For investigators
Everything below is derived from public chain data and re-checked every minute. Each row carries the transaction hashes needed to verify it independently. Snapshot 2026-10-09 21:30 UTC.
Freeze targets
attacker-controlled wallets holding USDT now · csv · jsonNo freezable stablecoin is sitting in an attacker-controlled wallet right now ($10.0M is already frozen). The attacker has converted holdings to ETH and BTC. This list refreshes every minute and a FREEZABLE alert fires the moment USDT lands in a tracked wallet; subscribe below.
Exchange deposits
0 · csvNo direct deposit into an exchange-labelled address has been indexed yet.
Second-order exchange deposits
0 · csvWallets that are not the attacker but received stolen USDT (unlabelled high-volume counterparties, OTC-type, with a pre-theft history) and deposited to an exchange within 48 hours of receiving it. These are leads for the exchange, not proof that the account belongs to the thief.
None indexed.
Exports
Alerts
curl -X POST https://peel.watch/api/alerts \
-H 'content-type: application/json' \
-d '{"url":"https://your.endpoint/peel","types":["FREEZABLE","CEX","FROZEN","FINDING"]}'Event types: FREEZABLE (stablecoin landed in an attacker wallet), CEX (exchange deposit), FROZEN, MIXER, BRIDGE (decoded leg), WAKE (dormant wallet moved), FINDING.
How roles are assigned
- theft_address: the ten addresses disclosed on 9 Oct 2026 that received the victims' funds directly.
- attacker_controlled_hop: received ≥ $10k from a theft address or another hop, and is not labelled as a bridge, exchange, DEX or contract by MistTrack / Arkham (or is labelled as the drainer itself). Every hop has an evidence path.
- Venues are services that received funds; they are listed so their own teams can act, not as suspects.