solana:9x2ZKxZv19WPkdF6iM5JMCxJp6JrZzJhiALCwXxpump fresh wallets bought up ~20% of supply
The token bottomed at $0.036 on July 28 and ran +240% in a week from there
Here's what happened to the distribution and who profited the most on this pump:
> Holders went to 56,010 from 32,951 in July
> The old top-30 held 30.04% of supply, today those same 30 addresses hold 17.97%
> 30 addresses in the top-100 bought solana:9x2ZKxZv19WPkdF6iM5JMCxJp6JrZzJhiALCwXxpump for the first time after July 20 and hold 16.7% of supply
Top 5 most profitable fresh wallets:
+$1.32m, bought at $37m mc
0xA8a57DC6adFaed37349CB8a20b3dC83F37E9643B
+$904k, bought at $45 - 61m mc
0xF33f69658744F7a05DD657f51b50AaD7043cf61f
+$846k, bought at $44m mc
0x8224c04a8f66557DF682FD0581eB3724BD2BeE07
+$605k, bought at $45m mc
0xFD2d8Fc98dD2d56883270E4D7E0963fe06806Bd5
+$536k, bought at $43m mc
0xDfE5d7B83a1085B9a6414f8e885599581af6A28a
How ~$75M was drained from wallets without ever touching a device
Coldcard is a hardware Bitcoin wallet where the public blockchain alone was enough to reconstruct the private keys of other people's cold wallets.
Here is the full on-chain breakdown of how the attacker pulled funds from wallets nobody ever touched...
On March 1, 2021, a single firmware commit swapped out the source of randomness. Instead of the chip's hardware random number generator, seed generation started calling a software fallback.
The library checked whether the hardware RNG macro existed, not whether it was enabled, and the guard that should have stopped the build stayed silent. From there everything unwound down the chain.
> the seed came from a predictable value built from the chip serial and a timer
> on newer models the reseed took only 4 bytes out of 32
> the key space collapsed to roughly 2^32
> that range is brute-forceable on ordinary hardware
Mechanically this echoes Milk Sad, CVE-2023-39910, where the libbitcoin library built a seed from a 32-bit value seeded by system time, and the keys were brute-forced offline the same way.
How the attacker recovered the keys:
> generated candidate seeds locally, never touching victim devices
> derived addresses from each one across all standard derivation paths
> checked them against the public blockchain and found the ones holding coins
> signed the withdrawal with his own recovered key
The theft looked like a sweep out of cold storage with no breach and no physical access.
The common denominator showed up in coin age: not a single stolen coin is older than block 674,951, which is when the vulnerable firmware shipped, March 17, 2021.
Wave one, July 30, 2026, 1,082.65 $BTC
The sweeps ran across 1,195 victim addresses.
> every sweep was shaped the same way: one input, one output, fee around 30 sat/vB
> 594.51 $BTC from 500 addresses went through an intermediary hub, 488.10 $BTC from 695 addresses was pulled directly
- hub aggregator: bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0
The money landed in three safes, branches do not overlap:
1) bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r took 562.02 $BTC from 500 victims, the only safe filled through the hub, in a 341-input consolidation
2) bc1qx76cae2706qd5q576feh7xq8rfcsjpf2htfhe3 took 398.48 $BTC from 491 victims directly
3) bc1q8jy96fe5lf8vfugydnte3cguk92gpev7kwtp3q took 89.62 $BTC from 204 victims directly
Wave two came on July 31, 2026, when 76.09 $BTC was taken
A day later a follow-up ran in blocks 960,352 to 960,377, across 1,478 victim addresses, in two branches with different fees.
> 45.90 $BTC from 1,126 victims went through a second hub bc1qsjrf5ze5tmulz7y2x4pc7qaex2a35sanp3rqlx and landed in safe bc1qtfrwa4j6rmj9rsgspv6a0yjumkg39js2numu75
> 30.18 $BTC from 352 victims was pulled directly into safe bc1qmd5m5ktv7m5ffujxv4248fxv36myvdx79n8jp6
The money is almost all still sitting there
On-chain, seven collector addresses across the first two waves hold 1,158.66 $BTC, around $75M at that day's price.
> 5 safes are frozen and hold 1,126 $BTC, not a single outgoing spend
> 2 addresses are transit hubs that only consolidated coins onward
> only about 0.19 $BTC left the campaign in a small peel to a fresh address
> no trace of a mixer, a bridge, or a cash-out
According to Block engineers, the attacker ran reconnaissance through a paid account at a blockchain service provider, so the attribution goes beyond the on-chain pattern alone.
How Verus was drained twice in 2 months for ~$19M
Verus is a fair-launch blockchain, where a payout on the Ethereum side is authorized by notary signatures and a Merkle proof
But the contract never checks that the amount paid out is actually backed by assets locked on the Verus side.
Here is how both attacks worked...
The proof the contract accepts has 3 parts:
1. snapshot of Verus state, signed by the notaries
2. proof that a transaction sits inside that snapshot
3. list of payouts whose fingerprint is committed in that same transaction
The contract pays if all 3 line up, but it never checks that the list is backed by real collateral. A $10 export passes the exact same way as a $10M one.
How the attacker built such a proof:
> pushed 0.01 through the bridge so his own operation became the last link in the Verus export chain
> hand-built a Verus transaction and wrote 8 transfers to his own address into it, worth millions
> waited for the notaries to notarize the network state as usual, then relayed their signatures to Ethereum himself
> called the import: the snapshot is signed, his tx is in it, the list fingerprint matches, the contract paid out
Signatures, math and block inclusion were all genuine. The one missing check that a payout worth millions was backed by more than the $10 that went in.
First hack, May 17-18
The attacker submitted a forged import: an export of ~0.02 $VRSC (~$10) against a $11.58M payout
> drained 1,625 $ETH + 103.57 $tBTC + 147,659 $USDC
> swapped into $ETH in 21 minutes via UniswapX, consolidated into 5,402.4 $ETH
- Bridge: 0x71518580f36FeCEFfE0721F06bA4703218cD7F63
- Attacker: 0x5aBb91B9c01A5Ed3aE762d32B236595B459D5777
- Loot wallet: 0x65Cb8b128Bf6e690761044CCECA422bb239C25F9
- Exploit tx: 0x6990f01720f57fc515d0e976a0c4f8157e0a9529194c4c15d190e98d087eb321
On May 21 the attacker returned 75% and kept 25% as a bounty. The 1,350 $ETH still sit untouched on 0xa8d3662af2fc73ede0ba005b9cb10568b7c68372
On July 8 the recovered funds were redeposited into the same contract and the redeploy ran on unpatched logic.
The vulnerable function was never touched and the hole stayed open for 66 days.
Second hack, July 22-23
> drained in a single transaction: 1,137 $ETH + 71.5 $tBTC + 220,357 $DAI + 149,275 $USDC + 92,784 $scrvUSD + 78,300 $USDT + 59.43 $MKR + 31,475 $EURC
> swapped into ~3,916 $ETH and sent to Tornado Cash 1.5 hours later
> the loot wallet has been empty since, down to 0.09 $ETH of dust today
- Attacker: 0xbda71b58cec0b1c20a8f87ccd52fa0679747855c
- Loot wallet: 0xcfd0a20703cd11e0b9f665e1c3f1ef989c142d54
- Exploit tx: 0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099
~$1.25M made on $VLAD
On July 23 the @vladtenev account was hacked and posted $VLAD as the "official mascot of Robinhood Chain"
The token had been deployed 46 min before the post, and the sniper wallets were funded before launch
Here's the full on-chain breakdown...
$VLAD was deployed on through @ponsdotfamily (Uniswap V3, 1% fee, LP locked)
CA: 0x92D176ccBeEffeCd8089e841D09ea17b6C22D969
Dev: 0xD70627FD9eE5b70906620a6f2001BA74457b438D
The Relay bridge funded the deployer and the sniper wallets with gas 73 to 78 min before launch, at 15:20-15:25 UTC.
By the time the hacked account posted, the bundle was already sitting in the book.
The snipers bought at launch and dumped $VLAD into the inflow. Main wallets and their proceeds from the dump:
0xe26d978d4d9b2aa6f2f594880dd415d74055c27d
0x7ccdb7b7c98a366e5c529ce30ad70bcf31e54706
0xa01ed60b443967bbdff6bf7511c7e2ae5d3c6268
0x1338c1a92368e36e072d7d2e146b093e03e20d77
0x2a129a2cd8250136ed60ce99ace6153096ea8939
0x678da315c3852a9a810fc630a3e7c891fda4c3bd
2 more wallets funded by the bridge before launch added to the consolidation:
0xb1C426D94DB2a16Aa0A3310966C29eb1dB4aD774
0xf00d0450982dfF5aa2256e88A79476D19212593e
The proceeds were consolidated through 5 staging wallets and bridged to Ethereum via Relay:
0xA5E61836cA5Ee714Dbd0138fFeF775a30d888A73
0xdCF9777101d63d970Ea6c360a24488C2Ef83fEB2
0xBa45DDE5b29Ef06266F3317d2Fbf71B30B262CFb
0xEa96883a740CD1d681f97E026f716bA441F1768D
0x21a8aF1820400BF63D746618D11da95538eb6884
In total ~670 $ETH left Robinhood Chain, ~657 $ETH (~$1.25M) landed on L1.
Plus 39.2 $WETH (~$74K) in Pons fees, pulled by the deployer via collectFees and withdraw.
$PONS holders breakdown
15k wallets hold the token, 66.6% of them own less than $45 worth
At launch on July 13, 4,836 wallets bought in the first 24 hours and held 78.9% of supply by end of day
> 3,710 of them sold within 6 hours of their buy
> ~82% have now sold everything
The team burned 202.2m $PONS, that's 20.2% of supply:
> 68m tokens came from the dev's buy for 0.1 $WETH inside the deploy transaction, when the token had no price yet
> 49.4m came from LP fees
> the rest was bought back from the market for 169.7 $WETH
Not a single known team wallet has sold a single token
$40,610 has already left the treasury:
> $30,410 bridged out of the chain
> $10,200 went to a wallet with no tags that moved almost all of it onward
0xd48e5622a6f0d015388fbed4272a336535927fa4
Out of the top 30, 9 wallets bought on the market and never sold, holding together 7.26% of supply. They invested $975,672, now worth $2.5m
0x194d98d18113bdd5720a0a89fe2f98c75ece7344
0x0a6ebed0155edb4b21d92ad02897a626cd90119e
0x7e3ba68c49561aae7c23c1d20fef0f1d7615a3ad
0x9963597a9246b39b13330992f571f8378c18c262
0xd6938bf8a05c04f655fa0c428dab9ca50c3102c8
0x0ed1f91769d6add12f3aca1229f96eea198ac0ed
0x06de9c48b1e639ed5c13ec8fbd4080a38e39f2d1
0xbb94d7e03b6f10b0cb423a0d788cddaba86a246b
0x56e95b47a07210f1ea9fa418c7c5dc164c419ac0
A cluster of 5 wallets holds 0.75% of supply. Merged into one, it'd rank #13
0x45fd36c9cdd500c1b372d99ba3bd79da0d358504
0x699d731048f2f1b40af3a3736a33c11288237512
0xb0b8a1ec009684a5739f94b7378aaeb55be09698
0xcb1cffdce993397b03c439c68f93c1ad6463cf8d
0xead3f93ff737a1be0c8a11529f3c034b44549bb1
$CASHCAT holders breakdown
Token is down 64% from ATH, FDV $80m, 32,951 holders
At launch on June 18, 223 wallets bought up 89% of total supply on day one
> 157 of them sold within the first 6 hours
> 82% of wallets fully sold out
> together they pulled roughly $16m out of the market
The second wave was made by whales who sit at the top of the holders list today
They accumulated below $0.02 a week before the pump and dumped $2.7m net into the pump on July 8β11
The largest of them cashed out $845k:
0xF29f0A86420399F662577b68C48137D510084d96
The team earned around $149.5k in fees over the entire period
80% of all volume traded above the current price, meaning most holders are underwater
The top 60 wallets hold just 15.6% of supply
Out of the top 30 holders, only 2 wallets bought on the open market and never sold:
0x7Eb928E636c151bF2BDC835c7ce2B2CF5E64A955
0x7c85a758c75b4dFCd00A1730863A7520F90AA08D
Clusters among top holders:
1. A funder financed 4 wallets that currently hold 1.9% of supply:
0x6851D84cDFcef07338Ae7a21A0F8F0350c542B0c
0xd6938BF8a05c04f655fA0C428daB9ca50C3102c8
0xEB5Dc28b566CF1AF7e6bC809E94eEea62013bc5b
0xa7C85cDDF4Fa368Ff5ECf52d21Da58d98b397528
2. One operator on two wallets, moving $ETH and the token directly without a router:
0x32C34a18CC5FD58C0EcE1e472e9BF95De8906a8A
0xeee29d1a6fa5873065ad8789c6e15231b48318a0