13
@SpecterAnalyst
Specter
Skipped detailed analysis: Personal account of an onchain investigator/analyst, not a crypto project, protocol, or investable product.
AI Analysisneutral
Confidence
30%
Skipped detailed analysis: Personal account of an onchain investigator/analyst, not a crypto project, protocol, or investable product.
Recent tweetsSee all on 𝕏 →
It looks like the attacker has no intention of returning any funds to jaredfromsubway.
The attacker has now deposited $5.1M of the $7.5M stolen from jaredfromsubway into Tornado Cash.
A few hours ago, the attacker deposited 2,000 ETH into Tornado Cash in 20 X 100 ETH each, and swapped the remaining 1,422 ETH for $2.44M in DAI.
Stay smart.
Tether froze $72M of $120M USDT on TRON on June 12.
I traced the remaining $48M to current destination wallet
The key wallets TA6YHqB2xh5HhfmC7WoLQaWmqq7Vv4zCoQ TBzrPEsStbZAUx2SBhD4oHz8UW3FX9Ak9W
On June 11, the entity received $120.2M into TA6YHq, then moved $94.9M to TBzrPE. $72M was later frozen. The rest was distributed and bridged
here's where it went.
Received $6M
THnK9QocskTMW8WBn68bL9AT6hR7gvLBvX
This wallet received $6M directly from the two key wallets and deposited $5.7M to KuCoin nested service across 32+ transactions. The remaining $350K went to other exchanges.
An additional $1.5M was deposited to KuCoin nested service from wallets linked to the same entity:
TGEb9HyyiF8t1Samqf6aoqg8jSANoTLaWx TN3PNzcJPxDucscmSk1pHtaZkXUrL3PeB5 TFec9HsPDkLwLm2N5fjMKAJZeDiAHjq9b9
Received $12.5M
THPYzDXTurrum6pJmBLm9Ab9sL5rKNvART
$7.8M deposited to KuCoin nest service. ~$1M was used to place Monero orders, causing a price spike as reported by zachxbt .
The remaining was bridged to Ethereum:
0x4d0b6F1c67D2F84639879DA8d2988fc86F8162a0 0x5032C6eCdB0eCFC05CAEa8A003c44ba92C6CC011 0xC97fD1a1556e258044117bE6F60D4466aDca034C 0xBAA0a03A70b31Fb2F13CcB4eEeAc176bE6c1B8b9 0x8Ccb2b33313F4BAf6793cBD5EE7dDA7232EcF0Af
$2.5M USDD swap THacr2zmq484rqCdAPkvjQVSXRtmAQDjBG
Received $1M
THfrCTfQ9J9xiAiwGnAk7ShKJdfBAZPAJN
$600K bridged to Ethereum via Near Intent and deposited to Tornado Cash: 0xe0b7490A5Aa619935699C1d1807C8Ca6A65314D3
The key wallets deposited $4.7M to Instant exchanges for Bitcoin via 33 txs
The remaining funds were bridged to Bitcoin via Near Intent.
$500K went to Wasabi mixer bc1qrkrm9maue9zhh4p8vqsz3ts82f0wkdpalkzfz5
in total, $19.59M remains on Bitcoin network accross 24 wallet and
15M+ were directly deposited into Kucoin 👀
All key addresses and the Bitcoin addresses will be uploaded and link will be available below
While there is no public attribution yet, the combination of such a large amount of funds and getting blacklisted by Tether suggests the funds are likely tied to illicit activity.
Stay Smart
There may have been a $7M+ drain from a victim wallet.
It looks like it involves JaredFromSubway MEV.
If anyone can figure out what happened, kindly do.
Address: 0x3e37f4A10d771Ba9dE44b6d301410b1BEdeA65d0 https://t.co/YLP1p182sA
It’s been over a month since THORChain halted all trading due to an exploit.
This is the same protocol that couldn’t pause trading for just a few hours during other protocol exploits or laundering flows even simple ETH↔BTC routes.
Now, there is no trading at all across the chain on THORChain, when they were the victim 😊
Stay smart.
The UXLink attacker has returned depositing the stolen funds into Tornado Cash.
So far, the attacker has deposited $8.1M after swapping the funds from DAI into ETH.
100 ETH X 46
In total, the attacker has laundered approximately $19.1M of the stolen funds and is still holding around $16M.
Stay smart.
Signal Timeline
PA
@Paddy_Stash followed
Score breakdown0–100
🎯Scout quality
+17.5 / 25
📚Signal stack
0 / 30
🪪Profile
+12 / 15
✍️Content
+5 / 10
🤖AI verdict
+8 / 20
⚠️Penalties
-30 / 20
13
Below threshold (70)
Watching for additional signals.
Watching for additional signals.
Followers
13.3K
Account age
2.1y
Scouts
0
First seen
2mo ago