EVM Wallet Forensics is where a wallet investigation comes together. A completed run lands here as a risk score plus a set of tabs, each one a different angle on the address — what it did, who it dealt with, what it still has approved, and how a security event unfolded.
Why it exists
Investigating a wallet needs more than a transaction list. You want the events in order, the approvals that are still live, a profile of who the wallet transacted with, a narrative of what happened, and an evidence package you can hand to someone else. Those are genuinely different views, so the page keeps them as a consistent tab set rather than one long scroll.
Who uses it
- Forensics analyst — works a suspect wallet from several angles and assembles the picture.
- Compliance officer — reviews the compliance screening and exports the evidence set.
How to open it
- From a wallet forensics run after it completes.
- From the Wallets inventory — click a wallet card.
- Direct URL —
/evm-eoa?network=<chain>&address=<0x…>.
What each tab covers
An overall risk score with a per-component breakdown sits above the tabs. From there:
- Timeline — the wallet’s events in chronological order.
- Findings — detector hits for this wallet.
- Dust — dust-attack indicators.
- Fund Flow — a graph of value in and out.
- Counterparties — profiled interaction partners with risk signals.
- Approvals — outstanding token and NFT approvals and their risk.
- Attacks — attack patterns matched against the wallet’s activity.
- Post-Mortem and Reconstruction — the narrative and step-by-step rebuild of a security event.
- Compliance — sanctions and compliance screening.
- Evidence — the items packaged for reporting.
Limits
- Requires a signed-in account and a wallet that has a completed analysis for the given network and address.
- Tabs load as you open them; some populate a moment after the first render.
- An empty tab — no fund flow, no compliance match — is a valid result, not an error; most wallets are unremarkable on most axes.
Related pages
- EVM Wallet Analyzer — the in-progress view that feeds this page.
- Wallet — the entry point for new runs.
- Wallets — the inventory of completed runs.