Forensics
The Forensics tab runs a wallet's funding history against Wallet Sleuth's threat corpus and reports what it finds: counterparty safety flags, where its funds trace back to, and how close it sits to anything labelled.
What you'll see


Counterparty Safety
A severity badge (Critical, High, Elevated, Unknown, or Clear) sums up what was found, followed by any individual flags, each with a detail line, a link to its evidence when there is one, and the path of addresses the taint travelled through to reach this wallet. A coverage line at the bottom lists which signals were actually available to check.
Fund Provenance
A bar breaks down where the wallet's funds trace back to: clean, insider-funded, unknown, or tainted, each as a share of the total. An Insider-funded badge appears when the wallet was seeded by an address already known to be an insider, and a line beneath the bar names when and from where the wallet was first funded, when that's known.
Going deeper
Trace deeper re-runs the safety and provenance checks over a wider funding history, spending from your trace allowance. A wallet with no graph data yet shows a note asking you to run a trace from the Token tab first.
For what counts as a label, how it can reach a wallet, and how taint proximity is scored, see Threat intelligence and taint.
Common questions
Forensics shows a lock instead of any results. Forensics is available on plans that include it; see pricing.
Coverage looks thin for this wallet. Blocklist coverage differs by chain; see the coverage caveats in Threat intelligence and taint.