CCIP Incident — Fund Tracer

← Airdrop console
What this shows — how to read the graph
On 20 Sep 2026 a compromised SingularityNET bridge key minted ~486.5M unauthorized WMTX on Ethereum. This tracer follows every WMTX transfer since the first exploit block, outward from the four attacker wallets. An address is flagged only if tainted funds actually reached it, in chain order — money it sent or received before the attacker's funds arrived does not count against it.

Two kinds of exposure. Direct = the funds travelled from the attacker through personal wallets only (EOA→EOA) — attacker-controlled movement, the serious list. Market = the trail passes through a DEX pool or router — these are mostly ordinary users who bought WMTX on the open market after the attacker dumped ~256M into Uniswap. They are shown for completeness, not accusation.

The view starts focused on the attacker cluster and the largest flows; each card's +N chips count hidden counterparties — double-click to reveal them.

Flow graph

taint on Base/BNB/Arbitrum is seeded by the attacker cluster found on Ethereum
attacker (seed) direct exposure contract (DEX / router / pool) market exposure · flow runs left→right by hops from the attacker · edge width = amount · double-click a card to expand its hidden counterparties · drag cards to arrange · wheel zooms

Bridge participants

Every wallet that sent or received one of the stranded CCIP transfers, and whether it had any WMTX history on any chain before the hack: prior holder = held WMTX at the pin (Ethereum snapshot or an L2 balance) · prior interaction only = transacted WMTX on Ethereum before the hack but held none at the pin · no prior = first-ever WMTX touch was after the exploit — bought the dumped tokens and bridged them; the cohort the execution policy must decide on.
download: participants.csv

Stuck bridge transfers

1,225 CCIP transfers were burned on their source chain but never minted on the destination (the emergency shutdown revoked minting). Each one is checked against the taint set: clear = neither sender nor receiver ever touched tainted funds; market = they hold WMTX bought on the open market after the hack; direct = on the attacker's own laundering path (currently zero); no coverage = Solana-origin or proxy-routed, needs manual identification. Every EVM-origin burn has been independently re-verified on-chain.
download: verdicts.csv · trace.csv · validation.md