# Wallet Forensics Reference Guide

This guide supports authorized incident response, fraud triage, and compliance
investigations. Do not attempt to access wallets, seed phrases, private keys, or
accounts without explicit legal authority and owner consent.

## Intake Questions
- Which address, chain, wallet software, and approximate incident time are in scope?
- Is the wallet custodial, smart-contract based, hardware-backed, or browser-based?
- Are seed phrases, devices, logs, or screenshots available through consented collection?
- Are law enforcement, insurer, or exchange reporting deadlines involved?

## Evidence Sources
- Public chain transactions and token approvals.
- Wallet application logs exported by the owner.
- Browser extension install history and permissions.
- Device malware scans and recent downloads.
- Exchange deposit/withdrawal records supplied by the owner.

## Triage Workflow
1. Preserve the owner's narrative and timeline.
2. Identify all relevant addresses and chains.
3. Export transactions and token approvals.
4. Cluster counterparties by exchange, bridge, mixer, contract, or unknown.
5. Revoke risky approvals from a clean device if approved by the owner.
6. Prepare exchange/law-enforcement evidence packets when appropriate.

## Reporting Fields
| Field | Notes |
|---|---|
| Address | Full checksummed address |
| Chain | Ethereum, Polygon, Base, Solana, etc. |
| Transaction hash | Linkable public transaction ID |
| Direction | Inbound / outbound / approval / contract call |
| Counterparty | Known exchange, bridge, contract, or unknown |
| Confidence | High / medium / low with rationale |
