
AMLBot
2K posts

AMLBot
@AMLBotHQ
Blockchain Intelligence at your fingertips. Crypto Tracing / AML Screening / Incident Response





Project @SwanTreasury was drained of ~$625K on BNB Chain due to a private key compromise The attacker used the compromised signer to buy ~687K STY at a 100x discount, then dumped the tokens for ~625K USDT. Funds were consolidated to a secondary EOA and bridged to Ethereum via Transit Finance ~345 ETH (~$649K) is now lying dormant at this address 0x57503a992fe99fd69cad9ef94ed7e26a2057cfd2 on Ethereum We are currently monitoring for movement








Good news! @cascade_xyz has recovered $1.22M of the $1.34M USDC drained in the July 15 exploit Tracing shows the stolen funds moved through several hops, including a bridge to Solana and back to Ethereum via Relay, before returning to Cascade's multisig. The attacker kept ~$120K as a bounty in exchange for returning the funds


Thank you to everyone for patiently waiting as we’ve sought to resolve the incident. The parties involved have cooperated with us and have returned the funds drained from CLS. The retrieved funds are available in this multisig address: 0x8074583b0f9cfa345405320119d4b6937c152304 All users who had funds in CLS will be able to get back 100% of their value as of July 15 at 21:08:00 UTC, immediately before the counterparty deposited their money onto the platform. A claim will be available within the coming few days.

AFX (@AFX_XYZ) on @arbitrum was exploited for ~$24.15M in USDC Attacker bridged the stolen funds to Ethereum via CCTP, then swapped to ~12.47k ETH through DEX Funds are currently held at 0x627654b2782bfc57580ecd11d40869b350b6ebac We are actively monitoring the address




AFX (@AFX_XYZ) on @arbitrum was exploited for ~$24.15M in USDC Attacker bridged the stolen funds to Ethereum via CCTP, then swapped to ~12.47k ETH through DEX Funds are currently held at 0x627654b2782bfc57580ecd11d40869b350b6ebac We are actively monitoring the address


We're aware of a report of a bridge hack on Arbitrum and are investigating. We can confirm that the transaction in question originated from a third party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way. We will coordinate with the third party team and will report more details when we have them.


The returned Verus bridge funds have now been converted back into the original currencies for reintegration into the Verus network. The Verus recovery address currently holds 1,194.86 ETH (73.51% recovered), 76.0321 tBTC (73.41% recovered), and 147,727.67 USDC (100% recovered as discussed in the community meetings). One issue we noticed is that some DEX interfaces have blocked the Verus return/recovery address. This address is not the attacker’s wallet. It is the community recovery address holding community funds. We ask @Uniswap (your compliance department has been notified, we are still waiting for a response) @1inch @blockaid_ to review and correct the classification of the Verus recovery address (0xF9AB28cB7b72B518e6a351FbdaBe69362cBC1A74). We ask the community to help by tagging relevant DEX interfaces, wallets, block explorers, and tracking services below, so the Verus recovery address is correctly recognized across the ecosystem. 0xF9AB28cB7b72B518e6a351FbdaBe69362cBC1A74


Protocol @Barn_Bridge was exploited for ~$776K in USDC ~776.6K USDC from the stolen funds was swapped for ETH, and 415 ETH was sent to 0x2c4c1848e22006d63eBb732B61EDc871AF30Ef16, where it is now lying dormant We are monitoring the related addresses and will post updates if funds move again

Protocol @42dao_official on #BSC was exploited for over $900K Tracing shows the stolen funds were consolidated, then bridged to Ethereum. The funds were then shielded through Railgun, cutting off further on-chain traceability



