Leonard Peterson

Specimen — illustrative data — not a real matter

Specimen evidence package

This is a specimen document. It exists to show the structure, method and standard of the reports this practice produces. The matter, parties, addresses, transaction identifiers and values are invented. No real case is described. Where a real report would carry client-identifying material, this specimen carries illustrative substitutes.

Case notes describing real matters are published only with client consent and in anonymised form — those are on the case notes page.


Report on the Tracing of Digital Assets

Matter reference
SPECIMEN/001
Prepared for
[Instructing solicitor / firm]
Prepared by
Leonard Peterson, practice name
Date of report
[date]
Status
Final
Version
1.0

1. Instructions and scope

1.1 I was instructed on [date] by [instructing firm] on behalf of their client (“the Claimant”) to establish, so far as the public ledger permits, the movement of digital assets transferred by the Claimant on [date] and to identify the services at which those assets came to rest.

1.2 My instructions were limited to on-chain analysis. I was not instructed to identify any individual, to contact any third party, or to advise on the merits of any claim.

1.3 This report addresses: (a) the path taken by the assets; (b) the points at which the assets were commingled with assets of unknown origin; (c) the attribution of terminal deposit addresses to identifiable services; and (d) the limitations of the foregoing.

2. Summary of findings

2.1 On [date], 412,000 USDT (TRC-20) was transferred from an address controlled by the Claimant to an address I refer to as R1.

2.2 The assets moved through six intermediate addresses over approximately 31 hours before arriving at two deposit addresses, T1 and T2.

2.3 T1 and T2 are attributed to two centralised exchanges, identified at paragraphs 6.3 and 6.4 below. The basis of each attribution, and my confidence in it, is stated.

2.4 At one point in the chain (paragraph 5.7) the Claimant’s assets were commingled with assets of unknown origin. From that point the connection between the Claimant’s funds and the terminal deposits is a matter of proportion and inference rather than direct correspondence. Balances before, during and after that event are set out at Schedule C so that the position can be assessed.

2.5 Approximately 6% of the traced value was converted through a decentralised swap service to a different asset and is addressed separately at paragraph 5.9.

3. Method

3.1 Analysis was conducted using named analytics platform, version, licence and, independently, by direct query of public ledger data via [node / explorer], in order that platform-derived conclusions could be checked against primary source data.

3.2 All ledger data was captured between [date] and [date]. Capture times are recorded in Schedule A. Blockchain data is append-only and the transactions described are final and immutable; however, attribution data held by third-party platforms is subject to revision, and the attributions at section 6 reflect the position on the query dates stated.

3.3 Where I have relied on address clustering, I identify the heuristic relied upon and treat the resulting conclusion as an inference. Where I have relied on attribution supplied by a commercial platform, I say so and do not present it as my own independent determination.

3.4 I have distinguished throughout between observation (what the ledger records) and inference (what I conclude from it). Findings are labelled accordingly.

4. Source data and integrity

4.1 Primary data exports are listed at Schedule A with, for each: source, query parameters, capture timestamp (UTC), file name, and SHA-256 hash.

4.2 Original exports are retained unmodified. Working analysis is maintained separately. Both are available for inspection.

4.3 Materials received from the Claimant are listed at Schedule B with date of receipt and method of transfer.

5. Findings

Format illustrated; a real report would run to the full chain.

  1. 5.1 [Observation]

    On [date] at 09:14:22 UTC, transaction a3f1…9c2b transferred 412,000 USDT (TRC-20) from address TQ9x…4mF2 to address R1 (TJ7k…2pW8). Block 61,204,881.

  2. 5.2 [Observation]

    The Claimant’s records, exhibited at LP/3, identify TQ9x…4mF2 as an address under the Claimant’s control at the material time.

  3. 5.3 [Observation]

    At 09:41:07 UTC the full balance of R1 was transferred to R2 (TN4b…7yQ1) by transaction c8d2…14ae. R1 had no prior transaction history and no subsequent activity.

  4. 5.4 [Inference — high confidence]

    The pattern at 5.3 (single-use address, immediate onward transfer of the full balance, no other activity) is consistent with a pass-through address controlled by the recipient of the original transfer rather than by an independent third party.

  5. 5.7 [Observation]

    At 14:02:55 UTC, R4 (TB2m…8xZ3) received 412,000 USDT from R3. R4 held a balance of 1,340,000 USDT immediately prior to that receipt, derived from transactions unconnected to the Claimant, giving a balance of 1,752,000 USDT. Between that receipt and the terminal deposits described at 5.10, R4’s balance fell to a low of 286,000 USDT at 16:48:12 UTC, before further unconnected deposits were received. Full balance history at Schedule C.

  6. 5.8 [Limitation]

    From the point described at 5.7, the Claimant’s assets cannot be followed as identifiable property. The intermediate low of 286,000 USDT is below the sum received from the Claimant, and any conclusion as to what proportion of subsequent outflows is attributable to the Claimant is a legal question on which I express no view. The ledger data necessary to address it is set out at Schedule C.

  7. 5.9 [Observation]

    At 18:30:41 UTC, 26,000 USDT was routed through [swap service] and emerged as [asset]. The transaction pair is exhibited at LP/9. The onward path of that portion is traced separately at Appendix 2.

6. Attribution

6.1 Attribution identifies the service that controls a deposit address. It does not identify any individual. Identification of an account holder is a matter for the service, and typically requires an order of the court.

6.2 Deposit addresses were attributed on [date] using [platform]. Where possible I sought a second, independent indicator; these are stated below.

6.3 T1 (TX5v…3hK9) — attributed by [platform] to [Exchange A]. Query date [date]. Secondary indicator: the address appears in [Exchange A]’s published deposit address documentation / exhibits a deposit-consolidation pattern consistent with that service. Confidence: high.

6.4 T2 (TC8n…1jR4) — attributed by [platform] to [Exchange B]. Query date [date]. No independent secondary indicator was available. Confidence: moderate. This attribution rests on a single commercial source and should be treated accordingly.

6.5 I make no finding as to which corporate entity within either exchange’s group holds the relevant records, or as to the appropriate respondent to any application. Those are matters for the instructing solicitor.

7. Timing data for record identification

7.1 Deposits to T1 and T2 are set out at Schedule D with block timestamps in UTC and block heights.

7.2 A service’s internal crediting time may differ from block timestamp. Where a search of the service’s records is to be requested, I would suggest a window of not less than ±2 hours around the times stated.

8. Limitations

8.1 This report addresses the public ledger only. It does not establish who controls any address.

8.2 The commingling described at 5.7 limits what can be asserted about the terminal deposits as a matter of identifiable property.

8.3 Attributions reflect third-party data as at the query dates stated and are subject to revision.

8.4 Address clustering relies on heuristics that are strong but not conclusive. Where relied upon, the heuristic is identified.

8.5 The position described is as at the capture dates. Assets may since have moved.

8.6 I have not been provided with, and have not sought, any material from any party other than the Claimant.

9. Declaration

9.1 I have set out in this report all matters within my knowledge which I consider relevant to the conclusions expressed, including matters which do not support those conclusions.

9.2 I have distinguished between fact and inference and have stated the basis of each inference.

9.3 Interest in the outcome: my fee for this matter is contingent upon funds being recovered by the Claimant, at [X]% of sums received. I have disclosed this so that the reader may take it into account when weighing my conclusions.

9.4 I am aware that this report may be relied upon in proceedings and may be disclosed to other parties.

Signed

[signature]

Leonard Peterson

qualifications

[date]

Schedules

Schedule A
Data captures: source, query, capture time (UTC), filename, SHA-256
Schedule B
Materials received from the Claimant
Schedule C
Balance history of R4 across the commingling period
Schedule D
Terminal deposits: address, tx hash, block, timestamp (UTC), value
Schedule E
Full address schedule with role and first/last activity
Appendix 1
Transaction flow diagram (reconciling to Schedules D and E)
Appendix 2
Traced path of the converted portion

The flow diagram reconciles exactly to the transaction schedule — same addresses, same order, same values. Each node is labelled with the short-form address used in the findings (R1, R2, T1) so the reader can move between narrative, diagram and schedule without translation.

Specimen — illustrative data — not a real matter