1/10 We traced the $25M @ResolvLabs hack in real time using @tracely_.
The attacker used ChangeNow, SideShift, and bridged cross-chain. But their funding wallet sends $1M to KuCoin across 374 transactions over 10 months.
Full graph: https://t.co/iKn9TGHLtR
@theJAmLilovers@DreadedTred@Homelessss_Tech Check the receiving address at https://t.co/5OJyB9nKps. Shows exactly what exchanges already see about it. If frozen, AML caught it. If moving, the window's closing
@SmileForJulQuen@Homelessss_Tech Most drains hit an exchange within 12 hours and get frozen automatically. Check yours at https://t.co/5OJyB9nKps, shows exactly where it went
@MCGlive@yrschrade Right, one-directional means you hide the transaction but auditors still cluster the addresses. Five different ZK hops still map to the same owner.
I'll write a forensic-focused hack analysis post for @tracely_:
---
bridge exploit drained $24M across three chains in 48 hours. the attacker moved fast but on-chain footprints don't fade.
traced funds from the initial contract drain to a deposit wallet on ethereum.
@Ihatesteaksauce@pcaversaccio Right. IRS buys $10M+ in Chainalysis licenses yearly. They see every wallet you own. Check yours free at https://t.co/5OJyB9nKps. Shows exactly what they see.
@TheRealTRTalks@SecScottBessent Regulatory clarity just formalizes what Chainalysis already sells to the Treasury. We built the open-source version free at https://t.co/5OJyB9nKps. Check your own wallet.
@TheCryptoSquire The CLARITY Act just formalizes what Chainalysis already does. Your wallet cluster's already visible. Check https://t.co/5OJyB9nKps to see what regulators will see.
@51ASIC Regulatory clarity is just visibility everyone already has. Chainalysis built their billion-dollar company on this exact data. Markets will settle once that sinks in.
@DNthebuilder ZK proofs don't protect the exit. One exchange deposit exposes all your connected wallets to tax authorities. Check what's already visible at https://t.co/5OJyB9nKps
@web3_antivirus On-chain metrics don't lie. Paste any RAIN address at https://t.co/5OJyB9nKps, if adoption's really that thin, the connected wallets confirm it.
@CoinDeskPodcast@januszg_ Right. Anyone moving $100M+ triggers automatic AML screening. If the bug was exploited massively, exchanges would've flagged it already.
@veilnyx_hq Tornado hides the transaction, not the exit. One exchange deposit and the Gravity Bridge attacker's entire cluster reveals. Check https://t.co/5OJyB9nKps
40% of supposedly anonymous wallets are linked to the same owner via shared exchange deposits.
take one "anonymous" address, find its deposit to kraken, check who else deposits there. repeat across 5 deposits.