If crypto disappeared from your wallet after you connected it to an Aurum-branded site, this page is about your case specifically. It is the same answer for everyone it happened to, so you should not have to work it out alone.
Nobody stole your seed phrase. You approved something — a token approval, or an account delegation — on a site that looked like Aurum. That permission let a contract move funds out of your wallet, and it keeps working until you cancel it. The funds were pooled in one collector wallet, then split: part bridged to TRON, part sent straight to an exchange account, a smaller part left sitting on Ethereum. The drain is still running today against wallets whose approvals are still live.
Paste your address. The check is free, needs no account and no payment, and reads the live chain. It answers one question and only that question: what this operation took out of your wallet, and where it went. You stay on this page — nothing here turns into a general wallet report you then have to read through. It takes 20–60 seconds, because it reads three chains and the live approval state rather than a stored copy.
We do not ask who you are, we have no account for you, and we will never ask for a seed phrase, private key or wallet password — nor should anyone else.
Two mechanisms, both of which need you to sign once and nothing after that.
Approving a token tells a contract it may move that token out of your wallet — any amount, any time, until you cancel. It is the same mechanism every legitimate exchange and swap uses, which is what makes it convincing. An approval granted months ago still works today.
Newer and worse: the account itself is pointed at a contract, so that contract can act as your wallet. A delegation you did not set means the wallet is compromised, not just one token. No website can remove it — the removal has to be signed inside your own wallet app, which is a useful thing to know, because anyone offering to remove it for you from a website is lying.
TraceHunt has step-by-step removal instructions for SafePal, MetaMask and Trust Wallet, taken from each wallet's own documentation.
Every address below is real and public — open any of them on a block explorer and check this yourself. That is the point of publishing them.
Victims connected a wallet to an Aurum-branded site and approved a transaction. Two mechanisms were used: a normal token approval, which lets a contract move that token out of your wallet whenever it likes, and an EIP-7702 delegation, which hands control of the account itself to a contract. Neither needs your seed phrase. Both keep working until you cancel them — which is why wallets are still being emptied today.
The operator address named in the phishing sites' own configuration. It receives the approvals and is the hard-coded owner on the drainer contracts. Still active — the most recent token movement seen on it was 2026-09-13, so this is not a closed case.
Two separate contracts — verified as distinct code on chain, not one contract redeployed. They call transferFrom in batches against every wallet that still has a live approval. A third contract ran the same sweep on Arbitrum.
This is the wallet most victims will recognise from their own transaction list. It is a pass-through, not a vault: funds land and are swept onward within minutes, so what sits in it at any moment is a rounding error against what has gone through it. Read live on 13 Sep 2026 it held 11,231.15 BSC-USD on BNB Chain and $297.35 of USDT plus $367.24 of USDC on Ethereum — about $11,900 in total, against $3,607,504.73 of victim funds that have moved through it in 11,394 transfers from 8,930 separate wallets between 23 July and 13 September 2026. Those are counted transfer by transfer from chain, not estimated. The throughput is the fact; the balance is not.
AF2 did not hold anything. It split what it collected four ways:
The largest single exit: about $2.14M swapped through a cross-chain service into USDT on TRON, landing at TXWVpPX1…qgumK and swept onward into the operation's TRON cash-out network.
What can be done: A bridge breaks the transaction chain — the TRON side has no hash link back to the BNB Chain side. Only the swap service's own order records join them, which is a subpoena, not a scan.
About $850,000 went directly to a deposit address at a major exchange. A deposit address belongs to one identified account holder.
What can be done: This is the strongest lead in the whole drain arm: the same deposit address was also fed by the platform side of the operation, so one account connects both. Police can ask the exchange who it is.
The Ethereum leg. It held more earlier in the case and has been drawn down since: $3,288.65 of USDT when read live on 13 September 2026. Small, but it is the one balance in the drain arm still sitting at an address the operation controls rather than inside an exchange.
What can be done: USDT can be frozen by its issuer at a law-enforcement request, and this address is not on the blacklist today. It is the cleanest freeze target in the drain arm, and it is shrinking — which is the whole argument for reporting early rather than waiting.
About $160,000 into a second bridge service's depository.
What can be done: Same problem as the first bridge: service records are the only link.
The drain arm touched four: BNB Chain (where most of it happened, in BSC-USD and USDC), Ethereum (a smaller leg, in USDT — and the one pot still sitting still), Arbitrum (a third drainer contract running the same approval sweep), and TRON (not drained directly — this is where the bridged money landed, as USDT). Nothing else on this page belongs to any other case.
This is the drain arm only — the money that came out of victims' wallets. Read live on 2026-09-12. self-verified
| Where it went | Chain | What can be done about it | Amount |
|---|---|---|---|
| Bridgers/SWFT bridge 0xb685760ebd368a891f27ae547391f4e2a289895b lands at TXWVpPX1aRWfRLeUmdTeBQHkG4W9iqgumK on TRON as USDT | BNB Chain | A bridge is not a transfer — the funds are paid out on the other chain from the service's own liquidity, so there is no transaction hash joining the two sides. The TRON payout address is known and the amount and timing match, which is why it is stated here, but the link is an inference from the service's behaviour, not a hash. Only the bridge operator's own order records prove it, and those come out under legal process, not a scan. On TRON the funds were swept onward into the operation's cash-out network, where they are mixed with funds from its platform arm and from unrelated users. Past that point no amount can honestly be attributed to the wallet drain specifically. | $2.14M |
| Binance deposit address 0x2bfc43abaa244edfe531736b168df8ab2c4bc6e0 | BNB Chain | This is a per-customer deposit address, which means it credits ONE identified account. That is where on-chain tracing stops and it stops for a good reason: once value is inside an exchange it stops being a blockchain balance and becomes a ledger entry in that company's database. No explorer, no tool and no analyst can see past it. What happens next is not a tracing problem at all — it is a request from law enforcement to the exchange. This is the strongest lead on the whole drain arm. The same deposit address was also fed from the operation's platform side, so a single account connects both. An exchange holds identity documents, IP and device records, and the onward movement — and can freeze a balance on a valid request. Reporting quickly is what makes that possible. | $850,000 |
| Relay bridge depository 0x4cd00e387622c35bddb9b4c962c136462338bc31 | BNB Chain | Second bridge service, same problem: the payout happens from the service's liquidity on the destination chain, so no hash joins the two sides. The service's order records are the only link. | $160,001 |
| Still at an operation address 0x31Fc20dEcaC7e9A32286876dBBaFf18596560A4e | Ethereum | The one drain-arm balance not inside an exchange or a bridge service. USDT, and freezable by its issuer on a law-enforcement request. | $3,289 |
3,607,504.73 US dollars in stablecoins left victims' wallets and passed through the collector. These are the operation's aggregate figures for the whole drain arm — not any one person's money. Your own figure is whatever your own wallet shows, and the free check above computes it from your own transactions.
self-verified On 2026-09-13 every inbound transfer to the collector was counted, block by block, on all three chains it runs on:
| Chain | Wallets drained | Value taken |
|---|---|---|
| BNB Chain | 5,312 | $3.25M |
| Ethereum | 460 | $294,573 |
| Base | 58 | $63,933 |
| arbitrum | 39 | $1,641 |
| Total | 5,620 | $3.61M |
5,620 wallets lost a dollar or more, totalling $3,607,504.73 — of which 2,109 lost over $100 and 548 lost over $1,000. The case file said about 8,500 wallets and $3.2M; that counted BNB Chain only and never included the 456 wallets drained on Ethereum or the 46 on Base.
A further 3,310 addresses sent the collector less than a dollar in total. We count those separately and not as thefts — addresses caught up in something like this get sprayed with worthless tokens, and including them would inflate the victim count by more than half while changing the money total by about eight hundred dollars. If yours is one of them the check above will still find it and show you exactly what it was.
The most recent one arrived on 2026-09-13, the day this was counted. This is not a closed case being written up — wallets are still being emptied, and the only thing that stops it for your wallet is cancelling the permission. Treat the total as a floor.
Two of them are bridges. A bridge does not send your coins across — it takes them on one chain and pays out different coins on the other chain from its own reserve, so there is no transaction hash joining the two sides. The destination is known and the amounts and timing match, but proving the link needs the bridge operator's own order records, and those come out under legal process.
One is an exchange deposit address, and that is a different kind of ending. Once value is inside an exchange it stops being a blockchain balance and becomes a line in that company's private ledger. No explorer, no analyst and no tool can see past it — and that is not bad news. An exchange knows who owns the account, holds their identity documents, and can freeze a balance when law enforcement asks. An exchange deposit address is the best place for stolen money to stop, because it is the one place a person is attached to it. It is the reason to report quickly rather than to keep tracing.
The Ethereum leg of the drain: $3,289 of USDT as of 2026-09-12. It is the only drain-arm balance that is neither inside an exchange nor inside a bridge service. USDT can be frozen at the contract level by its issuer on a law-enforcement request, and this address is not on the blacklist today. It is also shrinking — it held roughly sixteen times this amount earlier in the case — which is the whole argument for reporting now rather than waiting to see what happens.
The same operation also ran a deposit platform, and most of the money tracked in this case — about $11,901,448 as of 2026-09-12 — came from that side, not from drained wallets. It is a much larger pot and it is not yours. It is mentioned so that you recognise the figure if you see it quoted elsewhere about this case, and know that it is a different pot from the one your wallet was emptied into.
Every address on this page is watched. This table is read from the chains themselves when you load it — not from a stored copy — so you can see whether the wallets involved in this case are active right now.
Reading the chains…
This is the part people ask for and rarely get: what happened after the bridge. We walked it on chain on 13 September 2026, one transfer at a time, always following the largest amount out of each address. self-verified
Publicly tagged Bridgers and carrying over five million transactions — this is the service's hot wallet, paying out to whoever each order names. It is not the operation's wallet and everything in it belongs to thousands of unrelated users.
Received 178,975.73 USDT from the bridge wallet and passed 178,970 straight on, over 30-31 July 2026. Ten transactions in its entire life and nothing left in it.
Took the 178,970 plus a further 9,923.50 paid directly by the bridge wallet, and forwarded 188,880 the same day.
700,000 USDT in from two sources, 700,000 straight out. More arrived here than came down the trail, so from this point on the balance is not all drain money.
1,569,782.23 USDT in from five addresses, split onward into two amounts of 1,100,000 and 469,780.
1,100,000 USDT in and the same amount straight out, same day.
This address was already in the case file as a commingled OTC tap, and the walk arrived at it independently — which is the useful part. It has over 227,000 transactions and took money from 882 different addresses in the two days to 13 September alone. Anything here is mixed with funds that have nothing to do with this case.
565,857 USDT in, split three ways within a day.
The last address before the exchange. It has collected 27,281,967.65 USDT from 84 addresses since September 2025 and sent effectively all of it to one place.
Publicly tagged as Bybit and carrying tens of millions of transactions, so this is an exchange wallet rather than one customer's deposit address. This is where on-chain tracing ends.
Read honestly, this is a trail and not a receipt. Each hop was verified on chain, but from the fourth address onward more money arrives at each stop than came down the trail, so the funds are mixed with money from elsewhere. Nobody — not this service, not a commercial analytics firm — can say which specific dollars at the end belong to which victim. What the walk does establish is the route and the destination, and that is what a police officer or an exchange compliance desk needs in order to ask the next question.
The trail ends at an exchange wallet. That is the honest boundary of what any on-chain tool can do: once value is inside an exchange it stops being a blockchain balance and becomes a line in that company's private ledger. The last two addresses are recorded here so they are on file and anyone can check them for themselves.
Collected $27,281,967.65 from 84 addresses and sent effectively all of it onward to the exchange below. Money from this case is mixed here with money from elsewhere, so no share of what sits at this address can be attributed to any one victim — it is on file as part of the route, not as a claim on the balance.
Publicly tagged Bybit, and carrying tens of millions of transactions — an exchange wallet, not one customer's deposit address, so it does not by itself identify anybody. What it does mean is that a named company holds the records of what happened next and can be asked for them by law enforcement. That is the next step, and it is not a tracing step.
Checked live on 13 September 2026 against public nodes. self-verified
| Chain | Collector active? | What we found |
|---|---|---|
| BNB Chain | yes · 90 transactions | Where most of the drain ran. AF2 holds 11,231.15 BSC-USD. |
| Ethereum | yes · 39 transactions | AF2 holds $297.35 USDT and $367.24 USDC. Both drainer contracts deployed. |
| Base | yes · 20 transactions | Both drainer contracts deployed here with identical code, and AF2 has 20 transactions. Balances are empty today, so whatever came through has moved on — but an approval granted to those contracts on Base is still live until it is cancelled. |
| Arbitrum | yes · 6 transactions | Confirmed: both drainer contracts are deployed here with the same code as everywhere else, the operator address has 18 transactions and AF2 has 6. 39 wallets lost a dollar or more here. An earlier version of this page could not check Arbitrum and said so; it can now, and the case file was right. |
| Optimism | no · never used | AF2 has never sent a transaction and holds nothing. |
| Avalanche | no · never used | AF2 has never sent a transaction and holds nothing. |
| Gnosis | no · never used | AF2 has never sent a transaction and holds nothing. |
The two contracts that pulled funds out of wallets are deployed at the same addresses on BNB Chain, Base and Ethereum, with byte-identical code — verified by reading the runtime bytecode from each chain and comparing its SHA-256 hash:
3,147 bytes of runtime code, SHA-256 b985fc20ec5f7699… — identical on BNB Chain, Ethereum, Base, Arbitrum.
6,371 bytes of runtime code, SHA-256 e92f751c1851ad26… — identical on BNB Chain, Ethereum, Base, Arbitrum.
This matters to you directly: an approval you granted on Base or Ethereum is exactly as live as one on BNB Chain. This page did not previously mention Base at all, and the free check above now reads all four chains.
A drain that is still running is a permission that is still live. Run the free scan below on your own wallet: it reads every chain and lists the approvals and delegations that exist right now. Cancel them in your own wallet. TraceHunt never touches your keys and cannot do it for you.
An EIP-7702 delegation you did not set means someone else can act as that account. Removing it stops the sweeper, but whoever set it can set it again if they still hold what let them do it. Move anything of value to a brand-new wallet with a new secret phrase, and treat the old one as burned.
Tracing produces evidence; it does not recover funds. What acts on evidence is a police report and an exchange compliance desk. The reporting channel is different in every country and every one of them is free.
The same operation rebranded as a paid “recovery” service and went back to its own victim list. Anyone who contacts you offering to recover this money for a fee is running the second fraud. Official reporting is free, and no website can undo a delegation — only your own wallet app can.
Check your wallet against this case Where to report, by country Is the USDT frozen?
After the drain, the same operation rebranded and went back to its own victim list offering paid "recovery". If someone contacts you about this loss offering to get the money back for a fee, an unlock payment, a tax, or a wallet connection, that is the second fraud and you are being targeted because you are on a list. Reporting to police is free. Nobody can return funds from a blockchain by asking for a payment first, and no website can remove a delegation.
self-verified figures were read live from public blockchain data by this service's own tooling on the date shown — balances, transfer aggregates and contract code. report-sourced figures come from case documents and are labelled where used; victim-count figures in particular are early list counts known to include addresses later found not to be victims, so they are deliberately not quoted on this page as a headline. Attribution of an address to a role is an assessment at a stated confidence level, not proof of who controls it — identifying any individual requires legal process directed at a service, which is police work, not ours. No natural person is named anywhere in this service.