Incident timelines correlate on-chain transactions with off-chain events — phishing emails, device changes, support contacts, and user actions — to establish sequence and causation hypotheses.

Precise timestamps, timezone normalization, and block confirmation times anchor on-chain events. Off-chain logs from email, devices, and exchanges fill contextual gaps.

Timeline reconstruction supports internal incident review, advisor consultation, and evidence organization for potential legal proceedings.

Timeline quality depends on evidence preservation; delayed or incomplete records weaken forensic conclusions.