[{"data":1,"prerenderedAt":2860},["ShallowReactive",2],{"article-block-time-finality-reorgs-timestamps":3,"content-query-RtDbmF0kbU":733,"related-block-time-finality-reorgs-timestamps":1262},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"slug":10,"date":11,"lastUpdated":11,"author":12,"readingTime":13,"category":14,"tags":15,"ogImage":20,"featured":6,"body":21,"_type":727,"_id":728,"_source":729,"_file":730,"_stem":731,"_extension":732},"\u002Farticles\u002F34-block-time-finality-reorgs-timestamps","articles",false,"","Block time is not wall-clock time: finality, reorgs, timestamps","A block timestamp is a protocol input, not a certified clock. How inclusion, confirmations, finality, and reorgs shape timing evidence in litigation.","block-time-finality-reorgs-timestamps","2026-08-01","Nick Kampe",16,"Education",[16,17,18,19],"blockchain-basics","evidence","finality","timestamps","\u002Fog\u002Fblock-time-finality-reorgs-timestamps.png",{"type":22,"children":23,"toc":702},"root",[24,32,54,61,76,99,140,146,151,226,233,254,260,281,287,307,312,318,323,328,334,339,409,414,420,433,439,462,468,499,518,524,557,570,576,614,620,626,636,642,651,657,666,672,681],{"type":25,"tag":26,"props":27,"children":28},"element","p",{},[29],{"type":30,"value":31},"text","A block explorer page for a transaction shows a timestamp and a confirmation count, and the comfortable reading is that the payment happened at that displayed time and is now permanent. In blockchain evidence, that reading fails twice: the timestamp is protocol metadata set under the chain's own timestamp rule, not a certified reading of a real-world clock, and the transaction's place in history can change until the network reaches finality. The operational question for litigators and experts is therefore narrow: what does a block timestamp establish about when an event happened, and what does it take before that event is final? This article separates six moments that timing disputes routinely conflate: local signing, network broadcast, mempool observation, block inclusion, confirmation depth, and protocol finality.",{"type":25,"tag":26,"props":33,"children":34},{},[35,37,44,46,52],{"type":30,"value":36},"For the field-by-field reading of a transaction, see ",{"type":25,"tag":38,"props":39,"children":41},"a",{"href":40},"\u002Fresources\u002Fhow-to-read-a-blockchain-transaction",[42],{"type":30,"value":43},"How to Read a Blockchain Transaction",{"type":30,"value":45},", and for the admissibility framework that will govern this material, ",{"type":25,"tag":38,"props":47,"children":49},{"href":48},"\u002Fresources\u002Fblockchain-evidence-admissibility",[50],{"type":30,"value":51},"Blockchain Evidence in Litigation",{"type":30,"value":53},". This piece addresses the temporal proof question those articles do not cover in depth.",{"type":25,"tag":55,"props":56,"children":58},"h2",{"id":57},"what-a-block-timestamp-is-and-what-it-cannot-prove",[59],{"type":30,"value":60},"What a Block Timestamp Is (and What It Cannot Prove)",{"type":25,"tag":26,"props":62,"children":63},{},[64,66,74],{"type":30,"value":65},"A blockchain bundles transactions into blocks, each cryptographically linked to the previous one. NIST's technology overview (",{"type":25,"tag":38,"props":67,"children":71},{"href":68,"rel":69},"https:\u002F\u002Fnvlpubs.nist.gov\u002Fnistpubs\u002Fir\u002F2018\u002FNIST.IR.8202.pdf",[70],"nofollow",[72],{"type":30,"value":73},"NIST IR 8202, Blockchain Technology Overview",{"type":30,"value":75},", October 2018) describes a block header carrying identifying metadata, including a timestamp, together with the transactions it commits to. When an explorer shows a transaction date and time in UTC, it is displaying that header field converted to calendar format.",{"type":25,"tag":26,"props":77,"children":78},{},[79,81,88,90,97],{"type":30,"value":80},"The rules for what a Bitcoin producer may put in that field are loose by design. Bitcoin's accepted-stamp rule, set out in the ",{"type":25,"tag":38,"props":82,"children":85},{"href":83,"rel":84},"https:\u002F\u002Fen.bitcoin.it\u002Fwiki\u002FBlock_timestamp",[70],[86],{"type":30,"value":87},"Bitcoin Wiki's Block timestamp page",{"type":30,"value":89},", is that the value must be greater than the median timestamp of the previous 11 blocks and less than the network-adjusted time plus two hours, where network-adjusted time is the median of the timestamps reported by a node's connected peers. The documentation is blunt about the consequence: block timestamps are not exactly accurate and do not need to be, and block times are accurate only to within an hour or two. The same field feeds difficulty adjustment. Every 2,016 blocks, the ",{"type":25,"tag":38,"props":91,"children":94},{"href":92,"rel":93},"https:\u002F\u002Fdeveloper.bitcoin.org\u002Fdevguide\u002Fblock_chain.html",[70],[95],{"type":30,"value":96},"Bitcoin developer documentation",{"type":30,"value":98}," uses header timestamps to compute elapsed seconds against an ideal of 1,209,600 seconds (two weeks).",{"type":25,"tag":26,"props":100,"children":101},{},[102,104,111,113,120,122,129,131,138],{"type":30,"value":103},"Ethereum's proof-of-stake regime is different in mechanics, including the timestamp field. The Merge specification (",{"type":25,"tag":38,"props":105,"children":108},{"href":106,"rel":107},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-3675",[70],[109],{"type":30,"value":110},"EIP-3675",{"type":30,"value":112},", created July 2021, status Final) replaced proof-of-work consensus with proof-of-stake and refers to the most recent finalized block. The detailed rules live in the ethereum\u002Fconsensus-specs repository. Under the Bellatrix beacon-chain specification (",{"type":25,"tag":38,"props":114,"children":117},{"href":115,"rel":116},"https:\u002F\u002Fgithub.com\u002Fethereum\u002Fconsensus-specs\u002Fblob\u002Fv1.4.0\u002Fspecs\u002Fbellatrix\u002Fbeacon-chain.md",[70],[118],{"type":30,"value":119},"v1.4.0",{"type":30,"value":121},"), a valid execution payload timestamp must equal ",{"type":25,"tag":123,"props":124,"children":126},"code",{"className":125},[],[127],{"type":30,"value":128},"compute_timestamp_at_slot",{"type":30,"value":130},": genesis time plus the slot index times twelve seconds. A proposer cannot slide that field inside a two-hour band. The ",{"type":25,"tag":38,"props":132,"children":135},{"href":133,"rel":134},"https:\u002F\u002Fgithub.com\u002Fethereum\u002Fconsensus-specs\u002Fblob\u002Fv1.4.0\u002Fspecs\u002Fphase0\u002Fbeacon-chain.md",[70],[136],{"type":30,"value":137},"Phase 0 specification",{"type":30,"value":139}," divides time into 12-second slots and 32-slot epochs; a checkpoint pairs an epoch with the block root at the start of that epoch. Missed slots leave 12-second gaps, and genesis time is a protocol parameter rather than a certified clock. The stamp remains chain-relative metadata: block time proves position in a sequence first and calendar time second. For a calendar-time claim, the needed foundation comes from external records, addressed below.",{"type":25,"tag":55,"props":141,"children":143},{"id":142},"six-moments-in-a-transactions-timeline",[144],{"type":30,"value":145},"Six Moments in a Transaction's Timeline",{"type":25,"tag":26,"props":147,"children":148},{},[149],{"type":30,"value":150},"Timing claims collapse when these six moments are treated as one event. A defensible analysis names the moment each claim refers to, and cross-examination of an opponent's expert should do the same. In order:",{"type":25,"tag":152,"props":153,"children":154},"ol",{},[155,167,177,187,197,216],{"type":25,"tag":156,"props":157,"children":158},"li",{},[159,165],{"type":25,"tag":160,"props":161,"children":162},"strong",{},[163],{"type":30,"value":164},"Local signing.",{"type":30,"value":166}," The wallet creates and signs the transaction. The signature itself contains no time, and any timestamp on the device comes from a local clock that may be wrong, misconfigured, or altered.",{"type":25,"tag":156,"props":168,"children":169},{},[170,175],{"type":25,"tag":160,"props":171,"children":172},{},[173],{"type":30,"value":174},"Network broadcast.",{"type":30,"value":176}," The transaction leaves the wallet for the network's nodes, which relay it into their mempools of pending transactions. Broadcast itself is not recorded on the chain.",{"type":25,"tag":156,"props":178,"children":179},{},[180,185],{"type":25,"tag":160,"props":181,"children":182},{},[183],{"type":30,"value":184},"Mempool observation.",{"type":30,"value":186}," Indexers and exchanges log the pending transaction against their own clocks. An observation supports a claim that the observing system had the transaction at its recorded time; it does not establish inclusion. An unconfirmed transaction can be replaced, resubmitted with different fees, or dropped from mempools entirely.",{"type":25,"tag":156,"props":188,"children":189},{},[190,195],{"type":25,"tag":160,"props":191,"children":192},{},[193],{"type":30,"value":194},"Block inclusion.",{"type":30,"value":196}," The transaction lands at a specific index in a specific block. This is the first moment the chain itself attests to, and the block header's timestamp is the on-chain time.",{"type":25,"tag":156,"props":198,"children":199},{},[200,205,207,214],{"type":25,"tag":160,"props":201,"children":202},{},[203],{"type":30,"value":204},"Confirmation depth.",{"type":30,"value":206}," Each block built on top of the containing block is a confirmation. The ",{"type":25,"tag":38,"props":208,"children":211},{"href":209,"rel":210},"https:\u002F\u002Fbitcoin.org\u002Fbitcoin.pdf",[70],[212],{"type":30,"value":213},"Bitcoin whitepaper",{"type":30,"value":215}," states the design: the network timestamps transactions by hashing them into a chain of proof-of-work, forming a record that cannot be changed without redoing the proof-of-work, and each additional timestamp reinforces the ones before it.",{"type":25,"tag":156,"props":217,"children":218},{},[219,224],{"type":25,"tag":160,"props":220,"children":221},{},[222],{"type":30,"value":223},"Protocol finality.",{"type":30,"value":225}," A protocol-defined state beyond which the chain treats history as settled. It exists on some chains, and its conditions differ by chain as described below.",{"type":25,"tag":227,"props":228,"children":230},"h3",{"id":229},"probabilistic-confirmation-on-proof-of-work",[231],{"type":30,"value":232},"Probabilistic Confirmation on Proof of Work",{"type":25,"tag":26,"props":234,"children":235},{},[236,238,243,245,252],{"type":30,"value":237},"Bitcoin never declares a block final. Full nodes independently store only blocks they validate, as the ",{"type":25,"tag":38,"props":239,"children":241},{"href":92,"rel":240},[70],[242],{"type":30,"value":96},{"type":30,"value":244}," puts it, and they resolve competing branches by following the most difficult chain to recreate. Settlement is therefore probabilistic: the whitepaper observes that blocks added after a transaction further confirm that the network has accepted it, and the more work accumulates on top, the harder any alternative history becomes. Familiar thresholds such as six confirmations are risk judgments. The ",{"type":25,"tag":38,"props":246,"children":249},{"href":247,"rel":248},"https:\u002F\u002Fdeveloper.bitcoin.org\u002Fdevguide\u002Fpayment_processing.html",[70],[250],{"type":30,"value":251},"Bitcoin developer documentation on payment processing",{"type":30,"value":253}," calls six confirmations somewhat arbitrary and still recommends that software handling high-value transactions wait for at least that many before treating a payment as accepted. That wait is not a protocol event. For evidence purposes, deep confirmation plus sustained chain stability is usually more persuasive than any particular block count, but neither is an irreversible verdict.",{"type":25,"tag":227,"props":255,"children":257},{"id":256},"finality-on-proof-of-stake",[258],{"type":30,"value":259},"Finality on Proof of Stake",{"type":25,"tag":26,"props":261,"children":262},{},[263,265,271,273,279],{"type":30,"value":264},"Ethereum defines finality explicitly. Under the ",{"type":25,"tag":38,"props":266,"children":268},{"href":133,"rel":267},[70],[269],{"type":30,"value":270},"Phase 0 beacon-chain specification",{"type":30,"value":272},", a checkpoint is justified when the balance attesting to that epoch's target is at least two-thirds of total active balance. The specification then applies defined justification-bit and epoch-linkage conditions to finalize an earlier justified checkpoint. Until those attestations land, recent Ethereum history is technically contestable, so a transaction with one or two confirmations is not yet final on Ethereum either. Conflicting Casper FFG attestations can be slashable, including double votes and surround votes. Chains that market instant finality use different consensus designs and settle on different terms, and layer-2 systems add their own sequencing and settlement assumptions. Identify whose definition of finality is at issue before the word appears in a brief. Disputes over smart contract execution raise the same chain-time questions from the contract side, covered in ",{"type":25,"tag":38,"props":274,"children":276},{"href":275},"\u002Fresources\u002Fsmart-contract-disputes",[277],{"type":30,"value":278},"Smart Contract Disputes",{"type":30,"value":280},".",{"type":25,"tag":55,"props":282,"children":284},{"id":283},"reorganizations-when-the-record-you-read-changes",[285],{"type":30,"value":286},"Reorganizations: When the Record You Read Changes",{"type":25,"tag":26,"props":288,"children":289},{},[290,292,297,299,305],{"type":30,"value":291},"A reorganization, or reorg, is a change in which branch of the chain is canonical. Two miners can produce valid blocks near-simultaneously; nodes hold both temporarily; peers then follow the most difficult chain to recreate and throw away stale blocks, as the ",{"type":25,"tag":38,"props":293,"children":295},{"href":92,"rel":294},[70],[296],{"type":30,"value":96},{"type":30,"value":298}," describes in its treatment of simultaneous blocks and stale blocks. A later section of the same guide, on detecting forks, describes SPV clients connecting to several full nodes and comparing height as a hard-fork warning, which is a different problem from a short reorg of simultaneous blocks. NIST's overview shows the practical consequence: transactions that were in the orphaned block but not in the winning branch return to the pending transaction pool (",{"type":25,"tag":38,"props":300,"children":302},{"href":68,"rel":301},[70],[303],{"type":30,"value":304},"NIST IR 8202",{"type":30,"value":306},"). A transaction that briefly carried confirmations can therefore reappear in a different block with a different timestamp, sit again in a mempool, or in the worst case never be re-included at all.",{"type":25,"tag":26,"props":308,"children":309},{},[310],{"type":30,"value":311},"On proof-of-stake Ethereum the hazard is compressed but real before finality: recent blocks can be displaced by a competing branch, and proposer splits or missed slots can shuffle the latest history. Checkpoint finalization changes the analysis because conflicting Casper FFG attestations can be slashable; the practical exposure window is ordinarily the unfinalized period rather than days of history. The general rule for evidence is the same on every chain: a point-in-time capture records what the chain looked like, not what it became.",{"type":25,"tag":227,"props":313,"children":315},{"id":314},"hypothetical-example-the-deadline-payment",[316],{"type":30,"value":317},"Hypothetical Example: The Deadline Payment",{"type":25,"tag":26,"props":319,"children":320},{},[321],{"type":30,"value":322},"Hypothetical example: a contract requires payment \"received by 23:59:59 UTC\" on a stated date. The client broadcasts at 23:58 local time. An explorer query at 23:59:41 shows the transaction included in a block stamped 23:59:41 with one confirmation. A short proof-of-work reorg then re-parents that block, and an hour later the transaction sits in a block stamped 00:01:17 UTC. The payment that looked timely at the moment of capture now looks late, and a screenshot from 23:59:41, contradicted by the current explorer page, is exactly the exhibit an opposing expert enjoys dismantling.",{"type":25,"tag":26,"props":324,"children":325},{},[326],{"type":30,"value":327},"The technical record is richer than either snapshot. The first block existed and carried the transaction; a full node, archive node, or indexed service that recorded the view at 23:59:41 can support a conclusion that the transaction was included, at least briefly, before midnight, if the record is authenticated. Whether that satisfies \"received by\" is a contract question, but the sequence can be established if the point-in-time state was preserved. Corroboration from an exchange or from the recipient's own node at the same minute turns an ambiguous reorg story into a timeline. The opposite trap is the unconfirmed broadcast: a client who watched the transaction in a mempool at 23:59:30 and never checked again has no on-chain inclusion at all, and the eventual inclusion, after fee competition, can carry a timestamp hours later.",{"type":25,"tag":55,"props":329,"children":331},{"id":330},"corroborating-blockchain-time-with-independent-records",[332],{"type":30,"value":333},"Corroborating Blockchain Time with Independent Records",{"type":25,"tag":26,"props":335,"children":336},{},[337],{"type":30,"value":338},"Block time establishes order on its own chain more reliably than it establishes calendar time. Converting sequence into calendar time is a corroboration exercise, and the sources that do it well:",{"type":25,"tag":340,"props":341,"children":342},"ul",{},[343,360,370,380,390],{"type":25,"tag":156,"props":344,"children":345},{},[346,351,353,359],{"type":25,"tag":160,"props":347,"children":348},{},[349],{"type":30,"value":350},"Exchange records.",{"type":30,"value":352}," Deposits, withdrawals, order fills, and KYC events carry timestamps from the exchange's own systems and can provide an independent clock. Production must identify which system generated the timestamp, its timezone, and its clock basis. Practical production guidance is in ",{"type":25,"tag":38,"props":354,"children":356},{"href":355},"\u002Fresources\u002Fsubpoenaing-cryptocurrency-exchange-records",[357],{"type":30,"value":358},"How to Subpoena Cryptocurrency Exchange Records",{"type":30,"value":280},{"type":25,"tag":156,"props":361,"children":362},{},[363,368],{"type":25,"tag":160,"props":364,"children":365},{},[366],{"type":30,"value":367},"Server and application logs.",{"type":30,"value":369}," A party's own API logs, payment-processor logs, and NTP-synced servers can fix broadcast or receipt times, once the log's clock configuration is established.",{"type":25,"tag":156,"props":371,"children":372},{},[373,378],{"type":25,"tag":160,"props":374,"children":375},{},[376],{"type":30,"value":377},"Device forensics.",{"type":30,"value":379}," Wallet application data, browser history, and filesystem metadata show when software was installed, when keys were created, and when a transaction was initiated. The device clock itself must be assessed: timezone, synchronization, and whether the clock changed between the relevant date and imaging.",{"type":25,"tag":156,"props":381,"children":382},{},[383,388],{"type":25,"tag":160,"props":384,"children":385},{},[386],{"type":30,"value":387},"Communications and receipts.",{"type":30,"value":389}," Emails, messages, and invoices that reference a transaction hash fix context and intent, and carrier or server headers add their own timestamps. They prove that someone was communicating about the transaction, not chain time itself.",{"type":25,"tag":156,"props":391,"children":392},{},[393,398,400,407],{"type":25,"tag":160,"props":394,"children":395},{},[396],{"type":30,"value":397},"Time-stamp services for documents.",{"type":30,"value":399}," Where a party needs evidence that a document existed before a particular time rather than a consensus byproduct, a standards-based time-stamp service, such as one using the ",{"type":25,"tag":38,"props":401,"children":404},{"href":402,"rel":403},"https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc3161.html",[70],[405],{"type":30,"value":406},"RFC 3161",{"type":30,"value":408}," protocol, can issue a token for the document's hash. The service's time source and policy still require examination. This is different evidence from a block stamp.",{"type":25,"tag":26,"props":410,"children":411},{},[412],{"type":30,"value":413},"The corroboration principle: on-chain data is the sequence, external records are the calendar. Record every external timestamp with its clock basis and timezone, the same discipline applied to any electronically stored information.",{"type":25,"tag":55,"props":415,"children":417},{"id":416},"what-an-expert-can-safely-say-about-timing",[418],{"type":30,"value":419},"What an Expert Can Safely Say About Timing",{"type":25,"tag":26,"props":421,"children":422},{},[423,425,431],{"type":30,"value":424},"An expert opinion about timing is only as strong as the moment it specifies. In ",{"type":25,"tag":38,"props":426,"children":428},{"href":427},"\u002Fservices#blockchain-tracing",[429],{"type":30,"value":430},"blockchain tracing",{"type":30,"value":432}," work, conclusions are held to a test: can the claim be re-derived from the preserved data, and does it survive a reorg or a clock challenge?",{"type":25,"tag":227,"props":434,"children":436},{"id":435},"conclusions-that-hold-up",[437],{"type":30,"value":438},"Conclusions that hold up",{"type":25,"tag":340,"props":440,"children":441},{},[442,447,452,457],{"type":25,"tag":156,"props":443,"children":444},{},[445],{"type":30,"value":446},"That transaction X is included at index i of block N on chain C, and the block header records timestamp T, stated with the node or explorer queried, the retrieval time, and the block height at capture.",{"type":25,"tag":156,"props":448,"children":449},{},[450],{"type":30,"value":451},"That X precedes Y in inclusion order on the same chain, a property the chain itself attests.",{"type":25,"tag":156,"props":453,"children":454},{},[455],{"type":30,"value":456},"That as of a stated observation date X remained in the canonical chain with a stated confirmation depth.",{"type":25,"tag":156,"props":458,"children":459},{},[460],{"type":30,"value":461},"That an independent indexer or exchange recorded the transaction at time S, attributed to that system's own clock.",{"type":25,"tag":227,"props":463,"children":465},{"id":464},"conclusions-that-do-not",[466],{"type":30,"value":467},"Conclusions that do not",{"type":25,"tag":340,"props":469,"children":470},{},[471,476,489,494],{"type":25,"tag":156,"props":472,"children":473},{},[474],{"type":30,"value":475},"That a wallet screen timestamp proves when the defendant signed, without device-clock evidence.",{"type":25,"tag":156,"props":477,"children":478},{},[479,481,487],{"type":30,"value":480},"That the transaction occurred \"at T\" because the block header says T, without stating which protocol's timestamp rule applies. Bitcoin's window, again per ",{"type":25,"tag":38,"props":482,"children":484},{"href":83,"rel":483},[70],[485],{"type":30,"value":486},"Bitcoin Wiki",{"type":30,"value":488},": greater than the median of the previous 11 blocks and less than network-adjusted time plus two hours. Ethereum's payload timestamp must equal slot time; that still does not prove when the wallet signed or when the transaction was first broadcast.",{"type":25,"tag":156,"props":490,"children":491},{},[492],{"type":30,"value":493},"That the transaction \"is irreversible,\" stated categorically. The defensible version names the protocol and its finality state: finalized under Ethereum's checkpoint rules, or deeply confirmed on Bitcoin as of the observation date.",{"type":25,"tag":156,"props":495,"children":496},{},[497],{"type":30,"value":498},"That a single explorer screenshot of two confirmations proves final status, without a current-state query answering whether the block survived.",{"type":25,"tag":26,"props":500,"children":501},{},[502,504,508,510,516],{"type":30,"value":503},"These are professional practices in a technical discipline. What a forum requires of the evidence is a separate legal question under its own evidence and expert-testimony standards; the federal and Missouri framework is covered in ",{"type":25,"tag":38,"props":505,"children":506},{"href":48},[507],{"type":30,"value":51},{"type":30,"value":509}," and the case law in ",{"type":25,"tag":38,"props":511,"children":513},{"href":512},"\u002Fresources\u002Fdaubert-blockchain-experts-courts",[514],{"type":30,"value":515},"Daubert and Blockchain Experts",{"type":30,"value":517},". A report that conflates the technical layer with the legal standard is the one that gets challenged.",{"type":25,"tag":227,"props":519,"children":521},{"id":520},"a-short-checklist-for-timing-evidence",[522],{"type":30,"value":523},"A Short Checklist for Timing Evidence",{"type":25,"tag":152,"props":525,"children":526},{},[527,532,537,542,547,552],{"type":25,"tag":156,"props":528,"children":529},{},[530],{"type":30,"value":531},"Name the moment: signing, broadcast, mempool, inclusion, confirmation, or finality.",{"type":25,"tag":156,"props":533,"children":534},{},[535],{"type":30,"value":536},"Record the exact query: node or explorer, block height, transaction index, retrieval time.",{"type":25,"tag":156,"props":538,"children":539},{},[540],{"type":30,"value":541},"Preserve both the point-in-time view and the current-state view, with hashes of any exports.",{"type":25,"tag":156,"props":543,"children":544},{},[545],{"type":30,"value":546},"State the confirmation depth and finality state at capture, and re-check afterward for reorgs.",{"type":25,"tag":156,"props":548,"children":549},{},[550],{"type":30,"value":551},"Corroborate calendar time with at least one independent clock, and name its basis.",{"type":25,"tag":156,"props":553,"children":554},{},[555],{"type":30,"value":556},"Test the alternative story: reorg, fee replacement, dropped mempool, or clock error.",{"type":25,"tag":26,"props":558,"children":559},{},[560,562,568],{"type":30,"value":561},"This checklist is the core of the ",{"type":25,"tag":38,"props":563,"children":565},{"href":564},"\u002Fmethodology",[566],{"type":30,"value":567},"methodology",{"type":30,"value":569}," applied to timing questions in our engagements.",{"type":25,"tag":55,"props":571,"children":573},{"id":572},"questions-to-ask-about-timing-evidence",[574],{"type":30,"value":575},"Questions to Ask About Timing Evidence",{"type":25,"tag":152,"props":577,"children":578},{},[579,584,589,594,599,604,609],{"type":25,"tag":156,"props":580,"children":581},{},[582],{"type":30,"value":583},"Which field did the analysis read: the explorer's rendered timestamp or the raw block header value from a node?",{"type":25,"tag":156,"props":585,"children":586},{},[587],{"type":30,"value":588},"What were the block height, index, and confirmation count at capture, and what are they now?",{"type":25,"tag":156,"props":590,"children":591},{},[592],{"type":30,"value":593},"Has the transaction reorged since capture, and how would the detection method know?",{"type":25,"tag":156,"props":595,"children":596},{},[597],{"type":30,"value":598},"For exchange production: which system generated the timestamp, in what timezone, and with what clock basis?",{"type":25,"tag":156,"props":600,"children":601},{},[602],{"type":30,"value":603},"For devices: timezone, NTP state, and any clock changes between the event and imaging.",{"type":25,"tag":156,"props":605,"children":606},{},[607],{"type":30,"value":608},"For communications: do they reference the transaction hash, and do message-header times agree with the exchange's internal times?",{"type":25,"tag":156,"props":610,"children":611},{},[612],{"type":30,"value":613},"What does the operative contract or statute select as the moment that matters, and which of the six moments can the evidence actually prove?",{"type":25,"tag":55,"props":615,"children":617},{"id":616},"frequently-asked-questions",[618],{"type":30,"value":619},"Frequently Asked Questions",{"type":25,"tag":227,"props":621,"children":623},{"id":622},"q-if-the-block-explorer-shows-140422-utc-is-that-the-exact-time-of-the-transaction",[624],{"type":30,"value":625},"Q: If the block explorer shows 14:04:22 UTC, is that the exact time of the transaction?",{"type":25,"tag":26,"props":627,"children":628},{},[629,634],{"type":25,"tag":160,"props":630,"children":631},{},[632],{"type":30,"value":633},"A:",{"type":30,"value":635}," It is the timestamp stored in the block header, displayed in UTC. On Bitcoin, a valid stamp must be greater than the median timestamp of the previous 11 blocks and less than network-adjusted time plus two hours, and the documentation states block times are accurate only to within an hour or two. On Ethereum, a valid execution payload timestamp must equal genesis time plus twelve seconds times the slot, so the field tracks slot time by validity rule rather than miner latitude. Neither is a certified clock of signing or broadcast. For an exact-time claim, corroborate with an independent clock: exchange logs, server logs, or device forensics.",{"type":25,"tag":227,"props":637,"children":639},{"id":638},"q-when-is-a-blockchain-transaction-truly-final",[640],{"type":30,"value":641},"Q: When is a blockchain transaction truly final?",{"type":25,"tag":26,"props":643,"children":644},{},[645,649],{"type":25,"tag":160,"props":646,"children":647},{},[648],{"type":30,"value":633},{"type":30,"value":650}," It depends on the protocol. Bitcoin has no formal finality event; each block added on top reinforces acceptance, and the practical risk of reversal falls toward zero. Proof-of-stake Ethereum defines finality in the Phase 0 specification: a checkpoint is justified when the balance attesting to that epoch's target is at least two-thirds of total active balance, and the specification applies defined justification-bit and epoch-linkage conditions to finalize an earlier justified checkpoint. Conflicting Casper FFG attestations can be slashable. Finality thresholds differ by chain, and litigation rarely needs absolute irreversibility. It needs a defensible statement of the chain state at the relevant moment.",{"type":25,"tag":227,"props":652,"children":654},{"id":653},"q-my-clients-transaction-was-confirmed-and-then-disappeared-from-the-explorer-what-happened",[655],{"type":30,"value":656},"Q: My client's transaction was confirmed and then disappeared from the explorer. What happened?",{"type":25,"tag":26,"props":658,"children":659},{},[660,664],{"type":25,"tag":160,"props":661,"children":662},{},[663],{"type":30,"value":633},{"type":30,"value":665}," Most likely a reorganization: a competing block branch won, the block that had contained the transaction became stale or orphaned, and the transaction returned to the pending pool, where it may be re-included later or expire. NIST's overview describes this behavior directly: transactions in the orphaned block that are absent from the winning branch return to the pending transaction pool. Unconfirmed transactions can also be replaced or dropped because of fee competition. Recover the current chain state and any archived views; the pre-reorg history is itself evidence of the sequence.",{"type":25,"tag":227,"props":667,"children":669},{"id":668},"q-can-a-block-producer-set-the-timestamp-to-anything-they-want",[670],{"type":30,"value":671},"Q: Can a block producer set the timestamp to anything they want?",{"type":25,"tag":26,"props":673,"children":674},{},[675,679],{"type":25,"tag":160,"props":676,"children":677},{},[678],{"type":30,"value":633},{"type":30,"value":680}," On Bitcoin, no, but the permitted window is wide. The stamp must exceed the median timestamp of the previous 11 blocks and stay below network-adjusted time plus two hours, so a producer has latitude inside that window, including times earlier than a node's clock. On Ethereum, a proposer cannot pick an arbitrary time: the payload timestamp must equal the computed slot time. That still leaves genesis-time accuracy, missed slots, and the fact that slot time is not a certification of when a user signed. External records with named clocks are how the calendar moment gets pinned down.",{"type":25,"tag":26,"props":682,"children":683},{},[684,686,692,694,700],{"type":30,"value":685},"Timing evidence fails in predictable places: an unexamined device clock, a reorg between capture and hearing, an explorer view mistaken for a guarantee. The habits that protect a case are naming which of the six moments a claim is about, preserving the chain state at capture, and corroborating absolute time with an independent record. Cases vary in contract language, forum rules, and chain, and a consultation is the right place to work through the specifics of a particular matter. If you are litigating a timing question and need an ",{"type":25,"tag":38,"props":687,"children":689},{"href":688},"\u002Fservices#expert-witness",[690],{"type":30,"value":691},"expert witness",{"type":30,"value":693}," for the analysis, ",{"type":25,"tag":38,"props":695,"children":697},{"href":696},"\u002Fcontact",[698],{"type":30,"value":699},"contact us",{"type":30,"value":701}," to discuss it.",{"title":7,"searchDepth":703,"depth":703,"links":704},2,[705,706,711,714,715,720,721],{"id":57,"depth":703,"text":60},{"id":142,"depth":703,"text":145,"children":707},[708,710],{"id":229,"depth":709,"text":232},3,{"id":256,"depth":709,"text":259},{"id":283,"depth":703,"text":286,"children":712},[713],{"id":314,"depth":709,"text":317},{"id":330,"depth":703,"text":333},{"id":416,"depth":703,"text":419,"children":716},[717,718,719],{"id":435,"depth":709,"text":438},{"id":464,"depth":709,"text":467},{"id":520,"depth":709,"text":523},{"id":572,"depth":703,"text":575},{"id":616,"depth":703,"text":619,"children":722},[723,724,725,726],{"id":622,"depth":709,"text":625},{"id":638,"depth":709,"text":641},{"id":653,"depth":709,"text":656},{"id":668,"depth":709,"text":671},"markdown","content:articles:34-block-time-finality-reorgs-timestamps.md","content","articles\u002F34-block-time-finality-reorgs-timestamps.md","articles\u002F34-block-time-finality-reorgs-timestamps","md",{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"slug":10,"date":11,"lastUpdated":11,"author":12,"readingTime":13,"category":14,"tags":734,"ogImage":20,"featured":6,"body":735,"_type":727,"_id":728,"_source":729,"_file":730,"_stem":731,"_extension":732},[16,17,18,19],{"type":22,"children":736,"toc":1239},[737,741,755,759,769,785,813,817,821,878,882,898,902,917,921,937,941,945,949,953,957,961,1015,1019,1023,1032,1036,1055,1059,1084,1098,1102,1129,1138,1142,1173,1177,1181,1189,1193,1201,1205,1213,1217,1225],{"type":25,"tag":26,"props":738,"children":739},{},[740],{"type":30,"value":31},{"type":25,"tag":26,"props":742,"children":743},{},[744,745,749,750,754],{"type":30,"value":36},{"type":25,"tag":38,"props":746,"children":747},{"href":40},[748],{"type":30,"value":43},{"type":30,"value":45},{"type":25,"tag":38,"props":751,"children":752},{"href":48},[753],{"type":30,"value":51},{"type":30,"value":53},{"type":25,"tag":55,"props":756,"children":757},{"id":57},[758],{"type":30,"value":60},{"type":25,"tag":26,"props":760,"children":761},{},[762,763,768],{"type":30,"value":65},{"type":25,"tag":38,"props":764,"children":766},{"href":68,"rel":765},[70],[767],{"type":30,"value":73},{"type":30,"value":75},{"type":25,"tag":26,"props":770,"children":771},{},[772,773,778,779,784],{"type":30,"value":80},{"type":25,"tag":38,"props":774,"children":776},{"href":83,"rel":775},[70],[777],{"type":30,"value":87},{"type":30,"value":89},{"type":25,"tag":38,"props":780,"children":782},{"href":92,"rel":781},[70],[783],{"type":30,"value":96},{"type":30,"value":98},{"type":25,"tag":26,"props":786,"children":787},{},[788,789,794,795,800,801,806,807,812],{"type":30,"value":103},{"type":25,"tag":38,"props":790,"children":792},{"href":106,"rel":791},[70],[793],{"type":30,"value":110},{"type":30,"value":112},{"type":25,"tag":38,"props":796,"children":798},{"href":115,"rel":797},[70],[799],{"type":30,"value":119},{"type":30,"value":121},{"type":25,"tag":123,"props":802,"children":804},{"className":803},[],[805],{"type":30,"value":128},{"type":30,"value":130},{"type":25,"tag":38,"props":808,"children":810},{"href":133,"rel":809},[70],[811],{"type":30,"value":137},{"type":30,"value":139},{"type":25,"tag":55,"props":814,"children":815},{"id":142},[816],{"type":30,"value":145},{"type":25,"tag":26,"props":818,"children":819},{},[820],{"type":30,"value":150},{"type":25,"tag":152,"props":822,"children":823},{},[824,832,840,848,856,870],{"type":25,"tag":156,"props":825,"children":826},{},[827,831],{"type":25,"tag":160,"props":828,"children":829},{},[830],{"type":30,"value":164},{"type":30,"value":166},{"type":25,"tag":156,"props":833,"children":834},{},[835,839],{"type":25,"tag":160,"props":836,"children":837},{},[838],{"type":30,"value":174},{"type":30,"value":176},{"type":25,"tag":156,"props":841,"children":842},{},[843,847],{"type":25,"tag":160,"props":844,"children":845},{},[846],{"type":30,"value":184},{"type":30,"value":186},{"type":25,"tag":156,"props":849,"children":850},{},[851,855],{"type":25,"tag":160,"props":852,"children":853},{},[854],{"type":30,"value":194},{"type":30,"value":196},{"type":25,"tag":156,"props":857,"children":858},{},[859,863,864,869],{"type":25,"tag":160,"props":860,"children":861},{},[862],{"type":30,"value":204},{"type":30,"value":206},{"type":25,"tag":38,"props":865,"children":867},{"href":209,"rel":866},[70],[868],{"type":30,"value":213},{"type":30,"value":215},{"type":25,"tag":156,"props":871,"children":872},{},[873,877],{"type":25,"tag":160,"props":874,"children":875},{},[876],{"type":30,"value":223},{"type":30,"value":225},{"type":25,"tag":227,"props":879,"children":880},{"id":229},[881],{"type":30,"value":232},{"type":25,"tag":26,"props":883,"children":884},{},[885,886,891,892,897],{"type":30,"value":237},{"type":25,"tag":38,"props":887,"children":889},{"href":92,"rel":888},[70],[890],{"type":30,"value":96},{"type":30,"value":244},{"type":25,"tag":38,"props":893,"children":895},{"href":247,"rel":894},[70],[896],{"type":30,"value":251},{"type":30,"value":253},{"type":25,"tag":227,"props":899,"children":900},{"id":256},[901],{"type":30,"value":259},{"type":25,"tag":26,"props":903,"children":904},{},[905,906,911,912,916],{"type":30,"value":264},{"type":25,"tag":38,"props":907,"children":909},{"href":133,"rel":908},[70],[910],{"type":30,"value":270},{"type":30,"value":272},{"type":25,"tag":38,"props":913,"children":914},{"href":275},[915],{"type":30,"value":278},{"type":30,"value":280},{"type":25,"tag":55,"props":918,"children":919},{"id":283},[920],{"type":30,"value":286},{"type":25,"tag":26,"props":922,"children":923},{},[924,925,930,931,936],{"type":30,"value":291},{"type":25,"tag":38,"props":926,"children":928},{"href":92,"rel":927},[70],[929],{"type":30,"value":96},{"type":30,"value":298},{"type":25,"tag":38,"props":932,"children":934},{"href":68,"rel":933},[70],[935],{"type":30,"value":304},{"type":30,"value":306},{"type":25,"tag":26,"props":938,"children":939},{},[940],{"type":30,"value":311},{"type":25,"tag":227,"props":942,"children":943},{"id":314},[944],{"type":30,"value":317},{"type":25,"tag":26,"props":946,"children":947},{},[948],{"type":30,"value":322},{"type":25,"tag":26,"props":950,"children":951},{},[952],{"type":30,"value":327},{"type":25,"tag":55,"props":954,"children":955},{"id":330},[956],{"type":30,"value":333},{"type":25,"tag":26,"props":958,"children":959},{},[960],{"type":30,"value":338},{"type":25,"tag":340,"props":962,"children":963},{},[964,977,985,993,1001],{"type":25,"tag":156,"props":965,"children":966},{},[967,971,972,976],{"type":25,"tag":160,"props":968,"children":969},{},[970],{"type":30,"value":350},{"type":30,"value":352},{"type":25,"tag":38,"props":973,"children":974},{"href":355},[975],{"type":30,"value":358},{"type":30,"value":280},{"type":25,"tag":156,"props":978,"children":979},{},[980,984],{"type":25,"tag":160,"props":981,"children":982},{},[983],{"type":30,"value":367},{"type":30,"value":369},{"type":25,"tag":156,"props":986,"children":987},{},[988,992],{"type":25,"tag":160,"props":989,"children":990},{},[991],{"type":30,"value":377},{"type":30,"value":379},{"type":25,"tag":156,"props":994,"children":995},{},[996,1000],{"type":25,"tag":160,"props":997,"children":998},{},[999],{"type":30,"value":387},{"type":30,"value":389},{"type":25,"tag":156,"props":1002,"children":1003},{},[1004,1008,1009,1014],{"type":25,"tag":160,"props":1005,"children":1006},{},[1007],{"type":30,"value":397},{"type":30,"value":399},{"type":25,"tag":38,"props":1010,"children":1012},{"href":402,"rel":1011},[70],[1013],{"type":30,"value":406},{"type":30,"value":408},{"type":25,"tag":26,"props":1016,"children":1017},{},[1018],{"type":30,"value":413},{"type":25,"tag":55,"props":1020,"children":1021},{"id":416},[1022],{"type":30,"value":419},{"type":25,"tag":26,"props":1024,"children":1025},{},[1026,1027,1031],{"type":30,"value":424},{"type":25,"tag":38,"props":1028,"children":1029},{"href":427},[1030],{"type":30,"value":430},{"type":30,"value":432},{"type":25,"tag":227,"props":1033,"children":1034},{"id":435},[1035],{"type":30,"value":438},{"type":25,"tag":340,"props":1037,"children":1038},{},[1039,1043,1047,1051],{"type":25,"tag":156,"props":1040,"children":1041},{},[1042],{"type":30,"value":446},{"type":25,"tag":156,"props":1044,"children":1045},{},[1046],{"type":30,"value":451},{"type":25,"tag":156,"props":1048,"children":1049},{},[1050],{"type":30,"value":456},{"type":25,"tag":156,"props":1052,"children":1053},{},[1054],{"type":30,"value":461},{"type":25,"tag":227,"props":1056,"children":1057},{"id":464},[1058],{"type":30,"value":467},{"type":25,"tag":340,"props":1060,"children":1061},{},[1062,1066,1076,1080],{"type":25,"tag":156,"props":1063,"children":1064},{},[1065],{"type":30,"value":475},{"type":25,"tag":156,"props":1067,"children":1068},{},[1069,1070,1075],{"type":30,"value":480},{"type":25,"tag":38,"props":1071,"children":1073},{"href":83,"rel":1072},[70],[1074],{"type":30,"value":486},{"type":30,"value":488},{"type":25,"tag":156,"props":1077,"children":1078},{},[1079],{"type":30,"value":493},{"type":25,"tag":156,"props":1081,"children":1082},{},[1083],{"type":30,"value":498},{"type":25,"tag":26,"props":1085,"children":1086},{},[1087,1088,1092,1093,1097],{"type":30,"value":503},{"type":25,"tag":38,"props":1089,"children":1090},{"href":48},[1091],{"type":30,"value":51},{"type":30,"value":509},{"type":25,"tag":38,"props":1094,"children":1095},{"href":512},[1096],{"type":30,"value":515},{"type":30,"value":517},{"type":25,"tag":227,"props":1099,"children":1100},{"id":520},[1101],{"type":30,"value":523},{"type":25,"tag":152,"props":1103,"children":1104},{},[1105,1109,1113,1117,1121,1125],{"type":25,"tag":156,"props":1106,"children":1107},{},[1108],{"type":30,"value":531},{"type":25,"tag":156,"props":1110,"children":1111},{},[1112],{"type":30,"value":536},{"type":25,"tag":156,"props":1114,"children":1115},{},[1116],{"type":30,"value":541},{"type":25,"tag":156,"props":1118,"children":1119},{},[1120],{"type":30,"value":546},{"type":25,"tag":156,"props":1122,"children":1123},{},[1124],{"type":30,"value":551},{"type":25,"tag":156,"props":1126,"children":1127},{},[1128],{"type":30,"value":556},{"type":25,"tag":26,"props":1130,"children":1131},{},[1132,1133,1137],{"type":30,"value":561},{"type":25,"tag":38,"props":1134,"children":1135},{"href":564},[1136],{"type":30,"value":567},{"type":30,"value":569},{"type":25,"tag":55,"props":1139,"children":1140},{"id":572},[1141],{"type":30,"value":575},{"type":25,"tag":152,"props":1143,"children":1144},{},[1145,1149,1153,1157,1161,1165,1169],{"type":25,"tag":156,"props":1146,"children":1147},{},[1148],{"type":30,"value":583},{"type":25,"tag":156,"props":1150,"children":1151},{},[1152],{"type":30,"value":588},{"type":25,"tag":156,"props":1154,"children":1155},{},[1156],{"type":30,"value":593},{"type":25,"tag":156,"props":1158,"children":1159},{},[1160],{"type":30,"value":598},{"type":25,"tag":156,"props":1162,"children":1163},{},[1164],{"type":30,"value":603},{"type":25,"tag":156,"props":1166,"children":1167},{},[1168],{"type":30,"value":608},{"type":25,"tag":156,"props":1170,"children":1171},{},[1172],{"type":30,"value":613},{"type":25,"tag":55,"props":1174,"children":1175},{"id":616},[1176],{"type":30,"value":619},{"type":25,"tag":227,"props":1178,"children":1179},{"id":622},[1180],{"type":30,"value":625},{"type":25,"tag":26,"props":1182,"children":1183},{},[1184,1188],{"type":25,"tag":160,"props":1185,"children":1186},{},[1187],{"type":30,"value":633},{"type":30,"value":635},{"type":25,"tag":227,"props":1190,"children":1191},{"id":638},[1192],{"type":30,"value":641},{"type":25,"tag":26,"props":1194,"children":1195},{},[1196,1200],{"type":25,"tag":160,"props":1197,"children":1198},{},[1199],{"type":30,"value":633},{"type":30,"value":650},{"type":25,"tag":227,"props":1202,"children":1203},{"id":653},[1204],{"type":30,"value":656},{"type":25,"tag":26,"props":1206,"children":1207},{},[1208,1212],{"type":25,"tag":160,"props":1209,"children":1210},{},[1211],{"type":30,"value":633},{"type":30,"value":665},{"type":25,"tag":227,"props":1214,"children":1215},{"id":668},[1216],{"type":30,"value":671},{"type":25,"tag":26,"props":1218,"children":1219},{},[1220,1224],{"type":25,"tag":160,"props":1221,"children":1222},{},[1223],{"type":30,"value":633},{"type":30,"value":680},{"type":25,"tag":26,"props":1226,"children":1227},{},[1228,1229,1233,1234,1238],{"type":30,"value":685},{"type":25,"tag":38,"props":1230,"children":1231},{"href":688},[1232],{"type":30,"value":691},{"type":30,"value":693},{"type":25,"tag":38,"props":1235,"children":1236},{"href":696},[1237],{"type":30,"value":699},{"type":30,"value":701},{"title":7,"searchDepth":703,"depth":703,"links":1240},[1241,1242,1246,1249,1250,1255,1256],{"id":57,"depth":703,"text":60},{"id":142,"depth":703,"text":145,"children":1243},[1244,1245],{"id":229,"depth":709,"text":232},{"id":256,"depth":709,"text":259},{"id":283,"depth":703,"text":286,"children":1247},[1248],{"id":314,"depth":709,"text":317},{"id":330,"depth":703,"text":333},{"id":416,"depth":703,"text":419,"children":1251},[1252,1253,1254],{"id":435,"depth":709,"text":438},{"id":464,"depth":709,"text":467},{"id":520,"depth":709,"text":523},{"id":572,"depth":703,"text":575},{"id":616,"depth":703,"text":619,"children":1257},[1258,1259,1260,1261],{"id":622,"depth":709,"text":625},{"id":638,"depth":709,"text":641},{"id":653,"depth":709,"text":656},{"id":668,"depth":709,"text":671},[1263,2041,2351],{"_path":1264,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":1265,"description":1266,"slug":1267,"date":1268,"lastUpdated":1268,"author":12,"readingTime":1269,"category":14,"tags":1270,"ogImage":1274,"featured":6,"body":1275,"_type":727,"_id":2038,"_source":729,"_file":2039,"_stem":2040,"_extension":732},"\u002Farticles\u002F26-token-approvals-permit-signatures","Token approvals, permits, and transfer attribution","Explains how ERC-20 approvals and permit signatures separate token ownership, transfer submission, delegated authority, and proof of owner intent.","token-approvals-permit-signatures","2026-06-06",10,[17,1271,1272,1273],"smart-contracts","wallet-ownership","litigation","\u002Fog\u002Ftoken-approvals-permit-signatures.png",{"type":22,"children":1276,"toc":2020},[1277,1282,1287,1293,1298,1336,1348,1354,1359,1452,1472,1484,1490,1519,1532,1580,1586,1591,1689,1702,1708,1735,1747,1761,1766,1778,1784,1789,1794,1800,1812,1817,1823,1828,1871,1883,1889,1894,1917,1930,1934,1940,1963,1969,1978,1984,1993,1999,2008],{"type":25,"tag":26,"props":1278,"children":1279},{},[1280],{"type":30,"value":1281},"An ERC-20 token leaving a wallet does not necessarily mean the wallet owner submitted the transfer transaction or approved that particular recipient. The owner may previously have granted another address authority to spend tokens through an allowance. A signed permit can create the same authority even though the owner never broadcasts an approval transaction.",{"type":25,"tag":26,"props":1283,"children":1284},{},[1285],{"type":30,"value":1286},"That distinction matters in fraud, commercial, and probate matters. The blockchain can establish that a token balance changed, but the investigator still must separate the transaction sender, token owner, authorized spender, recipient, and signature author before drawing conclusions about human intent.",{"type":25,"tag":55,"props":1288,"children":1290},{"id":1289},"why-is-a-token-transfer-different-from-a-native-asset-transfer",[1291],{"type":30,"value":1292},"Why is a token transfer different from a native-asset transfer?",{"type":25,"tag":26,"props":1294,"children":1295},{},[1296],{"type":30,"value":1297},"In an ordinary top-level transfer of a blockchain's native asset, such as ETH, the transaction sender signs a transaction containing its destination and value. Contract execution can produce additional native-asset movements, so even that record may require a trace. ERC-20 tokens add another layer because the token contract maintains the balances.",{"type":25,"tag":26,"props":1299,"children":1300},{},[1301,1303,1310,1312,1318,1320,1326,1328,1334],{"type":30,"value":1302},"The ",{"type":25,"tag":38,"props":1304,"children":1307},{"href":1305,"rel":1306},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-20",[70],[1308],{"type":30,"value":1309},"ERC-20 token standard",{"type":30,"value":1311}," defines two relevant transfer paths. A holder can call ",{"type":25,"tag":123,"props":1313,"children":1315},{"className":1314},[],[1316],{"type":30,"value":1317},"transfer(to, value)",{"type":30,"value":1319}," from the holder's own address. Alternatively, another address can call ",{"type":25,"tag":123,"props":1321,"children":1323},{"className":1322},[],[1324],{"type":30,"value":1325},"transferFrom(from, to, value)",{"type":30,"value":1327}," after the token owner has authorized that spender. Both paths can produce the same ",{"type":25,"tag":123,"props":1329,"children":1331},{"className":1330},[],[1332],{"type":30,"value":1333},"Transfer",{"type":30,"value":1335}," event showing tokens moving from the owner's balance to the recipient.",{"type":25,"tag":26,"props":1337,"children":1338},{},[1339,1341,1346],{"type":30,"value":1340},"A block explorer's token-transfer display therefore answers an accounting question: which token contract recorded a debit, a credit, and an amount? It does not, by itself, answer who signed the outer transaction or why the debit was authorized. For the foundational transaction fields, see ",{"type":25,"tag":38,"props":1342,"children":1343},{"href":40},[1344],{"type":30,"value":1345},"how to read a blockchain transaction",{"type":30,"value":1347},". The unique issue here is delegated token authority.",{"type":25,"tag":55,"props":1349,"children":1351},{"id":1350},"which-addresses-perform-the-relevant-roles",[1352],{"type":30,"value":1353},"Which addresses perform the relevant roles?",{"type":25,"tag":26,"props":1355,"children":1356},{},[1357],{"type":30,"value":1358},"A defensible analysis identifies each role separately rather than using \"sender\" for all of them:",{"type":25,"tag":340,"props":1360,"children":1361},{},[1362,1388,1405,1415,1432,1442],{"type":25,"tag":156,"props":1363,"children":1364},{},[1365,1370,1372,1378,1380,1386],{"type":25,"tag":160,"props":1366,"children":1367},{},[1368],{"type":30,"value":1369},"Token owner:",{"type":30,"value":1371}," The address whose token balance is debited. In a ",{"type":25,"tag":123,"props":1373,"children":1375},{"className":1374},[],[1376],{"type":30,"value":1377},"transferFrom",{"type":30,"value":1379}," call, this is the ",{"type":25,"tag":123,"props":1381,"children":1383},{"className":1382},[],[1384],{"type":30,"value":1385},"from",{"type":30,"value":1387}," argument.",{"type":25,"tag":156,"props":1389,"children":1390},{},[1391,1396,1398,1403],{"type":25,"tag":160,"props":1392,"children":1393},{},[1394],{"type":30,"value":1395},"Spender:",{"type":30,"value":1397}," The address whose allowance permits it to withdraw from the owner's balance. In a standard direct ",{"type":25,"tag":123,"props":1399,"children":1401},{"className":1400},[],[1402],{"type":30,"value":1377},{"type":30,"value":1404}," call, this is the immediate caller seen by the token contract.",{"type":25,"tag":156,"props":1406,"children":1407},{},[1408,1413],{"type":25,"tag":160,"props":1409,"children":1410},{},[1411],{"type":30,"value":1412},"Transaction sender:",{"type":30,"value":1414}," The address recovered as the signer of the outer blockchain transaction. It may be the owner, the spender, or an address interacting with another contract.",{"type":25,"tag":156,"props":1416,"children":1417},{},[1418,1423,1425,1430],{"type":25,"tag":160,"props":1419,"children":1420},{},[1421],{"type":30,"value":1422},"Recipient:",{"type":30,"value":1424}," The address credited in the token contract's ",{"type":25,"tag":123,"props":1426,"children":1428},{"className":1427},[],[1429],{"type":30,"value":1333},{"type":30,"value":1431}," event.",{"type":25,"tag":156,"props":1433,"children":1434},{},[1435,1440],{"type":25,"tag":160,"props":1436,"children":1437},{},[1438],{"type":30,"value":1439},"Token contract:",{"type":30,"value":1441}," The contract that enforces balances and allowances and emits the relevant events.",{"type":25,"tag":156,"props":1443,"children":1444},{},[1445,1450],{"type":25,"tag":160,"props":1446,"children":1447},{},[1448],{"type":30,"value":1449},"Signature author:",{"type":30,"value":1451}," For a permit, the address whose private key produced the authorization signature. A relayer can submit that signature on-chain later.",{"type":25,"tag":26,"props":1453,"children":1454},{},[1455,1457,1463,1465,1470],{"type":30,"value":1456},"These roles can collapse into fewer addresses. An owner may call ",{"type":25,"tag":123,"props":1458,"children":1460},{"className":1459},[],[1461],{"type":30,"value":1462},"transfer",{"type":30,"value":1464}," directly. In a routed transaction, the owner may call an application contract, that contract may be the approved spender, and the token contract may debit the owner through ",{"type":25,"tag":123,"props":1466,"children":1468},{"className":1467},[],[1469],{"type":30,"value":1377},{"type":30,"value":1471},". In a disputed delegated transfer, the owner's address may appear only as the debited account.",{"type":25,"tag":26,"props":1473,"children":1474},{},[1475,1477,1483],{"type":30,"value":1476},"The next question is attribution to a person. An address-level finding does not establish who controlled the address at the relevant time. That requires the separate analysis described in ",{"type":25,"tag":38,"props":1478,"children":1480},{"href":1479},"\u002Fresources\u002Funderstanding-wallet-ownership-evidence",[1481],{"type":30,"value":1482},"understanding wallet ownership evidence",{"type":30,"value":280},{"type":25,"tag":55,"props":1485,"children":1487},{"id":1486},"how-does-an-erc-20-allowance-create-delegated-authority",[1488],{"type":30,"value":1489},"How does an ERC-20 allowance create delegated authority?",{"type":25,"tag":26,"props":1491,"children":1492},{},[1493,1495,1501,1503,1509,1511,1517],{"type":30,"value":1494},"Under ERC-20, ",{"type":25,"tag":123,"props":1496,"children":1498},{"className":1497},[],[1499],{"type":30,"value":1500},"approve(spender, value)",{"type":30,"value":1502}," sets the amount that a spender may withdraw from the owner's account. Calling ",{"type":25,"tag":123,"props":1504,"children":1506},{"className":1505},[],[1507],{"type":30,"value":1508},"approve",{"type":30,"value":1510}," again overwrites the existing allowance for that owner-spender pair. The standard's ",{"type":25,"tag":123,"props":1512,"children":1514},{"className":1513},[],[1515],{"type":30,"value":1516},"allowance(owner, spender)",{"type":30,"value":1518}," function reports how much the spender is still allowed to withdraw.",{"type":25,"tag":26,"props":1520,"children":1521},{},[1522,1524,1530],{"type":30,"value":1523},"An approval for a specific amount bounds the spender's authority by that value, subject to prior uses and the token's implementation. An approval set to the maximum ",{"type":25,"tag":123,"props":1525,"children":1527},{"className":1526},[],[1528],{"type":30,"value":1529},"uint256",{"type":30,"value":1531}," value is commonly treated as effectively unlimited because it may support repeated withdrawals. Standard ERC-20 approval data identifies a spender and amount, not the later recipient or business purpose.",{"type":25,"tag":26,"props":1533,"children":1534},{},[1535,1537,1543,1545,1550,1552,1557,1559,1564,1566,1571,1573,1578],{"type":30,"value":1536},"The events also have limits. ERC-20 requires an ",{"type":25,"tag":123,"props":1538,"children":1540},{"className":1539},[],[1541],{"type":30,"value":1542},"Approval",{"type":30,"value":1544}," event after a successful ",{"type":25,"tag":123,"props":1546,"children":1548},{"className":1547},[],[1549],{"type":30,"value":1508},{"type":30,"value":1551}," call and a ",{"type":25,"tag":123,"props":1553,"children":1555},{"className":1554},[],[1556],{"type":30,"value":1333},{"type":30,"value":1558}," event when tokens move. It does not require an ",{"type":25,"tag":123,"props":1560,"children":1562},{"className":1561},[],[1563],{"type":30,"value":1542},{"type":30,"value":1565}," event every time ",{"type":25,"tag":123,"props":1567,"children":1569},{"className":1568},[],[1570],{"type":30,"value":1377},{"type":30,"value":1572}," consumes allowance. An investigator should not assume the latest visible ",{"type":25,"tag":123,"props":1574,"children":1576},{"className":1575},[],[1577],{"type":30,"value":1542},{"type":30,"value":1579}," event equals the remaining allowance immediately before a disputed transfer.",{"type":25,"tag":55,"props":1581,"children":1583},{"id":1582},"how-should-counsel-reconstruct-the-approval-timeline",[1584],{"type":30,"value":1585},"How should counsel reconstruct the approval timeline?",{"type":25,"tag":26,"props":1587,"children":1588},{},[1589],{"type":30,"value":1590},"The key sequence is authority first, use second. A useful reconstruction proceeds as follows:",{"type":25,"tag":152,"props":1592,"children":1593},{},[1594,1604,1628,1638,1662,1679],{"type":25,"tag":156,"props":1595,"children":1596},{},[1597,1602],{"type":25,"tag":160,"props":1598,"children":1599},{},[1600],{"type":30,"value":1601},"Fix the chain, token contract, and block range.",{"type":30,"value":1603}," Record the contract address, chain identifier, transaction hashes, block numbers, and UTC timestamps. A ticker symbol is not enough.",{"type":25,"tag":156,"props":1605,"children":1606},{},[1607,1612,1614,1619,1621,1626],{"type":25,"tag":160,"props":1608,"children":1609},{},[1610],{"type":30,"value":1611},"Classify the movement.",{"type":30,"value":1613}," Decode the input and trace to determine whether the token received ",{"type":25,"tag":123,"props":1615,"children":1617},{"className":1616},[],[1618],{"type":30,"value":1462},{"type":30,"value":1620},", ",{"type":25,"tag":123,"props":1622,"children":1624},{"className":1623},[],[1625],{"type":30,"value":1377},{"type":30,"value":1627},", or an intermediary-contract call. Do not rely solely on an explorer's summary label.",{"type":25,"tag":156,"props":1629,"children":1630},{},[1631,1636],{"type":25,"tag":160,"props":1632,"children":1633},{},[1634],{"type":30,"value":1635},"Identify the immediate caller.",{"type":30,"value":1637}," The outer transaction sender and the contract that called the token may differ. The trace shows which address acted as spender at the token contract.",{"type":25,"tag":156,"props":1639,"children":1640},{},[1641,1646,1648,1653,1655,1660],{"type":25,"tag":160,"props":1642,"children":1643},{},[1644],{"type":30,"value":1645},"Locate the grant of authority.",{"type":30,"value":1647}," Search backward for relevant ",{"type":25,"tag":123,"props":1649,"children":1651},{"className":1650},[],[1652],{"type":30,"value":1542},{"type":30,"value":1654}," events and transactions involving the same owner, spender, and token. Determine whether authority arose from ",{"type":25,"tag":123,"props":1656,"children":1658},{"className":1657},[],[1659],{"type":30,"value":1508},{"type":30,"value":1661},", a permit, or a token-specific mechanism.",{"type":25,"tag":156,"props":1663,"children":1664},{},[1665,1670,1672,1677],{"type":25,"tag":160,"props":1666,"children":1667},{},[1668],{"type":30,"value":1669},"Calculate intervening use.",{"type":30,"value":1671}," Review prior ",{"type":25,"tag":123,"props":1673,"children":1675},{"className":1674},[],[1676],{"type":30,"value":1377},{"type":30,"value":1678}," calls, replacements, revocations, and failed calls. Where available, query contract state immediately before execution.",{"type":25,"tag":156,"props":1680,"children":1681},{},[1682,1687],{"type":25,"tag":160,"props":1683,"children":1684},{},[1685],{"type":30,"value":1686},"Preserve the data.",{"type":30,"value":1688}," Retain input, receipts, logs, traces, relevant contract code, ABI, and retrieval method. A screenshot is an orientation aid, not the complete record.",{"type":25,"tag":26,"props":1690,"children":1691},{},[1692,1694,1700],{"type":30,"value":1693},"Proxy contracts and upgrades can change the relevant code over time. The correct question is what logic governed the token at the disputed block, not what a current block-explorer page displays today. Our ",{"type":25,"tag":38,"props":1695,"children":1697},{"href":1696},"\u002Fservices#evidence-review",[1698],{"type":30,"value":1699},"evidence review work",{"type":30,"value":1701}," treats decoded explorer labels as leads to verify against contract data, not as substitutes for it.",{"type":25,"tag":55,"props":1703,"children":1705},{"id":1704},"what-changes-when-authority-comes-from-a-permit-signature",[1706],{"type":30,"value":1707},"What changes when authority comes from a permit signature?",{"type":25,"tag":26,"props":1709,"children":1710},{},[1711,1718,1720,1726,1728,1733],{"type":25,"tag":38,"props":1712,"children":1715},{"href":1713,"rel":1714},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-2612",[70],[1716],{"type":30,"value":1717},"ERC-2612",{"type":30,"value":1719}," adds a ",{"type":25,"tag":123,"props":1721,"children":1723},{"className":1722},[],[1724],{"type":30,"value":1725},"permit",{"type":30,"value":1727}," function that can set an ERC-20 allowance from a signed message. The signed fields include the owner, spender, value, nonce, and deadline. The token contract verifies the signature, updates the allowance, increments the owner's nonce, and emits an ",{"type":25,"tag":123,"props":1729,"children":1731},{"className":1730},[],[1732],{"type":30,"value":1542},{"type":30,"value":1734}," event if the standard's conditions are satisfied.",{"type":25,"tag":26,"props":1736,"children":1737},{},[1738,1740,1745],{"type":30,"value":1739},"The permit caller can be any address. The owner can sign off-chain, while a relayer, application, spender, or unrelated address pays gas and submits the permit. The permit transaction sender is therefore not necessarily the signature author. The permit grants allowance; it does not prove that the owner submitted or separately approved a later ",{"type":25,"tag":123,"props":1741,"children":1743},{"className":1742},[],[1744],{"type":30,"value":1377},{"type":30,"value":1746}," transaction.",{"type":25,"tag":26,"props":1748,"children":1749},{},[1750,1752,1759],{"type":30,"value":1751},"ERC-2612 uses ",{"type":25,"tag":38,"props":1753,"children":1756},{"href":1754,"rel":1755},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-712",[70],[1757],{"type":30,"value":1758},"EIP-712 typed structured-data signing",{"type":30,"value":1760},". Its domain can include a name, version, chain identifier, and verifying-contract address, helping distinguish similar messages intended for different applications or contracts. EIP-712 supplies the format and domain separation, but leaves replay protection to the application.",{"type":25,"tag":26,"props":1762,"children":1763},{},[1764],{"type":30,"value":1765},"ERC-2612 uses an owner nonce that must match and then increments, plus a deadline after which the permit must revert. The deadline can be set so far out that the authorization is effectively nonexpiring. Examine the domain, nonce, and deadline together. A signature image or shortened wallet prompt does not establish the complete signed data.",{"type":25,"tag":26,"props":1767,"children":1768},{},[1769,1771,1776],{"type":30,"value":1770},"Not every token with a function called ",{"type":25,"tag":123,"props":1772,"children":1774},{"className":1773},[],[1775],{"type":30,"value":1725},{"type":30,"value":1777}," implements ERC-2612 exactly. The standard itself notes preexisting variants with different fields and semantics. The analyst must use the deployed contract's code and ABI at the relevant block rather than forcing every signed approval into the ERC-2612 template.",{"type":25,"tag":55,"props":1779,"children":1781},{"id":1780},"what-does-the-transfer-prove-and-what-remains-unresolved",[1782],{"type":30,"value":1783},"What does the transfer prove, and what remains unresolved?",{"type":25,"tag":26,"props":1785,"children":1786},{},[1787],{"type":30,"value":1788},"A verified on-chain record can establish that contract execution changed token balances and emitted specified logs. Decoded input and traces can identify the outer transaction sender, immediate callers, owner argument, recipient, amount, and method. A valid permit can establish that a signature associated with the owner address covered the exact typed fields under the contract's rules.",{"type":25,"tag":26,"props":1790,"children":1791},{},[1792],{"type":30,"value":1793},"Those facts do not prove that a particular human knowingly authorized the disputed transfer. They do not establish who possessed the key, what the wallet displayed, whether the signer understood the authority, or whether another person had device access. They also do not resolve consent, agency, capacity, mistake, breach of duty, or fraud. Those conclusions depend on governing law and evidence beyond the ledger.",{"type":25,"tag":227,"props":1795,"children":1797},{"id":1796},"hypothetical-example",[1798],{"type":30,"value":1799},"Hypothetical example",{"type":25,"tag":26,"props":1801,"children":1802},{},[1803,1805,1811],{"type":30,"value":1804},"Assume Wallet O holds 80,000 units of Token T. On January 4, O signs an ERC-2612 permit authorizing Contract S to spend up to 80,000 units, with a deadline six months later. Relayer R submits the permit and pays the gas. On February 12, Address A calls S, and S executes ",{"type":25,"tag":123,"props":1806,"children":1808},{"className":1807},[],[1809],{"type":30,"value":1810},"transferFrom(O, B, 30,000)",{"type":30,"value":280},{"type":25,"tag":26,"props":1813,"children":1814},{},[1815],{"type":30,"value":1816},"The February transfer shows Token T debited O and credited B during execution initiated by A. The trace may show S as the spender, while the January permit identifies R as its submitter. Neither transaction proves that the human associated with O selected B or understood that the signature let S choose a later recipient. The investigation should recover the typed message, identify who controlled O and A, inspect S's code and call parameters, and seek device and communications evidence.",{"type":25,"tag":55,"props":1818,"children":1820},{"id":1819},"what-evidence-should-counsel-request-beyond-the-chain",[1821],{"type":30,"value":1822},"What evidence should counsel request beyond the chain?",{"type":25,"tag":26,"props":1824,"children":1825},{},[1826],{"type":30,"value":1827},"Discovery should target the authorization event as closely as the transfer event. Useful requests and examination questions include:",{"type":25,"tag":340,"props":1829,"children":1830},{},[1831,1836,1841,1846,1851,1856,1861,1866],{"type":25,"tag":156,"props":1832,"children":1833},{},[1834],{"type":30,"value":1835},"The wallet application, browser extension, hardware wallet, or custodial interface used when the approval or permit was created.",{"type":25,"tag":156,"props":1837,"children":1838},{},[1839],{"type":30,"value":1840},"Wallet records, device logs, browser history, notifications, and prompts showing what the user was presented.",{"type":25,"tag":156,"props":1842,"children":1843},{},[1844],{"type":30,"value":1845},"The exact EIP-712 typed-data payload, signature, domain fields, nonce, deadline, and originating website or application.",{"type":25,"tag":156,"props":1847,"children":1848},{},[1849],{"type":30,"value":1850},"Communications concerning the spender, transaction purpose, expected amount, intended recipient, and any claimed revocation.",{"type":25,"tag":156,"props":1852,"children":1853},{},[1854],{"type":30,"value":1855},"Evidence of remote access, malicious extensions, credential compromise, or shared key material.",{"type":25,"tag":156,"props":1857,"children":1858},{},[1859],{"type":30,"value":1860},"Exchange, custodian, or account records connecting the relevant addresses to identified persons.",{"type":25,"tag":156,"props":1862,"children":1863},{},[1864],{"type":30,"value":1865},"Source code, deployment records, upgrade history, and administrative controls for the token and spender contracts.",{"type":25,"tag":156,"props":1867,"children":1868},{},[1869],{"type":30,"value":1870},"Testimony explaining why the approval amount was chosen and whether the signer understood that approval and transfer were separate acts.",{"type":25,"tag":26,"props":1872,"children":1873},{},[1874,1876,1881],{"type":30,"value":1875},"Preserve timestamps, time zones, file metadata, and acquisition methods. Wallet prompts and local artifacts may disappear even though the on-chain record remains. The ",{"type":25,"tag":38,"props":1877,"children":1878},{"href":564},[1879],{"type":30,"value":1880},"ConsensusIntel methodology",{"type":30,"value":1882}," explains how technical findings are separated from attribution opinions and legal conclusions.",{"type":25,"tag":55,"props":1884,"children":1886},{"id":1885},"how-should-an-expert-describe-the-result",[1887],{"type":30,"value":1888},"How should an expert describe the result?",{"type":25,"tag":26,"props":1890,"children":1891},{},[1892],{"type":30,"value":1893},"Avoid language such as \"the owner sent the tokens\" unless the evidence actually establishes that proposition. A more precise formulation is:",{"type":25,"tag":1895,"props":1896,"children":1897},"blockquote",{},[1898],{"type":25,"tag":26,"props":1899,"children":1900},{},[1901,1903,1908,1910,1915],{"type":30,"value":1902},"Transaction X was signed by Address A. Its execution caused Token Contract T to emit a ",{"type":25,"tag":123,"props":1904,"children":1906},{"className":1905},[],[1907],{"type":30,"value":1333},{"type":30,"value":1909}," event debiting Owner Address O and crediting Recipient Address B. The execution trace shows Spender Contract S called ",{"type":25,"tag":123,"props":1911,"children":1913},{"className":1912},[],[1914],{"type":30,"value":1377},{"type":30,"value":1916},". An earlier approval authorized S to spend up to V units from O. The on-chain evidence does not, without additional attribution evidence, establish who controlled A or O, what a human signer understood, or whether O intended this specific transfer.",{"type":25,"tag":26,"props":1918,"children":1919},{},[1920,1922,1928],{"type":30,"value":1921},"If a permit is involved, the report should separately state whether the signature validated for the owner address, the exact fields covered, who submitted the permit transaction, and which later call exercised the allowance. This phrasing preserves strong technical conclusions while avoiding one of the ",{"type":25,"tag":38,"props":1923,"children":1925},{"href":1924},"\u002Fresources\u002Fcommon-mistakes-crypto-investigations",[1926],{"type":30,"value":1927},"common mistakes in cryptocurrency investigations",{"type":30,"value":1929},": treating address activity as self-proving evidence of a person's identity or intent.",{"type":25,"tag":55,"props":1931,"children":1932},{"id":616},[1933],{"type":30,"value":619},{"type":25,"tag":227,"props":1935,"children":1937},{"id":1936},"q-does-a-transfer-event-prove-the-token-owner-sent-the-transaction",[1938],{"type":30,"value":1939},"Q: Does a Transfer event prove the token owner sent the transaction?",{"type":25,"tag":26,"props":1941,"children":1942},{},[1943,1947,1949,1954,1956,1961],{"type":25,"tag":160,"props":1944,"children":1945},{},[1946],{"type":30,"value":633},{"type":30,"value":1948}," No. A ",{"type":25,"tag":123,"props":1950,"children":1952},{"className":1951},[],[1953],{"type":30,"value":1333},{"type":30,"value":1955}," event proves that the token contract recorded a movement from one address to another. If the movement resulted from ",{"type":25,"tag":123,"props":1957,"children":1959},{"className":1958},[],[1960],{"type":30,"value":1377},{"type":30,"value":1962},", an approved spender may have initiated it. The transaction input and execution trace are needed to identify the actual call path.",{"type":25,"tag":227,"props":1964,"children":1966},{"id":1965},"q-does-signing-a-permit-authorize-one-specific-transfer",[1967],{"type":30,"value":1968},"Q: Does signing a permit authorize one specific transfer?",{"type":25,"tag":26,"props":1970,"children":1971},{},[1972,1976],{"type":25,"tag":160,"props":1973,"children":1974},{},[1975],{"type":30,"value":633},{"type":30,"value":1977}," Not necessarily. A standard ERC-2612 permit authorizes a named spender up to a stated value, subject to a nonce and deadline. It does not name the eventual transfer recipient. The spender may use the resulting allowance in one or more later transactions within the authorization's bounds.",{"type":25,"tag":227,"props":1979,"children":1981},{"id":1980},"q-can-a-relayer-submit-a-permit-without-owning-the-tokens",[1982],{"type":30,"value":1983},"Q: Can a relayer submit a permit without owning the tokens?",{"type":25,"tag":26,"props":1985,"children":1986},{},[1987,1991],{"type":25,"tag":160,"props":1988,"children":1989},{},[1990],{"type":30,"value":633},{"type":30,"value":1992}," Yes. ERC-2612 does not tie the permit caller to the owner. Any address can submit a valid signed permit, while the token contract verifies that the signature corresponds to the owner and that the nonce and deadline conditions are satisfied.",{"type":25,"tag":227,"props":1994,"children":1996},{"id":1995},"q-what-is-the-most-important-evidence-outside-the-blockchain",[1997],{"type":30,"value":1998},"Q: What is the most important evidence outside the blockchain?",{"type":25,"tag":26,"props":2000,"children":2001},{},[2002,2006],{"type":25,"tag":160,"props":2003,"children":2004},{},[2005],{"type":30,"value":633},{"type":30,"value":2007}," The most useful evidence often includes the exact signed payload, wallet or device artifacts showing the signing context, records identifying who controlled each address, and communications about the spender and transaction purpose. Those materials address identity, knowledge, and intent that the ledger does not record.",{"type":25,"tag":26,"props":2009,"children":2010},{},[2011,2013,2018],{"type":30,"value":2012},"If a disputed token transfer turns on delegated authority, ",{"type":25,"tag":38,"props":2014,"children":2015},{"href":696},[2016],{"type":30,"value":2017},"contact ConsensusIntel",{"type":30,"value":2019}," to discuss the approval timeline, permit evidence, and limits of the available attribution.",{"title":7,"searchDepth":703,"depth":703,"links":2021},[2022,2023,2024,2025,2026,2027,2030,2031,2032],{"id":1289,"depth":703,"text":1292},{"id":1350,"depth":703,"text":1353},{"id":1486,"depth":703,"text":1489},{"id":1582,"depth":703,"text":1585},{"id":1704,"depth":703,"text":1707},{"id":1780,"depth":703,"text":1783,"children":2028},[2029],{"id":1796,"depth":709,"text":1799},{"id":1819,"depth":703,"text":1822},{"id":1885,"depth":703,"text":1888},{"id":616,"depth":703,"text":619,"children":2033},[2034,2035,2036,2037],{"id":1936,"depth":709,"text":1939},{"id":1965,"depth":709,"text":1968},{"id":1980,"depth":709,"text":1983},{"id":1995,"depth":709,"text":1998},"content:articles:26-token-approvals-permit-signatures.md","articles\u002F26-token-approvals-permit-signatures.md","articles\u002F26-token-approvals-permit-signatures",{"_path":2042,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":2043,"description":2044,"slug":2045,"date":2046,"lastUpdated":2046,"author":12,"readingTime":2047,"category":14,"tags":2048,"ogImage":2054,"featured":6,"body":2055,"_type":727,"_id":2348,"_source":729,"_file":2349,"_stem":2350,"_extension":732},"\u002Farticles\u002F17-cryptocurrency-wrong-address-irrecoverability","What happens when cryptocurrency is sent to the wrong address","Learn why a cryptocurrency transfer to the wrong address is usually irreversible, which recovery paths may remain, and how counsel can assess them.","cryptocurrency-wrong-address-irrecoverability","2026-05-16",7,[2049,2050,2051,1271,2052,2053],"irreversibility","blockchain-evidence","recovery","bitcoin","ethereum","\u002Fog\u002Fcryptocurrency-wrong-address-irrecoverability.png",{"type":22,"children":2056,"toc":2335},[2057,2062,2068,2073,2078,2083,2089,2099,2109,2119,2129,2139,2165,2171,2176,2192,2202,2212,2218,2223,2228,2233,2238,2244,2255,2260,2271,2275,2281,2290,2296,2305,2311,2320,2326],{"type":25,"tag":26,"props":2058,"children":2059},{},[2060],{"type":30,"value":2061},"One of the most consequential properties of public blockchain systems is the near-total irreversibility of confirmed transactions. When cryptocurrency is sent to the wrong address: through a typographical error, a scam, a technical mistake, or a moment of confusion, recovery is rarely possible through the same mechanisms that allow bank wire reversals or credit card chargebacks. Understanding why, and what options actually exist, is essential for attorneys handling client matters involving this scenario.",{"type":25,"tag":55,"props":2063,"children":2065},{"id":2064},"why-transfers-cannot-be-reversed",[2066],{"type":30,"value":2067},"Why Transfers Cannot Be Reversed",{"type":25,"tag":26,"props":2069,"children":2070},{},[2071],{"type":30,"value":2072},"Blockchain transactions are irreversible by design. When a transaction is confirmed and included in a block, the record of that transfer is incorporated into an append-only ledger replicated across thousands of nodes worldwide. No single party, not an exchange, not a developer, not any government, has the technical authority to reach into the ledger and undo a confirmed transaction.",{"type":25,"tag":26,"props":2074,"children":2075},{},[2076],{"type":30,"value":2077},"This is not a policy choice that can be reversed by calling customer service. It is an architectural feature. The value of the immutability guarantee, which makes blockchain records trustworthy as evidence, is inseparable from the fact that no one can alter records after the fact, including to correct a mistake.",{"type":25,"tag":26,"props":2079,"children":2080},{},[2081],{"type":30,"value":2082},"The private key controls the funds. Whoever possesses the private key for the destination address can authorize the next transaction from that address. If the destination address is controlled by an unintended third party, recovery requires that party's cooperation. If the destination address has no known controller, a burned or unspendable address, recovery is impossible.",{"type":25,"tag":55,"props":2084,"children":2086},{"id":2085},"scenarios-and-what-each-means",[2087],{"type":30,"value":2088},"Scenarios and What Each Means",{"type":25,"tag":26,"props":2090,"children":2091},{},[2092,2097],{"type":25,"tag":160,"props":2093,"children":2094},{},[2095],{"type":30,"value":2096},"Typo resulting in a valid but unintended address",{"type":30,"value":2098},": If a sender mistypes a wallet address and the resulting address is a valid address that happens to exist on the blockchain, the funds are received by whoever controls that address, or they sit at an address with no known controller. Most addresses generated by random typos will be uncontrolled, no one has the private key, but the funds are still irretrievable because no private key exists to authorize a transaction out.",{"type":25,"tag":26,"props":2100,"children":2101},{},[2102,2107],{"type":25,"tag":160,"props":2103,"children":2104},{},[2105],{"type":30,"value":2106},"Hypothetical example:",{"type":30,"value":2108}," A sender transposes characters while entering an address and sends funds to a valid address with no known controller. Once the transfer is confirmed, the sender cannot authorize a new transaction from that destination without its private key.",{"type":25,"tag":26,"props":2110,"children":2111},{},[2112,2117],{"type":25,"tag":160,"props":2113,"children":2114},{},[2115],{"type":30,"value":2116},"Funds sent to a known exchange address",{"type":30,"value":2118},": If the destination address belongs to a centralized exchange (Coinbase, Kraken, Binance, etc.), the exchange controls the private key. Exchanges generally have processes for recovering mistakenly sent funds into their hot wallet infrastructure, but these processes are discretionary, may require extensive documentation, and often involve fees. Some exchanges refuse to assist at all. There is no legal obligation in most jurisdictions requiring an exchange to return mistakenly sent funds, though restitution and unjust enrichment theories may provide an equitable basis for a claim.",{"type":25,"tag":26,"props":2120,"children":2121},{},[2122,2127],{"type":25,"tag":160,"props":2123,"children":2124},{},[2125],{"type":30,"value":2126},"Funds sent to a smart contract address",{"type":30,"value":2128},": Many cryptocurrency tokens sent to a smart contract that has no function to return or handle them are permanently locked. The classic example is ERC-20 tokens sent to the ERC-20 token contract itself: a common mistake. The contract typically has no function to recover such tokens, and because the contract is code (not a human-controlled wallet), no one can override it. Hundreds of millions of dollars in ERC-20 tokens have been permanently locked this way.",{"type":25,"tag":26,"props":2130,"children":2131},{},[2132,2137],{"type":25,"tag":160,"props":2133,"children":2134},{},[2135],{"type":30,"value":2136},"Funds sent through a scam",{"type":30,"value":2138},": When a victim sends cryptocurrency in response to a phishing email, impersonation scam, or other fraud, the destination address was provided by the scammer, who controls the private key and will immediately move the funds. This is a theft scenario, not a transaction error, and is analyzed differently forensically.",{"type":25,"tag":26,"props":2140,"children":2141},{},[2142,2147,2149,2155,2157,2163],{"type":25,"tag":160,"props":2143,"children":2144},{},[2145],{"type":30,"value":2146},"The \"burned\" address scenario",{"type":30,"value":2148},": Some addresses are known to be unspendable by design. The most common is address ",{"type":25,"tag":123,"props":2150,"children":2152},{"className":2151},[],[2153],{"type":30,"value":2154},"0x000...0000",{"type":30,"value":2156}," (the zero address on Ethereum) or ",{"type":25,"tag":123,"props":2158,"children":2160},{"className":2159},[],[2161],{"type":30,"value":2162},"1BitcoinEaterAddressDoNotSend...",{"type":30,"value":2164}," on Bitcoin. Sending to these addresses permanently destroys the asset: the transaction is confirmed, the funds are received at the address, and no private key exists to move them.",{"type":25,"tag":55,"props":2166,"children":2168},{"id":2167},"legal-options-for-recovery",[2169],{"type":30,"value":2170},"Legal Options for Recovery",{"type":25,"tag":26,"props":2172,"children":2173},{},[2174],{"type":30,"value":2175},"Because blockchain transactions cannot be reversed by the sender, legal recovery requires either cooperation from the recipient or legal process compelling that cooperation.",{"type":25,"tag":26,"props":2177,"children":2178},{},[2179,2184,2186,2191],{"type":25,"tag":160,"props":2180,"children":2181},{},[2182],{"type":30,"value":2183},"Against a known exchange",{"type":30,"value":2185},": If forensic tracing establishes that the funds reached a centralized exchange wallet, and the exchange maintains customer records for that wallet, a legal demand or civil action may compel the exchange to hold and return the funds. The legal theory typically involves unjust enrichment, constructive trust, or restitution. The success of this approach depends on whether the exchange has a segregated customer account for the receiving address or pooled funds in an omnibus wallet. Counsel considering that path may also need to evaluate ",{"type":25,"tag":38,"props":2187,"children":2188},{"href":355},[2189],{"type":30,"value":2190},"subpoenaing cryptocurrency exchange records",{"type":30,"value":280},{"type":25,"tag":26,"props":2193,"children":2194},{},[2195,2200],{"type":25,"tag":160,"props":2196,"children":2197},{},[2198],{"type":30,"value":2199},"Against an identified scammer",{"type":30,"value":2201},": If the recipient is identified through exchange KYC records or other evidence, conventional fraud and theft remedies apply. The blockchain evidence establishing the fund flow is an essential component of the claim.",{"type":25,"tag":26,"props":2203,"children":2204},{},[2205,2210],{"type":25,"tag":160,"props":2206,"children":2207},{},[2208],{"type":30,"value":2209},"Against a party who made the error",{"type":30,"value":2211},": In some disputes, the wrongly addressed transaction was a mistake by a third party, a business partner, an employee, a financial professional, who sent funds to the wrong address. Negligence or breach of fiduciary duty claims against that party may be available regardless of whether the funds themselves are recoverable.",{"type":25,"tag":55,"props":2213,"children":2215},{"id":2214},"what-cannot-be-done",[2216],{"type":30,"value":2217},"What Cannot Be Done",{"type":25,"tag":26,"props":2219,"children":2220},{},[2221],{"type":30,"value":2222},"It is important to be clear with clients about what is not possible:",{"type":25,"tag":26,"props":2224,"children":2225},{},[2226],{"type":30,"value":2227},"No authority can reverse a confirmed blockchain transaction. The FBI, the SEC, and federal courts do not have the technical ability to reverse blockchain transfers. Courts can compel parties to transfer assets from their controlled addresses. They cannot reach into the blockchain and rearrange already-confirmed records.",{"type":25,"tag":26,"props":2229,"children":2230},{},[2231],{"type":30,"value":2232},"Blockchain analytics firms cannot recover funds. They can trace where funds went, identify the controlling party, and assist in locating the funds within the system, but that is investigation, not recovery.",{"type":25,"tag":26,"props":2234,"children":2235},{},[2236],{"type":30,"value":2237},"Exchange customer support cannot typically assist when the receiving address is not an exchange address. If the funds went to a private wallet that neither the sender nor the exchange controls, the exchange has no access to those funds.",{"type":25,"tag":55,"props":2239,"children":2241},{"id":2240},"the-forensic-role",[2242],{"type":30,"value":2243},"The Forensic Role",{"type":25,"tag":26,"props":2245,"children":2246},{},[2247,2249,2253],{"type":30,"value":2248},"A blockchain forensic expert can establish: the exact transaction details (hash, timestamp, amount, source, destination), confirmation that the transaction was final and included in the blockchain, the current state of the destination address (whether funds remain there or were subsequently moved), and, if funds were moved, where they went and whether they can be attributed to an identified party. This type of ",{"type":25,"tag":38,"props":2250,"children":2251},{"href":427},[2252],{"type":30,"value":430},{"type":30,"value":2254}," helps determine whether recovery efforts can focus on an identifiable recipient or institution.",{"type":25,"tag":26,"props":2256,"children":2257},{},[2258],{"type":30,"value":2259},"This establishes the evidentiary record for any legal proceeding. The tracing analysis also determines whether legal process against an exchange or other institution is viable. If the funds reached an exchange wallet and remain there, the case for legal intervention is much stronger than if they moved through multiple wallets to a private address that cannot be attributed to anyone.",{"type":25,"tag":26,"props":2261,"children":2262},{},[2263,2265,2269],{"type":30,"value":2264},"The irreversibility of blockchain transactions is one of the most important practical realities attorneys must communicate to clients early in a matter. Setting accurate expectations while pursuing available legal remedies requires understanding both what the technology makes impossible and what the law may still provide. The ",{"type":25,"tag":38,"props":2266,"children":2267},{"href":564},[2268],{"type":30,"value":567},{"type":30,"value":2270}," for documenting transaction evidence can help counsel assess the available next steps.",{"type":25,"tag":55,"props":2272,"children":2273},{"id":616},[2274],{"type":30,"value":619},{"type":25,"tag":227,"props":2276,"children":2278},{"id":2277},"q-what-information-should-counsel-preserve-before-deciding-whether-recovery-is-realistic",[2279],{"type":30,"value":2280},"Q: What information should counsel preserve before deciding whether recovery is realistic?",{"type":25,"tag":26,"props":2282,"children":2283},{},[2284,2288],{"type":25,"tag":160,"props":2285,"children":2286},{},[2287],{"type":30,"value":633},{"type":30,"value":2289}," Preserve the transaction hash, timestamp, amount, source address, destination address, and records showing how the address was obtained or used. A forensic expert can verify the confirmed transfer, determine whether the funds remain at the destination, and trace later movements. Those facts help show whether an identifiable recipient, exchange, or other institution is a viable target for legal process.",{"type":25,"tag":227,"props":2291,"children":2293},{"id":2292},"q-can-a-court-order-a-confirmed-cryptocurrency-transfer-to-be-reversed",[2294],{"type":30,"value":2295},"Q: Can a court order a confirmed cryptocurrency transfer to be reversed?",{"type":25,"tag":26,"props":2297,"children":2298},{},[2299,2303],{"type":25,"tag":160,"props":2300,"children":2301},{},[2302],{"type":30,"value":633},{"type":30,"value":2304}," No. A court cannot alter an already confirmed blockchain record. It can order a person or entity that controls the destination address to transfer assets, so the available remedy depends on identifying a party with control of the funds.",{"type":25,"tag":227,"props":2306,"children":2308},{"id":2307},"q-when-is-it-worth-seeking-records-or-relief-from-an-exchange",[2309],{"type":30,"value":2310},"Q: When is it worth seeking records or relief from an exchange?",{"type":25,"tag":26,"props":2312,"children":2313},{},[2314,2318],{"type":25,"tag":160,"props":2315,"children":2316},{},[2317],{"type":30,"value":633},{"type":30,"value":2319}," It is worth evaluating when tracing shows that the funds reached an exchange wallet. Exchange records may identify the customer associated with the wallet, but the result can depend on whether the exchange used a segregated customer account or pooled funds in an omnibus wallet. Documentation, fees, and the exchange's willingness to assist may also affect a practical recovery effort.",{"type":25,"tag":227,"props":2321,"children":2323},{"id":2322},"q-how-should-counsel-distinguish-a-wrong-address-error-from-a-cryptocurrency-scam",[2324],{"type":30,"value":2325},"Q: How should counsel distinguish a wrong-address error from a cryptocurrency scam?",{"type":25,"tag":26,"props":2327,"children":2328},{},[2329,2333],{"type":25,"tag":160,"props":2330,"children":2331},{},[2332],{"type":30,"value":633},{"type":30,"value":2334}," A mistaken transfer can place funds at a valid address with no known controller, while a scam transfer is made to an address supplied by a fraudster who controls the private key. The distinction depends on the surrounding evidence, such as phishing or impersonation communications, not on the transaction record alone. If the recipient can be identified through exchange KYC records or other evidence, fraud and theft remedies may be available.",{"title":7,"searchDepth":703,"depth":703,"links":2336},[2337,2338,2339,2340,2341,2342],{"id":2064,"depth":703,"text":2067},{"id":2085,"depth":703,"text":2088},{"id":2167,"depth":703,"text":2170},{"id":2214,"depth":703,"text":2217},{"id":2240,"depth":703,"text":2243},{"id":616,"depth":703,"text":619,"children":2343},[2344,2345,2346,2347],{"id":2277,"depth":709,"text":2280},{"id":2292,"depth":709,"text":2295},{"id":2307,"depth":709,"text":2310},{"id":2322,"depth":709,"text":2325},"content:articles:17-cryptocurrency-wrong-address-irrecoverability.md","articles\u002F17-cryptocurrency-wrong-address-irrecoverability.md","articles\u002F17-cryptocurrency-wrong-address-irrecoverability",{"_path":2352,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":2353,"description":2354,"slug":2355,"date":2046,"lastUpdated":2046,"author":12,"readingTime":2356,"category":14,"tags":2357,"ogImage":2363,"featured":6,"body":2364,"_type":727,"_id":2857,"_source":729,"_file":2858,"_stem":2859,"_extension":732},"\u002Farticles\u002F16-cryptocurrency-bankruptcy-trustee-checklist","Cryptocurrency in bankruptcy: a trustee's investigation checklist","A checklist for bankruptcy trustees and creditors' counsel to identify, trace, and value cryptocurrency assets during insolvency investigations.","cryptocurrency-bankruptcy-trustee-checklist",8,[2358,2359,2360,2361,2362],"bankruptcy","trustee","hidden-assets","asset-discovery","digital-assets","\u002Fog\u002Fcryptocurrency-bankruptcy-trustee-checklist.png",{"type":22,"children":2365,"toc":2838},[2366,2371,2377,2382,2387,2392,2398,2404,2409,2437,2442,2448,2453,2471,2476,2482,2495,2523,2528,2534,2539,2562,2567,2572,2578,2583,2588,2611,2617,2622,2632,2642,2652,2662,2672,2678,2683,2701,2706,2711,2717,2722,2750,2755,2774,2778,2784,2793,2799,2808,2814,2823,2829],{"type":25,"tag":26,"props":2367,"children":2368},{},[2369],{"type":30,"value":2370},"Cryptocurrency has become a significant concealment vehicle in bankruptcy proceedings. The same properties that attracted early adopters, self-custody, no institutional intermediaries, pseudonymous addresses, make digital assets attractive to debtors attempting to shelter value from creditors. For trustees and creditors' counsel, the investigative approach to cryptocurrency assets is fundamentally different from the approach to traditional financial accounts, and requires different tools.",{"type":25,"tag":55,"props":2372,"children":2374},{"id":2373},"why-cryptocurrency-presents-a-discovery-challenge",[2375],{"type":30,"value":2376},"Why Cryptocurrency Presents a Discovery Challenge",{"type":25,"tag":26,"props":2378,"children":2379},{},[2380],{"type":30,"value":2381},"A bank account belongs to a named account holder at an institution. The institution has records. A trustee can subpoena the bank, get account statements, and establish the balance. A cryptocurrency wallet is not a bank account. It has no institution, no account number in the traditional sense, and no bank to subpoena. What exists instead is a public-key address on a blockchain and a private key, typically stored on a device or as a written seed phrase, that authorizes transactions from that address.",{"type":25,"tag":26,"props":2383,"children":2384},{},[2385],{"type":30,"value":2386},"If the debtor controls a wallet and declines to disclose it, there is no institution the trustee can call. The wallet address may not appear in any traditional financial record. The balance may be substantial. Without specific investigative steps targeting digital assets, significant value can be concealed in plain sight.",{"type":25,"tag":26,"props":2388,"children":2389},{},[2390],{"type":30,"value":2391},"A further complication: digital asset values are highly volatile. A cryptocurrency holding worth $50,000 at one point in time may be worth $200,000 or $15,000 at another. The timing of valuation relative to the petition date and to any pre-petition transfers is legally and practically significant.",{"type":25,"tag":55,"props":2393,"children":2395},{"id":2394},"the-investigation-checklist",[2396],{"type":30,"value":2397},"The Investigation Checklist",{"type":25,"tag":227,"props":2399,"children":2401},{"id":2400},"step-1-compel-full-disclosure-in-schedules-and-sofa",[2402],{"type":30,"value":2403},"Step 1: Compel Full Disclosure in Schedules and SOFA",{"type":25,"tag":26,"props":2405,"children":2406},{},[2407],{"type":30,"value":2408},"The bankruptcy schedules and Statement of Financial Affairs are signed under penalty of perjury. Specifically request:",{"type":25,"tag":340,"props":2410,"children":2411},{},[2412,2417,2422,2427,2432],{"type":25,"tag":156,"props":2413,"children":2414},{},[2415],{"type":30,"value":2416},"All cryptocurrency holdings as of the petition date, including amounts, asset types, and wallet addresses",{"type":25,"tag":156,"props":2418,"children":2419},{},[2420],{"type":30,"value":2421},"All cryptocurrency accounts at exchanges or custodians (Coinbase, Kraken, Binance, Gemini, etc.)",{"type":25,"tag":156,"props":2423,"children":2424},{},[2425],{"type":30,"value":2426},"All cryptocurrency transactions in the two years before the petition date (preference period and beyond)",{"type":25,"tag":156,"props":2428,"children":2429},{},[2430],{"type":30,"value":2431},"Hardware wallets, USB devices, or paper seed phrases in the debtor's possession",{"type":25,"tag":156,"props":2433,"children":2434},{},[2435],{"type":30,"value":2436},"Any cryptocurrency held by third parties on the debtor's behalf",{"type":25,"tag":26,"props":2438,"children":2439},{},[2440],{"type":30,"value":2441},"Cryptocurrency-specific questioning is essential. General asset disclosure questions rarely prompt full disclosure of digital holdings because debtors may not consider them \"accounts\" in the traditional sense.",{"type":25,"tag":227,"props":2443,"children":2445},{"id":2444},"step-2-obtain-tax-records",[2446],{"type":30,"value":2447},"Step 2: Obtain Tax Records",{"type":25,"tag":26,"props":2449,"children":2450},{},[2451],{"type":30,"value":2452},"IRS Form 8949 and Schedule D report capital gains and losses from cryptocurrency transactions. A debtor who traded or sold cryptocurrency but disclosed no digital asset holdings is a significant red flag. Request:",{"type":25,"tag":340,"props":2454,"children":2455},{},[2456,2461,2466],{"type":25,"tag":156,"props":2457,"children":2458},{},[2459],{"type":30,"value":2460},"Three to five years of federal tax returns",{"type":25,"tag":156,"props":2462,"children":2463},{},[2464],{"type":30,"value":2465},"Any IRS CP2000 notices or other correspondence about cryptocurrency reporting",{"type":25,"tag":156,"props":2467,"children":2468},{},[2469],{"type":30,"value":2470},"State tax returns if the jurisdiction taxes capital gains separately",{"type":25,"tag":26,"props":2472,"children":2473},{},[2474],{"type":30,"value":2475},"The IRS has aggressively pursued cryptocurrency reporting compliance, including information returns from exchanges. If the debtor received a 1099-DA or similar form from an exchange, that form establishes that exchange account.",{"type":25,"tag":227,"props":2477,"children":2479},{"id":2478},"step-3-subpoena-known-exchange-accounts",[2480],{"type":30,"value":2481},"Step 3: Subpoena Known Exchange Accounts",{"type":25,"tag":26,"props":2483,"children":2484},{},[2485,2487,2493],{"type":30,"value":2486},"Any exchange account identified through disclosure, tax records, or other discovery should be subpoenaed immediately. ",{"type":25,"tag":38,"props":2488,"children":2490},{"href":2489},"\u002Fservices#exchange-custody",[2491],{"type":30,"value":2492},"Exchange and custody record review",{"type":30,"value":2494}," can produce:",{"type":25,"tag":340,"props":2496,"children":2497},{},[2498,2503,2508,2513,2518],{"type":25,"tag":156,"props":2499,"children":2500},{},[2501],{"type":30,"value":2502},"Account registration information (KYC documents, email address, phone number)",{"type":25,"tag":156,"props":2504,"children":2505},{},[2506],{"type":30,"value":2507},"Complete transaction history: deposits, withdrawals, trades",{"type":25,"tag":156,"props":2509,"children":2510},{},[2511],{"type":30,"value":2512},"Associated payment methods: bank accounts used for fiat deposits or withdrawals",{"type":25,"tag":156,"props":2514,"children":2515},{},[2516],{"type":30,"value":2517},"IP address logs and login history",{"type":25,"tag":156,"props":2519,"children":2520},{},[2521],{"type":30,"value":2522},"Any linked wallets (withdrawal addresses the debtor used)",{"type":25,"tag":26,"props":2524,"children":2525},{},[2526],{"type":30,"value":2527},"The withdrawal addresses in exchange account records are often the most valuable discovery output. These addresses link the exchange account to on-chain wallets the debtor controls: potentially wallets they did not disclose in schedules.",{"type":25,"tag":227,"props":2529,"children":2531},{"id":2530},"step-4-trace-withdrawal-addresses-on-chain",[2532],{"type":30,"value":2533},"Step 4: Trace Withdrawal Addresses On-Chain",{"type":25,"tag":26,"props":2535,"children":2536},{},[2537],{"type":30,"value":2538},"Every withdrawal address extracted from exchange records should be treated as an investigative lead. A blockchain forensic analyst can:",{"type":25,"tag":340,"props":2540,"children":2541},{},[2542,2547,2552,2557],{"type":25,"tag":156,"props":2543,"children":2544},{},[2545],{"type":30,"value":2546},"Determine the current balance at each address",{"type":25,"tag":156,"props":2548,"children":2549},{},[2550],{"type":30,"value":2551},"Identify any subsequent transfers out of those addresses (the debtor may have moved funds to secondary wallets)",{"type":25,"tag":156,"props":2553,"children":2554},{},[2555],{"type":30,"value":2556},"Identify any re-deposits at other exchanges, creating additional subpoena targets",{"type":25,"tag":156,"props":2558,"children":2559},{},[2560],{"type":30,"value":2561},"Map the full wallet cluster controlled by the debtor",{"type":25,"tag":26,"props":2563,"children":2564},{},[2565],{"type":30,"value":2566},"This step frequently uncovers wallets not disclosed in schedules and identifies additional exchange accounts the debtor did not voluntarily disclose.",{"type":25,"tag":26,"props":2568,"children":2569},{},[2570],{"type":30,"value":2571},"Hypothetical example: An exchange production identifies a withdrawal address absent from a debtor's schedules. On-chain records show a later deposit from that address to another exchange. The second exchange becomes an additional potential subpoena target.",{"type":25,"tag":227,"props":2573,"children":2575},{"id":2574},"step-5-search-for-pre-petition-transfers",[2576],{"type":30,"value":2577},"Step 5: Search for Pre-Petition Transfers",{"type":25,"tag":26,"props":2579,"children":2580},{},[2581],{"type":30,"value":2582},"The bankruptcy trustee's core tool for fraudulent transfers, Section 548 of the Bankruptcy Code, requires tracing transfers made before the petition date. Cryptocurrency transfers are well-suited for this analysis because the blockchain records every transfer with a precise timestamp.",{"type":25,"tag":26,"props":2584,"children":2585},{},[2586],{"type":30,"value":2587},"Investigate:",{"type":25,"tag":340,"props":2589,"children":2590},{},[2591,2596,2601,2606],{"type":25,"tag":156,"props":2592,"children":2593},{},[2594],{"type":30,"value":2595},"Any transfers from known wallets in the two years before the petition date (and further back for actual fraud claims)",{"type":25,"tag":156,"props":2597,"children":2598},{},[2599],{"type":30,"value":2600},"Transfers to addresses associated with family members, business partners, or related entities",{"type":25,"tag":156,"props":2602,"children":2603},{},[2604],{"type":30,"value":2605},"Large transfers that occurred as financial difficulty became apparent",{"type":25,"tag":156,"props":2607,"children":2608},{},[2609],{"type":30,"value":2610},"Conversion of cryptocurrency to privacy coins (Monero, Zcash) or through mixing services in the pre-petition period, which may indicate deliberate concealment",{"type":25,"tag":227,"props":2612,"children":2614},{"id":2613},"step-6-search-publicly-available-data",[2615],{"type":30,"value":2616},"Step 6: Search Publicly Available Data",{"type":25,"tag":26,"props":2618,"children":2619},{},[2620],{"type":30,"value":2621},"Several investigative sources can surface undisclosed cryptocurrency activity without subpoena:",{"type":25,"tag":26,"props":2623,"children":2624},{},[2625,2630],{"type":25,"tag":160,"props":2626,"children":2627},{},[2628],{"type":30,"value":2629},"Public blockchain data",{"type":30,"value":2631},": All transactions on Bitcoin, Ethereum, and other public blockchains are publicly accessible. A forensic analyst can search for blockchain addresses associated with the debtor's email, known device identifiers, or other identifying information.",{"type":25,"tag":26,"props":2633,"children":2634},{},[2635,2640],{"type":25,"tag":160,"props":2636,"children":2637},{},[2638],{"type":30,"value":2639},"Exchange data leaks",{"type":30,"value":2641},": Several major exchanges have experienced data breaches where customer email addresses or usernames were publicly exposed. If the debtor's email appears in such a dataset associated with an exchange account, it establishes that account's existence even if not disclosed in schedules.",{"type":25,"tag":26,"props":2643,"children":2644},{},[2645,2650],{"type":25,"tag":160,"props":2646,"children":2647},{},[2648],{"type":30,"value":2649},"Social media and online forums",{"type":30,"value":2651},": Debtors who participated in cryptocurrency communities, promoted projects, or received payments in connection with blockchain activities may have disclosed wallet addresses in forum posts, on GitHub, or in other public contexts.",{"type":25,"tag":26,"props":2653,"children":2654},{},[2655,2660],{"type":25,"tag":160,"props":2656,"children":2657},{},[2658],{"type":30,"value":2659},"OpenSea and NFT marketplace profiles",{"type":30,"value":2661},": Debtors who held or traded NFTs may have public marketplace profiles linked to wallet addresses. These addresses can be traced.",{"type":25,"tag":26,"props":2663,"children":2664},{},[2665,2670],{"type":25,"tag":160,"props":2666,"children":2667},{},[2668],{"type":30,"value":2669},"DeFi protocol interactions",{"type":30,"value":2671},": Debtors who participated in DeFi, lending, yield farming, liquidity provision, may have significant value locked in protocol positions that do not appear as a simple wallet balance. An analyst familiar with DeFi protocols can identify and value these positions.",{"type":25,"tag":227,"props":2673,"children":2675},{"id":2674},"step-7-value-the-assets-correctly",[2676],{"type":30,"value":2677},"Step 7: Value the Assets Correctly",{"type":25,"tag":26,"props":2679,"children":2680},{},[2681],{"type":30,"value":2682},"Cryptocurrency valuation requires careful attention to the relevant date. For bankruptcy purposes, assets are typically valued as of the petition date. This requires:",{"type":25,"tag":340,"props":2684,"children":2685},{},[2686,2691,2696],{"type":25,"tag":156,"props":2687,"children":2688},{},[2689],{"type":30,"value":2690},"The specific assets held at each address as of the petition date (confirmed via historical blockchain data)",{"type":25,"tag":156,"props":2692,"children":2693},{},[2694],{"type":30,"value":2695},"The market price of those assets on the petition date, from a verifiable exchange rate source",{"type":25,"tag":156,"props":2697,"children":2698},{},[2699],{"type":30,"value":2700},"A conversion to USD using that rate",{"type":25,"tag":26,"props":2702,"children":2703},{},[2704],{"type":30,"value":2705},"If assets were transferred before the petition date, valuation of those transfers for avoidance purposes requires the market price on the date of each transfer.",{"type":25,"tag":26,"props":2707,"children":2708},{},[2709],{"type":30,"value":2710},"For tax purposes and proof of claim purposes, different valuation dates may apply. Document each valuation date and its source explicitly.",{"type":25,"tag":55,"props":2712,"children":2714},{"id":2713},"when-to-engage-a-forensic-expert",[2715],{"type":30,"value":2716},"When to Engage a Forensic Expert",{"type":25,"tag":26,"props":2718,"children":2719},{},[2720],{"type":30,"value":2721},"In straightforward matters, a debtor with a single disclosed exchange account and modest holdings, a trustee may not need a forensic expert. In matters where:",{"type":25,"tag":340,"props":2723,"children":2724},{},[2725,2730,2735,2740,2745],{"type":25,"tag":156,"props":2726,"children":2727},{},[2728],{"type":30,"value":2729},"The debtor's schedules are suspicious or incomplete",{"type":25,"tag":156,"props":2731,"children":2732},{},[2733],{"type":30,"value":2734},"Significant unexplained wealth or lifestyle exists relative to disclosed assets",{"type":25,"tag":156,"props":2736,"children":2737},{},[2738],{"type":30,"value":2739},"The debtor has a known connection to cryptocurrency trading, development, or DeFi activity",{"type":25,"tag":156,"props":2741,"children":2742},{},[2743],{"type":30,"value":2744},"Pre-petition transfers are suspected",{"type":25,"tag":156,"props":2746,"children":2747},{},[2748],{"type":30,"value":2749},"The exchange records reveal withdrawal addresses with significant subsequent activity",{"type":25,"tag":26,"props":2751,"children":2752},{},[2753],{"type":30,"value":2754},"...engagement of a blockchain forensic expert to trace on-chain activity, identify undisclosed wallets, and map fund flows is appropriate and frequently results in discovery that increases the estate.",{"type":25,"tag":26,"props":2756,"children":2757},{},[2758,2760,2766,2768,2772],{"type":30,"value":2759},"The blockchain is not searchable by name. It does not produce a list of wallets belonging to a given person. The investigative approach requires connecting the debtor to specific addresses through exchange records, disclosure, and behavioral pattern analysis. ",{"type":25,"tag":38,"props":2761,"children":2763},{"href":2762},"\u002Fresources\u002Fcan-blockchain-transactions-be-traced",[2764],{"type":30,"value":2765},"How blockchain transactions can be traced",{"type":30,"value":2767}," describes the on-chain portion of that work. The ",{"type":25,"tag":38,"props":2769,"children":2770},{"href":564},[2771],{"type":30,"value":567},{"type":30,"value":2773}," for documenting those connections supports a clear record once an address is identified.",{"type":25,"tag":55,"props":2775,"children":2776},{"id":616},[2777],{"type":30,"value":619},{"type":25,"tag":227,"props":2779,"children":2781},{"id":2780},"q-after-an-exchange-subpoena-produces-withdrawal-addresses-what-should-i-do-first",[2782],{"type":30,"value":2783},"Q: After an exchange subpoena produces withdrawal addresses, what should I do first?",{"type":25,"tag":26,"props":2785,"children":2786},{},[2787,2791],{"type":25,"tag":160,"props":2788,"children":2789},{},[2790],{"type":30,"value":633},{"type":30,"value":2792}," Treat each withdrawal address as an investigative lead and trace its current balance and subsequent transfers on-chain. Look for re-deposits at other exchanges, because they can identify additional subpoena targets. Compare the resulting activity with the debtor's schedules to identify wallets that may not have been disclosed.",{"type":25,"tag":227,"props":2794,"children":2796},{"id":2795},"q-can-i-say-an-on-chain-wallet-belongs-to-the-debtor-just-because-an-exchange-sent-assets-to-it",[2797],{"type":30,"value":2798},"Q: Can I say an on-chain wallet belongs to the debtor just because an exchange sent assets to it?",{"type":25,"tag":26,"props":2800,"children":2801},{},[2802,2806],{"type":25,"tag":160,"props":2803,"children":2804},{},[2805],{"type":30,"value":633},{"type":30,"value":2807}," No. A blockchain does not identify a wallet owner by name, so an address requires attribution evidence rather than assumption. Exchange records, the debtor's disclosures, and behavioral pattern analysis can connect a debtor to a specific address, while the on-chain record documents the transactions at that address.",{"type":25,"tag":227,"props":2809,"children":2811},{"id":2810},"q-what-should-i-investigate-if-the-debtor-used-defi-or-held-nfts",[2812],{"type":30,"value":2813},"Q: What should I investigate if the debtor used DeFi or held NFTs?",{"type":25,"tag":26,"props":2815,"children":2816},{},[2817,2821],{"type":25,"tag":160,"props":2818,"children":2819},{},[2820],{"type":30,"value":633},{"type":30,"value":2822}," Review DeFi interactions for lending, yield farming, liquidity provision, and other positions that may hold value outside a simple wallet balance. For NFTs, look for public marketplace profiles, including OpenSea profiles, that link to wallet addresses. Trace any identified addresses and value the assets or protocol positions as of the applicable date.",{"type":25,"tag":227,"props":2824,"children":2826},{"id":2825},"q-does-the-current-cryptocurrency-price-establish-the-value-of-property-in-the-bankruptcy-estate",[2827],{"type":30,"value":2828},"Q: Does the current cryptocurrency price establish the value of property in the bankruptcy estate?",{"type":25,"tag":26,"props":2830,"children":2831},{},[2832,2836],{"type":25,"tag":160,"props":2833,"children":2834},{},[2835],{"type":30,"value":633},{"type":30,"value":2837}," Usually, the article describes bankruptcy assets as valued as of the petition date, using the assets held at each address on that date and a verifiable market price source. A later price can differ substantially because digital assets are volatile. Pre-petition transfers require valuation on each transfer date for avoidance analysis, and tax or proof of claim purposes may use different dates.",{"title":7,"searchDepth":703,"depth":703,"links":2839},[2840,2841,2850,2851],{"id":2373,"depth":703,"text":2376},{"id":2394,"depth":703,"text":2397,"children":2842},[2843,2844,2845,2846,2847,2848,2849],{"id":2400,"depth":709,"text":2403},{"id":2444,"depth":709,"text":2447},{"id":2478,"depth":709,"text":2481},{"id":2530,"depth":709,"text":2533},{"id":2574,"depth":709,"text":2577},{"id":2613,"depth":709,"text":2616},{"id":2674,"depth":709,"text":2677},{"id":2713,"depth":703,"text":2716},{"id":616,"depth":703,"text":619,"children":2852},[2853,2854,2855,2856],{"id":2780,"depth":709,"text":2783},{"id":2795,"depth":709,"text":2798},{"id":2810,"depth":709,"text":2813},{"id":2825,"depth":709,"text":2828},"content:articles:16-cryptocurrency-bankruptcy-trustee-checklist.md","articles\u002F16-cryptocurrency-bankruptcy-trustee-checklist.md","articles\u002F16-cryptocurrency-bankruptcy-trustee-checklist",1790145013677]