

Seizing devices is far more than finding coins — it is to reconstruct an entire behavioral chain. What investigators really look for is:

Wallet entry points (apps, plugins, cold-wallet pairing)

Seed phrase / private key / keystore / wallet.dat

Exchange apps and login traces

Chat logs, transfer notes, screenshots

Various operational traces

Pieced together, these fragments answer a series of questions: who arranged the USDT swap, who provided the receiving address, who directed cross-chain transfers, who handled the final cash-out. In joint crimes, this chain defines each person's role and the boundary of responsibility.

From device to case file: the full forensic chain of a crypto case

The topology below structures the above process into a complete forensic chain — from case lead all the way to judicial disposal.

flowchart TD

A["Case lead: victim report / abnormal funds"] --> B["Seize electronic devices
Phone · Computer · Hard drive · Hardware wallet"]

B --> C["Extract wallet entry points
Seed phrase · Private key · keystore · wallet.dat · Login records"]

C --> D{"Confirm control relationship"}

D --> D1["Distinguish watch-only / cold / multisig wallets"]

D1 --> E["On-chain fund tracing"]

E --> F["Exchange assistance request / freeze"]

F --> G["Judicial disposal: physical seizure · key replacement · account freeze"]

C -.support.-> H["Chat logs · Screenshots · Transfer notes"]

H -.reconstruct roles.-> E

3. Forensic tools automatically surface crypto leads

Many underestimate the power of forensic tools. The study systematically surveys a set already used on the front line; they can auto-extract address, seed-phrase, and private-key leads from chat logs, image OCR, memos, documents, and wallet files:

FileLocator: full-disk regex search to fish out lines resembling 12–24-word seed phrases.

Python mnemonic library: validates fished-out word groups against the BIP39 standard, filtering out noise.

Pinghang PF5200: multi-channel phone forensics, brute-sweeping WeChat, QQ, notepad, and memos for suspected seed phrases and addresses.

Honglian Fireeye, Qi An Xin Pangushi: offline retrieval of mainstream exchange account info and wallet account info.

MeiyaPico Forensic Master: PC-side multi-chain address regex search and address tracing.

Pinghang X501, MeiyaPico Spark platform: visual analysis platforms that auto-extract crypto elements from chat logs, cloud drives, memos, and image OCR, and trace which app or exchange an address came from.

In other words, once a device is in hand, a seed phrase hidden in a chat screenshot, a casual memo, or a single phone-album photo may be auto-recovered. This is exactly why Delta & Capital keeps stressing: how you store seed phrases and private keys is itself the first line of security.

4. Exchange data cannot simply be "password-free forensically extracted"

This is a commonly misunderstood point, but one thing is clear: there is currently no mature tool that can perform password-free database forensics on exchange data. Exchanges are centralized custodians; the data sits on platform servers, not decryptable directly like local wallet files.

So to obtain an exchange's account, balance, orders, and cloud data usually relies on these paths: account login, the suspect's disclosed credentials, screenshots to fix evidence, and — most critically — an assistance request to the platform. As for freezing, mainstream exchanges that currently accept freeze documents served via government-department email include Binance, Huobi, and OKX; the freeze period is generally six months and renewable.

For those doing source-of-funds proof (SOF/SOW) and compliance communication, this matters especially: platforms and authorities repeatedly demand fund sources, transaction paths, and chat logs precisely because the on-chain segment can self-prove, while the account subject and fund source must be completed with off-chain materials.

5. On-chain tracing is far more than looking at a block explorer

Real on-chain tracing is a combination punch. Authorities dig layer by layer along these dimensions: fund flow, fee source, first-activation address, cross-chain bridges, aggregators, contract event logs, and the deposit paths into DEXs / mixers / exchanges.

A classic fee-tracing case: technicians started from a scam-site developer's payment address and found via block explorer that its first fee of 30 TRX came from another address, whose own first fee had interacted with Binance — a fee-inheritance chain that strung together the server lessee, exchange account, and wallet seed phrase, finally pinning down the technical-developer suspect. A seemingly trivial trace like a transaction fee is often the key that connects an anonymous address to a real identity.

When funds enter cross-chain bridges, aggregators, or mixers like Tornado, tracing difficulty spikes: mixing physically severs the inflow-outflow direction by blending different users' funds. Then one must analyze contract event logs line by line (e.g. reading from the Data field which address funds finally reached via BSC and OKC) or use device collision, time-and-amount collision, and similar methods to reconstruct the path.

A typical on-chain fund-tracing path

The topology below is a typical structure of funds leaving a case-involved address, being obfuscated layer by layer, and finally landing at an exchange.

flowchart LR

S["Case-involved address"] --> T1["Fee-source tracing"]

S --> T2["First-activation address"]

T1 --> X["Fund dispersal / multi-layer transfer"]

T2 --> X

X --> B1["Cross-chain bridge"]

X --> B2["Aggregator
e.g. TransitSwap"]

X --> B3["Mixer
e.g. Tornado"]

B1 --> Y["DEX swap"]

B2 --> Y

B3 --> Y

Y --> Z["Centralized exchange deposit"]

Z --> K["KYC landing
lock holder identity"]

A notable trend: crypto crime is accelerating the shift of funds to offshore exchanges and no-KYC platforms, making offshore and no-KYC platforms a real physical barrier in case assessment.

6. Seizure and freezing: procedural compliance is the red line

At the disposal stage, there are three main routes to seize case-involved crypto, each with pros and cons:

Physical seizure: seize the phone, hard drive, hardware wallet. The risk: without the private key, if hardware is damaged or an at-large accomplice holds the seed phrase, assets can still be moved.

Custody by the judicial authority itself: set up a dedicated multisig wallet, enforce "two people, two locks", move case assets to a dedicated address, achieving key replacement. In theory this is the best route.

Commissioning a compliant third party to assist with custody: transfer to a third-party dedicated wallet, sign an agreement, take periodic inventory — this offloads the investigators' own risk but incurs fees.

Several procedural red lines must also hold: separate casework from management, avoiding investigators controlling case assets themselves; keep source and destination clear; have technically capable personnel operate; accept external oversight from the procuratorate, finance, etc., safeguarding the party's right to know and to appeal; and avoid disposal delays — because coin prices swing sharply, delay drastically changes the value of case assets.

7. Key reminders for parties and lawyers

Combining the above casework logic, from the party's side, Delta & Capital thinks ordinary users especially should know:

On-chain records only prove fund movement, not subjective knowledge. An address receiving coins does not mean the person knew the upstream was criminal proceeds.

Having an exchange app installed on your phone does not mean you control the case-involved address. Control needs evidentiary support; do not assume.

Never rashly delete chat logs, uninstall wallets, or dispose of seed phrases. After a case breaks, such acts may be read as destroying evidence or transferring case property, pushing you into a far more passive position.

The core in one line: in a crypto case, more than the on-chain transfers, what really decides fate is often whether "control" and "knowledge" can be proven off-chain. An address is not control; receiving coins is not subjective knowledge — but all of this needs evidence, not words.

8. Delta & Capital's view: the judicial investigation chain is also a capability map for asset-recovery and unfreezing services

Break down these seven steps and one thing emerges: the underlying logic of how authorities handle crypto cases is highly isomorphic to how a professional on-chain forensics firm works — both answer the same core question: how to lawfully and reproducibly bind an anonymous address to a real person and fund path. The difference is stance and endpoint: authorities serve criminal prosecution; Delta & Capital stands on the side of victims and enterprises, using the same technical language to speak with law enforcement, exchanges, and judicial bodies, aiming to drive compliant recovery and unfreezing of stolen, defrauded, or frozen assets. For Delta & Capital, on-chain forensics and fund tracing are only part of the whole service.

Mapped step by step, the techniques used in judicial investigation are almost all essential capabilities in Delta & Capital's asset-recovery and unfreezing services:

Who controls the wallet → Delta & Capital's address attribution, activation-parent trace-back, and address-cluster analysis specifically solve the address-to-person binding problem.

On-chain tracing is far more than a block explorer → Delta & Capital's fee tracing, cross-chain bridge event reconciliation (hard reconciliation on amount + time window + contract counterparty), and mixer de-mixing heuristics are exactly the combination punch against fund dispersal, cross-chain, and mixing.

Exchanges resist password-free forensics and require assistance requests → Delta & Capital's VASP assistance network and SOF/SOW source-of-funds evidence chain complete the off-chain segment.

Procedural compliance is the red line → Delta & Capital adheres to the FATF risk-based methodology, separates fact/inference/assumption, anchors each conclusion to on-chain evidence, and produces independently reproducible, court-admissible reports.

These capabilities are not armchair talk. Across the various anonymized cases Delta & Capital has handled — from layer-by-layer peeling of single-chain addresses, fund hops between cross-chain bridges and DEXs, to mixer de-mixing, and on to cross-border assistance, compliant account handling, asset recovery, and unfreezing — almost every category of difficulty mentioned here has a matching real-world scenario.

A fair assessment

Comparing this study's casework logic against Delta & Capital's field experience yields a few judgments:

On casework trends: crypto-crime investigation is rapidly becoming tooled and systematized. Anonymous addresses long ceased to mean safety; on-chain traces plus off-chain corroboration is an irreversible direction — details once ignored, like fees, activation sources, and cross-chain events, are now the keys to a real identity.

For ordinary users: the real line of defense has moved forward to daily life — how you store seed phrases and private keys, not deleting data after an incident, understanding that on-chain records are not subjective knowledge — matters more than remediation after the fact.

On Delta & Capital's positioning: Delta & Capital does asset recovery and account unfreezing; on-chain forensics is only one step. It does not replace law enforcement or platforms, but stands with victims and enterprises: first using enforcement-grade technical methods to clarify the fund path and solidify evidence, then translating complex on-chain results into materials platforms, courts, and exchanges can understand, and on that basis driving lawful asset recovery and unfreezing of blocked accounts. Rather than promising an outcome, Delta & Capital values walking this path from forensics and tracing to recovery and unfreezing professionally, compliantly, and reproducibly.

9. If you are unfortunately drawn into a crypto case

Do not destroy or alter any data: keep chat logs, wallets, seed phrases, and transaction records exactly as they are;

Fully fix on-chain information: the wallet addresses, transaction hashes, approval records, and cross-chain/swap paths involved;

Map fund source and destination: prepare materials that explain the lawful source of funds (SOF/SOW approach);

Seek professional legal advice immediately: let a lawyer judge your role and the boundary of responsibility, avoiding self-operation that amplifies risk;

Cooperate with lawful assistance requests: provide materials to platforms or authorities through lawful channels, and never trust "pay to unfreeze" or "fixed via insiders" secondary-scam pitches.

10. Summary

Investigating a crypto criminal case is essentially an evidence-engineering effort to "restore an anonymous address into real-person conduct": first prove who controls the wallet, then use device forensics to complete the control relationship, then connect the fund path along fees, cross-chain, mixing, and exchange deposits, and finally complete seizure, freezing, and disposal under procedural compliance.

For ordinary users, it is a required course on seed-phrase custody and anti-fraud; for parties involved, it warns that on-chain records are not subjective knowledge, and you must not tamper with data after an incident; for compliance and security professionals, it explains why fund source, transaction path, and on-chain evidence are all indispensable. In the digital-asset world, the chain shows where the money went, but lawfully binding address, funds, and person is always serious work supported by both technology and procedure.

Key concepts at a glance

Seed phrase (Mnemonic): per BIP39, turns a random seed into a sequence of 12–24 English words; holding it recovers the private key and controls the wallet.

Private key / keystore / wallet.dat: the core credential authorizing transactions and its storage forms — the primary forensic target.

Watch-only / cold / multisig wallet: respectively view-only, offline signing, and multi-party authorization — the key distinction for judging control.

Fee tracing: via the inheritance relationship of gas/fee sources, reverse-associate the real person or exchange behind an address.

Cross-chain bridge / aggregator / mixer: tools that lengthen or sever the source-destination correspondence of funds, significantly raising tracing difficulty.

KYT / SOF / SOW: on-chain transaction monitoring, source-of-funds proof, source-of-wealth proof — the core materials for compliance communication and assistance requests.

FAQ

Q: What does the judiciary check first in a crypto case?

The first step is usually to prove "who controls this wallet". On-chain addresses carry no name, so authorities reconstruct the control relationship from seed phrases, private keys, keystores, and login records on devices.

Q: My address once received coins of unknown origin — could I be in trouble?

Receiving coins on-chain does not itself equal subjective knowledge that the upstream was criminal proceeds. What matters is whether off-chain evidence proves you knew or participated, so keeping complete records and seeking legal advice promptly is important.

Q: Can authorities freely obtain exchange data?

There is currently no mature tool for password-free forensics on exchange data. Obtaining accounts, balances, orders, etc. usually requires account login, disclosure, screenshot fixing, or an assistance request to the platform.

Q: After an incident, should I hurry to delete chat logs and uninstall wallets?

No. Such acts may be deemed destroying evidence or transferring case property, worsening your position. The right approach is to keep data intact and consult a professional lawyer promptly.

Content support: this article is provided with on-chain security and compliance educational support by the Delta & Capital technical team at "https://deltacapitalhk.com/". Delta & Capital focuses on blockchain data analytics and compliance-technology research, with core capabilities spanning: on-chain transaction tracing and fund-flow analysis, on-chain forensics and recovery, KYT/AML real-time risk control and address-risk identification, KYT/SOW (source-of-funds proof) tracing and reconstruction, cross-chain and multi-asset fund-path restoration, and appeal/lifting support for CEX/DEX account restrictions, risk controls, and freezes; it also provides on-chain evidence organization and technical support for police reports and judicial assistance.

Risk & compliance notice: this article is anti-fraud and investor-education content, not investment advice, and constitutes no guarantee of recovery or unfreezing. Digital-asset prices are volatile and high-risk — view rationally and guard against related risks; if assets are stolen, defrauded, or you are drawn into a related case, first pursue rights through lawful channels and consult a professional lawyer, guarding against secondary scams under the guise of recovery or unfreezing.