Crypto Scam Investigation: Evidence to Preserve
A crypto scam investigation needs more than a transaction hash. Preserve the payment record, the instructions that led to it, the account and wallet history, and the original messages or files that connect the parties. Start by securing any compromised accounts and saving evidence that may disappear. The questions an investigator can answer, and any prospect of recovering funds, depend on the service, the transaction path and the countries involved.
What the Evidence Needs to Establish
Build the file around specific questions instead of collecting every screen you can find. A useful investigation distinguishes the amount actually lost from a number displayed on a website, and a verified transaction from a theory about who owns an address.
| Question | Records that help answer it | Common gap |
|---|---|---|
| What was the actual loss? | Bank statement, exchange withdrawal, wallet transfer and any funds genuinely returned. | A fake dashboard “profit” is counted as money paid. |
| Who gave the instruction? | Full chat export, email with headers, invoice, domain and account identifier. | Only a cropped message or display name remains. |
| Where did the crypto go? | Full transaction hash, network, token, addresses and explorer record. | An internal exchange reference is mistaken for a blockchain hash. |
| Who controlled the destination? | Platform records, reliable attribution and investigative findings. | A public address is treated as a person’s identity. |
| What can be acted on? | Current service lead, police report and evidence linking the loss to that lead. | A historic trace is presented as proof that recoverable assets are still held. |
Start with verified facts. Label an explorer’s service tag, a person’s claim or a tracing hypothesis as a lead until it is corroborated. This helps support and investigators understand what information they still need.
Secure Access Without Erasing the Record
If an exchange account, email or wallet may still be compromised, stop further payments and act on account security promptly. Change passwords from a trusted device, end unknown sessions, review withdrawal addresses and API keys, and assess suspicious wallet approvals. Where the wallet itself is compromised, move remaining assets to a new secure wallet if you can do so safely. Record each action and its time.
Save the relevant account notices and recent activity before closing sessions where possible. If a device may contain malware or unauthorised remote-access software, avoid further use and ask a qualified responder about preserving it. Security takes priority; a victim is not expected to leave an active compromise in place solely to keep a screenshot.
The joint European supervisory authorities’ crypto-fraud factsheet advises victims to stop transactions, secure accounts, contact the crypto provider through official channels and report the incident. It also warns about people posing as recovery agents after an initial scam.
For a step-by-step response to an active theft, see How to Recover Stolen Cryptocurrency: First Steps. Deal with account security and urgent notifications while you organise the investigation file.
Preserve the Original Evidence by Source
Keep original exports and received files in one folder, and use copies for highlighting or analysis. Give every item a short filename, capture date and note explaining what it is. If a service no longer allows an export, document what you can access and when.
| Evidence | What it helps prove | How to preserve it |
|---|---|---|
| Exchange or wallet activity | Your account’s transfers and the link between your account and a payment. | Download the original CSV or PDF; retain the withdrawal ID, fee and time. |
| On-chain transaction | Network, transfer result, asset, amount and destination visible on-chain. | Copy the full hash and address; save the network explorer URL and dated view. |
| Bank, card or payment record | The fiat funding leg, payer, payee, value and payment reference. | Keep a statement or receipt showing the relevant fields. |
| Messages, calls and emails | The representations, payment request, contact identifier and timing. | Export full conversations; retain original emails and headers where available. |
| Website, app and advertisements | The domain, claimed balance, withdrawal terms and public representations. | Save the URL, dated screenshots, page export and ad or app identifier. |
| Wallet connection or approval | Which contract or spender received permission and when. | Record the wallet, chain, approval transaction and visible permission; keep the original view. |
| Provider and authority replies | When you reported, what you requested and what the recipient did. | Preserve the full ticket thread, case number, attachments and acknowledgement. |
A screenshot can show what the victim saw, but a cropped image may omit the URL, account name, date or surrounding conversation. Keep both the original export and a readable screenshot when available. Do not edit an original image to remove embarrassing or contradictory material; explain it in the chronology instead.
Make a Transaction Schedule Investigators Can Check
Use one row per real transfer. Number the rows so the reader can match a withdrawal, blockchain record and corresponding instruction without guessing. Include:
- date and time in UTC, and the original local time if it matters;
- sending service or wallet, network, asset, amount and displayed fee;
- full sending and receiving addresses, hash or internal transfer reference;
- the bank or card payment that funded the purchase, if relevant;
- the message, invoice or screen that instructed this particular payment;
- the current transaction status and your source for that status; and
- whether the destination is verified, merely labelled by a tool, or still unknown.
A platform’s withdrawal ID and an on-chain hash are separate fields. If you have only the withdrawal ID, include it and ask the sending service for the corresponding network and hash. For an internal platform transfer, the public hash may not exist; account records then become more important.
Blockchain Tracing and Crypto Evidence Analysis can follow visible movements, but pooled exchange balances, bridges and swaps may create gaps. The schedule should show where verification stops rather than fill those gaps with a guess.
Record the Story Around Each Payment
Create a single chronology covering the first contact, claims made, account creation, each payment instruction, transfers, withdrawal attempts and later requests for fees or documents. Attach a file reference to each significant event, such as “Chat-03” or “Bank-02”. Distinguish something you personally observed from what the suspect told you.
Messages and Identities
Preserve usernames, account IDs, phone numbers, email addresses, profile URLs and full chat context. A contact can change a display name or delete messages. If you received a voice call, note the date, number shown and what was said; save any recording only where its creation and use are lawful in your country.
Websites and Displayed Balances
Capture the domain and the exact URL, not just the brand name. Save the deposit page, terms, dashboard, withdrawal error and any demand for tax or “verification” money. A website balance may be invented; compare it with actual deposits and any real payouts. Do not keep logging into a suspicious site from a device you believe has been compromised.
Emails, Documents and Devices
Keep original emails with headers if you can, plus attachments in their original format. Preserve invoices, contracts, app download details and any remote-access request. If you suspect malware, a qualified examiner may need the device and metadata; avoid installing unknown “recovery” utilities that could alter the evidence or expose credentials.
What the Blockchain Proves, and What It Does Not
In its report on criminal use of cryptocurrencies, Europol describes the visibility of many public blockchain transactions and the techniques that can hinder tracing. A hash can establish a recorded movement on a specified network; it does not, on its own, name the person who controlled the receiving address or prove that the same assets remain there.
If an explorer labels an address as belonging to an exchange, identify the label as a possible service lead. Custodial services may move funds through pooled addresses and use internal records that the public cannot inspect. Ask the platform to assess the address, and provide the verified facts to investigators who may be able to seek further records.
A tracing chart can be useful evidence when it includes sources, timestamps and explicit confidence levels. A chart without the underlying transaction list should not be treated as proof of an individual’s identity, an account freeze or a recoverable balance.
Notify the Platform with a Focused Evidence File
Use the official fraud or security contact for the sending exchange and, if the destination plausibly reaches another platform, that provider too. Give the network, full hash, amount, relevant addresses, time and short explanation. Ask it to preserve relevant account records, review the suspected destination and tell you how competent authorities should contact the service. Do not demand another customer’s private account details.
Suggested wording:
“I am reporting suspected crypto fraud involving [asset and amount] on [network]. The transfer [hash] left my [wallet or exchange account] at [time, UTC] for [full address]. The payment instruction is attached as [file name]. Please review whether this address relates to your service, preserve relevant records and confirm my case reference and the channel for requests from the investigating authority.”
If the address attribution comes only from a tracing tool, say that. Preserve the acknowledgement and later responses alongside the original ticket, and send supplementary information under the same case number.
Pass the File to the Competent Authority
Submit a report to the police or national cybercrime reporting channel in your country. Lead with the actual loss and a one-page chronology, then attach the numbered transaction schedule and an evidence index. State clearly which names or services are verified and which are suspected. Ask for the report reference and add it to your platform tickets.
The detailed reporting steps in How to Report a Crypto Scam and Preserve Evidence can be followed once the core investigation file is organised. You can report the facts you already have and send a supplement later; you need not solve the entire blockchain trail first.
For cross-border criminal proceedings, Eurojust’s overview of the EU e-evidence package describes tools for competent authorities to seek preservation or production of electronic evidence from service providers under applicable conditions. Such formal orders belong to the authorities, not to a victim or a private analyst. A victim can identify the provider and the records likely to matter so investigators know what to request.
When an Expert or Lawyer Can Help
Technical help is proportionate when there are many transactions, several networks, uncertain service attributions or a disputed wallet-approval mechanism. A legal review may be useful when a provider holds potentially relevant records or assets, multiple countries are involved, a substantial loss is documented, or a formal preservation or court step is being considered. Ask for an initial scope and fee tied to a concrete deliverable.
A legitimate recovery process should separate a traceable transfer, an identifiable account, assets capable of being restricted and the victim’s legal route to return. None follows automatically from the one before it.
Get a Free Crypto Scam Case Assessment
Get a Free Case Assessment from P&P through our Crypto Scam Recovery and Crypto Fraud Legal Support service if you need to determine whether the existing records justify investigation or legal action. Share a short chronology and numbered transaction list through a verified channel; do not provide wallet credentials.
Mistakes That Weaken the Evidence
- Mixing fake “profits” with actual loss. List real outgoing payments and genuine receipts separately from dashboard figures.
- Saving only cropped screenshots. Keep the full URL, date, account context and original export where available.
- Replacing an original file with an annotated version. Work on a copy and retain the received file unchanged.
- Claiming a tool’s wallet label proves who stole the funds. Explain the basis for attribution and mark it as provisional.
- Sending unrelated documents in bulk. Index the core evidence and explain what each item helps establish.
- Waiting to report until every address is traced. Notify the platform and authority promptly with verified facts; supplement later.
What the Investigation May Achieve
A well-preserved file can support an accurate loss calculation, a credible transaction trail, a platform review or a request for information by competent authorities. It may also reveal that a website balance was fictional, that a labelled address was uncertain or that assets moved beyond a reachable custodian. An investigation can produce useful findings without producing a refund.
If a platform or authority restricts assets, a separate process may still be needed to establish the victim’s claim and arrange any return. Keep all acknowledgements and updates. Avoid further spending where the next paid step cannot be tied to a specific unanswered question or a realistic recipient for the evidence.
Frequently Asked Questions
What if I do not have a transaction hash?
Start with the exchange withdrawal record, wallet history, date, amount, asset and destination address. Ask the sending platform whether it can provide the network and hash. Report the incident with the information already available and add the hash later if obtained.
Are screenshots enough for an investigation?
They are useful for showing a message or screen that may disappear, especially if the URL and context are visible. Original messages, emails, exports and transaction records are usually more informative. Keep both and explain which screenshot corresponds to each payment.
Should I keep using a phone or computer that may be compromised?
Secure your accounts from a trusted device and stop using the suspect device for sensitive logins. If there is a serious loss or suspected malware, ask a qualified responder how to preserve the device before resetting it. You do not need to keep a live attacker connected to preserve evidence.
Can I obtain the suspected exchange customer’s details myself?
A provider may not disclose another customer’s personal information to you. Supply the verified transfer details, ask it to preserve relevant records and provide its channel for lawful requests. The investigating authority can assess the appropriate route.
What if a chat or website has already disappeared?
Record when you last accessed it and what remains: notifications, email copies, browser records, saved links, app details, counterpart messages and payment instructions. Do not recreate a conversation as though it were an original export. Explain the gap and preserve the surrounding evidence.
Get a Clear View of Your Options
Tell us what happened. We aim to respond in English within one business day.
- Evidence-led first review
- EU/EEA and cross-border support
- No seed phrases or private keys required


