Recoveris Monthly · Edition 01
April–May in on-chain investigations.
Once a month, we summarise the patterns from the past four weeks of incidents, explain one concept in plain language for legal and compliance professionals, share what we’re shipping at Recoveris, and tell you how to reach us when you need an expert source.
Less than 5 minutes to read · Forward freely
Last 4 Weeks · April 20 – May 17
$55M drained, $701M restrained.
Our weekly incident reports covered 19 of the period’s biggest exploits, alongside one major international enforcement action against scam-compound infrastructure.
Drained: approximately $55M
From DeFi protocols and corporate wallets, across 19 incidents we covered in our weekly reports.
Restrained: $701M
FBI-led action against Southeast Asian scam compounds. 9 compounds dismantled.
The patterns we saw
01 / Infrastructure
Infrastructure beat code.
Most of the dollar losses this period came from breached people and systems, not from broken code. Attackers took over administrator credentials, inserted themselves into the small groups of executives who must co-approve large transfers, and ran phishing and social engineering against the staff who operate the wallets day to day. On the blockchain itself, the resulting transactions look legitimate: a real, authorised employee signed each one. For practitioners, that means the early case file lives off-chain. It sits on the executive’s laptop, in internal access logs, in email systems, and in team chats. The blockchain only records the clean signature at the end.
02 / Attack surface
The attack surface keeps widening.
Attackers are moving from the code itself to the systems around it. In recent weeks: a bridge that moves funds between two blockchains was exploited, a widely-used developer software library was secretly tampered with and propagated into thousands of wallets and apps that depend on it, and the permission system on a major trading protocol was abused at scale. The vulnerable surface now stretches past the smart contracts into the bridges between chains, the systems that authorise transfers, the open-source code that protocols rely on, and the IT environments around all of them. For practitioners, that changes what evidence a case needs. Expect to coordinate forensic work across code repositories, software libraries, employee devices, and email systems well before anyone looks at the blockchain. Build that into the intake workflow, because by day 30 the off-chain evidence may already be gone.
03 / Enforcement
Enforcement worked, at scale.
Cross-border asset freezes are happening faster. A single FBI-led operation against Southeast Asian scam compounds produced $701M in restrained assets and dismantled nine sites, with coordination between jurisdictions moving from first report to asset freeze in days rather than months. Recovery itself still runs through years of litigation after the freeze. What’s changed is upstream of that: the legal and operational machinery for cross-border action has matured to the point where an early freeze is realistic in the first week of a case. For practitioners, how quickly a victim engages counsel has become a decisive factor in whether the funds are still reachable when the order lands.
04 / Human layer
The human layer is still leaking.
Almost every individual victim loss in the period traced back to one of four things: phishing, scammers impersonating real platforms or people, victims being tricked into signing a transaction that quietly handed the scammer ongoing permission to drain their wallet later, or private keys exposed years ago being collected and used now. The dormant-wallet drains in late April were the clearest example: keys leaked in old breaches are being harvested and used today against wallets that hadn’t moved in years. For practitioners handling individual victim intake, the wallet’s full permission history and how the victim has stored their keys over the years matter as much as the transactions immediately around the loss. Old exposures resurface as fresh theft, and the case file has to look further back than the date of loss itself.
Full weekly breakdowns and source links →
CONCEPT OF THE MONTH
Mixers, explained.
Plain language for legal and compliance professionals: what mixers are, how the trail survives them, and why sanctioned mixers became a board-level question.
A mixer is a service that breaks the on-chain link between an address that sends crypto and the address that receives it. You deposit funds into a shared smart-contract pool alongside hundreds or thousands of other users. Later, a different address that you control withdraws an equivalent amount from the pool. The blockchain still records every transaction, but the obvious A-to-B trail is gone.
The most prominent example is Tornado Cash, sanctioned by OFAC in August 2022 and then delisted on March 21, 2025 after the Fifth Circuit held that the protocol’s immutable smart contracts could not be classified as “property” under IEEPA. Others include Sinbad (still designated, sanctioned November 2023), Railgun (which uses zero-knowledge proofs), and Cyclone Protocol. The mixing happens through deliberate pooling and time-shifted withdrawals. The contract’s own activity stays fully visible on the blockchain.
For lawyers, two practical points. First, the trail still exists. Timing patterns, deposit-and-withdrawal correlations, downstream KYC linkages at receiving exchanges, and clustering analysis usually reconstruct a working hypothesis about where the funds went. The methodology has held up in both civil and criminal proceedings when properly evidenced, and it’s the spine of much of our own casework.
Second, the sanctions posture around mixers is in active flux. The Tornado Cash delisting reset the smart-contract sanctions question for now, but Sinbad and others remain designated, and the criminal prosecution of Tornado Cash developer Roman Storm is running on a separate track from any contract-level question. For institutions with crypto flows, the live question is whether funds touching any currently-designated mixer trigger sanctions enforcement against the receiving institution, and what the post-Tornado legal environment will produce next. That has stayed a board-level question.
Go deeper · further reading
- Curiously Crypto: What is a cryptocurrency mixer? – short primer for non-technical viewers
- Altostratus: Bitcoin mixers: how the Binance hackers laundered their stolen bitcoin – case study on real laundering
- Blockchain Central: Fully anonymous bitcoin transactions with a bitcoin mixer – how the obfuscation works in practice
FROM RECOVERIS
What we’ve been working on.
Recent cases, investigations, and product updates from the team.
Recent Cases & Investigations

How an on-chain investigation cracked Europe’s biggest crypto scandal of 2026.
Our forensic team traced ZondaCrypto’s main BTC hot wallet from 55.7 BTC down to 0.18 BTC, a 99.7% collapse, and identified $21M of systematic outflows to a single Kraken deposit address. Three weeks after publication of our findings with money.pl, the exchange was offline, the CEO had reportedly left the country, and the Polish Prosecutor’s Office had opened a criminal investigation with damages now estimated above 350M PLN ($96.4M). Over 700 victims have already registered.
Investigation · Poland → Russia
Quicko: tracing the crypto bridge to Moscow.
Our analysts mapped how Polish payment institution Quicko was technically integrated with Trustee Global, a crypto wallet operator that routes users to no-KYC “instant exchange” intermediaries in the Seychelles, Georgia, Ukraine, and St Vincent. Two of those intermediaries showed direct flows to OFAC-sanctioned Garantex, and Kassa.cc allows instant conversion of crypto into rubles credited to Sberbank, PSB, and Avangard. Quicko issued the BIN numbers that put Russian Trustee Wallet users inside Visa and Mastercard rails as ostensibly safe Polish-EU instruments.
An entity operating from the EU did not choose partners from this region, but instead tied itself to entities in tax havens or risky jurisdictions with a looser approach to crypto regulation.
– DOMINIK KONOPACKI, BLOCKCHAIN INVESTIGATIONS MANAGER · BANKIER.PL
On January 21, KNF revoked Quicko’s payment-institution licence with immediate effect.
Read the full Bankier piece (Polish) →
$10.5M recovered
From a Swiss investment scam.
The Schwyz cantonal police announced one of the largest crypto seizures in Swiss history. The trace and VASP coordination that produced the freeze were led by Umberto Buonora, our Head of Investigations. The team mapped the receiving infrastructure across multiple chains within days of intake, identified Tether and Bitfinex as the points where the funds had landed, and worked institutional channels until USDT was frozen at the address level and $10.5M was held on Bitfinex’s books pending prosecution. Tether has now burned and reminted the value; the victim is being made whole.
Product, Partnerships & Webinars
FrontOffice is now our case intake portal.
We’ve replaced the legacy victim submission form with FrontOffice, a structured intake portal with guided workflows for asset recovery, Source of Funds investigations, and address checks. Submissions arrive complete, an embedded AI chatbot handles first-line questions 24/7, and the dashboard gives submitters visibility from intake to resolution across 6 status stages.
If you refer cases or victims, the link to share remains recoveris.io/schedule-a-consultation.

EY DLA launches June 2 in Zurich.
On June 2, EY hosts its Crypto Compliance Breakfast in Zurich, where our joint product with EY’s wealth management practice goes public. EY DLA (Distributed Ledger Analysis) covers source-of-funds tracing, custody verification, and AML risk scoring at the institutional level.
If you work with banks or family offices facing client exposure to digital assets, this is the workflow they’ll likely encounter on the compliance side.
Register for the EY Crypto Compliance Breakfast →
Digital Asset Recovery Around the World.
A frontline view of digital asset recovery in a jurisdiction where active conflict, fast crypto adoption, and an evolving regulatory frame collide. Expect the legal landscape, recovery pathways, notable cases, and a live Q&A.
Register for the Ukraine session →
Missed the April 1 Singapore session with Setia Law?
Danny Ong and Yam Wern-Jhien walked through how Singapore’s courts approach tracing, freezing, and recovery, with several recent precedents practitioners should know.

► Watch on YouTube · Singapore session
TALK TO US
Need an expert on the record?
Working a case that needs a forensic blockchain expert? If you need a court-admissible tracing report, an expert witness, or technical input on a live recovery matter, reach out to [email protected]. Our investigations team responds within one business day.
If you’re a journalist covering crypto crime, DeFi exploits, asset recovery, sanctions exposure, or the regulatory frame around digital assets, our investigations and corporate affairs teams comment on the record. Recent topics: cross-chain bridge exploits, mixers in modern obfuscation, the architecture behind the $701M scam-compound seizure, and Switzerland’s positioning in the digital asset stack. For on-deadline requests, reach out to [email protected].
Best for new matters, case referrals, and structured intake.