F1The trail starts and ends in Railgun
Verified
At 14:15 UTC the attacker's wallet 0x42c2…9353 received 0.049875 ETH through Railgun's RelayAdapt: 0.05 WETH unshielded, minus Railgun's 0.25% fee. At 16:45 it sent its whole balance, 114.13 ETH, to a fresh address 0x951A…2f1a. One minute later that address shielded 114.03 ETH back into Railgun. The Railgun contract logged a Shield event and took its 0.25% fee (0.285 WETH). After that point the funds cannot be followed on-chain.
Evidence: 0xc5dc2606…852b (funding), 0x3a5663d9…53f9 (empty), 0xa20636bf…6dc9 (shield).
F2Aave's pools were used, not broken
Verified
Inside the exploit transaction, Aave received a 1,335.26 WETH repayment of Safe 1's debt and released 1,306.48 weETH of Safe 1's collateral. That is normal pool behaviour. What failed was the decision to do it: the Safes' module, FlashLoopAdapter, carried it out for a caller that was not the owner.
Evidence: 0x75328f91…6fc4, logs 1017–1027.
F3One transaction, five protocols
Verified
Morpho lent 11,537 WETH for the length of the transaction. The attack contract repaid Safe 1's Aave debt, took its weETH and 6.43 weETH from Safe 2, sold 1,312.9 weETH through ParaSwap (routed via Curve, Fluid and Uniswap v3 and v4) for 1,449.35 WETH, repaid Morpho and unwrapped the difference: 114.096 ETH.
Evidence: 0x75328f91…6fc4, block 26,098,264.
F4The attacker prepared for 53 minutes
Verified
After the Railgun funding at 14:15 UTC, the wallet deployed a helper contract at 14:44, sent itself an empty transaction at 14:56, and had the helper create the attack contract 0xF091…67ff at 15:02. The exploit followed six minutes later. The attack contract's code is not verified.
Evidence: 0x378c128d…8e71, 0x0c2bbaf2…3884.
F5The owner of both Safes offered a 10% bounty on-chain
Verified messageLabel attributed
At 21:03 UTC, 0x329c…3eD4, the only owner of both Safes, sent the attacker a message: keep 11.41 ETH, return 102.69 ETH before Oct 3, 18:00 UTC, and the matter is treated as a whitehat rescue. The wallet it reached had been empty since 16:45. Blockscout labels the sender "AAVE: Deployer 13". We read the ownership from the Safes themselves; the label is Blockscout's.
Evidence: 0x94b69189…89d0 (message in the input data).
F6Address poisoners targeted the attacker
Verified
From 17:00 UTC, addresses starting 0x951A and ending 2f1a, imitating the attacker's fresh address, sent fake "ETH" tokens and dust to the attacker's wallet. It is the same trick seen in File #001, this time aimed at a thief. We filtered these before counting any flow.
Evidence: e.g. 0x951A25c9…0f1a, 0x951b4647…2f1a.