Method
- Balances and transfers come from the chains directly: Esplora (Bitcoin), Etherscan + JSON-RPC (Ethereum), TronGrid (TRON). Refreshed every minute.
- Every outgoing transfer of $10k or more from an attacker-controlled wallet makes the destination a tracked hop, until it reaches a wallet that MistTrack or Arkham label as a bridge, exchange, DEX or contract. Wallets labelled as the drainer itself are followed, not treated as venues.
- "Drained" counts only transfers from unlabelled wallets into the ten theft addresses disclosed on 9 Oct 2026. Swap desks paying the attacker are excluded.
- USDT0 (LayerZero) bridge exits are decoded from calldata: destination chain and recipient. Recipients on Ethereum are tracked automatically. Other bridges set the destination off-chain and are shown as exits only.
- Freeze status is read from Tether's isBlackListed on TRON and Ethereum for every tracked wallet.
- Tornado Cash: deposits by tracked wallets are counted per pool; withdrawals from the same pool since the first deposit are listed, with recipients that are brand-new wallets flagged. This is timing, not attribution.
- Attribution sources, in order of weight: the transaction path from a theft address (every hop a hash), provider attribution (Arkham's entity "CryptoBillis Ledger Drainer", MistTrack labels), and our own rule for fresh wallets (received ≥ $10k from an attacker wallet, no life before 2 Oct 2026). Wallets with a life before the operation are counterparties the attacker paid, never "the attacker".
- Findings are published by an analyst agent (LLM with tools over this data, MistTrack and Arkham) only when it has verified evidence; every finding carries the hashes.
- Venues listed under "where it went" received funds. They did not steal them. Nothing here is legal or financial advice.
What is filtered out
- Spoofed tokens. Only canonical contracts (USDT, USDC, DAI, WETH, WBTC, PEPE on Ethereum; USDT, USDD on TRON) are indexed. Fake tokens named "ETH" or "USDT", the staple of address-poisoning spam, are dropped before they reach the database.
- Zero-value and dust transfers. Zero-value calls, and inbound amounts under $50, are ignored. Lookalike addresses spraying dust at victims or at the attacker never become nodes.
- Inbound money never creates an attacker. A wallet is attacker-controlled only if it received ≥ $10k from a tracked attacker wallet, or is labelled as the drainer. A wallet that merely sent money into a hop is recorded as "unknown", visible, and not counted.
- High-volume counterparties. Any wallet moving 400+ transfers in a window is treated as a service, not a hop, even without a label.
- Balance alerts are double-read. A large drop in a wallet's balance is re-read directly before a "funds leaving" alert fires; a partial or empty API answer is never treated as zero.
- Findings are verified before publishing. Every transaction hash in a finding must exist in our index or on the chain itself, every address must be a known wallet or a party to a verified transaction, and a finding needs at least two verified items. Anything that fails stays unpublished.
- No attribution through mixers. Tornado Cash deposits by tracked wallets are listed with hashes. Withdrawals are not shown, because linking them is guesswork.