
Disclaimer: This article draws on cryptocurrency probate cases supported by AnChain.AI as blockchain forensics experts and relies solely on publicly available information. It is provided for technical and informational purposes only and does not constitute legal, tax, accounting, or investment advice.
Nearly one in five U.S. adults has used cryptocurrency, rising to 27% among upper-income households, per 2026 Pew Research. As digital assets become a more meaningful part of private wealth, they are increasingly surfacing in estates, trusts, divorces, and probate disputes.
QuadrigaCX case offers a striking example.
Four years after the QuadrigaCX (Canadian crypto exchange)’s founder, Gerald Cotten, died, multiple Bitcoin addresses tied to the failed platform suddenly moved approximately 104 BTC. The blockchain could show exactly when the funds moved, which UTXOs were spent, and which outputs received them. It could not show who controlled the private keys, whether the transfers were authorized, or who legally owned the assets.
That gap between transaction evidence and legal ownership is one of the central technical challenges in cryptocurrency probate.
QuadrigaCX was an insolvency proceeding rather than a conventional probate case, but the forensic issues closely mirror those now appearing in estates, trusts, divorces, and private-wealth disputes. Creditors ultimately filed claims for approximately 24,427 BTC, 65,458 ETH, and 87,031 LTC. Depending on the valuation date used in the proceeding, total claims were calculated at approximately C$224.3 million or C$290.8 million—a C$66.5 million difference. [Court file from ONTARIO SUPERIOR COURT OF JUSTICE]
For investigators, the case reduces to three distinct questions:
Those questions require different evidence, different forensic techniques, and different levels of confidence.
In this article, AnChain.AI uses public QuadrigaCX court records and blockchain data to demonstrate how professional crypto forensics can reconstruct assets, trace fund flows, establish attribution, and address the five technical and legal challenges of cryptocurrency in probate and estate disputes.
Court-appointed monitor Ernst & Young identified six historical
QuadrigaCX Bitcoin cold-wallet addresses:

View the live crypto graph: https://ciso.anchainai.com/s/5JE0jZEzxkr
The monitor reported that approximately 104 BTC had been inadvertently transferred into inaccessible cold wallets in February 2019. Five of the identified addresses later spent their balances during a narrow period in December 2022.
One of the corresponding transactions included:

The bitcoin ledger establishes the transaction path. It does not independently establish the human signer, authorization, beneficial owner, or legal purpose. This is why blockchain evidence must be interpreted rather than merely displayed.
A Bitcoin address is not a wallet.
Modern Bitcoin wallets commonly use hierarchical deterministic key structures. Under BIP-32, a root key can derive large numbers of receiving and change addresses. BIP-39 can introduce an optional passphrase: the same mnemonic combined with a different passphrase produces a different seed and therefore a different wallet.

An executor may recover the correct 12 or 24 words, restore a wallet, see zero BTC, and incorrectly conclude that no assets exist. The funds may be associated with another passphrase, derivation path, account index, address type, or multisignature configuration.
The same discovery problem extends beyond Bitcoin. An estate may contain ETH in self-custody, stablecoins at centralized exchanges, assets in a multisignature wallet, collateral in a lending protocol, staking positions, or tokens bridged onto Layer 2 networks.
A professional investigation therefore expands from known evidence---addresses, xpubs, wallet descriptors, devices, transaction hashes, exchange withdrawals, tax records, and smart-contract interactions---to build the most complete evidence-supported inventory
possible.
Bitcoin does not maintain conventional account balances. Its spendable state consists of unspent transaction outputs, or UTXOs. A transaction consumes previous UTXOs and creates new outputs:
Input value = output value + transaction fee
The transaction lineage is deterministic. Ownership attribution is not.

One widely used technique is the common-input ownership heuristic. When several addresses provide inputs to an ordinary transaction, investigators may infer common transaction control because the spending conditions for those inputs had to be satisfied together.
Change-address detection can extend the cluster. If a wallet spends a large UTXO to make a smaller payment, the remainder will often return to a new address controlled by the sender. Repeatedly following these change outputs can reveal a peel chain and expose systematic
liquidation or transfers to exchanges.
These techniques require caution. CoinJoin deliberately combines unrelated participants. Exchanges consolidate UTXOs associated economically with many customers. One incorrect heuristic connection can propagate through a cluster and create false attribution.
For court-facing analysis, deterministic transaction edges and heuristic ownership edges should be clearly distinguished.
Ethereum and other smart-contract networks require a different forensic model than bitcoin.
A single transaction may call a router, execute swaps, deposit collateral, create debt, mint a vault share, and transfer assets through several contracts. Looking only at from, to, and value can miss most of the economic activity.

Investigators may need to reconstruct event logs, call traces, token transfers, protocol state, and historical contract implementations.
A wallet showing little ETH can still control substantial wealth. If 500 ETH was deposited into a lending protocol and USDC was borrowed against it, the relevant estate position includes collateral, receipt tokens, rewards, and outstanding liabilities.
A useful forensic model is:
Net position = spot assets + rewards − liabilities − exit costs
For DeFi-heavy estates, wallet balance and economic ownership can be materially different.
A modern asset flow may cross several entities on different blockchains:
BTC → centralized exchange → USDC on Ethereum → bridge → Arbitrum →
DEX → DeFi wallet
(There is no universal transaction ID connecting these networks)

Cross-chain analysis instead correlates protocol-specific evidence such as bridge contracts, message identifiers, nonces, source events, destination recipients, token mappings, and mint or release transactions.
Centralized exchanges create a more important evidentiary break. If BTC enters an address attributed to Kraken, the blockchain may support attribution of the endpoint to Kraken-controlled infrastructure. It generally does not identify the customer.
Customer identity sits behind the exchange's internal ledger and may require KYC information, deposit-credit records, trading history, withdrawal instructions, IP records, or legal process.
The distinction is important:
A transaction graph is not a forensic opinion.
Court-facing analysis should separate four layers of evidence: blockchain fact, technical inference, real-world attribution, and legal ownership.

A confirmed Bitcoin transaction is a blockchain fact. Identifying an output as change is a technical inference. Associating an address with an exchange is attribution. Determining that the cryptocurrency legally belongs to an estate is a legal conclusion.
Those layers should not be collapsed. Possession of a private key demonstrates the ability to satisfy a blockchain spending condition. It does not necessarily establish beneficial ownership. The key holder could be an owner, executor, trustee, custodian, employee, or unauthorized possessor.
A defensible forensic record should preserve transaction hashes, addresses, block data, attribution sources, clustering methodology, valuation inputs, analyst annotations, and confidence levels.
QuadrigaCX is often remembered as a lost-private-key story.
From a blockchain forensic perspective, it was much more: a case involving custody, asset segregation, attribution, accounting, valuation, and evidentiary reconstruction.
The blockchain can show where assets moved. Determining who controlled it, who legally owned it, and proving those conclusions in court is the work of blockchain forensics.
AnChain.AI combines blockchain intelligence, crypto tracing, graph analytics, and expert forensic review for complex digital-asset investigations.
Need help with a crypto probate or estate matter?
Schedule a consultation : https://anchain.ai/investigation
Disclaimer: This article draws on cryptocurrency probate cases supported by AnChain.AI as blockchain forensics experts and relies solely on publicly available information. It is provided for technical and informational purposes only and does not constitute legal, tax, accounting, or investment advice.