Map
PDF
KALLISTI BLOCKCHAIN FORENSICS
TRC-20 (USDT primary asset) + native TRX ---
Target Wallet Address
TBwBJwj81yXc4DNKS19GJcpUUzfSWRbBzS
Report Date: 2026-06-03  ·  Prepared by Kallisti Blockchain Forensics
…UUzfSWRbBzS · TRON · 2026-06-03

S0 — Executive Summary

Attributed Entity  ·  TRON
OKX. Hot Wallet_116
TBwBJwj81yXc4DNKS19GJcpUUzfSWRbBzS
USDT In
$52.15M
659 inbound events
USDT Out
$80.86M
1321 outbound events
Balance
$3.63M
Current USDT on-chain
Active Span
5
days · 0.01 years
Transactions
96,386
659 USDT in · 1321 USDT out
Counterparties
1216
distinct USDT counterparties
AML Risk Score
10CLEAR
Clear
Low
Medium
High
Critical
Intelligence Brief
Case Facts
Wallet AddressTBwBJwj81yXc4DNKS19GJcpUUzfSWRbBzS
BlockchainTRON mainnet · TRC-20 USDT
First Seen2026-05-28 20:27:48 UTC
Last Active2026-06-03 02:01:33 UTC
Account Age5 days (0.01 years)
Primary TokenUSDT (…8otSzgjLj6t)
TRX Balance45568.7134 TRX
Counterparty Exposure by Category
Regulated CEX
$26.60M
Finding 01  · 
Attribution Confirmed — HIGH
Arkham 'OKX: Hot Wallet (TBwBJ)' and OKLink '#OKX Hot Wallet_116' independently agree. Attribution confidence: HIGH.
Finding 02  · 
Phishing Address Counterparty — $22.76M
TMj17yryskb2aP7H9BMgb2qhXKNNaN89Gs, labeled 'Phishing address' by OKLink, received 28.2% of all outflows ($22.76M) from this wallet. Residual balance: $2.48M USDT + $3.34K TRX.
Finding 03  · 
BTSE Inter-Exchange Settlement
BTSE Cold Wallet_1 received 22.7% of outflows ($18.39M) — confirmed institutional inter-exchange settlement routing.
Finding 04  · 
5-Day New Wallet
Wallet created 2026-05-28; only 5 days of operational history. Behavioral characterization is based on limited data.
Supporting Detail
AML Scorecard
Sanctions (OFAC/EU/UN)
CLEAR
Fraud/Scam Exposure
CLEAR
Ransomware/Darknet
CLEAR
Mixer/CoinJoin
CLEAR
Exchange Source Verif.
CLEAR
Structuring/Layering
CLEAR
Third-Party Risk
ELEVATED
Address Poisoning
CLEAR
Key Dates
2026-05-28Wallet Creation — OKX Hot Wallet_116 First Transaction
Attribution Hypotheses
H1OKX Exchange Infrastructure — Hot Wallet_116 with Phishing Counterparty
95%
H2Attribution Error or Wallet Rotation
5%
Confirmed OKX exchange hot wallet — $22.76M routed to OKLink-confirmed phishing address (TMj17); Third-Party Risk elevated
Investigator Summary
TBwBJwj81yXc4DNKS19GJcpUUzfSWRbBzS is a confirmed OKX exchange hot wallet (Hot Wallet_116), independently attributed by Arkham and OKLink. In its first 5 days of operation, the wallet processed $52.15M in / $80.86M out across 1,980 USDT transfers with 1,216 counterparties. The principal adverse finding is that the top outflow destination — TMj17yryskb2aP7H9BMgb2qhXKNNaN89Gs, labeled 'Phishing address' by OKLink — received $22.76M (28.2% of all outflows). For an exchange hot wallet, this constitutes a Third-Party Risk flag: OKX customers likely withdrew funds to a phishing-controlled address, indicating a significant phishing campaign targeting OKX users. The wallet itself is not the fraud perpetrator.
Recommended ActionsFlag TMj17yryskb2aP7H9BMgb2qhXKNNaN89Gs across all monitoring systems; determine whether OKX has been notified of the phishing activity and whether customer restitution proceedings are underway.  ·  Assess whether any institutional counterparty interacted with TMj17 and evaluate SAR obligations accordingly.
…UUzfSWRbBzS · TRON · 2026-06-03

S1 — TARGET PROFILE, FINANCIALS & ACTIVITY

Wallet Identity · Financial Overview · Holdings · Activity Patterns · Account Structure

DEPLOYMENT 155.1% Sent Out USDT IN$52.15MSent Out$80.86MNet Balance$-28.71MCURRENT HOLDINGSUSDT99.40%$3.63M$3.62MTRX0.40%45,568.7134 TRX$15,152.64WIN0.10%178,950,522 WIN$3,401.62NFT0.10%12,363,322,663 NFT$3,364.24SUNOLD20 SUNOLD$343.18AEDT10 AEDT$2.81COUNTERPARTIESPrivate / Unattributed7.9%OTC / BrokerRegulated CEX92.1%DeFi / ProtocolMixer / ObfuscationGovernmentCriminal / FraudSanctioned Entity
EntityOKX. Hot Wallet_116
BlockchainTRON mainnet · TRC-20 USDT wallet
Account Age5 days (0.01 years) ‖ Active: 2026-05-28 20:27:48 UTC → 2026-06-03 02:01:33 UTC
TRX Balance45568.7134 TRX
Transactions96,386 total · 1980 USDT transfers (659 in · 1321 out) · 1216 counterparties
Total USDT In$52.15M
Total USDT Out$80.86M
Net Balance$-28.71M

Activity Overview

BY YEAR Jun $15M $17M $14M InflowOutflow BY HOUR (UTC) 2 20 40 00 06 12 18 23 BY DAY Mon 411 Tue 518 Wed 16 Thu 38 Fri 369 Sat 357 Sun 271

Behavioral Classification

Confirmed OKX exchange hot wallet (Hot Wallet_116) — bidirectional high-volume flows consistent with customer withdrawal disbursement and institutional reserve funding. The wallet is 5 days old at scrape time; inflows are 100% OKX institutional. The critical finding is a $22.76M outflow to a confirmed phishing address (OKLink: 'Phishing address'), representing the largest single outflow destination in the wallet's short operational history.

Transaction Size Profile

Inflows averaged $79,136 per event (659 events, $52.15M total) reflecting institutional reserve transfers from OKX Withdraw_159 and user routing. Outflows averaged $61,210 per event (1,321 events, $80.86M total) reflecting customer withdrawal disbursements of varying sizes. The 2:1 outbound-to-inbound transfer ratio is standard for exchange withdrawal hot wallet operations.

Operational Profile

45,568.71 TRX (≈$15.1K) float maintained for energy and bandwidth. 96,386 transactions in 5 days (19,277/day) confirms continuous automated operation. Principal adverse finding: TMj17yryskb2aP7H9BMgb2qhXKNNaN89Gs (OKLink: ‘Phishing address’) received $22.76M (28.2% of outflows) — OKX customers directed withdrawals to this phishing-controlled address. BTSE Cold Wallet_1 received $18.39M (22.7%) as inter-exchange institutional settlement.

Temporal Activity Pattern

Over 5 days, UTC 14:00 was the hourly peak (143 events, 7.2%) with a broad active cluster from 09:00 to 20:00 UTC. Near-zero activity at 02:00 UTC (17 events) is consistent with a brief maintenance window during China morning hours (10:00 CST). Wednesday and Thursday DOW figures are creation-date artifacts. The distribution is consistent with OKX's Asia Pacific operational base and global user coverage.

Automation Assessment

Confirmed automated operation. 96,386 transactions in 5 days and continuous bidirectional USDT routing confirm exchange software processing. No manual operation signature is present; withdrawal disbursement is systematic and programmatic.

Sources
S1Tronscan — On-chain dataset · tronscan.org/#/address/TBwBJwj81yXc4DNKS19GJcpUUzfSWRbBzS
S2OKLink — TRON Address Detail · www.oklink.com/tron/address/TBwBJwj81yXc4DNKS19GJcpUUzfSWRbB…
…UUzfSWRbBzS · TRON · 2026-06-03

S2 — TRANSACTION NETWORK & FUND FLOW

Counterparty Map · Inflow Architecture · Outflow Architecture

IN 51.0% OUT 33.3% 29.8% 8.1% 28.2% 22.7% 4.9% 4.8% OKX. Withdraw_159 51.0% OKX. User 29.8% OKX. User 8.1% OKX. User 1.9% OKX. User 1.3% Phishing 28.2% BTSE. Cold Wallet_1 22.7% Binance. User 4.9% Binance. User 4.8% …fSWRbBzS$3.63MOKX. HOT WALLET_116 NODE: Exchange Unattributed Illicit/SDN OTC/Clean Mixer node size ∝ volume · edge weight ∝ share

Inflow

Upstream · Top 5 Funders

IDAddressVolume inAttributionRisk
A1TLaGjwhvA8XQYSxFAcAXy7Dvuue9eGYitv$26.60MOKX. Withdraw_159LOW
A2TVxG5YKwAtfuM3QmTqWDehk9FYGytru6Xi$15.53MOKX. UserLOW
A3TR2mVXEqL1gcsdhPbT6Z5AoQxKb7L1LxeD$4.21MOKX. UserLOW
A4TXKrjJBiaDqFatpDYGHNowEvVc3i9887KJ$969,995.70OKX. UserLOW
A5TXAyqdGYU6sSousxoFMVQAUenXUeZqRLPr$701,399.00OKX. UserLOW

Outflow

Downstream · Top 5 Destinations

IDAddressVolume outAttributionRisk
B1TLaGjwhvA8XQYSxFAcAXy7Dvuue9eGYitv$26.92MOKX. Withdraw_159MEDIUM
B2TMj17yryskb2aP7H9BMgb2qhXKNNaN89Gs$22.76MPhishingMEDIUM
B3TNBDqsyDiHB2j7NaQGyw3Kej6L4MAZGPg5$18.39MBTSE. Cold Wallet_1MEDIUM
B4TLeQfDqi9VeT8VgTgXHtivdsLJiZkB1ro4$4.00MBinance. UserLOW
B5TTRib8xqiN1sfDBYSAYsG1HQTdxTghvNGa$3.91MBinance. UserLOW
…UUzfSWRbBzS · TRON · 2026-06-03

S3 — OPERATIONAL PROFILE & SECURITY ASSESSMENT

Account Structure · Protocol Interactions · Threat Exposure

Security
Rating
COMPROMISEDADEQUATEPROFICIENT
90
PROFICIENT

Account Structure

Address TypeTRON Account (EOA)
Script EncodingTRC-20 USDT wallet
UTXO CountN/A — TRON account model
ClusteringArkham: 'OKX: Hot Wallet (TBwBJ)'; OKLink: '#OKX Hot Wallet_116'
Service LabelOKX Exchange — Hot Wallet_116 (attribution HIGH)
VASP ExposureOKX exchange (confirmed custodial VASP)
Wallet SoftwareExchange infrastructure (automated); created 2026-05-28

Protocol Interactions

CategoryStatus
Exchange Deposits / WithdrawalsACTIVE
Confirmed — OKX Hot Wallet_116 withdrawal disbursement function
DeFi / Smart Contract InteractionNONE
none identified
Lightning Network ChannelsNONE
Ordinals / InscriptionsNONE
Mixing / CoinJoin ServicesNONE
Cross-Chain BridgesNONE
Sanctions-Listed Address ContactNONE
none (TMj17 is phishing-labeled, not OFAC/EU/UN sanctioned)

Threat Exposure

DateCategorySourceNominalOutcome
2026-05-28Third-Party Risk…XKNNaN89Gs$22.76M USDT (28.2% of outflows)FUNDS SENT
Operational Summary

Network connections bifurcate into two categories: (1) OKX ecosystem (inflows and some outflows) representing the legitimate exchange network; (2) TMj17 phishing address, representing an adverse network link at 28.2% of outflows. BTSE Cold Wallet_1 represents a confirmed institutional inter-exchange connection. The phishing address (TMj17) retains $2.48M USDT, indicating the phishing operation may still be active or the proceeds have not been fully liquidated.

…UUzfSWRbBzS · TRON · 2026-06-03

S4 — AML / RISK ASSESSMENT

Sanctions Fraud/Scam Ransomware Mixer Exch.Source Structuring Third-Party Addr.Poison CRITERION EXPOSURE RATING Sanctions (OFAC/EU/UN) CLEAR Fraud/Scam Exposure CLEAR Ransomware/Darknet CLEAR Mixer/CoinJoin CLEAR Exchange Source Verif. CLEAR Structuring/Layering CLEAR Third-Party Risk LOW Address Poisoning CLEAR OVERALL AML RISK 10 CLEAR Scale: CLEAR=no exposure detected · MEDIUM=indirect signal · HIGH=direct confirmed exposure
CRITERIONFINDINGASSESSMENT
1. Sanctions (OFAC/EU/UN)
No OFAC, EU, or UN designation found. OKX is a licensed exchange; no sanctions exposure identified on this wallet.
CLEAR
2. Fraud/Scam Exposure
This wallet is OKX exchange infrastructure processing customer withdrawal requests; the phishing destination reflects customer-directed transfers, not fraud committed by this wallet. No direct fraud attribution on this address.
CLEAR
3. Ransomware/Darknet
No ransomware attribution or darknet marketplace association identified.
CLEAR
4. Mixer/CoinJoin
No mixer or CoinJoin interaction detected.
CLEAR
5. Exchange Source Verif.
100% of identified inflows originate from confirmed OKX infrastructure (OKX Withdraw_159 51%; OKX Users 41.3%). Exchange source fully verified.
CLEAR
6. Structuring/Layering
No structuring pattern. Mixed-size bidirectional flows consistent with exchange withdrawal disbursement operations.
CLEAR
7. Third-Party Risk
TMj17yryskb2aP7H9BMgb2qhXKNNaN89Gs, confirmed by OKLink as 'Phishing address', received $22.76M (28.2% of all outflows). Residual balance $2.48M USDT + $3.34K TRX remains unflushed. This represents a significant third-party risk signal — OKX customers directed withdrawal funds to a phishing-controlled address.
ELEVATED
8. Address Poisoning
No address poisoning pattern targeting this wallet detected.
CLEAR
Assessment

OKX is a registered global cryptocurrency exchange. The wallet is confirmed OKX infrastructure; its operations are consistent with normal VASP withdrawal disbursement. The phishing counterparty finding (TMj17) does not constitute a regulatory violation by OKX — exchange hot wallets process customer-directed withdrawal requests and do not independently verify every destination address. However, the $22.76M scale of phishing-linked outflows warrants notification to OKX compliance and may trigger SAR reporting obligations under applicable AML regulations for institutions with counterparty exposure to TMj17.

…UUzfSWRbBzS · TRON · 2026-06-03

S5 — NOTABLE EVENTS & ANOMALIES

Flagged Patterns & Significant Observations

OPERATIONAL PERIOD 2026-05 2026-06 Wallet Creation — OKX Hot Wallet_116 A-01 2026-05-28 HIGH — critical finding HIGH — monitor LOW — contextual
IDDateEventSeveritySignificance
A-012026-05-28Phishing Address Counterparty — $22.76M Outflow. TMj17yryskb2aP7H9BMgb2qhXKNNaN89Gs (OKLink: 'Phishing address') received 28.2% of all outflows ($22.76M) from this OKX hot wallet. Residual balance: $2.48M USDT + $3.34K TRX.CRITICALLargest single outflow destination is a confirmed phishing address. Indicates a large-scale phishing campaign targeting OKX withdrawal customers. The wallet is not the perpetrator; it processed customer-directed withdrawal requests.
Synthesis

TBwBJwj81yXc4DNKS19GJcpUUzfSWRbBzS is confirmed OKX Hot Wallet_116, independently attributed by Arkham and OKLink. In 5 days: $52.15M in / $80.86M out across 1,980 USDT transfers; 1,216 counterparties. Critical finding: TMj17yryskb2aP7H9BMgb2qhXKNNaN89Gs (OKLink 'Phishing address') received $22.76M (28.2% of outflows) — Third-Party Risk elevated to 0.25. All inflows fully OKX-sourced. AML: LOW. Security: PROFICIENT (90). Attribution: HIGH. Priority action: flag TMj17 and notify OKX compliance.

…UUzfSWRbBzS · TRON · 2026-06-03

S6 — OWNERSHIP ATTRIBUTION MODEL

Hypothesis Assessment

OKX Exchange Infrastructure — Hot Wallet_116 with Phishing Counterparty 95%

Attribution Error or Wallet Rotation 5%

Probabilities sum to 100%. Attribution confidence: 95 / 5.

What This Means For You

This wallet is confirmed OKX exchange infrastructure. Any counterparty interaction with this address is an interaction with the OKX platform. The phishing address finding (TMj17, $22.76M) indicates a significant phishing campaign targeting OKX customers. If TMj17 appears in your customer's transaction history, enhanced due diligence and SAR assessment are warranted. If you are an OKX customer who withdrew funds to a phishing address during May–June 2026, contact OKX security immediately.

…UUzfSWRbBzS · TRON · 2026-06-03

S7 — LINKS, DIGITAL FOOTPRINT & PUBLIC RECORD

Government Records · Press Coverage · Research & Analytics · Blockchain Intelligence

Blockchain Explorers
OKLink
2026-06-02
Address tagged '#OKX Hot Wallet_116' by OKLink. Counterparty TMj17yryskb2aP7H9BMgb2qhXKNNaN89Gs labeled 'Phishing address' by OKLink — the critical adverse finding in this case.
Tronscan
2026-06-02
On-chain history retrieved. 96,386 transactions in 5 days. 45,568 TRX operational float confirmed. No Tronscan risk tag on subject address.
Government & Official Records
OFAC SDN List
2026-06-02
NEGATIVE SWEEP: Address not found in OFAC Specially Designated Nationals list as of 2026-06-02.
Media & Press
OKX Exchange
2026-06-02
Subject address is confirmed OKX exchange infrastructure. OKX is a global tier-1 centralized cryptocurrency exchange serving 50M+ users in 180+ countries. Exchange entity is the registered operator of this wallet.
Research & Analytics
CoinGecko — OKX
2026-06-02
OKX exchange profile on CoinGecko confirms top-5 global CEX by spot volume. TRON/USDT operations active. No adverse regulatory designation listed as of 2026-06-02.
Chainabuse
2026-06-02
NEGATIVE SWEEP: No reports filed for this address on Chainabuse as of 2026-06-02. Phishing counterparty TMj17 should be checked as a separate OSINT target.
Intelligence Platforms
Arkham Intelligence
2026-06-02
Address attributed to OKX exchange (Hot Wallet) by Arkham Intelligence cluster. Attribution independently confirmed by OKLink entity tag.
OSINT Summary

Inbound flows are 100% OKX institutional. Outbound routing contains one critical adverse link: TMj17 phishing address ($22.76M, 28.2%). BTSE institutional settlement and 1,200+ customer withdrawals account for the remainder.

…UUzfSWRbBzS · TRON · 2026-06-03

S8 — RECOMMENDED FURTHER INVESTIGATION

Priority Actions & Engagement Opportunities

P1Notify OKX Compliance — Report the phishing counterparty finding (TMj17, $22.76M) to OKX security/compliance team. Request confirmation of the phishing incident and any customer restitution actions. · Regulatory
P2Flag TMj17 Across All Systems — Add TMj17yryskb2aP7H9BMgb2qhXKNNaN89Gs to all monitoring systems. Track residual $2.48M USDT balance for movement; any outflow may indicate active liquidation of phishing proceeds. · On-chain
P3SAR Assessment — Evaluate SAR obligations for any institution with documented counterparty exposure to TMj17yryskb2aP7H9BMgb2qhXKNNaN89Gs. · SAR
P4OSINT — Phishing Address Investigation — Conduct OSINT on TMj17yryskb2aP7H9BMgb2qhXKNNaN89Gs; search for OKX phishing incident reports, security advisories, and any victim disclosures referencing this address or the May–June 2026 period. · OSINT
Investigator Assessment

Priority action: flag TMj17yryskb2aP7H9BMgb2qhXKNNaN89Gs (phishing address, $22.76M received) across all monitoring systems and notify OKX compliance. The $2.48M residual USDT balance at the phishing address has not been moved — monitoring for outflow will indicate when/if the phishing operator liquidates remaining proceeds.

…UUzfSWRbBzS · TRON · 2026-06-03

APPENDIX A — MASTER SOURCE LIST

REFSOURCE
S1On-chain dataset -- TRC-20 Transfers
https://tronscan.org/#/address/TBwBJwj81yXc4DNKS19GJcpUUzfSW…
Full TRC-20 transfer history via Tronscan API. Retrieved 2026-06-03.
S2On-chain dataset -- Raw Transactions
https://tronscan.org/#/address/TBwBJwj81yXc4DNKS19GJcpUUzfSW…
Full transaction log via Tronscan API. Retrieved 2026-06-03.
S3Arkham -- Address Profile
https://intel.arkm.com/explorer/address/TBwBJwj81yXc4DNKS19G…
Screenshot captured 2026-06-03. File: screenshot_arkham.png
S4Tronscan -- Address Profile
https://tronscan.org/#/address/TBwBJwj81yXc4DNKS19GJcpUUzfSW…
Screenshot captured 2026-06-03. File: screenshot_tronscan.png
S5Oklink -- Address Profile
https://www.oklink.com/tron/address/TBwBJwj81yXc4DNKS19GJcpU…
Screenshot captured 2026-06-03. File: screenshot_oklink.png
…UUzfSWRbBzS · TRON · 2026-06-03

APPENDIX B — GLOSSARY OF TERMS

TERMDEFINITION
Phishing AddressAn address flagged by blockchain intelligence platforms as associated with phishing operations — typically used to receive funds from victims deceived into providing fraudulent withdrawal or payment destinations.
Inter-Exchange SettlementA transfer between two known exchange cold or treasury wallets representing institutional-level liquidity movement, not a customer transaction — standard in exchange treasury management.
Hot WalletAn exchange-operated online wallet used for processing real-time customer deposits and withdrawals; maintains a working balance of assets for immediate disbursement.