Wallet type changes who controls the keys and how much cooperation or access an investigator may need. A hosted wallet usually means a third party retains key control, while an unhosted wallet places control with the user. That distinction affects evidence collection, attribution, and the likely next steps for tracing funds or seeking records from service providers.
How wallet type changes the investigative path
Wallet classification is not a label exercise, it determines where evidence can realistically come from and who can be compelled or asked to produce it. If a wallet is hosted, the provider may hold logs, account metadata, or transaction context that can support tracing. If it is unhosted, the investigator usually has to rely more heavily on blockchain analysis, device evidence, and user attribution.
The practical difference is control. With a hosted wallet, the investigator may be able to pursue records from a service provider, correlate account activity with KYC or access logs, and test whether the suspect ever controlled the account directly. With an unhosted wallet, that cooperative path is usually absent, so the investigation shifts toward device forensics, wallet software artifacts, and behavioural links to the transaction graph.
Wallet type also changes how you interpret movement of funds. A hosted wallet can reflect platform-controlled operational behaviour, while an unhosted wallet more strongly suggests direct key control by the user or a party acting through that user-controlled environment. That affects whether the next step is a records request, a preservation notice, a subpoena, or a purely technical tracing workflow.
Why custody and access assumptions matter
The custody model affects how much confidence you can place in the identity behind a transaction. Hosted wallets often leave a wider evidentiary trail, but that trail belongs to the provider and may not map cleanly to the beneficial owner or the person currently using the account. Unhosted wallets can be harder to attribute because there may be no intermediary records at all, only on-chain activity and whatever endpoint evidence survives.
That distinction matters because investigators often need to decide whether the key issue is possession, control, or mere association. A wallet can appear linked to a suspect address while the actual signing authority sits elsewhere, or while multiple users share access to the same hosted service account. The wallet type therefore shapes the strength of any attribution claim and the kinds of corroboration that should be sought.
In practice, wallet type can also change the evidentiary threshold for action. If the wallet is hosted, the best evidence may be provider logs and account records. If it is unhosted, the best evidence may be a recovered seed phrase, a browser profile, a hardware wallet device, or signs that a particular machine initiated the signing event.
What changes in tracing, records requests, and follow-up steps
Once you know the wallet type, the investigation path becomes more efficient. Hosted wallets support requests for records, account freeze actions where available, and time-bounded searches around login, withdrawal, and device access. Unhosted wallets generally do not support those shortcuts, so tracing becomes more dependent on chain analytics, exchange chokepoints, and linkage from endpoint or network evidence.
That is why wallet type should be identified early in the case. It helps decide whether the next best step is preservation of provider records, imaging of a suspect device, analysis of seed phrase artifacts, or follow-up with exchanges and virtual asset service providers. For a useful overview of how identity, custody, and control affect investigative decisions, see eIDAS 2.0, the EU Digital Identity Framework, which illustrates how digital wallet models can change trust and verification assumptions.
Risk and Threat Considerations
Wallet type is a risk signal because it changes the available control surface. Hosted services can expose account takeover, insider access, log retention gaps, or delayed cooperation; unhosted wallets can expose poor key hygiene, loss of control, and limited recoverability after compromise or deletion.
Failure mechanism: Investigators misclassify the wallet as hosted or unhosted, then pursue the wrong evidence path, miss provider records, or overstate who actually controlled the keys at the relevant time.
Impact: Attribution weakens, fund tracing slows, preservation opportunities are lost, and the case can hinge on weaker circumstantial evidence instead of the strongest available records.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP API Security Top 10 address the attack surface, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-9 — Service Identification and Authentication | Wallet custody affects how service-side access and authentication evidence is obtained. |
| Recommendation — Use IA-9 to govern service-controlled access and retain authentication evidence for hosted wallet investigations. | ||
| NIST CSF 2.0 | ID.AM-07 — Inventories are maintained of network, software, and hardware assets | Investigations depend on identifying whether evidence sits with a provider, device, or user-controlled wallet stack. |
| Recommendation — Inventory the wallet ecosystem and evidence sources before choosing a tracing or preservation path. | ||
| MITRE ATT&CK | TA0006 — Credential Access | Wallet investigations often hinge on whether keys, seed phrases, or access tokens were obtained or abused. |
| Recommendation — Map key theft and access abuse to credential-access techniques when reconstructing wallet compromise. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | Hosted wallet platforms depend on account authentication that can determine access and evidence availability. |
| Recommendation — Assess hosted-wallet access paths for authentication weaknesses that could affect account control and logs. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Wallet type changes who controls access and what records can be requested or preserved. |
| Recommendation — Apply access-control governance to distinguish custodial from user-controlled wallet evidence paths. | ||
Practitioner Guidance
What to verify: Determine whether the wallet is custodial, non-custodial, or a hybrid arrangement before you choose the next collection step. The key question is not the brand name of the wallet, but who could sign transactions and who can produce logs or account records.
Decision rule: If a third party can access, freeze, or export account data, prioritize preservation and records requests early. If only the user controls the keys, prioritize endpoint, device, and chain-based evidence before assuming any provider will be able to help.
Practitioner takeaway: The wallet type tells you whether the investigation should run through a service provider, a device, or the blockchain itself, and that choice often determines whether attribution is strong enough to stand up later.