What device and login records may assist cryptocurrency attribution?¶
Device and login records can help connect cryptocurrency account activity to a particular access route, device or user context.
Avoid the dangerous assumption¶
The dangerous assumption is that one IP address or device identifier proves who completed the transaction.
Useful provider records may include login times, IP addresses, device names, operating systems, browser details, application versions, session IDs and authentication methods.
They may also include failed logins, password resets, recovery events, new-device registration and security alerts.
Transaction records should be compared with the active device and session at the relevant time.
A withdrawal may be requested on one device and approved on another.
Notifications may also appear on several devices without showing which one initiated the action.
IP addresses can be shared, reassigned or obscured by mobile networks, VPNs, proxies or organisational connections.
Device names may be user-selected and inaccurate.
A registered device may remain authorised after it is sold, replaced or passed to another person.
Preserve the provider’s original device and session identifiers, not just the friendly names shown to the customer.
Compare provider records with seized-device artefacts, application data, communications, location evidence and account behaviour.
Look for converging evidence rather than a single technical match.
When reporting, state what the provider record associates with the account and transaction.
Do not describe the device owner or subscriber as the user unless the wider evidence supports that conclusion.
Operational takeaway¶
Use device and login records to identify access routes and sessions, then corroborate the actual user through device examination, communications and surrounding evidence.