Many victims have already taken action through ChainBounty. Report now and join the effort to stop online crime

무차별 리딩방홍보
★공지사항★ 🏆 비트코인(BTC) & 주식 리딩 안녕하세요. 대성투자그룹입니다. 재테크 손실로 고민 중이시거나 새로운 투자 정보를 찾고 계신 분들을 위해 무료 리딩을 운영하고 있습니다. 📈 비트코인(BTC) 및 주식 리딩을 함께 진행하며, 실시간 종목 브리핑과 매매 전략을 제공해드립니다. ⏰ 운영 시간 안내 📈 09:00 ~ 12:00 │ 오전 주식 리딩 🍽 12:00 ~ 13:00 │ 중식 및 시장 모니터링 📉 13:00 ~ 15:30 │ 오후 주식 리딩 —————————————— 🪙 16:00 ~ 16:30 │ 코인 단체 트레이딩 1부 🪙 16:50 ~ 17:20 │ 코인 단체 트레이딩 2부 🪙 17:50 ~ 18:20 │ 코인 단체 트레이딩 3부 아래 링크를 클릭하신 후 입장하여 편안하게 둘러보시기 바랍니다. 👇 무료 입장 링크 👇 https://t.me/+uAGPFGdvzktiY2U1 📌 입장 후 단체방 상단에 고정된 공지사항을 반드시 확인해주시기 바랍니다. 또한, 원활한 안내와 상담을 위해 상담센터 연결은 필수로 진행해주시기 바랍니다. 항상 회원 여러분께 도움이 되는 정보와 안정적인 투자 환경을 제공하기 위해 최선을 다하는 대성투자그룹이 되겠습니다.
주식스팸
안녕하세요, 회원님! 성공으로 가는 길입니다. 며칠 전 구매하신 상품은 잘 받아보셨나요? 고객님의 소중한 후기는 다른 구매자분들에게 큰 도움이 됩니다. 지금 리뷰를 작성하세요! 진심으로 감사드립니다. 구매상품: 주식에 물려 계신 분 1분만 확인해보세요 오르기만 기다리고 계십니까 ? 국내 시장은 더 이상 어렵습니다. 주가가 하락 할 때에도 양방향 매매로 이익을 낼 수 있습니다. 하나부터 열까지 세세히 알려 드립니다. 강의자료 모두 공유 , 매일 수기/보이스 강의 진 모의투자 무료 발급, 매매 예치 시 선 반영 되는 지원금, 입장하여 3일만 구경해보세요 , 말로만 하지 않고 직접 보여드리겠습니다. https://t.me/+EbV8Iz3MfslkZWFk
투자 종용
⭐️ 금일 수익내역 안내 07월 17일 손익 안내입니다. 항셍 : - 4,658,960원 나스닥 : + 3,225,525원 총 손익금: 손실마감 (1계약 기준 수익입니다.) 단체신호공유 및 정회원 복구솔루션 수익 실현하신 회원님들께 진심으로 축하드립니다. 더욱 분발하여 더 좋은 수익 내도록 최선을 다해 노력하고 회원님들의 소중한 자산 신중하고 책임감 있게 컨설팅 하겠습니다. 타 회원님들의 주말간 편안한 휴식을 위해 단체방 채팅은 다음주 월요일 오전 09:00부터 이용해주시면 감사하겠습니다. 현재 투자자금 지원행사도 진행중이오니 많은 관심 부탁드리며 단체신호공유 및 복구솔루션 문의는 고객센터로 문의주시기 바랍니다. 고생하신 회원님들에게 더 나은 내일로 보답하겠습니다. 💬 상담센터 : https://t.me/VipInvecenter
포머클린 청소끝났어요
포머클린 01021840909 님 청소 끝났어요 예약해 주신 해외선물 나스닥으로 7일간 996만이익 완료 // 청소를 마쳤어요 작업 마친 시각 이익보는구간 비법무료공유 및 무료타점공유 무료강의 청소한 날짜는 입장 : [ t.me/+scZ-KJgH2VZmZTA0 ] 요청하신 범위까지 살펴봤어요 빠진 데 없나 확인 부탁드려요 다음에도 깨끗하게 청소해 드릴게요 편안한 하루 보내세요
Allbridge forensic intelligence reportINVESTIGATION TARGET: Allbridge Core Flash-Loan Exploit & Multi-Chain Fund FlowDATE OF ISSUANCE: July 22, 20261. Executive SummaryOn July 19, 2026, the Allbridge Core cross-chain liquidity protocol fell victim to a flash-loan price manipulation exploit, resulting in an initial protocol drain valued at approximately $1.65 Million USD.The perpetrator executed a cross-chain extraction, bridging funds from Solana to the Ethereum Mainnet via deBridge Finance, consolidating primary assets at wallet address 0x651591b68A9c9650FB23F642162353306281ffDe. Subsequently, a multi-layered, highly structured laundering operation was initiated within hours. [Solana Exploit] │ ▼ (deBridge Finance) ┌─────────────────────────────────────────┐ │ Ethereum Primary Receipt Hub │ │ 0x651591b68A9c9650FB23F642162353306281ffDe│ └────┬──────────┬───────────┬───────────┬─┘ │ │ │ │ ▼ ▼ ▼ ▼ [Railgun ZK] [Maya Router] [NEAR Bridge] [Binance / MEXC] ($614K DAI) (515+ ETH) (195 ETH) (682+ ETH) Key Analytical FindingsActionable Immediate Recovery Target: As of July 22, 2026, 300,237.26 DAI and 45.71 USDC remain dormant at the primary Ethereum hub (0x651591b68A9c9650FB23F642162353306281ffDe). These assets are immediately freezable via protocol blacklisting and exchange freeze notices.Privacy Obfuscation (Forensic Dead-End): Approximately 614,000 DAI was routed into the Railgun Privacy Protocol (0xfa7093cdd...), creating a cryptographic zero-knowledge shield that halts deterministic on-chain tracing.Cross-Chain Liquidity Offramps: Assets were extensively dispersed through decentralized cross-chain swap protocol Maya Protocol Router (515+ ETH), THORChain Router (247+ ETH), and NEAR Intents Bridge (195 ETH).CEX Offramp Outflows: Over 612 ETH reached Binance deposit endpoints (Korean FIU registered/approved VASP), while 70 ETH was deposited into MEXC (Korean FIU blacklisted/unregistered exchange).2. Investigative MethodologyThis investigation was executed via SentinelTX Forensic Intelligence System, combining real-time server-side block scanning, multi-hop deterministic graph tracing, and cross-chain bridge indexers on Ethereum Mainnet (Chain ID 1). Phase 1: OSINT & Primary Hub Identification ├── Target: Allbridge Core Exploit (2026-07-19) └── Extraction: Solana bridge origin & Ethereum receipt address Phase 2: Multichain Footprint Reconnaissance ├── Address labeling DB cross-referencing └── Asset state & balance indexing Phase 3: Deep Multi-Hop Outbound Tracing ├── Scan Window: 2026-07-20 00:00 UTC – 2026-07-22 23:59 UTC └── Outbound Depth: 5 Hops from primary hub Phase 4: CEX & Privacy Classification ├── Zero-Knowledge dead-end identification (Railgun) └── VASP compliance mapping (FIU Licensed vs. Non-Licensed) 3. Incident Visualizations & Flow Diagrams3.1 Multi-Hop Fund Dispersal Architecture (Mermaid Graph)4. Attack Timeline & Sequence of EventsTimeline Log TableDate / Timestamp (UTC) Block Range Event Description On-Chain TX Hash Anchor 2026-07-19-Solana $\rightarrow$ Ethereum bridge initiated via deBridge FinanceSolana Anchor Pending2026-07-19 23:xx25570xxxDAI 557,774.21 deposited to primary hub via address 0xc106...77410x70a6953a85d60aecd0e68385ce7053ab1b75ed864c123759b3fb87e2e1db07c52026-07-19 23:xx25570xxxUSDC 45.71 bridged directly to primary hub via deBridge0x2b0ba6056a66be68110dc3ebbadbba1cd172e8c01ae581832fe2bcc5bf2205b22026-07-20 00:00–03:0025570215–25570455First-wave ETH dispersal to Maya Protocol Router (Multiple tranches)0x5b5e047eae58483557767b6030c8718b3c6e8b223faf18e0be91e470202edf98 0x5278562f16f28c8778265bded368f3c844d21058bbb3fc320daa3ebb3f4561ca2026-07-20 00:00–03:0025570xxxDAI 614,000+ deposited into Railgun Privacy Protocol0xcf97bb5901dfbf2dca8bf3c2ddcf7e9d85e26b45f13ef074b815d3e5d3571e34 0xb13b9d881e280dfd6108489d39b5e566a82505855b8f5d04dfd48b66e25453d12026-07-20 01:xx25570xxxETH 195.00 transferred to NEAR Intents Bridge0xeab5d5da3018d8fcd1f5da0503a4f2307c7fabcdd2168979d70e50d59dbda7f32026-07-20–07-2125572062–25583683High-volume WETH/Relay.link routing (6,416+ ETH) & CEX dispersal0xf7160b9ac72d00215b97551c1e1c18f10d2077e73fd57cfc0a74f1b2bf9d38bc 0xe3eac63fc55855731cd292c04a17c15842fe0578365f2186ac4907115dda52cd5. Stolen & Traced Asset BreakdownValuation Notice: Quantities are grounded in verbatim on-chain units. USD figures represent spot evaluations at execution/compile time. USD-pegged stablecoins (USDT/USDC/DAI) are converted 1:1.Token Traced On-Chain Quantity Est. USD Value Current Forensic Status ETH1,050+ (Maya) + 195 (NEAR) + 612+ (Binance) + 247+ (THORChain) + 70 (MEXC) + 3,485 (Intermediate)~$1.65M+Dispersed / Deposited across exchanges & cross-chain protocolsDAI557,774.21 (Initial) + 614,000 (Railgun) + 300,237.26 (Hub)~$1.47M$614K obfuscated in Railgun; $300K frozen at Primary HubUSDC45.71 (Hub) + 500,000 (Swap Return)~$500,04545.71 remains at Hub; 500k received via DEX swap routing6. Deep-Dive Fund Flow & Layering Analysis6.1 Solana $\rightarrow$ Ethereum IngressThe attacker used deBridge Finance (0xef4fb24ad0916217251f553c0596f8edc630eb66) to cross-bridge assets to the primary Ethereum Hub (0x651591b68A9c9650FB23F642162353306281ffDe).6.2 Primary Hub Fan-Out & Structuring (PEEL Chain)Within 3 hours of receipt on July 20, 2026, the primary hub executed a structuring "peel chain" fan-out, splitting ETH into 10+ uniform tranches (10–45 ETH each) to bypass automated Exchange Anti-Money Laundering (AML) triggers.Railgun Obfuscation: 614,000+ DAI was deposited directly into the zero-knowledge pool (0xfa7093cdd9ee6932b4eb2c9e1cde7ce00b1fa4b9). Post-deposit tracking is mathematically obfuscated without private key disclosure or voluntary compliance reporting.DEX & Cross-Chain Routing: 515+ ETH was routed through Maya Protocol, 247+ ETH through THORChain, and 195 ETH through NEAR Intents Bridge.Intermediate High-Volume Swapper: Address 0xc1062b7c5dc8e4b1df9f200fe360cdc0ed6e7741 acted as an automated market mixer, handling over 6,416 ETH across 11,978 transactions between July 20 and July 21.7. Key Address & Entity Attribution MatrixAddress Label / Role Hop Confidence Rating On-Chain Evidence / Notes 0x651591b68A9c9650FB23F642162353306281ffDePrimary Ethereum Hub0Unverified (Inferred)*Consolidated bridge receipt wallet. Holds residual DAI/USDC.0xef4fb24ad0916217251f553c0596f8edc630eb66deBridge Finance1Unverified (Inferred)*Cross-chain bridge contract.0xc1062b7c5dc8e4b1df9f200fe360cdc0ed6e7741Intermediate Router / Swapper1Unverified (Inferred)*Executed 6,416+ ETH in WETH/Relay.link routing.0xfa7093cdd9ee6932b4eb2c9e1cde7ce00b1fa4b9Railgun Privacy Proxy2Unverified (Inferred)*Zero-knowledge privacy pool destination.0x7f2cabce04f012df9ed86b6522a3903b6a66d86dBinance Deposit Address3Unverified (Inferred)*Received 250.35 ETH. Korean VASP Jurisdiction.0x28c6c06298d514db089934071355e5743bf21d60Binance Hot Wallet4Unverified (Inferred)*Received 306.28 ETH.0x2767b11afc19c8b2407a381843126d80c4de374aBinance Deposit Address3Unverified (Inferred)*Received 55.92 ETH.0x9642b23ed1e01df1092b92641051881a322f5d4eMEXC Deposit Address4Unverified (Inferred)*Received 70.01 ETH. Korean FIU Blacklisted VASP.Note: Degraded to "Unverified (Inferred)" per SentinelTX Integrity Gate Rule INV-12 pending formal judicial transaction corroboration.8. Exchange Deposit Analysis & Recovery Strategy8.1 Binance Offramp Analysis (Korean Licensed VASP)Funds were split across three distinct Binance endpoints: [Primary Ethereum Hub] │ ├─── 250.35 ETH ───► Deposit Endpoint: 0x7f2cabce...86d (Hop 3) ├─── 306.28 ETH ───► Hot Wallet Endpoint: 0x28c6c062...d60 (Hop 4) └─── 55.92 ETH ───► Deposit Endpoint: 0x2767b11a...74a (Hop 3) Legal Strategy: Because Binance operates under regulatory alignment with Korean FIU standards, domestic law enforcement (Korean National Police / Prosecutors' Office) can issue emergency disclosure and freeze orders under Article 10-2 of the Specific Financial Information Act.8.2 MEXC Offramp Analysis (Unlicensed High-Risk Exchange)Deposit Endpoint: 0x9642b23ed1e01df1092b92641051881a322f5d4e (70.009 ETH)Legal Strategy: MEXC is included on the Korean FIU non-compliant/blocked exchange list. Freeze actions require international Mutual Legal Assistance Treaties (MLAT), Letters Rogatory, or emergency INTERPOL assistance.9. Actionable Recommendations ┌─────────────────────────────────────────────────────────────────────────┐ │ ACTIONABLE RECOVERY ROADMAP │ ├─────────────────────────────────────────────────────────────────────────┤ │ 1. EMERGENCY TOKEN FREEZE │ │ └─ Issue emergency freeze notice to Circle (USDC) & MakerDAO (DAI) │ │ targeting 0x6515...ffDe ($300,283 USD total). │ │ │ │ 2. VASP SUBPOENAS (BINANCE) │ │ └─ File formal judicial disclosure orders to Binance Compliance │ │ for endpoints 0x7f2c..., 0x28c6..., and 0x2767.... │ │ │ │ 3. CROSS-CHAIN BRIDGE LOG REQUESTS │ │ ├─ deBridge: Request Solana origin wallet & signature logs. │ │ ├─ NEAR Intents: Extract destination wallet on NEAR L1. │ │ └─ Relay.link: Request IP/API connection logs for address 0xc106.... │ │ │ │ 4. DOMESTIC LAW ENFORCEMENT FILINGS │ │ └─ Submit case file to KoFIU & Korean Police Cyber Bureau. │ └─────────────────────────────────────────────────────────────────────────┘ 10. Chain of Custody & Evidence FingerprintParameter Specification / Record Primary Chain IDEthereum Mainnet (Chain ID 1)Block Range Covered25570xxx – 25583xxxExtraction Window2026-07-19 00:00 UTC – 2026-07-22 23:59 UTCAnalysis EngineSentinelTX Forensic Intelligence Engine v4.2Graph State Fingerprint3f1c7f6aSnapshot SHA-2560de6f0401b9ac6921d91ee13886878549308e918a446fb19e0837683094b1a58Document Content SHA-256d55427ba8964062ab6ed2bbf625fff7baa8325adeebe1300aa3ba2f9fd80aaacAnalyst DeclarationI declare that this report represents an accurate, objective record of the on-chain forensic investigation conducted into the Allbridge Core Flash-Loan Exploit. All findings are derived directly from Ethereum Mainnet transactions and cross-referenced with accredited address intelligence databases. Address-poisoning and spam transactions have been isolated and filtered out of the monetary flow analysis.

ChainBounty is a Web3-powered platform where your contributions matter. Complete community tasks, submit quality reports, and earn rewards based on accuracy and relevance. Stay active, avoid duplicate submissions, and build your reputation while getting rewarded. Join the community, contribute value, and turn your effort into opportunities. 🚀Hashtags: #ChainBounty #Web3 #Crypto #Blockchain #CommunityRewards #EarnCrypto #BountyTasks #Airdrop #DeFi
Hello I'm I the only person who is having a reduction in CBP? Mine gets deducted daily now, quite noticeable,I believe I have over 160 CBP last week but somehow turned 40 CBP. I don't know if this is normal.

Gravity Bridge Exploit: Full Attacker Fund Flow Traced — 113 Transactions Reveal Sophisticated…
Gravity Bridge Exploit: Full Attacker Fund Flow Traced — 113 Transactions Reveal Sophisticated Laundering OperationThe laundering infrastructure behind the recent Gravity Bridge exploit has now been largely uncovered.After tracing 87 confirmed attacker transactions and an additional 26 downstream movements, the overall flow of stolen funds is becoming clear. What initially appeared to be a straightforward bridge exploit has evolved into a highly structured laundering operation involving decentralized exchanges, relay wallets, non-custodial swap services, and centralized exchanges.This report summarizes the complete fund flow observed so far and highlights the remaining recovery opportunities.Executive SummaryTotal tracked transactions: 113Initial stolen assets converted into ETH almost immediatelyApproximately $4.7M converted through KyberSwap and 1inch2,600 ETH consolidated into a secondary aggregation walletFunds dispersed through dozens of one-time relay walletsConfirmed deposits identified at ChangeNOW and KuCoinMultiple staging wallets still hold potentially recoverable fundsSeveral laundering paths remain active and require real-time monitoringPhase 1 — Asset ConversionThe attacker-controlled wallet:0x7B582033061b96cC3F9421e73a749ED7C62da1F9immediately began converting stolen stablecoins into ETH.The swaps were executed primarily through KyberSwap and 1inch, suggesting the attacker wanted to reduce exposure to token freezes while maximizing liquidity.Observed transactions include:$100K USDC → ETH$200K USDC → ETH$500K USDC → ETH$400K USDT → ETHMultiple additional swapsIn total:Approximately $4.3M USDCApproximately $434K USDTwere converted into ETH within a short time window.The rapid conversion indicates pre-planning and suggests the operator anticipated potential blacklisting or asset recovery attempts.Phase 2 — ETH ConsolidationAfter conversion, the attacker consolidated funds into a second wallet:0x4d3ca32e687e871a58b78AcAc73bE59AC37C7A47A total of 2,600 ETH was transferred through multiple transactions:600 ETH500 ETH500 ETH500 ETH500 ETHThis wallet appears to have functioned as the primary distribution hub for the laundering operation.Rather than cashing out directly, the operator implemented a layered relay strategy designed to fragment attribution and complicate tracing efforts.Phase 3 — Distributed Relay LaunderingThe most notable discovery is the laundering architecture itself.Instead of sending large transfers directly to exchanges, the attacker repeatedly split funds into dozens of temporary wallets.The observed pattern resembles:Primary Wallets → One-Time Relay Wallets → Swap Service / Exchange → Cross-Chain ExitIndividual transfers were commonly observed in the 6–10 ETH range.This methodology significantly reduces the visibility of exchange deposits and makes automated clustering more difficult.The pattern appears intentional and operationally mature.Confirmed ChangeNOW ActivityThe largest identified laundering route currently leads to ChangeNOW.Observed destination:0xeba88149813bec1cccccfdb0dacefaaa5de94cb1Estimated deposits:Approximately 114 ETHRoughly $230,000 equivalentBecause ChangeNOW is non-custodial, recovery options are more limited.However, transaction records still exist.The highest priority investigative question is determining what assets these ETH deposits were converted into.Particular attention should be given to:Monero (XMR)Privacy-focused assetsCross-chain bridge destinationsIf conversion into privacy-preserving assets occurred, tracing may become significantly more difficult.Confirmed KuCoin DepositsA second laundering path has been identified through KuCoin.Known deposit address:0x45300136662dd4e58fc0df61e6290dffd992b785Estimated deposits:Approximately 6 ETHAdditional suspected deposit address:0x58edf78281334335effa23101bbe3371b6a36a51Status:Further confirmation requiredUnlike ChangeNOW, KuCoin operates as a custodial exchange and maintains KYC records.This creates a potential recovery and attribution opportunity if law enforcement or affected parties act quickly.Remaining On-Chain FundsSeveral wallets remain active and continue to warrant monitoring.Primary Staging Wallet0xc8c71ae4261e55a66d9967f2ac252be4e669f562Current observations:Received 59 ETHOnly 15 ETH moved onwardApproximately 44 ETH potentially remains under attacker controlThis wallet may represent an operational staging point rather than a final cash-out destination.Additional Unresolved Destinations0xf1ed839d08309e2a52e58d69b06d286d35fc18bc — 15 ETH0xe1e471614305656114c39294637b65adccf665a3 — ~13 ETH0x58432e011aa493c404f80409d997b1eabdfd8e24 — 9 ETH0x79f376453537878eeb79fb7d2cdb2c10bc58f454 — 9 ETH0x98d9022fa2789c0d8e9cd49707599c6848619ed8 — 10 ETHThese wallets currently represent unresolved portions of the laundering network.Immediate Investigative Priorities1. KuCoin Cooperation RequestThis remains the strongest recovery opportunity.Required actions:Identify account owner(s)Preserve account recordsFreeze assets if still presentObtain associated KYC informationTiming is critical.2. ChangeNOW Exit TracingInvestigators should determine:Destination chainDestination assetConversion timingPotential privacy-coin exposureThis path likely contains the most important unanswered questions in the investigation.3. Real-Time Monitoring of Staging WalletsThe wallet:0xc8c71ae4261e55a66d9967f2ac252be4e669f562should be monitored continuously.A significant portion of attacker-controlled funds may still be sitting on-chain.Any future movement could reveal:Additional exchange depositsAdditional swap servicesNew laundering infrastructureFinal cash-out attemptsConclusionThe Gravity Bridge attacker did not rely on a simple exchange cash-out strategy.Instead, the operator employed a structured relay-wallet laundering network designed to fragment attribution, obscure exchange deposits, and delay investigation.While a meaningful portion of the funds has already entered laundering channels, several opportunities remain.The most actionable leads currently include:KuCoin deposit attributionChangeNOW conversion tracingMonitoring of the 59 ETH staging walletThe next movements from these wallets will likely determine whether investigators can continue following the money — or whether the trail disappears into privacy infrastructure permanently.
ChainBounty
2 months ago
Unmasking a Sophisticated Solana Scam Network: A $SUBY Forensic Investigation
How automated bots and shared infrastructure revealed a 10-month-old organized crime syndicate.The blockchain never forgets, but it can be incredibly complex to navigate. Recently, ChainBounty conducted a deep-dive forensic investigation into a significant asset theft involving $SUBY and other Solana-based tokens. What began as a single incident report evolved into the discovery of a professional, long-standing scam infrastructure that has now led to an active criminal investigation by the Cyber Crime Investigation Division in Seoul, South Korea.1. The Incident: Precision and AutomationOn May 30, 2025, a victim’s wallet was drained of approximately 8.2 million $SUBY tokens, along with $SSE and $DAW. The speed of the transfer was alarming.Our forensic analysis revealed that this wasn’t a manual operation. The assets were moved to an intermediary wallet (46S5bgHq...) and immediately processed through automated scripts. These bots executed swaps into stablecoins and distributed funds across multiple "hop" wallets with 0-second latency, ensuring the trail became as fragmented as possible within minutes.2. Identifying the “Cash Out” InfrastructureBy tracing the flow of stolen assets, we identified two primary exit points: Bitget Exchange and FixedFloat (a mixing service). While some deposits to these platforms occurred shortly before or after the specific $SUBY theft, our “Infrastructure Analysis” proved a definitive link. We discovered a massive, interconnected network:27 Common Fee Payers: A cluster of wallets consistently funded the gas fees for the attack wallets.63 Shared Addresses: These wallets acted as a central hub for multiple thefts over a 10-month period.The Forensic Anomaly: Why tracking the criminal organization is more effective than tracking the tokens aloneThis confirms that the attackers are not “lone wolves” but an organized syndicate operating a “Scam-as-a-Service” model on the Solana network.3. The Evidence: The Smoking GunThe most compelling evidence of organized crime was the Machine-like Transfer Patterns. Our timeline analysis showed batch processing intervals of exactly 15 to 28 seconds. This level of synchronization is only possible through a dedicated command-and-control (C2) botnet designed for money laundering.Through our investigation, we identified over $142,430 USDT funneled through the Bitget deposit addresses associated with this specific group.Inhuman execution: Batch processing and mechanical intervals confirm the use of laundering bots.4. Active Investigation and Next StepsChainBounty has officially submitted this forensic package to the Seoul Metropolitan Police Agency. The investigation is currently focused on:KYC De-anonymization: Working with Bitget to identify the account holders behind the identified deposit addresses.Cross-Chain Tracking: Tracing funds that exited via FixedFloat into Ethereum and Bitcoin.Asset Freezing: Coordinating with exchanges to blacklist and freeze the identified criminal infrastructure.Conclusion: Vigilance in the Web3 EraThis case is a stark reminder that in the world of DeFi, your digital footprint — and that of the hackers — is permanent. At ChainBounty, we are committed to turning the tide against these scam networks.We urge the community to stay vigilant. Do not click on suspicious partnership links or authorize “blind signings” in your wallet. The scammers are professional, but so is our pursuit of justice.Join the Fight. Follow our investigation and report suspicious activities at our community: 🔗 https://community.chainbounty.io 📧 For inquiries: [email protected]#ChainBounty #Solana #Forensics #CyberCrime #Web3Security #OSINT #CryptoInvestigation
ChainBounty
6 months ago
MemeCore (M) Digital Asset Theft Incident: On-Chain Forensics & OSINT Analysis Report
IntroductionThis report details a real-world case submitted by an applicant to ChainBounty’s Victim Relief Program. The victim approached us after suffering a significant loss due to a targeted social engineering attack. ChainBounty is actively assisting the victim by providing comprehensive on-chain forensics and intelligence analysis to trace the stolen assets and identify the perpetrators for law enforcement purposes.1. Executive SummaryThis report synthesizes the results of on-chain forensic analysis and Open Source Intelligence (OSINT) investigation regarding the digital asset theft incident that occurred between December 7 and 8, 2025.The incident appears to have originated from a social engineering attack targeting an active user of Memex, a major dApp in the MemeCore (M) ecosystem. The attacker impersonated community administrators and creators to lure the victim into a fake Telegram group, then induced them to connect their wallet to a fraudulent bot service using “high-yield staking rewards” as bait.The victim created a new wallet and transferred assets as instructed, but the flow was designed to funnel funds into the attacker’s scam network.On-chain analysis reveals that the stolen funds did not end with a simple transfer. A multi-stage laundering flow was observed, involving MRC-20 token swaps within the MemeCore network, repetitive transactions based on the WM contract, cross-chain bridging via Meson Finance, inflows into Centralized Exchanges (CEX), and dispersed withdrawals across multiple exchanges.Notably, a “direct-to-exchange” flow is clearly visible in the early stages. M tokens were directly transferred from the victim’s wallet to Suspect Bitget Deposit 1 (0x7a5d…), and this fund was collected into the exchange’s hot wallet (0x1ab4…) within a short period. This suggests the attacker operated a direct route to the exchange alongside other methods to accelerate cash-out early on.The damage is calculated based on two criteria:Total M Token Outflow (Direct): 2,151.11 M, approx. $2,881.39 (Combined sum of direct transfers to exchange + EOA/Gathering Wallet).Total M Token Outflow (Including Bridge): 8,280.11 M, approx. $11,150.17 (Direct outflow + Meson bridge outflow included).Furthermore, clues suggesting a connection to specific social accounts and developer community profiles were identified in Gathering Wallet 2 (0x1c00…5f), which was confirmed as a key hub for money laundering. Based on this, grounds to narrow down suspect candidates have been partially secured. However, this is a circumstantial judgment based on the correlation between public information (OSINT) and on-chain data, and is not a legally confirmed conclusion.1.1 Summary StatisticsThe key flows are summarized as follows:1.2 Summary of Key Flows (4 Core Paths)Path 1: Victim → Direct Outflow to Bitget (Attempt at Immediate Cash-out)A total of 2,140.72 M (approx. $2,867) was directly transferred from the Victim Wallet (0xdc54…) to Suspect Bitget Deposit 1 (0x7a5d…).The deposit was collected into the Bitget exchange hot wallet (Bitget 6, 0x1ab4…) within minutes (approx. 3–5 mins).This flow represents the attacker sending “M tokens that are easy to cash out immediately” straight to the exchange.Path 2: Victim → Gathering Wallet 1 → Meson Bridge → Gathering Wallet 2 (Mainstream of Indirect Laundering)After WM contract processing, 5 types of MRC-20 tokens were received by the Victim Wallet and then drained to Gathering Wallet 1 (0x8325…e6).In Gathering Wallet 1, MRC-20s were swapped back to M, and 6,129 M was bridged via Meson Finance (0x25ab…48d3).6,122.87 M arrived at Gathering Wallet 2 (0x1c00…5f) on the BNB Chain.Path 3: Gathering Wallets 1, 2 → Reconsolidation at Bitget Deposit 2 (Possible Mixing with Other Victims’ Funds)900.65 M from Gathering Wallet 1 and 5,007.02 M from Gathering Wallet 2 flowed into Suspect Bitget Deposit 2 (0xb408…).The combined total is 5,907.67 M. As there is a “possibility of other victims’ funds being mixed,” this needs to be interpreted separately from the victim’s sole damage amount.Subsequent collection into Bitget 6 (0x1ab4…) was confirmed.Path 4: Multi-chain Dispersed Withdrawal from Gathering Wallet 2 (Evasion/Smurfing)From Gathering Wallet 2, after swapping M → BNB, there is a record of 37.51 BNB being dispersed and withdrawn in 48 transactions to 5 exchanges: Bybit, Bitget, MEXC, Binance, and Remitano.Activity of the same address was confirmed on Arbitrum and Base as well as BNB, reinforcing the cross-chain laundering pattern.2. Incident Mechanism and Psychological AnalysisThis incident appears to have started from a social engineering scenario targeting human trust rather than technical flaws such as system vulnerabilities. It seems to be a variation of the typical “Pig Butchering (Sha Zhu Pan)” tactic adapted to the MemeCore ecosystem context. There are indications that the attacker analyzed the community atmosphere and the victim’s activity patterns beforehand to approach with a tailored script.2.1 Manipulating the Environment to Build Trust: “The Illusion of the Fake Room” The attack seems to have begun with an approach from an account mimicking an acquaintance active on Memex. In anonymous messenger environments like Telegram, profile pictures and Display Names can be configured similarly, and Usernames (Handles) are hard to distinguish with just a one-character difference. The attacker judged to have secured trust by exploiting these characteristics. The Telegram room the victim was invited to contained multiple accounts impersonating Admins and Creators. They staged the room to look like an “Official Community” by continuing conversations or sharing profit verification screenshots even before the victim joined. In such an environment, it was easy to mistake the room for an extension of the official Memex community, which became the basis for the fraud.2.2 Technical Deception: Fake Bot and Inducing Wallet Connection Once a certain level of trust was established, the attacker guided the victim saying, “You can receive staking rewards if you connect your wallet via the Telegram bot”. The method is close to a typical Phishing or Drainer type. The wallet (0xDC54…69b) the victim newly created and connected was a “clean wallet” with almost no transaction history. The moment the victim trusted the instructions and moved assets, it is likely the attacker secured control through one (or a combination) of the following methods:Possibility that the transaction signed via the bot was actually an Unlimited Token Approval, not staking.Possibility that it was designed to execute an asset Transfer transaction during the signing or connection process.Possibility that keys or permissions were exposed to the attacker during the wallet creation/connection process. The key point is that “Wallet Connection” may have turned into an act of handing over actual asset authority, rather than simple login or authentication.3. Technical Characteristics of MemeCore Ecosystem and Asset StructureTo interpret the fund flow, it is necessary to first understand the background of the MemeCore chain where the victim’s assets existed and the asset structure. This explains why the attacker performed repetitive swaps and why the laundering path developed into a specific pattern.3.1 MemeCore and Proof of Meme (PoM) MemeCore is a Layer 1 chain aimed at connecting the cultural value of Memes with an economic reward structure. It promotes Proof of Meme (PoM) as its consensus structure, which includes elements like community contribution and viral activities in the reward system alongside simple staking. The base asset of this chain is the M token. M is used for core functions such as gas fees, governance, and validator staking, and has relatively high liquidity, which is why the attacker ultimately pooled funds into M for laundering.3.2 MRC-20 Token Standard and Cash-out Constraints Tokens such as NinjaMEX, walxop, LIFT, Bubger, and Abudium identified in the swap path of this incident follow the MemeCore-specific token standard (MRC-20). These appear to be “transit tokens” temporarily passed through during the process of the attacker exchanging stolen assets on the internal DEX, rather than assets originally held by the victim. Technically similar to ERC-20, they are structured for the creation and circulation of meme tokens within MemeCore. The issue is external compatibility. Since it is rare for external chains, centralized exchanges, or bridges to directly support MRC-20, it is difficult for the attacker to move them out externally and cash them out in the MRC-20 state. Eventually, to proceed to the actual cash-out stage, they must go through the flow of: converting back to M on the internal DEX -> moving to an external chain (BNB Chain, etc.) via a bridge -> attempting cash-out via swap/dispersed withdrawal on the external chain. The massive internal swap transactions observed in the report are interpreted as reflecting the constraint of having to convert back to M for external export, along with the possibility of transit swaps intended to confuse tracking in some sections.4. Incident Timeline and Detailed Forensic ReconstructionThis incident is clearly divided into Reconnaissance & Testing on December 7 and the Main Exploit on December 8. The attacker checked the validity of the path the day before, and then stole all available assets and proceeded with rapid laundering the next day.4.1 Phase 1: Reconnaissance and Initial Infiltration (Dec 7) — Traces Left by Destination Choice Immediately after securing access rights, the attacker showed a pattern of verifying two things with small (or relatively small) transfers first, rather than moving the full amount immediately:Whether the wallet is actually usable by the attacker.Whether the exchange deposit is processed normally (no risk of detection/blocking). At 10:18 UTC, 388.717 M was transferred to Bitget Deposit 1 (0x7a5d…), and at 14:08 UTC, an additional 752 M was transferred via the same path. This flow aligns with the typical pattern of a small test followed by additional transfers. The notable point is that the receiving address 0x7a5d…337 is estimated to be a User-Assigned Deposit Address of a Centralized Exchange (Bitget), not a personal wallet. Funds flowing into this address were observed being collected into the Bitget hot wallet (0x1ab4…f23) within minutes. If cooperation with the exchange is established, there is a possibility that tracking can continue on an account basis (KYC-based).4.2 Phase 2: Full-Scale Asset Theft and Laundering (Dec 8) — Forced Conversion to M and Exfiltration The full-scale theft proceeded rapidly on December 8. In this phase, it is observed that repetitive processing of the WM contract and mass liquidation (swap) of MRC-20 tokens were carried out in parallel with simple transfers.4.2.1 WM Repetitive Processing Pattern: Between 06:45 and 06:49 UTC, 8 repetitive transactions occurred against the WM contract, confirming processing (Deposit/Withdraw) of approximately 8,000 M. This repetitive wrapping/unwrapping can be interpreted as (1) a staging to confuse tracking, or (2) a preparatory step to match the asset form required for subsequent swaps/bridging.4.2.2 Organized Outflow of 5 MRC-20 Tokens and Immediate Cash-out: Around 1:24 PM, continuous M→MRC-20 swap transactions via the internal DEX occurred in the victim’s wallet, which appear to have been performed by the attacker. Subsequently, these 5 MRC-20 tokens were transferred to Gathering Wallet 1 (0x8325…eae6), where a process of converting them back to M via the Swap Router was observed. This choice is pragmatic from the attacker’s perspective. The longer low-liquidity meme tokens are held, the greater the price fluctuation and tracking traces may become. It seems the attacker chose to quickly convert MRC-20 to M to increase mobility and cash-out potential.4.3 Phase 3: Cross-Chain Bridging and Final Concealment — Attempt to Evade Tracking via Chain Hopping The secured M tokens did not stay in the MemeCore chain for long and were observed moving to the BNB Chain via the Meson Finance (0x25ab…48d3) cross-chain bridge.Meson Bridge: 6,129 M Deposited.BNB Chain Arrival: 6,122.87 M received at Gathering Wallet 2 (0x1c00…5f) (Approx. 3 mins to arrive). Gathering Wallet 2 subsequently acts as a hub to send funds to exchanges or disperse them to other chains (Base, Arbitrum). It has a strong character of a “Operational Wallet” used repeatedly rather than a simple transit point.5. Fund Flow Structure AnalysisFunds drained from the victim’s wallet moved largely in two directions:Direct Outflow straight to the exchange (Priority: Speed).Indirect Laundering via gathering wallets and bridges (Priority: Evasion).5.1 Key Deposit (Receiving) AddressesSuspect Bitget Deposit 1: 0x7a5d...337 / Received: 2,140.72 M (~$2,867.47) / Note: Exchange Transfer.Gathering Wallet 1 (MemeCore): 0x8325...eae6 / Received: 5 MRC-20s + 10.39 M / Note: MRC-20 → M Swap.Gathering Wallet 2 (Multi-chain Same Address): 0x1c00...285f / Received: 6,122.87 M & Multi-chain activity (BNB/Arbitrum/Base).Suspect Bitget Deposit 2: 0xb408...dd5c / Received: 5,907.67 M (~$7,969) / Note: From Gathering Wallets 1, 2 → Exchange. Caution: Possibility of mixing with other victims' funds..5.2 Characteristics and Implications in Fund Flow First, the laundering strategy is split into two. Part of it prioritized speed by sending it quickly to the exchange (Path 1), while the rest tried to make tracking difficult through bridging and multi-chain dispersion (Paths 2, 4). Second, Bitget appears repeatedly. Both the direct outflow path (0x7a5d…) and the path from the gathering wallet (0xb408…) converge to Bitget deposit addresses. In particular, 0xb408… is a common point receiving funds from both Gathering Wallet 1 and Gathering Wallet 2, making it a candidate for a key cash-out window. However, as other victims’ funds may be mixed in this section, definitive conclusions should be avoided. Third, Gathering Wallet 2 (0x1c00…5f) functions as a central node that receives bridged funds and then performs exchange transfers or dispersion to other chains.5.3 Multi-Exchange Dispersed Withdrawal (Smurfing) Statistics (BNB Only) From Gathering Wallet 2 (BNB Chain) → Exchange Withdrawal Statistics:Bybit: 23.44 BNB / 16 txsBitget: 7.15 BNB / 2 txsMEXC Global: 5.06 BNB / 22 txsRemitano: 1.30 BNB / 4 txsBinance: 0.56 BNB / 4 txsTotal Exchange Withdrawals: 37.51 BNB / 48 txs / 5 Exchanges Note: After swapping M → BNB at Gathering Wallet 2, dispersed withdrawals were made to multiple exchanges. Activity of the same address was confirmed on Arbitrum and Base, reinforcing the cross-chain laundering pattern. Reference: Remitano is known as a platform widely used for P2P trading in Southeast Asia, which can serve as a reference clue for geographic profiling (Note: Do not conclude).6. Relevant Actor Intelligence AnalysisIn this investigation, by cross-examining on-chain flows and off-chain public activity traces, we secured clues to narrow down the relevant Actor (Actor A) and associated account/profile candidates. The central address of the analysis is Gathering Wallet 2 (0x1c00…5f), and OSINT information was organized around this address.6.1 Circumstances Connecting On-Chain Activity and Digital Identity In this case, some clues were observed where 0x1c00…5f, identified as a key gathering address, could be connected to external public activities. If the same address is repeatedly mentioned or exposed in specific social accounts or community profiles, it can serve as important evidence connecting on-chain addresses with off-chain activities. There are circumstances where a specific social account marked as (Redacted) posted the 0x1c00…5f address multiple times in posts related to past airdrops, whitelist registrations, faucet participation, etc. This raises the possibility that the address is associated with the account’s activity to a certain level.6.2 Detailed Identity Profile (Circumstantial) In the OSINT investigation, circumstances were confirmed where the social account/handle marked as (Redacted) is connected to a specific bounty/task platform (e.g., Superteam Earn) account/profile. The following additional information is derived from this:Real Name/Legal Identity: (Redacted)Country/Region of Residence: (Redacted; Partially consistent with Remitano usage patterns, etc.)Professional Identity: (Redacted; Based on self-introduction)Tech Stack Claims: (Redacted)Activity Character: (Redacted)Additional Explanation: Meaning of “Partially Consistent with Remitano Usage Patterns” Here, “Partially consistent with Remitano usage patterns” does not mean concluding residence in a specific country/region (e.g., Vietnam) solely because Remitano appeared. It is intended to be referred to as a supplementary clue that increases probability from the perspective of Geo-profiling. specifically:Regional Character of Remitano: Remitano is known to be relatively widely used for P2P On/Off-ramp (cash-out/settlement) purposes in Southeast Asia (especially Vietnam) rather than being used equally worldwide like global major exchanges. Therefore, if Remitano is naturally included and repeatedly observed in the multi-exchange withdrawal flow, the possibility that the actor’s living sphere/settlement environment touches the Southeast Asian region (including Vietnam) relatively increases.Hints form “Exchange Combination”: In this case, regional P2P channels like Remitano appear alongside general-purpose exchanges like Bybit, Binance, and MEXC. This combination can be interpreted as a form often observed in dispersed withdrawals considering the final cash-out route, rather than simple investor propensity.Therefore, Remitano traces are worth referencing as a “Geographic Clue Candidate”. However, it is a “Supplementary Clue,” not definitive evidence. Final confirmation must be made through cooperation/investigation data such as exchange KYC, login/access logs (IP/Device), and withdrawal methods (Bank/Payment info).7. Conclusion & Our CommitmentComprehensive Conclusion This incident, occurring on December 7–8, 2025, was a social engineering-based asset theft. Funds were laundered through two parallel paths:A direct path flowing straight into the Bitget exchange (Speed).An indirect path exfiltrated to external chains via the Meson bridge after internal swaps on MemeCore (Stealth).Additionally, circumstantial evidence links “Gathering Wallet 2” (0x1c00...5f) to specific social accounts and developer profiles, providing strong identification clues for law enforcement.Response Strategy ChainBounty has advised a phased response:Phase 1: Immediate reporting to law enforcement with key TxIDs and requesting asset freezing at Bitget.Phase 2: International cooperation review for cross-border tracking.Phase 3: Continuous monitoring of suspect addresses and community education on risk factors.Need help tracking stolen funds? Recovering stolen assets starts with professional tracking. If you have been targeted by a similar exploit, do not hesitate to reach out. ChainBounty’s Victim Relief Program provides the forensic evidence needed for law enforcement reporting and exchange cooperation.👉 Apply for Victim Relief Program: https://chainbounty.io/en/event/campaign-victim-support/(Disclaimer: This report is based on on-chain data and public OSINT. Identity-related content is circumstantial estimation. Final legal judgments must be confirmed through lawful procedures by law enforcement agencies.)
ChainBounty
6 months ago