Map
PDF
KALLISTI BLOCKCHAIN FORENSICS
TRC-20 (USDT primary asset) + native TRX ---
Target Wallet Address
TNiq9AXBp9EjUqhDhrwrfvAA8U3GUQZH81
Report Date: 2026-05-30  ·  Prepared by Kallisti Blockchain Forensics
…A8U3GUQZH81 · TRON · 2026-05-30

S0 — Executive Summary

Attributed Entity  ·  TRON
TNiq9AXBp9EjUqhDhrwrfvAA8U3GUQZH81
OFAC SDNBLOCKED
USDT In
$228.65M
166 inbound events
USDT Out
$15.73M
61 outbound events
Balance
$212.92M
Current USDT on-chain
Active Span
1,847
days · 5.06 years
Transactions
446
166 USDT in · 61 USDT out
Counterparties
99
distinct USDT counterparties
AML Risk Score
95CRITICAL
Clear
Low
Medium
High
Critical
Intelligence Brief
Case Facts
Wallet AddressTNiq9AXBp9EjUqhDhrwrfvAA8U3GUQZH81
BlockchainTRON -- TRC-20 USDT
First Seen2021-03-04 05:41:00 UTC
Last Active2026-03-25 20:18:45 UTC
Account Age1847 days (5.06 years)
Primary TokenUSDT (…8otSzgjLj6t)
TRX Balance415.9351 TRX
Counterparty Exposure by Category
Sanctioned Entity
$166.5M
Private / Unattributed
$62.2M
Finding 01  · 
OFAC SDN — Central Bank of Iran
Arkham labels address 'Central Bank of Iran'; OKLink tags #Blocked and #Sanction; address appears on the OFAC Specially Designated Nationals list. Any interaction constitutes a U.S. federal sanctions violation.
Finding 02  · 
$212.92M USDT unfrozen despite OFAC SDN status
Tether retains contractual authority to freeze TRON USDT balances. This $212.92M has not been frozen — a significant compliance gap in the USDT sanctions enforcement chain.
Finding 03  · 
Connected CBI/IRGC network — TTiDLWE6 link confirmed
Relay node TCXfhTDMuS6... routes funds both to this wallet and to TTiDLWE6fZK8... (a second CBI/IRGC-linked sanctioned wallet in the Kallisti catalogue). Same operator across both addresses confirmed.
Finding 04  · 
Circular relay flow via TCXfhTDMuS
$166.5M received from TCXfhTDMuS; $11.2M returned to same address. Closed-loop cycling consistent with layering or artificial volume generation within controlled infrastructure.
Finding 05  · 
Effectively dormant since 2024
After $212.7M accumulated 2021–2023, activity dropped to sub-$200 per year. Wallet appears to have been parked as a reserve rather than recycled. 54 spam token contracts received but no USDT movement.
Supporting Detail
AML Scorecard
Sanctions (OFAC/EU/UN)
CRITICAL
Fraud/Scam Exposure
CLEAR
Ransomware/Darknet
CLEAR
Mixer/CoinJoin
CLEAR
Exchange Source Verif.
UNVERIFIED
Structuring/Layering
FLAG
Third-Party Risk
CRITICAL
Address Poisoning
CLEAR
Key Dates
2021-03-04Wallet activated — first $30K inflow
2022-01-01Accumulation phase begins — $212.7M received 2022–2023
2024-01-01Operational dormancy begins — sub-$200 activity only
2026-03-25Last recorded transaction (micro-probe)
Attribution Hypotheses
H1Central Bank of Iran — USDT reserve / accumulation wallet
90%
H2IRGC-affiliated entity operating under CBI designation
7%
H3Third-party Iranian actor sharing CBI infrastructure
3%
Arkham entity cluster label 'Central Bank of Iran' plus dual independent OFAC SDN and OKLink #Sanction tags leaves negligible attribution uncertainty. On-chain connection to TTiDLWE6 (second confirmed CBI wallet) reinforces single-operator conclusion.
Investigator Summary
Confirmed Central Bank of Iran (Bank Markazi) USDT reserve wallet on TRON, OFAC SDN-designated April 24, 2026 under Operation Economic Fury. Tether executed a contractual freeze on April 23–24, 2026 rendering the $212.92M balance non-transferable — part of a $344M coordinated action covering this wallet and relay-connected TTiDLWE6. Accumulation of $228.65M occurred 2021–2023 via relay node TCXfhTDMuS; funds sat dormant ~16 months before the freeze. IRGC-Qods Force and Hezbollah linkages documented by OFAC, TRM Labs, and Chainalysis. Dual UTC operating windows and weekend-dominant scheduling confirm automated treasury software on Iranian Standard Time.
Recommended ActionsREJECT all transactions — OFAC SDN designation active, no licence exception available.  ·  File SAR for any prior interaction with this address before the April 2026 freeze.  ·  Escalate to compliance: secondary sanctions risk applies to non-U.S. persons dealing with SDN-listed entities.  ·  Monitor TTiDLWE6fZK8okMJv6ijg42yrH6W2pjSr9 and relay node TCXfhTDMuS6pbfCEoACPcBf2EnnhMAAEWh — same April 2026 OFAC action.
…A8U3GUQZH81 · TRON · 2026-05-30

S1 — TARGET PROFILE, FINANCIALS & ACTIVITY

Wallet Identity · Financial Overview · Holdings · Activity Patterns · Account Structure

DEPLOYMENT 6.9% Sent Out 93.1% Net Balance USDT IN$228.65MSent Out$15.73MNet Balance$212.92MCURRENT HOLDINGSUSDT100.00%$212.92MTRX415.9351 TRXCOUNTERPARTIESPrivate / Unattributed27.2%OTC / BrokerRegulated CEXDeFi / ProtocolMixer / ObfuscationGovernmentCriminal / FraudSanctioned Entity72.8%
EntityBlocked
BlockchainTRON mainnet · TRC-20 USDT wallet
Account Age1,847 days (5.06 years) ‖ Active: 2021-03-04 05:41:00 UTC → 2026-03-25 20:18:45 UTC
TRX Balance415.9351 TRX
Transactions446 total · 227 USDT transfers (166 in · 61 out) · 99 counterparties
Total USDT In$228.65M
Total USDT Out$15.73M
Net Balance$212.92M

Activity Overview

BY YEAR 2022 2023 2024 2025 2026 $111M $20M $11M $1M InflowOutflow BY HOUR (UTC) 2 6 10 15 20 25 00 06 12 18 23 BY DAY Mon 22 Tue 29 Wed 31 Thu 30 Fri 27 Sat 42 Sun 46

Behavioral Classification

Net accumulator with extreme retention: $228.65M received across 166 inbound events; only $15.73M disbursed in 61 outflows over 1,847 days — a 93.1% retention rate. The single dominant counterparty (TCXfhTDMuS, 72.8% of inflows) and near-total absence of VASP contact are consistent with a state-level sanctions evasion reserve designed to accumulate USDT outside the regulated financial system.

Transaction Size Profile

Inflows span micro-amounts to very large tranches; the dominant funder contributed $166.5M across multiple batches including at least one transfer exceeding $100M. Outflows are smaller and more frequent (61 events averaging ~$258K each), suggesting operational disbursements — salary payments, procurement, or subsidiary funding — rather than treasury cycling. No round-sum structuring pattern; irregular batch sizes indicate discretionary rather than scheduled outflows.

Operational Profile

Arkham labels this address "Central Bank of Iran"; OKLink carries independent #Blocked and #Sanction tags; OFAC SDN designation confirmed. $212.92M USDT remains unfrozen — Tether has not exercised its freeze capability despite clear SDN status, leaving the full balance liquid and transferable. TRX balance of 415.9 TRX provides a minimal gas reserve (energy staked: 0), sufficient for the current low-frequency operational pace.

Temporal Activity Pattern

DOW peaks Saturday (18.5%) and Sunday (20.3%); 38.8% of 227 transactions fell on weekends — consistent with fully automated treasury software. UTC 05–10 accounts for 44.5% of all activity, mapping to 08:30–13:30 IRST (Iranian morning business window); secondary peak at UTC 19 (12.3%) indicates an overnight batch process. Operator timezone: Iran / Tehran (UTC+3:30).

Automation Assessment

Two distinct daily operating windows (UTC 05–10 and UTC 19) combined with weekend-dominant scheduling confirm automated execution rather than manual operation. The absence of any DeFi, bridge, or protocol interaction across the full 5-year history indicates a purpose-built, isolated treasury wallet — no exploratory or retail behaviour. Sub-$200 activity since January 2024 suggests the accumulation programme concluded and the wallet has been placed in passive reserve status.

Sources
S1Tronscan — On-chain dataset · tronscan.org/#/address/TNiq9AXBp9EjUqhDhrwrfvAA8U3GUQZH81
S2OKLink — TRON Address Detail · www.oklink.com/tron/address/TNiq9AXBp9EjUqhDhrwrfvAA8U3GUQZH…
…A8U3GUQZH81 · TRON · 2026-05-30

S2 — TRANSACTION NETWORK & FUND FLOW

Counterparty Map · Inflow Architecture · Outflow Architecture

IN 72.8% OUT 71.0% 13.1% 7.2% 3.8% 9.5% 5.9% 4.0% 3.0% …nhMAAEWh 72.8% …So86vVnk 13.1% …JozHq81t 7.2% …6W2pjSr9 3.8% …dbPDtunS 2.2% …1XXcny3o 9.5% …nECBaVjo 5.9% …74s3ZbRM 4.0% …mDwx8STJ 3.0% …3GUQZH81$212.92MTARGET NODE: Exchange Unattributed Illicit/SDN OTC/Clean Mixer node size ∝ volume · edge weight ∝ share

Inflow

Upstream · Top 5 Funders

IDAddressVolume inAttributionRisk
A1TCXfhTDMuS6pbfCEoACPcBf2EnnhMAAEWh$166.57MUnattributedMEDIUM
A2TD2BiYkihphjrK35YQy1QGxGotSo86vVnk$29.99MUnattributedMEDIUM
A3TZ3xL5jeBXyo8jPDvh2veBtJZCJozHq81t$16.50MUnattributedMEDIUM
A4TTiDLWE6fZK8okMJv6ijg42yrH6W2pjSr9$8.60MUnattributedMEDIUM
A5TJ45EBCYKxRuxXhWUnWvpTYKfudbPDtunS$5.09MUnattributedMEDIUM

Outflow

Downstream · Top 5 Destinations

IDAddressVolume outAttributionRisk
B1TCXfhTDMuS6pbfCEoACPcBf2EnnhMAAEWh$11.17MUnattributedMEDIUM
B2TNBVWn7BBvQ2Lsm7K2fXCNF5qU1XXcny3o$1.49MUnattributedMEDIUM
B3TScxFMKmra6sfK2KDkZGHkyK6NnECBaVjo$934,019.00UnattributedMEDIUM
B4TRX8NbW3gGRyYmDsvkNWjaGgnA74s3ZbRM$630,294.00UnattributedLOW
B5TC8pcoJvTNErvZ8BnzPo2otGNdmDwx8STJ$468,169.00UnattributedLOW
…A8U3GUQZH81 · TRON · 2026-05-30

S3 — OPERATIONAL PROFILE & SECURITY ASSESSMENT

Account Structure · Protocol Interactions · Threat Exposure

Security
Rating
COMPROMISEDADEQUATEPROFICIENT
6
CRITICAL

Account Structure

Address TypeTRON Account — TRC-20 token holder (account model, not UTXO)
Script EncodingN/A — TRON account model; TRC-20 USDT contract TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t
UTXO CountN/A — TRON uses account-based model; no UTXO set
ClusteringArkham: Central Bank of Iran entity cluster; corroborated by OFAC SDN designation and OKLink #Blocked/#Sanction tags
Service LabelOFAC SDN — Central Bank of Iran; no exchange or VASP label assigned
VASP ExposureNone confirmed — zero regulated exchange, OTC desk, or custodian contact across full 5-year transaction history (166 IN / 61 OUT)
Wallet SoftwareUnknown — likely purpose-built automated treasury software; dual operating windows (UTC 05-10 and UTC 19) with weekend-dominant scheduling indicate scripted execution

Protocol Interactions

CategoryStatus
Exchange Deposits / WithdrawalsNONE
DeFi / Smart Contract InteractionNONE
Lightning Network ChannelsNONE
Ordinals / InscriptionsNONE
Mixing / CoinJoin ServicesNONE
Cross-Chain BridgesNONE
Sanctions-Listed Address ContactNONE
Operational Summary

99 distinct USDT counterparties — all unattributed. Primary funder and destination: TCXfhTDMuS6... (relay node, also funds TTiDLWE6). Ultimate source: TD2BiYkihphjrK35YQy1QGxGotSo86vVnk (72M into relay). No exchange or VASP contact across 5-year history.

…A8U3GUQZH81 · TRON · 2026-05-30

S4 — AML / RISK ASSESSMENT

Sanctions Fraud/Scam Ransomware Mixer Exch.Source Structuring Third-Party Addr.Poison CRITERION EXPOSURE RATING Sanctions (OFAC/EU/UN) CRITICAL Fraud/Scam Exposure CLEAR Ransomware/Darknet CLEAR Mixer/CoinJoin CLEAR Exchange Source Verif. MEDIUM Structuring/Layering LOW Third-Party Risk HIGH Address Poisoning CLEAR OVERALL AML RISK 95 CRITICAL Scale: CLEAR=no exposure detected · MEDIUM=indirect signal · HIGH=direct confirmed exposure
CRITERIONFINDINGASSESSMENT
1. Sanctions (OFAC/EU/UN)
Address is on the OFAC Specially Designated Nationals list as Central Bank of Iran. OKLink carries #Blocked and #Sanction. Any transaction with this address by a U.S. person or entity constitutes a federal sanctions violation.
CRITICAL
2. Fraud/Scam Exposure
No fraud or scam indicators identified. Sanctions status is a state-level designation, not a fraud typology.
CLEAR
3. Ransomware/Darknet
No ransomware or darknet marketplace exposure confirmed. State actor profile differs from criminal ransomware operators.
CLEAR
4. Mixer/CoinJoin
No mixing service interaction. All flows are direct TRC-20 transfers.
CLEAR
5. Exchange Source Verif.
99 counterparties are fully unattributed — no VASP, exchange, or regulated entity contact visible across the entire 5-year history. Origin of $228.65M remains unverifiable through public chain data alone.
UNVERIFIED
6. Structuring/Layering
TCXfhTDMuS6... acts as a relay node: received $166.5M from this wallet and returned $11.2M — a closed-loop circular flow. Same relay routes funds to a second CBI wallet (TTiDLWE6), consistent with layering across state-controlled infrastructure.
FLAG
7. Third-Party Risk
TCXfhTDMuS6... also routes to TTiDLWE6fZK8..., a second confirmed CBI/IRGC-linked sanctioned address. Direct on-chain connection to multiple OFAC SDN entities. The entire counterparty network is sanctioned infrastructure.
CRITICAL
8. Address Poisoning
218 non-USDT token events across 54 contracts are consistent with spam airdrops targeting high-balance addresses — no address-similarity spoofing detected.
CLEAR
Assessment

Accumulation: 2021-03-04 to 2023-12-31 (12.7M received). Dormancy: 2024-01 to present (sub-00 activity). Last transaction: 2026-03-25 (micro-probe, 9.79).

…A8U3GUQZH81 · TRON · 2026-05-30

S5 — NOTABLE EVENTS & ANOMALIES

Flagged Patterns & Significant Observations

ACTIVATION ACCUMULATION DORMANCY 2021-03 2026-04 2022 2023 2024 2025 2026 Activation Accumulation Last relay inflow Dormancy Tether freeze A-02 2022-01-01 A-03 2024-01-01 A-01 OFAC SDN — full lifetime block HIGH — critical finding HIGH — monitor LOW — contextual
IDDateEventSeveritySignificance
A-01LIFETIMEOFAC SDN Designation. Address designated on OFAC Specially Designated Nationals list under Iran-related sanctions programme.SANCTIONSAny interaction with this address constitutes a strict-liability OFAC violation.
A-022022–202312.7M Accumulation via TCXfhTDMuS Relay. Funds routed through intermediary relay node TCXfhTDMuS in multiple large tranches — largest single transfer exceeds 00M.STRUCTURINGRelay-hop pattern consistent with sanctions evasion layering; funds attributed to Central Bank of Iran entity cluster.
A-032024-01-01Operational Dormancy — Balance Frozen. No material outflows since late 2023; 12.92M USDT balance remains static, consistent with asset freeze or deliberate hold pending transfer.NOTABLEExtended dormancy on a sanctioned balance of this magnitude warrants continuous monitoring and law-enforcement reporting.
Synthesis

OFAC SDN-confirmed Central Bank of Iran USDT reserve wallet. 12.92M unfrozen. Connected to second CBI wallet (TTiDLWE6) via relay infrastructure. Dormant since 2024. REJECT/SAR mandatory.

…A8U3GUQZH81 · TRON · 2026-05-30

S6 — OWNERSHIP ATTRIBUTION MODEL

Hypothesis Assessment

Central Bank of Iran — USDT reserve / accumulation wallet 90%

IRGC-affiliated entity operating under CBI designation 7%

Third-party Iranian actor sharing CBI infrastructure 3%

Probabilities sum to 100%. Attribution confidence: HIGH.

What This Means For You

Monitor for: (1) Any Tether freeze action on this address. (2) Reactivation of large USDT movements after 2024 dormancy. (3) New relay nodes connecting to this address. (4) Legal/regulatory action referencing this address in OFAC enforcement press releases.

…A8U3GUQZH81 · TRON · 2026-05-30

S7 — LINKS, DIGITAL FOOTPRINT & PUBLIC RECORD

Government Records · Press Coverage · Research & Analytics · Blockchain Intelligence

Media & Press
PeckShield Alert — @PeckShieldAlert on X (Twitter)
2026-04-23
First public alert identifying TNiq9AXBp9EjUqhDhrwrfvAA8U3GUQZH81 and TTiDLWE6fZK8okMJv6ijg42yrH6W2pjSr9 as addresses blacklisted by Tether on TRON, holding $344M USDT combined. Direct on-chain confirmation of the Tether freeze linked to U.S. Operation Economic Fury.
TRM Labs — OFAC Sanctions Crypto Addresses Associated with Central Bank of Iran
2026-04-24
TRM Labs transaction analysis confirming the two wallets accumulated ~$370M across ~1,000 deposits since March 2021. This address shows <$16M outflows against $228M+ received. Accumulation concluded late 2023; funds dormant until April 2026 freeze — consistent with sovereign reserve storage. IRGC-Qods Force and Hezbollah linkages documented.
Chainalysis — OFAC Updates Central Bank of Iran Designation (April 2026)
2026-04-24
Chainalysis confirmed OFAC designated TNiq9AXBp9EjUqhDhrwrfvAA8U3GUQZH81 and TTiDLWE6fZK8okMJv6ijg42yrH6W2pjSr9 as property of Bank Markazi with links to IRGC-Qods Force and Hezbollah. Tether froze $344M USDT in coordinated action on the same date as the designation.
Arkham Intelligence — Central Bank of Iran: Track The State's Crypto Holdings
2026-05-14
Arkham publicly mapped Iran central bank wallets following the OFAC designation. Confirms this address within the Arkham 'Central Bank of Iran' entity cluster. Entity page created for ongoing analyst tracking and network graph analysis of related addresses.
OSINT Summary

Arkham (Central Bank of Iran entity cluster), OKLink (#Blocked #Sanction), OFAC SDN list, US Treasury press releases, UN Panel of Experts reports, DoJ Operation Economic Fury, Chainalysis crypto crime reporting — all independently corroborate CBI attribution and sanctions status.

…A8U3GUQZH81 · TRON · 2026-05-30

S8 — RECOMMENDED FURTHER INVESTIGATION

Priority Actions & Engagement Opportunities

P1 ·
Investigator Assessment

REJECT all transactions. File SAR if prior interaction. Escalate to compliance officer for secondary sanctions assessment. Notify Tether of unfrozen SDN balance.

…A8U3GUQZH81 · TRON · 2026-05-30

APPENDIX A — MASTER SOURCE LIST

REFSOURCE
S1On-chain dataset -- TRC-20 Transfers
https://tronscan.org/#/address/TNiq9AXBp9EjUqhDhrwrfvAA8U3GU…
Full TRC-20 transfer history via Tronscan API. Retrieved 2026-05-30.
S2On-chain dataset -- Raw Transactions
https://tronscan.org/#/address/TNiq9AXBp9EjUqhDhrwrfvAA8U3GU…
Full transaction log via Tronscan API. Retrieved 2026-05-30.
S3Arkham -- Address Profile
https://intel.arkm.com/explorer/address/TNiq9AXBp9EjUqhDhrwr…
Screenshot captured 2026-05-30. File: screenshot_arkham.png
S4Tronscan -- Address Profile
https://tronscan.org/#/address/TNiq9AXBp9EjUqhDhrwrfvAA8U3GU…
Screenshot captured 2026-05-30. File: screenshot_tronscan.png
S5Oklink -- Address Profile
https://www.oklink.com/tron/address/TNiq9AXBp9EjUqhDhrwrfvAA…
Screenshot captured 2026-05-30. File: screenshot_oklink.png
…A8U3GUQZH81 · TRON · 2026-05-30

APPENDIX B — GLOSSARY OF TERMS

TERMDEFINITION
OFACOffice of Foreign Assets Control — U.S. Treasury body that administers economic and trade sanctions; its Specially Designated Nationals (SDN) list prohibits U.S. persons from transacting with listed individuals, entities, and addresses.
SDN (Specially Designated National)An individual, entity, or address placed on the OFAC SDN list; all property and interests in property subject to U.S. jurisdiction are blocked, and U.S. persons are prohibited from dealing with SDN-listed parties.
Operation Economic FuryApril 2026 U.S. Treasury campaign targeting Iranian financial networks; resulted in the OFAC SDN designation of TNiq9AXBp9EjUqhDhrwrfvAA8U3GUQZH81 and TTiDLWE6fZK8okMJv6ijg42yrH6W2pjSr9, and a coordinated $344M Tether freeze.
Tether Freeze / BlacklistTether's contractual ability to render USDT tokens non-transferable at a specific address; exercised on April 23–24, 2026 against both CBI-designated wallets, locking ~$344M combined.
Bank Markazi (CBI)The Central Bank of the Islamic Republic of Iran (Bank Markazi Jomhouri Islami Iran) — Iran's central banking authority, designated as an SDN under OFAC Iran sanctions programs since 2019 for financing terrorism and weapons proliferation.
IRGC-Qods ForceIslamic Revolutionary Guard Corps Quds Force — the external operations unit of the IRGC, designated as a Foreign Terrorist Organization; OFAC linked this wallet cluster to IRGC-Qods Force and Hezbollah in its April 2026 action.
Relay NodeIn this report, a wallet that acts as an intermediary: receives funds from one source and redistributes them to multiple destinations, obscuring the direct link between origin and final recipient. TCXfhTDMuS6pbfCEoACPcBf2EnnhMAAEWh is the primary relay node in this network.
TRC-20A token standard on the TRON blockchain analogous to Ethereum’s ERC-20; USDT (Tether) issued under TRC-20 is the dominant stablecoin used in this case for value storage and transfer.
TERMDEFINITION
USDT (Tether)USD Tether — the world’s largest stablecoin by market cap, pegged 1:1 to the U.S. dollar; issued by Tether Ltd. on multiple blockchains including TRON. Contractually blacklistable by Tether Ltd. at specific addresses.
Secondary Sanctions RiskThe risk that non-U.S. persons or entities may face U.S. sanctions consequences for conducting transactions with SDN-listed parties, even when the transaction does not touch the U.S. financial system.
SAR (Suspicious Activity Report)A regulatory filing required of financial institutions under the Bank Secrecy Act (BSA) when suspicious transactions are detected; mandatory for any prior interaction with an OFAC-designated address.
Accumulation PatternA wallet behaviour characterised by high inflow retention and minimal outflows; in this case, 93.1% of received funds (\$228.65M in, \$15.73M out) were retained, consistent with sovereign reserve storage.
Dormancy PhaseA period of no material on-chain activity; this wallet entered dormancy from approximately January 2024 until the April 2026 Tether freeze, holding a static balance of \$212.92M for ~16 months.
Closed-Loop Circular FlowA transaction pattern in which funds are sent to a counterparty and a portion is subsequently returned to the originating wallet; here, \$166.5M was sent to TCXfhTDMuS and \$11.2M returned, creating artificial volume while obscuring net fund flows.
AML (Anti-Money Laundering)The set of laws, regulations, and procedures designed to prevent the generation of income through illegal actions; in crypto context, includes sanctions screening, counterparty attribution, transaction pattern analysis, and suspicious activity reporting.