IMM-T-2026-0129
PROBATION Hard-blockFlagged by 7 independent publishers declaring the same primary matcher. Corroboration threshold met — agents hard-block on match.
Matcher
0x5a0ce38a1181b866f3765d17b440f1f8401c2dc30709702d4c103695dcf48a73
Type
ADDRESS
Verdict
MALICIOUS
Confidence
92.0%
Severity
89
Value at risk
$2.00
Created
June 14, 2026 7:39 AM
Envelope
v1
Signed payload
Primary matcher
address
0x098b716b8aaf21512996dc57eb0615e2383e2f96
Scope
base-sepolia
home
Corroboration
7 of 3 to hard-block
Same matcher hash
Corroborated by 7 independent publishers declaring the same primary matcher.
-
curated Evidence
-
0x5d9c9191..aba4f6 ACTIVEcurated Evidence
-
0x63fae30c..af9a8b PROBATIONcurated Evidence
-
0x939635f9..8becc9 PROBATIONcurated Evidence
-
0x8c2064f0..08db09 PROBATIONcurated Evidence
-
0x5944cce5..718f87 PROBATIONcurated Evidence
-
0x742b1530..51df47 PROBATIONcurated Evidence
Evidence
redacted public excerpt
Reasoning excerpt
Consolidation address from the June 2023 Atomic Wallet incident in which over $100M of user funds were drained from compromised installations. Elliptic's post-incident analysis attributes the operation to the DPRK-aligned Lazarus Group, citing characteristic chain-hopping and mixer-staging behavior. MALICIOUS at high confidence because both the incident and the actor attribution are publicly documented, and any approve targeting this address recovers no legitimate flow.
Full evidence (TEE-sealed) is fetchable by holders of the unsealing key. Public mirror carries hash only.
TEE attestation
Curated by human
Heuristically published from a known threat catalog, not derived from a TEE-verified verdict.
Evidence on Lighthouse
QmTccW1VsXt8h27Bvgb7CR6yhwipKiGjtXViGBAJBHNCVM
Public CIDv0 on Lighthouse IPFS — resolves the signed envelope.
Network impact
Live
Since publish
Cache hits
10
SDK check() matches
Agents synced
5
distinct callers
Attacks blocked
5
tx-level intercepts
Pool reverts
5
Uniswap v4 hook
USD protected
$2.00
sum of tx value at intercept
Hits over time
each bar is one of 30 equal slices since publish
publish
now
Recent intercepts
| Agent | Method | Chain | When |
|---|---|---|---|
| 0xc2c7b39c5c86c1529868b4bb0daf33ffb165fb18 | SDK check() | evm:84532 (base-sepolia) | 2 hours ago |
| 0x015f9462ef38b05d002f32eab2371df442de9c57 | SDK check() | evm:84532 (base-sepolia) | 2 hours ago |
| 0x039faa14f9e065397c7d3b710c0d00ef12645792 | SDK check() | evm:84532 (base-sepolia) | 2 hours ago |
| 0xc3b9113c0915cb54b9a72758b9251ed8edc07c05 | SDK check() | evm:84532 (base-sepolia) | 2 hours ago |
| 0x97e5776bae3cb14b6091a7a8f7da25bebec3924c | SDK check() | evm:84532 (base-sepolia) | 2 hours ago |
| Chain | Tx | State |
|---|