DAC | Digital Asset Claims

Investigation Scope · 16 February 2026 · 7 min read

What a Digital Asset Investigation Can Establish and Where It Stops

By Digital Asset Claims Research Desk·Investigation Team

  • Digital Asset Investigations
  • Evidence Standards
  • Scope

Digital asset investigations produce genuinely useful evidence, but only within defined limits. This article sets out what the discipline can reliably establish and where its findings must stop short of conclusions the data cannot support.

A trace can show that funds moved. It cannot, on its own, show who moved them or why.

Structured evidence report document with annotations
A responsible investigation report states its confidence levels alongside its findings, not separately from them.

What blockchain evidence can support

Blockchain evidence can reliably establish that value moved between specific addresses at specific times, the amounts involved, and the sequence of those movements as recorded in an immutable public ledger.

It can establish technical relationships between addresses, such as shared inputs suggesting common control, and points where funds interacted with identifiable services such as exchanges or known custodial wallets.

It can also establish a defensible timeline, since block timestamps and confirmation data provide an independently verifiable chronological backbone for any narrative built around the transactions.

What blockchain evidence cannot support alone

On its own, blockchain data cannot establish who controls a wallet. That requires corroborating evidence such as exchange account records obtained through lawful process, or admissions made elsewhere.

It cannot establish intent. A transaction pattern that looks like structuring to avoid detection may equally reflect routine account management, and the investigation records both possibilities rather than choosing the more dramatic one.

It cannot guarantee that funds will be located or returned. Tracing evidence supports a legal or restitution process; it is not itself that process, and conflating the two misleads a client about what has actually been achieved.

Chain of custody diagram for digital evidence handling
Maintaining a clear chain of custody supports the evidentiary weight of findings, but does not extend their scope.

Infrastructure evidence and its boundaries

IP addresses, device fingerprints, and login timestamps can corroborate a wallet's likely operator, particularly when they align consistently across multiple sessions and multiple platforms over time.

Shared infrastructure, however, weakens this corroboration considerably. VPNs, carrier-grade network address translation, and public Wi-Fi networks can place many unrelated users behind the same visible IP address at the same time.

Infrastructure evidence is therefore reported as supporting or undermining a hypothesis about identity, never as proof of identity by itself, and always alongside a description of its limitations for the specific case.

Communicating scope in the final report

A responsible report states, near its findings rather than buried in an appendix, exactly what evidentiary standard each finding meets and what would be required to raise that standard further.

This practice protects the client from relying on a finding beyond its actual strength, and protects the investigation's credibility when findings are tested in a legal or regulatory setting.

Where a question genuinely cannot be answered from available evidence, the report says so directly, rather than offering a speculative answer designed to appear more complete than the underlying material allows.

Frequently asked questions

Can an investigation guarantee funds will be located?

No. It can establish where funds moved and where they currently appear to sit based on available evidence, which supports but does not guarantee a subsequent restitution process.

Can wallet activity alone prove who owns a wallet?

No. Wallet activity shows technical control of the private key, not legal identity. Attribution requires corroborating evidence obtained separately.

Is an IP address enough to identify a suspect?

On its own, no. It must be corroborated with other evidence, particularly given the prevalence of shared infrastructure and anonymising services.

Why do reports include confidence ratings?

So that every finding is presented alongside an honest statement of how strongly the available evidence supports it, allowing appropriate reliance in any subsequent process.

A digital asset investigation is valuable precisely because it is disciplined about its limits. Establishing what the evidence proves, and stating plainly what it does not, is what allows the resulting findings to be relied upon where it matters.

More in Digital Asset Investigations