Falsify First: The Question I Ask Before I Believe My Finding
Before I report a finding, I ask what else could produce the same on-chain record. A conclusion is only as strong as the credible alternatives it has already survived.
The easy part of investigation is finding a pattern that fits a story.
The hard part is asking what else could produce the same record.
That question should arrive before the conclusion is written, not as a disclaimer added at the end. A pattern that feels obvious can still have an ordinary explanation. A familiar-looking route can be shared infrastructure. An address that appears inactive can still be relevant through activity the surface view does not show.
The point is not to become paralysed by alternatives. It is to make the alternatives do work. If a finding survives them, the conclusion is stronger. If it does not, the report has avoided a mistake before anyone else has to find it.
A pattern is not yet an explanation
Suppose a set of movements looks coordinated. That may be consistent with common control. It may also be consistent with a shared service, routine settlement, or an unrelated sequence that merely resembles coordination at first view.
The observable record is still useful. It may justify a focused question, a request for more records, or a carefully bounded finding. What it cannot justify is skipping directly to the explanation that feels most satisfying.
This is why the language in Evidence Tiers matters. Observed facts and interpretations belong in different places. Falsification is the discipline that keeps them there.
The rival explanation test
Before I trust a conclusion, I ask four questions:
- What exactly is observed, with no conclusion attached?
- What explanation does the observation appear to support?
- What other credible explanation could fit the same observation?
- What evidence would distinguish those explanations?
The fourth question is often the most valuable. Sometimes the answer is public information. Sometimes it is a record held by an exchange, a platform, a company, or a person with legal authority. Sometimes the distinction cannot yet be made. Each outcome changes how the finding should be written.
Why this protects a case
A report gains credibility when it volunteers the ordinary explanation a sceptical reader would raise anyway. It shows the reader that the conclusion was tested, rather than merely discovered.
It also makes handovers better. A lawyer, compliance team, or investigator can see which question remains open and what kind of record would help resolve it. The work moves forward instead of hardening into an unsupported claim.
In I Name the Crime Last, Not First, the same idea operates one level higher. A category chosen too early can make later observations look like proof. Falsification interrupts that loop by keeping alternatives alive until evidence rules them out.
This is not a recipe for public disclosure
There is a line worth keeping. Explaining that competing explanations must be tested is useful professional practice. Publishing the exact signals, thresholds, or methods used to separate them can expose investigative capability or make a public article into a playbook.
The public standard is therefore simple: name the question, state the evidence boundary, and explain the conclusion at the level the record supports. Keep the operational answer key where it belongs.
A report should be harder on itself first
The best time to discover a weak alternative explanation is before the report reaches a client, a court, or the person whose conduct it discusses.
That is why “what else could explain this?” is not a caveat. It is part of the investigation.