We are a team of digital assets recovery specialists combining technical expertise, legal proficiency and a swift & discreet process to get your property back.
๐ Token Recovery at @Cambridge_Uni Faculty of Law
Last week, we were honoured to lecture at the Digital Economy class at the University of Cambridge Faculty of Law.
Together with Matt Green of Lawrence Stephens, we explored:
โช๏ธ Case law involving blockchain technology and our practical experience working with clients
โช๏ธ The Law Commission of England and Walesโ work on recognising digital assets as a new form of property
โช๏ธ The Property (Digital Assets etc.) Act 2025 โ why it was proposed and how it reshapes the common law landscape
โช๏ธ How misappropriated crypto assets are traced and recovered through the Courts, supported by blockchain analytics and OSINT in expert evidence
Engaging with the next generation of legal professionals on digital asset disputes, evidentiary standards, and enforcement strategy remains a privilege.
A special thank you to Ann Sofie Cloots for the invitation and for facilitating such thoughtful discussion at the intersection of law and emerging technology.
#DigitalAssets #BlockchainLaw #CryptoInvestigations #AssetRecovery #Web3 #Compliance #Disputes #TokenRecovery
A must-read for financial institutions navigating todayโs evolving fraud landscape. Crypto-enabled fraud increasingly starts outside crypto โ recognising the warning signs early is key to preventing losses. ๐
๐งต Crypto fraud isn't a crypto-native problem anymore. It's showing up inside mainstream banks, PSPs, and ecommerce platforms โถ๏ธ often before anyone even realises crypto is involved. Scott Pounder (@tokenrecovery_) breaks down the fraud typologies every institution needs to recognise ๐๏ธ https://t.co/twN6xk07M7
Crypto scams are no longer just a crypto problem โ theyโre a mainstream financial crime risk.
In his latest article for @ThePaypers, Scott Pounder explores how pig butchering, phishing, fake investment platforms, AI and scam-as-a-service are changing the fraud landscape โ and why banks, PSPs and exchanges need to recognise the warning signs earlier.
Read the full article ๐
https://t.co/WkWdJPW5Uu
#FinancialCrime #CryptoFraud #BlockchainForensics
@Cointelegraph $70M gone, and not a single device was hacked.
Attackers just did the math the hardware forgot to. This is why "cold storage" isn't a strategy โ entropy is. If your seed predates July 30, assume it's compromised until proven otherwise.
The ColdCard Mk3 bug is a reminder that "cold storage" isn't automatically safe storage.
On July 30, Coinkite disclosed a critical entropy flaw in ColdCard Mk3 firmware (v4.0.1+): instead of pulling randomness from the device's secure hardware chip, affected units fell back to a predictable software method. Seed entropy dropped from an intended 128 bits to as little as ~40โ72 bits.
Attackers needed no phishing, malware, or physical access โ just enough to brute-force the narrowed seed space directly. They swept roughly 594 BTC (~$38M) from ~500 wallets in 25 minutes, a figure that's since grown past 1,000 BTC as more opportunistic actors search for exposed wallets.
A few things worth highlighting from a security and recovery perspective:
โ ๐ง๐ต๐ถ๐ ๐๐ฎ๐๐ป'๐ ๐ฎ ๐๐ถ๐๐ฐ๐ผ๐ถ๐ป ๐ฐ๐ฟ๐๐ฝ๐๐ผ๐ด๐ฟ๐ฎ๐ฝ๐ต๐ ๐ณ๐ฎ๐ถ๐น๐๐ฟ๐ฒ. The protocol worked exactly as designed. The failure was in how one vendor's firmware generated randomness at wallet creation โ self-custody is only as strong as its weakest implementation detail.
โ ๐ง๐ต๐ฒ ๐ฐ๐ผ๐บ๐ฝ๐ฟ๐ผ๐บ๐ถ๐๐ฒ ๐๐ฟ๐ฎ๐๐ฒ๐น๐ ๐๐ถ๐๐ต ๐๐ต๐ฒ ๐๐ฒ๐ฒ๐ฑ, ๐ป๐ผ๐ ๐๐ต๐ฒ ๐ฑ๐ฒ๐๐ถ๐ฐ๐ฒ. If your seed was originally generated on a vulnerable ColdCard โ even after moving it to different hardware โ you're still exposed. The weakness lives in the secret, not whatever holds it today.
โ ๐ ๐๐น๐๐ถ๐๐ถ๐ด ๐ผ๐ป๐น๐ ๐ต๐ฒ๐น๐ฝ๐ ๐ถ๐ณ ๐ธ๐ฒ๐๐ ๐ฎ๐ฟ๐ฒ ๐๐ฟ๐๐น๐ ๐ถ๐ป๐ฑ๐ฒ๐ฝ๐ฒ๐ป๐ฑ๐ฒ๐ป๐. Users running 2-of-3 setups with two ColdCard Mk3 keys were still at risk โ risk distribution only works when entropy sources are actually distributed.
โ ๐ ๐๐๐ฃ-๐ฏ๐ต ๐ฝ๐ฎ๐๐๐ฝ๐ต๐ฟ๐ฎ๐๐ฒ ๐ผ๐ฟ ๐ฑ๐ถ๐ฐ๐ฒ-๐ฟ๐ผ๐น๐น๐ฒ๐ฑ ๐ฒ๐ป๐๐ฟ๐ผ๐ฝ๐ ๐บ๐ฒ๐ฎ๐ป๐ถ๐ป๐ด๐ณ๐๐น๐น๐ ๐ฐ๐ต๐ฎ๐ป๐ด๐ฒ๐ฑ ๐๐ต๐ฒ ๐ผ๐๐๐ฐ๐ผ๐บ๐ฒ โ wallets with either were largely insulated, a strong case for defense-in-depth even on "gold standard" hardware.
โ ๐ง๐ต๐ถ๐ ๐ถ๐ ๐ฎ๐น๐๐ผ ๐ฎ ๐ฝ๐ฟ๐ฒ๐๐ถ๐ฒ๐ ๐ผ๐ณ ๐๐-๐ฎ๐ฐ๐ฐ๐ฒ๐น๐ฒ๐ฟ๐ฎ๐๐ฒ๐ฑ ๐๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ ๐ฑ๐ถ๐๐ฐ๐ผ๐๐ฒ๐ฟ๐. ๐ง๐ต๐ฒ ๐ณ๐น๐ฎ๐ โ a single line of code โ reportedly sat dormant for years. Investigators believe an LLM is what finally surfaced it: open-weight models like Kimi K3 reportedly pinpointed the issue in minutes, while more safety-tuned models like Anthropic's Fable and ChatGPT were more restricted or evasive in response. The same speed that helps defenders find flaws helps bad actors weaponize them just as fast.
โ ๐ข๐ป-๐ฐ๐ต๐ฎ๐ถ๐ป ๐ณ๐ผ๐ฟ๐ฒ๐ป๐๐ถ๐ฐ๐ ๐บ๐ฎ๐๐๐ฒ๐ฟ ๐ต๐ฒ๐ฟ๐ฒ, ๐๐ฟ๐ด๐ฒ๐ป๐๐น๐. Every Bitcoin transaction is public, so tracing swept funds is possible โ but the window narrows every hour funds keep moving.
If you hold BTC on affected ColdCard firmware: verify your firmware version and seed history, move funds to a newly generated wallet, and treat any exposed seed as permanently compromised โ never reuse it.
If funds are already gone, time-sensitive tracing is often the difference between a recoverable trail and one that goes cold. This is exactly the kind of case our team investigates daily.
#Bitcoin #SelfCustody #CryptoSecurity #BlockchainForensics #AssetRecovery
$17 billion was stolen from crypto users in 2025. Almost none of it through a smart contract bug.
Phishing. Compromised wallets. Insider threats. Social engineering that AI made 4.5 times more profitable last year.
An audit cannot stop someone clicking a convincing link. So we stopped pretending prevention was the whole job.
Hashlock is now partnered with @tokenrecovery_ ๐
They trace stolen assets, run forensic investigations, preserve evidence, and support legal recovery. $5B+ traced. 300+ investigations. Court recognised expert witnesses with 20+ years across law enforcement.
We handle the before. They handle the after. Nothing falls in between.
๐ Full announcement: https://t.co/t7aPiZzJRu
"We recovered stolen USDT" sounds like a heist reversed.
It isn't. It's a freeze, a burn, and a refund โ all built into Tether's own smart contract, matching to the last decimal.
Our investigator, Guglielmo Anfossi, breaks down how it actually works ๐งต๐
@tether
https://t.co/x3ZQGyPyi7
#BlockchainForensics #CryptoRecovery #USDT #Tether #Web3Security
"The funds entered a Bitcoin mixer. Further tracing is not possible."
That's where most investigations stop.
Ours didn't.
Instead of chasing individual transactions, we used mathematical constraints and wallet clustering to identify the wallet cluster responsible for moving thousands of stolen BTC through a mixer.
Sometimes the blockchain tells the story.
Sometimes the numbers do.
Read more:
https://t.co/7oWgGqur9t
#Bitcoin #BlockchainForensics #CryptoRecovery
We are proud to have contributed to @GBBC_ioโs 101 Real-World Blockchain Use Cases Handbook (2026 Edition) as use case #71.
This Handbook is a valuable reference guide for government agencies, regulators, and central banks, providing an educational resource to deepen their understanding of blockchain & digital assets.
Learn more๐
https://t.co/BioSblCIBX
#GBBC
โ๏ธ Heading to @BTCPrague 2026 this week (June 11โ13) at the PVA Expo Prague ๐จ๐ฟ
Looking forward to connecting with people from across the Bitcoin and digital asset space, hearing fresh perspectives, and having some great conversations about where the industry is heading.
๐ Heading up a blockchain forensics company means I spend a lot of time helping organisations navigate the challenges of an increasingly complex crypto ecosystem.
Events like BTC Prague are a great opportunity to learn, share insights, and meet the people building the future of the industry.
๐โ๏ธ If you're attending, feel free to reach out. It would be great to grab a coffee โ and chat about bitcoin:native, blockchain, investigations, compliance, security, or whatever is top of mind for you.
See you in Prague! ๐
#BTCPrague #BTCPrague2026 #Bitcoin #Blockchain #Crypto #BlockchainForensics #CryptoInvestigations #CryptoCompliance #BlockchainAnalytics #DigitalAssets #CyberSecurity
Last week our team โ Scott Pounder, Rob Moore and Darya Akry โ attended the @nordicblock conference in Stockholm. Two days of panels and conversations that reinforced what we see in our casework every day. Here is what stood out.
๐ด THE SCALE OF THE PROBLEM
โ Damages from cybercrime last year were $9.5 trillion. If cybercrime were an economy, it would be the third largest in the world after the US and China. โ
The global AML system spends half a trillion dollars a year at an efficiency rate of 0.02%. The traditional tools are not keeping up โ and crypto has become a preferred channel for moving the proceeds.
๐ต HOW CRYPTO CRIME IS EVOLVING
Around 60% of illicit crypto activity now flows through stablecoins โ fast, cheap, and hard to freeze. Laundering techniques are increasingly automated and programmatic, executed across hundreds of intermediary addresses with minimal human involvement.
โ In the age of AI, where you can instruct an agent to conduct transactions on your behalf โ this is only going to become more commonplace. โ
๐ก COMPLIANCE IS RISING ACROSS THE BOARD
AMLR, DAC8, MiCA, and the Travel Rule are collectively raising the bar on KYC, source-of-wealth, and transaction transparency across the EU. Anonymous accounts are being phased out. DAC8 reporting is live for 2026. The window to get ahead of this is narrowing.
For law firms, exchanges, and financial institutions โ blockchain evidence and transaction reconstruction are no longer just for litigation. They are becoming part of routine compliance.
๐ข WHERE WE COME IN
Blockchain analytics doesn't stop crime. What it does is: when crypto has been stolen, you can track where it's gone and the blockchain doesn't forget.
That is what we do. We work with hack and fraud victims, law firms, and financial institutions to trace stolen assets, reconstruct transaction histories, and build court-ready evidence packages.
The Nordic market is growing fast. If crypto recovery, investigations, or source-of-wealth challenges are part of your world โ we would like to talk.
#TokenRecovery #BlockchainForensics #CryptoRecovery #CryptoCompliance #FinancialCrime #AssetRecovery #NordicBlockchainConference #NBC2026 #Web3
Stockholm. Next week. Let's go. ๐ธ๐ช
Token Recovery will be at @nordicblock Conference 2026 โ Scott Pounder, Rob Moore, and Darya Akry representing the team.
If you're an exchange, custodian, law firm, compliance team, or investigator โ let's talk.
Every transaction leaves a trace. We find it. Come talk.
๐ 26โ27 May ยท Stockholm
๐ https://t.co/UFjsIOIs4P
#NBC2026 #NordicBlockchain #CryptoRecovery #BlockchainForensics #CryptoCrime
$624,000,000 stolen. 25 protocols hacked. 30 days.
This is the worst month in DeFi history.
Here's what happened, why it keeps happening, and what to do if you were hit. ๐
โโโ
๐ช๐ต๐ฎ๐ ๐ต๐ฎ๐ฝ๐ฝ๐ฒ๐ป๐ฒ๐ฑ
@KelpDAO โ $293M
@DriftProtocol โ $285M (social engineering operation)
@rhea_finance โ $18.4M
Grinex โ $15M
+ 21 more protocols.
Two exploits alone wiped out 93% of the total. KelpDAO's token losing its peg also created domino effect.
โโโ
๐ช๐ต๐ ๐ถ๐ ๐ธ๐ฒ๐ฒ๐ฝ๐ ๐ต๐ฎ๐ฝ๐ฝ๐ฒ๐ป๐ถ๐ป๐ด
These attacks aren't random. The largest are carried out by organized, government-backed groups with professional laundering operations โ attribution for the KelpDAO and Drift attacks points to a North Korean-linked unit. The rest exploit predictable gaps:
โ Smart contract logic errors
โ Flash loan and oracle manipulation
โ Cross-chain bridge vulnerabilities
โ Access control and social engineering flaws
By the time a team responds, funds are already moving.
โโโ
๐๐ณ ๐๐ผ๐ ๐๐ฒ๐ฟ๐ฒ ๐ฎ๐ณ๐ณ๐ฒ๐ฐ๐๐ฒ๐ฑ โ ๐ฑ๐ผ ๐๐ต๐ถ๐ ๐ป๐ผ๐
1. Revoke all wallet spending permissions and/or move the funds to a secure wallet immediately
2. Document every interaction resulting in the loss of funds
3. Request exchange freezes โ CEXs can freeze stolen funds; however, the ultimate destination of funds is often unknown. We inform clients that if stolen assets reach exchanges, there may be an opportunity to freeze them.
4. Get on-chain forensics started, but time is of the essence; funds can be traced across bridges and exchanges
The first 72 hours are everything.
โโโ
Recovery chances depend heavily on who attacked you. Opportunistic hackers have returned funds for bounties. Organized state-backed groups are a different story entirely โ be cautious of fake recovery scams
If you or your team were affected by any of these incidents, reach out directly. The sooner we engage, the better the outcome.
#DeFi #CryptoSecurity #Web3 #TokenRecovery #BlockchainSecurity
DeFi security is no longer just a smart contract problem โ itโs a human problem.
The latest losses in web3 show a clear pattern: attackers are increasingly exploiting social engineering, weak operational controls, compromised infrastructure, and cross-chain validation gaps rather than breaking code alone.
For blockchain forensics teams, this is a critical shift. Once funds move, the priority is no longer only tracing transactions โ itโs understanding how the compromise happened, where controls failed, and how similar patterns can be detected earlier.
Audits still matter, but they are not enough on their own. The future of DeFi security must combine code review with operational hardening, continuous monitoring, and forensic preparedness.
#BlockchainForensics #DeFiSecurity #Web3Security #CryptoInvestigation #OperationalRisk #OnChainAnalysis Token Recovery