Reconstruct what happened. Verify the loss. Preserve the evidence.
A Forensic Investigation is an independent reconstruction of a specific on-chain incident, delivered as a written report that states what the evidence shows, what it does not show, and how confident we are in each. From $2 500 per incident, quoted against your case. You are charged only once you accept the quote.
What we do with what you submit
- 1.
You submit the case. The exploit contract address, the transaction hashes, the chain, and, if you are testing a claim against a policy, that policy's own text.
- 2.
We parse the transactions independently. Re-derived from chain data rather than from any third-party account of the incident.
- 3.
We calculate the loss and price it. Anything that cannot be priced is disclosed as unpriced, never quietly dropped from the total. Where the loss is of a kind we do not yet reconstruct - bad debt left behind in a lending market, or deposits already invested elsewhere - the figure is stated as a floor rather than a total, and the report says which it is.
- 4.
We check it against our own incident ledger. Matched against real, classified DeFi exploits on record, establishing whether this is a new incident or a follow-on to a known one.
- 5.
The draft is independently verified against raw data. Five checks, every time, described below. The reviewer sees the underlying evidence, never just the system's conclusion.
- 6.
You receive the report. With its confidence level stated, and what would raise or lower it.
Every report is independently verified before it reaches you
Five checks run on every case regardless of how confident the draft was: that the transactions exist and match the claim; that the loss figure is reproducible from raw data rather than trusted from our own arithmetic; that the pattern match describes what actually happened; that the contract belongs to the protocol named; and, where a policy is in scope, that the policy's own words address this scenario. Any mismatch is an automatic escalation to a further review pass, not a low-confidence approval.
The loss itself is measured twice, two independent ways: the net change in the affected address's balances, and the sum of the transactions attributed to the incident. Every report states how far apart those two figures landed. That gap is what can be checked on a case where no published total exists to compare against, which is most real cases.
Read the Forensics ManualWhat the report contains
Executive summary
the incident and outcome in brief, before the detail.
Incident timeline
each submitted transaction placed in chronological order.
Attack-path reconstruction
how the exploit actually worked, step by step.
Affected-contract analysis
which contracts were involved and how each was identified.
Transaction-level evidence
the on-chain data the findings are drawn from.
Loss calculation
the verified loss amount and how it was derived.
Affected addresses and net position
every address whose holdings changed, and by how much, with the event's block timestamp.
Root-cause analysis
the underlying flaw that made the exploit possible.
Remediation review
what was done, or should be done, in response.
Limitations
what the evidence does not show.
Evidence appendix
sources and supporting data cited throughout.
Evidence-to-clause determination
each policy clause set against the evidence that bears on it.
The sample report below follows exactly this structure, against a real, fully public incident.
Sample report (PDF)
See what a Forensic Investigation delivers before you request one.
What it is not
The report is evidence for your decision, not the decision. Not a ruling on a claim, not an instruction on what to do, not legal advice on how a policy would be read in a dispute. We state what the evidence shows and connect it to your policy's own clauses.
Timing and price
Turnaround depends on complexity and is estimated with your quote rather than promised in advance. Price is anchored on the scale of the loss under determination, then moves with the number of contracts and chains, transaction volume, whether bridges are involved, exploit complexity, loss-verification requirements, and reporting scope. Where the fee would be disproportionate to what is at stake, we say so rather than quote.
What we need from you
The correct contract address, the correct transaction hashes, and, if a policy is in scope, its current text rather than a summary. Our verification checks our own work against the chain; it cannot catch a case built on the wrong transaction.
The incident also has to sit on a chain we can reach. The request form lists the chains we can investigate today. If yours is not among them, ask anyway: the request is declined with a reason rather than quietly accepted, and what people ask for is how the list grows.
