Investigative Methodology
Our investigation methodology: on-chain forensics, OSINT, source corroboration, anonymization.
On-chain forensics
Every investigation starts on the ledger, not on social media. We trace the deployer wallet, the funding hops, the approval calls and the cash-out path across explorers, and we only publish loss figures we can reconstruct transaction by transaction. Where a contract is involved we read the bytecode or the verified source and quote the exact function that traps the victim.
Two independent sources before publication
A case reaches draft only with two independent sources plus on-chain proof: an incident report or security post from one side, and a verifiable transaction, contract or domain record from the other. Single-source claims, unverified screenshots and forwarded Telegram rumours stay in the queue until they can be corroborated or they are dropped.
Anonymisation rules
Victims are never identifiable. Real names, handles and full addresses are masked (0x1234...abcd), amounts are rounded where precision could dox someone, and attacker infrastructure is described without turning the report into a how-to. We name protocols and contracts, not private individuals.
Corrections and updates
Loss totals and case status change as recoveries or new tracing land. When we revise a figure we log a public "Updated <date> — reason" line on the investigation instead of silently editing it, and material errors are corrected at the top of the page. Editorial contact: cryptostrapon@proton.me.
AI assistance, human accountability
AI helps us summarise transaction sets and draft structure; it never decides what is true. A human editor from the Cryptostrapon Desk verifies every claim, source and number before a story goes live, and the desk is the author of record for everything we publish.
Visit https://cryptostrapon.com/methodology with JavaScript enabled for the full interactive experience.