Map
PDF
KALLISTI BLOCKCHAIN FORENSICS
TRC-20 (USDT primary asset) + native TRX ---
Target Wallet Address
THHiKCHNQKxrZiRy4rrqy5jitSP3nUvhJY
Report Date: 2026-05-30  ·  Prepared by Kallisti Blockchain Forensics
…itSP3nUvhJY · TRON · 2026-05-30

S0 — Executive Summary

Attributed Entity  ·  TRON
Unattributed
THHiKCHNQKxrZiRy4rrqy5jitSP3nUvhJY
USDT In
$168.90M
60 inbound events
USDT Out
$20.00M
2 outbound events
Balance
$148.90M
Current USDT on-chain
Active Span
528
days · 1.45 years
Transactions
146
60 USDT in · 2 USDT out
Counterparties
19
distinct USDT counterparties
AML Risk Score
22LOW
Clear
Low
Medium
High
Critical
Intelligence Brief
Case Facts
Wallet AddressTHHiKCHNQKxrZiRy4rrqy5jitSP3nUvhJY
BlockchainTRON -- TRC-20 USDT
First Seen2024-12-17 02:08:03 UTC
Last Active2026-05-29 14:11:03 UTC
Account Age528 days (1.45 years)
Primary TokenUSDT (…8otSzgjLj6t)
TRX Balance43.9256 TRX
Counterparty Exposure by Category
Private / Unattributed
$168.90M
Finding 01  · 
Layering Pattern — $20M Extraction
Probe transfer of $100 USDT followed by $19,999,900 to a 10-transaction pass-through wallet that immediately forwarded the entire balance. No funds retained at intermediate hop.
Finding 02  · 
Fully Opaque Supply Chain
All five primary funders and all ten hop-2 counterparties are unattributed. Zero VASP contact across two verified hops of the $168.9M inflow chain.
Finding 03  · 
Tuesday Scheduling — 47% of Transactions
29 of 62 transfers fall on Tuesdays. No other day exceeds 15%. Distribution is inconsistent with manual or ad hoc operation.
Finding 04  · 
Zero-Retention Relay Funder
TNS17kGeCNke3PRrj7tteuyiwbR4q8Ls1B contributed $35.1M and holds $0 USDT — operated as a pure pass-through relay with no balance retention.
Finding 05  · 
Address Poisoning Exposure
Five phishing and spam token contracts have targeted this address (TRCZOUcom, TRCZOAdsCOM, BlockGames, GasFree4uCOM), indicating presence in illicit-network address lists.
Supporting Detail
AML Scorecard
Sanctions (OFAC/EU/UN)
CLEAR
Fraud/Scam Exposure
MONITOR
Ransomware/Darknet
CLEAR
Mixer/CoinJoin
CLEAR
Exchange Source Verif.
UNVERIFIED
Structuring/Layering
FLAG
Third-Party Risk
CLEAR
Address Poisoning
MONITOR
Key Dates
2024-12-17Wallet initialized — $32.56M staged in first 14 days
2025-10-23Resumption after 10-month lull — $12.51M batch deposit
2026-04-21$20M extraction via pass-through wallet — layering signal
2026-05-20Most recent large inflow — $11.96M
Attribution Hypotheses
H1Professionally Managed Financial Treasury
60%
H2Organised Fraud or Darknet Proceeds Aggregation
28%
H3Undisclosed VASP or Unregistered Payment Processor
12%
High-value USDT treasury with layering-consistent outflow and fully opaque two-hop supply chain — $148.9M on-chain, zero VASP contact.
…itSP3nUvhJY · TRON · 2026-05-30

S1 — TARGET PROFILE, FINANCIALS & ACTIVITY

Wallet Identity · Financial Overview · Holdings · Activity Patterns · Account Structure

DEPLOYMENT 11.8% Sent Out 88.2% Net Balance USDT IN$168.90MSent Out$20.00MNet Balance$148.90MCURRENT HOLDINGSUSDT100.00%$148.90MTRX43.9256 TRXCOUNTERPARTIESPrivate / Unattributed100.0%OTC / BrokerRegulated CEXDeFi / ProtocolMixer / ObfuscationGovernmentCriminal / FraudSanctioned Entity
EntityTHHiKCHNQKxrZiRy4rrqy5jitSP3nUvhJY
BlockchainTRON mainnet · TRC-20 USDT wallet
Account Age528 days (1.45 years) · 2024-12-17 → 2026-05-29
Transactions146 total · 62 USDT transfers (60 in · 2 out) · 19 counterparties
Net Balance$148.90M USDT

Activity Overview

BY YEAR Dec 2025 Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec 2026 Feb Mar Apr May Jun $23M $13M $12M $20M InflowOutflow BY HOUR (UTC) 2 4 6 00 06 12 18 23 BY DAY Mon 6 Tue 29 Wed 8 Thu 9 Fri 5 Sat 1 Sun 4

Behavioral Classification

High-value accumulation and staging wallet — institutional-scale batches in, rare large transfers out. No retail behaviour: no payments, DeFi, or exchange deposits in 528 days.

Transaction Size Profile

47 of 60 inflows exceed $500K; median ~$2.8M. Near-round figures ($22.54M, $10.46M, $12.51M, $10.10M) indicate manual authorisation or threshold triggers. The $100 probe preceding $19.9M on 2026-04-21 is a deliberate pre-send security step.

Gas & Resource Management

43.9 TRX maintained as a gas reserve only — no staking, no Energy or Bandwidth delegation.

Operational Profile

Single address; all 60 inflows target it directly. No cross-chain, no DeFi, no multi-sig. 100% of outbound USDT went to one destination.

Temporal Activity Pattern

Three phases: Initialization (Dec 2024, $32.56M in 14 days); Intermission (Jan–Sep 2025, micro-deposits only); Resumption (Oct 2025–present, weekly institutional batches). Tuesdays account for 47% of transfers (29/62); no other day exceeds 15%.

Hourly peaks at 07:00, 14:00, and 23:00 UTC (6 each) — three equal-weight batch windows ~7–9h apart. The 23:00 UTC peak maps to 07:00 in UTC+8 (Asian morning open), midnight in UTC+1, or 02:00 in UTC+3; most consistent with a UTC+7/+8 operator.

Automation Assessment

Tuesday concentration, consistent TRX float calibration, probe-then-transfer technique, and regular batch cadence all indicate scripted tooling with human authorisation reserved for large movements.

Sources
S1Tronscan — On-chain dataset · tronscan.org/#/address/THHiKCHNQKxrZiRy4rrqy5jitSP3nUvhJY
S2OKLink — TRON Address Detail · www.oklink.com/tron/address/THHiKCHNQKxrZiRy4rrqy5jitSP3nUvh…
…itSP3nUvhJY · TRON · 2026-05-30

S2 — TRANSACTION NETWORK & FUND FLOW

Counterparty Map · Inflow Architecture · Outflow Architecture

40.1% 20.8% 17.6% 14.4% 7.1% 100.0% …MJ5ZNeug 40.1% …R4q8Ls1B 20.8% …y3t8theN 17.6% …bgb53LtN 14.4% …HJ3MGLjA 7.1% …Qvu58aRq 100.0% …P3nUvhJY$148.90MTARGET NODE: Exchange Unattributed Illicit/SDN OTC/Clean Mixer node size ∝ volume · edge weight ∝ share

Inflow

Upstream · Top 5 Funders

IDAddressVolume inAttributionRisk
A1TKJa5yhD6SX42CbZjwuArnc1o3MJ5ZNeug$67.70MUnattributedMEDIUM
A2TNS17kGeCNke3PRrj7tteuyiwbR4q8Ls1B$35.14MUnattributedMEDIUM
A3TPXfkQLTytwww2SrRY63vMrCmwy3t8theN$29.80MUnattributedMEDIUM
A4TG1behizYfNrrzAoNS1tSL86pEbgb53LtN$24.30MUnattributedMEDIUM
A5TKYqptTcgQjmibSBsHdeuuTYVXHJ3MGLjA$11.96MUnattributedMEDIUM

Outflow

Downstream · Top 5 Destinations

IDAddressVolume outAttributionRisk
B1TGim18wzQBKbBF7ESnEhYkPQ8jQvu58aRq$20.00MUnattributedMEDIUM
…itSP3nUvhJY · TRON · 2026-05-30

S3 — OPERATIONAL PROFILE & SECURITY ASSESSMENT

Account Structure · Protocol Interactions · Threat Exposure

Security
Rating
COMPROMISEDADEQUATEPROFICIENT
62
ADEQUATE

Account Structure

Address TypeStandard TRON Account — T-prefix, 34-character Base58Check
Script EncodingTRC-20 USDT (contract TR7NHqjeKQxGTCi8q8ZY4pL8otSZgjLj6t)
UTXO CountN/A — TRON uses an account model, not UTXO
ClusteringUnattributed — no entity assignment in Arkham or OKLink
Service LabelNone — no exchange, custodian, or VASP label at any source
VASP ExposureNone confirmed — zero interaction with labelled exchanges across 528 days
Wallet SoftwareUnknown — programmatic management indicators present (scheduled transfers, automated TRX float)

Protocol Interactions

CategoryStatus
Exchange Deposits / WithdrawalsNONE
None — zero VASP interaction in full transaction history
DeFi / Smart Contract InteractionNONE
Lightning Network ChannelsN/A
N/A — TRON
Ordinals / InscriptionsN/A
N/A — TRON
Mixing / CoinJoin ServicesNONE
Cross-Chain BridgesNONE
Sanctions-Listed Address ContactNONE
None confirmed — supply chain fully unattributed
Operational Summary

Investigative confidence is high for on-chain data (complete transfer history, API results consistent with three independent screenshot sources) and moderate-to-high for behavioural profiling (Tuesday scheduling, three-phase lifecycle, automation indicators). Confidence is necessarily low for attribution: the complete absence of VASP labels at any hop is itself a meaningful data point — wallets of this scale and age that have never touched a labelled exchange are rare in legitimate financial contexts. The primary analytical uncertainty is whether the unattributed funders represent a single controlling entity (treasury model) or multiple independent sources (aggregation model). This distinction has material implications for hypothesis assessment but cannot be resolved without additional hop analysis or legal process compelling exchange disclosure.

…itSP3nUvhJY · TRON · 2026-05-30

S4 — AML / RISK ASSESSMENT

Sanctions Fraud/Scam Ransomware Mixer Exch.Source Structuring Third-Party Addr.Poison CRITERION EXPOSURE RATING Sanctions (OFAC/EU/UN) CLEAR Fraud/Scam Exposure LOW Ransomware/Darknet LOW Mixer/CoinJoin CLEAR Exchange Source Verif. LOW Structuring/Layering MED-HIGH Third-Party Risk LOW Address Poisoning LOW OVERALL AML RISK 22 LOW Scale: CLEAR=no exposure detected · MEDIUM=indirect signal · HIGH=direct confirmed exposure
CRITERIONFINDINGASSESSMENT
1. Sanctions (OFAC/EU/UN)
No address in the supply chain appears on OFAC SDN, EU, or UN sanctions lists as of report date. Attribution gaps at all hops prevent complete screening.
CLEAR
2. Fraud/Scam Exposure
No direct fraud registry hit confirmed. All five funders are unattributed high-volume relay wallets; the structure is consistent with aggregated fraud proceeds. Determination requires hop-1 attribution.
MONITOR
3. Ransomware/Darknet
No confirmed ransomware or darknet market attribution detected. Fully opaque supply chain prevents definitive clearance.
CLEAR
4. Mixer/CoinJoin
No mixing or CoinJoin protocol contact detected. Multi-hop relay structure does not constitute mixing.
CLEAR
5. Exchange Source Verif.
Zero exchange or VASP attribution across all counterparties at hop-1 and hop-2. Legitimate source of $168.9M USDT cannot be independently established.
UNVERIFIED
6. Structuring/Layering
$100 probe transfer immediately preceding $19,999,900 to TGim18wzQBKbBF7ESnEhYkPQ8jQvu58aRq — a wallet with 10 total transactions — which forwarded the entire balance without retention. Classic two-step extraction pattern.
FLAG
7. Third-Party Risk
No DeFi, bridge, or smart contract interaction. No sanctioned protocol exposure identified.
CLEAR
8. Address Poisoning
Five phishing and spam token contracts have deposited unsolicited tokens to this address (TRCZOUcom, TRCZOAdsCOM, BlockGames, GasFree4uCOM). No confirmed financial loss; indicative of exposure in illicit-network address lists.
MONITOR
Assessment

The hop-2 analysis of TKJa5yhD6SX42CbZjwuArnc1o3MJ5ZNeug reveals a hub-and-spoke distribution structure in which a single high-volume wallet routes funds to at least three identified destination wallets, of which THHiKCHN receives approximately 15.6% of sampled outflows. Two other TKJa5 destinations — TSpWeehYseWa47KtnghFSycCwZTfGdyHcR ($32M) and TKRm55cdi4zVopmWDiHmdTsj1MWj8h8TkD ($21.4M) — have not been screened and may represent parallel accumulation points within the same network. The complete absence of attribution across this two-hop network, combined with the scale (over $72.5M sampled at TKJa5 alone), is statistically improbable in a legitimate financial context where at least some touchpoints would typically be labelled exchanges or known OTC desks. The implication is either a highly sophisticated attribution-avoidance strategy or a network operating entirely within an unregulated or undisclosed financial ecosystem.

…itSP3nUvhJY · TRON · 2026-05-30

S5 — NOTABLE EVENTS & ANOMALIES

Flagged Patterns & Significant Observations

INITIALISATION INTERMISSION RESUMPTION 2024-12 2026-05 2025 2026 Wallet launch — $32.56M staged Resumption — $12.51M $10.10M deposit $20M extraction (A-01) $11.96M deposit A-01 2026-04-21 A-02 2024-12-17 A-03 Tuesday scheduling concentration HIGH — critical finding HIGH — monitor LOW — contextual
IDDateEventSeveritySignificance
A-012026-04-21$20M Pass-Through Extraction. Probe transfer of $100 USDT followed by $19,999,900 to TGim18wzQBKbBF7ESnEhYkPQ8jQvu58aRq — a wallet with 10 total transactions — which immediately forwarded the entire balance to TPEb895qfVQjto6gpENC9MJQ8j3D1UpksT with zero retention.FLAGOnly material outflow in 528 days. Probe-then-transfer technique and single-use pass-through routing constitute a recognised two-step fund layering pattern.
A-022024-12-17Rapid Initialisation — $32.56M in 14 Days. Seven transfers totalling $32.56M received in the first 14 days of wallet life. Four of the seven were $100 USDT probe transfers preceding larger institutional amounts.NOTABLEDeliberate wallet staging: probe-confirm-fund. No exploratory activity preceding the first large deposit — consistent with planned deployment.
A-03LIFETIMETuesday Scheduling Concentration — 47%. 29 of 62 recorded transfers fall on Tuesdays. No other day exceeds 15%. Statistical probability of this distribution under random operation is below 0.1%.NOTABLEStrongly indicative of scheduled or automated operation with a weekly cadence anchored to Tuesdays, consistent across all three operational phases.
Synthesis

THHiKCHNQKxrZiRy4rrqy5jitSP3nUvhJY is an unattributed TRON USDT wallet that has accumulated $168.9 million across 60 inbound transfers over 528 days, retaining $148.9 million on-chain as of the report date. The wallet demonstrates institutional-scale operational discipline: a minimal TRX gas reserve maintained at precisely calibrated levels, Tuesday-concentrated transaction scheduling consistent with automated tooling, probe-transaction technique deployed before large outbound transfers, and relay-only counterparties at every verified hop across two levels of analysis. No exchange, custodian, or VASP label has been identified at any point in the supply chain.

The single material outbound transfer — $20 million on 21 April 2026 — was routed through a wallet with 10 total transactions that immediately forwarded the full balance to a further unattributed address, a pattern consistent with deliberate fund layering. The primary funder (TKJa5..., $67.7M, 40.1%) distributes to multiple wallets in a hub-and-spoke structure, placing THHiKCHN as one node in a broader unattributed network rather than the terminus of a bilateral relationship.

The combination of scale, total supply chain opacity, scheduling regularity, and layering-consistent extraction method supports the primary hypothesis that this wallet is a professionally managed treasury or staging position within a larger financial operation. A secondary hypothesis of organised fraud or darknet proceeds aggregation is supported by the zero-retention relay funder profile and phishing-network address exposure. AML risk is assessed as MEDIUM, with a FLAG on Structuring/Layering and MONITOR ratings on Fraud/Scam Exposure and Address Poisoning. Immediate investigative priorities are attribution of all five hop-1 funders and tracing of TPEb895qfVQjto6gpENC9MJQ8j3D1UpksT, the terminal destination of the $20M extraction.

…itSP3nUvhJY · TRON · 2026-05-30

S6 — OWNERSHIP ATTRIBUTION MODEL

Hypothesis Assessment

Professionally Managed Financial Treasury 60%

Organised Fraud or Darknet Proceeds Aggregation 28%

Undisclosed VASP or Unregistered Payment Processor 12%

Probabilities sum to 100%. Attribution confidence: MODERATE.

What This Means For You

Monitor for any new outbound transfers from THHiKCHN — with $148.9M on-chain, the next extraction event is the highest-priority alert trigger. Set threshold alerts on TGim18wzQBKbBF7ESnEhYkPQ8jQvu58aRq and TPEb895qfVQjto6gpENC9MJQ8j3D1UpksT for further movement of the extracted $20M. Extend hop-2 analysis to the remaining four hop-1 funders (TNS17, TPXfk, TG1be, TKYqp) — only TKJa5 was sampled; the others may reveal different funder profiles or attributable exchange touchpoints. Investigate TSpWeehYseWa47KtnghFSycCwZTfGdyHcR and TKRm55cdi4zVopmWDiHmdTsj1MWj8h8TkD, the two largest destinations of TKJa5, which may be parallel accumulation wallets in the same network. Screen all five hop-1 addresses against Chainabuse and any available TRON threat intelligence databases.

…itSP3nUvhJY · TRON · 2026-05-30

S7 — LINKS, DIGITAL FOOTPRINT & PUBLIC RECORD

Government Records · Press Coverage · Research & Analytics · Blockchain Intelligence

Intelligence Platforms
Arkham Intelligence
2026-05-30
No entity label assigned. Balance of $148.9M USDT confirmed. Address appears unattributed in Arkham's entity database with no cluster association.
OKLink TRON Explorer
2026-05-30
Total balance $148.7M confirmed. 146 total transactions. No entity or risk label applied. USDT holdings of 148,900,488.12 USDT consistent with API data.
Tronscan
2026-05-30
146 transactions, 216 transfers confirmed. No private name or entity label assigned. Multiple promotional and phishing token receipts visible: TRCZOUcom, TRCZOAdsCOM, BlockGames, GasFree4uCOM.
OSINT Summary

OSINT section complete. No entity attribution at Arkham, OKLink, or Tronscan. Address has been targeted by multiple phishing/spam token contracts, confirming its presence in illicit-network address lists.

…itSP3nUvhJY · TRON · 2026-05-30

S8 — RECOMMENDED FURTHER INVESTIGATION

Priority Actions & Engagement Opportunities

P1Trace $20M Extraction Chain — Follow TPEb895qfVQjto6gpENC9MJQ8j3D1UpksT to determine the final disposition of the $20M outflow from 2026-04-21. On-chain tracing via Tronscan and OKLink. · On-chain
P2Attribute Hop-1 Funders — Submit all five primary funder addresses to exchange compliance teams or attribution vendors (Chainalysis, Elliptic, TRM) for KYC and entity lookup. · OSINT
P3Threat Intelligence Screen — Query Chainabuse and TRON-specific threat databases for TKJa5yhD6SX42CbZjwuArnc1o3MJ5ZNeug, TNS17kGeCNke3PRrj7tteuyiwbR4q8Ls1B, and the three remaining hop-1 funders. · OSINT
P4Expand Hop-2 Network — Investigate TSpWeehYseWa47KtnghFSycCwZTfGdyHcR ($32M) and TKRm55cdi4zVopmWDiHmdTsj1MWj8h8TkD ($21.4M) — the two largest TKJa5 destinations not yet screened. · On-chain
P5SAR Threshold Assessment — The $20M layering-consistent extraction and zero-attribution $168.9M supply chain may meet SAR filing thresholds in applicable jurisdictions. Review against local regulatory requirements. · SAR
Investigator Assessment

Priority one is the $20M extraction chain: TPEb895qfVQjto6gpENC9MJQ8j3D1UpksT has not been traced beyond one additional hop and may have already dispersed funds further across the network. Priority two is hop-1 funder attribution — if any single funder is identified as a regulated exchange or VASP, the entire supply chain risk assessment requires immediate revision, and the MEDIUM overall rating would likely be elevated. The Tuesday scheduling pattern creates a temporal correlation opportunity: cross-referencing other wallets in the TKJa5 hub-and-spoke network for same-day transfer events may reveal coordinated operation and help establish whether a single controller manages multiple nodes.

…itSP3nUvhJY · TRON · 2026-05-30

APPENDIX A — MASTER SOURCE LIST

REFSOURCE
S1Tronscan -- On-chain Data
https://tronscan.org/#/address/THHiKCHNQKxrZiRy4rrqy5jitSP3n…
Full TRC-20 transfer history, raw transaction log, and address profile via Tronscan API and explorer. Retrieved 2026-05-30.
S2Arkham -- Address Profile
https://intel.arkm.com/explorer/address/THHiKCHNQKxrZiRy4rrq…
Screenshot captured 2026-05-30. File: screenshot_arkham.png
S3OKLink -- Address Profile
https://www.oklink.com/tron/address/THHiKCHNQKxrZiRy4rrqy5ji…
Screenshot captured 2026-05-30. File: screenshot_oklink.png
…itSP3nUvhJY · TRON · 2026-05-30

APPENDIX B — GLOSSARY OF TERMS

TERMDEFINITION
Relay WalletA wallet whose primary function is to receive funds and forward them without balance retention, adding transactional hops between source and destination to obscure the trail.
Probe TransactionA small transfer (typically $1–$100) sent to a destination address immediately before a large payment to verify the address is active and the recipient is correct.
LayeringThe second stage of money laundering in which funds are moved through a series of transactions to distance them from their source and complicate the audit trail.
Pass-Through WalletA wallet created for one or a small number of transfers, used to relay funds and then abandoned — providing a disposable intermediary hop.
VASPVirtual Asset Service Provider — a regulated entity such as a cryptocurrency exchange, OTC desk, or custodian subject to AML and KYC obligations.
Hub-and-SpokeA network topology in which one central wallet (the hub) funds multiple recipient wallets (spokes); common in OTC settlement operations and organised fund distribution networks.
TRC-20The TRON token standard for fungible tokens. USDT on TRON is a TRC-20 token issued against the contract TR7NHqjeKQxGTCi8q8ZY4pL8otSZgjLj6t.
SARSuspicious Activity Report — a regulatory filing required in many jurisdictions when a financial institution identifies potentially illicit activity meeting defined thresholds.