Case study — tracing a stolen-asset chain to custody
A fake-giveaway phishing theft, Dec 2020 → 4-hop trace to Binance custody in 1h 40m → a registrant fingerprint that surfaced a serial-pattern lead across multiple look-alike domains → reported to the FBI via IC3
This is the public case study of the L0gic Verify operator's own loss — 751,670.96 VET stolen in December 2020 through a "x2 VET giveaway" impersonation site at vet4.net. It is published here, with the operator's explicit consent, as a real-world demonstration of how an on-chain chain-of-custody trace isolates the one fact that matters: the exchange-attributable identity at the end of the money.
There is no shame in being phished by a well-built impersonation. There would be shame in hiding it while building a tool that helps others trace the same kind of theft.
What happened
In December 2020, a website at vet4.net impersonated the VeChain project and advertised a "send VET, get 2× back" giveaway — a classic advance-fee impersonation scam. The operator sent 751,670.96 VET (approximately $15,000 at the time) to the contribution address the site published. Nothing came back. The funds were gone in under two hours.
The question a forensic trace answers is not "can I get it back" — on-chain transfers are irreversible, and tracing is not recovery. The question it answers is: where did the money end up, and who can a subpoena reach there?
The transaction chain
Every address and transaction hash below is permanent public on-chain data. Select any one and paste it into VeChainStats or explore.vechain.org to verify the trace independently — nothing here asks you to take the operator's word for it.
The entity behind the site: 7 warning signs, all free to check
Before a single coin moved, vet4.net was identifiable as fraudulent from free public lookups alone. The scorecard below shows each signal twice: the technical field (for forensic reviewers) and a plain-English translation (for someone with no crypto background).
whois.com · dnschecker.org · icann.org WHOIS lookup · any browser's "view source"
The bigger lead — one theft may point to many
The trace above is one theft. But pivoting on a single registrant fingerprint surfaced a lead to something potentially larger: a cluster of look-alike giveaway-scam domains that appear to share that fingerprint across multiple impersonated brands. What looked like a lone loss may be one node in a wider pattern — a lead now under further investigation, not yet a closed finding.
That could elevate the case from a single compliance request toward a serial-fraud pattern — and the findings have been reported to federal law enforcement via an FBI/IC3 complaint. The lesson for any victim: a fingerprint that means nothing in isolation can, cross-referenced, begin to open up the wider infrastructure behind a theft.
The method, so you can re-run it
This case is not a magic trick — it is a procedure anyone can reproduce from public data. That reproducibility is the point: a trace nobody can independently verify is just an assertion.
- Anchor the loss. Identify the victim wallet and the exact outbound transaction (hash, block, timestamp, amount).
- Follow the value, hop by hop. At each wallet, take the outbound TX that carries the loss amount forward. Record every hash — the chain is the evidence.
- Profile each intermediate wallet. Lifetime in/out counts and total volume separate single-use burners from aggregators. An aggregator handling many times the single loss is the signature of a multi-victim ring.
- Find the custody boundary. The first labeled exchange wallet is where the public trail ends and the private trail (KYC) begins. The deposit TX into that wallet is the anchor a subpoena attaches to.
- Profile the entity layer in parallel. WHOIS + DNS on the scam domain establish age, registrar, registrant, hosting, and authenticity — the 7-sign scorecard above.
- Hand it to the channel that can act. Tracing is not recovery. The deliverable is a documented chain that an exchange compliance team, a federal complaint (e.g., IC3), or counsel-led subpoena can act on.
What this trace establishes (and what it does not)
It establishes the custody boundary and the attributable identity. The stolen VET did not vanish into anonymity — it landed in Binance custody at a specific, hash-anchored deposit, behind which sits a KYC'd customer account. That is the single fact that converts "I was robbed by a stranger on the internet" into "the receiving party is identifiable by subpoena."
It does not, by itself, recover funds or name the perpetrator publicly. The identity behind the Hop-4 deposit is held by Binance under KYC; surfacing it requires a lawful request (an exchange compliance process, a law-enforcement referral such as an IC3 complaint, or a counsel-led subpoena). Tracing produces the map; lawful process walks it. L0gic Verify produces the map.
The aggregator finding has reach beyond this one loss. Because Hop 3 handled roughly six times this theft in volume, the same documented wallet is likely a junction for other victims' funds — which is precisely the kind of pattern that supports a consolidated complaint rather than a lonely one.
What L0gic Verify does (and does not) do
This case study is published because the L0gic Verify product addresses the documentation problem, not the fund-recovery problem.
L0gic Verify would not have stopped the original 2020 transfer. The send was authorized by the operator to a published address; on-chain, it was a valid transaction. The harm was the destination, and the destination was only verifiable as fraudulent through the entity-layer check the operator did not run in time.
What L0gic Verify provides is the documented chain of custody after the fact — the verifiable trace from victim wallet to exchange custody, plus the entity-layer scorecard on the scam domain. That is the artifact that makes a loss actionable for exchange compliance, federal complaint, and counsel.
The standard $95 Forensic Report tier delivers single-transaction in-depth verification with an operator-signed PDF (see the sample report on the landing page). Case-study-class engagements like the one above — multi-hop reconstructions with entity-layer analysis — are scoped per case by hop count, time range, and complexity, quoted after initial review. Reach out to discuss your situation.
The product is not an asset-recovery service and makes no claim to be. It is a verifier of the chain of custody between exchange-reported state and canonical on-chain state, with optional PDF report generation for counsel-led use.
Why this case study is public
The operator was phished by a well-built impersonation scam, and has spent the years since building the documentation tools he wishes he'd had that day. Publishing this case is the simplest way to show that:
- The product's detectors are tuned against a real scam pattern, not a synthetic one
- The operator has lived through exactly what the product is meant to address
- The forensic chain of custody is materially useful years after the loss — the open 2026 compliance follow-up runs on a trace of a 2020 theft
Every transaction hash here is permanent on the VeChain blockchain. Every WHOIS and DNS field was, and remains, publicly checkable. Publishing this case study just connects what was already public — and shows you the method, so you can check our work.
All wallet addresses and transaction hashes are public on-chain data, independently verifiable on VeChainStats and explore.vechain.org. Any operator(s) behind the suspected pattern are not named here; identities, where established, live only in the law-enforcement file and are surfaced only to lawful process. This document does not constitute legal, tax, or financial advice. Consult licensed counsel for guidance specific to your situation.