Digital Asset Investigations in Cyprus

    Crypto investigations for companies and boards

    When an organisation needs to know what actually happened.

    Cryptocurrency fraud investigations for companies, exchanges and VASPs, funds, insolvency practitioners, boards, insurers, and the law firms that instruct on their behalf. A scoped, confidential engagement that combines on-chain evidence with internal records, corporate structures, documents, and interviews, and ends in a written report you can act on.

    Is an investigation what you need?

    An investigation answers a question about people and conduct: what happened, who was involved, and what the evidence supports. That is a different question from where the money went, and it needs more than a blockchain. If your question is purely about funds, you want transaction tracing. If you are a victim of theft and you want the value back, start with crypto asset recovery. If proceedings are already running and you need an independent opinion for the court, you want an expert witness. An investigation is the engagement you commission when something has gone wrong inside or around an organisation, nobody yet knows the shape of it, and a decision has to be taken about people, money, or disclosure.

    Investigations We Are Engaged For

    The trigger is usually a number that will not reconcile, a compliance alert, a whistleblower, or a counterparty that has stopped answering. What follows is the same discipline in each case: establish the facts before anyone acts on an assumption.

    Internal fraud & insider misappropriation

    A suspicion that an employee, contractor, or officer has diverted digital assets, abused treasury or wallet access, or manipulated records to hide it. Often surfaces as a reconciliation that will not close.

    Partner, counterparty & supplier fraud

    Value paid away against fabricated invoices, undisclosed related parties, or a counterparty whose stated business does not match its on-chain behaviour. Frequently involves entities in several jurisdictions.

    Platform & project failure

    Examining a platform or token project before committing to it, or reconstructing what happened after it collapsed: where user funds went, when the shortfall began, and who was directing the movements.

    Insolvency asset identification

    Work for office holders and creditors: identifying digital assets belonging to the estate, reconstructing transfers made before the relevant date, and separating estate property from personal holdings.

    Sanctions & AML breach investigations

    A hit, an alert, or an audit finding suggests exposure a firm should not have taken. We establish what actually occurred, over what period, how it passed controls, and what the records show.

    Pre-transaction due diligence

    Examining a person, company, or project before an acquisition, an investment, an onboarding decision, or a senior hire. Corporate history, adverse findings, and the on-chain record behind the claims.

    How an Investigation Is Governed

    Two decisions in the first week determine whether the findings can be relied on later: who the investigator reports to, and how the evidence is handled.

    Reporting lines and independence

    Whoever engages us should sit outside the conduct being examined. In practice that is the board, the audit or risk committee, a non-executive director, or the organisation's external lawyers instructing on the client's behalf. Where management is within scope, management should not set the scope, direct the work, or see findings first. We agree the reporting line and the distribution list in writing before starting, run a conflict check, and confirm the questions we are being asked. None of this implies anything about the people involved. It is what stops a reasonable finding being dismissed later on the grounds that the investigator was reporting to the person under examination.

    Confidentiality and chain of custody

    Work proceeds on a need-to-know basis, with material in access-controlled storage and correspondence limited to named recipients. Evidence is recorded from the point of collection: what was taken, when, from where, by whom, and how it has been held since. On-chain material is captured at a fixed point and remains verifiable at source. Sequencing matters as much as security. Preserving records, logs, and access before any subject becomes aware of the engagement is usually the difference between a complete evidence set and a partial one, because deletion and asset movement start the moment word gets out.

    On-Chain Evidence, and Everything Around It

    The blockchain shows movement. It does not show authorisation, intent, or who was at the keyboard. Those come from the records the organisation already holds, and from the people who were there.

    On-chain records

    Wallet and transaction history across the major chains, address clustering, bridges, swaps, and off-ramps. Permanent, public, and verifiable at source, which makes it the most durable evidence in most cases.

    Exchange & custodian records

    Account statements, deposit and withdrawal history, and identity material held by regulated venues. Obtained through the client, through their lawyers, or through the authorities. We do not obtain it by any other route.

    Internal systems & documents

    Accounting ledgers, treasury and wallet approvals, access logs, contracts, board minutes, and email where the organisation lawfully holds it and has a proper basis to review it.

    Corporate & banking material

    Company filings, ownership and directorship records, group structures, and bank statements where available. Digital asset fraud almost always touches a company and a bank account somewhere.

    Open-source intelligence

    Registries, court and insolvency records, sanctions and adverse media, domain and infrastructure data, and the public footprint of the people and projects involved. Gathered from public sources only.

    Interviews

    Structured conversations with staff and third parties who agree to speak, conducted after the documentary and on-chain evidence is in hand rather than before, and recorded in a written note.

    The on-chain analysis itself is our transaction tracing capability, run inside the investigation rather than sold as a separate exercise.

    How an Investigation Runs

    Scope, reporting line, and distribution agreed in writing before any work starts. Scope can change as findings emerge, but it changes by instruction, not by drift.

    01

    Instruction & scoping

    You tell us the concern and who is engaging. We run a conflict check, agree the questions in writing, fix the reporting line, and set the distribution list before any work begins.

    02

    Evidence preservation

    Securing what could be lost first: system access, logs, devices, records, and the on-chain position as at a fixed point. This happens before anyone in scope is aware of the engagement.

    03

    Analysis & corroboration

    On-chain tracing run against internal records, banking material, and corporate structures. A finding is not a finding until it is supported from more than one direction.

    04

    Interim findings

    We report to the engaging party as material issues emerge rather than holding everything to the end, so decisions about people, systems, and disclosure can be taken in time to matter.

    05

    Report & handover

    A written report with findings, evidence schedules, chain of custody, and stated limitations. Handed to whoever was named at the outset, with a briefing if the recipients want one.

    Interim findings, the report, and privilege

    We report material issues as they emerge rather than saving everything for the end. Boards usually have to make decisions before an investigation closes: whether to suspend access, whether to preserve a claim, whether something has to be disclosed to a regulator, an insurer, or a counterparty. Interim findings are given for that purpose and are clearly marked as provisional, because early readings do change once further evidence arrives.

    The final report sets out the instructions and the agreed scope, the material examined and how it was obtained, the methodology, the findings with the evidence supporting each one, and the limitations. Evidence schedules and flow-of-funds exhibits are annexed. We separate what the record establishes from what we infer from it, and we say where the evidence runs out. If the matter later moves into proceedings, that same work supports a formal expert report and testimony, which is a separate instruction carrying a duty to the court.

    Privilege is a legal question and not one we answer. It depends on the jurisdiction, on who instructs, and on how the work is documented. Many organisations instruct through external counsel with that in mind, and we are comfortable working under that structure. Confirm the position with your own lawyers before the engagement starts, because the structure set up at the beginning is hard to change afterwards.

    What an Investigation Can and Cannot Deliver

    Worth agreeing before the engagement, because expectations set at the start are what the report is measured against at the end.

    It can deliver

    • A documented account of what the available evidence supports
    • A reconstructed timeline of transfers, approvals, and access
    • Identification of the accounts, entities, and structures involved
    • The control failures that allowed it, and where they still exist
    • Evidence packaged for your lawyers, insurers, or the authorities
    • An honest read on how far the evidence will carry the point

    It cannot deliver

    • Certainty — findings rest on evidence, and evidence has limits
    • A guaranteed conclusion, since some investigations end inconclusive
    • Compulsion, because we cannot require anyone to answer or produce
    • Seizure or freezing of assets, accounts, or wallets
    • Any law-enforcement or regulatory power, which we do not hold
    • The decision on dismissal, reporting, or litigation, which is yours

    Where the evidence does not settle a question, we say so and set out what further material would resolve it. We will not write a conclusion the record will not carry, and we will not soften one it does.

    Crypto Investigation FAQ

    What is the difference between an investigation and transaction tracing?

    Tracing answers a question about funds: what moved, when, and where it ended up. An investigation answers a question about people and conduct: what happened, who was involved, and what the evidence supports. Tracing is one input into an investigation, usually an important one, but rarely sufficient on its own. An investigation also draws on internal records, system logs, corporate structures, banking material, open-source research, and interviews, and it ends with findings about events rather than a map of transfers. If what you need is the map, start with transaction tracing and instruct an investigation only if the answer raises questions about people.

    Who should engage us, and who should we report to?

    Whoever is engaging should sit outside the conduct under examination. In practice that means the board, the audit or risk committee, a non-executive director, or the organisation's external lawyers instructing on the client's behalf. Where management is within scope, management should not control the engagement, set the scope, or receive findings first. This is not a comment on anyone's integrity. It is what makes the findings usable later, because the first question anyone asks about an internal investigation is who was directing it.

    How is the scope set, and can it change?

    We agree the questions in writing before work starts: what is being examined, which people, entities, accounts, and periods are in scope, what we are not being asked to look at, and who receives the output. Scope can change, and often does, because investigations surface things nobody expected. When that happens we come back to you with what we have found and a proposed variation rather than quietly widening the work. Nothing outside the agreed scope is examined without instruction.

    Will the investigation be confidential?

    We work on a need-to-know basis and agree the distribution list at the outset. Material is held in access-controlled storage, correspondence stays with the named recipients, and we do not confirm the existence of an engagement to anyone outside it. In an internal matter, confidentiality is also operational: if the subject learns of the work before evidence is preserved, records get deleted and funds get moved. Sequencing evidence preservation ahead of any interview is usually the single most important decision in the first week.

    What about legal privilege?

    Privilege is a legal question, and it depends on the jurisdiction, the nature of the engagement, and how the work is instructed and documented. We are accountants and investigators, not your lawyers, and we do not advise on it. Many organisations choose to instruct through external counsel with privilege in mind, and we are used to working under that structure. Confirm the position with your own lawyers before the engagement starts, because the way instructions and reporting lines are set up at the beginning is difficult to correct afterwards.

    Do you have any powers to compel evidence or freeze assets?

    No. We are a private firm, not law enforcement and not a regulator. We cannot compel anyone to answer questions, obtain records by order, search premises, seize devices, or freeze an account or a wallet. What we can do is work with the material the organisation lawfully holds or can lawfully obtain, analyse public blockchain records, and produce evidence in a form that supports whatever step you decide to take next, including a report to the authorities or an application made through your lawyers.

    What if the findings are inconclusive?

    Then the report says so. Some investigations end without establishing what happened, because the records were incomplete, the trail ran into services that do not respond, or the available evidence supports more than one explanation. Reporting an inconclusive result plainly is more useful than reporting a conclusion that the evidence will not carry, and much safer for the organisation if the matter is later tested by a regulator, an insurer, or a court. We will also set out what further material would resolve the point, if anything would.

    We have been hacked. Is that an investigation or a recovery engagement?

    It can be both, and the order matters. In the first hours the priority is containment, evidence preservation, and following the funds while they are still moving, which is recovery and tracing work. The investigation follows: how the attacker got in, whether internal access or internal knowledge was involved, what controls failed, what the organisation is obliged to tell regulators, customers, and insurers, and whether anything similar happened previously and went unnoticed. If the incident is live, start with crypto asset recovery and treat the investigation as the second phase.

    What do you deliver at the end, and can it be used in proceedings?

    A written report setting out the instructions, the scope, the material examined, the methodology, the findings, the basis for each finding, and the limitations. Evidence schedules and flow-of-funds exhibits are annexed, with a chain of custody recorded from the point of collection. Many investigations stop there and are used internally. Where the matter goes further, the same work usually supports a formal expert report and testimony, which is a separate instruction with different duties attached. It is easier to write an investigation report that can carry that weight than to retrofit one that cannot.

    More questions answered on our general FAQ.

    Something has gone wrong and you need the facts

    Tell us the concern and who would be engaging. We will tell you what an investigation can realistically establish, and what it will take, before you commit to one.