At 19:34:47 UTC on July 24, 2026, 500,000 USDC left an Ethereum wallet publicly identified with Triple-A, a licensed crypto payments processor, and went to an address created for the occasion. Thirty six seconds later another 500,000 USDC followed. Within eighteen minutes the same destination had received 1,215,000 USDC, 307,000 USDT and 32,000 PYUSD. By 20:34 that evening the proceeds were being swapped to ether and forwarded to a single consolidation address, which as we write holds 5,287.630687 ETH and has never sent anything out.
We recomputed every figure in this piece from the chain before writing it, which is the entire point. The number in circulation was 5,227 ETH and "9.7 million dollars". Both were already stale when they were published. This is a companion to our argument in compliance is not verifiability, and to the reserve teardowns in reserves you can verify.
What actually happened
The mechanism is a hot wallet key compromise, not a smart contract flaw. There is no exploited function to point at. Whoever held the signing key simply signed, and the chain did what it was told. The on-chain analyst Specter flagged the outflows first and the security firm PeckShield followed; per those reports the drain spanned several chains and the proceeds were bridged to Ethereum. The company had not published a statement explaining the incident as of the coverage we checked, so everything below is what the chain shows rather than what anyone has confirmed.
The detail worth pausing on is that the theft did not look like an event. The operating wallet in question has been live since February 2022 and settles merchant payments continuously, in amounts from a few dollars to a few thousand. Across our window it made 1,020 outbound stablecoin transfers. Twenty one of them were the theft. The rest were business as usual, running in the same minutes, from the same address, in the same tokens.
What the on-chain data shows
The consolidation address is 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1. Its native balance is 5,287.630687 ETH as of 01:20 UTC on July 26, which at an ether price of 1,878.15 dollars is about 9.93 million dollars. Every one of those 5,287.63 ETH arrived between 20:34:59 UTC on July 24 and 11:55:47 UTC on July 25, and total outbound is zero. The reported figure of 5,227 ETH was roughly 60 ETH low, about 114,000 dollars, because the wallet was still receiving while the story was being written.
We restricted the attacker cluster to addresses that provably sent value directly into that wallet. There are six with a non-zero amount, dominated by 0x8335d258438e47cd8eb1532c04cfe445e011aef6 at 5,149.4969 ETH and 0x9a28573c8c29ceedcf4193769fac01775b2c946a at 125.3529 ETH. Walking a second hop back inflates the set to 252 addresses and sweeps in exchanges, a bridge router and unrelated senders, so we did not use it. A large cluster is easy to draw and proves nothing.
Tracing the operating wallet into that cluster gives 1,590,058.04 in stablecoins on Ethereum across 21 transfers, and 413,300.00 on Polygon across 11. That is 2,003,358.04 total on the two chains we can read directly, or about a fifth of the consolidated total. The remainder came from chains we did not recompute, and we are not going to assert numbers for them. Reports disagree on which chains those were: DefiLlama lists Ethereum, Tron and Arbitrum, while press coverage lists Ethereum, Tron, TON and Solana. We checked Arbitrum ourselves and found zero transfers for this address in the window, while Polygon, which DefiLlama does not list, was one of the busiest legs. Take the chain lists with that in mind.
The laundering path is ordinary. 1,200,000 USDC, then 15,000 USDC and 32,000 PYUSD, went through CoW Protocol's settlement contract at 0x9008D19f58AAbD9eD0D60971565AA8510560ab41, which we confirmed is the GPv2Settlement contract rather than assuming it from the prefix. USDT went out in tranches to four addresses, the largest being 198,250 to 0x69427344382602a5bae42e11a4dbbd38e5b78122 and 86,467.50 to 0x9c2e6af596a352aac58711339f79bf9fe3d1c48c.
One trap for anyone checking this themselves. A separate poisoning campaign is riding along on the theft, minting worthless tokens whose symbols are the strings "ETH" and "T" and sending them in amounts that mirror the real transfers, 100, 112, 157, 615.4288443956624 and 4,140.404980655625, to vanity addresses that copy the consolidation address's leading and trailing characters and all end in 53b1. One of those fake "ETH" transfers landed in the real consolidation wallet. If you read the token transfer tab you will double count, and if you copy an address from it you will send money to a stranger. Our 5,287.63 figure is the native balance from the balance endpoint, which those spoofs cannot touch.
Here is the finding we did not expect. Taking 19:34:47 UTC on July 24 as the moment the theft began, the Ethereum wallet went on to receive 272 further inbound stablecoin transfers worth 579,528.83, the most recent at 01:19:35 UTC on July 26, more than twenty nine hours later. Over that same period it made 505 routine outbound payouts worth 313,747.88. Polygon was still transacting at 01:16:48 UTC on July 26. The deposit rail was never closed. Customers kept paying in, in ordinary amounts, into an address that had been under someone else's control since the previous evening.
Why a live, recomputable check would not have saved a customer here
We want to be precise about this rather than sell a product into someone else's bad week. Continuous reserve monitoring would not have prevented this incident, and it would not have helped an individual merchant.
The reason is structural. There is no on-chain claim to check. A merchant holding a balance with a payments processor holds a row in that processor's database. There is no token whose supply you can read, no vault whose share price you can recompute, no attestation with a signature and a timestamp. You cannot ask "is my balance still backed" in any way that resolves against a chain, because the relationship between the operating wallet and your account balance exists only inside the company. That is not a criticism unique to this firm. It is how custodial payments works, and it is a reasonable trade for a merchant who wants settlement in local currency and does not want to hold keys.
What a continuous check would have done is compress the detection window from the outside. The signature of this drain is legible: a wallet whose normal transfer distribution is hundreds of payments between a few dollars and a few thousand suddenly emits 500,000, then 500,000, then 250,000, then 200,000, to a destination it has never paid before, inside eighteen minutes. A monitor watching the shape of outflows rather than their total would have raised that in minutes, and the deposit rail could have been closed the same evening instead of staying open for another twenty nine hours. The theft would still have happened. The 579,528 that arrived afterwards is the part that a check catches.
The honest general lesson is smaller than the headline and more useful. Continuous verification is not a shield against key compromise. Nothing is, other than not having a key that can move everything. What verification changes is how long a compromise runs before anyone outside the company knows, and whether the people still sending money in are among the last to find out.
Where Kerne stands
We are not going to use this to claim immunity, because we hold keys too. Kerne's on-chain leg is attestor-optional and holder-recomputable: kUSD's collateral and the vault's share accounting resolve against the chain, and the hourly signed Proof of Reserves at /api/por/signed and its on-chain leg at /api/por are things you can re-derive without asking us. The hedge leg sits on a venue and is disclosed rather than fully on-chain-verifiable, which we have said in every piece where it is relevant and are saying again here. Our live risk surface is at /api/risk-status.
Key compromise is a risk we carry as much as anyone in this business. The difference we do claim is narrow: if it happened to us, the collateral leg would move on a chain you can watch, on a clock you control, rather than inside a ledger you have no access to. That is a smaller claim than "this could not happen here" and it is the only one we can support. A /verify pass proves an attestation is authentic and fresh. It is not an audit and it is not a solvency opinion. Nothing here is an offer of any token to any person.
What a holder should do
Before the next one, and it does not matter whether you hold a synthetic dollar, a vault share or a balance with a processor, work out which of these you can answer. Is there a token or a vault whose supply and share price you can read yourself, or is your balance only a number someone shows you? If there is an attestation, when was it last signed, and can you check the signature without the issuer's help? Do you know which addresses hold the operating float, and would you notice if their outflow pattern changed tonight? If the answer to all three is no, you are not holding a verifiable claim, you are holding a relationship, and that can be the right choice as long as you have made it on purpose.
The specific habit worth building from this incident is watching shape rather than size. The drain here was visible within eighteen minutes to anyone comparing outbound transfers against that wallet's own history, and invisible for a day and a half to everyone who was not looking. Our free checks at /verify do this for on-chain reserves and vault share prices, and every address and query in this piece is reproducible without us.
Figures are point-in-time as of 01:20 UTC on July 26, 2026 and were recomputed by us from the Etherscan V2 API on Ethereum, Polygon and Arbitrum: the consolidation address 0x01F83B5d4fb30E8AA3daC1681B4048D9135253b1, the operating wallet 0x8195d3496305d2dbe43b21d51e6cc77b6c9c8364 from block 25598869 on Ethereum and 90764135 on Polygon, and the settlement contract 0x9008D19f58AAbD9eD0D60971565AA8510560ab41. Ether was converted at 1,878.15 dollars per CoinGecko at the same time. The initial detection and the multi-chain scope are per on-chain analyst Specter and PeckShield as carried by AMBCrypto, CoinPedia and BeInCrypto; the chain list differs between those reports and DefiLlama's hacks dataset, which we note in the body. Tron, TON and Solana legs were not recomputed and no figure here covers them. Triple-A had not published a statement on the incident as of the sources checked, and we make no claim about the cause beyond what the transfers show. Reported loss figures in incidents like this are routinely revised; recompute before relying on any number here. Kerne is not affiliated with any firm named. Kerne's own claims resolve to live endpoints: the hourly signed Proof of Reserves at /api/por/signed, its on-chain leg at /api/por, and the live risk surface at /api/risk-status. A /verify pass proves an attestation is authentic and fresh; it is not an audit and not a solvency opinion.
Verify it yourself
Run the same check on any reserve, or have it run for you.
Paste any issuer's signed attestation into the free verify tool and recover the signer, rehash the figures, and check freshness in your own browser. For a machine-signed, point-in-time read of an address you name, delivered on the page in about two minutes, the instant self-serve read is $29; a human-reviewed read is $149. A teardown like this one, commissioned on any target you name, is $499. An independent read of a counterparty you hold or allocate to is $2,500. Attestation tooling, not an audit, and not a solvency opinion.