[{"data":1,"prerenderedAt":3871},["ShallowReactive",2],{"article-evm-receipts-logs-execution-traces":3,"content-query-JrZtfXH6Rb":1064,"related-evm-receipts-logs-execution-traces":1864},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"slug":10,"date":11,"lastUpdated":11,"author":12,"readingTime":13,"category":14,"tags":15,"ogImage":20,"featured":6,"body":21,"_type":1058,"_id":1059,"_source":1060,"_file":1061,"_stem":1062,"_extension":1063},"\u002Farticles\u002F27-evm-receipts-logs-execution-traces","articles",false,"","Beyond the transaction hash: receipts, logs, and EVM traces","A transaction hash proves submission, not success. Receipts, event logs, and EVM traces answer whether execution succeeded and what assets moved.","evm-receipts-logs-execution-traces","2026-06-13","Nick Kampe",12,"Methodology",[16,17,18,19],"ethereum","smart-contracts","blockchain-tracing","evidence","\u002Fog\u002Fevm-receipts-logs-execution-traces.png",{"type":22,"children":23,"toc":1037},"root",[24,41,48,117,150,156,216,246,253,305,311,324,399,434,440,485,513,570,576,581,618,646,652,661,673,706,740,766,801,806,812,817,822,827,832,837,842,848,919,925,930,936,942,966,972,981,987,1009,1015,1024],{"type":25,"tag":26,"props":27,"children":28},"element","p",{},[29,32,39],{"type":30,"value":31},"text","A transaction hash is where most investigations start and where too many stop. The hash identifies the envelope: the signed message broadcast to the network, containing the sender, the recipient, the value, and the input data. It does not say whether execution succeeded, which contracts actually ran, or what assets moved. Those facts live in other artifacts: the receipt, the event logs, the call tree, and the execution trace. Each answers a different question and each carries different evidentiary weight. Explorer pages fuse these layers into one screen, which is exactly why lawyers overstate what a hash proves. For the fundamentals of reading a single transaction, ",{"type":25,"tag":33,"props":34,"children":36},"a",{"href":35},"\u002Fresources\u002Fhow-to-read-a-blockchain-transaction",[37],{"type":30,"value":38},"start with the basic guide",{"type":30,"value":40},".",{"type":25,"tag":42,"props":43,"children":45},"h2",{"id":44},"why-the-transaction-hash-proves-submission-not-execution",[46],{"type":30,"value":47},"Why the Transaction Hash Proves Submission, Not Execution",{"type":25,"tag":26,"props":49,"children":50},{},[51,53,60,62,70,72,78,80,86,87,93,94,100,102,108,110,115],{"type":30,"value":52},"The hash is a cryptographic fingerprint of the signed transaction, computed from the transaction data at signing time. Retrieving the transaction object through ",{"type":25,"tag":54,"props":55,"children":57},"code",{"className":56},[],[58],{"type":30,"value":59},"eth_getTransactionByHash",{"type":30,"value":61},", a method in the ",{"type":25,"tag":33,"props":63,"children":67},{"href":64,"rel":65},"https:\u002F\u002Fgithub.com\u002Fethereum\u002Fexecution-apis",[66],"nofollow",[68],{"type":30,"value":69},"execution-apis JSON-RPC collection",{"type":30,"value":71},", returns the envelope: ",{"type":25,"tag":54,"props":73,"children":75},{"className":74},[],[76],{"type":30,"value":77},"from",{"type":30,"value":79},", ",{"type":25,"tag":54,"props":81,"children":83},{"className":82},[],[84],{"type":30,"value":85},"to",{"type":30,"value":79},{"type":25,"tag":54,"props":88,"children":90},{"className":89},[],[91],{"type":30,"value":92},"value",{"type":30,"value":79},{"type":25,"tag":54,"props":95,"children":97},{"className":96},[],[98],{"type":30,"value":99},"input",{"type":30,"value":101}," data, ",{"type":25,"tag":54,"props":103,"children":105},{"className":104},[],[106],{"type":30,"value":107},"nonce",{"type":30,"value":109},", gas parameters, fee fields, block number, and index. The ",{"type":25,"tag":54,"props":111,"children":113},{"className":112},[],[114],{"type":30,"value":77},{"type":30,"value":116}," address is derived from the cryptographic signature, so the envelope establishes which account signed the message, not which person held that account.",{"type":25,"tag":26,"props":118,"children":119},{},[120,122,127,129,134,136,141,143,148],{"type":30,"value":121},"If ",{"type":25,"tag":54,"props":123,"children":125},{"className":124},[],[126],{"type":30,"value":85},{"type":30,"value":128}," is a contract address, the ",{"type":25,"tag":54,"props":130,"children":132},{"className":131},[],[133],{"type":30,"value":99},{"type":30,"value":135}," field is an encoded function call, and the envelope alone does not reveal what that function did, whether it succeeded, or whether any token changed hands. The ",{"type":25,"tag":54,"props":137,"children":139},{"className":138},[],[140],{"type":30,"value":92},{"type":30,"value":142}," field carries only native ETH and only the top-level amount: a 5,000 USDC transfer typically appears with a ",{"type":25,"tag":54,"props":144,"children":146},{"className":145},[],[147],{"type":30,"value":92},{"type":30,"value":149}," of zero. Confirm finality before treating a mined hash as settled: a transaction in a block reorganized out of the canonical chain can disappear from the record.",{"type":25,"tag":42,"props":151,"children":153},{"id":152},"the-receipt-the-networks-verdict-on-success",[154],{"type":30,"value":155},"The Receipt: The Network's Verdict on Success",{"type":25,"tag":26,"props":157,"children":158},{},[159,161,167,169,176,178,184,186,192,193,199,200,206,208,214],{"type":30,"value":160},"Unlike a trace, a receipt is consensus data. Blocks commit a receipts root, and a node that still holds the relevant history can serve the receipt via ",{"type":25,"tag":54,"props":162,"children":164},{"className":163},[],[165],{"type":30,"value":166},"eth_getTransactionReceipt",{"type":30,"value":168},". The ",{"type":25,"tag":33,"props":170,"children":173},{"href":171,"rel":172},"https:\u002F\u002Fgithub.com\u002Fethereum\u002Fexecution-apis\u002Fblob\u002Fmain\u002Fsrc\u002Fschemas\u002Freceipt.yaml",[66],[174],{"type":30,"value":175},"execution-apis receipt schema",{"type":30,"value":177}," requires ",{"type":25,"tag":54,"props":179,"children":181},{"className":180},[],[182],{"type":30,"value":183},"status",{"type":30,"value":185}," (after Byzantium), ",{"type":25,"tag":54,"props":187,"children":189},{"className":188},[],[190],{"type":30,"value":191},"gasUsed",{"type":30,"value":79},{"type":25,"tag":54,"props":194,"children":196},{"className":195},[],[197],{"type":30,"value":198},"cumulativeGasUsed",{"type":30,"value":79},{"type":25,"tag":54,"props":201,"children":203},{"className":202},[],[204],{"type":30,"value":205},"logs",{"type":30,"value":207},", and ",{"type":25,"tag":54,"props":209,"children":211},{"className":210},[],[212],{"type":30,"value":213},"effectiveGasPrice",{"type":30,"value":215},", the amount actually deducted per gas. Some clients prune old receipts and return a \"pruned history unavailable\" error, so confirm the node still holds the block before treating a missing receipt as proof that the transaction never existed.",{"type":25,"tag":26,"props":217,"children":218},{},[219,221,228,230,237,239,244],{"type":30,"value":220},"Status semantics come from ",{"type":25,"tag":33,"props":222,"children":225},{"href":223,"rel":224},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-658",[66],[226],{"type":30,"value":227},"EIP-658",{"type":30,"value":229},", which replaced the receipt's intermediate state root with a status code: 1 for success, 0 for failure. The change activated with the ",{"type":25,"tag":33,"props":231,"children":234},{"href":232,"rel":233},"https:\u002F\u002Fblog.ethereum.org\u002F2017\u002F10\u002F12\u002Fbyzantium-hf-announcement",[66],[235],{"type":30,"value":236},"Byzantium hard fork",{"type":30,"value":238}," at block 4,370,000 on October 16, 2017. Transactions before that fork have no status field, and failure was inferred by comparing ",{"type":25,"tag":54,"props":240,"children":242},{"className":241},[],[243],{"type":30,"value":191},{"type":30,"value":245}," against the gas limit. EIP-658's own motivation explains why that heuristic became unsound: with the REVERT opcode, \"it is no longer possible for users to assume that a transaction failed iff it consumed all gas.\" For pre-Byzantium transactions, the outcome can only be reconstructed by replaying execution.",{"type":25,"tag":247,"props":248,"children":250},"h3",{"id":249},"failed-transactions-still-cost-money",[251],{"type":30,"value":252},"Failed Transactions Still Cost Money",{"type":25,"tag":26,"props":254,"children":255},{},[256,258,265,267,273,275,281,283,288,290,295,297,303],{"type":30,"value":257},"A status of 0 means the top-level call failed and every state change rolled back. The transaction is still recorded, its nonce is consumed, and the sender pays for gas actually used. After Byzantium that is often well below the gas limit: ",{"type":25,"tag":33,"props":259,"children":262},{"href":260,"rel":261},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-140",[66],[263],{"type":30,"value":264},"EIP-140",{"type":30,"value":266}," added REVERT so a contract can \"stop execution and revert state changes, without consuming all provided gas.\" Solidity ",{"type":25,"tag":54,"props":268,"children":270},{"className":269},[],[271],{"type":30,"value":272},"require",{"type":30,"value":274}," and ",{"type":25,"tag":54,"props":276,"children":278},{"className":277},[],[279],{"type":30,"value":280},"revert",{"type":30,"value":282}," use that opcode. Exceptional failures such as out-of-gas still consume remaining gas. ",{"type":25,"tag":54,"props":284,"children":286},{"className":285},[],[287],{"type":30,"value":191},{"type":30,"value":289}," multiplied by ",{"type":25,"tag":54,"props":291,"children":293},{"className":292},[],[294],{"type":30,"value":213},{"type":30,"value":296}," (or ",{"type":25,"tag":54,"props":298,"children":300},{"className":299},[],[301],{"type":30,"value":302},"gasPrice",{"type":30,"value":304}," where that is the legacy price) is the fee figure, usable for damages even when the transfer failed. Success means only that the call did not revert, so no asset conclusion should rest on the status field alone.",{"type":25,"tag":42,"props":306,"children":308},{"id":307},"event-logs-the-contracts-own-testimony",[309],{"type":30,"value":310},"Event Logs: The Contract's Own Testimony",{"type":25,"tag":26,"props":312,"children":313},{},[314,316,322],{"type":30,"value":315},"Logs are stored inside the receipt and emitted by contract code during execution. Each log carries the emitting contract address, up to four indexed topics, and a data payload, and history can be queried with ",{"type":25,"tag":54,"props":317,"children":319},{"className":318},[],[320],{"type":30,"value":321},"eth_getLogs",{"type":30,"value":323},", filtered by address and topic signature. The \"token transfers\" panels on explorers are decodes of these logs, not independent data.",{"type":25,"tag":26,"props":325,"children":326},{},[327,329,336,338,344,346,352,353,359,361,367,369,375,377,382,384,390,392,397],{"type":30,"value":328},"The ",{"type":25,"tag":33,"props":330,"children":333},{"href":331,"rel":332},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-20",[66],[334],{"type":30,"value":335},"ERC-20 standard (EIP-20)",{"type":30,"value":337}," requires a ",{"type":25,"tag":54,"props":339,"children":341},{"className":340},[],[342],{"type":30,"value":343},"Transfer",{"type":30,"value":345}," event on every ",{"type":25,"tag":54,"props":347,"children":349},{"className":348},[],[350],{"type":30,"value":351},"transfer",{"type":30,"value":274},{"type":25,"tag":54,"props":354,"children":356},{"className":355},[],[357],{"type":30,"value":358},"transferFrom",{"type":30,"value":360}," call, including zero-value transfers, and an ",{"type":25,"tag":54,"props":362,"children":364},{"className":363},[],[365],{"type":30,"value":366},"Approval",{"type":30,"value":368}," event on every successful ",{"type":25,"tag":54,"props":370,"children":372},{"className":371},[],[373],{"type":30,"value":374},"approve",{"type":30,"value":376},". A token that creates new tokens SHOULD emit a ",{"type":25,"tag":54,"props":378,"children":380},{"className":379},[],[381],{"type":30,"value":343},{"type":30,"value":383}," with ",{"type":25,"tag":54,"props":385,"children":387},{"className":386},[],[388],{"type":30,"value":389},"_from",{"type":30,"value":391}," set to the zero address. Those conventions are why ",{"type":25,"tag":54,"props":393,"children":395},{"className":394},[],[396],{"type":30,"value":343},{"type":30,"value":398}," logs are the backbone of token-flow reconstruction.",{"type":25,"tag":26,"props":400,"children":401},{},[402,404,409,411,416,418,424,426,432],{"type":30,"value":403},"The protocol does not enforce any of it. Events are emitted by whatever code the contract runs, and the EVM does not check whether an emitted ",{"type":25,"tag":54,"props":405,"children":407},{"className":406},[],[408],{"type":30,"value":343},{"type":30,"value":410}," corresponds to a real balance change. A noncompliant contract can emit a ",{"type":25,"tag":54,"props":412,"children":414},{"className":413},[],[415],{"type":30,"value":343},{"type":30,"value":417}," without moving a token, or move tokens while emitting nothing. EIP-140 notes that reverting an EVM execution means \"all changes, including LOGs, are lost,\" so a failed transaction's receipt carries no logs, and an event from a failed subcall disappears even when the surrounding transaction succeeds. Fee-on-transfer and rebasing tokens can log an amount that differs from the balance delta. Treat logs as admissions by the contract, not ground truth. Corroborate with ",{"type":25,"tag":54,"props":419,"children":421},{"className":420},[],[422],{"type":30,"value":423},"balanceOf",{"type":30,"value":425}," at the relevant block via ",{"type":25,"tag":54,"props":427,"children":429},{"className":428},[],[430],{"type":30,"value":431},"eth_call",{"type":30,"value":433},", check that an allowance was consumed, and confirm the flow against the call tree.",{"type":25,"tag":42,"props":435,"children":437},{"id":436},"the-call-tree-what-actually-executed",[438],{"type":30,"value":439},"The Call Tree: What Actually Executed",{"type":25,"tag":26,"props":441,"children":442},{},[443,445,451,453,460,462,467,468,474,476,483],{"type":30,"value":444},"One envelope can fan out into many internal executions, and the shape of that tree is often the entire case. A contract that calls another executes the callee's code in the callee's context, with the caller as ",{"type":25,"tag":54,"props":446,"children":448},{"className":447},[],[449],{"type":30,"value":450},"msg.sender",{"type":30,"value":452},". Delegatecall, the opcode ",{"type":25,"tag":33,"props":454,"children":457},{"href":455,"rel":456},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-7",[66],[458],{"type":30,"value":459},"added in the Homestead fork (EIP-7)",{"type":30,"value":461},", inverts that: the callee's code runs in the caller's storage context, preserving ",{"type":25,"tag":54,"props":463,"children":465},{"className":464},[],[466],{"type":30,"value":450},{"type":30,"value":274},{"type":25,"tag":54,"props":469,"children":471},{"className":470},[],[472],{"type":30,"value":473},"msg.value",{"type":30,"value":475},". This is the mechanism behind ",{"type":25,"tag":33,"props":477,"children":480},{"href":478,"rel":479},"https:\u002F\u002Fwww.openzeppelin.com\u002Fnews\u002Fproxy-patterns",[66],[481],{"type":30,"value":482},"upgradeable proxies",{"type":30,"value":484},", where a user calls a proxy address and the proxy delegatecalls an implementation contract. The forensic consequence is direct: the address that received the call is not necessarily the address whose code ran, and a plain transaction page will not tell you which is which.",{"type":25,"tag":26,"props":486,"children":487},{},[488,490,495,497,503,505,511],{"type":30,"value":489},"Routers and aggregators add a third layer. A swap transaction shows ",{"type":25,"tag":54,"props":491,"children":493},{"className":492},[],[494],{"type":30,"value":85},{"type":30,"value":496}," equal to a router address; the call tree shows the router calling pair contracts, which move tokens on their own ledgers. ETH that a contract forwards onward appears only in the trace, and ERC-20 movement appears only in the token contract's logs and ledger. Where holdings pass through several protocol contracts inside one transaction, ",{"type":25,"tag":33,"props":498,"children":500},{"href":499},"\u002Fresources\u002Fwhat-lawyers-need-to-know-about-defi",[501],{"type":30,"value":502},"tracing through DeFi mechanics",{"type":30,"value":504}," is where that analysis gets its teeth, while ",{"type":25,"tag":33,"props":506,"children":508},{"href":507},"\u002Fresources\u002Fsmart-contract-disputes",[509],{"type":30,"value":510},"smart contract disputes",{"type":30,"value":512}," covers the contract interpretation and remedies side of the same record.",{"type":25,"tag":26,"props":514,"children":515},{},[516,518,525,527,534,536,543,545,551,553,560,562,568],{"type":30,"value":517},"Retrieval is where standardization ends. Tracing RPCs are client-specific: geth exposes trace methods in its ",{"type":25,"tag":33,"props":519,"children":522},{"href":520,"rel":521},"https:\u002F\u002Fgeth.ethereum.org\u002Fdocs\u002Finteracting-with-geth\u002Frpc\u002Fns-debug",[66],[523],{"type":30,"value":524},"debug namespace",{"type":30,"value":526}," and documents tracing as ",{"type":25,"tag":33,"props":528,"children":531},{"href":529,"rel":530},"https:\u002F\u002Fgeth.ethereum.org\u002Fdocs\u002Fdevelopers\u002Fevm-tracing",[66],[532],{"type":30,"value":533},"re-running transactions locally",{"type":30,"value":535},". ",{"type":25,"tag":33,"props":537,"children":540},{"href":538,"rel":539},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-3155",[66],[541],{"type":30,"value":542},"EIP-3155",{"type":30,"value":544}," proposed a JSON format for EVM traces during state tests; it remains at Last Call and is not a finalized ",{"type":25,"tag":54,"props":546,"children":548},{"className":547},[],[549],{"type":30,"value":550},"debug_traceTransaction",{"type":30,"value":552}," standard. ",{"type":25,"tag":33,"props":554,"children":557},{"href":555,"rel":556},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-1474",[66],[558],{"type":30,"value":559},"EIP-1474",{"type":30,"value":561},", which cataloged JSON-RPC methods, is stagnant; the maintained specification is the ",{"type":25,"tag":33,"props":563,"children":565},{"href":64,"rel":564},[66],[566],{"type":30,"value":567},"execution-apis repository",{"type":30,"value":569},". Because output depends on the client, its version, and the tracer, an expert's methodology documentation matters as much as the trace itself.",{"type":25,"tag":42,"props":571,"children":573},{"id":572},"node-and-archive-requirements-for-reproducible-tracing",[574],{"type":30,"value":575},"Node and Archive Requirements for Reproducible Tracing",{"type":25,"tag":26,"props":577,"children":578},{},[579],{"type":30,"value":580},"Traces are re-execution, not stored data. Reproducing what a transaction did requires the state that existed at that block.",{"type":25,"tag":26,"props":582,"children":583},{},[584,586,593,594,600,602,608,610,616],{"type":30,"value":585},"A full node caches only recent state, on the order of the last 128 blocks, per ",{"type":25,"tag":33,"props":587,"children":590},{"href":588,"rel":589},"https:\u002F\u002Fethereum.org\u002Fdevelopers\u002Fdocs\u002Fnodes-and-clients\u002Farchive-nodes\u002F",[66],[591],{"type":30,"value":592},"ethereum.org's archive-node documentation",{"type":30,"value":274},{"type":25,"tag":33,"props":595,"children":597},{"href":529,"rel":596},[66],[598],{"type":30,"value":599},"geth's tracing notes",{"type":30,"value":601},". Older states can be regenerated from checkpoints, which becomes expensive the further back you go. Geth's default ",{"type":25,"tag":54,"props":603,"children":605},{"className":604},[],[606],{"type":30,"value":607},"reexec",{"type":30,"value":609}," window is 128 blocks; beyond it, a trace fails unless the window is increased or the node is an archive node. An ",{"type":25,"tag":33,"props":611,"children":613},{"href":588,"rel":612},[66],[614],{"type":30,"value":615},"archive node",{"type":30,"value":617}," stores historical states so those queries return immediately, at the cost of multiple terabytes of disk. Confirm archive-state access or provider tracing support before promising a trace of an old transaction, and record the node type, client version, sync mode, tracer, and block height.",{"type":25,"tag":26,"props":619,"children":620},{},[621,623,629,631,637,638,644],{"type":30,"value":622},"Opcode-level traces can run to hundreds of megabytes for a busy transaction, which makes them impractical to attach wholesale; high-level call tracers are compact but capture a different layer. Execution is deterministic given the same client, state, and tracer, but different client versions can produce different output. Our ",{"type":25,"tag":33,"props":624,"children":626},{"href":625},"\u002Fmethodology",[627],{"type":30,"value":628},"methodology",{"type":30,"value":630}," treats reproducibility and documented retrieval as core requirements of blockchain forensic work; for packaging this evidence for court, ConsensusIntel offers ",{"type":25,"tag":33,"props":632,"children":634},{"href":633},"\u002Fservices#blockchain-tracing",[635],{"type":30,"value":636},"blockchain tracing",{"type":30,"value":274},{"type":25,"tag":33,"props":639,"children":641},{"href":640},"\u002Fservices#evidence-review",[642],{"type":30,"value":643},"evidence review",{"type":30,"value":645}," built around artifact-level preservation rather than explorer screenshots.",{"type":25,"tag":42,"props":647,"children":649},{"id":648},"hypothetical-example-one-transaction-four-evidence-layers",[650],{"type":30,"value":651},"Hypothetical Example: One Transaction, Four Evidence Layers",{"type":25,"tag":26,"props":653,"children":654},{},[655],{"type":25,"tag":656,"props":657,"children":658},"strong",{},[659],{"type":30,"value":660},"Hypothetical example: the addresses and amounts below are invented for illustration; no real matter is described.",{"type":25,"tag":26,"props":662,"children":663},{},[664,666,671],{"type":30,"value":665},"A victim account (V) has an outstanding ",{"type":25,"tag":54,"props":667,"children":669},{"className":668},[],[670],{"type":30,"value":374},{"type":30,"value":672}," to an attacker-controlled contract (D) for 5,000 USDC. D was deployed with code that delegatecalls a reusable template (T). V signs a single transaction to D. The explorer shows \"Method: transfer\", \"Status: Success\", and a tokens-transferred panel reading \"USDC 5,000 from V to A\".",{"type":25,"tag":26,"props":674,"children":675},{},[676,678,683,685,690,692,697,699,704],{"type":30,"value":677},"Layer 1, the envelope: ",{"type":25,"tag":54,"props":679,"children":681},{"className":680},[],[682],{"type":30,"value":77},{"type":30,"value":684}," V, ",{"type":25,"tag":54,"props":686,"children":688},{"className":687},[],[689],{"type":30,"value":85},{"type":30,"value":691}," D, ",{"type":25,"tag":54,"props":693,"children":695},{"className":694},[],[696],{"type":30,"value":92},{"type":30,"value":698}," 0, a small ",{"type":25,"tag":54,"props":700,"children":702},{"className":701},[],[703],{"type":30,"value":99},{"type":30,"value":705}," payload. V submitted a message to D; no ETH moved to D; there is no USDC in this artifact.",{"type":25,"tag":26,"props":707,"children":708},{},[709,711,716,718,723,725,730,732,738],{"type":30,"value":710},"Layer 2, the receipt: status 1, ",{"type":25,"tag":54,"props":712,"children":714},{"className":713},[],[715],{"type":30,"value":191},{"type":30,"value":717}," 94,220, and three logs: ",{"type":25,"tag":54,"props":719,"children":721},{"className":720},[],[722],{"type":30,"value":343},{"type":30,"value":724}," from V to D of 5,000 USDC, ",{"type":25,"tag":54,"props":726,"children":728},{"className":727},[],[729],{"type":30,"value":343},{"type":30,"value":731}," from D to A of 5,000 USDC, and ",{"type":25,"tag":54,"props":733,"children":735},{"className":734},[],[736],{"type":30,"value":737},"RewardsClaimed",{"type":30,"value":739}," for V. Execution succeeded, the sender paid for the gas, and the USDC contract recorded two transfers.",{"type":25,"tag":26,"props":741,"children":742},{},[743,745,750,752,757,759,764],{"type":30,"value":744},"Layer 3, logs plus ledger state: ",{"type":25,"tag":54,"props":746,"children":748},{"className":747},[],[749],{"type":30,"value":423},{"type":30,"value":751}," at the final block shows V's USDC fell by 5,000, D's rose and then fell, and A's rose by 5,000. The ledger corroborates the two ",{"type":25,"tag":54,"props":753,"children":755},{"className":754},[],[756],{"type":30,"value":343},{"type":30,"value":758}," logs. ",{"type":25,"tag":54,"props":760,"children":762},{"className":761},[],[763],{"type":30,"value":737},{"type":30,"value":765}," corresponds to no balance change: a fabricated reward event with no asset behind it.",{"type":25,"tag":26,"props":767,"children":768},{},[769,771,776,778,784,786,792,794,799],{"type":30,"value":770},"Layer 4, the call tree: D delegatecalled T, so template code ran in D's storage with ",{"type":25,"tag":54,"props":772,"children":774},{"className":773},[],[775],{"type":30,"value":450},{"type":30,"value":777}," still V. D then called ",{"type":25,"tag":54,"props":779,"children":781},{"className":780},[],[782],{"type":30,"value":783},"USDC.transferFrom",{"type":30,"value":785}," to pull the allowance, ",{"type":25,"tag":54,"props":787,"children":789},{"className":788},[],[790],{"type":30,"value":791},"USDC.transfer",{"type":30,"value":793}," to send on to A, and forwarded 0.02 ETH to A internally. The executing code was T's, running in D's context, and 0.02 ETH reached A inside a transaction whose ",{"type":25,"tag":54,"props":795,"children":797},{"className":796},[],[798],{"type":30,"value":92},{"type":30,"value":800}," field says zero.",{"type":25,"tag":26,"props":802,"children":803},{},[804],{"type":30,"value":805},"A careless report says \"V transferred USDC to A.\" A defensible report stacks the layers: the envelope proves V signed to D; the ledger plus logs prove the USDC flow; the trace proves which code ran and where the ETH landed.",{"type":25,"tag":42,"props":807,"children":809},{"id":808},"a-hierarchy-of-claims-an-expert-can-defend",[810],{"type":30,"value":811},"A Hierarchy of Claims an Expert Can Defend",{"type":25,"tag":26,"props":813,"children":814},{},[815],{"type":30,"value":816},"From the envelope alone: submission, sender account, recipient, payload, fee parameters, and block inclusion.",{"type":25,"tag":26,"props":818,"children":819},{},[820],{"type":30,"value":821},"From the receipt: inclusion, success or failure, execution cost, and the set of logs emitted. Nothing about assets.",{"type":25,"tag":26,"props":823,"children":824},{},[825],{"type":30,"value":826},"From logs plus ledger reads: token flows as recorded by the token contract, always subject to that contract's truthfulness about its own state.",{"type":25,"tag":26,"props":828,"children":829},{},[830],{"type":30,"value":831},"From the call tree: which code executed, in whose storage context, in what order, and where ETH flowed internally.",{"type":25,"tag":26,"props":833,"children":834},{},[835],{"type":30,"value":836},"From state at a block: balances, allowances, and storage as the network recorded them, the ground-truth layer for assets.",{"type":25,"tag":26,"props":838,"children":839},{},[840],{"type":30,"value":841},"Below the line sit claims no artifact supports: who physically held the private key, what the sender intended, and anything that happened off-chain. Label every conclusion with its source layer. A report that lets a receipt's status carry the weight of a token movement, or a log carry the weight of a balance, has overstated the evidence.",{"type":25,"tag":42,"props":843,"children":845},{"id":844},"a-practitioner-checklist-for-preserving-execution-evidence",[846],{"type":30,"value":847},"A Practitioner Checklist for Preserving Execution Evidence",{"type":25,"tag":849,"props":850,"children":851},"ol",{},[852,858,882,887,899,904,909,914],{"type":25,"tag":853,"props":854,"children":855},"li",{},[856],{"type":30,"value":857},"Confirm the transaction is on the canonical chain and check finality before treating the hash as settled.",{"type":25,"tag":853,"props":859,"children":860},{},[861,863,868,869,874,875,880],{"type":30,"value":862},"Capture raw JSON output for ",{"type":25,"tag":54,"props":864,"children":866},{"className":865},[],[867],{"type":30,"value":59},{"type":30,"value":79},{"type":25,"tag":54,"props":870,"children":872},{"className":871},[],[873],{"type":30,"value":166},{"type":30,"value":207},{"type":25,"tag":54,"props":876,"children":878},{"className":877},[],[879],{"type":30,"value":321},{"type":30,"value":881}," at query time; record the timestamp, the node or provider, the client and version, and the exact parameters.",{"type":25,"tag":853,"props":883,"children":884},{},[885],{"type":30,"value":886},"Preserve a hash of every exported file and note whether the data came from a direct node query, a provider API, or an explorer, because those sources differ in provenance.",{"type":25,"tag":853,"props":888,"children":889},{},[890,892,897],{"type":30,"value":891},"Read token balances and relevant storage at the final block with ",{"type":25,"tag":54,"props":893,"children":895},{"className":894},[],[896],{"type":30,"value":431},{"type":30,"value":898},", and check that allowances were consumed.",{"type":25,"tag":853,"props":900,"children":901},{},[902],{"type":30,"value":903},"Obtain a call-level trace with call types and depths, plus a state diff showing pre and post values for the balances at issue.",{"type":25,"tag":853,"props":905,"children":906},{},[907],{"type":30,"value":908},"If the transaction failed, preserve the revert reason from the trace alongside the receipt.",{"type":25,"tag":853,"props":910,"children":911},{},[912],{"type":30,"value":913},"For transactions older than roughly the state-retention window, confirm archive-state access or provider tracing before commissioning a trace, and record the tracer configuration.",{"type":25,"tag":853,"props":915,"children":916},{},[917],{"type":30,"value":918},"Cross-check at least one field against a second independent source. Use explorer screenshots only as supporting exhibits; the raw JSON is the primary record.",{"type":25,"tag":42,"props":920,"children":922},{"id":921},"limitations",[923],{"type":30,"value":924},"Limitations",{"type":25,"tag":26,"props":926,"children":927},{},[928],{"type":30,"value":929},"Traces and logs reconstruct execution, not people. They cannot prove who held a private key, what a party intended, or any off-chain fact. Explorer \"internal transactions\" tabs are client-generated renderings, not consensus data. Reorganizations can orphan a transaction, log queries can be range-limited, and some nodes prune old receipts. On layer-2 rollups, receipts describe sequencer-era execution and the layer-1 commitments are a separate artifact. Everything before October 2017 on Ethereum lacks a receipt status, and the absence of an event proves nothing. How a court weighs these artifacts depends on the forum's evidence rules.",{"type":25,"tag":42,"props":931,"children":933},{"id":932},"frequently-asked-questions",[934],{"type":30,"value":935},"Frequently Asked Questions",{"type":25,"tag":247,"props":937,"children":939},{"id":938},"q-the-explorer-shows-method-transfer-and-status-success-does-that-prove-the-tokens-were-sent",[940],{"type":30,"value":941},"Q: The explorer shows \"Method: transfer\" and \"Status: Success\". Does that prove the tokens were sent?",{"type":25,"tag":26,"props":943,"children":944},{},[945,950,952,957,959,964],{"type":25,"tag":656,"props":946,"children":947},{},[948],{"type":30,"value":949},"A:",{"type":30,"value":951}," No. Status proves only that the transaction did not revert. Token movement is evidenced by the token contract's ",{"type":25,"tag":54,"props":953,"children":955},{"className":954},[],[956],{"type":30,"value":343},{"type":30,"value":958}," logs and by ",{"type":25,"tag":54,"props":960,"children":962},{"className":961},[],[963],{"type":30,"value":423},{"type":30,"value":965}," at the relevant block. The explorer's \"transfer\" label is a decode of the input data and says nothing about whether tokens moved.",{"type":25,"tag":247,"props":967,"children":969},{"id":968},"q-what-is-the-difference-between-a-receipt-and-a-trace",[970],{"type":30,"value":971},"Q: What is the difference between a receipt and a trace?",{"type":25,"tag":26,"props":973,"children":974},{},[975,979],{"type":25,"tag":656,"props":976,"children":977},{},[978],{"type":30,"value":949},{"type":30,"value":980}," A receipt is consensus data: status, gas used, and logs, stored with the block. A trace is a reconstruction: a node re-executes the transaction locally. Receipts exist for every included transaction the node still holds. Traces depend on the client, the tracer, and historical state, which generally means an archive node for old transactions. There is no finalized trace-format standard.",{"type":25,"tag":247,"props":982,"children":984},{"id":983},"q-a-failed-transaction-still-costs-gas-what-can-the-fee-evidence-prove",[985],{"type":30,"value":986},"Q: A failed transaction still costs gas. What can the fee evidence prove?",{"type":25,"tag":26,"props":988,"children":989},{},[990,994,996,1001,1002,1007],{"type":25,"tag":656,"props":991,"children":992},{},[993],{"type":30,"value":949},{"type":30,"value":995}," ",{"type":25,"tag":54,"props":997,"children":999},{"className":998},[],[1000],{"type":30,"value":191},{"type":30,"value":289},{"type":25,"tag":54,"props":1003,"children":1005},{"className":1004},[],[1006],{"type":30,"value":213},{"type":30,"value":1008}," is the fee the sender paid, which can support damages even when the transfer failed. The receipt also proves the failure: status 0, state changes rolled back, nonce consumed. That pairing can establish that the account was operated, that an attempt occurred, and what it cost.",{"type":25,"tag":247,"props":1010,"children":1012},{"id":1011},"q-how-far-back-can-execution-traces-be-recovered",[1013],{"type":30,"value":1014},"Q: How far back can execution traces be recovered?",{"type":25,"tag":26,"props":1016,"children":1017},{},[1018,1022],{"type":25,"tag":656,"props":1019,"children":1020},{},[1021],{"type":30,"value":949},{"type":30,"value":1023}," Envelope, receipt, and logs are available only if the node still holds that history; some clients prune old receipts. Traces require state as of the target block. Recent transactions can be traced on a full node; old ones generally need an archive node or a tracing provider. Pre-Byzantium transactions (before October 2017) have no receipt status and can only be reconstructed by replay.",{"type":25,"tag":26,"props":1025,"children":1026},{},[1027,1029,1035],{"type":30,"value":1028},"Every matter turns on its own facts, and the weight a court gives these artifacts depends on the jurisdiction, the claims, and how the evidence was collected and preserved. If you are litigating or investigating a matter where EVM execution details matter, ",{"type":25,"tag":33,"props":1030,"children":1032},{"href":1031},"\u002Fcontact",[1033],{"type":30,"value":1034},"contact ConsensusIntel",{"type":30,"value":1036}," to discuss what a forensic analysis can defensibly establish from your specific transactions.",{"title":7,"searchDepth":1038,"depth":1038,"links":1039},2,[1040,1041,1045,1046,1047,1048,1049,1050,1051,1052],{"id":44,"depth":1038,"text":47},{"id":152,"depth":1038,"text":155,"children":1042},[1043],{"id":249,"depth":1044,"text":252},3,{"id":307,"depth":1038,"text":310},{"id":436,"depth":1038,"text":439},{"id":572,"depth":1038,"text":575},{"id":648,"depth":1038,"text":651},{"id":808,"depth":1038,"text":811},{"id":844,"depth":1038,"text":847},{"id":921,"depth":1038,"text":924},{"id":932,"depth":1038,"text":935,"children":1053},[1054,1055,1056,1057],{"id":938,"depth":1044,"text":941},{"id":968,"depth":1044,"text":971},{"id":983,"depth":1044,"text":986},{"id":1011,"depth":1044,"text":1014},"markdown","content:articles:27-evm-receipts-logs-execution-traces.md","content","articles\u002F27-evm-receipts-logs-execution-traces.md","articles\u002F27-evm-receipts-logs-execution-traces","md",{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"slug":10,"date":11,"lastUpdated":11,"author":12,"readingTime":13,"category":14,"tags":1065,"ogImage":20,"featured":6,"body":1066,"_type":1058,"_id":1059,"_source":1060,"_file":1061,"_stem":1062,"_extension":1063},[16,17,18,19],{"type":22,"children":1067,"toc":1845},[1068,1077,1081,1133,1161,1165,1211,1233,1237,1277,1281,1291,1349,1377,1381,1415,1435,1475,1479,1483,1511,1530,1534,1541,1551,1579,1607,1629,1657,1661,1665,1669,1673,1677,1681,1685,1689,1693,1752,1756,1760,1764,1768,1788,1792,1800,1804,1824,1828,1836],{"type":25,"tag":26,"props":1069,"children":1070},{},[1071,1072,1076],{"type":30,"value":31},{"type":25,"tag":33,"props":1073,"children":1074},{"href":35},[1075],{"type":30,"value":38},{"type":30,"value":40},{"type":25,"tag":42,"props":1078,"children":1079},{"id":44},[1080],{"type":30,"value":47},{"type":25,"tag":26,"props":1082,"children":1083},{},[1084,1085,1090,1091,1096,1097,1102,1103,1108,1109,1114,1115,1120,1121,1126,1127,1132],{"type":30,"value":52},{"type":25,"tag":54,"props":1086,"children":1088},{"className":1087},[],[1089],{"type":30,"value":59},{"type":30,"value":61},{"type":25,"tag":33,"props":1092,"children":1094},{"href":64,"rel":1093},[66],[1095],{"type":30,"value":69},{"type":30,"value":71},{"type":25,"tag":54,"props":1098,"children":1100},{"className":1099},[],[1101],{"type":30,"value":77},{"type":30,"value":79},{"type":25,"tag":54,"props":1104,"children":1106},{"className":1105},[],[1107],{"type":30,"value":85},{"type":30,"value":79},{"type":25,"tag":54,"props":1110,"children":1112},{"className":1111},[],[1113],{"type":30,"value":92},{"type":30,"value":79},{"type":25,"tag":54,"props":1116,"children":1118},{"className":1117},[],[1119],{"type":30,"value":99},{"type":30,"value":101},{"type":25,"tag":54,"props":1122,"children":1124},{"className":1123},[],[1125],{"type":30,"value":107},{"type":30,"value":109},{"type":25,"tag":54,"props":1128,"children":1130},{"className":1129},[],[1131],{"type":30,"value":77},{"type":30,"value":116},{"type":25,"tag":26,"props":1134,"children":1135},{},[1136,1137,1142,1143,1148,1149,1154,1155,1160],{"type":30,"value":121},{"type":25,"tag":54,"props":1138,"children":1140},{"className":1139},[],[1141],{"type":30,"value":85},{"type":30,"value":128},{"type":25,"tag":54,"props":1144,"children":1146},{"className":1145},[],[1147],{"type":30,"value":99},{"type":30,"value":135},{"type":25,"tag":54,"props":1150,"children":1152},{"className":1151},[],[1153],{"type":30,"value":92},{"type":30,"value":142},{"type":25,"tag":54,"props":1156,"children":1158},{"className":1157},[],[1159],{"type":30,"value":92},{"type":30,"value":149},{"type":25,"tag":42,"props":1162,"children":1163},{"id":152},[1164],{"type":30,"value":155},{"type":25,"tag":26,"props":1166,"children":1167},{},[1168,1169,1174,1175,1180,1181,1186,1187,1192,1193,1198,1199,1204,1205,1210],{"type":30,"value":160},{"type":25,"tag":54,"props":1170,"children":1172},{"className":1171},[],[1173],{"type":30,"value":166},{"type":30,"value":168},{"type":25,"tag":33,"props":1176,"children":1178},{"href":171,"rel":1177},[66],[1179],{"type":30,"value":175},{"type":30,"value":177},{"type":25,"tag":54,"props":1182,"children":1184},{"className":1183},[],[1185],{"type":30,"value":183},{"type":30,"value":185},{"type":25,"tag":54,"props":1188,"children":1190},{"className":1189},[],[1191],{"type":30,"value":191},{"type":30,"value":79},{"type":25,"tag":54,"props":1194,"children":1196},{"className":1195},[],[1197],{"type":30,"value":198},{"type":30,"value":79},{"type":25,"tag":54,"props":1200,"children":1202},{"className":1201},[],[1203],{"type":30,"value":205},{"type":30,"value":207},{"type":25,"tag":54,"props":1206,"children":1208},{"className":1207},[],[1209],{"type":30,"value":213},{"type":30,"value":215},{"type":25,"tag":26,"props":1212,"children":1213},{},[1214,1215,1220,1221,1226,1227,1232],{"type":30,"value":220},{"type":25,"tag":33,"props":1216,"children":1218},{"href":223,"rel":1217},[66],[1219],{"type":30,"value":227},{"type":30,"value":229},{"type":25,"tag":33,"props":1222,"children":1224},{"href":232,"rel":1223},[66],[1225],{"type":30,"value":236},{"type":30,"value":238},{"type":25,"tag":54,"props":1228,"children":1230},{"className":1229},[],[1231],{"type":30,"value":191},{"type":30,"value":245},{"type":25,"tag":247,"props":1234,"children":1235},{"id":249},[1236],{"type":30,"value":252},{"type":25,"tag":26,"props":1238,"children":1239},{},[1240,1241,1246,1247,1252,1253,1258,1259,1264,1265,1270,1271,1276],{"type":30,"value":257},{"type":25,"tag":33,"props":1242,"children":1244},{"href":260,"rel":1243},[66],[1245],{"type":30,"value":264},{"type":30,"value":266},{"type":25,"tag":54,"props":1248,"children":1250},{"className":1249},[],[1251],{"type":30,"value":272},{"type":30,"value":274},{"type":25,"tag":54,"props":1254,"children":1256},{"className":1255},[],[1257],{"type":30,"value":280},{"type":30,"value":282},{"type":25,"tag":54,"props":1260,"children":1262},{"className":1261},[],[1263],{"type":30,"value":191},{"type":30,"value":289},{"type":25,"tag":54,"props":1266,"children":1268},{"className":1267},[],[1269],{"type":30,"value":213},{"type":30,"value":296},{"type":25,"tag":54,"props":1272,"children":1274},{"className":1273},[],[1275],{"type":30,"value":302},{"type":30,"value":304},{"type":25,"tag":42,"props":1278,"children":1279},{"id":307},[1280],{"type":30,"value":310},{"type":25,"tag":26,"props":1282,"children":1283},{},[1284,1285,1290],{"type":30,"value":315},{"type":25,"tag":54,"props":1286,"children":1288},{"className":1287},[],[1289],{"type":30,"value":321},{"type":30,"value":323},{"type":25,"tag":26,"props":1292,"children":1293},{},[1294,1295,1300,1301,1306,1307,1312,1313,1318,1319,1324,1325,1330,1331,1336,1337,1342,1343,1348],{"type":30,"value":328},{"type":25,"tag":33,"props":1296,"children":1298},{"href":331,"rel":1297},[66],[1299],{"type":30,"value":335},{"type":30,"value":337},{"type":25,"tag":54,"props":1302,"children":1304},{"className":1303},[],[1305],{"type":30,"value":343},{"type":30,"value":345},{"type":25,"tag":54,"props":1308,"children":1310},{"className":1309},[],[1311],{"type":30,"value":351},{"type":30,"value":274},{"type":25,"tag":54,"props":1314,"children":1316},{"className":1315},[],[1317],{"type":30,"value":358},{"type":30,"value":360},{"type":25,"tag":54,"props":1320,"children":1322},{"className":1321},[],[1323],{"type":30,"value":366},{"type":30,"value":368},{"type":25,"tag":54,"props":1326,"children":1328},{"className":1327},[],[1329],{"type":30,"value":374},{"type":30,"value":376},{"type":25,"tag":54,"props":1332,"children":1334},{"className":1333},[],[1335],{"type":30,"value":343},{"type":30,"value":383},{"type":25,"tag":54,"props":1338,"children":1340},{"className":1339},[],[1341],{"type":30,"value":389},{"type":30,"value":391},{"type":25,"tag":54,"props":1344,"children":1346},{"className":1345},[],[1347],{"type":30,"value":343},{"type":30,"value":398},{"type":25,"tag":26,"props":1350,"children":1351},{},[1352,1353,1358,1359,1364,1365,1370,1371,1376],{"type":30,"value":403},{"type":25,"tag":54,"props":1354,"children":1356},{"className":1355},[],[1357],{"type":30,"value":343},{"type":30,"value":410},{"type":25,"tag":54,"props":1360,"children":1362},{"className":1361},[],[1363],{"type":30,"value":343},{"type":30,"value":417},{"type":25,"tag":54,"props":1366,"children":1368},{"className":1367},[],[1369],{"type":30,"value":423},{"type":30,"value":425},{"type":25,"tag":54,"props":1372,"children":1374},{"className":1373},[],[1375],{"type":30,"value":431},{"type":30,"value":433},{"type":25,"tag":42,"props":1378,"children":1379},{"id":436},[1380],{"type":30,"value":439},{"type":25,"tag":26,"props":1382,"children":1383},{},[1384,1385,1390,1391,1396,1397,1402,1403,1408,1409,1414],{"type":30,"value":444},{"type":25,"tag":54,"props":1386,"children":1388},{"className":1387},[],[1389],{"type":30,"value":450},{"type":30,"value":452},{"type":25,"tag":33,"props":1392,"children":1394},{"href":455,"rel":1393},[66],[1395],{"type":30,"value":459},{"type":30,"value":461},{"type":25,"tag":54,"props":1398,"children":1400},{"className":1399},[],[1401],{"type":30,"value":450},{"type":30,"value":274},{"type":25,"tag":54,"props":1404,"children":1406},{"className":1405},[],[1407],{"type":30,"value":473},{"type":30,"value":475},{"type":25,"tag":33,"props":1410,"children":1412},{"href":478,"rel":1411},[66],[1413],{"type":30,"value":482},{"type":30,"value":484},{"type":25,"tag":26,"props":1416,"children":1417},{},[1418,1419,1424,1425,1429,1430,1434],{"type":30,"value":489},{"type":25,"tag":54,"props":1420,"children":1422},{"className":1421},[],[1423],{"type":30,"value":85},{"type":30,"value":496},{"type":25,"tag":33,"props":1426,"children":1427},{"href":499},[1428],{"type":30,"value":502},{"type":30,"value":504},{"type":25,"tag":33,"props":1431,"children":1432},{"href":507},[1433],{"type":30,"value":510},{"type":30,"value":512},{"type":25,"tag":26,"props":1436,"children":1437},{},[1438,1439,1444,1445,1450,1451,1456,1457,1462,1463,1468,1469,1474],{"type":30,"value":517},{"type":25,"tag":33,"props":1440,"children":1442},{"href":520,"rel":1441},[66],[1443],{"type":30,"value":524},{"type":30,"value":526},{"type":25,"tag":33,"props":1446,"children":1448},{"href":529,"rel":1447},[66],[1449],{"type":30,"value":533},{"type":30,"value":535},{"type":25,"tag":33,"props":1452,"children":1454},{"href":538,"rel":1453},[66],[1455],{"type":30,"value":542},{"type":30,"value":544},{"type":25,"tag":54,"props":1458,"children":1460},{"className":1459},[],[1461],{"type":30,"value":550},{"type":30,"value":552},{"type":25,"tag":33,"props":1464,"children":1466},{"href":555,"rel":1465},[66],[1467],{"type":30,"value":559},{"type":30,"value":561},{"type":25,"tag":33,"props":1470,"children":1472},{"href":64,"rel":1471},[66],[1473],{"type":30,"value":567},{"type":30,"value":569},{"type":25,"tag":42,"props":1476,"children":1477},{"id":572},[1478],{"type":30,"value":575},{"type":25,"tag":26,"props":1480,"children":1481},{},[1482],{"type":30,"value":580},{"type":25,"tag":26,"props":1484,"children":1485},{},[1486,1487,1492,1493,1498,1499,1504,1505,1510],{"type":30,"value":585},{"type":25,"tag":33,"props":1488,"children":1490},{"href":588,"rel":1489},[66],[1491],{"type":30,"value":592},{"type":30,"value":274},{"type":25,"tag":33,"props":1494,"children":1496},{"href":529,"rel":1495},[66],[1497],{"type":30,"value":599},{"type":30,"value":601},{"type":25,"tag":54,"props":1500,"children":1502},{"className":1501},[],[1503],{"type":30,"value":607},{"type":30,"value":609},{"type":25,"tag":33,"props":1506,"children":1508},{"href":588,"rel":1507},[66],[1509],{"type":30,"value":615},{"type":30,"value":617},{"type":25,"tag":26,"props":1512,"children":1513},{},[1514,1515,1519,1520,1524,1525,1529],{"type":30,"value":622},{"type":25,"tag":33,"props":1516,"children":1517},{"href":625},[1518],{"type":30,"value":628},{"type":30,"value":630},{"type":25,"tag":33,"props":1521,"children":1522},{"href":633},[1523],{"type":30,"value":636},{"type":30,"value":274},{"type":25,"tag":33,"props":1526,"children":1527},{"href":640},[1528],{"type":30,"value":643},{"type":30,"value":645},{"type":25,"tag":42,"props":1531,"children":1532},{"id":648},[1533],{"type":30,"value":651},{"type":25,"tag":26,"props":1535,"children":1536},{},[1537],{"type":25,"tag":656,"props":1538,"children":1539},{},[1540],{"type":30,"value":660},{"type":25,"tag":26,"props":1542,"children":1543},{},[1544,1545,1550],{"type":30,"value":665},{"type":25,"tag":54,"props":1546,"children":1548},{"className":1547},[],[1549],{"type":30,"value":374},{"type":30,"value":672},{"type":25,"tag":26,"props":1552,"children":1553},{},[1554,1555,1560,1561,1566,1567,1572,1573,1578],{"type":30,"value":677},{"type":25,"tag":54,"props":1556,"children":1558},{"className":1557},[],[1559],{"type":30,"value":77},{"type":30,"value":684},{"type":25,"tag":54,"props":1562,"children":1564},{"className":1563},[],[1565],{"type":30,"value":85},{"type":30,"value":691},{"type":25,"tag":54,"props":1568,"children":1570},{"className":1569},[],[1571],{"type":30,"value":92},{"type":30,"value":698},{"type":25,"tag":54,"props":1574,"children":1576},{"className":1575},[],[1577],{"type":30,"value":99},{"type":30,"value":705},{"type":25,"tag":26,"props":1580,"children":1581},{},[1582,1583,1588,1589,1594,1595,1600,1601,1606],{"type":30,"value":710},{"type":25,"tag":54,"props":1584,"children":1586},{"className":1585},[],[1587],{"type":30,"value":191},{"type":30,"value":717},{"type":25,"tag":54,"props":1590,"children":1592},{"className":1591},[],[1593],{"type":30,"value":343},{"type":30,"value":724},{"type":25,"tag":54,"props":1596,"children":1598},{"className":1597},[],[1599],{"type":30,"value":343},{"type":30,"value":731},{"type":25,"tag":54,"props":1602,"children":1604},{"className":1603},[],[1605],{"type":30,"value":737},{"type":30,"value":739},{"type":25,"tag":26,"props":1608,"children":1609},{},[1610,1611,1616,1617,1622,1623,1628],{"type":30,"value":744},{"type":25,"tag":54,"props":1612,"children":1614},{"className":1613},[],[1615],{"type":30,"value":423},{"type":30,"value":751},{"type":25,"tag":54,"props":1618,"children":1620},{"className":1619},[],[1621],{"type":30,"value":343},{"type":30,"value":758},{"type":25,"tag":54,"props":1624,"children":1626},{"className":1625},[],[1627],{"type":30,"value":737},{"type":30,"value":765},{"type":25,"tag":26,"props":1630,"children":1631},{},[1632,1633,1638,1639,1644,1645,1650,1651,1656],{"type":30,"value":770},{"type":25,"tag":54,"props":1634,"children":1636},{"className":1635},[],[1637],{"type":30,"value":450},{"type":30,"value":777},{"type":25,"tag":54,"props":1640,"children":1642},{"className":1641},[],[1643],{"type":30,"value":783},{"type":30,"value":785},{"type":25,"tag":54,"props":1646,"children":1648},{"className":1647},[],[1649],{"type":30,"value":791},{"type":30,"value":793},{"type":25,"tag":54,"props":1652,"children":1654},{"className":1653},[],[1655],{"type":30,"value":92},{"type":30,"value":800},{"type":25,"tag":26,"props":1658,"children":1659},{},[1660],{"type":30,"value":805},{"type":25,"tag":42,"props":1662,"children":1663},{"id":808},[1664],{"type":30,"value":811},{"type":25,"tag":26,"props":1666,"children":1667},{},[1668],{"type":30,"value":816},{"type":25,"tag":26,"props":1670,"children":1671},{},[1672],{"type":30,"value":821},{"type":25,"tag":26,"props":1674,"children":1675},{},[1676],{"type":30,"value":826},{"type":25,"tag":26,"props":1678,"children":1679},{},[1680],{"type":30,"value":831},{"type":25,"tag":26,"props":1682,"children":1683},{},[1684],{"type":30,"value":836},{"type":25,"tag":26,"props":1686,"children":1687},{},[1688],{"type":30,"value":841},{"type":25,"tag":42,"props":1690,"children":1691},{"id":844},[1692],{"type":30,"value":847},{"type":25,"tag":849,"props":1694,"children":1695},{},[1696,1700,1722,1726,1736,1740,1744,1748],{"type":25,"tag":853,"props":1697,"children":1698},{},[1699],{"type":30,"value":857},{"type":25,"tag":853,"props":1701,"children":1702},{},[1703,1704,1709,1710,1715,1716,1721],{"type":30,"value":862},{"type":25,"tag":54,"props":1705,"children":1707},{"className":1706},[],[1708],{"type":30,"value":59},{"type":30,"value":79},{"type":25,"tag":54,"props":1711,"children":1713},{"className":1712},[],[1714],{"type":30,"value":166},{"type":30,"value":207},{"type":25,"tag":54,"props":1717,"children":1719},{"className":1718},[],[1720],{"type":30,"value":321},{"type":30,"value":881},{"type":25,"tag":853,"props":1723,"children":1724},{},[1725],{"type":30,"value":886},{"type":25,"tag":853,"props":1727,"children":1728},{},[1729,1730,1735],{"type":30,"value":891},{"type":25,"tag":54,"props":1731,"children":1733},{"className":1732},[],[1734],{"type":30,"value":431},{"type":30,"value":898},{"type":25,"tag":853,"props":1737,"children":1738},{},[1739],{"type":30,"value":903},{"type":25,"tag":853,"props":1741,"children":1742},{},[1743],{"type":30,"value":908},{"type":25,"tag":853,"props":1745,"children":1746},{},[1747],{"type":30,"value":913},{"type":25,"tag":853,"props":1749,"children":1750},{},[1751],{"type":30,"value":918},{"type":25,"tag":42,"props":1753,"children":1754},{"id":921},[1755],{"type":30,"value":924},{"type":25,"tag":26,"props":1757,"children":1758},{},[1759],{"type":30,"value":929},{"type":25,"tag":42,"props":1761,"children":1762},{"id":932},[1763],{"type":30,"value":935},{"type":25,"tag":247,"props":1765,"children":1766},{"id":938},[1767],{"type":30,"value":941},{"type":25,"tag":26,"props":1769,"children":1770},{},[1771,1775,1776,1781,1782,1787],{"type":25,"tag":656,"props":1772,"children":1773},{},[1774],{"type":30,"value":949},{"type":30,"value":951},{"type":25,"tag":54,"props":1777,"children":1779},{"className":1778},[],[1780],{"type":30,"value":343},{"type":30,"value":958},{"type":25,"tag":54,"props":1783,"children":1785},{"className":1784},[],[1786],{"type":30,"value":423},{"type":30,"value":965},{"type":25,"tag":247,"props":1789,"children":1790},{"id":968},[1791],{"type":30,"value":971},{"type":25,"tag":26,"props":1793,"children":1794},{},[1795,1799],{"type":25,"tag":656,"props":1796,"children":1797},{},[1798],{"type":30,"value":949},{"type":30,"value":980},{"type":25,"tag":247,"props":1801,"children":1802},{"id":983},[1803],{"type":30,"value":986},{"type":25,"tag":26,"props":1805,"children":1806},{},[1807,1811,1812,1817,1818,1823],{"type":25,"tag":656,"props":1808,"children":1809},{},[1810],{"type":30,"value":949},{"type":30,"value":995},{"type":25,"tag":54,"props":1813,"children":1815},{"className":1814},[],[1816],{"type":30,"value":191},{"type":30,"value":289},{"type":25,"tag":54,"props":1819,"children":1821},{"className":1820},[],[1822],{"type":30,"value":213},{"type":30,"value":1008},{"type":25,"tag":247,"props":1825,"children":1826},{"id":1011},[1827],{"type":30,"value":1014},{"type":25,"tag":26,"props":1829,"children":1830},{},[1831,1835],{"type":25,"tag":656,"props":1832,"children":1833},{},[1834],{"type":30,"value":949},{"type":30,"value":1023},{"type":25,"tag":26,"props":1837,"children":1838},{},[1839,1840,1844],{"type":30,"value":1028},{"type":25,"tag":33,"props":1841,"children":1842},{"href":1031},[1843],{"type":30,"value":1034},{"type":30,"value":1036},{"title":7,"searchDepth":1038,"depth":1038,"links":1846},[1847,1848,1851,1852,1853,1854,1855,1856,1857,1858],{"id":44,"depth":1038,"text":47},{"id":152,"depth":1038,"text":155,"children":1849},[1850],{"id":249,"depth":1044,"text":252},{"id":307,"depth":1038,"text":310},{"id":436,"depth":1038,"text":439},{"id":572,"depth":1038,"text":575},{"id":648,"depth":1038,"text":651},{"id":808,"depth":1038,"text":811},{"id":844,"depth":1038,"text":847},{"id":921,"depth":1038,"text":924},{"id":932,"depth":1038,"text":935,"children":1859},[1860,1861,1862,1863],{"id":938,"depth":1044,"text":941},{"id":968,"depth":1044,"text":971},{"id":983,"depth":1044,"text":986},{"id":1011,"depth":1044,"text":1014},[1865,2579,3285],{"_path":1866,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":1867,"description":1868,"slug":1869,"date":1870,"lastUpdated":1870,"author":12,"readingTime":1871,"category":14,"tags":1872,"ogImage":1876,"featured":6,"body":1877,"_type":1058,"_id":2576,"_source":1060,"_file":2577,"_stem":2578,"_extension":1063},"\u002Farticles\u002F39-crypto-seizure-warrant-trace-hamas-2026","What a seizure-warrant trace reveals about blockchain evidence","A case study of DOJ's September 2026 Hamas crypto seizures, showing how sworn warrant records layer blockchain paths with service-provider evidence.","crypto-seizure-warrant-trace-hamas-2026","2026-09-05",13,[1873,18,1874,19,1875],"case-study","seized-assets","litigation","\u002Fog\u002Fcrypto-seizure-warrant-trace-hamas-2026.png",{"type":22,"children":1878,"toc":2553},[1879,1884,1889,1895,1900,1905,1958,1963,1968,1974,1997,2003,2017,2023,2044,2050,2055,2061,2066,2072,2077,2083,2088,2094,2099,2109,2119,2131,2137,2142,2152,2205,2210,2216,2221,2334,2340,2345,2355,2365,2375,2385,2405,2411,2416,2444,2471,2475,2481,2490,2496,2505,2511,2520,2526,2535,2541],{"type":25,"tag":26,"props":1880,"children":1881},{},[1882],{"type":30,"value":1883},"On September 1, 2026, the Justice Department announced that it had seized over $560,000 in cryptocurrency intended for Hamas and disrupted the domains and servers the group used to solicit donations and recruit supporters. The announcement was the cumulative public record of a longer investigation: seizure warrants issued in the District of Columbia on March 25, June 25, and October 10, 2025, followed by infrastructure warrants on July 29 and August 18, 2026. The government then posted the underlying sworn warrant materials online. The posted packets include AO 109 returns, but those return, inventory, and certification fields are blank, so the public file documents authorization, not the date of execution.",{"type":25,"tag":26,"props":1885,"children":1886},{},[1887],{"type":30,"value":1888},"This is a public, government-published example of a trace described in sworn warrant materials. This article walks through that record to extract a transferable method for litigators and forensic experts, while being careful about what the materials do and do not prove. The legal posture of a criminal seizure investigation differs substantially from a private civil dispute, and the value of this case study is methodological, not an invitation to import government conclusions wholesale.",{"type":25,"tag":42,"props":1890,"children":1892},{"id":1891},"the-procedural-posture-allegations-probable-cause-and-seizure",[1893],{"type":30,"value":1894},"The Procedural Posture: Allegations, Probable Cause, and Seizure",{"type":25,"tag":26,"props":1896,"children":1897},{},[1898],{"type":30,"value":1899},"Before reading any warrant record, establish which legal conclusion the document supports. This case study is a useful lesson precisely because the September announcement reports a seizure premised on probable cause, not a judgment or conviction.",{"type":25,"tag":26,"props":1901,"children":1902},{},[1903],{"type":30,"value":1904},"These are the categories, in order of increasing legal weight:",{"type":25,"tag":1906,"props":1907,"children":1908},"ul",{},[1909,1919,1938,1948],{"type":25,"tag":853,"props":1910,"children":1911},{},[1912,1917],{"type":25,"tag":656,"props":1913,"children":1914},{},[1915],{"type":30,"value":1916},"Attributed allegations.",{"type":30,"value":1918}," The government states that Hamas, a designated Foreign Terrorist Organization, used the addresses and infrastructure to raise funds and recruit. At the point of a seizure, these are the government's allegations resting on its investigation, not judicial findings of fact.",{"type":25,"tag":853,"props":1920,"children":1921},{},[1922,1927,1929,1936],{"type":25,"tag":656,"props":1923,"children":1924},{},[1925],{"type":30,"value":1926},"Probable cause.",{"type":30,"value":1928}," The authorizing judge issued each warrant on a probable-cause showing. Under ",{"type":25,"tag":33,"props":1930,"children":1933},{"href":1931,"rel":1932},"https:\u002F\u002Fwww.law.cornell.edu\u002Frules\u002Ffrcrmp\u002Frule_41",[66],[1934],{"type":30,"value":1935},"Federal Rule of Criminal Procedure 41",{"type":30,"value":1937},", a judge must issue a warrant if probable cause is shown by affidavit or other information; the judge may also rely on sworn testimony.",{"type":25,"tag":853,"props":1939,"children":1940},{},[1941,1946],{"type":25,"tag":656,"props":1942,"children":1943},{},[1944],{"type":30,"value":1945},"The seizure itself.",{"type":30,"value":1947}," The Department announced that the FBI seized the funds and infrastructure. A seizure does not itself resolve ownership; a completed forfeiture process is ordinarily needed for a final forfeiture determination.",{"type":25,"tag":853,"props":1949,"children":1950},{},[1951,1956],{"type":25,"tag":656,"props":1952,"children":1953},{},[1954],{"type":30,"value":1955},"Final adjudication.",{"type":30,"value":1957}," Forfeiture, administrative or judicial, requires notice and an opportunity for claimants to contest before title finally vests. None of the materials in this announcement evidence an adjudicated finding against any person.",{"type":25,"tag":26,"props":1959,"children":1960},{},[1961],{"type":30,"value":1962},"For a private litigator, read a warrant document as a menu of investigative steps that were persuasive enough for a magistrate, and treat each fact asserted inside it as an allegation the government must still prove. That distinction matters enormously in civil work, where the burden of proof and the rules of evidence differ from a probable-cause determination.",{"type":25,"tag":26,"props":1964,"children":1965},{},[1966],{"type":30,"value":1967},"I have not and will not repeat specific unverified operational details from these affidavits here, because reproducing what an affidavit alleges about live infrastructure serves no legal-pedagogical purpose and can be inaccurate if read out of context. The lesson is in the structure.",{"type":25,"tag":42,"props":1969,"children":1971},{"id":1970},"how-the-evidence-was-layered-not-just-traced",[1972],{"type":30,"value":1973},"How the Evidence Was Layered, Not Just Traced",{"type":25,"tag":26,"props":1975,"children":1976},{},[1977,1979,1986,1988,1995],{"type":30,"value":1978},"Reading the public record as a whole, the investigation assembled at least six distinct categories of evidence. Few are blockchain analysis alone. The ",{"type":25,"tag":33,"props":1980,"children":1983},{"href":1981,"rel":1982},"https:\u002F\u002Fwww.justice.gov\u002Fopa\u002Fpr\u002Fjustice-department-continues-disrupt-hamas-terrorist-financing-schemes-through-seizures",[66],[1984],{"type":30,"value":1985},"press release",{"type":30,"value":1987}," describes cryptocurrency seizures, the seizure of domains and servers, and disruption of fundraising and recruitment platforms; industry reporting on the affidavits, such as ",{"type":25,"tag":33,"props":1989,"children":1992},{"href":1990,"rel":1991},"https:\u002F\u002Fwww.chainalysis.com\u002Fblog\u002Ffbi-seizes-hamas-crypto-fundraising-network\u002F",[66],[1993],{"type":30,"value":1994},"Chainalysis's review of the filings",{"type":30,"value":1996},", adds detail on how the on-chain work connected to accounts and intermediaries.",{"type":25,"tag":247,"props":1998,"children":2000},{"id":1999},"on-chain-transaction-paths",[2001],{"type":30,"value":2002},"On-Chain Transaction Paths",{"type":25,"tag":26,"props":2004,"children":2005},{},[2006,2008,2015],{"type":30,"value":2007},"The foundational layer is the public ledger record itself. The March 2025 warrant materials (25-sz-20, issued March 25, 2025, in the District of Columbia, in the ",{"type":25,"tag":33,"props":2009,"children":2012},{"href":2010,"rel":2011},"https:\u002F\u002Fwww.justice.gov\u002Fopa\u002Fmedia\u002F1459791\u002Fdl?inline",[66],[2013],{"type":30,"value":2014},"public media library",{"type":30,"value":2016},") cover the initial action, which industry reporting describes as involving roughly $200,000 in stablecoins donated to Hamas. The blockchain showed what moved, when, in what amounts, and between which addresses.",{"type":25,"tag":247,"props":2018,"children":2020},{"id":2019},"controlled-or-observed-transactions",[2021],{"type":30,"value":2022},"Controlled or Observed Transactions",{"type":25,"tag":26,"props":2024,"children":2025},{},[2026,2028,2034,2036,2042],{"type":30,"value":2027},"A distinctive feature in this record is that the government did not merely observe historical flows; it interposed itself. The June 25, 2025 warrant (25-sz-34, ",{"type":25,"tag":33,"props":2029,"children":2032},{"href":2030,"rel":2031},"https:\u002F\u002Fwww.justice.gov\u002Fopa\u002Fmedia\u002F1459796\u002Fdl?inline",[66],[2033],{"type":30,"value":2014},{"type":30,"value":2035},") states in affidavit paragraph 1 that its subject matter is related to seizure 25-sz-20, approved March 25, 2025. Attachment A-1 of that packet is a Tether burn-and-reissue instruction listing USDT addresses; it has no footnotes. The June affidavit describes Tether freezing USDT at law-enforcement request, including a March 12, 2025 freeze of additional funds in accounts funded by an operational wallet, and a further freeze on or about April 15, 2025 of listed donation addresses. It also describes Binance independently freezing withdrawals from three target accounts on April 14, 2025. Those are issuer and exchange compliance actions, not a court restraining order. The October 10, 2025 warrant (25-sz-42, ",{"type":25,"tag":33,"props":2037,"children":2040},{"href":2038,"rel":2039},"https:\u002F\u002Fwww.justice.gov\u002Fopa\u002Fmedia\u002F1459801\u002Fdl?inline",[66],[2041],{"type":30,"value":2014},{"type":30,"value":2043},") describes additional Tether freezes at FBI request on May 22, 2025 and June 14, 2025, and a Binance freeze of withdrawals from a listed account, likewise issuer and exchange actions. Controlled or blocked transactions create evidence that no purely passive observer could produce: the point at which value was diverted, frozen, or redirected is a documented event.",{"type":25,"tag":247,"props":2045,"children":2047},{"id":2046},"communications-and-platform-content",[2048],{"type":30,"value":2049},"Communications and Platform Content",{"type":25,"tag":26,"props":2051,"children":2052},{},[2053],{"type":30,"value":2054},"The disruption of domains and servers gave investigators access to solicitation content and supporter interactions, not merely financial data. According to the DOJ, the action disrupted Hamas's fundraising and recruitment communication platforms and websites. Industry reporting on the filings adds that the seized domains and servers included infrastructure associated with the al-Qassam Brigades' main website, which investigators said allowed them to intercept intended donations and gather information about individuals attempting to contribute.",{"type":25,"tag":247,"props":2056,"children":2058},{"id":2057},"service-provider-records",[2059],{"type":30,"value":2060},"Service-Provider Records",{"type":25,"tag":26,"props":2062,"children":2063},{},[2064],{"type":30,"value":2065},"Per industry reporting on the June 2025 affidavit, the investigators traced original donations through a web of new addresses and accounts, and identified service-provider accounts, including one believed to be associated with a Lebanon-based over-the-counter broker and another exhibiting patterns consistent with money mule activity. Those descriptions are attributed allegations within a probable-cause document, reported secondhand; the underlying records, subpoenas, or production requests are not public. The affidavit leans on service-provider records as a bridge from pseudonymous addresses to operating accounts.",{"type":25,"tag":247,"props":2067,"children":2069},{"id":2068},"address-rotation-and-obfuscation",[2070],{"type":30,"value":2071},"Address Rotation and Obfuscation",{"type":25,"tag":26,"props":2073,"children":2074},{},[2075],{"type":30,"value":2076},"The same reporting describes Hamas adapting its techniques after the initial March 2025 seizure, moving funds through new addresses and, in the October 2025 affidavit, using bridging services and single-use donation wallets, with investigators following the trail despite the obfuscation. Address rotation is a fact pattern, not a dead end: every rotated address still transacts on a public ledger, and each new address can be examined for links to a cluster or a service provider.",{"type":25,"tag":247,"props":2078,"children":2080},{"id":2079},"legal-process-as-evidence",[2081],{"type":30,"value":2082},"Legal Process as Evidence",{"type":25,"tag":26,"props":2084,"children":2085},{},[2086],{"type":30,"value":2087},"Finally, the warrant process itself is part of the record. Multiple sequentially authorized warrants support an inference of an iterative investigation, and the June affidavit's paragraph 1 reference to 25-sz-20 shows investigators expressly building a later application on the earlier one. In private cases, the analog is the discovery sequence: each subpoena response or production can become the foundation for the next.",{"type":25,"tag":42,"props":2089,"children":2091},{"id":2090},"path-tracing-vs-actor-attribution",[2092],{"type":30,"value":2093},"Path Tracing vs. Actor Attribution",{"type":25,"tag":26,"props":2095,"children":2096},{},[2097],{"type":30,"value":2098},"Dissecting this record requires separating two questions that prosecutors and civil litigators constantly conflate.",{"type":25,"tag":26,"props":2100,"children":2101},{},[2102,2107],{"type":25,"tag":656,"props":2103,"children":2104},{},[2105],{"type":30,"value":2106},"Path tracing",{"type":30,"value":2108}," asks where value went. It is answered almost entirely on-chain: the March 25, June 25, and October 10, 2025 seizure warrants set out alleged donation flow through successive addresses as investigators followed the funds.",{"type":25,"tag":26,"props":2110,"children":2111},{},[2112,2117],{"type":25,"tag":656,"props":2113,"children":2114},{},[2115],{"type":30,"value":2116},"Actor attribution",{"type":30,"value":2118}," asks who controlled the addresses. On-chain data alone cannot answer this. The record answers it through everything off-chain: platform accounts, service-provider records, communications content, and the observable behavior of the infrastructure.",{"type":25,"tag":26,"props":2120,"children":2121},{},[2122,2124,2130],{"type":30,"value":2123},"A private civil expert should replicate this split explicitly in any report. The path analysis can be stated with high confidence; the attribution analysis should be stated with a confidence level tied to the caliber of the off-chain evidence actually obtained. When a proposed report merges the two, the opposing expert's job becomes easy. For a practical framework on this very division, see the discussion of address attribution in ",{"type":25,"tag":33,"props":2125,"children":2127},{"href":2126},"\u002Fresources\u002Funderstanding-wallet-ownership-evidence",[2128],{"type":30,"value":2129},"wallet ownership evidence",{"type":30,"value":40},{"type":25,"tag":42,"props":2132,"children":2134},{"id":2133},"a-worked-hypothetical-modeled-on-the-structure",[2135],{"type":30,"value":2136},"A Worked Hypothetical Modeled on the Structure",{"type":25,"tag":26,"props":2138,"children":2139},{},[2140],{"type":30,"value":2141},"The following is a hypothetical illustration built to mirror the layering technique described above, not a description of any actual investigation.",{"type":25,"tag":26,"props":2143,"children":2144},{},[2145,2150],{"type":25,"tag":656,"props":2146,"children":2147},{},[2148],{"type":30,"value":2149},"Hypothetical example:",{"type":30,"value":2151}," You represent a judgment creditor whose debtor, a third-party vendor, is suspected of funneling kickbacks through cryptocurrency. You have a single lead: the vendor's tax return disclosed a wallet address used to receive client overpayments.",{"type":25,"tag":849,"props":2153,"children":2154},{},[2155,2165,2175,2185,2195],{"type":25,"tag":853,"props":2156,"children":2157},{},[2158,2163],{"type":25,"tag":656,"props":2159,"children":2160},{},[2161],{"type":30,"value":2162},"Establish the seed address.",{"type":30,"value":2164}," Query the disclosed address on a block explorer and capture the full transaction history, including inbound overpayments that match client remittance schedules. Document the queries and exports for reproducibility.",{"type":25,"tag":853,"props":2166,"children":2167},{},[2168,2173],{"type":25,"tag":656,"props":2169,"children":2170},{},[2171],{"type":30,"value":2172},"Follow the path.",{"type":30,"value":2174}," Trace outbound value from the seed address to subsequent addresses using standard clustering (common input ownership and change output). Identify a pattern of same-day movements into a single consolidation wallet: the analog of the Hamas affidavits' consolidation pattern.",{"type":25,"tag":853,"props":2176,"children":2177},{},[2178,2183],{"type":25,"tag":656,"props":2179,"children":2180},{},[2181],{"type":30,"value":2182},"Find the service-provider touchpoint.",{"type":30,"value":2184}," When the consolidation wallet funds are sent to a deposit address attributable to an exchange, subpoena the exchange for account records tied to that deposit address, including KYC documents.",{"type":25,"tag":853,"props":2186,"children":2187},{},[2188,2193],{"type":25,"tag":656,"props":2189,"children":2190},{},[2191],{"type":30,"value":2192},"Corroborate with communications and behavior.",{"type":30,"value":2194}," Depose the vendor about the exchange account and the consolidation wallet. Correlate transaction timestamps with vendor travel or project milestones to create the attribution layer the ledger alone cannot supply.",{"type":25,"tag":853,"props":2196,"children":2197},{},[2198,2203],{"type":25,"tag":656,"props":2199,"children":2200},{},[2201],{"type":30,"value":2202},"Preserve the control evidence.",{"type":30,"value":2204}," Move for production of device forensics or a signed message from the disputed addresses, exactly as the government's legal process secured the off-chain records in the seizure wave.",{"type":25,"tag":26,"props":2206,"children":2207},{},[2208],{"type":30,"value":2209},"This sequence is a scaled-down civil analog of the six evidence categories above: path, interposition (the discovery demand), communications, service-provider records, obfuscation detection, and legal process.",{"type":25,"tag":42,"props":2211,"children":2213},{"id":2212},"a-checklist-for-reading-any-public-warrant-or-seizure-record",[2214],{"type":30,"value":2215},"A Checklist for Reading Any Public Warrant or Seizure Record",{"type":25,"tag":26,"props":2217,"children":2218},{},[2219],{"type":30,"value":2220},"When a client hands you a government warrant, press release, or affidavit, run this checklist before forming any opinion:",{"type":25,"tag":1906,"props":2222,"children":2225},{"className":2223},[2224],"contains-task-list",[2226,2244,2259,2274,2289,2304,2319],{"type":25,"tag":853,"props":2227,"children":2230},{"className":2228},[2229],"task-list-item",[2231,2236,2237,2242],{"type":25,"tag":99,"props":2232,"children":2235},{"disabled":2233,"type":2234},true,"checkbox",[],{"type":30,"value":995},{"type":25,"tag":656,"props":2238,"children":2239},{},[2240],{"type":30,"value":2241},"Identify the legal instrument.",{"type":30,"value":2243}," Is it a warrant application, a returned warrant, an affidavit, a forfeiture complaint, or a press release? Each supports a different conclusion.",{"type":25,"tag":853,"props":2245,"children":2247},{"className":2246},[2229],[2248,2251,2252,2257],{"type":25,"tag":99,"props":2249,"children":2250},{"disabled":2233,"type":2234},[],{"type":30,"value":995},{"type":25,"tag":656,"props":2253,"children":2254},{},[2255],{"type":30,"value":2256},"Separate allegations from findings.",{"type":30,"value":2258}," Flag every sentence the government asserts as investigatory belief rather than adjudicated fact.",{"type":25,"tag":853,"props":2260,"children":2262},{"className":2261},[2229],[2263,2266,2267,2272],{"type":25,"tag":99,"props":2264,"children":2265},{"disabled":2233,"type":2234},[],{"type":30,"value":995},{"type":25,"tag":656,"props":2268,"children":2269},{},[2270],{"type":30,"value":2271},"Locate the probable-cause foundation.",{"type":30,"value":2273}," If an affidavit exists, identify which factual predicates support it and which are speculative or attributed.",{"type":25,"tag":853,"props":2275,"children":2277},{"className":2276},[2229],[2278,2281,2282,2287],{"type":25,"tag":99,"props":2279,"children":2280},{"disabled":2233,"type":2234},[],{"type":30,"value":995},{"type":25,"tag":656,"props":2283,"children":2284},{},[2285],{"type":30,"value":2286},"Map each evidence category.",{"type":30,"value":2288}," Place every assertion into one of: on-chain path, interposed transaction, communications, service-provider records, obfuscation indicators, or legal process.",{"type":25,"tag":853,"props":2290,"children":2292},{"className":2291},[2229],[2293,2296,2297,2302],{"type":25,"tag":99,"props":2294,"children":2295},{"disabled":2233,"type":2234},[],{"type":30,"value":995},{"type":25,"tag":656,"props":2298,"children":2299},{},[2300],{"type":30,"value":2301},"Split path from attribution.",{"type":30,"value":2303}," State what the record proves about value movement versus what it proves about persons.",{"type":25,"tag":853,"props":2305,"children":2307},{"className":2306},[2229],[2308,2311,2312,2317],{"type":25,"tag":99,"props":2309,"children":2310},{"disabled":2233,"type":2234},[],{"type":30,"value":995},{"type":25,"tag":656,"props":2313,"children":2314},{},[2315],{"type":30,"value":2316},"Note what is sealed or withheld.",{"type":30,"value":2318}," Warrants are often unsealed only in part. Redactions and sealed exhibits leave gaps in the public record; they do not establish what the nonpublic material proves.",{"type":25,"tag":853,"props":2320,"children":2322},{"className":2321},[2229],[2323,2326,2327,2332],{"type":25,"tag":99,"props":2324,"children":2325},{"disabled":2233,"type":2234},[],{"type":30,"value":995},{"type":25,"tag":656,"props":2328,"children":2329},{},[2330],{"type":30,"value":2331},"Check the return.",{"type":30,"value":2333}," The warrant's return, inventory, and certification are the place to look for what was actually taken, which may differ from what was authorized. In the posted March, June, and October packets, those AO 109 fields are blank, so reconstruct execution from provider production rather than treating the public return as a filled inventory.",{"type":25,"tag":42,"props":2335,"children":2337},{"id":2336},"limitations-burdens-tools-and-sealed-material",[2338],{"type":30,"value":2339},"Limitations: Burdens, Tools, and Sealed Material",{"type":25,"tag":26,"props":2341,"children":2342},{},[2343],{"type":30,"value":2344},"A government seizure record is a persuasive and instructive document, but it is not a template to be transplanted into civil litigation without adaptation.",{"type":25,"tag":26,"props":2346,"children":2347},{},[2348,2353],{"type":25,"tag":656,"props":2349,"children":2350},{},[2351],{"type":30,"value":2352},"Lower burdens.",{"type":30,"value":2354}," Probable cause is a lower standard than proof by a preponderance of the evidence, and both are lower than proof beyond a reasonable doubt. A magistrate's authorization does not constitute a finding that any defendant is liable or guilty.",{"type":25,"tag":26,"props":2356,"children":2357},{},[2358,2363],{"type":25,"tag":656,"props":2359,"children":2360},{},[2361],{"type":30,"value":2362},"Different tools.",{"type":30,"value":2364}," The government can compel records from providers, request issuer or exchange freezes of stablecoin balances, and take control of infrastructure using authorities a civil litigant does not possess. A private party can pursue relevant nonprivileged discovery, but that process is subject to objections, privilege, and cross-jurisdictional enforcement problems.",{"type":25,"tag":26,"props":2366,"children":2367},{},[2368,2373],{"type":25,"tag":656,"props":2369,"children":2370},{},[2371],{"type":30,"value":2372},"Sealed and incomplete records.",{"type":30,"value":2374}," The affidavits posted by the DOJ are partial views. Significant portions of the underlying investigation, including provider communications and foreign records, are not public. An expert who builds a civil case on a partial warrant record without confirming the evidentiary foundation is building on sand. When the record is incomplete, the correct response is narrow analysis, not confidence.",{"type":25,"tag":26,"props":2376,"children":2377},{},[2378,2383],{"type":25,"tag":656,"props":2379,"children":2380},{},[2381],{"type":30,"value":2382},"No adjudication.",{"type":30,"value":2384}," None of the September 2026 materials reflect a conviction, a forfeiture order, or a finding against any individual. Any use of this case study must preserve that distinction.",{"type":25,"tag":26,"props":2386,"children":2387},{},[2388,2390,2396,2398,2404],{"type":30,"value":2389},"For the civil analog of these methods as applied to Ponzi and fraud structures, see the ",{"type":25,"tag":33,"props":2391,"children":2393},{"href":2392},"\u002Fresources\u002Fdeconstructing-ponzi-blockchain-methodology",[2394],{"type":30,"value":2395},"methodological walkthrough of blockchain Ponzi reconstruction",{"type":30,"value":2397},", and for the foundational question of what tracing can and cannot establish, see ",{"type":25,"tag":33,"props":2399,"children":2401},{"href":2400},"\u002Fresources\u002Fcan-blockchain-transactions-be-traced",[2402],{"type":30,"value":2403},"can blockchain transactions be traced",{"type":30,"value":40},{"type":25,"tag":42,"props":2406,"children":2408},{"id":2407},"discovery-and-evidence-questions-worth-asking",[2409],{"type":30,"value":2410},"Discovery and Evidence Questions Worth Asking",{"type":25,"tag":26,"props":2412,"children":2413},{},[2414],{"type":30,"value":2415},"If you are building or challenging a trace modeled on this record, these are the questions to ask of your own expert, or of the opposing expert in deposition if the opinion rests on a warrant or government filing:",{"type":25,"tag":849,"props":2417,"children":2418},{},[2419,2424,2429,2434,2439],{"type":25,"tag":853,"props":2420,"children":2421},{},[2422],{"type":30,"value":2423},"Which addresses are claimed to be connected, and which clustering heuristic supports each connection?",{"type":25,"tag":853,"props":2425,"children":2426},{},[2427],{"type":30,"value":2428},"What is the confidence level attached to the path analysis versus the attribution analysis?",{"type":25,"tag":853,"props":2430,"children":2431},{},[2432],{"type":30,"value":2433},"Which service-provider records were obtained, from whom, and by what legal authority?",{"type":25,"tag":853,"props":2435,"children":2436},{},[2437],{"type":30,"value":2438},"Were any transactions observed, frozen, or redirected by an investigator or third party, and what effect does that interposition have on the integrity of the trace?",{"type":25,"tag":853,"props":2440,"children":2441},{},[2442],{"type":30,"value":2443},"Which assertions in the opinion trace to a publicly available primary source, and which rest on sealed or secondhand material?",{"type":25,"tag":26,"props":2445,"children":2446},{},[2447,2449,2454,2456,2462,2464,2469],{"type":30,"value":2448},"An expert who cannot answer each of these questions with a specific, verifiable response has not yet completed the analysis. If you need to build this evidence layer yourself, ",{"type":25,"tag":33,"props":2450,"children":2451},{"href":633},[2452],{"type":30,"value":2453},"ConsensusIntel's blockchain tracing services",{"type":30,"value":2455}," cover the path and attribution work, and ",{"type":25,"tag":33,"props":2457,"children":2459},{"href":2458},"\u002Fservices#expert-witness",[2460],{"type":30,"value":2461},"expert witness services",{"type":30,"value":2463}," cover the report and testimony stage. The ",{"type":25,"tag":33,"props":2465,"children":2466},{"href":625},[2467],{"type":30,"value":2468},"methodology page",{"type":30,"value":2470}," explains how evidence produced in this layered fashion is documented for litigation.",{"type":25,"tag":42,"props":2472,"children":2473},{"id":932},[2474],{"type":30,"value":935},{"type":25,"tag":247,"props":2476,"children":2478},{"id":2477},"q-can-i-rely-on-a-doj-seizure-warrant-as-proof-in-my-civil-case",[2479],{"type":30,"value":2480},"Q: Can I rely on a DOJ seizure warrant as proof in my civil case?",{"type":25,"tag":26,"props":2482,"children":2483},{},[2484,2488],{"type":25,"tag":656,"props":2485,"children":2486},{},[2487],{"type":30,"value":949},{"type":30,"value":2489}," Not directly. A warrant establishes that a magistrate found probable cause to seize property, which is a lower threshold than civil proof and carries no finding of liability. You can use the warrant as a roadmap for what evidence exists and where it came from, then obtain and verify the underlying records yourself. Treat the government's factual assertions as allegations supported by an investigation you have not seen in full.",{"type":25,"tag":247,"props":2491,"children":2493},{"id":2492},"q-what-is-the-difference-between-path-tracing-and-actor-attribution-in-these-affidavits",[2494],{"type":30,"value":2495},"Q: What is the difference between path tracing and actor attribution in these affidavits?",{"type":25,"tag":26,"props":2497,"children":2498},{},[2499,2503],{"type":25,"tag":656,"props":2500,"children":2501},{},[2502],{"type":30,"value":949},{"type":30,"value":2504}," Path tracing shows where value moved on-chain: addresses, amounts, and timestamps, which is directly observable on the public ledger. Actor attribution connects addresses to persons or organizations, which the ledger cannot do alone. In the Hamas seizure record, attribution rests on the off-chain layers: platform accounts, service-provider records, communications content, and the government's control of infrastructure. Any expert report that merges the two without labeling the confidence of each will be vulnerable on cross-examination.",{"type":25,"tag":247,"props":2506,"children":2508},{"id":2507},"q-why-did-the-government-release-these-warrant-materials-to-the-public",[2509],{"type":30,"value":2510},"Q: Why did the government release these warrant materials to the public?",{"type":25,"tag":26,"props":2512,"children":2513},{},[2514,2518],{"type":25,"tag":656,"props":2515,"children":2516},{},[2517],{"type":30,"value":949},{"type":30,"value":2519}," The Department did not state a separate reason for publication. It posted the seizure warrants and related materials through its Office of Public Affairs with the September 1, 2026 announcement. The applications were filed under seal, and the posted packets are redacted, so the public record is partial. Practitioners should treat the posted documents as the evidentiary window the government chose to open, not the complete file.",{"type":25,"tag":247,"props":2521,"children":2523},{"id":2522},"q-do-blockchain-seizure-warrants-identify-real-people",[2524],{"type":30,"value":2525},"Q: Do blockchain seizure warrants identify real people?",{"type":25,"tag":26,"props":2527,"children":2528},{},[2529,2533],{"type":25,"tag":656,"props":2530,"children":2531},{},[2532],{"type":30,"value":949},{"type":30,"value":2534}," Sometimes, but their focus is property, not persons. Warrants name addresses, accounts, and infrastructure as the items to be seized, and affidavits describe the investigation supporting probable cause. Names can appear where service-provider records or communications tie an account to an individual, but a warrant is not a charging document or a conviction. Do not read an uncharged name in an affidavit as an adjudicated finding.",{"type":25,"tag":42,"props":2536,"children":2538},{"id":2537},"closing",[2539],{"type":30,"value":2540},"Closing",{"type":25,"tag":26,"props":2542,"children":2543},{},[2544,2546,2551],{"type":30,"value":2545},"This case study is a particularly clean example of investigative layering in a real enforcement record, but every matter differs in its facts, jurisdictions, and available evidence. If you are evaluating a trace, preparing to challenge an opposing expert, or considering whether a public seizure record can advance your client's interests, a consultation is the right next step. ",{"type":25,"tag":33,"props":2547,"children":2548},{"href":1031},[2549],{"type":30,"value":2550},"Contact ConsensusIntel",{"type":30,"value":2552}," to discuss the specifics of your matter.",{"title":7,"searchDepth":1038,"depth":1038,"links":2554},[2555,2556,2564,2565,2566,2567,2568,2569,2575],{"id":1891,"depth":1038,"text":1894},{"id":1970,"depth":1038,"text":1973,"children":2557},[2558,2559,2560,2561,2562,2563],{"id":1999,"depth":1044,"text":2002},{"id":2019,"depth":1044,"text":2022},{"id":2046,"depth":1044,"text":2049},{"id":2057,"depth":1044,"text":2060},{"id":2068,"depth":1044,"text":2071},{"id":2079,"depth":1044,"text":2082},{"id":2090,"depth":1038,"text":2093},{"id":2133,"depth":1038,"text":2136},{"id":2212,"depth":1038,"text":2215},{"id":2336,"depth":1038,"text":2339},{"id":2407,"depth":1038,"text":2410},{"id":932,"depth":1038,"text":935,"children":2570},[2571,2572,2573,2574],{"id":2477,"depth":1044,"text":2480},{"id":2492,"depth":1044,"text":2495},{"id":2507,"depth":1044,"text":2510},{"id":2522,"depth":1044,"text":2525},{"id":2537,"depth":1038,"text":2540},"content:articles:39-crypto-seizure-warrant-trace-hamas-2026.md","articles\u002F39-crypto-seizure-warrant-trace-hamas-2026.md","articles\u002F39-crypto-seizure-warrant-trace-hamas-2026",{"_path":2580,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":2581,"description":2582,"slug":2583,"date":2584,"lastUpdated":2584,"author":12,"readingTime":13,"category":14,"tags":2585,"ogImage":2589,"featured":6,"body":2590,"_type":1058,"_id":3282,"_source":1060,"_file":3283,"_stem":3284,"_extension":1063},"\u002Farticles\u002F38-multisig-contract-wallet-attribution","One address, many actors: contract wallet attribution","Contract wallets and multisigs are not one-person accounts. Experts reconstruct owners, signers, modules, and relayers to attribute on-chain activity.","multisig-contract-wallet-attribution","2026-08-29",[2586,2587,2588,17,19],"multisig","wallet","account-abstraction","\u002Fog\u002Fmultisig-contract-wallet-attribution.png",{"type":22,"children":2591,"toc":3259},[2592,2597,2603,2617,2639,2644,2649,2655,2661,2666,2672,2677,2683,2696,2702,2723,2729,2752,2758,2763,2796,2808,2814,2819,2825,2839,2844,2850,2855,3054,3059,3065,3070,3082,3088,3093,3098,3136,3154,3158,3164,3173,3179,3188,3194,3203,3209,3218,3224,3233],{"type":25,"tag":26,"props":2593,"children":2594},{},[2595],{"type":30,"value":2596},"When a disputed wallet is a smart contract, the address is an execution account, not a person. Authority over it is defined by code: an owner list, a signature threshold, enabled modules, guards, and sometimes delegation or account-abstraction infrastructure. For fraud, corporate, and probate counsel the question is therefore not \"who owns this address\" but \"whose authorization moved these assets,\" and where that answer stops being a chain fact and becomes inference.",{"type":25,"tag":42,"props":2598,"children":2600},{"id":2599},"contract-wallets-are-not-ordinary-accounts",[2601],{"type":30,"value":2602},"Contract Wallets Are Not Ordinary Accounts",{"type":25,"tag":26,"props":2604,"children":2605},{},[2606,2608,2615],{"type":30,"value":2607},"Ethereum distinguishes externally owned accounts (EOAs) from contract accounts. An EOA is controlled by its private key; a contract account has no private key and acts according to its code when called. EIP-7702 adds a third fact an analyst may need to account for: an EOA can carry a delegation indicator that causes calls to execute delegated code. The ",{"type":25,"tag":33,"props":2609,"children":2612},{"href":2610,"rel":2611},"https:\u002F\u002Fethereum.org\u002Fdevelopers\u002Fdocs\u002Faccounts\u002F",[66],[2613],{"type":30,"value":2614},"ethereum.org account documentation",{"type":30,"value":2616}," describes the EOA and contract-account distinction.",{"type":25,"tag":26,"props":2618,"children":2619},{},[2620,2622,2629,2631,2637],{"type":30,"value":2621},"A transaction that appears \"signed by the wallet\" is signed by whatever actors the wallet's code accepts. Contracts cannot sign the way key-based accounts do, which is why the ",{"type":25,"tag":33,"props":2623,"children":2626},{"href":2624,"rel":2625},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-1271",[66],[2627],{"type":30,"value":2628},"ERC-1271 standard",{"type":30,"value":2630}," exists: a contract exposes ",{"type":25,"tag":54,"props":2632,"children":2634},{"className":2633},[],[2635],{"type":30,"value":2636},"isValidSignature(hash, signature)",{"type":30,"value":2638}," and returns a fixed magic value when the signature is valid for it. Validation can be context dependent, keyed to time, state, or a signer's authorization level.",{"type":25,"tag":26,"props":2640,"children":2641},{},[2642],{"type":30,"value":2643},"An analyst who treats a contract-wallet address as an EOA misattributes everything downstream, because the assumption of one key, one signer, one person does not hold.",{"type":25,"tag":26,"props":2645,"children":2646},{},[2647],{"type":30,"value":2648},"Safe Smart Account, formerly Gnosis Safe, is a common multisig implementation. A Safe stores an owner list and a threshold, the minimum number of owner approvals needed to execute, on-chain. Changes to the owner set or threshold are Safe transactions, so the same address can have different control arrangements at different times.",{"type":25,"tag":42,"props":2650,"children":2652},{"id":2651},"the-actors-behind-a-single-address",[2653],{"type":30,"value":2654},"The Actors Behind a Single Address",{"type":25,"tag":247,"props":2656,"children":2658},{"id":2657},"owners-and-signers",[2659],{"type":30,"value":2660},"Owners and Signers",{"type":25,"tag":26,"props":2662,"children":2663},{},[2664],{"type":30,"value":2665},"Owners are the addresses permitted to approve transactions; each approval is a signature over the transaction hash. Owners can themselves be contracts, a configuration ERC-1271 anticipated, so owner lists can nest. In Safe's standard execution path, transaction input contains a packed signature value that can include an ECDSA signature, an ERC-1271 contract signature identifying its verifying contract, or a pre-validated hash. For that execution path, the analyst can often enumerate which approving addresses were presented: a chain fact.",{"type":25,"tag":247,"props":2667,"children":2669},{"id":2668},"the-threshold",[2670],{"type":30,"value":2671},"The Threshold",{"type":25,"tag":26,"props":2673,"children":2674},{},[2675],{"type":30,"value":2676},"The threshold is a control setting, not a person; a change from 2-of-3 to 1-of-1 is a concentration-of-control event that leaves its own signed record. The threshold in force on the transfer date is usually the first thing to pin down.",{"type":25,"tag":247,"props":2678,"children":2680},{"id":2679},"modules",[2681],{"type":30,"value":2682},"Modules",{"type":25,"tag":26,"props":2684,"children":2685},{},[2686,2688,2694],{"type":30,"value":2687},"Modules are contracts an owner set enables through an approved wallet transaction. Once enabled, a module can execute transactions through the wallet without collecting the owner-threshold signatures used in ordinary Safe execution. Evidentiary significance: a transfer executed through a module does not carry owner signatures in the standard ",{"type":25,"tag":54,"props":2689,"children":2691},{"className":2690},[],[2692],{"type":30,"value":2693},"execTransaction",{"type":30,"value":2695}," encoding, and whether owners approved depends on the module logic rather than the threshold.",{"type":25,"tag":247,"props":2697,"children":2699},{"id":2698},"guards",[2700],{"type":30,"value":2701},"Guards",{"type":25,"tag":26,"props":2703,"children":2704},{},[2705,2707,2713,2715,2721],{"type":30,"value":2706},"Guards add pre- and post-execution checks; unlike modules they cannot originate transactions, only pass or block them. A guard change is recorded on-chain, including the ",{"type":25,"tag":54,"props":2708,"children":2710},{"className":2709},[],[2711],{"type":30,"value":2712},"ChangedGuard",{"type":30,"value":2714}," event emitted by Safe's ",{"type":25,"tag":54,"props":2716,"children":2718},{"className":2717},[],[2719],{"type":30,"value":2720},"setGuard",{"type":30,"value":2722}," function. That interface is a transaction guard on ordinary Safe execution. A module-executed transfer is a different path, so a claim that the guard should have stopped it requires showing the guard actually ran on that execution.",{"type":25,"tag":247,"props":2724,"children":2726},{"id":2725},"relayers-bundlers-paymasters-and-delegated-code",[2727],{"type":30,"value":2728},"Relayers, Bundlers, Paymasters, and Delegated Code",{"type":25,"tag":26,"props":2730,"children":2731},{},[2732,2734,2741,2743,2750],{"type":30,"value":2733},"Submission is not approval. Safe contracts allow relayed execution, so the account submitting an execution can differ from the owners who signed it. Under account abstraction the separation is structural: ",{"type":25,"tag":33,"props":2735,"children":2738},{"href":2736,"rel":2737},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-4337",[66],[2739],{"type":30,"value":2740},"ERC-4337",{"type":30,"value":2742}," defines UserOperations, a pseudo-transaction naming the sender account, factory data, gas limits and fees, optional paymaster data, and a signature the account itself validates. Bundlers collect valid UserOperations and submit them to a shared EntryPoint contract, so the on-chain transaction's sender is the bundler, not the smart-account address. Paymasters can sponsor fees. A related mechanism is ",{"type":25,"tag":33,"props":2744,"children":2747},{"href":2745,"rel":2746},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-7702",[66],[2748],{"type":30,"value":2749},"EIP-7702",{"type":30,"value":2751},", under which an EOA signs an authorization tuple writing a persistent delegation indicator into its account code. The authorization list is processed before that transaction's execution, and the indicator remains in effect on later calls until it is updated, so attribution requires reading the delegation indicator in effect at the disputed date along with the delegate contract.",{"type":25,"tag":42,"props":2753,"children":2755},{"id":2754},"reconstructing-configuration-at-the-disputed-time",[2756],{"type":30,"value":2757},"Reconstructing Configuration at the Disputed Time",{"type":25,"tag":26,"props":2759,"children":2760},{},[2761],{"type":30,"value":2762},"For an identified wallet implementation, configuration changes may be recoverable from its transactions, event logs, and historical state. The analyst must establish from the code and records which changes are observable, then reconstruct the configuration to the relevant date rather than reading today's state. The reconstruction runs in six layers:",{"type":25,"tag":849,"props":2764,"children":2765},{},[2766,2771,2776,2781,2786,2791],{"type":25,"tag":853,"props":2767,"children":2768},{},[2769],{"type":30,"value":2770},"Classify the account: EOA or contract, including any EIP-7702 delegation indicator, and the implementation behind any proxy.",{"type":25,"tag":853,"props":2772,"children":2773},{},[2774],{"type":30,"value":2775},"Rebuild the configuration history to the disputed date.",{"type":25,"tag":853,"props":2777,"children":2778},{},[2779],{"type":30,"value":2780},"Classify each execution path: owner-signed, module-executed, or delegated call.",{"type":25,"tag":853,"props":2782,"children":2783},{},[2784],{"type":30,"value":2785},"Extract approving addresses from signature data where the execution path encodes it.",{"type":25,"tag":853,"props":2787,"children":2788},{},[2789],{"type":30,"value":2790},"Identify infrastructure actors: submitter, gas payer, refund receiver, bundler, paymaster.",{"type":25,"tag":853,"props":2792,"children":2793},{},[2794],{"type":30,"value":2795},"Map addresses to persons or entities using off-chain evidence.",{"type":25,"tag":26,"props":2797,"children":2798},{},[2799,2801,2806],{"type":30,"value":2800},"What is not on-chain deserves equal emphasis. Which human held each key is almost always an off-chain question, and confirmations collected before a transaction reached threshold may live only in the wallet provider's services. The ",{"type":25,"tag":33,"props":2802,"children":2803},{"href":2126},[2804],{"type":30,"value":2805},"evidence methods used to tie keys to people",{"type":30,"value":2807}," apply here with one twist: a single key is only part of the authorization.",{"type":25,"tag":42,"props":2809,"children":2811},{"id":2810},"account-abstraction-and-the-erc-4337-pipeline",[2812],{"type":30,"value":2813},"Account Abstraction and the ERC-4337 Pipeline",{"type":25,"tag":26,"props":2815,"children":2816},{},[2817],{"type":30,"value":2818},"ERC-4337 changes how wallets are created and run. The sender account can be deployed for the first time inside the UserOperation via factory data, so the wallet can be created and transacted in one flow. The EntryPoint contract validates gas, calls the account's validation function, then calls it to execute; what counts as a valid signature is defined by the account's own code. Safe's ERC-4337 integration uses a module that validates a UserOperation against Safe owner signatures, then executes a module transaction. The forensic consequence: the chain identifies the account and the executor infrastructure, while authority lives in the account's code.",{"type":25,"tag":42,"props":2820,"children":2822},{"id":2821},"counterfactual-accounts-authorization-before-the-contract-exists",[2823],{"type":30,"value":2824},"Counterfactual Accounts: Authorization Before the Contract Exists",{"type":25,"tag":26,"props":2826,"children":2827},{},[2828,2830,2837],{"type":30,"value":2829},"Deterministic deployment means an account's address can be computed before any code exists at it, using a factory and a salt; funds can sit at an address with no bytecode. ",{"type":25,"tag":33,"props":2831,"children":2834},{"href":2832,"rel":2833},"https:\u002F\u002Feips.ethereum.org\u002FEIPS\u002Feip-6492",[66],[2835],{"type":30,"value":2836},"ERC-6492",{"type":30,"value":2838}," standardizes signature validation for predeploy contracts: the signature is wrapped with the factory address, deployment calldata, and the underlying ERC-1271 signature, ending in magic bytes that cannot collide with a key-based signature. The specification requires a verifier to detect the magic bytes first and, when they are present, call the factory with the deployment calldata (deploying if the wallet is not already deployed) before validating the inner ERC-1271 signature; then perform standard ERC-1271 checks if code exists; if that ERC-1271 call failed and the factory call was skipped because the wallet already had code, execute the factory calldata and retry; and attempt ecrecover only as a final step.",{"type":25,"tag":26,"props":2840,"children":2841},{},[2842],{"type":30,"value":2843},"The evidentiary upshot: a party can produce a signature for a counterfactual wallet before that wallet exists on-chain. The intended configuration may then be reconstructed from the factory address and deployment calldata in the ERC-6492 wrap, from any later on-chain deployment if one exists, and from off-chain records of the planned owner set; on-chain state alone may under-describe what happened.",{"type":25,"tag":42,"props":2845,"children":2847},{"id":2846},"an-attribution-matrix-for-expert-reports-and-deposition",[2848],{"type":30,"value":2849},"An Attribution Matrix for Expert Reports and Deposition",{"type":25,"tag":26,"props":2851,"children":2852},{},[2853],{"type":30,"value":2854},"The table below is the organizing device I use in expert reports and at deposition; it forces a separate answer for each actor type and labels each as fact or inference.",{"type":25,"tag":2856,"props":2857,"children":2858},"table",{},[2859,2888],{"type":25,"tag":2860,"props":2861,"children":2862},"thead",{},[2863],{"type":25,"tag":2864,"props":2865,"children":2866},"tr",{},[2867,2873,2878,2883],{"type":25,"tag":2868,"props":2869,"children":2870},"th",{},[2871],{"type":30,"value":2872},"Actor",{"type":25,"tag":2868,"props":2874,"children":2875},{},[2876],{"type":30,"value":2877},"What the chain shows",{"type":25,"tag":2868,"props":2879,"children":2880},{},[2881],{"type":30,"value":2882},"Off-chain evidence needed",{"type":25,"tag":2868,"props":2884,"children":2885},{},[2886],{"type":30,"value":2887},"Typical dispute question",{"type":25,"tag":2889,"props":2890,"children":2891},"tbody",{},[2892,2916,2939,2962,2985,3008,3031],{"type":25,"tag":2864,"props":2893,"children":2894},{},[2895,2901,2906,2911],{"type":25,"tag":2896,"props":2897,"children":2898},"td",{},[2899],{"type":30,"value":2900},"Owner signer",{"type":25,"tag":2896,"props":2902,"children":2903},{},[2904],{"type":30,"value":2905},"Approving address in executed signature data",{"type":25,"tag":2896,"props":2907,"children":2908},{},[2909],{"type":30,"value":2910},"Which person controlled the key",{"type":25,"tag":2896,"props":2912,"children":2913},{},[2914],{"type":30,"value":2915},"Did this person approve?",{"type":25,"tag":2864,"props":2917,"children":2918},{},[2919,2924,2929,2934],{"type":25,"tag":2896,"props":2920,"children":2921},{},[2922],{"type":30,"value":2923},"Threshold",{"type":25,"tag":2896,"props":2925,"children":2926},{},[2927],{"type":30,"value":2928},"Current value and every change, each with signatures",{"type":25,"tag":2896,"props":2930,"children":2931},{},[2932],{"type":30,"value":2933},"Who pushed the change and why",{"type":25,"tag":2896,"props":2935,"children":2936},{},[2937],{"type":30,"value":2938},"Was control concentrated?",{"type":25,"tag":2864,"props":2940,"children":2941},{},[2942,2947,2952,2957],{"type":25,"tag":2896,"props":2943,"children":2944},{},[2945],{"type":30,"value":2946},"Module",{"type":25,"tag":2896,"props":2948,"children":2949},{},[2950],{"type":30,"value":2951},"Module executions and enable\u002Fdisable records; signatures depend on the module",{"type":25,"tag":2896,"props":2953,"children":2954},{},[2955],{"type":30,"value":2956},"Module code and operator",{"type":25,"tag":2896,"props":2958,"children":2959},{},[2960],{"type":30,"value":2961},"Who could move funds without threshold signers?",{"type":25,"tag":2864,"props":2963,"children":2964},{},[2965,2970,2975,2980],{"type":25,"tag":2896,"props":2966,"children":2967},{},[2968],{"type":30,"value":2969},"Guard",{"type":25,"tag":2896,"props":2971,"children":2972},{},[2973],{"type":30,"value":2974},"Guard address and change events; whether that guard ran on this execution path",{"type":25,"tag":2896,"props":2976,"children":2977},{},[2978],{"type":30,"value":2979},"Guard code and operator",{"type":25,"tag":2896,"props":2981,"children":2982},{},[2983],{"type":30,"value":2984},"Why did no check stop it?",{"type":25,"tag":2864,"props":2986,"children":2987},{},[2988,2993,2998,3003],{"type":25,"tag":2896,"props":2989,"children":2990},{},[2991],{"type":30,"value":2992},"Relayer or bundler",{"type":25,"tag":2896,"props":2994,"children":2995},{},[2996],{"type":30,"value":2997},"Submitter and gas records on the execution",{"type":25,"tag":2896,"props":2999,"children":3000},{},[3001],{"type":30,"value":3002},"Operator identity and logs",{"type":25,"tag":2896,"props":3004,"children":3005},{},[3006],{"type":30,"value":3007},"Does submission equal authorization?",{"type":25,"tag":2864,"props":3009,"children":3010},{},[3011,3016,3021,3026],{"type":25,"tag":2896,"props":3012,"children":3013},{},[3014],{"type":30,"value":3015},"Paymaster",{"type":25,"tag":2896,"props":3017,"children":3018},{},[3019],{"type":30,"value":3020},"UserOperation paymaster data and EntryPoint deposits",{"type":25,"tag":2896,"props":3022,"children":3023},{},[3024],{"type":30,"value":3025},"Sponsorship terms and operator",{"type":25,"tag":2896,"props":3027,"children":3028},{},[3029],{"type":30,"value":3030},"Who paid for the move?",{"type":25,"tag":2864,"props":3032,"children":3033},{},[3034,3039,3044,3049],{"type":25,"tag":2896,"props":3035,"children":3036},{},[3037],{"type":30,"value":3038},"Deployer or factory",{"type":25,"tag":2896,"props":3040,"children":3041},{},[3042],{"type":30,"value":3043},"Deployment transaction and factory parameters",{"type":25,"tag":2896,"props":3045,"children":3046},{},[3047],{"type":30,"value":3048},"Factory operator records",{"type":25,"tag":2896,"props":3050,"children":3051},{},[3052],{"type":30,"value":3053},"What configuration was fixed at creation?",{"type":25,"tag":26,"props":3055,"children":3056},{},[3057],{"type":30,"value":3058},"This matrix operationalizes the six-layer reconstruction order. Each step yields either an on-chain fact or an inference needing its own evidence, and the expert report must state which.",{"type":25,"tag":42,"props":3060,"children":3062},{"id":3061},"hypothetical-the-two-of-three-corporate-wallet",[3063],{"type":30,"value":3064},"Hypothetical: The Two-of-Three Corporate Wallet",{"type":25,"tag":26,"props":3066,"children":3067},{},[3068],{"type":30,"value":3069},"Illustrative scenario: a company runs a 2-of-3 Safe holding operating funds. The owners are keys held by two officers and one outside investor. Over ten months the threshold is raised to 3, then lowered to 2, and a spending-limit module is enabled. The disputed transfer, a large payment to a new address, executes with two signatures: one key-based and one ERC-1271 contract signature from a second Safe added as an owner eight months prior. Gas is paid by a relayer address that is not an owner.",{"type":25,"tag":26,"props":3071,"children":3072},{},[3073,3075,3081],{"type":30,"value":3074},"Replaying the Safe's history shows the second Safe entering the owner set, the threshold change that made two approvals sufficient, and the module enable with its authorizing transaction. Parsing the disputed transaction's signature data shows the two approving addresses and their types, including the nested Safe's verifying contract address. What the chain does not show is which humans held the officer keys or whether the module was operated by an employee with no owner status; those answers require device forensics, exchange records, custody policies, and depositions, following the ",{"type":25,"tag":33,"props":3076,"children":3078},{"href":3077},"\u002Fresources\u002Fself-custody-vs-custodial-wallets",[3079],{"type":30,"value":3080},"self-custody discovery playbook",{"type":30,"value":40},{"type":25,"tag":42,"props":3083,"children":3085},{"id":3084},"limitations-and-the-questions-to-ask",[3086],{"type":30,"value":3087},"Limitations and the Questions to Ask",{"type":25,"tag":26,"props":3089,"children":3090},{},[3091],{"type":30,"value":3092},"Proposals that never reached threshold exist only off-chain. Recovered signature addresses can identify an approving key or verifying contract, not a human. Implementations can be upgraded through proxies, so authority can change without the address changing; the upgrade is on-chain, but its effect requires code review. The same address can be deployed deterministically across chains with different states, so each chain is analyzed separately. ERC-1271 validation is context dependent by design: a signature valid on one date may be invalid on another, so validity at the relevant date, not today, is the question. A smart account has no native KYC record comparable to an exchange account, although a related service may hold records.",{"type":25,"tag":26,"props":3094,"children":3095},{},[3096],{"type":30,"value":3097},"The discovery questions that follow:",{"type":25,"tag":849,"props":3099,"children":3100},{},[3101,3106,3111,3116,3121,3126,3131],{"type":25,"tag":853,"props":3102,"children":3103},{},[3104],{"type":30,"value":3105},"Was the address an EOA or a contract at the relevant date, including any EIP-7702 delegation indicator, and what implementation is behind it?",{"type":25,"tag":853,"props":3107,"children":3108},{},[3109],{"type":30,"value":3110},"Produce the full configuration history: every owner, threshold, module, and guard change, with transaction hashes.",{"type":25,"tag":853,"props":3112,"children":3113},{},[3114],{"type":30,"value":3115},"Produce raw transaction input data and event logs for each disputed transaction, not block explorer summaries.",{"type":25,"tag":853,"props":3117,"children":3118},{},[3119],{"type":30,"value":3120},"Which disputed transactions ran through modules, and what code was each module running?",{"type":25,"tag":853,"props":3122,"children":3123},{},[3124],{"type":30,"value":3125},"Who submitted each execution and who paid gas, including bundler and paymaster activity?",{"type":25,"tag":853,"props":3127,"children":3128},{},[3129],{"type":30,"value":3130},"Produce confirmation and signing records from any wallet provider interface used before execution.",{"type":25,"tag":853,"props":3132,"children":3133},{},[3134],{"type":30,"value":3135},"Document key custody for every owner address: devices, seed phrases, corporate policy, personnel changes.",{"type":25,"tag":26,"props":3137,"children":3138},{},[3139,3141,3146,3148,3152],{"type":30,"value":3140},"These are forensic facts and methods that apply in any U.S. forum. How a court weighs them depends on the jurisdiction's evidence rules, and the legal responsibility of each actor is a conclusion built on the factual record under corporate, agency, probate, or criminal law. Conduct executed through code is still conduct; the ",{"type":25,"tag":33,"props":3142,"children":3143},{"href":507},[3144],{"type":30,"value":3145},"smart contract disputes article",{"type":30,"value":3147}," covers how courts treat it. Our ",{"type":25,"tag":33,"props":3149,"children":3150},{"href":625},[3151],{"type":30,"value":2468},{"type":30,"value":3153}," explains how expert reports separate chain facts from inference.",{"type":25,"tag":42,"props":3155,"children":3156},{"id":932},[3157],{"type":30,"value":935},{"type":25,"tag":247,"props":3159,"children":3161},{"id":3160},"q-is-a-multisig-address-owned-by-any-single-person",[3162],{"type":30,"value":3163},"Q: Is a multisig address owned by any single person?",{"type":25,"tag":26,"props":3165,"children":3166},{},[3167,3171],{"type":25,"tag":656,"props":3168,"children":3169},{},[3170],{"type":30,"value":949},{"type":30,"value":3172}," No, not in the way an ordinary wallet is. The address is a contract with an owner list and threshold stored on-chain; control is defined by code, by the threshold number of owner approvals or the module's rules. \"Ownership\" is a legal characterization, resolved by who holds which key and what the parties agreed. No single owner key is sufficient unless the threshold is one.",{"type":25,"tag":247,"props":3174,"children":3176},{"id":3175},"q-if-a-transaction-was-signed-by-enough-owners-who-is-responsible-for-it",[3177],{"type":30,"value":3178},"Q: If a transaction was signed by enough owners, who is responsible for it?",{"type":25,"tag":26,"props":3180,"children":3181},{},[3182,3186],{"type":25,"tag":656,"props":3183,"children":3184},{},[3185],{"type":30,"value":949},{"type":30,"value":3187}," The approvals are on-chain facts, but responsibility is a legal question depending on the signers' relationships. Signature evidence shows which addresses approved and the exact approval set; mapping those to persons, and deciding whether an approval binds the entity, the signer, or both, requires off-chain evidence and applicable law. The forensic contribution is pinning down who approved, when, and through which mechanism.",{"type":25,"tag":247,"props":3189,"children":3191},{"id":3190},"q-can-activity-from-an-erc-4337-smart-account-be-traced-to-the-person-who-initiated-it",[3192],{"type":30,"value":3193},"Q: Can activity from an ERC-4337 smart account be traced to the person who initiated it?",{"type":25,"tag":26,"props":3195,"children":3196},{},[3197,3201],{"type":25,"tag":656,"props":3198,"children":3199},{},[3200],{"type":30,"value":949},{"type":30,"value":3202}," Only partially, and not from the chain alone. Under ERC-4337 the on-chain transaction is submitted by a bundler; the actor is the sender account, a contract whose code defines what signatures it accepts. The UserOperation contains signature data, but whether that data identifies approving keys depends on the account implementation. Connecting any approving address to a human, and separating the initiator from the infrastructure, requires the same off-chain evidence used for any self-custody wallet.",{"type":25,"tag":247,"props":3204,"children":3206},{"id":3205},"q-what-does-it-mean-if-a-wallet-was-not-deployed-when-the-disputed-authorization-happened",[3207],{"type":30,"value":3208},"Q: What does it mean if a wallet was not deployed when the disputed authorization happened?",{"type":25,"tag":26,"props":3210,"children":3211},{},[3212,3216],{"type":25,"tag":656,"props":3213,"children":3214},{},[3215],{"type":30,"value":949},{"type":30,"value":3217}," The address existed as a computation, a deterministic deployment waiting to happen, with no bytecode on-chain at the time. ERC-6492 standardizes validating signatures for such predeploy accounts by wrapping the signature with factory and deployment data. For attribution, the intended owner set must be reconstructed from the factory address and deployment calldata in that wrap, from any later on-chain deployment if one exists, and from off-chain records, because the chain holds no configuration for a contract that did not yet exist.",{"type":25,"tag":247,"props":3219,"children":3221},{"id":3220},"q-what-discovery-should-you-request-when-the-other-side-controls-a-contract-wallet",[3222],{"type":30,"value":3223},"Q: What discovery should you request when the other side controls a contract wallet?",{"type":25,"tag":26,"props":3225,"children":3226},{},[3227,3231],{"type":25,"tag":656,"props":3228,"children":3229},{},[3230],{"type":30,"value":949},{"type":30,"value":3232}," Go beyond the address. Request the implementation and proxy records, the full history of owner, threshold, module, and guard changes with transaction hashes, raw input data for each disputed transaction, module code, submission and gas records, wallet provider confirmation logs, and key custody documentation for every owner address. Without that layer, a contract-wallet attribution rests on the false premise that one address equals one person.",{"type":25,"tag":26,"props":3234,"children":3235},{},[3236,3238,3243,3245,3250,3251,3257],{"type":30,"value":3237},"Each matter turns on its own facts, and the line between what the chain proves and what must be proven around it varies with the wallet design and the parties' records. If you are facing that line, ",{"type":25,"tag":33,"props":3239,"children":3240},{"href":1031},[3241],{"type":30,"value":3242},"contact us",{"type":30,"value":3244}," to discuss the evidence picture, or see how ",{"type":25,"tag":33,"props":3246,"children":3247},{"href":633},[3248],{"type":30,"value":3249},"blockchain tracing engagements",{"type":30,"value":274},{"type":25,"tag":33,"props":3252,"children":3254},{"href":3253},"\u002Fservices#litigation-consulting",[3255],{"type":30,"value":3256},"litigation consulting",{"type":30,"value":3258}," are structured.",{"title":7,"searchDepth":1038,"depth":1038,"links":3260},[3261,3262,3269,3270,3271,3272,3273,3274,3275],{"id":2599,"depth":1038,"text":2602},{"id":2651,"depth":1038,"text":2654,"children":3263},[3264,3265,3266,3267,3268],{"id":2657,"depth":1044,"text":2660},{"id":2668,"depth":1044,"text":2671},{"id":2679,"depth":1044,"text":2682},{"id":2698,"depth":1044,"text":2701},{"id":2725,"depth":1044,"text":2728},{"id":2754,"depth":1038,"text":2757},{"id":2810,"depth":1038,"text":2813},{"id":2821,"depth":1038,"text":2824},{"id":2846,"depth":1038,"text":2849},{"id":3061,"depth":1038,"text":3064},{"id":3084,"depth":1038,"text":3087},{"id":932,"depth":1038,"text":935,"children":3276},[3277,3278,3279,3280,3281],{"id":3160,"depth":1044,"text":3163},{"id":3175,"depth":1044,"text":3178},{"id":3190,"depth":1044,"text":3193},{"id":3205,"depth":1044,"text":3208},{"id":3220,"depth":1044,"text":3223},"content:articles:38-multisig-contract-wallet-attribution.md","articles\u002F38-multisig-contract-wallet-attribution.md","articles\u002F38-multisig-contract-wallet-attribution",{"_path":3286,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":3287,"description":3288,"slug":3289,"date":3290,"lastUpdated":3290,"author":12,"readingTime":3291,"category":14,"tags":3292,"ogImage":3296,"featured":6,"body":3297,"_type":1058,"_id":3868,"_source":1060,"_file":3869,"_stem":3870,"_extension":1063},"\u002Farticles\u002F37-reproducible-blockchain-evidence","Reproducible blockchain evidence beyond the explorer screenshot","Collecting blockchain evidence that another qualified analyst can reproduce: provenance fields, raw response hashes, query documentation, and label provenance.","reproducible-blockchain-evidence","2026-08-22",16,[19,3293,628,3294,3295],"blockchain","expert-witness","digital-forensics","\u002Fog\u002Freproducible-blockchain-evidence.png",{"type":22,"children":3298,"toc":3843},[3299,3304,3324,3330,3335,3340,3363,3369,3374,3380,3385,3391,3396,3402,3407,3413,3441,3447,3452,3458,3471,3477,3491,3496,3502,3507,3520,3526,3538,3564,3569,3574,3580,3585,3590,3596,3601,3664,3669,3675,3680,3728,3734,3753,3757,3763,3772,3778,3787,3793,3802,3808,3817,3823,3832],{"type":25,"tag":26,"props":3300,"children":3301},{},[3302],{"type":30,"value":3303},"Every blockchain record offered in litigation is the output of a query. Someone asked a node, a provider, or a third-party website to return a slice of a distributed database, and the record in the exhibit file is what came back, usually after the interface reformatted it. That means the evidentiary question is rarely about the blockchain itself, which is verifiable by anyone. The question is whether the collection process that produced the exhibit is documented well enough that another qualified person can reproduce the result after the explorer, the label, or the API has changed.",{"type":25,"tag":26,"props":3305,"children":3306},{},[3307,3309,3315,3317,3323],{"type":30,"value":3308},"This article is a technical acquisition protocol, not another admissibility survey. It defines the minimum provenance fields for a defensible collection package, explains how to preserve raw outputs and hash them before any normalization, separates protocol-derived facts from third-party labels, and provides a reproducibility appendix template for expert reports. For the legal framework around authentication, see ",{"type":25,"tag":33,"props":3310,"children":3312},{"href":3311},"\u002Fresources\u002Fblockchain-evidence-admissibility",[3313],{"type":30,"value":3314},"how blockchain records are authenticated under FRE 901 and 902",{"type":30,"value":3316}," and the ",{"type":25,"tag":33,"props":3318,"children":3320},{"href":3319},"\u002Fresources\u002Fblockchain-evidence-federal-missouri-rules",[3321],{"type":30,"value":3322},"federal and Missouri admissibility rules",{"type":30,"value":40},{"type":25,"tag":42,"props":3325,"children":3327},{"id":3326},"why-an-explorer-screenshot-is-not-an-acquisition-record",[3328],{"type":30,"value":3329},"Why an Explorer Screenshot Is Not an Acquisition Record",{"type":25,"tag":26,"props":3331,"children":3332},{},[3333],{"type":30,"value":3334},"A screenshot of a block explorer records pixels, not provenance. It captures what a third-party interface chose to display at one moment: a decoded value, an applied label, a converted time zone, a color-coded flow diagram. What it does not capture is everything the record needs to be reproduced later.",{"type":25,"tag":26,"props":3336,"children":3337},{},[3338],{"type":30,"value":3339},"The missing information is not exotic. A screenshot does not tell you which node or API answered the request, what query method and parameters produced the view, whether the displayed value is a protocol field or an assembled inference, what time source the interface used, or what the raw response contained before the interface normalized it. Copied text from an explorer is worse in one respect: the copy loses the structure of the underlying response, so decimals, hex encodings, and log positions that the interface already decoded are unrecoverable from the paste itself. A live link to an explorer page is the least durable of the three, because the page can be re-rendered, relabeled, or taken down, and the URL records only the query, not the answer.",{"type":25,"tag":26,"props":3341,"children":3342},{},[3343,3345,3352,3354,3361],{"type":30,"value":3344},"The rules point in the same direction. Under the ",{"type":25,"tag":33,"props":3346,"children":3349},{"href":3347,"rel":3348},"https:\u002F\u002Fwww.uscourts.gov\u002Fsites\u002Fdefault\u002Ffiles\u002F2025-02\u002Ffederal-rules-of-evidence-dec-1-2024.pdf",[66],[3350],{"type":30,"value":3351},"Federal Rules of Evidence pamphlet effective December 1, 2024",{"type":30,"value":3353},", self-authentication under Rule 902(13) or 902(14) requires a qualified person's certification, plus written notice under Rule 902(11). As the 2017 ",{"type":25,"tag":33,"props":3355,"children":3358},{"href":3356,"rel":3357},"https:\u002F\u002Fwww.law.cornell.edu\u002Frules\u002Ffre\u002Frule_902",[66],[3359],{"type":30,"value":3360},"Advisory Committee Note to Rule 902(13)",{"type":30,"value":3362}," explains, that certification must contain \"information that would be sufficient to establish authenticity were that information provided by a witness at trial.\" A witness can only describe what was actually recorded during collection. A screenshot alone does not supply that information, and it would be wrong to suggest that an unadorned screenshot satisfies Rule 902(13) or 902(14), which require a qualified person's certification describing the electronic process or the copying process, plus notice under Rule 902(11). The practical takeaway: treat the screenshot as a demonstrative exhibit and the collection package as the evidence.",{"type":25,"tag":42,"props":3364,"children":3366},{"id":3365},"what-a-reproducible-collection-package-must-contain",[3367],{"type":30,"value":3368},"What a Reproducible Collection Package Must Contain",{"type":25,"tag":26,"props":3370,"children":3371},{},[3372],{"type":30,"value":3373},"A collection package is the set of raw outputs, identifiers, and documentation captured at collection time. The goal is that a second analyst, given the package, can regenerate every exhibit in the report and confirm each recorded value. Six groups of provenance fields cover nearly every blockchain data type.",{"type":25,"tag":247,"props":3375,"children":3377},{"id":3376},"chain-identity",[3378],{"type":30,"value":3379},"Chain Identity",{"type":25,"tag":26,"props":3381,"children":3382},{},[3383],{"type":30,"value":3384},"Record the network by name and by numeric chain identifier, distinguish mainnet from testnet, and note whether the chain uses proof of work, proof of stake, or another consensus rule. Ethereum mainnet uses chain ID 1; Bitcoin has no chain ID equivalent, so the network name and the genesis block hash serve the same purpose of disambiguating which chain is at issue. Screenshots routinely omit this, and a transaction that looks identical on a testnet is not evidence of anything.",{"type":25,"tag":247,"props":3386,"children":3388},{"id":3387},"block-and-transaction-identifiers",[3389],{"type":30,"value":3390},"Block and Transaction Identifiers",{"type":25,"tag":26,"props":3392,"children":3393},{},[3394],{"type":30,"value":3395},"Record the block number and block hash, the transaction hash, the transaction's position within the block, and the block timestamp as reported by the chain. Also record how many confirmations the block had at collection time and whether the chain's finality mechanism had already marked it final. These fields let a later analyst locate the exact record even if an explorer has changed its display entirely.",{"type":25,"tag":247,"props":3397,"children":3399},{"id":3398},"contract-token-and-log-data",[3400],{"type":30,"value":3401},"Contract, Token, and Log Data",{"type":25,"tag":26,"props":3403,"children":3404},{},[3405],{"type":30,"value":3406},"For token transfers and smart contract activity, record the contract address, the token standard (for example ERC-20 or ERC-721 on EVM chains), the event signature, the receipt log position alongside the block-scoped log index, and the decoder that was used. Decoding is a transformation, not raw data: the raw log is hex, and the readable \"250,000 USDC\" is the output of an ABI decoder. The package needs both the raw log and the decoder version so the decode can be re-run.",{"type":25,"tag":247,"props":3408,"children":3410},{"id":3409},"query-and-endpoint-records",[3411],{"type":30,"value":3412},"Query and Endpoint Records",{"type":25,"tag":26,"props":3414,"children":3415},{},[3416,3418,3424,3426,3431,3433,3439],{"type":30,"value":3417},"Document the exact request: the RPC method (such as ",{"type":25,"tag":54,"props":3419,"children":3421},{"className":3420},[],[3422],{"type":30,"value":3423},"eth_getBlockByNumber",{"type":30,"value":3425}," or ",{"type":25,"tag":54,"props":3427,"children":3429},{"className":3428},[],[3430],{"type":30,"value":166},{"type":30,"value":3432},"), every parameter, the endpoint URL, whether the node is a full node or archive node, the client software and version (for example geth or Nethermind by name and release), and the provider if data came through a commercial API rather than a self-run node. The ",{"type":25,"tag":33,"props":3434,"children":3436},{"href":555,"rel":3435},[66],[3437],{"type":30,"value":3438},"EIP-1474 remote procedure call specification",{"type":30,"value":3440},", created in 2018 and marked Stagnant, documents these method shapes. Citing the specification that defines the request format is part of reproducibility, but it is not a substitute for recording the request you actually sent.",{"type":25,"tag":247,"props":3442,"children":3444},{"id":3443},"time-and-time-source",[3445],{"type":30,"value":3446},"Time and Time Source",{"type":25,"tag":26,"props":3448,"children":3449},{},[3450],{"type":30,"value":3451},"Record capture time in UTC, note the clock source (system clock, NTP-synchronized host, or the provider's response header), and record any time zone conversion as a separate presentation step. Blockchain timestamps are second-granularity values set by block producers, not investigator observation times, and the two must never be conflated in a report. Chain timestamps are protocol data; the time you pressed \"collect\" is an observation fact; each has its own field.",{"type":25,"tag":247,"props":3453,"children":3455},{"id":3454},"raw-outputs-and-hashes",[3456],{"type":30,"value":3457},"Raw Outputs and Hashes",{"type":25,"tag":26,"props":3459,"children":3460},{},[3461,3463,3469],{"type":30,"value":3462},"Save the raw response verbatim, in the format the API returned it, before any parsing, decoding, or visualization. Compute a cryptographic hash of each saved file at the moment of save and record the algorithm and the hash value. The 2017 ",{"type":25,"tag":33,"props":3464,"children":3466},{"href":3356,"rel":3465},[66],[3467],{"type":30,"value":3468},"Advisory Committee Note to Rule 902(14)",{"type":30,"value":3470}," explains why this is the accepted practice for copied electronic data: if the hash values for the original and the copy are the same, \"it is highly improbable that the original and copy are not identical.\" The collection-time hash lets the analyst verify the integrity of the saved artifact later by hashing the exhibit or copy and comparing it with the recorded value. Subsequent multi-source verification addresses a different question, whether the response matches canonical chain state.",{"type":25,"tag":42,"props":3472,"children":3474},{"id":3473},"preserve-raw-outputs-before-normalization",[3475],{"type":30,"value":3476},"Preserve Raw Outputs Before Normalization",{"type":25,"tag":26,"props":3478,"children":3479},{},[3480,3482,3489],{"type":30,"value":3481},"Forensic process guidance does not change because the data source is a blockchain. ",{"type":25,"tag":33,"props":3483,"children":3486},{"href":3484,"rel":3485},"https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fsp\u002F800\u002F86\u002Ffinal",[66],[3487],{"type":30,"value":3488},"NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response",{"type":30,"value":3490}," (August 2006), frames the work in phases, starting with collection and examination before analysis and reporting, and its core discipline is that the collector preserves the data as found and documents integrity. Applied to blockchain evidence, the rule is simple: raw first, derived second, and every derivation logged.",{"type":25,"tag":26,"props":3492,"children":3493},{},[3494],{"type":30,"value":3495},"Concretely, the JSON response from an RPC call is the \"as found\" artifact. The pretty-printed CSV, the chart, and the report table are derived products. If the analyst only saves the CSV, the original hex values, error fields, and unmodified response object are gone. Keep the raw file in a directory that is never edited, record its hash there, and build the derived products from copies. If a transformation script is involved, record the script's name and version and hash the script too, so a later analyst can confirm the transformation that produced the exhibit. This is a methodological recommendation, not a legal obligation; what the law requires is whatever authentication standard governs your forum, but the recording discipline is what makes certification under Rules 902(13) and (14), or live testimony under Rule 901, actually supportable.",{"type":25,"tag":42,"props":3497,"children":3499},{"id":3498},"separate-protocol-facts-from-third-party-labels",[3500],{"type":30,"value":3501},"Separate Protocol Facts From Third-Party Labels",{"type":25,"tag":26,"props":3503,"children":3504},{},[3505],{"type":30,"value":3506},"A recurring weakness in blockchain exhibits is presenting a label as if it were a chain fact. \"Funds arrived at Binance\" mixes two different claims: the protocol fact that funds moved to a specific address, and the inference, drawn from a third party's directory, that the address is controlled by Binance. The address is on the chain. The label is someone else's research product, and it can be wrong, stale, or contested.",{"type":25,"tag":26,"props":3508,"children":3509},{},[3510,3512,3518],{"type":30,"value":3511},"Record labels separately from protocol data, and record the label's own provenance: which service assigned it, when it was captured, what the service advertises as its methodology, and whether it agrees with any independent check. Recommendation, not a rule: verify high-stakes labels against a second source, such as a published wallet list, an exchange's deposit address, or records produced in discovery. The ",{"type":25,"tag":33,"props":3513,"children":3515},{"href":3514},"\u002Fresources\u002Fwhy-blockchain-forensic-reports-fail-daubert",[3516],{"type":30,"value":3517},"Daubert failure analysis",{"type":30,"value":3519}," of blockchain reports treats unverified platform attribution as the first failure pattern; the collection package is the place to prevent that. In the report, state plainly which sentences are protocol facts, which are inferences, and which are recommendations, because the three have very different evidentiary lives.",{"type":25,"tag":42,"props":3521,"children":3523},{"id":3522},"a-worked-hypothetical-collecting-one-transfer",[3524],{"type":30,"value":3525},"A Worked Hypothetical: Collecting One Transfer",{"type":25,"tag":26,"props":3527,"children":3528},{},[3529,3531,3537],{"type":30,"value":3530},"Hypothetical example: an analyst needs to preserve the record of a 250,000 USDC transfer on Ethereum mainnet. Assume the transaction hash is 0x3f9a1c2e (illustrative), the block number is 25,300,672 (mined approximately four hours earlier), and collection happens on June 12, 2026 at 14:05 UTC from the analyst's own archive node running geth version 1.15, accessed over local RPC at ",{"type":25,"tag":33,"props":3532,"children":3535},{"href":3533,"rel":3534},"http:\u002F\u002F127.0.0.1:8545",[66],[3536],{"type":30,"value":3533},{"type":30,"value":40},{"type":25,"tag":26,"props":3539,"children":3540},{},[3541,3543,3548,3550,3555,3557,3562],{"type":30,"value":3542},"The analyst issues ",{"type":25,"tag":54,"props":3544,"children":3546},{"className":3545},[],[3547],{"type":30,"value":59},{"type":30,"value":3549}," with the transaction hash and ",{"type":25,"tag":54,"props":3551,"children":3553},{"className":3552},[],[3554],{"type":30,"value":166},{"type":30,"value":3556}," with the same hash, and saves both raw JSON responses verbatim into the raw directory, recording sha256 hashes of each file immediately (illustrative values: 1f4b7c2e... and 9a03d8f1...). The receipt shows the transfer occurred at position 2 in the transaction's logs array (with its corresponding block logIndex), and the analyst decodes that log with a specific ABI decoder version to produce \"250,000 USDC from 0xA1B2... to 0xC3D4...\". The block is retrieved with ",{"type":25,"tag":54,"props":3558,"children":3560},{"className":3559},[],[3561],{"type":30,"value":3423},{"type":30,"value":3563}," at the noted height with the full-transactions flag, confirming the timestamp and the transaction's position in the block. At 14:05 UTC the block has 1,193 confirmations and the chain has already finalized it through proof of stake finality, both recorded.",{"type":25,"tag":26,"props":3565,"children":3566},{},[3567],{"type":30,"value":3568},"An explorer page for the receiving address displays the label \"Exchange X\" next to 0xC3D4.... The analyst records the label separately, with the explorer name, the capture timestamp, and a note that the label is an unverified third-party attribution. Six weeks later, the explorer reclassifies the address and removes the label. The protocol-derived portion of the exhibit, backed by the raw responses and hashes, is unaffected; only the label has decayed, and the package shows precisely where the label sat in the analysis.",{"type":25,"tag":26,"props":3570,"children":3571},{},[3572],{"type":30,"value":3573},"If the analyst had only taken the screenshot, the reclassification would silently change what the exhibit appeared to show. With the package, the report can state what the chain said at collection, what a third party labeled at collection, and what the label says now, which is a far stronger position on both direct and cross.",{"type":25,"tag":42,"props":3575,"children":3577},{"id":3576},"test-the-package-before-you-need-it",[3578],{"type":30,"value":3579},"Test the Package Before You Need It",{"type":25,"tag":26,"props":3581,"children":3582},{},[3583],{"type":30,"value":3584},"A reproducible package is worthless until someone has actually reproduced from it. Before the report is served, run a verification pass that does not reuse the same node, provider, or session: re-query the same transactions from a different provider or a second self-run node, compare the raw fields field by field, and recalculate the recorded hashes from the saved files. Differences are not automatically errors. During a chain reorganization, or before a proof of stake chain has finalized a block, different nodes can legitimately return different block contents for the same height, which is why confirmation count and finality status must be in the package in the first place. Mempool observations are not chain data at all and belong in a clearly separate category.",{"type":25,"tag":26,"props":3586,"children":3587},{},[3588],{"type":30,"value":3589},"Two practical tests catch most failures. First, hand the package to a colleague with no memory of the analysis and ask them to regenerate one exhibit from raw files alone; if they cannot, the package is missing a step. Second, re-query the data after a lag of weeks, when explorer labels, API versions, and provider defaults have had time to drift, and confirm every protocol-derived field is stable. If the second test changes the exhibit, the drift is a feature of the package: it shows exactly what depended on a mutable third party.",{"type":25,"tag":42,"props":3591,"children":3593},{"id":3592},"reproducibility-appendix-template",[3594],{"type":30,"value":3595},"Reproducibility Appendix Template",{"type":25,"tag":26,"props":3597,"children":3598},{},[3599],{"type":30,"value":3600},"For the expert report, include a reproducibility appendix with one entry per collected item, each containing all of the following fields:",{"type":25,"tag":849,"props":3602,"children":3603},{},[3604,3609,3614,3619,3624,3629,3634,3639,3644,3649,3654,3659],{"type":25,"tag":853,"props":3605,"children":3606},{},[3607],{"type":30,"value":3608},"Network name, chain ID or genesis identity, and mainnet or testnet designation.",{"type":25,"tag":853,"props":3610,"children":3611},{},[3612],{"type":30,"value":3613},"Block number, block hash, and block timestamp as reported by the chain.",{"type":25,"tag":853,"props":3615,"children":3616},{},[3617],{"type":30,"value":3618},"Transaction hash and position within the block.",{"type":25,"tag":853,"props":3620,"children":3621},{},[3622],{"type":30,"value":3623},"Contract address, token standard, event signature, receipt log position, and block log index where applicable.",{"type":25,"tag":853,"props":3625,"children":3626},{},[3627],{"type":30,"value":3628},"RPC method and complete request parameters.",{"type":25,"tag":853,"props":3630,"children":3631},{},[3632],{"type":30,"value":3633},"Endpoint URL, node type, client software and version, or provider name and plan.",{"type":25,"tag":853,"props":3635,"children":3636},{},[3637],{"type":30,"value":3638},"Capture timestamp in UTC and the clock source.",{"type":25,"tag":853,"props":3640,"children":3641},{},[3642],{"type":30,"value":3643},"Confirmation count and finality status at capture.",{"type":25,"tag":853,"props":3645,"children":3646},{},[3647],{"type":30,"value":3648},"File names of the saved raw responses and the hash algorithm and value for each.",{"type":25,"tag":853,"props":3650,"children":3651},{},[3652],{"type":30,"value":3653},"Decoder or transformation tool, version, and its own hash if a script.",{"type":25,"tag":853,"props":3655,"children":3656},{},[3657],{"type":30,"value":3658},"Every third-party label used, its source, its capture date, and its verification status.",{"type":25,"tag":853,"props":3660,"children":3661},{},[3662],{"type":30,"value":3663},"The independent verification pass: second source queried, date, and result.",{"type":25,"tag":26,"props":3665,"children":3666},{},[3667],{"type":30,"value":3668},"Keeping this appendix current is a report discipline, not a one-time act. Every time a new address, block, or token enters the analysis, the corresponding entry should be created at collection, not reconstructed at drafting. A contemporaneous appendix is a methodology record; a retroactive one is a story.",{"type":25,"tag":42,"props":3670,"children":3672},{"id":3671},"questions-to-ask-the-collecting-expert",[3673],{"type":30,"value":3674},"Questions to Ask the Collecting Expert",{"type":25,"tag":26,"props":3676,"children":3677},{},[3678],{"type":30,"value":3679},"Whether the expert is yours or the opposing party's, these questions expose whether the underlying record is reproducible:",{"type":25,"tag":1906,"props":3681,"children":3682},{},[3683,3688,3693,3698,3703,3708,3713,3718,3723],{"type":25,"tag":853,"props":3684,"children":3685},{},[3686],{"type":30,"value":3687},"Which node, provider, or explorer answered each query, and which software version?",{"type":25,"tag":853,"props":3689,"children":3690},{},[3691],{"type":30,"value":3692},"What was the exact RPC method and parameter set for each exhibit?",{"type":25,"tag":853,"props":3694,"children":3695},{},[3696],{"type":30,"value":3697},"Where are the raw responses, and what are their hashes, recorded at collection time?",{"type":25,"tag":853,"props":3699,"children":3700},{},[3701],{"type":30,"value":3702},"How many confirmations did each block have, and was the chain's finality mechanism satisfied?",{"type":25,"tag":853,"props":3704,"children":3705},{},[3706],{"type":30,"value":3707},"What clock produced the timestamps, and were they converted from UTC?",{"type":25,"tag":853,"props":3709,"children":3710},{},[3711],{"type":30,"value":3712},"Which displayed values are protocol fields, and which are third-party labels with what provenance?",{"type":25,"tag":853,"props":3714,"children":3715},{},[3716],{"type":30,"value":3717},"What scripts, spreadsheets, or tools transformed raw data into the exhibit, and what versions?",{"type":25,"tag":853,"props":3719,"children":3720},{},[3721],{"type":30,"value":3722},"What changed between the collection date and the report date: explorer versions, labels, or API behavior?",{"type":25,"tag":853,"props":3724,"children":3725},{},[3726],{"type":30,"value":3727},"Did anyone independently re-query a sample, from a different source, and what did the comparison show?",{"type":25,"tag":42,"props":3729,"children":3731},{"id":3730},"limitations-of-the-acquisition-approach",[3732],{"type":30,"value":3733},"Limitations of the Acquisition Approach",{"type":25,"tag":26,"props":3735,"children":3736},{},[3737,3739,3744,3746,3751],{"type":30,"value":3738},"The collection package documents provenance; it does not by itself authenticate conclusions. It records what the chain returned and what was collected, not who controlled a wallet or whether a label is correct, and those attribution questions still depend on off-chain evidence and the analytical methods covered separately in the admissibility articles. Reorganization risk is real on proof of work chains, where the confirmation-depth convention exists precisely because short chains can be replaced, and finality on proof of stake chains takes effect only after the chain's finality gadget runs. Testnet and forked data replicate the mechanics without the evidentiary weight of the production chain. Provider responses can differ during reorgs, so multi-source divergence should be expected and documented rather than hidden. And none of this is jurisdiction-specific advice in the form of a rule: federal courts apply the Federal Rules of Evidence, Missouri state courts apply rules that closely parallel them with their own case law, and the practitioner should confirm the applicable authentication and certification requirements in the specific forum before relying on any of these practices. The ",{"type":25,"tag":33,"props":3740,"children":3741},{"href":625},[3742],{"type":30,"value":3743},"ConsensusIntel methodology",{"type":30,"value":3745}," describes how this collection discipline is applied in engagement work, and ",{"type":25,"tag":33,"props":3747,"children":3748},{"href":640},[3749],{"type":30,"value":3750},"evidence review services",{"type":30,"value":3752}," cover structured assessment of another expert's package.",{"type":25,"tag":42,"props":3754,"children":3755},{"id":932},[3756],{"type":30,"value":935},{"type":25,"tag":247,"props":3758,"children":3760},{"id":3759},"q-is-an-explorer-screenshot-ever-sufficient-as-blockchain-evidence",[3761],{"type":30,"value":3762},"Q: Is an explorer screenshot ever sufficient as blockchain evidence?",{"type":25,"tag":26,"props":3764,"children":3765},{},[3766,3770],{"type":25,"tag":656,"props":3767,"children":3768},{},[3769],{"type":30,"value":949},{"type":30,"value":3771}," A screenshot is a demonstrative record of a third-party interface; it is not a complete acquisition record, because it does not show which node answered, what query was run, what the raw response contained, or whether displayed labels were verified. By itself, a screenshot does not supply the qualified person's certification or written notice required to use Rule 902(13) or (14). In a contested matter, treat the screenshot as a visual aid and rely on a collection package that another analyst can reproduce.",{"type":25,"tag":247,"props":3773,"children":3775},{"id":3774},"q-what-is-a-chain-id-and-why-does-it-matter-for-evidence",[3776],{"type":30,"value":3777},"Q: What is a chain ID and why does it matter for evidence?",{"type":25,"tag":26,"props":3779,"children":3780},{},[3781,3785],{"type":25,"tag":656,"props":3782,"children":3783},{},[3784],{"type":30,"value":949},{"type":30,"value":3786}," A chain ID is the numeric identifier that distinguishes one EVM-compatible network from another; Ethereum mainnet uses chain ID 1, and test networks and forks use different values. Chains without a chain ID, like Bitcoin, are identified by network name and genesis hash. Recording this field prevents a testnet or forked transaction from being presented, or challenged, as if it occurred on the production chain.",{"type":25,"tag":247,"props":3788,"children":3790},{"id":3789},"q-should-blockchain-data-be-collected-from-my-own-node-or-from-a-commercial-provider",[3791],{"type":30,"value":3792},"Q: Should blockchain data be collected from my own node or from a commercial provider?",{"type":25,"tag":26,"props":3794,"children":3795},{},[3796,3800],{"type":25,"tag":656,"props":3797,"children":3798},{},[3799],{"type":30,"value":949},{"type":30,"value":3801}," Either can be defensible, but the package must document which one was used. A self-run node gives the analyst direct control over the client version and query, while a commercial provider is faster but adds a third party whose response is itself part of the chain of custody. The reproducible standard is the same for both: record the endpoint, the client or provider, the version, the exact query, and the raw response with its hash, and verify a sample against an independent source.",{"type":25,"tag":247,"props":3803,"children":3805},{"id":3804},"q-what-does-reproducible-require-of-an-expert-report",[3806],{"type":30,"value":3807},"Q: What does \"reproducible\" require of an expert report?",{"type":25,"tag":26,"props":3809,"children":3810},{},[3811,3815],{"type":25,"tag":656,"props":3812,"children":3813},{},[3814],{"type":30,"value":949},{"type":30,"value":3816}," A reproducible report lets a second qualified analyst regenerate each exhibit from the recorded inputs: raw responses, hashes, query parameters, software versions, and transformation steps, with the appendix fields listed above. Reproducibility is a methodology requirement separate from admissibility. A report that describes conclusions without the underlying package cannot be independently tested and may invite a reliability challenge under Daubert; the admissibility decision remains for the court in the applicable forum.",{"type":25,"tag":247,"props":3818,"children":3820},{"id":3819},"q-how-do-hash-values-fit-into-the-collection-record",[3821],{"type":30,"value":3822},"Q: How do hash values fit into the collection record?",{"type":25,"tag":26,"props":3824,"children":3825},{},[3826,3830],{"type":25,"tag":656,"props":3827,"children":3828},{},[3829],{"type":30,"value":949},{"type":30,"value":3831}," Hashing each raw file at collection records a value for its contents at that moment. Hash a later exhibit or copy with the same algorithm and compare the result to the recorded value; a mismatch shows that the files differ, while a match makes it highly improbable that they differ. The 2017 Advisory Committee Note to FRE 902(14) describes this practice for copied electronic data. Record the algorithm, the value, and the time of hashing alongside the file.",{"type":25,"tag":26,"props":3833,"children":3834},{},[3835,3837,3841],{"type":30,"value":3836},"This article explains one part of a broader question, and the right answer always depends on the specific matter: the chain, the data type, and the forum's authentication requirements all affect what a court will require. If you are preparing or challenging blockchain evidence in a specific case, ",{"type":25,"tag":33,"props":3838,"children":3839},{"href":1031},[3840],{"type":30,"value":3242},{"type":30,"value":3842}," to discuss the collection and review process for your matter.",{"title":7,"searchDepth":1038,"depth":1038,"links":3844},[3845,3846,3854,3855,3856,3857,3858,3859,3860,3861],{"id":3326,"depth":1038,"text":3329},{"id":3365,"depth":1038,"text":3368,"children":3847},[3848,3849,3850,3851,3852,3853],{"id":3376,"depth":1044,"text":3379},{"id":3387,"depth":1044,"text":3390},{"id":3398,"depth":1044,"text":3401},{"id":3409,"depth":1044,"text":3412},{"id":3443,"depth":1044,"text":3446},{"id":3454,"depth":1044,"text":3457},{"id":3473,"depth":1038,"text":3476},{"id":3498,"depth":1038,"text":3501},{"id":3522,"depth":1038,"text":3525},{"id":3576,"depth":1038,"text":3579},{"id":3592,"depth":1038,"text":3595},{"id":3671,"depth":1038,"text":3674},{"id":3730,"depth":1038,"text":3733},{"id":932,"depth":1038,"text":935,"children":3862},[3863,3864,3865,3866,3867],{"id":3759,"depth":1044,"text":3762},{"id":3774,"depth":1044,"text":3777},{"id":3789,"depth":1044,"text":3792},{"id":3804,"depth":1044,"text":3807},{"id":3819,"depth":1044,"text":3822},"content:articles:37-reproducible-blockchain-evidence.md","articles\u002F37-reproducible-blockchain-evidence.md","articles\u002F37-reproducible-blockchain-evidence",1790145013677]