DAC | Digital Asset Claims

Investigation Method · 2 February 2026 · 8 min read

Backward and Forward Reconstruction in a Digital Asset Investigation

By Digital Asset Claims Research Desk·Investigation Team

  • Digital Asset Investigations
  • Methodology
  • Reconstruction

Digital asset investigations usually need to look in two directions from a known point: backward to origin and forward to destination. This article explains why each direction is handled as a distinct exercise and how the two are combined into one evidentiary map.

Knowing where funds went does not tell you where they came from, and neither direction should borrow the other's certainty.

Investigation dashboard showing linked transaction records
Backward and forward trails from the same anchor point are logged and verified as separate evidentiary tracks.

Choosing the anchor point

Every reconstruction begins with an anchor: a wallet address, transaction hash, or account known to be central to the matter under investigation, chosen because it is independently verifiable and directly relevant to the question being asked.

The anchor point is documented with the same rigour as any other piece of evidence, including how it was identified and what record establishes its relevance, so the starting point of the reconstruction is itself defensible.

From this single anchor, the investigation can extend in either or both directions, but the anchor itself never changes mid-investigation without a documented reason for doing so.

Working backward to origin

Backward reconstruction traces inputs to their preceding transactions, asking where the value held at the anchor point came from before it arrived there, hop by verified hop.

This direction is often used to test a specific hypothesis, for example whether funds at the anchor point can be traced back to a known fraudulent transfer, and the investigation is structured to test that hypothesis rather than assume it.

Historical data availability limits how far backward reconstruction can reliably extend; where records become sparse or a service provider no longer retains logs, that limit is stated rather than papered over with inference.

Diagram showing bidirectional transaction flow from a central wallet
Forward and backward trails are tracked as separate branches from the same verified anchor point.

Working forward to destination

Forward reconstruction follows the anchor point's outputs through subsequent transactions, aiming to establish where value currently resides or where it was converted, exchanged, or dissipated.

This direction typically encounters more active obfuscation, since a party seeking to conceal assets has an incentive to complicate the forward path, so investigators pay particular attention to timing patterns and structuring behaviour.

Where forward tracing reaches an exchange or custodial service, the investigation notes this as a potential restitution or freezing point, distinct from the tracing exercise itself, which stops at documenting the location of the funds.

Combining both directions into one map

Once backward and forward trails have been independently verified, they are combined into a single map anchored at the shared starting point, showing the fullest evidenced lifecycle of the funds available from the data.

Any point where the two trails intersect a common third-party wallet is treated as requiring fresh verification rather than assumed to be automatically confirmed by both directions meeting there.

The final map explicitly separates confirmed segments from probabilistic ones, giving the reader a single reference document rather than two disconnected narratives requiring reconciliation.

Frequently asked questions

Why not always trace in both directions at once?

Resource and evidentiary constraints often mean one direction answers the immediate question more directly. Both are pursued when the investigation's scope requires a complete lifecycle picture.

Which direction is harder to verify?

Backward tracing is often limited by record retention over time; forward tracing is often limited by active obfuscation. Each has distinct challenges rather than one being uniformly harder.

Can the two directions contradict each other?

They can appear inconsistent if one relies on unverified inference. That is precisely why each direction is verified independently before being combined.

What happens at an intersection point?

It is treated as a new anchor requiring its own verification, not assumed reliable simply because two trails converge there.

Reconstructing a digital asset's lifecycle means treating origin and destination as separate evidentiary questions, each subject to its own verification standard, before combining them into a single map that is honest about what is proven and what remains open.

More in Digital Asset Investigations