Features

Organized around outcomes, not tools.

Every capability exists to answer one question: what happened, who’s behind it, where did the money go — and what do we do now.

Capabilities

Built around the outcome, not the tool.

Each capability is a focused answer to a stage of an incident — and they work together as one evidence-backed loop.

Monitoring

Know the moment something moves that shouldn’t.

  • Continuous watch on treasury, authority, and critical accounts
  • Behavior-based detection rules that fire when activity deviates
  • Alerts with context attached — not a bare notification
Detection

Signals you can act on, not noise.

  • Treasury transfers, new recipients, dormant activation, suspicious funding, bridge movement
  • Severity and a stated reason for every signal
  • Built to stay quiet when nothing is wrong
Fund Tracing

Follow the money to a destination you can act on.

  • Multi-hop traces across Solana, hop by hop
  • Entity-aware stops at known exchanges, bridges, and mixers
  • Source and destination analysis on both ends of a flow
Relationship Intelligence

Understand who is connected — and who just shares infrastructure.

  • Shared funders, fee payers, and execution fingerprints
  • Graph cutting discounts known entities instead of inflating clusters
  • Relationships labeled with the basis for the link
Evidence

Every claim labeled, every conclusion reviewable.

  • Observed, derived, attributed, and inferred — kept separate
  • Deterministic facts outrank inference
  • A wrong label is treated as worse than a missing one
Cases

One place for the whole investigation.

  • Timeline, notes, pinned wallets, and saved queries under one case
  • Flagged addresses, typed findings, and applied tags as the investigation develops
  • Append-only notes and decisions — a changed mind is a new row, not a rewrite
Response

Hand off with evidence, not screenshots.

  • A structured case record for protocol teams and security contacts
  • Investigation ID, methodology, typed findings, and versioned reports
  • Case decisions and snapshots preserved with provenance
Continuous Watch

An incident response that never goes quiet.

  • The actor stays on a watchlist after the incident
  • New movement raises a webhook alert with evidence
  • The same case file continues until closed
Evidence

The credibility machinery.

VikingIntel’s evidence ladder keeps blockchain facts and analytical judgment apart — so a finding can always be checked, reproduced, and defended.

Observed01
An on-chain fact, verified at the source.

12.4M USDC transferred from treasury_1 at 2026-08-04T14:32:04Z.

Deterministic. Never argued away.

Derived02
Computed from observed facts by a documented method.

Funds hop treasury_1 → 8qLm…2kDe → CEX deposit.

Reproducible, stamped with method and version.

Attributed03
A wallet linked to an entity on the basis of evidence.

CEX deposit address matches a verified exchange entity in the registry.

Only used when the link can be shown, not assumed.

Inferred04
An analytical judgment awaiting human confirmation.

The address set is likely operated by a single actor.

Never overrides facts. Never persisted unconfirmed.

Unknown

When evidence is missing, exhausted, or ambiguous, the answer is unknown — stated plainly, never papered over with a guess. Unlabeled means unchecked; truncated means truncated.

Evidence flow

From blockchain fact to analytical judgment.

Every finding sits somewhere on this line. The label says exactly where.

Blockchain fact
ObservedDerived

What actually happened on-chain — observed at the source or computed from it by a documented method.

Analysis
Attributed

Linking wallets and flows to entities on the basis of evidence — never on assumption.

Judgment
Inferred

An analytical conclusion that stays labeled as inference until a human confirms it.

Every finding is placed on this line — never silently promoted.

Continuous watch

An incident response that never goes quiet.

The actor behind an incident stays on a watchlist. New movement raises a webhook alert with the evidence attached — so when the money moves again, you are notified with context.

Incident
incident-014
treasury compromise
Attacker wallet
8qLm…2kDe
identified by evidence
Watchlist
+1 address
added in one click
New movement
0.4 SOL · 2 events
detected 14:47:02Z
Alert raised
webhook + evidence
same case file

The loop closes. The attacker stays on the watchlist. New movement raises a webhook alert with the evidence attached — the investigation continues from the same case file, not from zero.

Run the lifecycle on the accounts that matter.

Create a free account to start investigating, or talk to us about monitoring your critical accounts.