Product

Investigator

A professional forensic workspace for Solana: trace funds forward and backward, profile any wallet, detect coordination, triage address lists at scale, and carry every investigation from first signature to defensible evidence bundle. Protocols, security teams, researchers, and compliance teams work in the same place.

  1. Investigate
  2. Trace
  3. Enrich
  4. Correlate
  5. Attribute
  6. Preserve evidence
  7. Report
  8. Monitor

Tracer

Forward and backward fund-flow tracing with documented depth budgets. Hops are labeled against the verified destination registry; unlabeled addresses are shown as unlabeled.

Wallet intelligence

Per-wallet profile: first/last seen, counterparties, balance history, trading fingerprint, and an async composite risk score with per-component detail, confidence, and explanation.

Bulk triage

Paste a large address list — a heist's cashouts, a suspicious distribution — and rank it by exchange proximity with per-address hit detail. Pro plan.

Cases

The investigation record: wallets/clusters/tokens as items, notes, decisions, typed findings (OBSERVED / DERIVED / ATTRIBUTED / INFERRED), pins, saved queries, and snapshots.

Timeline & entity graph

Chronological merge of fund-flow hops, alerts, and cluster events across everything in the case — plus a persisted entity graph of the surrounding cluster structure.

Evidence & reports

Typed findings (OBSERVED / DERIVED / ATTRIBUTED / INFERRED) with provenance, append-only case decisions, versioned reports, and snapshots — artifacts a third party can review and verify.

Monitoring

Register a protocol's critical assets. Helius webhooks + backfill feed canonical chain events into deterministic detectors that raise incident alerts and notify your webhook.

Copilot & API

An investigation copilot over case data, a documented OpenAPI surface with tiered keys, weighted credit metering, and burst + sustained rate limits.

OSINT enrichment

Enrich an investigation with public-source evidence from project websites, domain infrastructure, repositories, and public identities — each piece carrying its source, timestamp, and confidence.

OSINT enrichment

Investigate beyond the blockchain.

Start with a Solana address or investigation and enrich it with publicly available evidence from project websites, domains, infrastructure, repositories, and public identities. When public evidence exists, VikingIntel surfaces it alongside on-chain intelligence.

What VikingIntel preserves

  • Source — which collector or website produced this finding
  • Timestamp — when the evidence was collected
  • Evidence type — observed, attributed, derived, or inferred
  • Provenance — the collector version and evidence builder metadata
  • Staleness — flagged when data is more than 30 days old
  • Confidence — when available, per-evidence confidence score

From evidence to inference

ObservedWebsite publicly lists wallet X
ObservedWebsite links repository Y
ObservedRepository contains a Solana address in commit history
DerivedIndependent evidence supports the relationship
InferredRelationship may be relevant to the investigation

The last step is not equivalent to ownership proof. It is an analytical judgment that warrants further review.

Evidence discipline

Built so conclusions survive review

Every analytical claim carries its type, its confidence, and its provenance — and absence is stated honestly instead of papered over.

Findings carry OBSERVED / DERIVED / ATTRIBUTED / INFERRED labels. Auto-materialized detections stay distinct from analyst conclusions — badge colors differ so the taxonomy never blurs.

Typed claims everywhere

Composite risk ships per-component detail, top-level confidence, a plain-language explanation, and computedAt — because a score without a why is how false positives ship unnoticed.

Confidence with provenance

Unscored wallets say "not evaluated"; unknown destinations say "unlabeled"; truncated traces say TRAIL_TRUNCATED. Absence is stated, never papered over.

Honest absence

Also in the workspace

Watchlists with webhook notifications, wallet comparison, token mint lineage and holder concentration, deposit-sweep candidate harvesting, private researcher labels that override the shared registry inside your own traces, transaction lookup, global search, and curated Labs tools (Reputation Check, Trace, Consolidation Scan).

Open the workspace

Free accounts include tracing quota, screening, cases, and the full investigator loop.