Map
PDF
KALLISTI BLOCKCHAIN FORENSICS
TRC-20 (USDT primary asset) + native TRX ---
Target Wallet Address
TSDHK2dr4iAeDRTsmSMXz2kLgJdK1jnhyd
Report Date: 2026-06-03  ·  Prepared by Kallisti Blockchain Forensics
…LgJdK1jnhyd · TRON · 2026-06-03

S0 — Executive Summary

Attributed Entity  ·  TRON
Unattributed — Tether Blacklisted
TSDHK2dr4iAeDRTsmSMXz2kLgJdK1jnhyd
USDT In
$1.79M
36 inbound events
USDT Out
$0.00
0 outbound events
Balance
$1.79M
Current USDT on-chain
Active Span
710
days · 1.95 years
Transactions
931
36 USDT in · 0 USDT out
Counterparties
26
distinct USDT counterparties
AML Risk Score
85CRITICAL
Clear
Low
Medium
High
Critical
Intelligence Brief
Case Facts
Wallet AddressTSDHK2dr4iAeDRTsmSMXz2kLgJdK1jnhyd
BlockchainTRON mainnet · TRC-20 USDT
First Seen2024-06-20 17:00:36 UTC
Last Active2026-05-31 19:41:21 UTC
Account Age710 days (1.95 years)
Primary TokenUSDT (…8otSzgjLj6t)
TRX Balance6.0100 TRX
Counterparty Exposure by Category
Private / Unattributed
$1.79M
Finding 01  · 
Tether Blacklist — Confirmed
OKLink flags address as 'Blocked'; Arkham flags 'Suspicious Banned by USDT'. The entire $1.79M USDT balance is permanently frozen by contract-level enforcement.
Finding 02  · 
Two-Hop Relay Chain
TM3tNvmfwH2XXQ67qZnoZaWzhnmB35Katv → TVrQ3eUjXkDnq5xJbv9TfQPdtTQcUXPJRd → TSDHK — exact $1,790,000 passthrough at each hop with zero intermediate retention. All nodes unattributed.
Finding 03  · 
Zero Outflows — 710 Days
No outbound USDT transfer since wallet creation. Operator has been unable to move funds since Tether intervention.
Finding 04  · 
Transit Swap DeFi Tag
OKLink records a #Transit Swap User tag alongside the Blocked flag, indicating prior TRON DeFi aggregator activity by the wallet operator.
Supporting Detail
AML Scorecard
Sanctions (OFAC/EU/UN)
CLEAR
Fraud/Scam Exposure
FLAG
Ransomware/Darknet
CLEAR
Mixer/CoinJoin
CLEAR
Exchange Source Verif.
MONITOR
Structuring/Layering
ELEVATED
Third-Party Risk
MONITOR
Address Poisoning
CLEAR
Key Dates
2024-06-20$1,790,000 USDT Receipt — Tether Freeze Applied
Attribution Hypotheses
H1Fraud Proceeds — Tether Freeze on Illicit Funds
75%
H2Victim Wallet — Fraud Target Preserved by Tether
20%
H3Erroneous Blacklisting
5%
Fraud proceeds wallet frozen by Tether Limited — $1.79M USDT irrecoverable; two-hop relay chain fully unattributed
Investigator Summary
This TRON TRC-20 address received $1,791,526.83 USDT on 2024-06-20 via a two-hop relay chain and has never disbursed any funds — the entire balance is permanently frozen under a Tether Limited blacklist order. Both OKLink and Arkham independently confirm the blocked/banned status, establishing a confirmed illicit-origin determination by the USDT issuer. The combination of single large receipt, zero outflows over 710 days, and verified Tether freeze is consistent with fraud or theft proceeds intercepted by Tether's compliance mechanism.
Recommended ActionsTrace TM3tNvmfwH2XXQ67qZnoZaWzhnmB35Katv (hop-2 originator) upstream to identify the primary source of the $1,790,000 USDT.  ·  Contact Tether Limited compliance to confirm the blacklist basis (law enforcement referral, proactive freeze, or court order) and determine whether a criminal investigation is already underway.
…LgJdK1jnhyd · TRON · 2026-06-03

S1 — TARGET PROFILE, FINANCIALS & ACTIVITY

Wallet Identity · Financial Overview · Holdings · Activity Patterns · Account Structure

DEPLOYMENT 100.0% Net Balance USDT IN$1.79MSent Out$0.00Net Balance$1.79MCURRENT HOLDINGSUSDT100.00%$1.79M$1.79MTRX6.0100 TRX$2.00COUNTERPARTIESPrivate / Unattributed99.9%OTC / BrokerRegulated CEXDeFi / ProtocolMixer / ObfuscationGovernmentCriminal / FraudSanctioned Entity
EntityBlocked
BlockchainTRON mainnet · TRC-20 USDT wallet
Account Age710 days (1.95 years) ‖ Active: 2024-06-20 17:00:36 UTC → 2026-05-31 19:41:21 UTC
TRX Balance6.0100 TRX
Transactions931 total · 36 USDT transfers (36 in · 0 out) · 26 counterparties
Total USDT In$1.79M
Total USDT Out$0.00
Net Balance$1.79M

Activity Overview

BY YEAR Jun Jul Aug Sep Oct Nov Dec 2025 Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec 2026 Feb Mar Apr May Jun $2M $1K $1K InflowOutflow BY HOUR (UTC) 2 4 6 8 00 06 12 18 23 BY DAY Mon 5 Tue 3 Wed 5 Thu 15 Fri 4 Sat 2 Sun 2

Behavioral Classification

This wallet exhibits a pure receipt-and-hold pattern with confirmed Tether freeze — a static terminus in a two-hop relay chain. Its behavioral profile is consistent with a fraud or theft destination wallet whose operator lost practical control of the funds upon Tether intervention. No exchange, custodial, DeFi protocol, or commercial activity has been detected beyond a historical Transit Swap interaction noted in OKLink metadata.

Transaction Size Profile

A single inbound transfer of $1,790,000 USDT constitutes 99.95% of all USDT value received. Subsequent inflows are sub-$1,000 probes. This size profile — one dominant institutional-scale receipt followed by silence — is inconsistent with retail accumulation, exchange infrastructure, or commercial VASP activity; it is consistent with a targeted fraud-proceeds deposit.

Operational Profile

Zero outflows across 710 days; the 6.010012 TRX float is minimal and has never been consumed for fees. A #Transit Swap User tag (OKLink) indicates prior interaction with the Transit Swap DeFi aggregator — likely as a fund-movement tool before the freeze — but no active positions remain. The 931 raw transaction count is inflated by TRON spam airdrop tokens.

Temporal Activity Pattern

Thursday dominates at 41.7% of USDT events; Monday and Wednesday at 13.9% each. UTC 08:00 peak (22.2%); secondary peaks 15:00 (11.1%) and 09:00 (8.3%); dead zones 03:00, 06:00–07:00, 18:00–20:00. Post-freeze distribution is probe-dominated and cannot reliably characterise operator hours. The single meaningful transaction (2024-06-20 17:00 UTC) maps to late-night East Asia; most probable timezone UTC+7 to UTC+9, low confidence.

Automation Assessment

No evidence of automated operation is present. The single substantive transaction appears manual or semi-manual. All post-freeze inflows are passively received external probes, not operator-generated.

Sources
S1Tronscan — On-chain dataset · tronscan.org/#/address/TSDHK2dr4iAeDRTsmSMXz2kLgJdK1jnhyd
S2OKLink — TRON Address Detail · www.oklink.com/tron/address/TSDHK2dr4iAeDRTsmSMXz2kLgJdK1jnh…
…LgJdK1jnhyd · TRON · 2026-06-03

S2 — TRANSACTION NETWORK & FUND FLOW

Counterparty Map · Inflow Architecture · Outflow Architecture

99.9% …QcUXPJRd 99.9% …PgXAakQN 0.0% …t4JDjzQy 0.0% …GfCpNdiG 0.0% …nXqyBG9R 0.0% …dK1jnhyd$1.79MTARGET NODE: Exchange Unattributed Illicit/SDN OTC/Clean Mixer node size ∝ volume · edge weight ∝ share

Inflow

Upstream · Top 5 Funders

IDAddressVolume inAttributionRisk
A1TVrQ3eUjXkDnq5xJbv9TfQPdtTQcUXPJRd$1.79MUnattributedMEDIUM
A2TVRei3E1hEq42UZKSzk29R3cnZPgXAakQN$800.00UnattributedMEDIUM
A3TKNaZqrMt1ef3oojYHmgJPJmM6t4JDjzQy$600.00UnattributedMEDIUM
A4TFBmyki5C8FJzqaRaCwqRC5p89GfCpNdiG$36.00UnattributedMEDIUM
A5TJP3ikWfsFsbbVHc6M424ii2TbnXqyBG9R$30.00UnattributedMEDIUM

Outflow

Downstream · Top 5 Destinations

No outbound transactions as of 31/05/2026

…LgJdK1jnhyd · TRON · 2026-06-03

S3 — OPERATIONAL PROFILE & SECURITY ASSESSMENT

Account Structure · Protocol Interactions · Threat Exposure

Security
Rating
COMPROMISEDADEQUATEPROFICIENT
22
COMPROMISED

Account Structure

Address TypeTRON Account (EOA)
Script EncodingTRC-20 USDT wallet
UTXO CountN/A — TRON account model
ClusteringNo Arkham cluster; labeled 'Suspicious Banned by USDT'
Service LabelNone — Unattributed; confirmed Tether blacklisted
VASP ExposureNone confirmed
Wallet SoftwareUnknown; prior Transit Swap DeFi aggregator interaction noted

Protocol Interactions

CategoryStatus
Exchange Deposits / WithdrawalsNONE
none confirmed
DeFi / Smart Contract InteractionLIMITED
Transit Swap aggregator (historical — per OKLink tag; no active positions)
Lightning Network ChannelsNONE
Ordinals / InscriptionsNONE
Mixing / CoinJoin ServicesNONE
Cross-Chain BridgesNONE
Sanctions-Listed Address ContactNONE
none (Tether blacklist is issuer contractual action, not OFAC/EU/UN sanction)

Threat Exposure

DateCategorySourceNominalOutcome
2024-06-20Issuer Freeze (Tether)Tether Limited$1,791,526.83 USDT frozen in fullONGOING
Operational Summary

Network analysis is constrained by the absence of outbound flows. The inbound relay chain is fully resolved at two hops. Beyond TM3t, the upstream chain was not traced in this investigation. The relay wallet TVrQ3e holds 21.644 TRX and zero USDT, consistent with a depleted transit wallet post-forwarding. All five FLOW_INFLOWS counterparties are unattributed; no exchange or entity clustering has been established for any node in the identified chain.

…LgJdK1jnhyd · TRON · 2026-06-03

S4 — AML / RISK ASSESSMENT

Sanctions Fraud/Scam Ransomware Mixer Exch.Source Structuring Third-Party Addr.Poison CRITERION EXPOSURE RATING Sanctions (OFAC/EU/UN) CLEAR Fraud/Scam Exposure HIGH Ransomware/Darknet CLEAR Mixer/CoinJoin CLEAR Exchange Source Verif. LOW Structuring/Layering LOW Third-Party Risk LOW Address Poisoning CLEAR OVERALL AML RISK 85 HIGH Scale: CLEAR=no exposure detected · MEDIUM=indirect signal · HIGH=direct confirmed exposure
CRITERIONFINDINGASSESSMENT
1. Sanctions (OFAC/EU/UN)
No OFAC, EU, or UN designation found. Tether blacklist is a contractual issuer action, not a government sanction designation.
CLEAR
2. Fraud/Scam Exposure
Confirmed Tether blacklist — OKLink 'Blocked address' and Arkham 'Suspicious Banned by USDT' independently corroborate a freeze on the full $1,791,526.83 USDT balance, consistent with confirmed fraud or theft proceeds.
FLAG
3. Ransomware/Darknet
No ransomware attribution, darknet marketplace association, or threat-intel flag identified.
CLEAR
4. Mixer/CoinJoin
No mixer or CoinJoin interaction detected. Sequential relay wallets are layering, not mixing — no obfuscation service involved.
CLEAR
5. Exchange Source Verif.
All five inbound counterparties are unattributed. No exchange or VASP sourcing has been established for any node in the identified chain.
MONITOR
6. Structuring/Layering
Two-hop relay with exact $1,790,000 passthrough and zero intermediate retention at each stage. Same-amount sequential forwarding without any fee, slippage, or intermediate balance retention is a hallmark of deliberate rapid layering.
ELEVATED
7. Third-Party Risk
All relay and inbound counterparties are unattributed. Transit Swap DeFi tag noted on OKLink — prior aggregator interaction by wallet operator adds moderate third-party protocol exposure.
MONITOR
8. Address Poisoning
Subsequent sub-$1,000 inflows are external monitoring probes, not an address-poisoning attack pattern directed at this wallet.
CLEAR
Assessment

This wallet is subject to a confirmed Tether Limited blacklist — a unilateral contract-level freeze by the USDT issuer under the TRC-20 contract's admin key powers. This mechanism is distinct from, but functionally equivalent to, OFAC sanctions: the balance is frozen and non-transferable, but the authority derives from Tether's terms of service rather than a government designation. Tether has historically applied blacklists in response to law enforcement requests following confirmed hacks or fraud, proactive fraud prevention actions, and court orders. The presence of a blacklist on a $1.79M balance wallet implies Tether has received or independently identified evidence of illicit origin — constituting a material compliance finding. Any institution with counterparty exposure to wallets in this relay chain should conduct enhanced due diligence and consider SAR obligations under applicable AML regulations.

…LgJdK1jnhyd · TRON · 2026-06-03

S5 — NOTABLE EVENTS & ANOMALIES

Flagged Patterns & Significant Observations

FROZEN BALANCE 2024-06 2026-05 2025 2026 $1.79M USDT Receipt — Tether Freeze A-01 2024-06-20 A-02 Zero Outflows HIGH — critical finding HIGH — monitor LOW — contextual
IDDateEventSeveritySignificance
A-012024-06-20$1,790,000 USDT Receipt + Tether Blacklist. Single large inbound transfer via two-hop relay; entire balance subsequently frozen by Tether Limited. OKLink and Arkham both confirm blacklist status.CRITICALConfirmed illicit-origin determination by Tether Limited. The $1.79M USDT is permanently non-transferable — the wallet is an irrecoverable frozen terminus.
A-022024-06-20Zero Outflows — 710-Day Dormancy. No outbound USDT transfer has occurred since wallet creation. Operator has been unable to move funds since Tether intervention.NOTABLEConsistent with a Tether-frozen address whose operator cannot transact. Sustained dormancy over 710 days with active balance confirms the freeze is effective.
Synthesis

TSDHK2dr4iAeDRTsmSMXz2kLgJdK1jnhyd is a confirmed Tether-blacklisted TRON wallet holding $1,791,526.83 USDT permanently frozen since receipt on 2024-06-20. The single $1.79M inflow arrived via a two-hop relay (TM3t → TVrQ3e → TSDHK), both hops fully unattributed. Zero outflows in 710 days. AML risk: HIGH — Fraud/Scam 0.85 (confirmed Tether freeze); Structuring 0.25 (two-hop exact-value relay). Attribution: Unattributed — Tether Blacklisted. Security: COMPROMISED (22). Recommended priority action: upstream trace of TM3tNvmfwH2XXQ67qZnoZaWzhnmB35Katv and Tether compliance inquiry to establish criminal investigation status.

…LgJdK1jnhyd · TRON · 2026-06-03

S6 — OWNERSHIP ATTRIBUTION MODEL

Hypothesis Assessment

Fraud Proceeds — Tether Freeze on Illicit Funds 75%

Victim Wallet — Fraud Target Preserved by Tether 20%

Erroneous Blacklisting 5%

Probabilities sum to 100%. Attribution confidence: 75 / 20 / 5.

What This Means For You

This wallet holds $1.79M in USDT that is legally and technically frozen by Tether Limited — the funds cannot be moved, swapped, bridged, or transferred, and have zero practical utility to any current holder. Any institution that received funds from or sent funds to nodes in this relay chain should treat this as a confirmed fraud-exposure signal and conduct enhanced due diligence on those counterparties. If this wallet address or any node in its relay chain appears in a customer's transaction history, a SAR filing is strongly advisable under standard AML compliance obligations.

…LgJdK1jnhyd · TRON · 2026-06-03

S7 — LINKS, DIGITAL FOOTPRINT & PUBLIC RECORD

Government Records · Press Coverage · Research & Analytics · Blockchain Intelligence

Blockchain Explorers
OKLink
2026-06-02
Address flagged 'Blocked address' by OKLink. Balance confirmed: 1,791,526.83 USDT + 6.010012 TRX. Risk alert active at time of scrape.
Tronscan
2026-06-02
Full on-chain history retrieved. 931 total transactions; zero outbound USDT transfers. Tether blacklist status confirmed.
Government & Official Records
OFAC SDN List
2026-06-02
NEGATIVE SWEEP: Address not found in OFAC Specially Designated Nationals list as of 2026-06-02.
Media & Press
WebSearch
2026-06-02
NEGATIVE SWEEP: No news articles, forum posts, or adverse media referencing this address found in open web search as of 2026-06-02.
Research & Analytics
Chainabuse
2026-06-02
NEGATIVE SWEEP: No community reports filed for this address on Chainabuse as of 2026-06-02.
Intelligence Platforms
Arkham Intelligence
2026-06-02
Address labeled 'Suspicious Banned by USDT' by Arkham. No entity cluster assigned. Label confirmed via screenshot 2026-06-02.
OSINT Summary

Fund flow terminates at this wallet. No outbound transfers exist. The inbound relay chain is fully resolved at two hops (TM3t → TVrQ3e → TSDHK); upstream of TM3t is uncharted and warrants further investigation.

…LgJdK1jnhyd · TRON · 2026-06-03

S8 — RECOMMENDED FURTHER INVESTIGATION

Priority Actions & Engagement Opportunities

P1Upstream Trace — TM3tNvmfwH2XXQ67qZnoZaWzhnmB35Katv — Trace the hop-2 originator wallet upstream to identify the primary source of the $1,790,000 USDT. Determine whether TM3t connects to a known exchange, OTC desk, or prior fraud-linked address. · On-chain
P2Tether Compliance Inquiry — Contact Tether Limited compliance to confirm the basis for the blacklist (law enforcement referral, proactive detection, or court order) and whether a criminal investigation is currently active. · Regulatory
P3SAR Filing Assessment — Assess SAR obligations for any institution with documented counterparty exposure to TSDHK or any node in the identified relay chain (TM3t, TVrQ3e). · SAR
P4OSINT — Advanced Sweep — Conduct advanced OSINT on TM3tNvmfwH2XXQ67qZnoZaWzhnmB35Katv; search for any reported theft, fraud, or exchange hack in June 2024 involving a $1.79M USDT amount on TRON. · OSINT
Investigator Assessment

Priority investigation action: trace TM3tNvmfwH2XXQ67qZnoZaWzhnmB35Katv upstream — this is the originator of the $1,790,000 and the key to establishing whether this freeze is connected to a known exchange hack, fraud campaign, or law enforcement action. Contact Tether Limited compliance to determine the blacklist basis; their answer will indicate whether a criminal investigation is already underway and whether victim restitution proceedings have been initiated. Flag all relay chain addresses in your monitoring systems.

…LgJdK1jnhyd · TRON · 2026-06-03

APPENDIX A — MASTER SOURCE LIST

REFSOURCE
S1On-chain dataset -- TRC-20 Transfers
https://tronscan.org/#/address/TSDHK2dr4iAeDRTsmSMXz2kLgJdK1…
Full TRC-20 transfer history via Tronscan API. Retrieved 2026-06-03.
S2On-chain dataset -- Raw Transactions
https://tronscan.org/#/address/TSDHK2dr4iAeDRTsmSMXz2kLgJdK1…
Full transaction log via Tronscan API. Retrieved 2026-06-03.
S3Arkham -- Address Profile
https://intel.arkm.com/explorer/address/TSDHK2dr4iAeDRTsmSMX…
Screenshot captured 2026-06-03. File: screenshot_arkham.png
S4Tronscan -- Address Profile
https://tronscan.org/#/address/TSDHK2dr4iAeDRTsmSMXz2kLgJdK1…
Screenshot captured 2026-06-03. File: screenshot_tronscan.png
S5Oklink -- Address Profile
https://www.oklink.com/tron/address/TSDHK2dr4iAeDRTsmSMXz2kL…
Screenshot captured 2026-06-03. File: screenshot_oklink.png
…LgJdK1jnhyd · TRON · 2026-06-03

APPENDIX B — GLOSSARY OF TERMS

TERMDEFINITION
Tether BlacklistA contract-level freeze applied by Tether Limited using the TRC-20/ERC-20 admin key, rendering a designated address permanently unable to transfer USDT; applied upon confirmation of illicit origin or via law enforcement directive.
Transit SwapA TRON-ecosystem DeFi aggregator enabling token swaps across multiple liquidity pools; historical interaction with this service is noted in OKLink address metadata.
Two-Hop RelayA fund movement pattern in which proceeds pass through two intermediate wallets before reaching a terminus, creating layering obfuscation between the originating source and the final destination.
Terminus WalletThe final destination address in a fund movement chain, from which no further outbound transfers occur; in this case, the terminus is frozen and the operator cannot transact.