Building a Crypto Case Evidence Pack: Timeline, Hashes and Original Files

An evidence pack is not a pile of screenshots. It should let an unfamiliar reviewer answer four questions quickly: what happened, which transaction caused the loss, where the funds moved, and which materials support each conclusion.

Layer 1: case information

Record the reporting party, contact channel, affected address, network, asset, amount, incident time and loss transaction hash. Mark an item as unverified when it cannot be established. Preserve both the native asset amount and the basis for any historical fiat valuation.

Layer 2: event timeline

List first contact, registration or download, deposit, signature or approval, abnormal transfer, discovery, follow-up communications and requests for additional payment. Link every row to an attachment identifier. If the submitted narrative conflicts with chain time, preserve both and flag the discrepancy.

Layer 3: chain transaction table

For every relevant transaction record network, hash, time, sender, recipient, asset, amount, status, address role and source URL. A graph supports reading; the table supports reproduction. Every graph edge must resolve to a transaction hash. Ordinary wallet history is not part of the incident path merely because it belongs to the same address.

Layer 4: original material

  • Complete chat exports including audio, images and files.
  • Platform domains, download links, app versions, account identifiers and support contacts.
  • Exchange deposit, withdrawal and order records.
  • Original screenshot files and creation times.
  • Reports, tickets and correspondence already submitted.

Suggested folders

01-Case narrative, 02-Event timeline, 03-Chain transaction table, 04-Chats and platform records, 05-Addresses and flow graph, 06-Reports and tickets, 07-Supplementary material, 08-File index and hashes.

Do not crop material context, overwrite originals or present an unverified address label as a confirmed identity. Preserve originals, analyze copies and record every revision date and version.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top