Contract exploit report VR-99A3B8E7
Investigator report
Filed by a vetted PublicAML investigator rather than by an anonymous reader. The account itself has not been independently re-checked.
The addresses below carry a risk label from this report.
- Type
- Hack
- Reported as
- Contract exploit
- Chain
- ethereum
- Reported by
- DenysInvestigator
- Incident date
- Aug 23, 2026
- Published
- Sep 9, 2026
What happened
Addresses laundering the proceeds of the Term Labs exploit (23 August 2026, ~$8.5M lost), reported by PeckShieldAlert on 4 September 2026. PeckShield's alert referenced the exploiter address only inside a screenshot. PublicAML recovered the full addresses from the block numbers visible in that screenshot and verified every movement on-chain. 0xC14007663A5bb9F13d4d2AEE8c6FE9075eF1d83e β deposits into Tornado Cash. Verified on-chain: four deposits of 100 ETH each into the Tornado Router in blocks 25904455, 25904456, 25904457 and 25904460 on 4 September 2026 between 14:08:35 and 14:09:35 UTC. PeckShield reported 960 ETH (~$2.35M) deposited in total. Our own enrich already flagged this address as mixer-interaction before this report. 0xD5183d8BfC65a50863C62aF2538198A8288FFc13 β the funding address that supplied it. Verified on-chain: 100 ETH on 24 August, 400 ETH on 4 September 13:58, 100 ETH and 400 ETH on 4 September 19:10-19:12, then 2,000 ETH and 41.48 ETH on 5 September 05:03-05:16. Both are externally owned accounts, not contracts, and both are now effectively empty. Note on roles: PeckShield labels the first address the "Term Labs exploiter". The second is upstream of it and is recorded here as the source of the laundered funds, not as a separately confirmed exploiter. Source: https://x.com/PeckShieldAlert/status/2095881691017646109. Filed by PublicAML from public reporting plus our own on-chain verification, not by a victim of the incident.
Addresses named in this report
Named here and believe it is wrong? Open the address page above and use the flag on the assessment. Every dispute is read.
