The evidence speaks for itself
Each case below is anonymised. Clients, jurisdictions, and identifying details have been changed. The methodologies and outcomes are real.
Hidden Asset Recovery: Cross-Border Shell Structure
A law firm representing a defrauded investor needed to locate assets held by a respondent who had moved funds offshore through a series of shell entities. Conventional discovery had hit a wall.
The Challenge
The respondent had used nominee directors, bearer shares, and layered corporate structures across four jurisdictions to obscure beneficial ownership. Public records appeared to lead nowhere.
Our Approach
Deed conducted a full OSINT sweep of the respondent's known associates, business activities, and digital presence. Cross-referencing corporate registry data from six jurisdictions, domain registration records, and leaked corporate filings, we reconstructed a network of 14 entities — 9 of which were undisclosed.
Key Findings
Token Flow Reconstruction: DeFi Protocol Exploit
A digital asset fund lost $8.7M in a sophisticated exploit of a DeFi lending protocol. The attacker had taken steps to obscure the trail across multiple chains and mixer services.
The Challenge
The attacker used a flash loan exploit to drain funds, then immediately routed proceeds through three cross-chain bridges and a privacy protocol. On-chain data was voluminous and apparently disconnected.
Our Approach
Deed deployed AI-assisted wallet clustering to identify the attacker's address network before the exploit — detecting the reconnaissance phase 6 hours prior to execution. We then reconstructed the full fund movement timeline across Ethereum, Arbitrum, Polygon, and BSC.
Key Findings
Insider Threat Detection: Anomalous Pattern Analysis
A financial services firm suspected internal fraud but had no specific suspect and could not justify the cost of a full forensic audit of 400 staff across three offices.
The Challenge
Transaction data was clean on individual review. Nothing flagged in standard compliance monitoring. The fraud was too distributed and too slow to trigger existing rules-based systems.
Our Approach
Deed ingested three years of transaction logs, access logs, and communication metadata (with appropriate legal authorisation). Using temporal pattern analysis and network graph modelling, we identified a cluster of anomalous behaviour that correlated strongly across four employees who had never appeared in the same report.
Key Findings
Have a similar situation?
Every investigation is different. Tell us what you're dealing with and we'll tell you what we can find.
Start an Investigation