1/ 🎉 On Nov 21, 2025, at the #HKICT Awards in Hong Kong, SlowMist’s blockchain AML tracking system @MistTrack_io won the Gold Award in the FinTech (RegTech: Regulatory and Risk Management)! 🏆
📸 SlowMist Partner & CPO——Keywolf joined government, regulators & industry leaders to witness this milestone.
HKICT Awards, established in 2006, is one of Hong Kong’s most recognized tech awards, organized by the Gov Digital Policy Office.🇭🇰
We have blacklisted and are monitoring the related addresses, and will work with the community to combat money laundering activities.🧐
https://t.co/XUbyh71qH0
Integrating diverse data sources is key to breaking silos and improving risk visibility across the ecosystem.
Looking forward to helping build a more transparent and compliant environment together 🤝🛡️
#KYT#AML#SlowMist
🤝 𝗧𝗵𝗲 𝗣𝗼𝘄𝗲𝗿 𝗼𝗳 𝟯: 𝗠𝘂𝗹𝘁𝗶-𝗩𝗲𝗻𝗱𝗼𝗿 𝗦𝗰𝗿𝗲𝗲𝗻𝗶𝗻𝗴
Why rely on a single data source? We’ve integrated the industry's best: @chainalysis@elliptic@MistTrack_io
Cross-reference data from all three, delivering the most accurate risk tags and breaking data silos. 🎯
#AML #KYT #KYA #DigitalAsset #Security
Ready to empower your #AI Agents with on-chain security? Use MistTrack Skills today and start building safer, smarter workflows.
👉 https://t.co/zGqhbFEU5i
🚨 MistTrack Skills Released|Empowering AI Agents with On-Chain AML Risk Analysis Capabilities.
⚠️ How can AI systems develop sound security judgment when executing on-chain transactions, analyzing crypto addresses, or handling digital assets?
In response, SlowMist has released MistTrack Skills — an AI Agent skill package built on the @MistTrack_io OpenAPI (indexing 400M+ addresses) for automated address risk analysis and AML compliance.
👉 https://t.co/6pyfkfEsUX
It enables AI Agents to:
🔹 Perform address and transaction risk scoring
🔹 Retrieve entity labels and behavioral profiles
🔹 Trace fund flows (inbound/outbound)
🔹 Analyze counterparties
🔹 Detect DEX / Exchange / Mixer exposure ratios
🔹 Run asynchronous deep-risk tasks
🌍 Supporting major blockchains including #Bitcoin, #Ethereum, #TRON, #Solana, #Toncoin and more.
MistTrack Skills integrates with leading AI Agent tools such as #OpenClaw and #ClaudeCode and works alongside wallet skills (like @BitgetWallet or @TrustWallet) to ensure AML screening becomes a background process, automatically triggered before any transfer is finalized.
⚠️ Why It Matters: MistTrack Skills makes address-level security a default feature, protecting your assets from sanctioned entities and hacker wallets.
🛠️ How to Use MistTrack Skills?
1️⃣ Installation: npx skills add slowmist/misttrack-skills
2️⃣ Set the environment variable (recommended): export MISTTRACK_API_KEY=your_api_key_here
3️⃣ See SKILL[.]md for full API documentation: https://t.co/dzRMBXxvjC
✨Once configured, your AI Agent can handle prompts like:
"Check the risk score for this ETH address."
"Analyze the fund origins of this BTC wallet."
"Is this transaction safe to execute?"
Ready to empower your #AI Agents with on-chain security? Use MistTrack Skills today and start building safer, smarter workflows.
🔗 Read the full technical breakdown and integration guide:
https://t.co/KcCljB8Z8Z
🚨 MistTrack Alert 🧐
The hacker behind the 2023 ~$200M exploit of #Mixin (0x52E86988bd07447C596e9B0C7765F8500113104c) became active again ~16 hours ago.
So far:
👉 2,005 $ETH sent to 0x9cba859288fa0b4ec43ebb90bb64a9dbbddc787f;
👉 That address subsequently routed 2,000 $ETH into #TornadoCash.
The hacker 0x52E8 still holds 57,802 $ETH (~$113M).
🔗https://t.co/gHjdr8xUaI
🚨 MistTrack Alert 👀
The attacker behind the #Upbit hack (~$36M loss) —
0x93A0649e62C7E3AE8F7Eec14F6674aa6b554f904 — is actively moving funds to Tornado Cash.
So far, 1,400 $ETH has been transferred. We are continuously monitoring the activity.
https://t.co/WJi2PfR8kt
🍻In Q4, MistTrack Team assisted 9 victims in successfully freezing or recovering approximately USD 1 million in stolen assets.🎉
If you’ve fallen victim to cryptocurrency theft, we provide a free case assessment for stolen/scammed funds👇
https://t.co/iKEjWLSVTK
Stay secure. Stay vigilant.🔒
🚨 SlowMist: 2025 Q4 MistTrack Stolen Funds Analysis
1/ Since opening the @MistTrack_io fund-recovery submission feature, we continue to receive hundreds of theft reports each quarter from affected users worldwide.
In Q4 2025:
🔹 300 stolen fund reports received ((Don't cover those reported via other channels)
🔹 ~$1M frozen or recovered across 9 successful cases
This is why we publish quarterly analysis — to transform real theft cases into actionable awareness for #Web3 users.
🔗 Full analysis:
https://t.co/yvtS6KBAbg
🚨 WARNING (AGAIN)
DPRK threat actors are still rekting way too many of you via their fake Zoom / fake Teams meets.
They're taking over your Telegrams -> using them to rekt all your friends.
They've stolen over $300m via this method already.
Read this. Stop the cycle. 🙏
🚨Beware of Solana #Phishing Attacks: Wallet Owner Permissions Can Be Altered
1️⃣Recently, we assisted a victim of a phishing attack that resulted in the unauthorized transfer of his account’s Owner permission. This is similar to the "malicious multisig" –style attack commonly seen on #TRON.
The victim lost over $3M in assets. Another $2M locked in DeFi protocols was inaccessible — though fortunately, this portion has now been successfully recovered with help from the relevant #DeFi teams.👏
2️⃣How the #Solana Owner Modification Works🔐
The attacker exploited two counter-intuitive behaviors:
🔹No visible balance change during signing: Wallets typically simulate transactions and show balance effects. The attacker crafted a transaction with no visible changes, lowering suspicion.
🔹Users don’t intuitively expect ownership to be changeable: Unlike Ethereum EOAs, Solana accounts allow their Owner field to be reassigned, which many users don’t realize.
3️⃣Understanding Solana Account Ownership🧩
Solana accounts fall into two major types:
🔹Normal Accounts
🔹PDA (Program-Derived Accounts)
Token accounts also use their own ownership rules enforced by the token program, which are frequently targeted in phishing campaigns.
4️⃣MistTrack Tracing🕵️
Our @MistTrack_io analysis of the attacker’s address revealed highly complex fund movements. Assets were routed primarily through two hubs:
🔹BaBcXD…
🔹7pSj1R…
The laundering pattern included:
• rapid multi-address hops
• multi-platform mixing
• cross-chain cycling
• CEX deposits
• reuse of DeFi assets
5️⃣How to Protect Yourself from Similar Attacks🛡️
This incident ultimately stems from phishing. Attackers use fake:
✨ airdrops
✨ quests
✨ whitelist invites
✨ announcements
✨ reward claims
These links trigger signature requests containing high-risk operations like Owner reassignment.
Before clicking or signing, always ask:
🔹 Is the source legitimate?
🔹 Is this really from the official team?
🔹 What exactly is this signature doing?
🔹 Are there unfamiliar permissions or unknown addresses?
If you don’t understand the permission request — STOP! Never sign out of uncertainty‼️
6️⃣Best Practices to Reduce Risk🧊
✔️Use a low-value wallet for interactions, quests, and airdrop hunting.
✔️Keep high-value assets isolated — ideally in cold storage.
✔️Avoid granting unlimited approvals; limit allowances whenever possible.
✔️Always verify URLs and signature prompts.
✔️Never approve operations that seem unrelated to what you intended to do.
Your strongest defense is simple:
⛔Don’t click blindly. Don’t sign blindly.
🔗Details: https://t.co/3ljUts50oI
🚨MistTrack Fund Flow Analysis — @yearnfi Exploit🕵️
1️⃣The exploiter made roughly $9M from this incident. The initial seed funds came from a small amount of ETH sent via #Railgun.
🔗Tx: https://t.co/3j2j5jER5m
2️⃣After launching the attack, the exploiter funneled 1,100 $ETH into Tornado Cash, later withdrawing 100 ETH to continue the operation.
🔗Tx: https://t.co/iAhRlxxGbg
3️⃣The remaining profit — around $6M, consisting of 128 $ETH, 48.96 $cbETH, 203.55 $rETH, 742.63 $frxETH, 857.48 $pxETH, and 167.67 $stETH — was then consolidated into: 0xa80d3f2022f6bfd0b260bf16d72cad025440c822
🔗Tx: https://t.co/PENqNlzGdo
4️⃣To prep for batch operations, the exploiter first executed a 7702 delegate call to 0x1A1Efc...
🔗Tx: https://t.co/R7JwT0GkhF
5️⃣Then came a major consolidation step:
All cbETH, rETH, frxETH, and stETH were swapped in a single transaction into 1,184.9 WETH.
🔗Tx: https://t.co/oYzg4v1aBN
6️⃣The exploiter then attempted to convert the 1,184.9 $WETH → $ETH and batch-deposit it into Tornado Cash — but the transaction failed ❌
🔗Tx: https://t.co/ndmKrg0y2o
7️⃣A key twist: Yearn successfully recovered ~$2.4M by burning the exploiter’s 857.48 $pxETH, later re-minting it and returning it to the Redacted Cartel multisig. 🛠️
🔗Tx: https://t.co/IqSEDGEOaq
As of now, the exploiter’s address still holds 1,184.9 WETH and 128 ETH. We’ll continue to monitor the movements 👀
🚨On Dec 1, @yearnfi was exploited, resulting in ~$9M in losses.
🛠️The SlowMist security team analyzed the incident and identified the root cause:👇
The vulnerability stems from the logic inside the _calc_supply function used to calculate supply in Yearn’s yETH Weighted Stableswap Pool contract. Due to unsafe mathematical operations, the function allows overflow and rounding during calculation. This flaw leads to a significant deviation when computing the product of the new supply and virtual balance, enabling attackers to manipulate liquidity to specific values and mint an excessive supply of LP tokens, thereby profiting illicitly.
🔍We recommend strengthened edge-case testing and the use of secure, validated arithmetic operations to prevent severe vulnerabilities like overflow in similar protocols.
Full analysis👉 https://t.co/aVzCpSc65n
🚀MistTrack has upgraded the onboarding experience for institutional users!
Organizations can now create new accounts for themselves and their team members using just an email + verification code — no password needed. Register and Login instantly for a smoother, faster workflow.📊
🔍Start tracking smarter with MistTrack: https://t.co/35HJ4rGQws
🚨MistTrack Alert🚨
.@DoodiPals has been compromised — the hacker swapped $DOODi tokens for $SOL, making a profit of 917 SOL so far.
The stolen funds have since been transferred to multiple FixedFloat addresses.
MistTrack is monitoring the flow.
Circle recently implemented a precautionary freeze on 4 EVM addresses.
Intelligence indicates that the funds in these addresses originated from a Coinbase-related theft, during which the attacker profited significantly by purchasing $ETH.
According to @zachxbt@MistTrack_io
⚠️ MistTrack Alert ⚠️
WOO X Exploiter began transferring stolen funds after being silent for more than two months.
https://t.co/GfIlyjUjWw
#MistTrack#cryptocurrency#security
🚨SlowMist: 2025 Q3 MistTrack Stolen Funds Analysis
1/ Since launching the @MistTrack_io stolen fund report submission feature, we’ve received hundreds of cases every quarter from victims seeking help with fund tracing & recovery — some involving losses in the tens of millions.
In Q3 2025 alone:
🔹317 stolen fund reports submitted (Don't cover those reported via other channels.
🔹$3.73M in assets sccessfully frozen or recovered across 10 cases
This is why we published quarterly reports: to share insights from real-world incident, dissect attack methods, and raise awareness in the Web3 community.
🔗https://t.co/6gciGkRsfh
Proud to join the @Blockchair dApp Gallery! 🎉
MistTrack now helps users identify entities, exchanges & wallets on address pages across 17 chains.
🔎 300M+ labeled addresses
⚡ Seamless counterparty insights
Explore now 👉 https://t.co/gzqAGW43h4
Big news! @SlowMist_Team’s MistTrack is live on Blockchair dApp Gallery!
Identify address entities and counterparties directly on address pages across 17 chains. Access 300M+ labeled addresses to understand exchanges, wallets, and transaction relationships.
Check it out today!
🚨MistTrack Alert:
@tether has just frozen a total of 4.35M $USDT across 25 addresses, with the largest amount being $1.75M USDT:
0xe4fac553502745c3d5a6558304deccaa05014583
TCNTdakbmgSZasagGy7iBtB3awRs9uJya6
TBs6XaWFepJ5gK2bt5NZHZPKdRtAFLvbhE
TCa7AhDFMKNhvQqp13jhUtTtRopr3WAGQr
TDHNbkZ8mdjKmHHiZtfiY7tyQAfko1Tm4x
TE2D2wovKPenDnsTatLB87kZWhHNNJdVTM
TFRXgsmSFGWa4uzaxR2SM56mE7fB745vMR
TFSDHbG9jq1AmtPCvsAbNRbuReMcCNyfFA
TGJqKXetZMs3HNTdnFDYNob3A9jFewQoJH
THrFd9dm9ioJe8b7aEfuwLntcgiryH4sx5
TJ8uNRcDwM7Jz8Fzhbb4JsNrHeiE457bU7
TKD22Cs5fdgcVUdQU1N8dD1D4YQEcd9Lyn
TPgbMcS5sPWgZXosVqzvkQdzG8x1gR3MDh
TPy8oBgpGmWsL2167nb68YsuM3H5XRVizU
TQHMK8yo9ZRYJzg574qMZxeBmo4X17qWou
TRqYtKRg8kLUiyFF2AxCHhtooTCYNXFk1N
TRr4WPT4FSYS2eHpuZHxEdgNrMnoxt6Nra
TSM6TZZKUftEqRxfGWMBaShTQZL6Qp3NvU
TSyETeTEJmwPj6BChTSfdr6iwFBQxPtF7q
TUNZfgrkygJvYEEcP9Rv6P2MpEC5jVJPFf
TVaHjN7mNE9C4f1rsZk65gTABeMBLCAX81
TWb3Wh4a7dWUwk2VRd3AfdRcAHhXC2MyWa
TX47ZBMhiuMfwLVXRXjajgDFuocyTFL86Z
TMk5ji4vTGZG8E1RnKEYvaK6kgNobLSTtE
TTozbiknXuBHri6cBLgtwPQXvAXK9wUS1y
🔗https://t.co/oYd1N92IO9
🤝 Since partnering with @KeyblckSolution, MistTrack has supported continuous optimization of compliance governance in virtual asset funds — a strong example of effective AML in practice.
As regulations tighten, more fund service providers will need reliable tools to raise compliance standards. MistTrack is expanding blockchain coverage, refining algorithms, and strengthening data to deliver robust AML infrastructure.
👉 For details or a product demo, DM us!
🔐 Strengthening Compliance in the Virtual Asset Funds: @KeyblckSolution x @MistTrack_io
Since 2024, Keyblock has fully adopted MistTrack, the AML product developed by @SlowMist_Team, integrating its #KYT solution into Keyblock’s own review mechanisms to complete #KYW and #SOT verification.
💡 The Challenge
In the daily subscription process of a virtual asset fund, teams must quickly determine whether an investor’s capital source is trustworthy and whether potential risks exist.
🚀 The Solution
MistTrack plays a central role in Keyblock’s compliance framework, converting complex on-chain data into actionable insights through risk assessments, address labeling, and continuous monitoring.
1️⃣ Fund Risk & Source Analysis
All investor addresses, whether from #CeFi or #DeFi wallets, are evaluated using MistTrack’s AML scoring system, which combines ownership details, transaction history, and SlowMist’s threat intelligence.
MistTrack has identified 14 categories of risk sources, including #Sanctions, Illicit Coins, Terrorism Financing, Coin Mixers, Darknet Markets, Risky Exchanges, and more. MistTrack’s address database covering 1,000+ entities and 400M+ labeled addresses.
2️⃣ Continuous Monitoring & Business Risk Analysis
Compliance doesn’t end with a one-time review. Investor funds are constantly moving, and ongoing monitoring is essential. MistTrack provides:
Transaction Risk Monitoring – real-time KYT analysis of monitored addresses, with alert notifications for risk-related activity.
Risk Score Overview – real-time records and OpenAPI integration, giving Keyblock both a macro view of overall risk distribution and micro-level transaction details.
3️⃣ Risk Reports & Regulatory Compliance
If an investor’s funds are linked to illicit sources such as hacking, mixers, or darknet markets, MistTrack-generated risk reports are used for compliance archiving and #STR submission. MistTrack’s visualization and reporting functions enhance traceability, ensuring Keyblock can meet strict regulatory standards while safeguarding assets.
✅ The Result
By adopting MistTrack, Keyblock has significantly improved the efficiency and accuracy of its #AML reviews, reduced risks in investor subscriptions, and built a strong foundation for ongoing compliance.
🌍 SlowMist will continue to expand blockchain support, broaden data coverage, and refine risk identification algorithms — delivering robust, reliable, and future-ready AML infrastructure for the #Web3 ecosystem.
🔗 https://t.co/UOdYWhRvyt