Inspiration
A friend of mine had his wallet compromised, and I watched him spend days trying to trace what happened manually. He was jumping between explorers, transactions, and addresses, trying to understand how the attack happened and where his funds had gone. Eventually, the experience frustrated him enough that he basically gave up on crypto.
When I saw the Taskmaster challenge, I immediately thought about that experience. After a wallet compromise, the victim should not have to become an onchain investigator just to understand what happened.
That became the idea behind NEMESIS: give it the affected wallet and let an autonomous agent investigate the incident, identify the likely compromise, trace the stolen funds, keep watching when the trail goes quiet, and surface the strongest evidence and next actions available for recovery or escalation.
so when someone comes after your wallet, NEMESIS goes after them.
What it does
NEMESIS is an autonomous crypto incident response agent that investigates compromised wallets, traces stolen funds, and continues monitoring when the trail goes quiet.
A user can start with only a wallet address. NEMESIS searches the wallet's history, ranks possible incident transactions, verifies the likely compromise using deterministic onchain evidence, reconstructs the stolen assets, and traces subsequent fund movement across multiple hops and branches.
When funds stop moving, NEMESIS does not simply end the investigation. It keeps affected branches under monitoring and can resume tracing when new movement is detected.
Throughout the investigation, deterministic facts, AI interpretation, and unknowns are kept clearly separated so the system does not present assumptions as evidence.
How we built it
NEMESIS uses a FastAPI backend with Firestore for persistent investigation and branch state. Google ADK and Gemini provides constrained incident assessment while deterministic tracing remains grounded in verified blockchain data.
Alchemy, Chainabuse and other onchain data sources that support transaction discovery and fund tracing. Google Cloud Run hosts the application, while Cloud Scheduler and Pub/Sub power the asynchronous monitoring loop that allows NEMESIS to continue working after the user's initial investigation.
The frontend then presents the resulting investigation as a case containing the incident assessment, fund graph, evidence, timeline, branch states, and next actions.
Challenges we ran into
One of our biggest challenges was getting NEMESIS to follow a real hack beyond the first few transactions. In our early tests, it could identify the incident correctly, but the trace would stop after only two hops. We had to keep testing against real incidents until NEMESIS could follow the funds across multiple addresses and branches.
We also ran into a problem where blockchain data providers would sometimes slow down or stop responding during larger investigations. That forced us to make NEMESIS distinguish between “the trail ends here” and “I couldn't retrieve enough data to continue.” We didn't want a technical failure to become a false conclusion.
Finally, building the background monitoring was harder than simply tracing once. We wanted NEMESIS to remember a case, keep watching dormant funds, and automatically continue the investigation when those funds moved again, without the victim having to start over.
Accomplishments that we're proud of
We built and deployed a real end-to-end investigation workflow rather than a scripted demo.
In our Bybit incident test, NEMESIS started with only the affected wallet, examined 69 candidate transactions, independently selected the correct incident transaction with 1.0 selection confidence, and traced the resulting fund movement across a multi-hop branching graph.
We are especially proud of the autonomous monitoring loop. Dormant branches remain monitored in the background, and NEMESIS can automatically resume tracing when new movement appears without requiring the user to restart the investigation.
What we learned
Building NEMESIS taught us that tracing stolen crypto is much harder than simply following transactions from one wallet to another. Funds can split across many addresses, move through different types of transactions, or remain dormant before moving again.
We also learned how important it is for an investigation tool to know when it has enough evidence to make a conclusion and when it doesn't. That shaped how NEMESIS separates verified onchain evidence from its own assessment and clearly shows what is still unknown.
What's next for Nemesis
Next, we want to expand NEMESIS to more chains, strengthen attribution of exchanges, bridges and other destinations, and make its recovery and escalation workflows even more useful.
Our longer term goal is for NEMESIS to become an incident response layer that victims and investigators can turn to immediately after a wallet compromise, from discovering what happened to tracing the funds, monitoring future movement, preserving evidence, and helping determine the best next action.
Built With
- cloud-run
- cloud-scheduler
- fastapi
- firebase-authentication
- firestore
- gemini
- google-adk
- google-cloud
- next.js
- pub/sub
- python
- typescript
Log in or sign up for Devpost to join the conversation.