PDF Forensics Exposes Forged Proof-of-Funds Letters in Crypto OTC
Crypto OTC desks lack automated checks on proof-of-funds PDFs. Forensic patterns reveal how forged bank letters slip past compliance and how to catch them.
Proof-of-funds (POF) letters — the one-page bank attestations that gate multimillion-dollar crypto OTC trades — remain a structural blind spot for most desks. Compliance teams eyeball letterhead, signatures, and reference numbers, while on-chain analytics tools like Chainalysis or TRM Labs only see wallet history, not the PDF sitting in the inbox.
Forensic analysis of these documents reveals three distinct forgery patterns, each leaving a different structural signature. Altered real letters — produced by overwriting a genuine PDF with consumer tools like Adobe Acrobat or Smallpdf — leave visible traces: multiple write sessions in the cross-reference table and mismatched creation/modification timestamps. More sophisticated forgeries, such as screenshot-wrapped letterheads built with jsPDF or img2pdf, or fully rebuilt documents generated from scratch with PDFKit or ReportLab, produce clean, internally consistent files with no editing history, returning an inconclusive verdict rather than a clear modified flag.
For institutional crypto desks, that inconclusive verdict is the actionable signal: private banks don't issue POF letters through general-purpose PDF libraries, so a mismatch between claimed origin and toolchain fingerprint should trigger an independent callback to the bank — using a switchboard number pulled from the bank's own website, not the one printed on the letter. With trade sizes in the $5M-$50M range, structural PDF analysis pays for itself even under a low forgery-frequency regime.