Forensics

The Forensics tab runs a wallet's funding history against Wallet Sleuth's threat corpus and reports what it finds: counterparty safety flags, where its funds trace back to, and how close it sits to anything labelled.

What you'll see

The Forensics tab showing the Counterparty Safety and Fund Provenance cards

Counterparty Safety

A severity badge (Critical, High, Elevated, Unknown, or Clear) sums up what was found, followed by any individual flags, each with a detail line, a link to its evidence when there is one, and the path of addresses the taint travelled through to reach this wallet. A coverage line at the bottom lists which signals were actually available to check.

Fund Provenance

A bar breaks down where the wallet's funds trace back to: clean, insider-funded, unknown, or tainted, each as a share of the total. An Insider-funded badge appears when the wallet was seeded by an address already known to be an insider, and a line beneath the bar names when and from where the wallet was first funded, when that's known.

Going deeper

Trace deeper re-runs the safety and provenance checks over a wider funding history, spending from your trace allowance. A wallet with no graph data yet shows a note asking you to run a trace from the Token tab first.

For what counts as a label, how it can reach a wallet, and how taint proximity is scored, see Threat intelligence and taint.

Common questions

Forensics shows a lock instead of any results. Forensics is available on plans that include it; see pricing.

Coverage looks thin for this wallet. Blocklist coverage differs by chain; see the coverage caveats in Threat intelligence and taint.

Related