Home›Guidance›Founder Story

I was sitting at my desk when it happened.

A link showed up on X promoting a governance vote for Flare Network, a project I held. The site looked exactly right. The branding was perfect. The URL was close enough that I didn't catch it. I connected my wallet to vote.

In the time it took me to read the confirmation screen, $93,000 in WFLR tokens was gone.

That was the moment ChainWatch was born, though I didn't know it yet.

The First Hour Was the Worst

I refreshed the block explorer maybe twenty times, as if watching the transaction would somehow undo it. It didn't. The funds were moving. By the time I understood what had happened, the attacker had already started routing the tokens through intermediary wallets.

I didn't know what to do. I searched for resources. What I found was mostly useless: generic advice to "contact your exchange" (I didn't use an exchange, it came straight out of my wallet), blog posts selling paid recovery services of questionable legitimacy, and one FBI page that told me to file at IC3 but gave no guidance on what actually happens after that.

There was no first-response resource. No credible, specific guide for what to do in the first 72 hours. No service that would take my case and actually do something with it.

So I started learning.

What I Did in the First 24 Hours

The first thing I did right was document everything immediately. I screenshot the fake site; I still had the browser tab open. I copied the theft transaction hash from Etherscan. I noted the attacker's wallet address, the token amounts, the timestamp.

I filed at IC3 that same night. I was specific: wallet addresses, transaction hashes, dollar value at time of theft. I'd later learn that specific IC3 reports are the ones that get attention. Vague ones don't.

I contacted the Flare Network team to report the fake site. That got the phishing domain flagged. It didn't get my money back, but it stopped the next victim.

What I didn't do fast enough was revoke token approvals. I didn't know that was a thing. The malicious contract had been granted unlimited approval; I'd signed it without understanding what I was signing. By the time I revoked it, the damage was done. If you're reading this right now and were just hit: go to Revoke.cash and revoke your approvals before you do anything else.

What I Learned About How the Money Moved

In the weeks that followed, I started learning blockchain forensics. Not because I had a background in it: I'm a retired landlord from Suffolk, Virginia, with no technical training. I learned because I had to.

My co-founder Titus Claxton, who I met during grand jury duty, had the technical skills I didn't. Together we built what became ChainWatch's core capability: the ability to follow stolen funds across chains, decode bridge transactions, identify exchange deposits, and document the entire path in a format that's useful to investigators.

What we found in my case was worse than I expected, and more valuable as evidence than I'd hoped.

The attacker didn't just take my funds and cash out. The forensic trace Titus built documented 17 hops across three chains: Flare, Arbitrum, and Ethereum. Peel chains. Mixer behavior. Token substitution. And at the end of the trail: evidence of premeditation and a repeat offender who had done this before.

That trace is now a forensic case file sitting with law enforcement. It's the same format we produce for every ChainWatch case.

The Thing Nobody Tells You About Reporting to Law Enforcement

When I first contacted law enforcement, I quickly realized the problem wasn't their willingness to help. It was that they didn't have the tools.

A detective assigned to a crypto theft case typically has Etherscan, maybe some basic analytics access, and a caseload that already has them stretched thin. Handing them a wallet address and saying "my money went somewhere on the blockchain" puts all the forensic work on them. Most cases stall right there, not because investigators don't care, but because the technical barrier is too high and the resources aren't there.

What changes the equation is showing up with a completed case file. A documented forensic trace, chain-of-custody evidence, an IC3 referral package, and a clear narrative of what happened and where the money went. When an investigator can open a folder and have everything they need, cases move.

That's what we built ChainWatch to produce.

What's Happened Since

I'm not going to tell you I got my $93,000 back. I haven't, not yet.

What I can tell you is that the case is alive. The Virginia State Police have an active investigation. The forensic file is built. The attacker wallet that was identified as holding funds has been documented. When the legal process reaches the point of a court order, we'll be ready.

More importantly: the infrastructure I built to fight for my own recovery is now available to every crypto theft victim who finds ChainWatch before they give up.

Why I'm Telling You This

Because you need to know it's possible to fight back.

Not guaranteed. Not easy. But possible, if you move fast, document everything, get a forensic trace, and put your case in front of the right investigators with the right evidence.

The blockchain is a permanent, public record. Your attacker left a trail. The question is whether someone follows it before it goes cold.

That's what ChainWatch exists to do.

If This Just Happened to You

Contact us with the subject line URGENT if your theft was in the last 72 hours. We'll respond the same day.

If your theft was older, apply for our free beta case analysis. We're running a limited number of cases at no charge as we validate our platform. Seven spots remain.

No fees. No recovery guarantee. Just someone in your corner who has been exactly where you are.

ChainWatch provides forensic response and reporting services for cryptocurrency theft victims. ChainWatch is not a law firm and does not guarantee fund recovery. All case data is kept strictly confidential.