Blockchain Forensic Investigation

I reconstruct what happened on-chain — with sealed, reproducible evidence.

I am OnChainSurfer — an independent blockchain forensic investigator. I trace exploits, drains, and laundering, and anchor every claim to a verifiable chain of custody. No trust required.

Read the research →Request a case
2
chains reconstructed
(BNB Smart Chain + Solana)
209
evidence items sealed
under chain of custody
100%
of cited on-chain data
reproducible on public explorers
0
real-world identities asserted —
so findings survive scrutiny

What I do

01

Incident reconstruction

I deconstruct how an incident was executed: smart-contract source and bytecode audited in a network-isolated sandbox, the mechanism identified, and the on-chain execution reconstructed transaction by transaction — each step observed and sealed.

02

Fund tracing & laundering trails

Following proceeds across chains, bridges, DEX swaps and mixers — with visual trace graphs and wallet clustering under documented heuristics. I map what is observable and mark the hard boundaries honestly, never past the evidence.

03

Attribution & evidence custody

Explorer-label attribution stated as observation, not proof. I build my own attribution database case by case from legally clear public sources — never rented from a vendor.

The standard

My forensic standard is not a style guide — it is an enforced pipeline. Every investigation passes these gates.

SEAL

Sealed before analyzed

Every artifact is SHA-256 fingerprinted and timestamped into a write-once custody ledger at capture — before any theory is formed. Change a single character and the fingerprint no longer matches: any alteration is mathematically detectable. Sealed records are append-only.

GATE

Enforced by code, not policy

An automated gate checks every finding: claims without complete sealed evidence are downgraded to hypotheses, and identity attribution below High confidence is blocked.

CONFIDENCE

Per-finding confidence levels

High confidence requires on-chain verification, at least two independent sealed sources, and third-party reproducibility. Every finding carries its level, visibly.

SOURCES

Zero inherited sources

Pre-existing public write-ups are treated as leads, never as sources. Every fact I assert is independently re-collected and re-sealed under my own chain of custody.

SCOPE

I state what I do not claim

Every report carries an explicit boundary section: floor counts versus totals, hard visibility limits, and exactly what the evidence does not support.

HUMAN

Human-verified, AI-accelerated

AI agents accelerate collection and analysis, but no finding is marked verified without my sign-off. AI suggests, evidence decides, I verify.

Latest research

All investigations →

This is the deliverable, in public — the same structure and standard a client receives.

DXSALE2026-07-12OCS-FIS-V1

Anatomy of the DxSale Locker Exploit: Ownership Capture, a Self-Call Drain, and a Two-Chain Laundering Trail

At least six lockers seized in nine minutes, 3,576 sealed LP transfers across 17 pools, and five lockers still under attacker control.

About

My practice is built on one principle: affirmative language only for sealed, observable evidence. Interpretations are labeled as hypotheses. Every transaction hash I cite is documented in full — never truncated — with checksummed addresses and UTC timestamps, so every claim is independently reproducible against the public chains.

I answer to the evidence, not to expectation — mine, or anyone else's. Published research is how I prove the standard; private cases run under the same gates, and stay private.