Blockchain forensics · Financial-crime intelligence
Follow the money.
Even when states hide it.
State-linked illicit crypto flows, tracked from raw chain data to court-ready SARs and disruption reports.
Coverage
Three state programs. One watchlist.
North Korean laundering networks
Peeling chains, mixer egress and off-ramp corridors mapped end-to-end across Ethereum and TRON.
Iranian shadow banking
Schema-as-data ontology covering red flags RF-01–RF-14 and IRGC-linked settlement programs.
A7A5 ruble-stablecoin network
Daily token-transfer pulls joined to live Telegram bearer-redemption chatter with attribution scoring.
The Platform
Five layers. One chain of custody.
Every fact carries its origin, its confidence and its reviewer. Nothing enters the record without provenance.
Data ingestion
Every source, one stream.
Daily A7A5 token-transfer pulls from Ethereum (Etherscan) and TRON (TronGrid). Live Telegram monitoring of Satoshkin and Grinex chats for bearer-redemption chatter. OFAC SDN and Consolidated lists with wallet-address joins. ICIJ offshore-leaks datasets.
- ETH Token transfers via Etherscan, refreshed daily
- TRX TRON transfers via TronGrid, refreshed daily
- TG Live redemption-chatter monitoring
- REF OFAC sanctions + ICIJ leaks fused at ingest
Entity resolution & provenance
Every claim carries its confidence.
Fuzzy-matching fusion — Jaro-Winkler plus token-set — joins sanctions, leaks and on-chain data. Telegram redemption events are temporally joined to TRON transfers with attribution scores. An append-only audit trail and analyst sign-off ledger govern every promotion.
- PRV Provenance label on every entity and edge
- LOG Append-only audit trail — replayable
- SGN Analyst sign-off ledger for promotion
Graph & ontology
A network that scores itself.
Scored network ontology: forensic scores, peeling-chain detection, holder tiers, velocity timelines. A schema-as-data ontology models Iranian shadow banking — RF-01 through RF-14 and IRGC programs — as first-class objects.
- SCR Forensic scoring and peeling-chain detection
- TIER Holder tiers and velocity timelines
- RF RF-01–RF-14 red-flag schema, IRGC programs
Detection & disruption
Seven pipelines. One SAR.
Seven always-on detection pipelines auto-populate SAR red flags as they fire. Disruption tooling adds betweenness and articulation-point targeting, fragmentation curves, COA wargaming and a Q-learning red/blue simulator.
- DET Detections write SAR red-flag fields directly
- CUT Articulation-point targeting, fragmentation curves
- SIM COA wargaming, Q-learning red/blue simulator
Intelligence products
From graph to court-ready document.
D3 ontology explorer, case registry, threat map, SIGINT feed and report viewer. KAI answers questions over platform data. Findings anchor to Hyperledger Fabric and Optimism for tamper-evident custody.
- SAR SARs and disruption reports from live findings
- APP Explorer, registry, threat map, SIGINT feed
- ANC Evidence anchoring — Fabric / Optimism
Capabilities
Seven detection pipelines, always on.
Each pipeline scans continuously and writes its findings straight into SAR red-flag fields.
Rahbar Loop
Detects the circular settlement patterns characteristic of Iranian shadow-banking clearance. Loop participants are flagged and RF-coded red flags feed SAR drafts automatically.
Stablecoin Anomalies
Watches A7A5 mint, burn and transfer telemetry for off-pattern volume and bearer-redemption bursts. Anomalies are temporally joined to Telegram redemption chatter.
Dark-Fleet Shipping
Correlates sanctioned-fleet vessel behavior with on-chain settlement activity. Port calls and AIS gaps line up against wallet flows to expose maritime sanctions evasion.
OFAC N-Hop Proximity
Scores every wallet by graph distance to sanctioned entities. Short-hop proximity to SDN-listed addresses raises exposure ratings across the whole cluster.
Offshore UBO Layering
Traverses ICIJ offshore-leaks structures to expose the beneficial owners behind shell counterparties. Layered ownership chains collapse into a single accountable entity.
Shared Intermediaries
Surfaces wallets, brokers and OTC desks serving multiple flagged networks at once. One shared intermediary often unlocks several cases simultaneously.
Crypto Off-Ramps
Identifies the exchange and OTC egress points where illicit value tries to reach fiat. Off-ramp fingerprints are the choke points disruption planning starts from.
Disruption tooling
Find the node that breaks the network.
Betweenness and articulation-point analysis ranks the wallets whose removal fragments a laundering network fastest. Fragmentation curves quantify each option; COA wargaming and a Q-learning red/blue simulator pressure-test the plan before anyone acts.
KAI console
Ask the platform a question.
KAI is an LLM console over live platform data. Every answer cites the entities, transfers and provenance labels behind it.
Partner feed
A read-only incident feed for partners.
205 curated incident records — vectors, regions, loss figures and Fionn references — served as a versioned snapshot API.
GET /v1/incidents/nk-2026-0117
{
"id": "nk-2026-0117",
"name": "Bridge validator-key compromise",
"region": "North Korea",
"vector": "Private key compromise",
"amount_usd": 102000000,
"fionn_ref": "CHA-NK-0117",
"summary": "Validator keys exfiltrated via
spear-phish; funds peeled across 14 hops
into TRON OTC egress."
}
Request feed access
Intelligence products
See it in action.
Ingestion to disruption in one continuous cut.
"Intelligence you can't defend in court is just rumor. Every finding here is anchored, audited and signed."
Anchored evidence
Findings anchor to Hyperledger Fabric and Optimism — a cryptographic timestamp proving what was known, and when.
Append-only audit trail
Nothing is edited in place. Every join, score change and promotion appends to an immutable trail an auditor can replay.
Analyst sign-off
Machine findings become intelligence only when a named analyst signs them into the ledger. Confidence is earned, not assumed.