Skip to content
ONLINE
--:--:-- UTC
Writing
5 min read5 sources

On-chain evidence: what survives from trace to courtroom

A blockchain records every movement and names nobody. The Prince Group forfeiture and the Bybit theft show where on-chain tracing ends, where forensic evidence begins, and which habits decide whether an attribution holds up.

Shuja Abrar · Blockchain Consultant & Engineer

  • digital forensics
  • electronic evidence
  • on-chain analytics
  • aml
  • law enforcement
On this page
  1. 01A trace is not yet evidence
  2. 02Keys, devices and the seizure itself
  3. 03When the money moves in hours
  4. 04What holds up and what does not
  5. 05Practical takeaways
  6. Sources (5)

On 14 October 2025 the US Department of Justice filed a civil forfeiture complaint against roughly 127,271 bitcoin tied to Prince Group and its chairman, Chen Zhi, worth about $15 billion at the time. The department called it the largest forfeiture action in its history. The number is what gets repeated. What deserves more attention is how the government expects to prove that those coins are what it says they are.

A public blockchain gives an investigator a complete, timestamped, tamper-evident ledger of movements and almost no information about people. Everything that happens between those two facts is forensic work, and most of it is more fragile than the ledger underneath it.

01A trace is not yet evidence

Tracing is the easy half. Every transfer on Bitcoin or Ethereum is public, ordered by block and permanent. Analytics platforms group addresses into clusters using heuristics such as common-input ownership on Bitcoin, reuse of exchange deposit addresses, and the behavioural fingerprints of particular wallet software. From those clusters they draw a graph from a theft or a scam to wherever the funds come to rest.

That graph is an investigative lead. It becomes evidence only when someone can explain, to a judge who has never opened a block explorer, why each hop is attributed the way it is and what would have to be true for the attribution to be wrong.

The distinction matters because clustering is probabilistic. Common-input ownership breaks against CoinJoin and payjoin transactions. Exchange attribution depends on labels a vendor assembled from test deposits, subpoena returns and open-source intelligence, and those labels are proprietary. Defence teams in US prosecutions have already challenged the reliability of commercial tracing tools, and the honest answer from an expert witness is usually the same: the heuristic is reliable in general, and has to be corroborated in the specific case.

The habit worth building is simple. Every link in the chain should be supported by something other than the tool's own label, whether that is an exchange's KYC return, a recovered device, a document, or a transaction pattern that cannot plausibly be coincidence.

02Keys, devices and the seizure itself

The Prince case shows what a strong digital asset case looks like. According to the Justice Department, the bitcoin sat in unhosted wallets whose private keys the defendant personally held, and he kept diagrams recording how some of the funds were laundered through what prosecutors describe as spraying and funnelling across many addresses. TRM Labs' account of the investigation describes the funds consolidating into a single cluster and investigators correlating wallet movements over several years with enforcement activity.

The on-chain analysis narrowed the field. Off-chain material, meaning keys, seed phrases, documents and devices, pinned it to a person. Neither would have been enough alone.

Chain of custody for crypto assets also works differently from physical evidence. The asset is not the device. Seizing a hardware wallet seizes nothing if someone else holds the seed phrase, so the seizure is itself a transaction: funds moved to an address the government controls. That transfer needs to be documented like any other evidential act, with the transaction hash, block height, source and destination addresses, who held which keys, who witnessed it, and hashes of any device images taken beforehand.

Investigators should also record the state of the chain before they act. A screenshot of a block explorer is a poor exhibit. Raw transaction data exported from a node the investigator controls, with block heights and UTC timestamps, can be independently reproduced by the other side, which is exactly what makes it persuasive.

03When the money moves in hours

Not every case gives investigators years. On 21 February 2025 roughly $1.5 billion was taken from Bybit's Ethereum cold wallet. Five days later the FBI publicly attributed the theft to North Korean actors it tracks as TraderTraitor, published the addresses being used for laundering, and asked RPC node operators, exchanges, bridges, analytics firms and DeFi services to block transactions with them.

Chainalysis described the laundering as it unfolded: funds dispersed through layers of intermediary addresses, large amounts of ETH swapped into bitcoin and DAI, assets moved across chains through decentralised exchanges, bridges and instant swap services, and a substantial share left dormant to wait out the initial scrutiny. By mid-2025 Chainalysis counted more than $2.17 billion stolen from services for the year, already above the whole of 2024.

In an incident like this, forensics runs in real time. The priority is to identify outflow addresses quickly, share them with the chokepoints that can act, such as stablecoin issuers, centralised exchanges and bridge operators, and freeze what can be frozen. Evidence preservation has to run in parallel. Every flag raised, every freeze request and the basis for it should be logged with a time and a reason, because freezing a third party's funds on the strength of your attribution will be questioned later, sometimes by an innocent counterparty.

04What holds up and what does not

Some things consistently hold up. A reproducible method, where anyone with a node can verify every transaction relied on. Attribution corroborated off-chain. Timestamps in UTC tied to block heights. A plain statement of which heuristics were used and where they are known to fail. Exported datasets hashed at the time they were produced.

Other things consistently do not. Screenshots of a vendor dashboard as the primary exhibit. A cluster label with no stated provenance. Conclusions phrased with more certainty than the method supports.

Cross-chain movement is the weakest point in most reports. Bridges and swap services break the simple graph, and matching a deposit on one chain to a withdrawal on another by amount and timing is inference, not observation. Some bridges emit linked events that make the match deterministic. Many services do not. A good report says which kind of link it is relying on, and a good cross-examination asks.

05Practical takeaways

For exchanges and other service providers, keep records as if they will become evidence, because some of them will. Deposit attribution, KYC linkages and internal blocks should be logged immutably and exportable in a form that can be hashed and handed over without a screenshot in sight.

For investigators and analysts, keep leads and evidence in separate parts of the report. Say what the tool concluded, what corroborates it, and what would falsify it.

For compliance teams, recognise that the Travel Rule and screening data you collect today is tomorrow's exhibit, and protect its integrity accordingly.

For lawyers on either side, the most useful question to put to any blockchain expert is still the simplest one: what would make this attribution wrong?

All writing