October 05, 2026

ChainBounty · Report analysis · CASE-10DA91A7
Ethereum mainnet · Activity: September 30, 2026 · Source: SentinelTX report generated October 5, 2026
SentinelTX’s MUSystem report follows four Ethereum transactions that combine supplied capital, repeated deposit-and-return cycles, and repaid flash loans. It reports a 5.335155071161390070 ETH reduction at the affected contract and a 3.190655071161390070 ETH increase at the initiating account before fees. A third address received 2.1445 ETH. The distinction between those amounts is central to the report: receipts, account changes, and an incident-wide loss answer different questions.
Report status matters here. The exported PDF says its automated integrity gate downgraded six claims and flagged one finding. Its chronology and conclusion carry an “unverified (auto-downgraded)” label, and page 83 flags a time-inverted path. This article presents the report’s findings with those qualifications. The figures below adapt its bounded transaction narrative; they do not reproduce the flagged onward path or certify the report’s findings. (SentinelTX, pp. 4, 10, 17, 21, 83)
All four transactions fall in Ethereum block 26,087,602, timestamped September 30, 2026, at 03:27:35 UTC. SentinelTX calls the first transaction the Run and the following three Sample 1, Sample 2, and Sample 3. The report’s accounting covers those four operations. It does not establish that they comprise the entire campaign or all activity involving the affected contract.
The principal roles are the initiating and receiving externally owned account, or EOA; the contract it created and used to coordinate the operations; the affected MUSystem contract; and newly created helper contracts. The report calls the coordinating contract the attack contract. This article uses “orchestration contract” to make its execution role clear without suggesting a separately identified operator. The third recipient’s role and control remain unresolved.
The report sets an observation cutoff of October 5, 2026, at 10:00 UTC. It separately identifies address-history, token, and balance observations retrieved around 10:11–10:15 UTC that day as later observations. That distinction matters when reading its statements about activity after the four transactions. (SentinelTX, pp. 4, 8, 18)
The last three transactions produced receipts of approximately 5.9475 ETH, 5.0703 ETH, and 2.8368 ETH for the EOA. Together, those receipts total 13.854604425661360100 ETH. Looking only at that part of the sequence omits the EOA’s earlier contribution in the Run.
In the Run, the EOA sent 10.7 ETH to the orchestration contract and received 0.036050645500029970 ETH back. Its net change for that transaction was therefore −10.663949354499970030 ETH before fees. The Run also contained the same repeated-cycle pattern seen later; it was more than a preliminary funding transfer.
SentinelTX breaks the Run into a priming deposit and sixteen helper cycles. The orchestration contract first paid 44.101139073399812544 ETH to the affected contract. During that call, the affected contract sent 26.460683444039887526 ETH back to the orchestration contract and 2.1445 ETH to the unresolved third address. The report gives the affected contract’s net increase on this leg as 15.495955629359925018 ETH.
The sixteen subsequent cycles reduced the affected contract’s ETH by 6.976506274859954988 ETH. Combining those two parts leaves the affected contract with a reported Run increase of 8.519449354499970030 ETH. The later sample transactions then reduce that amount. Including the Run is essential to understanding the four-transaction result. (SentinelTX, pp. 6, 10–11)

Figure 1. The report’s four-transaction sequence in one Ethereum block. It records 16 helper contracts in the Run, 16 in Sample 1, 16 in Sample 2, and 11 in Sample 3, for 59 in total. These counts describe contracts, not independent people. All four transactions share the block timestamp; spacing shows sequence rather than elapsed time.
Color key: Slate identifies sequence markers and the directly labeled helper counts.
Source: SentinelTX, CASE-10DA91A7, pp. 4, 8, 10, 13–15. The chronology is marked unverified by the report’s automated gate. Transaction links appear in the source register below.
The first helper cycle in Sample 1 provides a compact example of the pattern SentinelTX describes. The proxy at 0x8b0856e9b0787d09f9abded66bccc85feb5561d4 calls the affected contract with 53.355703172210117028 ETH. It receives an initial payment of 32.253522567601017211 ETH. After a second call, it receives another 21.502348378400678141 ETH.
The two payments total 53.755870946001695352 ETH. The proxy then forwards that amount to the orchestration contract. The excess over the original deposit is 0.400167773791578324 ETH for this cycle. Repeated deposits and forwarding create much larger gross movement volumes, so adding every leg would obscure the net result. The report explicitly excludes gross helper forwarding and large graph aggregates from its economic totals. (SentinelTX, pp. 12, 15)

Diagram 1. The ETH legs in Sample 1’s first helper cycle, as described in the report. The same proxy sends 53.355703172210117028 ETH and receives two payments totaling 53.755870946001695352 ETH, an excess of 0.400167773791578324 ETH. Artwork values are rounded. Equal-width arrows show the direction of each leg, not its relative size.
Color key: Slate outlines the same proxy P in each row; sage outlines the affected contract. Slate amount text labels the deposit and sage amount text labels the two returns.
Address key: Proxy = 0x8b0856e9…561d4; affected contract = 0x9bdf81e6…d9364. The proxy appearing in each row is the same account. MUS token movements are outside this native-ETH calculation.
Source: SentinelTX, CASE-10DA91A7, pp. 12, 17–18; Sample 1 transaction. The report marks the cycle-pattern observation unverified and treats the root-cause explanation as attributed analysis.
The proposed explanation comes from external research cited in the PDF. SentinelTX attributes to SlowMist a first-deposit bonus that was credited both in an immediate ETH refund and in the user’s MUS allocation, with same-transaction redemption allowing total ETH returned to exceed the deposit. It also cites the DeFiHackLabs reproduction. SentinelTX did not execute that reproduction, and it does not present the root cause as independently verified from the affected contract’s source code.
The report distinguishes that explanation from its interpretation of the calls. It says the first selector matches the common deposit() signature, while the second selector’s ABI meaning remains undecoded. It treats the use of fresh proxies as consistent with a per-address first-deposit condition, rather than as decoded proof of that condition. In the example, the first and second payments are approximately 60.45 percent and 40.30 percent of the deposit. Those proportions describe this example; they are not a constant return promised for every cycle. (SentinelTX, pp. 17–18)
SentinelTX reports a Balancer Vault WETH loan in each transaction, with the principal returned in the same transaction. It also says the corresponding native-ETH unwrap and rewrap amounts match. These movements explain how substantial capital passes through the execution sequence without turning the entire principal into a reported loss.
WETH principal borrowed and repaid
The report attributes a zero FlashLoan fee to the analyst’s receipt parsing, citing log indexes 276, 345, 414, and 463. It also notes a conflict with a comment in the public reproduction about attacker-owned capital and says it prefers the receipt evidence. These are the report’s stated source choices; this article does not claim to have rerun the reproduction or independently re-established the loans. (SentinelTX, pp. 7, 17)
MUS remains a separate token record. The PDF describes a 49.75309010988246 MUS transfer, at display precision, from the affected contract to the orchestration contract in the Run. It calls this a transfer or allocation because the source is the affected contract rather than the zero address. It leaves token decimals, raw values, and log-level completeness unresolved in its anchored evidence. Neither that displayed quantity nor the WETH principal is added to native ETH when calculating the four-transaction changes. (SentinelTX, pp. 7–8, 21–22)
The EOA’s three sample receipts exceed 13.85 ETH, but the preceding Run produces a negative EOA change of more than 10.66 ETH. SentinelTX’s four-transaction total incorporates both sides.
EOA native-ETH change before fees
The report separately attributes 0.005781774786752720 ETH in fees to these four transactions. Deducting those fees gives its stated EOA change of +3.184873296374637350 ETH. That number excludes other costs and any value associated with residual MUS. It is not an account balance or a campaign-wide profit figure. (SentinelTX, pp. 6–7, 21–22)

Figure 2. The report’s native-ETH changes for the EOA across the four transactions, before fees. The negative Run and three positive sample receipts produce a reported total increase of 3.190655071161390070 ETH. Values in the artwork are rounded; the table preserves the PDF’s precision. The scope is a change across selected transactions, not the wallet’s starting or ending balance.
Color key: Slate is the Run; sage is Samples 1–3. Explicit signs and the zero axis distinguish decreases from increases.
Source: SentinelTX, CASE-10DA91A7, pp. 6–7, 21–22. The report’s conclusion marks these findings unverified (auto-downgraded). Full transaction links and hashes are listed below.
At the account level, SentinelTX reports a reduction of 5.335155071161390070 ETH at the affected contract, an increase of 3.190655071161390070 ETH at the EOA before fees, and a 2.1445 ETH receipt at the third address. Its reconciliation assigns zero net ETH to the orchestration contract and the 59 helpers within each transaction. These net changes are an accounting summary; they do not identify the third recipient’s owner or purpose.
The approximately $36,900 headline remains a separate, attributed claim. SentinelTX credits it to SlowMist and explicitly declines to reconcile it to the native-asset figures. The article therefore does not convert the report’s ETH changes into a new dollar-loss estimate. (SentinelTX, pp. 6, 8, 18, 21–22)
The third address, 0xA30911099156608A32e35c11aCf2956258E0F645, receives its 2.1445 ETH during the Run’s priming-deposit call. SentinelTX does not establish whether the recipient is controlled by the attacker, unrelated to the attacker, a fee or referral recipient, or an existing participant. Its appearance in the sequence supports a reported payment, not one of those explanations.
The PDF’s post-incident observations are also bounded. It says no outbound movement from the EOA was observed in the queried datasets through the later retrieval period around 10:11–10:15 UTC on October 5. It identifies no exchange deposit on the examined outbound paths of the EOA or orchestration contract. The report expressly says those observations do not prove unspent proceeds, recovery, a freeze, or current balances. Later blocks, other chains, and off-chain disposition fall outside those conclusions. (SentinelTX, pp. 8, 18, 22)
Earlier funding history should be read in its own time. The report places the RAILGUN Relay Adapt receipt and LiFi departure before the incident, and it leaves the origin of the later Relay.link payout unresolved. It excludes that earlier history from incident proceeds and cash-out totals. The service labels do not establish who controlled the EOA or what anyone intended. These earlier routes are not drawn as an onward path in this article. (SentinelTX, pp. 10, 18)
The useful distinction in this case is between capital that passed through the contracts and the net changes the report assigns to the selected transactions. SentinelTX describes a repeated two-payment cycle and reports a positive EOA change after including the Run’s contribution. It keeps the repaid WETH principal, native-ETH account changes, and MUS transfer record separate.
Its unresolved questions remain material: the third recipient’s role, activity outside the four transactions and outside Ethereum, the origin of the Relay.link payout, token-level details, and an additional orchestration-contract nonce increment. The PDF’s own proposed next steps include source and ABI decoding, a fuller log-level token ledger, and a dated valuation with an agreed incident scope. None of these is presented as completed work. (SentinelTX, pp. 18, 21–22)

Figure 3. The conclusion and its limits, adapted from SentinelTX. The reported four-transaction amounts do not establish total campaign loss, real-world control of the third recipient, current holdings, recovery, or completed cash-out. The source PDF retains an automated integrity warning and labels the conclusion unverified.
Color key: Slate labels the unresolved section; amber frames the directly stated report-integrity warning. Color does not indicate attribution or independently verified status.
Source: SentinelTX, CASE-10DA91A7, pp. 21–22 and 83. The INV-5 warning concerns a time-inverted path in the report; that path is not included in these figures.
This article adapts SentinelTX’s “MUSystem: Four-Transaction Ethereum Investigation — 30 September 2026,” case CASE-10DA91A7, an 85-page PDF generated on October 5, 2026, at 11:25:40 UTC. Page references above refer to that export. The source is the exported report, including its attributed claims and integrity qualifications; the article is not an independent on-chain audit or a certification of the report’s signature or custody claims.
The four transaction identifiers in the PDF are:
External analysis cited by the report:
Address key, using the roles in this article:
7 reads