Get advice from AML Crypto experts
When corporate cryptocurrency is stolen from a wallet accessed by multiple people, the immediate suspicion often falls on the employee "with the keys." This is a logical starting point—but it is not yet proof.

A developer's account could have been hacked. A seed phrase might have leaked from a work laptop. A contractor might have lost access long ago, which an external attacker later exploited. Conversely, an incident that looks exactly like an external hack might actually be a carefully planned insider theft.
An insider is not necessarily a full-time employee. According to the CERT Insider Threat Center, this category also includes former employees, contractors, business partners, and external specialists if they had or still have authorized access to the organization's critical assets.
The goal of a corporate investigation is not to pick the most suspicious employee, but to link a specific individual to the opportunity, actions, and digital footprint of the theft.
The Core: 5 Principles of Insider Investigations
  1. Access does not equal guilt — the access could have been exploited by an external attacker.
  2. On-chain routes must be correlated with logs: devices, IPs, VPNs, emails, and transaction approval workflows.
  3. Behavior before and after the theft can be more critical than the operation itself.
  4. Interviews and polygraphs supplement, but do not replace, technical and blockchain evidence.
  5. The outcome must be an evidence-based conclusion, strictly separating facts, indicators, and hypotheses.

1. First, Map All Access Points

An investigation begins not with suspects, but with the actual circle of people technically capable of influencing the assets.

Who to include in the map:
  • Who knew the seed phrase and held the private key
  • Who was part of the multisig scheme
  • Who could authorize actions on the exchange, change whitelists, or alter withdrawal limits
  • Who had access to corporate email, password managers, cloud storage, and servers
  • From whose devices transactions were signed
In smaller companies, crypto is often managed not through complex custodial infrastructure, but via 2–3 laptops, a hardware wallet, and the person who "usually handles it." It is the actual authority, not the job title, that defines the initial scope of analysis.

2. Reconstruct the Stolen Transaction's Lifecycle

A single TXID is not enough. You need to understand how the operation originated inside the company.
  • Who generated the destination address?
  • Where did this address first appear?
  • Was there a withdrawal request? Who approved it?
  • Which key signed the transfer?
  • From which device and under which account?
The blockchain shows what happened to the assets. Corporate systems help establish how the operation was initiated.

3. Correlate On-Chain Data with Corporate Logs

The timestamp of the stolen transaction must be overlaid onto the company's digital chronology. NIST SP 800-61 explicitly identifies the collection and analysis of logs as a core task of incident response.

What to analyze:
  • Logins to corporate systems
  • IP addresses and VPN sessions
  • Email and messenger activity
  • Access to key storage
  • Transaction approval systems
Example: A transaction is signed at 03:17. At the exact same time, the employee's corporate account logs in via their usual VPN from their work device. A significant coincidence. But if it turns out that malware was installed on the device an hour earlier, or the session was hijacked, the narrative changes.

The investigation must constantly test two alternatives: the person used their access themselves, or someone else used their access instead of them.

4. Preparation Signs Appear Long Before the Theft

An insider operation rarely begins at the moment of a major withdrawal. CERT recommends that organizations establish a baseline model of normal employee behavior specifically to detect deviations.
Any single indicator on its own might have an innocent explanation. Its significance emerges only when combined with other data.

5. The Behavior of Stolen Funds Provides Additional Clues

The blockchain route sometimes reveals the knowledge and habits of the attacker.
  • Assets pass through services previously used by a specific employee
  • The gas fee is paid from an address already seen in corporate operations
  • A portion of the funds lands on an old personal wallet or exchange deposit address linked to the individual
  • Familiar routes and transaction patterns are repeated
Important: A single familiar service proves almost nothing. The coincidence of a known address, gas source, timing, and internal activity forms a strong narrative. Address clustering is an analytical conclusion, not an automatic identification of a person.

6. Check Known Wallets of the Employee or Contractor

The company may possess addresses the individual used legitimately: for corporate payouts, expense reimbursements, or previous operations.

These can be compared against the route of the stolen funds, exchange credentials, corporate correspondence, and other legally obtained data. Infrastructure overlaps are especially valuable: a common gas source, identical intermediate services, or the merging of funds.

But the principle remains: a single matching pattern does not turn into an accusation. It becomes forensically relevant only in conjunction with other facts.

7. Motive Comes Only After Technical Data

Conflicts with management, resignations, and financial hardships look convincing in a detective novel. In a corporate investigation, they are weaker than a specific TXID, an authorization event, and a preserved log.

Motive can support an existing narrative, but it should not create it from scratch. Build the investigation from objective data to the person, not from a preferred suspect to the confirmation of their guilt.

8. Conduct Interviews After Initial Data Analysis

Questions should be built around specific chronologies and identified discrepancies:
  • Why was the account active at a specific time?
  • Why was the limit changed?
  • Who owns a specific address?
  • Why did the device connect to a specific service?
This is far more productive than asking, "Did you steal the cryptocurrency?" Premature accusations create risk: the person will realize which narrative is being investigated and gain time to destroy evidence or coordinate alibis.

9. The Polygraph: Where It Strengthens the Investigation

When an insider is suspected, a polygraph becomes an additional tool—especially when there is already a specific incident, a limited circle of individuals, and a set of verifiable facts.

The U.S. National Research Council, after analyzing scientific studies, concluded that when investigating specific events, a polygraph can distinguish truthful from deceptive answers better than random guessing, but its accuracy is far from absolute and heavily depends on testing conditions.

The wrong approach looks like this:
"The polygraph showed deception—therefore, the employee stole the money."
The right approach looks like this:
"The technical investigation revealed specific discrepancies. Based on these, precise questions were formulated. The polygraph results are evaluated alongside blockchain data, logs, and interviews."
Question Quality Matters More Than the Machine

Asking "Have you ever stolen cryptocurrency?" is uninformative. It is useful to verify the specific circumstances of the investigated episode: timing of operations, specific addresses, approval details, key sources.

Only a specialist who has already conducted the blockchain analysis and gathered the facts can formulate such questions.

10. Restrict the Suspect's Access Without Destroying Evidence

If the narrative is serious enough, compromised access must be restricted. But the same principle applies as with an external attack: protect the assets without destroying the evidence.
  • What to do:
    • Revoke privileges
    • Terminate active sessions
    • Rotate corporate keys
    • Move remaining assets out of the risk zone
  • What NOT to do before preserving evidence:
    • Chaotically wipe the work laptop
    • Delete logs and accounts
    • Factory-reset devices
Exercise extreme caution with the employee's personal devices and accounts. The ability to investigate them depends on the law, corporate policies, and contracts. The technical team must work here alongside lawyers.

11. Separate Facts, Indicators, and Hypotheses

This is one of the most critical principles of the entire investigation.
If these levels are mixed, the report starts sounding more convincing than the data allows. A strong final document shows not just the conclusion, but the basis and the degree of confidence for every key link.

What the Investigation Outcome Should Be

The result is not a table of names with suspicion percentages.

The company must receive a connected evidentiary picture:
  • Who had access
  • How the stolen transaction originated
  • Which devices and accounts were involved
  • Where the funds went
  • Which addresses might be linked to suspects
  • Which alternative narratives remain possible
Interview results and, if used, polygraph results are added to this. But the final assessment must rely primarily on verifiable digital and blockchain data.
The Main Takeaway

An insider is identified not by a single suspicious indicator, but by the totality of on-chain data, access logs, corporate chronology, and confirmed opportunity to execute the operation.

FAQ

  • Can a contractor be considered an insider?
    Yes. What matters is not the employment format, but the presence of current or former authorized access to the organization's critical assets.
  • Does logging in under an employee's account prove their involvement?
    No. Credentials, devices, or active sessions could have been compromised. The fact must be correlated with other technical and blockchain data.
  • Can a polygraph be used in the investigation?
    As a supplementary tool—yes, if permissible in the jurisdiction. The result is not infallible and should not be viewed as standalone evidence.
  • When is the best time to conduct a polygraph?
    After the initial investigation, when specific transactions, timeframes, and discrepancies are already known. This allows for targeted questions rather than general screening.
  • Should the suspect be suspended from access immediately?
    If there is a risk of the incident continuing, access to critical systems should be restricted. However, devices, logs, and other evidence must be preserved.
Want to learn more and get expert advice? Leave your email and we will contact you promptly!
We also recommend