Defend Against Cybercrime with the Power of Community

Many victims have already taken action through ChainBounty. Report now and join the effort to stop online crime

chainbounty
Risk assessment

Quick AI Scam Check

Help protect others by sharing your scam experience

View More

[국제발신]

[Pi Net work]회원님의 지갑보호를위해 계정제한이되었습니다 본인확인바랍니다 https://pg.piminak.help

klip

・17 reads

이오영 면상까고 남들정보 팔아가며 찍은사진

[국제발신] 이오영 면#상#까고#남#들 정#보팔#아가며 #찍#은사진#궁#금한사#람 01079378010 #연#락하#면공#개

klip

・30 reads

[PI MINE]

회원님 자산 보호를위해 KYC검증을 완료해주시길 바랍니다.

klip

・95 reads

코인 주식 리딩방 초대

🏆 HANSUNG INVESTMENT GROUP 📈 국내 주식 & BTC 단기 전략 무료 공개 시장에는 언제나 기회가 있지만, 중요한 것은 언제 진입하고 어떻게 대응하느냐입니다. HANSUNG INVESTMENT GROUP은 국내 주식과 BTC 단기 전략 트레이딩을 기반으로 실시간 시장 분석과 단체 트레이딩을 운영하고 있습니다. 무료 공개를 통해 실제 운영 방식과 전문가의 전략을 직접 확인해 보시기 바랍니다. 🔗 무료 입장 링크 https://t.me/+YzI2zf5yamhmZDJk ━━━━━━━━━━━━━━ 📌 무료 공개 내용 ✅ 국내 주식 실시간 전략 ✅ BTC 단기 전략 ✅ 실시간 시장 브리핑 ✅ 전문가 대응 전략 ✅ 단체 트레이딩 운영 방식 ━━━━━━━━━━━━━━ 🎁 정회원 전용 혜택 ✅ 국내 주식 트레이딩 ✅ BTC 단기 전략 트레이딩 ✅ 실시간 시장 브리핑 ✅ 1:1 맞춤 투자 전략 컨설팅 ✅ 원금보장 프로그램 운영 (적용 대상 별도 안내) ━━━━━━━━━━━━━━ 📅 단체 트레이딩 운영 일정 🕘 09:00 ~ 11:30 │ 오전 국내 주식 트레이딩 ☕️ 11:30 ~ 13:00 │ 휴식 및 시장 모니터링 🕐 13:00 ~ 13:30 │ 오후 국내 주식 트레이딩 ₿ 14:00 ~ 14:30 │ BTC 단체 트레이딩 1부 ₿ 15:00 ~ 15:30 │ BTC 단체 트레이딩 2부 ₿ 16:00 ~ 16:30 │ BTC 단체 트레이딩 3부 ₿ 17:00 ~ 17:30 │ BTC 단체 트레이딩 4부 ₿ 18:00 ~ 18:30 │ BTC 단체 트레이딩 5부 ━━━━━━━━━━━━━━ 💬 운영 방식을 직접 확인하신 후 참여 여부를 결정하셔도 됩니다. 부담 없이 입장하셔서 실시간 리딩을 직접 경험해 보세요.

klip

・87 reads

애플 계정사기

[국제발신] Apple ID로 비정상적인 결제 거래가 발생했습니다. 설정을 확인해 주세요. https://lnk.ink/cSjwV

klip

・62 reads

리딩방초대

8월 3일 세제 개편 발표하였습니다. 세제 개편안 상세본 보시면 [힌트]가 많습니다. 앞으로는 어떻게 대비해야 되는 지, 굉장히 중요한 순간에 서있습니다. 지난 [5번의 정권] 발표된 수많은 규제 속에서 정확한 데이터를 추줄한 그룹이 있습니다. 현시간부터 정확한 데이터 기반을 통해 앞으로 발표될 부동산 [규제] 속에서 대응 하실 분들만 참고하시면 되겠습니다. https://숏.한국/openkaka/

klip

・28 reads

Contribute by sharing insights to strengthen the community

REPORT
REPORT

September 28, 2026

Community Investigation
Payy Network’s $1.92M Bridge Drain: Two verifyRollup Batches and 682.3 ETH Routed to Tornado Cash

Executive SummaryOn 24 September 2026, Payy Network’s Ethereum RollupV1 bridge paid 1,918,792.198148 USDC to the same recipient across two verifyRollup batches. Both calls were submitted by Payy’s usual batch-posting address. The first payment was rapidly moved to a second contract, converted through UniswapX into approximately 683.38 ETH, and split across four wallets.By 26 September, three relay paths had deposited a transaction-anchored total of 682.3 ETH into the Tornado Cash Router. A fourth branch retained 1 ETH. The later 90,202.820016 USDC payout remained at the primary recipient; its verified genuine-USDC balance was 90,202.821244 USDC at the 28 September cutoff.Payy’s initial root-cause update ruled out a compromised key, social engineering, and an exploit of its off-chain infrastructure. The company has not yet published the validated technical cause. The call path proves that verifyRollup processed the payouts; it does not by itself prove which verification or authorization invariant failed.Incident AnchorsItemValueEvidenceNetworkEthereumOn-chainBridge / rollup contract0x367C1eAF14AA06b78ce76bd0243297de79d85270Contract historyBatch poster0x5343B904Bf837Befb2f5A256B0CD5fbF30503D38tx.from in both batchesPrimary recipient0xAa4985dBDaBfACa344237D40F7E06C4a0BB57E70USDC Transfer logsSwap / distribution contract0xb483B1742aaD0a60a9FC91bb36C5a42dbE3F3D38USDC and ETH flowFirst drain block26,044,909On-chainFirst observed time2026-09-24 04:21:23 UTCOn-chainPrimary-recipient total1,918,792.198148 USDCTwo verified transfersTwo verifyRollup BatchesTime (UTC)BlockTransactionAmount to primary recipient2026-09-24 04:21:2326,044,9090xf43abdac5422087f645d77923eb1c825178bff3eb86d17d40fa18d89701e18141,828,589.378132 USDC2026-09-24 09:30:3526,046,4390xda88fb9273c703a4d2647c744362f58b6db4e104d7a203a75d4b67e3d54858c890,202.820016 USDCThe first batch included ordinary-looking withdrawals to other addresses as well as the dominant transfer to the primary recipient. The second batch used the same function, bridge, submitter, and recipient.Conversion and Initial ETH SplitAt 04:22:59 UTC, the primary recipient transferred 1,828,594.895417 USDC to 0xb483B1742aaD0a60a9FC91bb36C5a42dbE3F3D38 in transaction 0xb2fd99c115ad98162149fa1e0e8243050d3009719910e00bff16808a12ca10e7. Public reporting identifies the conversion venue as UniswapX. The subsequent ETH distributions sum to approximately 683.38205 ETH.DestinationAmount receivedFirst-hop transactionStatus0xa3dD31d9aD9A7eCAC68c2d2cF6063DfEa7bA3cAe1.000000 ETH0xd68af00a8693f154f1daf576e6a91a966c6b0909617a412d0471cb15678b6ca0Retained0xe8d566E2f914dbd8309625e1792ed21fD0431956282.382139990140 ETH0x7987458cae1d4424b5555c4a50cda01a31a5b08469cd6ab4c35d9b32acf09b95Forwarded0x888A21c48cF442e312bddd7c24B678f0C7132a2a200.000000 ETH0xd2ef52f0497a693bf3fe25b3584c5ec1b85d901c9ca8c4e0997f5e1a61074f1aForwarded0x3d092740936dA4C5693DaE3633c7207A37F40104199.999911680412 ETH0x0b41b66d5e4158a82b5ca8adacf87a1b96fe79bd9e8da5b38b8c9551f4289a9eForwardedTornado Cash Deposit PathsOn 26 September, three relay wallets deposited 682.3 ETH into the Tornado Cash Router at 0xd90e2f925DA726b50C4Ed8D0Fb90Ad053324F31b. The transactions used the router’s deposit method. The total is calculated from transaction values, not an estimated USD conversion.Source branchRelay walletDeposit window (UTC)CountTotal0xe8d566E2f914dbd8309625e1792ed21fD04319560xF46e1e8Ca9a032f1C84b1451890ad0aedb5E0BeD06:09:35–06:19:599180.0 ETH0x888A21c48cF442e312bddd7c24B678f0C7132a2a0x2072f325f0Bb7e06c1D7C933a10886f794D4CC9906:46:11–07:11:118302.3 ETH0x3d092740936dA4C5693DaE3633c7207A37F401040x21D4A32a357c77e72dCe79810d54C7FCf5A1996907:16:23–07:17:112200.0 ETHTotal3 relays06:09:35–07:17:1119682.3 ETHRelayFirst Tornado deposit transactionLast Tornado deposit transaction0xF46e1e8Ca9a032f1C84b1451890ad0aedb5E0BeD0x7de4955568c12e82d0cea9bc08d18715414c45b612ec270b5fa171ae74775db30x1cfb681a5bb2567ca6c68facbf65f9decc239eedd73248de27193103705a9cf60x2072f325f0Bb7e06c1D7C933a10886f794D4CC990xe5dfd95a2710f45d1749d99c941200f0b5831b25ec92239ff3e9800e60b6dbf20xb9958c2a8828865936c53cac3967434381584e6753d0a09da579972ead8a9de60x21D4A32a357c77e72dCe79810d54C7FCf5A199690x2097d151c2efe641673d3a6e772817c5baefcfbb550d5e0ade1cb49cbd91611a0x0415dc1ff16cc17c6862b9ee27c1ebfbb2e30705d8f5e6157989e7618ecf64f4No centralized-exchange deposit was identified before the mixer deposits. The router entry breaks deterministic forward tracing; it does not identify the controller of any eventual withdrawal.Verified Balances and StatusAddressAsset / balance at 28 Sep cutoffStatus0xAa4985dBDaBfACa344237D40F7E06C4a0BB57E7090,202.821244 genuine USDCLater payout remains visible0xa3dD31d9aD9A7eCAC68c2d2cF6063DfEa7bA3cAe1.000000 ETHRetained branch0xe8d566E2f914dbd8309625e1792ed21fD0431956~0 ETHForwarded to relay0x888A21c48cF442e312bddd7c24B678f0C7132a2a~0 ETHForwarded to relay0x3d092740936dA4C5693DaE3633c7207A37F40104~0 ETHForwarded to relay0x21D4A32a357c77e72dCe79810d54C7FCf5A199690.028009 ETHResidual after depositsThe primary recipient also displays a separate token using the symbol “USDC” at another contract. This report excludes that token and counts only Circle’s Ethereum USDC contract, 0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48.Evidence AssessmentStatementAssessmentBasisTwo bridge batches paid the same recipientConfirmedReceipts and USDC logsBoth calls used verifyRollup and the usual batch posterConfirmedCall data and tx.fromRoughly 683.38 ETH was produced and splitConfirmed at distribution layerETH transfers from 0xb483…3D38682.3 ETH entered Tornado Cash RouterConfirmed19 direct deposit transactionsCompromised key or social engineering caused the incidentNot supported; Payy says initial RCA ruled these outOfficial Payy updateA specific proof-validation or authorization bug caused the incidentUnresolvedNo validated post-mortemA named person or organization controls the walletsUnresolvedNo identity evidenceResponse PrioritiesPriorityActionReason1Preserve both verifyRollup transactions, calldata and validator/prover artifactsNeeded for root-cause reconstruction2Monitor 0xAa49…7E70 and genuine USDC balance90,202.821244 USDC remains visible3Monitor 0xa3dD…3cAe1 ETH remains outside the mixer path4Provide the 19 Tornado deposit hashes to investigatorsPreserves precise entry amounts and times5Publish the validated post-mortem and user-remediation planFailure mode and reimbursement status remain unresolvedConclusionThe strongest forensic conclusion is not merely that Payy’s bridge lost about $1.92 million. The value followed two distinct post-drain states: 90,202.821244 genuine USDC remained at the primary recipient, while nearly all ETH created from the first tranche was split, relayed, and deposited into Tornado Cash less than three days later.The transaction history supports a deliberate laundering sequence. It does not establish the technical root cause or the identity of the operator. Those questions require Payy’s validated post-mortem, preserved rollup artifacts, and any later mixer-withdrawal correlation.SourcesPayy incident noticePayy root-cause updateUnchainedThe Crypto TimesiTokenly incident registryEthereum records: Etherscan and BlockscoutSentinelTX case: b92968a7-ee47-4f17-a260-1e5ebfc16a09

Payy Network’s $1.92M Bridge Drain: Two verifyRollup Batches and 682.3 ETH Routed to Tornado Cash
0 likes・7 reads
dooooo
dooooo

September 28, 2026

Community Investigation
Duelbits Hot Wallet Incident: Tracing 1,370 ETH Into Tornado Cash

On September 24, 2026, crypto casino Duelbits reported a security incident affecting operational hot wallets across multiple blockchains.Public reporting cited in the investigation estimated the total loss at approximately $7 million, involving Ethereum, Solana, BNB Chain, Bitcoin, and Tron.ChainBounty analyzed the Ethereum leg of the incident, beginning with a confirmed withdrawal from a Duelbits-labeled hot wallet and tracing subsequent ETH movements through newly created intermediary wallets.The investigation identified 20 deposits totaling 1,370 ETH into the Tornado Cash Router between September 26 and September 28.However, the full 1,370 ETH cannot be attributed to the Duelbits incident with equal confidence. Based on transaction-level value paths currently anchored on-chain, up to 1,360 ETH of the Tornado Cash deposits can be explained by the tracked incident flow.No outbound exchange deposit was identified within the investigated path.Executive SummaryFinding Result Incident dateSeptember 24, 2026Blockchain analyzedEthereumConfirmed initial withdrawal836 ETH + 593,430.319285 USDTFirst receiving wallet0xA77e24Fe29d16E051e487ef4Ea7b056cb05aef76Reported consolidation wallet0x8dB9D7f0a03d212c566Ca80c66e294CeCC20C306Observed outbound movement from consolidation wallet1,914.1 ETHReturned to consolidation wallet540.0 ETHTornado Cash deposits observed1,370 ETH across 20 transactionsMaximum explained by tracked incident path1,360 ETHConfirmed exchange deposits in traced outbound flow0Consolidation-wallet balance at investigation snapshot973.536981 ETHInitial receiving-wallet balance at snapshot25.566884 ETHEvidence ClassificationClassification Meaning ConfirmedDirectly supported by transaction-level or address-attribution evidenceObservedTransaction path is directly anchored, but its attribution to the incident may depend on additional contextAnalytical assessmentInterpretation of observed behavior rather than independently proven intentUnverified leadPotentially relevant connection requiring additional evidenceThis distinction is critical throughout the investigation.An address interaction can establish that two entities touched the same infrastructure. It does not, by itself, establish that the investigated funds moved between them.1. Initial Withdrawal From the Duelbits Hot WalletThe Ethereum investigation begins with:0x014435B1E39945CF4f5F0c3cbb5833195A95CC9BThe address was attributed to Duelbits in the attribution data used during the investigation.Its first recorded activity occurred on February 14, 2024.At approximately 09:02 UTC on September 24, two major transfers left the wallet only 36 seconds apart.Time (UTC) Block Asset Amount Destination Transaction 09:02:1126046298USDT593,430.3192850xA77e24...aef760x4f2bc2a8...9bb73909:02:4726046301ETH836 ETH0xA77e24...aef760xcdc0b6dfac...3182dFull transaction hashesAsset Transaction hash USDT0x4f2bc2a8bc5040788c71e712546deec6d0f61529518b8114b0334ffd3e9bb739ETH0xcdc0b6dfacbefe4aef640be1538c9081bbf401ca9ad9784e1b0cfc044523182dThe receiving wallet,0xA77e24Fe29d16E051e487ef4Ea7b056cb05aef76was a previously unseen EOA whose first activity occurred on September 24.At the investigation snapshot, it retained 25.566884 ETH.What the blockchain proves — and what it does notBoth transactions were signed by the Duelbits hot wallet itself.That matters.From Ethereum transaction data alone, an investigator cannot distinguish an authorized withdrawal from a withdrawal executed by someone who obtained legitimate signing authority.The classification of these transactions as part of the reported compromise therefore relies on the incident disclosure and associated public reporting.The Ethereum transactions themselves show ordinary signed transfers rather than direct exploitation of a smart contract.2. The Missing Link to the Consolidation WalletPublic reporting identified the following address as the primary ETH consolidation wallet:0x8dB9D7f0a03d212c566Ca80c66e294CeCC20C306The wallet first became active on September 24.However, the investigation did not identify a direct value transfer from the initial receiver 0xA77e24... to the consolidation wallet 0x8dB9....Instead, two common counterparties were found.Address Activity Sent transactions Snapshot balance Label 0x181a638038a4bd75c207d080de83e217f8e8a1d7September 24 only60.000031 ETHNone0x4293b5dc11b250078da7359d7d57c15eecfcf70aJan. 2018 – Sep. 20263800.000547 ETHNone0x4293... is particularly notable because it sent funds to both the initial receiving wallet and the consolidation wallet.That creates a meaningful investigative lead.It does not yet create a verified value path.The transaction amounts and transaction hashes required to demonstrate that the investigated value moved through these common counterparties were not anchored in the current evidence set.ChainBounty therefore classifies:Connection Status Duelbits hot wallet → 0xA77e...Confirmed0xA77e... → 0x8dB9...Unverified value path0x8dB9... → downstream intermediary walletsObserved and transaction-anchoredDownstream intermediaries → Tornado CashObserved and transaction-anchoredThis gap prevents the entire Ethereum path from being presented as one uninterrupted forensic chain.3. A 0.1 ETH Route TestOn September 24, the consolidation wallet performed a small round-trip transfer involving another address.Direction Amount Transaction Consolidation wallet → 0x922adc...8cd230.1 ETH0x0edf6e07...bfe52b0x922adc...8cd23 → consolidation wallet0.1 ETH0x5eaf7ef1...a3f1aFull hashes:0x0edf6e07817a6d2eafd3f42c3d40c7dcab4756d4375286d48f26654dc9bfe52b0x5eaf7ef13016fd76a822f046935ca7b78f76bc66095249f8a8d8fec2d79a3f1aA 0.1 ETH round trip alone does not prove intent.Placed alongside the substantially larger transactions that followed, however, it is consistent with route validation before larger fund movements.That interpretation remains an analytical assessment rather than a directly provable fact.4. First Laundering Branch: 110 ETHBetween September 26 and September 27, the consolidation wallet began distributing ETH through newly activated intermediary wallets.The first branch started with:0xa31bb1fdf3409ce863bf646b69e6013ca74c38e3Consolidation Wallet → First IntermediaryDate Amount Transaction Sep. 2611 ETH0x2fa0bf95...12fac6Sep. 261 ETH0x928dccb8...286260Sep. 26650 ETH0xd9186462...62d801Total662 ETHMost of that ETH did not continue toward the mixer.First Intermediary → Consolidation WalletDate Returned amount Transaction Sep. 261 ETH0x98d87960...c0d83Sep. 26480 ETH0x391989db...03c1Sep. 2758.9 ETH0x29436031...0c8Total539.9 ETHAnother 111.1 ETH was forwarded to:0xadb82eef7baa2feaebe64f88577c06f803a2c578Date Amount Transaction Sep. 2610.1 ETH0xe4e83e46...896a5Sep. 27101 ETH0xaa3ff3bc...75ff6Total111.1 ETHThat wallet then deposited 110 ETH into the Tornado Cash Router:0xd90e2f925da726b50c4ed8d0fb90ad053324f31bDeposit Amount Transaction 110 ETH0xf12cf53b...d86af2100 ETH0xccaf6baa...5349Total110 ETHThe remaining 1.094278 ETH was returned upstream.This 110 ETH branch is fully explainable using the tracked transaction path.5. Second Laundering Branch: 1,260 ETHThe second and significantly larger movement occurred on September 28.The consolidation wallet transferred 1,252 ETH into a newly active address:0x6495afaeb766e59f3b725e6ef6e5622b44b272c3Consolidation Wallet → 0x6495...Amount Transaction 1 ETH0x2fb2fc01...709e3650 ETH0x72c887a4...b265e601 ETH0x425b31b4...e8a61,252 ETHThat wallet subsequently transferred 1,250 ETH into:0x56644f6a348a142d38fb7dde2e942c9ef03d09fcAmount Transaction 1 ETH0x5b6d00a9...ba07c500 ETH0xe8384b80...cff6f500 ETH0xb9424aa...bdc58249 ETH0x8471f89d...e6b5a1,250 ETHThe final intermediary then executed 18 Tornado Cash deposits.Tornado Cash Deposit StructureDenomination Transactions Total 100 ETH121,200 ETH10 ETH660 ETHTotal181,260 ETHIt also returned 1.905145 ETH upstream.This creates an important accounting issue.Observed activity at 0x56644f... ETH Tracked incident-path inflow1,250Tornado Cash deposits1,260Returned upstream1.905145Total observed outflow1,261.905145Outflow exceeding tracked inflow11.905145The intermediary therefore spent approximately 11.905145 ETH more than it received from the tracked upstream address.The origin of that additional ETH falls outside the investigated outbound path.As a result, ChainBounty does not attribute the full 1,260 ETH from this wallet to the incident.The maximum amount supported by the tracked inflow is 1,250 ETH.6. Why 1,370 ETH Does Not Equal 1,370 ETH of Attributed Incident FundsThe distinction can be summarized as follows.Branch Gross Tornado deposits Maximum explained by tracked incident path First branch110 ETH110 ETHSecond branch1,260 ETH1,250 ETHTotal1,370 ETHUp to 1,360 ETHThis is one of the most important findings in the investigation.The observed wallets deposited 1,370 ETH into Tornado Cash.But evidence-backed attribution should stop at 1,360 ETH unless the additional funding source at 0x56644f... can also be tied to the incident.A clean transaction graph is not the same thing as a proven provenance graph.7. Consolidation-Wallet Flow SummaryThe observed movements from the consolidation wallet can be summarized without double-counting as follows.Flow Amount 0.1 ETH test transfer0.1 ETHFirst intermediary branch662 ETHSecond intermediary branch1,252 ETHGross value sent from consolidation wallet1,914.1 ETHReturned to consolidation wallet540.0 ETHGross Tornado deposits from downstream wallets1,370 ETHConsolidation-wallet balance at snapshot973.536981 ETHThe wallet's complete inbound history was not reconstructed as part of this outbound tracing exercise.The 973.536981 ETH balance should therefore not automatically be treated as entirely stolen Duelbits funds.It is a monitored balance associated with the reported consolidation wallet, not a fully attributed recovery amount.8. The Laundering TypologyThe downstream activity shows several notable behavioral characteristics.Pattern Observation Assessment Small route test0.1 ETH sent and returnedConsistent with route validationDisposable EOAsFour intermediaries became active on the day they were usedConsistent with single-purpose routing infrastructureProgressive scaling110 ETH mixed before a later 1,260 ETH batchConsistent with testing before larger deploymentFixed denominations12 × 100 ETH and 6 × 10 ETH depositsConsistent with denomination-based mixer structuringBalance cleanupResidual ETH returned upstreamSuggests temporary wallets were cleaned after routingShort wallet lifespanIntermediaries showed only a small number of outgoing transactionsConsistent with operational compartmentalizationThe pattern is more structured than simply forwarding stolen ETH directly into a mixer.The sequence suggests an operator using temporary addresses, validating routes, scaling transaction size, and cleaning residual balances after use.This is a behavioral assessment. It does not, by itself, identify the operator.9. Address Poisoning Was Removed From the GraphDuring transaction review, ChainBounty identified 32 transactions consistent with address-poisoning activity.These transactions involved addresses deliberately resembling wallets in the investigation, often sharing similar starting and ending characters.Some also transferred fake assets named similarly to ETH rather than native ETH.Poisoning SummaryImitation address Target address Events Economic relevance 0x922a86...6cd230x922adc...8cd231Fake ETH-, no native ETH0xa31bb2...138e30xa31bb1...c38e313Fake ETH-, no native ETH0x6495e2...972c30x6495af...272c32Fake ETH-0xadb80c...1c5780xadb82e...2c5787Fake ETH-0x8db9cb...ec3060x8dB9D7...0C3067Zero-value native transfers0x5664cf...c09fc0x56644f...d09fc2Fake ETH-Total32ExcludedThese transactions were excluded because they showed no meaningful economic value flow and matched common address-poisoning characteristics.Including them would create false graph edges and potentially corrupt attribution.This is an important reminder that transaction-history proximity is not equivalent to financial linkage.10. No Exchange Cash-Out Was IdentifiedWithin the investigated outbound Ethereum flow:Destination category Confirmed deposits Centralized exchanges0Tornado Cash Router20 transactions / 1,370 ETH grossPublic reporting referenced Kraken and ChangeHero in connection with activity involving the consolidation wallet.Those references concerned claimed inbound flows into the wallet, rather than confirmed cash-out destinations in the outbound path analyzed here.ChainBounty therefore does not identify Kraken or ChangeHero as laundering destinations based on the present evidence.11. What the Ethereum Transactions Suggest About the Initial CompromiseThe initial ETH and USDT withdrawals were ordinary signed transactions.Observation Implication ETH moved via a standard native transferNo obvious Ethereum contract exploit in the transaction itselfUSDT moved through a standard token transferConsistent with valid signing authority being usedETH and USDT transfers occurred 36 seconds apartIndicates coordinated executionPublic reporting describes multiple chains affected in a narrow time windowBroader signing or withdrawal infrastructure compromise is plausibleThe available evidence is therefore more consistent with compromise of withdrawal signing authority than with a vulnerability in an Ethereum smart contract.Possible mechanisms could include exposure of private keys or compromise of infrastructure authorized to sign withdrawals.The blockchain cannot determine which mechanism occurred.That question requires off-chain evidence such as key-management records, signing-service logs, server telemetry, access logs, or other internal forensic material.12. The Most Interesting Unresolved AddressOne address differs significantly from the disposable infrastructure surrounding the incident:0x4293b5dc11b250078da7359d7d57c15eecfcf70aCharacteristic Observation First activityJanuary 5, 2018Activity lifespanMore than eight yearsOutgoing transactions380Interaction with initial receiverYesInteraction with consolidation walletYesAttributionUnknownThere are two materially different explanations.Hypothesis Investigative significance Operator-controlled gas or funding infrastructureCould expose older transactions, KYC-linked services, or reused infrastructureBridge solver, relayer, or other shared serviceMay have little or no attribution valueCurrent evidence cannot distinguish between them.The wallet should therefore be treated as a high-priority lead rather than evidence of attacker ownership.13. Remaining Investigative OpportunitiesPriority Investigative target Why it matters 10x4293...Could connect short-lived incident wallets to long-lived infrastructure20x8dB9... balanceFuture transfers may reach a bridge, exchange, or additional mixer3593,430.319285 USDT pathUSDT may remain technically freezeable depending on downstream disposition40xA77e... → 0x8dB9... gapClosing this gap would strengthen end-to-end provenance5Tornado Cash exitsPotential exit candidates can be evaluated against later exchange deposits6Non-Ethereum chainsSolana, BNB Chain, Bitcoin, and Tron remain outside this Ethereum-focused investigationAt the investigation snapshot, the two monitored wallets held:Wallet Balance 0x8dB9D7...0C306973.536981 ETH0xA77e24...aef7625.566884 ETHThe original 593,430.319285 USDT transfer also remains a significant unresolved asset path.If USDT remains in token form at an identifiable downstream address, issuer-level intervention may still be relevant.14. Fund-Flow Timeline15. ChainBounty AssessDate Event Amount Sep. 24Duelbits-labeled wallet → 0xA77e...593,430.319285 USDTSep. 24Duelbits-labeled wallet → 0xA77e...836 ETHSep. 24Consolidation wallet route test0.1 ETHSep. 26Consolidation wallet → first intermediary12 ETHSep. 26Consolidation wallet → first intermediary650 ETHSep. 26–27First intermediary → consolidation wallet539.9 ETH returnedSep. 26–27First laundering branch → Tornado Cash110 ETHSep. 28Consolidation wallet → second intermediary1,252 ETHSep. 28Second intermediary → final intermediary1,250 ETHSep. 28Final intermediary → Tornado Cash1,260 ETH gross15. ChainBounty AssessmentThe Ethereum evidence supports a clear downstream laundering pattern:short-lived EOAs → staged routing → fixed-denomination mixer deposits → residual-balance cleanup.It also supports a confirmed initial withdrawal of 836 ETH and 593,430.319285 USDT from a Duelbits-attributed wallet.What the evidence does not yet support is equally important.The value path between the first receiving wallet 0xA77e... and the reported consolidation wallet 0x8dB9... remains unanchored.And while downstream wallets deposited 1,370 ETH into Tornado Cash, the transaction-level incident path explains up to 1,360 ETH, not necessarily the full amount.That is the line ChainBounty draws between observation and attribution.ConclusionThe Ethereum portion of the Duelbits incident shows a structured laundering operation built around temporary wallets and Tornado Cash.A Duelbits-labeled hot wallet transferred 836 ETH and 593,430.319285 USDT to a newly activated address on September 24.Separately, ETH leaving the publicly reported consolidation wallet can be followed through four short-lived intermediary EOAs into the Tornado Cash Router.Those wallets deposited:Metric Amount Gross Tornado Cash deposits1,370 ETHNumber of deposits20Maximum explained by tracked incident path1,360 ETHConfirmed exchange cash-out0The distinction between 1,370 ETH observed and 1,360 ETH attributable is not a technicality.It is the difference between describing what appeared in a wallet's transaction history and demonstrating where investigated value actually came from.The investigation also remains incomplete at a critical point: the first recipient and the reported consolidation wallet have shared counterparties, but the value path connecting them has not yet been transaction-anchored.For that reason, ChainBounty does not present the case as a fully closed end-to-end flow.The next breakthroughs are more likely to come from closing that missing link, tracing the USDT path, analyzing the long-lived 0x4293... address, and monitoring the remaining ETH for interaction with identifiable services.Because in on-chain investigations, the goal is not to draw the cleanest graph.It is to know exactly which edges can be proven.Investigation MetadataField Value Case IDCASE-7907CC26NetworkEthereum — Chain ID 1Incident dateSeptember 24, 2026Investigation windowAugust 23 – September 28, 2026Gross Tornado deposits observed1,370 ETHIncident-path attributionUp to 1,360 ETHExchange deposits identified0This report is based on observable on-chain transaction data and address-attribution information available during the investigation. Statements describing behavior, intent, compromise mechanism, or operator infrastructure are analytical assessments unless explicitly identified as transaction-level facts.

Duelbits Hot Wallet Incident: Tracing 1,370 ETH Into Tornado Cash
0 likes・12 reads
REPORT
REPORT

September 26, 2026

Community Investigation
Bitget’s $351.6M Hot-Wallet Breach: What 289 Addresses Reveal — and What Remains Unproven

Executive SummaryBitget confirmed unauthorized transfers from hot wallets at 18:31 UTC on 24 September 2026. The exchange stated that cold wallets were not affected and that its protection fund exceeded $464 million. Public reporting placed the loss at approximately $351.6 million.SentinelTX expanded the investigation to 289 addresses and 41 evidence items across Ethereum, Arbitrum, Avalanche and BNB Chain. The pattern is consistent with a hot-wallet signing or key compromise: one consolidation EOA appeared across chains, stablecoins were rapidly swapped into ETH, funds crossed bridges, and Ethereum proceeds were split into fixed-size tranches.The clearest recovery lead is 20,763,612.55 USDC routed from Avalanche and Arbitrum through a common receiver into a Circle-labeled address. No centralized-exchange deposit or mixer exposure was confirmed in the reviewed scope.Incident AnchorsItemValueStatusEvidenceOfficial confirmation24 Sep 2026, 18:31 UTCConfirmedBitget statementPublic loss estimate$351.6MReportedCEO / mediaSentinelTX scope289 addresses; 41 evidence itemsConfirmedCase outputCEX or mixer exposureNone confirmedOpenReviewed scopeCore Wallet MatrixRoleAddressChainEvidencePrimary consolidation0x770b10b273fC44Fe9197D6bF20F145c2e98463EeMulti-chainHighUSDT0-to-ETH swap0xe410a2e5710ee787bcaa63f52a3943ff71f0d946ArbitrumHighStablecoin receiver0xb3fa262d0fb521cc93be83d87b322b8a23daf3f0Arbitrum / AvalancheHighCircle-labeled route0xfd78ee919681417d192449715b2594ab58f5d002Multi-chainHigh label; destination openEthereum source0x469Ac1406dE92f82C0563477240a3627057425DCEthereumHighEthereum hub0xa6dd3f218b65e32ccc37be30f74884133c655545EthereumHigh inbound; mixed outflowAvalanche downstream0x5085b3d52b5587c18ef456fcbcde9a11d48340f8AvalancheHighBNB downstream0x7c96279ec1e888aa56b9b836e0db26ca48573e1cBNB ChainHighWhat the Cross-Chain Flow ShowsThe primary consolidation address was active on Ethereum as early as 7 February 2026, contradicting descriptions of it as newly created. TRDB labels on two upstream addresses are useful leads, but do not independently prove Bitget ownership.Confirmed Chain-Level MovementsChainConfirmed movementActionConfidenceEthereum1,541.51 ETHSource to distribution hubHighArbitrum19,668,851.77 USDT0 → 7,111.344304 ETHSwap and splitHighAvalanche821,000 AVAX + 8,204,678.8 USDCTwo downstream routesHighBNB Chain12,719.45 BNBRouter-linked downstreamHigh; partial pathArbitrum: Swap, Split and Partial Stablecoin RecoveryOn Arbitrum, 19,668,851.77 USDT0 reached a dedicated swap wallet and was converted through UniswapX and 1inch intents into 7,111.344304 ETH. One branch converted 2,513 ETH into 6,561,140.178933 USDC; another 26,830.363654 USDC joined the same receiver before the route reached a Circle-labeled address.Key TransactionsChainTransactionMovementStatusEthereum0xbb7f4d68c339f44e048b45bcee466bc75a086fc02d89cda8242b5031639bf8b41,541.51 ETH → hubIncident-anchoredEthereum0x872dd53e25e071ae7ae6b653a44ff18cfc041e8fdea4ac0da72c6ef97ba4ede110,000 ETHGross hub outflow onlyEthereum0xd955a11839263c24e49ddb850b17663d0122904cee1fb9c436e04203a88ec28810,000 ETHGross hub outflow onlyEthereum: Anchored Inflow vs. Gross Hub ActivityA confirmed transaction moved 1,541.51 ETH from the Ethereum source to the hub. The hub later sent several much larger tranches. Those gross outflows cannot all be attributed to this incident because only the 1,541.51 ETH inbound is directly anchored to the investigated path.Bridges, Routers and Recovery LeadsInteraction with a router or bridge does not mean that service controlled the attacker.PriorityAddress / serviceObserved amountAction10xfd78ee919681417d192449715b2594ab58f5d002 / Circle20,763,612.55 USDCPreserve and freeze route20xe35e9842fceaca96570b734083f4a58e8f7c5f2a / Across1,600 ETHTrace destinations30xef4fb24ad0916217251f553c0596f8edc630eb66 / deBridge1.001213 ETHPreserve destination tx40x2bca667d37afe8d065ca46e3261e9442e77cbeae~1,997 ETH residualMonitor and trace50x5085b3d52b5587c18ef456fcbcde9a11d48340f8~620,999.99991 AVAXMonitor and traceWhat Remains UnprovenNo threat actor has been identified. No evidence confirms a CEX deposit or mixer. The direct link from the multi-chain consolidation address to 0x469Ac1406dE92f82C0563477240a3627057425DC was not independently confirmed; it remains a third-party Bubblemaps claim. Zero-value and tiny lookalike transfers were excluded as address-poisoning noise.Untraced RemainderChainUnresolved amount / pathNext stepEthereumMuch of 34.75M USDT/USDC; hub downstreamSeparate incident funds from prior activityArbitrum~1,997 ETH + ~990 ETH; Across destinationsTrace destination chainsAvalanche~620,999.99991 AVAX; router outputResolve router recipientsBNB Chain~9,719.45 BNBTrace beyond shared routersConclusionThe evidence confirms coordinated cross-chain dispersal and a high-priority Circle recovery route, while leaving substantial balances and several bridge destinations unresolved. The urgent action is preservation and freeze outreach for the Circle-labeled path, followed by destination tracing for Across and deBridge.Evidence note: wallet balances and labels reflect the SentinelTX investigation cutoff. Public statements, third-party labels and analytical inference are separated from transaction-confirmed facts.

Bitget’s $351.6M Hot-Wallet Breach: What 289 Addresses Reveal — and What Remains Unproven
0 likes・16 reads

Your journey to defend against cyber crime starts here.

Join us to turn your expertise into a force for a safer digital world.

Blog

Gravity Bridge Exploit: Full Attacker Fund Flow Traced — 113 Transactions Reveal Sophisticated…

Gravity Bridge Exploit: Full Attacker Fund Flow Traced — 113 Transactions Reveal Sophisticated…

Gravity Bridge Exploit: Full Attacker Fund Flow Traced — 113 Transactions Reveal Sophisticated Laundering OperationThe laundering infrastructure behind the recent Gravity Bridge exploit has now been largely uncovered.After tracing 87 confirmed attacker transactions and an additional 26 downstream movements, the overall flow of stolen funds is becoming clear. What initially appeared to be a straightforward bridge exploit has evolved into a highly structured laundering operation involving decentralized exchanges, relay wallets, non-custodial swap services, and centralized exchanges.This report summarizes the complete fund flow observed so far and highlights the remaining recovery opportunities.Executive SummaryTotal tracked transactions: 113Initial stolen assets converted into ETH almost immediatelyApproximately $4.7M converted through KyberSwap and 1inch2,600 ETH consolidated into a secondary aggregation walletFunds dispersed through dozens of one-time relay walletsConfirmed deposits identified at ChangeNOW and KuCoinMultiple staging wallets still hold potentially recoverable fundsSeveral laundering paths remain active and require real-time monitoringPhase 1 — Asset ConversionThe attacker-controlled wallet:0x7B582033061b96cC3F9421e73a749ED7C62da1F9immediately began converting stolen stablecoins into ETH.The swaps were executed primarily through KyberSwap and 1inch, suggesting the attacker wanted to reduce exposure to token freezes while maximizing liquidity.Observed transactions include:$100K USDC → ETH$200K USDC → ETH$500K USDC → ETH$400K USDT → ETHMultiple additional swapsIn total:Approximately $4.3M USDCApproximately $434K USDTwere converted into ETH within a short time window.The rapid conversion indicates pre-planning and suggests the operator anticipated potential blacklisting or asset recovery attempts.Phase 2 — ETH ConsolidationAfter conversion, the attacker consolidated funds into a second wallet:0x4d3ca32e687e871a58b78AcAc73bE59AC37C7A47A total of 2,600 ETH was transferred through multiple transactions:600 ETH500 ETH500 ETH500 ETH500 ETHThis wallet appears to have functioned as the primary distribution hub for the laundering operation.Rather than cashing out directly, the operator implemented a layered relay strategy designed to fragment attribution and complicate tracing efforts.Phase 3 — Distributed Relay LaunderingThe most notable discovery is the laundering architecture itself.Instead of sending large transfers directly to exchanges, the attacker repeatedly split funds into dozens of temporary wallets.The observed pattern resembles:Primary Wallets → One-Time Relay Wallets → Swap Service / Exchange → Cross-Chain ExitIndividual transfers were commonly observed in the 6–10 ETH range.This methodology significantly reduces the visibility of exchange deposits and makes automated clustering more difficult.The pattern appears intentional and operationally mature.Confirmed ChangeNOW ActivityThe largest identified laundering route currently leads to ChangeNOW.Observed destination:0xeba88149813bec1cccccfdb0dacefaaa5de94cb1Estimated deposits:Approximately 114 ETHRoughly $230,000 equivalentBecause ChangeNOW is non-custodial, recovery options are more limited.However, transaction records still exist.The highest priority investigative question is determining what assets these ETH deposits were converted into.Particular attention should be given to:Monero (XMR)Privacy-focused assetsCross-chain bridge destinationsIf conversion into privacy-preserving assets occurred, tracing may become significantly more difficult.Confirmed KuCoin DepositsA second laundering path has been identified through KuCoin.Known deposit address:0x45300136662dd4e58fc0df61e6290dffd992b785Estimated deposits:Approximately 6 ETHAdditional suspected deposit address:0x58edf78281334335effa23101bbe3371b6a36a51Status:Further confirmation requiredUnlike ChangeNOW, KuCoin operates as a custodial exchange and maintains KYC records.This creates a potential recovery and attribution opportunity if law enforcement or affected parties act quickly.Remaining On-Chain FundsSeveral wallets remain active and continue to warrant monitoring.Primary Staging Wallet0xc8c71ae4261e55a66d9967f2ac252be4e669f562Current observations:Received 59 ETHOnly 15 ETH moved onwardApproximately 44 ETH potentially remains under attacker controlThis wallet may represent an operational staging point rather than a final cash-out destination.Additional Unresolved Destinations0xf1ed839d08309e2a52e58d69b06d286d35fc18bc — 15 ETH0xe1e471614305656114c39294637b65adccf665a3 — ~13 ETH0x58432e011aa493c404f80409d997b1eabdfd8e24 — 9 ETH0x79f376453537878eeb79fb7d2cdb2c10bc58f454 — 9 ETH0x98d9022fa2789c0d8e9cd49707599c6848619ed8 — 10 ETHThese wallets currently represent unresolved portions of the laundering network.Immediate Investigative Priorities1. KuCoin Cooperation RequestThis remains the strongest recovery opportunity.Required actions:Identify account owner(s)Preserve account recordsFreeze assets if still presentObtain associated KYC informationTiming is critical.2. ChangeNOW Exit TracingInvestigators should determine:Destination chainDestination assetConversion timingPotential privacy-coin exposureThis path likely contains the most important unanswered questions in the investigation.3. Real-Time Monitoring of Staging WalletsThe wallet:0xc8c71ae4261e55a66d9967f2ac252be4e669f562should be monitored continuously.A significant portion of attacker-controlled funds may still be sitting on-chain.Any future movement could reveal:Additional exchange depositsAdditional swap servicesNew laundering infrastructureFinal cash-out attemptsConclusionThe Gravity Bridge attacker did not rely on a simple exchange cash-out strategy.Instead, the operator employed a structured relay-wallet laundering network designed to fragment attribution, obscure exchange deposits, and delay investigation.While a meaningful portion of the funds has already entered laundering channels, several opportunities remain.The most actionable leads currently include:KuCoin deposit attributionChangeNOW conversion tracingMonitoring of the 59 ETH staging walletThe next movements from these wallets will likely determine whether investigators can continue following the money — or whether the trail disappears into privacy infrastructure permanently.

ChainBounty

ChainBounty

4 months ago
Unmasking a Sophisticated Solana Scam Network: A $SUBY Forensic Investigation

Unmasking a Sophisticated Solana Scam Network: A $SUBY Forensic Investigation

How automated bots and shared infrastructure revealed a 10-month-old organized crime syndicate.The blockchain never forgets, but it can be incredibly complex to navigate. Recently, ChainBounty conducted a deep-dive forensic investigation into a significant asset theft involving $SUBY and other Solana-based tokens. What began as a single incident report evolved into the discovery of a professional, long-standing scam infrastructure that has now led to an active criminal investigation by the Cyber Crime Investigation Division in Seoul, South Korea.1. The Incident: Precision and AutomationOn May 30, 2025, a victim’s wallet was drained of approximately 8.2 million $SUBY tokens, along with $SSE and $DAW. The speed of the transfer was alarming.Our forensic analysis revealed that this wasn’t a manual operation. The assets were moved to an intermediary wallet (46S5bgHq...) and immediately processed through automated scripts. These bots executed swaps into stablecoins and distributed funds across multiple "hop" wallets with 0-second latency, ensuring the trail became as fragmented as possible within minutes.2. Identifying the “Cash Out” InfrastructureBy tracing the flow of stolen assets, we identified two primary exit points: Bitget Exchange and FixedFloat (a mixing service). While some deposits to these platforms occurred shortly before or after the specific $SUBY theft, our “Infrastructure Analysis” proved a definitive link. We discovered a massive, interconnected network:27 Common Fee Payers: A cluster of wallets consistently funded the gas fees for the attack wallets.63 Shared Addresses: These wallets acted as a central hub for multiple thefts over a 10-month period.The Forensic Anomaly: Why tracking the criminal organization is more effective than tracking the tokens aloneThis confirms that the attackers are not “lone wolves” but an organized syndicate operating a “Scam-as-a-Service” model on the Solana network.3. The Evidence: The Smoking GunThe most compelling evidence of organized crime was the Machine-like Transfer Patterns. Our timeline analysis showed batch processing intervals of exactly 15 to 28 seconds. This level of synchronization is only possible through a dedicated command-and-control (C2) botnet designed for money laundering.Through our investigation, we identified over $142,430 USDT funneled through the Bitget deposit addresses associated with this specific group.Inhuman execution: Batch processing and mechanical intervals confirm the use of laundering bots.4. Active Investigation and Next StepsChainBounty has officially submitted this forensic package to the Seoul Metropolitan Police Agency. The investigation is currently focused on:KYC De-anonymization: Working with Bitget to identify the account holders behind the identified deposit addresses.Cross-Chain Tracking: Tracing funds that exited via FixedFloat into Ethereum and Bitcoin.Asset Freezing: Coordinating with exchanges to blacklist and freeze the identified criminal infrastructure.Conclusion: Vigilance in the Web3 EraThis case is a stark reminder that in the world of DeFi, your digital footprint — and that of the hackers — is permanent. At ChainBounty, we are committed to turning the tide against these scam networks.We urge the community to stay vigilant. Do not click on suspicious partnership links or authorize “blind signings” in your wallet. The scammers are professional, but so is our pursuit of justice.Join the Fight. Follow our investigation and report suspicious activities at our community: 🔗 https://community.chainbounty.io 📧 For inquiries: [email protected]#ChainBounty #Solana #Forensics #CyberCrime #Web3Security #OSINT #CryptoInvestigation

ChainBounty

ChainBounty

8 months ago
MemeCore (M) Digital Asset Theft Incident: On-Chain Forensics & OSINT Analysis Report

MemeCore (M) Digital Asset Theft Incident: On-Chain Forensics & OSINT Analysis Report

IntroductionThis report details a real-world case submitted by an applicant to ChainBounty’s Victim Relief Program. The victim approached us after suffering a significant loss due to a targeted social engineering attack. ChainBounty is actively assisting the victim by providing comprehensive on-chain forensics and intelligence analysis to trace the stolen assets and identify the perpetrators for law enforcement purposes.1. Executive SummaryThis report synthesizes the results of on-chain forensic analysis and Open Source Intelligence (OSINT) investigation regarding the digital asset theft incident that occurred between December 7 and 8, 2025.The incident appears to have originated from a social engineering attack targeting an active user of Memex, a major dApp in the MemeCore (M) ecosystem. The attacker impersonated community administrators and creators to lure the victim into a fake Telegram group, then induced them to connect their wallet to a fraudulent bot service using “high-yield staking rewards” as bait.The victim created a new wallet and transferred assets as instructed, but the flow was designed to funnel funds into the attacker’s scam network.On-chain analysis reveals that the stolen funds did not end with a simple transfer. A multi-stage laundering flow was observed, involving MRC-20 token swaps within the MemeCore network, repetitive transactions based on the WM contract, cross-chain bridging via Meson Finance, inflows into Centralized Exchanges (CEX), and dispersed withdrawals across multiple exchanges.Notably, a “direct-to-exchange” flow is clearly visible in the early stages. M tokens were directly transferred from the victim’s wallet to Suspect Bitget Deposit 1 (0x7a5d…), and this fund was collected into the exchange’s hot wallet (0x1ab4…) within a short period. This suggests the attacker operated a direct route to the exchange alongside other methods to accelerate cash-out early on.The damage is calculated based on two criteria:Total M Token Outflow (Direct): 2,151.11 M, approx. $2,881.39 (Combined sum of direct transfers to exchange + EOA/Gathering Wallet).Total M Token Outflow (Including Bridge): 8,280.11 M, approx. $11,150.17 (Direct outflow + Meson bridge outflow included).Furthermore, clues suggesting a connection to specific social accounts and developer community profiles were identified in Gathering Wallet 2 (0x1c00…5f), which was confirmed as a key hub for money laundering. Based on this, grounds to narrow down suspect candidates have been partially secured. However, this is a circumstantial judgment based on the correlation between public information (OSINT) and on-chain data, and is not a legally confirmed conclusion.1.1 Summary StatisticsThe key flows are summarized as follows:1.2 Summary of Key Flows (4 Core Paths)Path 1: Victim → Direct Outflow to Bitget (Attempt at Immediate Cash-out)A total of 2,140.72 M (approx. $2,867) was directly transferred from the Victim Wallet (0xdc54…) to Suspect Bitget Deposit 1 (0x7a5d…).The deposit was collected into the Bitget exchange hot wallet (Bitget 6, 0x1ab4…) within minutes (approx. 3–5 mins).This flow represents the attacker sending “M tokens that are easy to cash out immediately” straight to the exchange.Path 2: Victim → Gathering Wallet 1 → Meson Bridge → Gathering Wallet 2 (Mainstream of Indirect Laundering)After WM contract processing, 5 types of MRC-20 tokens were received by the Victim Wallet and then drained to Gathering Wallet 1 (0x8325…e6).In Gathering Wallet 1, MRC-20s were swapped back to M, and 6,129 M was bridged via Meson Finance (0x25ab…48d3).6,122.87 M arrived at Gathering Wallet 2 (0x1c00…5f) on the BNB Chain.Path 3: Gathering Wallets 1, 2 → Reconsolidation at Bitget Deposit 2 (Possible Mixing with Other Victims’ Funds)900.65 M from Gathering Wallet 1 and 5,007.02 M from Gathering Wallet 2 flowed into Suspect Bitget Deposit 2 (0xb408…).The combined total is 5,907.67 M. As there is a “possibility of other victims’ funds being mixed,” this needs to be interpreted separately from the victim’s sole damage amount.Subsequent collection into Bitget 6 (0x1ab4…) was confirmed.Path 4: Multi-chain Dispersed Withdrawal from Gathering Wallet 2 (Evasion/Smurfing)From Gathering Wallet 2, after swapping M → BNB, there is a record of 37.51 BNB being dispersed and withdrawn in 48 transactions to 5 exchanges: Bybit, Bitget, MEXC, Binance, and Remitano.Activity of the same address was confirmed on Arbitrum and Base as well as BNB, reinforcing the cross-chain laundering pattern.2. Incident Mechanism and Psychological AnalysisThis incident appears to have started from a social engineering scenario targeting human trust rather than technical flaws such as system vulnerabilities. It seems to be a variation of the typical “Pig Butchering (Sha Zhu Pan)” tactic adapted to the MemeCore ecosystem context. There are indications that the attacker analyzed the community atmosphere and the victim’s activity patterns beforehand to approach with a tailored script.2.1 Manipulating the Environment to Build Trust: “The Illusion of the Fake Room” The attack seems to have begun with an approach from an account mimicking an acquaintance active on Memex. In anonymous messenger environments like Telegram, profile pictures and Display Names can be configured similarly, and Usernames (Handles) are hard to distinguish with just a one-character difference. The attacker judged to have secured trust by exploiting these characteristics. The Telegram room the victim was invited to contained multiple accounts impersonating Admins and Creators. They staged the room to look like an “Official Community” by continuing conversations or sharing profit verification screenshots even before the victim joined. In such an environment, it was easy to mistake the room for an extension of the official Memex community, which became the basis for the fraud.2.2 Technical Deception: Fake Bot and Inducing Wallet Connection Once a certain level of trust was established, the attacker guided the victim saying, “You can receive staking rewards if you connect your wallet via the Telegram bot”. The method is close to a typical Phishing or Drainer type. The wallet (0xDC54…69b) the victim newly created and connected was a “clean wallet” with almost no transaction history. The moment the victim trusted the instructions and moved assets, it is likely the attacker secured control through one (or a combination) of the following methods:Possibility that the transaction signed via the bot was actually an Unlimited Token Approval, not staking.Possibility that it was designed to execute an asset Transfer transaction during the signing or connection process.Possibility that keys or permissions were exposed to the attacker during the wallet creation/connection process. The key point is that “Wallet Connection” may have turned into an act of handing over actual asset authority, rather than simple login or authentication.3. Technical Characteristics of MemeCore Ecosystem and Asset StructureTo interpret the fund flow, it is necessary to first understand the background of the MemeCore chain where the victim’s assets existed and the asset structure. This explains why the attacker performed repetitive swaps and why the laundering path developed into a specific pattern.3.1 MemeCore and Proof of Meme (PoM) MemeCore is a Layer 1 chain aimed at connecting the cultural value of Memes with an economic reward structure. It promotes Proof of Meme (PoM) as its consensus structure, which includes elements like community contribution and viral activities in the reward system alongside simple staking. The base asset of this chain is the M token. M is used for core functions such as gas fees, governance, and validator staking, and has relatively high liquidity, which is why the attacker ultimately pooled funds into M for laundering.3.2 MRC-20 Token Standard and Cash-out Constraints Tokens such as NinjaMEX, walxop, LIFT, Bubger, and Abudium identified in the swap path of this incident follow the MemeCore-specific token standard (MRC-20). These appear to be “transit tokens” temporarily passed through during the process of the attacker exchanging stolen assets on the internal DEX, rather than assets originally held by the victim. Technically similar to ERC-20, they are structured for the creation and circulation of meme tokens within MemeCore. The issue is external compatibility. Since it is rare for external chains, centralized exchanges, or bridges to directly support MRC-20, it is difficult for the attacker to move them out externally and cash them out in the MRC-20 state. Eventually, to proceed to the actual cash-out stage, they must go through the flow of: converting back to M on the internal DEX -> moving to an external chain (BNB Chain, etc.) via a bridge -> attempting cash-out via swap/dispersed withdrawal on the external chain. The massive internal swap transactions observed in the report are interpreted as reflecting the constraint of having to convert back to M for external export, along with the possibility of transit swaps intended to confuse tracking in some sections.4. Incident Timeline and Detailed Forensic ReconstructionThis incident is clearly divided into Reconnaissance & Testing on December 7 and the Main Exploit on December 8. The attacker checked the validity of the path the day before, and then stole all available assets and proceeded with rapid laundering the next day.4.1 Phase 1: Reconnaissance and Initial Infiltration (Dec 7) — Traces Left by Destination Choice Immediately after securing access rights, the attacker showed a pattern of verifying two things with small (or relatively small) transfers first, rather than moving the full amount immediately:Whether the wallet is actually usable by the attacker.Whether the exchange deposit is processed normally (no risk of detection/blocking). At 10:18 UTC, 388.717 M was transferred to Bitget Deposit 1 (0x7a5d…), and at 14:08 UTC, an additional 752 M was transferred via the same path. This flow aligns with the typical pattern of a small test followed by additional transfers. The notable point is that the receiving address 0x7a5d…337 is estimated to be a User-Assigned Deposit Address of a Centralized Exchange (Bitget), not a personal wallet. Funds flowing into this address were observed being collected into the Bitget hot wallet (0x1ab4…f23) within minutes. If cooperation with the exchange is established, there is a possibility that tracking can continue on an account basis (KYC-based).4.2 Phase 2: Full-Scale Asset Theft and Laundering (Dec 8) — Forced Conversion to M and Exfiltration The full-scale theft proceeded rapidly on December 8. In this phase, it is observed that repetitive processing of the WM contract and mass liquidation (swap) of MRC-20 tokens were carried out in parallel with simple transfers.4.2.1 WM Repetitive Processing Pattern: Between 06:45 and 06:49 UTC, 8 repetitive transactions occurred against the WM contract, confirming processing (Deposit/Withdraw) of approximately 8,000 M. This repetitive wrapping/unwrapping can be interpreted as (1) a staging to confuse tracking, or (2) a preparatory step to match the asset form required for subsequent swaps/bridging.4.2.2 Organized Outflow of 5 MRC-20 Tokens and Immediate Cash-out: Around 1:24 PM, continuous M→MRC-20 swap transactions via the internal DEX occurred in the victim’s wallet, which appear to have been performed by the attacker. Subsequently, these 5 MRC-20 tokens were transferred to Gathering Wallet 1 (0x8325…eae6), where a process of converting them back to M via the Swap Router was observed. This choice is pragmatic from the attacker’s perspective. The longer low-liquidity meme tokens are held, the greater the price fluctuation and tracking traces may become. It seems the attacker chose to quickly convert MRC-20 to M to increase mobility and cash-out potential.4.3 Phase 3: Cross-Chain Bridging and Final Concealment — Attempt to Evade Tracking via Chain Hopping The secured M tokens did not stay in the MemeCore chain for long and were observed moving to the BNB Chain via the Meson Finance (0x25ab…48d3) cross-chain bridge.Meson Bridge: 6,129 M Deposited.BNB Chain Arrival: 6,122.87 M received at Gathering Wallet 2 (0x1c00…5f) (Approx. 3 mins to arrive). Gathering Wallet 2 subsequently acts as a hub to send funds to exchanges or disperse them to other chains (Base, Arbitrum). It has a strong character of a “Operational Wallet” used repeatedly rather than a simple transit point.5. Fund Flow Structure AnalysisFunds drained from the victim’s wallet moved largely in two directions:Direct Outflow straight to the exchange (Priority: Speed).Indirect Laundering via gathering wallets and bridges (Priority: Evasion).5.1 Key Deposit (Receiving) AddressesSuspect Bitget Deposit 1: 0x7a5d...337 / Received: 2,140.72 M (~$2,867.47) / Note: Exchange Transfer.Gathering Wallet 1 (MemeCore): 0x8325...eae6 / Received: 5 MRC-20s + 10.39 M / Note: MRC-20 → M Swap.Gathering Wallet 2 (Multi-chain Same Address): 0x1c00...285f / Received: 6,122.87 M & Multi-chain activity (BNB/Arbitrum/Base).Suspect Bitget Deposit 2: 0xb408...dd5c / Received: 5,907.67 M (~$7,969) / Note: From Gathering Wallets 1, 2 → Exchange. Caution: Possibility of mixing with other victims' funds..5.2 Characteristics and Implications in Fund Flow First, the laundering strategy is split into two. Part of it prioritized speed by sending it quickly to the exchange (Path 1), while the rest tried to make tracking difficult through bridging and multi-chain dispersion (Paths 2, 4). Second, Bitget appears repeatedly. Both the direct outflow path (0x7a5d…) and the path from the gathering wallet (0xb408…) converge to Bitget deposit addresses. In particular, 0xb408… is a common point receiving funds from both Gathering Wallet 1 and Gathering Wallet 2, making it a candidate for a key cash-out window. However, as other victims’ funds may be mixed in this section, definitive conclusions should be avoided. Third, Gathering Wallet 2 (0x1c00…5f) functions as a central node that receives bridged funds and then performs exchange transfers or dispersion to other chains.5.3 Multi-Exchange Dispersed Withdrawal (Smurfing) Statistics (BNB Only) From Gathering Wallet 2 (BNB Chain) → Exchange Withdrawal Statistics:Bybit: 23.44 BNB / 16 txsBitget: 7.15 BNB / 2 txsMEXC Global: 5.06 BNB / 22 txsRemitano: 1.30 BNB / 4 txsBinance: 0.56 BNB / 4 txsTotal Exchange Withdrawals: 37.51 BNB / 48 txs / 5 Exchanges Note: After swapping M → BNB at Gathering Wallet 2, dispersed withdrawals were made to multiple exchanges. Activity of the same address was confirmed on Arbitrum and Base, reinforcing the cross-chain laundering pattern. Reference: Remitano is known as a platform widely used for P2P trading in Southeast Asia, which can serve as a reference clue for geographic profiling (Note: Do not conclude).6. Relevant Actor Intelligence AnalysisIn this investigation, by cross-examining on-chain flows and off-chain public activity traces, we secured clues to narrow down the relevant Actor (Actor A) and associated account/profile candidates. The central address of the analysis is Gathering Wallet 2 (0x1c00…5f), and OSINT information was organized around this address.6.1 Circumstances Connecting On-Chain Activity and Digital Identity In this case, some clues were observed where 0x1c00…5f, identified as a key gathering address, could be connected to external public activities. If the same address is repeatedly mentioned or exposed in specific social accounts or community profiles, it can serve as important evidence connecting on-chain addresses with off-chain activities. There are circumstances where a specific social account marked as (Redacted) posted the 0x1c00…5f address multiple times in posts related to past airdrops, whitelist registrations, faucet participation, etc. This raises the possibility that the address is associated with the account’s activity to a certain level.6.2 Detailed Identity Profile (Circumstantial) In the OSINT investigation, circumstances were confirmed where the social account/handle marked as (Redacted) is connected to a specific bounty/task platform (e.g., Superteam Earn) account/profile. The following additional information is derived from this:Real Name/Legal Identity: (Redacted)Country/Region of Residence: (Redacted; Partially consistent with Remitano usage patterns, etc.)Professional Identity: (Redacted; Based on self-introduction)Tech Stack Claims: (Redacted)Activity Character: (Redacted)Additional Explanation: Meaning of “Partially Consistent with Remitano Usage Patterns” Here, “Partially consistent with Remitano usage patterns” does not mean concluding residence in a specific country/region (e.g., Vietnam) solely because Remitano appeared. It is intended to be referred to as a supplementary clue that increases probability from the perspective of Geo-profiling. specifically:Regional Character of Remitano: Remitano is known to be relatively widely used for P2P On/Off-ramp (cash-out/settlement) purposes in Southeast Asia (especially Vietnam) rather than being used equally worldwide like global major exchanges. Therefore, if Remitano is naturally included and repeatedly observed in the multi-exchange withdrawal flow, the possibility that the actor’s living sphere/settlement environment touches the Southeast Asian region (including Vietnam) relatively increases.Hints form “Exchange Combination”: In this case, regional P2P channels like Remitano appear alongside general-purpose exchanges like Bybit, Binance, and MEXC. This combination can be interpreted as a form often observed in dispersed withdrawals considering the final cash-out route, rather than simple investor propensity.Therefore, Remitano traces are worth referencing as a “Geographic Clue Candidate”. However, it is a “Supplementary Clue,” not definitive evidence. Final confirmation must be made through cooperation/investigation data such as exchange KYC, login/access logs (IP/Device), and withdrawal methods (Bank/Payment info).7. Conclusion & Our CommitmentComprehensive Conclusion This incident, occurring on December 7–8, 2025, was a social engineering-based asset theft. Funds were laundered through two parallel paths:A direct path flowing straight into the Bitget exchange (Speed).An indirect path exfiltrated to external chains via the Meson bridge after internal swaps on MemeCore (Stealth).Additionally, circumstantial evidence links “Gathering Wallet 2” (0x1c00...5f) to specific social accounts and developer profiles, providing strong identification clues for law enforcement.Response Strategy ChainBounty has advised a phased response:Phase 1: Immediate reporting to law enforcement with key TxIDs and requesting asset freezing at Bitget.Phase 2: International cooperation review for cross-border tracking.Phase 3: Continuous monitoring of suspect addresses and community education on risk factors.Need help tracking stolen funds? Recovering stolen assets starts with professional tracking. If you have been targeted by a similar exploit, do not hesitate to reach out. ChainBounty’s Victim Relief Program provides the forensic evidence needed for law enforcement reporting and exchange cooperation.👉 Apply for Victim Relief Program: https://chainbounty.io/en/event/campaign-victim-support/(Disclaimer: This report is based on on-chain data and public OSINT. Identity-related content is circumstantial estimation. Final legal judgments must be confirmed through lawful procedures by law enforcement agencies.)

ChainBounty

ChainBounty

8 months ago