What this tutorial says in five lines
- Evidence that is not dated, labelled and captioned cannot be used by an analyst.
- Copy address and hash text rather than screenshotting it — images cannot be matched programmatically.
- Preserve the platform evidence before you confront anyone, because access is usually cut.
- One folder, one index, one page numbers. Institutions ask for the same six things.
- Originals stay with you. Send copies, and record what you sent to whom and when.
Why this matters
Two victims with identical losses and identical traces routinely get different outcomes, and the difference is almost always the evidence pack. A complaint that describes a loss in prose is filed; a complaint that documents it with dated identifiers is actioned. This tutorial is the checklist that turns your account of events into a document an analyst, a bank fraud team or an investigator can actually use — and the order to assemble it in so nothing is lost while you work.
Why "specific" is the word that decides everything
A fraud analyst receives a large volume of messages. The triage question is not whether the person is telling the truth; it is whether this submission contains something that can be checked against a system. Prose cannot be checked. An address can.
This is why the difference between a filed report and an actioned one is rarely emotional or rhetorical. It is whether the message contains identifiers that resolve.
One consequence is worth stating: a short report with correct hashes outperforms a long report with none, every time.
Never screenshot an address when you could copy the text instead. A screenshot of a 42-character string cannot be matched against records programmatically, which means it is evidence in appearance only.
The evidence checklist
Assemble in this order. The sequence matters because platform access and on-chain records can both become unavailable, and the items earlier in the list are the ones that disappear first.
Tick every row you can. Partial is far better than none, and the first four rows alone make a report usable.
| # | Evidence item | How to capture it | Why it disappears |
|---|---|---|---|
| 1 | Platform screenshots | Dashboard, balance, deposit page, withdrawal refusal, support chat | Access is cut once you press on withdrawal |
| 2 | Full transaction history export | Export from your wallet or exchange, before it is pruned | Some wallets prune history over time |
| 3 | Transaction hashes, as text | Copy from the explorer, paste into a text file | Never lost on-chain, but easy to lose locally if only screenshotted |
| 4 | Receiving addresses, as text | Copy from the explorer or the platform deposit page | Same as above |
| 5 | The trace output | Export the movement record as a file | Reconstructable, but time-consuming |
| 6 | The dated timeline | One line per event, date first | Your own recall degrades within days |
| 7 | Communications | Messages, emails, handles, phone numbers, dates | Accounts are deleted or the contacts vanish |
| 8 | Payment records | Card statements, transfer confirmations, exchange withdrawal records | Bank statements age out of easy access |
| 9 | Identity of introducer | Whoever brought you to the platform, if applicable | Often deleted once the loss is complete |
| 10 | Your own identifiers | Your sending address, and proof the funds were yours | Needed to establish standing, easily overlooked |
What makes evidence usable rather than merely present
Presence is not the standard. Usability is. These four properties are what separate a folder of screenshots from an evidence pack.
The chart below shows how much of a complaint’s actionability comes from each property, which is why the first one is worth checking twice.
What contributes most to a complaint being actioned
Relative contribution of each property to the likelihood a filing is actioned
Reading: The bottom two rows are the ones people invest the most time in. Length and emotion do not move a case; identifiers and dates do.
Building the pack
The pack is one folder with one index page. Once built, it is the same document for every destination, which is the entire reason to build it properly the first time.
Name files so they sort correctly, and never rename an original after you have sent a copy.
- 01Create one folder with subfolders: 01-summary, 02-timeline, 03-identifiers, 04-trace, 05-platform, 06-payments, 07-communications.
- 02Write the one-page summary first. Facts only: what happened, total lost, key addresses, contact details.
- 03Put the timeline in a single file, one line per event, date in a consistent format, each event in under twenty words.
- 04Put every address and hash in the identifiers file as plain text, one per line, with the chain and amount beside it.
- 05Export the trace as a file, not a screenshot set, and keep the export settings used.
- 06Caption every screenshot with the date it was taken and what it shows. An uncaptioned screenshot is close to worthless six months later.
- 07Create an index page listing every file with its date, and put it at the top of the folder.
Forty minutes of assembly produces a pack that serves a card dispute, a freeze request, an IC3 filing, a police report and a lawyer. Do it once.
Handling, and the mistakes that reduce value
Evidence deteriorates through handling more often than through absence. These are the errors that cost the most.
Note that two of them are about going too fast: filing before the pack is assembled, and confronting the platform before preserving anything.
- 01Sending originals anywhere. Copies only, keep the originals, and log what went to whom and when.
- 02Confronting the platform before capturing everything. The confrontation is what closes your access.
- 03Editing screenshots — cropping, highlighting or annotating. Keep an unaltered copy of everything alongside any annotated version.
- 04Using a single undated PDF with no index, which forces an analyst to guess what is important.
- 05Filing five separate reports as the evidence grows rather than one complete report. Duplicates have to be reconciled, which costs time.
- 06Storing the only copy on the device that was compromised.
If the device that was compromised holds your only copy of the evidence, you are one incident away from losing the case. Put the pack on a second, clean device or an account you did not use for the fraud.
Preservation requests, for the parts you do not control
Some of the most useful records are held by third parties, and third parties delete things on schedules. A preservation request is simply a dated written demand that a record not be destroyed yet — and it costs nothing to send.
Send these the same week. They are cheap, they create a dated paper trail, and they are frequently overlooked.
- 01Your own bank: ask in writing that the transaction and related communications be preserved while the dispute is open.
- 02Your card issuer: same, referencing the dispute case number.
- 03The receiving bank, where a bank transfer was involved: a preservation request can be sent directly, and it puts them on notice before any recall decision.
- 04The exchange that received on-chain funds: include the identifiers and ask that deposit records be retained pending review.
- 05The social platform or app store where the platform was advertised: report it, and reference that you have filed elsewhere.
The visual summary
Everything above, reduced to the four stages that matter for this topic. If you only look at one thing on this page, look at this.
Where this fits in the pattern
Before contact
Nothing has happened yet. This is when every tutorial here is most useful and costs you nothing but reading.
During the approach
The script is running. The verification tests in this tutorial are designed to be run here, neutrally, without confrontation.
At the money request
The decisive moment. Any request for funds, fees, taxes or unlock deposits is the end of the script, not a stage of it.
After a loss
Prevention is over; evidence work begins. Preserve, report, and never pay a second fee to recover the first.
Common questions
Generate the whole pack, formatted
Enter your details once and the Report Builder produces the complaint, the cover email, the police statement, the IC3 narrative and a demand letter — ready to attach to this evidence folder.
Primary sources and further reading
- FBI IC3 — What to Include in a Complaint www.ic3.gov
- FTC — Report Fraud reportfraud.ftc.gov
External links open in a new tab so you can verify the underlying material yourself. TrueMoneyTalk is not affiliated with these organisations.
Prevention only works if it reaches people before the contact does.
Disclaimer: this tutorial is general information, not legal, financial or recovery advice, and is not a substitute for advice from a licensed professional in your jurisdiction. Individual outcomes vary and are never guaranteed.