Where did the funds come from?
Trace the immediate counterparties. Keep transaction references close to the question you are trying to answer.
Follow the money. Understand the threat. Connect onchain exposure and offchain intelligence in a private desktop workspace built for the people protecting digital assets.
An unexpected connection.
Follow activity. Examine relationships.
Explore capabilityConnect financial and technical context.
Explore capabilityGive every finding a defensible record.
Explore capabilityKeep important investigations in view.
Explore capabilityMore data is easy.
A clearer decision takes context.
Trace the immediate counterparties. Keep transaction references close to the question you are trying to answer.
Look beyond an isolated address. Review contract relationships, infrastructure, and the intelligence sources relevant to the case.
Preserve the evidence, record your reasoning, and give the next analyst a useful starting point.
Move from raw activity to a structured investigation. Explore relationships, preserve the source context, and document what deserves a closer look.
A focused queue of signals, with the context to decide what deserves a closer look.
Begin with the public record. Expand the investigation through the relationships, source context, and analyst knowledge that give it meaning.
Wallet activity, native balances, deployed code, and contract metadata. A reproducible snapshot at a specific block.
An investigation model for connecting wallet leads with actor reporting, campaigns, and technical indicators from licensed sources.
Case notes, review status, saved watchlists, and evidence packages. Keep the reasoning with the record.
Five networks.
One investigation approach.
Direct network reads, public explorer context, and a consistent record across ecosystems.
Explore the coverage modelFrom the first suspicious transfer to a considered ecosystem review, give every investigation a method and every handoff a usable record.
A suspicious address is a starting point. Capture its state, review the indexed activity, and turn the strongest leads into a case another analyst can pick up.
Capture the address and relevant network snapshot.
Inspect counterparties, contract context, and source references.
Record the hypothesis, unresolved questions, and follow-up actions.
An incident brief with transaction references and a clear investigation scope.
When a case moves between teams, the context should move with it. GroundTruth keeps the source record, the analyst’s interpretation, and the next question together.
Capture what the source actually reports, with the network, block, and time that put it in context.
Describe the relationship and record your hypothesis. Keep uncertainty and alternative explanations visible.
Save the rationale, mark the case’s review state, and export a record the next person can examine.
One record. Enough context for the next decision.
Review the funding relationship in context. A shared counterparty is an observation; the case records the evidence needed to assess its significance.
Independent exchanges, asset services, and security teams see different parts of the same threat. GroundTruth brings those perspectives into a common investigation approach, shaped around each partner’s priorities.
Explore ecosystem partnershipsGive the team a shared starting point for reviewing protocols, counterparties, and emerging patterns.
Trace a lead from the first alert to a source-backed case the right team can act on.
Make diligence more repeatable, with evidence that can be checked and questions that can be answered.
Follow the funds with blockchain intelligence. Understand the actors with threat intelligence. Bring the infrastructure and the evidence into the same picture.
Chainalysis, TRM Labs, and Elliptic. Wallet screening, transaction context, and entity attribution, attached to the case that needs them.
Flashpoint and Recorded Future. Bring deep and dark web reporting, threat-actor context, and indicator relationships into the investigation.
Commercial sources require appropriate API access and licensing. Data entitlements and network coverage vary by provider.
Explore all 11 integrationsWork with a local case store or connect the desktop app to a GroundTruth server in your environment. Choose the data boundary that fits the investigation.
Investigations · Notes · Evidence
Local or connected workspace
Public data · Source references
A practical sequence for turning a reported address into a scoped, reviewable investigation.
Read the playbookA structured approach to reviewing a public address without losing the business context behind the question.
Read the field guideKeep observations, source assessments, and analyst conclusions distinct throughout an investigation.
Read the methodologyGroundTruth supports address and contract investigations, incident triage, counterparty reviews, and ecosystem diligence. Begin with a public address, inspect the available evidence, and preserve the reasoning behind your next decision.
Address investigations cover Ink, Ethereum, Base, Arbitrum, and Optimism. GroundTruth combines a block-specific network snapshot with available explorer context. Indexed activity, source coverage, and provider limits are kept in context so your team can assess the evidence appropriately.
A case keeps the address, network, snapshot context, source references, and analyst notes together. Observed relationships remain separate from your conclusions. Review status and exported briefs help the next analyst understand both the evidence and the open questions.
Integration scope starts with your existing provider licenses, API access, and operational requirements. Blockchain analytics, threat-actor reporting, infrastructure intelligence, and security operations tools each contribute a different kind of context. Data entitlements and coverage are assessed source by source.
Export a structured JSON evidence package, a CSV transaction worksheet, or a Markdown case brief. The saved analyst notes and source references travel with the relevant case export, giving reviewers a record they can inspect in their own workflow.
Use a local workspace with a case database on your Mac, or connect to a GroundTruth server with account-scoped access. The Security page explains the storage, session, and network boundaries so your team can evaluate the deployment against its requirements.
A wider view of the threat.
A clearer next move.