HomeDocumentationIncident Analysis

    Incident Analysis

    Incident Analysis turns a raw attacker address into a structured forensics report. You create an incident, run the fund trace, and ChainHint automatically evaluates the risk, computes the estimated loss in USD, and generates an AI-powered narrative report.

    Analysis Pipeline

    1

    Create Incident

    Enter the attacker address and incident date. ChainHint saves it as a draft.

    2

    Fund Trace

    Run BFS from the attacker address. Graph shows where funds went — exchanges, mixers, bridges.

    3

    Auto-Analysis

    Claude AI analyzes the trace graph, classifies the attack type, and scores the incident risk (0–100).

    4

    Report & Export

    Get a written forensics report, estimated loss in USD, and a compliance-ready PDF export.

    Loss Calculation

    Every transfer is valued with DeFiLlama historical prices for the day it moved — not one price for the whole trace. A trace that runs over weeks or months would otherwise report what the assets were worth on a single arbitrary date. Both native tokens (ETH, BTC, SOL, BNB…) and ERC-20 / SPL tokens are included, and tokens are priced strictly by contract address, never by the symbol they report about themselves.

    A token with no historical price for a given day is left unpricedrather than valued at today's price, and the graph records which days it could and could not price. Each transfer also carries its value at today's price, so you can switch between "value when moved" and "value today" without re-running the trace.

    Attack Classification

    Flash Loan AttackReentrancyPrice Oracle ManipulationPrivate Key CompromiseRug PullPhishing / Social EngineeringBridge ExploitSmart Contract BugGovernance AttackMEV / Sandwich
    Incident detail page — AI analysis report
    Incident view with risk score, estimated loss, attack classification, and traced fund flow