How to conduct an internal investigation and identify the cryptocurrency thief inside the company

How to conduct an internal investigation and identify the cryptocurrency thief inside the company

Even a coincidence between the time of a transaction and an employee's activity does not yet mean that it was that person who committed the theft: their device or session could have been compromised.

Aug 14, 2026

When funds disappear from a corporate cryptocurrency wallet that several people have access to, suspicion almost automatically falls on the employee who had the keys. This is indeed a logical starting point for an investigation, yet the mere existence of access does not prove anything in itself.

A developer's account could have been hacked. A seed phrase could have fallen into the wrong hands through a work computer. A former contractor could have lost access to the company long ago, but their credentials could later have been used by an external attacker. At the same time, an incident that at first glance looks like an ordinary external attack may well turn out to be a carefully prepared theft by someone who had internal access.

Therefore, the task of a corporate investigation is not to pick the most suspicious employee as quickly as possible. It is necessary to establish a specific person by linking them simultaneously to the opportunity to commit the theft, to specific actions and to the digital trace those actions left behind.

Where the investigation of an insider theft begins

Therefore, blockchain data must be matched against corporate event logs: information about devices, IP addresses, VPN sessions, email and transaction-approval processes. No less important may be the person's behavior immediately before and after the theft. Sometimes it is precisely changes in habitual activity that make it possible to detect the preparation of a crime or an attempt to hide its traces.

Interviews with employees and a polygraph can complement the investigation, but they should not replace technical and blockchain evidence. The final conclusion must be based on evidence and clearly separate established facts from circumstantial signs and working hypotheses.

First, you need to identify everyone who could actually have obtained access

The investigation should begin not with a list of suspects but with a reconstruction of the real circle of people who technically could have influenced the cryptocurrency assets.

It is necessary to establish who knew the seed phrase or held the private key, who was part of the multisig scheme, who could carry out operations on the exchange, change the lists of allowed addresses or the withdrawal limits. This same circle includes people with access to corporate email, password managers, cloud storage and servers. Separately, it should be determined from which devices transactions were actually signed.

It is especially important not to limit yourself to employees' job titles. In a small company, cryptocurrency assets are often managed much more simply: a few laptops, a hardware wallet and a person who «usually handles the crypto». In such a situation, the formal job title says almost nothing about the real level of authority. It is precisely the actual access and real capabilities of a person that should define the initial boundaries of the investigation.

One TXID is not enough: you need to reconstruct the entire history of the transaction

The identifier of the stolen transaction makes it possible to see what happened to the assets, but does not explain how the operation arose inside the company itself.

Therefore, the investigation must reconstruct the entire life cycle of the transaction. It is necessary to establish who created the recipient address and where this address first appeared in the corporate infrastructure. If there was an internal transfer request before the withdrawal, it is necessary to determine who created it and who approved it. Then it is necessary to establish which key signed the transaction, from which device this happened and under which account.

Thus, the blockchain shows what happened to the assets, while corporate systems make it possible to establish how exactly the operation was initiated inside the organization.

The blockchain must be matched against corporate logs

The next stage is to overlay the time of the stolen transaction onto the company's overall digital timeline. The timestamp of the operation in itself means little until it has been matched with what was happening in the corporate infrastructure at the same moment.

It is necessary to check logins to corporate systems, IP addresses, VPN sessions, email and messengers, access to key-storage systems and actions in transaction-approval systems. It is precisely this kind of matching that makes it possible to link a blockchain event to specific digital activity inside the company.

For example, a transaction could have been signed at 03:17, and at exactly the same time an employee's corporate account could have logged in through their usual VPN from their work computer. This is a serious coincidence. But if it turns out that an hour earlier malware had been installed on the computer, or that the user's session had been hijacked, the interpretation of the event changes completely.

Therefore, the investigation must constantly test two alternative versions: the employee used their own authority, or someone else used their access.

Preparation for a theft can begin long before the withdrawal of funds

An insider attack rarely begins at the very moment of a large cryptocurrency withdrawal. Preparatory actions can take place long before the incident itself.

Therefore, it is important for an organization to understand the normal behavior model of employees and to track significant deviations from it. Before a theft, such deviations may be requests to expand access, attempts to obtain a key export, bypassing standard approval procedures, disabling logging, carrying out test transactions or preparing new addresses.

During the theft itself, attention may be drawn by an active session of a specific user, a device or VPN habitual for them, the use of a restricted key, or the execution of an operation in accordance with internal procedures that are usually applied only by a certain employee.

After the theft, different signs become significant: the deletion of files and correspondence, contradictory explanations of what happened, unusual interest in the investigation materials or attempts to alter event logs.

At the same time, none of these signs is evidence in itself. Their significance appears only when they coincide with other independent data.

The movement of the stolen funds can reveal the attacker's habits

After the cryptocurrency leaves the corporate wallet, its further movement can provide additional information about the person behind the operation.

For example, the stolen assets may pass through services that a specific employee has used before. The transaction fee may be paid from an address that has already appeared in corporate operations. Part of the funds may end up in an old personal wallet or on an exchange deposit address linked to a certain person. Finally, the attacker may repeat routes and transaction patterns familiar to them.

However, a single coincidence proves almost nothing. Far stronger is the combination of several independent signs — for example, a match of a known service, the source of gas, the time of the operation and the company's internal activity.

At the same time, clustering addresses is an analytical conclusion, not an automatic establishment of the owner's identity. In other words, the link between addresses must be proven by a body of data, not taken as an established fact.

Employees' known wallets can become part of the investigation

A company may already have addresses that a specific employee or contractor legitimately used in the past. These may be wallets for corporate payments, expense reimbursement or previous operations.

Such addresses can be matched against the route of the stolen funds, exchange credentials, corporate correspondence and other lawfully obtained information. Infrastructure matches become especially valuable: the same fee source, the use of the same intermediary services or the pooling of funds.

But even here the same principle applies: a single match does not automatically turn into an accusation. It acquires evidentiary value only in combination with other established facts.

Motive must not be placed above technical evidence

A conflict with management, a dismissal, financial problems or other personal circumstances may look convincing in a detective novel. In a corporate investigation, however, they are much weaker than a specific TXID, an authorization event or a preserved system log.

Talking to the suspect makes sense after the initial data analysis

Interviews with employees become significantly more effective after the technical investigation has already revealed a specific timeline and certain inconsistencies.

Instead of the general question «Did you steal the cryptocurrency?», it is much more useful to clarify the circumstances of specific events. For example, why the account was active at a certain time, for what reason a limit was changed, who owns a specific address or why a device connected to a certain service.

This approach makes it possible to ask questions whose answers can be matched against already existing digital data.

A premature accusation, on the contrary, creates additional risks. The person will understand exactly which version is being investigated and may gain time to destroy evidence or align their version of events with other participants.

A polygraph can complement the investigation but not replace it

If suspicion regarding an insider has already been formed on the basis of specific technical data, a polygraph can be used as an additional tool. It looks most appropriate in a situation where there is a specific incident, the circle of potentially involved persons is relatively limited, and the main facts can be verified independently of the test results.

Therefore, the conclusion «the polygraph showed deception — therefore the employee stole the money» is wrong. The correct approach assumes that the technical investigation first reveals specific inconsistencies, after which precise questions are formulated on their basis. The polygraph results are then assessed together with blockchain data, corporate logs and interview results.

The quality of the questions themselves is of particular importance. The question «Have you ever stolen cryptocurrency?» is practically useless for investigating a specific incident. It is far more informative to check specific circumstances: the time of operations, particular addresses, details of transaction approval and the source of the key.

Such questions should be formulated by a specialist who has already carried out the blockchain analysis and gathered the factual information on the case.

At the same time, before conducting a polygraph, it is necessary to separately assess the requirements of labor law, the rules for processing personal data and the admissibility of using a polygraph in a specific jurisdiction. The result of such testing must not become the sole basis for an accusation, the dismissal of an employee or the referral of the case to law enforcement.

The suspect's access must be restricted, but evidence must not be destroyed

If the collected data indicates a serious risk, the compromised access must be restricted. However, the same principle applies here as in the investigation of an external cyberattack: the assets must be protected without destroying digital evidence.

A company can revoke a user's privileges, terminate active sessions, replace corporate keys and move the remaining funds out of the risk zone. But before evidence is preserved, one should not chaotically wipe a work laptop, delete logs and accounts or reset devices to factory settings.

Particular caution is required when handling an employee's personal devices and accounts. The possibility of examining them depends on the law, corporate policies and contract terms. Therefore, in such situations the technical team must work together with lawyers.

Facts, signs and hypotheses must be separated

One of the most important principles of an investigation is a clear distinction between what has been established, what merely points to a possible connection, and what still remains a hypothesis.

If it turns out that the destination address previously interacted with a service that this employee used, this is already an indicator, but not an established fact of their involvement. And the assumption that the employee controls this address and personally committed the theft is a hypothesis.

If these three levels are mixed, the final report may start to look far more convincing than the real data allows. A strong investigation must show not only the final conclusion but also the grounds for each key statement, as well as the degree of confidence in the established connection.

What the result of the investigation should be

The result of the investigation should not be a table with employees' names and notional percentages of suspicion.

The company should receive a connected evidentiary picture that shows who had access to the assets, how the stolen transaction arose, which devices and accounts were involved in the operation and where the funds moved afterward.

In addition, the investigation must establish possible links between blockchain addresses and specific individuals, and honestly indicate which alternative explanations of what happened still remain possible.

The results of interviews and, if one was used, of a polygraph can be added to this picture. However, verifiable digital and blockchain data must remain the basis of the final assessment.

The main takeaway

It is precisely the combination of these elements that makes it possible to move from mere suspicion to a well-founded conclusion about who could have been behind the theft of corporate cryptocurrency.

#Cryptofraud
How to identify an insider at a crypto company: from TXID to the suspect's computer