deed
Case Studies

The evidence speaks for itself

Each case below is anonymised. Clients, jurisdictions, and identifying details have been changed. The methodologies and outcomes are real.

01
OSINT · Law Firm
International Litigation
$14M in assets identified
outcome

Hidden Asset Recovery: Cross-Border Shell Structure

A law firm representing a defrauded investor needed to locate assets held by a respondent who had moved funds offshore through a series of shell entities. Conventional discovery had hit a wall.

The Challenge

The respondent had used nominee directors, bearer shares, and layered corporate structures across four jurisdictions to obscure beneficial ownership. Public records appeared to lead nowhere.

Our Approach

Deed conducted a full OSINT sweep of the respondent's known associates, business activities, and digital presence. Cross-referencing corporate registry data from six jurisdictions, domain registration records, and leaked corporate filings, we reconstructed a network of 14 entities — 9 of which were undisclosed.

Key Findings

Identified 9 previously unknown corporate entities linked to the respondent
Traced beneficial ownership through nominee structures to 3 real-estate holdings
Located two active bank accounts in jurisdictions amenable to freezing orders
Documented provenance of assets enabling $14M recovery
02
Blockchain · Crypto Fraud
Cryptocurrency / DeFi
$8.7M traced across 4 chains
outcome

Token Flow Reconstruction: DeFi Protocol Exploit

A digital asset fund lost $8.7M in a sophisticated exploit of a DeFi lending protocol. The attacker had taken steps to obscure the trail across multiple chains and mixer services.

The Challenge

The attacker used a flash loan exploit to drain funds, then immediately routed proceeds through three cross-chain bridges and a privacy protocol. On-chain data was voluminous and apparently disconnected.

Our Approach

Deed deployed AI-assisted wallet clustering to identify the attacker's address network before the exploit — detecting the reconnaissance phase 6 hours prior to execution. We then reconstructed the full fund movement timeline across Ethereum, Arbitrum, Polygon, and BSC.

Key Findings

Attributed 23 wallet addresses to a single cluster with 91% confidence
Reconstructed complete $8.7M fund flow timeline across 4 chains
Identified two deposit addresses at centralised exchanges (enabling legal process)
Detected a coordination pattern with a prior exploit at a related protocol
03
Data Analysis · Enterprise
Financial Services
Fraud ring of 4 identified
outcome

Insider Threat Detection: Anomalous Pattern Analysis

A financial services firm suspected internal fraud but had no specific suspect and could not justify the cost of a full forensic audit of 400 staff across three offices.

The Challenge

Transaction data was clean on individual review. Nothing flagged in standard compliance monitoring. The fraud was too distributed and too slow to trigger existing rules-based systems.

Our Approach

Deed ingested three years of transaction logs, access logs, and communication metadata (with appropriate legal authorisation). Using temporal pattern analysis and network graph modelling, we identified a cluster of anomalous behaviour that correlated strongly across four employees who had never appeared in the same report.

Key Findings

Identified coordinated anomalous activity across 4 employees in 3 offices
Reconstructed a 28-month transaction diversion scheme totalling €2.3M
Produced timeline and evidence package used in successful prosecution
Identified the specific data access patterns enabling early detection of recurrence

Have a similar situation?

Every investigation is different. Tell us what you're dealing with and we'll tell you what we can find.

Start an Investigation