Agentic investigations for the on-chain economy
The future of finance is tokenized. The future of investigations is agentic. We operate at the intersection.
The future of finance is tokenized. The future of investigations is agentic. We operate at the intersection.
Recoveris is headquartered in Zug, Switzerland, at the heart of Crypto Valley. Switzerland’s neutral jurisdiction provides a secure, stable environment, essential for the sensitive nature of our work. Like our clients, we value operating in an atmosphere of trust and stability. Precision and reliability are in our DNA, and we approach every case with sharp focus and meticulous care — qualities synonymous with Switzerland itself.
A regulated Swiss private bank needed defensible AML documentation for a high-net-worth client with complex on-chain wealth origins. EY and Recoveris jointly delivered a structured compliance file built to pass regulatory scrutiny on first submission.
Read full case
The challenge: A regulated private bank receives an onboarding application from a HNW client whose wealth originates from early crypto positions and active DeFi participation. Traditional AML and source-of-funds frameworks cannot answer the two questions every regulator expects on digital asset onboarding: where did the funds originate, and who actually controls them today. Building this capability in-house takes years and no single onboarding justifies it. The bank engages the EY DLA Offering, jointly delivered by EY Switzerland Managed Services Financial Services and Recoveris.
Our approach: EY DLA combines three disciplines into one defensible compliance file. DLI (Distributed Ledger Intelligence) reconstructs the client’s on-chain wealth history and traces transactions back to documented origins. CODA (Control Over Digital Assets) verifies, through structured signing exercises and on-chain attestations, that the declared wallets are under the client’s exclusive control. AML risk scoring maps every historical counterparty interaction to PASS / FLAG / BLOCK outcomes against the bank’s risk policy. EY leads client and risk-committee interface and governance documentation; Recoveris executes the forensic work.
Outcome: The bank receives a single structured DLA file – DLI source-of-funds report with management summary, CODA verification record, and AML risk-scoring overview – cross-referenced and aligned to its internal policy framework. Cleared wealth is supported with full documentation; flagged segments are ring-fenced; unattributable holdings can be excluded from scope. The file is built to pass internal risk committee on first submission and support regulator notification where required, in a Big 4 governance frame no single bank can stand up in-house.
EY announcement: Distributed Ledger Analysis for the regulated financial industry – EY Switzerland
In December 2024, attackers stole USD 2.2M from 1inch’s smart contract and laundered it through Tornado Cash, where conventional analytics stalled. Recoveris identified the perpetrator’s exit strategy using behavioral profiling, re-opening recovery pathways where the trail had appeared to end.
Read full case
The challenge: Tornado Cash demixing is a niche specialism that takes years of methodology development and continuous case volume to maintain – capability no single protocol can justify building in-house. Rather than attempting an internal investigation, 1inch engaged Recoveris to lead the investigation. In December 2024, attackers compromised 1inch’s Limited Resolver smart contract and funneled approximately 545 ETH (c. USD 2.2M) through Tornado Cash – a critical point where most investigations stall. Tornado Cash breaks on-chain links between deposits and withdrawals, creating an anonymity set where stolen funds blend with thousands of legitimate privacy-seeking transactions. Conventional blockchain analytics reached their limit, unable to identify valid candidates among the 6,231 mixer withdrawals examined. The objective was to determine whether the stolen funds could still be linked to identifiable endpoints targetable through legal process.
Our approach: Rather than relying on address clustering alone, we deployed advanced behavioural profiling methodologies that operate beyond conventional tools. By systematically analysing operational patterns – withdrawal structures, timing, amounts, and post-withdrawal behaviour – across the entire six-month dataset of mixer withdrawals, we identified a singular behavioural fingerprint occurring across withdrawals matching the stolen amount. This pattern revealed consistent post-withdrawal activity across multiple blockchains, ultimately consolidating at addresses with distinct operational characteristics. No other withdrawal pattern in the dataset matched this behavioural profile for a comparable ETH amount.
Outcome: The funds moved through cross-chain infrastructure before converging at endpoints that included identifiable cryptocurrency service providers – providing high-confidence attribution of the perpetrator’s exit strategy from Tornado Cash. The result was actionable intelligence linking mixer-obscured funds to real-world service environments, delivered in a structured forensic report with a clear evidential narrative. What would have required years of internal methodology development and case volume that no single protocol generates was delivered ready for immediate use by legal counsel and enforcement, re-opening recovery pathways where the trail initially appeared to have ended.
Public coverage: 1inch promptly responds to an unauthorized access incident
Upbit’s Solana hot wallet was compromised, with over USD 35M in tokens immediately dispersed across multiple chains. Recoveris led a real-time investigation, disrupting laundering channels and securing asset freezes through coordinated multi-party intervention.
Read full case
The challenge: Upbit exchange’s Solana hot wallet was compromised, with multiple tokens stolen totalling over USD 35 million. Part of the assets moved immediately through a nested service on a large centralised exchange, was exchanged for ETH, and dispersed across a cluster of fresh Ethereum wallets being pre-funded with gas – a classic staging step for rapid laundering. The remaining tokens sat on Solana, positioned for either bridging or blacklist-resistant movement. With token issuers’ freeze windows narrowing and the perpetrators preparing to bridge across chains and enter privacy protocols, time-sensitive coordination across exchanges, issuers, bridge providers, and privacy services was required in parallel. In a multi-chain, multi-jurisdiction laundering scenario unfolding in real time, assembling the relationships, tooling, and coordination capacity in-house is neither realistic nor cost-justified for any single exchange. The exchange engaged Recoveris to lead the investigation and recovery response.
Our approach: We reverse-engineered the nested exchange’s withdrawal pattern, identifying fresh Ethereum addresses with no prior history receiving ETH in amounts consistent with the anticipated staging. This allowed us to correlate deposits and withdrawals and pre-identify destination wallets before the perpetrators routed stolen funds through them. When the attackers began bridging assets to Ethereum as stablecoins, they landed in addresses already under active monitoring. We coordinated simultaneously with token issuers on freezes, with the bridge provider on flagging, and with a privacy protocol whose proof-of-innocence mechanism (which holds deposits pending reports of theft) began rejecting the perpetrators’ deposits once we alerted its operators. Under pressure, the attackers escalated to a high-profile mixer, where Recoveris demixed transactions with high likelihood, even as withdrawn assets were immediately re-deposited into the privacy protocol.
Outcome: The investigation forced the perpetrators through a cascading sequence of obfuscation services – nested exchanges, cross-chain bridges, and privacy protocols – with each step documented and several pathways closed mid-laundering. Direct and coordinated freezes secured a portion of the stolen assets, and several laundering channels were disrupted in real time. Following the engagement, Recoveris was retained on a permanent mandate, giving the exchange instant-response incident capacity to secure operations and users against future events. The case illustrates how rapid predictive wallet identification and multi-party coordination can actively disrupt laundering even where direct seizure is not achievable at every hop – outcomes that depend on standing relationships and our investigative workflow, ready-deployed in advance of the incident.
A victim was targeted twice by attackers posing as wealthy investors, losing approximately USD 2.7M across two incidents. Recoveris traced the funds cross-chain and coordinated freezes, recovering over USD 1.7M across multiple chains and layering hops.
Read full caseThe challenge: An anonymized victim was targeted twice by perpetrators posing as wealthy investors. Under the pretext of assessing the victim’s ability to handle crypto payments for interest and dividend distributions, the attackers gained access to the victim’s wallet. The first theft moved approximately USD 1.2M in stablecoins on Ethereum. The second, targeting the same victim, took approximately USD 1.5M through a more complex layering scheme designed to evade tracing. Both incidents required immediate, jurisdiction-ready evidence to reach the relevant stablecoin issuers and law enforcement before the funds converted to cash-out endpoints.
Our approach: In the first incident, we traced the stablecoins across a bridge into another major blockchain, where they were redistributed across multiple wallets. A forensic report was issued promptly, enabling law enforcement to engage the token issuer for freeze action. In the second incident, we produced real-time mapping as the perpetrators progressively bridged assets across chains, identifying which wallets still held the stablecoins unspent. When the remaining funds were partially sent to centralised services and bridged onward to the Bitcoin blockchain, we tracked those flows to two centralised services and engaged directly with their compliance teams.
Outcome: Approximately USD 1M was frozen from the first theft. In the second, approximately USD 700k was frozen through law enforcement coordination with the token issuer, and courtesy freezes were secured at both centralised services for the onward Bitcoin flow – preserving additional balances for formal seizure. Total frozen and preserved assets exceeded USD 1.7M across multiple chains and layering hops. Cross-chain forensic tracing, direct relationships with token issuers, and coordinated law-enforcement engagement across jurisdictions are not capabilities a victim – or most institutions supporting victims – can assemble in the hours that matter. This is the kind of case our investigative workflow is built to absorb on day one.
A sophisticated phishing operation deceived corporate personnel into transferring approximately USD 40M, immediately dispersed through a complex multi-chain layering scheme. Recoveris secured USD 1.6M in freezes and kept further recovery pathways open.
Read full caseThe challenge: A sophisticated phishing operation deceived key personnel within a corporate organisation, resulting in fraudulent wire transfers totalling approximately USD 40 million. The funds were forwarded to a regulated centralised exchange, withdrawn as stablecoins, and then entered an elaborate layering scheme: a significant portion was routed through wallets consistent with OTC service operators, a further portion passed through non-custodial instant exchanges, and a remainder was held unspent as stablecoins. The priority was to freeze unspent assets quickly and follow the laundered portion into cash-out channels before funds became unrecoverable. With freeze windows measured in hours and laundering already underway across multiple chains and instant-exchange services, the corporate had no realistic path to stand up internal blockchain forensics capability in time. Recoveris was engaged to run the cross-chain investigation and coordinate law-enforcement liaison.
Our approach: We triaged the layering scheme by focusing first on the unspent stablecoin balances and producing a detailed forensic memo that enabled law enforcement to pursue immediate freeze action. In parallel, we analysed deposits into the non-custodial instant exchanges and correlated them with outgoing withdrawals across Bitcoin, Ethereum, and XRP ledgers. This cross-chain reconstruction allowed us to pinpoint downstream wallets holding meaningful residual balances. When one such flow resulted in 1 BTC being deposited into a non-custodial exchange across three transactions, we intervened in real time to secure a courtesy freeze pending formal law enforcement action.
Outcome: Approximately USD 1.6M in stablecoins was frozen through the initial law enforcement coordination, and a courtesy freeze of 1 BTC was secured for subsequent seizure. These outcomes were possible only because our investigative workflow and standing exchange relationships were ready to deploy on day one – an internal team built from scratch would not have closed the freeze windows in time. Significant Bitcoin, Ethereum, and XRP balances remain unspent in identified wallets, keeping further recovery pathways open as enforcement proceeds. Work to attribute the OTC service operators involved in the laundering is ongoing, with the potential to unlock additional recovery routes.
Recoveris detected ZondaCrypto’s looming insolvency before its public collapse, using on-chain analytics across six blockchains combined with off-chain monitoring and field intelligence. The published investigation triggered a criminal probe with 700+ victims and PLN 350M+ in damages.
Read full case
The challenge: By early 2026, Zondacrypto – one of the oldest and most popular among Poles crypto exchanges – was showing two parallel signals. Sporadic complaints about delayed or blocked withdrawals had appeared on its Polish-language Telegram channel since December 2025, increasing steadily from January onwards while remaining absent from the exchange’s global and Italian-language channels. Members of our team placed test withdrawal orders: smaller orders went through; a larger BTC withdrawal initiated on April 1 sat in “pending” status for over fourteen hours and was eventually cancelled. Detecting balance-sheet failure at a regulated counterparty – before withdrawals freeze, regulators intervene, and media coverage breaks – requires combining multi-provider on-chain analytics, proprietary attribution data, sustained off-chain monitoring, and field intelligence from inside the local industry. Few institutions exposed to exchange counterparties can justify assembling this stack internally for every venue they touch. Recoveris ran the investigation independently, with the findings published through money.pl on April 6, 2026.
Our approach: We ran three parallel streams of inquiry, each cross-checking the others.
The on-chain stream traced flows across six blockchains (Bitcoin, Ethereum, Polygon, Arbitrum, Avalanche, Optimism), reviewing Zondacrypto’s wallet clusters as labelled by the major analytics providers and looking for outflows to cold storage or external venues. Approximately one million addresses were reviewed in total. We combine seven blockchain analytics providers with our own attribution database, giving coverage comparable to top-tier law enforcement agencies outside the United States.
The off-chain digital stream involved continuous scraping of Zondacrypto’s official Telegram channel from December 2025 onwards, monitoring of user reports on X, and tracking the exchange’s own communications over time.
The field-intelligence stream came from industry events and direct conversations within the Polish crypto community: withdrawn sponsorships, unpaid invoices to event organisers, and weak presence at conferences where the exchange would normally be visible.
Outcome: Two findings carried the investigation. First, the monthly average BTC balance on Zondacrypto’s main labelled BTC cluster fell from a peak of 55.7 BTC in August 2024 to 0.18 BTC in March 2026 – a 99.7% decline. The daily balance stayed below 1 BTC every day of March 2026, and below 0.5 BTC on 27 of the 31 days. The balance on April 1 was 0.086 BTC, roughly $9,700. For context, peer European exchanges of comparable size held an average of 308 BTC across their main BTC hot wallets (range 50-600 BTC); even Kuna, an exchange operating from a country in active armed conflict, held roughly 10 BTC.
Second, between mid-December 2025 and April 2, 2026, we identified 511 transfers from Zondacrypto wallets to a single Kraken-controlled deposit address, totalling approximately $21M (roughly 76M PLN). The transfers spanned thirty different assets and crossed all six analysed chains, indicating systematic movement rather than a single technical operation.
The investigation was published by money.pl on April 6, 2026. Within twenty-two days, Zondacrypto’s website was offline, its CEO had reportedly left the country, the Polish government had held a press conference at the Prime Minister’s Office, and the Prosecutor’s Office had opened a criminal investigation under Article 286 §1 (fraud) and Article 299 (money laundering) – assigned to the Central Bureau for Combating Cybercrime. As of April 28, the prosecutor’s spokesman has confirmed over 700 registered victims and damages “certainly larger than 350M PLN ($96.4M).” According to the information published by the exchange, the victim was supposed to have around 1.3M customers (mostly from Poland).
The case demonstrates the value of combining multi-provider on-chain intelligence with off-chain and field signals to assess exchange health – capability institutions exposed to crypto counterparties cannot build alone but can access through Recoveris.
Detailed coverage: The Zondacrypto Investigation – Recoveris
A Swiss company lost millions to a sophisticated investment fraud operation. By rapidly tracing the complex multi-chain asset flows, Recoveris secured a USD 10.5M freeze at Tether and Bitfinex, leading to one of the largest successful crypto recoveries in Swiss history.
Read full caseThe challenge: In December 2024, a company in Canton Schwyz filed a criminal complaint with the Schwyz Public Prosecutor’s Office. The perpetrators had posed as a legitimate investment counterparty, induced the company to transfer crypto to a wallet under their control, and disappeared within days. Investment fraud at this scale produces a narrow recovery window. Once stolen funds reach mixers, cross-chain bridges, or non-cooperating jurisdictions, the cost and time required to recover them rise sharply. The case began with a single wallet address, and what happened in the next few days would determine whether recovery was possible at all.
Our approach: Umberto Buonora, our Head of Investigations, and his team picked up the trace within days of intake. Stolen funds rarely sit at the address they were sent to. The perpetrators had moved them across multiple addresses and multiple chains to break the on-chain link to the original receiving wallet. The team followed those movements through to the receiving infrastructure where the funds eventually rested: wallets under the custody of Tether, the issuer of USDT, and Bitfinex, a major exchange. A wallet address with no path to a regulated counterparty cannot be frozen. With those endpoints identified, the team opened direct institutional channels with both parties, presented the on-chain evidence, and pursued issuer-level and exchange-level action in parallel.
Outcome: Tether froze the relevant USDT holdings at the address level. Bitfinex held USD 10.5M of value on its books pending the criminal proceeding. With the funds locked, the case was handed to the Schwyz Cybercrime unit and, on the basis of findings about the perpetrators, escalated to the Ticino Public Prosecutor’s Office. Tether then executed the standard burn-and-remint: the stablecoins at the frozen address were destroyed and an equivalent supply reissued to an address designated by the authority, returning the value to the victim. The recovery is one of the largest crypto seizures in Swiss history. Recoveries of this size hinge on the investigators knowing which VASPs to call, in what order, with what evidence, and within what window. Without the trace, there is no freeze. Without the freeze, there is no recovery.
In general, yes, stolen crypto can often be recovered. However, everything depends on what happened. While blockchain transactions are irreversible, blockchain intelligence companies like Recoveris can trace where assets go, identify control points, and arrange freezing them before they’re laundered beyond reach. Success chances depend on timing, jurisdictional and legal factors, law enforcement cooperation, and the criminals’ techniques used, meaning that each case is different and subject to analysis.
Every cryptocurrency transaction is recorded on one of several immutable and publicly available blockchain ledgers. The team at Recoveris uses advanced blockchain analysis techniques to follow funds across multiple chains, wallets, and services. Even when criminals use obfuscation techniques, like mixers or privacy tools, our forensic specialists aim to trace the flow through behavioral patterns to ultimately identify where funds land at exchanges or other platforms.
Investigation means tracing where your stolen funds went. Freezing means stopping the assets from moving further, a step that for most crypto-assets is only possible on addresses or wallets hosted by centralized services (e.g. crypto exchanges). Such platforms freeze the funds upon law enforcement requests, legal orders, or sometimes voluntarily. Recovery means actually getting your funds back through settlement, law enforcement action, or restitution. Recoveris assists with all three phases of this process.
Our pricing depends on case complexity and the amount involved. The initial case review is free and is how we determine whether recovery is viable before any paid work begins. If you decide to proceed with a full investigation, you receive a written proposal with the scope of work and the fee defined upfront, invoiced from Recoveris AG in Switzerland. Contact us with the details of your case for a confidential consultation.
Yes. Like law firms and licensed investigators, legitimate recovery firms charge a professional fee. Tracing assets on-chain, packaging evidence, coordinating with exchanges and law enforcement, and producing court-grade reports is technical, time-intensive work, and no serious firm does it for free.
At Recoveris, the initial case review is free and is how we determine whether recovery is viable. If you decide to proceed with a full investigation, you receive a written proposal first, with scope and fee defined upfront. The invoice comes from Recoveris AG in Switzerland.
Act immediately: secure any remaining funds in a safe wallet, preserve evidence (screenshots, transaction IDs, timelines), notify your exchange or wallet provider, report your case to law enforcement and contact specialized recovery experts like Recoveris, who can advise you how to proceed and get your funds back.
It depends on several factors, among others: the amount stolen, how quickly you act, whether funds touched regulated exchanges, and the attack method used. Recoveris provides preliminary assessments based on provided details to help you understand if recovery is viable in your specific case.
Gather all transaction details, wallet addresses (yours and the scammer’s), exact dates and times, any communication with scammers, and details about how the theft occurred. The more evidence you preserve immediately, the better the chances of successful recovery for our team at Recoveris. Use our recovery form to provide us with the details, so we can offer you a confidential consultation.
Recoveris handles all major types: wallet draining, fake investment schemes, exchange account hacks, phishing, hacks, DeFi protocol exploits, romance scams, ransomware, and social engineering attacks. The Recoveris team has experience across Bitcoin, Ethereum, and all other major blockchains.
We never ask for your private keys, passwords, or access to your accounts. Recoveris is a legitimate company registered in Switzerland (and representing the country in the Swiss VentureLab startup team), with a major investor, a team of former law enforcement officers, legal professionals, and blockchain experts who regularly appear publicly, is legitimized by mentions in the press, and a recognized player in the industry.
Yes, your information is stored securely on private servers and never shared with third parties. Recoveris maintains strict confidentiality and only shares information when necessary for recovery efforts or legal proceedings, always with your consent.
Yes, the Recoveris team regularly works to recover compromised crypto-assets across jurisdictions and has experience coordinating with law enforcement, virtual asset services providers (e.g. crypto exchanges), and legal systems in multiple countries. Cases are typically immediately cross-border , involving international coordination and cross-border enforcement actions.
Asset freezing can happen within hours or days if conditions are right. Complete recovery typically takes weeks, months or even years, depending on legal complexities, jurisdictional factors, and cooperation from exchanges or other platforms holding the funds.
Possibly. While acting quickly improves chances, older cases can still be viable if funds remain traceable or if new enforcement opportunities arise. Recoveris can assess your specific situation to determine if crypto recovery efforts are worthwhile.
If you have any questions about our approach or services, our team of blockchain intelligence experts is ready to assist.