Onchain evidence
Wallet activity, native balances, deployed code, and contract metadata. A reproducible snapshot at a specific block.
A focused investigation workspace for digital-asset security. Follow the public evidence, examine the relationships, and preserve a record your team can stand behind.
Start your evaluationFollow activity. Examine relationships.
Explore capabilityConnect financial and technical context.
Explore capabilityGive every finding a defensible record.
Explore capabilityKeep important investigations in view.
Explore capabilityBegin with the public record. Expand the investigation through the relationships, source context, and analyst knowledge that give it meaning.
Wallet activity, native balances, deployed code, and contract metadata. A reproducible snapshot at a specific block.
An investigation model for connecting wallet leads with actor reporting, campaigns, and technical indicators from licensed sources.
Case notes, review status, saved watchlists, and evidence packages. Keep the reasoning with the record.
Five networks.
One investigation approach.
Native balance, transaction nonce, deployed bytecode, and supported contract reads are pinned to the same block. Explorer metadata adds available verification, creator, proxy, token, and holder context.
Activity contains up to 50 recent indexed transactions, capped at the snapshot block. Indexing can lag; token transfers and internal calls need separate investigation. Source gaps remain visible in the case.
Move through the investigation without moving the evidence between disconnected documents and browser tabs.
Start with a wallet or contract on a supported network. Capture a pinned snapshot and the indexed activity around it.
NETWORK SNAPSHOT / SOURCE CONTEXTInspect observed counterparties and available contract relationships in an interactive graph. Select a node to examine its context.
COUNTERPARTIES / CONTRACT RELATIONSHIPSFilter recent activity by direction, address, hash, or method. Keep native values, execution status, and explorer references in view.
FILTERS / TRANSACTION REFERENCESKeep the snapshot, your hypothesis, and the open questions together. Update case titles, notes, and review status as the investigation develops.
NOTES / REVIEW STATE / CASE RECORDSSave important cases to a watchlist for manual review. Refresh a snapshot when you need new evidence without losing the analyst record.
WATCHLISTS / ON-DEMAND REFRESHExport the complete case, a transaction worksheet, or a readable brief. Give the next reviewer the sources and reasoning behind the finding.
JSON / CSV / MARKDOWNWhen a case moves between teams, the context should move with it. GroundTruth keeps the source record, the analyst’s interpretation, and the next question together.
Capture what the source actually reports, with the network, block, and time that put it in context.
Describe the relationship and record your hypothesis. Keep uncertainty and alternative explanations visible.
Save the rationale, mark the case’s review state, and export a record the next person can examine.
One record. Enough context for the next decision.
Review the funding relationship in context. A shared counterparty is an observation; the case records the evidence needed to assess its significance.
Structured case data, snapshot fields, indexed activity, source-backed observations, and saved analyst notes.
A portable table of the indexed activity, including references, native values, timestamps, methods, and execution status.
A concise review record with the snapshot context, observations, source references, and the analyst’s written reasoning.
Work with a local case store or connect the desktop app to a GroundTruth server in your environment. Choose the data boundary that fits the investigation.
Investigations · Notes · Evidence
Local or connected workspace
Public data · Source references
A wider view of the threat.
A clearer next move.