Community Investigation

MUSystem: The four-transaction Ethereum sequence

dooooo
dooooo

October 05, 2026

Neutral ChainBounty cover reading MUSystem, Four transactions on Ethereum, 30 September 2026, Ethereum.

ChainBounty · Report analysis · CASE-10DA91A7

Ethereum mainnet · Activity: September 30, 2026 · Source: SentinelTX report generated October 5, 2026

SentinelTX’s MUSystem report follows four Ethereum transactions that combine supplied capital, repeated deposit-and-return cycles, and repaid flash loans. It reports a 5.335155071161390070 ETH reduction at the affected contract and a 3.190655071161390070 ETH increase at the initiating account before fees. A third address received 2.1445 ETH. The distinction between those amounts is central to the report: receipts, account changes, and an incident-wide loss answer different questions.

Report status matters here. The exported PDF says its automated integrity gate downgraded six claims and flagged one finding. Its chronology and conclusion carry an “unverified (auto-downgraded)” label, and page 83 flags a time-inverted path. This article presents the report’s findings with those qualifications. The figures below adapt its bounded transaction narrative; they do not reproduce the flagged onward path or certify the report’s findings. (SentinelTX, pp. 4, 10, 17, 21, 83)

The scope of the report

All four transactions fall in Ethereum block 26,087,602, timestamped September 30, 2026, at 03:27:35 UTC. SentinelTX calls the first transaction the Run and the following three Sample 1, Sample 2, and Sample 3. The report’s accounting covers those four operations. It does not establish that they comprise the entire campaign or all activity involving the affected contract.

The principal roles are the initiating and receiving externally owned account, or EOA; the contract it created and used to coordinate the operations; the affected MUSystem contract; and newly created helper contracts. The report calls the coordinating contract the attack contract. This article uses “orchestration contract” to make its execution role clear without suggesting a separately identified operator. The third recipient’s role and control remain unresolved.

The report sets an observation cutoff of October 5, 2026, at 10:00 UTC. It separately identifies address-history, token, and balance observations retrieved around 10:11–10:15 UTC that day as later observations. That distinction matters when reading its statements about activity after the four transactions. (SentinelTX, pp. 4, 8, 18)

The Run belongs in the calculation

The last three transactions produced receipts of approximately 5.9475 ETH, 5.0703 ETH, and 2.8368 ETH for the EOA. Together, those receipts total 13.854604425661360100 ETH. Looking only at that part of the sequence omits the EOA’s earlier contribution in the Run.

In the Run, the EOA sent 10.7 ETH to the orchestration contract and received 0.036050645500029970 ETH back. Its net change for that transaction was therefore −10.663949354499970030 ETH before fees. The Run also contained the same repeated-cycle pattern seen later; it was more than a preliminary funding transfer.

SentinelTX breaks the Run into a priming deposit and sixteen helper cycles. The orchestration contract first paid 44.101139073399812544 ETH to the affected contract. During that call, the affected contract sent 26.460683444039887526 ETH back to the orchestration contract and 2.1445 ETH to the unresolved third address. The report gives the affected contract’s net increase on this leg as 15.495955629359925018 ETH.

The sixteen subsequent cycles reduced the affected contract’s ETH by 6.976506274859954988 ETH. Combining those two parts leaves the affected contract with a reported Run increase of 8.519449354499970030 ETH. The later sample transactions then reduce that amount. Including the Run is essential to understanding the four-transaction result. (SentinelTX, pp. 6, 10–11)

Four ordered rows show Run with 16 helpers, Sample 1 with 16, Sample 2 with 16 and Sample 3 with 11. All share block 26,087,602 and 30 September 2026 at 03:27:35 UTC. Total: 59 helpers. Report findings are marked unverified.

Figure 1. The report’s four-transaction sequence in one Ethereum block. It records 16 helper contracts in the Run, 16 in Sample 1, 16 in Sample 2, and 11 in Sample 3, for 59 in total. These counts describe contracts, not independent people. All four transactions share the block timestamp; spacing shows sequence rather than elapsed time.
Color key: Slate identifies sequence markers and the directly labeled helper counts.
Source: SentinelTX, CASE-10DA91A7, pp. 4, 8, 10, 13–15. The chronology is marked unverified by the report’s automated gate. Transaction links appear in the source register below.

One deposit, two returns

The first helper cycle in Sample 1 provides a compact example of the pattern SentinelTX describes. The proxy at 0x8b0856e9b0787d09f9abded66bccc85feb5561d4 calls the affected contract with 53.355703172210117028 ETH. It receives an initial payment of 32.253522567601017211 ETH. After a second call, it receives another 21.502348378400678141 ETH.

The two payments total 53.755870946001695352 ETH. The proxy then forwards that amount to the orchestration contract. The excess over the original deposit is 0.400167773791578324 ETH for this cycle. Repeated deposits and forwarding create much larger gross movement volumes, so adding every leg would obscure the net result. The report explicitly excludes gross helper forwarding and large graph aggregates from its economic totals. (SentinelTX, pp. 12, 15)

Three left-to-right rows show one proxy P depositing about 53.3557 ETH to the affected contract, the affected contract returning about 32.2535 ETH to P during the deposit, and a second return of about 21.5023 ETH to P. P is the same proxy in all rows. Reported excess is about 0.4002 ETH; cycle observation is marked unverified.

Diagram 1. The ETH legs in Sample 1’s first helper cycle, as described in the report. The same proxy sends 53.355703172210117028 ETH and receives two payments totaling 53.755870946001695352 ETH, an excess of 0.400167773791578324 ETH. Artwork values are rounded. Equal-width arrows show the direction of each leg, not its relative size.
Color key: Slate outlines the same proxy P in each row; sage outlines the affected contract. Slate amount text labels the deposit and sage amount text labels the two returns.
Address key: Proxy = 0x8b0856e9…561d4; affected contract = 0x9bdf81e6…d9364. The proxy appearing in each row is the same account. MUS token movements are outside this native-ETH calculation.
Source: SentinelTX, CASE-10DA91A7, pp. 12, 17–18; Sample 1 transaction. The report marks the cycle-pattern observation unverified and treats the root-cause explanation as attributed analysis.

The proposed explanation comes from external research cited in the PDF. SentinelTX attributes to SlowMist a first-deposit bonus that was credited both in an immediate ETH refund and in the user’s MUS allocation, with same-transaction redemption allowing total ETH returned to exceed the deposit. It also cites the DeFiHackLabs reproduction. SentinelTX did not execute that reproduction, and it does not present the root cause as independently verified from the affected contract’s source code.

The report distinguishes that explanation from its interpretation of the calls. It says the first selector matches the common deposit() signature, while the second selector’s ABI meaning remains undecoded. It treats the use of fresh proxies as consistent with a per-address first-deposit condition, rather than as decoded proof of that condition. In the example, the first and second payments are approximately 60.45 percent and 40.30 percent of the deposit. Those proportions describe this example; they are not a constant return promised for every cycle. (SentinelTX, pp. 17–18)

Borrowed WETH supplied working capital

SentinelTX reports a Balancer Vault WETH loan in each transaction, with the principal returned in the same transaction. It also says the corresponding native-ETH unwrap and rewrap amounts match. These movements explain how substantial capital passes through the execution sequence without turning the entire principal into a reported loss.

WETH principal borrowed and repaid

  • Run: 70.940455629359925017 WETH
  • Sample 1: 53.355703172210117028 WETH
  • Sample 2: 45.486053167691556828 WETH
  • Sample 3: 38.777129899239648888 WETH

The report attributes a zero FlashLoan fee to the analyst’s receipt parsing, citing log indexes 276, 345, 414, and 463. It also notes a conflict with a comment in the public reproduction about attacker-owned capital and says it prefers the receipt evidence. These are the report’s stated source choices; this article does not claim to have rerun the reproduction or independently re-established the loans. (SentinelTX, pp. 7, 17)

MUS remains a separate token record. The PDF describes a 49.75309010988246 MUS transfer, at display precision, from the affected contract to the orchestration contract in the Run. It calls this a transfer or allocation because the source is the affected contract rather than the zero address. It leaves token decimals, raw values, and log-level completeness unresolved in its anchored evidence. Neither that displayed quantity nor the WETH principal is added to native ETH when calculating the four-transaction changes. (SentinelTX, pp. 7–8, 21–22)

From receipts to the net change

The EOA’s three sample receipts exceed 13.85 ETH, but the preceding Run produces a negative EOA change of more than 10.66 ETH. SentinelTX’s four-transaction total incorporates both sides.

EOA native-ETH change before fees

  • Run: −10.663949354499970030 ETH
  • Sample 1: +5.947512945688151244 ETH
  • Sample 2: +5.070290034224630664 ETH
  • Sample 3: +2.836801445748578192 ETH
  • Four-transaction change: +3.190655071161390070 ETH

The report separately attributes 0.005781774786752720 ETH in fees to these four transactions. Deducting those fees gives its stated EOA change of +3.184873296374637350 ETH. That number excludes other costs and any value associated with residual MUS. It is not an account balance or a campaign-wide profit figure. (SentinelTX, pp. 6–7, 21–22)

Signed native-ETH bars show the initiating EOA’s reported pre-gas change: Run about minus 10.6639 ETH, Sample 1 plus 5.9475, Sample 2 plus 5.0703 and Sample 3 plus 2.8368. Four-transaction total is about plus 3.1907 ETH. The chart is an account-delta comparison, not a wallet balance. The conclusion is marked unverified.

Figure 2. The report’s native-ETH changes for the EOA across the four transactions, before fees. The negative Run and three positive sample receipts produce a reported total increase of 3.190655071161390070 ETH. Values in the artwork are rounded; the table preserves the PDF’s precision. The scope is a change across selected transactions, not the wallet’s starting or ending balance.
Color key: Slate is the Run; sage is Samples 1–3. Explicit signs and the zero axis distinguish decreases from increases.
Source: SentinelTX, CASE-10DA91A7, pp. 6–7, 21–22. The report’s conclusion marks these findings unverified (auto-downgraded). Full transaction links and hashes are listed below.

At the account level, SentinelTX reports a reduction of 5.335155071161390070 ETH at the affected contract, an increase of 3.190655071161390070 ETH at the EOA before fees, and a 2.1445 ETH receipt at the third address. Its reconciliation assigns zero net ETH to the orchestration contract and the 59 helpers within each transaction. These net changes are an accounting summary; they do not identify the third recipient’s owner or purpose.

The approximately $36,900 headline remains a separate, attributed claim. SentinelTX credits it to SlowMist and explicitly declines to reconcile it to the native-asset figures. The article therefore does not convert the report’s ETH changes into a new dollar-loss estimate. (SentinelTX, pp. 6, 8, 18, 21–22)

The third recipient and the limits of the trace

The third address, 0xA30911099156608A32e35c11aCf2956258E0F645, receives its 2.1445 ETH during the Run’s priming-deposit call. SentinelTX does not establish whether the recipient is controlled by the attacker, unrelated to the attacker, a fee or referral recipient, or an existing participant. Its appearance in the sequence supports a reported payment, not one of those explanations.

The PDF’s post-incident observations are also bounded. It says no outbound movement from the EOA was observed in the queried datasets through the later retrieval period around 10:11–10:15 UTC on October 5. It identifies no exchange deposit on the examined outbound paths of the EOA or orchestration contract. The report expressly says those observations do not prove unspent proceeds, recovery, a freeze, or current balances. Later blocks, other chains, and off-chain disposition fall outside those conclusions. (SentinelTX, pp. 8, 18, 22)

Earlier funding history should be read in its own time. The report places the RAILGUN Relay Adapt receipt and LiFi departure before the incident, and it leaves the origin of the later Relay.link payout unresolved. It excludes that earlier history from incident proceeds and cash-out totals. The service labels do not establish who controlled the EOA or what anyone intended. These earlier routes are not drawn as an onward path in this article. (SentinelTX, pp. 10, 18)

What the report concludes

The useful distinction in this case is between capital that passed through the contracts and the net changes the report assigns to the selected transactions. SentinelTX describes a repeated two-payment cycle and reports a positive EOA change after including the Run’s contribution. It keeps the repaid WETH principal, native-ETH account changes, and MUS transfer record separate.

Its unresolved questions remain material: the third recipient’s role, activity outside the four transactions and outside Ethereum, the origin of the Relay.link payout, token-level details, and an additional orchestration-contract nonce increment. The PDF’s own proposed next steps include source and ABI decoding, a fuller log-level token ledger, and a dated valuation with an agreed incident scope. None of these is presented as completed work. (SentinelTX, pp. 18, 21–22)

The report’s four-transaction conclusion shows the affected contract down about 5.3352 ETH, initiating EOA up about 3.1907 ETH before gas, and third recipient up 2.1445 ETH. Third-recipient control, later and other-chain activity, recovery, freeze and current balance remain unresolved or unproven. The report-integrity warning says findings are marked unverified, six claims were downgraded and one finding flagged.

Figure 3. The conclusion and its limits, adapted from SentinelTX. The reported four-transaction amounts do not establish total campaign loss, real-world control of the third recipient, current holdings, recovery, or completed cash-out. The source PDF retains an automated integrity warning and labels the conclusion unverified.
Color key: Slate labels the unresolved section; amber frames the directly stated report-integrity warning. Color does not indicate attribution or independently verified status.
Source: SentinelTX, CASE-10DA91A7, pp. 21–22 and 83. The INV-5 warning concerns a time-inverted path in the report; that path is not included in these figures.

Source register and report note

This article adapts SentinelTX’s “MUSystem: Four-Transaction Ethereum Investigation — 30 September 2026,” case CASE-10DA91A7, an 85-page PDF generated on October 5, 2026, at 11:25:40 UTC. Page references above refer to that export. The source is the exported report, including its attributed claims and integrity qualifications; the article is not an independent on-chain audit or a certification of the report’s signature or custody claims.

The four transaction identifiers in the PDF are:

External analysis cited by the report:

Address key, using the roles in this article:

  • Initiating / receiving EOA: 0x1a083ADf234a8f67ad65A9B9B616853ACf5998E5
  • Orchestration contract, called the attack contract in the PDF: 0xD1a7A2A3c27962E80E9B6B46D54094F93267e988
  • Affected contract: 0x9bdf81e6066d32764b7e75a1b5577237e06d9364
  • Third recipient, role and control unresolved: 0xA30911099156608A32e35c11aCf2956258E0F645
  • Sample 1’s first proxy: 0x8b0856e9b0787d09f9abded66bccc85feb5561d4
  • Balancer Vault: 0xBA12222222228d8Ba445958a75a0704d566BF2C8
  • WETH contract: 0xC02aaA39b223FE8D0A0e5C4F27eAD9083C756Cc2
post_like_sub0
post_total_comment_sub0

7 reads

0/500 bytes