Documenting an Incident Properly
What to record, in what order, while it is fresh. Everything that follows depends on the documentation and most victims produce none.
Priya Raman · 2 min read
After containment, documentation is the next priority. Reports, exchange freezes and any eventual legal process all depend on it, and it becomes harder to assemble by the hour.
Record first
Every transaction hash. The outgoing transactions, and any earlier approval or signature you now believe was the cause.
Timestamps. When each event occurred, in a consistent time zone.
Addresses. Yours, the destination, and any intermediate addresses visible on the explorer.
Amounts. Per asset, with the value in your local currency at the time.
The URL. The exact address of any site involved, including the full path. Screenshot it if it is still accessible.
Conversations. Screenshots of any messages, including profile names and identifiers, before accounts are deleted. They are deleted quickly.
What you did. A plain chronological account. What you clicked, what you signed, what you were told.
Then trace
Open the destination address on a block explorer and follow the funds forward.
You are looking for one thing: whether they reach an address labelled as an exchange deposit. If they do, that venue may be able to freeze them, and the window is short.
Record every hop. Analysis firms and exchange compliance teams will want the chain.
Then report
The receiving exchange, if funds reached one. Immediately, with the hashes. This is the only realistic recovery route and speed determines whether it works. Venues with a real compliance function, such as platforms with a real complaints process, publish a contact channel for exactly this.
Your national fraud reporting body. With the full documentation.
Chain analysis databases that accept public scam address reports. This feeds exchange screening and reduces the attacker’s ability to cash out.
The platform where the contact originated. Social networks, messaging services and advertising platforms all have reporting mechanisms, and these campaigns run until reported.
What not to do
Do not post publicly with details before reporting. Public posts attract recovery scammers within minutes, and they will reference the details you posted to appear credible.
Do not contact the attacker. It achieves nothing and confirms the address is live.
Do not engage with anyone who contacts you offering help. Every unsolicited approach after a loss is the second scam.
Why documentation matters even when recovery fails
Most reports do not result in recovery. They do contribute to cases that occasionally reach prosecution, and the addresses reported feed screening systems that make cashing out harder.
For you, the documentation also determines the tax treatment in jurisdictions where a theft loss can be claimed, and those standards are strict.
The template
Keep a blank document with these headings somewhere accessible: hashes, timestamps, addresses, amounts, URLs, conversations, chronology, reports filed.
Having the structure ready is the difference between documentation produced in the first hour and a reconstruction attempted a week later from memory.
Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.