How it works

From first movement to evidence-backed investigation.

Seven stages, one continuous loop. VikingIntel watches the accounts you put under watch, turns anomalies into evidence-backed investigations, and keeps watching after the incident is contained.

The lifecycle

Monitor → Detect → Triage → Investigate → Verify → Respond → Watch

01
Monitor

Watch the assets that matter.

02
Detect

See what moved, and why it is unusual.

03
Triage

Decide what is worth investigating.

04
Investigate

Turn an alert into a timeline.

05
Verify

Separate facts from inference.

06
Respond

Hand off with evidence, not screenshots.

07
Watch

Keep watching after the incident.

Stage 01 · Monitor

Watch the assets that matter.

Continuous watch over treasury wallets, protocol authority, and the accounts that hold critical value. A change in expected behavior is the trigger — not another generic alert you have to triage by hand.

  • Continuous watch on treasury wallets, protocol authority, and critical accounts
  • Behavior-based detection rules that fire when activity deviates
  • Alerts with context attached — not a bare notification
Monitored accountscontinuous · behavior-based
  • Treasury_1
    12.4M USDC · 4 signers
    Normal
  • Authority multisig
    owner set · threshold 3
    Watching
  • Cold wallet 7xKX…4nQp
    idle 8 months
    Normal
  • Liquidity pool vault
    bridged assets
    Normal

Illustrative example — mock accounts and statuses.

Stage 02 · Detect

See what moved, and why it is unusual.

Detection rules and behavior models flag the patterns that precede incidents: unexpected treasury transfers, new recipients, dormant wallets waking, authority changes, and bridge movement.

  • Signals for treasury transfers, new recipients, dormant activation, suspicious funding, bridge movement, and authority changes
  • Severity and a stated reason for every signal
  • Existing context folded in before the signal reaches you
Signal fired
Unexpected treasury transfer

12.4M USDC · treasury_1 → 8qLm…2kDe · 14:32:04Z

Amount exceeds the authorized threshold by 14×. Recipient has no history with this treasury.

High severityContext attached

Illustrative example — mock signal with mock amounts and addresses.

Stage 03 · Triage

Decide what is worth investigating.

Severity, affected assets, and blast radius sort the noise into a short list a human actually reads. Most signals never need an investigation; the ones that do arrive with context attached.

  • Priority from severity and exchange proximity
  • A short list a human actually reads
  • Most signals never become investigations
Triage queue4 signals · 2 to investigate
  • Unexpected treasury transfer
    HighInvestigate
  • Dormant wallet activation
    HighInvestigate
  • Fan-out to many destinations · 84 addr
    MediumWatch
  • Bridge movement · out-of-pattern
    LowDismiss

Illustrative example — mock queue, severities, and actions.

Stage 04 · Investigate

Turn an alert into a timeline.

Fund flow, related wallets, affected assets, and evidence families combine into findings with confidence — a timeline of what happened, who touched it, and where the money went.

  • A reconstructed timeline of the incident
  • Fund flow traced to an actionable destination
  • Related wallets, affected assets, findings, and confidence — under one case
  • Public-source evidence from project websites, domains, and repositories — where available
Case · incident-014
Treasury compromise
VerifiedConfidence · HighWatchlist +1
TimelineReconstructed
Affected assets2
Related wallets46
Evidence3 families
Evidence families
Funding Lineage

Trace passes through a known exchange — signal cut, not counted.

Discounted
Execution Fingerprint

Compromised wallet and 6 downstream wallets share an uncommon fee-payer sequence.

Strong
Timing

Splitting window of 90 seconds across 84 addresses.

Medium
Fund flow
Compromised wallet
7xKX…4nQp
12.4M USDC out
Intermediate
8qLm…2kDe
11.9M USDC
Splitting
84 addresses
90s window
Exchange cash-out
CEX · known
stopped here
Findings
  • Observed — 12.4M USDC left treasury_1 at 14:32:04Z, authority was intact.
  • Attributed — the destination matches a verified exchange entity in the registry. Shown, not assumed.
  • Inferred — the 84 split addresses may share an operator. Awaiting confirmation.

Illustrative example — mock case file with mock evidence values.

Stage 05 · Verify

Separate facts from inference.

Observed on-chain facts are held apart from derived, attributed, and inferred claims. Consequential conclusions wait for human confirmation — VikingIntel never overrides deterministic evidence.

  • Observed, derived, attributed, and inferred findings — labeled separately
  • Deterministic on-chain facts outrank inference
  • Human confirmation gates consequential conclusions
  • Public-source findings carry the same typed labels and provenance as on-chain evidence
Observed01
An on-chain fact, verified at the source.

12.4M USDC transferred from treasury_1 at 2026-08-04T14:32:04Z.

Deterministic. Never argued away.

Derived02
Computed from observed facts by a documented method.

Funds hop treasury_1 → 8qLm…2kDe → CEX deposit.

Reproducible, stamped with method and version.

Attributed03
A wallet linked to an entity on the basis of evidence.

CEX deposit address matches a verified exchange entity in the registry.

Only used when the link can be shown, not assumed.

Inferred04
An analytical judgment awaiting human confirmation.

The address set is likely operated by a single actor.

Never overrides facts. Never persisted unconfirmed.

VikingIntel distinguishes these levels in every finding. An inferred conclusion is labeled inferred — it is never presented as a verified fact, and it never overrides deterministic evidence.

Unknown

When evidence is missing, exhausted, or ambiguous, the answer is unknown — stated plainly, never papered over with a guess. Unlabeled means unchecked; truncated means truncated.

Stage 06 · Respond

Hand off with evidence, not screenshots.

A reviewable evidence package a protocol team, exchange, or security contact can act on — with the reasoning attached, so a decision can be checked after the fact.

  • A structured case record, not screenshots
  • Investigation ID, methodology, typed findings, and versioned reports
  • Case decisions and snapshots preserved with provenance
Evidence Report
Cluster sybil-cluster-0192
Verified
Investigation ID
inv_8f3a2c
Cluster ID
sybil-cluster-0192
Wallet count
41
Classification
Coordinated
Confidence
High
Evidence families
3 / 4
Entity exclusions
1 (Binance Hot Wallet)
Generated
2026-08-04T14:36:11Z
Report hash
sha256:9a41…e02c

Illustrative example — mock cluster, report hash, and Verified badge.

Stage 07 · Watch

Keep watching after the incident.

Put the attacker’s wallets on a watchlist in one click. New movement raises a webhook alert with the evidence attached — the investigation does not stop when the first finding is made.

  • The actor stays on a watchlist after the incident
  • New movement raises a webhook alert with evidence
  • The investigation continues until it is closed
Incident
incident-014
treasury compromise
Attacker wallet
8qLm…2kDe
identified by evidence
Watchlist
+1 address
added in one click
New movement
0.4 SOL · 2 events
detected 14:47:02Z
Alert raised
webhook + evidence
same case file

The loop closes. The attacker stays on the watchlist. New movement raises a webhook alert with the evidence attached — the investigation continues from the same case file, not from zero.

Illustrative example — mock watchlist flow with mock movement.

Put the lifecycle to work.

Create a free account and start with tracing, screening, and cases — monitoring is one plan up.