Crypto NewsSecurity

YFarmX investigation: Venus attack proceeds flowed into the funding trail behind Tectonic on Cronos

Venus Protocol named its attacker in March. Those proceeds went to the wallet that five months later funded the Cronos drain, a link we can find no prior published account of. Every hop across three chains, graded by evidence.

Editorial hero on off-white halftone newsprint with torn red corners: one large worn iron key photographed in high-contrast black and white, laid flat across the frame, its single shaft branching into two identical toothed heads so that one key ends in two working ends. Headed VENUS + TECTONIC in square monospaced extrabold with the subtitle ONE OPERATOR, TWO CHAINS, FIVE MONTHS APART. The Venus Protocol logo on a torn card at the upper left, the Tectonic logo on a torn card at the right, the Tornado Cash logo on a card at the lower left, and a torn ruled spec sheet at the upper right with two dates pencilled on it: 15 MAR 2026 and 30 AUG 2026.

This is a reference document rather than a news report. The Cronos events are covered in our news piece; what follows is the underlying record across three chains, laid out so that anyone can check it, argue with it, or take it further.

It began as the funding trail behind one exploit. It is not that. The same wallets ran the Venus Protocol donation attack on BNB Smart Chain in March 2026 and funded the Tectonic drain on Cronos in August, and Venus Protocol’s own incident post-mortem names one of them. Section 10 carries that, and it is the part to read first if you read nothing else.

How we did it is written up separately. The nine methods run against Tornado Cash in the course of this, what each returned, and the two that returned nothing, are in a companion piece: we ran nine methods against Tornado Cash and the mixer held. The short version is that the mixer was never broken and the money was traceable anyway.

What is new here, and what is not. BlockSec’s March analysis already names this funding wallet in full, states the 7,447 ETH it received through Tornado Cash, and traces the nine months of token accumulation that followed across multiple wallets. Venus Protocol’s own post-mortem covers the same ground. Much of what sections 5 to 10 describe retraces a path BlockSec walked first, and we claim none of it.

What we can find no prior account of is one step: that the wallet on the receiving end of the Venus proceeds is the wallet that five months later paid for the Cronos stake. BlockSec’s report predates the Cronos attack by five months and mentions neither Cronos nor Tectonic, which anyone can check by opening it. Everything on the Cronos side, sections 3, 4, 11 and 13, is our own.

We reached the link from the Cronos end, tracing funding backwards without knowing where it went, and only then found Venus and BlockSec describing the same wallets from the other direction. If someone published the connection first, we will say so here and credit them.

Every claim carries a grade. Where the evidence stops, it says so.

Grade What it means
Fact Reproducible from the hashes and calls given here
Decoded A protocol message parsed byte by byte, or arithmetic
Counted A volume, note count or population matched across a window
Inference A heuristic reading of on-chain patterns
Lead A candidate that fits, and is not shown
Limit Something we tested and could not establish

All times are UTC. Balances and nonces were read on 1 September 2026 and will drift. Cronos hashes marked ORPHANED no longer resolve, because the rollback replaced the blocks holding them; they are not broken references, they are what a rewind leaves behind.

Menu


1. The incident in one page

What happened Tectonic’s lending markets on Cronos were emptied in one transaction
How much left the pools About $124.5m, from Tectonic’s own borrow records
When 30 August 2026, position opened 12:38:56, markets drained 12:49:39
The chain’s response Halted at 14:32:47, then rewound 10,962 block heights
What the rewind returned $5,000,950.223954 of the attacker’s own stake
What it did not remove The attack contract, still deployed, 16,569 bytes, nonce 3
What reached Ethereum 3,356.444730 ETH, where no rollback goes
Where the funding starts A 0.0974 ETH Tornado Cash note, 6 June 2025
Where the funding trail ends At the mixer, and we proved it ends there
Where the money went BNB Smart Chain, about $9m, converted into BNB
What it did there The Venus Protocol attack, 15 March 2026, section 10
Confirmed by Venus Protocol’s own post-mortem, which names our wallets
Our best-named suspect Downgraded from likely to unlikely, section 6

Counted, with a caveat that has to travel with the figure. The $124.5m is our own tally of every Borrow record across all eighteen Tectonic markets for the blocks covering the attack, and it comes to $124,472,178. We read those records off the halted chain within hours, before the rollback. They are no longer reproducible: the borrow events sat in the blocks the rewind replaced, so anyone checking today will find nothing at those heights. That is why the figure is graded rather than stated flat, and it is also why estimates in circulation differ. A $75m figure published on the afternoon counts what was found sitting in the attacker’s wallets; ours counts what left Tectonic’s pools. DefiLlama’s record supports the larger number, showing Tectonic at $121.7m at midnight and about $3.08m by the evening.

The shape of the case is unusual and worth stating at the top. A rollback is normally described as undoing a theft. This one undid the spending of the stake and left the funding of it intact, because the funding happened before the boundary and the spending after. The attacker’s launch capital came back to them.


2. Timeline

When What Grade
25 Jan 2025 A second wallet begins withdrawing 100 ETH notes Fact
8 May 2025 The BitoPro exchange is breached, per the exchange Fact
14 May 2025 06:28 to 08:22 BitoPro Exploiter 2 deposits 55 notes, 4,091.5 ETH Fact
6 Jun 2025 03:16:35 The funding wallet is created by a relayed 0.0974 ETH note Decoded
6 Jun 2025 04:01:23 Forty-five minutes later it withdraws its first 100 ETH note Fact
Jun 2025 to Jun 2026 83 notes, 8,300 ETH, in four batches Counted
13 Jun 2025 A rehearsal on Venus: borrow $200,000 against XVS collateral Fact
Jun 2025 to Feb 2026 About 30,000 micro-swaps buy at least 39.7m THE on BSC Counted
15 Mar 2026 04:59 One rehearsal pass of the Venus attack loop, at trivial size Fact
15 Mar 2026 11:55:18 The Venus attack contract is deployed; 36.1m THE donated Fact
15 Mar 2026 12:42 to 13:26 The position is liquidated 8,039 times Fact
22 and 24 Mar 2026 605.829 and 1,743.027 ETH reach the funding wallet Fact
21 to 24 Apr 2026 The round trip: 23 notes in, 23 out, 1,800 ETH to Tron Counted
15 to 16 Jun 2026 2,575.5 ETH returned to Tornado, then silence Fact
5 to 6 Aug 2026 The depth probe on Cronos, about $1,180 of slippage bought Decoded
18 Aug 2026 14:47:15 The attack contract is deployed at nonce 0 Decoded
21 Aug 2026 09:46 to 10:05 The function test, ending in a deliberate liquidation Decoded
30 Aug 2026 10:35:32 2,160,000 USDC.e arrives in the stake wallet Fact
30 Aug 2026 12:38:52 Block 90,896,188, the last block both chains agree on Fact
30 Aug 2026 12:49:39 Eleven Tectonic markets emptied in one transaction Fact
30 Aug 2026 14:32:47 Cronos stops producing blocks at 90,907,150 Fact
30 Aug 2026 14:42:59 Ten minutes after the halt, an Ethereum wallet is topped up Fact
31 Aug 2026 17:43 182,178.22 USDC converted to 73.734618 ETH Fact
31 Aug 2026 23:57:59 140 ETH leaves the largest escape wallet Fact

3. The rollback, and the asymmetry inside it

Fact. Three heights define the rewind, and all three were confirmed identical on three independent Cronos endpoints.

Height Time Status
90,896,188 12:38:52 The last block both chains agree on
90,896,189 12:38:55 The first height rebuilt with different content
90,907,150 14:32:47 The old tip, discarded

Hash of the common ancestor: 0x53c11afca70a74758968bddab1377831070e79095f195e4251de2caab5a1b008

Hash of the first replaced height on the chain running today: 0x1fdcf36ebc628b6de2e51d119ddf213816b7afeb5bfe9ce50510cc47936dc223

10,962 block heights were replaced.

Decoded. The asymmetry follows from the timestamps and needs no interpretation. The stake was funded at 10:35:32, which is inside the surviving history. The position opened at 12:38:56, four seconds after the boundary, which is inside the discarded history. A rewind can only remove what came after the fork point, so it removed the attacker’s spending and left their money.

0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc holds 5,000,950.223954 USDC.e and has made no outbound transfer since.

You do not have to take our word for that figure. We publish a page that reads these balances live from public Cronos and Ethereum nodes, in your own browser: check the Tectonic wallets yourself. It covers the stake the rewind gave back, what reached Ethereum, and the three wallets fuelled on 21 August and never used.

The token carries no switch

Decoded. The bridged USDC.e contract on Cronos, 0xc21223249ca28397b4b6541dffaecc539bff0c59, is 10,994 bytes.

We did not search the bytecode for those words. Function names are not generally present as readable strings in deployed code, so a string search would prove nothing. What we searched for is four-byte function selectors, the first four bytes of the Keccak hash of each signature, which is what a contract’s dispatcher compares against to route an incoming call. Absent from the dispatcher: blacklist, isBlacklisted, pause, unpause, paused, seize, burnFrom, destroyBlackFunds, addBlackList and freeze, in their standard signatures.

Two limits on that, stated rather than glossed. A function reachable only under a non-standard signature would not be caught, because we can only search for signatures we thought to hash. And the absence of implementation and upgradeTo selectors is weaker evidence of “not a proxy” than a DELEGATECALL scan of the runtime code would be. We report it as what it is.

Cronos does carry a freezable token: Circle’s own native USDC at 0x3d7f2c478aafdb65542bcb44bceec05849999d2d, with a blacklister at 0x31f58b04f03d791c56de058211f0c767af96b464. Circle launched it on Cronos only weeks before the exploit, so almost all of Tectonic’s depth was still the bridged version. The attacker holds 2,900.00 of the native token, also predating the exploit, and isBlacklisted returns 0 for every cluster address we hold.

A narrower claim than it looks. This is about the token, not about possibility. A chain that has just rewritten 10,962 blocks has demonstrated it can act at the chain level whenever it chooses. And the claim about the token is only as wide as the test: we found no standard freeze or blacklist control in the selector set the contract exposes. A privileged path under a non-standard signature is not excluded by that. What we can say is that the ordinary lever, the one an issuer reaches for, is not there to pull.

The machinery survived

Fact. 0x085f3115ca368aa262246d22f9476e1e2c87e8be holds 16,569 bytes of code at nonce 3 on the canonical chain. It was deployed at nonce 0 on 18 August, twelve days before it was used, and we re-derived the address independently from keccak256(rlp([deployer, 0])).

Its bytecode carries 48 four-byte sequences that could be function selectors. Four are ASCII fragments from embedded strings, so 44 are plausible. Six of those four-byte sequences map to known function signatures:

Four-byte sequence Maps to
0xb61d27f6 execute(address,uint256,bytes)
0x2e1a7d4d withdraw(uint256)
0x38ed1739 swapExactTokensForTokens(uint256,uint256,address[],address,uint256)
0x095ea7b3 approve(address,uint256)
0xa9059cbb transfer(address,uint256)
0x70a08231 balanceOf(address)

The row worth reading carefully is the first. execute(address,uint256,bytes) is the signature of an arbitrary-call primitive: where it is a live entry point, it lets whoever controls the contract make it call any address with any payload.

Three claims, and we are only making the first. There is a difference between bytes present in the runtime code, a function the dispatcher actually routes to, and a function that was called. Our enumeration walks the bytecode for four-byte sequences; it does not disassemble it opcode by opcode. So what we establish is that the sequence 0xb61d27f6 is present in the runtime of a contract with no published source. We have not confirmed it sits in the dispatcher, and we make no claim at all about whether it was ever invoked. Cronos is not covered by the transaction-history APIs we used for the Ethereum and BNB Smart Chain work, so we could not test that third question either way and we are not going to imply an answer to it. Capital restored, machinery intact, and both of those are readable today.


4. The rehearsal, 5 to 21 August

The preparation is the part that changes how the attack should be read, because it is not the work of someone improvising.

The depth probe

Decoded. On 5 and 6 August, 0x7ebe55588db070da035f9Bf5505d4fB880dA400a took in 2,267,290,551,430 TONIC and sold every unit into all three TONIC markets, finishing at exactly zero.

Pool Pair TONIC
0x2f12d47fe49b907d7a5df8159c1ce665187f15c4 USDC/TONIC 1,223,645,275,715
0x4b377121d968bf7a62d51b96523d59506e7c2bf0 WCRO/TONIC 643,645,275,715
0xa922530960a1f94828a7e132ec1ba95717ed1eab VVS/TONIC 400,000,000,000

The dollars coming back decay monotonically across eleven fills: 3,541.50, 3,451.68, 3,384.33, 3,304.42, 3,253.58, 3,197.25, 3,136.81, 3,069.35, 2,994.42, 2,940.69, 2,407.89.

The decay is the output. A fixed input paying less each time measures how much price impact the market absorbs before it breaks. About $32,390 of notional bought roughly $1,180 of slippage as a reading.

token0 of the USDC/TONIC pool is the same contract that tUSDC.underlying() returns. The probed pair and the lending market’s supply asset are the same token, confirmed from both directions.

The function test

Decoded. On 21 August they did not check that deposits work. They borrowed to the edge of liquidation and let it happen.

UTC Block Action
09:46:12 89,379,277 mint 1,000 USDC into tUSDC
09:50:03 89,379,686 borrow 700,000,000 VVS
09:52:39 89,379,978 borrow 100,000,000 VVS
09:54:12 89,380,153 borrow 50,000,000 VVS
09:59:42 89,380,743 liquidated
10:04:53 89,381,356 self-repay 425,027,150.29 VVS
10:05:35 89,381,420 redeem 557 USDC

At a 0.80 collateral factor, 1,000 USDC gave $800.08 of borrowing capacity. The three borrows took the debt to $658.63, then $752.72, then $799.77, which is 99.961 per cent of capacity. Four basis points inside the limit.

The VVS oracle then ticked up 0.70 per cent and the position became liquidatable. The liquidator repaid 424,974,805.4824 VVS, exactly half the 850m borrowed, matching closeFactorMantissa of 0.5, and seized 4,104.80940265 tUSDC at a seize-to-repay ratio of 1.1000, matching liquidationIncentiveMantissa.

Whole rehearsal: 19 minutes 23 seconds. Cost: $443.

Inference, and it cuts against the obvious reading. The probe touched exactly two markets: tUSDC on the supply side and tVVS on the borrow side. tVVS was never touched in the attack. tTONIC, the market whose price was moved, the probe never touched at all. Someone testing the specific attack would have tested the specific markets. This reads as a check that the liquidation machinery behaves as documented, not as a dry run.

Total reconnaissance spend: roughly $1,200. That $1,200 established that $5m of stake was enough to move the market.

The plumbing put in place alongside it

Fact. On 17 August at 14:20:47 a wallet was created as the recipient of a Tornado withdrawal of 0.0978607229504 ETH, then topped up with 10 ETH the following day. 0x9E2CFB823AdB9BD67a41C1845C0Dd70453D7D378 has since sent 16 transactions and still holds 4.042018684 ETH. It is the gas dispenser: it fuels the wallets that do the work rather than doing any itself, and it is the address that pays the fourth escape wallet on 31 August in section 11.

Fact. On 21 August three further Ethereum wallets were fuelled and then never used at all.

Address Held Sent
0xbaA143E23285a7bBB4803cB023724e5c616547e2 0.2 ETH 0
0x0F8C0c8d5b9906F5e439c9a1086BF2f742fb7495 0.1 ETH 0
0x3b5a2d0D6050Aeae57EA20b17e2b0cA263356644 0.1 ETH 0

All three are still at nonce 0 today. One of them, 0xbaA143E2, was topped up again at 14:42:59 on 30 August, ten minutes and twelve seconds after Cronos stopped producing blocks. The chain had halted. The infrastructure had not.


5. The origin, and the wall

Everything above is Cronos. Everything from here is Ethereum, where nothing was rolled back and the whole preparation is still legible.

Where it starts

Decoded. The funding wallet 0x7a79969a0B9D51D922C4810D2950560360F6f234 was created on 6 June 2025 at 03:16:35 by a withdrawal from the Tornado Cash 0.1 ETH pool. The pool’s own Withdrawal event carries every detail.

Field Value
Transaction 0xb186d5d86e5662124c2c40fc5946be6b0433fad486e2964d1f3b71cec50e482c
Block 22,642,816
Relayer fee 0.002580596806050000 ETH
Net to the wallet 0.097419403193950000 ETH

Nullifier 0x0aebe2f23857e8f8347babfcebce4c40f48e1fb7377a7b61b31db31e7a6cfdde.

Etherscan header view of transaction 0xb186d5d8, a Tornado Router withdraw call sent by a relayer at 03:16:35 UTC on 6 June 2025.
The same transaction from the top. A relayer sent it, which is why the wallet paid no gas and left no funding trace of its own. Source: Etherscan, captured 1 September 2026.
Etherscan screenshot of transaction 0xb186d5d8: 0.0974 ETH flows from the Tornado.Cash 0.1 ETH pool to wallet 0x7a79969a, with 0.0026 ETH going to the relayer as a fee, dated 6 June 2025 03:16:35 UTC.
The transaction that created the funding wallet. The pool pays the recipient and the relayer separately, so both figures are readable. Source: Etherscan, captured 1 September 2026.
Etherscan overview page for wallet 0x7a79969a, showing it was first funded by Tornado.Cash 0.1 ETH one year and 86 days before capture, with 526 transactions sent.
The wallet itself. Etherscan names its first funder as the Tornado 0.1 ETH pool. Source: Etherscan, captured 1 September 2026.

Forty-five minutes later, at 04:01:23, the wallet called the Tornado router itself and 100 ETH arrived. Every one of the 83 withdrawals that followed has the same shape: relayer field set to the zero address, fee zero, gas limit 550,000, and a 3.000 gwei priority fee. That combination is consistent with the stock Tornado front end, and that is how we use it below: as a fingerprint that groups transactions, not as proof of which client was open.

Etherscan screenshot of the first 100 ETH withdrawal: sent by the wallet itself to the Tornado Router with no relayer, 100 ETH arriving from Tornado.Cash 100 ETH, at a gas price of 3.847 gwei, block 22,643,040 on 6 June 2025 04:01:23 UTC.
Forty-five minutes after being created. The wallet sends the call itself, so there is no relayer and no fee, and 100 ETH comes back. Source: Etherscan, captured 1 September 2026.
Etherscan header view of the first 100 ETH withdrawal at block 22,643,040, 6 June 2025 04:01:23 UTC, sent by the wallet itself to the Tornado Router.
Block 22,643,040. The gas price of 3.847 gwei and the 550,000 gas limit are the stock front-end profile that all 83 withdrawals share. Source: Etherscan, captured 1 September 2026.

One behavioural detail survives from the origin hop. The first withdrawal was relayed, by a service address that has since sent 7,101 transactions and holds 15.62 ETH. Every withdrawal in the April 2026 round trip was self-relayed with a zero fee. Between June 2025 and April 2026 the operation started paying its own gas. The relayer identifies nobody; it sells gas to anyone who pays.

What came out

Counted. Eighty-three withdrawals of exactly 100 ETH, in four batches. The table also gives the pool’s unspent-note count at each batch’s first withdrawal, which is the anonymity set the operator was hiding inside.

Batch Dates Notes Unspent notes in pool
B1 6 to 19 Jun 2025 24 1,254
B2 2 to 18 Dec 2025 28 about 2,945
B3 2 to 5 Feb 2026 22 about 2,008
B4 5 Jun 2026 9 about 2,012

The B1 figure is checked against the contract’s own balance: 125,400 ETH at block 22,643,039, which is 1,254 notes exactly.

A correction to our own published thread. Our X thread said the wallet “pushes” those notes through the pool. The counts, the months and the 8,300 ETH total are all right; the direction is not. Those 83 came out. The wallet also deposited, but 25 notes of 100 ETH, and all of them in June 2026.

Etherscan screenshot of the wallet's oldest internal transfers: 0.0974 ETH arriving from the Tornado.Cash 0.1 ETH pool at block 22,642,816, followed by repeated 100 ETH arrivals from the Tornado.Cash 100 ETH pool from block 22,643,040 onwards.
Direction is legible on the page. The 100 ETH rows are arrivals from the pool, not payments into it. Source: Etherscan, captured 1 September 2026.

The wall, and how we tested it

Limit. 0x7a79969a is the furthest back anyone gets, and this is the single most important limit in the document.

The note that created it came out of Tornado, so the deposit that funded it is unlinkable by construction. The obvious question is whether the note-counting method that worked on the April round trip works here. It does not, and we ran it rather than assuming.

Every Deposit and Withdrawal the 0.1 ETH pool emitted across 5 to 7 June 2025:

Count
Withdrawals 39
Distinct recipients 24
Deposits 59
Distinct depositors 25

April worked because 23 notes in and 23 notes out was a count nobody else in the window came near. Here the wallet took one note, and it is one of 19 recipients that week who took exactly one. A single note is the most ordinary transaction the pool has. There is no unique match to find.

It is worse than that for anyone hoping to push further: a Tornado note can sit unspent for years, so the true candidate set is every unspent deposit in the pool’s history, not the 25 depositors in that window.

The origin of the capital is behind the mixer and stays there. We record this because a stated limit is worth more than a silence.

What the withdrawal calls themselves leak

The proof hides which deposit was spent. It does not hide how the proof was made, and that turns out to carry more than we expected. We decoded the calldata of all 83 withdrawals directly rather than reading Etherscan’s rendering of them.

Decoded. Every call is withdraw(address,bytes,bytes32,bytes32,address,address,uint256,uint256). Across all 83: the relayer field is the zero address, the fee is zero, the refund is zero, the pool is the 100 ETH pool and the recipient is the wallet. That confirms the self-relaying from the calldata itself rather than from a fee that happens to be absent.

Decoded, and this is new. The third argument is the Merkle root the client had synced when it built the proof. Across the 83 withdrawals there are 24 distinct roots, and the root changes at 23 of the 82 transitions.

Read that carefully, because it bounds the claim. Fifty-nine of the 82 consecutive pairs share a root with the withdrawal before them, and the longest unbroken run of a single root is ten withdrawals. A shared root is what a batch built in one sitting looks like. The evidence therefore establishes at least 24 separate occasions on which a client re-synced the tree and built proofs, not 83 live moments.

What it does rule out is one single batch: a single sitting would have left one root across all 83. Instead there are two dozen, advancing whenever deposits had landed in between, with several withdrawals following each sync.

The practical consequence survives the narrower reading. There are 83 broadcast timestamps and at least 24 separate sessions in which something fetched the pool’s event history. Whichever RPC endpoint or front end served those fetches may hold network telemetry capable of identifying the client, though a local node, a rotating set of providers, or a VPN would each weaken that, and nothing on chain says which was used.

Inference. Sixty-one of the gaps between consecutive withdrawals fall inside half an hour, with a median of 108 seconds and a floor of 60. That interval is consistent with proof generation plus a confirmation step. It does not distinguish a person clicking from a queue pacing itself. The June 2026 re-deposits went in 12 to 24 seconds apart, and deposits need no proof, so that end of the range is a script.

On 12 June 2025 the root refreshed between withdrawals 84 and 96 seconds apart, while an unlabelled depositor was in the middle of a 110-note run. Two clients were working the same pool in the same minutes.

Inference, and it cuts against the lead in the next section. Eighty-three withdrawals across 18 distinct days, plus the second cluster wallet’s 10, gives 26 days of activity. Twenty-three of those 26 are Monday to Friday. Not one falls on a Sunday. Under a uniform assumption the odds of drawing 26 days with three or fewer at a weekend are about one in 27.

Treat that as suggestive rather than settled: 26 days is a small sample and someone can choose when to press a button. The hour-of-day profile, for what it is worth, does not localise anything. Activity spans 02:00 to 23:00 UTC with dead hours scattered through it, and it does not match the compressed early-UTC working day associated with the state-linked crews that dominate exchange thefts. Whoever this is appears to keep a working week and take Sundays off.


6. The deposit side, and the BitoPro lead

If the link cannot be made deterministically, the next question is what the pool looked like before each batch. That is observable: the population of deposits, their timing, denominations, tooling and funders.

Three-panel chart. Top: unspent 100 ETH notes in the Tornado pool from January 2025 to July 2026, rising from about 1,254 at batch one to 2,945 at batch two and settling near 2,000 for batches three and four. Middle: weekly deposits into the pool, with a clipped bar showing 1,338 deposits in the week of 4 November 2025 and fourteen numbered markers for labelled depositors. Bottom: the wallet's own 100 ETH withdrawals per day, clustered into four batches of 24, 28, 22 and 9 notes.
The anonymity set at each batch, above the pool's deposit traffic and the wallet's own withdrawals. The set never falls below about 1,250 notes, which is why no batch can be resolved to a depositor. Chart built from 8,228 deposit and 7,477 withdrawal events.

Counted. All Deposit and Withdrawal events of the 100 ETH pool from 1 January 2025 to 17 June 2026: 8,228 deposits and 7,477 withdrawals, with depositor addresses resolved for 8,220 of them. 1,806 distinct addresses deposited; 4,541 received withdrawals.

One number from that dataset kills a tempting shortcut. 2,951 of the withdrawals, 39 per cent, were self-relayed exactly like this wallet’s. Self relaying is a common pattern, not a signature.

Etherscan page for the Tornado.Cash 100 ETH pool contract showing a balance of 245,100 ETH at the time of capture, which is 2,451 unspent notes.
The pool holds 245,100 ETH today, which is 2,451 unspent notes. Dividing the contract balance by the denomination is how the anonymity-set figures above were checked. Source: Etherscan, captured 1 September 2026.

Batch 1 is the one with structure

Batch 1 is the batch worth working, because the wallet was new and its gas came from a 0.1-pool note, which is a preparation step a depositor has to have made.

Chart of daily deposits into the Tornado 100 ETH pool from 1 May to 20 July 2025, with labelled depositors coloured: BitoPro Exploiter 2 with 40 notes on 14 May, two phishing-funded addresses with 20 and 30, Cork Exploiter 2 with 39 on 25 June, Infini Exploiter 3 with 50 on 17 July, and an unlabelled address with 110 on 12 June. Below it, the wallet's own withdrawals of 4, 1, 4, 5, 5, 3 and 2 notes across June, with triangles marking the two 0.1 ETH gas notes.
Every deposit into the pool in the ten weeks around batch one, coloured where the depositor or its funder carries a public label. Grey is everyone else, and grey is most of it.

Fact. In the 30 days before 6 June 2025 there were 634 deposits from 224 addresses.

Lead. The best-fitting single depositor is the address Etherscan labels BitoPro Exploiter 2, 0x454cf3892a949c94569ab2663090ecdca811a6f0. On 14 May 2025, between 06:28 and 08:22, it deposited 40 × 100 ETH, 9 × 10, 1 × 1 and 5 × 0.1, 55 notes and 4,091.5 ETH, then swept its last 0.0317 ETH out and stopped.

BitoPro is a Taiwanese exchange. It was breached on 8 May 2025 and confirmed the attack on 3 June, telling Fortune it had been “attacked by hackers” during a wallet system upgrade and that withdrawals had continued normally throughout. The investigator ZachXBT put the loss at about $11.5m and published first; the exchange’s statement followed hours later.

Etherscan screenshot of transactions from the address labelled BitoPro Exploiter 2 to the Tornado Router, listed newest first as Etherscan renders them, so the nine deposits of 10 ETH from 07:54 UTC appear above the run of 40 deposits of 100 ETH that ran earlier, from 06:28 to 07:54 UTC on 14 May 2025.
The 14 May 2025 deposit run. The denomination ladder, 100s then 10s then 1s then 0.1s, is the same order the funding wallet used in reverse on its own way out. Source: Etherscan, captured 1 September 2026.
Etherscan overview page for address 0x454cf389 carrying the public name tag BitoPro Exploiter 2, an exploit warning citing the investigator ZachXBT, and a Funded By line naming BitoPro Exploiter 1.
The label is Etherscan's, sourced from ZachXBT, not ours. We did not re-derive the tag beyond the funding link shown on the page. Source: Etherscan, captured 1 September 2026.

For the lead. Forty fresh notes 23 days before the wallet started, and batch one’s 24 notes fit inside them. It is one of only two large depositors in the window that also parked 0.1 ETH gas notes, five of them, and this wallet drew two 0.1-pool notes. Between 14 May and 22 June 2025 the funding wallet is the only recipient of two or more notes that was gas-funded from the 0.1 pool and then self-relayed its withdrawals; the next such address appears on 23 June. Both sides used the same front-end fingerprint.

Against the lead, and this is the heavier column. The anonymity set was 1,254 unspent notes and 224 depositors in the prior month, and nothing in the proof system narrows that. The wallet took 83 notes and the cluster at least 119; BitoPro’s depositor placed 40, so at most a fraction of the operator’s notes could be BitoPro’s. The second cluster wallet was already withdrawing on 25 January, 3 April and 7 May 2025, before BitoPro was breached at all. The 3 gwei priority fee is the front-end default and four of the eight depositors in that window share it. And a competing candidate exists: an unlabelled address placed nine 0.1 ETH gas notes on 30 and 31 May, six days before the wallet started.

The behaviour also sits oddly. This operator held ETH on Ethereum for a year, farmed Aave, borrowed stablecoins and bridged out in small pieces. The BitoPro depositor moved through THORChain and Tornado’s token pools within days.

Etherscan screenshot of token transfers on 8 May 2025 from the address labelled BitoPro Exploiter 1 to BitoPro Exploiter 2: 58.48 wrapped bitcoin and 3,521,865 DAI, followed by conversion through Uniswap.
Eight May 2025, the day of the breach. The funding of the address that six days later deposited into Tornado. Source: Etherscan, captured 1 September 2026.
Etherscan overview page for address 0x2453933c carrying the public name tag BitoPro Exploiter 1 and an exploit warning.
The address one step upstream, also labelled by Etherscan. It funded the depositor on the day of the breach. Source: Etherscan, captured 1 September 2026.

Three further tests, and they all point away from it

We kept going, because a lead that only ever gets stronger is a lead nobody is testing. Three checks were run against the pool’s wider history. All three weaken the case rather than strengthen it.

The cheap test does not exist. BitoPro’s depositor also placed nine 10 ETH, one 1 ETH and five 0.1 ETH notes. Small pools hold tens of unspent notes rather than thousands, so a matching bundle leaving one shortly afterwards would be close to a proof. No matching bundle left in the following 48 hours. The largest 10-pool withdrawals on 14 and 15 May were pairs. Whoever held those notes was patient, or split them, and the one cheap test that could have tied BitoPro’s notes to a specific cash-out address is gone.

Etherscan screenshot of the smaller Tornado deposits from BitoPro Exploiter 2 on 14 May 2025: five deposits of 0.1 ETH and one of 1 ETH, with the final sweep of 0.0317 ETH leaving the address at 08:28 UTC.
The small notes that would have settled it, if any matching bundle had left the small pools afterwards. None did. Source: Etherscan, captured 1 September 2026.

That check also removed a decoy worth recording, because it nearly caught us. On 14 May an address ending …e876 deposited nine 10 ETH, four 1 ETH and seven 0.1 ETH notes, and 0x3553…58ef withdrew exactly those counts minutes later and bridged the proceeds out through LI.FI. Identical bundles minutes apart in thin pools is near-certain linkage. It looked like BitoPro’s small change, since BitoPro had deposited nine 10 ETH notes ninety minutes earlier. The deposit timeline shows it was somebody else entirely.

The crowd that withdrew after BitoPro’s deposit does not behave like this operator. Between 14 May and 1 June 2025, 422 notes left the pool to 334 addresses.

What they did Addresses
Took one note and sent it straight to the LI.FI bridge 117
Sent to another wallet or swapped immediately through CoW 203
Self-relayed, the way this wallet does 4

Four addresses, seven notes. Fast, one note per fresh address, swap and bridge, is what professional laundering of an exchange theft looks like on this pool, and it is what BitoPro’s own depositor did on the way in. Stylistically BitoPro’s notes belong with that crowd, not with a wallet that then farmed Aave for a year.

The clock does not fit either. Splitting the cluster’s 723 outgoing transactions into working sessions, using a 30-minute gap as the break, gives 163 sessions.

Two bar charts of activity by hour of day in UTC. The upper chart shows the operator cluster's 163 working sessions spread across the day with peaks at 12:00, 17:00 and 19:00 to 20:00 UTC and a shallow trough from 02:00 to 07:00. The lower chart shows BitoPro Exploiter 1 and 2's 104 transactions concentrated sharply at 07:00 UTC with 41 transactions, plus a second cluster at 21:00 to 23:00.
Session start times for the operator cluster, above the BitoPro addresses' activity for comparison. The two shapes are not the same, and neither is the compressed early-UTC block that Korea-Standard-Time office hours produce.

Sixty-five per cent of sessions start between 11:00 and 21:00 UTC and 26 per cent between 00:00 and 10:00, with Saturdays quietest. That reads as a daytime and evening pattern somewhere around UTC to UTC+3, or a working day in the Americas. The BitoPro addresses, over 104 transactions in one week, cluster at 06:00 to 08:00 and 17:00 to 23:00. A small sample, and time-zone inference from timestamps is soft evidence, but the shapes differ.

Verdict: unlikely. The timing fit is real and we are not dismissing it. But the small-note test came back empty, the population BitoPro’s notes sat among behaves nothing like this operator, and the clock leans the other way. Someone with subpoena power or commercial demixing data could still settle it. On what is visible on chain, it is a weak candidate rather than a strong one.

Batches 2 to 4

Inference. For the later batches the pool’s composition changes the question. By December 2025 roughly 2,945 notes were unspent, and more than a third had arrived in two unlabelled bursts: 407 notes on 23 to 26 October and about 1,228 notes in a single night on 4 to 5 November 2025, split across some twenty addresses. Most of the inventory the operator was hiding among came from depositors nobody has labelled.

Labelled contributions in the same period came from addresses Etherscan tags as Infini Exploiter 3, Balancer Exploiter 7, a “Multisig Drainer” and two phishing addresses. The Multisig Drainer deposited on three of the wallet’s December withdrawal days, five to eight hours apart each time, which is suggestive of overlapping schedules and nothing more.

Etherscan overview page for address 0x1fCf carrying the public name tag Multisig Drainer, showing 79 notes deposited into Tornado between December 2025 and May 2026.
The depositor whose December days overlap the wallet's. Five to eight hours apart each time, which is a shared calendar at most. Source: Etherscan, captured 1 September 2026.
Etherscan overview page for address 0x7142 carrying the public name tag Infini Exploiter 3, with a warning citing PeckShield, showing 204 notes deposited in July 2025 and February 2026.
The largest labelled feeder of the pool across the period, at 204 notes. Source: Etherscan, captured 1 September 2026.
Etherscan overview page for address 0x0e9c carrying the public name tag Balancer Exploiter 7, with a warning citing SEAL 911, showing 37 notes deposited on 15 November 2025.
Another labelled feeder, 37 notes in November 2025. Source: Etherscan, captured 1 September 2026.
Etherscan overview page for address 0x9dA0 carrying the public name tag Fake_Phishing1691337, with a warning citing SpecterAnalyst, one of two addresses that deposited 82 notes each on 19 December 2025.
One of two phishing-tagged addresses that put 82 notes each into the pool on a single day in December. Source: Etherscan, captured 1 September 2026.
Etherscan overview page for address 0x778d, the 25 June 2025 depositor of 39 notes, showing it was funded by the address labelled Cork Protocol Exploiter 2.
And a fourth, funded by an address Etherscan ties to the Cork Protocol exploit. None of these is an attribution; they are the population the operator was hiding among. Source: Etherscan, captured 1 September 2026.

No single candidate stands out for batches 2 to 4.

The constraint that eliminates rather than suggests

There is one test that rules candidates out rather than nominating them. A single source must have deposited more notes than the cluster had withdrawn, at every date. Run against the pool’s 2024 history, which adds 4,481 deposits and 4,279 withdrawals, it does real work.

The dominant feature of that year is September 2024: an address Etherscan labels for the WazirX exchange theft deposited 26 notes on 2 September, followed by a chain of fresh addresses depositing 50 notes almost daily until the 27th. About 749 notes, roughly 74,900 ETH, against a withdrawal spike of 895 that month where the normal rate is about 250. Most of it left within weeks.

Applying the rule: the second cluster wallet’s three notes on 25 January 2025 rule out every 2025 theft as a sole source. Batch 1 needs at least 31 notes from one source before 19 June 2025, and the operation’s whole life needs at least 119. Three explanations survive, and only three: an unspent residue of the September 2024 chain, the February 2025 group of 103 notes combined with something else, or an operator drawing on several deposits at once. The last is the simplest, and it is what a serial thief or a laundering service looks like.


7. The operator cluster

Five addresses tie to the same operator without any mixer heuristics at all, because they fund one another directly.

Address Role Grade
0x5770c25e…f704e Second cash-out wallet, 36 notes from Jan 2025 Inference
0x16f0…bf07 Gas and DAI hop, funded by the wallet Fact
0x1A35…16231 Consolidation, 1,743.027 ETH to the wallet Fact
0x43c7…2f82 Consolidation, 605.829 ETH to the wallet Fact
0xa212417f…3a7f Re-mixing wallet, 23 notes back into Tornado Fact

Fact. 0x16f0…bF07 received a 0.1 ETH test from the wallet on 7 February 2026, then 500,000 DAI, bridged the DAI out through Relay, and on 18 March sent 0.049 ETH to 0x1A35…16231. That consolidation wallet then took 1,350.8 ETH from a Relay solver and 392.0 ETH from Relay Router V3 and passed 1,743.027 ETH to the wallet on 24 March. A second consolidation wallet did the same with 605.829 ETH on 22 March. Gas from one, funds to the other, both ends readable.

Etherscan screenshot of transactions from address 0x16f0: DAI approvals, Relay Approval Proxy transfers bridging the DAI out, a Relay Depository deposit, and 0.049 ETH sent to address 0x1A35, which is the gas that starts the consolidation wallet.
One address doing two jobs: bridging 500,000 DAI out through Relay, and paying the gas that brings the consolidation wallet to life. Source: Etherscan, captured 1 September 2026.

Inference, strong. The second cash-out wallet 0x5770c25edcc98cb9f2a2483690a99d5f80df704e was funded from the Tornado 10 ETH pool in January 2025 and has taken 36 withdrawals of 100 ETH from the same pool, first on 25 January 2025 and last on 26 June 2026, using the same tooling and the same Aave gateway. It withdrew on the same day as the funding wallet twice, 5 February 2026 and 5 June 2026. There is no direct transfer between them, so this is behavioural rather than deterministic.

Combined, the two wallets have drawn 11,900 ETH out of the 100 ETH pool.

Etherscan overview of wallet 0x5770c25e showing it was funded by Tornado.Cash 10 ETH one year and 219 days before capture, and holds approximately 9.2 million dollars of token holdings, largely Aave positions.
The second cash-out wallet. Same origin pattern, same Aave habit, and it started four months before the funding wallet existed. Source: Etherscan, captured 1 September 2026.
Etherscan screenshot of the second cash-out wallet's internal transfers, showing repeated 100 ETH arrivals from the Tornado.Cash 100 ETH pool.
The second cash-out wallet taking its own 100 ETH notes from the same pool, on the same tooling. Source: Etherscan, captured 1 September 2026.
Etherscan overview page for address 0x16f0 showing it was funded by the subject wallet 205 days before capture, on 7 February 2026.
Etherscan states the funding relationship on the page itself, which is why this link needs no heuristic. Source: Etherscan, captured 1 September 2026.
Etherscan overview page for the consolidation wallet 0x1A35bD28, showing it was funded by 0x16f0 and later received 1,743 ETH via Relay before forwarding it to the subject wallet.
The consolidation wallet on Ethereum. At this point in the investigation we could not say where its 1,743 ETH came from. [Section 10](#10-the-cronos-funding-wallet-received-the-venus-attack-proceeds) answers that. Source: Etherscan, captured 1 September 2026.

That January 2025 start is the strongest single argument against any 2025 theft being the source of this operation’s capital. The stash predates them.


8. What the money did between the batches

Fact. The ETH was not idle. Across a year the funding wallet ran a leveraged book on Aave V3.

Position Figure
Supplied as collateral 8,435.79 ETH, 36 events
Borrowed against it $11,364,723
Of which USDT 6,670,158
Of which DAI 2,501,437
Of which USDC 2,193,128

All of it was repaid. What remains of the debt today is 0.86 USDT.

Stablecoin flow across the wallet’s life came to about $21.9m: $13,388,624 USDT, $5,573,287 DAI and $2,952,120 USDC, with inbound matching outbound to the cent on all three. The balance today is zero.

It swapped 3,112 ETH through KyberSwap and 2,754 ETH through ParaSwap, used Odos, and moved value off Ethereum through five bridges: Symbiosis 55 calls, Relay 23, Stargate 10, LI.FI 3 and Across 1.

Inference, and a caveat we are carrying deliberately. A year of leverage and $21.9m of stablecoin churn is equally consistent with one operator running their own funds and with a service handling other people’s as well. Nothing on chain separates those two readings. Any description of this wallet as simply “the attacker’s wallet” is doing more work than the evidence supports.

The exit

Fact. On 15 and 16 June 2026 the wallet put 2,575.5 ETH back into Tornado across 42 deposits: 25 × 100, 7 × 10, 5 × 1 and 5 × 0.1. Thirty-one of those deposits went in on 16 June inside 27 minutes, between 10:58:47 and 11:26:35. At 12:41:35 it sent 0.02 ETH to a Symbiosis bridge and stopped.

That was just under 75 days before the Cronos position opened: 74 days, 23 hours and 57 minutes, to be exact.

Etherscan screenshot of the wallet's final transactions in June 2026: a run of deposits to the Tornado Router in 100, 10, 1 and 0.1 ETH denominations, followed by two Symbiosis bridge calls of 0.02 ETH.
The last day. The denomination ladder runs down from 100 to 0.1, then two bridge calls, then nothing for ten weeks. Source: Etherscan, captured 1 September 2026.

Where the bridges took it, and this part needed no mixer analysis at all

The bridges are the opposite of Tornado. Symbiosis, Relay, Stargate and Across all publish per-transaction status keyed by the source hash, so every one of the cluster’s cross-chain transfers can simply be looked up.

Fact. Resolving all of them gives one destination. Everything goes to BNB Smart Chain. About $4.9m direct from the funding wallet across June and December 2025, and about $4.3m more from the stablecoin hops between December 2025 and February 2026, converted into BNB and WBNB in pieces of $50,000 to $100,000.

From When Amount and destination
the funding wallet 6 to 9 Jun 2025 about 423,000 USDT, to itself on BSC
the funding wallet 10 to 21 Jun 2025 about 1.9m, to three BSC addresses
the funding wallet 2 to 23 Dec 2025 about 2.95m, to BNB and WBNB
0xbb37…ef87 26 Dec to 15 Jan 2026 1.8m USDT in eighteen 100k pieces
0x89e3…ddb6 28 to 29 Jan 2026 about 2m DAI, to WBNB
0x16f0…bf07 Feb 2026 500,000 DAI

Nothing went to Cronos on any bridge. Whatever paid for the Cronos stake did not travel by this route.

Decoded, and this is the part that opens a new door. The recipients on BNB Smart Chain are the same addresses. An Ethereum address is derived from its private key, and the derivation is identical on every EVM chain, so an address that is active on BSC is the same key. We checked all seven directly against a BNB Smart Chain node.

Address Transactions sent on BSC
0x7a79969a…0F6f234, the funding wallet 61
0x16f09b91…25bf07 605
0xa212417f…12f23a7f, the April re-mix wallet 1,328
0x564a073f…82a4591, seen only on BSC 3,338
0x89e3615f…affdddb6 4,263
0xbb378204…65a4ef87 18,720
0xf052219f…7429c58aa, seen only on BSC 33,991

That is 62,306 transactions. On Ethereum the April re-mix wallet sent about twenty-five in its whole life. The same key has sent 1,328 on BSC, and two of its neighbours have sent over 50,000 between them.

All seven hold dust today, a fraction of a BNB each and no significant token balances. About $9m arrived, became BNB, and left.

Inference, and it sharpens the caveat above rather than softening it. Tens of thousands of transactions is not the profile of a person moving their own stolen money. It is the profile of a service running at volume. Combined with the year of Aave leverage and the $21.9m of stablecoin churn, the reading that fits best is that the Ethereum wallets we have traced are one arm of something that also operates at scale on BNB Smart Chain. Whether the Cronos attacker owns that operation or is a customer of it is not something the chain will tell us.

Two loose ends, stated so nobody assumes they were tidy. The funding wallet’s very last act, on 16 June 2026, was a $36 Symbiosis route ending in USDT on Tron, which is a thread nobody has pulled. And the second cluster wallet’s 2.74m USDC hop moved by plain transfers and through a contract rather than Relay, so its destination is unresolved.


9. The April round trip, and the two hops that carry the case

The round trip

Counted, with a negative control. On 21 April 2026 the wallet sent 101 ETH and then 2,200 ETH to 0xa212417f73f4d1a4178ee7c3b1412e3c12f23a7f.

Leg Time Hash
101 ETH 13:53:23 0x2b61c4b9962c25bf70c900555fe4657fbaa9f07adc5b7d6340261e20ce29dd22
2,200 ETH 13:59:23 0xfd6c9005fd6be5c84d9d02eeb811e50cd53d4b74b5c25ed69df3a12a015b6dcd
0.926 ETH back 21:03:35 0xea29676af6d59137fecf2c028ea4f9fe7cd0f36e49c427e0178567e8eaf88573

That wallet deposited exactly 23 notes of 100 ETH into the pool the same day, returned the change, and was never used again. In the same window exactly 23 notes were withdrawn to 0x871ab7d790Ae319279239d84C3f78fa896449b01, in alternating batches, all self-relayed with zero fee.

Across those four days the pool saw five depositors and eight withdrawers. Exactly one deposited 23 and exactly one withdrew 23.

What this is not. We did not break Tornado Cash. Its cryptography is intact and we did not attempt it. This is transaction-pattern analysis. To test whether the method proves anything, we ran it against the wallet’s other batches: three matched on count alone, and all three failed the next test, which was following the funding backwards. This one did not fail it.

Etherscan screenshot of wallet 0xa212417f: deposits of 100 ETH to the Tornado Router, 0.926 ETH returned to the funding wallet, and address-poisoning dust arriving from four addresses that copy the funding wallet's 7a79 prefix and f234 suffix rather than this wallet's own.
The re-mixing wallet. The dust rows are address poisoning, and note which address they imitate: `0x5b430cda…60f6f234`, `0x68b49746…60f6f234`, `0x7a793408…1763af234` and `0x7a79c6f2…edaa8f234` all copy the funding wallet's pattern, not this one's. The poisoners were aiming at the wallet that had just sent the 0.926 ETH back. Source: Etherscan, captured 1 September 2026.
Etherscan overview page for wallet 0xa212417f showing it was funded by the subject wallet 132 days before capture, on 21 April 2026.
The re-mixing wallet, funded by the hub and used for one day only. Source: Etherscan, captured 1 September 2026.

The destination, written in plaintext

Decoded. This is the strongest hop in the case, because it needs no inference at all. THORChain writes the destination into the transaction as readable text. Thirteen swaps carry the same 51 bytes, byte for byte identical:

=:tr:TZEJLhqXz2roiCgxxLbJV1i1LFyf5VZR8v:0/1/0:ss:60

tr is TRON.TRX in THORChain’s own asset table. The affiliate tag ss appears in THORChain’s worked examples without being defined; community registries call it ShapeShift and we do not treat that as established.

Those thirteen legs carried 1,800 ETH between 21 and 24 April.

The trail closes

Counted. 2,300 ETH came out of Tornado. It left by three doors and one is still open.

Route ETH
THORChain, 13 legs 1,800
NEAR Intents, 14 addresses 310
Relay 72
Still held in the wallet 116.951349

That totals 2,298.951349 against 2,300, a difference of 1.048651 ETH, which is gas. Every ETH is accounted for.

The NEAR Intents leg deserves its own note. Fourteen single-use Ethereum addresses fed the published treasury, and every one of the fourteen has a matching TRX arrival on the other side, 82 to 100 seconds later. Fourteen for fourteen. That is a timing correlation across two chains with no shared address.

The key reuse

Decoded. The Ethereum side and the Tron side are two separate bodies of evidence. What joins them is neither clustering nor heuristics. It is a mistake: the operator used one private key on two blockchains.

Ethereum Tron
0xC0E272092e74688b31313c8e3d9846628Fd71508 TTZ61bYGEm6JHf4pzB5JLPu5KB35g2uovA
0x1A59697a7c499f0144dfa1b100e24822f5e21638 TCNXgW8PvRn8UFjegkUUyTf5nSfHGfyZqR

Tron derives its address as base58check(0x41 ‖ addr20) from the same key material as an Ethereum address. We derived both directions and the checksums match. This is arithmetic, not judgement.


10. The Cronos funding wallet received the Venus attack proceeds

This is the largest single finding in the investigation, and it is the one place where an outside party confirms us rather than the reverse.

Credit where it is owed, before the finding. BlockSec published its analysis in March. It names this funding wallet in full, gives the 7,447 ETH it took through Tornado Cash, and traces the nine months of accumulation that followed. Venus Protocol’s post-mortem covers the same ground. Most of what this section describes about the Venus attack was established there rather than here, and anyone checking our work should read theirs.

What we could find no prior account of is the step after it: that the wallet on the receiving end of the Venus proceeds is the wallet that five months later paid for the Cronos stake. BlockSec’s report predates the Cronos attack by five months and mentions neither Cronos nor Tectonic. We arrived at the link from the Cronos end, tracing funding backwards without knowing where it went.

Venus Protocol is a lending market on BNB Smart Chain. On 15 March 2026 it was attacked, and it published its own incident post-mortem. That document names two addresses:

Address Venus calls it We had it as
0x1a35bd28efd46cfc46c2136f878777d69ae16231 the primary attacker our consolidation wallet
0x737bc98f1d34e19539c074b8ad1169d5d45da619 the attack contract new to us

The first of those is the wallet we had already traced sending 1,743.027 ETH to the funding wallet on 24 March 2026, nine days after the attack. In our earlier work that inflow was recorded as unexplained. It is the proceeds.

Flow-of-funds diagram across two chains. On the Ethereum side: the Tornado Cash 100 ETH pool sends 83 notes to the wallet and 36 to the sibling, the wallet supplies 8,436 ETH to Aave v3 and borrows about 11.4 million dollars of stablecoins, which leave through Stargate, Symbiosis, Relay, Across and LI.FI in pieces of 100,000 dollars or less. On the BNB Chain side the same keys receive the stablecoins, buy at least 39.7 million THE in about 30,000 micro-swaps on Thena, and push tens of millions of THE into Venus's vTHE market. The position is liquidated 8,039 and 603 times, leaving Venus about 2.15 million dollars of bad debt. The retained CAKE, BTCB and WBNB return through Relay, landing as 2,340.3 ETH across 46 transfers at two addresses, which send 605.8 and 1,743.0 ETH back to the wallet in March 2026, and 4,875.5 ETH goes back into Tornado between April and June 2026.
The whole loop on both chains. Solid arrows are direct transfers with a hash; dashed arrows are bridge legs resolved through the bridges' own records. The money leaves the mixer, works for nine months, commits an exploit, and comes back to the mixer.

What our figures and theirs do to each other

Venus writes that the wallet behind the attack received “7,447 ETH (~$16.29M) in 77 transactions from Tornado Cash” and supplied it to Aave as collateral to borrow stablecoins.

We reconstructed that from the other end, before seeing their document. Counting every Tornado transfer into the funding wallet before their attack timestamp gives 76 transfers and 7,400.191 ETH.

Transactions ETH
Venus Protocol’s post-mortem 77 7,447
Our own count 76 7,400.191
Difference 1 46.809, or 0.63%

Two parties working from opposite ends, neither having seen the other’s work, landing 0.63 per cent apart on the same wallet.

The tell, and it is visible in three numbers

We checked all three addresses directly against a BNB Smart Chain node on 1 September 2026.

Address On BNB Smart Chain On Ethereum
0x737bc98f… the attack contract contract, 19,865 bytes does not exist
0x43c743e3… the attack operator EOA, nonce 90 EOA, nonce 1
0x1a35bd28… the position wallet EOA, nonce 208 EOA, nonce 1

Read the bottom two rows across. On Ethereum each of those wallets sent exactly one transaction in its entire life: 605.829 ETH and 1,743.027 ETH, both to the funding wallet, both in March 2026. Their real work is on BSC. They exist on Ethereum for one delivery each.

Etherscan screenshot of the transaction sending 1,743.027 ETH from address 0x1A35bD28 to the funding wallet 0x7a79969a on 24 March 2026.
1,743.027 ETH, 24 March 2026. The single Ethereum transaction of the wallet Venus names as its primary attacker. Source: Etherscan, captured 1 September 2026.
Etherscan header view of the 1,743.027 ETH transaction on 24 March 2026, showing its block, timestamp and value.
The same transaction from the top, with its block and timestamp. Source: Etherscan, captured 1 September 2026.
Etherscan screenshot of the transaction sending 605.829 ETH from address 0x43c743e3 to the funding wallet 0x7a79969a on 22 March 2026.
605.829 ETH, 22 March 2026, from the wallet that deployed the attack contract. Source: Etherscan, captured 1 September 2026.
Etherscan header view of the 605.829 ETH transaction on 22 March 2026, showing its block, timestamp and value.
And its counterpart, two days earlier. Source: Etherscan, captured 1 September 2026.

Who did what on BNB Smart Chain

Fact. Nine addresses carry the attack itself on that chain. Seven are keys that also exist on Ethereum, and two appear only on BSC, which we confirmed by reading each one’s Ethereum nonce: 0x564a…4591 and 0xf052…58aa are at zero there and have never sent an Ethereum transaction. Three more BSC-only addresses sit outside this table: the June 2025 rehearsal wallet, a second XVS wallet from December, and the attack contract. Roles and windows:

Address Nonce Role on BNB Smart Chain
0x7a79…f234 61 the hub’s own key. Buys XVS and THE, seeds the others
0x16f0…bf07 605 600 micro-swaps; donates 1.25m THE
0xa212…3a7f 1,328 buys THE, then draws 900,000 CAKE on the position wallet’s account
0x564a…4591 3,338 3,283 micro-swaps; donates 3.92m THE in the attack
0x89e3…ddb6 4,263 4,198 micro-swaps; donates 9.47m THE
0xbb37…ef87 18,720 micro-swaps at volume; donates 7.53m THE
0xf052…58aa 33,991 micro-swaps at volume; donates 13.22m THE
0x1a35…6231 208 the position wallet. Holds the collateral, liquidated 8,039 times
0x43c7…2f82 90 the attack operator. Active 7 to 21 March only

The nonce column is each account’s transaction count read live from a BNB Smart Chain node on 1 September 2026, which is the authoritative figure. Two further addresses belong to the operation but are not the cluster’s Ethereum keys: a rehearsal wallet used in June 2025 and a second XVS wallet from December, both BSC-only. The attack contract itself sent 55 transactions.

The swap counts in this section are floors, not totals. BscScan’s transaction lists stop at 10,000 rows, and two of these accounts are well past that, so every “micro-swaps” figure below is a lower bound.

Nine months of preparation, and a rehearsal in the first week

Fact. Within a week of the very first Tornado withdrawal in June 2025, borrowed stablecoins were arriving on BNB Smart Chain at the cluster’s own keys. Four addresses bought about 8m THE, the token of the Thena exchange, and supplied 7.97m of it to Venus between 13 and 15 June 2025.

Alongside it the funding wallet bought 63,916 XVS, which is Venus’s own governance token, and handed it to a BSC-only wallet. That wallet supplied the XVS to Venus as collateral, borrowed 80,000 USDC and 120,000 USDT against it, and forwarded them to the position wallet on 13 June 2025. That was the position wallet’s first funding.

Inference. A small borrow-against-collateral exercise on the exact protocol that would be attacked, nine months early, is a rehearsal. It is the same shape as the Cronos function test in section 4: learn the machinery at trivial size, then return at scale.

Fact. From December 2025 to February 2026 the second and third Tornado batches went into Aave, and the borrowed USDT and DAI crossed to BSC in $100,000 pieces. There the cluster bought THE in a stream of roughly 30,000 micro-swaps through Thena’s WBNB/THE pool, each buying a few hundred to a few thousand tokens. The visible purchases total at least 39.7m THE, and the real figure is higher because two of the transaction lists are truncated at 10,000 rows.

Inference, and this is the craft of it. The clip size is the point, not the count. Buying tens of millions of a thin token in hundred-dollar pieces over nine months moves its price far less than block trades would. It kept the collateral cheap right up to the day the operator needed it expensive.

On 21 January 2026 three of the buying addresses transferred their vTHE holdings into the position wallet, concentrating the collateral in one account.

15 March 2026, minute by minute

The mechanism. Venus caps how much THE its market will accept, and enforces that cap when tokens are deposited through the normal path. But the market calculates its exchange rate from the contract’s raw token balance. So tokens sent directly to the contract, bypassing the deposit function, raise the value of every share already issued without touching the cap. The operator held the shares.

Timeline chart of 15 March 2026 in UTC showing five parallel tracks: a single rehearsal loop by 0x1a35 at 04:59, then from 11:55 the deployment of the attack contract by 0x43c7, 48 loop calls on that contract between 11:55 and 12:30, 49 borrow-and-swap calls by 0x1a35 between 11:55 and 12:45, 603 liquidations of the contract's account from 12:04 to 12:42, and 8,039 liquidations of 0x1a35's account from 12:42 to 13:26.
The whole attack, five tracks, ninety minutes. The single mark at 04:59 is a rehearsal run of one loop at trivial size, seven hours before the real thing.
Time (UTC) What happened
04:59 to 05:01 one rehearsal pass: borrow 1 BNB, wrap, buy THE, deposit
11:55:11 the position wallet approves THE and updates its Venus delegate
11:55:18 the attack contract is deployed, and its constructor fires
11:55:28 to 12:30 48 loop calls on the contract by the operator wallet
11:55:41 to 12:45 in parallel, 49 borrow-and-donate loops by the position wallet
12:04:40 to 12:42 603 liquidations strip the contract’s account
12:42:34 to 13:26 8,039 liquidations strip the position wallet

The constructor is the attack. In the deployment transaction itself, the contract pulled 36,096,716 THE from six cluster addresses and sent it straight into the market, then borrowed against the inflated rate. The six addresses had approved the contract before it existed, which is possible because a contract’s address can be computed from its deployer’s nonce in advance.

BscScan screenshot of the attack transaction showing tokens pulled from six addresses and transferred into the vTHE contract in a single transaction on 15 March 2026.
The donation, inside the deployment transaction. Six addresses, 36,096,716 THE, one transaction. Source: BscScan, captured 1 September 2026 in a narrow browser window, so the page renders in mobile layout.
BscScan contract page for 0x737bc98f carrying the public name tag Venus Exploiter 1 and a Blockaid security warning.
BscScan's own label on the contract. The tag is theirs, not ours. Source: BscScan, captured 1 September 2026.
BscScan header view of the attack transaction 0x4f477e94 on 15 March 2026 at 11:55:18 UTC, showing a contract creation.
The transaction itself. A contract creation, and the donation happens inside the constructor. Source: BscScan, captured 1 September 2026.
BscScan screenshot showing the creator of contract 0x737bc98f is address 0x43c743e3.
The deployer. `0x43c743e3` is the same wallet that seven days later sent 605.829 ETH to the funding wallet. Source: BscScan, captured 1 September 2026.

Then it ran in a loop. The contract borrowed CAKE, sold it for wrapped BNB, bought THE with the proceeds, and pushed the THE back into the market to raise the rate again. Forty-eight times. In parallel the position wallet borrowed BNB and did the same, forty-nine times, with the swap’s recipient set to the market contract so the purchase landed as a donation directly.

BscScan screenshot of one of the 48 loop calls, method 0x91f38bff, sent by 0x43c743e3 to the attack contract.
One turn of the loop. The same method, forty-eight times, over thirty-five minutes. Source: BscScan, captured 1 September 2026.
BscScan token-transfer view of one loop call, showing CAKE borrowed from Venus being sold into the PancakeSwap CAKE to wrapped BNB pair.
Inside one loop: borrowed CAKE goes out, wrapped BNB comes back. Source: BscScan, captured 1 September 2026.
BscScan token-transfer view showing the Thena pair returning THE tokens to the attack contract within the same loop call.
And the other half of the same loop: the wrapped BNB buys THE, which goes straight back into the market. Source: BscScan, captured 1 September 2026.

The liquidators arrived within nine minutes. From 12:04 the contract’s account was seized in 603 separate transactions; from 12:42 the position wallet’s account was seized 8,039 times. The price of THE had gone from about $0.26 to about $0.51 on the way up and fell back through $0.22 as the collateral was sold off.

BscScan overview page for address 0x1a35bD28 on BNB Smart Chain, showing its transaction history and the liquidation activity.
The position wallet on BNB Smart Chain, where its real life is. Source: BscScan, captured 1 September 2026.

How big the position got. Venus’s own post-mortem puts the collateral at 53.2 million THE at its peak. BlockSec gives the same figure, and Halborn puts it at 53.23 million, which it notes is 367 per cent of the market’s 14.5 million supply cap. Those three agree, and they are the figures to use.

Venus was left with about $2.15m of bad debt. It paused THE borrowing and withdrawals, and paused several other markets as a precaution.

Getting the money out, and back to the mixer

Fact. What the operator kept was what it had borrowed and never repaid: CAKE, BTCB, wrapped BNB and BNB, worth roughly $5.05m. Three days later the attack operator called the contract three times to release its balances to itself, opening with a 1 WBNB test before taking 1,971.5 WBNB and 16,093 CAKE.

BscScan screenshot of the attack contract releasing wrapped BNB to address 0x43c743e3 on 18 March 2026.
Emptying the contract, 18 March. A single-token test first, then the balance. The same habit as every other hop in this case. Source: BscScan, captured 1 September 2026.

Fact. The proceeds went back to Ethereum through Relay. Counted on the Ethereum side, where every leg has a hash we can read, the two wallets received 2,340.327 ETH in 46 Relay transfers: 1,747.107 ETH in 39 payments from the Relay solver 0xf70da978, and 593.220 ETH in seven internal transfers from Relay Router V3 0xb92fe925. A further 8.529 ETH arrived in 13 small transfers, of 0.010 to 3.773 ETH, from 13 other addresses. One of those 13 is the gas hop 0x16f0…bF07 from section 7, paying the 0.049 ETH that brought the consolidation wallet to life.

A count to discard before you reproduce ours. Both wallets also received 13 transfers carrying 0.00000022 ETH between them, from five addresses whose first and last characters copy the funding wallet’s. That is address poisoning: spam sent so a careless operator copies the wrong address out of their transaction history. It is aimed at the cluster rather than sent by it, and we exclude it. Anyone summing the raw transfer list will count 26 non-Relay inflows where we count 13.

That is 2,348.857 ETH in total, and it is the whole of what either wallet ever received. Both then emptied themselves in a single transaction each:

Wallet Total received Sent to the funding wallet Left behind
0x43c7…2f82 605.829069 ETH 605.829 ETH, 22 March 0.000069 ETH
0x1A35…16231 1,743.027643 ETH 1,743.027 ETH, 24 March 0.000643 ETH
Both 2,348.856712 ETH 2,348.856 ETH 0.000712 ETH

Neither wallet held a balance before the Venus attack and neither held one after. They exist to carry that money from the bridge to the funding wallet, and the sums reconcile to the milli-ETH in both directions.

BscScan screenshot of a Relay bridge transfer sent from address 0x1a35bD28 through the Relay approval proxy on BNB Smart Chain.
One of the Relay legs carrying the proceeds off BNB Smart Chain. Source: BscScan, captured 1 September 2026.
BscScan screenshot of a Relay bridge transfer moving 50,000 CAKE from BNB Smart Chain to Ethereum.
CAKE leaving for Ethereum. Legs like this one landed as 2,340.327 ETH on the Ethereum side. Source: BscScan, captured 1 September 2026.
Etherscan screenshot of a USDT repayment to Aave from the funding wallet on 15 June 2026.
Closing the book. The Aave stablecoin debt is repaid on 14 and 15 June 2026. Source: Etherscan, captured 1 September 2026.
Etherscan screenshot of a withdrawal of 1,834 ETH from Aave by the funding wallet on 15 June 2026.
And the collateral comes back out. The next day the wallet put 2,575.5 ETH into Tornado and stopped. Source: Etherscan, captured 1 September 2026.

From there the trail rejoins the one this document has already set out: 2,300 ETH back into Tornado through the April wallet on 21 April, the Aave position unwound in June, and 2,575.5 ETH back into Tornado on 15 and 16 June.

Seventy-four days after that, the Cronos position opened.

What this changes

The investigation began as the funding trail behind one exploit. It is not that.

The two attacks share funding infrastructure, and the method repeats. Buy a thin collateral asset patiently over months. Rehearse the protocol’s machinery at trivial cost. Break the accounting on the day. Keep what was borrowed. Bridge out, wash, repeat. Venus in March on BNB Smart Chain; Tectonic in August on Cronos. The Cronos depth probe in section 4, which bought $1,180 of price-impact readings on a thin token, is the same first move as nine months of micro-buying THE.

One caution we are keeping. Everything above establishes that the Venus attacker’s proceeds funded the wallet that funded the Cronos stake. It does not establish that one person did both. The volume evidence in section 8, tens of thousands of BSC transactions, is equally consistent with a service that several customers use. Nothing on chain separates those two readings, and we are not going to pretend otherwise.


11. Where the money is now

Fact. Four Ethereum wallets received what escaped before the halt.

ETH Address State on 1 September
2,452.115261 0xc404160b79bd8905061a1caecbeca2eeab3f72dd moving
670.625462 0xfDb11781ee3818135eebd2acd2247C263e266652 unmoved
19.869463 0x86616cE5D1829Beb030742e65bD3C1fbEE8F082E unmoved
73.734618 0x9ea6b75940de7c57bd1827001536e33ed667b55d converted 31 August

Fact. The fourth of those is the one the gas dispenser in section 4 pays. At 17:42:47 on 31 August 0x9E2CFB82… sent it gas, and thirty-six seconds later, at 17:43:23 and again at 17:46:11, that wallet converted 182,178.22 USDC into 73.734618 ETH. Its USDC balance is now zero. A wallet that had sat still since the halt moved within half a minute of being funded, which is what a dispenser is for.

The largest of the four started moving while this document was being written, and it has not stopped. What follows was read at 02:00 on 1 September 2026 and is the most perishable material here.

Fact. The money has moved three hops in under two hours, and the same signature appears at every one: a small test transfer, then the real amounts.

Hop one. At 23:55:59 on 31 August the escape wallet sent 0.1 ETH, waited two minutes, then at 23:57:59 sent 140 ETH, both to 0x6df89c42f0abdfaa2b5b77edcdafbc945ed6ee6c.

0x8f33074e3109ea245e08f4b0234a5e94b06b343a8845221ac3cdde4d592f96a6 0x5a0cb654b9a462fe2d36a839d8c53873e84fc815c16536cd7172329cbe9d4e3b

Hop two. Between 01:06:23 and 01:12:11 on 1 September that address forwarded 58.199 ETH to 0x7560e936a6978ad4ecda6b395f4c7d1c65f8a595, in five transfers: 0.1, then 10, 20, 20 and 8.099. It kept the rest. Its nonce is 5 and it still holds 81.900879 ETH.

Hop three. Between 01:25:35 and 01:42:23 the receiving address sent 58.166807 ETH onward in five transfers, again opening with 0.1, and emptied itself down to 0.032 ETH. The destination is 0x4cd00e387622c35bddb9b4c962c136462338bc31.

That address is the Relay bridge depository. It is the same contract the funding wallet’s own depository, used 22 times during 2025 and 2026; section 8 counts 23 because it includes one call to Relay’s receiver contract. The money is leaving Ethereum by the route this operation has always used.

Stage Amount State
Sent from the escape wallet 140.100000 ETH done
Held at the first staging address 81.900879 ETH waiting
Bridged out through Relay 58.166807 ETH gone

Inference. A test transfer before each real one, repeated at three separate hops within two hours, reads as someone confirming control of each address before committing to it. The 81.9 ETH still sitting at the first staging address is the next tranche rather than a remainder, on the same reading. The escape wallet itself still holds 2,452.115261 ETH at nonce 42, so on the evidence of the last two hours this is the opening of a cash-out and not the whole of it.

And they are being poisoned as they do it. From 00:01:59 on 1 September, four minutes after the first real transfer, fake tokens calling themselves ETH began arriving from 0x6df8c0e7…ee6c, 0x6df8fc38…ee6c and 0x6df8c006…ee6c. Those copy the destination’s first four and last four characters, and the fake transfers copy both the 0.1 and the 140 amounts, so a history read at a glance shows the wrong address beside the right numbers. The same happened again one hop later, against the 7560…a595 pattern.

Inference. The test send and the real send went to the same address at every hop, and every lookalike arrived after both, so each destination was chosen rather than fallen into.

A note for anyone checking our work. Address poisoning is thick around this cluster and it will catch a careless reader. Six lookalikes of the April wallet exist: 0xa2123cae…3a7f, 0xa2125b59…3a7f, 0xa212481c…3a7f, 0xa2126daf…3a7f, 0xa21f638a…3a7f and 0xa21fdc71…3a7f. The real one is 0xa212417f73f4d1a4178ee7c3b1412e3c12f23a7f. Compare all 40 characters, every time.


12. What would settle the questions we could not

The on-chain record has been read as far as it goes. What remains is off-chain, and each item exists precisely because the operator avoided intermediaries that would have hidden it.

RPC and front-end telemetry. Self-relaying means the operator’s own browser or script signed 83 transactions and broadcast them through an RPC provider, and built proofs against a pool history it had to fetch from somewhere. Whichever endpoint served those requests may hold network telemetry for 6 June 2025 04:01 UTC and 82 other slots, plus the two dozen sync events in section 5. A self-hosted node, several rotating providers, or a VPN would each blunt that, and nothing on chain says which applies.

Bridge counterparties. Relay, Symbiosis, Stargate, Across and LI.FI each hold destination-chain records. The March 2026 Relay inflows have an originating chain and address, and solver fills can be matched to the source deposit.

Commercial demixing. Chainalysis, TRM and Elliptic run Tornado heuristics over full-chain clustering and hold attributions from exchange and law-enforcement channels that are not public. If BitoPro’s notes have been assigned to withdrawal addresses in those tools, this wallet either appears in that set or it does not.

Off-ramps. The stablecoins bridged out in $100,000 to $1m pieces end at exchanges or desks on other chains. Those are the accounts a subpoena reaches.

One question on this list has since been answered, and it is worth saying how, because the method is reusable and cost nothing. The full set of methods, with the failures, is in the companion methods piece. The bridge records did it. Following the transfers forward, rather than trying to break the mixer backwards, produced section 10: the Venus attack, the nine months of preparation before it, and the return of the proceeds to the same wallet. None of that needed a single heuristic. The lesson generalises: when a mixer blocks the view backwards, the same operator’s forward trail is usually wide open.


13. Ruled out, with the test that did it

Recording failures is what makes the rest of a document like this worth reading.

Going further back than the funding wallet. Tested in section 5. The note-counting method that worked in April fails against a single note in a pool holding over a thousand.

The relayer as attribution. The address that relayed the origin withdrawal has sent 7,101 transactions and holds 15.62 ETH. It is a public service selling gas to anyone. It identifies nobody.

A $20m address-poisoning loss. An earlier reading of the wallet’s transfers suggested the operator had lost around $20m to lookalike addresses. That was wrong, and it is worth saying why, because the same trap catches everyone. The apparent transfers of 6m USDT, 3m DAI and 7.95m USDC were emitted by counterfeit token contracts that mint fake Transfer events naming the victim as sender. Filtered to the real token contracts, the three largest destinations return aEthUSDT, aEthUSDC and aEthDAI from their own symbol() call: they are Aave aToken contracts holding every depositor’s money, which is why they look like recipients that never spend. Every genuine large transfer went to an address the operator had first tested with a small send, and those addresses forwarded the funds on. There was no poisoning loss.

Paxos. Ruled out by a two-hop closure test. The intersection was empty.

The Rhino.fi figure. A claimed distribution of $5,073,411 to 36 wallets could not be checked either way. The BNB Smart Chain wallet in question holds 22,213.90 real USDT and has sent 39 transactions in its life; the transfer list that appeared to show the distribution is address-poisoning spam using a token called U5DT. We could not reconstruct its real history, because no free BNB Smart Chain endpoint serves it. Unresolved, and neither confirmed nor refuted.


14. Method, and the traps that cost us time

Anyone re-deriving this will hit the same walls we did.

There is no free archive state anywhere useful. Cronos public nodes serve about eleven days and the window slides forward. Ethereum’s free endpoints return “state is pruned”. BNB Smart Chain returns “missing trie node”. Plan around event logs, which are retained, not around historical balances, which are not.

eth_getLogs range caps produce false absences. Cronos caps ranges at 2,000 blocks, and a wider range errors in a way a naive parser reads as “no logs”. We caught this only because a running-balance reconciliation failed to add up. A query that returns nothing is not the same as a period in which nothing happened.

A PUSH4 regex over bytecode picks up strings. Byte 0x63 is both the PUSH4 opcode and ASCII c, so scanning for selectors finds string data too. In the attack contract that produced four false positives, which is why we say 44 plausible selectors rather than 48.

The obvious filter is itself lossy and we will not pretend otherwise. Discarding candidates whose four bytes are all printable ASCII also discards any genuine selector that happens to be four printable bytes. Opcode-aware disassembly is the correct tool and we did not run one, so treat every selector count here as approximate.

The absence list in section 3 is bounded differently, because it was not produced by enumeration at all. We hashed specific signatures and searched for those exact four bytes, so no string coincidence can hide a selector that is present. Its limit is the one stated there: it covers only signatures we thought to hash.

Filtering by value silently drops legs. An early pass over the wallet’s counterparties used a 50 ETH floor and lost Odos, LI.FI and Across entirely.

A token contract looks like a hoarding wallet. Always call symbol() on a destination before describing it as a recipient. Section 13 is that lesson.

A finding is evidence, not a verdict. In one earlier sweep of our own published work, five of sixteen reported errors were themselves wrong. Re-derive a second way before changing a published word.

Two checks that returned nothing, recorded anyway

The note-account leak does not exist here. Tornado’s optional note-account feature publishes encrypted notes as events from the depositor’s own address, which would link deposits to whoever holds that key. The contract recorded no transactions at all between January 2025 and June 2026. Nobody in this case used it.

The private-mempool question is open. If the 83 withdrawals had been broadcast through a private relay rather than the public mempool, that would be a rare and strong fingerprint, and the relay operator would hold the addresses. Etherscan’s static pages carry no marker for it, so this could not be settled with the tools available. It stays a question for a mempool-data provider.

Checking it without us

The live balances in this document, on both chains, are readable from our verification page, which queries public nodes from your browser rather than reporting our numbers back to you. It also gives the raw calls, so you can run them yourself against any node.

Reproducing the counts

Wallet history: the Etherscan address page, internal-transactions tab, 110 rows of which 83 are from the 100 ETH pool and 2 from the 0.1 ETH pool.

Withdraw decoding: the router input is withdraw(address,bytes,bytes32,bytes32,address,address,uint256,uint256); for all 83 calls the relayer field is the zero address and the fee is 0.

Pool events: Deposit topic 0xa945e51eec50ab98c161376f0db4cf2aeba3ec92755fe2fcd388bdbbb80ff196 and Withdrawal topic 0xe9e508bad6d4c3227e881ca19068f099da81b5164dd6d62b2eaf1e8bc6c34931 on the pool contract from block 21,525,000.

Anonymity set: eth_getBalance of the pool at blocks 21,525,890 and 22,643,039 on any archive node, divided by 100.


15. The register

Every address in this document, in one place.

Ethereum, funding

Address Role
0x7a79969a0B9D51D922C4810D2950560360F6f234 the funding wallet
0x5770c25edcc98cb9f2a2483690a99d5f80df704e second cash-out wallet
0xa212417f73f4d1a4178ee7c3b1412e3c12f23a7f April deposit wallet
0x871ab7d790Ae319279239d84C3f78fa896449b01 April withdrawal wallet
0xC0E272092e74688b31313c8e3d9846628Fd71508 key reused on Tron
0x1A59697a7c499f0144dfa1b100e24822f5e21638 key reused on Tron

Ethereum, preparation and escape

Address Role
0x9E2CFB823AdB9BD67a41C1845C0Dd70453D7D378 gas dispenser
0xc404160b79bd8905061a1caecbeca2eeab3f72dd escape wallet, now moving
0x6df89c42f0abdfaa2b5b77edcdafbc945ed6ee6c staging address, 140.1 ETH
0xfDb11781ee3818135eebd2acd2247C263e266652 escape wallet
0x86616cE5D1829Beb030742e65bD3C1fbEE8F082E escape wallet
0x9ea6b75940de7c57bd1827001536e33ed667b55d escape wallet, converted
0xbaA143E23285a7bBB4803cB023724e5c616547e2 fuelled 21 August, never used
0x0F8C0c8d5b9906F5e439c9a1086BF2f742fb7495 fuelled 21 August, never used
0x3b5a2d0D6050Aeae57EA20b17e2b0cA263356644 fuelled 21 August, never used

BNB Smart Chain, the Venus attack

Address Role
0x737bc98f1d34e19539c074b8ad1169d5d45da619 the attack contract, 19,865 bytes
0x1a35bd28efd46cfc46c2136f878777d69ae16231 the position wallet, liquidated 8,039 times
0x43c743e316f40d4511762eedf6f6d484f67b2f82 deployed the contract, ran 48 loop calls
0x564a073fa4cfa81c2c882168fa760a88b82a4591 buying wallet, BSC only
0xf052219f767612c411c9fe4a0f334237429c58aa buying wallet, BSC only
0x89e3615f356b3b40acb2f8598117eab1affdddb6 buying wallet, same key as on Ethereum
0xbb3782048735091ab4c304693a69371965a4ef87 buying wallet, same key as on Ethereum
0x16f09b91604053e742ee0408909bafa6a825bf07 gas and DAI hop, same key as on Ethereum

The Venus attack transaction is 0x4f477e941c12bbf32a58dc12db7bb0cb4d31d41ff25b2457e6af3c15d7f5663f.

Cronos

Address Role
0x7d4e7e5dcb0ccc66b4f0f8b0f30da5078ad4f2dc the stake wallet, $5,000,950
0x085f3115ca368aa262246d22f9476e1e2c87e8be the attack contract
0x4266a0e6a0f0ef90abcff3bb089932ca0cce3652 the operator
0x7ebe55588db070da035f9Bf5505d4fB880dA400a the depth probe
0xcdfba496180865a71266608ade6b21ab1f788888 funded the stake

Tron

Address Role
TZEJLhqXz2roiCgxxLbJV1i1LFyf5VZR8v the war chest, named in the memos
TYbiKCan1AZgNQioG64uB2zVDA7b26FRze the 15.6m TRX consolidation
TXtEs6t2oUWQsNos7m68gbHdE9Q5n6x2oN where it emptied, 29 August

Corrections to anything here are welcome and will be made in place, with the correction stated.

Sources

  1. Tornado Cash 100 ETH pool contract, Etherscanetherscan.io
  2. The funding wallet 0x7a79969a, Etherscanetherscan.io
  3. The April deposit wallet 0xa212417f, Etherscanetherscan.io
  4. The April withdrawal wallet 0x871ab7d7, Etherscanetherscan.io
  5. The second cluster wallet 0x5770c25e, Etherscanetherscan.io
  6. BitoPro Exploiter 2, Etherscan public labeletherscan.io
  7. Taiwanese crypto exchange BitoPro confirms estimated $11.5 million hack (Fortune)fortune.com
  8. THORChain developer documentation, transaction memosdev.thorchain.org
  9. THORChain developer documentation, memo length reduction, giving tr = TRON.TRXdev.thorchain.org
  10. NEAR Intents, published treasury addressesdocs.near-intents.org
  11. Tectonic documentation, money market parameterstectonic.gitbook.io
  12. Tectonic documentation, price oracletectonic.gitbook.io
  13. Cronos documentation, general FAQ on validators and consensusdocs.cronos.com
  14. Cronos Network, announcing the halt (30 August 2026)x.com
  15. Tectonic, incident acknowledgement (30 August 2026)x.com
  16. Aave developer documentationaave.com
  17. Venus Protocol, THE market incident post-mortem (the protocol's own account)community.venus.io
  18. BlockSec, Venus Thena (THE) incident analysisblocksec.com
  19. Halborn, Explained: the Venus Protocol hack (March 2026)halborn.com
  20. The Venus attack contract 0x737bc98f on BscScanbscscan.com
  21. The Venus position wallet 0x1a35bd28 on BscScanbscscan.com