YFarmX investigation: Venus attack proceeds flowed into the funding trail behind Tectonic on Cronos
Venus Protocol named its attacker in March. Those proceeds went to the wallet that five months later funded the Cronos drain, a link we can find no prior published account of. Every hop across three chains, graded by evidence.

This is a reference document rather than a news report. The Cronos events are covered in our news piece; what follows is the underlying record across three chains, laid out so that anyone can check it, argue with it, or take it further.
It began as the funding trail behind one exploit. It is not that. The same wallets ran the Venus Protocol donation attack on BNB Smart Chain in March 2026 and funded the Tectonic drain on Cronos in August, and Venus Protocol’s own incident post-mortem names one of them. Section 10 carries that, and it is the part to read first if you read nothing else.
How we did it is written up separately. The nine methods run against Tornado Cash in the course of this, what each returned, and the two that returned nothing, are in a companion piece: we ran nine methods against Tornado Cash and the mixer held. The short version is that the mixer was never broken and the money was traceable anyway.
What is new here, and what is not. BlockSec’s March analysis already names this funding wallet in full, states the 7,447 ETH it received through Tornado Cash, and traces the nine months of token accumulation that followed across multiple wallets. Venus Protocol’s own post-mortem covers the same ground. Much of what sections 5 to 10 describe retraces a path BlockSec walked first, and we claim none of it.
What we can find no prior account of is one step: that the wallet on the receiving end of the Venus proceeds is the wallet that five months later paid for the Cronos stake. BlockSec’s report predates the Cronos attack by five months and mentions neither Cronos nor Tectonic, which anyone can check by opening it. Everything on the Cronos side, sections 3, 4, 11 and 13, is our own.
We reached the link from the Cronos end, tracing funding backwards without knowing where it went, and only then found Venus and BlockSec describing the same wallets from the other direction. If someone published the connection first, we will say so here and credit them.
Every claim carries a grade. Where the evidence stops, it says so.
| Grade | What it means |
|---|---|
| Fact | Reproducible from the hashes and calls given here |
| Decoded | A protocol message parsed byte by byte, or arithmetic |
| Counted | A volume, note count or population matched across a window |
| Inference | A heuristic reading of on-chain patterns |
| Lead | A candidate that fits, and is not shown |
| Limit | Something we tested and could not establish |
All times are UTC. Balances and nonces were read on 1 September 2026 and will drift. Cronos hashes marked ORPHANED no longer resolve, because the rollback replaced the blocks holding them; they are not broken references, they are what a rewind leaves behind.
1. The incident in one page
| What happened | Tectonic’s lending markets on Cronos were emptied in one transaction |
| How much left the pools | About $124.5m, from Tectonic’s own borrow records |
| When | 30 August 2026, position opened 12:38:56, markets drained 12:49:39 |
| The chain’s response | Halted at 14:32:47, then rewound 10,962 block heights |
| What the rewind returned | $5,000,950.223954 of the attacker’s own stake |
| What it did not remove | The attack contract, still deployed, 16,569 bytes, nonce 3 |
| What reached Ethereum | 3,356.444730 ETH, where no rollback goes |
| Where the funding starts | A 0.0974 ETH Tornado Cash note, 6 June 2025 |
| Where the funding trail ends | At the mixer, and we proved it ends there |
| Where the money went | BNB Smart Chain, about $9m, converted into BNB |
| What it did there | The Venus Protocol attack, 15 March 2026, section 10 |
| Confirmed by | Venus Protocol’s own post-mortem, which names our wallets |
| Our best-named suspect | Downgraded from likely to unlikely, section 6 |
Counted, with a caveat that has to travel with the figure. The $124.5m is our
own tally of every Borrow record across all eighteen Tectonic markets for the
blocks covering the attack, and it comes to $124,472,178. We read those
records off the halted chain within hours, before the rollback. They are no
longer reproducible: the borrow events sat in the blocks the rewind replaced,
so anyone checking today will find nothing at those heights. That is why the
figure is graded rather than stated flat, and it is also why estimates in
circulation differ. A $75m figure published on the afternoon counts what was
found sitting in the attacker’s wallets; ours counts what left Tectonic’s pools.
DefiLlama’s record supports the larger number, showing Tectonic at $121.7m at
midnight and about $3.08m by the evening.
The shape of the case is unusual and worth stating at the top. A rollback is normally described as undoing a theft. This one undid the spending of the stake and left the funding of it intact, because the funding happened before the boundary and the spending after. The attacker’s launch capital came back to them.
2. Timeline
| When | What | Grade |
|---|---|---|
| 25 Jan 2025 | A second wallet begins withdrawing 100 ETH notes | Fact |
| 8 May 2025 | The BitoPro exchange is breached, per the exchange | Fact |
| 14 May 2025 06:28 to 08:22 | BitoPro Exploiter 2 deposits 55 notes, 4,091.5 ETH | Fact |
| 6 Jun 2025 03:16:35 | The funding wallet is created by a relayed 0.0974 ETH note | Decoded |
| 6 Jun 2025 04:01:23 | Forty-five minutes later it withdraws its first 100 ETH note | Fact |
| Jun 2025 to Jun 2026 | 83 notes, 8,300 ETH, in four batches | Counted |
| 13 Jun 2025 | A rehearsal on Venus: borrow $200,000 against XVS collateral | Fact |
| Jun 2025 to Feb 2026 | About 30,000 micro-swaps buy at least 39.7m THE on BSC | Counted |
| 15 Mar 2026 04:59 | One rehearsal pass of the Venus attack loop, at trivial size | Fact |
| 15 Mar 2026 11:55:18 | The Venus attack contract is deployed; 36.1m THE donated | Fact |
| 15 Mar 2026 12:42 to 13:26 | The position is liquidated 8,039 times | Fact |
| 22 and 24 Mar 2026 | 605.829 and 1,743.027 ETH reach the funding wallet | Fact |
| 21 to 24 Apr 2026 | The round trip: 23 notes in, 23 out, 1,800 ETH to Tron | Counted |
| 15 to 16 Jun 2026 | 2,575.5 ETH returned to Tornado, then silence | Fact |
| 5 to 6 Aug 2026 | The depth probe on Cronos, about $1,180 of slippage bought | Decoded |
| 18 Aug 2026 14:47:15 | The attack contract is deployed at nonce 0 | Decoded |
| 21 Aug 2026 09:46 to 10:05 | The function test, ending in a deliberate liquidation | Decoded |
| 30 Aug 2026 10:35:32 | 2,160,000 USDC.e arrives in the stake wallet | Fact |
| 30 Aug 2026 12:38:52 | Block 90,896,188, the last block both chains agree on | Fact |
| 30 Aug 2026 12:49:39 | Eleven Tectonic markets emptied in one transaction | Fact |
| 30 Aug 2026 14:32:47 | Cronos stops producing blocks at 90,907,150 | Fact |
| 30 Aug 2026 14:42:59 | Ten minutes after the halt, an Ethereum wallet is topped up | Fact |
| 31 Aug 2026 17:43 | 182,178.22 USDC converted to 73.734618 ETH | Fact |
| 31 Aug 2026 23:57:59 | 140 ETH leaves the largest escape wallet | Fact |
3. The rollback, and the asymmetry inside it
Fact. Three heights define the rewind, and all three were confirmed identical on three independent Cronos endpoints.
| Height | Time | Status |
|---|---|---|
| 90,896,188 | 12:38:52 | The last block both chains agree on |
| 90,896,189 | 12:38:55 | The first height rebuilt with different content |
| 90,907,150 | 14:32:47 | The old tip, discarded |
Hash of the common ancestor:
0x53c11afca70a74758968bddab1377831070e79095f195e4251de2caab5a1b008
Hash of the first replaced height on the chain running today:
0x1fdcf36ebc628b6de2e51d119ddf213816b7afeb5bfe9ce50510cc47936dc223
10,962 block heights were replaced.
Decoded. The asymmetry follows from the timestamps and needs no interpretation. The stake was funded at 10:35:32, which is inside the surviving history. The position opened at 12:38:56, four seconds after the boundary, which is inside the discarded history. A rewind can only remove what came after the fork point, so it removed the attacker’s spending and left their money.
0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc holds 5,000,950.223954 USDC.e
and has made no outbound transfer since.
You do not have to take our word for that figure. We publish a page that reads these balances live from public Cronos and Ethereum nodes, in your own browser: check the Tectonic wallets yourself. It covers the stake the rewind gave back, what reached Ethereum, and the three wallets fuelled on 21 August and never used.
The token carries no switch
Decoded. The bridged USDC.e contract on Cronos,
0xc21223249ca28397b4b6541dffaecc539bff0c59, is 10,994 bytes.
We did not search the bytecode for those words. Function names are not generally
present as readable strings in deployed code, so a string search would prove
nothing. What we searched for is four-byte function selectors, the first four
bytes of the Keccak hash of each signature, which is what a contract’s dispatcher
compares against to route an incoming call. Absent from the dispatcher:
blacklist, isBlacklisted, pause, unpause, paused, seize, burnFrom,
destroyBlackFunds, addBlackList and freeze, in their standard signatures.
Two limits on that, stated rather than glossed. A function reachable only
under a non-standard signature would not be caught, because we can only search
for signatures we thought to hash. And the absence of implementation and
upgradeTo selectors is weaker evidence of “not a proxy” than a DELEGATECALL
scan of the runtime code would be. We report it as what it is.
Cronos does carry a freezable token: Circle’s own native USDC at
0x3d7f2c478aafdb65542bcb44bceec05849999d2d, with a blacklister at
0x31f58b04f03d791c56de058211f0c767af96b464. Circle launched it on Cronos only
weeks before the exploit, so almost all of Tectonic’s depth was still the bridged
version. The attacker holds 2,900.00 of the native token, also predating the
exploit, and isBlacklisted returns 0 for every cluster address we hold.
A narrower claim than it looks. This is about the token, not about possibility. A chain that has just rewritten 10,962 blocks has demonstrated it can act at the chain level whenever it chooses. And the claim about the token is only as wide as the test: we found no standard freeze or blacklist control in the selector set the contract exposes. A privileged path under a non-standard signature is not excluded by that. What we can say is that the ordinary lever, the one an issuer reaches for, is not there to pull.
The machinery survived
Fact. 0x085f3115ca368aa262246d22f9476e1e2c87e8be holds 16,569 bytes of
code at nonce 3 on the canonical chain. It was deployed at nonce 0 on 18 August,
twelve days before it was used, and we re-derived the address independently from
keccak256(rlp([deployer, 0])).
Its bytecode carries 48 four-byte sequences that could be function selectors. Four are ASCII fragments from embedded strings, so 44 are plausible. Six of those four-byte sequences map to known function signatures:
| Four-byte sequence | Maps to |
|---|---|
0xb61d27f6 |
execute(address,uint256,bytes) |
0x2e1a7d4d |
withdraw(uint256) |
0x38ed1739 |
swapExactTokensForTokens(uint256,uint256,address[],address,uint256) |
0x095ea7b3 |
approve(address,uint256) |
0xa9059cbb |
transfer(address,uint256) |
0x70a08231 |
balanceOf(address) |
The row worth reading carefully is the first. execute(address,uint256,bytes) is
the signature of an arbitrary-call primitive: where it is a live entry point, it
lets whoever controls the contract make it call any address with any payload.
Three claims, and we are only making the first. There is a difference between
bytes present in the runtime code, a function the dispatcher actually routes to,
and a function that was called. Our enumeration walks the bytecode for four-byte
sequences; it does not disassemble it opcode by opcode. So what we establish is
that the sequence 0xb61d27f6 is present in the runtime of a contract with no
published source. We have not confirmed it sits in the dispatcher, and we make
no claim at all about whether it was ever invoked. Cronos is not covered by the
transaction-history APIs we used for the Ethereum and BNB Smart Chain work, so we
could not test that third question either way and we are not going to imply an
answer to it. Capital restored, machinery intact, and both of those are readable
today.
4. The rehearsal, 5 to 21 August
The preparation is the part that changes how the attack should be read, because it is not the work of someone improvising.
The depth probe
Decoded. On 5 and 6 August, 0x7ebe55588db070da035f9Bf5505d4fB880dA400a took
in 2,267,290,551,430 TONIC and sold every unit into all three TONIC markets,
finishing at exactly zero.
| Pool | Pair | TONIC |
|---|---|---|
0x2f12d47fe49b907d7a5df8159c1ce665187f15c4 |
USDC/TONIC | 1,223,645,275,715 |
0x4b377121d968bf7a62d51b96523d59506e7c2bf0 |
WCRO/TONIC | 643,645,275,715 |
0xa922530960a1f94828a7e132ec1ba95717ed1eab |
VVS/TONIC | 400,000,000,000 |
The dollars coming back decay monotonically across eleven fills: 3,541.50, 3,451.68, 3,384.33, 3,304.42, 3,253.58, 3,197.25, 3,136.81, 3,069.35, 2,994.42, 2,940.69, 2,407.89.
The decay is the output. A fixed input paying less each time measures how much price impact the market absorbs before it breaks. About $32,390 of notional bought roughly $1,180 of slippage as a reading.
token0 of the USDC/TONIC pool is the same contract that tUSDC.underlying()
returns. The probed pair and the lending market’s supply asset are the same token,
confirmed from both directions.
The function test
Decoded. On 21 August they did not check that deposits work. They borrowed to the edge of liquidation and let it happen.
| UTC | Block | Action |
|---|---|---|
| 09:46:12 | 89,379,277 | mint 1,000 USDC into tUSDC |
| 09:50:03 | 89,379,686 | borrow 700,000,000 VVS |
| 09:52:39 | 89,379,978 | borrow 100,000,000 VVS |
| 09:54:12 | 89,380,153 | borrow 50,000,000 VVS |
| 09:59:42 | 89,380,743 | liquidated |
| 10:04:53 | 89,381,356 | self-repay 425,027,150.29 VVS |
| 10:05:35 | 89,381,420 | redeem 557 USDC |
At a 0.80 collateral factor, 1,000 USDC gave $800.08 of borrowing capacity. The three borrows took the debt to $658.63, then $752.72, then $799.77, which is 99.961 per cent of capacity. Four basis points inside the limit.
The VVS oracle then ticked up 0.70 per cent and the position became liquidatable.
The liquidator repaid 424,974,805.4824 VVS, exactly half the 850m borrowed,
matching closeFactorMantissa of 0.5, and seized 4,104.80940265 tUSDC at a
seize-to-repay ratio of 1.1000, matching liquidationIncentiveMantissa.
Whole rehearsal: 19 minutes 23 seconds. Cost: $443.
Inference, and it cuts against the obvious reading. The probe touched exactly two markets: tUSDC on the supply side and tVVS on the borrow side. tVVS was never touched in the attack. tTONIC, the market whose price was moved, the probe never touched at all. Someone testing the specific attack would have tested the specific markets. This reads as a check that the liquidation machinery behaves as documented, not as a dry run.
Total reconnaissance spend: roughly $1,200. That $1,200 established that $5m of stake was enough to move the market.
The plumbing put in place alongside it
Fact. On 17 August at 14:20:47 a wallet was created as the recipient of a
Tornado withdrawal of 0.0978607229504 ETH, then topped up with 10 ETH the
following day. 0x9E2CFB823AdB9BD67a41C1845C0Dd70453D7D378 has since sent 16
transactions and still holds 4.042018684 ETH. It is the gas dispenser: it
fuels the wallets that do the work rather than doing any itself, and it is the
address that pays the fourth escape wallet on 31 August in section 11.
Fact. On 21 August three further Ethereum wallets were fuelled and then never used at all.
| Address | Held | Sent |
|---|---|---|
0xbaA143E23285a7bBB4803cB023724e5c616547e2 |
0.2 ETH | 0 |
0x0F8C0c8d5b9906F5e439c9a1086BF2f742fb7495 |
0.1 ETH | 0 |
0x3b5a2d0D6050Aeae57EA20b17e2b0cA263356644 |
0.1 ETH | 0 |
All three are still at nonce 0 today. One of them, 0xbaA143E2, was topped up
again at 14:42:59 on 30 August, ten minutes and twelve seconds after Cronos
stopped producing blocks. The chain had halted. The infrastructure had not.
5. The origin, and the wall
Everything above is Cronos. Everything from here is Ethereum, where nothing was rolled back and the whole preparation is still legible.
Where it starts
Decoded. The funding wallet 0x7a79969a0B9D51D922C4810D2950560360F6f234 was
created on 6 June 2025 at 03:16:35 by a withdrawal from the Tornado Cash 0.1 ETH
pool. The pool’s own Withdrawal event carries every detail.
| Field | Value |
|---|---|
| Transaction | 0xb186d5d86e5662124c2c40fc5946be6b0433fad486e2964d1f3b71cec50e482c |
| Block | 22,642,816 |
| Relayer fee | 0.002580596806050000 ETH |
| Net to the wallet | 0.097419403193950000 ETH |
Nullifier 0x0aebe2f23857e8f8347babfcebce4c40f48e1fb7377a7b61b31db31e7a6cfdde.
Forty-five minutes later, at 04:01:23, the wallet called the Tornado router itself and 100 ETH arrived. Every one of the 83 withdrawals that followed has the same shape: relayer field set to the zero address, fee zero, gas limit 550,000, and a 3.000 gwei priority fee. That combination is consistent with the stock Tornado front end, and that is how we use it below: as a fingerprint that groups transactions, not as proof of which client was open.
One behavioural detail survives from the origin hop. The first withdrawal was relayed, by a service address that has since sent 7,101 transactions and holds 15.62 ETH. Every withdrawal in the April 2026 round trip was self-relayed with a zero fee. Between June 2025 and April 2026 the operation started paying its own gas. The relayer identifies nobody; it sells gas to anyone who pays.
What came out
Counted. Eighty-three withdrawals of exactly 100 ETH, in four batches. The table also gives the pool’s unspent-note count at each batch’s first withdrawal, which is the anonymity set the operator was hiding inside.
| Batch | Dates | Notes | Unspent notes in pool |
|---|---|---|---|
| B1 | 6 to 19 Jun 2025 | 24 | 1,254 |
| B2 | 2 to 18 Dec 2025 | 28 | about 2,945 |
| B3 | 2 to 5 Feb 2026 | 22 | about 2,008 |
| B4 | 5 Jun 2026 | 9 | about 2,012 |
The B1 figure is checked against the contract’s own balance: 125,400 ETH at block 22,643,039, which is 1,254 notes exactly.
A correction to our own published thread. Our X thread said the wallet “pushes” those notes through the pool. The counts, the months and the 8,300 ETH total are all right; the direction is not. Those 83 came out. The wallet also deposited, but 25 notes of 100 ETH, and all of them in June 2026.
The wall, and how we tested it
Limit. 0x7a79969a is the furthest back anyone gets, and this is the single
most important limit in the document.
The note that created it came out of Tornado, so the deposit that funded it is unlinkable by construction. The obvious question is whether the note-counting method that worked on the April round trip works here. It does not, and we ran it rather than assuming.
Every Deposit and Withdrawal the 0.1 ETH pool emitted across 5 to 7 June 2025:
| Count | |
|---|---|
| Withdrawals | 39 |
| Distinct recipients | 24 |
| Deposits | 59 |
| Distinct depositors | 25 |
April worked because 23 notes in and 23 notes out was a count nobody else in the window came near. Here the wallet took one note, and it is one of 19 recipients that week who took exactly one. A single note is the most ordinary transaction the pool has. There is no unique match to find.
It is worse than that for anyone hoping to push further: a Tornado note can sit unspent for years, so the true candidate set is every unspent deposit in the pool’s history, not the 25 depositors in that window.
The origin of the capital is behind the mixer and stays there. We record this because a stated limit is worth more than a silence.
What the withdrawal calls themselves leak
The proof hides which deposit was spent. It does not hide how the proof was made, and that turns out to carry more than we expected. We decoded the calldata of all 83 withdrawals directly rather than reading Etherscan’s rendering of them.
Decoded. Every call is
withdraw(address,bytes,bytes32,bytes32,address,address,uint256,uint256). Across
all 83: the relayer field is the zero address, the fee is zero, the refund is
zero, the pool is the 100 ETH pool and the recipient is the wallet. That confirms
the self-relaying from the calldata itself rather than from a fee that happens to
be absent.
Decoded, and this is new. The third argument is the Merkle root the client had synced when it built the proof. Across the 83 withdrawals there are 24 distinct roots, and the root changes at 23 of the 82 transitions.
Read that carefully, because it bounds the claim. Fifty-nine of the 82 consecutive pairs share a root with the withdrawal before them, and the longest unbroken run of a single root is ten withdrawals. A shared root is what a batch built in one sitting looks like. The evidence therefore establishes at least 24 separate occasions on which a client re-synced the tree and built proofs, not 83 live moments.
What it does rule out is one single batch: a single sitting would have left one root across all 83. Instead there are two dozen, advancing whenever deposits had landed in between, with several withdrawals following each sync.
The practical consequence survives the narrower reading. There are 83 broadcast timestamps and at least 24 separate sessions in which something fetched the pool’s event history. Whichever RPC endpoint or front end served those fetches may hold network telemetry capable of identifying the client, though a local node, a rotating set of providers, or a VPN would each weaken that, and nothing on chain says which was used.
Inference. Sixty-one of the gaps between consecutive withdrawals fall inside half an hour, with a median of 108 seconds and a floor of 60. That interval is consistent with proof generation plus a confirmation step. It does not distinguish a person clicking from a queue pacing itself. The June 2026 re-deposits went in 12 to 24 seconds apart, and deposits need no proof, so that end of the range is a script.
On 12 June 2025 the root refreshed between withdrawals 84 and 96 seconds apart, while an unlabelled depositor was in the middle of a 110-note run. Two clients were working the same pool in the same minutes.
Inference, and it cuts against the lead in the next section. Eighty-three withdrawals across 18 distinct days, plus the second cluster wallet’s 10, gives 26 days of activity. Twenty-three of those 26 are Monday to Friday. Not one falls on a Sunday. Under a uniform assumption the odds of drawing 26 days with three or fewer at a weekend are about one in 27.
Treat that as suggestive rather than settled: 26 days is a small sample and someone can choose when to press a button. The hour-of-day profile, for what it is worth, does not localise anything. Activity spans 02:00 to 23:00 UTC with dead hours scattered through it, and it does not match the compressed early-UTC working day associated with the state-linked crews that dominate exchange thefts. Whoever this is appears to keep a working week and take Sundays off.
6. The deposit side, and the BitoPro lead
If the link cannot be made deterministically, the next question is what the pool looked like before each batch. That is observable: the population of deposits, their timing, denominations, tooling and funders.
Counted. All Deposit and Withdrawal events of the 100 ETH pool from 1
January 2025 to 17 June 2026: 8,228 deposits and 7,477 withdrawals, with
depositor addresses resolved for 8,220 of them. 1,806 distinct addresses
deposited; 4,541 received withdrawals.
One number from that dataset kills a tempting shortcut. 2,951 of the withdrawals, 39 per cent, were self-relayed exactly like this wallet’s. Self relaying is a common pattern, not a signature.
Batch 1 is the one with structure
Batch 1 is the batch worth working, because the wallet was new and its gas came from a 0.1-pool note, which is a preparation step a depositor has to have made.
Fact. In the 30 days before 6 June 2025 there were 634 deposits from 224 addresses.
Lead. The best-fitting single depositor is the address Etherscan labels
BitoPro Exploiter 2, 0x454cf3892a949c94569ab2663090ecdca811a6f0. On 14 May 2025,
between 06:28 and 08:22, it deposited 40 × 100 ETH, 9 × 10, 1 × 1 and 5 × 0.1,
55 notes and 4,091.5 ETH, then swept its last 0.0317 ETH out and stopped.
BitoPro is a Taiwanese exchange. It was breached on 8 May 2025 and confirmed the attack on 3 June, telling Fortune it had been “attacked by hackers” during a wallet system upgrade and that withdrawals had continued normally throughout. The investigator ZachXBT put the loss at about $11.5m and published first; the exchange’s statement followed hours later.
For the lead. Forty fresh notes 23 days before the wallet started, and batch one’s 24 notes fit inside them. It is one of only two large depositors in the window that also parked 0.1 ETH gas notes, five of them, and this wallet drew two 0.1-pool notes. Between 14 May and 22 June 2025 the funding wallet is the only recipient of two or more notes that was gas-funded from the 0.1 pool and then self-relayed its withdrawals; the next such address appears on 23 June. Both sides used the same front-end fingerprint.
Against the lead, and this is the heavier column. The anonymity set was 1,254 unspent notes and 224 depositors in the prior month, and nothing in the proof system narrows that. The wallet took 83 notes and the cluster at least 119; BitoPro’s depositor placed 40, so at most a fraction of the operator’s notes could be BitoPro’s. The second cluster wallet was already withdrawing on 25 January, 3 April and 7 May 2025, before BitoPro was breached at all. The 3 gwei priority fee is the front-end default and four of the eight depositors in that window share it. And a competing candidate exists: an unlabelled address placed nine 0.1 ETH gas notes on 30 and 31 May, six days before the wallet started.
The behaviour also sits oddly. This operator held ETH on Ethereum for a year, farmed Aave, borrowed stablecoins and bridged out in small pieces. The BitoPro depositor moved through THORChain and Tornado’s token pools within days.
Three further tests, and they all point away from it
We kept going, because a lead that only ever gets stronger is a lead nobody is testing. Three checks were run against the pool’s wider history. All three weaken the case rather than strengthen it.
The cheap test does not exist. BitoPro’s depositor also placed nine 10 ETH, one 1 ETH and five 0.1 ETH notes. Small pools hold tens of unspent notes rather than thousands, so a matching bundle leaving one shortly afterwards would be close to a proof. No matching bundle left in the following 48 hours. The largest 10-pool withdrawals on 14 and 15 May were pairs. Whoever held those notes was patient, or split them, and the one cheap test that could have tied BitoPro’s notes to a specific cash-out address is gone.
That check also removed a decoy worth recording, because it nearly caught us. On
14 May an address ending …e876 deposited nine 10 ETH, four 1 ETH and seven 0.1
ETH notes, and 0x3553…58ef withdrew exactly those counts minutes later and
bridged the proceeds out through LI.FI. Identical bundles minutes apart in thin
pools is near-certain linkage. It looked like BitoPro’s small change, since
BitoPro had deposited nine 10 ETH notes ninety minutes earlier. The deposit
timeline shows it was somebody else entirely.
The crowd that withdrew after BitoPro’s deposit does not behave like this operator. Between 14 May and 1 June 2025, 422 notes left the pool to 334 addresses.
| What they did | Addresses |
|---|---|
| Took one note and sent it straight to the LI.FI bridge | 117 |
| Sent to another wallet or swapped immediately through CoW | 203 |
| Self-relayed, the way this wallet does | 4 |
Four addresses, seven notes. Fast, one note per fresh address, swap and bridge, is what professional laundering of an exchange theft looks like on this pool, and it is what BitoPro’s own depositor did on the way in. Stylistically BitoPro’s notes belong with that crowd, not with a wallet that then farmed Aave for a year.
The clock does not fit either. Splitting the cluster’s 723 outgoing transactions into working sessions, using a 30-minute gap as the break, gives 163 sessions.
Sixty-five per cent of sessions start between 11:00 and 21:00 UTC and 26 per cent between 00:00 and 10:00, with Saturdays quietest. That reads as a daytime and evening pattern somewhere around UTC to UTC+3, or a working day in the Americas. The BitoPro addresses, over 104 transactions in one week, cluster at 06:00 to 08:00 and 17:00 to 23:00. A small sample, and time-zone inference from timestamps is soft evidence, but the shapes differ.
Verdict: unlikely. The timing fit is real and we are not dismissing it. But the small-note test came back empty, the population BitoPro’s notes sat among behaves nothing like this operator, and the clock leans the other way. Someone with subpoena power or commercial demixing data could still settle it. On what is visible on chain, it is a weak candidate rather than a strong one.
Batches 2 to 4
Inference. For the later batches the pool’s composition changes the question. By December 2025 roughly 2,945 notes were unspent, and more than a third had arrived in two unlabelled bursts: 407 notes on 23 to 26 October and about 1,228 notes in a single night on 4 to 5 November 2025, split across some twenty addresses. Most of the inventory the operator was hiding among came from depositors nobody has labelled.
Labelled contributions in the same period came from addresses Etherscan tags as Infini Exploiter 3, Balancer Exploiter 7, a “Multisig Drainer” and two phishing addresses. The Multisig Drainer deposited on three of the wallet’s December withdrawal days, five to eight hours apart each time, which is suggestive of overlapping schedules and nothing more.
No single candidate stands out for batches 2 to 4.
The constraint that eliminates rather than suggests
There is one test that rules candidates out rather than nominating them. A single source must have deposited more notes than the cluster had withdrawn, at every date. Run against the pool’s 2024 history, which adds 4,481 deposits and 4,279 withdrawals, it does real work.
The dominant feature of that year is September 2024: an address Etherscan labels for the WazirX exchange theft deposited 26 notes on 2 September, followed by a chain of fresh addresses depositing 50 notes almost daily until the 27th. About 749 notes, roughly 74,900 ETH, against a withdrawal spike of 895 that month where the normal rate is about 250. Most of it left within weeks.
Applying the rule: the second cluster wallet’s three notes on 25 January 2025 rule out every 2025 theft as a sole source. Batch 1 needs at least 31 notes from one source before 19 June 2025, and the operation’s whole life needs at least 119. Three explanations survive, and only three: an unspent residue of the September 2024 chain, the February 2025 group of 103 notes combined with something else, or an operator drawing on several deposits at once. The last is the simplest, and it is what a serial thief or a laundering service looks like.
7. The operator cluster
Five addresses tie to the same operator without any mixer heuristics at all, because they fund one another directly.
| Address | Role | Grade |
|---|---|---|
0x5770c25e…f704e |
Second cash-out wallet, 36 notes from Jan 2025 | Inference |
0x16f0…bf07 |
Gas and DAI hop, funded by the wallet | Fact |
0x1A35…16231 |
Consolidation, 1,743.027 ETH to the wallet | Fact |
0x43c7…2f82 |
Consolidation, 605.829 ETH to the wallet | Fact |
0xa212417f…3a7f |
Re-mixing wallet, 23 notes back into Tornado | Fact |
Fact. 0x16f0…bF07 received a 0.1 ETH test from the wallet on 7 February 2026,
then 500,000 DAI, bridged the DAI out through Relay, and on 18 March sent 0.049
ETH to 0x1A35…16231. That consolidation wallet then took 1,350.8 ETH from a Relay
solver and 392.0 ETH from Relay Router V3 and passed 1,743.027 ETH to the wallet on
24 March. A second consolidation wallet did the same with 605.829 ETH on 22 March.
Gas from one, funds to the other, both ends readable.
Inference, strong. The second cash-out wallet
0x5770c25edcc98cb9f2a2483690a99d5f80df704e was funded from the Tornado 10 ETH
pool in January 2025 and has taken 36 withdrawals of 100 ETH from the same
pool, first on 25 January 2025 and last on 26 June 2026, using the same tooling
and the same Aave gateway. It withdrew on the same day as the funding wallet
twice, 5 February 2026 and 5 June 2026. There is no direct transfer between them,
so this is behavioural rather than deterministic.
Combined, the two wallets have drawn 11,900 ETH out of the 100 ETH pool.
That January 2025 start is the strongest single argument against any 2025 theft being the source of this operation’s capital. The stash predates them.
8. What the money did between the batches
Fact. The ETH was not idle. Across a year the funding wallet ran a leveraged book on Aave V3.
| Position | Figure |
|---|---|
| Supplied as collateral | 8,435.79 ETH, 36 events |
| Borrowed against it | $11,364,723 |
| Of which USDT | 6,670,158 |
| Of which DAI | 2,501,437 |
| Of which USDC | 2,193,128 |
All of it was repaid. What remains of the debt today is 0.86 USDT.
Stablecoin flow across the wallet’s life came to about $21.9m: $13,388,624 USDT, $5,573,287 DAI and $2,952,120 USDC, with inbound matching outbound to the cent on all three. The balance today is zero.
It swapped 3,112 ETH through KyberSwap and 2,754 ETH through ParaSwap, used Odos, and moved value off Ethereum through five bridges: Symbiosis 55 calls, Relay 23, Stargate 10, LI.FI 3 and Across 1.
Inference, and a caveat we are carrying deliberately. A year of leverage and $21.9m of stablecoin churn is equally consistent with one operator running their own funds and with a service handling other people’s as well. Nothing on chain separates those two readings. Any description of this wallet as simply “the attacker’s wallet” is doing more work than the evidence supports.
The exit
Fact. On 15 and 16 June 2026 the wallet put 2,575.5 ETH back into Tornado across 42 deposits: 25 × 100, 7 × 10, 5 × 1 and 5 × 0.1. Thirty-one of those deposits went in on 16 June inside 27 minutes, between 10:58:47 and 11:26:35. At 12:41:35 it sent 0.02 ETH to a Symbiosis bridge and stopped.
That was just under 75 days before the Cronos position opened: 74 days, 23 hours and 57 minutes, to be exact.
Where the bridges took it, and this part needed no mixer analysis at all
The bridges are the opposite of Tornado. Symbiosis, Relay, Stargate and Across all publish per-transaction status keyed by the source hash, so every one of the cluster’s cross-chain transfers can simply be looked up.
Fact. Resolving all of them gives one destination. Everything goes to BNB Smart Chain. About $4.9m direct from the funding wallet across June and December 2025, and about $4.3m more from the stablecoin hops between December 2025 and February 2026, converted into BNB and WBNB in pieces of $50,000 to $100,000.
| From | When | Amount and destination |
|---|---|---|
| the funding wallet | 6 to 9 Jun 2025 | about 423,000 USDT, to itself on BSC |
| the funding wallet | 10 to 21 Jun 2025 | about 1.9m, to three BSC addresses |
| the funding wallet | 2 to 23 Dec 2025 | about 2.95m, to BNB and WBNB |
0xbb37…ef87 |
26 Dec to 15 Jan 2026 | 1.8m USDT in eighteen 100k pieces |
0x89e3…ddb6 |
28 to 29 Jan 2026 | about 2m DAI, to WBNB |
0x16f0…bf07 |
Feb 2026 | 500,000 DAI |
Nothing went to Cronos on any bridge. Whatever paid for the Cronos stake did not travel by this route.
Decoded, and this is the part that opens a new door. The recipients on BNB Smart Chain are the same addresses. An Ethereum address is derived from its private key, and the derivation is identical on every EVM chain, so an address that is active on BSC is the same key. We checked all seven directly against a BNB Smart Chain node.
| Address | Transactions sent on BSC |
|---|---|
0x7a79969a…0F6f234, the funding wallet |
61 |
0x16f09b91…25bf07 |
605 |
0xa212417f…12f23a7f, the April re-mix wallet |
1,328 |
0x564a073f…82a4591, seen only on BSC |
3,338 |
0x89e3615f…affdddb6 |
4,263 |
0xbb378204…65a4ef87 |
18,720 |
0xf052219f…7429c58aa, seen only on BSC |
33,991 |
That is 62,306 transactions. On Ethereum the April re-mix wallet sent about twenty-five in its whole life. The same key has sent 1,328 on BSC, and two of its neighbours have sent over 50,000 between them.
All seven hold dust today, a fraction of a BNB each and no significant token balances. About $9m arrived, became BNB, and left.
Inference, and it sharpens the caveat above rather than softening it. Tens of thousands of transactions is not the profile of a person moving their own stolen money. It is the profile of a service running at volume. Combined with the year of Aave leverage and the $21.9m of stablecoin churn, the reading that fits best is that the Ethereum wallets we have traced are one arm of something that also operates at scale on BNB Smart Chain. Whether the Cronos attacker owns that operation or is a customer of it is not something the chain will tell us.
Two loose ends, stated so nobody assumes they were tidy. The funding wallet’s very last act, on 16 June 2026, was a $36 Symbiosis route ending in USDT on Tron, which is a thread nobody has pulled. And the second cluster wallet’s 2.74m USDC hop moved by plain transfers and through a contract rather than Relay, so its destination is unresolved.
9. The April round trip, and the two hops that carry the case
The round trip
Counted, with a negative control. On 21 April 2026 the wallet sent 101 ETH and
then 2,200 ETH to 0xa212417f73f4d1a4178ee7c3b1412e3c12f23a7f.
| Leg | Time | Hash |
|---|---|---|
| 101 ETH | 13:53:23 | 0x2b61c4b9962c25bf70c900555fe4657fbaa9f07adc5b7d6340261e20ce29dd22 |
| 2,200 ETH | 13:59:23 | 0xfd6c9005fd6be5c84d9d02eeb811e50cd53d4b74b5c25ed69df3a12a015b6dcd |
| 0.926 ETH back | 21:03:35 | 0xea29676af6d59137fecf2c028ea4f9fe7cd0f36e49c427e0178567e8eaf88573 |
That wallet deposited exactly 23 notes of 100 ETH into the pool the same day,
returned the change, and was never used again. In the same window exactly 23
notes were withdrawn to 0x871ab7d790Ae319279239d84C3f78fa896449b01, in
alternating batches, all self-relayed with zero fee.
Across those four days the pool saw five depositors and eight withdrawers. Exactly one deposited 23 and exactly one withdrew 23.
What this is not. We did not break Tornado Cash. Its cryptography is intact and we did not attempt it. This is transaction-pattern analysis. To test whether the method proves anything, we ran it against the wallet’s other batches: three matched on count alone, and all three failed the next test, which was following the funding backwards. This one did not fail it.
The destination, written in plaintext
Decoded. This is the strongest hop in the case, because it needs no inference at all. THORChain writes the destination into the transaction as readable text. Thirteen swaps carry the same 51 bytes, byte for byte identical:
=:tr:TZEJLhqXz2roiCgxxLbJV1i1LFyf5VZR8v:0/1/0:ss:60
tr is TRON.TRX in THORChain’s own asset table. The affiliate tag ss appears in
THORChain’s worked examples without being defined; community registries call it
ShapeShift and we do not treat that as established.
Those thirteen legs carried 1,800 ETH between 21 and 24 April.
The trail closes
Counted. 2,300 ETH came out of Tornado. It left by three doors and one is still open.
| Route | ETH |
|---|---|
| THORChain, 13 legs | 1,800 |
| NEAR Intents, 14 addresses | 310 |
| Relay | 72 |
| Still held in the wallet | 116.951349 |
That totals 2,298.951349 against 2,300, a difference of 1.048651 ETH, which is gas. Every ETH is accounted for.
The NEAR Intents leg deserves its own note. Fourteen single-use Ethereum addresses fed the published treasury, and every one of the fourteen has a matching TRX arrival on the other side, 82 to 100 seconds later. Fourteen for fourteen. That is a timing correlation across two chains with no shared address.
The key reuse
Decoded. The Ethereum side and the Tron side are two separate bodies of evidence. What joins them is neither clustering nor heuristics. It is a mistake: the operator used one private key on two blockchains.
| Ethereum | Tron |
|---|---|
0xC0E272092e74688b31313c8e3d9846628Fd71508 |
TTZ61bYGEm6JHf4pzB5JLPu5KB35g2uovA |
0x1A59697a7c499f0144dfa1b100e24822f5e21638 |
TCNXgW8PvRn8UFjegkUUyTf5nSfHGfyZqR |
Tron derives its address as base58check(0x41 ‖ addr20) from the same key
material as an Ethereum address. We derived both directions and the checksums
match. This is arithmetic, not judgement.
10. The Cronos funding wallet received the Venus attack proceeds
This is the largest single finding in the investigation, and it is the one place where an outside party confirms us rather than the reverse.
Credit where it is owed, before the finding. BlockSec published its analysis in March. It names this funding wallet in full, gives the 7,447 ETH it took through Tornado Cash, and traces the nine months of accumulation that followed. Venus Protocol’s post-mortem covers the same ground. Most of what this section describes about the Venus attack was established there rather than here, and anyone checking our work should read theirs.
What we could find no prior account of is the step after it: that the wallet on the receiving end of the Venus proceeds is the wallet that five months later paid for the Cronos stake. BlockSec’s report predates the Cronos attack by five months and mentions neither Cronos nor Tectonic. We arrived at the link from the Cronos end, tracing funding backwards without knowing where it went.
Venus Protocol is a lending market on BNB Smart Chain. On 15 March 2026 it was attacked, and it published its own incident post-mortem. That document names two addresses:
| Address | Venus calls it | We had it as |
|---|---|---|
0x1a35bd28efd46cfc46c2136f878777d69ae16231 |
the primary attacker | our consolidation wallet |
0x737bc98f1d34e19539c074b8ad1169d5d45da619 |
the attack contract | new to us |
The first of those is the wallet we had already traced sending 1,743.027 ETH to the funding wallet on 24 March 2026, nine days after the attack. In our earlier work that inflow was recorded as unexplained. It is the proceeds.
What our figures and theirs do to each other
Venus writes that the wallet behind the attack received “7,447 ETH (~$16.29M) in 77 transactions from Tornado Cash” and supplied it to Aave as collateral to borrow stablecoins.
We reconstructed that from the other end, before seeing their document. Counting every Tornado transfer into the funding wallet before their attack timestamp gives 76 transfers and 7,400.191 ETH.
| Transactions | ETH | |
|---|---|---|
| Venus Protocol’s post-mortem | 77 | 7,447 |
| Our own count | 76 | 7,400.191 |
| Difference | 1 | 46.809, or 0.63% |
Two parties working from opposite ends, neither having seen the other’s work, landing 0.63 per cent apart on the same wallet.
The tell, and it is visible in three numbers
We checked all three addresses directly against a BNB Smart Chain node on 1 September 2026.
| Address | On BNB Smart Chain | On Ethereum |
|---|---|---|
0x737bc98f… the attack contract |
contract, 19,865 bytes | does not exist |
0x43c743e3… the attack operator |
EOA, nonce 90 | EOA, nonce 1 |
0x1a35bd28… the position wallet |
EOA, nonce 208 | EOA, nonce 1 |
Read the bottom two rows across. On Ethereum each of those wallets sent exactly one transaction in its entire life: 605.829 ETH and 1,743.027 ETH, both to the funding wallet, both in March 2026. Their real work is on BSC. They exist on Ethereum for one delivery each.
Who did what on BNB Smart Chain
Fact. Nine addresses carry the attack itself on that chain. Seven are keys
that also exist on Ethereum, and two appear only on BSC, which we confirmed by
reading each one’s Ethereum nonce: 0x564a…4591 and 0xf052…58aa are at zero
there and have never sent an Ethereum transaction. Three more BSC-only addresses
sit outside this table: the June 2025 rehearsal wallet, a second XVS wallet from
December, and the attack contract. Roles and windows:
| Address | Nonce | Role on BNB Smart Chain |
|---|---|---|
0x7a79…f234 |
61 | the hub’s own key. Buys XVS and THE, seeds the others |
0x16f0…bf07 |
605 | 600 micro-swaps; donates 1.25m THE |
0xa212…3a7f |
1,328 | buys THE, then draws 900,000 CAKE on the position wallet’s account |
0x564a…4591 |
3,338 | 3,283 micro-swaps; donates 3.92m THE in the attack |
0x89e3…ddb6 |
4,263 | 4,198 micro-swaps; donates 9.47m THE |
0xbb37…ef87 |
18,720 | micro-swaps at volume; donates 7.53m THE |
0xf052…58aa |
33,991 | micro-swaps at volume; donates 13.22m THE |
0x1a35…6231 |
208 | the position wallet. Holds the collateral, liquidated 8,039 times |
0x43c7…2f82 |
90 | the attack operator. Active 7 to 21 March only |
The nonce column is each account’s transaction count read live from a BNB Smart Chain node on 1 September 2026, which is the authoritative figure. Two further addresses belong to the operation but are not the cluster’s Ethereum keys: a rehearsal wallet used in June 2025 and a second XVS wallet from December, both BSC-only. The attack contract itself sent 55 transactions.
The swap counts in this section are floors, not totals. BscScan’s transaction lists stop at 10,000 rows, and two of these accounts are well past that, so every “micro-swaps” figure below is a lower bound.
Nine months of preparation, and a rehearsal in the first week
Fact. Within a week of the very first Tornado withdrawal in June 2025, borrowed stablecoins were arriving on BNB Smart Chain at the cluster’s own keys. Four addresses bought about 8m THE, the token of the Thena exchange, and supplied 7.97m of it to Venus between 13 and 15 June 2025.
Alongside it the funding wallet bought 63,916 XVS, which is Venus’s own governance token, and handed it to a BSC-only wallet. That wallet supplied the XVS to Venus as collateral, borrowed 80,000 USDC and 120,000 USDT against it, and forwarded them to the position wallet on 13 June 2025. That was the position wallet’s first funding.
Inference. A small borrow-against-collateral exercise on the exact protocol that would be attacked, nine months early, is a rehearsal. It is the same shape as the Cronos function test in section 4: learn the machinery at trivial size, then return at scale.
Fact. From December 2025 to February 2026 the second and third Tornado batches went into Aave, and the borrowed USDT and DAI crossed to BSC in $100,000 pieces. There the cluster bought THE in a stream of roughly 30,000 micro-swaps through Thena’s WBNB/THE pool, each buying a few hundred to a few thousand tokens. The visible purchases total at least 39.7m THE, and the real figure is higher because two of the transaction lists are truncated at 10,000 rows.
Inference, and this is the craft of it. The clip size is the point, not the count. Buying tens of millions of a thin token in hundred-dollar pieces over nine months moves its price far less than block trades would. It kept the collateral cheap right up to the day the operator needed it expensive.
On 21 January 2026 three of the buying addresses transferred their vTHE holdings into the position wallet, concentrating the collateral in one account.
15 March 2026, minute by minute
The mechanism. Venus caps how much THE its market will accept, and enforces that cap when tokens are deposited through the normal path. But the market calculates its exchange rate from the contract’s raw token balance. So tokens sent directly to the contract, bypassing the deposit function, raise the value of every share already issued without touching the cap. The operator held the shares.
| Time (UTC) | What happened |
|---|---|
| 04:59 to 05:01 | one rehearsal pass: borrow 1 BNB, wrap, buy THE, deposit |
| 11:55:11 | the position wallet approves THE and updates its Venus delegate |
| 11:55:18 | the attack contract is deployed, and its constructor fires |
| 11:55:28 to 12:30 | 48 loop calls on the contract by the operator wallet |
| 11:55:41 to 12:45 | in parallel, 49 borrow-and-donate loops by the position wallet |
| 12:04:40 to 12:42 | 603 liquidations strip the contract’s account |
| 12:42:34 to 13:26 | 8,039 liquidations strip the position wallet |
The constructor is the attack. In the deployment transaction itself, the contract pulled 36,096,716 THE from six cluster addresses and sent it straight into the market, then borrowed against the inflated rate. The six addresses had approved the contract before it existed, which is possible because a contract’s address can be computed from its deployer’s nonce in advance.
Then it ran in a loop. The contract borrowed CAKE, sold it for wrapped BNB, bought THE with the proceeds, and pushed the THE back into the market to raise the rate again. Forty-eight times. In parallel the position wallet borrowed BNB and did the same, forty-nine times, with the swap’s recipient set to the market contract so the purchase landed as a donation directly.
The liquidators arrived within nine minutes. From 12:04 the contract’s account was seized in 603 separate transactions; from 12:42 the position wallet’s account was seized 8,039 times. The price of THE had gone from about $0.26 to about $0.51 on the way up and fell back through $0.22 as the collateral was sold off.
How big the position got. Venus’s own post-mortem puts the collateral at 53.2 million THE at its peak. BlockSec gives the same figure, and Halborn puts it at 53.23 million, which it notes is 367 per cent of the market’s 14.5 million supply cap. Those three agree, and they are the figures to use.
Venus was left with about $2.15m of bad debt. It paused THE borrowing and withdrawals, and paused several other markets as a precaution.
Getting the money out, and back to the mixer
Fact. What the operator kept was what it had borrowed and never repaid: CAKE, BTCB, wrapped BNB and BNB, worth roughly $5.05m. Three days later the attack operator called the contract three times to release its balances to itself, opening with a 1 WBNB test before taking 1,971.5 WBNB and 16,093 CAKE.
Fact. The proceeds went back to Ethereum through Relay. Counted on the
Ethereum side, where every leg has a hash we can read, the two wallets received
2,340.327 ETH in 46 Relay transfers: 1,747.107 ETH in 39 payments from the
Relay solver 0xf70da978, and 593.220 ETH in seven internal transfers from Relay
Router V3 0xb92fe925. A further 8.529 ETH arrived in 13 small transfers, of
0.010 to 3.773 ETH, from 13 other addresses. One of those 13 is the gas hop
0x16f0…bF07 from section 7, paying the 0.049 ETH that brought the consolidation
wallet to life.
A count to discard before you reproduce ours. Both wallets also received 13 transfers carrying 0.00000022 ETH between them, from five addresses whose first and last characters copy the funding wallet’s. That is address poisoning: spam sent so a careless operator copies the wrong address out of their transaction history. It is aimed at the cluster rather than sent by it, and we exclude it. Anyone summing the raw transfer list will count 26 non-Relay inflows where we count 13.
That is 2,348.857 ETH in total, and it is the whole of what either wallet ever received. Both then emptied themselves in a single transaction each:
| Wallet | Total received | Sent to the funding wallet | Left behind |
|---|---|---|---|
0x43c7…2f82 |
605.829069 ETH | 605.829 ETH, 22 March | 0.000069 ETH |
0x1A35…16231 |
1,743.027643 ETH | 1,743.027 ETH, 24 March | 0.000643 ETH |
| Both | 2,348.856712 ETH | 2,348.856 ETH | 0.000712 ETH |
Neither wallet held a balance before the Venus attack and neither held one after. They exist to carry that money from the bridge to the funding wallet, and the sums reconcile to the milli-ETH in both directions.
From there the trail rejoins the one this document has already set out: 2,300 ETH back into Tornado through the April wallet on 21 April, the Aave position unwound in June, and 2,575.5 ETH back into Tornado on 15 and 16 June.
Seventy-four days after that, the Cronos position opened.
What this changes
The investigation began as the funding trail behind one exploit. It is not that.
The two attacks share funding infrastructure, and the method repeats. Buy a thin collateral asset patiently over months. Rehearse the protocol’s machinery at trivial cost. Break the accounting on the day. Keep what was borrowed. Bridge out, wash, repeat. Venus in March on BNB Smart Chain; Tectonic in August on Cronos. The Cronos depth probe in section 4, which bought $1,180 of price-impact readings on a thin token, is the same first move as nine months of micro-buying THE.
One caution we are keeping. Everything above establishes that the Venus attacker’s proceeds funded the wallet that funded the Cronos stake. It does not establish that one person did both. The volume evidence in section 8, tens of thousands of BSC transactions, is equally consistent with a service that several customers use. Nothing on chain separates those two readings, and we are not going to pretend otherwise.
11. Where the money is now
Fact. Four Ethereum wallets received what escaped before the halt.
| ETH | Address | State on 1 September |
|---|---|---|
| 2,452.115261 | 0xc404160b79bd8905061a1caecbeca2eeab3f72dd |
moving |
| 670.625462 | 0xfDb11781ee3818135eebd2acd2247C263e266652 |
unmoved |
| 19.869463 | 0x86616cE5D1829Beb030742e65bD3C1fbEE8F082E |
unmoved |
| 73.734618 | 0x9ea6b75940de7c57bd1827001536e33ed667b55d |
converted 31 August |
Fact. The fourth of those is the one the gas dispenser in section 4 pays. At
17:42:47 on 31 August 0x9E2CFB82… sent it gas, and thirty-six seconds
later, at 17:43:23 and again at 17:46:11, that wallet converted 182,178.22
USDC into 73.734618 ETH. Its USDC balance is now zero. A wallet that had sat
still since the halt moved within half a minute of being funded, which is what a
dispenser is for.
The largest of the four started moving while this document was being written, and it has not stopped. What follows was read at 02:00 on 1 September 2026 and is the most perishable material here.
Fact. The money has moved three hops in under two hours, and the same signature appears at every one: a small test transfer, then the real amounts.
Hop one. At 23:55:59 on 31 August the escape wallet sent 0.1 ETH, waited
two minutes, then at 23:57:59 sent 140 ETH, both to
0x6df89c42f0abdfaa2b5b77edcdafbc945ed6ee6c.
0x8f33074e3109ea245e08f4b0234a5e94b06b343a8845221ac3cdde4d592f96a6
0x5a0cb654b9a462fe2d36a839d8c53873e84fc815c16536cd7172329cbe9d4e3b
Hop two. Between 01:06:23 and 01:12:11 on 1 September that address forwarded
58.199 ETH to 0x7560e936a6978ad4ecda6b395f4c7d1c65f8a595, in five
transfers: 0.1, then 10, 20, 20 and 8.099. It kept the rest. Its nonce is 5 and
it still holds 81.900879 ETH.
Hop three. Between 01:25:35 and 01:42:23 the receiving address sent
58.166807 ETH onward in five transfers, again opening with 0.1, and emptied
itself down to 0.032 ETH. The destination is
0x4cd00e387622c35bddb9b4c962c136462338bc31.
That address is the Relay bridge depository. It is the same contract the funding wallet’s own depository, used 22 times during 2025 and 2026; section 8 counts 23 because it includes one call to Relay’s receiver contract. The money is leaving Ethereum by the route this operation has always used.
| Stage | Amount | State |
|---|---|---|
| Sent from the escape wallet | 140.100000 ETH | done |
| Held at the first staging address | 81.900879 ETH | waiting |
| Bridged out through Relay | 58.166807 ETH | gone |
Inference. A test transfer before each real one, repeated at three separate hops within two hours, reads as someone confirming control of each address before committing to it. The 81.9 ETH still sitting at the first staging address is the next tranche rather than a remainder, on the same reading. The escape wallet itself still holds 2,452.115261 ETH at nonce 42, so on the evidence of the last two hours this is the opening of a cash-out and not the whole of it.
And they are being poisoned as they do it. From 00:01:59 on 1 September, four
minutes after the first real transfer, fake tokens calling themselves ETH began
arriving from 0x6df8c0e7…ee6c, 0x6df8fc38…ee6c and 0x6df8c006…ee6c. Those
copy the destination’s first four and last four characters, and the fake transfers
copy both the 0.1 and the 140 amounts, so a history read at a glance shows the
wrong address beside the right numbers. The same happened again one hop later,
against the 7560…a595 pattern.
Inference. The test send and the real send went to the same address at every hop, and every lookalike arrived after both, so each destination was chosen rather than fallen into.
A note for anyone checking our work. Address poisoning is thick around this
cluster and it will catch a careless reader. Six lookalikes of the April wallet
exist: 0xa2123cae…3a7f, 0xa2125b59…3a7f, 0xa212481c…3a7f, 0xa2126daf…3a7f,
0xa21f638a…3a7f and 0xa21fdc71…3a7f. The real one is
0xa212417f73f4d1a4178ee7c3b1412e3c12f23a7f. Compare all 40 characters, every
time.
12. What would settle the questions we could not
The on-chain record has been read as far as it goes. What remains is off-chain, and each item exists precisely because the operator avoided intermediaries that would have hidden it.
RPC and front-end telemetry. Self-relaying means the operator’s own browser or script signed 83 transactions and broadcast them through an RPC provider, and built proofs against a pool history it had to fetch from somewhere. Whichever endpoint served those requests may hold network telemetry for 6 June 2025 04:01 UTC and 82 other slots, plus the two dozen sync events in section 5. A self-hosted node, several rotating providers, or a VPN would each blunt that, and nothing on chain says which applies.
Bridge counterparties. Relay, Symbiosis, Stargate, Across and LI.FI each hold destination-chain records. The March 2026 Relay inflows have an originating chain and address, and solver fills can be matched to the source deposit.
Commercial demixing. Chainalysis, TRM and Elliptic run Tornado heuristics over full-chain clustering and hold attributions from exchange and law-enforcement channels that are not public. If BitoPro’s notes have been assigned to withdrawal addresses in those tools, this wallet either appears in that set or it does not.
Off-ramps. The stablecoins bridged out in $100,000 to $1m pieces end at exchanges or desks on other chains. Those are the accounts a subpoena reaches.
One question on this list has since been answered, and it is worth saying how, because the method is reusable and cost nothing. The full set of methods, with the failures, is in the companion methods piece. The bridge records did it. Following the transfers forward, rather than trying to break the mixer backwards, produced section 10: the Venus attack, the nine months of preparation before it, and the return of the proceeds to the same wallet. None of that needed a single heuristic. The lesson generalises: when a mixer blocks the view backwards, the same operator’s forward trail is usually wide open.
13. Ruled out, with the test that did it
Recording failures is what makes the rest of a document like this worth reading.
Going further back than the funding wallet. Tested in section 5. The note-counting method that worked in April fails against a single note in a pool holding over a thousand.
The relayer as attribution. The address that relayed the origin withdrawal has sent 7,101 transactions and holds 15.62 ETH. It is a public service selling gas to anyone. It identifies nobody.
A $20m address-poisoning loss. An earlier reading of the wallet’s transfers
suggested the operator had lost around $20m to lookalike addresses. That was
wrong, and it is worth saying why, because the same trap catches everyone. The
apparent transfers of 6m USDT, 3m DAI and 7.95m USDC were emitted by counterfeit
token contracts that mint fake Transfer events naming the victim as sender.
Filtered to the real token contracts, the three largest destinations return
aEthUSDT, aEthUSDC and aEthDAI from their own symbol() call: they are Aave
aToken contracts holding every depositor’s money, which is why they look like
recipients that never spend. Every genuine large transfer went to an address the
operator had first tested with a small send, and those addresses forwarded the
funds on. There was no poisoning loss.
Paxos. Ruled out by a two-hop closure test. The intersection was empty.
The Rhino.fi figure. A claimed distribution of $5,073,411 to 36 wallets could
not be checked either way. The BNB Smart Chain wallet in question holds 22,213.90
real USDT and has sent 39 transactions in its life; the transfer list that appeared
to show the distribution is address-poisoning spam using a token called U5DT. We
could not reconstruct its real history, because no free BNB Smart Chain endpoint
serves it. Unresolved, and neither confirmed nor refuted.
14. Method, and the traps that cost us time
Anyone re-deriving this will hit the same walls we did.
There is no free archive state anywhere useful. Cronos public nodes serve about eleven days and the window slides forward. Ethereum’s free endpoints return “state is pruned”. BNB Smart Chain returns “missing trie node”. Plan around event logs, which are retained, not around historical balances, which are not.
eth_getLogs range caps produce false absences. Cronos caps ranges at 2,000
blocks, and a wider range errors in a way a naive parser reads as “no logs”. We
caught this only because a running-balance reconciliation failed to add up. A
query that returns nothing is not the same as a period in which nothing happened.
A PUSH4 regex over bytecode picks up strings. Byte 0x63 is both the PUSH4
opcode and ASCII c, so scanning for selectors finds string data too. In the
attack contract that produced four false positives, which is why we say 44
plausible selectors rather than 48.
The obvious filter is itself lossy and we will not pretend otherwise. Discarding candidates whose four bytes are all printable ASCII also discards any genuine selector that happens to be four printable bytes. Opcode-aware disassembly is the correct tool and we did not run one, so treat every selector count here as approximate.
The absence list in section 3 is bounded differently, because it was not produced by enumeration at all. We hashed specific signatures and searched for those exact four bytes, so no string coincidence can hide a selector that is present. Its limit is the one stated there: it covers only signatures we thought to hash.
Filtering by value silently drops legs. An early pass over the wallet’s counterparties used a 50 ETH floor and lost Odos, LI.FI and Across entirely.
A token contract looks like a hoarding wallet. Always call symbol() on a
destination before describing it as a recipient. Section 13 is that lesson.
A finding is evidence, not a verdict. In one earlier sweep of our own published work, five of sixteen reported errors were themselves wrong. Re-derive a second way before changing a published word.
Two checks that returned nothing, recorded anyway
The note-account leak does not exist here. Tornado’s optional note-account feature publishes encrypted notes as events from the depositor’s own address, which would link deposits to whoever holds that key. The contract recorded no transactions at all between January 2025 and June 2026. Nobody in this case used it.
The private-mempool question is open. If the 83 withdrawals had been broadcast through a private relay rather than the public mempool, that would be a rare and strong fingerprint, and the relay operator would hold the addresses. Etherscan’s static pages carry no marker for it, so this could not be settled with the tools available. It stays a question for a mempool-data provider.
Checking it without us
The live balances in this document, on both chains, are readable from our verification page, which queries public nodes from your browser rather than reporting our numbers back to you. It also gives the raw calls, so you can run them yourself against any node.
Reproducing the counts
Wallet history: the Etherscan address page, internal-transactions tab, 110 rows of which 83 are from the 100 ETH pool and 2 from the 0.1 ETH pool.
Withdraw decoding: the router input is
withdraw(address,bytes,bytes32,bytes32,address,address,uint256,uint256); for all
83 calls the relayer field is the zero address and the fee is 0.
Pool events: Deposit topic
0xa945e51eec50ab98c161376f0db4cf2aeba3ec92755fe2fcd388bdbbb80ff196 and
Withdrawal topic
0xe9e508bad6d4c3227e881ca19068f099da81b5164dd6d62b2eaf1e8bc6c34931 on the pool
contract from block 21,525,000.
Anonymity set: eth_getBalance of the pool at blocks 21,525,890 and 22,643,039 on
any archive node, divided by 100.
15. The register
Every address in this document, in one place.
Ethereum, funding
| Address | Role |
|---|---|
0x7a79969a0B9D51D922C4810D2950560360F6f234 |
the funding wallet |
0x5770c25edcc98cb9f2a2483690a99d5f80df704e |
second cash-out wallet |
0xa212417f73f4d1a4178ee7c3b1412e3c12f23a7f |
April deposit wallet |
0x871ab7d790Ae319279239d84C3f78fa896449b01 |
April withdrawal wallet |
0xC0E272092e74688b31313c8e3d9846628Fd71508 |
key reused on Tron |
0x1A59697a7c499f0144dfa1b100e24822f5e21638 |
key reused on Tron |
Ethereum, preparation and escape
| Address | Role |
|---|---|
0x9E2CFB823AdB9BD67a41C1845C0Dd70453D7D378 |
gas dispenser |
0xc404160b79bd8905061a1caecbeca2eeab3f72dd |
escape wallet, now moving |
0x6df89c42f0abdfaa2b5b77edcdafbc945ed6ee6c |
staging address, 140.1 ETH |
0xfDb11781ee3818135eebd2acd2247C263e266652 |
escape wallet |
0x86616cE5D1829Beb030742e65bD3C1fbEE8F082E |
escape wallet |
0x9ea6b75940de7c57bd1827001536e33ed667b55d |
escape wallet, converted |
0xbaA143E23285a7bBB4803cB023724e5c616547e2 |
fuelled 21 August, never used |
0x0F8C0c8d5b9906F5e439c9a1086BF2f742fb7495 |
fuelled 21 August, never used |
0x3b5a2d0D6050Aeae57EA20b17e2b0cA263356644 |
fuelled 21 August, never used |
BNB Smart Chain, the Venus attack
| Address | Role |
|---|---|
0x737bc98f1d34e19539c074b8ad1169d5d45da619 |
the attack contract, 19,865 bytes |
0x1a35bd28efd46cfc46c2136f878777d69ae16231 |
the position wallet, liquidated 8,039 times |
0x43c743e316f40d4511762eedf6f6d484f67b2f82 |
deployed the contract, ran 48 loop calls |
0x564a073fa4cfa81c2c882168fa760a88b82a4591 |
buying wallet, BSC only |
0xf052219f767612c411c9fe4a0f334237429c58aa |
buying wallet, BSC only |
0x89e3615f356b3b40acb2f8598117eab1affdddb6 |
buying wallet, same key as on Ethereum |
0xbb3782048735091ab4c304693a69371965a4ef87 |
buying wallet, same key as on Ethereum |
0x16f09b91604053e742ee0408909bafa6a825bf07 |
gas and DAI hop, same key as on Ethereum |
The Venus attack transaction is
0x4f477e941c12bbf32a58dc12db7bb0cb4d31d41ff25b2457e6af3c15d7f5663f.
Cronos
| Address | Role |
|---|---|
0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc |
the stake wallet, $5,000,950 |
0x085f3115ca368aa262246d22f9476e1e2c87e8be |
the attack contract |
0x4266a0e6a0f0ef90abcff3bb089932ca0cce3652 |
the operator |
0x7ebe55588db070da035f9Bf5505d4fB880dA400a |
the depth probe |
0xcdfba496180865a71266608ade6b21ab1f788888 |
funded the stake |
Tron
| Address | Role |
|---|---|
TZEJLhqXz2roiCgxxLbJV1i1LFyf5VZR8v |
the war chest, named in the memos |
TYbiKCan1AZgNQioG64uB2zVDA7b26FRze |
the 15.6m TRX consolidation |
TXtEs6t2oUWQsNos7m68gbHdE9Q5n6x2oN |
where it emptied, 29 August |
Corrections to anything here are welcome and will be made in place, with the correction stated.
Sources
- Tornado Cash 100 ETH pool contract, Etherscanetherscan.io
- The funding wallet 0x7a79969a, Etherscanetherscan.io
- The April deposit wallet 0xa212417f, Etherscanetherscan.io
- The April withdrawal wallet 0x871ab7d7, Etherscanetherscan.io
- The second cluster wallet 0x5770c25e, Etherscanetherscan.io
- BitoPro Exploiter 2, Etherscan public labeletherscan.io
- Taiwanese crypto exchange BitoPro confirms estimated $11.5 million hack (Fortune)fortune.com
- THORChain developer documentation, transaction memosdev.thorchain.org
- THORChain developer documentation, memo length reduction, giving tr = TRON.TRXdev.thorchain.org
- NEAR Intents, published treasury addressesdocs.near-intents.org
- Tectonic documentation, money market parameterstectonic.gitbook.io
- Tectonic documentation, price oracletectonic.gitbook.io
- Cronos documentation, general FAQ on validators and consensusdocs.cronos.com
- Cronos Network, announcing the halt (30 August 2026)x.com
- Tectonic, incident acknowledgement (30 August 2026)x.com
- Aave developer documentationaave.com
- Venus Protocol, THE market incident post-mortem (the protocol's own account)community.venus.io
- BlockSec, Venus Thena (THE) incident analysisblocksec.com
- Halborn, Explained: the Venus Protocol hack (March 2026)halborn.com
- The Venus attack contract 0x737bc98f on BscScanbscscan.com
- The Venus position wallet 0x1a35bd28 on BscScanbscscan.com


