From Blockchain to Courtroom in 90 Seconds
Paste a wallet address. Get a complete investigation — transaction graph, entity attribution across 1.27M+ addresses, privacy chain intelligence (Monero, Zcash, Dash), 15 fraud patterns, and a court-ready report with auto-generated legal notices.
The Problem
Every crypto case hits the same walls.
The Trail Goes Cold at the Exchange
Global forensics tools trace funds to an exchange deposit address — and stop. They can't tell you who withdrew the money, which bank account received it, or which UPI ID cashed out.
Privacy Chains Break Everything
Suspects move funds through Monero, Zcash, or Dash to destroy traceability. Existing tools flag these transactions as "Opaque" and give up. No ring analysis, no correlation, no leads.
Weeks Per Case, Manual Everything
Every investigation means manually querying blockchain APIs, cross-referencing entity databases, building graphs, writing reports, and drafting legal notices — for every single suspect address.
Global Tools, Local Blind Spots
95% of Indian crypto fraud uses USDT on Tron. Existing tools are built for US/EU markets — they don't cover Indian P2P exchanges, Telegram OTC channels, or UPI payment rails.
The Solution
CryptoFlow runs the full investigation for you.
From a single wallet address to a complete forensic picture — automatically.
Paste Address
Instant multi-signal triage — chain, sanctions, risk tier, nearest exchange.
Build Graph
Visual fund-flow across 25 chains. Add multiple addresses, find hidden links.
Auto-Investigate
8 sequential steps, SSE-streamed live to canvas.
LE Report
Court-ready PDF with AI narrative, evidence chain & Section 91 notice.
End result: A complete forensic dossier — transaction graph, entity attribution, sanctions status, AI narrative, and signed LE Report — ready for submission.
Auto-Investigate
Eight steps. One click. Full picture.
CryptoFlow's investigation engine runs sequentially — each step builds on the last — to surface every relevant signal about a suspect address.
Exchange Detection
Checks 1.27M entity DB and 4 external APIs to identify if the address belongs to a known exchange or custodian.
Velocity Profile
Analyses transaction volume, frequency, fund-through rate, and temporal patterns to detect anomalous activity.
Counterparty Analysis
Identifies top counterparties, classifies by entity type, and flags high-risk or sanctioned connections.
Adaptive Transactions
Fetches additional transaction rounds beyond the default, adapting depth based on address activity level.
Multi-Hop Exposure
Expands the graph 2-3 hops deep, computing exposure percentages to risky entity categories across the network.
Backward Trace
BFS traversal upstream — traces where funds originally came from to surface source wallets and entry points.
Forward Trace
BFS traversal downstream — follows where funds went, identifying cash-out points and final destinations.
AI Signal Assessment
Aggregates all 7 prior results and generates an AI investigation narrative with triggered signals and risk verdict.
Platform Capabilities
Four pillars. One complete investigation.
1.27 million entities. Instant attribution.
Entity Database
1.27M+ attributed addresses from 15 verified sources — exchanges, mixers, ransomware, OFAC sanctions, Tether blacklist, GraphSense, OKX Proof of Reserves.
Multi-Jurisdiction Sanctions
953 OFAC SDN + 717 OpenSanctions (EU, UK, UN, Israel) + Tether blacklist screened in real-time. Provider gateway swaps in commercial feeds (Chainalysis, TRM) when available — no UI change for officers.
Instant Triage
Paste any address. Get chain detection, sanctions hits, entity attribution, risk score, exposure breakdown, and nearest exchange path in seconds.
Forensic Device Extraction
Drop a Cellebrite UFDR or EnCase E01 folder. 8 examination methods unwrap Android Backups, strip Cellebrite HTML reports, decode Samsung Kies UTF-16 binary backups (SMS/MMS/contacts), run Tesseract OCR over device photos, and parse WhatsApp/Telegram databases. Cryptographic checksum chain drops 99% of binary noise — validated on a real Cellebrite Galaxy S5 sample (4,452 → 40 candidates). Now live in the case-evidence upload flow.
P2P × Telegram Identity
Scrapes 5 major P2P exchanges (Binance, WazirX, CoinDCX, OKX, Bybit) and 33+ Telegram OTC channels. Cross-source identity tab surfaces P2P traders matched to Telegram senders by phone, UPI, or wallet — one click on either record shows the other side.
25 chains. 6-hop depth. Follow every path.
25 Blockchains
BTC (legacy + Bech32 SegWit + Bech32m Taproot), the full EVM family (ETH, BSC, MATIC, ARB, BASE, OP, AVAX, FTM, LINEA, SCROLL, ZKSYNC, BLAST), TRX, SOL, XRP, TON, ADA, Cosmos, XLM, LTC, DOGE, BCH, DASH, FIRO, plus 3 privacy chains (XMR, ZEC, DASH). Auto-detected from address format with cryptographic checksum verification.
Interactive Graph
Cytoscape.js canvas with expand, filter, follow-the-money, undo/redo, timeline playback, and multi-address link discovery.
Multi-Hop Trace
4-6 hop backward and forward tracing with BFS. Early termination at exchanges. Hop-by-hop entity classification.
Follow the Money
One-click path discovery from suspect to exchange. Highlights the gold path on canvas with value flow, timestamps, and entity stops along the way.
Where global tools go blind, we generate leads.
Monero Ring Elimination
Import exchange CSVs, cross-reference against 16-member decoy rings. Reduce candidates from 16 to as few as 1. STRONG/GOOD/MODERATE/WEAK confidence scoring.
Privacy Deep Check
4 parallel correlation engines — canvas timing, exchange timestamps, THORChain swap detection, P2P/no-KYC exchange matching. Generates ranked subpoena leads.
Z-to-T Unshielding
Automatically detects when Zcash funds exit the shielded pool. Reveals the transparent address and amount for continued tracing.
Subpoena Engine
13 pre-configured targets (exchanges + swap services) with status tracking. Next-Best-Action recommends which to subpoena based on evidence gaps.
15 fraud patterns. Court-ready reports. Legal notices.
15 Fraud Patterns
Auto-detected with confidence scoring: peel chain, pig butchering, mixer hop, fan-in mule rings, shadow banking, rug pull, dust attack, dormant activation, and 7 more.
LE Investigation Report
Court-ready PDF with AI narrative, signal assessment, transaction timeline, entity attribution, and evidence appendices.
Section 91/94 CrPC
Auto-generated legal notices pre-filled with exchange nodal officer details, FIR context, and relevant transaction evidence.
Animated Playback
Show judges the money moving visually from victim to suspect. Timeline-based graph animation for courtroom presentation.
Built for India
Capabilities no global tool can match.
Global tools are built for US/EU markets. They can't connect crypto to Indian payment rails, don't monitor Indian P2P exchanges, and can't generate CrPC notices.
Crypto-to-UPI Bridge
Traces funds from blockchain all the way to Indian bank accounts and UPI IDs. When you find a suspect's wallet, we tell you which UPI received the INR.
P2P Exchange Intelligence
Aggregates P2P advertisements from Binance, WazirX, CoinDCX, OKX, and Bybit. Profiles high-volume traders, detects mule patterns, and links wallets to real identities.
Telegram OSINT
33+ monitored channels — Indian crypto P2P, Hawala networks, privacy coin trading, and swap service communities. Deep backfill extracts wallet addresses, phone numbers, and trader identities.
Section 91/94 CrPC Automation
Auto-generates court notices pre-filled with exchange nodal officer details for WazirX, CoinDCX, Zebpay, and 50+ more. From investigation to legal submission in one click.
Shadow Bank Detection
Proprietary algorithm detects Hawala/OTC aggregation patterns in USDT-TRC20 flows — the dominant laundering method in Indian crypto fraud.
Tron-First Architecture
95% of Indian crypto fraud uses USDT on Tron. Our platform is optimized for TRC20 from the ground up — not an afterthought bolted onto an ETH-centric tool.
How It Works
From one address to full intelligence.
Paste Any Address
Enter a wallet address — TRON, ETH, BTC, BSC, Polygon, or Solana. System auto-detects the chain and runs a 7-signal risk triage in seconds.
Build the Transaction Graph
Expand the network visually. Cytoscape graph shows fund flow across hops. Filter by risk tier, entity type, or transaction value to find what matters.
Auto-Investigate in One Click
8-step pipeline runs automatically: exchange detection, velocity profiling, adaptive fetch, multi-hop exposure, privacy chain ring-elimination, and AI assessment. Watch results stream in live.
Export the LE Report
Generates a court-ready PDF with investigation narrative, transaction timeline, sanctions screening, signal scores, and all source data. Submission-ready in minutes.
Paste Any Address
Enter a wallet address — TRON, ETH, BTC, BSC, Polygon, or Solana. System auto-detects the chain and runs a 7-signal risk triage in seconds.
Build the Transaction Graph
Expand the network visually. Cytoscape graph shows fund flow across hops. Filter by risk tier, entity type, or transaction value to find what matters.
Auto-Investigate in One Click
8-step pipeline runs automatically: exchange detection, velocity profiling, adaptive fetch, multi-hop exposure, privacy chain ring-elimination, and AI assessment. Watch results stream in live.
Export the LE Report
Generates a court-ready PDF with investigation narrative, transaction timeline, sanctions screening, signal scores, and all source data. Submission-ready in minutes.
Why CryptoFlow
Built for India. Not adapted.
Trust & Security
Government-grade security. Your data, your control.
On-Premise Deployment
Deploy in your government data center or private cloud. Docker-based, no external dependencies. Your investigation data never leaves your infrastructure.
Zero-Installation Access
Fully browser-based — works on any authorized workstation. JWT authentication with role-based access control (Admin, Officer, Analyst). Session expiry and login rate limiting.
Evidence Chain of Custody
Every search, investigation, and action logged with user ID, timestamp, and IP. Full audit trail meets IT Act and MHA compliance requirements.
Indigenous IP
Built by Indian engineers. No vendor lock-in, no US cloud dependency. Source code auditable. Zero dependency on foreign-controlled attribution databases.
Activity Audit Logging
Every API call logged automatically — who investigated which address, when, from where. Fire-and-forget middleware with zero performance impact.
Data Sovereignty
PostgreSQL + NetworkX for core analysis — no external graph DB dependency. All entity data, investigation state, and evidence stored in your PostgreSQL instance.
Built For
For those who close cases.
Cyber Cells
State and central cyber crime investigation units. Paste suspect addresses and run an 8-step automated investigation — trace fund flow, identify mule networks, find cash-out points, and discover links between suspects in minutes.
Prosecutors
Build stronger cases with an AI-generated investigation narrative and visual fund-flow evidence judges understand. No crypto expertise required to present or review the findings.
Forensic Labs
Direct ingest of Cellebrite UFDR and EnCase E01 extractions — 8 examination methods including Android Backup unwrap, Samsung Kies UTF-16 decoding, SQLite-aware reading, Tesseract OCR, and WhatsApp/Telegram-specific decoders. Cryptographic checksum chain (Base58Check, Bech32m, ed25519 curve verification) cuts false positives by 99% on real device extractions. Per-method audit trail in every manifest.
Ready to close more cases?
See the full 7-step investigation run on a real suspect address. Free pilot program for qualified government agencies.