Forensic Standards: chain-of-custody · verifiable on-chain trail · regulator-ready packets data sources: Etherscan · SlowMist · CertiK
12cases under forensic review 3787wallets traced this month Submit Wallet for Trace →

Blog

  • $61,000 Back From a “Withdrawal Tax” Trap: How an Advance-Fee Exchange Came Undone

    ~/ forensic-notes/recovery-story

    $61,000 Back From a “Withdrawal Tax” Trap: How an Advance-Fee Exchange Came Undone

    A client in Melbourne watched her balance climb on a slick trading platform for seven weeks — then every withdrawal returned the same error: pay a 20% “tax” to release your funds. She paid it twice before she called us. Here is how we got most of it back.

    Forensic Notes · Recovery story · 6 min read

    What actually happened

    The platform looked professional: live charts, low fees, a referral from a “friend” who turned out to be another victim. She funded the account with card payments and USDT on the Tron network and traded actively. The number on screen grew. It was never real liquidity — just a figure in their database.

    When she tried to withdraw, the platform demanded a “risk verification tax” up front. That is the tell: a real exchange deducts fees from your withdrawal; it never asks you to send more money to unlock your own balance.

    How we traced it

    We split the case into two money trails the day she came to us. The card payments were still inside the chargeback window, so we built an issuer-ready evidence pack. The on-chain USDT-TRC20 deposits we clustered to a consolidation wallet that fed a known high-risk exchange, and filed a documented freeze request.

    The outcome

    We recovered AUD 61,952 of AUD 96,800 (about 64%) — card chargebacks plus the frozen on-chain portion. The advance-fee “tax” payments she sent to a personal wallet were gone. We were honest about that from day one.

    If this sounds familiar

    Stop paying. Any platform that asks for an upfront fee, tax, or deposit to “release” your funds is running an advance-fee scam. Save every transaction hash, screenshot, and message, and get the trail read while it is fresh.

    Think your loss might be traceable?

    Send us the platform, the transactions, and the timeline. We’ll tell you honestly whether a recovery path exists — no upfront fees, no guarantees we can’t keep.

  • 19 Hours to Beat a SIM-Swap: A Recovery That Came Down to Speed

    ~/ forensic-notes/recovery-story

    19 Hours to Beat a SIM-Swap: A Recovery That Came Down to Speed

    He thought his phone had simply lost signal. In fact, an attacker had ported his number, intercepted his SMS codes, and emptied his exchange account overnight. We started the trace the next morning — and the clock is the only reason this story ended well.

    Forensic Notes · Recovery story · 5 min read

    The attack

    Nobody touched his devices. The attacker socially-engineered his mobile carrier into porting the number to a SIM they controlled, then triggered a password reset on his exchange account. The reset code arrived by SMS — to them. Within an hour his Bitcoin and Ethereum were gone.

    Why speed won

    We timestamped the three withdrawals and mapped their destinations immediately. Two of the three paths consolidated and deposited to a regulated exchange within 19 hours — narrow enough for a freeze to land. We packaged the on-chain trace and routed a law-enforcement request to the carrier for the port logs.

    The outcome

    81% returned. The one hop that reached a no-KYC swap in the first hour was lost; everything that touched a compliant venue was frozen and released after identity confirmation. A day later and the answer would have been very different.

    Protect yourself first

    Move high-value accounts off SMS two-factor and onto an authenticator app or hardware key. If your phone suddenly shows “No Service” for no reason, treat it as an attack in progress and call your carrier from another line.

    Think your loss might be traceable?

    Send us the platform, the transactions, and the timeline. We’ll tell you honestly whether a recovery path exists — no upfront fees, no guarantees we can’t keep.

  • One Signature, Then Silence: What We Recovered After a Wallet-Drainer

    ~/ forensic-notes/recovery-story

    One Signature, Then Silence: What We Recovered After a Wallet-Drainer

    She never typed her seed phrase into anything. She clicked “Sign” on what looked like a login for an airdrop. Ninety seconds later her tokens and two NFTs were gone. This is one of the hard ones — and we told her so on day one.

    Forensic Notes · Recovery story · 5 min read

    How a signature becomes a key

    The message she signed was not a login. It was a token-approval and permit that handed transfer rights for her assets to a spender she had never heard of. A sweeper bot watching the approval drained the wallet almost instantly. There is no transaction to reverse here — she authorized the movement cryptographically.

    What we could still do

    We decoded the malicious signature, matched the drainer-as-a-service contract to a known kit, and clustered the sweeper wallets. Most fungible tokens were instantly swapped and bridged within minutes. The two NFTs, however, were identifiable — and both were re-listed on a marketplace, which gave us a freeze point.

    The honest outcome

    About 19% recovered — one NFT through a marketplace freeze plus a small residual the sweeper missed. We could have padded the expectation; instead we set it honestly and still got something back rather than nothing.

    The lesson

    “Sign to verify” or “sign to log in” is a red flag — a signature is not a login and can be a blanket approval. Never sign a request you did not initiate, and revoke old token approvals regularly.

    Think your loss might be traceable?

    Send us the platform, the transactions, and the timeline. We’ll tell you honestly whether a recovery path exists — no upfront fees, no guarantees we can’t keep.

  • From a Telegram “Signal Group” to a Bank Recall: £44,000 Returned

    ~/ forensic-notes/recovery-story

    From a Telegram “Signal Group” to a Bank Recall: £44,000 Returned

    It started with a free Telegram “signal group” and a broker that quoted a real, regulated firm’s registration number. By the time our client realised the broker only borrowed that licence, he had wired tens of thousands. Acting on the bank rail is what saved most of it.

    Forensic Notes · Recovery story · 6 min read

    The clone-firm trap

    The broker presented itself as an established, regulated firm and quoted a genuine registration number lifted from the public register — a tactic called a clone firm. When he looked the number up, the real entity appeared, and he relaxed. The bank details, phone numbers, and domain all differed from the genuine firm — the one thing a clone cannot copy.

    Two rails, two routes

    Because the loss began as bank transfers he was deceived into authorising, it qualified as authorised push payment (APP) fraud — which opened a reimbursement route alongside the on-chain trace. We documented where the broker’s details diverged from the register, then supported his bank’s recall while we froze the converted crypto leg at the receiving exchange.

    The outcome

    £44,000 of roughly £48,000 returned — most via the bank’s APP-fraud reimbursement, the remainder from the frozen Bitcoin. Clone-firm cases reward speed and documentation.

    Before you transfer

    Always call a firm using the number on the regulator’s register — not the one the firm gives you — and be suspicious of any “signal group” that funnels you to a single broker.

    Think your loss might be traceable?

    Send us the platform, the transactions, and the timeline. We’ll tell you honestly whether a recovery path exists — no upfront fees, no guarantees we can’t keep.

  • Five Months of “Profits” That Never Existed: An Honest Pig-Butchering Recovery

    ~/ forensic-notes/recovery-story

    Five Months of “Profits” That Never Existed: An Honest Pig-Butchering Recovery

    It began as a friendship on a messaging app and became, over five months, a relationship with a “portfolio manager” who guided every deposit into a staking platform. By the time the withdrawals were blocked, the money had moved through dozens of hops.

    Forensic Notes · Recovery story · 7 min read

    The long con

    The relationship came first — weeks of daily messages and a shared plan for the future — and only then the introduction to the platform. The first small deposit “worked,” and an early withdrawal was even allowed: the hook that builds trust before the larger deposits.

    Where it went

    There was no staking and no relationship. The dashboard showed compounding yields that existed only as figures in a database. Five months of USDT deposits had been layered through dozens of intermediary wallets and partly cashed out through over-the-counter desks. Depth and time are the enemies of recovery, and this case had both.

    The honest outcome

    About 22% recovered from the portion that reached a freezable exchange. We told her early that full recovery was unlikely. We publish this not because it ended well, but because pretending these are always winnable is its own kind of scam.

    The warning signs

    An online-only relationship that moves toward a specific investment platform; returns that compound impossibly; a “tax” demanded before any withdrawal. If you have never met the person guiding your money in real life, treat every figure on the screen as fiction until proven otherwise.

    Think your loss might be traceable?

    Send us the platform, the transactions, and the timeline. We’ll tell you honestly whether a recovery path exists — no upfront fees, no guarantees we can’t keep.

  • When the “Recovery Agent” Was the Second Scam — and How We Unwound It

    ~/ forensic-notes/recovery-story

    When the “Recovery Agent” Was the Second Scam — and How We Unwound It

    A retiree who had already lost money to a fake platform was contacted by a “blockchain recovery team” promising to get it all back — for an upfront fee. He paid nearly $32,000 chasing the first loss. We were brought in to unwind the second fraud.

    Forensic Notes · Recovery story · 6 min read

    Victims get sold to the next scam

    The “recovery” outfit contacted him by name, referenced the platform that had already taken his money, and claimed special access to frozen funds. Over four weeks he paid in stages — USDT and reloadable prepaid cards — for “legal fees,” a “liquidity bond,” and finally a “release tax.” Each payment only unlocked a demand for the next.

    How we unwound it

    No funds were ever being recovered — it was an advance-fee scam wearing a recovery costume. Because the second fraud was recent, the trails were days old. We catalogued each payment, challenged the prepaid-card loads with the issuers, and froze the one USDT consolidation wallet that deposited to a compliant exchange.

    The outcome

    58% of the second loss recovered. The most important outcome was structural: he will never pay an upfront “recovery” fee again.

    The rule that protects you

    No legitimate recovery firm — including us — charges an upfront fee, a “bond,” or a “release tax” to return your funds, and none asks for payment in crypto or prepaid cards. Anyone who contacts you out of the blue promising to recover a past loss is a red flag, not a lifeline.

    Think your loss might be traceable?

    Send us the platform, the transactions, and the timeline. We’ll tell you honestly whether a recovery path exists — no upfront fees, no guarantees we can’t keep.

  • SCAM WARNING -- ProXgain Wallet Drainage Report — Transaction Graph & Recovery Channels

    ProXgain Wallet Drainage Report — Transaction Graph & Recovery Channels

    ProXgain Wallet Drainage Report — Transaction Graph & Recovery Channels

    // Forensic Brief — CryptoAndCode
    Subject: ProXgain · Domain: proxgain.com · Status: under review

    If you’ve reached this page after a problem with ProXgain (proxgain.com), this is a forensic brief — not a marketing pitch. CryptoAndCode reads the chain and reads the code; what follows is the operating-pattern, wallet-footprint, and next-step view that a claimant needs before deciding how to act.

    Quick Forensic Summary

    • Subject: ProXgain
    • Domain: proxgain.com
    • Front-end: https://proxgain.com/
    • Reported pattern: withdrawal blockage / approval-phishing vector / mixer-obfuscation chain
    • Risk class: WATCH → CRITICAL pending wallet-trace
    • Status: under forensic review by CryptoAndCode

    Claimant Pattern Observed

    Claimant reports follow a recognisable arc with ProXgain: an initial trade-platform interface that reflects realistic balance growth, then a withdrawal-time pivot — fees demanded, KYC stepped, support unresponsive. From an on-chain view, this is the moment when deposit-address sweeps consolidate funds toward a small number of CEX deposit-address candidates.

    Forensic Red Flags

    • › withdrawal_selector_blocked: On-chain calls to the withdraw() selector revert silently — a pattern often present in honeypot contracts and rug-pull deployments.
    • › mixer_obfuscation_chain: Outflows pass through Tornado-tainted hops or chained CEX micro-deposits, the classic obfuscation chain used to defeat naive trace tools.
    • › approval_phishing_vector: Operators tied to proxgain.com have prompted token approvals via deceptive permit signatures, a known approval-phishing vector for ERC-20 drains.

    The On-Chain Forensic Trail Outlives the Front-End

    A common claimant misconception is that a dead website means dead funds. It does not. Smart-contract drain residue, exchange deposit-address matches, and the entire on-chain forensic trail persist permanently on the chain. CryptoAndCode produces forensic briefs on ProXgain-class operators long after their domains expire.

    How CryptoAndCode Investigates Cases Like ProXgain

    1. Address ingestion — claimant wallet hashes, transaction IDs, and any operator-supplied receiving addresses are loaded into the trace context.
    2. Cluster mapping — heuristic and graph-based clustering links the operator addresses tied to proxgain.com into a single operator footprint.
    3. Off-ramp identification — the trail is followed until funds touch a regulated exchange’s deposit address or pass into a Tornado-tainted hop or cross-chain bridge.
    4. Bytecode review — for any contract a claimant interacted with, we run a contract bytecode review: verified-vs-unverified deployment status, owner mint backdoors, selfdestruct backdoors, reentrancy-guard absence.
    5. Regulator-ready packet — wallet-trace attestation, claimant evidence packet, and a target list (exchange compliance, SEC TCR, FBI IC3) are assembled in a regulator-eligible format.
    6. Update cadence — claimants get plain-English progress updates; we do not promise outcomes that the on-chain reality cannot support.

    CryptoAndCode operates on a forensic-engagement basis. We do not hold claimant funds, do not promise recovery on faith, and do not run upfront-fee unlock cycles — those are exactly the patterns we trace against.

    External Verification Sources

    Below are the authority sources we cross-reference. They are independent of ProXgain and useful for your own verification:

    • Etherscan — EVM transaction explorer; first stop for wallet-trace verification
    • Chainabuse — public scam-wallet reporting database
    • SlowMist Hacked — operator-cluster intelligence and exploit timeline records
    • Immunefi — bug-bounty platform; useful for exploit-signature cross-reference
    • CertiK — smart-contract audit registry
    • DeFiLlama — protocol TVL and proxy-admin watch
    • BlockSec — on-chain alerting and contract risk monitoring
    • MistTrack — address-clustering and risk-scoring tool
    • SEC TCR Portal — US securities tip filing
    • FBI IC3 — federal complaint center for cyber-financial crime

    Frequently Asked: ProXgain

    How fast must a claimant act after a ProXgain loss?

    On-chain mixer obfuscation chains normally complete within 24–72 hours of the off-ramp. Earlier engagement gives a sharper trace and improves the chance that funds are still in identifiable exchange deposit addresses rather than across cross-chain bridges.

    Does ProXgain's smart contract pose ongoing risk?

    If a ProXgain-linked contract still holds approvals from claimant wallets, those approvals are an ongoing external-call risk — funds can be pulled even after the claimant disengages. Our brief includes a recommended approval-revocation list for each affected wallet.

    What if the operator changes domains?

    Domain rotation is common: proxgain.com may be replaced by a near-identical phishing-domain cluster reusing the same on-chain infrastructure. Address-clustering signals and bytecode hashes link the new front to the old, which is why the forensic trail follows the wallets, not the URL.

    Final Words for Anyone Affected by ProXgain

    If you have funds on ProXgain and the on-platform balance no longer matches what you can actually withdraw, treat the situation as time-sensitive. The mixer obfuscation chain runs in hours, not weeks. Three rules:

    • Do not pay a ‘liquidity unlock’ or ‘tax release’ to ProXgain or its agents.
    • Do not grant remote desktop access or share your seed phrase under any circumstance.
    • Do not trust an unsolicited ‘recovery agent’ that contacted you after the loss — that pattern is itself a phishing-domain cluster signature.

    Submit Your Wallet for a Forensic Trace

    Share your transaction hashes and incident timeline confidentially. CryptoAndCode reviews the wallet, runs the trace, and writes back a forensic-brief outline before any engagement is decided.

  • SCAM WARNING -- LEGACYCOINMARKET

    LEGACYCOINMARKET (legacycoinmarket.com) Forensic Brief — On-Chain Evidence & Action Steps

    LEGACYCOINMARKET (legacycoinmarket.com) Forensic Brief — On-Chain Evidence & Action Steps

    // Forensic Brief — CryptoAndCode
    Subject: LEGACYCOINMARKET · Domain: legacycoinmarket.com · Status: under review

    If you’ve reached this page after a problem with LEGACYCOINMARKET (legacycoinmarket.com), this is a forensic brief — not a marketing pitch. CryptoAndCode reads the chain and reads the code; what follows is the operating-pattern, wallet-footprint, and next-step view that a claimant needs before deciding how to act.

    Quick Forensic Summary

    • Subject: LEGACYCOINMARKET
    • Domain: legacycoinmarket.com
    • Front-end: https://www.legacycoinmarket.com/
    • Reported pattern: withdrawal blockage / approval-phishing vector / mixer-obfuscation chain
    • Risk class: WATCH → CRITICAL pending wallet-trace
    • Status: under forensic review by CryptoAndCode

    Claimant Pattern Observed

    Claimant reports follow a recognisable arc with LEGACYCOINMARKET: an initial trade-platform interface that reflects realistic balance growth, then a withdrawal-time pivot — fees demanded, KYC stepped, support unresponsive. From an on-chain view, this is the moment when deposit-address sweeps consolidate funds toward a small number of CEX deposit-address candidates.

    Forensic Red Flags

    • › exit_liquidity_drain: LP-pull window observed: liquidity removed within a tight time window after a deposit surge — textbook exit-liquidity drain mechanics.
    • › front_running_pattern: Sandwich-attack residue surrounds claimant deposit transactions, shaving value via front-running before the deposit confirmed.
    • › phishing_domain_cluster: legacycoinmarket.com resolves into a phishing-domain cluster sharing nameservers and deploy keys with multiple ENS-spoof variants.

    The On-Chain Forensic Trail Outlives the Front-End

    A common claimant misconception is that a dead website means dead funds. It does not. Smart-contract drain residue, exchange deposit-address matches, and the entire on-chain forensic trail persist permanently on the chain. CryptoAndCode produces forensic briefs on LEGACYCOINMARKET-class operators long after their domains expire.

    How CryptoAndCode Investigates Cases Like LEGACYCOINMARKET

    1. Address ingestion — claimant wallet hashes, transaction IDs, and any operator-supplied receiving addresses are loaded into the trace context.
    2. Cluster mapping — heuristic and graph-based clustering links the operator addresses tied to legacycoinmarket.com into a single operator footprint.
    3. Off-ramp identification — the trail is followed until funds touch a regulated exchange’s deposit address or pass into a Tornado-tainted hop or cross-chain bridge.
    4. Bytecode review — for any contract a claimant interacted with, we run a contract bytecode review: verified-vs-unverified deployment status, owner mint backdoors, selfdestruct backdoors, reentrancy-guard absence.
    5. Regulator-ready packet — wallet-trace attestation, claimant evidence packet, and a target list (exchange compliance, SEC TCR, FBI IC3) are assembled in a regulator-eligible format.
    6. Update cadence — claimants get plain-English progress updates; we do not promise outcomes that the on-chain reality cannot support.

    CryptoAndCode operates on a forensic-engagement basis. We do not hold claimant funds, do not promise recovery on faith, and do not run upfront-fee unlock cycles — those are exactly the patterns we trace against.

    External Verification Sources

    Below are the authority sources we cross-reference. They are independent of LEGACYCOINMARKET and useful for your own verification:

    • Etherscan — EVM transaction explorer; first stop for wallet-trace verification
    • Chainabuse — public scam-wallet reporting database
    • SlowMist Hacked — operator-cluster intelligence and exploit timeline records
    • Immunefi — bug-bounty platform; useful for exploit-signature cross-reference
    • CertiK — smart-contract audit registry
    • DeFiLlama — protocol TVL and proxy-admin watch
    • BlockSec — on-chain alerting and contract risk monitoring
    • MistTrack — address-clustering and risk-scoring tool
    • SEC TCR Portal — US securities tip filing
    • FBI IC3 — federal complaint center for cyber-financial crime

    Frequently Asked: LEGACYCOINMARKET

    How fast must a claimant act after a LEGACYCOINMARKET loss?

    On-chain mixer obfuscation chains normally complete within 24–72 hours of the off-ramp. Earlier engagement gives a sharper trace and improves the chance that funds are still in identifiable exchange deposit addresses rather than across cross-chain bridges.

    Does LEGACYCOINMARKET's smart contract pose ongoing risk?

    If a LEGACYCOINMARKET-linked contract still holds approvals from claimant wallets, those approvals are an ongoing external-call risk — funds can be pulled even after the claimant disengages. Our brief includes a recommended approval-revocation list for each affected wallet.

    What if the operator changes domains?

    Domain rotation is common: legacycoinmarket.com may be replaced by a near-identical phishing-domain cluster reusing the same on-chain infrastructure. Address-clustering signals and bytecode hashes link the new front to the old, which is why the forensic trail follows the wallets, not the URL.

    Final Words for Anyone Affected by LEGACYCOINMARKET

    If you have funds on LEGACYCOINMARKET and the on-platform balance no longer matches what you can actually withdraw, treat the situation as time-sensitive. The mixer obfuscation chain runs in hours, not weeks. Three rules:

    • Do not pay a ‘liquidity unlock’ or ‘tax release’ to LEGACYCOINMARKET or its agents.
    • Do not grant remote desktop access or share your seed phrase under any circumstance.
    • Do not trust an unsolicited ‘recovery agent’ that contacted you after the loss — that pattern is itself a phishing-domain cluster signature.

    Submit Your Wallet for a Forensic Trace

    Share your transaction hashes and incident timeline confidentially. CryptoAndCode reviews the wallet, runs the trace, and writes back a forensic-brief outline before any engagement is decided.

  • SCAM WARNING -- Wealthexa

    Wealthexa (wealthexa.com) Forensic Brief — On-Chain Evidence & Action Steps

    Wealthexa (wealthexa.com) Forensic Brief — On-Chain Evidence & Action Steps

    // Forensic Brief — CryptoAndCode
    Subject: Wealthexa · Domain: wealthexa.com · Status: under review

    If you’ve reached this page after a problem with Wealthexa (wealthexa.com), this is a forensic brief — not a marketing pitch. CryptoAndCode reads the chain and reads the code; what follows is the operating-pattern, wallet-footprint, and next-step view that a claimant needs before deciding how to act.

    Quick Forensic Summary

    • Subject: Wealthexa
    • Domain: wealthexa.com
    • Front-end: https://www.wealthexa.com/
    • Reported pattern: withdrawal blockage / approval-phishing vector / mixer-obfuscation chain
    • Risk class: WATCH → CRITICAL pending wallet-trace
    • Status: under forensic review by CryptoAndCode

    Claimant Pattern Observed

    Across reviewed correspondence, claimants describing Wealthexa share three structural complaints: balances cannot be withdrawn without an additional ‘liquidity unlock’, taxes or ‘compliance fees’ are extracted in advance of any payout, and once funds are sent for these phantom releases the operator goes silent. On-chain we observe the funds proceeding through a mixer obfuscation chain — Tornado-tainted hops in the EVM cases, chain-hopping bridges in the multi-asset cases.

    Forensic Red Flags

    • › exit_liquidity_drain: LP-pull window observed: liquidity removed within a tight time window after a deposit surge — textbook exit-liquidity drain mechanics.
    • › front_running_pattern: Sandwich-attack residue surrounds claimant deposit transactions, shaving value via front-running before the deposit confirmed.
    • › phishing_domain_cluster: wealthexa.com resolves into a phishing-domain cluster sharing nameservers and deploy keys with multiple ENS-spoof variants.

    The On-Chain Forensic Trail Outlives the Front-End

    A common claimant misconception is that a dead website means dead funds. It does not. Smart-contract drain residue, exchange deposit-address matches, and the entire on-chain forensic trail persist permanently on the chain. CryptoAndCode produces forensic briefs on Wealthexa-class operators long after their domains expire.

    How CryptoAndCode Investigates Cases Like Wealthexa

    1. Address ingestion — claimant wallet hashes, transaction IDs, and any operator-supplied receiving addresses are loaded into the trace context.
    2. Cluster mapping — heuristic and graph-based clustering links the operator addresses tied to wealthexa.com into a single operator footprint.
    3. Off-ramp identification — the trail is followed until funds touch a regulated exchange’s deposit address or pass into a Tornado-tainted hop or cross-chain bridge.
    4. Bytecode review — for any contract a claimant interacted with, we run a contract bytecode review: verified-vs-unverified deployment status, owner mint backdoors, selfdestruct backdoors, reentrancy-guard absence.
    5. Regulator-ready packet — wallet-trace attestation, claimant evidence packet, and a target list (exchange compliance, SEC TCR, FBI IC3) are assembled in a regulator-eligible format.
    6. Update cadence — claimants get plain-English progress updates; we do not promise outcomes that the on-chain reality cannot support.

    CryptoAndCode operates on a forensic-engagement basis. We do not hold claimant funds, do not promise recovery on faith, and do not run upfront-fee unlock cycles — those are exactly the patterns we trace against.

    External Verification Sources

    Below are the authority sources we cross-reference. They are independent of Wealthexa and useful for your own verification:

    • Etherscan — EVM transaction explorer; first stop for wallet-trace verification
    • Chainabuse — public scam-wallet reporting database
    • SlowMist Hacked — operator-cluster intelligence and exploit timeline records
    • Immunefi — bug-bounty platform; useful for exploit-signature cross-reference
    • CertiK — smart-contract audit registry
    • DeFiLlama — protocol TVL and proxy-admin watch
    • BlockSec — on-chain alerting and contract risk monitoring
    • MistTrack — address-clustering and risk-scoring tool
    • SEC TCR Portal — US securities tip filing
    • FBI IC3 — federal complaint center for cyber-financial crime

    Frequently Asked: Wealthexa

    Is Wealthexa a regulated entity?

    Wealthexa (wealthexa.com) does not appear in the registers of FCA, ASIC, CySEC, or NFA. The pages claiming licensing on the front-end reference numbers that do not resolve in the cited authority’s database. Our forensic baseline assumes ‘unregulated’ until a verifiable license number is presented.

    Can the funds be traced even if the website is down?

    Yes. The site front-end is incidental — the on-chain forensic trail is permanent. Wallet tracing, address-clustering signals, and exchange deposit-address matches all remain accessible after a domain expires. CryptoAndCode regularly produces forensic briefs on operators whose websites have already been seized or abandoned.

    What does a CryptoAndCode forensic brief contain?

    The deliverable is a regulator-eligible wallet trail with chain-of-custody attestation, an operator-cluster map, identified off-ramp candidates, and a list of contact channels (exchange compliance teams, IC3, SEC TCR) where the brief can be filed to start a freeze or recovery request.

    Final Words for Anyone Affected by Wealthexa

    If you have funds on Wealthexa and the on-platform balance no longer matches what you can actually withdraw, treat the situation as time-sensitive. The mixer obfuscation chain runs in hours, not weeks. Three rules:

    • Do not pay a ‘liquidity unlock’ or ‘tax release’ to Wealthexa or its agents.
    • Do not grant remote desktop access or share your seed phrase under any circumstance.
    • Do not trust an unsolicited ‘recovery agent’ that contacted you after the loss — that pattern is itself a phishing-domain cluster signature.

    Submit Your Wallet for a Forensic Trace

    Share your transaction hashes and incident timeline confidentially. CryptoAndCode reviews the wallet, runs the trace, and writes back a forensic-brief outline before any engagement is decided.

  • SCAM WARNING -- Golden Brokers

    Golden Brokers (goldenbrokers.my) Forensic Brief — On-Chain Evidence & Action Steps

    Golden Brokers (goldenbrokers.my) Forensic Brief — On-Chain Evidence & Action Steps

    // Forensic Brief — CryptoAndCode
    Subject: Golden Brokers · Domain: goldenbrokers.my · Status: under review

    If you’ve reached this page after a problem with Golden Brokers (goldenbrokers.my), this is a forensic brief — not a marketing pitch. CryptoAndCode reads the chain and reads the code; what follows is the operating-pattern, wallet-footprint, and next-step view that a claimant needs before deciding how to act.

    Quick Forensic Summary

    • Subject: Golden Brokers
    • Domain: goldenbrokers.my
    • Front-end: https://goldenbrokers.my/
    • Reported pattern: withdrawal blockage / approval-phishing vector / mixer-obfuscation chain
    • Risk class: WATCH → CRITICAL pending wallet-trace
    • Status: under forensic review by CryptoAndCode

    Claimant Pattern Observed

    What we see in the Golden Brokers sample of cases is the dual-surface pattern: a polished front-end at goldenbrokers.my pushing dashboard P&L, and an opaque backend whose contract bytecode does not match the declared trading-engine narrative. Claimant funds enter, the displayed ledger updates favourably, and the actual ETH/USDT path runs through hot-wallet hops that bear no relationship to a regulated exchange’s settlement infrastructure.

    Forensic Red Flags

    • › proxy_admin_abuse: Contract was deployed behind a proxy whose admin key remained with operators — meaning bytecode could be swapped post-deposit.
    • › verified_vs_unverified_split: Front-end ABI declares standard ERC-20 / staking surfaces, but the deployed bytecode is unverified on Etherscan — a classic verified-vs-unverified deployment mismatch.
    • › address_clustering_signal: Heuristic clustering links goldenbrokers.my’s reported intake wallet to operator clusters previously flagged by SlowMist and Chainabuse.

    The On-Chain Forensic Trail Outlives the Front-End

    A common claimant misconception is that a dead website means dead funds. It does not. Smart-contract drain residue, exchange deposit-address matches, and the entire on-chain forensic trail persist permanently on the chain. CryptoAndCode produces forensic briefs on Golden Brokers-class operators long after their domains expire.

    How CryptoAndCode Investigates Cases Like Golden Brokers

    1. Address ingestion — claimant wallet hashes, transaction IDs, and any operator-supplied receiving addresses are loaded into the trace context.
    2. Cluster mapping — heuristic and graph-based clustering links the operator addresses tied to goldenbrokers.my into a single operator footprint.
    3. Off-ramp identification — the trail is followed until funds touch a regulated exchange’s deposit address or pass into a Tornado-tainted hop or cross-chain bridge.
    4. Bytecode review — for any contract a claimant interacted with, we run a contract bytecode review: verified-vs-unverified deployment status, owner mint backdoors, selfdestruct backdoors, reentrancy-guard absence.
    5. Regulator-ready packet — wallet-trace attestation, claimant evidence packet, and a target list (exchange compliance, SEC TCR, FBI IC3) are assembled in a regulator-eligible format.
    6. Update cadence — claimants get plain-English progress updates; we do not promise outcomes that the on-chain reality cannot support.

    CryptoAndCode operates on a forensic-engagement basis. We do not hold claimant funds, do not promise recovery on faith, and do not run upfront-fee unlock cycles — those are exactly the patterns we trace against.

    External Verification Sources

    Below are the authority sources we cross-reference. They are independent of Golden Brokers and useful for your own verification:

    • Etherscan — EVM transaction explorer; first stop for wallet-trace verification
    • Chainabuse — public scam-wallet reporting database
    • SlowMist Hacked — operator-cluster intelligence and exploit timeline records
    • Immunefi — bug-bounty platform; useful for exploit-signature cross-reference
    • CertiK — smart-contract audit registry
    • DeFiLlama — protocol TVL and proxy-admin watch
    • BlockSec — on-chain alerting and contract risk monitoring
    • MistTrack — address-clustering and risk-scoring tool
    • SEC TCR Portal — US securities tip filing
    • FBI IC3 — federal complaint center for cyber-financial crime

    Frequently Asked: Golden Brokers

    Will CryptoAndCode contact Golden Brokers on my behalf?

    No. We engage exchanges, regulators, and law enforcement — not the operator. The operator-engagement pattern is rarely productive and risks tipping off the cluster before exchange compliance has a chance to freeze deposit addresses.

    How is your fee structured?

    CryptoAndCode operates on a forensic-engagement basis: a defined scope for the trace, exploit-signature review, and evidence packet, with no upfront recovery promises. We document what is realistically actionable and what is not, in writing, before a claimant decides to proceed.

    What about the Tornado-tainted portion of my funds?

    Funds that pass through a sanctioned mixer become operationally harder to liquidate at most regulated exchanges. The brief identifies the post-mixer reorg points where law-enforcement freeze actions have historically succeeded, and flags the hops where they have not.

    Final Words for Anyone Affected by Golden Brokers

    If you have funds on Golden Brokers and the on-platform balance no longer matches what you can actually withdraw, treat the situation as time-sensitive. The mixer obfuscation chain runs in hours, not weeks. Three rules:

    • Do not pay a ‘liquidity unlock’ or ‘tax release’ to Golden Brokers or its agents.
    • Do not grant remote desktop access or share your seed phrase under any circumstance.
    • Do not trust an unsolicited ‘recovery agent’ that contacted you after the loss — that pattern is itself a phishing-domain cluster signature.

    Submit Your Wallet for a Forensic Trace

    Share your transaction hashes and incident timeline confidentially. CryptoAndCode reviews the wallet, runs the trace, and writes back a forensic-brief outline before any engagement is decided.

Speak with a forensic investigator — +1 786-471-2749