Add 3 ETH addresses from stolen-funds laundering trail (STG GROUP AG / VQF Member 100702)#566
Open
gg3971 wants to merge 2 commits into
Open
Add 3 ETH addresses from stolen-funds laundering trail (STG GROUP AG / VQF Member 100702)#566gg3971 wants to merge 2 commits into
gg3971 wants to merge 2 commits into
Conversation
… Swiss VASP, AML)
…ed 2026-05-08 evening
Author
|
Update 2026-05-08 evening UTC — operator continued movement after initial PR. Added 4 more ETH vanity-prefix lookalikes to the blacklist:
Operator pattern: creating multiple parallel vanity-prefix wallets to fragment the trail. All ending in same hex suffix as the original active hops. Also: the BTC destination from the original report ( Cross-reports updated: Chainabuse 6 new IDs filed 2026-05-08 evening (9382de35-e5ee-4f59-86ea-02afc4479e03 + 5 more). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adding 3 Ethereum addresses observed laundering proceeds from a stolen-customer-funds event traced 2026-05-04 to 2026-05-08. Reported by STG GROUP AG (Swiss VASP, VQF Member 100702 under FINMA/VQF SRO oversight) acting in AML/CFT capacity.
Addresses
0x118c80bd57d89df96a7dc4f6c096ac07d35fefea(primary laundering wallet)0x14a88277239dcf197408861465ef0409168f0fa6(hop 1)0xa09a78a79146b8f0d920886e7817cb0b918075a4(hop 2)On-chain evidence
0xeccac2726663de3fff6c7a5a668660a239d41700023d4932e1bf737695a074d0)0xc212fa0e6b975c1cd3e8f43f6cbd5de61af4c8144ba3acd4bd30b77b5d019f50)bc1q986dy509crwj2ylp0vp5t7zqls2yfmx6lwn4rm. THORChain Router itself NOT included in this PR (false-positive risk: protocol used by thousands daily).Cross-reports filed in parallel
03481efd-c709-464b-b31c-ae903a0270d3(primary laundering wallet)ad69c664-134e-42d0-8262-7d605695b72b(hop 1)88864653-00c6-4302-a2b6-341081c2e5c8(hop 2)4955d98d-d4f1-4968-bba2-ded88e15a28d(BTC destinationbc1q986dy...)Reporter
Rationale
Pattern: split-forward-consolidate within minutes of source compromise, terminal asset DAI (deliberately freeze-resistant since DAI cannot be issuer-frozen unlike USDT/USDC), THORChain off-ramp to Bitcoin. Flagging here protects MetaMask / Phantom / Rabby / Coinbase Wallet / OpenSea users from inadvertent interactions with these wallets while investigation is ongoing.