Guglielmo Anfossisincronik.itBook a call

A Finding Stands Without You

Constraints, episode 12

A Finding Stands Without You

A report leaves my desk on a Tuesday and arrives, weeks later, in a room I have never seen. Opposing counsel reads it. A judge reads it, or an officer deciding whether a freeze is worth asking for, or a compliance analyst deciding whether to act on an address before the weekend. Nobody in that room can ask me what I meant in paragraph nine. Whatever the document does there, it does without me.

Most investigative writing is not built for that room. It is built for the meeting where the author is present, answering questions and filling the gaps out loud. Those gaps are invisible while you are speaking, and they are the whole structure once you stop.

This is the distinction I work to. A finding makes you see it. An opinion needs you to explain it.

An opinion is a conclusion held up by its author’s hands. It stands while you speak and it drops the moment you let go. A finding stays standing after you let go, because what holds it up is inside the document: the data, the steps, and the reason each step forces the next.

Both can be true. That is the uncomfortable part. An opinion can be correct, reached by an experienced investigator with good instincts, and still be an opinion, because its correctness lives in the investigator rather than on the page. When the case moves and the investigator does not move with it, nothing travels.

Finding the answer is half the work. Representing it so that someone else reaches it independently is the other half, and it is the half that decides whether the first half survives contact with anyone.

Two layers, and the line between them

The raw material helps here. On-chain data is not a statement made by someone, it is residue left by something. Nobody wrote a transaction to be read, which is why it cannot be phrased, spun or softened, and why I trust it more than any document a party hands me. It is also why it never tells you who. A name laid over a residue is a reading, and a reading is an act performed by a person.

So every report I write has two layers. What the chain forces, and what I concluded from it. Both belong in the document. Only one of them is checkable by looking, and the reader has to be able to tell which sentences are which without asking me.

That sounds easier than it is, because the two layers are written in the same sentences, in the same tone, and a conclusion inherits the authority of the data sitting next to it. “The funds were consolidated by the attacker before the swap” is one clause of record and one clause of attribution, fused. The record part is a set of transfers into one address. The attribution part is mine, resting on timing, on control, on behavior consistent across addresses, and each of those is a judgment someone can dispute without disputing a single transaction.

Splitting that sentence costs a paragraph and buys the whole document. The transfers go where they can be reproduced from primary data. The attribution goes where it is named as an attribution, with the grounds under it and the alternative it rules out.

Where the reading always enters

Some of these joins are so routine that they stop looking like inferences, and those are the ones worth marking hardest.

A cluster is a model, not a fact about the chain. Common-input heuristics and behavioral similarity produce a grouping that is usually right and occasionally load-bearing, and when it is load-bearing it has to be visible as a hypothesis with evidence under it rather than as a name on a diagram.

The purpose of a contract call is read from its code and its effects, not from its label. A decoded payload shows what executed. What it was for is my sentence.

Intent is never on the chain at all. The chain records the movement. Whether that movement was theft, a withdrawal, a service payment or a mistake is a reading built from context that mostly lives off-chain.

None of these should be kept out of a report. A document that refuses to interpret is not evidence of rigor, it is a set of transaction hashes that leaves the whole job to the reader. The discipline is in interpreting out loud, in a way that lets somebody accept the data and reject my reading of it, which is exactly the move an adversary will try to make.

The assumptions that never get written

There is a quieter version of the same problem. The premises I do not state are the ones I no longer notice: that a labelled address still belongs to whoever it was labelled as, that a data source reflects the chain’s current state, that a balance shown by a platform tracking transfers matches what the contract itself would say, that the scope I was handed rests on a correct account of what happened.

Each of those can be wrong without anything in my reasoning looking wrong. Stating them changes the failure mode. An unstated assumption that turns out to be false takes the conclusion down with it silently. A stated one gives the reader a place to check, and gives me a document that fails loudly, which is the only kind of failure worth having.

Who has to be able to walk it

None of my readers can take my word for it, and this is not a matter of trust. An analyst validating a freeze request works against criteria I do not set. An officer, in most jurisdictions, cannot adopt what I found at all, because the investigation has to be theirs and every step they cannot reproduce is one they rebuild from nothing. A lawyer takes me as the expert and comes back with objections that should have been answered before they were raised.

The requirement is constant across all three, and the shape it arrives in is not mine to choose. What survives the difference is the separation itself: a document whose layers are already apart can be re-cut for a reader who needs it presented another way. One that fused them has to be rebuilt from the beginning.

The test

Hand the work to someone who wants it wrong.

That is not a thought experiment in this field. Adversarial review is the default condition: a defense lawyer, an exchange’s counsel, a colleague paid to find the seam. If they reach my conclusion only while I walk them through it, it was never a finding. It only looked like one from where I was standing.

It is also why I prefer deterministic, auditable reasoning to opaque probabilistic output. Probabilistic output is often accurate. Auditable reasoning can be shown to be wrong, and that is the only condition under which being right means anything.

The complication I will not pretend away: sometimes the strongest conclusion available is probabilistic, and no amount of discipline turns it into a proof. A cluster attribution resting on behavioral similarity is a reading, and it stays a reading however many analysts share it. The honest move is to mark it as one, in the sentence where it appears, and keep it structurally separate from what the chain forces. A report written that way has fewer confident lines in it. It survives cross-examination on the lines it kept.

Most cases I have watched fall apart did not fall apart over the data. Both sides had the same data. They disagreed about what the data was allowed to mean, and the side that lost was usually the one whose document could not show where its own meaning had been added.

Where this leaves the writing

Pedagogy set the standard and I still work to it: a reconstruction nobody can walk through without me is only a report that a reconstruction once happened. So I do not write to be believed. I write to be understood by someone who is not in the room, every step laid down for a reader to walk alone, and to break if they can.

The practical form of that is unglamorous. Stated premises, inferences labelled as inferences, and fewer sentences that sound certain. What it buys is a case that keeps working when I am not there to defend it, and an error that can be found by someone other than me.

An opinion can be right. A finding stands without you.

Could an adversary reach your conclusion from the document alone?

Next: Episode #13: The Strings Stay Public (Why Tracing Is Not Enough)