Cryptocurrency artifact detection for recovering cryptocurrency assets
The system automatically detects and verifies cryptocurrency artifacts like seed phrases and keys, addressing inefficiencies in existing forensic methods by ensuring accurate and timely recovery of lost assets while preventing fraudulent transactions.
Patent Information
- Application Number
- PCT/US2024/031991
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-03
- Filing Date
- 2024-05-31
- Publication Date
- 2025-10-09
AI Technical Summary
Current cryptocurrency forensic solutions are inefficient and prone to human error in identifying unknown cryptocurrency artifacts and assets, as they require manual expertise and cannot automatically trace unknown blockchain addresses.
A system and method for automatically detecting cryptocurrency artifacts such as seed phrases and public/private keys by scanning digital data, using multi-pass validation tests to verify their validity and activity on the blockchain, enabling efficient and accurate recovery of lost or stolen assets.
Automated cryptocurrency forensics efficiently and accurately recover assets by reducing human error, enabling real-time detection and prevention of fraudulent transactions, and ensuring accountability through secure chain of custody logging.
Smart Images

Figure US2024031991_09102025_PF_FP_ABST
Abstract
Description
Attorney Docket No. P-636557-PC CRYPTOCURRENCY ARTIFACT DETECTION FOR RECOVERING CRYPTOCURRENCY ASSETS Field of the Invention
[0001] Embodiments of the invention relate to cryptocurrency forensics and, in particular, to detecting cryptocurrency artifacts to recover unknown, lost or stolen cryptocurrency assets. Background of the Invention
[0002] Law enforcement agencies routinely seize physical assets such as stolen goods, illegal drugs, weapons, and / or currency. With cryptocurrencies however, there are no physical assets to seize.
[0003] By design, cryptocurrency is conventionally not centrally controlled so the integrity of cryptocurrency assets relies on the security and secrecy of its protocols including encryption and masking making cryptocurrency assets difficult to locate and seize.
[0004] Current state of the art solutions for cryptocurrency forensics fall into two broad categories.
[0005] A first category is general-purpose digital forensic analysis of data recovered from computers, mobile devices, or cloud backups. A trained investigator can use these tools to manually browse the forensic data for cryptocurrency artifacts, but this process requires expert knowledge to know what to look for and where to look for it. These solutions can not automatically identify unknown cryptocurrency artifacts. This manual process is tedious, time consuming and prone to human error.
[0006] A second category is tracking cryptocurrency transactions across accounts by analyzing blockchain records. In these solutions, investigators begin with known blockchain addresses; they do not identify unknown addresses. Given a known blockchain address, investigators can then trace the flow of cryptocurrency transactions to other addresses. These solutions fail when blockchain addresses are not known.
[0007] Accordingly, there is a longstanding need in the art for a cryptocurrency forensic solution that automatically identifies unknown cryptocurrency artifacts and assets.Attorney Docket No. P-636557-PC Summary of the Invention
[0008] A cryptocurrency forensic solution solves this longstanding need in the art by providing a cryptocurrency artifact search that automatically scans digital data for cryptocurrency artifacts that are byproducts of using cryptocurrency assets. Cryptocurrency artifacts include digital wallets, public / private keys pairs for encrypting / decrypting the assets, seed phrases used to recover the key pairs, etc. Cryptocurrency assets that are unknown leave behind data trails of those cryptocurrency artifacts. Embodiment of the invention automatically trace these cryptocurrency artifacts to automatically locate and recover unknown, lost or stolen cryptocurrency assets.
[0009] An embodiment of the invention provides a device, system, and method for automatically searching for cryptocurrency artifacts that are seed phrases to recover cryptocurrency assets. Digital data (e.g., raw files or text-converted data) suspected to contain unknown cryptocurrency artifacts may be ingested. At one or more local seed phrase detector processors, the digital data may be searched to detect one or more candidate seed phrases. Each candidate seed phrase may include a permutation of words all in a single predetermined seed phrase library consecutively listed in a sequence having a fixed length predetermined according to a cryptocurrency standard. Each candidate seed phrase may be tested to determine if it is a valid seed phrase configured to recover a public and private key pair used to control a cryptocurrency asset. A multi-pass seed phrase validation test may include: executing a first pass (e.g., at the one or more local seed phrase detector processors) comprising verifying a checksum of one or more words in the candidate seed phrase, and, upon verifying the first pass, executing (or requesting and receiving the result of executing at one or more external cryptocurrency processors), a second pass comprising verifying in a blockchain if there has been activity using a cryptocurrency asset encrypted using a public key in a key pair recovered from the candidate seed phrase. Upon verifying the valid seed phrase, cryptocurrency assets may be recovered using a private key in the key pair.
[0010] An embodiment of the invention provides a device, system, and method for automatically searching for cryptocurrency artifacts that are public or private cryptocurrency keys to recover cryptocurrency assets. At one or more local address / public key or private keyAttorney Docket No. P-636557-PC detector processors, the digital data may be searched to detect one or more candidate public or private keys. Each candidate public or private key includes a permutation of alphanumeric characters consecutively listed in a sequence having a fixed length or beginning with a preliminary alphanumeric sequence predetermined according to a cryptocurrency standard. Each candidate public or private key may be tested to determine if it is a valid public or private key configured to identify, or execute transactions with, a cryptocurrency asset. A multi-pass key validation test may include: executing a first pass (e.g., at the one or more local public or private key detector processors) comprising verifying a checksum of at least some of the alphanumeric characters in the candidate public or private key, and upon verifying the first pass, executing (or requesting and receiving the result of executing at the one or more external cryptocurrency processors) a second pass comprising verifying in a blockchain if there has been activity using a cryptocurrency asset encrypted using the candidate public key or a public key corresponding to the candidate private key. Upon verifying the valid public or private key, cryptocurrency assets may be recovered using the private key in the key pair. Brief Description of the Figures
[0011] The subject matter regarded as the invention is particularly pointed out and distinctly claimed in the concluding portion of the specification. The invention, however, both as to organization and method of operation, together with objects, features, and advantages thereof, may best be understood by reference to the following detailed description when read with the accompanying drawings in which:
[0012] Fig.1 is a schematic illustration of a system for detecting cryptocurrency artifacts to recover cryptocurrency assets, in accordance with some embodiments of the invention;
[0013] Fig. 2 is a schematic illustration of a user interface visualizing results of a cryptocurrency artifact search, in accordance with some embodiments of the invention;
[0014] Fig.3 is a schematic illustration of a system for detecting cryptocurrency artifacts to recover cryptocurrency assets, in accordance with some embodiments of the invention; and
[0015] Fig. 4 is a flowchart of a method for detecting cryptocurrency artifacts to recover cryptocurrency assets, in accordance with some embodiments of the invention.Attorney Docket No. P-636557-PC
[0016] It will be appreciated that for simplicity and clarity of illustration, elements shown in the figures have not necessarily been drawn to scale. For example, the dimensions of some of the elements may be exaggerated relative to other elements for clarity. Further, where considered appropriate, reference numerals may be repeated among the figures to indicate corresponding or analogous elements. Detailed Description of the Invention
[0017] Cryptocurrency assets, even when hidden or unknown, leave behind a trail of associated cryptocurrency artifacts as byproducts to use those assets. A cryptographic forensic tool is provided to automatically detect those cryptocurrency artifacts and use those artifacts as seeds to follow this trail to locate their associated cryptocurrency assets, generate or repair cryptocurrency tools to control the assets, and / or recover or seize the assets.
[0018] Automated cryptocurrency forensics provides efficient, consistent and accurate recovery of assets solving problems of conventional labor intensive manual processes subject to inconsistencies in human expertise and prone to human errors. Automation and parallelization allows real-time cryptocurrency artifact detection enabling pre-emptively preventing transactions or actions on cryptocurrency assets before they occur when the assets (or their associated artifacts) are detected as fraudulent. A pre-emptive fraud prevention action may include, for example, canceling or delaying an in-progress transaction on the asset before it is executed, canceling or delaying future downstream transactions on the asset before they are committed, altering or escalating the security requirements associated with executing transactions on the asset (e.g., requiring two-form authentication), quarantining or seizing the asset and / or accounts associated with the asset or owner(s), sending fraud detection alerts to fraud investigators or enforcement, etc. In addition, assets often become increasingly difficult to recover as time grows because transacting and / or masking those assets may escalate over time. Accordingly, it becomes increasingly (e.g., exponentially) more difficult to recover assets the longer it takes, or in some cases impossible past a critical point in time (e.g., after a divestment in those assets). Automation and parallelization of cryptocurrency artifact detection thus not only recovers assets quantitatively faster than a human, but also qualitatively recovers more assetsAttorney Docket No. P-636557-PC (e.g., capturing assets which, subject to human review, would be beyond recovery and lost forever). Automated cryptocurrency forensics further records a forensic chain of custody logging access to cryptocurrency artifacts and / or assets to interrogate and prove compliance of the forensic tools themselves. This solves accountability problems of conventional forensics, such as, the lone wolf problem, in which a forensic officer without oversight may hide their own illicit activity (e.g., overlooking evidence or stealing assets themselves).
[0019] Reference is made to Fig.1, which schematically illustrates a system for detecting cryptocurrency artifacts to recover associated hidden or unknown cryptocurrency assets, in accordance with some embodiments of the invention. The system of Fig. 1 may operate using devices or components described in reference to Fig.3. For security, the cryptocurrency artifact search may be executed at one or more secure processor(s), for example, entirely or partially executed within a secure or air-gapped computer (e.g., 144 of Fig.3) or network (e.g., 100 of Fig. 3) or entirely or partially outside a secure or air-gapped computer or network in encrypted, encoded or otherwise masked form (e.g., executed remotely over the cloud under FHE). Cryptocurrency recovery in Fig. 1 may be fully-automated or semi-automated via control by a user (e.g., a fraud or forensic investigator) operating a device 2, e.g., using a one-click asset seizure protocol.
[0020] A cryptocurrency artifact search according to embodiments of the invention may initiate by identifying and ingesting digital data 8 (e.g., raw files) retrieved by one or more processor(s) 6 (e.g., file processor) from storage in a digital data source(s) 4 (e.g., a file server). The cryptocurrency artifact search may initiate automatically or prompted by an investigator via a computer interface on device 2. The ingesting digital data 8 may be obtained by various external sources including, for example, data extractions from seized computer(s), mobile device(s) or cloud backups, linked to local or cloud account(s) for user(s) or entit(ies) under investigation, etc. The digital data 8 may be uploaded to digital data source(s) 4 automatically or by an investigator via the computer interface. Processor(s) 6 may then recursively process and parse disk images, file system formats, and archives, to extract and store the constituent raw files for analysis. The ingested digital data 8 may be stored in database(s) in permanent or temporary secure storageAttorney Docket No. P-636557-PC unit(s) (e.g., database(s) 115 of Fig.3 stored on an air-gapped computer, secure USB flash drive, or other secure hardware storage unit(s)).
[0021] After storing, or in real-time as the digital data 8 is ingested, the digital data 8 may be filtered, e.g., by data type, such as format, file or application type, to retain predetermined target data types suspected or likely to contain cryptocurrency artifacts (and / or delete, omit or ignore the remaining data types unlikely or not suspected to contain cryptocurrency artifacts). Filtering out data types of digital data unlikely to contain cryptocurrency artifacts may significantly reduce the memory usage and computational load of the search. Data types may be determined by their extension type (e.g., .doc is a text document, .jpg is an image, etc.), data signature (e.g., representing the first six bytes indicative of a file type), a machine learning (ML) model trained on verified data-datatype input-output pairs, or other tests of data type. In some embodiments, data type may be determined by multiple tests, executed in parallel or in sequence, e.g., in multiple respective passes. In one embodiment, a multi-pass data type test may include a first pass test determining data type by extension and a second pass test determining data type by signature. In one embodiment, the second pass may be selectively skipped when the first pass test is positive (executed only when the first pass test is negative), for example, to reduce redundant testing and increase program speed and efficiency. In another embodiment, the second pass may be executed even when the first pass test is positive to validate or invalidate the first pass test (e.g., detect if an extension type was fraudulently altered to hide relevant files). Different data types detected in the first and second passes may cause the data to be flagged or prioritized for searching.
[0022] The retained data types may be parsed to convert into computer-readable data format(s), such as any one or combination of: plaintext, encoded, hashed, masked, encrypted (e.g., under homomorphic encryption (HE), such as fully HE (FHE)) or other format(s). A text converter 10 (e.g., a processor executing optical character recognition (OCR) and / or a ML model) may convert non-text files (e.g., images with machine or handwritten text, QR codes, etc.) of the ingested digital data 8 into text files 12. A ML model or large language model (LLM) may be used to restore damaged or missing text, e.g., adding, deleting or correcting words caused by hardware, software, file or text converter 10 (e.g., OCR) errors.Attorney Docket No. P-636557-PC
[0023] In some embodiments, the cryptocurrency artifact search may triage or order the ingested data 8 for review / analysis and / or storage prioritized according to their likelihood of containing cryptocurrency artifacts, e.g., based on data type, fraud flags or ratings, etc. Ordering the data sources searched based on their likelihood of containing artifacts may increase speed and efficiency of finding those artifacts. In one example, cryptographic wallets (e.g., having a relatively high likelihood of containing crypto assets) may be prioritized above and reviewed prior to word documents (e.g., having a relatively lower likelihood to contain crypto assets). Additionally or alternatively, ingested data 8 may be searched in the order in which crypto objects expected therein are needed to recover crypto assets, e.g., first searching data types likely to contain cryptocurrency artifacts, then cryptocurrency recovery tools associated with those artifacts, and finally cryptocurrency assets recovered with those tools. In some embodiments, the cryptocurrency artifact search may parallelize its processes across a network of multiple processors or servers to increase speed and efficiency. Parallelization may be toggled off to serialize processes that depend on each others’ outputs (e.g., reconstructing a full seed phrase may precede and is not parallelized with using full seed phrases to recover key pairs).
[0024] In some embodiments, a seed phrase detector 14 may automatically scan the digital data for a cryptocurrency artifact that is a cryptocurrency seed / recovery phrases, which is a human-readable mnemonic sequence of words used to encode and recover a public / private key pair to control cryptocurrency assets or accounts. The seed phrase detector 14 may search text (in original or (e.g., OCR) converted ingested digital data stored in raw file 8 database or text 12 database, such as, digital wallet(s), password manager(s), word file(s), text-converted QR code(s)) for predefined keywords from one or more seed librar(ies). The seed phrase detector 14 may search for combinations of all permutations of words from a single predetermined seed phrase library that are consecutively listed in a sequence of a predetermined fixed length (or in a range of lengths), where the predetermined library and predetermined sequence length (or range of lengths) are predefined according to the same cryptocurrency protocol or standard. For example, the Bitcoin Improvement Proposal (BIP 39) standard defines a sequence length of 12 or 24 word seed phrases selected from a library of 2,048 words, although other seed libraries, phrase lengths and formats used by other cryptocurrencies may additionally or alternatively beAttorney Docket No. P-636557-PC used. The seed phrase detector 14 may search, according to multiple cryptocurrency protocols, for seed phrases associated with multiple protocol libraries and multiple corresponding respective sequence lengths (or ranges). Seed phrases are commonly hidden (e.g., buried in text files, split into different documents, ordered backwards, or otherwise obfuscated) as their possession allows full control of associated assets. Since seed phrases are generally linguistically nonsensical random combination of words (e.g., carpet, cat, flower, chair, foot, river, make, image, amazing, three, say, shoe), the seed phrase detector 14 in some embodiments may additionally analyze the linguistic context of candidate seed phrases (or the entire text files) to detect sequences of words that do not make linguistic sense (e.g., do not match next word(s) prediction using large language model (LLM) or other machine learning (ML) models), break a set of predefined grammatical rules, or have an above threshold measure of grammatical or linguistic randomness. The seed phrase detector 14 may define a confidence metric that a sequence of words is a seed phrase to be directly proportional to the randomness or incoherence of the linguistic or grammatical context (or inversely proportional to the coherence of the linguistic or grammatical context). Additionally or alternatively, the confidence metric may be directly proportional to the length of the candidate (or partial) seed phrase, directly proportional to a visual randomness of the surrounding image, screen shot, etc., and / or measured based on a location or data type context of the file location or file type in which the seed phrase was found (e.g., some locations or types having more or less likelihood of containing seed phrases). The confidence metric may be used to weigh the likelihood that a candidate phrase is a seed phrase. The confidence metric may be used to order the candidate phrases for analysis (e.g., in descending order of their likelihood to be a seed phrase), as a pre or post processing filter to add or remove phrases as candidates that are within or outside a range predefined for seed phrase linguistic context, serve as basis for increased or decreased validation tests (e.g., a single pass candidate validation test for an above threshold confidence metric and a multi-pass candidate validation test for a below threshold confidence metric), as an error margin to inform an investigator of the automated forensic certainty, etc.
[0025] In some cases, the digital data may contain partial seed phrases, for example, to hide or mask a full seed phrase by splitting it up into multiple partial seed phrases (e.g., a 12-word seedAttorney Docket No. P-636557-PC phrase divided into two strings of 6 phrases, 3 strings of 4, etc.) or to omit a word to obfuscate the seed phrase or due to damaged files (e.g., a string of 11 of 12 or 23 of 24 words omitting one word in the phrase). The seed phrase detector 14 may search for partial cryptocurrency seed / recovery phrases, each of which is an incomplete subset of words of a full cryptocurrency seed / recovery phrase that alone as a partial phrase cannot, but when combined into the full phrase can, be used to recover a public / private key pair to control cryptocurrency assets. Each partial seed phrase may have fewer words than the number predetermined for a full length seed phrase of its cryptocurrency type, but at least a multiple minimum number of words (e.g., 2, 3, 4, …). In some embodiments, the seed phrase detector 14 may determine whether a partial phrase (e.g., a word sequence of length less than the predetermined seed phrase length(s)) qualifies as a candidate partial seed phrase based on a combination of factors, such as its word length (e.g., the longer a phrase is that contains exclusively seed library words, the more likely it is to be a seed phrase), its linguistic context (e.g., the less grammatically or linguistically correct a phrase is, the more likely it is to be a seed phrase) and / or other factors. In one example, the seed phrase detector 14 may compute, for each partial phrase, a weighted sum based on its word length, confidence metric, etc. and only phrases with a weighted sum within a range may be considered and analyzed as candidate partial seed phrases (ignoring the remaining phrases as false candidates). The seed phrase detector 14 may search for partial seed phrases as combinations of all permutations of words from a single predetermined seed phrase library that are consecutively listed in a sequence of within a predetermined fixed range of lengths (e.g., greater than a minimum length of multiple words, e.g., > 2, 3, 5, etc. to increase search efficiency and decrease false positives, and up to the length of the full seed phrase). The seed phrase detector 14 may reconstruct candidate full seed phrases as all permutations of partial seed phrases into combinations which are of full predetermined seed phrase length. If a partial or recombined seed phrase is missing one or more words (e.g., 11 of 12 words or 23 of 24 words), the seed phrase detector 14 may reconstruct candidate full seed phrase by inserting and testing each word from the associated seed phrase library, either in a known missing position(s) or testing all possible missing position(s), and performing checksum validation to confirm the reconstructed seed phrase is valid. In one embodiment, this brute force approach of searchingAttorney Docket No. P-636557-PC for missing words may be executed up to a maximum number of missing words (e.g., 1-3) above which the computations become prohibitively time-consuming and computationally intensive).
[0026] Once candidate seed phrases of this format are found or reconstructed each candidate seed phrase may be tested to determine if it is valid, e.g., able to control a real cryptocurrency asset. In some embodiments, multiple validation test may be used. In one embodiment, the seed phrase detector 14 may test each candidate seed phrase for proper protocol format, e.g., using checksum verification (e.g., verifying if the checksum of the first (n- 1, e.g., 11 of 12) words of the seed phrase matches the checksum of the last (nth, e.g., 12th) word of the seed phrase). Additionally or alternatively, e.g., at the request of the seed phrase detector 14, the cryptocurrency processor 16 (e.g., Blockchain processor) may validate or invalidate that the candidate seed phrase is associated with real cryptocurrency assets by determining if there is any activity (e.g., transactions) logged in a cryptocurrency database 18 using an address (public key) recovered using the candidate seed phrase. In some embodiments, the cryptocurrency processor 16 queries the cryptocurrency database 18 based on historic cryptocurrency activity up to a current time and / or may add an alert request to send a signal upon detecting future cryptocurrency activity using the address. The cryptocurrency processor 16 may convert the candidate seed phrase into an address (e.g., a public key in a key pair derived from the seed phrase). The cryptocurrency processor 16 may then search a cryptocurrency database 18 (e.g., blockchain cache) for an index associated with the address. If an index associated with the address exists, at least one cryptocurrency asset associated with that address / seed phrase exists and the seed phrase is validated as real. If however no index associated with the address exists, then no cryptocurrency asset is associated with the address / seed phrase and the seed phrase is invalidated as a false positive.
[0027] In some embodiments, the multiple validation tests may be staged as a multi-pass or multi-tier test to optimize both computational speed and accuracy. For example, a multi-pass test may validate candidate seed phrases by, for each candidate, executing a first pass validation comprising the format (checksum) test and, only if positive, executing a second pass validation comprising checking the logged asset activity. A candidate may be validated as a real seed phrases only upon testing positive for both passes. The first pass is a relatively fast and efficient test toAttorney Docket No. P-636557-PC exclude the vast majority of false positives locally (e.g., at the seed phrase detector 14) as compared to the second pass that is relatively less efficient as it relies on transmission to and execution by an external system (e.g., cryptocurrency processor 16) and searching a typically large database of transactions (e.g., querying database 18). The second pass on the other hand identifies real-world seed phrases and so is significantly more accurate (e.g., 1 in 1036, i.e., 1 in an undecillion, probability of a false positive) compared to the first pass checksum test (e.g., 1 in sixteen probability of a false positive). Executing the multi-pass test optimizes both efficiency (eliminating executing the less efficient second-pass test on the majority of false positive candidates eliminated by the more efficient first-pass) and accuracy (executing the full accuracy second pass for all viable candidate seed phrases).
[0028] Once a valid seed phrase is found under a first cryptocurrency protocol (e.g., BIP39), seed phrase detector 14 may derive additional artifacts, assets, accounts and / or addresses using additional cryptocurrency protocol(s) (e.g., BIP44 or legacy derivation methods).
[0029] All validated seed phrases are automatically output by the system as cryptocurrency artifacts (e.g., “Seed Phrases” visualized in the user interface of Fig. 2 on user device 2 of Fig. 1). Conversely, the seed phrase detector 14 may ignore, omit or delete all non- seed phrase text (word combinations that are not in the library, do not have non-predetermined phrase lengths and / or do not pass the candidate seed phrase validation test(s)), for example, eliminating the extraneous data as noise.
[0030] The validated seed phrases may be used to access or control their associated cryptocurrency assets. In one embodiment, the cryptocurrency processor 16 may transfer the address (public key) generated based on the validated seed phrase(s) (only, and not the invalidated seed phrases) to the blockchain 20, from which the cryptocurrency processor 16 may request and receive information on (e.g., a balance of) assets encrypted with the address and / or associated user(s), wallet(s), account(s), or other data structures or entities. Additionally or alternatively, the cryptocurrency processor 16 may transfer the private key generated based on the validated seed phrase(s) to the blockchain 20 to control, transact or seize assets decrypted with the private key and / or associated user(s), wallet(s), account(s), or other data structures or entities.Attorney Docket No. P-636557-PC
[0031] In some embodiments, an address / public key detector 22 or private key detector may automatically scan the ingested digital data for a cryptocurrency artifact that is a cryptocurrency address / public key and / or private key. An address / public key is configured to query and read transactions for, but not execute transactions with, a cryptocurrency asset, while a private key is configured to control, recover and seize those assets. Because some blockchains have different public or private key formats, the address detector 22 or private key detector may also be able to associate an address or private key with its specific blockchain. The address detector 22 or private key detector may search text (in original or (e.g., OCR) converted ingested digital data stored in raw file 8 database or text 12 database, such as, digital wallet(s), password manager(s), word file(s), text-converted QR code(s)) for a permutation of alphanumeric characters consecutively listed in a sequence having a fixed length (or within a range of lengths) or beginning with a preliminary alphanumeric sequence or prefix predetermined according to a cryptocurrency standard. The address detector 22 or private key detector may search for addresses or private keys of multiple different lengths and / or prefixes predetermined according to multiple respective protocols. The address detector 22 or private key detector may also search text for partial addresses or private keys (e.g., of less than the predetermined length for a protocol) and combine multiple partial addresses or private keys or insert missing alphanumeric characters therein to reconstruct a full length address or private key. Some standards may have a checksum test that may be used in a first pass to validate the address or private key before testing blockchain activity in a second pass associated with the key. At the request of the address detector 22 or private key detector, the cryptocurrency processor 16 (e.g., Blockchain processor) may validate or invalidate that the candidate address or private key is associated with real cryptocurrency assets by determining if there is any activity (e.g., transactions) logged in a cryptocurrency database 18 using the address (e.g., linked to the private key in its key pair). For example, the cryptocurrency processor 16 may search a cryptocurrency database 18 (e.g., blockchain cache) for an index associated with the address. If an index associated with the address exists, at least one cryptocurrency asset associated with that address (and / or its associated or private key) exists and the address or private key is validated as real. If however no index associated with the address exists, then no cryptocurrency asset is associated with theAttorney Docket No. P-636557-PC address (and / or its associated or private key) and the address or private key is invalidated as a false positive. All validated addresses or private keys are automatically output by the system as cryptocurrency artifacts (e.g., “Addresses” visualized in the user interface of Fig.2 on user device 2 of Fig. 1). The validated addresses may be used to query and review information for (e.g., a balance associated with) their associated cryptocurrency assets, and validated or private keys may be used to control and recover / seize those assets. In one embodiment, the cryptocurrency processor 16 may automatically transfer the validated address (public key) or private key to the blockchain 20, from which the cryptocurrency processor 16 may request and receive information on (e.g., a balance of) assets encrypted with the address and / or associated user(s), wallet(s), account(s), or other data structures or entities. The cryptocurrency processor 16 may transfer the validated private key to the blockchain 20 to control, transact or seize assets decrypted with the private key and / or associated user(s), wallet(s), account(s), or other data structures or entities.
[0032] The seed phrase detector 14, address detector 22 and / or private key detector may each use an Application Programming Interface (API) in the cryptocurrency processor 16 to validate artifacts, detected accounts, and derived addresses. The cryptocurrency processor 16 may also access cryptocurrency balances and transactions from the blockchain 20. The blockchain 20 data may also be redundantly stored in the cryptocurrency database 18 to access the data locally or more proximally and / or avoid round-trip network access calls to the blockchain 20 to improve speed and efficiency of data requests and responses.
[0033] In some embodiments, a web address detector 24 may automatically scan the ingested digital data for a cryptocurrency artifact that is a cryptocurrency web address (e.g., domain name / host name / URL / IP address) matching those in a watchlist of known cryptocurrency web addresses. Web address detector 24 may scan digital data with data types suspected or likely to store web addresses, such as, files containing cookies, browser histories, or email addresses. Detecting a web address access in the digital data may indicate that a user, computer, account or entity associated with that digital data is suspected or likely to have assets and artifacts associated with the cryptocurrency type supported by that web address. Detecting a web address access may automatically trigger a search of, or raise the priority of searchingAttorney Docket No. P-636557-PC (reordering search data files to search earlier), digital data with a type associated with the cryptocurrency supported by that web address. For example, detecting a metamask web address access may trigger (or raise priority of) searching metamask files for metamask artifacts. All detected web address are automatically output by the system as cryptocurrency artifacts (e.g., “Domains” visualized in the user interface of Fig.2 on user device 2 of Fig.1).
[0034] In some embodiments, a software application detector 26 may automatically scan the ingested digital data for a cryptocurrency artifact that is a cryptocurrency software application (e.g., a cryptocurrency wallet, a cryptocurrency exchange, a cryptocurrency service, a cryptocurrency mining application, etc.) having a file type, name or data structure matching those associated with a watchlist of known cryptocurrency software applications. The software application detector 26 may search, e.g., based on the operating system (OS), target locations where applications are known to be stored. Once an application in the target location is detected that matches one in the cryptocurrency software application watchlist, the system may automatically (or upon user request) attempt to gain access to the application and / or account under investigation. In one example, for wallets that do not limit the number of password attempts, the system may cycle through passwords to gain access to the wallet. In another example, the system may search for cryptocurrency artifacts that are application passwords and insert candidate detected application passwords into the detected software application to automatically gain access to the application and its assets and artifacts (e.g., access to a cryptocurrency wallet may gain control of the wallet’s assets and its seed phrase). All detected software application are automatically output by the system as cryptocurrency artifacts (e.g., “Applications” visualized in the user interface of Fig.2 on user device 2 of Fig.1). The system may automatically gain access to the software application (e.g., cryptocurrency wallet) as well as its assets and artifacts (e.g., cryptocurrency assets in the wallet and seed phrase artifact) that may be used to control, transact or seize those assets and / or associated software application(s), account(s), or other data structures associated with the detected software application.
[0035] In some embodiments, a hardware (e.g., USB) connection detector 28 may automatically scan hardware connection logs in the digital data for a cryptocurrency artifact that is a hardware connector identification (e.g., a Vendor Identification (VID) and / or ProductAttorney Docket No. P-636557-PC Identification (PID)) matching those in a watchlist of known registered cryptocurrency hardware devices (e.g., a dedicated flash drive cryptocurrency wallet comprising a wallet on secure chip), indicating a device under investigation was connected to the known registered cryptocurrency hardware device. The hardware connection detector 28 may search target locations where hardware connections are known to be logged (e.g., USB log files) for records of past connection to the watchlist devices (e.g., by cryptocurrency vendor and product ID (VID / PID). The hardware connection detector 28 may alert an investigator to a device (e.g., identified by VID / PID) containing missing, lost or stolen cryptocurrency assets. Finding a hardware connector identification may trigger the system to search for other artifacts (e.g., private keys, applications, etc.), accounts or assets associated with the same cryptocurrency type of the detected hardware. Each cryptocurrency type has a different protocol and so may trigger a different model to search for its associated artifacts, accounts or assets (e.g., N types of cryptocurrency flash wallets each trigger a different one of N respective models to search). Each of the cryptocurrency-specific models may search for specific seed phrases (e.g., using different seed libraries), address types, domains, applications, etc. All detected hardware connections are automatically output by the system as cryptocurrency artifacts (e.g., “USB Devices” visualized in the user interface of Fig. 2 on user device 2 of Fig.1).
[0036] Detectors 14, 22, 24, 26 and / or 28 may run in parallel or in series, for example, collaboratively such that the output of one detector triggers an action in another detector. In one example, artifacts detected in one or more type(s) of cryptocurrency by web address detector 24, software application detector 26 and / or hardware connection detector 28 (e.g., detecting an application for 5 types of cryptocurrency wallets) may trigger seed phrase detector 14 and / or address detector 22 to search for artifacts according to the formats or protocols of those cryptocurrency type(s) (e.g., detecting 3 domains, 2 software applications and 1 hardware connection in 5 different cryptocurrency protocols may automatically trigger seed phrase detector 14 to search for seed phrases in 5 cryptocurrency-specific seed phrase libraries and with 5 cryptocurrency-specific word sequence lengths and / or address detector 22 to search for addresses in those corresponding 5 protocols).Attorney Docket No. P-636557-PC
[0037] Detectors 14, 22, 24, 26 and / or 28 may each output artifacts stored in an artifact database 30 (e.g., Artifact Results) in one or more permanent or temporary secure storage unit(s) (e.g., database(s) 115 of Fig. 3 or stored on an air-gapped computer, secure USB flash drive, or other secure hardware storage unit(s)).
[0038] An application server 32 may output and display the detected cryptocurrency artifacts (stored in artifact database 30) on user device 2. Application server 32 may include a machine learning (ML) or deterministic (e.g., decision tree) model trained to input the detected artifacts and automatically output a forensic summary of the detected artifacts and / or assets. The forensic summary may include an indication of whether or not one or more target user(s), account(s), case(s), digital dataset(s) or file(s), device(s), network(s), and / or entit(ies) contain detected cryptocurrency artifacts, assets or information, an listing of the detected artifacts (e.g., as shown in Fig. 2), the type(s) or protocols of detected cryptocurrency(ies), detected cryptocurrency or fiat values, access to detailed information related to the detected artifacts, a human-readable story describing a temporal sequence of events associated with the detected artifacts and / or associated assets, owners, accounts or entities, executable actionable tasks that are automatically executed and / or recommended to recover unknown, lost or stolen cryptocurrency assets (e.g., quarantining or seizing assets, canceling or delaying in-progress or pre-emptively preventing future transactions on the assets, recovering detected hardware (e.g., USB flash wallets), etc.). In some embodiments, the application server 32 may generate interactive data, e.g., including a user prompt (via device 2), such that the user may ask questions of, and receive responses from, application server 32 (such as, e.g., “show me seizable assets,” “How do I seize this asset?,” etc.). The application server 32 may generate the forensic story and or interactive responses using a forensic summary model stored in application data 34 that may include one or more transformers to generate words to input into pre-written templates or a large language model (LLM) to generate the summary using next word prediction. The application server 32 may also utilize stored application data 34 to provide additional management workflows including user management, case management, and chain of custody oversight features. In some embodiments, oversight features may require a witness prior to accessing theAttorney Docket No. P-636557-PC exhibit details and / or send a notification to an investigator’s supervisor that a case with private key material is being accessed.
[0039] Embodiments of the invention may provide fully-automated or semi-automated, e.g., one-click, asset seizure. In one embodiment, the system of Fig.1 may automatically execute the dataflow described herein and indicated by arrows in Fig. 1 to automatically detect cryptocurrency artifacts. In some embodiments, the system of Fig. 1 may recover assets for which those artifacts are generated automatically or semi-automatically (e.g., using a one-click “seize assets” button). In one embodiment, detecting a seed phrase or private key may automatically or semi-automatically (e.g., using a one-click “seize assets” button) trigger the system of Fig. 1 to transfer the associated assets (e.g., in blockchain 20) to a predetermined different wallet or using a predetermined different seed phrase or private key. The cryptocurrency protocol, format or type of the predetermined seizing wallet, seed phrase or private key may be automatically selected to match that of the seized assets (e.g., as detected by detector(s) 14, 22, 24, 26 and / or 28).
[0040] In some embodiments, system operation in Fig. 1 may generate static (e.g., one- time) results or dynamic results, e.g., updated periodically or in real-time (e.g., as digital data is continuously ingested).
[0041] In some embodiments, in the system of Figs. 1 and / or 3, all hardware may be located and all processes may be executed locally in a secure computing environment (in the same physical location, such as a room, building or physical address, and / or on the same one or more device(s)) and not remotely (separated in multiple different locations, such as, at different physical addresses). In some embodiments, in the system of Figs. 1 and / or 3, a portion or all of the hardware may be located and a subset or all of the processes may be executed globally outside of a secure computing environment (e.g., the security of which is partially, below threshold or unknown). In such embodiments, system data may be encrypted, encoded, or otherwise masked to maintain the security of the data, e.g., for all of the system data or specific high-privacy data types, such as cryptocurrency artifacts and assets (such as keys, passwords, entropy, seed phrases, etc.) and / or ingested digital data filtered as suspected to contain cryptocurrency artifacts or assets, but not general data (such as ingested digital data filtered outAttorney Docket No. P-636557-PC as unlikely to contain cryptocurrency artifacts or assets, ML training data, etc.). In some embodiments, the system may be deployed as a cloud-based Software as a Service (SaaS) solution or as an on-premise software package.
[0042] In some embodiments of the invention, systems and methods provide an automated search to scour, crawl or scan ingested and / or parsed digital data to extract cryptocurrency artifacts accurately and efficiently. In some embodiments of the invention, systems and methods provide unified automated cryptocurrency forensics including: ● Automatic timely detection of cryptocurrency artifacts in digital data, e.g., collected during investigations or in real-time (e.g., as data containing the artifacts is ingested and / or transactions are executed on associated assets). Artifact detection may be validated based on historic (past) blockchain activity and / or alerts may be set up for future validation based on future activity. ● Automatic or semi-automatic (e.g., one-click) seizure of cryptocurrency assets. ● Canceling or delaying in-progress transactions (before completion) on recovered assets or assets for which detected artifacts are generated. ● Pre-emptive prevention of future predicted transactions or actions on the detected cryptocurrency assets before they occur. ● Actionable cryptocurrency asset intelligence on artifacts discovered during digital data triage. ● Agency-wide chain of custody and audit trail for sensitive and high value cryptocurrency asset discovery by personnel as they triage digital data, e.g., reducing the risk of lone wolf violations. ● Standardized workflows for the automatic seizure of cryptocurrency assets. ● Secure custody workflows for the storage of seized cryptocurrency assets.
[0043] In some embodiments of the invention, systems and methods improve the field of cryptocurrency forensics by providing: ● Automated consistent cryptocurrency forensics solving the problem of human variability in expertise yielding inconsistent results across casesAttorney Docket No. P-636557-PC ● Multi-pass artifact validation to increase accuracy and efficiency of cryptocurrency forensics by fast elimination of false positive artifacts in a first pass. Filtering ingested data to search only a subset suspected as likely to contain cryptocurrency artifacts and / or assets, selectively applying the filter by efficient and accurate multi-pass data type test, and / or search parallelization additionally or alternatively increases the speed and efficiency of cryptocurrency forensics. Deleting the remaining ingested data unlikely to contain cryptocurrency artifacts may reduce the memory and search space increasing computational search speed and decreasing memory usage. ● Redundant local blockchain data storage to avoid round-trip network access calls to the blockchain improves speed and efficiency of validating artifacts. ● Efficient cryptocurrency forensics allows real-time cryptocurrency artifact detection enabling pre-emptive prevention of current in-progress or future transactions or actions on associated cryptocurrency assets before they occur. ● Efficient cryptocurrency forensics increases the likelihood of recovering assets before they become unrecoverable, e.g., as the likelihood of divestment or irreversible obfuscation increases with time. ● Automated consistent chain of custody logging in forensic analysis provides forensic accountability and solves the lone wolf problem ● Alerts for future artifact validation based on future cryptocurrency activity ● Encrypting the digital data (e.g., under homomorphic encryption (HE), such as fully HE (FHE)) or irreversible encoding, hashing, masking or otherwise obfuscating the digital data allows automated secure cryptocurrency forensics in an insecure or unknown security computer environment.
[0044] Other or different improvements may be realized according to various embodiments of the invention.
[0045] Discoverable cryptocurrency artifacts may include applications (e.g., software crypto wallets), evidence of previously connected USB hardware wallets, blockchain addresses, URL domains for cryptocurrency websites, private and / or public keys for crypto assets, and / or seed / recovery phrases to recover those keys. These artifacts may be found in several locationsAttorney Docket No. P-636557-PC including application files, web browser bookmarks and histories, email or text messaging apps, user documents, and media files.
[0046] Cryptocurrency assets may be investigated or seized by law enforcement including national security personnel and / or investigators for criminal or civil cases. Additionally or alternatively, cryptocurrency assets may be investigated or seized by commercial and / or private organizations or their personnel. Other applications may also be used.
[0047] Reference is made to Fig. 2, which schematically illustrates a user interface visualizing results of a cryptocurrency artifact search, in accordance with some embodiments of the invention. The user interface of Fig.2 may be generated using the system of Fig.1 and / or 3, which may be output on a (e.g., forensic investigator) device 2 of Fig. 1 or computer 140 of Fig. 3.
[0048] A Main Menu pane across the top may provide application functionality, status indicators, and a search field that can be used to search for a specific query within the ingested digital data (e.g., a specific exhibit file).
[0049] The user interface may visualize search results of one or more cryptocurrency artifacts - seed phrases detected by seed phrase detector 14, addresses detected by address detector 22, private keys detected by private key detector, web addresses detected by web address detector 24, software applications detected by software application detector 26 and / or hardware connections detected by hardware connection detector 28 of Fig.1. A Navigation Pane may categorize the cryptocurrency artifacts broken down by artifact type (e.g., Applications, USB Devices, Addresses, Domains, and Seed Phrases) and by Sources (e.g., Browser, Documents, Emails, Messages, and Images). Additionally or alternatively, the cryptocurrency artifacts may be sorted by cryptocurrency type (e.g., Bitcoin vs Ethereum). The number of artifacts found in each category is displayed after the category name.
[0050] Selecting one of the Artifact or Source categories may populate the Tabular Data Pane with its corresponding information. In the example shown in Fig.2, the Browser source has been selected and the Tabular Data Pane displays summary information for each of the three Browser artifacts. The columns of the table change based on the selected Artifact or Source typeAttorney Docket No. P-636557-PC and in this case the Value column shows the URL artifact and the Category shows where the value was found.
[0051] Selecting one of the rows of the Tabular Data Pane, populates its corresponding information in the Detail Pane. This pane shows additional summary information for the selected artifact which will change based on the artifact type. In one example, the source digital data (e.g., exhibit file) and Location within the source digital data are displayed for all artifact types to allow for independent verification of the automated forensic results of embodiments of the invention. Drill into each data point by selecting it to view source data.
[0052] Other visualizations or layouts to represent the same or different data (adding or deleting results) may be used according to embodiments of the invention.
[0053] A computer system according to an embodiment of the invention may detect, identify, and present specific cryptocurrency artifacts from digital data, wherein: a. artifacts may be detected in cryptocurrency wallet application data including flat files, databases, and / or binary data structures, wherein: i. cryptocurrency software applications may be identified by scraping bundle / package IDs in app store catalogs; and / or ii. obfuscated crypto wallet applications that have been renamed and / or moved from their default location may be identified by analyzing application data structures; b. evidence of previously connected USB hardware devices (e.g., hardware wallets) may be detected, identified, and presented to an investigator as a cryptocurrency artifact; c. cryptocurrency addresses may be detected, identified, and presented to the investigator, wherein: i. the specific blockchain for a given cryptocurrency address may be identified; d. cryptocurrency-specific URLs and domains may be detected, identified and presented to the investigator as a crypto artifact, wherein:Attorney Docket No. P-636557-PC i. URL domains may be classified as a particular application or cryptocurrency; and ii. URL domains may be classified as either a Centralized or Decentralized Exchange; e. cryptocurrency private encryption keys may be detected, identified, and presented to the investigator as a crypto artifact, wherein: i. address derivation may be used to detect, identify, and present child addresses related to the parent account to the investigator; and ii. seed phrases may be detected, identified, and presented to the investigator, wherein: 1. non-standard or custom seed phrases may be detected, identified, and presented to the investigator; 2. partial or incomplete seed phrases may be detected, identified, and presented to the investigator; 3. brute force methods may be used to recover or reconstruct missing seed phrase words; and 4. machine-written or hand-written seed phrases in media files may be detected using Optical Character Recognition (OCR),wherein: a. Machine Learning (ML) models may be used to improve OCR detection, parsing, and validation of potential seed phrases.
[0054] A computer system according to an embodiment of the invention may analyze specific sources in digital data exhibits for cryptocurrency artifacts, wherein: f. cryptocurrency artifacts may be detected in software wallet apps; g. evidence of cryptocurrency artifacts may be detected in hardware connection logs, wherein: i. evidence of cryptocurrency artifacts may be detected in USB hardware connection logs;Attorney Docket No. P-636557-PC ii. evidence of cryptocurrency artifacts may be detected for NFC connections; and / or iii. evidence of cryptocurrency artifacts may be detected for Bluetooth connections; h. evidence of cryptocurrency artifacts may be detected in web browser histories and bookmarks; i. evidence of cryptocurrency artifacts may be detected in user documents; j. evidence of cryptocurrency artifacts may be detected in emails; k. evidence of cryptocurrency artifacts may be detected in media files (e.g., photos, videos, audios, etc.); l. evidence of cryptocurrency artifacts may be detected in messenger apps (SMS, MMS, Instagram, Snapchat, etc.); m. evidence of cryptocurrency artifacts may be detected in calendar apps; and n. evidence of cryptocurrency artifacts may be detected in note taking applications.
[0055] A computer system according to an embodiment of the invention may manage chain of custody for cryptocurrency artifact exhibits, wherein: o. investigators’ supervisors may be notified when a case is created to examine an exhibit potentially including cryptocurrency artifacts; p. one or more witnesses may confirm access before an investigator accesses an exhibit potentially including cryptocurrency artifacts; and / or q. system logs may be maintained to provide an access audit trail.
[0056] A computer system according to an embodiment of the invention may summarize and report on artifacts across multiple types of cryptocurrencies, wherein: r. a total fiat value may be provided across all cryptocurrency artifacts; s. the fiat value may be provided for each type of cryptocurrency artifact; and / or t. the fiat value may be provided for each cryptocurrency address artifact.
[0057] Additionally or alternatively, the aforementioned computer systems may comprise any combination of all of their features, for example, mixing and matching elements from different computer systems.Attorney Docket No. P-636557-PC
[0058] Reference is made to Fig. 3, which schematically illustrates a system 100 for detecting cryptocurrency artifacts to recover cryptocurrency assets, according to some embodiments of the invention. The embodiments described herein may be executed using any single or combination of devices and / or components of system 100 of Fig. 3. The devices of system 100 may be used to operate one or more devices, data structures, parties or services, such as, those described in reference to Fig. 1, to implement the user interface of Fig.2 and / or to execute the method of Fig.4.
[0059] System 100 may include one or more server(s) 110, database(s) 115, and / or computer(s) 140, 150, …, any of which may operate to generate, trade and track digital data, cryptocurrency and / or cryptocurrency artifacts. Any or all of system 100 devices may be connected via one or more network(s) 120.
[0060] Database 115 may include software processes or applications for storing and retrieving digital data, cryptocurrency assets and / or cryptocurrency artifacts 117 such as data structures used by and in Figures 1-2, and 4. Data 117 may also include code (e.g., software code) or logic, e.g., to enable detecting, identifying, and presenting cryptocurrency artifacts from digital data and recovering cryptocurrency assets according to embodiments of the invention. Database 115 may be internal or external to one or more of server(s) 110 and / or computer(s) 140 and / or 150 (not shown) and may be connected thereto by a local or remote and a wired or wireless connection. In alternate embodiments, data 117 may be stored in an alternate location separate from database 115, e.g., memory unit(s) 118, 148, and / or 158.
[0061] Computers 140 and 150 may be servers, personal computers, desktop computers, mobile computers, laptop computers, and notebook computers or any other suitable device such as a cellular telephone, personal digital assistant (PDA), video game console, etc., and may include wired or wireless connections or modems. Computers 140 and 150 may be specialized secure hardware, such as, an air-gapped computer, connected USB hardware device, etc. Computers 140 and 150 may include one or more input devices 142 and 152, respectively, for operating the user interface of Figure 2 and receiving input from a user (e.g., via a pointing device, click-wheel or mouse, keys, touch screen, recorder / microphone, other input components). Computers 140 and 150 may include one or more output devices 144 and 154 (e.g., a monitor orAttorney Docket No. P-636557-PC screen) for displaying data, e.g., via the user interface of Figure 2, to a user provided by or for server(s) 110.
[0062] Network 120, which connects server(s) 110 and computers 140 and 150, may be any public or private network such as the Internet. Access to network 120 may be through wire line, terrestrial wireless, satellite or other systems well known in the art.
[0063] Server(s) 110 and computers 140 and 150, may include one or more controller(s) or processor(s) 116, 146, and 156, respectively, for executing operations according to embodiments of the invention and one or more memory unit(s) 118, 148, and 158, respectively, for storing data (e.g., digital data, cryptocurrency and / or cryptocurrency artifacts) and / or instructions (e.g., software for applying computations or calculations for detecting, identifying, and presenting cryptocurrency artifacts from digital data and recovering cryptocurrency assets according to embodiments of the invention) executable by the processor(s). Processor(s) 116, 146, and / or 156 may include, for example, a central processing unit (CPU), a digital signal processor (DSP), a microprocessor, a controller, a chip, a microchip, an integrated circuit (IC), or any other suitable multi-purpose or specific processor or controller. Processor(s) 116, 146, and / or 156 may be dedicated secure processor(s), such as, dedicated computers-on-a-chip or microprocessors, secure cryptoprocessors, etc. Memory unit(s) 118, 148, and / or 158 may include, for example, a random access memory (RAM), a dynamic RAM (DRAM), a flash memory, a volatile memory, a non-volatile memory, a cache memory, a buffer, a short term memory unit, a long term memory unit, or other suitable memory units or storage units.
[0064] Embodiments of the invention may include an article such as a computer or processor readable non-transitory storage medium, such as for example a memory, a disk drive, or a USB flash memory device (e.g., memory unit(s) 118, 148, and / or 158 of Fig. 3) encoding, including or storing instructions, e.g., computer-executable instructions, which when executed by a processor or controller (e.g., controller(s) or processor(s) 108, 110, and / or 112 of Fig. 1), cause the processor or controller to carry out methods disclosed herein.
[0065] Additional, fewer or alternative hardware components or connections therebetween may be used.Attorney Docket No. P-636557-PC
[0066] Reference is made to Fig. 4, which is a flowchart of a method for detecting cryptocurrency artifacts to recover cryptocurrency assets, in accordance with some embodiments of the invention. The method of Fig.4 may be executed using the system of Figs.1 and / or 3. Operations described in reference to Figs. 4 may be executed using one or more device(s) and / or processor(s) described in reference to Figs.1 and / or 3.
[0067] In operation 400, one or more processor(s) (e.g., file processor 6 of Fig. 1 and / or processor(s) 116, 146, and / or 156 of Fig. 3) may ingest digital data (e.g., raw files or text- converted data). The one or more processor(s) may search for artifacts (only) in digital data suspected to contain unknown cryptocurrency artifacts. In some embodiments, the one or more processor(s) may detect if the digital data is suspected to contain unknown cryptocurrency artifact by executing a test to detect data types in which seed words are known to be suspected or not (e.g., some data types have more or less likelihood of containing seed phrases). The data type test may be a multi-pass test including: a first pass to determine the digital data type by an extension on a file containing the digital data, and a second pass test to determine the digital data type by obtaining a signature of the contents of the file containing the digital data. When the data type detected in the two passes do not match, the digital data may have been altered and it is considered suspect (e.g., regardless of its data type).
[0068] In operation 410, one or more processor(s) (e.g., executing local seed phrase detector 14 of Fig.1) may search the digital data to detect one or more candidate seed phrases. Each candidate seed phrase may include a permutation of words from a single predetermined seed phrase library (possibly all words in each of multiple libraries) consecutively listed in a sequence having a fixed length predetermined according to a cryptocurrency standard. In some embodiments, the one or more processor(s) may reconstruct at least one of the candidate seed phrases from one or more partial candidate seed phrases each having a fixed length less than predetermined according to a cryptocurrency standard. In one embodiment, the one or more processor(s) may reconstruct the candidate seed phrase by combining multiple partial seed phrases detected in the searched digital data. Additionally or alternatively, the one or more processor(s) may reconstruct the candidate seed phrase by inserting one or more missing words randomly selected from the seed phrase library into the partial seed phrase. For example, if upAttorney Docket No. P-636557-PC to a maximum number of (e.g., 1-3) words are missing, the one or more processor(s) may brute force the missing words by inserting all combinations of words from the seed phrase library and check the checksums. For 1 missing word, the one or more processor(s) may try each different word from one or more libraries and tests and identifies for which inserted word, the seed phrase passes the checksum test (e.g., usually over 100 inserted words that pass). Then the one or more processor(s) may take this shortlist of potential missing words, derive private / public key pairs on different chains and check for activity history to be able to tell definitively which one of the words that passed the checksum is the real missing word in the seed phrase.
[0069] In some embodiments, the one or more processor(s) may compute a confidence metric for each candidate or partial seed phrase quantifying a likelihood that a candidate phrase is a seed phrase. The confidence metric may be directly proportional to the length of the candidate or partial seed phrase, directly proportional to the linguistic randomness of the sequence of words in the candidate seed phrase (e.g., the randomness of the seed words to each other and / or to the surrounding text), directly proportional to a visual randomness of the surrounding image, screen shot, etc., and or measured based on a location or data type context of the file location or file type (e.g., using the digital data type test of operation 400) in which the seed phrase was found (e.g., some locations or types having more or less likelihood of containing seed phrases). The confidence metric may be used to order the candidate phrases for analysis (e.g., in descending order of their likelihood to be a seed phrase), as a pre or post processing filter to add or remove phrases as candidates that are within or outside a range predefined for seed phrase linguistic context, serve as basis for increased or decreased validation tests (e.g., a single pass candidate validation test for an above threshold confidence metric and a multi-pass candidate validation test for a below threshold confidence metric), as an error margin to inform an investigator of the automated forensic certainty, etc.
[0070] A multi-pass seed phrase validation test may be executed for each candidate seed phrase to determine if it is a valid seed phrase by in operation 420 (first pass) and operation 430 (second pass).
[0071] In operation 420, one or more processor(s) (e.g., operating local seed phrase detector 14 of Fig. 1) may execute the first pass of the multi-pass seed phrase validation testAttorney Docket No. P-636557-PC comprising verifying a checksum of one or more words in the candidate seed phrase. Only upon verifying the first pass, a processor or processor may proceed to operation 430.
[0072] In operation 430, one or more processor(s) (e.g., external cryptocurrency processors 16 of Fig.1) may execute and / or one or more processor(s) (e.g., operating local seed phrase detector 14 of Fig.1) may request and receive the result of executing, the second pass of the multi-pass seed phrase validation test comprising verifying in a blockchain if there has been activity using a cryptocurrency asset encrypted using a public key in a key pair recovered from the candidate seed phrase.
[0073] Because there is an extremely large number of potential seed phrases (e.g., an exponential factor of the number of words in a seed phrases library), there is also a potentially extremely large incidence of false positive seed phrases, so performing the full Blockchain validation test in the second pass (operation 430) on each candidate seed phrase is typically prohibitively time-consuming and computationally intensive. Implementing a fast and efficient first pass (checksum) validation (operation 420) eliminates the vast majority of those false positives. This multi-pass seed phrase validation test thus only performs the second pass full Blockchain validation test (operation 430) on a significantly reduced number (e.g., minority) of candidate phrases compared with performing a one-pass full Blockchain validation test on all candidate phrases, thereby significantly improving the speed and reducing the computational load for seed phrase validation.
[0074] In some embodiments, the first pass (operation 420) may test multiple cryptocurrency standard-specific checksums on each candidate seed phrase to identify a valid checksum. If the checksum of the seed phrase is valid for one or more standard-specific checksums, the seed phrase may potentially be generated according to any of those standards. The second pass (operation 430) may then query the blockchain(s) for all those checksum validated standards to test if there is activity associated with the seed phrase. If so, the standard associated with the blockchain exhibiting activity is the standard used to generate the seed phrase.
[0075] In one embodiment, a process or processor may determine which cryptocurrency standard is used to generate a candidate seed phrase and if the seed phrase is valid, for example,Attorney Docket No. P-636557-PC as follows: 1) Determine if there are consecutive seed words from any of a plurality of standard- specific seed libraries. 2) Determine which seed library contains the words (the words may be common to multiple standard-specific seed libraries).3) Determine the number of words in the seed phrase. 4) Determine if there are any standards that support seed phrases of that length and with those words.5) If yes, verify the validity of the seed phrase via a checksum check (first pass operation 420). 6) Derive public / private key pairs for the seed phrase to check addresses associated with the seed phrase on different blockchains for the different standards to check for transaction history or current balance (second pass operation 430) (if the phrase is supported by multiple standards, check the blockchain for activity associated with the seed phrase for all of the multiple standards). Only the one cryptocurrency standard used to generate the seed phrase will exhibit activity.
[0076] Only upon verifying the second pass, a processor or processor may proceed to operation 440.
[0077] In operation 440, one or more processor(s) (e.g., on device 2 of Fig. 1) may automatically recover cryptocurrency assets using a private key in the recovered key pair.
[0078] In addition to the seed phrase detection of operations 400-440, some embodiments of the invention may (e.g., separately or in tandem) execute public key / address detection, private key detection, web address detection, software application detection and / or hardware connection detection.
[0079] In some embodiments, one or more processor(s) (e.g., executing a public or private key detector 22 of Fig.1) may search the digital data (ingested in operation 400) to detect one or more candidate public or private keys (e.g., configured to identify, or execute transactions with, a cryptocurrency asset). Each key may include a permutation of alphanumeric characters consecutively listed in a sequence having a fixed length or beginning with a preliminary alphanumeric sequence predetermined according to a cryptocurrency standard. The one or more processor(s) may test if each candidate public or private key is a valid public or private key configured to identify, or execute transactions with, a cryptocurrency asset. The one or more processor(s) may test if each candidate public or private key is a valid public or private key by executing a multi-pass key validation test. The one or more processor(s) may execute the multi-Attorney Docket No. P-636557-PC pass key validation test by: executing a first pass of the multi-pass key validation test comprising verifying a checksum of at least some of the alphanumeric characters in the candidate public or private key. Upon verifying the first pass, one or more processor(s) (e.g., external cryptocurrency processors 16 of Fig.1) may execute and / or one or more processor(s) (e.g., operating local public or private key detector 22 of Fig.1) may request and receive the result of executing, the second pass comprising verifying in a blockchain if there has been activity using a cryptocurrency asset encrypted using the candidate public key or a public key corresponding to the candidate private key. Upon verifying the valid public or private key, one or more processor(s) (e.g., on device 2 of Fig.1) may automatically recover cryptocurrency assets using the private key in the key pair.
[0080] In some embodiments, one or more processor(s) (e.g., executing web address detector 24 of Fig.1) may search the digital data to detect a cryptocurrency service web address (e.g., domain name / host name / URL / IP address) matching those in a list of known cryptocurrency service web addresses, and identify one or more cryptocurrency artifacts of a type associated with the detected cryptocurrency service web address.
[0081] In some embodiments, one or more processor(s) (e.g., executing software application detector 26 of Fig.1) may search the digital data to detect a cryptocurrency software application (e.g., software wallets) having a file type, name or data structure matching those associated with a list of known cryptocurrency software applications, and identify one or more cryptocurrency artifacts of a type associated with the detected cryptocurrency software application.
[0082] In some embodiments, one or more processor(s) (e.g., executing hardware connection detector 28 of Fig. 1) may search hardware connection logs in the digital data to detect a hardware connector identification (e.g., Vendor Identification and Product Identification (VID / PID)) matching those registered in a catalog of cryptocurrency hardware devices indicating a device logged in the hardware connection logs was connected to the registered cryptocurrency hardware device with the detected hardware connector identification.
[0083] The one or more processor(s) may iteratively repeat operations 400-440 for seed phrase detection (and one or more of the other artifact detections) for each single or multiple (fixed or dynamic) upload of digital data, times or time windows (e.g., periodically or with variableAttorney Docket No. P-636557-PC frequency), or triggered by condition(s) (e.g., receiving a fraud alert). Additional or different operations may be used, operations may be excluded, and different orders of operations may be used. For example, when the first pass (operation 420) or second pass (operation 430) is not verified, the processor(s) may terminate the process.
[0084] Recovering assets may refer to transferring assets on one or more Blockchains from a first (e.g., seized) wallet generated from the detected artifact seed phrase or private key to a second (e.g., investigator-controlled) wallet generated from a different seed phrase or private key (e.g., the second wallet supports the same standard as the detected seed phrase or private key, and may be the same type as the first wallet). Once the second wallet is populated with the transferred assets, a user or automated system may execute transactions with those recovered assets on the one or more Blockchains.
[0085] Real-time may refer, for example, to actions executed at simultaneous, overlapping or substantially similar times, for example, within 1-10 seconds or minutes of each other.
[0086] A cryptocurrency artifact may refer to a data structure configured to generate, store, transmit / receive, transact with, or otherwise use, a cryptocurrency-specific asset (e.g., and is not the cryptocurrency asset itself). A non-limiting list of examples of cryptocurrency artifacts includes a public key used to encrypt a cryptocurrency asset, a private key used to decrypt a cryptocurrency asset, a public / private key pair used to encrypt / decrypt a cryptocurrency asset, a seed phrase (complete or partial) configured to recover a private key used to decrypt a cryptocurrency asset, a cryptocurrency wallet, a cryptocurrency wallet password, cryptocurrency entropy, a cryptocurrency web address such as domain name / host name / URL / IP address hosted by a cryptocurrency service (e.g., exchange, mining service, storage platform, software or hardware company, etc.), a cryptocurrency software application, and / or a cryptocurrency hardware connection.
[0087] Cryptocurrency asset may refer to any cryptographic digital asset with monetary value. Although embodiments of the invention are described in reference to cryptocurrency, other digital (non-cryptocurrency) artifacts and assets may also be detected and recovered.Attorney Docket No. P-636557-PC
[0088] One skilled in the art will realize the invention may be embodied in other specific forms without departing from the spirit or essential characteristics thereof. The embodiments described herein are therefore to be considered in all respects illustrative rather than limiting. In detailed description, numerous specific details are set forth in order to provide an understanding of the invention. However, it will be understood by those skilled in the art that the invention can be practiced without these specific details. In other instances, well-known methods, procedures, and components, modules, units and / or circuits have not been described in detail so as not to obscure the invention.
[0089] Embodiments may include different combinations of features noted in the described embodiments, and features or elements described with respect to one embodiment or flowchart can be combined with or used with features or elements described with respect to other embodiments.
[0090] Although embodiments of the invention are not limited in this regard, discussions utilizing terms such as, for example, “processing,” “computing,” “calculating,” “determining,” “establishing”, “analyzing”, “checking”, or the like, can refer to operation(s) and / or process(es) of a computer, or other electronic computing device, that manipulates and / or transforms data represented as physical (e.g., electronic) quantities within the computer’s registers and / or memories into other data similarly represented as physical quantities within the computer’s registers and / or memories or other information non-transitory storage medium that can store instructions to perform operations and / or processes.
[0091] The term set when used herein can include one or more items. Unless explicitly stated, the method embodiments described herein are not constrained to a particular order or sequence. Additionally, some of the described method embodiments or elements thereof can occur or be performed simultaneously, at the same point in time, or concurrently.
Claims
Attorney Docket No. P-636557-PC Claims 1. A method for automatically searching for cryptocurrency artifacts to recover cryptocurrency assets, the method comprising: ingesting digital data suspected to contain unknown cryptocurrency artifacts; at one or more local processors, searching the digital data to detect one or more candidate seed phrases, each candidate seed phrase comprising a permutation of words from a single predetermined seed phrase library consecutively listed in a sequence having a fixed length predetermined according to a cryptocurrency standard; testing if each candidate seed phrase is a valid seed phrase configured to recover a public and private key pair used to control a cryptocurrency asset, comprising executing a multi-pass seed phrase validation test including: executing a first pass of the multi-pass seed phrase validation test comprising verifying a checksum of one or more words in the candidate seed phrase; and upon verifying the first pass, requesting and receiving the result of executing at one or more external processors, the second pass comprising verifying in a blockchain if there has been activity using a cryptocurrency asset encrypted using a public key in a key pair recovered from the candidate seed phrase; and upon verifying the valid seed phrase, recovering cryptocurrency assets using a private key in the key pair.
2. The method of Claim 1, wherein the first pass identifies under which of one or more cryptocurrency standards the seed phrase is potentially generated using standard- specific checksum verification and the second pass verifies the activity in in one blockchain for one of the identified cryptocurrency standards.
3. The method of Claim 1, wherein at least one of the candidate seed phrases is reconstructed from one or more partial candidate seed phrases each having a fixed length less than predetermined according to a cryptocurrency standard.
4. The method of Claim 3 comprising reconstructing the candidate seed phrase by combining multiple partial seed phrases detected in the searched digital data.Attorney Docket No. P-636557-PC 5. The method of Claim 3 comprising reconstructing the candidate seed phrase by inserting one or more missing words randomly selected from the seed phrase library into the partial seed phrase.
6. The method of Claim 1 comprising computing a confidence metric for each candidate seed phrase to be directly proportional to the linguistic randomness of the sequence of words in the candidate seed phrase.
7. The method of Claim 1 comprising, at one or more processors: searching the digital data to detect one or more candidate public or private keys, each key comprising a permutation of alphanumeric characters consecutively listed in a sequence having a fixed length or beginning with a preliminary alphanumeric sequence predetermined according to a cryptocurrency standard; testing if each candidate public or private key is a valid public or private key configured to identify, or execute transactions with, a cryptocurrency asset; and upon verifying the valid public or private key, recovering cryptocurrency assets using the private key in the key pair.
8. The method of Claim 7, wherein testing if each candidate public or private key is a valid public or private key comprises executing a multi-pass key validation test including: executing a first pass of the multi-pass key validation test comprising verifying a checksum of at least some of the alphanumeric characters in the candidate public or private key; and upon verifying the first pass, requesting and receiving the result of executing at the one or more external processors, the second pass comprising verifying in a blockchain if there has been activity using a cryptocurrency asset encrypted using the candidate public key or a public key corresponding to the candidate private key.
9. The method of Claim 1 comprising, at a web address detector, searching the digital data to detect a cryptocurrency service web address matching those in a list of known cryptocurrency service web addresses; and identifying one or more cryptocurrency artifacts of a type associated with the detected cryptocurrency service web address.Attorney Docket No. P-636557-PC 10. The method of Claim 1 comprising, at a software application detector, searching the digital data to detect a cryptocurrency software application having a file type, name or data structure matching those associated with a list of known cryptocurrency software applications; and identifying one or more cryptocurrency artifacts of a type associated with the detected cryptocurrency software application.
11. The method of Claim 1 comprising, at a hardware connection detector, searching hardware connection logs in the digital data to detect a hardware connector identification matching those registered in a catalog of cryptocurrency hardware devices indicating a device logged in the hardware connection logs was connected to the registered cryptocurrency hardware device with the detected hardware connector identification.
12. The method of Claim 1, wherein detecting if the digital data is suspected to contain unknown cryptocurrency artifact comprises executing a multi-pass digital data type test including: a first pass to determine the digital data type by an extension on a file containing the digital data; and a second pass test to determine the digital data type by obtaining a signature of the contents of the file containing the digital data.
13. A system comprising: one or more memories configured to store ingested digital data suspected to contain unknown cryptocurrency artifacts; and one or more processors configured to: search the digital data to detect one or more candidate seed phrases, each candidate seed phrase comprising a permutation of words from a single predetermined seed phrase library consecutively listed in a sequence having a fixed length predetermined according to a cryptocurrency standard, test if each candidate seed phrase is a valid seed phrase configured to recover a public and private key pair used to control a cryptocurrency asset, comprising executing a multi-pass seed phrase validation test including:Attorney Docket No. P-636557-PC executing a first pass of the multi-pass seed phrase validation test comprising verifying a checksum of one or more words in the candidate seed phrase; and upon verifying the first pass, requesting and receiving the result of one or more external processors executing a second pass of the multi- pass seed phrase validation test comprising verifying in a blockchain if there has been activity using a cryptocurrency asset encrypted using a public key in a key pair recovered from the candidate seed phrase; and upon verifying the valid seed phrase, recover cryptocurrency assets using a private key in the key pair.
14. The system of Claim 13, wherein the one or more processors are configured to execute the first pass to identify under which of one or more cryptocurrency standards the seed phrase is potentially generated using standard-specific checksum verification and the second pass verifies the activity in one blockchain for one of the identified cryptocurrency standards.
15. The system of Claim 13, wherein the one or more processors are configured to reconstruct at least one of the candidate seed phrases from one or more partial candidate seed phrases each having a fixed length less than predetermined according to a cryptocurrency standard.
16. The system of Claim 15, wherein the one or more processors are configured to reconstruct the candidate seed phrase by combining multiple partial seed phrases detected in the searched digital data.
17. The system of Claim 15, wherein the one or more processors are configured to reconstruct the candidate seed phrase by inserting one or more missing words randomly selected from the seed phrase library into the partial seed phrase.
18. The system of Claim 13, wherein the one or more processors are configured to compute a confidence metric for each candidate seed phrase to be directly proportional to the linguistic randomness of the sequence of words in the candidate seed phrase.
19. The system of Claim 13 comprising one or more processors configured to:Attorney Docket No. P-636557-PC search the digital data to detect one or more candidate public or private keys, each key comprising a permutation of alphanumeric characters consecutively listed in a sequence having a fixed length or beginning with a preliminary alphanumeric sequence predetermined according to a cryptocurrency standard, test if each candidate public or private key is a valid public or private key configured to identify, or execute transactions with, a cryptocurrency asset, and upon verifying the valid public or private key, recover cryptocurrency assets using the private key in the key pair.
20. The system of Claim 19, wherein the one or more processors are configured to test if each candidate public or private key is a valid public or private key by executing a multi- pass key validation test including: executing a first pass of the multi-pass key validation test comprising verifying a checksum of at least some of the alphanumeric characters in the candidate public or private key, and upon verifying the first pass, requesting and receiving the result of executing at the one or more external processors a second pass of the multi-pass key validation test comprising verifying in a blockchain if there has been activity using a cryptocurrency asset encrypted using the candidate public key or a public key corresponding to the candidate private key.
21. The system of Claim 13 comprising one or more processors configured to search the digital data to detect a cryptocurrency service web address matching those in a list of known cryptocurrency service web addresses; and identifying one or more cryptocurrency artifact(s) of a type associated with the detected cryptocurrency service web address.
22. The system of Claim 13 comprising one or more processors configured to search the digital data to detect a cryptocurrency software application having a file type, name or data structure matching those associated with a list of known cryptocurrency software applications; and identifying one or more cryptocurrency artifact(s) of a type associated with the detected cryptocurrency software application.Attorney Docket No. P-636557-PC 23. The system of Claim 13 comprising one or more processors configured to search hardware connection logs in the digital data to detect a hardware connector identification matching those registered in a catalog of cryptocurrency hardware devices indicating a device logged in the hardware connection logs was connected to the registered cryptocurrency hardware device with the detected hardware connector identification.
24. The system of Claim 13, wherein the one or more processors are configured to detect if the digital data is suspected to contain unknown cryptocurrency artifact by executing a multi-pass digital data type test including: a first pass to determine the digital data type by an extension on a file containing the digital data, and a second pass test to determine the digital data type by obtaining a signature of the contents of the file containing the digital data.
Citation Information
Patent Citations
Changing an existing blockchain trust configuration
US20180123882A1
Hybrid consensus for blockchain using proof of work and proof of stake
US20190370793A1
Automated Blockchain Protocol Update
US20200084041A1
Systems and methods for selecting and utilizing a committee of validator nodes in a distributed system
US20210099312A1
Computer-implemented system and method providing a decentralised protocol for the recovery of cryptographic assets
US20220417025A1
Cited By
Secure Large Language Model Data Gateway
US20250378268A1
Secret Scanner
US20260080077A1