<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Guglielmo Anfossi</title><description>Blockchain investigator in Milan. I work with law firms and law enforcement to trace illicit crypto funds and turn them into actionable evidence.</description><link>https://sincronik.it/</link><language>en-us</language><item><title>The Transfer That Never Happened (Delta-Neutral Siphoning)</title><link>https://sincronik.it/writing/the-transfer-that-never-happened/</link><guid isPermaLink="true">https://sincronik.it/writing/the-transfer-that-never-happened/</guid><description>Delta-neutral siphoning moves value without a single transfer, which is why it walks straight past the method most investigations start with.</description><pubDate>Mon, 05 Oct 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/delta-neutral-siphon.png&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;The Transfer That Never Happened&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;/p&gt;
&lt;p&gt;Some questions arrive about performance, not theft. A book has lost steadily for months, and the people whose money it is want to know whether that is bad luck, bad judgment or something else. A trace of the funds comes back clean: deposits, trades, settlements, no transfer to anyone.&lt;/p&gt;
&lt;p&gt;Sometimes it is something else, with a shape I now look for whenever someone trades other people’s money with a share of the upside: delta-neutral siphoning. It moves value without a single transfer, which is why it walks straight past the method most investigations start with.&lt;/p&gt;
&lt;h2 id=&quot;how-it-works&quot;&gt;How it works&lt;/h2&gt;
&lt;p&gt;The pattern needs two books. The first belongs to a fund or a company, traded by someone paid a share of its gains: a performance fee, a bonus, carry. The second is his own, somewhere else, holding the opposite side of the same exposure. It need not be the same instrument or venue: a long perpetual on one side can be mirrored by a short position built from options on the other.&lt;/p&gt;
&lt;p&gt;The hedge does not need to be perfectly delta-neutral at every moment. What matters is that the two positions create opposing economic exposures over the relevant trade.&lt;/p&gt;
&lt;p&gt;The sizing is what turns a hedge into a siphon. The personal leg is sized so that its payoff mirrors his bonus. In the simplest linear case, with a 5% performance fee, that means 5% of the fund’s position.&lt;/p&gt;
&lt;p&gt;Run the numbers on that simple case. Every dollar the fund gains pays him 5 cents of bonus and costs him 5 cents on his own book: net zero. Every dollar the fund loses pays him 5 cents on his own book, and there is no bonus to give back. He never gains from the fund’s success and always gains from its failure. What he collects is a fixed share of every loss the fund books.&lt;/p&gt;
&lt;h2 id=&quot;why-it-looks-reckless&quot;&gt;Why it looks reckless&lt;/h2&gt;
&lt;p&gt;Winning trades leave him flat, and losing trades pay him in proportion to the loss. What he wants, then, is exposure that can produce large losses while his personal hedge remains alive, which creates an incentive for volatility and concentrated risk.&lt;/p&gt;
&lt;p&gt;From the fund’s side it reads as conviction bordering on recklessness. From his, every large loss is a large payout. In most small and mid-size setups a bonus is paid on gains and rarely clawed back on losses, so the fund has effectively handed him an option-like payoff on its own losses. Stricter structures, with a hard high-water mark or a real clawback, tighten the numbers without closing the door.&lt;/p&gt;
&lt;p&gt;One habit gives it away: no leverage, above all on his own book. A leveraged personal leg can be liquidated by a swing in the fund’s favour before the fund’s trade has had time to lose. If the market then turns, the fund loses and he is no longer on the other side to collect. The fund’s leg has to be allowed to lose in its own time, so his leg has to survive whatever comes first.&lt;/p&gt;
&lt;p&gt;A trader chasing losses usually reaches for leverage first. Recklessness without leverage is a strange kind of recklessness. It looks less like a mood than like a constraint someone is respecting.&lt;/p&gt;
&lt;h2 id=&quot;the-governance-tokens&quot;&gt;The governance tokens&lt;/h2&gt;
&lt;p&gt;The siphon has running costs: fees, funding and spread on both legs, paid on every trade. Farming is how those costs get paid down. Put the personal leg on a DeFi protocol that rewards activity with its governance token, and every mirrored trade earns rewards and airdrops on top of its share of the fund’s losses.&lt;/p&gt;
&lt;p&gt;That makes it a second channel of extraction. The fund’s losses pay him directly, while the trading activity that accompanies those losses is rewarded again by the protocol’s incentives. What accumulates on top is a vote that can be sold: a claim on how the protocol is run, bought with trading the fund financed.&lt;/p&gt;
&lt;h2 id=&quot;how-it-shows-up&quot;&gt;How it shows up&lt;/h2&gt;
&lt;p&gt;With no transfer to follow, the evidence is a symmetry. Exposures offset across two books, entries and exits fall in the same windows, and the personal leg holds a steady proportion of the fund’s position.&lt;/p&gt;
&lt;p&gt;Over many trades the net result points one way, and the fund’s appetite for risk rises exactly as the second book grows. A single trade is noise. The series is the signature.&lt;/p&gt;
&lt;p&gt;On its own, the signature is a reading, and I mark it as one.&lt;/p&gt;
&lt;p&gt;It becomes record through something outside the trades, and the most reliable one is the bonus itself. After a winning stretch the fund pays him, and his own leg has just lost by about the same amount. The payout has to go somewhere, and it usually goes back into that leg, restoring the proportion before the next trade.&lt;/p&gt;
&lt;p&gt;That refill is the one real transfer in the whole scheme: from the fund, through his pay, into the book on the other side. The shape says where to look. The refill, together with the same proportion and timing across both books, is what a court can check.&lt;/p&gt;
&lt;p&gt;The investors see a bad quarter and a trader who took too much risk. The protocol sees volume. The only trace of the transfer is a loss that someone else hedged too well.&lt;/p&gt;</content:encoded><category>Methods</category></item><item><title>The Strings Stay Public (Why Tracing Is Not Enough)</title><link>https://sincronik.it/writing/the-strings-stay-public-why-tracing-is-not-enough/</link><guid isPermaLink="true">https://sincronik.it/writing/the-strings-stay-public-why-tracing-is-not-enough/</guid><description>Tracing funds walks edges until they end in a mixer, a nested service, a deposit address you cannot compel. It sees what moved.</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Tracing funds walks edges until they end in a &lt;a href=&quot;/glossary/coin-mixer/&quot;&gt;mixer&lt;/a&gt;, a &lt;a href=&quot;/glossary/nested-service/&quot;&gt;nested service&lt;/a&gt;, a deposit address you cannot compel. It sees what moved. It never asks who arranged the movement, and that hand survives every wall built to stop the money. The wallets are a marionette, and the strings run through other layers of the same data. I pull four, each reaching a layer the money trail never touches.&lt;/p&gt;
&lt;h2 id=&quot;who-built-it&quot;&gt;Who built it&lt;/h2&gt;
&lt;p&gt;Contracts have authors: a deployer, an upgrade admin, role holders, multisig signers. None of it is money, all of it is public, and it rarely matches the wallets on stage.&lt;/p&gt;
&lt;p&gt;I built my own tool for this layer, because nothing in my toolkit did it and reading it by hand kept losing details: a role granted three upgrades ago, a signer swapped on a multisig, a deployer funded two hops back. From known tokens and contracts it climbs to their deployers, the deployers’ deployers, and whoever paid their first gas, reading proxy admin slots, role grants and signer lists on the way. Every edge is one on-chain fact with its transaction, and the same input returns the same tree.&lt;/p&gt;
&lt;figure&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image25.png&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Each edge is one on-chain fact: a creation transaction, an admin slot, a role grant, a signer.&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;figcaption&gt;Each edge is one on-chain fact: a creation transaction, an admin slot, a role grant, a signer.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;What comes back is mostly addresses you did not have: sometimes one freshly funded wallet at the root of several “unrelated” launches, the same signer on every admin multisig. The money ends in a dozen places. The authorship converges.&lt;/p&gt;
&lt;h2 id=&quot;where-it-was-rehearsed&quot;&gt;Where it was rehearsed&lt;/h2&gt;
&lt;p&gt;A contract exploit is rarely fired blind. The attacker needs to know the call sequence works against the target, and the cheap place to find out is a public testnet, where gas is free and failure costs nothing.&lt;/p&gt;
&lt;p&gt;Rehearsals are careless in ways attacks are not. One key means one address on every EVM chain, so a reused deployer brings its practice history along. The work itself leaves a signature too. Sometimes the attacker deploys a contract, and the one used in the attack usually matches the one tested: the same bytecode, or at least the same function selectors.&lt;/p&gt;
&lt;p&gt;Sometimes nothing is deployed at all, and the rehearsal is a sequence of calls: the same functions of the target, hit in the same order, with the same kind of parameters. Either way, searching for the pattern finds the practice run and whoever ran it, even from an address never used on mainnet. And testnet gas comes from somewhere: a faucet, a bridge, a wallet that also funded something else. Two addresses the operator kept apart on mainnet meet in rehearsal, where nobody expected to be watched. The most careful criminals skip the testnet and fork mainnet locally, which leaves nothing to find. The trail catches the rest.&lt;/p&gt;
&lt;p&gt;Both strings live on public chains. The next one starts where the chain was built to go dark.&lt;/p&gt;
&lt;h2 id=&quot;where-it-left-a-fingerprint&quot;&gt;Where it left a fingerprint&lt;/h2&gt;
&lt;p&gt;Monero is the purest place built for edges to end: decoys, hidden amounts, off-chain recipients. You rarely need to beat that cryptography.&lt;/p&gt;
&lt;p&gt;Value has to enter and leave. Often both ends pass through the same swap service or exchange, from the same machine, and the service saw one device fingerprint on the way in and on the way out. The match sits in records a court can request, and the decoys never enter the question. Different services on each end make it harder, not impossible: many keep device and session data, and a fingerprint retained on both sides can still be matched.&lt;/p&gt;
&lt;h2 id=&quot;what-they-did-and-when&quot;&gt;What they did, and when&lt;/h2&gt;
&lt;p&gt;Three strings start from something in hand: a contract, a rehearsal, a service. Sometimes you hold only a behavior and need every wallet that could have produced it. That is what queries are for: a good one describes an act, not a flow.&lt;/p&gt;
&lt;p&gt;In the &lt;a href=&quot;/writing/inside-inferno-drainer/&quot;&gt;Inferno Drainer&lt;/a&gt; case, thousands of addresses were exploited by the same malware contracts in the same way. The query that worked asked which of them had touched the tokens of the attacked ecosystem, because whoever drained that protocol’s users carries its tokens more densely than any other operator of the kit. Thousands became a few dozen, and one lit up.&lt;/p&gt;
&lt;p&gt;Time is the other filter. On a prediction market that resolves on news, the price shows when the news went public: the winning side jumps and stays. Only buyers before that moment matter. They still need an order, weighed on conviction (stake on the winning side), entry (surprise captured by the price paid) and record. Skilled traders lose often and win more. Someone betting on known outcomes almost never loses, and appears for one event rather than hundreds.&lt;/p&gt;
&lt;p&gt;A ranked list is not a verdict. It picks who deserves a manual look against news timelines and funding origins, and cannot tell inside information from exceptional analysis. That limit goes in the report, next to the ranking.&lt;/p&gt;
&lt;h2 id=&quot;what-the-strings-are-for&quot;&gt;What the strings are for&lt;/h2&gt;
&lt;p&gt;None of this recovers anything alone. A deployer tree freezes no account, a testnet trace returns nothing stolen, a fingerprint seizes no coins, a ranking convicts nobody. Together they map the hands behind an operation from facts others can check and queries anyone can rerun, which is what enforcement, counsel and compliant venues act on.&lt;/p&gt;
&lt;p&gt;The money trail says where value landed. The strings say whose hand was on it. Most operations hide the first and forget the second.&lt;/p&gt;
&lt;p&gt;So a cold trail does not close the file. When the money goes dark, the marionette stops moving. The strings stay public.&lt;/p&gt;</content:encoded><category>Methods</category></item><item><title>A Finding Stands Without You</title><link>https://sincronik.it/writing/a-finding-stands-without-you/</link><guid isPermaLink="true">https://sincronik.it/writing/a-finding-stands-without-you/</guid><description>A report leaves my desk on a Tuesday and arrives, weeks later, in a room I have never seen. Opposing counsel reads it.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image24.png&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;A Finding Stands Without You&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;/p&gt;
&lt;p&gt;A report leaves my desk on a Tuesday and arrives, weeks later, in a room I have never seen. Opposing counsel reads it. A judge reads it, or an officer deciding whether a freeze is worth asking for, or a compliance analyst deciding whether to act on an address before the weekend. Nobody in that room can ask me what I meant in paragraph nine. Whatever the document does there, it does without me.&lt;/p&gt;
&lt;p&gt;Most investigative writing is not built for that room. It is built for the meeting where the author is present, answering questions and filling the gaps out loud. Those gaps are invisible while you are speaking, and they are the whole structure once you stop.&lt;/p&gt;
&lt;p&gt;This is the distinction I work to. A finding makes you see it. An opinion needs you to explain it.&lt;/p&gt;
&lt;p&gt;An opinion is a conclusion held up by its author’s hands. It stands while you speak and it drops the moment you let go. A finding stays standing after you let go, because what holds it up is inside the document: the data, the steps, and the reason each step forces the next.&lt;/p&gt;
&lt;p&gt;Both can be true. That is the uncomfortable part. An opinion can be correct, reached by an experienced investigator with good instincts, and still be an opinion, because its correctness lives in the investigator rather than on the page. When the case moves and the investigator does not move with it, nothing travels.&lt;/p&gt;
&lt;p&gt;Finding the answer is half the work. Representing it so that someone else reaches it independently is the other half, and it is the half that decides whether the first half survives contact with anyone.&lt;/p&gt;
&lt;h2 id=&quot;two-layers-and-the-line-between-them&quot;&gt;Two layers, and the line between them&lt;/h2&gt;
&lt;p&gt;The raw material helps here. On-chain data is not a statement made by someone, it is residue left by something. Nobody wrote a transaction to be read, which is why it cannot be phrased, spun or softened, and why I trust it more than any document a party hands me. It is also why it never tells you who. A name laid over a residue is a reading, and a reading is an act performed by a person.&lt;/p&gt;
&lt;p&gt;So every report I write has two layers. What the chain forces, and what I concluded from it. Both belong in the document. Only one of them is checkable by looking, and the reader has to be able to tell which sentences are which without asking me.&lt;/p&gt;
&lt;p&gt;That sounds easier than it is, because the two layers are written in the same sentences, in the same tone, and a conclusion inherits the authority of the data sitting next to it. “The funds were consolidated by the attacker before the swap” is one clause of record and one clause of attribution, fused. The record part is a set of transfers into one address. The attribution part is mine, resting on timing, on control, on behavior consistent across addresses, and each of those is a judgment someone can dispute without disputing a single transaction.&lt;/p&gt;
&lt;p&gt;Splitting that sentence costs a paragraph and buys the whole document. The transfers go where they can be reproduced from primary data. The attribution goes where it is named as an attribution, with the grounds under it and the alternative it rules out.&lt;/p&gt;
&lt;h2 id=&quot;where-the-reading-always-enters&quot;&gt;Where the reading always enters&lt;/h2&gt;
&lt;p&gt;Some of these joins are so routine that they stop looking like inferences, and those are the ones worth marking hardest.&lt;/p&gt;
&lt;p&gt;A cluster is a model, not a fact about the chain. Common-input heuristics and behavioral similarity produce a grouping that is usually right and occasionally load-bearing, and when it is load-bearing it has to be visible as a hypothesis with evidence under it rather than as a name on a diagram.&lt;/p&gt;
&lt;p&gt;The purpose of a contract call is read from its code and its effects, not from its label. A decoded payload shows what executed. What it was for is my sentence.&lt;/p&gt;
&lt;p&gt;Intent is never on the chain at all. The chain records the movement. Whether that movement was theft, a withdrawal, a service payment or a mistake is a reading built from context that mostly lives off-chain.&lt;/p&gt;
&lt;p&gt;None of these should be kept out of a report. A document that refuses to interpret is not evidence of rigor, it is a set of transaction hashes that leaves the whole job to the reader. The discipline is in interpreting out loud, in a way that lets somebody accept the data and reject my reading of it, which is exactly the move an adversary will try to make.&lt;/p&gt;
&lt;h2 id=&quot;the-assumptions-that-never-get-written&quot;&gt;The assumptions that never get written&lt;/h2&gt;
&lt;p&gt;There is a quieter version of the same problem. The premises I do not state are the ones I no longer notice: that a labelled address still belongs to whoever it was labelled as, that a data source reflects the chain’s current state, that a balance shown by a platform tracking transfers matches what the contract itself would say, that the scope I was handed rests on a correct account of what happened.&lt;/p&gt;
&lt;p&gt;Each of those can be wrong without anything in my reasoning looking wrong. Stating them changes the failure mode. An unstated assumption that turns out to be false takes the conclusion down with it silently. A stated one gives the reader a place to check, and gives me a document that fails loudly, which is the only kind of failure worth having.&lt;/p&gt;
&lt;h2 id=&quot;who-has-to-be-able-to-walk-it&quot;&gt;Who has to be able to walk it&lt;/h2&gt;
&lt;p&gt;None of my readers can take my word for it, and this is not a matter of trust. An analyst validating a &lt;a href=&quot;/glossary/freeze-request/&quot;&gt;freeze request&lt;/a&gt; works against criteria I do not set. An officer, in most jurisdictions, cannot adopt what I found at all, because the investigation has to be theirs and every step they cannot reproduce is one they rebuild from nothing. A lawyer takes me as the expert and comes back with objections that should have been answered before they were raised.&lt;/p&gt;
&lt;p&gt;The requirement is constant across all three, and the shape it arrives in is not mine to choose. What survives the difference is the separation itself: a document whose layers are already apart can be re-cut for a reader who needs it presented another way. One that fused them has to be rebuilt from the beginning.&lt;/p&gt;
&lt;h2 id=&quot;the-test&quot;&gt;The test&lt;/h2&gt;
&lt;p&gt;Hand the work to someone who wants it wrong.&lt;/p&gt;
&lt;p&gt;That is not a thought experiment in this field. Adversarial review is the default condition: a defense lawyer, an exchange’s counsel, a colleague paid to find the seam. If they reach my conclusion only while I walk them through it, it was never a finding. It only looked like one from where I was standing.&lt;/p&gt;
&lt;p&gt;It is also why I prefer deterministic, auditable reasoning to opaque probabilistic output. Probabilistic output is often accurate. Auditable reasoning can be shown to be wrong, and that is the only condition under which being right means anything.&lt;/p&gt;
&lt;p&gt;The complication I will not pretend away: sometimes the strongest conclusion available is probabilistic, and no amount of discipline turns it into a proof. A cluster attribution resting on behavioral similarity is a reading, and it stays a reading however many analysts share it. The honest move is to mark it as one, in the sentence where it appears, and keep it structurally separate from what the chain forces. A report written that way has fewer confident lines in it. It survives cross-examination on the lines it kept.&lt;/p&gt;
&lt;p&gt;Most cases I have watched fall apart did not fall apart over the data. Both sides had the same data. They disagreed about what the data was allowed to mean, and the side that lost was usually the one whose document could not show where its own meaning had been added.&lt;/p&gt;
&lt;h2 id=&quot;where-this-leaves-the-writing&quot;&gt;Where this leaves the writing&lt;/h2&gt;
&lt;p&gt;Pedagogy set the standard and I still work to it: a reconstruction nobody can walk through without me is only a report that a reconstruction once happened. So I do not write to be believed. I write to be understood by someone who is not in the room, every step laid down for a reader to walk alone, and to break if they can.&lt;/p&gt;
&lt;p&gt;The practical form of that is unglamorous. Stated premises, inferences labelled as inferences, and fewer sentences that sound certain. What it buys is a case that keeps working when I am not there to defend it, and an error that can be found by someone other than me.&lt;/p&gt;
&lt;p&gt;An opinion can be right. A finding stands without you.&lt;/p&gt;
&lt;p&gt;Could an adversary reach your conclusion from the document alone?&lt;/p&gt;</content:encoded><category>Methods</category></item><item><title>The Magic of Flash Loans (Part 2): The Next Octave</title><link>https://sincronik.it/writing/the-magic-of-flash-loans-part-2-the-next-octave/</link><guid isPermaLink="true">https://sincronik.it/writing/the-magic-of-flash-loans-part-2-the-next-octave/</guid><description>A wall taken down at one layer has a way of reappearing at the next. Silence it in one octave, and it returns in another.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image23.jpeg&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;The Magic of Flash Loans (Part 2): The Next Octave&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;/p&gt;
&lt;p&gt;A wall taken down at one layer has a way of reappearing at the next. It is less a wall than a note: silence it in one octave, and it returns in another, altered in pitch but unchanged in character.&lt;/p&gt;
&lt;p&gt;Part one ended with a simple claim. &lt;a href=&quot;/writing/the-magic-of-flash-loans-part-1-capital-was-never-the-constraint/&quot;&gt;Flash loans removed one constraint&lt;/a&gt;, capital, and what fills the space that opens up is decided by us. You no longer need to own a fortune to act on Ethereum; you can borrow millions for the length of a single transaction, as long as you can write the code that pays it back. The contest moved from wealth to engineering.&lt;/p&gt;
&lt;p&gt;This episode is about what is filling that space. The short version: the opportunity is going private.&lt;/p&gt;
&lt;p&gt;When I was building my small liquidation scraper, everything I needed was public. Positions sat on-chain for anyone to read. Pending transactions waited in a public waiting room, the mempool, where anyone could watch them before they were confirmed. That openness was the quiet assumption behind the whole promise of flash loans. Capital could be borrowed, and the opportunity could be seen. A person with a laptop and a good idea could, at least in principle, compete.&lt;/p&gt;
&lt;p&gt;That second half is quietly changing. A growing share of transactions never enters the public waiting room at all. Wallets and apps send them straight to a small number of specialised companies called builders, the ones who assemble the blocks that make up the ledger. Some wallets sell the right to see their users’ transactions first, in private auctions, and hand part of the proceeds back to the user. Builders who receive the most exclusive flow can assemble the most profitable blocks, win more of them, and attract even more exclusive flow. It is a flywheel, and left alone it spins toward fewer hands. It has not closed the market: builders still compete, and some private routes are built to share flow with many of them. But the pull runs in one direction.&lt;/p&gt;
&lt;p&gt;The consequence is simple to state. A flash loan can lend you the capital for a trade. No loan can lend you the view, or the place in line that turns what you see into something you can act on. If the opportunity is sold before it ever becomes visible, let alone actionable, it does not matter how good your code is: you never get to see it, and even if you did, someone else has already been given the right to move first. Capital stopped being the moat; access is becoming the new one.&lt;/p&gt;
&lt;p&gt;It would be easy to make the private channels the villain of this story, and that would be dishonest. The same curtain protects ordinary users from the sandwich described in part one, the person in the queue who sees your hamburger order, cuts in front of you and sells it back at a higher price. A transaction sent through a &lt;a href=&quot;https://docs.flashbots.net/flashbots-protect/overview&quot;&gt;protected route&lt;/a&gt; cannot be spotted by those bots, a protection that already covers a good part of everyday trading, and some users even get paid a share of the value their transaction creates. So the private channel is two things at once. It shields the individual from predators. And it changes who the opportunity belongs to. In the open waiting room, the chance to profit from a transaction went to whoever spotted it and built the best response. Behind the curtain, that same chance becomes something a wallet or a builder can hold, price and sell, and it goes only to whoever has the right agreement. The opportunity does not disappear. It gets an owner. The honest position is to hold both sides at the same time, not to collapse them into a slogan.&lt;/p&gt;
&lt;p&gt;And the flywheel does not stop at the builders.&lt;/p&gt;
&lt;p&gt;By 2026, what sits on top of Ethereum is no longer only a price. It is a yield. Ethereum is secured by people who lock up their ETH as a guarantee of good behaviour, a practice called staking, and who are paid for keeping the network running. Today you do not have to do any of that yourself. You can buy an ETF, a fund traded on the stock exchange like any share, that &lt;a href=&quot;https://www.ishares.com/us/products/348532/ishares-staked-ethereum-trust-etf&quot;&gt;holds ETH, stakes it, and passes the income on to you&lt;/a&gt;. The fund does not run the machines itself. It hands the ETH to specialised companies that keep it safe and operate the infrastructure, while the people who own the fund never touch it. The ETF is a straw into the network, and a great many people drink through it without once seeing the machinery underneath.&lt;/p&gt;
&lt;p&gt;It is tempting to call this a threat to decentralization and stop there, but the word is too blunt to be useful. It helps to separate three different jobs. The first is confirming blocks: this is done by validators, backed by the staked ETH. The second is deciding what goes into each block: in practice this is done by the builders. The third is the waiting room, where transactions sit before anyone picks them up, in plain view or behind a curtain. Staking ETFs concentrate the first job. Private flow concentrates the second and the third. Neither automatically causes the other. The danger is in what happens when they meet.&lt;/p&gt;
&lt;p&gt;A validator on its own has a mostly economic power: it takes part in confirming blocks and gets paid for it. Economic power is loud and tends to limit itself. The power that matters is quieter. When a large share of the stake relies on the same few builders, and those builders rely on the same private flow, the question stops being how much you are willing to pay to get your transaction through. It becomes whether your transaction gets through at all, and who decided. That is not a market. It is a gate.&lt;/p&gt;
&lt;p&gt;Here is the part I keep returning to. What matters about this stake is not simply its size, but its temperament. Ethereum’s ability to resist censorship, to refuse to block a transaction because someone powerful wants it blocked, was never guaranteed by code alone. It also depended on the people running validators being many, scattered, and free to say no. The stake piling up behind ETFs changes who is in a position to say no. The investor owns a share of a fund. The fund’s ETH sits with a custodian. The machines are run by regulated companies. The person who owns the ETF has no say in how any of it behaves.&lt;/p&gt;
&lt;p&gt;If that stake ends up concentrated in the hands of a few operators, and those operators lean on a few builders with exclusive flow, the network’s ability to resist pressure depends less on the wishes of millions of owners than on the decisions of a handful of institutions.&lt;/p&gt;
&lt;p&gt;This is a risk to watch, not a behaviour already on display: large operators still tend to work with many builders. That does not make censorship inevitable. It changes where the ability to resist censorship lives.&lt;/p&gt;
&lt;p&gt;In a &lt;a href=&quot;/writing/a-powerful-tool-will-not-save-you/&quot;&gt;previous episode&lt;/a&gt; I argued that the danger of a powerful tool is not its power but its opacity. Here the danger is not the power of the stake either. It is the distance between the person who owns it and the machinery that uses it.&lt;/p&gt;
&lt;p&gt;None of this is settled, and Ethereum is not standing still. It has answered this kind of drift before, more than once. Two defences are being built against exactly this problem, and the shape they take is worth noticing.&lt;/p&gt;
&lt;p&gt;The first is inclusion lists. Under a proposal called FOCIL, a rotating group of validators publishes lists of valid waiting transactions, and a block that leaves them out is rejected. FOCIL has been &lt;a href=&quot;https://blog.ethereum.org/2026/09/07/protocol-hegota-eips&quot;&gt;locked in as a headline feature&lt;/a&gt; of Ethereum’s next major upgrade, Hegotá. It takes away the power to leave things out.&lt;/p&gt;
&lt;p&gt;The second is encrypted waiting rooms. Proposals such as LUCID and Shutter keep the content of a transaction sealed until its place in the block is already fixed. Nobody can discriminate against a transaction whose content they cannot read, and nobody can sell a first look at something no one can see. It takes away the power to see what to leave out, and with it, part of the reason to make the opportunity private in the first place.&lt;/p&gt;
&lt;p&gt;Read together, the logic is plain. Censorship needs two powers: the power to see what you want to block, and the power to leave it out. FOCIL attacks the second. Encryption attacks the first.&lt;/p&gt;
&lt;p&gt;They act on the constraints, not on the actors.&lt;/p&gt;
&lt;p&gt;Whether they arrive fast enough, and whether they hold once this much regulated capital and this much private flow are inside the system, is the open question. I do not think it is decided.&lt;/p&gt;
&lt;p&gt;Which returns us to where part one left off. Flash loans were a lesson in how quickly a constraint everyone believed in can turn out to be optional. This is the other half of the lesson. A constraint that falls does not vanish. It relocates, and it tends to relocate somewhere less visible than where it started.&lt;/p&gt;
&lt;p&gt;Flash loans opened the opportunity to anyone who could write the transaction. The next octave decides whether anyone can still see it.&lt;/p&gt;
&lt;p&gt;Capital stopped being the constraint on acting and returned, an octave away, as the constraint on being seen and being included.&lt;/p&gt;
&lt;p&gt;Freedom on this network was never really about who can afford to act. It was about whether the network can still refuse to be told what to leave out, and who gets to look first.&lt;/p&gt;
&lt;p&gt;That is the constraint worth watching now, and it is the one no clever wallet can route around.&lt;/p&gt;</content:encoded><category>Systems</category></item><item><title>The Magic of Flash Loans (Part 1): Capital Was Never the Constraint</title><link>https://sincronik.it/writing/the-magic-of-flash-loans-part-1-capital-was-never-the-constraint/</link><guid isPermaLink="true">https://sincronik.it/writing/the-magic-of-flash-loans-part-1-capital-was-never-the-constraint/</guid><description>Flash loans look like free money. They are a primitive that removes the constraint everyone assumed was fundamental.</description><pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image22.png&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;The Magic of Flash Loans (Part 1): Capital Was Never the Constraint&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;/p&gt;
&lt;p&gt;Flash loans look like free money. They are something stranger: a primitive that removes the constraint everyone assumed was fundamental, and in removing it, shows which constraint was doing the real work.&lt;/p&gt;
&lt;p&gt;The first time I heard the term flash loan, I assumed someone was joking.&lt;/p&gt;
&lt;p&gt;A loan with no collateral, no credit check and no paperwork, where a wallet holding nothing at all can borrow millions for the length of a single transaction. Outside a blockchain that is not a financial product, it is a contradiction.&lt;/p&gt;
&lt;p&gt;Inside one it is one of the more elegant primitives anyone has built, and not for the reason people usually give. It does not conjure money out of thin air.&lt;/p&gt;
&lt;p&gt;It quietly changes what a loan is.&lt;/p&gt;
&lt;p&gt;Picture someone handing you a hundred million dollars. You can do whatever you like with it: trade it, liquidate positions, buy assets, sell them, move liquidity across protocols.&lt;/p&gt;
&lt;p&gt;There is one condition.&lt;/p&gt;
&lt;p&gt;Before the transaction ends, every cent has to come back, along with a small fee. If it does not, the transaction reverts and every step inside it is rolled back together. Not unwound partially, not settled at a loss. The failed attempt still costs you the gas you spent making it, and that is the only trace it leaves.&lt;/p&gt;
&lt;p&gt;That condition is the entire trick, and it rests on something the traditional financial system does not have.&lt;/p&gt;
&lt;p&gt;A blockchain executes a transaction atomically.&lt;/p&gt;
&lt;p&gt;From the lender’s side the risk is close to zero. The funds return inside the same transaction, or they never left the vault. Repayment is not a promise you are trusted to keep.&lt;/p&gt;
&lt;p&gt;It is a precondition for the money existing in your hands at all.&lt;/p&gt;
&lt;p&gt;There is a detail worth making explicit, because it changes who the borrower even is. You do not take a flash loan by pressing a button from an ordinary address.&lt;/p&gt;
&lt;p&gt;The lender sends the funds and then calls back into the borrower to run the rest of the sequence, which means the borrower has to be code: a contract holding the whole thing, borrow, act, repay, as one programmed instruction the chain executes in one breath. Since the &lt;a href=&quot;https://ethereum.org/roadmap/pectra/&quot;&gt;Pectra upgrade&lt;/a&gt; an ordinary account can temporarily point at such code and act as that borrower itself, so deploying a separate contract is no longer strictly required.&lt;/p&gt;
&lt;p&gt;Either way the account can be empty of funds.&lt;/p&gt;
&lt;p&gt;What it cannot be empty of is logic.&lt;/p&gt;
&lt;p&gt;That idea held my attention longer than I expected. For a while I spent most of my evenings on EigenPhi, watching liquidations, arbitrage, just-in-time liquidity, and every other mechanism people were inventing on top of borrowed capital.&lt;/p&gt;
&lt;p&gt;At one point I built a small liquidation scraper of my own. Instead of monitoring every position across a lending protocol, I narrowed the search to wallets deployed through a specific contract that let users run recursive leverage loops, borrowing against their own collateral again and again to amplify their exposure to one product’s incentives.&lt;/p&gt;
&lt;p&gt;Leverage of that shape does not simply enlarge a position, it shortens the distance to the liquidation threshold: the ratio between what is owed and what is posted moves faster than the price of the asset underneath it, so a fall that an ordinary borrower would absorb pushes a looped one over the line.&lt;/p&gt;
&lt;p&gt;When the underlying dropped, those wallets went first, and they unwound into liquidations far larger than average.&lt;/p&gt;
&lt;p&gt;I could not out-execute the professionals, who were colocated, tuned, and wired into private orderflow. So I tried to compete on the search space instead: fewer opportunities, each worth much more. I set it aside eventually, not because it could not work, but because I had more important things to build.&lt;/p&gt;
&lt;p&gt;What it left behind was a suspicion about where the real limits in finance actually sit.&lt;/p&gt;
&lt;p&gt;Flash loans quietly loosen one of the oldest of them, which is capital. If an operation is guaranteed by construction to end with more than it started, and by enough to cover the loan fee and the gas, you no longer need to own the money to run it. You borrow it for the span of a single transaction and hand it straight back.&lt;/p&gt;
&lt;p&gt;The barrier does not disappear so much as move, and where it moves to is worth watching: who sees the opportunity first, who can get their transaction into the block on the right terms, who can act without broadcasting their intention into a public mempool, who sits closer to the network, who has built the better machine.&lt;/p&gt;
&lt;p&gt;The contest shifts away from wealth and toward engineering.&lt;/p&gt;
&lt;p&gt;Most people meet flash loans through stories of exploits, which is a shame, because many of their uses are ordinary and useful.&lt;/p&gt;
&lt;p&gt;Arbitrage is the clearest. Suppose ETH trades at three thousand dollars on one venue and three thousand and ten on another, and both of them are on-chain, because that is the condition that matters here: a transaction can only be atomic across things the chain itself settles.&lt;/p&gt;
&lt;p&gt;You can borrow fifty million through a flash loan, buy on the cheaper venue, sell on the dearer one, repay the loan with its fee, and keep what is left, having never owned fifty million at any point. Whether anything is left is a separate question, since the fee, the gas, and the price impact of pushing fifty million through a pool all eat into that ten dollar spread first.&lt;/p&gt;
&lt;p&gt;What you needed was not the capital. It was the ability to run every step as one indivisible act.&lt;/p&gt;
&lt;p&gt;Liquidations are the other honest case. Lending protocols let people borrow against collateral, and when the collateral falls too far, someone has to repay part of the debt and take the collateral at a discount. Without flash loans that job is rationed by access to deployable capital: it belongs to whoever happens to be sitting on enough of it at the right moment.&lt;/p&gt;
&lt;p&gt;With them, anyone who can write the transaction can borrow the repayment amount, close the unhealthy position, sell the collateral, return the loan, and keep the bonus.&lt;/p&gt;
&lt;p&gt;The protocol stays solvent, the bad debt is cleared, the liquidator is paid. It is a mechanism where the incentives happen to point the right way.&lt;/p&gt;
&lt;p&gt;Like any primitive with this much reach, it is neutral about how it is used, and the same atomicity that makes arbitrage clean makes certain attacks cheap.&lt;/p&gt;
&lt;p&gt;One is liquidity manipulation. Many protocols quietly assume that prices or pool depth stay roughly stable across a transaction. A flash loan can flood a pool with capital, distort its state for the length of a few instructions, exploit a second protocol that trusts that distorted state, and drain the capital back out before the transaction closes.&lt;/p&gt;
&lt;p&gt;Nothing was broken at the protocol level. A protocol had taken a number that was cheap to move and treated it as a reading of something expensive to move.&lt;/p&gt;
&lt;p&gt;The assumption was simply false, and the loan was large enough to prove it.&lt;/p&gt;
&lt;p&gt;Then there is the sandwich.&lt;/p&gt;
&lt;p&gt;Imagine you are standing in line to buy a hamburger at the posted price. The person behind you sees your order before it is filled. They step in front of you, buy the last hamburger at that price, which pushes the price up, and then turn around and sell it to you at the higher number, keeping the difference.&lt;/p&gt;
&lt;p&gt;You still walk away with your hamburger. You just paid more for it than you would have a moment earlier, and the extra went to someone who did nothing but stand between you and the counter.&lt;/p&gt;
&lt;p&gt;On-chain the counter is a decentralized exchange, the queue is the public mempool, and your purchase is the filling: the attacker buys just before you and sells just after, wrapping your transaction on both sides. A flash loan can pay for that position, so the attacker does not have to own the capital that moves the price.&lt;/p&gt;
&lt;p&gt;But capital was never what made this hard.&lt;/p&gt;
&lt;p&gt;This is why modern MEV is not mainly a story about money. Capital still matters, and some strategies are made of little else. But once temporary liquidity is available to anyone who can write the transaction, it stops being the thing that separates the people who capture value from the people who watch it go past.&lt;/p&gt;
&lt;p&gt;What separates them is information, position, and execution: who sees the opportunity first, who can get their bundle into the block that actually gets built, who avoids leaking their intent into the open, who has built the machine that does all three a little better than everyone else.&lt;/p&gt;
&lt;p&gt;And getting there is not a footrace to the validator. It is an auction, run through searchers and builders and relays, where the bid is not only in gas.&lt;/p&gt;
&lt;p&gt;Capital stopped being the moat.&lt;/p&gt;
&lt;p&gt;The moat is now upstream, in the engineering.&lt;/p&gt;
&lt;p&gt;Which brings the whole thing back to where this newsletter usually starts. The magic of flash loans was never that they abolished collateral. It was that they exposed a mistaken assumption about which constraint was load-bearing.&lt;/p&gt;
&lt;p&gt;We treated capital as the wall, the thing you had to own before you could act, when capital was only ever a proxy for the constraint that actually bound: time, and the trust that has to fill it.&lt;/p&gt;
&lt;p&gt;Borrowing, trading, settlement and repayment were separate acts with gaps between them, and traditional finance has spent a century building machinery to survive those gaps. Credit lines, prime brokers, collateral agreements, netting, intraday facilities: all of it is a way of paying someone to carry the risk the gap creates.&lt;/p&gt;
&lt;p&gt;Atomicity does not manage the gap. It removes it, and with it the need to be trusted across it.&lt;/p&gt;
&lt;p&gt;Once that became possible, the wall we had been building against turned out not to be there.&lt;/p&gt;
&lt;p&gt;It made some markets dramatically more efficient and it handed some people a cheaper way to steal. All it did was remove one constraint. What fills the space that opens up is not decided by the primitive.&lt;/p&gt;
&lt;p&gt;It is decided by us.&lt;/p&gt;
&lt;p&gt;That raises a different question: where does the constraint reappear once capital is no longer the gate?&lt;/p&gt;</content:encoded><category>Systems</category></item><item><title>Two Sweeps Pointed at the Same Address</title><link>https://sincronik.it/writing/two-sweeps-pointed-at-the-same-address/</link><guid isPermaLink="true">https://sincronik.it/writing/two-sweeps-pointed-at-the-same-address/</guid><description>The tracing was done and the report was already with law enforcement when the client told me the part that reopened the case.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image21.jpeg&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Two Sweeps Pointed at the Same Address&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;/p&gt;
&lt;p&gt;The tracing was done and the report was already with law enforcement when the client told me the part that reopened the case. His wallet had been emptied weeks earlier. The seed phrase had leaked, the balance was gone before anyone noticed, and that is normally where the conversation ends.&lt;/p&gt;
&lt;p&gt;Part of his ETH had never been in the wallet. It was staked.&lt;/p&gt;
&lt;p&gt;Ethereum runs on two halves. The execution layer is the one everybody sees, where transactions are sent and balances move. The consensus layer is the ledger of validators, the machines that lock up ETH to secure the network and get paid for it. Staked ETH is credited to a validator over there, and it comes back to an ordinary address only when the validator leaves and the protocol pays it out, which is slow by design and visible to everyone.&lt;/p&gt;
&lt;p&gt;So there was money with a legitimate owner, untouched, scheduled to arrive in an address whose key a thief also held. The thief had to do nothing. His software was already waiting.&lt;/p&gt;
&lt;h2 id=&quot;the-machine-on-the-other-side&quot;&gt;The machine on the other side&lt;/h2&gt;
&lt;p&gt;A sweeper bot is a script with one instruction: watch this address, and move anything of value out of it the moment it appears. Leaked keys are collected in bulk, from phishing kits, fake wallet apps, a seed phrase photographed into a cloud backup, and each one is handed to the same loop. The loop costs almost nothing to run, so it can wait for years.&lt;/p&gt;
&lt;p&gt;This account was close to ideal for one. A compromised key cannot be un-compromised. The payout address was not going to change either: once a validator’s withdrawal credentials are set, pointing them at a clean address is not something the protocol offers today, whatever may come later. And the schedule was public, so both sides were reading the same screen.&lt;/p&gt;
&lt;p&gt;Quality varies at the other end. Cheap sweepers take the native ETH and leave the tokens, which is why victims sometimes find their ERC-20 balances untouched inside an account that empties itself every time it is funded. The better ones bring their own gas and take those too.&lt;/p&gt;
&lt;p&gt;Sending gas is the trap that makes most rescues fail. Moving a token takes a transaction, and a transaction takes ETH sitting in the same account, so rescuing a token means funding the account that holds it. That funding is exactly what the bot is watching for. Plenty of people meet their sweeper by feeding it, and watch the gas leave for another address seconds later.&lt;/p&gt;
&lt;h2 id=&quot;the-tools-for-the-ordinary-case&quot;&gt;The tools for the ordinary case&lt;/h2&gt;
&lt;p&gt;The stack I use when the account holds assets it cannot move and the gas has to come from outside is &lt;a href=&quot;https://dark.florist/&quot;&gt;Dark Florist’s&lt;/a&gt;, open source and free.&lt;/p&gt;
&lt;p&gt;The Interceptor is a browser extension that sits between the dApp and the wallet. It simulates every transaction before you sign it and says in plain language what it will do. Its simulation stack runs several transactions in sequence, as if they had been mined one after another, so you can see whether step three still works after steps one and two changed the state. It also lets you browse as any address without holding its keys, which is how a rescue gets built for an account you cannot sign for yet.&lt;/p&gt;
&lt;p&gt;Bouquet turns that simulation into a bundle. It lays out the sequence with values and fees, takes the signing keys and keeps them in the browser, and asks you to top up a temporary funding account with what the bundle needs plus a margin for a rising base fee. Rescue bundles go out through the relay only, so the funding is never exposed in the public mempool on its own, and nothing can be slipped between the funding and the rescue sweep. It also refuses to work on a stale picture, rejecting an import that did not come cleanly out of the simulation and warning when the transactions it holds no longer match what the simulation shows. With one attempt available, the refusal is the feature.&lt;/p&gt;
&lt;p&gt;The rest of the stack has the same shape, small interfaces with no backend to trust: Lunaria for sending tokens, NFT Sender for NFTs, Petal Lock for immutable ENS subnames, Horswap as a censorship resistant interface to Uniswap.&lt;/p&gt;
&lt;h2 id=&quot;the-money-arrives-without-a-transaction&quot;&gt;The money arrives without a transaction&lt;/h2&gt;
&lt;p&gt;Here the case stopped resembling anything I had done before.&lt;/p&gt;
&lt;p&gt;The consensus layer does not pay out by sending a transaction. The protocol raises the balance of the destination address directly, while the block is being built. No sender, no gas, no code running at the receiving end, nothing sitting in the queue of pending transactions where everyone watches for prey. Ethereum’s own &lt;a href=&quot;https://ethereum.org/staking/withdrawals/&quot;&gt;documentation&lt;/a&gt; has a name for this way of paying validators out, and the name is the sweep: the same word the industry uses for what the thief’s software does to a compromised account.&lt;/p&gt;
&lt;h2 id=&quot;the-fight-happens-in-the-next-block&quot;&gt;The fight happens in the next block&lt;/h2&gt;
&lt;p&gt;The absence of a transaction cuts both ways. There is nothing to front-run, and nothing to get ahead of: withdrawals from the consensus layer are credited after all the transactions in the block that carries them, so that ETH cannot be spent inside that block by anyone, thief included. Everything is decided at the top of the next one.&lt;/p&gt;
&lt;p&gt;And we did not know what the bot could see. A basic one reads the pending transactions in the public mempool, which is the thing you can hide from. A better one also reads each block once it is confirmed, reacting to the balance itself and not only to somebody’s stated intentions, and it can follow the exit queue and see the payout coming roughly when we did.&lt;/p&gt;
&lt;p&gt;The gas trap did not apply here, and that helped less than it sounds. What was landing was ETH, and ETH pays for its own movement, so there was no funding to smuggle in and nothing to wrap it with. One transfer, out of an address that two parties can sign for, and the only thing left to win was position in the block after the credit.&lt;/p&gt;
&lt;p&gt;You can still stop broadcasting. Instead of entering the public mempool, the transaction goes privately to a builder through a relay, inside a bundle aimed at a specific block. That matters because you cannot line up a public transaction for money that has not arrived yet: execution clients reject it from their transaction pools. A bundle can wait for the block where the money will be. It is never gossiped across the public network while it waits, and if it is not included it simply expires without being mined, so the attacker has nothing to see and nothing to react to.&lt;/p&gt;
&lt;p&gt;The saved fee is not the point. Losing the block costs everything, because there is one credit and whoever moves first keeps it.&lt;/p&gt;
&lt;p&gt;So the choice was between two risks. Public, and be outbid inside the mempool by a bot that answers in milliseconds and pays more. Private, and depend on a builder carrying your bundle winning that particular block, against an adversary who may be reading the balance rather than the mempool, and who can stay public with an enormous tip that any builder in the market will take.&lt;/p&gt;
&lt;p&gt;How many blocks to cover, what to pay for each attempt, whether to stay private or go loud: those were the real decisions, there was no time to work through them properly, and I did not have the repetitions behind me to make them fast.&lt;/p&gt;
&lt;h2 id=&quot;where-i-stopped&quot;&gt;Where I stopped&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://www.flashbots.net/&quot;&gt;Flashbots&lt;/a&gt; is the research organisation formed to study and mitigate MEV, the value extracted by whoever decides the order of transactions inside a block. Much of the infrastructure a rescue like this leans on came from there: the bundle model, MEV-Boost, Protect, and now BuilderNet. Whitehat rescues have lived in its orbit from the beginning.&lt;/p&gt;
&lt;p&gt;I introduced the client to them and stepped back. Every rescue I was familiar with had the same shape: the assets are still sitting in the account, and the opponent is a bot with a faster reaction time. This one was different in the parts that decide the outcome. The money arrives once. How the wallet was being watched, and what triggered the signature, we never knew. A miss cannot be taken back. Those are things you get right by having done them often, and I had not.&lt;/p&gt;
&lt;p&gt;I checked when the redemption came due. The money got out in time.&lt;/p&gt;
&lt;p&gt;Two sweeps were pointed at the same address, and only one of them was going to end up with the money. Method includes knowing which part of a problem you can time, and handing the rest to somebody who can.&lt;/p&gt;</content:encoded><category>Investigations</category></item><item><title>The Desk Opens on Monday</title><link>https://sincronik.it/writing/the-desk-opens-on-monday/</link><guid isPermaLink="true">https://sincronik.it/writing/the-desk-opens-on-monday/</guid><description>The stolen value lands at an exchange on a Saturday night. You watch the deposit confirm. That desk opens on Monday.</description><pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image20.png&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;The Desk Opens on Monday&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;/p&gt;
&lt;p&gt;The stolen value lands at an exchange on a Saturday night. You watch the deposit confirm. One action can stop it now and it is not yours to take: somebody at that exchange has to freeze the account, and that desk opens on Monday.&lt;/p&gt;
&lt;p&gt;A recovery turns on moments like that one. Stolen value cannot stay in motion forever, and sooner or later it comes to rest with somebody who holds it on the thief’s behalf: an exchange, a broker, some custodial service. That is the window, and it exists because a third party now has the funds and can decline to release them. Most of the attention in this work goes to the tracing that finds the window. What decides the case is more often whether somebody is ready to act in the hours it stays open.&lt;/p&gt;
&lt;p&gt;The width of a window is not something you read off the chain. What governs the outcome is how much of that time somebody on the receiving end is awake, reachable, and authorised to act.&lt;/p&gt;
&lt;p&gt;A great deal of illicit value moves late on a Friday. The ledger is no darker then and the timing conceals nothing; it leaves the request with nowhere to land. Public holidays do the same with more leverage, joining two dead stretches into one, so a desk closing on a Wednesday evening may not reopen until the following Monday. And a recovery rarely depends on a single desk: the exchange sits in one country, the authority whose signature is needed usually in another, and their waits do not overlap. Each handoff begins when the one before it ends, so the delays add.&lt;/p&gt;
&lt;p&gt;The fastest thing that can happen to a case needs no authority at all. An exchange can freeze an account on its own initiative, before a court has said anything, and that is the only route quick enough to catch a window opening on a Saturday. It is conditional on form. Every venue has its own way of receiving such a request, and its compliance team has to validate what arrives against criteria you do not set and cannot see. A request they cannot validate is not usually refused. It comes back as a question, or it waits in a queue until somebody can classify it, and inside a window a slow answer and a refusal produce the same result: the money moves on.&lt;/p&gt;
&lt;p&gt;Most of the time you do not learn what they need until you have already sent something. The requirements are rarely published, they differ between venues and between the people staffing them, and they change. So the volley that happens at a lawyer’s desk happens here too, compressed into hours. They come back wanting the path expressed differently: the bridge hops decoded in a more familiar way, or the share of each transaction attributable to fraudster-controlled funds calculated according to a methodology they recognise. And the same finding has to be restated in a structure their own systems will accept. Each question is another day against a window that is already open.&lt;/p&gt;
&lt;p&gt;I lost a window that way. I had sent an exchange the path as I had built it, with the bridge transfers evidenced from the transaction payloads, which is where the proof actually sits. The compliance team did not work in that form and could not check it. They came back asking, and I rewrote the report around links to the same transfers on a bridge explorer, in a view they could open and read without taking my word for any of it. The second version was correct, and so was the first. While the two of us established that, the funds left the exchange.&lt;/p&gt;
&lt;p&gt;Preparation, then, cannot mean knowing the answer beforehand. It has to mean producing a new version of the finding in hours rather than weeks: the decoding automated, the path already normalised, the evidence held in a form that can be re-cut on demand. The usual case for automation is speed, and speed of tracing counts for nothing by then, because the tracing is done. What automation buys is the ability to re-present a finished finding, in a shape nobody warned you about, before the window closes. What you build in advance is the capacity to rebuild the document, rather than the document.&lt;/p&gt;
&lt;p&gt;When that route is closed, or has been pursued as far as it can go, the case goes to one of two desks, and they are not interchangeable. On the civil route it belongs to a lawyer acting for the victim, who brings you in as the expert. On the criminal route it belongs to law enforcement, and in most jurisdictions they cannot adopt what you found: the investigation has to be theirs, conducted and evidenced independently, however good the work that reaches them.&lt;/p&gt;
&lt;p&gt;That obligation settles what the report has to be. A document written to persuade is the wrong object for a reader who is not permitted to be persuaded. What they need is a route they can walk themselves: sources, queries, and reasoning set out so each step can be reproduced from primary data on their own systems. Every step they cannot reproduce is one they have to rebuild from nothing, and rebuilding is counted in weeks. The report works better as a teaching document than as an argument.&lt;/p&gt;
&lt;p&gt;The lawyer’s desk fails in the opposite direction. There you are taken as the expert, and what follows is a volley: why this address and not the one beside it, what rules out the innocent explanation, how this holds if the other side puts an expert against it. Each round of questions costs days. A report that answers them only once they are asked has spent the window on its own correspondence.&lt;/p&gt;
&lt;p&gt;Before any of that, the instruction itself needs reading. It comes from the lawyer, and it carries a non-technical model of what happened, so a scope drawn from a mistaken premise produces a narrow task, carried out correctly, that answers a question nobody needed answered. The cost stays invisible until the work comes back and the real question is still standing. Examining the assumptions inside the request, and saying so early, belongs to the work rather than to the courtesy around it.&lt;/p&gt;
&lt;p&gt;Whatever is handed across is closer to a photograph than to a live feed: the case as it stood when it was taken, faithful to its instant and to nothing after. None of it can be timed. The money surfaces when it surfaces and will not wait for the offices to open, so the preparation has to be finished before the night it is needed, down to one named person watching the few addresses that matter, so that a movement reaches somebody instead of a queue.&lt;/p&gt;
&lt;p&gt;A picture can also stop being true while nobody touches it. A balance can read as full after the tokens behind it have been burned, on platforms that follow transfers without reading the contract’s own state. Whoever holds the case then acts in full confidence on a screen that stopped being accurate hours earlier, and speed is no protection, because the fault is in how the balance is represented rather than in the delay.&lt;/p&gt;
&lt;p&gt;Which is where this stops being a problem of logistics. Three readers, and the same requirement in three shapes: a compliance team that has to validate on its own criteria, an officer who has to rebuild the case as their own, a lawyer who has to defend it against someone paid to break it. None of them can take your word for it. Finding the truth is half of an investigation; representing it so that somebody else can reach it independently is the other half.&lt;/p&gt;
&lt;p&gt;The blockchain keeps no calendar. Everyone who can act on what it shows keeps one. Knowing where the money is changes nothing by itself: the work that decides the outcome happens before the window opens, and consists of making sure somebody is standing in it, holding a picture still true enough to act on.&lt;/p&gt;</content:encoded><category>Methods</category></item><item><title>Achilles Catches the Tortoise Where It Has to Stop</title><link>https://sincronik.it/writing/achilles-catches-the-tortoise-where-it-has-to-stop/</link><guid isPermaLink="true">https://sincronik.it/writing/achilles-catches-the-tortoise-where-it-has-to-stop/</guid><description>An investigation moves in steps. What it chases appears not to. Every action is discrete: you pull transactions, map a cluster, document a finding.</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image19.png&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Achilles Catches the Tortoise Where It Has to Stop&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;/p&gt;
&lt;p&gt;An investigation moves in steps. What it chases appears not to.&lt;/p&gt;
&lt;p&gt;Every action is discrete: you pull transactions, map a cluster, document a finding. Each step costs time and resources, and each has to survive later scrutiny: authorized, reproducible, auditable. Automation only shortens the steps.&lt;/p&gt;
&lt;p&gt;The bottleneck it never removes is the delivery of the report, which stays a discrete, accountable act no matter how fast the tracing gets. The procedures that confer evidentiary weight are quantized by nature.&lt;/p&gt;
&lt;p&gt;You cannot half-file a report. A court will not accept a motion still in motion. Meanwhile the funds you documented an hour ago have already crossed a bridge and split into forty new addresses.&lt;/p&gt;
&lt;p&gt;The adversary lives under no such rule. They can split funds across hundreds of addresses, cross a bridge, enter a &lt;a href=&quot;/glossary/coin-mixer/&quot;&gt;mixer&lt;/a&gt;, and do it again, at any hour, with no form to sign and no record to defend. Their motion looks continuous. While you commit to a snapshot, they keep going.&lt;/p&gt;
&lt;p&gt;But it only looks continuous. A blockchain is still block after block, transaction after transaction. The adversary’s advantage is not the absence of discreteness; it is the absence of gates. No authorization, no documentation, no accountability.&lt;/p&gt;
&lt;p&gt;Without those forced pauses, their discrete actions blur into a kind of operational continuity. The shared discreteness does not erase the asymmetry. It shows exactly where it lives: in who is forced to stop between the units, and who is not.&lt;/p&gt;
&lt;p&gt;It is tempting to call that motion infinite. It is not, and the whole premise of this newsletter is why. An adversary in constant motion still runs on rails it cannot leave. Balances reconcile. Code executes exactly as written. Every transaction must satisfy the protocol’s own validity rules. Speed is not freedom from constraint.&lt;/p&gt;
&lt;p&gt;The attacker can move without pause, but never without obeying the system that carries them.&lt;/p&gt;
&lt;p&gt;So the real asymmetry is not the one it first appears to be. Both sides are bounded, and both move in discrete events. What separates them is accountability.&lt;/p&gt;
&lt;p&gt;The investigator has to stop in order to be right out loud: to document, to authorize, to produce something that holds. The adversary never does. One advantage is kinetic, the freedom to move without justifying a single step. The other is epistemic, the duty to produce knowledge that survives scrutiny. And here the ground favors the investigator: on-chain, nothing the adversary does is ever erased, and work done well only gets stronger the harder it is examined.&lt;/p&gt;
&lt;p&gt;That is the asymmetry, and it changes the shape of the problem. Not how a small force defeats an endless one, but how a process that moves in steps can pin one that never pauses.&lt;/p&gt;
&lt;p&gt;It feels like Zeno’s paradox. By the time Achilles reaches where the tortoise was, it has moved again. The gap shrinks forever and never closes.&lt;/p&gt;
&lt;p&gt;An investigation often feels the same, though not because you cannot see the money. You can watch it move in real time. The lag is in the step you are allowed to take: by the time a report is written, sent, and processed, the situation it describes has already shifted. Each accountable move lands a beat behind the thing it was aimed at. But the paradox rests on one assumption: that the tortoise can run forever.&lt;/p&gt;
&lt;p&gt;You do not try to match the adversary’s speed. You will lose that race by design. You aim your discrete steps at what cannot move: the constraints. The coins have already left the address you found. The rules that govern where they can go have not.&lt;/p&gt;
&lt;p&gt;And the report is not your only move. You can put constraints in place ahead of the money: flag adversary-controlled addresses at their likely destinations and keep those flags persistent as the value changes form, bridged, swapped, wrapped. The objective is to ensure that even a compliance system conducting a deep search cannot be defeated by a single additional protocol-mediated hop.&lt;/p&gt;
&lt;p&gt;Not every destination will act on the flag, and not every trap will hold. That is beside the point. Every constraint removes another place where the money can land cleanly. At that point, you are no longer just chasing the runner. You are fencing off the ground it has left to run on.&lt;/p&gt;
&lt;p&gt;This is why the report, the most quantized artifact of all, is both weakness and strength. Comparing its latency to the adversary’s speed is comparing two different games. But the games are entangled: the kinetic advantage and the epistemic one resolve into a single outcome. The adversary has to win every step to stay free; you have to make just one accountable move that holds.&lt;/p&gt;
&lt;p&gt;On a public ledger the trail does not decay. Every move made to outrun you also records the path you will later follow. Latency is fatal only against evidence that fades.&lt;/p&gt;
&lt;p&gt;And the flight has a destination. Stolen value almost never stays in perpetual motion. It seeks a cash-out: an exchange, a purchase, a point where it must re-enter the recorded world.&lt;/p&gt;
&lt;p&gt;Sometimes you do not even need to wait. If the value sits inside an issuer-controlled token whose contract allows blacklisting, the tortoise can be stopped where it stands. The instant it halts, by arrival or by freeze, the race ends. You were never going to overtake it stride for stride. You were going to be waiting where it had to come to rest.&lt;/p&gt;
&lt;p&gt;You move in steps. You will not catch it by running. You catch it where it has to stop.&lt;/p&gt;</content:encoded><category>Methods</category></item><item><title>Why Blind Experts Fail, and How Great Teams Connect the Dots</title><link>https://sincronik.it/writing/why-blind-experts-fail-and-how-great-teams-connect-the-dots/</link><guid isPermaLink="true">https://sincronik.it/writing/why-blind-experts-fail-and-how-great-teams-connect-the-dots/</guid><description>Imagine a world where everyone is an expert in a different cheese, yet no one knows how to pair them, or even notices when one has gone bad.</description><pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image18.jpeg&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Why Blind Experts Fail, and How Great Teams Connect the Dots&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;/p&gt;
&lt;p&gt;Imagine a world where everyone is an expert in a different cheese, yet no one knows how to pair them, or even notices when one has gone bad.&lt;/p&gt;
&lt;p&gt;That is how skyscrapers of knowledge end up built on foundations of fog.&lt;/p&gt;
&lt;p&gt;We are often told that specialization broadens our horizons. And within a single field, it does. But when every path leads deeper into the same narrow ground, something is quietly lost. Specialization channels us, standardizes us, and slowly makes us interchangeable: predictable and useful within our lane, yet strangely helpless the moment a problem refuses to stay inside it.&lt;/p&gt;
&lt;h2 id=&quot;the-age-of-the-blind-expert&quot;&gt;The Age of the Blind Expert&lt;/h2&gt;
&lt;p&gt;This is what fragmentation does to a mind.&lt;/p&gt;
&lt;p&gt;It produces blind experts, incapable of seeing beyond the borders of their own domain. It is like knowing every room of a house yet never having seen it from the street.&lt;/p&gt;
&lt;p&gt;The more we know within our narrow fields, the less capable we seem of navigating the complexity of the real world, where problems never arrive neatly labeled by department. And cheeses, to continue the metaphor, are rarely meant to be enjoyed on their own.&lt;/p&gt;
&lt;p&gt;Extreme specialization promises progress. More often, it produces a sophisticated form of ignorance: we know everything about our tiny piece of the puzzle, yet we have lost the map that shows where it belongs.&lt;/p&gt;
&lt;p&gt;And there is a quiet cost to this. When you only ever know your own function, it becomes hard to picture how the whole fits together, or to imagine that it might fit differently.&lt;/p&gt;
&lt;p&gt;The answer is not to reject expertise. It is to reclaim the right to intellectual curiosity across disciplines, and to ease the friction that keeps us from reaching the seemingly useless, the unexpected connection, the open channel to another field.&lt;/p&gt;
&lt;p&gt;Ancient wisdom understood this well: fragmented knowledge is lifeless knowledge. The great thinkers of the past were natural philosophers, artist-scientists, poet-mathematicians. Not because they lacked depth, but because they recognized that reality is woven from connections invisible to the specialist’s microscope.&lt;/p&gt;
&lt;p&gt;An expert who never leaves their own discipline is like a cheesemonger who knows everything about Roquefort yet has never tasted wine. The expertise is real. The judgment, without enough context, is not.&lt;/p&gt;
&lt;p&gt;Regaining the ability to “pair the cheeses” takes a small, everyday discipline:&lt;/p&gt;
&lt;p&gt;Cultivate curiosity and venture beyond your own field. Speak with people whose work is nothing like yours. Practice the art of analogy. Learn to express your own discipline in plain language.&lt;/p&gt;
&lt;p&gt;And remember that we are human beings before we are professionals. No specialist, however brilliant, is free from error. I have never met anyone who never made a mistake, and I have made plenty myself.&lt;/p&gt;
&lt;p&gt;What makes a team resilient is not the absence of mistakes, but the presence of complementary perspectives and mutual checks. You notice what I overlook; I recognize patterns invisible to you. The value is not only in the redundancy that ensures safety, but in the mutual correction of the larger picture.&lt;/p&gt;
&lt;p&gt;We often celebrate individual expertise while overlooking something even more valuable: the channels through which expertise flows. Information does not become understanding simply because it is shared. It becomes understanding only when another mind can receive it without distortion.&lt;/p&gt;
&lt;h2 id=&quot;knowledge-against-resistance&quot;&gt;Knowledge Against Resistance&lt;/h2&gt;
&lt;p&gt;The real world makes this unavoidable. Hard problems do not respect academic departments or professional silos. They cut straight across them, and they are often hardest precisely where the boundaries lie.&lt;/p&gt;
&lt;p&gt;Nowhere is this clearer than in an investigation.&lt;/p&gt;
&lt;p&gt;An investigation is, in the end, the acquisition of knowledge against an antagonistic constraint: someone has worked to keep that knowledge from you.&lt;/p&gt;
&lt;p&gt;The trail is fragmented on purpose, the channels deliberately broken, the cheeses scattered so that no single nose can pair them. To reconstruct what someone has labored to hide, you must move across the very domains they counted on staying separate.&lt;/p&gt;
&lt;p&gt;This tells us something about knowledge itself.&lt;/p&gt;
&lt;p&gt;We assume that because information is abundant, knowledge is too. It is not. Knowledge behaves like a material. It has structure, density, friction, and scarcity. Access to information does not automatically grant access to knowledge, just as owning bricks does not teach you how to build a cathedral.&lt;/p&gt;
&lt;p&gt;One thinker who put this well was Gurdjieff. He argued that knowledge is not an infinite common resource. It exists in finite quantities, concentrated in particular places, moments, and relationships. It must be acquired, not merely accessed.&lt;/p&gt;
&lt;h2 id=&quot;navigation-in-the-era-of-ai&quot;&gt;Navigation in the Era of AI&lt;/h2&gt;
&lt;p&gt;This distinction becomes even more critical in the age of AI.&lt;/p&gt;
&lt;p&gt;AI drastically lowers the cost of obtaining answers, but it does not lower the cost of asking the right questions. It accelerates retrieval and pattern-matching, but it inherits the very corpus fragmentation it was trained on.&lt;/p&gt;
&lt;p&gt;Information is abundant. Knowledge is scarce.&lt;/p&gt;
&lt;p&gt;Anyone can ask an AI a question. Expertise is knowing whether the question is even worth asking, or merely misleading.&lt;/p&gt;
&lt;p&gt;As answers become increasingly abundant, good questions become increasingly scarce.&lt;/p&gt;
&lt;p&gt;As Umberto Eco (whose legacy I luckily caught a glimpse of through his student, my semiotics professor) often argued: culture is not the accumulation of information. It is the ability to navigate it, to know where to look, how to evaluate what we find, and how to connect it into understanding.&lt;/p&gt;
&lt;h2 id=&quot;the-architecture-of-a-team&quot;&gt;The Architecture of a Team&lt;/h2&gt;
&lt;p&gt;This is why assembling a team is not simply a matter of gathering the best specialists. A team is an architecture of knowledge. Each person holds a different fragment, but value emerges only when those fragments become connected.&lt;/p&gt;
&lt;p&gt;The bridge itself is knowledge, and has to be shared to work.&lt;/p&gt;
&lt;p&gt;Not the specialists. Not the information they possess. The bridge that allows one domain to reach another without distortion, without translation loss, without filters.&lt;/p&gt;
&lt;p&gt;The highest-leverage nodes are often the translators, the synthesizers, the boundary-spanners: the ones who can move between domains with minimal distortion. They reduce friction and catch blind spots, and out of those connections, understanding finally emerges.&lt;/p&gt;
&lt;p&gt;Knowledge does not merely reside in people. It resides in the bridges between them.&lt;/p&gt;
&lt;p&gt;Specialists collect cheeses. Great teams learn how to pair them.&lt;/p&gt;</content:encoded><category>Methods</category></item><item><title>Second-Hand World (Part 2): The Role of Knowing</title><link>https://sincronik.it/writing/second-hand-world-part-2-the-role-of-knowing/</link><guid isPermaLink="true">https://sincronik.it/writing/second-hand-world-part-2-the-role-of-knowing/</guid><description>The argument so far leaves us in an uncomfortable place. The old question returns: is the model merely manipulating symbols, or does it know something?</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image17.png&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Second-Hand World (Part 2): The Role of Knowing&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;/p&gt;
&lt;p&gt;The argument so far leaves us in an uncomfortable place. &lt;a href=&quot;/writing/second-hand-world-part-1-what-llms-inherit-from-the-world-they-never-touched/&quot;&gt;(Read Part 1)&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;If grounding admits of degrees, and if testimonial knowledge already relies on inherited contact with the world, then the old question returns in a sharper form: is the model merely manipulating symbols, or does it know something?&lt;/p&gt;
&lt;p&gt;And that question exposes what was really being assumed all along.&lt;/p&gt;
&lt;p&gt;We asked whether the LLM is the kind of thing that can know, as if kinds came stamped in advance. We asked whether its symbols mean anything, as if meaning were a built-in property rather than a projected role something plays in a world.&lt;/p&gt;
&lt;p&gt;Both questions take for granted that “knows” names a natural boundary out there in reality, waiting to be respected or violated.&lt;/p&gt;
&lt;p&gt;Perhaps it does. Perhaps it doesn’t.&lt;/p&gt;
&lt;p&gt;The functional tradition rejects that assumption. It treats “knows” as a role rather than a substance: a functional term wearing the costume of a deep fact about reality.&lt;/p&gt;
&lt;p&gt;It stretched from perception to memory to testimony to instruments, and no agreed essence was ever isolated. The thermometer detects. The immune system remembers. Each extension was metaphor hardening into ordinary use.&lt;/p&gt;
&lt;p&gt;The point is not that these cases prove anything about language models. They do not.&lt;/p&gt;
&lt;p&gt;The point is historical: vocabulary has repeatedly expanded beyond conscious agents without waiting for a settled theory of essence to authorize the move.&lt;/p&gt;
&lt;p&gt;And there is a twist the model cannot escape: this very history, of epistemic words spreading without a license, sits inside the corpus it was trained on.&lt;/p&gt;
&lt;p&gt;It has read the case for its own admission.&lt;/p&gt;
&lt;p&gt;The cleanest version of the question has a classical form: knowledge as justified true belief, a belief that is true and that the knower can justify. It’s the right tool, and instructive for the same reason the formal system was: because of where it strains.&lt;/p&gt;
&lt;p&gt;In 1963, Gettier showed that the three conditions can all be met and still fall short: a belief can be true, and justified, and true for reasons that have nothing to do with what justifies it.&lt;/p&gt;
&lt;p&gt;The justification does its work; luck slips in between it and the truth. So justification alone stops drawing the line.&lt;/p&gt;
&lt;p&gt;What epistemology (the branch of philosophy that studies knowledge) did next is the telling part.&lt;/p&gt;
&lt;p&gt;It didn’t conclude that knowledge has no boundary; it went looking for the boundary elsewhere, in reliability, in intellectual virtue, in the exclusion of luck, in proper function.&lt;/p&gt;
&lt;p&gt;Each account draws a line, and draws it somewhere real.&lt;/p&gt;
&lt;p&gt;But each line is built by a theory answering to a purpose, never found sitting in the world before the theory arrived.&lt;/p&gt;
&lt;p&gt;A realist can read the same sixty years as a hard boundary not yet located. Perhaps; the history is compatible with both readings. But sixty years of defensible, divergent lines do not prove there is no essence; they only take from the realist the right to assume one.&lt;/p&gt;
&lt;p&gt;And for the argument here, that is enough. The functional reading doesn’t need to win; it needs only to be as legitimate as its rival, because everything that follows stands on that parity alone.&lt;/p&gt;
&lt;p&gt;So the clean question, “is this real knowledge or mere metaphor?”, is badly posed.&lt;/p&gt;
&lt;p&gt;Not because it has no answer, and not because rejecting an essence makes everything blur together: chess is still chess, photosynthesis is still photosynthesis, and some uses of “knowing” are settled and stay settled.&lt;/p&gt;
&lt;p&gt;It’s badly posed because it assumes there is a threshold between real knowledge and mere metaphor that existed before we came along, waiting to be discovered.&lt;/p&gt;
&lt;p&gt;There isn’t, or at least no one has earned the right to assume there is. Every threshold we have was drawn by a theory of knowledge, for that theory’s own purposes.&lt;/p&gt;
&lt;p&gt;This doesn’t mean the question is empty. There are real, checkable constraints on when grounding holds: a chain of cause and history linking the system to the thing it represents, a function the representation actually serves, a process that is reliable, an outcome that isn’t just luck.&lt;/p&gt;
&lt;p&gt;A given system can satisfy these constraints to a greater or lesser degree, and in different ways.&lt;/p&gt;
&lt;p&gt;Second-hand grounding names a route, contact through traces rather than through contact, and the constraints apply to that route as they apply to any other. A long chain is not automatically a weak one, and a short chain is not automatically strong.&lt;/p&gt;
&lt;p&gt;Once you fix which constraints matter, whether that system counts as knowing is a real question with a real answer.&lt;/p&gt;
&lt;p&gt;What doesn’t exist is an answer that comes before any constraints, a fact about where the flattering label “knows” belongs that holds independently of them. And this is how the label actually spreads: every time “knowledge” gets extended to a new kind of system, a metaphor is slowly becoming literal.&lt;/p&gt;
&lt;p&gt;Slowly, and never by simple declaration.&lt;/p&gt;
&lt;p&gt;But who decides which resemblances count? No theory does, in advance. Practice decides, retrospectively, and not practice as mere popularity.&lt;/p&gt;
&lt;p&gt;An extension stays honest not because no one rejects it, but because it withstands the attempts at rejection: because it keeps holding up against the same constraints (the causal chain, the function served, the reliability, the exclusion of luck) when someone actively tries to break it.&lt;/p&gt;
&lt;p&gt;“The thermometer detects” survived the people who tested it, not just the people who never noticed. That resistance under pressure is what keeps the extension honest.&lt;/p&gt;
&lt;p&gt;What’s left is the collapse of the frame that generated the two options. Grounding comes in degrees and in kinds; Knowing was never the private property of minds, nor of theorems. It was a role, and a role doesn’t care about the inner nature of whatever fills it, though it cares very much whether it is filled at all.&lt;/p&gt;
&lt;p&gt;Some architectures may turn out to be a real case of it; others may fail to be. That is exactly the question worth asking.&lt;/p&gt;
&lt;p&gt;What we are owed is not a verdict in advance on which kinds of thing are eligible, but an account, case by case, of which systems stand in the relations the role requires.&lt;/p&gt;
&lt;p&gt;A model that knows the world only second-hand knows it thinly, unevenly, by inheritance. So does anyone who has read more than they have lived. The difference is that the reader grafts what they read onto a stock of first-hand contact, and the model has no stock to graft onto.&lt;/p&gt;
&lt;p&gt;That asymmetry is real. But it is exactly what the constraints are for: a difference to be measured, not a disqualification to be announced in advance.&lt;/p&gt;
&lt;p&gt;The knower being neither mind nor theorem was only ever a problem for a theory that needed it to be one. It was never obvious that knowledge required either.&lt;/p&gt;
&lt;p&gt;The argument here is not that language models belong inside the category. It is that no theory has earned the right to close the category before the investigation begins. Whether a system possesses a thin form of grounding and whether it is the right engineering solution are largely orthogonal questions.&lt;/p&gt;
&lt;p&gt;Epistemic legitimacy and engineering wisdom are often different questions with different answers.&lt;/p&gt;
&lt;p&gt;One personal note to end on.&lt;/p&gt;
&lt;p&gt;The interesting question is whether these systems can ground their outputs. The boring truth is that many of them should not be running an LLM at all.&lt;/p&gt;
&lt;p&gt;A model has been dropped into the middle of pipelines that a rule or a lookup handled fine, and the substitution rarely pays. It weakens reliability, because a guaranteed output is traded for a plausible one. It weakens independence, because the system now leans on a component whose behavior no one fully owns and whose every output has to be checked in high-stakes cases. And it raises cost across the board.&lt;/p&gt;
&lt;p&gt;Grounding is real and worth taking seriously.&lt;/p&gt;
&lt;p&gt;That is not the same as needing a language model, and treating the two as one is how you end up with something slower, flakier, and more expensive than what it replaced.&lt;/p&gt;</content:encoded><category>Systems</category></item><item><title>Second-Hand World (Part 1): What LLMs Inherit From the World They Never Touched</title><link>https://sincronik.it/writing/second-hand-world-part-1-what-llms-inherit-from-the-world-they-never-touched/</link><guid isPermaLink="true">https://sincronik.it/writing/second-hand-world-part-1-what-llms-inherit-from-the-world-they-never-touched/</guid><description>A formal system derives its conclusions because they follow from its axioms: its starting rules, assumed true without proof.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image14.png&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Second-Hand World (Part 1): What LLMs Inherit From the World They Never Touched&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;/p&gt;
&lt;p&gt;A formal system derives its conclusions because they follow from its axioms: its starting rules, assumed true without proof. Consistency is guaranteed by construction. An LLM, by contrast, returns whatever sounds plausible. It may reach the same conclusions, but nothing in its architecture guarantees consistency, or that its output follows from anything at all.&lt;/p&gt;
&lt;p&gt;The easy objection is that an LLM is “just statistics.” Too easy. We don’t know what the mind runs on either, and we still call what it does knowing. “It’s just statistics” settles nothing.&lt;/p&gt;
&lt;p&gt;The real question is grounding: whether a system has a causal grip on what it’s talking about.&lt;/p&gt;
&lt;p&gt;Here the formal system is instructive precisely because it’s blind. Its symbols point only to other symbols; it tracks no world. But notice: it was never supposed to. Peano arithmetic (the standard set of basic rules for the natural numbers) isn’t defective for failing to touch a world it was never about. “Tracks no world” is a defect only relative to a purpose.&lt;/p&gt;
&lt;p&gt;So grounding isn’t a single thing you either have or lack; it’s a relation between a system and what its work requires.&lt;/p&gt;
&lt;p&gt;That reframes the LLM. It tracks patterns in text. The tempting conclusion: patterns built on patterns touch nothing, the formal system’s blindness in a new costume.&lt;/p&gt;
&lt;p&gt;But text is not a closed symbol game.&lt;/p&gt;
&lt;p&gt;Text is a causal trace left by writers who were grounded in a world: someone saw the rain, ran the experiment, lost the money.&lt;/p&gt;
&lt;p&gt;And predicting that text well pushes the model to arrange its representations so that the distances between them mirror relations that hold among the things the words are about, the geometry of the meaning-space becomes a partial imprint of the structure of the world that produced the text.&lt;/p&gt;
&lt;p&gt;That is how grounding enters through the back door: not earned through sensory contact, but inherited as structure from the world the whole body of training text records. The imprint is not reference, and it is not clean; it is exactly the kind of thing the constraints are there to measure.&lt;/p&gt;
&lt;p&gt;Call the first kind primary grounding: an organism in direct causal contact with its world. Call the second kind second-hand grounding: a system in contact with the traces that grounding leaves behind in text.&lt;/p&gt;
&lt;p&gt;Testimonial knowledge already assumes that grounding can survive transmission; most human knowledge arrives through chains of representations rather than direct encounter. But not all transmissions preserve grounding equally.&lt;/p&gt;
&lt;p&gt;The disagreement is not over whether grounding can travel, but over how much survives the journey. Second-hand, thin, deniable.&lt;/p&gt;
&lt;p&gt;Deniable, yes. But consider what that denial entails. If our ignorance of the substrate’s qualities, and of how much grounding is preserved, prevents the skeptic from dismissing an LLM as “just statistics,” it constrains us as well.&lt;/p&gt;
&lt;p&gt;We do not know the substrate of thought either, nor the mechanisms by which it becomes experience.&lt;/p&gt;
&lt;p&gt;We say we know our own minds because we live them from the inside. We attribute minds to others without ever inspecting their substrate. That attribution is not the result of direct access to their mind, but of inference.&lt;/p&gt;
&lt;p&gt;Notice what did the work just now: living a mind from the inside is itself a mark of embodiment, and leaning on it hardly makes embodiment irrelevant.&lt;/p&gt;
&lt;p&gt;If anything, it shows how much embodiment carries. Embodiment may be the strongest indication of grounding we possess; the weaker claim is only that evidence for grounding should not be mistaken for a definition of grounding.&lt;/p&gt;
&lt;p&gt;But notice where this leaves us.&lt;/p&gt;
&lt;p&gt;If grounding survives transmission, and survives it in degrees, then the question is no longer whether the model touches the world. It’s what that thin, inherited contact entitles us to say.&lt;/p&gt;
&lt;p&gt;And there is one word we reach for the moment we try to say it: we grant that a system knows, or we withhold the word.&lt;/p&gt;
&lt;p&gt;That word has been doing quiet work under everything so far, unexamined. Whether the model has earned it is the question the next part takes up.&lt;/p&gt;</content:encoded><category>Systems</category></item><item><title>A Scam Made to Measure</title><link>https://sincronik.it/writing/a-scam-made-to-measure/</link><guid isPermaLink="true">https://sincronik.it/writing/a-scam-made-to-measure/</guid><description>The client I remember most was a smart contract developer. He signed a single drainer transaction. Everything gone.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image13.png&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;A Scam Made to Measure&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;/p&gt;
&lt;p&gt;The client I remember most was a smart contract developer.&lt;/p&gt;
&lt;p&gt;He writes the code that moves value on-chain. He understands approvals and signatures at a depth most users never reach. He was lured by a fake airdrop, a distribution of governance tokens to active users in an ecosystem, and signed a single &lt;a href=&quot;/glossary/drainer/&quot;&gt;drainer&lt;/a&gt; transaction: a malicious request that, once authorized, empties the wallet.&lt;/p&gt;
&lt;p&gt;It was over. Everything gone.&lt;/p&gt;
&lt;p&gt;If it can happen to him, it can happen to anyone. That sentence gets repeated so often it has gone soft. It deserves to be taken literally.&lt;/p&gt;
&lt;p&gt;Over the years I have started to read scams the way a tailor reads garments. Fraud comes in sizes, and each size is cut for a different level of knowledge.&lt;/p&gt;
&lt;p&gt;At the entry level hangs the off-the-rack work: pig butchering, fake investment platforms. Cut loose, so it fits almost anyone. Slow, patient manipulation that builds trust for months before draining the account. The craft is in the patience, and the measurements are generic: loneliness, hope, the wish for a quiet return on savings.&lt;/p&gt;
&lt;p&gt;At the high end sits the bespoke work: drainers and malicious approvals. These target people who know the fabric. The victim has to understand what a token approval is, what a signature authorizes, how a legitimate claim page behaves, and be fooled anyway. The trap only works on a trained eye, and a trained eye is exactly who it was made for.&lt;/p&gt;
&lt;p&gt;This is what makes drainers so insidious. They are built for one specific day: the ordinary one. You are moving fast. You are half distracted. The site looks exactly like the one you have used a hundred times. One signature is enough. It says nothing about you and everything about how well the trap was designed.&lt;/p&gt;
&lt;p&gt;Running through every tier, from the crudest to the finest, is the same craft: social engineering.&lt;/p&gt;
&lt;p&gt;The tailor’s skill was never the sewing. It is the measuring. And that work does not happen only online. It happens in person, in a conversation, a handshake, a moment of misplaced trust. The strength of the cryptography is irrelevant when the target is the person who holds the keys. The technique adapts to the wearer.&lt;/p&gt;
&lt;p&gt;I worked a case where a founder met his “investors” the way anyone would: over dinners, introductions, a partnership that took shape over weeks. There were business cards, a real office, a term sheet that read like the dozens he had seen before. The trust was built across a table, in handshakes and shared bottles of wine, long before a single transaction was signed. By the time they asked him to move funds to a “jointly controlled” wallet “to close the round,” the outcome was already decided. No malware, no spoofed domain.&lt;/p&gt;
&lt;p&gt;The whole attack was social, and the keys never stood a chance.&lt;/p&gt;
&lt;p&gt;The developer from the opening taught me something I have had to relearn several times since. He knew what a signature could authorize. He had written that logic himself, and the trap held anyway. Knowledge raises the price of fooling you. It rarely makes that price unpayable. A token approval set too high. A transaction signed on autopilot. One click while your attention is somewhere else, and the attack surface you spent years minimizing opens up completely.&lt;/p&gt;
&lt;p&gt;Security that depends on a human being permanently alert is a system that only works on your best day.&lt;/p&gt;
&lt;p&gt;This is also why empathy belongs in this work. When we hear how someone lost their funds, judgment comes cheap. But behind the transaction hash there is almost always a household.&lt;/p&gt;
&lt;p&gt;I have sat across from families who lost the work of a lifetime: entire pensions, the savings of thirty years of early mornings and postponed wishes, the money that was supposed to become a home, a retirement, a margin of safety for the children. A retired couple moving that pension into what looked like a regulated platform was not being greedy; they were applying the rules of a world they knew, where institutional appearance equaled safety.&lt;/p&gt;
&lt;p&gt;Every mistake has to be read against the knowledge and the circumstances of the person who made it. On-chain it reads as a single transfer, a row in a spreadsheet. In a living room it’s a silence at the dinner table that no recovery effort can turn down.&lt;/p&gt;
&lt;p&gt;The same reading applies to everyone, the retired couple and the smart contract developer alike. What looks obvious from the outside rarely felt obvious in the moment, under pressure, mid-distraction, at the end of a long day. And the people it fits most cruelly are often the ones who brought everything they had, because the trap was built for exactly that: a lifetime of trust, concentrated in one account.&lt;/p&gt;
&lt;p&gt;Many businesses still underestimate custody and secure operational workflows, and the tailoring model explains why. They train people to recognize the trap, then leave the fitting room open. Security is a design problem before it is a training problem.&lt;/p&gt;
&lt;p&gt;The developer needed a workflow where an unknown contract could never reach a signature at all: the roster of trusted contracts settled ahead of time, in a calm moment instead of a distracted one. The decision made once, deliberately, so the malicious request that emptied his wallet would simply never have arrived.&lt;/p&gt;
&lt;p&gt;The founder needed something else entirely. No contract could have saved him; the trap was built across a dinner table, not hidden in a domain name. But signing infrastructure that shows the authorizer exactly what a transaction will do every single time, forcing deliberate inspection and leaving no room for ambiguity, transforms “move the funds to close the round” from a socially conditioned next step into a concrete, inspectable action. It turns a moment of distraction into a controlled decision.&lt;/p&gt;
&lt;p&gt;Each of these measures does the same thing: it moves the critical decision away from your worst moment and into your calmest one. Every contract whitelisted in advance, every signature the signer actually understands. A workflow that never lets an unknown contract reach a signature gives him nothing to fit.&lt;/p&gt;
&lt;p&gt;The goal is not to create humans who never make mistakes. The goal is to design systems where ordinary human moments cannot become irreversible losses.&lt;/p&gt;</content:encoded><category>Investigations</category></item><item><title>A Powerful Tool Will Not Save You</title><link>https://sincronik.it/writing/a-powerful-tool-will-not-save-you/</link><guid isPermaLink="true">https://sincronik.it/writing/a-powerful-tool-will-not-save-you/</guid><description>Complexity is not chaos. Chaos has no handles. Complexity does: it is a dialogue of dependencies, tensions, and patterns awaiting interpretation.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image12.png&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;A stick&amp;#x27;s trail&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;A stick’s trail&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Complexity is not chaos. Chaos has no handles. Complexity does: it is a dialogue of dependencies, tensions, and patterns awaiting interpretation.&lt;/p&gt;
&lt;p&gt;The difference matters because it tells you what to do when you are overwhelmed. In the face of chaos you brace. In the face of complexity you read. The work is not to make the mess go away but to find the grammar already running underneath it.&lt;/p&gt;
&lt;p&gt;Most people, faced with a hard problem, reach for a tool. Newer, faster, more powerful: surely the right instrument will cut through. Tools do help. But we forget what a tool actually is.&lt;/p&gt;
&lt;p&gt;A tool is a hypothesis with a spine. Every instrument encodes a belief about where the answer lives and how the world is shaped. A dashboard assumes the signal is in the metrics it chose to plot. A clustering algorithm assumes the entity you are hunting behaves the way its heuristics expect. The tool is not neutral. It is an argument about reality, frozen into software, and it carries that argument silently into every problem you point it at.&lt;/p&gt;
&lt;p&gt;This is the trap. Choose the wrong tool and its blind spots become your own. You stop seeing what it cannot show you, and you mistake the edge of the instrument for the edge of the problem. The more powerful the tool, the more seductive its blind spots, because power buys you speed, and speed in the wrong direction is just a faster way to be wrong.&lt;/p&gt;
&lt;p&gt;Here is the part that gets missed: the danger is not power, it is opacity. A black box concentrates authority inside itself. It hands you an answer and hides the reasoning, so you either trust it or you do not, and either way the thinking has been taken out of your hands. The more transparent the tool, the more it gives the power back to the method. When you can see the assumptions, inspect the steps, and watch where the logic bends, the instrument stops being an oracle and becomes what it should be: an extension of your own reasoning, one you can audit and overrule. Transparency is what keeps the method in charge of the tool, instead of the other way around.&lt;/p&gt;
&lt;p&gt;Which is why method has to come first. Method is the thing that chooses the tool, interrogates its assumptions, and knows when to put it down. With a hypothesis of your own, a real one, even the most primitive instrument is enough. Take two cases at opposite ends of a career. My very first case was solved with nothing but a block explorer and a pencil. Years later, with every platform available to me, I had to run a full trace between two bridges on zkSync exactly the same way: a sheet of paper, a pencil, reading the raw chain by hand. Same minimum kit, then and now, because the method was always there. Software makes you fast. It does not make you correct.&lt;/p&gt;
&lt;p&gt;This changes how we think about expertise. Good training can absolutely teach method. The problem is when expertise becomes identified with a particular tool instead. Then the skill and the instrument begin to fuse. You learn where the buttons are, but not always why you are pressing them.&lt;/p&gt;
&lt;p&gt;There is real value in learning a platform. It gives you a common vocabulary, speeds up onboarding, and helps you become productive quickly. But those are the benefits of an accelerator, not an engine. If the platform changes, raises its price, or disappears, the method should still be standing.&lt;/p&gt;
&lt;p&gt;Technology changes. New instruments will keep arriving, and I will not pretend to know which of the ones I use today will fade. But I will bet on this: the ones that endure will be built on clarity, because a tool you can see into is one the method can keep trusting. The opaque win on speed for a season; the clear compound. Method endures the same way, and for the same reason: it was never about the tool.&lt;/p&gt;
&lt;p&gt;In the end the limiting factor is not the instrument in your hand. It is the quality of the thinking behind it. How you think determines what becomes possible. A powerful tool will not save you. Get the method right and the tools become what they were always meant to be: amplifiers of a mind that already knows where it is going.&lt;/p&gt;</content:encoded><category>Methods</category></item><item><title>What a USDT Recovery Actually Looks Like</title><link>https://sincronik.it/writing/what-a-usdt-recovery-actually-looks-like/</link><guid isPermaLink="true">https://sincronik.it/writing/what-a-usdt-recovery-actually-looks-like/</guid><description>People hear &quot;we recovered stolen Tether&quot; and picture a heist in reverse. A key cracked, the thief&apos;s wallet broken back into, the funds yanked out.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;figure&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image10.jpeg&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Tether smart contract representation: A visual analogy of automated execution.&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;figcaption&gt;Tether smart contract representation: A visual analogy of automated execution.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;People hear “we recovered stolen Tether” and picture a heist in reverse. A key cracked, the thief’s wallet broken back into, the funds yanked out.&lt;/p&gt;
&lt;p&gt;It is nothing like that. It is almost bureaucratic.&lt;/p&gt;
&lt;p&gt;So what is USDT, really? Not just a coin sitting in a wallet. A smart contract. Think of it as a vending machine. Instead of taking your money and handing you a snack, it takes an instruction and moves a credit from one account to another. Your “balance” is just a number the machine keeps next to your address. When you send USDT, you are not shipping an object anywhere. You are asking the machine to subtract from one row and add to another.&lt;/p&gt;
&lt;p&gt;That framing matters because a vending machine has an owner. Like any vending machine, it has an owner, and the owner can do things no customer ever could.&lt;/p&gt;
&lt;p&gt;The USDT contract has special functions only Tether can call. Three of them tell the whole process of a recovery: blacklisting, burning, and minting.&lt;/p&gt;
&lt;p&gt;A CRITICAL CAVEAT: not every token labeled “USDT” is actually issued by Tether. Common bridged versions of USDT (tokens that represent USDT on blockchains other than the native Tether-issued ones) cannot be frozen by Tether because they are not issued by Tether. They are separate tokens created and controlled by third-party bridge operators and backed by locked Tether-issued USDT as collateral. Although users often refer to them simply as “USDT,” they are technically distinct assets, and the freeze authority, if it exists, belongs to the bridge issuer, not to Tether.&lt;/p&gt;
&lt;h2 id=&quot;phase-one-the-freeze&quot;&gt;Phase one: the freeze&lt;/h2&gt;
&lt;p&gt;The first thing that happens in a recovery is the freeze. When Tether blacklists an address, that address goes sticky. The number next to it is still there, you can still see the balance, but the machine will no longer accept any instruction to move it. The funds are stranded in place so the thief cannot run while the legal process plays out.&lt;/p&gt;
&lt;p&gt;In practice, asset freezes are initiated early in the investigative cycle, often ahead of any final court ruling. Law enforcement agencies such as the FBI, DOJ, or their international counterparts secure the necessary legal authority under local procedures and coordinate with the stablecoin issuer. Speed is decisive: a delay of even a day can mean the difference between a successful freeze and an already emptied address.&lt;/p&gt;
&lt;p&gt;If you want to verify a freeze, you don’t guess from the wallet balance. You check the contract state. When passing an address to the USDT contract’s isBlackListed view function, it simply returns a boolean. This simple true/false flag is the ultimate ground truth of the address state within the smart contract.&lt;/p&gt;
&lt;h2 id=&quot;phases-two-and-three-burn-then-refund&quot;&gt;Phases two and three: burn, then refund&lt;/h2&gt;
&lt;p&gt;The freeze can sit for a long time. Weeks, months, or even years. And it does not always move at all. Many frozen addresses never proceed to a burn. They simply stay stuck. What comes next only happens when there is a legal basis for it and Tether decides to act.&lt;/p&gt;
&lt;p&gt;Once the legal basis is established, the final two phases usually unfold within minutes of each other.&lt;/p&gt;
&lt;p&gt;First comes the burn. Not a transfer. Not a seizure. A destruction, and the total supply shrinks by exactly that amount.&lt;/p&gt;
&lt;p&gt;When funds are removed through the special burn function, some analytics platforms (&lt;a href=&quot;https://www.linkedin.com/company/arkhamintelligence/posts/&quot;&gt;Arkham&lt;/a&gt; among them) may not register the balance change from that transaction type, so an address that has actually been emptied can still display a full balance. For this specific step, cross-check on a block explorer (or &lt;a href=&quot;https://usdtbanlist.com/&quot;&gt;USDTBanList&lt;/a&gt;) that reads the contract state directly, or you will think the money is still sitting there when it is already gone.&lt;/p&gt;
&lt;p&gt;But if the stolen USDT has been destroyed, where does the victim’s replacement come from?&lt;/p&gt;
&lt;p&gt;Not from the burned tokens, but from the treasury’s existing reserves.&lt;/p&gt;
&lt;p&gt;The Tether treasury is pre-funded: USDT is minted in advance, independently of any single recovery, in enormous amounts, often billions of dollars at a time. That supply sits in the treasury waiting, with no connection to the case it will later settle.&lt;/p&gt;
&lt;p&gt;On Tron, it is minted from a burn-style blackhole address and is then routed to the multisignature wallet; on Ethereum, it is issued directly into the treasury wallet from the Bitfinex multisig. See &lt;a href=&quot;https://usdt.tokenview.io/en/mint&quot;&gt;examples&lt;/a&gt; on Tokenview. However, this is a discretionary operational choice by Tether, and if you continue browsing through the pages you will find outliers.&lt;/p&gt;
&lt;p&gt;And here is the detail that makes it provable: the payout is aggregate. Every frozen address involved in the case is burned, and one fresh lump, equal to all of them added together, leaves the treasury in a single move. This is where the recovery becomes visible on-chain.&lt;/p&gt;
&lt;p&gt;The destroyed amount and the refunded amount match down to the last decimal.&lt;/p&gt;
&lt;figure&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image11.png&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;An example of a USDT recovery.&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;figcaption&gt;An example of a USDT recovery.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;This decimal-perfect equality is the fingerprint, and it is visible to anyone willing to look on-chain. In the recovery cases I personally worked on, this was the smoking gun: multiple criminal addresses were burned within a two-minute window, and the exact aggregated total was paid out as a single lump sum just sixty seconds later from the Tether treasury address, although the refund is a separate transaction rather than an automatic consequence of the burn.&lt;/p&gt;
&lt;p&gt;In these specific cases, the lump sum was forwarded to a &lt;a href=&quot;https://www.linkedin.com/company/bitfinex/&quot;&gt;Bitfinex&lt;/a&gt; deposit address, an exchange under the same iFinex corporate umbrella as Tether, re-entering the regulated market on its way back to the victim.&lt;/p&gt;
&lt;p&gt;So, the thief’s tokens are never chased or seized. They are simply switched off, while an identical amount is released from a pre-existing reserve, and the math lines up perfectly.&lt;/p&gt;
&lt;p&gt;The blockchain records every step.&lt;/p&gt;
&lt;p&gt;A crypto recovery doesn’t look like a Hollywood heist. It looks like an accountant flipping two entries on a spreadsheet.&lt;/p&gt;
&lt;p&gt;No cinematic exploits. Just absolute authority embedded directly into a smart contract.&lt;/p&gt;</content:encoded><category>Investigations</category></item><item><title>Welcome to Constraints</title><link>https://sincronik.it/writing/welcome-to-constraints/</link><guid isPermaLink="true">https://sincronik.it/writing/welcome-to-constraints/</guid><description>Every investigation hits a point where the evidence runs out. The graph ends. The wallet has no owner. What&apos;s left looks like too little to know anything.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image9.jpeg&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Welcome to Constraints&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;/p&gt;
&lt;p&gt;Every investigation hits a point where the evidence runs out. The graph ends. The wallet has no owner. What’s left looks like too little to know anything. That is where the real work starts, because the question is no longer where the money went. It is whether anything here can be known at all.&lt;/p&gt;
&lt;p&gt;The answer almost always has the same shape: what can this system not do, even if it wanted to?&lt;/p&gt;
&lt;p&gt;In a system built to hide the truth, the truth rarely stays visible. It survives as constraints: things the system cannot violate without contradicting itself. Balances must reconcile. Code executes exactly as written. Every transaction requires authorization and fees. When direct evidence disappears, constraints remain, and they are often enough.&lt;/p&gt;
&lt;p&gt;That is what this newsletter is about. It isn’t blockchain news, and it isn’t a bag of tricks, though you may pick up and share a few. Real investigative dynamics from actual cases will appear throughout. I won’t avoid them, but they are only examples, and I may run out of good ones. What we’re really doing is looking at the reasoning underneath them.&lt;/p&gt;
&lt;p&gt;I’ll keep the language plain and lean on examples. Nothing simplified, only explained. I’ll assume only an understanding of blockchains and about three or four minutes of your attention per episode (probably a better investment than the usual LinkedIn AI-digested motivational slop).&lt;/p&gt;
&lt;p&gt;The same move shows up far beyond blockchain: in law, intelligence, engineering, economics and more. Different fields, one method: when you can’t see the answer, you rebuild the question from what couldn’t have been otherwise.&lt;/p&gt;
&lt;p&gt;My hope is to make this a place where investigators, analysts, lawyers, developers, and anyone drawn to systems can exchange ideas grounded in that way of thinking. Not because these fields share answers, but because they share the same attitude: how to know something when everything is built to stop you. And in the conversations I hope will grow in the comments, I’ll ask the same of you: keep it plain, so people from different fields, with different vocabularies, can still understand one another.&lt;/p&gt;
&lt;p&gt;This is an epistemic problem before it is a technical one. A problem about what can be known, not about blockchain.&lt;/p&gt;
&lt;p&gt;If you’re starting today, begin with the episodes that came before this one:&lt;/p&gt;
&lt;p&gt;Episode -4: &lt;a href=&quot;/writing/inside-inferno-drainer/&quot;&gt;Inside Inferno Drainer&lt;/a&gt;. How shared criminal infrastructure becomes the very thing that identifies its users.&lt;/p&gt;
&lt;p&gt;Episode -3: &lt;a href=&quot;/writing/a-special-demixing-case/&quot;&gt;A Special Demixing Case&lt;/a&gt;. Following the money failed. Arithmetic didn’t.&lt;/p&gt;
&lt;p&gt;Episode -2: &lt;a href=&quot;/writing/wallet-balances/&quot;&gt;Wallet Balances&lt;/a&gt;. How a single screenshot identified a wallet holding millions.&lt;/p&gt;
&lt;p&gt;Episode -1: &lt;a href=&quot;/writing/guess-who-on-chain/&quot;&gt;Guess Who? (On-chain)&lt;/a&gt;. Finding a wallet from nothing but an NFT profile picture.&lt;/p&gt;
&lt;p&gt;The negative numbers are LinkedIn’s doing: newsletters can’t time-travel, so older articles were filed as Episodes -4 through -1. I call it a feature.&lt;/p&gt;
&lt;p&gt;New episodes follow a weekly cadence, typically on Wednesdays at 9:30 CET. Episodes are published only when they meet a required threshold of insight quality; otherwise, publication is deferred.&lt;/p&gt;
&lt;p&gt;Next up: &lt;a href=&quot;/writing/what-a-usdt-recovery-actually-looks-like/&quot;&gt;Episode #1: What a USDT Recovery Actually Looks Like.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Before we return to reasoning from constraints, let’s spend one episode looking under the hood of a USDT recovery. We’ll follow the on-chain footprints of a paradox: an asset moving on a decentralized network that ultimately answers to a single authority.&lt;/p&gt;
&lt;p&gt;Let’s meet where the evidence ends.&lt;/p&gt;</content:encoded><category>Methods</category></item><item><title>Guess Who? (On-chain)</title><link>https://sincronik.it/writing/guess-who-on-chain/</link><guid isPermaLink="true">https://sincronik.it/writing/guess-who-on-chain/</guid><description>He had a profile picture. That was the whole case. An X account. One avatar, an NFT, the kind people wear like a face.</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;figure&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image6.jpeg&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Guess Who?&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;figcaption&gt;Guess Who?&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;He had a profile picture. That was the whole case.&lt;/p&gt;
&lt;p&gt;An X account. One avatar, an NFT, the kind people wear like a face. Hair, eyes, skin, a colored background. Find the person behind it.&lt;/p&gt;
&lt;p&gt;No wallet from the handle. The username mapped to nothing: no &lt;a href=&quot;https://www.linkedin.com/company/debank/&quot;&gt;DeBank&lt;/a&gt;, no linked profile, no thread anywhere online that tied it to an address. Just a picture someone had chosen to be.&lt;/p&gt;
&lt;p&gt;Let me show you why that’s enough, in plain terms.&lt;/p&gt;
&lt;p&gt;For this kind of web3 collectable, every NFT is a recipe. A set of traits written into metadata: hair this color, eyes that color, skin this tone, those glasses, that background. The picture is the output. The metadata is the source seed. So if I could read the picture as a list of traits, I could turn a face back into a query. A bit like playing Guess Who.&lt;/p&gt;
&lt;p&gt;Simple. Except for one thing.&lt;/p&gt;
&lt;p&gt;The avatar wasn’t from a collection I could name. It was as if I couldn’t even start the game of Guess Who, because I didn’t know which version of the board my opponent was playing on. And it could just as easily have been a derivative. There are services that, for a fee, modify your NFT: the Bored Ape Yacht Club, for example, has a spin-off that “zombifies” yours, spitting out an unofficial variant that carries the same metadata as the original. And this can go several steps deep, a knockoff of a knockoff, and so on. So the picture could look like something famous, but actually come from somewhere obscure.&lt;/p&gt;
&lt;p&gt;That was the wall. No handle-to-wallet. No nameable collection. The point where most people write “anonymous, no entry point” and close the file.&lt;/p&gt;
&lt;p&gt;So I stopped trying to trace him. And I asked a different question.&lt;/p&gt;
&lt;p&gt;Not “where is his wallet?” but “who is standing next to him?”&lt;/p&gt;
&lt;p&gt;That was the crack in the wall.&lt;/p&gt;
&lt;figure&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image7.png&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Communities Within Networks&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;figcaption&gt;Communities Within Networks&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;Because nobody collects alone. An NFT community may intersect with other NFT communities: the same people hold overlapping sets. He’d scrubbed himself clean, but if I could find even one other wallet from his interactions, or from the accounts replying to his posts, I could find people holding the same kinds of collections he did, even behind a completely different profile picture.&lt;/p&gt;
&lt;p&gt;So I rolled up my sleeves. Pure elbow grease.&lt;/p&gt;
&lt;p&gt;I went through the accounts interacting with him (the replies, the mutuals, the people in his orbit), hunting for any fingerprint that led to a real address. I pulled a handful of wallets out of the noise, across multiple chains. Then I took each one to &lt;a href=&quot;https://www.linkedin.com/company/opensea-io/&quot;&gt;OpenSea&lt;/a&gt; (EVMs) or &lt;a href=&quot;https://www.linkedin.com/company/magic-eden/&quot;&gt;Magic Eden&lt;/a&gt; (Solana) to read its collections, and to open block explorers to see every NFT it had ever touched, even the ones held for a single day, even inside a narrow window.&lt;/p&gt;
&lt;p&gt;Bingo.&lt;/p&gt;
&lt;p&gt;In one neighbor’s history sat an NFT built like the one I was chasing. Same structure, same skeleton. That handed me the collection.&lt;/p&gt;
&lt;p&gt;Now I had the real thing. I could finally play Guess Who with the suspect. So I filtered it by my target’s metadata, the exact traits from his avatar, and there he was. His specific NFT. One token, out of the whole set.&lt;/p&gt;
&lt;p&gt;But a token still isn’t a person.&lt;/p&gt;
&lt;p&gt;This one had changed hands. Bought, sold, passed down a chain of owners. So I laid its transfer history against his activity on X: the timing of each sale, the time and context of his posts, who held it when. One address in that chain lined up with the man behind the avatar. Not a guess. A match between the blockchain and the social network’s timeline.&lt;/p&gt;
&lt;p&gt;That became the anchor. From there, everything downstream came loose.&lt;/p&gt;
&lt;p&gt;He erased every line from his name to his wallet. The handle led nowhere. The collection had no name.&lt;/p&gt;
&lt;p&gt;He just forgot that you collect in a crowd, and the crowd holds the same things you do.&lt;/p&gt;</content:encoded><category>Investigations</category></item><item><title>Wallet Balances</title><link>https://sincronik.it/writing/wallet-balances/</link><guid isPermaLink="true">https://sincronik.it/writing/wallet-balances/</guid><description>He sent me a screenshot. One wallet. A Solana balance. A few memecoins. Find the wallet, he said. No address. No transaction hash.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;figure&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image5.jpeg&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Sudoku Nakamoto&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;figcaption&gt;Sudoku Nakamoto&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;He sent me a screenshot.&lt;/p&gt;
&lt;p&gt;One wallet. A Solana balance. A few memecoins. Find the wallet, he said.&lt;/p&gt;
&lt;p&gt;No address. No transaction hash. No exchange account. No starting point. Not even the date the screenshot was taken.&lt;/p&gt;
&lt;p&gt;Just a screenshot.&lt;/p&gt;
&lt;p&gt;He also told me that several technicians and analysts had already looked at it and come up with nothing. My first thought was that it would be quick: write a query for every wallet that held that exact combination of tokens, match the balances down to the last decimal, and there is your wallet. A simple exercise.&lt;/p&gt;
&lt;p&gt;Then I opened the screenshot, and saw the real problem.&lt;/p&gt;
&lt;p&gt;The memecoins weren’t uniquely identifiable. On &lt;a href=&quot;https://www.linkedin.com/company/solana/&quot;&gt;Solana&lt;/a&gt;, dozens of tokens can share the same name. Many share the same logo. Some are outright impersonations of one another.&lt;/p&gt;
&lt;p&gt;The screenshot showed only the displayed names, logos, balances and position values. No token addresses, which is the one thing that actually tells two identical-looking coins apart.&lt;/p&gt;
&lt;p&gt;So before I could search for anything, I first had to work out which assets the screenshot was even showing.&lt;/p&gt;
&lt;p&gt;I started from the balances. Each holding showed both a quantity and a value, so I divided one by the other to get the price of a single token. That one number did a lot of the work: if a suspect coin had never traded at that price at any point in time, it could not be the one, and I dropped it. This was the slow part, mostly by hand, because the look-alikes ran into dozens and dozens.&lt;/p&gt;
&lt;p&gt;Only then could the real search begin.&lt;/p&gt;
&lt;p&gt;Even after the price filter, some of the memecoins still had more than one possible match. So I built a single query that took every surviving combination of candidate tokens and searched, in one pass, for wallets that had held that exact set at the same time. Every possible match landed in one dataset.&lt;/p&gt;
&lt;p&gt;The result was still enormous. Thousands of wallets. (Please, do not trade memecoins…)&lt;/p&gt;
&lt;p&gt;Then I went through all of those wallets with a Python script. For each one, it followed how the amount of a reference token in that wallet rose and fell over time, and threw the wallet out as soon as it was clear that no moment in its history matched the screenshot.&lt;/p&gt;
&lt;p&gt;My terminal was printing “excluded” every second. One by one they fell away. I actually found the match before I was even halfway through. I cracked open a Super Mario Actimel to celebrate, then let the program run to the end for completeness.&lt;/p&gt;
&lt;p&gt;Only one wallet was left.&lt;/p&gt;
&lt;p&gt;Then came validation. Did the token balances match? Did the timing match? Did the order of the assets match? Did the surrounding activity make sense?&lt;/p&gt;
&lt;p&gt;Everything lined up. That single wallet was the one.&lt;/p&gt;
&lt;p&gt;A wallet identified from nothing more than a screenshot. No address. No hash. No starting point. No time window, beyond the obvious fact that every coin involved already existed. Just a set of balances and a moment frozen in time. And it was sitting on millions.&lt;/p&gt;
&lt;p&gt;What looked like a simple query turned into one of the more tedious identifications I have done. The culprit was the memecoins: around eighty knockoffs of one another, barely any reliable historical price data (even on Dexscreener), what little existed scattered all over the place, the price feeds themselves carrying broken history, and far too many people holding memecoins to begin with. But the answer was always in there.&lt;/p&gt;
&lt;p&gt;People think blockchain investigations are about finding information. More often, they are about realizing how much was already in front of you.&lt;/p&gt;
&lt;p&gt;The screenshot wasn’t a picture. It was a set of constraints.&lt;/p&gt;
&lt;p&gt;And constraints are enough to find the truth.&lt;/p&gt;</content:encoded><category>Methods</category></item><item><title>A Special Demixing Case</title><link>https://sincronik.it/writing/a-special-demixing-case/</link><guid isPermaLink="true">https://sincronik.it/writing/a-special-demixing-case/</guid><description>Thousands of bitcoins walked out of a virtual asset service provider years ago. The wallets went quiet for a long time.</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;figure&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image4.jpeg&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Quantitative Tensegrity&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;figcaption&gt;Quantitative Tensegrity&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;A note before we start: the case as a whole was handled by the entire &lt;a href=&quot;https://www.linkedin.com/company/tokenrecovery/&quot;&gt;Token Recovery&lt;/a&gt; team, and this demixing work in particular was done together with &lt;a href=&quot;https://www.linkedin.com/in/ACoAAFVIcHcBL7B-tgIitNZN80vcFc63sXE8YtY&quot;&gt;Benjamin Brooks&lt;/a&gt;. That’s why I say “we” throughout, the credit is shared.&lt;/p&gt;
&lt;p&gt;Thousands of bitcoins walked out of a virtual asset service provider years ago. The wallets went quiet for a long time. When they woke up, the money didn’t go to another exchange. It went into a &lt;a href=&quot;/glossary/coin-mixer/&quot;&gt;mixer&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;A mixer is the one tool built specifically to beat people like us. Here is how we beat it back, in plain terms.&lt;/p&gt;
&lt;p&gt;A mixer is a black box for coins. You put Bitcoin in. Later, someone takes Bitcoin out. But what goes in and what comes out are deliberately disconnected: equal-sized chunks, shuffled together, no on-chain line you can draw from “money in” to “money out.” Everyone’s coins sit in one shared pool, and when a withdrawal happens the blockchain will not tell you whose deposit paid for it.&lt;/p&gt;
&lt;p&gt;So the obvious approach fails. We could see the stolen coins enter the mixer. Then the thread was cut. Thousands of withdrawals left the pool over the same period, and every one of them looked exactly like the next. No labels. No origin. Nothing that said “this one is the thief’s.”&lt;/p&gt;
&lt;p&gt;This is the wall. The point where most reports write “funds entered a mixer, trail lost” and close the file.&lt;/p&gt;
&lt;p&gt;But the attacker had one weakness they could not hide: the sheer scale of their deposits. They had pushed so much money through such a small mixer that, as we will see, that volume is the only reason any of this worked.&lt;/p&gt;
&lt;p&gt;We did not have a single withdrawal we could prove belonged to the attacker. So we stopped trying to follow the coins, and we asked a different question.&lt;/p&gt;
&lt;p&gt;Not “which coins are theirs?” but “how much of the pool has to be theirs?”&lt;/p&gt;
&lt;p&gt;Here is the key. A mixer can hide which coins belong to whom. It cannot break arithmetic. At any moment, the total sitting inside the mixer is just two things added together: our Threat Actor money, and everybody else’s money. There is no third pile.&lt;/p&gt;
&lt;p&gt;Threat Actor balance + everyone else’s balance = total balance. Always.&lt;/p&gt;
&lt;p&gt;And neither of those two balances can ever fall below zero. You cannot withdraw money that is not there.&lt;/p&gt;
&lt;p&gt;That last sentence is the crack in the wall.&lt;/p&gt;
&lt;p&gt;So we reconstructed the mixer’s total balance and sorted all of its activity into three buckets: deposits we could tie to the Threat Actor, deposits we could tie to everyone else, and withdrawals, which the mixer had scrambled on purpose so that no withdrawal could be traced back to whose deposit it came from.&lt;/p&gt;
&lt;p&gt;With everything broken down this way, we pushed the numbers to their two extremes.&lt;/p&gt;
&lt;p&gt;Extreme one: assume every unattributed withdrawal was the Threat Actor. This drives their balance as low as it can possibly go. Sometimes it gets driven all the way to zero, and the instant it does, the next withdrawal cannot be theirs, there is nothing left in their pile to take. That extra withdrawal has to belong to someone else.&lt;/p&gt;
&lt;p&gt;Extreme two: assume the opposite, that every unattributed withdrawal was everyone else’s. This drains the other pile to its minimum instead. When that one hits zero, the leftover withdrawals can’t belong to anyone else. They must be the Threat Actor.&lt;/p&gt;
&lt;p&gt;That forced leftover is the overflow: the amount the mixer was mathematically compelled to allocate to one side or the other within the now identified narrow time window. Not a guess, not a probability, a certainty squeezed out of the simple fact that a balance can’t go negative.&lt;/p&gt;
&lt;p&gt;The mixer’s whole promise was you can’t separate your coins from the crowd’s. True. We didn’t separate the coins. We separated the math.&lt;/p&gt;
&lt;p&gt;Now the part that actually matters: how do we know it’s right?&lt;/p&gt;
&lt;p&gt;The overflow told us that the attacker withdrew inside a specific window. It did not tell us which withdrawals were theirs. So we settled it by elimination.&lt;/p&gt;
&lt;p&gt;Working from the blockchain data itself, and using &lt;a href=&quot;https://www.linkedin.com/company/caudena/&quot;&gt;Caudena&lt;/a&gt;’s aggregation of clusters, we took a sample of the withdrawals from that window and followed each one to the wallet cluster it ended up in.&lt;/p&gt;
&lt;p&gt;Caudena let us easily see the deposit clusters ranked by volume and group the withdrawals into their own clusters. Then we listed the biggest players sending money into the mixer and pulling money out of it. For each one, we simply counted how much they were moving. That told us who the heavy hitters were.&lt;/p&gt;
&lt;p&gt;One withdrawals cluster towered over everyone else. The rest were all much smaller.&lt;/p&gt;
&lt;p&gt;Our Threat Actor was, by a wide margin, the one moving the most.&lt;/p&gt;
&lt;p&gt;And that is the whole reason this worked. The attacker was the mixer’s biggest depositor by far, pushing through more money than such a small service could ever hide. We checked every other player, right down to the second-biggest, and none of them came anywhere close to that volume found in the withdrawal cluster. Once they were all ruled out, only one wallet cluster was left that could explain the money: our Threat Actor.&lt;/p&gt;
&lt;p&gt;From that anchor, everything downstream came loose.&lt;/p&gt;
&lt;p&gt;The mixer was built so that no single withdrawal could ever be pinned to the thief.&lt;/p&gt;
&lt;p&gt;It never had to be. The balance sheet pinned them for us.&lt;/p&gt;</content:encoded><category>Investigations</category></item><item><title>Inside Inferno Drainer</title><link>https://sincronik.it/writing/inside-inferno-drainer/</link><guid isPermaLink="true">https://sincronik.it/writing/inside-inferno-drainer/</guid><description>A DeFi protocol&apos;s social media account got hijacked. Fake airdrop, cloned site, one phishing link, one malicious signature, wallets drained.</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;figure&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image1.jpeg&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Hell is clogged&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;figcaption&gt;Hell is clogged&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;A DeFi protocol’s social media account got hijacked. Fake airdrop, cloned site, one phishing link, one malicious signature, wallets drained.&lt;/p&gt;
&lt;p&gt;The malware was Inferno &lt;a href=&quot;/glossary/drainer/&quot;&gt;Drainer&lt;/a&gt;. And for two days, I couldn’t tell you who pulled the trigger.&lt;/p&gt;
&lt;p&gt;Let me show you why, in plain terms.&lt;/p&gt;
&lt;p&gt;When a victim approves the malicious transaction, their crypto doesn’t go straight to the thief. It flows through a chain of automated contracts. A throwaway “forwarder” contract (created on the spot, used once, never again) passes the native crypto into one shared contract that acts as the collection point for the loot. From there the operator can pull out their 80%. The remaining 20% goes to the people who built the malware. Other tokens get auto-split the same way, 80/20, in the same instant (with or without throwaway “forwarders” depending on the case).&lt;/p&gt;
&lt;figure&gt;&lt;img __ASTRO_IMAGE_=&quot;{&amp;#x22;src&amp;#x22;:&amp;#x22;./assets/image3.png&amp;#x22;,&amp;#x22;alt&amp;#x22;:&amp;#x22;Inferno Drainer diagram.&amp;#x22;,&amp;#x22;index&amp;#x22;:0}&quot;&gt;&lt;figcaption&gt;Inferno Drainer diagram.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;Clean. Industrial. And shared.&lt;/p&gt;
&lt;p&gt;That last word is the whole problem.&lt;/p&gt;
&lt;p&gt;Inferno Drainer is malware-as-a-service. Hundreds of independent criminals rent the exact same kit and push everything through the exact same contracts. That’s not a flaw. That’s the product. The shared infrastructure IS the anonymity.&lt;/p&gt;
&lt;p&gt;You’re not one thief in a room. You’re one thief in a stadium, and every move you make looks identical to everyone else’s.&lt;/p&gt;
&lt;p&gt;So I started where the money pools: that single shared collection contract (Smart Contract A). I pulled every address that ever took funds out of it.&lt;/p&gt;
&lt;p&gt;Thousands came back.&lt;/p&gt;
&lt;p&gt;Thousands of wallets, all looking identical. One of them ran the attack I was hunting. The rest were strangers, robbing other people, the same timeframe, with the same tool. No names. No labels. Nothing that said “this is the one.”&lt;/p&gt;
&lt;p&gt;This is the moment the malware is designed for.&lt;/p&gt;
&lt;p&gt;The point where a couple of obvious searches (E.g. time window query) come back with nothing, and most people write “untraceable” in the report and close the file.&lt;/p&gt;
&lt;p&gt;I didn’t have a single thing that separated my attacker from the crowd.&lt;/p&gt;
&lt;p&gt;So I stopped looking at the crowd. And I asked a different question.&lt;/p&gt;
&lt;p&gt;Who did this attacker actually target?&lt;/p&gt;
&lt;p&gt;Not random people. They cloned ONE specific protocol. So their victims weren’t random either, they were people who held that protocol’s tokens and the respective collateral. And if you’re the operator who handled all those drained wallets, your own address has to carry the residue: those same tokens showing up in your history far more than any unrelated criminal’s would.&lt;/p&gt;
&lt;p&gt;That was the crack in the wall.&lt;/p&gt;
&lt;p&gt;So I ran one query.&lt;/p&gt;
&lt;p&gt;Take that pile of thousands, and keep only the addresses that ever touched the 34 token contracts belonging to that protocol’s ecosystem. I built it on &lt;a href=&quot;https://www.linkedin.com/company/dune-analytics/&quot;&gt;Dune&lt;/a&gt; and turned the result into a heat map (think of it as a brightness score, where the more an address connects to those tokens, the hotter it glows).&lt;/p&gt;
&lt;p&gt;Thousands collapsed to 32.&lt;/p&gt;
&lt;p&gt;And inside those 32, one address didn’t just touch a token or two. It lit up across the entire board. Every ecosystem asset, all of it, on a single wallet, with the exact timing of the attack: funds arriving the moment the fake sites went live, activity stopping the moment the campaign ended.&lt;/p&gt;
&lt;p&gt;Not a coincidence. A confession written in timestamps.&lt;/p&gt;
&lt;p&gt;That became the Threat Actor’s Address. From that one anchor, everything unspooled: every victim’s wallet identified, and the money traced forward through bridges and laundering tricks designed to shake investigators off, all the way to deposit accounts inside exchanges that know exactly who opened them.&lt;/p&gt;
&lt;p&gt;The attacker hid inside shared infrastructure, thinking the crowd was cover.&lt;/p&gt;
&lt;p&gt;The crowd was the dataset.&lt;/p&gt;</content:encoded><category>Investigations</category></item></channel></rss>