Preserving crypto fraud evidence is defined as the immediate collection and securing of all transaction data, wallet addresses, communications, and platform records before digital traces disappear or are altered. Victims who act within the first 24–72 hours give investigators and attorneys the best possible foundation for recovery or prosecution. The core tools are transaction hashes, wallet addresses, screenshots, and communication exports from platforms like Telegram, WhatsApp, and Discord. Reporting to the FBI’s Internet Crime Complaint Center (IC3), centralized exchanges, and licensed legal counsel should follow directly after evidence is secured.
What are the essential types of evidence to collect immediately after you suspect crypto fraud?
The six most critical evidence items are transaction hashes, wallet addresses, communication screenshots, dates and timestamps, platform names, and asset IDs. Gathering these six items before your first call with an investigator or attorney puts you ahead of the vast majority of victims who arrive unprepared.
Transaction hashes are the single most important piece of evidence you can collect. Blockchain transaction hashes are unique, immutable digital fingerprints that allow forensic investigators to trace stolen funds across the blockchain. A screenshot of a transaction is far less useful than the raw alphanumeric hash itself, because investigators need the text to query blockchain explorers directly.
The full list of evidence to secure includes:
- Transaction hashes: Copy the full text of every hash from your wallet or exchange history.
- Wallet addresses: Record both your own wallet address and every address you sent funds to.
- Communication records: Screenshots of all messages on Telegram, WhatsApp, email, and social media.
- Dates and timestamps: Note the exact date and time of every transaction and key conversation.
- Platform and website URLs: Save the URLs of any trading platform, investment site, or app involved.
- Asset IDs and token contract addresses: Relevant for NFT fraud or token-based scams.
Scammers on Telegram can delete messages remotely, which means chat histories can vanish without warning. Photograph your screen with a second physical device as a backup, even if you also use the platform’s export function. This redundancy protects evidence that a remote deletion would otherwise destroy.
Pro Tip: Compile all evidence into a single organized document or folder before you make any calls or file any reports. Victims who arrive at intake calls with a complete file move through case evaluation far faster than those who piece together evidence on the fly.

Which tools and platforms support evidence preservation and reporting?
Blockchain explorers are the primary tools for verifying and documenting transaction data. Etherscan covers Ethereum and ERC-20 tokens, while BscScan covers the BNB Smart Chain. Entering a transaction hash into either explorer produces a full record of the transaction, including sender, recipient, amount, and timestamp. That record is publicly verifiable and carries forensic weight that a screenshot alone cannot match.
For communication evidence, each major platform offers a built-in export function:
- Telegram: Use Settings > Privacy and Security > Export Telegram Data to download chat histories.
- WhatsApp: Open a chat, tap the three-dot menu, and select “Export Chat” to save a text file.
- Discord: Third-party tools like DiscordChatExporter can archive server and direct message histories.
Export these immediately. Chat export functions should be used right away and supplemented by physical screen photographs, because exports do not recover messages already deleted by the scammer.
The table below summarizes the key tools and platforms for collecting and reporting crypto fraud evidence.
| Tool or Platform | Role | Key Feature |
|---|---|---|
| Etherscan / BscScan | Blockchain transaction verification | Public, immutable transaction records |
| Telegram Export | Communication preservation | Full chat history download |
| WhatsApp Export | Communication preservation | Text and media archive |
| FBI IC3 (ic3.gov) | Law enforcement complaint filing | Centralized federal fraud reporting |
| Exchange abuse contacts | Asset freeze requests | Logs wallet addresses for compliance teams |

Filing a report with the FBI’s IC3 is a required step, not an optional one. IC3 prioritizes complaints that include full evidence packages with wallet addresses and transaction hashes. Vague complaints without transaction data rarely generate follow-up action. Contact the exchange where funds were sent and report the receiving wallet address as well. Exchanges typically do not freeze assets on victim reports alone, but they log flagged addresses for their compliance teams, which strengthens future subpoenas.
What are the critical timing steps to preserve evidence effectively?
The first 24–72 hours after a crypto theft represent the window during which institutional freezes and forensic tracing are most effective. Once funds move through mixers or reach offshore exchanges, recovery becomes significantly harder. Speed and sequence both matter.
Follow these steps in order:
- Capture all evidence first. Before contacting anyone, copy every transaction hash, wallet address, and screenshot. Do not delete any messages or close any accounts.
- Export all chat histories. Use Telegram, WhatsApp, and Discord export functions immediately. Photograph screens with a second device as a backup.
- Report to the receiving exchange. Identify which exchange received the stolen funds and contact their abuse or compliance team with the wallet address and transaction hash.
- File a report with the FBI IC3. Submit a detailed complaint at ic3.gov. Include wallet addresses, transaction hashes, dates, and platform names.
- File a local police report. A police report number is often required for insurance claims, civil litigation, and some exchange cooperation requests.
- Contact a licensed crypto attorney. A qualified attorney can advise on civil recovery options, including emergency injunctions and disclosure orders, before assets move further.
Two common mistakes destroy cases before they start. The first is waiting more than 72 hours to report, which allows funds to move beyond the reach of exchange compliance teams. The second is deleting communications with the scammer out of frustration or embarrassment. Those messages are evidence.
Pro Tip: If your wallet is only partially compromised, move remaining assets to a new, clean wallet before taking any other action. Use a separate wallet to cover gas fees so you do not inadvertently interact with a compromised contract.
How is preserved evidence used by investigators and legal professionals?
Preserved evidence is the direct input for blockchain forensic analysis, civil litigation, and law enforcement subpoenas. Without it, investigators have no starting point and attorneys have no case to file.
Blockchain forensic investigators use transaction hashes to trace the path of stolen funds across wallets and exchanges. When funds land at a centralized exchange, that exchange holds Know Your Customer (KYC) data tied to the receiving wallet. Transaction hashes and wallet addresses in law enforcement reports enable subpoenas that reveal the fraudster’s identity, IP logs, and account data.
Legal professionals use a specific set of court tools to compel exchanges to disclose that data:
- Norwich Pharmacal Orders: Court orders that compel a third party, such as a centralized exchange, to disclose the identity of a wrongdoer. These disclosure orders are a primary mechanism for unmasking fraudsters from wallet addresses.
- Civil asset freezing orders: Emergency injunctions that prevent a fraudster from moving or spending identified assets.
- Criminal referrals: A well-documented IC3 complaint with full transaction data can support a federal criminal referral.
“Legal professionals emphasize the use of disclosure orders to compel exchanges to reveal fraudsters’ identities, making evidence preservation critical for these legal tools to be effective.”
Screenshots alone are legally insufficient for most of these proceedings. A court or exchange compliance team requires the raw transaction hash to verify the claim independently. Victims who document crypto scam evidence with full transaction data give their attorneys the tools to pursue every available legal avenue.
Key Takeaways
Victims who preserve crypto fraud evidence completely and immediately, including transaction hashes, wallet addresses, and communication records, give investigators and attorneys the foundation needed to trace funds and pursue legal recovery.
| Point | Details |
|---|---|
| Transaction hashes are essential | Copy the raw text of every hash. Screenshots alone are insufficient for forensic tracing. |
| Act within 72 hours | The first 24–72 hours is the critical window for exchange freezes and effective forensic tracing. |
| Export and photograph communications | Use platform export tools immediately and photograph screens to protect against remote message deletion. |
| File with IC3 and exchanges | Submit complete evidence packages to the FBI IC3 and the receiving exchange’s abuse team. |
| Legal tools require complete evidence | Norwich Pharmacal Orders and civil claims depend on documented transaction data, not vague complaints. |
What I’ve learned from watching victims lose recoverable cases
The most preventable loss I see is not the theft itself. It is the evidence that disappears in the hours after the theft because the victim did not know what to save. Victims often spend the first day calling their bank or posting on Reddit, while the scammer quietly deletes the Telegram chat and moves funds through a mixer. By the time a forensic investigator or attorney gets involved, the trail is cold.
The second pattern I see constantly is victims who have screenshots but no transaction hashes. They took photos of their screen showing a balance or a transaction confirmation, but they never copied the hash. That hash is the difference between a traceable case and an untraceable one. Investigators cannot work from a photo of a number. They need the text.
What actually works is treating the first hour after you realize you have been defrauded the same way you would treat a crime scene. You do not clean up. You do not delete anything. You document everything in its current state, then you call a professional. Victims who arrive at their first attorney or investigator call with a complete, organized evidence file consistently move faster through the recovery process than those who do not.
Proper documentation also matters even when immediate recovery is not possible. Preserved evidence supports insurance claims, tax loss documentation, and future civil litigation if the fraudster is later identified. The evidence you collect today may be the basis for a case filed two years from now.
— Mark
How Murphyslawcrypto helps victims build and use their evidence
Murphyslawcrypto is a licensed crypto law firm founded by Liam Murphy, Esq., a Penn Law graduate with courtroom experience from Paul Hastings, Selendy Gay, and McKool Smith. The firm has litigated significant cases involving Celsius, Terraform Labs, and BitMEX, and maintains an active docket of fraud and recovery matters.

If you have lost funds to a crypto scam, Murphyslawcrypto works directly with forensic investigators to analyze preserved evidence and pursue every available legal recovery option. The firm can advise on emergency injunctions, disclosure orders, IC3 submissions, and civil litigation. Unlike unregulated “crypto recovery services,” Murphyslawcrypto is a licensed law firm with real litigation experience. Contact the firm to discuss your case and learn how your preserved evidence can be put to work.
FAQ
What is the most important piece of evidence to collect after crypto fraud?
The transaction hash is the single most critical item. It is the only data that allows forensic investigators to trace stolen funds accurately on the blockchain.
How long do I have to preserve crypto fraud evidence before it is too late?
Act within 24–72 hours. That window is when centralized exchange freezes and forensic tracing are most effective before funds move beyond reach.
Are screenshots enough to document crypto scam evidence?
Screenshots are useful but insufficient on their own. Investigators and courts require the raw text of transaction hashes to verify and trace transactions independently.
Can scammers delete the evidence on Telegram or WhatsApp?
Yes. Telegram and WhatsApp allow senders to delete messages remotely. Export chat histories immediately and photograph your screen with a second physical device as a backup.
What happens to my evidence when I file a report with the FBI IC3?
The FBI IC3 logs your complaint and prioritizes cases that include complete evidence packages. Transaction hashes and wallet addresses enable law enforcement to subpoena exchanges for the fraudster’s identity and account data.