Métodos de investigação
Tracing stolen funds is different from recovering them
The strongest opportunity often appears when an on-chain flow reaches a centralised exchange, casino, payment processor or another custodial service.
Original publication · 12 Jul 2026. Figures, claims and opinions reflect the original publication date.
As publicações originais estão em inglês. A navegação está disponível em sete idiomas.
🚨 Two warnings:
Earlier, I gave someone a possible lead on how stolen funds might still be traced through legal channels.
But, tracing funds and actually recovering them are 2 very, very, very different things.
The strongest opportunity often appears when an on-chain flow reaches a centralised exchange, casino, payment processor or another custodial service.
On-chain, we usually see addresses, timestamps and transaction paths.
The platform may hold the missing off-chain layer: KYC records, account details, deposit-address mappings, withdrawal history, IP logs, device information and internal ledger entries.
A properly issued preservation request, subpoena or law-enforcement request may therefore connect an apparently anonymous wallet to a real customer account.
This is also why on-chain activity should never be treated as automatically anonymous.
Sending funds between a self-custody wallet and a KYC exchange can create a direct attribution point.
The blockchain records the public flow, while the custodial platform may know exactly which verified account deposited or withdrew the funds.
Even when money is routed through multiple intermediate wallets, timing, amounts, repeated counterparties and deposit patterns can still create useful evidence.
None of this guarantees recovery, but it may produce a legally actionable lead.
🚨 There are 2 important security warnings here:
First, simply receiving an unknown token or NFT does not normally give an attacker control over your wallet.
The real danger begins when the asset, message or fake opportunity pushes you towards a malicious website, compromised dApp or deceptive transaction request.
On Solana, a single transaction can contain multiple instructions and invoke several programs at once.
What appears in the interface as a harmless claim, swap or verification may actually include instructions to transfer SOL, move SPL tokens, assign delegate authority, change an account authority or close token accounts and redirect the recovered rent.
Once you approve the transaction, the network executes the signed instructions, not the explanation shown by the website.
Connecting a wallet alone is usually not the decisive step.
🚨 Signing is.
A seed phrase is not required if the victim authorises the transfer through a malicious or misleading transaction. That is why blind signing and unreadable transaction prompts are so dangerous.
Keep long-term assets in a separate vault wallet that never connects to unfamiliar applications.
Use a low-value burner wallet for new dApps, inspect transaction simulations, check the programs being invoked and reject anything you do not fully understand.
Review delegates and account authorities where possible, and never assume a polished interface means a safe transaction.
One final warning:
anyone who contacts a victim claiming they can recover the funds should be treated as hostile by default.
Recovery scammers actively target recent victims, use convincing profiles and fabricated credentials, then demand upfront fees or another wallet signature.
Block them, even when they appear professional.




