CryptoFlow
CryptoFlow
byOutris
🔒Crypto Forensics for Law Enforcement

From Blockchain to Courtroom in 90 Seconds

Paste a wallet address. Get a complete investigation — transaction graph, entity attribution across 1.27M+ addresses, privacy chain intelligence (Monero, Zcash, Dash), 15 fraud patterns, and a court-ready report with auto-generated legal notices.

Transaction Flow

The Problem

Every crypto case hits the same walls.

🚫

The Trail Goes Cold at the Exchange

Global forensics tools trace funds to an exchange deposit address — and stop. They can't tell you who withdrew the money, which bank account received it, or which UPI ID cashed out.

👻

Privacy Chains Break Everything

Suspects move funds through Monero, Zcash, or Dash to destroy traceability. Existing tools flag these transactions as "Opaque" and give up. No ring analysis, no correlation, no leads.

⏱️

Weeks Per Case, Manual Everything

Every investigation means manually querying blockchain APIs, cross-referencing entity databases, building graphs, writing reports, and drafting legal notices — for every single suspect address.

🌍

Global Tools, Local Blind Spots

95% of Indian crypto fraud uses USDT on Tron. Existing tools are built for US/EU markets — they don't cover Indian P2P exchanges, Telegram OTC channels, or UPI payment rails.

The Solution

CryptoFlow runs the full investigation for you.

From a single wallet address to a complete forensic picture — automatically.

1

Paste Address

Instant multi-signal triage — chain, sanctions, risk tier, nearest exchange.

2

Build Graph

Visual fund-flow across 25 chains. Add multiple addresses, find hidden links.

3

Auto-Investigate

8 sequential steps, SSE-streamed live to canvas.

4

LE Report

Court-ready PDF with AI narrative, evidence chain & Section 91 notice.

End result: A complete forensic dossier — transaction graph, entity attribution, sanctions status, AI narrative, and signed LE Report — ready for submission.

Minutes, not weeks

Auto-Investigate

Eight steps. One click. Full picture.

CryptoFlow's investigation engine runs sequentially — each step builds on the last — to surface every relevant signal about a suspect address.

1
Instant

Exchange Detection

Checks 1.27M entity DB and 4 external APIs to identify if the address belongs to a known exchange or custodian.

2
~5s

Velocity Profile

Analyses transaction volume, frequency, fund-through rate, and temporal patterns to detect anomalous activity.

3
~10s

Counterparty Analysis

Identifies top counterparties, classifies by entity type, and flags high-risk or sanctioned connections.

4
~15s

Adaptive Transactions

Fetches additional transaction rounds beyond the default, adapting depth based on address activity level.

5
~30s

Multi-Hop Exposure

Expands the graph 2-3 hops deep, computing exposure percentages to risky entity categories across the network.

6
~60s

Backward Trace

BFS traversal upstream — traces where funds originally came from to surface source wallets and entry points.

7
~60s

Forward Trace

BFS traversal downstream — follows where funds went, identifying cash-out points and final destinations.

8
~20s

AI Signal Assessment

Aggregates all 7 prior results and generates an AI investigation narrative with triggered signals and risk verdict.

Steps run sequentially — each builds on prior results
Results stream live to canvas via SSE — no waiting
Step 8 runs last — AI has all evidence to assess
0+
Attributed Entities
0
Fraud Patterns
0
Blockchain Chains
0
Seconds to Investigate

Platform Capabilities

Four pillars. One complete investigation.

Identify

1.27 million entities. Instant attribution.

Entity Database

1.27M+ attributed addresses from 15 verified sources — exchanges, mixers, ransomware, OFAC sanctions, Tether blacklist, GraphSense, OKX Proof of Reserves.

Multi-Jurisdiction Sanctions

953 OFAC SDN + 717 OpenSanctions (EU, UK, UN, Israel) + Tether blacklist screened in real-time. Provider gateway swaps in commercial feeds (Chainalysis, TRM) when available — no UI change for officers.

Instant Triage

Paste any address. Get chain detection, sanctions hits, entity attribution, risk score, exposure breakdown, and nearest exchange path in seconds.

Forensic Device Extraction

Drop a Cellebrite UFDR or EnCase E01 folder. 8 examination methods unwrap Android Backups, strip Cellebrite HTML reports, decode Samsung Kies UTF-16 binary backups (SMS/MMS/contacts), run Tesseract OCR over device photos, and parse WhatsApp/Telegram databases. Cryptographic checksum chain drops 99% of binary noise — validated on a real Cellebrite Galaxy S5 sample (4,452 → 40 candidates). Now live in the case-evidence upload flow.

P2P × Telegram Identity

Scrapes 5 major P2P exchanges (Binance, WazirX, CoinDCX, OKX, Bybit) and 33+ Telegram OTC channels. Cross-source identity tab surfaces P2P traders matched to Telegram senders by phone, UPI, or wallet — one click on either record shows the other side.

Trace

25 chains. 6-hop depth. Follow every path.

25 Blockchains

BTC (legacy + Bech32 SegWit + Bech32m Taproot), the full EVM family (ETH, BSC, MATIC, ARB, BASE, OP, AVAX, FTM, LINEA, SCROLL, ZKSYNC, BLAST), TRX, SOL, XRP, TON, ADA, Cosmos, XLM, LTC, DOGE, BCH, DASH, FIRO, plus 3 privacy chains (XMR, ZEC, DASH). Auto-detected from address format with cryptographic checksum verification.

Interactive Graph

Cytoscape.js canvas with expand, filter, follow-the-money, undo/redo, timeline playback, and multi-address link discovery.

Multi-Hop Trace

4-6 hop backward and forward tracing with BFS. Early termination at exchanges. Hop-by-hop entity classification.

Follow the Money

One-click path discovery from suspect to exchange. Highlights the gold path on canvas with value flow, timestamps, and entity stops along the way.

Crack Privacy Chains

Where global tools go blind, we generate leads.

Monero Ring Elimination

Import exchange CSVs, cross-reference against 16-member decoy rings. Reduce candidates from 16 to as few as 1. STRONG/GOOD/MODERATE/WEAK confidence scoring.

Privacy Deep Check

4 parallel correlation engines — canvas timing, exchange timestamps, THORChain swap detection, P2P/no-KYC exchange matching. Generates ranked subpoena leads.

Z-to-T Unshielding

Automatically detects when Zcash funds exit the shielded pool. Reveals the transparent address and amount for continued tracing.

Subpoena Engine

13 pre-configured targets (exchanges + swap services) with status tracking. Next-Best-Action recommends which to subpoena based on evidence gaps.

Prove It in Court

15 fraud patterns. Court-ready reports. Legal notices.

15 Fraud Patterns

Auto-detected with confidence scoring: peel chain, pig butchering, mixer hop, fan-in mule rings, shadow banking, rug pull, dust attack, dormant activation, and 7 more.

LE Investigation Report

Court-ready PDF with AI narrative, signal assessment, transaction timeline, entity attribution, and evidence appendices.

Section 91/94 CrPC

Auto-generated legal notices pre-filled with exchange nodal officer details, FIR context, and relevant transaction evidence.

Animated Playback

Show judges the money moving visually from victim to suspect. Timeline-based graph animation for courtroom presentation.

Built for India

Capabilities no global tool can match.

Global tools are built for US/EU markets. They can't connect crypto to Indian payment rails, don't monitor Indian P2P exchanges, and can't generate CrPC notices.

Crypto-to-UPI Bridge

Traces funds from blockchain all the way to Indian bank accounts and UPI IDs. When you find a suspect's wallet, we tell you which UPI received the INR.

P2P Exchange Intelligence

Aggregates P2P advertisements from Binance, WazirX, CoinDCX, OKX, and Bybit. Profiles high-volume traders, detects mule patterns, and links wallets to real identities.

Telegram OSINT

33+ monitored channels — Indian crypto P2P, Hawala networks, privacy coin trading, and swap service communities. Deep backfill extracts wallet addresses, phone numbers, and trader identities.

Section 91/94 CrPC Automation

Auto-generates court notices pre-filled with exchange nodal officer details for WazirX, CoinDCX, Zebpay, and 50+ more. From investigation to legal submission in one click.

Shadow Bank Detection

Proprietary algorithm detects Hawala/OTC aggregation patterns in USDT-TRC20 flows — the dominant laundering method in Indian crypto fraud.

Tron-First Architecture

95% of Indian crypto fraud uses USDT on Tron. Our platform is optimized for TRC20 from the ground up — not an afterthought bolted onto an ETH-centric tool.

How It Works

From one address to full intelligence.

1

Paste Any Address

Enter a wallet address — TRON, ETH, BTC, BSC, Polygon, or Solana. System auto-detects the chain and runs a 7-signal risk triage in seconds.

2

Build the Transaction Graph

Expand the network visually. Cytoscape graph shows fund flow across hops. Filter by risk tier, entity type, or transaction value to find what matters.

3

Auto-Investigate in One Click

8-step pipeline runs automatically: exchange detection, velocity profiling, adaptive fetch, multi-hop exposure, privacy chain ring-elimination, and AI assessment. Watch results stream in live.

4

Export the LE Report

Generates a court-ready PDF with investigation narrative, transaction timeline, sanctions screening, signal scores, and all source data. Submission-ready in minutes.

Why CryptoFlow

Built for India. Not adapted.

Feature
Global Tools
CryptoFlow
Privacy Chain Investigation
"Opaque" — stops
Ring Elimination + Deep Check
Automated Investigation
8-step pipeline, <90s
India P2P Intelligence
5 exchanges + Telegram
UPI / Banking Correlation
Wallet-to-UPI mapping
Court-Ready LE Report
Manual export
Auto-generated PDF + AI
Fraud Pattern Detection
Limited
15 patterns auto-detected
Sanctions Screening
OFAC only
OFAC + EU + UK + UN + IL (1,670)
Entity Coverage
300K+ global
1.27M from 15 sources
Legal Notice Generation
Section 91/94 CrPC auto
Telegram / OTC Monitoring
33 channels + identity cross-link
Blockchain Coverage
5-10 chains
25 chains incl. 3 privacy
Cellebrite / EnCase Ingest
8 examination methods + OCR
Data Sovereignty
US Cloud only
On-premise deployable

Trust & Security

Government-grade security. Your data, your control.

On-Premise Deployment

Deploy in your government data center or private cloud. Docker-based, no external dependencies. Your investigation data never leaves your infrastructure.

Zero-Installation Access

Fully browser-based — works on any authorized workstation. JWT authentication with role-based access control (Admin, Officer, Analyst). Session expiry and login rate limiting.

Evidence Chain of Custody

Every search, investigation, and action logged with user ID, timestamp, and IP. Full audit trail meets IT Act and MHA compliance requirements.

Indigenous IP

Built by Indian engineers. No vendor lock-in, no US cloud dependency. Source code auditable. Zero dependency on foreign-controlled attribution databases.

Activity Audit Logging

Every API call logged automatically — who investigated which address, when, from where. Fire-and-forget middleware with zero performance impact.

Data Sovereignty

PostgreSQL + NetworkX for core analysis — no external graph DB dependency. All entity data, investigation state, and evidence stored in your PostgreSQL instance.

Built For

For those who close cases.

🏛️

Cyber Cells

State and central cyber crime investigation units. Paste suspect addresses and run an 8-step automated investigation — trace fund flow, identify mule networks, find cash-out points, and discover links between suspects in minutes.

⚖️

Prosecutors

Build stronger cases with an AI-generated investigation narrative and visual fund-flow evidence judges understand. No crypto expertise required to present or review the findings.

🔬

Forensic Labs

Direct ingest of Cellebrite UFDR and EnCase E01 extractions — 8 examination methods including Android Backup unwrap, Samsung Kies UTF-16 decoding, SQLite-aware reading, Tesseract OCR, and WhatsApp/Telegram-specific decoders. Cryptographic checksum chain (Base58Check, Bech32m, ed25519 curve verification) cuts false positives by 99% on real device extractions. Per-method audit trail in every manifest.

Ready to close more cases?

See the full 7-step investigation run on a real suspect address. Free pilot program for qualified government agencies.