What evidence may connect a wallet to a device?¶
A wallet can be connected to a device through application data, key material, transaction artefacts and user activity found on that device.
Avoid the dangerous assumption¶
The dangerous assumption is that finding a wallet application proves the device controlled every address or transaction displayed within it.
Relevant evidence may include installed wallet software, account files, wallet databases, addresses, transaction history, seed phrases, private-key material and hardware-wallet connections.
Browser history, extensions, downloaded files and connected websites may also show wallet use.
Notifications, screenshots, copied addresses, QR codes and communications can link the wallet to specific transactions or instructions.
Device timestamps should be compared carefully with blockchain and provider records.
A wallet may be watch-only, meaning it displays addresses without controlling their keys.
It may also have been imported from a seed phrase used on several devices.
Cached or synchronised data can remain after active control has ended. A deleted or abandoned wallet may also leave addresses and transaction artefacts on the device.
Do not open, update or synchronise wallet software unnecessarily.
That may alter artefacts, expose network information or affect live assets.
Preserve the device through an appropriate forensic process and seek specialist support where sensitive key material or recoverable funds are involved.
Look for evidence of transaction creation, signing, address generation, wallet recovery or interaction with a hardware wallet rather than presence alone.
When reporting, distinguish the wallet application, address visibility, key possession and proven transaction control.
Operational takeaway¶
Connect a wallet to a device through key, application, transaction and usage artefacts, while excluding watch-only, imported, shared or stale wallet data explanations.