Recoveris Monthly · Edition 04
August in on-chain investigations.
About 11 minutes to read · Forward freely
Last weeks · July 27 – August 30
The patterns we saw.
Our August incident reviews kept returning to four problems: lending against inflated prices, paying out against deposits that never arrived, a single software flaw exposing many users, and stolen funds changing form before anyone could stop them. For teams handling crypto cases, each leaves a different evidence trail and calls for a different response.
1 · Inflated collateral
A higher token price became permission to borrow more.
Moonwell lost a reported USD 8.7 million and Tectonic an estimated USD 75 million after attackers pushed up the prices of tokens with little trading activity. They then used those tokens as security for loans and withdrew assets such as stablecoins and bitcoin. The platforms accepted a temporary, manipulated price as if it represented lasting value. For a case team, the sequence matters: who bought the token, how those purchases affected its price, and what was borrowed immediately afterwards. The evidence of preparation sits before the withdrawal, so the investigation has to start there.
Moonwell report → · Tectonic report →
2 · False deposits
Money went out because a system believed money had come in.
Allbridge lost about USD 190,000 after accepting a message about a transfer without checking that the corresponding funds had actually arrived. The Coreum bridge, a service for moving assets between blockchains, lost roughly USD 200,000 through a similar mistake: transactions between the attacker’s own accounts were counted as deposits into the bridge. Both systems released real assets against a payment that had never been made to them. For investigators, the task is to reconcile the claimed deposit with the actual transfer and identify whose genuine funds paid for the shortfall.
Allbridge analysis → · Coreum report →
3 · Shared vulnerabilities
One software flaw exposed many separate victims.
TRM Labs put the Coldcard losses at a preliminary USD 116 million across more than 5,200 addresses. The wallet software had generated predictable secret keys, allowing attackers to work them out without possessing the devices. Separately, a flaw in software shared by six blockchains led to USD 5.7 million in losses, according to the Cosmos EVM post-mortem. These cases make the software version and configuration part of the evidence. Linking victims to the same defect can establish common exposure, although it does not prove that the same attacker took everyone’s funds.
Coldcard assessment → · Cosmos EVM post-mortem →
4 · The first conversion
Recovery options changed when the stolen asset changed.
Coinsbuy lost more than USD 7.9 million, with proceeds quickly routed through swap services towards Monero, where following transfers on a public ledger becomes much harder. A six-figure sum was reportedly frozen with one provider’s help. In the Bofur Capital case, around USD 2 million in stolen USDC was converted into DAI and remained visible at one address when reported. That conversion removed the option of asking USDC’s issuer to freeze those tokens. The practical lesson is to identify both the asset and whoever can restrict it at each stage, because a visible balance can still be beyond the reach of the original issuer.
Coinsbuy report → · Bofur Capital report →
Full weekly breakdowns: recoveris.io/blog →
CONCEPT OF THE MONTH
Wallet keys and recovery phrases.
Why a software update may not secure an existing wallet
A hardware wallet protects the credentials that control virtual assets. The assets themselves remain recorded on the blockchain, while the device protects the private key that authorises a transfer. The recovery phrase is the human-readable backup from which compatible wallet software can recreate that key and every address derived from it. Anyone who can reproduce the phrase, together with any separate passphrase where one is used, can recreate the same wallet.
That makes the moment of key generation critical. A secure wallet needs a source of randomness strong enough that nobody can guess or calculate the result. In the Coldcard case, a software configuration error caused some devices to fall back to a much weaker method of generating that randomness. TRM Labs reported that the effective strength of affected keys could fall from the intended 128 bits to as little as 40 bits, low enough to be searched with modern computing power.
The attackers therefore did not need to steal a device, trick the owner into revealing a recovery phrase or install malware on the victim’s computer. They could calculate possible keys elsewhere, identify the corresponding blockchain addresses and test which of those addresses held bitcoin. TRM’s preliminary assessment put the theft near 1,816 BTC, roughly USD 116 million, across more than 5,200 addresses.
Installing patched software changes what happens the next time a wallet creates a new secret. It leaves an existing recovery phrase exactly as it was. Restoring that old phrase on a new or updated device recreates the same private keys and the same exposure. The device may now be secure while the wallet it reopened is still compromised.
Migration requires a genuinely new wallet. An affected owner needs to update the device, generate a new recovery phrase using the corrected process or another sound method that provides sufficient randomness, such as a properly executed series of dice rolls, verify a receiving address, and transfer the assets. A small test transaction helps confirm the destination before the remaining balance moves. Re-entering the old phrase, even on different hardware, does not complete that migration.
The case file needs the history of the secret. The current firmware version is only part of the record. Investigators should establish the device model, the software running when the recovery phrase was first generated, the date of creation, whether the owner added an independent source of randomness, the associated addresses, and the timing of unauthorised transfers. Shared exposure can connect many victims to one defect, but differences between the transactions may still point to several attackers.
Prevention and recovery remain separate. Moving the remaining balance to newly generated keys can prevent another withdrawal from the exposed wallet. It does not return assets already taken. Those funds require a separate investigation: trace the receiving addresses, preserve the evidence and prepare any exchange, issuer or law-enforcement action available when the assets move.
Read TRM Labs’ Coldcard assessment →
PRODUCT SPOTLIGHT
Source of Funds: prove where digital wealth came from.
Expert-led forensic provenance analysis
Automated risk tools can lose the trail at a bridge, inside an exchange or when a portfolio includes DeFi and privacy-coin activity. A high-risk score then leaves the central question unanswered: where did the client’s legitimate wealth come from, and what evidence will a bank, regulator or court accept?
A Recoveris Source of Funds report reconstructs the full origin of the assets across chains, bridges, mixers, exchanges and DeFi. Our forensic specialists reconcile on-chain flows with internal exchange records, verify trading and P2P counterparties, rebuild yield and other digital-asset profits, and preserve the supporting evidence with a documented chain of custody.
The final report combines an executive summary, visual transaction flows, profit verification, a privacy-coin evidence package where relevant, and an evidentiary annex. It is built for banks and VASPs handling onboarding or KYC remediation, legal professionals who need defensible documentation, and individuals proving legacy or pre-KYC wealth.

An anonymised cross-chain flow from a live Source of Funds report.
Discuss a Source of Funds case →
FIELD INTELLIGENCE
AI is widening the speed gap.
TRM Labs’ 2026 AI-in-Crime Adoption Index puts adoption across crypto crime at 54 out of 100, up from 28 in 2024. Scams are the only category assessed as mature. The share of scam reports in which AI was part of the scam has grown roughly 13 times since 2022, while reported deepfake-scam losses in 2026 to date already exceed the total for 2025 by 263%.
INTERPOL’s African Cyberthreat Assessment adds the response-side evidence. Its member-country survey found AI involved in some capacity in 55% of cybercrime cases observed in 2025, while 94% of agencies reported insufficient digital-forensics tools. Crypto-asset tracing sits among the skills in shortest supply, and the report calls for standardised forensic capability, cross-border cooperation and formal public-private partnerships.
Sol Cinosi made the policy consequence clear in BeInCrypto: some agencies still have no rules for responsible AI use, and investigators in certain jurisdictions are forbidden from using tools that criminals deploy every day. Her Market Intelligence Council discussion with Kodex’s Nick Pailthorpe and investor Evan Luthra connected that gap to recovery: the first hours define the available options, on-chain evidence needs off-chain account data, and jurisdiction is often harder than tracing.

Read the BeInCrypto interview → · Watch the panel →
RECOVERIS THIS MONTH
Our appearances
Patrick Prinz in The New York Times
The Times asked Patrick to assess the compliance issues around Aqua 1’s USD 100 million purchase from World Liberty Financial. He explained why a combination of prior business failures, sudden wealth, transaction size and an open investigation should trigger enhanced due diligence. He also noted that the Trump family’s status as politically exposed persons would typically attract heightened scrutiny. World Liberty Financial told the Times that it followed applicable laws and that its compliance programme meets or exceeds industry standards. Recoveris provides complex Digital Asset Source-of-Funds analysis for banks, financial institutions and Big Four firms.
Read The New York Times investigation →
How our AI Investigator works

Kateryna described a hybrid architecture with a machine-learning model trained on investigated cases and a fine-tuned open-weight language model that explains the result. The machine-learning layer classifies the activity; the language layer explains the output. The white-box design is intended to make findings explainable and reproducible, while investigators retain control over consequential decisions. The hardest stage was the data: collecting it, checking it and merging it across sources, because case-grounded inputs are what let the team test whether the model’s output can be trusted.
Watch Kateryna’s explanation →
Sol Cinosi on working with law enforcement

Most of Recoveris’ relationships with investigative agencies began with one case in which we had to prove we could do the work. Sol explains the boundary that makes those relationships work: law enforcement leads the investigation and makes the decisions, while Recoveris contributes technology, specialist knowledge and analytical capability.
Operationally, that support can include tracing, financial intelligence, wallet monitoring and assistance with address blocking, plus tools that automate repetitive collection. Cross-border cases also move at the speed of the relationships behind them, because a freeze crossing several jurisdictions depends on reaching a trusted counterpart where the funds landed.
Watch Sol on working with agencies →
IN THE FIELD
Where we contributed this month.
Singapore · Cambridge · Rome · Bishkek
Source of Funds with ACAMS Singapore
At a closed-door ACAMS Singapore Chapter roundtable, Marcin Zarakowski, Roman Bieda and Dominik Konopacki explained where automated blockchain tools stop being sufficient for Source of Funds work. The discussion covered cross-chain and exchange-record analysis, digital-asset profit verification, privacy-coin exposure and the evidence structure a risk committee can act on.
See the Singapore roundtable post →
Economic crime and crypto recovery in Cambridge
Marcin spoke at the 43rd Cambridge International Symposium on Economic Crime. He addressed pig butchering and romance fraud during an ICC FraudNet-sponsored workshop, then joined a session on the practical realities of tracing, freezing and recovering digital assets.
Multiple analytics tools for Europol EMPACT
In Rome, Head of Investigations Umberto Buonora spoke at a Europol EMPACT session about using several blockchain analytics solutions together. His contribution focused on building conclusions from the available evidence and methodology instead of allowing one platform’s coverage to define the investigation.
Virtual-asset supervision with the OSCE in Bishkek
Marcin co-led a two-day OSCE workshop as Virtual Asset Expert, working with the National Bank of the Kyrgyz Republic. The programme addressed the supervisory questions created by rapid growth in virtual-asset activity and translated those questions into practical institutional capacity.
SEPTEMBER CALENDAR
Meet the Recoveris team.
If you will be at one of these events, contact us to arrange a meeting.
3-4 September · Frankfurt
Frankfurt School of Finance & Management Lecture
Patrick Prinz and Dominik Konopacki · training
7-10 September · Strasbourg
The Underground Economy Conference
Umberto Buonora and Alessandro Rella · presenting
11 September · Prague
OSCE: Anticipating the Future of Finance
Marcin Zarakowski · attending
15-16 September · Luxembourg
10th Global Conference on Criminal Finances and Cryptoassets
Marcin Zarakowski and Sol Cinosi · presenting
24 September · London
Seize:London 2026
Sol Cinosi · attending
29-30 September · Vienna
5th INTERPOL New Technologies Forum
Patrick Prinz and Dominik Konopacki · presenting Recoveris products