$35,000 Gone in 15 Seconds: Tracing a TRON Address Poisoning Attack
A victim lost thirty-five thousand dollars to address poisoning on TRON. We followed the money across four hops, three DeFi protocols and a burn address, and found nothing a regulator can touch.
On August 27, 2026, a Chainabuse report landed under the category “Phishing Scams.” The victim had lost 35,000 USDT. The theft, they wrote, was not approved by them. The transaction hashes were right there in the report.
We opened them. This is what we found.
The attack: address poisoning in one transaction
Address poisoning is one of the simplest attacks in crypto. The attacker generates a wallet address that looks visually identical to one the victim has recently used, typically matching the first and last few characters. They send a tiny dust transaction from that fake address to the victim’s wallet, seeding it into the transaction history. The next time the victim copies an address from their history, they copy the attacker’s address instead.
In this case, the victim’s wallet TXnh9cZvY7VihQaWVbUCST9VYVwdR5TpYs sent 35,000 USDT to TFFi492pNbpo9QP8ZMpnXDzUFWaCBu5sUG on July 15, 2026 at 22:05:18 UTC. The funds were gone the moment the transaction confirmed. Fifteen seconds later, TFFi492… forwarded the full amount onward.
Fifteen seconds. No human sat at a keyboard and decided to move those funds. This relay was automated.
Hop 1: the relay
TFFi492… is an unlabelled address with no entity attribution in any public database we checked. Its behaviour is consistent with a pass-through relay: receive funds, forward the balance, move on. It holds no meaningful balance at rest.
The forward was 35,000.00001 USDT, a hundred-thousandth of a dollar more than it received, not less. That is not a fee; a fee would leave less behind, not more. It is most likely a sweep of the relay’s full balance, including a sliver of dust already sitting there from earlier activity, going out in the same transaction as the stolen funds.
The 15-second window eliminates any possibility of manual intervention. This is infrastructure, not a person.
tron_tx_transfers to resolve the seed transaction hash to sender, receiver, amount and token. Then tron_transfers_out on the relay address to confirm the forward and its timing.Hop 2: the hub
TWkvffFD… is where the trail gets complicated. This is not a wallet. It is a machine. Its role classification in on-chain data is “hub”: near-zero balance at all times, everything that comes in goes out immediately, to an enormous network of addresses. These figures move fast and the hub is still active, so treat them as a snapshot at time of publication, not a fixed count.
The $35,000 USDT entered this hub and dissolved.
tron_address_flow_summary to profile the hub, revealing its role, counterparty counts, and top inbound and outbound addresses. Then tron_flow_edges to map the major outflow paths by currency and volume.The four paths out
From the hub we identified four distinct outflow categories. Each has a different recovery profile, and a different next step.
Path A: the burn
The hub converts USDT to USDD via Sun.io, then sends it directly to the USDD PSM, TBXW4hS5KYjjbJXDpnrPf4zhkLwrpUjbyz, across 14 transfers. The PSM sends USDD to TRON’s black hole address, T9yD14Nj9j7xAB4dbGeiX9h8unkKHxuWwb, where it is permanently burned. In exchange, the depositor typically receives collateral, USDC, USDT or another stablecoin, through the PSM’s redemption side.
The burned tokens cannot be recovered. But the burn is not the full story.
tron_address_flow_summary. If that lands on an exchange deposit address, that is a freeze target. In parallel, the TRON DAO reserve team is worth contacting directly: this is their protocol, and a redemption this size is likely to leave an internal record even where the public event trail is thin.Path B: DEX swaps via Sun.io and JustSwap
USDT is swapped for TRX and other tokens through Sun.io’s router, TCFNp179Lg46D16zKoumd4Poa2WFFdtqYj, and JustSwap, TU2MJ5Veik1LRAgjeSzEdvmDYx7mefJZvd. Token conversion is a classic obfuscation step: it changes the asset identity, breaks stablecoin-specific chain monitoring, and produces outputs in a different currency that requires a separate trace.
No KYC exists at the DEX level. No identity is attached to any swap. The operator receives TRX back at an address they control, which can then be staked, converted, or used for gas.
tron_tx_transfers on the router addresses filtered to the relevant time window. Identify the recipient of the TRX output, then profile that address. TRX has three common next steps: staked on TRON (visible on-chain via energy and bandwidth records), converted back to USDT through a second swap (traceable through another DEX hop), or sent to an exchange deposit address. Run tron_trace_next_hop on the output address. If TRX lands at a labelled exchange address, that is the freeze target. Move fast: TRX withdrawals from exchanges clear quickly.Path C: UniversalRouter, a possible consolidation
USDD flows through Sun.io’s UniversalRouter, TSJEtPuqHpvSaVnSwvCsngaeBxrGUzp95Q, in one transfer of 100,000 USDD. Downstream of the router, an address we have flagged as a likely consolidator, TCc5deMgr64cQHfPs46zp5qXAAn9HmSwaP, forwards USDT to TBdiuvfuBtFAKPKAah4jKmLNQfvwphSMSn across 23 transfers totalling $426,912.25.
One caveat before treating this as confirmed: the UniversalRouter is a shared contract processing 425,000+ transactions for every Sun.io user, not just this theft, and its own largest outflow by far is back to the PSM itself, not to this consolidator. The router-to-consolidator link here is drawn from aggregate counterparty volume in the same window, not a single hop-by-hop confirmed transaction chain from the theft’s specific 100,000 USDD to the consolidator’s inflow. It is a real lead. It is not yet a proven chain. We did not confirm a KYC exchange at the end of this path.
tron_tx_transfers and check whether the theft’s specific 100,000 USDD resolves to the consolidator, rather than assuming it from aggregate flow. If confirmed, profile TBdiuvfuBtFAKPKAah4jKmLNQfvwphSMSn with tron_address_flow_summary and map its outflows with tron_flow_edges. If its top receivers include any labelled exchange addresses, cross-verify against a second source before acting on it. If a KYC exchange deposit is confirmed, two tracks run in parallel: contact the exchange compliance team directly with the full hop chain, and simultaneously request Tether freeze the USDT at the deposit address if it has not yet converted. Tether has a documented freeze mechanism. Speed matters: most exchanges process withdrawals within 24 hours of deposit.Path D: fragmented disbursement at scale
The remainder of the hub’s outbound volume goes to hundreds of thousands of unlabelled addresses in tiny increments of $1 to $10 USDT. This is layering at scale: break the original sum into fragments too small and numerous for manual review, then distribute across so many addresses that connecting them to the theft requires automated forensics far beyond what any individual investigator or regulator currently has access to.
A note on verification
One identification in this trace did not resolve cleanly on the first pass. A label lookup for the router in Path C, and for the black hole address in Path A, each returned a conflicting tag from a different source than the one we ultimately relied on. We did not take either identification on faith.
What we’re confident about, and what we’re not
Everything here comes from three independently checkable sources: the victim’s Chainabuse report and its transaction hashes, on-chain TRON/USDT-TRC20 transfer data, and public address labelling cross-verified across Tronscan and Arkham Intelligence.
Fifteen seconds to move it. Four paths to lose it.