From first movement to evidence-backed investigation.
Seven stages, one continuous loop. VikingIntel watches the accounts you put under watch, turns anomalies into evidence-backed investigations, and keeps watching after the incident is contained.
Monitor → Detect → Triage → Investigate → Verify → Respond → Watch
Watch the assets that matter.
See what moved, and why it is unusual.
Decide what is worth investigating.
Turn an alert into a timeline.
Separate facts from inference.
Hand off with evidence, not screenshots.
Keep watching after the incident.
Watch the assets that matter.
Continuous watch over treasury wallets, protocol authority, and the accounts that hold critical value. A change in expected behavior is the trigger — not another generic alert you have to triage by hand.
- Continuous watch on treasury wallets, protocol authority, and critical accounts
- Behavior-based detection rules that fire when activity deviates
- Alerts with context attached — not a bare notification
- NormalTreasury_112.4M USDC · 4 signers
- WatchingAuthority multisigowner set · threshold 3
- NormalCold wallet 7xKX…4nQpidle 8 months
- NormalLiquidity pool vaultbridged assets
Illustrative example — mock accounts and statuses.
See what moved, and why it is unusual.
Detection rules and behavior models flag the patterns that precede incidents: unexpected treasury transfers, new recipients, dormant wallets waking, authority changes, and bridge movement.
- Signals for treasury transfers, new recipients, dormant activation, suspicious funding, bridge movement, and authority changes
- Severity and a stated reason for every signal
- Existing context folded in before the signal reaches you
12.4M USDC · treasury_1 → 8qLm…2kDe · 14:32:04Z
Amount exceeds the authorized threshold by 14×. Recipient has no history with this treasury.
Illustrative example — mock signal with mock amounts and addresses.
Decide what is worth investigating.
Severity, affected assets, and blast radius sort the noise into a short list a human actually reads. Most signals never need an investigation; the ones that do arrive with context attached.
- Priority from severity and exchange proximity
- A short list a human actually reads
- Most signals never become investigations
- Unexpected treasury transferHighInvestigate
- Dormant wallet activationHighInvestigate
- Fan-out to many destinations · 84 addrMediumWatch
- Bridge movement · out-of-patternLowDismiss
Illustrative example — mock queue, severities, and actions.
Turn an alert into a timeline.
Fund flow, related wallets, affected assets, and evidence families combine into findings with confidence — a timeline of what happened, who touched it, and where the money went.
- A reconstructed timeline of the incident
- Fund flow traced to an actionable destination
- Related wallets, affected assets, findings, and confidence — under one case
- Public-source evidence from project websites, domains, and repositories — where available
Trace passes through a known exchange — signal cut, not counted.
Compromised wallet and 6 downstream wallets share an uncommon fee-payer sequence.
Splitting window of 90 seconds across 84 addresses.
- Observed — 12.4M USDC left treasury_1 at 14:32:04Z, authority was intact.
- Attributed — the destination matches a verified exchange entity in the registry. Shown, not assumed.
- Inferred — the 84 split addresses may share an operator. Awaiting confirmation.
Illustrative example — mock case file with mock evidence values.
Separate facts from inference.
Observed on-chain facts are held apart from derived, attributed, and inferred claims. Consequential conclusions wait for human confirmation — VikingIntel never overrides deterministic evidence.
- Observed, derived, attributed, and inferred findings — labeled separately
- Deterministic on-chain facts outrank inference
- Human confirmation gates consequential conclusions
- Public-source findings carry the same typed labels and provenance as on-chain evidence
12.4M USDC transferred from treasury_1 at 2026-08-04T14:32:04Z.
Deterministic. Never argued away.
Funds hop treasury_1 → 8qLm…2kDe → CEX deposit.
Reproducible, stamped with method and version.
CEX deposit address matches a verified exchange entity in the registry.
Only used when the link can be shown, not assumed.
The address set is likely operated by a single actor.
Never overrides facts. Never persisted unconfirmed.
VikingIntel distinguishes these levels in every finding. An inferred conclusion is labeled inferred — it is never presented as a verified fact, and it never overrides deterministic evidence.
When evidence is missing, exhausted, or ambiguous, the answer is unknown — stated plainly, never papered over with a guess. Unlabeled means unchecked; truncated means truncated.
Hand off with evidence, not screenshots.
A reviewable evidence package a protocol team, exchange, or security contact can act on — with the reasoning attached, so a decision can be checked after the fact.
- A structured case record, not screenshots
- Investigation ID, methodology, typed findings, and versioned reports
- Case decisions and snapshots preserved with provenance
- Investigation ID
- inv_8f3a2c
- Cluster ID
- sybil-cluster-0192
- Wallet count
- 41
- Classification
- Coordinated
- Confidence
- High
- Evidence families
- 3 / 4
- Entity exclusions
- 1 (Binance Hot Wallet)
- Methodology
- engine v1.1.0 · signal-family model
- Generated
- 2026-08-04T14:36:11Z
- Report hash
- sha256:9a41…e02c
Illustrative example — mock cluster, report hash, and Verified badge.
Keep watching after the incident.
Put the attacker’s wallets on a watchlist in one click. New movement raises a webhook alert with the evidence attached — the investigation does not stop when the first finding is made.
- The actor stays on a watchlist after the incident
- New movement raises a webhook alert with evidence
- The investigation continues until it is closed
The loop closes. The attacker stays on the watchlist. New movement raises a webhook alert with the evidence attached — the investigation continues from the same case file, not from zero.
Illustrative example — mock watchlist flow with mock movement.
Put the lifecycle to work.
Create a free account and start with tracing, screening, and cases — monitoring is one plan up.