Inspiration
I was hacked once for $80K. Then I spent four years volunteering in cybercrime analytics for victims with law enforcement. The hours right after a scam are the only hours a freeze request or a complete FBI IC3 complaint can still change the outcome — and they are exactly the hours a panicked, ashamed victim can't produce one or doesn't know where to go. Institutional forensics vendors won't touch cases too small below ~$2m USD, and law enforcement needs a format nobody tells you about or it's too hard to make them understand or act in time. Recourse is the first responder I wish had existed for me.
What it does
Paste your story in plain language, with whatever fragments you have — transaction hashes, wallet addresses, amounts, dates, URLs, or even voice to text transcription using an LLM. Recourse produces a canonical case file, an FBI IC3 complaint draft mapped to the real form's seven steps, an exchange freeze / records-preservation letter, an ordered action plan with official reporting links (exchange first, because funds move in hours), and an explicit list of everything it could not verify. A Strands agent runs the interview: it asks for one missing item at a time, most recoverable first — a bank wire with no reference number before anything else, because it's the only leg a bank can still try to recall — and screens the "we can get your money back" pitches that re-target victims within days. Every document is a draft for the victim's review. Nothing is ever guessed.
How we built it
Strands Agents SDK (Amazon Bedrock by default, Anthropic API optional) wrapping nine deterministic Python tools. Every hash, amount, and date is extracted by code and traced to a verbatim substring of the victim's story; the model narrates and interviews but never computes a fact. Facts the victim supplies mid-conversation enter through add_detail, which appends their words to the story and rebuilds — same provenance as everything else. Identity enters only through set_complainant, never from the story, because the email in a scam story is the scammer's. The drafting tools accept a case id and nothing else, so there is no story parameter for a model to paraphrase. The one place the model authors filing content — the IC3 narrative — passes through the same anti-invention audit before acceptance: any figure not traceable to the victim's words is rejected with the violations listed. A local web workbench shows every extracted fact beside its source quote. An eval gate (8 golden scenarios, 208 tests, runs in CI on every push) fails the build on any untraceable fact — and self-tests by tampering filings with an invented hash to prove it can fail.
Challenges we ran into
Making invention structurally impossible rather than merely discouraged by a prompt. Reading "$2.5 million" without it silently becoming $2.50 in a federal filing. Never adding BTC to dollars. Telling a stated total ("$10,000 across four transfers") apart from a transfer so the loss isn't overstated. Labeling "$12,500 worth of ETH" as ETH, not USD, on a letter to an exchange fraud desk. And never guessing who the victim is from a story where the only name and email belong to the scammer.
Accomplishments that we're proud of
The boundary holds: the model is never allowed to know a number, and the audit that enforces it runs at runtime on the model's own text, not just in CI. The eval gate caught real fabrications in our own extractor during the build — the $2.50 bug among them — which is exactly what it exists to do. The whole pipeline runs offline with no key and no network: same story in, same case id and same drafts out, on any machine, any day. And the recovery-scam screener addresses the second theft almost every victim faces and almost no tool mentions.
What we learned
Conservative extraction is a product decision, not a limitation: a missed fact lands in the "not verified" list and the victim can add it; a fabricated fact poisons a federal filing. An agent earns its place by doing what only an agent can — asking the right next question — while everything exact stays in code. And an honest "here is what we could not verify" builds more trust with a victim than any confident-sounding summary.
What's next for Recourse
Live-model hardening of the interview loop, a hosted front door so a victim never opens a terminal, bank recall letters for wire legs, and Solana/Tron identifiers. Built during the submission window with AI coding assistants, per the rules; all code net-new for this project. Apache-2.0.
Built With
- amazon-bedrock
- anthropic
- python
- strands-agents

Log in or sign up for Devpost to join the conversation.