October 06, 2026
ChainBounty investigation · USDT token shown for context; no endorsement or attribution to the issuer.
Key conclusion. One collector initiated 12 delegated USDT calls affecting nine token holders. Separately, two collectors consolidated 51,000 USDT. Neither the method nor the consolidation establishes victim consent, operator identity or total incident loss.
Public allegations about Tronify.rent / tron.store prompted a TRON transaction review. The strongest new finding is not merely where tokens moved: all twelve payment events in the examined subset were initiated by the same collector through the USDT contract’s transferFrom method. Nine different token-holder addresses were debited for a combined 15,864.609801 USDT. This contradicts describing these events as direct USDT transfers initiated by the debited wallets.
Two later direct transfers separately show 51,000 USDT converging on one address. That consolidation amount is not a verified loss total and is not added to the payment subset. Approval origin, victim consent, domain attribution and operator identity remain unresolved.
Measure | Result / scope |
|---|---|
Report version | 1.1 · editorial revision, 6 October 2026; no extension of the evidence window |
Network | TRON mainnet; TRC-20 USDT |
Primary period | 1–30 September 2026 UTC |
Follow-up cutoff | 6 October 2026, 02:46:45 UTC, as stated by investigation source |
Verified payment subset | 12 transferFrom calls; 9 distinct token holders; 15,864.609801 USDT |
Verified consolidation | 2 transfer calls; 51,000 USDT received in 81 seconds |
Public allegations | Approximately $69,651 / 80 victims; not reconciled or independently established |
────────────────────────────────
Question: who initiated the token movement? TRONSCAN distinguishes the transaction owner from the From field in the token-transfer event. In all twelve inspected transactions, the owner is C2, while the token-transfer From field identifies a different balance holder. The method is transferFrom, not transfer. All twelve are successful and confirmed; the token contract is TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t.
This establishes delegated movement of token balances by a common caller. It does not establish how the authorization was obtained, whether it was informed consent, or which website caused it. The sequence merits an approval-history investigation, but an approval-phishing conclusion would require that missing evidence.
Figure 1 — Delegated-transfer mechanism. Evidence P1–P12: C2 is the transaction owner; the token-event From field names the debited holder. Approval creation and consent remain unverified.
Role | Full address | Evidence boundary |
|---|---|---|
C2 · caller / collector | Owner of every payment call; recipient in some events | |
C1 · collector | Recipient in other payment events | |
H · consolidation | Receives the two later sweep transfers |
────────────────────────────────
Question: what does the observed amount measure? It is the sum of twelve transaction-event amounts, counted once per hash. It covers nine distinct token-holder addresses; repeated events for the same address are not additional victims. The largest event is 13,472 USDT, approximately 84.92% of the subset. No conversion to a contemporaneous USD price is applied.
Figure 2 — Full payment distribution. All twelve amounts use one linear, zero-based USDT scale. P5 dominates the inspected subset; the chart does not estimate total incident loss.
Figure 3 — Magnified smaller events. A separate 0–700 USDT axis makes the eleven smaller events readable. P5 is excluded only from this panel, not the aggregate. Do not compare bar lengths between Figures 2 and 3.
Unpaired collector inflows, recycled funding and downstream hops are not added. Publicly reported victim counts and losses are a different population. Their gap with this subset remains unexplained, not filled by assumptions.
────────────────────────────────
Question: is the consolidation connection real? Yes: on 30 September, C1 sends 36,000 USDT and C2 sends 15,000 USDT to H. Both transactions call transfer and are confirmed in the explorer. Convergence proves these transfers, not common ownership or that every token in them came from the twelve earlier events.
UTC / block | Movement | Full transaction |
|---|---|---|
2026-09-30 16:24:54 · 86704310 | E1 · C1 → H · 36,000 USDT | 501b95a1bd13510e495601f2b19e619763a5a73debc85619be2662301b5f48a9 |
2026-09-30 16:26:15 · 86704337 | E2 · C2 → H · 15,000 USDT | 63e05ce6c8739cdaf6357d3784e4d23d8d51947b6d9d7c0197990e696aee9bc3 |
Figure 4 — Collection and consolidation network. P1–P12 are payment events, not twelve victims. E1 and E2 identify the two verified consolidation transactions below; E3 is a source-only lead. Arrow direction indicates token movement, not ownership.
A later 100 USDT movement from H appears in the investigation output at e783e0a7579b27cd49f87c284b22fac22fea1f65e2fe7f415ec2fbe2fb20667d. Subtracting it from 51,000 does not establish a current balance of 50,900: a current balance snapshot and intervening activity are needed.
────────────────────────────────
UTC period / time | Event | Evidence level |
|---|---|---|
7–28 September | Twelve transferFrom calls in the verified subset | Independently checked |
30 September 16:24:54–16:26:15 | Two collector sweeps into H | Independently checked |
1–5 October | Nine additional TRX-seeded addresses reported; subsequent payments not established | Investigation source only |
5 October; exact post times not established | Initial public allegations and subsequent infrastructure correction | Public source attribution |
────────────────────────────────
The public source corrected its inclusion of TDii6vao7xyWg2rKPbCPWVRpSmne8xcqYx and identified it as legitimate Tronify infrastructure. The correction is material: service usage must not be treated as proof of operator control or collusion. Public correction.
Likewise, exchange labels observed on payer-side funding routes do not establish collector cash-out. Shared service use, timing proximity and a visually dense graph are not identity evidence.
────────────────────────────────
Evidence class | What it establishes | What it does not establish |
|---|---|---|
P1–P12 · directly checked | Successful transferFrom calls, amounts and transaction owner | Approval origin, consent or victim status |
E1–E2 · directly checked | Two transfers into H; 51,000 USDT in 81 seconds | Total loss, current balance or common ownership |
E3 · source-only lead | Reported later 100 USDT branch; hash retained | Independent re-verification or remaining balance |
Public reporting | Attributed incident context and correction | On-chain domain or human attribution |
Delegated transfers can occur in legitimate workflows as well as deceptive ones. The transaction method alone cannot establish fraud, intent or a stolen private key. A common transaction owner strengthens the operational connection of the examined calls, while actual operator identity remains unknown. Public allegations concerning Gemini recommendations, AI videos or search manipulation are off-chain claims and do not become proven causes through this ledger.
The reported TRX seeding and short delays are investigative context. The seeding transactions have not all been independently checked in this report, so they are not used to establish a universal causal mechanism. The provider also contains conflicting first-activity dates and broader historical paths; those values are not used to date the operation or aggregate losses.
────────────────────────────────
Question to resolve | Required evidence | Purpose |
|---|---|---|
How was C2 authorized? | USDT approval events, allowance history and wallet interaction records | Separate informed delegation from deceptive authorization |
Which domains induced transactions? | Victim records, browser history and legitimate service order logs | Connect on-chain movement to off-chain inducement |
Where are consolidated funds now? | Timestamped H balance and subsequent transaction ledger | Determine actual remaining exposure without assuming a balance |
Who owns the affected wallets? | Voluntary victim evidence or lawful records | Validate victim count and loss attribution |
These are evidence priorities, not claims that funds have been frozen, recovered or definitively traced to an exchange.
────────────────────────────────
Every payment below was independently checked in the TRONSCAN overview. The method is transferFrom and the transaction owner is C2 in every row. USDT native precision is six decimals. The hash is the deduplication key.
Common fields for P1–P12: TRON mainnet USDT; successful and confirmed transferFrom calls; transaction owner TV6n8cCLmX5mRCMMNvcE1K1i87Yo9Ys5rv. The tables separate movement from transaction anchors so full identifiers remain readable. Each P identifier refers to exactly one transaction hash.
Evidence / USDT | Token holder · From | Collector · To |
|---|---|---|
P1 · 100.0 | ||
P2 · 485.447918 | ||
P3 · 412.0 | ||
P4 · 181.0 |
Evidence | UTC / block | Full transaction hash |
|---|---|---|
P1 | 2026-09-07 19:51:06Z · 86046294 | 3c3b8a6fe26b69a760134f1bb3b944baa0ec049c89d3002a426bd3137784d035 |
P2 | 2026-09-10 13:25:27Z · 86124903 | 6a93656feb2b32058214bc6e8eaebc697f4312132f30e982f4a66325f2e3f84d |
P3 | 2026-09-11 07:00:33Z · 86145999 | a521b4b148ca8a58b35438981df742a27ee64a988d4c8077384f3e9ceb409304 |
P4 | 2026-09-12 15:18:09Z · 86184741 | b72f7690b7d5d8e92301018de4ac02c516b356b8d7ea9853564d3847b12977e5 |
Evidence / USDT | Token holder · From | Collector · To |
|---|---|---|
P5 · 13472.0 | ||
P6 · 177.0 | ||
P7 · 61.372883 | ||
P8 · 659.0 |
Evidence | UTC / block | Full transaction hash |
|---|---|---|
P5 | 2026-09-13 08:04:39Z · 86204865 | 8b003bd469b45956b430df31ad67b0c8d668a114808775e9897787b6e20ccbf6 |
P6 | 2026-09-14 02:10:24Z · 86226573 | e1bbcbac8dd49284e9745757f555dc663b66da42555544fdf5b9c7e2a0a0119e |
P7 | 2026-09-14 20:14:42Z · 86248253 | 877c9e0cb7ebccf7fe18ce63b0a9f4206aa32993b30c688679ad2f0a2bb83a65 |
P8 | 2026-09-14 22:44:30Z · 86251249 | e6bc783dc6f2f180b576a044f037afe44f4c688b87cd534460f49b19cf145cb5 |
Evidence / USDT | Token holder · From | Collector · To |
|---|---|---|
P9 · 101.0 | ||
P10 · 1.789 | ||
P11 · 210.0 | ||
P12 · 4.0 |
Evidence | UTC / block | Full transaction hash |
|---|---|---|
P9 | 2026-09-15 00:21:57Z · 86253196 | d52998a2a9f33af5894d50ab95cfa63a73427038ce4e059ffb5a14cba5b97a34 |
P10 | 2026-09-15 00:22:33Z · 86253208 | 3a9d82c197147bfba3d89fe0a3541fed23bf722e51302d690a5c83a94878e4b6 |
P11 | 2026-09-28 15:20:33Z · 86645460 | c0325bd4daa2c1c88668b8b9fbc7a670d1fec73c53a0ef63eb3c3cdc6b6837be |
P12 | 2026-09-28 15:33:48Z · 86645725 | c4d870bc9b0dc20802324b25641c721bca0a16840284b60d0915476f15f39e33 |
────────────────────────────────
Primary public sources: initial disclosure, infrastructure correction, off-chain follow-up. Transaction claims are anchored beside the relevant findings and in the appendix. Public allegations are not independently established totals.
The investigation output supplied candidate identifiers and contextual paths. This report independently compared all twelve payment calls and both consolidation transfers against visible explorer results, checked the aggregate and distinct-holder count, and corrected the direct-transfer interpretation. It does not claim a complete approval-history review, complete wallet balance audit or complete incident census.
Revision note — 6 October 2026. Version 1.1 improves evidence indexing, appendix structure, figure captions, visual spacing and the smaller-event chart. The verified transaction set, aggregate and investigation cutoff are unchanged.
14 reads