Cryptocurrency Crime Analyst (CCA)

Master cryptocurrency crime investigation, from wallet forensics and blockchain tracing to digital evidence and enforcement.

CCA Course Syllabus

The CCA syllabus is built around 6 core investigative skills.

  • Seed phrases, private keys, public keys, and wallet addresses
  • Wallet types and wallet forensic artefacts
  • Deterministic wallet structures and wallet generation
  • Blockchain address prefixes and blockchain explorers
  • Deep dive into EVM explorers
  • Investigation of major wallets including MetaMask, Trust Wallet, Phantom, Ledger, Trezor, Coinbase Wallet, Binance Wallet, Exodus, Electrum, Gnosis Safe, Brave Wallet, Monero GUI Wallet, Nexus Wallet, and Zengo
  • Service wallets and cross-chain wallet activity
  • Linking wallet activity to real-world identities
  • Private key, seed phrase, address, service wallet, explorer, and wallet investigation checklists
  • Best practices for cryptocurrency wallet forensics
  • Practical crypto crime investigation challenges
  • Blockchain core concepts including blocks, transactions, ledgers, hashing, Merkle trees, consensus, validators, miners, transaction propagation, immutability, and forks
  • Blockchain infrastructure including nodes, RPC endpoints, blockchain APIs, public and private node infrastructure, rate limits, and API key management
  • Smart contract basics and smart contract investigation
  • Smart contract vulnerabilities including access control failure, flash loan attacks, front-running, governance takeover, integer overflow/underflow, oracle manipulation, reentrancy, unchecked return values, upgrade function abuse, and weak randomness
  • Smart contract analysis checklist
  • Blockchain tokens and token creation using OpenZeppelin
  • Token standards across Algorand, Avalanche, Bitcoin-based systems, BNB Chain, Cardano, Cosmos, EVM, Hedera, Move-based chains, Polkadot/Substrate, Solana, Stellar, Tezos, TON, and Tron
  • Token analysis checklist
  • Internet and web technology including IP, DNS, HTTP, SMTP, FTP, SSL/TLS certificates, web servers, cloud infrastructure, CDNs, and web browsers
  • Investigation checklists for IP addresses, DNS, web servers, FTP servers, email, and browsers
  • On-chain and off-chain data types, sources, and evidence linkage
  • Python for investigators, including libraries for blockchain investigation, digital forensics, malware analysis, browser forensics, and penetration testing
  • How to think like a cryptocurrency investigator
  • Silk Road and the evolution of cryptocurrency investigations
  • Early Bitcoin thefts and cryptocurrency exchange hacks
  • Ponzi schemes, investment scams, ransomware, malware, DeFi exploits, and rug pulls
  • Darknet markets, crypto-enabled illicit trade, social engineering, identity exploits, and other cryptocurrency crimes
  • Investigation of cryptocurrency financial crimes, money laundering, and organized crime
  • Investigation of DeFi protocols including bridges, centralized exchanges, DEXs, derivatives, lending protocols, liquid staking protocols, NFT marketplaces, oracles, privacy protocols, restaking protocols, RWA protocols, stablecoins, synthetics, and yield aggregators
  • Investigation of blockchain ecosystems including Bitcoin, EVM, Tron, Binance, Solana, and alternate blockchains
  • Freezable tokens and chain controls
  • Investigation of decentralized domains including ENS, Handshake, Unstoppable Domains, and decentralized domain investigation approaches
  • Decentralized domain investigation checklist
  • Investigation of decentralized hosting and storage protocols including Arweave, Filecoin, IPFS, Sia, and Storj
  • Decentralized storage investigation checklist
  • Investigation of email platforms including Ethermail, Gmail, Proton Mail, Tutanota, temporary email services, and self-hosted email servers
  • Investigation of encrypted and obfuscated data including encrypted containers, password attacks, chain of custody, key management failures, live-system analysis, metadata, mobile and cloud encryption artefacts, steganography, and disposable services
  • Encrypted data investigation checklist
  • Investigation of encrypted messaging platforms including Blockscan Chat, Discord, Element, Session, Signal, Telegram, Threema, and WhatsApp
  • Encrypted messaging investigation checklist
  • Investigation of parallel internets including Freenet, GNUnet, I2P, Lokinet, mix networks, Tor, and ZeroNet
  • Parallel internet investigation checklist
  • Investigation of privacy-focused browsers including Brave Browser, DuckDuckGo Browser, LibreWolf, Mullvad Browser, and Tor Browser
  • Privacy-focused browser investigation checklist
  • Investigation of privacy-focused operating systems including CalyxOS, GrapheneOS, Kicksecure, Linux Kodachi, Qubes OS, Subgraph OS, Tails, and Whonix
  • Privacy operating system investigation checklist
  • Investigation of proxy and obfuscation tools including Lantern, Outline, Psiphon, Shadowsocks, Socks5 proxies, SSH tunneling, Surge, V2Ray, VPN services, and WireGuard
  • Proxy and obfuscation tool investigation checklist
  • Foundation and framework for cryptocurrency crime scene response, including purpose, scope, first responder roles, legal authority basics, and training requirements
  • Pre-incident preparation including agency seizure wallet infrastructure, equipment checklists, legal documentation, and pre-operation planning
  • Initial response and scene operations including scene arrival, critical first 60 seconds, five-minute scene assessment, and crypto crime scene indicators
  • Identification and categorization of hardware wallets, software wallets, paper wallets, exchange access devices, and mining equipment
  • Critical “do not” protocols covering power state management, network connectivity, device interaction, password and seed phrase handling, screen documentation, and common mistakes to avoid
  • Immediate asset preservation including drain risk assessment, transfer versus isolation decisions, legal authorization verification, wallet discovery, asset balance documentation, and emergency asset transfer execution
  • Evidence collection including scene photography, physical evidence collection, digital evidence capture, seed phrase and password search, exchange account documentation, and associated records
  • Chain of custody procedures including initial custody documentation, crypto-specific custody fields, transfer and handoff, storage, and access logging
  • Transport and storage protocols for powered devices, evidence organization, secure facilities, climate control, and access control
  • Special scenarios including exchange-based assets, DeFi protocols, NFTs, privacy coins, multi-signature wallets, large-scale mining operations, sophisticated threat actors, and active trading situations
  • Post-seizure procedures including immediate actions, handoff to specialists, supervisor notification, preliminary reporting, and after-action review
  • Field checklists for scene assessment, powered-on devices, asset transfer, wallet seizure, mobile and laptop seizure, seed phrase search, exchange account documentation, evidence photography, chain of custody, mining operations, DeFi interaction, multi-signature wallets, privacy coins, transport, post-seizure actions, pre-operation preparation, and quality assurance review
  • Photo atlas for identifying physical cryptocurrency evidence
  • Legal authority and cryptocurrency enforcement processes across Argentina, Australia, Bahrain, Bermuda, Brazil, British Virgin Islands, Canada, Cayman Islands, Chile, Colombia, El Salvador, European Union, Hong Kong, Iceland, India, Indonesia, Japan, Kazakhstan, Kenya, Liechtenstein, Mexico, Nigeria, Philippines, Singapore, South Africa, South Korea, Switzerland, Taiwan, Thailand, Turkey, United Arab Emirates, United Kingdom, United States, and Vietnam
  • Mutual Legal Assistance Treaty framework and international cooperation mechanisms
  • Regional mechanisms for cross-border cryptocurrency enforcement
  • Jurisdictional conflicts in cryptocurrency investigations
  • Privacy versus investigation issues, including GDPR and similar laws
  • Decentralized protocol challenges for investigators and enforcement agencies
  • Encryption and compelled decryption issues
  • Sanctions compliance in cryptocurrency investigations
  • Stateless transactions and enforcement challenges
  • Egmont Group and FIU cooperation
  • FATF Travel Rule implementation and investigative implications
  • Markets in Crypto-Assets Regulation (MiCA)
  • Central Bank Digital Currencies and investigation issues
  • 1-year access to all 6 volumes of the Cryptocurrency Investigation & Forensics Manual.
  • 1-year access to the c4 LEARN platform: interactive quizzes, deep-dive videos, and authentic court records and case documents.
  • Expert-led live online sessions with real investigators and practitioners.
  • 1-year access to c4 Lab (Analyst Edition). 103 investigation tools valued at $1,428.
  • Polygon-based blockchain tokens for hands-on practical exercises.
  • Globally recognised professional certification.
Real Investigations

Meet your Teacher

Rohas Nagpal is an author, lawyer and investigator with over 25 years of experience across digital forensics, cybercrime, financial crime and corporate liability. He has worked on complex matters across 18 countries, co-founded the Asian School of Cyber Laws in 1999, and assisted the Government of India in drafting rules under the Information Technology Act.

He is the author of the Cryptocurrency Investigation & Forensics Manual and the Cyber Crime Investigation Manual, described by The Times of India as the "Bible for cybercrime investigators". His work in cryptocurrency began in 2011 during a narcotics investigation. He has advised the Reserve Bank Innovation Hub on NFTs and CBDCs. He also maintains the open source Sara AI Wallet for cryptocurrencies and stablecoins.

c4 Lab

The Tools You Will Master

Unlike generic blockchain analytics platforms, every tool in c4 Lab is designed around real investigative tasks.

4 tools
c4 Checklists
Investigation playbooks for ransomware, money laundering, scams, and darknet workflows.
3 tools
c4 Seed
Seed phrase creation, recovery, and investigation across multiple derivation paths.
6 tools
c4 Blockchain
On-chain transaction and address analysis: trace funds, identify clusters, build intelligence.
1 Tool
c4 BAD
Lookup and flag risky or known blockchain addresses: exchanges, mixers, darknet markets, ransomware operators.
5 tools
c4 Wallet
Wallet artifact analysis, ownership profiling, and transaction operations.
9 tools
c4 DeFi
DeFi protocol, stablecoin, and chain-level investigation data: exploits, liquidity, and yield monitoring.
2 tools
c4 Tokens
Token symbol and contract intelligence: identify fraudulent launches, pump-and-dump schemes, and wash trading.
1 tool
TXG
Transaction graph visualization and flow tracing: map fund movements across wallets and chains.
3 tools
c4 Contract
Smart contract inspection and risk analysis: identify backdoors, hidden mints, and malicious upgrade mechanisms.
30 tools
c4 Utilities
General-purpose forensic helpers: encoding, time conversion, math, file, and text utilities.
23 tools
c4 Cyber
Suite of tools for Web Intelligence, Image Forensics, and File Forensics.
16 tools
c4 Cryptanalysis
Crypto and password analysis: hashing, cipher utilities, and cracking helpers for forensic investigations.

Recover and investigate wallets from seed phrases. Derive addresses across multiple derivation paths and analyze associated transaction history.

Deep forensic analysis of cryptocurrency wallets. Identify ownership patterns, transaction clusters, and links to known entities.

End-to-end blockchain transaction tracing. Follow the money across chains, identify obfuscation techniques, and build an evidence trail.

A searchable intelligence database of tagged blockchain addresses: exchanges, mixers, darknet markets, ransomware operators, sanctioned entities, and more.

Investigate specific cryptocurrencies: tokenomics, supply mechanics, known exploits, and on-chain behavior patterns relevant to investigations.

Monitor and investigate decentralized finance protocols. Detect exploits, rug pulls, flash loan attacks, and suspicious liquidity movements in real time.

Analyze token contracts, holder distributions, and transfer patterns. Identify pump-and-dump schemes, wash trading, and fraudulent token launches.

Forensic analysis of smart contracts. Identify malicious code, backdoors, hidden mint functions, and upgrade mechanisms used in crypto fraud.

Link on-chain activity to off-chain digital infrastructure: domains, IP addresses, email accounts, social profiles, and covert communications.

Analyze encrypted data, obfuscated communications, and hidden wallet artifacts found during digital forensic investigations.

The Manual

The Investigative Framework on Which CCA Is Built

6 volumes covering Wallet Forensics, Technical Foundations, Blockchain & Crypto Investigation, Covert Digital Infrastructure Investigation, Crime Scene First Response, and Global Enforcement. Written for practitioners. Designed to hold up in court.

CCA Application Form