Map
PDF
KALLISTI BLOCKCHAIN FORENSICS
TRC-20 (USDT primary asset) + native TRX ---
Target Wallet Address
TFvuXyB7AhCV7jZcC9uukZDqrqCvsZQMJh
Report Date: 2026-06-01  ·  Prepared by Kallisti Blockchain Forensics
…qrqCvsZQMJh · TRON · 2026-06-01

S0 — Executive Summary

Attributed Entity  ·  TRON
Unattributed
TFvuXyB7AhCV7jZcC9uukZDqrqCvsZQMJh
USDT In
$221.04M
40 inbound events
USDT Out
$75.00M
6 outbound events
Balance
$146.04M
Current USDT on-chain
Active Span
518
days · 1.42 years
Transactions
70
40 USDT in · 6 USDT out
Counterparties
11
distinct USDT counterparties
AML Risk Score
14CLEAR
Clear
Low
Medium
High
Critical
Intelligence Brief
Case Facts
Wallet AddressTFvuXyB7AhCV7jZcC9uukZDqrqCvsZQMJh
BlockchainTRON mainnet · TRC-20 USDT
First Seen2024-12-17 02:10:48 UTC
Last Active2026-05-20 00:25:57 UTC
Account Age518 days (1.42 years)
Primary TokenUSDT (…8otSzgjLj6t)
TRX Balance148.9935 TRX
Counterparty Exposure by Category
Private / Unattributed
$221.03M
Regulated CEX
$7,167
Finding 01  · 
99.6% of inflows from unattributed sources
Four structurally identical feeder wallets account for $220.03M of $221.04M total inflows; none carries an entity label across Arkham, OKLink, or Tronscan.
Finding 02  · 
222-day operational dormancy
No on-chain activity between 2025-03-15 (post-$60M outflow) and 2025-10-23; wallet then resumed with $67.6M in deposits over two days.
Finding 03  · 
Relay intermediary at hop-1 destination
Top outflow address (opngwSi21V6R) shows $716.6M lifetime throughput with IN = OUT to six decimal places; zero USDT residual balance; routes to a TDXb-prefixed address cluster.
Finding 04  · 
Gulf-region operator timezone signature
DOW distribution: Tue 34.8%, Thu 19.6%, Fri 2.2%. Hourly peak 08–16 UTC. Near-absent Friday + elevated Saturday consistent with Islamic business calendar (UTC+3/+4).
Finding 05  · 
Address poisoning — two instruments received
stUSD token (136.96M units, USDT name-mimic) and AML-named token airdropped to wallet; neither constitutes confirmed exploitation.
Finding 06  · 
Binance trace — de minimis
TAzsQ9Gx8eqFNFSKbeXrbi45CuVPHzA8wr (Binance: Withdraw_18) transferred $7,166.55 on 2026-01-10; confirms Binance network connectivity by negligible value.
Supporting Detail
AML Scorecard
Sanctions (OFAC/EU/UN)
CLEAR
Fraud/Scam Exposure
CLEAR
Ransomware/Darknet
CLEAR
Mixer/CoinJoin
CLEAR
Exchange Source Verif.
MONITOR
Structuring/Layering
MONITOR
Third-Party Risk
MONITOR
Address Poisoning
MONITOR
Key Dates
2024-12-17Activation · $33.6M initial deposits
2025-03-15$60M outflow to relay
2025-10-23Resumed after 222-day gap
2026-02-12$15M second outflow
2026-05-20Most recent activity
Attribution Hypotheses
H1Private Institutional Treasury (Gulf Region)
65%
H2Layering Intermediary in Multi-Hop Dispersal Chain
25%
H3OTC Broker Settlement Reserve
10%
Private USDT treasury accumulating from four unattributed feeder wallets; sources unverified, partial outflows via a pass-through relay intermediary; Gulf-region operator signature.
Investigator Summary
$146M USDT treasury active since December 2024, accumulating from four structurally identical unattributed feeder wallets that together account for 99.6% of $221M total inflows. Transaction timing is consistent with a Gulf-region operator: Friday carries 2.2% of events (Islamic rest day), and the 08–16 UTC hourly peak maps to working hours in the Gulf states (UTC+3/+4). Two outbound movements — $60M in March 2025, $15M in February 2026 — route through a pass-through relay with $716M lifetime throughput to an unidentified downstream cluster. A 222-day dormancy followed the first outflow; the wallet resumed with a $67.6M two-day deposit burst. Trace to Binance confirmed via de minimis $7,167 withdrawal (Binance: Withdraw_18). Address poisoning targeting confirmed. No sanctions, fraud, or mixing exposure identified. Risk assessment: LOW — no confirmed adverse indicators; four MONITOR items (unverified sources, aggregation pattern, relay outflows, address poisoning).
Recommended ActionsP1: Attribute top 4 feeder wallets (99.6% of inflows)  ·  P2: Trace relay destinations TDXbhgx…kHme ($512.6M) and TDZ1caS…vF8 ($204M)  ·  P3: Beneficial ownership inquiry if under legal review
…qrqCvsZQMJh · TRON · 2026-06-01

S1 — TARGET PROFILE, FINANCIALS & ACTIVITY

Wallet Identity · Financial Overview · Holdings · Activity Patterns · Account Structure

DEPLOYMENT 33.9% Sent Out 66.1% Net Balance USDT IN$221.04MSent Out$75.00MNet Balance$146.04MCURRENT HOLDINGSUSDT100.00%$146.04M$145.82MTRX148.9935 TRX$52.34COUNTERPARTIESPrivate / Unattributed100.0%OTC / BrokerRegulated CEXDeFi / ProtocolMixer / ObfuscationGovernmentCriminal / FraudSanctioned Entity
EntityTFvuXyB7AhCV7jZcC9uukZDqrqCvsZQMJh
BlockchainTRON mainnet · TRC-20 USDT wallet
Account Age518 days (1.42 years) ‖ Active: 2024-12-17 02:10:48 UTC → 2026-05-20 00:25:57 UTC
TRX Balance148.9935 TRX
Transactions70 total · 46 USDT transfers (40 in · 6 out) · 11 counterparties
Total USDT In$221.04M
Total USDT Out$75.00M
Net Balance$146.04M

Activity Overview

BY YEAR Dec 2025 Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec 2026 Feb Mar Apr May Jun $36M $22M $20M $60M $15M InflowOutflow BY HOUR (UTC) 2 4 6 00 06 12 18 23 BY DAY Mon 5 Tue 16 Wed 6 Thu 9 Fri 1 Sat 6 Sun 3

Behavioral Classification

This is a USDT accumulation wallet with treasury characteristics: 66% balance retention ($146M of $221M inflows held), concentrated sourcing from a small controlled feeder set, and infrequent bulk outflows. The wallet does not interact with DeFi protocols, does not receive material exchange deposits, and does not exhibit retail spending patterns. The operational signature is that of a dedicated single-purpose treasury account.

Transaction Size Profile

Inbound transfers range from four $100 activation probes — standard address ownership verification — to single deposits of $36M, with the dominant tranche size in the $5M–36M institutional range. Outbound transfers are strictly round: $60,000,000 on 2025-03-15 and $15,000,000 on 2026-02-12. Variable inbound sizes combined with round-number outflow discipline is consistent with instruction-driven treasury disbursement.

Operational Profile

The wallet is a standard TRON external account (EOA), not a smart contract. Address reuse is total across 518 days; all 11 counterparties interact with the same single address. The TRX float of 148.99 TRX is deliberately maintained at a level sufficient for bandwidth and energy without over-funding. Outflow concentration is extreme: two counterparties received 100% of outbound value on only two calendar dates across 518 active days.

Temporal Activity Pattern

Friday carries 2.2% of events vs. Monday–Thursday at 78.3% (peak Tuesday, 34.8%); hourly peak 08:00–16:00 UTC maps to Gulf working hours (UTC+3/+4) — consistent with an Islamic business calendar operator. The 222-day dormancy (2025-03-15 to 2025-10-23) is the defining feature: $60M dispatched, silence, then a $67.6M two-day burst on resumption — deliberate operational pause, not abandonment.

Automation Assessment

The wallet shows no evidence of automated or scripted operation. Transfer intervals are highly irregular (ranging from same-day batches to multi-month gaps), batch sizes vary widely, and no fixed-schedule or equal-amount pattern is present. The human-operated profile is reinforced by the business-hours DOW concentration and the manual address-probe pattern at activation.

Sources
S1Tronscan — On-chain dataset · tronscan.org/#/address/TFvuXyB7AhCV7jZcC9uukZDqrqCvsZQMJh
S2OKLink — TRON Address Detail · www.oklink.com/tron/address/TFvuXyB7AhCV7jZcC9uukZDqrqCvsZQM…
…qrqCvsZQMJh · TRON · 2026-06-01

S2 — TRANSACTION NETWORK & FUND FLOW

Counterparty Map · Inflow Architecture · Outflow Architecture

39.4% 30.1% 17.7% 12.8% 80.0% 20.0% …MJ5ZNeug 39.4% …bgb53LtN 30.1% …y3t8theN 17.7% …R4q8Ls1B 12.8% Binance: Withdraw_18 0.0% …wiD21V6R Relay — Pass-Through 80.0% …WEmTDSLQ 20.0% …CvsZQMJh$146.04MTARGET NODE: Exchange Unattributed Illicit/SDN OTC/Clean Mixer node size ∝ volume · edge weight ∝ share

Inflow

Upstream · Top 5 Funders

IDAddressVolume inAttributionRisk
A1TKJa5yhD6SX42CbZjwuArnc1o3MJ5ZNeug$87.10MUnattributedMEDIUM
A2TG1behizYfNrrzAoNS1tSL86pEbgb53LtN$66.43MUnattributedMEDIUM
A3TPXfkQLTytwww2SrRY63vMrCmwy3t8theN$39.22MUnattributedMEDIUM
A4TNS17kGeCNke3PRrj7tteuyiwbR4q8Ls1B$28.28MUnattributedMEDIUM
A5TAzsQ9Gx8eqFNFSKbeXrbi45CuVPHzA8wr$7,166.55Binance: Withdraw_18LOW

Outflow

Downstream · Top 5 Destinations

IDAddressVolume outAttributionRisk
B1TWvr9cZLK9995Nxg7Qans8opngwSi21V6R$60.00MRelay — Pass-ThroughMEDIUM
B2TKBs4Fwyz7dk8mBW726zNytnGHWEmTDSLQ$15.00MUnattributedMEDIUM
B3TWvrxbCvRvvy3tL5yfvPZ66wndwiD21V6R$0.00UnattributedLOW
…qrqCvsZQMJh · TRON · 2026-06-01

S3 — OPERATIONAL PROFILE & SECURITY ASSESSMENT

Account Structure · Protocol Interactions · Threat Exposure

Security
Rating
COMPROMISEDADEQUATEPROFICIENT
62
ADEQUATE

Account Structure

Address TypeTRON External Account (EOA) — standard externally controlled address
Script EncodingTRC-20 USDT account · native TRX
UTXO CountN/A — TRON account model
ClusteringNone identified — Arkham, OKLink, and Tronscan carry no cluster or entity label
Service LabelNone — unattributed across all sources
VASP ExposureIndirect — $7,166.55 received from Binance: Withdraw_18 (…45CuVPHzA8wr) on 2026-01-10
Wallet SoftwareUnknown — no characteristic on-chain footprint

Protocol Interactions

CategoryStatus
Exchange Deposits / WithdrawalsLIMITED
Indirect — $7,166.55 received from Binance (Withdraw_18) on 2026-01-10 · no direct exchange deposit or withdrawal identified
DeFi / Smart Contract InteractionNONE
None identified
Lightning Network ChannelsN/A
N/A — TRON
Ordinals / InscriptionsN/A
N/A — TRON
Mixing / CoinJoin ServicesNONE
None identified
Cross-Chain BridgesNONE
None identified
Sanctions-Listed Address ContactNONE
None identified

Threat Exposure

DateCategorySourceNominalOutcome
2026-06-01Address Poisoning…96ZmcTDRde136,959,514 stUSD units airdropped — USDT name-mimic; clipboard hijack riskLOW
2026-06-01Address Poisoning…oi3nmg4hnEAML-named token airdropped — social-engineering probe for compliance reviewersLOW
Operational Summary

Security rating ADEQUATE (62/100). The wallet is a standard TRON external account with no multisig protection, timelock, or smart-contract custody. The TRX float is appropriately sized for operational needs without over-funding. The primary security exposure is address poisoning: two targeted instruments have been airdropped, indicating this wallet is on active adversarial lists. A $146M balance without enhanced custody is a material operational risk; any operator sending from this address should verify recipient addresses independently of clipboard copy-paste workflows.

…qrqCvsZQMJh · TRON · 2026-06-01

S4 — AML / RISK ASSESSMENT

Sanctions Fraud/Scam Ransomware Mixer Exch.Source Structuring Third-Party Addr.Poison CRITERION EXPOSURE RATING Sanctions (OFAC/EU/UN) CLEAR Fraud/Scam Exposure LOW Ransomware/Darknet CLEAR Mixer/CoinJoin CLEAR Exchange Source Verif. LOW Structuring/Layering LOW Third-Party Risk LOW Address Poisoning LOW OVERALL AML RISK 14 CLEAR Scale: CLEAR=no exposure detected · MEDIUM=indirect signal · HIGH=direct confirmed exposure
CRITERIONFINDINGASSESSMENT
1. Sanctions (OFAC/EU/UN)
Screened against OFAC SDN, EU Consolidated List, and UN Sanctions; no entry found for the subject or any directly attributed counterparty.
CLEAR
2. Fraud/Scam Exposure
No fraud or scam reports on Chainabuse, BitcoinAbuse, or CryptoScamDB. The wallet is a target of address poisoning spam but is not listed as a perpetrating address.
CLEAR
3. Ransomware/Darknet
No ransomware family attribution or darknet marketplace exposure identified.
CLEAR
4. Mixer/CoinJoin
No interaction with known mixing services or CoinJoin protocols. The relay intermediary does not exhibit mixing characteristics (no equal-amount fan-out, no time-delay obfuscation).
CLEAR
5. Exchange Source Verif.
99.6% of $221M inflows originate from four wholly unattributed wallets. Only $7,166.55 (0.003% of inflows) traces to an identified exchange source (Binance: Withdraw_18).
MONITOR
6. Structuring/Layering
Four coordinated feeder wallets channel similar-magnitude tranches into the subject over overlapping periods. Primary outflow routes through a relay with zero residual balance, consistent with a layering hop.
MONITOR
7. Third-Party Risk
The relay’s downstream destination is a TDXb-prefixed address cluster receiving $716M in aggregate; these addresses are unattributed and may represent an unregulated OTC desk or exchange.
MONITOR
8. Address Poisoning
Two airdropped instruments identified: stUSD (136.96M tokens, USDT name-mimic contract) and an AML-named token. Both target operators who copy addresses from transaction history.
MONITOR
Assessment

The wallet has no DeFi, staking, cross-chain bridge, or protocol interaction of any kind. All 70 on-chain transactions are TRC-20 USDT transfers or associated zero-value contract events. The absence of protocol entanglement simplifies AML assessment: there is no DeFi obfuscation layer, no bridge-hop complexity, and no staking contract encumbrance to account for.

…qrqCvsZQMJh · TRON · 2026-06-01

S5 — NOTABLE EVENTS & ANOMALIES

Flagged Patterns & Significant Observations

PHASE 1 — INITIAL ACCUMULATION PHASE 2 — DORMANCY PHASE 3 — SECOND ACCUMULATION 2024-12 2026-05 2025 2026 Activation · $33.6M $60M outflow Resumed · $67.6M $20.2M deposit $15M outflow A-01 2025-03-15 A-02 2024-12-17 A-03 2025-03-15 HIGH — critical finding HIGH — monitor LOW — contextual
IDDateEventSeveritySignificance
A-012025-03-15222-Day Operational Dormancy. Following a $60M outflow on 2025-03-15, the wallet recorded no on-chain activity for 222 days, resuming 2025-10-23 with $67.6M in two-day inflows.NOTABLEExtended dormancy immediately after a large outflow may indicate a compliance review, key-holder unavailability, or a deliberate operational pause.
A-022024-12-17Address Verification Probes at Activation. Four separate $100 USDT transfers received on wallet activation date before the first substantive deposit ($21.56M on same date).LOWConsistent with address ownership verification by multiple parties before committing large capital; not adverse.
A-032025-03-15Zero-Value TRC-20 Events on Outflow Date. Two $0.00 TRC-20 transfer events recorded on the same date as the $60M outflow.LOWLikely contract trigger calls associated with the outflow transaction; not adverse.
Synthesis

TFvuXyB7AhCV7jZcC9uukZDqrqCvsZQMJh is an unattributed TRON USDT wallet holding $146.04M, accumulating $221.04M from four coordinated feeder wallets over 518 days. Source attribution is entirely unresolved for 99.6% of inflows. Activity pattern and timezone signature point to a Gulf-region operator (UTC+3/+4, Islamic business calendar). Two outflow events totalling $75M route through a relay wallet with $716M lifetime throughput connecting to an unidentified downstream cluster. AML risk is assessed LOW — no confirmed adverse indicator identified; four MONITOR items (source unverifiability, aggregation pattern, relay outflows, address poisoning) are investigation priorities.

…qrqCvsZQMJh · TRON · 2026-06-01

S6 — OWNERSHIP ATTRIBUTION MODEL

Hypothesis Assessment

Private Institutional Treasury (Gulf Region) 65%

Layering Intermediary in Multi-Hop Dispersal Chain 25%

OTC Broker Settlement Reserve 10%

Probabilities sum to 100%. Attribution confidence: MEDIUM.

What This Means For You

This report documents a $146M unattributed USDT treasury on the TRON blockchain. No sanctions exposure, fraud reports, or confirmed AML violations have been identified; the LOW rating reflects four unresolved MONITOR items rather than confirmed contamination; the inability to verify the source of 99.6% of inflows and the use of a relay intermediary for outflows. The wallet warrants continued monitoring and, where jurisdiction permits, counterparty verification requests to establish beneficial ownership.

…qrqCvsZQMJh · TRON · 2026-06-01

S7 — LINKS, DIGITAL FOOTPRINT & PUBLIC RECORD

Government Records · Press Coverage · Research & Analytics · Blockchain Intelligence

Blockchain Explorers
OKLink Explorer
2026-06-01
OKLink labels TAzsQ9Gx8eqFNFSKbeXrbi45CuVPHzA8wr as ‘Binance: Withdraw_18’ — a confirmed Binance TRON withdrawal address with 47M+ lifetime transactions and $848M current balance. Subject received $7,166.55 from this address on 2026-01-10.
Tronscan — Token Classification
2026-06-01
Thirteen token holdings flagged; 12 confirmed spam/airdrop tokens including a USDT-mimic (stUSD, 136.96M units) and an AML-named token, indicating active address poisoning targeting.
Government & Official Records
OFAC SDN List
2026-06-01
No entry found for TFvuXyB7AhCV7jZcC9uukZDqrqCvsZQMJh in the OFAC Specially Designated Nationals and Blocked Persons List. Screened 2026-06-01; wallet address not subject to any U.S. Treasury sanctions designation.
Media & Press
Open Web & Social Media Sweep
2026-06-01
General web search, news archive, and social media platforms (Twitter/X, Telegram, Reddit) returned no indexed references to TFvuXyB7AhCV7jZcC9uukZDqrqCvsZQMJh. No investigative journalism, law enforcement press releases, or community disclosures identified as of 2026-06-01.
Intelligence Platforms
Chainabuse / BitcoinAbuse
2026-06-01
No reports found for TFvuXyB7AhCV7jZcC9uukZDqrqCvsZQMJh. Wallet is not listed as a reported fraud, scam, ransomware, or theft address in Chainabuse or BitcoinAbuse community databases as of 2026-06-01.
CryptoScamDB
2026-06-01
No entry found for TFvuXyB7AhCV7jZcC9uukZDqrqCvsZQMJh in CryptoScamDB. Address is not flagged in the database of known scam and phishing addresses as of 2026-06-01.
…qrqCvsZQMJh · TRON · 2026-06-01

S8 — RECOMMENDED FURTHER INVESTIGATION

Priority Actions & Engagement Opportunities

P1Counterparty Attribution — Top 4 Feeder Wallets — Submit TKJa5yhD6SX42CbZjwuArnc1o3MJ5ZNeug, TG1behizYfNrrzAoNS1tSL86pEbgb53LtN, TPXfkQLTytwww2SrRY63vMrCmwy3t8theN, and TNS17kGeCNke3PRrj7tteuyiwbR4q8Ls1B to analytics platforms and cross-reference against OTC broker databases; these four wallets represent 99.6% of total inflows. · On-chain
P2Relay Downstream Tracing — Trace hop-1 relay (TWvr9cZLK9995Nxg7Qans8opngwSi21V6R) and its principal destinations TDXbhgxcFM7fnaTzz45HSzJMfCryE7kHme ($512.6M) and TDZ1caSxEinGpkFd9NjRdTsdws5qtawvF8 ($204M) to identify the terminus entity — likely an exchange or unregulated OTC desk. · On-chain
P3Beneficial Ownership Inquiry — If subject is under legal review, issue a voluntary disclosure or MLAT request to the operator of the primary feeder wallets to establish beneficial ownership of the subject address. · Legal
P4Monitoring Alert — Set automated alerts on subject wallet and the four feeder addresses for large-value USDT movements (threshold ≥$5M); the wallet remains active as of 2026-05-20. · On-chain
Investigator Assessment

Recommended actions are prioritised by investigative yield. Attribution of the four principal feeder wallets is the highest-value step as it would resolve the source of 99.6% of total inflows. Relay downstream tracing is the second priority and would identify the fund destination. Beneficial ownership inquiry requires legal process but would definitively resolve the operator identity.

…qrqCvsZQMJh · TRON · 2026-06-01

APPENDIX A — MASTER SOURCE LIST

REFSOURCE
S1On-chain dataset -- TRC-20 Transfers
https://tronscan.org/#/address/TFvuXyB7AhCV7jZcC9uukZDqrqCvs…
Full TRC-20 transfer history via Tronscan API. Retrieved 2026-06-01.
S2On-chain dataset -- Raw Transactions
https://tronscan.org/#/address/TFvuXyB7AhCV7jZcC9uukZDqrqCvs…
Full transaction log via Tronscan API. Retrieved 2026-06-01.
S3Arkham -- Address Profile
https://intel.arkm.com/explorer/address/TFvuXyB7AhCV7jZcC9uu…
Screenshot captured 2026-06-01. File: screenshot_arkham.png
S4Tronscan -- Address Profile
https://tronscan.org/#/address/TFvuXyB7AhCV7jZcC9uukZDqrqCvs…
Screenshot captured 2026-06-01. File: screenshot_tronscan.png
S5Oklink -- Address Profile
https://www.oklink.com/tron/address/TFvuXyB7AhCV7jZcC9uukZDq…
Screenshot captured 2026-06-01. File: screenshot_oklink.png
…qrqCvsZQMJh · TRON · 2026-06-01

APPENDIX B — GLOSSARY OF TERMS

TERMDEFINITION
USDT (Tether)A US dollar-pegged stablecoin issued by Tether Ltd; on the TRON blockchain it is a TRC-20 token and the most widely used settlement asset for large-value transfers.
TRC-20The TRON network standard for fungible tokens, equivalent to ERC-20 on Ethereum; USDT on TRON operates under this standard.
TRONA high-throughput, low-fee public blockchain network widely used for USDT transfers, particularly in Asia and the Middle East; native currency is TRX.
Feeder walletA wallet that aggregates funds from multiple sources and forwards them to a central address; used to collect and consolidate capital before onward transfer.
Relay walletA wallet that receives funds and immediately forwards them to one or more downstream addresses, retaining no residual balance; a classical layering instrument in multi-hop fund movement.
Address poisoningAn attack technique where a small amount of a look-alike or airdrop token is sent to a target wallet, hoping the victim copies the attacker’s address from transaction history when making future transfers.
Address probeA very small test transfer (typically $1–$100) sent to verify that a wallet address is live and correctly specified before committing a larger transaction.
EOA (Externally Owned Account)A standard blockchain account controlled by a private key, as opposed to a smart contract; TRON EOAs offer no multisig or programmable custody features.